Security frames in uwband

By using random numbers built on block or superblock time structures in ultra-wideband communication, the problem of difficulty in constructing unique random numbers in the prior art is solved, and effective protection of secure frames and security of communication is achieved.

CN119968873APending Publication Date: 2025-05-09HUAWEI TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202380070073.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-04-03
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

When the prior art enhances the accuracy of IEEE 802.15.4z ranging measurement, it is difficult to effectively build a unique random number for authentication encryption, affecting communication security.

Method used

By generating a secure frame scheme for ultra-wideband, a random number composed of identification information, round indexes and block indexes are constructed to protect the secure frames using a block-based time structure or a super-block-based time structure.

Benefits of technology

It realizes the execution of secure operations in ultra-wideband communication to ensure the security and accuracy of communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119968873A_ABST
    Figure CN119968873A_ABST
Patent Text Reader

Abstract

The embodiment of the invention relates to a method, equipment and device for communication and a computer readable storage medium. In some embodiments, a first security frame may be generated to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, where the block-based time structure or the superblock-based time structure includes a plurality of blocks, and where the block-based time structure includes a first block and a second block. Each block of the plurality of blocks comprises a plurality of rounds, each round of the plurality of rounds comprises a plurality of time slots, the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the second round. The block index is an index of the first block. Accordingly, a secure operation may be performed, and it may be ensured that communication is secure.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Exemplary embodiments of the present invention generally relate to the field of telecommunications, and more particularly, to methods, devices, apparatuses, and computer-readable storage media for communications. Background Art

[0002] One of the main purposes of the enhancement is to improve the accuracy of ranging measurements in Institute of Electrical and Electronic Engineers (IEEE) 802.15.4z.A block-based temporal structure or a super-block-based temporal structure can be used for ranging.

[0003] In ranging, an authenticated encryption with associated data (AEAD) security operation is proposed. An important input of the AEAD security operation is a unique random number (nonce). However, how to construct the random number requires further study. Summary of the invention

[0004] In general, exemplary embodiments of the present invention provide a scheme for security frames in ultra-wideband.

[0005] In a first aspect, a method is provided, comprising: generating a first security frame, the first security frame to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the first block; and sending the first security frame. Therefore, a security operation can be performed and communication can be guaranteed to be secure.

[0006] In some examples, the identification information includes a time slot index, which is an index of the time slot in which the first security frame is sent. Since the first security frame is sent in a specific time slot, the first random number can be used to protect the first security frame.

[0007] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index. In some examples, the first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number. In the case where the first number can be predefined, the agreement between the transmitter and the receiver can be simplified. In the case where the first number is variable, there may be some remaining bits in the first random number, which can be used for other information.

[0008] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is a packet number of the first security frame. Since the first PN is specific to the first security frame, the first random number can be used to protect the first security frame.

[0009] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0010] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0011] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0012] In some examples, a sum of the first number, the second number, and the third number is equal to a predefined total number.

[0013] Therefore, the first random number may be constructed by including the identification information, the round index, and the block index. Therefore, the first random number may be used to protect the first security frame.

[0014] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is in the plurality of blocks. Therefore, the period index can also be used to construct the first random number, and accordingly, the security key can be used for a longer time.

[0015] In some examples, the first random number includes a first block indicator indicating that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0016] In some examples, the first security frame includes the block index and the round index. Thus, the first security frame may include the block index and the round index so that the receiver can correctly construct the random number for deprotection.

[0017] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; a first round index presence indicator indicating the presence of the first round index. In the case where the block index or round index is a default value, the block index or round index may not be sent, thereby reducing signaling overhead.

[0018] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure. Therefore, whether the frame is secure can be determined based on the security indicator.

[0019] In some examples, the method further includes: generating a second security frame to be transmitted, the second security frame being protected by a second random number constructed based on a second PN, wherein the second PN is a packet number of the second security frame; and transmitting the second security frame. Thus, the PN can be used to construct a random number for a frame that is not based on a block-based time structure or a super-block-based time structure.

[0020] In some examples, the second random number includes a field having a predefined number of octets that carries the second PN.

[0021] In some examples, the second random number includes a second block indicator indicating that the second security frame is sent outside the block-based timing structure or the super-block-based timing structure.

[0022] In some examples, the second security frame includes a PN field carrying the second PN.

[0023] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0024] In some examples, the second security frame includes a security payload, and wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second time slot index presence indicator indicating whether a second time slot index is included.

[0025] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0026] In some examples, at least one of the second block index presence indicator, the second round index presence indicator, or the second slot index presence indicator indicates that the corresponding index is not included and implicitly indicates that the corresponding index is a default index.

[0027] In a second aspect, a method is provided, comprising: receiving a first security frame, the first security frame to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, and each of the multiple rounds includes multiple time slots; unprotecting the first security frame according to a first random number, wherein the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0028] In some examples, the identification information includes a time slot index, which is an index of the time slot in which the first security frame is transmitted.

[0029] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index. In some examples, the first number is determined based on the number of the plurality of time slots in each round, or the first number is a first predefined number.

[0030] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is the packet number of the first security frame. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0031] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0032] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0033] In some examples, a sum of the first number, the second number, and the third number is equal to a predefined total number.

[0034] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

[0035] In some examples, the first random number includes a first block indicator indicating that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0036] In some examples, the first security frame includes the block index and carries the round index.

[0037] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0038] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0039] In some examples, the method also includes: receiving a second security frame, the second security frame is not sent according to the block-based time structure or the super-block-based time structure; and unprotecting the second security frame according to a second random number, the second random number is constructed according to a second PN, wherein the second PN is a packet number of the second security frame.

[0040] In some examples, the second random number includes a field having a predefined number of octets that carries the second PN.

[0041] In some examples, the second random number includes a second block indicator indicating that the second frame is transmitted outside of the block-based timing structure or the super-block-based timing structure.

[0042] In some examples, the second security frame includes a PN field carrying the second PN.

[0043] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0044] In some examples, the second security frame includes a security payload, wherein unprotecting the second security frame includes unprotecting the security payload based on the second random number, and wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second time slot index presence indicator indicating whether a second time slot index is included.

[0045] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0046] In some examples, the method further includes: determining that the corresponding index is a default index based on a determination that at least one of the second block index presence indicator, the second round index presence indicator, or the second time slot index presence indicator indicates that the corresponding index is not included.

[0047] In a third aspect, a device is provided, comprising: a generating module, configured to generate a first security frame, wherein the first security frame is to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure comprises a plurality of blocks, each of the plurality of blocks comprises a plurality of rounds, each of the plurality of rounds comprises a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the first block; and a sending module, configured to send the first security frame.

[0048] The device may include various modules for implementing the method described in the first aspect, which are not listed one by one here for the sake of brevity.

[0049] In a fourth aspect, a device is provided, comprising: a receiving module, configured to receive a first security frame, wherein the first security frame is to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, and each of the multiple rounds includes multiple time slots; a deprotection module, configured to deprotect the first security frame according to a first random number, wherein the first random number is constructed according to identification information associated with the first security frame, a round index, and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0050] The device may include various modules for implementing the method described in the first aspect, which are not listed one by one here for the sake of brevity.

[0051] In a fifth aspect, a method is provided, comprising: generating a first security frame to be sent in a block-based time structure or a super-block-based time structure, wherein the first security frame is protected by a first random number constructed based on a first basic packet number (basepacket number, BPN) and a first packet number (packet number, PN), the first BPN is associated with an initiator and a responder, and the first PN is the packet number of the first security frame; sending the first security frame.

[0052] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0053] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0054] In some examples, the first security frame includes a first PN field carrying the first PN.

[0055] In some examples, the first security frame indicates a first BPN.

[0056] In some examples, the first security frame includes a BPN presence field, and the BPN presence field carries a BPN presence indicator indicating whether the BPN field is included.

[0057] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0058] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0059] In some examples, the method further includes storing the first BPN associated with a first communication direction between an initiator and a responder.

[0060] In some examples, the method further includes sending a second security frame including a second PN that is less than a PN included in a previous frame of the third security frame.

[0061] In some examples, the method further includes sending a third security frame including the second BPN.

[0062] In a sixth aspect, a method is provided, comprising: receiving a first security frame sent in a block-based time structure or a super-block-based time structure; and unprotecting the first security frame according to a first random number, wherein the first random number is constructed based on a first basic packet number (BPN) and a first packet number (PN), the first BPN is associated with an initiator and a responder, and the first PN is a packet number of the first security frame.

[0063] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0064] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0065] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0066] In some examples, the first security frame includes a BPN presence field, and the BPN presence field carries a BPN presence indicator indicating whether the BPN field is included.

[0067] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0068] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0069] In some examples, the method further includes storing the first BPN associated with a first communication direction between an initiator and a responder.

[0070] In some examples, the method further includes: receiving a second security frame including a second PN; and updating the first BPN by increasing by 1 based on a determination that the second PN is less than a PN included in a previous frame of the third security frame.

[0071] In some examples, the method further includes: receiving a third security frame including a second BPN; and replacing the first BPN with the second BPN.

[0072] In the seventh aspect, a device is provided, comprising: a generation module, used to generate a first security frame to be sent in a block-based time structure or a super-block-based time structure, wherein the first security frame is protected by a first random number constructed based on a first basic packet number (BPN) and a first packet number (PN); the first BPN is associated with an initiator and a responder, and the first PN is the packet number of the first security frame; and a sending module, used to send the first security frame.

[0073] The device may include various modules for implementing the method of the fifth aspect, which are not listed one by one here for the sake of brevity.

[0074] In an eighth aspect, a device is provided, comprising: a receiving module for receiving a first security frame sent in a block-based time structure or a super-block-based time structure; a deprotection module for deprotecting the first security frame according to a first random number, wherein the first random number is constructed based on a first basic packet number (base packet number, BPN) and a first packet number (packet number, PN), the first BPN is associated with an initiator and a responder, and the first PN is the packet number of the first security frame.

[0075] The device may include various modules for implementing the method of the sixth aspect, which are not listed one by one here for the sake of brevity.

[0076] In a ninth aspect, a communication device is provided, comprising: a processor, configured to execute at least the method described in the first aspect, the second aspect, the fifth aspect or the sixth aspect together with a transceiver.

[0077] In a tenth aspect, a system is provided, comprising: the device described in the third aspect and the device described in the fourth aspect.

[0078] In the eleventh aspect, a system is provided, comprising: the device described in the seventh aspect and the device described in the eighth aspect.

[0079] In a twelfth aspect, a non-transitory computer-readable medium comprising program instructions is provided, wherein the program instructions are used to cause an apparatus to at least execute the method described in the first aspect, the second aspect, the fifth aspect or the sixth aspect.

[0080] In the thirteenth aspect, a computer program comprising instructions is provided, which, when executed by a device, causes the device to at least perform the method described in the first aspect, the second aspect, the fifth aspect or the sixth aspect.

[0081] It should be understood that the summary of the invention is not intended to identify the key or essential features of the embodiments of the present invention, nor is it intended to be used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0082] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:

[0083] Figure 1A A schematic diagram showing a block-based temporal structure;

[0084] Figure 1B A schematic diagram showing a superblock-based temporal structure;

[0085] Figure 1C A schematic diagram of an MMS ranging session is shown;

[0086] Figure 1D A schematic diagram showing the format of a compressed PSDU;

[0087] Figure 1E A schematic diagram showing the format of a compressed header IE frame only;

[0088] Figure 1F A schematic diagram showing the format of a random number;

[0089] Figure 2A An exemplary communication system is shown in which some embodiments of the present invention may be implemented;

[0090] Figure 2B Another exemplary communication system in which some embodiments of the present invention may be implemented is shown;

[0091] Figure 3 A signaling diagram illustrating a communication process provided by some exemplary embodiments of the present invention is shown;

[0092] Figure 4 A schematic diagram showing an exemplary NBA-MMS ranging session in a block-based time structure provided by some exemplary embodiments of the present invention;

[0093] Figure 5 shows a signaling diagram illustrating the process of an exemplary MMS ranging session provided by some exemplary embodiments of the present invention;

[0094] Fig. 6A A schematic diagram showing the format of a SOR frame provided by some exemplary embodiments of the present invention;

[0095] Figure 6B A schematic diagram showing a format of a random number for protecting a frame sent in an outer block structure provided by some exemplary embodiments of the present invention;

[0096] Fig. 7A A schematic diagram showing the format of a POLL frame provided by some exemplary embodiments of the present invention;

[0097] Figure 7B A schematic diagram showing a format of a random number for protecting a frame in a block structure provided by some exemplary embodiments of the present invention;

[0098] Figure 7C An example of constructing a random number for protecting a compressed frame provided by some exemplary embodiments of the present invention is shown;

[0099] Figure 8 A schematic diagram showing another format of a random number for protecting a frame in a block structure provided by some exemplary embodiments of the present invention;

[0100] Fig. 9 A schematic diagram showing the format of a secure SOR frame provided by some exemplary embodiments of the present invention;

[0101] Fig. 10A An exemplary session between an initiator and a responder 1 provided by some exemplary embodiments of the present invention is shown;

[0102] Fig. 10B An exemplary session between an initiator and a responder 2 provided by some exemplary embodiments of the present invention is shown;

[0103] Fig.11A A schematic diagram showing a time structure including a period provided by some exemplary embodiments of the present invention;

[0104] Fig. 11B A schematic diagram showing the format of another secure SOR frame provided by some exemplary embodiments of the present invention;

[0105] Fig. 11C A schematic diagram showing another format of a random number for protecting a frame in a block structure provided by some exemplary embodiments of the present invention;

[0106] Fig. 12AA schematic diagram showing the construction of random numbers in a super-block-based time structure provided by some exemplary embodiments of the present invention;

[0107] Fig. 12B A schematic diagram showing the construction of random numbers in a super-block-based time structure provided by some exemplary embodiments of the present invention;

[0108] Fig.13 A schematic diagram showing another exemplary MMS ranging session in a block-based time structure provided by some exemplary embodiments of the present invention is shown;

[0109] Fig.14 A signaling diagram illustrating a process of another exemplary MMS ranging session provided by some exemplary embodiments of the present invention is shown;

[0110] Fig.15A A schematic diagram showing a format of a random number for protecting a frame provided by some exemplary embodiments of the present invention;

[0111] Fig. 15B A schematic diagram showing another format of a random number for protecting a frame provided by some exemplary embodiments of the present invention;

[0112] Fig.16A A schematic diagram showing the format of a secure RPRT frame provided by some exemplary embodiments of the present invention;

[0113] Fig. 16B A schematic diagram showing the format of an ADV-POLL frame provided by some exemplary embodiments of the present invention;

[0114] Fig.17 An exemplary session between an initiator and responders 1 and 2 provided by some exemplary embodiments of the present invention is shown;

[0115] Fig.18 A signaling diagram illustrating a communication process provided by some exemplary embodiments of the present invention is shown;

[0116] Fig.19 A schematic diagram showing an exemplary MMS ranging session provided by some exemplary embodiments of the present invention is shown;

[0117] Fig. 20 shows a signaling diagram illustrating the process of an exemplary MMS ranging session provided by some exemplary embodiments of the present invention;

[0118] Fig.21A A schematic diagram showing the format of a security frame during the initialization and establishment phases provided by some exemplary embodiments of the present invention;

[0119] Fig.21BA schematic diagram showing a format of a security frame during a measurement period provided by some exemplary embodiments of the present invention;

[0120] Fig. 21C A schematic diagram showing the format of a secure SOR frame provided by some exemplary embodiments of the present invention;

[0121] Fig.21D A schematic diagram showing the format of a secure PRM-REQ or PRM-RESP frame provided by some exemplary embodiments of the present invention;

[0122] Fig.21E A schematic diagram showing the format of random numbers provided by some exemplary embodiments of the present invention;

[0123] Fig.22A An exemplary downlink session from an initiator to a responder 1 provided by some exemplary embodiments of the present invention is shown;

[0124] Fig. 22B An exemplary uplink session from the responder 2 to the initiator provided by some exemplary embodiments of the present invention is shown;

[0125] Fig.23 An exemplary block diagram of a communication device provided by some embodiments of the present invention is shown;

[0126] Fig.24 An exemplary block diagram of another communication device provided by some embodiments of the present invention is shown;

[0127] Fig.25 A schematic block diagram of an apparatus that can be used to implement some embodiments of the present invention is shown.

[0128] Throughout the drawings, the same or similar reference numerals refer to the same or similar elements. DETAILED DESCRIPTION

[0129] The principle of the present invention will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described only for illustrative purposes, and to help those skilled in the art understand and implement the present invention, without any limitation to the scope of the present invention. The disclosure described herein can be realized in various ways except the mode described below.

[0130] Ultra-wideband (UWB) technology has been used for indoor positioning and other location services such as access control and asset location. In addition to dedicated devices and tags, UWB radios are becoming more common in high-end smartphones. A working group on enhancing UWB technology is underway.

[0131] UWB technology has been used in various scenarios such as device-free sensing, downlink time difference of arrival (DL-TDOA), long-distance ranging, etc. Multi-millisecond (MMS) ranging has been introduced to address long-distance ranging scenarios. The key idea behind MMS ranging is to distribute the UWB ranging frame into multiple segments, where each segment is sent in multiple milliseconds (ms), thereby overcoming the transmission energy limitation of 37nJ / ms. Narrowband assisted (NBA) MMS ranging can be regarded as an enhancement of MMS ranging, proposed by high-performance narrowband (NB) radio, which is used to provide time synchronization for UWB radio and for control signaling. In MMS ranging, the number of segments required for ranging depends on the range to be measured and the channel conditions, so it can be dynamically adjusted even in the same ranging session.

[0132] Figure 1A Schematic diagram of a block-based time structure 110 is shown. Figure 1A As shown, each block includes a plurality of rounds, and each round includes a plurality of time slots. The block-based time structure 110 can be used for a block-based ranging mode. The block-based mode can use a structured timeline, wherein the block-based time structure 110 is periodic by default. In some examples, a block may also be referred to as a ranging block, a round may also be referred to as a ranging round, and a time slot may also be referred to as a ranging time slot.

[0133] A ranging round is a time period of sufficient duration to complete a complete range measurement cycle involving the set of ERDEVs participating in a ranging exchange. A ranging slot is a time period of sufficient duration to transmit at least one frame. Figure 1A As shown, the start of the frame can be aligned with the start of the time slot, or a transmission offset can be applied from the start of the time slot to the start of the frame.

[0134] The block-based time structure 110 may be predetermined and remain unchanged during the ranging session. It should be understood that the block-based time structure 110 may not be suitable for NBA-MMS ranging scenarios, where the round duration may vary dynamically.

[0135] Figure 1B FIG. 1 shows a schematic diagram of a super-block-based time structure 120. Figure 1B As shown, each superblock includes multiple blocks. Different blocks in a superblock can have different configurations, such as block duration, round duration, slot duration, number of rounds in a block, number of slots in a round, etc. For example, Figure 1BThe super block K in includes block 0, block 1 and block 2, where block 0 includes 2 rounds, block 1 includes 7 rounds, and block 2 includes 3 rounds.

[0136] In some examples, different blocks in a super block can be used for different purposes. For example, block 0 can be used for DL-TDOA, block 1 can be used for ranging, and block 2 can be used for sensing. In some other examples, different blocks in a super block can be used for different scenarios in the same purpose. For example, block 0, block 1, and block 2 are all used for NBA-MMS ranging, but block 1 can be used for one-to-one ranging in a good channel situation, block 0 can be used for one-to-many ranging, block 2 can be used for one-to-one ranging in a bad channel situation, etc.

[0137] Figure 1C A schematic diagram of an MMS ranging session 130 is shown. The MMS ranging session 130 includes an initialization and establishment phase 131 and one or more measurement cycles 132. The MMS ranging session 130 involves an initiator and a responder. It should be understood that the initiator may be a device that initiates a UWB exchange by sending a first message, and the responder may be a device that receives and responds to the first message from the initiator.

[0138] In some examples, frames are sent in the initialization channel during the initialization and setup phase 131, and frames are sent in the ranging channel during one or more measurement periods 132. In some examples, the same channel can be used, for example, a well-known channel can be used, as the initialization channel and the ranging channel.

[0139] During the initialization and establishment phase 131, the initiator and the responder may negotiate the ranging configuration. Specifically, the initiator opportunistically sends an advertisement poll (ADV-POLL) frame at a time and interval determined by it, and if the responder intends to participate in a ranging session with the initiator, the responder may opportunistically listen to the incoming ADV-POLL frame and respond with an advertisement response (ADV-RESP) frame. Once the initiator receives the ADV-RESP frame, it sends a start of ranging (SOR) frame, which provides a time offset for the start of the first measurement cycle.

[0140] The measurement cycle is also called the distance measurement cycle, and includes a control phase, a ranging phase, and an optional measurement report phase. The control phase (or also called the ranging control phase) starts at the beginning of the distance measurement cycle. The initiator starts the ranging control phase by sending a POLL frame to the responder at the beginning of the first ranging time slot of the ranging round. The responder that receives the POLL frame successfully sends the RESP frame back to the initiator. The POLL frame and the RESP frame can enable the initiator and the responder to achieve time and frequency synchronization. In some examples, other control information may also be included in the POLL frame.

[0141] During the ranging phase, the initiator and responder may exchange zero or more UWB ranging sequence fragments (RSF) and optionally one or more UWB ranging integrity fragments (RIF). The RSF is used to perform ranging measurements, while the RIF is used to check the integrity of the ranging measurements.

[0142] The measurement report phase may start after the initiator or responder completes receiving all UWB segments of the ranging phase. In the measurement report phase, the initiator or responder may generate a ranging measurement report and send a ranging packet report (RPRT) frame carrying the measurement report to the peer device.

[0143] Frames in the control phase and frames in the ranging phase are sent using UWB for MMS ranging. Frames in the control phase are sent using NB, and frames in the ranging phase are sent using UWB for NBA-MMS ranging.

[0144] In order to provide more space for the information carried in the frame, compressed physical (PHY) service data unit (PSDU) was introduced. Figure 1D FIG. 1 is a schematic diagram showing the format of a compressed PSDU 140. The compressed PSDU 140 may be used for a NB control frame. Figure 1D As shown, the compressed PSDU 140 includes an identifier (ID) field having 1 octet, an address field having 2 octets, a payload field having a variable length, and a cyclic redundancy check (CRC) field having 2 octets.

[0145] Similarly, compression of header-only information element (IE) frames has also been introduced. Figure 1E FIG. 1 is a schematic diagram showing the format of a compressed header-only IE frame 150. The compressed header-only IE frame 150 may be used for broadcast traffic. Figure 1E As shown, the compressed header-only IE frame 150 includes a frame control field having 1 or 2 octets, an address field having 2 octets, a header IE message ID field having 1 octet, a payload field having a variable length, and a CRC field having 2 octets.

[0146] The compressed PSDU 140 or the compressed header-only IE frame 150 may be carried in an 802.15.4ab physical protocol data unit (PPDU). A conventional 802.15.4 frame carried in an 802.15.4ab physical protocol data unit (PPDU) may also be used for MMS ranging, and the frame may not carry the auxiliary security header field (and therefore the frame counter field).

[0147] As mentioned above, AEAD security operations are proposed. AEAD security operations use an extension of counter mode encryption and cipher block chaining message authentication codes. In addition to the security key, the important input of each AEAD security operation is a unique random number. Figure 1F FIG. 1 is a schematic diagram showing the format of the random number 160. The random number 160 may be used in a non-time slotted channel hopping (TSCH) mode. Figure 1F As shown, the random number 160 includes a source address field having 8 octets, a frame counter field having 4 octets, and a random number security level field having 1 octet.

[0148] If AEAD security operations are applied to compressed PSDUs or compressed header IE-only frames, or 802.15.4 frames that do not carry a frame counter field, further study should be conducted on how the random number is constructed.

[0149] The embodiment of the present invention provides a solution for a security frame in ultra-wideband. In some embodiments, a security frame can be generated according to a random number, wherein the random number is constructed according to identification information associated with the security frame, a block index and a round index associated with the round and block to which the first security frame is sent. Therefore, a security operation can be performed and communication can be guaranteed to be secure. The principle and implementation of the present invention are described in detail below in conjunction with the accompanying drawings.

[0150] Figure 2A An exemplary communication system 200 in which some embodiments of the present invention may be implemented is shown. The communication system 200 includes a controller 210, a controlled 220-1, and a controlled 220-2, wherein the controlled 220-1 and 220-2 may be collectively or individually referred to as a controlled 220.

[0151] In the present invention, the controller 210 may be a device that controls a UWB session and defines session parameters, and the controlled 220 may be a device that participates in the UWB session using the session parameters received from the controller 210 .

[0152] A UWB session may also be referred to as a UWB exchange. When participating in a UWB session, the controller 210 may be the initiator and the controlled 220 may be the responder, or the controlled 220 may be the initiator and the controller 210 may be the responder.

[0153] Figure 2B Another exemplary communication system 250 is shown in which some embodiments of the present invention may be implemented. Communication system 250 includes initiator 260, responder 270-1, and responder 270-2, where responders 270-1 and 270-2 may be collectively or individually referred to as responders 270.

[0154] In the present invention, initiator 260 may be a device that follows one or more instructions from the controller, and may initiate a UWB exchange by sending a first message of the exchange to responder 270. Responder 270 may be a device that responds to the first message received from initiator 260 and participates in the UWB exchange.

[0155] In the system 250, the link from the initiator 260 to the responder 270 is called a downlink (DL), and the link from the responder 270 to the initiator 260 is called an uplink (UL). In the downlink, the initiator 260 is a transmitting (TX) device (or transmitter), and the responder 270 is a receiving (RX) device (or receiver). In the uplink, the responder 270 is a transmitting TX device (or transmitter), and the initiator 260 is an RX device (or receiver).

[0156] It should be understood that the controller or the controlled party may be the initiator 260; similarly, the controlled party or the controller may be the responder 270. As a specific example, the initiator 260 is the controller 210, the responder 270-1 is the controlled party 220-1, and the responder 270-2 is the controlled party 220-2. However, it should be understood that this is only for the convenience of explanation and does not limit the scope of protection.

[0157] The device of the present invention, for example Figure 2A The controller 210 or the controller 220 or Figure 2B The initiator 260 or responder 270 in the communication system may be implemented as a tag, a mobile device, a remote control key, a vehicle, a door lock, etc., wherein the mobile device may include but is not limited to a smart phone, a personal digital assistant (PDA), a laptop computer, a tablet computer, a wearable device, an Internet of Things (IoT) device, a vehicle to everything (V2X) device, etc.

[0158] It should be understood that Figure 2A and Figure 2B The number of devices and their connection relationships and types shown in the figure are for illustration only and do not represent any limitation. System 200 or 250 may include any suitable number of devices suitable for implementing embodiments of the present invention.

[0159] Further references Figure 3 , shows a signaling diagram showing a communication process 300 provided by some exemplary embodiments of the present invention. The process 300 may involve a transmitter 301 and a receiver 302. It should be understood that referring to Figure 2A , the transmitter 301 may be the controller 210 or the controlled 220, and the receiver 302 may be the controlled 220 or the controller 210. It should be understood that, see Figure 2B , the sender 301 can be the initiator 260 or the responder 270 , and the receiver 302 can be the responder 270 or the initiator 260 .

[0160] The transmitter 301 generates (310) a first security frame. The first security frame is to be sent in a time slot (e.g., a first time slot) in a first round, wherein the first round is in a first block. A block-based time structure or a super-block-based time structure may be adopted, wherein each block includes a plurality of rounds, and each round includes a plurality of time slots. In some examples, when a block-based time structure is adopted, different blocks include the same number of rounds, and different rounds include the same number of time slots. In some other examples, when a super-block-based time structure is adopted, different blocks may include the same number of rounds or different numbers of rounds, and different numbers of rounds may include the same number of time slots or different numbers of time slots. The first security frame may be protected by a first random number, wherein the first random number is constructed based on identification information associated with the first security frame, a round index, and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block. In some embodiments, the transmitter 301 may construct the first random number and then generate the first security frame. In some examples, the identification information associated with the first security frame may include a time slot index or a first PN, which will be described in detail below.

[0161] In some exemplary embodiments, a first security frame may be sent during a measurement period. In some examples, the first random number is constructed based on a slot index, a round index, and a block index. For example, the identification information includes a slot index. The slot index is an index of a first slot in which the first security frame is sent, the round index is an index of a first round to which the first slot belongs, and the block index is an index of a first block to which the first round belongs.

[0162] The first random number may include a first field carrying a slot index, a second field carrying a round index, and a third field carrying a block index. The length of the first field may be equal to the first number, the length of the second field may be equal to the second number, and the length of the third field may be equal to the third number.

[0163] In some examples, the first number can be a first predefined number, such as 8 bits, 10 bits, or other values. In some examples, the first number can be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the first field can be predefined. In some other examples, the first number can be associated with the length of the first round (e.g., the number of time slots in the first round). For example, the first number can be M bits, where M is an integer and can be determined by equation (1): in, is the upper limit function of the variable X, i.e., the smallest integer not less than (≥) X. The “round duration” in equation (1) is the duration of the first round. The “slot duration” in equation (1) is the duration of the first slot. is the number of time slots per round (expressed as “NumSlots”). For example, the position of the start bit of the first field may be predefined, and the position of the end bit of the first field may be determined according to M.

[0164] In some examples, the second number can be a second predefined number, such as 15 bits, 13 bits, or other values. In some examples, the second number can be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the second field can be predefined. In some other examples, the second number can be associated with the length of the first block (e.g., the number of rounds in the first block). For example, the second number can be N bits, where n is an integer and can be determined by equation (2): Wherein, the “round duration” in equation (2) refers to the duration of the first round, the “block duration” in equation (2) refers to the duration of the first block, and Refers to the number of rounds per block (expressed as "NumRounds"). For example, the position of the start bit of the second field may be the bit after the first field, and the position of the end bit of the second field may be determined according to N.

[0165] In some examples, the third number can be a third predefined number, such as 16 bits, 18 bits, or other values. In other examples, the third number can be determined based on at least one of the first number and the second number. For example, the sum of the first number, the second number, and the third number can be equal to the predefined total number, so the third number can be determined based on the predefined total number, the first number, and the second number. For example, the predefined total number can be 39 bits, 35 bits, or other values. Alternatively, the combination of the first field, the second field, and the third field can be considered a frame counter field, for example, with a length of the predefined total number.

[0166] In the first random number, the first field, the second field and the third field may be continuous, for example, the second field is after the first field, and the third field is after the second field. However, it should be understood that the present invention is not limited to this aspect, for example, there may be one or more reserved bits or one or more other fields between the first field and the second field, for example, the third field may be located before the first field, etc., and the present invention will not list them one by one here.

[0167] In addition, the first random number may include a fourth field carrying a cycle index. The length of the fourth field may be equal to the fourth quantity. In the present invention, a new cycle may be defined, wherein a cycle includes one or more blocks. The cycle index is an index of the cycle including the first block. In some examples, the fourth quantity may be a fourth predefined quantity, such as 6 bits, 7 bits, 8 bits or other values. In other examples, the fourth quantity may be determined based on at least one of the first quantity, the second quantity and the third quantity. For example, the sum of the first quantity, the second quantity, the third quantity and the fourth quantity may be equal to the predefined total quantity, so the fourth quantity may be determined based on the predefined total quantity, the first quantity, the second quantity and the third quantity. Alternatively, the combination of the first field, the second field, the third field and the fourth field may be regarded as a frame counter field, for example, with a length of a predefined total quantity.

[0168] The first random number includes a first block indicator, wherein the first block indicator may indicate that the first security frame is sent based on a block-based time structure or a super-block-based time structure. For example, the first random number may include a field carrying the first block indicator, such as a block indicator field. In some examples, the term "block-based time structure or super-block-based time structure" may be referred to as an "internal block structure". The term "internal block structure" may refer to a time period in which the block-based time structure or the super-block-based time structure is known to both the transmitter 301 and the receiver 302. The length of the field carrying the first block indicator may be predefined, such as 1 bit, 2 bits, or other values. If the first block indicator is equal to the first value, it may indicate that the first security frame is in an internal block structure. For example, the first value may be 1 or 0. In some examples, the field carrying the first block indicator may be located at a predefined position of the first random number, such as at the end of the first random number.

[0169] The first random number includes a source address. For example, the first random number may include a field carrying the source address, such as a source address field. The length of the field carrying the source address may be predefined, such as 8 octets, 10 octets, or other values. The field carrying the source address may be located at a predefined position of the first random number, such as in front of the first random number. The source address may be an extended address of a device that initiates the first security frame, i.e., the address of the transmitter 301.

[0170] In some exemplary embodiments, the first security frame may be sent during the measurement period.As some examples, the first security frame may be any one of: a secure POLL, a secure RESP, or a secure RPRT.

[0171] The first safety frame may include a first block index presence indicator and a first round index presence indicator. The first block index presence indicator may indicate whether a block index exists in the first safety frame. The first round index presence indicator may indicate whether a round index exists in the first safety frame. For example, the first block index presence indicator is equal to a first value to indicate that a block index exists in the first safety frame, or is equal to a second value to indicate that a block index does not exist in the first safety frame. For example, the first round index presence indicator is equal to a first value to indicate that a round index exists in the first safety frame, or is equal to a second value to indicate that a round index does not exist in the first safety frame. The first value is 1 and the second value is 0, or the first value is 0 and the second value is 1.

[0172] For example, the first safety frame may include a first block index presence field carrying a first block index presence indicator and a first round index presence field carrying a first round index presence indicator. Alternatively, the first safety frame may include a presence control field (having a predefined length, such as 1 octet), the presence control field including a first block index presence field and a first round index presence field. In some examples, the length of the first block index presence field may be 1 bit, 2 bits, or other values, and the length of the first round index presence field may be 1 bit, 2 bits, or other values.

[0173] The first safety frame may include a block index. For example, if the first block index presence indicator indicates the presence of the block index, for example, the first block index presence indicator is equal to a first value. For example, the first safety frame may include a first block index field carrying the block index. Alternatively, the length of the first block index field may be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the first block index presence indicator is equal to the second value, the first block index field is not included, that is, the length of the first block index field is 0.

[0174] The first safety frame may include a round index. For example, if the first round index presence indicator indicates the presence of the round index, for example, the first round index presence indicator is equal to a first value. For example, the first safety frame may include a first block index field carrying a block index. Alternatively, the length of the first round index field may be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the first round index presence indicator is equal to a second value, the first round index field is not included, i.e., the length of the first round index field is 0.

[0175] Alternatively, the first security frame may include an open payload including a first block index present field, a first round index present field, a first block index field (if present), and a first round index field (if present).

[0176] The first security frame may include a first security indicator. For example, the first security frame may include a field carrying the first security indicator, such as a security indicator field. The first security indicator may indicate that the first security frame is secure. For example, the length of the field carrying the first security indicator may be predefined, such as 1 bit, 2 bits, or other values.

[0177] The first security frame may also include one or more of a field carrying an ID, a field carrying an address, a field carrying a security payload, and a field carrying a message integrity check (MIC). The security payload in the first security frame may be generated based on the first random number. In some examples, the security key may be used to generate the security payload in the first security frame.

[0178] The transmitter 301 transmits (320) a first security frame 322 to the receiver 302. The receiver 302 receives (324) the first security frame 322. The receiver 302 deprotects (330) the first security frame 322. Specifically, the receiver 302 deprotects the first security frame 322 using a random number constructed according to the round index and the block index.

[0179] It should be understood that the standards for constructing random numbers by the transmitter 301 and the receiver 302 should be consistent, that is, the random number constructed by the receiver 302 should be the same as the first random number constructed by the transmitter 301 for protecting the first security frame. If the random number constructed by the receiver 302 is different from the first random number constructed by the transmitter 301 for protecting the first security frame, deprotection of the first security frame will fail.

[0180] In some embodiments, the receiver 302 may construct a first random number and then deprotect the first security frame 322. The first random number constructed by the receiver 302 is similar to the random number described above (ie, the random number constructed by the sender), and is not described in detail for the sake of brevity.

[0181] As mentioned above, the first random number may include three fields, carrying a time slot index, a round index, and a block index, respectively. In some other examples, the first random number may include two fields, one of which carries one of the time slot index, the round index, and the block index, and the other field carries a combination of the other two of the time slot index, the round index, and the block index. For example, one field of the first random number carries the time slot index, and another field of the first random number carries a function of the round index and the block index. In some other examples, the first random number may include a field carrying a value (e.g., a frame counter (FC)), which is a function of the time slot index, the round index, and the block index. It should be understood that the first random number can also be determined according to the time slot index, the round index, and the block index in other ways, and the present invention is not limited to this aspect.

[0182] In addition, the transmitter 301 can generate a second security frame. The second security frame will not be sent according to the block-based time structure or the super-block-based time structure; that is, the second security frame will be sent in a non-block-based time structure or a non-super-block-based time structure or other structure. In some examples, the term "non-block-based time structure" or "non-block-based time structure" or "non-super-block-based time structure" or "non-super-block-based time structure" may be referred to as an "external block structure". The term "external block structure" may refer to a time period during which the block-based time structure or the super-block-based time structure is unknown to the transmitter 301 or the receiver 302.

[0183] The second security frame may be protected by a second random number, wherein the second random number is constructed according to a second packet number (PN), and the second PN is the packet number of the second security frame. In some embodiments, the transmitter 301 may construct a second random number and then generate a second security frame.

[0184] In some examples, the second random number may include a field carrying the second PN. The length of the field carrying the second PN may be equal to a predefined number, such as 4 octets, 3 octets, or other values.

[0185] The second random number includes a field carrying a second block indicator, wherein the second block indicator may indicate that the second safety frame is sent in an external block structure. The length of the field carrying the second block indicator may be predefined, such as 1 bit, 2 bits, or other values. If the second block indicator is equal to the second value, it may indicate that the second safety frame is in an external block structure. For example, the second value may be different from the first value of the first block indicator indicating that the first safety frame is in an internal block structure. For example, the first value is 1 and the second value is 0. For another example, the first value is 0 and the second value is 1. In some examples, the field carrying the second block indicator may be located at a predefined position of the second random number, such as at the end of the second random number.

[0186] The second random number includes a field carrying a source address. The length of the field carrying the source address may be predefined, such as 8 octets, 7 octets, or other values. The field carrying the source address may be located at a predefined position of the second random number, such as in front of the second random number. The source address may be an extended address of a device that initiates the second security frame, i.e., the address of the transmitter 301.

[0187] In some exemplary embodiments, the second security frame may be sent during the initialization and setup phases. As some examples, the second security frame may be any one of a secure ADV-RESP or a secure SOR.

[0188] The second safety frame may include a PN field carrying the second PN. The length of the PN field in the second safety frame may be predefined, such as 4 octets, 3 octets, or other values.

[0189] The second security frame may include a field carrying a second security indicator. The second security indicator may indicate that the second security frame is secure. For example, the length of the field carrying the second security indicator may be predefined, such as 1 bit, 2 bits, or other values.

[0190] The second security frame may also include one or more of a field carrying an ID, a field carrying an address, a field carrying a security level, a field carrying a security payload, and a field carrying a MIC. The security payload in the second security frame may be generated based on the second random number. In some examples, the security key may be used to generate a security payload in the second security frame.

[0191] In some examples, the security payload may include a second block index presence field carrying a second block index presence indicator, a second round index presence field carrying a second round index presence indicator, and a second slot index presence field carrying a second slot index presence indicator. The second block index presence indicator may indicate whether the second block index field exists. The second round index presence indicator may indicate whether the second round index field exists. The second slot index presence indicator may indicate whether the second slot index field exists.

[0192] For example, the second block index presence indicator is equal to the first value to indicate that the second block index field exists in the security payload, or is equal to the second value to indicate that the second block index field does not exist in the security payload. For example, the second round index presence indicator is equal to the first value to indicate that the second round index field exists in the security payload, or is equal to the second value to indicate that the second round index field does not exist in the security payload. For example, the second time slot index presence indicator is equal to the first value to indicate that the second time slot index field exists in the security payload, or is equal to the second value to indicate that the second time slot index field does not exist in the security payload. The first value is 1 and the second value is 0, or the first value is 0 and the second value is 1. Alternatively, the security payload may include a presence control field (with a predefined length, such as 1 octet), which includes a second block index presence field, a second round index presence field, and a second time slot index presence field. In some examples, the length of the second block index presence field can be 1 bit, 2 bits, or other values, the length of the second round index presence field can be 1 bit, 2 bits, or other values, and the length of the second time slot index presence field can be 1 bit, 2 bits, or other values.

[0193] The security payload may include a second block index field carrying a block index. For example, if a second block index presence indicator in the second block index presence field indicates the presence of a second block index field, for example, the second block index presence indicator is equal to a first value, then a second block index field carrying a block index is present. Alternatively, the length of the second block index field may be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the second block index presence indicator is equal to the second value, i.e., the length of the second block index field is 0, then the second block index field is not included.

[0194] The security payload may include a second round index field carrying the round index. For example, if a second round index presence indicator in the second round index presence field indicates the presence of the second round index field, for example, the second round index presence indicator is equal to a first value, then the second round index field carrying the round index is present. Alternatively, the length of the second round index field may be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the second round index presence indicator is equal to the second value, i.e., the length of the second round index field is 0, then the second round index field is not included.

[0195] The security payload may include a second slot index field carrying the slot index. For example, if the second slot index presence indicator in the second slot index presence field indicates the presence of the second slot index field, for example, the second slot index presence indicator is equal to the first value, then the second slot index field carrying the slot index is present. Alternatively, the length of the second slot index field may be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the second slot index presence indicator is equal to the second value, that is, the length of the second slot index field is 0, then the second slot index field is not included.

[0196] The transmitter 301 sends a second security frame to the receiver 302. The receiver 302 receives the second security frame. The receiver 302 releases protection for the second security frame. Specifically, the receiver 302 releases protection for the second security frame by using a random number constructed according to the second PN.

[0197] As described above, the standards for constructing random numbers by the transmitter 301 and the receiver 302 should be consistent, that is, the random number constructed by the receiver 302 should be the same as the second random number constructed by the transmitter 301 for protecting the second security frame. If the random number constructed by the receiver 302 for deprotecting the second security frame is different from the random number constructed by the transmitter 301 for protecting the second security frame, deprotection of the second security frame will fail.

[0198] In some embodiments, the receiver 302 may construct a second random number and then deprotect the second security frame. The second random number constructed by the receiver 302 is similar to the random number described above (ie, the random number constructed by the transmitter), and will not be described in detail for the sake of brevity.

[0199] In the case where the receiver 302 unprotects the second security frame, the receiver 302 may obtain information in the security payload of the second security frame. In some examples, if the second block index field, the second round index field, and the second time slot index field are included, the carried block index, round index, and time slot index may be obtained by the receiver 302. In other examples, if at least one of the second block index field, the second round index field, and the second time slot index field is not included, the receiver 302 may determine the corresponding index on its own. For example, if the second block index field is not included in the security payload, the receiver 302 may determine the block index as a default value, such as a block index of 0. Therefore, if the index is a default value (such as 0), it does not need to be included in the security payload, so signaling overhead can be saved.

[0200] According to some embodiments described above, different random numbers may be used to protect frames during the initialization and establishment phases and during the measurement period. Specifically, PN may be used to construct a random number for protecting frames sent in an "external block structure", and a slot index, a round index, and a block index may be used to construct a random number for protecting frames sent in an "internal block structure".

[0201] In some other exemplary embodiments, the first security frame generated by the transmitter 301 at 310 may be sent during the initialization and establishment phase or during the measurement period. Specifically, the block-based time structure or the super-block-based time structure may be established before or at the beginning of the initialization and establishment phase. In this case, the frames sent during the initialization and establishment phase are also in the block-based time structure or the super-block-based time structure.

[0202] The first random number used to protect the first security frame is constructed based on the block index, the round index and the first PN. The round index is the index of the first round of sending the first security frame, and the block index is the index of the first block to which the first round belongs. The first PN is the packet number of the first security frame. That is, the first PN is used to uniquely identify the first security frame.

[0203] The first random number may include a first field carrying a first PN, a second field carrying a round index, and a third field carrying a block index. The length of the first field may be equal to the first number, the length of the second field may be equal to the second number, and the length of the third field may be equal to the third number.

[0204] In some examples, the first number can be a first predefined number, such as 8 bits, 7 bits, or other values. In some examples, the first number can be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the first field can be predefined.

[0205] In some examples, the second number may be a second predefined number, such as 15 bits, 16 bits, or other values. In some examples, the second number may be determined by the position of the start bit and the position of the end bit. For example, the position of the start bit and the position of the end bit of the second field may be predefined. In some other examples, the second number may be associated with the length of the first block (e.g., the number of rounds in the first block). For example, the second number may be N bits, where N is an integer and may be determined by equation (2) above.

[0206] In some examples, the third number can be a third predefined number, such as 16 bits, 17 bits, or other values. In other examples, the third number can be determined based on at least one of the first number and the second number. For example, the sum of the first number, the second number, and the third number can be equal to the predefined total number, so the third number can be determined based on the predefined total number, the first number, and the second number. For example, the predefined total number can be 40 bits, 39 bits, or other values. Alternatively, the combination of the first field, the second field, and the third field can be considered a frame counter field, for example, with a length of the predefined total number.

[0207] In the first random number, the first field, the second field and the third field may be continuous, for example, the second field is after the first field, and the third field is after the second field. However, it should be understood that the present invention is not limited to this aspect, for example, there may be one or more reserved bits between the first field and the second field, for example, the third field may be located before the first field, and the present invention will not list them one by one here.

[0208] The first random number includes a field carrying a source address. The length of the field carrying the source address may be predefined, such as 8 octets, 7 octets, or other values. The field carrying the source address may be located at a predefined position of the first random number, such as in front of the first random number. The source address may be an extended address of a device that initiates the first security frame, i.e., the address of the transmitter 301.

[0209] Similarly, the transmitter 301 transmits (320) a first security frame 322, which is protected by a first random number constructed according to the first PN, the round index, and the block index. The receiver 302 may receive (324) the first security frame 322. The receiver 302 deprotects (330) the first security frame 322. Specifically, the receiver 302 may construct a first random number according to the first PN, the round index, and the block index, and deprotect the first security frame 322 using the first random number.

[0210] As mentioned above, the first random number may include three fields, which carry the first PN, the round index and the block index respectively. In some other examples, the first random number may include two fields, one field carries one of the first PN, the round index and the block index, and the other field carries a combination of the other two of the first PN, the round index and the block index. For example, one field of the first random number carries the first PN, and another field of the first random number carries a function of the round index and the block index. In some other examples, the first random number may include a field carrying a value (e.g., a frame counter (FC)), which is a function of the first PN, the round index and the block index. It should be understood that the first random number can also be determined based on the first PN, the round index and the block index in other ways, and the present invention is not limited to this aspect.

[0211] According to some embodiments described above, in the case where a block-based time structure or a super-block-based time structure can be established before or at the beginning of the initialization and establishment phase, a PN, round index and block index can be used to construct a random number for protecting a frame.

[0212] Some of the above embodiments have described that the identification information associated with the first security frame may include a time slot index or a first PN. In some other examples, the identification information associated with the first security frame may include a time slot index and a first PN. In some other examples, the identification information associated with the first security frame may include a first security frame-specific (or unique) parameter or value. The present invention is not limited in this respect.

[0213] In the present invention, a security frame is generated by protecting a compressed frame, wherein the compressed frame may be a compressed PSDU frame or a frame having a compressed header IE format as described above. Alternatively, a security frame may be generated by protecting an 802.15.4 frame that does not carry a frame counter field. Security operations may be performed using cryptographic operations such as authentication or encryption.

[0214] Figure 4 FIG. 4 is a schematic diagram showing an exemplary MMS ranging session 400 in a block-based time structure provided by some exemplary embodiments of the present invention. Figure 4 As shown, the MMS ranging session 400 includes an initialization and establishment phase 401 followed by one or more measurement cycles 402 .

[0215] During the initialization and establishment phase 401, the responder may not know the block-based time structure, so the initialization and establishment phase 401 is considered to be an "external block structure". During one or more measurement cycles 402, both the initiator and the responder participating in the MMS ranging session will know the block-based time structure, so the one or more measurement cycles 402 are considered to be an "internal block structure".

[0216] As shown at 410, during the initialization and setup phase 401, the PN is used to construct a random number. It should also be understood that the transmission duration of a frame during the initialization and setup phase 401 is not necessarily limited to 1 ms.

[0217] During one or more measurement cycles 402, the transmitter (initiator or responder) may only send a single frame in a time slot, so each frame is uniquely associated with a specific time slot. Therefore, the time slot index, round index and block index can be used to construct a random number for protecting the frame sent in the time slot. Since the index is strictly increasing, it can be guaranteed that the time slot index, round index and block index used to construct the random number will not be repeated in the current block structure, so the frame does not need to carry any PN, as shown in 420.

[0218] Figure 5 A signaling diagram illustrating a process 500 of an exemplary MMS ranging session is shown, provided by some exemplary embodiments of the present invention.

[0219] The process 500 begins with the controller and the controlled performing a session establishment 510. During the session establishment 510, long-term session parameters such as UWB channel number, preamble, default block structure (eg, number of blocks, block duration), etc. are negotiated. Figure 4 The long-term session parameters include default values ​​for m and n, where m is associated with the number of slots in each round (e.g., NumSlots = m+1, as Figure 4 As shown), and n is associated with the number of rounds in each block (e.g., NumRounds = n+1, as shown Figure 4 510 ). Long-term parameters are not expected to change during the MMS ranging session. When security is enabled, the controller will also provide at least one security key to the controlled party to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key common to all responders will also be provided. For NBA-MMS ranging sessions, narrowband-related parameters (e.g., NB channel number, etc.) can also be negotiated during session establishment 510.

[0220] Some other parameters such as the number of MMS fragments, reporting mode, etc. may be considered short-term parameters because they may be modified during the MMS ranging session.Session establishment 510 may be performed out-of-band, such as using a Bluetooth or Wi-Fi radio, or may be performed in-band, such as using a narrowband or UWB radio.

[0221] In addition, the roles of initiator and responder are also assigned during session establishment 510. Figure 5In the specific example shown in , it is assumed that the controller assumes the role of the initiator 260, and the controlled is assigned the role of the responder 270. However, it should be understood that it is also possible that the controlled is assigned the role of the initiator, and the controller assumes the role of the responder.

[0222] At 522, initiator 260 opportunistically sends ADV-POLL frames at times and intervals determined by it, and responder 270 can opportunistically listen for incoming ADV-POLL frames. At 524, if responder 270 intends to participate in a ranging session with initiator 260, responder 270 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN that is used to construct a random number used to protect the ADV-RESP frame. Figure 5 As shown, a secure ADV-RESP frame may be sent from responder 270 to initiator 260 .

[0223] Once the initiator 260 receives the ADV-RESP frame, it sends a SOR frame at 526, which provides the time offset for the start of the first distance measurement period. If security is enabled, the SOR frame carries a PN that is used to construct a random number for protecting the SOR frame. Figure 5 As shown, the secure SOR frame can be sent from the initiator 260 to the responder 270. It should be noted that the PN for UL and the PN for DL ​​can be used separately, that is, the PN in the uplink (responder to initiator) and downlink (initiator to responder) directions can use different numbering spaces, and the PN is increased by 1 each time a frame carrying the PN is sent.

[0224] At 528, the initiator 260 sends a secure POLL frame to the responder 270 at the beginning of the first time slot of a round, where the beginning of the first time slot is indicated by the time offset in the SOR frame. The initiator 260 may also include other control information in the POLL frame of the responder 270. At 530, the responder 270 sends a secure RESP frame back to the initiator 260 if it successfully receives the secure POLL frame. The POLL frame and the RESP frame may enable the initiator 260 and the responder 270 to achieve time and frequency synchronization.

[0225] During the ranging phase, initiator 260 and responder 270 may exchange zero or more UWB RSFs, and optionally one or more UWB RIFs. RSFs are used to perform ranging measurements, while RIFs are used to check the integrity of ranging measurements. Illustratively, the exchange Figure 5 As shown at 532 and 534 in FIG.

[0226] After the initiator 260 or the responder 270 completes receiving all UWB segments in the ranging phase, the reporting phase may begin. During the reporting phase, the initiator 260 or the responder 270 may generate a ranging measurement report and send a secure RPRT frame carrying the measurement report to the peer device. Figure 5 As shown, at 536 , the initiator 260 sends the secure RPRT frame to the responder 270 , and at 538 , the responder 270 sends the secure RPRT frame to the initiator 260 .

[0227] The time slot index of the corresponding frame in which the corresponding frame is transmitted and the round index and the block in which the time slot is located may be used to construct a random number for protecting the POLL frame, the RESP frame and the RPRT frame.

[0228] The present invention shows some exemplary formats of frames and random numbers in conjunction with the accompanying drawings. However, it should be noted that the examples are given for illustrative purposes and do not impose any restrictions on the present invention. For example, a frame or a random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may also be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying information and the other field reserved. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the arrangement of the fields may be another way, such as arranging in a different order. The present invention is not limited in this respect.

[0229] Fig. 6A FIG. 6 is a schematic diagram showing the format of a SOR frame 610 provided by some exemplary embodiments of the present invention. For example, the SOR frame 610 may be Figure 5 Although the SOR frame 610 is shown in a compressed PSDU format, the described process can work even if the frame is carried as a compressed header ID format or even as a traditional 802.15.4 frame.

[0230] like Fig. 6A As shown, the SOR frame 610 includes a field 611 carrying an ID, a field 612 carrying a security indicator, a field 613 carrying an address, a field 614 carrying a PN, a field 615 carrying a security level, a field 616 carrying a security payload, and a field 617 carrying a MIC. When carried as a traditional 802.15.4 frame, the PN field 614 and the security level field 615 may be carried in the auxiliary security header field in the MHR.

[0231] Fields 611 to 615 may be considered as a compressed header (CHR) of the SOR frame 610, wherein fields 611 to 613 are mandatory and fields 614 to 615 are optional. For example, if the frame is not secure, field 614 may not be included. For example, if the security level is negotiated in advance, field 615 may be omitted.

[0232] Field 611 may indicate an identification of SOR frame 610, for example, field 611 carries "0x22" indicating a SOR frame. Field 612 may indicate whether the frame is secure. In some examples, field 612 may be the most significant bit (MSB) of field 611, for example, carrying "1" or "0". For example, "1" indicates that the frame is secure, while "0" indicates that the frame is not secure. Fig. 6A As shown, the total length of field 611 and field 612 may be 1 octet.

[0233] Field 614 may carry the packet number of SOR frame 610. In some examples, initiator 260 may maintain a separate numbering space for each responder 270 of the security compressed frame to ensure that the same random number is never reused with the same security key. For example, a first numbering space is associated with responder 270-1 and a second numbering space is associated with responder 270-2. Fig. 6A As shown, field 614 may be 4 octets in length. Where the SOR frame is addressed to multiple responders, the PN may be the same for all responders and a separate security key negotiated for the broadcast transmission is used to protect or unprotect the SOR frame.

[0234] Field 615 may indicate the security level to be applied to the security operation performed on the frame. Alternatively, field 615 may be omitted if the security level is negotiated during session establishment 510 and it is assumed that the security level is fixed for the entire ranging session.

[0235] When the SOR frame 610 is encrypted, for example, the security level is one of 5, 6, or 7, the field 616 is secure (ie, encrypted). For example, the field 616 carries a security payload.

[0236] Field 617 carries the MIC generated by the AEAD transformation process. The size of the MIC depends on the security level. For example, the security level is 5 or 6, and the length of field 617 is 4 octets or 8 octets, respectively. It is also possible that only a portion of the MIC (e.g., the least significant 16 bits) is carried in the MIC field, and the same 16 bits are used by the responder for integrity checking.

[0237] It should be understood that since the MIC can detect any error in the frame content, the CRC field is no longer needed, that is, the CRC field can be replaced by the MIC field.

[0238] It should be understood that Fig. 6A The SOR frame 610 in may be considered a secure SOR frame. In some other examples, if a non-secure SOR frame is used, field 614 and field 615 are not included, and the payload in field 616 is a non-secure payload.

[0239] It should also be understood that although Fig. 6A The format of the SOR frame is shown, but a similar format can be applied to the secure ADV-RESP, which will not be described in detail here.

[0240] Figure 6B A schematic diagram of the format of a random number 620 for protecting a frame sent in an external block structure provided by some exemplary embodiments of the present invention is shown. For example, the random number 620 can be constructed by the initiator 260 for protecting a SOR or for deprotecting an ADV-RESP, or by the responder for protecting an ADV-RESP or for deprotecting a SOR. Alternatively, the random number 620 can be referred to as an external block-based random number.

[0241] like Figure 6B As shown, the random number 620 includes a frame 621 carrying a source address, a field 622 carrying a PN, a reserved field 623, a field 624 carrying a security level, and a field 615 carrying a block structure indicator.

[0242] Field 621 may indicate the extended address of the device that originates the frame. It is understandable that during session establishment 510, the controller and the controlled device will exchange and store the extended address of the peer device.

[0243] Field 622 may be considered a frame counter field and may be set to a PN, which is the same value as the PN field of the secure frame. For example, if the random number 620 is constructed by the initiator 260 to protect a SOR frame, or by the responder 270 to deprotect a SOR frame, the PN in field 622 should be the same as the PN in field 614. Field 622 may be 4 octets in length.

[0244] Field 624 may indicate a security level, namely, a random number security level. The security level may be an integer that is the same as the value of the security level field of the security frame. For example, if random number 620 is constructed by initiator 260 to protect a SOR frame, or by responder 270 to deprotect a SOR frame, the security level in field 624 should be the same as the security level in field 615. However, as described in reference Fig. 6AAs described, in the event that the security level is negotiated during session establishment 510 , field 615 may be omitted, in which case security level field 624 is set to the security level negotiated during session establishment 510 .

[0245] Field 625 may indicate a block structure indicator (or simply a block indicator). In some examples, field 625 may be the last bit of random number 620, for example, carrying a "1" or a "0". For example, a "1" indicates that the frame is in a block structure, and a "0" indicates that the frame is sent in an external block structure. Figure 6B As shown, since the random number 620 is used in the initialization and setup phases, the block structure indicator is 0.

[0246] It should be understood that the block structure indicator is used to ensure that the random numbers used to protect frames sent inside and outside the block structure are never reused. For example, in the case where a frame is sent or received outside the block structure, the block structure indicator can be set to "0".

[0247] Fig. 7A FIG. 7 is a schematic diagram showing the format of a POLL frame 710 provided by some exemplary embodiments of the present invention. For example, the POLL frame 710 may be Figure 5 The secure POLL frame sent at 528 in .

[0248] like Fig. 7A As shown, the POLL frame 710 includes a field 711 carrying an ID, a field 712 carrying a security indicator, a field 713 carrying an address, a field 714 serving as a presence control field, a field 715 carrying a block index, a field 716 carrying a round index, a field 717 carrying a security payload, and a field 718 carrying a MIC.

[0249] Fields 711 to 713 may be considered the CHR of the POLL frame 710. Field 711 may indicate the identity of the POLL frame 710. Field 712 may indicate whether the frame is secure. In some examples, field 712 may be the MSB of field 711, e.g., carrying a "1" or a "0". For example, a "1" indicates that the frame is secure, while a "0" indicates that the frame is not secure. Fig. 7A As shown, the total length of field 711 and field 712 may be 1 octet.

[0250] Fields 714 to 716 may be considered the open payload of the POLL frame 710. Regardless of the security level, the open payload of the secure frame may be authenticated but not encrypted. Field 714 includes a block index present field 7142 carrying a block index present indicator, a round index present field 7144 carrying a round index present indicator, and a reserved field 7146. Fig. 7AAs shown, field 714 may be 1 octet in length.

[0251] In some examples, the block index presence indicator is equal to a first value (e.g., 1) to indicate the presence of field 715, and the round index presence indicator is equal to a first value (e.g., 1) to indicate the presence of field 716 in the open payload. For example, the length of field 715 can be 2 octets, and the length of field 716 can be 2 octets. In some other examples, the block index presence indicator is equal to a second value (e.g., 0) to indicate that field 715 is not present, i.e., the length of field 715 is 0. In some other examples, the round index presence indicator is equal to a second value (e.g., 0) to indicate that field 716 is not present, i.e., the length of field 716 is 0. For example, if the block index is a default value (e.g., 0), field 715 can be omitted. For example, if the round index is a default value (e.g., 0), field 716 can be omitted.

[0252] When the POLL frame 710 is encrypted, for example, when the security level is one of 5, 6, or 7, field 717 is secure (i.e., encrypted). For example, field 717 carries a security payload. Field 718 carries a MIC generated by the AEAD transformation process. The size of the MIC depends on the security level. For example, the security level is 5 or 6, and accordingly, the length of field 718 is 4 octets or 8 octets.

[0253] Alternatively, the POLL frame 710 may include a field that carries a security level, which is similar to Fig. 6A Field 615 in is similar.

[0254] It should be understood that Fig. 7A The POLL frame 710 in may be considered as a secure POLL frame. The secure POLL frame 710 is sent in the first time slot in the round indicated by the SOR frame (eg, secure SOR frame 610) to synchronize the receiver of the secure POLL frame 710 (responder 270) with the block structure.

[0255] It should also be understood that although Fig. 7A The format of the POLL frame is shown, but a similar format can be applied to the secure RESP or secure RPRT, which will not be described in detail here.

[0256] Figure 7BA schematic diagram of the format of a random number 720 for protecting a frame within a block structure provided by some exemplary embodiments of the present invention is shown. For example, the random number 720 may be constructed by the initiator 260 for protecting a POLL, deprotecting a secure RESP, protecting a RPRT, or deprotecting a secure RPRT, or may be constructed by the responder for deprotecting a secure POLL, protecting a RESP, deprotecting a secure RPRT, or protecting a RPRT. Alternatively, the random number 720 may be referred to as an internal block-based random number.

[0257] like Figure 7B As shown, the random number 720 includes a frame 721 carrying a source address, a field 722 carrying a time slot index, a field 723 carrying a round index, a field 724 carrying a block index, and a field 725 carrying a block structure indicator.

[0258] Field 721 may indicate the extended address of the device that originates the frame. It is understandable that during session establishment 510, the controller and the controlled device will exchange and store the extended address of the peer device.

[0259] Fields 722 to 724 may be considered as frame counter fields of random number 720. Fields 722 to 724 may be set to the index of the slot, round, and block in which the frame is transmitted (while protected) or received (while unprotected). Figure 7B As shown, each length of fields 722 to 724 is predefined, and the total number of lengths is 39 bits.

[0260] Field 725 may indicate a block structure indicator (or simply a block indicator). In some examples, field 725 may be the last bit of random number 720, for example, carrying a "1" or a "0". For example, a "1" indicates that the frame is in a block structure, and a "0" indicates that the frame is sent in an external block structure. Figure 7B As shown, since the random number 720 is used to measure the period, the block structure indicator is 1.

[0261] Alternatively, the random number 720 may include a field that carries a security level, which is similar to Figure 6B Field 624 in is similar.

[0262] In some examples, field 724 may be split into two fields, one of which carries the block index and the other of which is reserved. In some examples, the order of fields 722 to 724 may be another way, such as Figure 7B Reverse order as shown.

[0263] It should be understood that the block structure indicator is used to ensure that the random numbers used to protect frames sent inside and outside the block structure are never reused. For example, in the case where a frame is sent or received in an external block structure, the block structure indicator can be set to "0".

[0264] Figure 7C An example 730 of constructing a random number for protecting a compressed frame provided by some exemplary embodiments of the present invention is shown. Figure 7C As shown, if the security frame is to be sent in slot 1 of round 1 of block 1 in a block-based timing structure, the random number may include a field 732 carrying slot index 1, a field 733 carrying round index 1, and a field carrying block index 1.

[0265] It should be understood that example 730 also applies to a responder that desecures a frame, for example, the secure frame is received in slot 1 of round 1 of block 1 in a block-based timing structure, and the random number is constructed in the same manner.

[0266] As reference FIG. 7B to FIG. 7C As described, the lengths of the fields carrying the slot index, round index, and block index may be set to fixed values, such as 8 bits, 15 bits, and 16 bits, respectively. In the present invention, there may be a single frame being sent in a slot to ensure that the random number for the same security key is never repeated. In this case, a greater number of frame counter values ​​may be required, and accordingly, the frame counter space may be exhausted quickly. Therefore, if the frame counter wraps around (i.e., rolls to 0), the security key needs to be changed to ensure that the random number for the same security key is never repeated.

[0267] Table 1 below shows the increase of the frame counter value in the random number (e.g., random number 720) based on the internal block when the security frame is sent or received in the first time slot of different rounds in 3 consecutive blocks. It can be seen that the value of the frame counter increases by 8,388,865 every time the block index is updated. For example, for a block structure with a block duration of 96ms, the frame counter will wrap around in 6291 seconds = 104 minutes. Table 1

[0268] Figure 8 FIG. 8 is a schematic diagram showing another format of a random number 800 for protecting a frame within a block structure provided by some exemplary embodiments of the present invention. Alternatively, the random number 820 may be referred to as an intra-block based random number.

[0269] like Figure 8As shown, the random number 800 includes a frame 821 carrying a source address, a field 822 carrying a time slot index, a field 823 carrying a round index, a field 824 carrying a block index, and a field 825 carrying a block structure indicator. It should be noted that the random number 800 and Figure 7B The random number 720 in is similar, however, the lengths of fields 822 to 824 are not fixed values.

[0270] For example, the length of field 822 (i.e., the first bit number), the length of field 823 (i.e., the second bit number), and the length of field 824 (i.e., the third bit number) may be determined based on the block-based time structure. Figure 8 The values ​​of M and N in may be determined according to equations (1) and (2), respectively. In some examples, the values ​​of M and N may be indicated by initiator 260, for example, in SOR frame 610.

[0271] Alternatively, the random number 800 may include a field carrying a security level, which is similar to Figure 6B Alternatively, in some other examples, field 814 may be split into three fields, one field carrying the block index, one field carrying the security level, and one field reserved.

[0272] As a specific example, assume that each block includes 16 rounds, each round includes 16 time slots, so the number of time slots per round (NumSlots) = the number of rounds per block (NumRounds) = 16. Therefore, M = N = 4 bits. Table 2 below shows the increase of the frame counter value in the random number (e.g., random number 800) based on the internal block when the security frame is sent or received in the first time slot of different rounds in 3 consecutive blocks. It can be seen that the value of the frame counter increases by 273 every time the block index is updated. For example, for a block structure with a block duration of 96ms, the frame counter will wrap around in 3,435,974 minutes. Table 2

[0273] By comparing Table 2 with Table 1, it can be seen that the rapid increase of the frame counter value can be prevented if the random number 800 is used. Therefore, it is not necessary to update the security key so frequently.

[0274] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (3), Figure 8 The same effect can also be achieved by constructing a frame counter (FC) field with a random number in , without dividing the frame counter field into slot index, round index, and block index fields (e.g., 822 to 824): FC=Block_Index×NumRounds×NumSlots+Round_Index×NumSlots+Slot_Index (3)

[0275] In equation (3), Block_index, Round_Index, and Slot_Index represent a block index, a round index, and a slot index, respectively.

[0276] Figure 8 The random numbers in can also have Figure 6B The random number has the same format as in the Frame Counter field, i.e., the frame counter field is 4 octets long and the random number includes a random number security level field.

[0277] Fig. 9 FIG. 9 is a schematic diagram showing the format of a secure SOR frame 900 provided by some exemplary embodiments of the present invention. Fig. 6A Similar to that described in , the secure SOR frame 900 includes a field 616 that carries a security payload.

[0278] Field 616 includes field 911 as a presence control field, field 912 carrying a time offset, field 913 carrying a block index, field 914 carrying a round index, and field 915 carrying a slot index. Field 911 may include field 9112 carrying a block index presence indicator, field 9114 carrying a round index presence indicator, field 9116 carrying a slot index presence indicator, and a reserved field 9118.

[0279] In the case where the controller is to be assigned to an existing block structure, the block index, round index, and slot index pointed to by the Time Offset field of the SOR frame may not start from zero. If the POLL frame sent at the time pointed to by the Time Offset field of the SOR frame does not carry the round and block indexes in the open payload (such as Fig. 7A As shown), that is, if the index is encrypted; the responder will not be able to deprotect the POLL frame because it will not be able to construct a random number. When indicating the first round assigned to the controller, in addition to the time offset of the block / round assigned in field 912, if the controller also includes the index of the block, round and time slot pointed to by the time offset field 912, for example, in field 616 of the secure SOR frame 900. This will enable the first frame (e.g., POLL frame) sent in the block, round and time slot pointed to by the time offset field 912 to be encrypted.

[0280] In some other examples, if any of the block index presence indicator in field 9112, the round index presence indicator in field 9114, and the slot index presence indicator in field 9116 indicate that the corresponding index is not included, a default index (e.g., zero) may be applied.

[0281] Fig. 10A An exemplary session 1010 between the initiator 260 and the responder 1 (eg, the responder 270 - 1 ) provided by some exemplary embodiments of the present invention is shown. Fig. 10B An exemplary session 1020 between initiator 260 and responder 2 (e.g., responder 270-2) provided by some exemplary embodiments of the present invention is shown. In both examples, the number of rounds per block (NumRounds) = 16; and the number of slots per round (Numslots) = 16. This results in the number of bits of the round index (N) = the number of bits of the slot index (M) = 4. The frame counter field used to construct a random number for protecting / deprotecting each frame is shown below the frame, such as "Random number: FC = ...".

[0282] like Fig. 10A As shown, the SOR frame sent to responder 1 can be as follows Fig. 6A The secure SOR frame shown, therefore, responder 1 will assume that the slot index, round index, and block index are all 0. Therefore, the first POLL frame (POLL 1) sent to responder 1 is sent in slot 0 (0x0) of round 0 of block 0, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the POLL 1 frame can be calculated as 0x0000. Similarly, the 128th RPRT frame (RPRT 128) is sent in slot 7 (0x7) of round 0 (0x0) of block 127 (0x7F), and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the RPRT 128 frame can be calculated as 0x7F07.

[0283] like Fig. 10B As shown, the SOR frame sent to responder 2 may be as follows: Fig. 9The secure SOR frame shown, therefore, responder 2 will understand the existing block-based time structure and indexing of slots, rounds, and blocks by deprotecting the secure SOR frame, where the first POLL is expected, for example, "block index = 1, round index = 1, slot index = 0" shown at 1022. Therefore, the first POLL frame (POLL 1) sent to responder 2 is sent in slot 0 of round 1 of block 1, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number for protecting / deprotecting the POLL 1 frame can be calculated as 0x0110. Similarly, the 129th RPRT frame (RPRT 129) is transmitted in time slot 15 (0xF) of round 1 (0x1) of block 128 (0x80), and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / deprotecting the RPRT 128 frame can be calculated as 0x801F.

[0284] Assuming that the indexes of the block, round, and slot structures are always increasing and that the block structure never restarts in the same session between a pair of initiators and responders, an internal block random number, such as random number 720 or random number 800, is constructed. In the event that the block structure restarts two or more times between the same pair of initiators and responders, the internal block random number may be repeated if the same security key is used to protect the frames, which may violate security.

[0285] In some embodiments, the security key should be updated when the block structure is restarted, that is, a new security key should be used every time a new block structure is established between the same pair of initiator and responder.

[0286] In some other embodiments, a cycle may be defined to avoid this situation, wherein a cycle includes multiple blocks. That is, a layer may be added on top of the block: the cycle. When the security key remains unchanged, each time the block structure is restarted between the same pair of initiator and responder, the index of the cycle will increase. Fig.11A FIG. 1 shows a schematic diagram of a time structure 1110 including a period provided by some exemplary embodiments of the present invention. Fig.11A As shown, two cycles, cycle 0 and cycle 1, are shown.

[0287] If the period is newly defined, the index of the period in which the security frame is sent can also be used to construct the internal block random number. For example, the internal block random number can be constructed based on the time slot index, round index, block index and period index.

[0288] Fig. 11BFIG. 1 is a schematic diagram showing the format of another secure SOR frame 1120 provided by some exemplary embodiments of the present invention. Fig. 9 Similar to that described in , the secure SOR frame 11200 includes a field 616 that carries a security payload.

[0289] Field 616 includes field 1121, which is a presence control field and includes field 1124 carrying a block index presence indicator, field 1125 carrying a round index presence indicator, field 1126 carrying a time slot index presence indicator, field 1127 carrying a cycle index presence indicator, and a reserved field 1128.

[0290] Fields 1124 to 1126 may be used with Fig. 9 Fields 9112 to 9116 in are similar and will not be described again. Fig. 11B , assuming that fields 1124 to 1126 indicate that there is no block index field, round index field, or time slot index field, then Fig. 11B There is no Fig. 9 Fields corresponding to fields 913 to 915 in.

[0291] Field 1127 carries a cycle index presence indicator, which may indicate whether field 1123 is included. Fig. 11B As shown, field 616 includes a field 1122 that carries a time offset and a field 1123 that carries a period index.

[0292] Alternatively, if the block index presence indicator in field 1124 is 1, a block index field carrying a block index may also be included, Fig. 9 If the round index presence indicator in field 1125 is 1, a round index field carrying the round index may also be included, similar to field 913 in FIG. Fig. 9 If the slot index presence indicator in field 1126 is 1, a slot index field carrying a round index may also be included, similar to field 914 in FIG. Fig. 9 The security payload 616 may include a presence control field (e.g., field 911 or 1121), a field carrying a time offset (e.g., field 912 or 1122), and may also include zero or more of a block index field, a round index field, a time slot index field, and a cycle index field, without any order restriction. For example, the field carrying a time offset (e.g., field 912 or 1122) may be located at the end of field 616, i.e., the last two octets.

[0293] In some examples, initiator 260 may use secure SOR frame 1120 to inform responder 270 of the cycle index each time a new block structure is started, so as to allow the responder to synchronize with the cycle index.

[0294] Fig. 11C A schematic diagram showing another format of a random number 1130 for protecting a frame within a block structure provided by some exemplary embodiments of the present invention. Alternatively, the random number 1130 may be referred to as an intra-block based random number.

[0295] like Fig. 11C As shown, the random number 1130 includes: a frame 1131 carrying a source address, a field 1132 carrying a time slot index, a field 1133 carrying a round index, a field 1134 carrying a block index, a field 1135 carrying a cycle index, and a field 1136 carrying a block structure indicator. It should be noted that the random number 1130 and Figure 8 The random number 800 in is similar, except that Figure 8 Field 824 in is split into Fig. 11C Field 1134 and field 1135 in. For example, some MSBs of the block index field may be allocated to the cycle index, such as 6 bits to allow a maximum of 64 cycles.

[0296] Alternatively, the random number 1130 may include a field that carries a security level, which is similar to Figure 6B Alternatively, field 1135 may be split into two fields, one of which carries the period index and the other of which is reserved. In some examples, the order of fields 1132 to 1135 may be another way, such as Fig. 11C Reverse order as shown.

[0297] According to the above combination Figures 4 to 9 In some embodiments described, some security frames may include a field carrying a PN, such as SOR frame 610 or 900. Table 3 below lists some frames, some of which may need to include a PN, while other frames may not. Table 3

[0298] Specifically, frames sent outside of the block structure (e.g., ADV-POLL, ADV-RESP, SOR) include a PN field in the frame and use a random number based on the outer block (e.g., Figure 6B The random number 620 shown in FIG. 60 is used, while frames sent within the block structure (e.g., POLL, RESP, RPRT, PRM-RESP, PRM-REQ, ADV-HBS) do not include a PN field in the frame and use an internal block-based random number (e.g., Figure 7B The random number 720 shown, or Figure 8 The random number shown is 800).

[0299] In some examples, the operation of protecting the frame may also be referred to as an AEAD transform, and the operation of removing protection from the security frame may also be referred to as an inverse AEAD transform, but the present invention is not limited in this regard.

[0300] Although the above reference Figures 4 to 11C Some embodiments are described in relation to a block-based temporal structure, but it should be understood that they may also be related to a super-block-based temporal structure.

[0301] Fig. 12A A schematic diagram 1210 of random number construction in a super-block-based temporal structure provided by some exemplary embodiments of the present invention is shown. Fig. 12A As shown, the super block consists of three types of blocks: block 0 includes 2 rounds, each round has 32 time slots, block 1 includes 8 rounds, each round has 8 time slots, and block 2 includes 16 rounds, each round has 16 time slots. If the frame is sent in time slot 0 of round 7 or block 4, the random number may include a field 1212 carrying "time slot index = 0", a field 1214 carrying "round index = 7", and a field 1216 carrying "block index = 4". Fig. 12A The random number in may be an internal block random number based on the random number 720, wherein the length of fields 1212 to 1216 is fixed.

[0302] Fig. 12B A schematic diagram 1220 of random number construction in a super-block-based temporal structure provided by some exemplary embodiments of the present invention is shown. Fig. 12A Similarly, a superblock consists of three types of blocks: block 0 includes 2 rounds, each with 32 time slots, block 1 includes 8 rounds, each with 8 time slots, and block 2 includes 16 rounds, each with 16 time slots. If the frame is sent in slot 0 of round 7 or block 4, the random number may include a field 1222 carrying "slot index = 0", a field 1224 carrying "round index = 7", and a field 1226 carrying "block index = 4".

[0303] Fig. 12B The random number in may be an internal block random number based on the random number 800, wherein the lengths of fields 1222 to 1226 are not fixed. Specifically, the maximum number of slots in a round (Max_NumSlots) = max(32,8,16) = 32, so M can be determined to be 5. Therefore, the length of field 1222 is 5 bits. Specifically, the maximum number of rounds in a block (Max_NumRounds) = max(2,8,16) = 16, so N can be determined to be 4. Therefore, the length of field 1224 is 4 bits.

[0304] Therefore, PN can be used to construct an outer block random number, and the time slot index, round index and block index (and optional cycle index) can be used to construct an inner block random number. The frames transmitted between the initiator and the responder can be protected accordingly, thereby ensuring the security of communication.

[0305] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (4), Fig. 12A The same effect can be achieved by constructing the frame counter field with a random number in , without dividing the frame counter field into slot index, round index, and block index fields: FC=Block_Index×Max_NumRounds×Max_NumSlots+Round_Index×Max_NumSlots+Slot_Index (4)

[0306] In equation (4), Block_index, Round_Index and Slot_Index represent block index, round index and slot index respectively. In the case where the block index in the super block is expressed as a relative block index, the block index can be calculated according to equation (5): Block_Index=Hyper_Block_Index×NumBlocks+Relative_Block_Index (5)

[0307] In equation (5), Hyper_Block_Index is the index of the super block, Relation_Block_Index is the relative block index, and NumBlocks is the number of blocks in the super block.

[0308] Fig.13 A schematic diagram of another exemplary MMS ranging session 1300 in a block-based time structure provided by some exemplary embodiments of the present invention is shown. As shown in diagram 1300, the MMS ranging session 1300 includes an initialization and establishment phase, followed by one or more measurement periods.

[0309] exist Fig.13 In the example, it is assumed that the block structure also exists during the initialization and setup phase. For example, the controller may establish the block structure right at the beginning of the initialization and setup phase (i.e., even before or at the beginning). Therefore, the initialization and setup phase and one or more measurement cycles are within the block structure.

[0310] Since the synchronization between the initiator 260 and the responder 270 at the slot level may not be easy during the initialization and establishment phases, the slot index is not used to construct the random number, but a short PN (e.g., 1 octet long) may be used. In this case, the PN, round index, and block index may be used to construct the random number used to protect the frame, as shown in 1310. Since the round index is used, it is recommended that the initialization and establishment phases should be completed within one round to prevent loss of synchronization due to changes in the round index. Fig.14 A signaling diagram illustrating a process 1400 of another exemplary MMS ranging session provided by some exemplary embodiments of the present invention is shown.

[0311] Process 1400 begins with the controller and two controlled devices performing session establishment 1412 and session establishment 1414, respectively. During session establishment 1412 / 1414, long-term session parameters such as UWB channel number, preamble, block structure (e.g., number of blocks, block duration), etc. are negotiated. When security is enabled, the controller will also provide at least one security key to each controlled device to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders is also provided. For NBA-MMS ranging sessions, narrowband-related parameters (e.g., NB channel number, number of MMS fragments, etc.) can also be negotiated during session establishment 1412 / 1414. Although Fig.13 It is shown that the same block structure is used for the initialization and setup phase and the measurement period, but different block structures can also be used for the initialization and setup phase and the measurement period. In this case, one security key can also be negotiated for the initialization and setup phase and a different security key can be negotiated for the measurement period. In this case, the PN space is also different for the initialization and setup phase and the measurement period. In addition, the block index of the block structure of the measurement period can start from zero at the time pointed to by the time offset of the SOR frame.

[0312] Some other parameters such as the number of MMS fragments, reporting mode, etc. may be considered short-term parameters because they may be modified during the MMS ranging session.Session establishment 1412 / 1414 may be performed out-of-band, such as using a Bluetooth or Wi-Fi radio, or may be performed in-band, such as using a narrowband or UWB radio.

[0313] Additionally, the roles of initiator and responder are also assigned during session establishment 1412 / 1414. Fig.14 In the specific example shown in , it is assumed that the controller assumes the role of the initiator 260, and the controlled is assigned the roles of the responders 270-1 and 270-2. However, it should be understood that it is also possible that the controlled is assigned the role of the initiator, and the controller assumes the role of the responder.

[0314] At 1416, the controller (initiator 260) starts the block structure before sending the first ADV-POLL frame. For example, the initiator 260 can establish a block and round structure, for example, at least defining a block duration and a round duration. In some cases, a time slot structure may also be defined, in which case, whether inside or outside the block structure, a time slot index can be used instead of a PN for random number construction.

[0315] At 1422, the initiator 260 opportunistically sends ADV-POLL frames at times and intervals determined by it, and the responders 270-1 and 270-2 can opportunistically listen for incoming ADV-POLL frames. In order to allow the responders 270-1 and 270-2 to synchronize with the block structure, the ADV-POLL frame includes the index of the round and block in which the ADV-POLL frame is sent, as well as the duration of the current round. If a slot structure is also defined, the ADV-POLL frame also includes the slot index of the slot in which the ADV-POLL frame is sent.

[0316] At 1424, if responder 270-1 intends to participate in a ranging session with initiator 260, responder 270-1 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN (e.g., PN_U1) that is used to construct a random number for protecting the ADV-RESP frame. Fig.14 As shown, a secure ADV-RESP frame may be sent from responder 270 - 1 to initiator 260 .

[0317] At 1426, if responder 270-2 intends to participate in a ranging session with initiator 260, responder 270-2 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN (e.g., PN_U2) that is used to construct a random number for protecting the ADV-RESP frame. Fig.14 As shown, a secure ADV-RESP frame may be sent from responder 270 - 2 to initiator 260 .

[0318] At 1428, once the initiator 260 receives the ADV-RESP frame, it sends a SOR frame that provides the time offset for the start of the first distance measurement period. The SOR frame may be sent in a broadcast manner so that both the responder 270-1 and the responder 270-2 can detect the frame. If security is enabled, the SOR frame carries a broadcast PN (e.g., PN_B) that is used to construct a random number for protecting the SOR frame. Fig.14As shown, a secure SOR frame can be sent from the initiator 260 to the responders 270-1 and 270-2. It should be noted that different numbering spaces can be used for the PNs of unicast and broadcast frames. In this case, the time offset field in the SOR frame points to the time when the first POLL frame is sent. Alternatively, it is also possible that the SOR frame carries multiple time offset fields, one for each responder; or the initiator can send multiple unicast SOR frames, one for each responder; the time offset field points to the exact time when the ranging measurement period of a specific responder begins.

[0319] At 1432, initiator 260 sends a broadcast POLL frame to responders 270-1 and 270-2 at the beginning of the first time slot of a round, where the beginning of the first time slot is indicated by the time offset in the SOR frame. Initiator 260 may also include other control information in the POLL frames of responders 270-1 and 270-2.

[0320] At 1434, the responder 270-1 sends a RESP frame back to the initiator 260 if it successfully receives the POLL frame. The POLL frame and the RESP frame may enable the initiator 260 and the responder 270-1 to achieve time and frequency synchronization.

[0321] During the ranging phase, initiator 260 and responder 270-1 may exchange zero or more UWB RSFs, and optionally one or more UWB RIFs. RSFs are used to perform ranging measurements, while RIFs are used to check the integrity of ranging measurements. Fig.14 The exchanges between initiator 260 and responder 270-1 are shown at 1436 and 1438 in FIG.

[0322] After the initiator 260 or the responder 270-1 completes receiving all UWB segments in the ranging phase, the reporting phase may begin. During the reporting phase, the initiator 260 or the responder 270-1 may generate a ranging measurement report and send an RPRT frame carrying the measurement report to the peer device. Fig.14 As shown, at 1440 , the initiator 260 sends a secure RPRT frame to the responder 270 - 1 , and at 1442 , the responder 270 - 1 sends a secure RPRT frame to the initiator 260 .

[0323] The processes 1452 to 1462 between the initiator 260 and the responder 270 - 2 are similar to the processes 1432 to 1442 between the initiator 260 and the responder 270 - 1 , and thus will not be described again herein.

[0324] like Fig.14As shown, each of all security frames carries an appropriate PN. The PN together with the round and block indexes can be used to construct a random number for protecting POLL, RESP and RPRT frames.

[0325] The present invention shows some exemplary formats of frames and random numbers in conjunction with the accompanying drawings. However, it should be noted that the examples are given for illustrative purposes and do not impose any restrictions on the present invention. For example, a frame or a random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may also be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying information and the other field reserved. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the arrangement of the fields may be another way, such as arranging in a different order. The present invention is not limited in this respect.

[0326] Fig.15A A schematic diagram showing the format of a random number 1510 for protecting a frame provided by some exemplary embodiments of the present invention is shown. For example, the random number 1510 may be constructed by the initiator 260 or the responder 270-1 or 270-2.

[0327] like Fig.15A As shown, the random number 1510 includes a frame 1511 carrying a source address, a field 1512 carrying a PN, a field 1513 carrying a round index, and a field 1514 carrying a block index.

[0328] Field 1511 may indicate an extended address of the device originating the frame. Fields 1512 to 1514 may be considered as a frame counter random number 720 .

[0329] The length of the field 1512 carrying the PN may be 1 octet, i.e., 8 bits. The PN may also be referred to as a short PN. For example, the PN starts at 0 in each round and may not wrap around in a round. It should be understood that the maximum number of safe frames per round depends on the length of the field 1512. For example, if the field 1512 occupies 8 bits, the maximum number of safe frames per round is 256.

[0330] like Fig.15A As shown, the length of field 1513 is fixed, for example, 15 bits (8 to 22). In some other examples, the length of the field carrying the round index may not be a fixed value. Fig. 15BA schematic diagram of another format of a random number 1520 is shown, which includes a frame 1521 carrying a source address, a field 1522 carrying a PN, a field 1523 carrying a round index, and a field 1524 carrying a block index. The length of field 1523 is N bits, where N can be determined by the above equation (2).

[0331] Alternatively, the random number 1510 or 1520 may include a field that carries a security level, which is similar to Figure 6B Alternatively, field 1514 or 1524 may be split into two fields, one of which carries the block index and the other of which is reserved. In some examples, the order of fields 1512 to 1514 or 1522 to 1524 may be another way, such as Fig.15A or Fig. 15B Reverse order as shown.

[0332] Fig.16A FIG. 1 is a schematic diagram showing the format of a secure RPRT frame 1610 provided by some exemplary embodiments of the present invention. For example, the secure RPRT frame 1610 may be Fig.14 Any of the frames sent at 1440, 1442, 1460 and 1462.

[0333] like Fig.16A As shown, the secure RPRT frame 1610 includes a field 1611 carrying an ID, a field 1612 carrying a security indicator, a field 1613 carrying an address, a field 1614 carrying a PN, a field 1615 carrying a security payload, and a field 1616 carrying a MIC. Fields 1611 to 1614 may be considered to be the CHR of the secure RPRT frame 1610. Although the RPRT frame 1610 is shown in a compressed PSDU format, the described process may work even if the frame is carried as a compressed header ID format or even as a legacy 802.15.4 frame.

[0334] Field 1611 may indicate an identification of a secure RPRT frame 1610. Field 1612 may indicate whether the frame is secure. In some examples, field 1612 carrying a "1" indicates that the frame is secure. Fig.16A As shown, the total length of field 1611 and field 1612 may be 1 octet.

[0335] Field 1614 may carry the packet number of the secure RPRT frame 1610. Fig.14PN_U1 may be maintained for an upstream transmission from responder 270-1 to initiator 260, and PN_D1 may be maintained for a downstream transmission from initiator 260 to responder 270-1. PN_U2 may be maintained for an upstream transmission from responder 270-2 to initiator 260, and PN_D2 may be maintained for a downstream transmission from initiator 260 to responder 270-2. Fig.16A As shown, field 1614 may be 1 octet in length.

[0336] Field 1615 carries the security payload. Field 1616 carries the MIC generated by the AEAD transformation process. Field 1616 may be 4 octets or 8 octets in length.

[0337] Alternatively, the secure RPRT frame 1610 may include a field that carries a security level, which is similar to Fig. 6A Field 615 in is similar.

[0338] Fig. 16B FIG. 1 is a schematic diagram showing the format of an ADV-POLL frame 1620 provided by some exemplary embodiments of the present invention. For example, the ADV-POLL frame 1620 may be Fig.14 The frame sent at 1422.

[0339] like Fig. 16B As shown, the ADV-POLL frame 1620 includes a field 1621 carrying an ID, a field 1622 carrying a security indicator, a field 1623 carrying an address, a field 1624 as a presence control field, a field 1625 carrying a block index, a field 1626 carrying a round index, a field 1627 carrying a round duration, a field 1628 carrying a payload, and a field 1629 carrying a CRC. Fields 1621-1623 can be considered as the CHR of the ADV-POLL frame 1620, and fields 1624 to 1627 can be considered as the open payload of the ADV-POLL frame 1620.

[0340] Field 1621 may indicate an identification of ADV-POLL frame 1620. Field 1622 may indicate whether ADV-POLL frame 1620 is secure. In some examples, field 1622 carrying "0" indicates that ADV-POLL frame 1620 is not secure. Fig. 16B As shown, the total length of field 1621 and field 1622 may be 1 octet.

[0341] Field 1624 includes: a block index presence field 1681 carrying a block index presence indicator, a round index presence field 1682 carrying a round index presence indicator, a round duration presence field 1683 carrying a round duration presence indicator, and a reserved field 1684. Fig. 16B As shown, field 1624 may be 1 octet in length.

[0342] In some examples, the block index presence indicator is equal to a first value (e.g., 1) to indicate the presence of the block index field 1625, the round index presence indicator is equal to a first value (e.g., 1) to indicate the presence of the round index field 1626, and the round duration presence indicator is equal to a first value (e.g., 1) to indicate the presence of the round duration field 1627. For example, each of fields 1625 to 1627 can be 2 octets in length.

[0343] Alternatively, the secure ADV-POLL frame 1620 may include a field that carries a security level, which is similar to Fig. 6A Alternatively, the present invention does not limit the order of fields 1625 to 1627 and fields 1681 to 1683.

[0344] Since the ADV-POLL frame 1620 is sent at the beginning of a round and includes block structure information (e.g., block index, round index, round duration in fields 1625-1627), the initiator and one or more responders can synchronize to the block structure during the initialization and establishment phase.

[0345] Fig.17 An exemplary session 1700 of the initiator 260, the responder 1 (e.g., the responder 270-1), and the responder 2 (e.g., the responder 270-2) provided by some exemplary embodiments of the present invention is shown. Assuming that Fig. 15B The random number shown is 1520. As a specific example, assume that each block includes 16 rounds, that is, NumRounds=16, so it can be determined that N=4.

[0346] A downlink security frame from the initiator to responder 1 is shown at 1710, and a downlink security frame from the initiator to responder 2 is shown at 1720. A frame counter field used to construct a random number for protecting / deprotecting each frame is shown below the frame.

[0347] like Fig.17 As shown, the ADV-RESP frames from responder 1 and responder 2 are both secure frames sent in round 1 of block 6, and the PN field in both frames may be set to 0 (ie, as shown in FIG. Fig.17As shown, PN=0x00). The least significant 20 bits (expressed in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the ADV-RESP frame can be calculated as 0x06100. Although the FC of the two ADV-RESP frames is the same, this does not violate security because the source address field in the random number is different and the security keys used for responder 1 and responder 2 are different. Similarly, the 128th RPRT frame (RPRT 128) with the PN field set to 0xFF is sent to responder 1 in round 0 (0x0) of block 127 (0x7F), and the least significant 20 bits (expressed in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the RPRT 128 frame can be calculated as 0x7F0FF.

[0348] A potential wraparound of the PN field in the RPRT frame is also shown at 1712 in box 127. If wraparound of the PN field occurs within the same round, this will cause the frame counter (0x7F000) to repeat (the same counter used for the POLL frame (POLL 128)) and cause the random number to be reused. However, as long as the limit of 256 frames per device per round is followed, the frame counter will not repeat and this problem can be avoided.

[0349] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (6), Fig.15A or Fig. 15B The construction of the frame counter field with a random number in can also achieve the same effect without the need to divide the frame counter field into PN, round index and block index fields: FC=Block_Index×NumRounds×2 M +Round_Index×2 M +PN (6)

[0350] In equation (6), Block_index and Round_Index refer to block index and round index, respectively, and M = the number of bits used for the PN field.

[0351] According to the combination Figures 3 to 17 In some embodiments, the block index, round index, and time slot index / PN may be used to construct a random number, wherein the random number may be used to protect a frame or to deprotect a secure frame sent according to a block-based or super-block-based time structure, so that AEAD security operations may be applied and secure communication between the initiator and the responder may be guaranteed.

[0352] Further references Fig.18, shows a signaling diagram showing a communication process 1800 provided by some exemplary embodiments of the present invention. The process 1800 may involve a transmitter 1801 and a receiver 1802. It should be understood that referring to Figure 2A , the transmitter 1801 may be the controller 210 or the controlled 220, and the receiver 1802 may be the controlled 220 or the controller 210. It should be understood that, see Figure 2B , the sender 1801 can be the initiator 260 or the responder 270 , and the receiver 1802 can be the responder 270 or the initiator 260 .

[0353] The transmitter 1801 generates (1810) a first security frame. The first security frame may be protected by a first random number, wherein the first random number is constructed based on a first base packet number (BPN) and a first PN. In some embodiments, the transmitter 1801 may construct the first random number and then generate the first security frame.

[0354] The first BPN is associated with the initiator and the responder. Specifically, the first BPN is associated with the communication direction from the transmitter 1801 to the receiver 1802. For example, if the transmitter 1801 is the initiator 260, the first BPN is the DL BPN; if the transmitter 1801 is the responder 270, the first BPN is the DL BPN. The first PN is the packet number of the first security frame.

[0355] The first random number includes a first field carrying a first BPN and a second field carrying a first PN. The length of the first field may be equal to the first number, such as N1 bits. The length of the second field may be equal to the second number, such as N2 bits. For example, the total number of the first number and the second number may be a predefined value, such as 40 bits. The initial value of the first BPN may be stored locally in the transmitter 1801 and may be indicated to the receiver 1802 during session establishment, etc. and stored locally in the receiver. Alternatively, a default value (e.g., 0) may be used as the initial value of the first BPN.

[0356] The first random number includes a source address. For example, the first random number may include a field carrying the source address, such as a source address field. The length of the field carrying the source address may be predefined, such as 8 octets, 7 octets, or other values.

[0357] In some exemplary embodiments, the first security frame will be sent during the initialization and establishment phase or during the measurement period. In some examples, the first security frame may include the first BPN and the first PN. In some other examples, the first security frame may include the first PN without the first BPN, in which case the locally stored first BPN may be used.

[0358] The first security frame may include a first security indicator. For example, the first security frame may include a field carrying the first security indicator, such as a security indicator field. The first security indicator may indicate whether the first security frame is secure. For example, the first security indicator may be "1" to indicate that the first security frame is secure. For example, the length of the field carrying the first security indicator is 1 bit.

[0359] The first security frame includes a first PN field carrying a first PN. The length of the first PN field may be a predefined value, such as 1 octet.

[0360] The first security frame may include a BPN presence field carrying a BPN presence indicator. The BPN presence indicator may indicate whether the BPN field is included. For example, the BPN presence indicator is "1" to indicate that the BPN field is present. The first security frame may include a BPN field carrying a first BPN to allow the receiver to obtain a BPN for deprotecting the frame and subsequent security frames sent by the same initiator. In some examples, if the first BPN is equal to a default number (e.g., 0), the BPN presence indicator may be "0" to indicate that the BPN field is not included.

[0361] The transmitter 1801 transmits (1820) a first security frame 1822 to the receiver 1802. The receiver 1802 receives (1824) the first security frame 1822. The receiver 1802 deprotects (1830) the first security frame 1822. Specifically, the receiver 1802 deprotects the first security frame 1822 using a random number constructed based on the first BPN and the first PN.

[0362] Specifically, if the first security frame 1822 includes a BPN field and a first PN field, the receiver 1802 can directly obtain the first BPN and the first PN. If the BPN field is not included, a default value (such as 0) can be used as the first BPN. The receiver 1802 can also construct a random number for deprotecting the first security frame 1822 based on the first BPN and the first PN. The receiver 1802 stores the first BPN locally.

[0363] The random number constructed by the receiver 1802 should be the same as the first random number used to protect the first security frame constructed by the transmitter 1801. The first random number constructed by the receiver 1802 is similar to the random number described above (i.e., the random number constructed by the transmitter), and for the sake of brevity, it will not be described in detail.

[0364] In some exemplary embodiments, transmitter 1801 may also send a second security frame to receiver 1802, wherein the second security frame includes a second PN but does not include the first BPN. Receiver 1802 may receive the second security frame and construct a second random number for deprotecting the second security frame based on the second PN and the locally stored first BPN. In some examples, if the second PN is less than the PN in the previous security frame, receiver 1802 may determine that the PN has been wrapped around and should therefore update the locally stored first BPN by increasing by 1.

[0365] In some other exemplary embodiments, the transmitter 1801 may also send a third security frame to the receiver 1802, wherein the third security frame includes a second BPN and a third PN. The receiver 1802 may receive the third security frame. Since the second BPN is different from the first BPN stored locally, the receiver 1802 may replace the first BPN with the second BPN. That is, the second BPN is stored locally instead of the first BPN. The receiver 1802 also constructs a third random number for deprotecting the third security frame based on the second BPN and the third PN.

[0366] In the present invention, the security frame is generated by protecting the compressed frame, wherein the compressed frame can be a compressed PSDU frame or a frame with a compressed header IE format as described above. The security operation can be performed by using cryptographic operations such as authentication or encryption.

[0367] Fig.19 A schematic diagram of an exemplary MMS ranging session 1900 provided by some exemplary embodiments of the present invention is shown. As shown in diagram 1900, the MMS ranging session 1900 includes an initialization and establishment phase, followed by one or more measurement cycles, wherein the initialization and establishment phase are outside the block structure, and the one or more measurement cycles are inside the block structure.

[0368] exist Fig.19 In the example, the PN and the locally stored BPN can be used to construct a random number for protecting the frame, whether outside or inside the block structure, as shown in 1910. Table 4 Responder ID DL BPN UL BPN 1 0x00000078 0x00000048 2 0x00000294 0x000000159 …… Table 5 Initiator ID DL BPN UL BPN 1 0x00000078 0x00000048 Table 6 Initiator ID DL BPN UL BPN 1 0x00000294 0x000000159

[0369] An example of a BPN stored locally at an initiator (e.g., initiator 26) is shown in Table 4, and an example of a BPN stored locally at a responder (e.g., responders 270-1 and 270-2) is shown in Table 5 and Table 6, respectively. The DL BPN is used for security frames sent by the initiator to one or more responders, and the UL BPN is used for security frames sent by one or more responders to the initiator.

[0370] Fig. 20 A signaling diagram illustrating a process 2000 of an exemplary MMS ranging session is shown, provided by some exemplary embodiments of the present invention.

[0371] Similar to some embodiments described above, process 2000 begins with the controller and the controlled performing session establishment 2010. During session establishment 2010, it is assumed that security keys and security levels will be exchanged, and long-term session parameters such as UWB channel number, preamble, block structure (e.g., number of blocks, block duration), etc. are negotiated. During the MMS ranging session, long-term parameters are not expected to change. When security is enabled, the controller will also provide at least one security key to each controlled to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders will also be provided. For NBA-MMS ranging sessions, narrowband-related parameters (e.g., NB channel number, number of MMS fragments, etc.) can also be negotiated during session establishment 2010. Some other parameters such as the number of MMS fragments, reporting mode, etc. can be considered short-term parameters because they may be modified during the MMS ranging session. Session establishment 2010 can be performed out-of-band, such as using Bluetooth or Wi-Fi radios, or can also be performed in-band, such as using narrowband or UWB radios.

[0372] In addition, the roles of initiator and responder are also assigned during session establishment 2010. Fig. 20 In the specific example shown in , it is assumed that the controller assumes the role of the initiator 260, and the controlled is assigned the role of the responder 270. However, it should be understood that it is also possible that the controlled is assigned the role of the initiator, and the controller assumes the role of the responder.

[0373] At 2022, the initiator 260 opportunistically sends ADV-POLL frames at times and intervals determined by itself, and the responder 270 may opportunistically listen for incoming ADV-POLL frames.

[0374] At 2024, if responder 270 intends to participate in a ranging session with initiator 260, responder 270 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries the PN and BPN associated with the uplink transmission, and the PN and BPN (UL) are used to construct a random number for protecting the ADV-RESP frame. Fig. 20 As shown, a secure ADV-RESP frame may be sent from responder 270 to initiator 260 .

[0375] Once the initiator 260 has received the ADV-RESP frame, it stores the BPN(UL) locally. At 2026, the initiator 260 sends a SOR frame that provides the time offset for the start of the first distance measurement period. If security is enabled, the SOR frame carries the PN and the BPN associated with the downlink transmission, and the PN and BPN(DL) are used to construct a random number for protecting the SOR frame. Fig. 20 As shown, a secure SOR frame can be sent from the initiator 260 to the responder 270. Once the responder 270 receives the SOR frame, it stores the BPN (DL) locally. It should be noted that the PN in the uplink (responder to initiator) and downlink (initiator to responder) directions can use different numbering spaces.

[0376] At 2028, the initiator 260 sends a POLL frame to the responder 270 at the beginning of the first time slot of a round, where the beginning of the first time slot is indicated by the time offset in the SOR frame. The initiator 260 may also include other control information in the POLL frame of the responder 270. At 2030, the responder 270 sends a RESP frame back to the initiator 260 if it successfully receives the POLL frame. The POLL frame and the RESP frame may enable the initiator 260 and the responder 270 to achieve time and frequency synchronization.

[0377] During the ranging phase, initiator 260 and responder 270 may exchange zero or more UWB RSFs, and optionally one or more UWB RIFs. RSFs are used to perform ranging measurements, while RIFs are used to check the integrity of ranging measurements. Illustratively, the exchange Fig. 20 As shown at 2032 and 2034 in FIG.

[0378] After the initiator 260 or the responder 270 completes receiving all UWB segments in the ranging phase, the reporting phase may begin. During the reporting phase, the initiator 260 or the responder 270 may generate a ranging measurement report and send an RPRT frame carrying the measurement report to the peer device. Fig. 20As shown, at 2036 , the initiator 260 sends a secure RPRT frame to the responder 270 , and at 2038 , the responder 270 sends a secure RPRT frame to the initiator 260 .

[0379] Each of the secure POLL frame, secure RESP frame and secure RPRT frame carries a PN, and the carried PN and the locally stored BPN can be used to construct a random number for protecting / releasing protection of the POLL, RESP and RPRT frames.

[0380] In addition, if Fig. 20 As shown, PRM-RESP frames and PRM-REQ frames may be exchanged between the initiator 260 and the responder 270. The initiator 260 may send a secure PRM-RESP frame including a new BPN (i.e., a new BPN (DL)). The responder 270 may send a secure PRM-REQ frame including a new BPN (i.e., a new BPN (UL)). Thus, the locally stored BPN may be updated.

[0381] The present invention shows some exemplary formats of frames and random numbers in conjunction with the accompanying drawings. However, it should be noted that the examples are given for illustrative purposes and do not impose any restrictions on the present invention. For example, a frame or a random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may also be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying information and the other field reserved. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the arrangement of the fields may be another way, such as arranging in a different order. The present invention is not limited in this respect.

[0382] Fig.21A FIG. 2 is a schematic diagram showing the format of a security frame 2110 during the initialization and establishment phase provided by some exemplary embodiments of the present invention. For example, the security frame 2110 may be Fig. 20 The secure ADV-RESP frame sent at 2024 or the secure SOR frame sent at 2026. The secure frame 2110 may be based on a compressed PSDU or may be based on a compressed header ID format or even based on a legacy 802.15.4 frame format, in which case the security enable field in the frame control (FC) field is set to 1 to indicate that the auxiliary security header field is not present in the MHR.

[0383] like Fig.21AAs shown, the security frame 2110 includes a field 2111 carrying an ID, a field 2112 carrying a security indicator, a field 2113 carrying an address, a field 2114 serving as a presence control field (including a field 2114-1 carrying a BPN presence indicator and a reserved field 2114-2), a field 2115 carrying a PN, a field 2116 carrying a BPN, a field 2117 carrying a security payload, and a field 2118 carrying a MIC.

[0384] Field 2112 may indicate whether the frame is secure. In some examples, field 2112 may carry a "1" to indicate that the field is secure. In other examples, field 2112 may carry a "0" to indicate that the field is not secure, such as field 2115 may not be included.

[0385] Fields 2114 through 2116 may be considered the open payload of the secure frame 2110. The open payload may be authenticated but not encrypted because the BPN and PN are used by the receiver to construct a random number.

[0386] In the case where the security frame 2110 is a secure ADV-RESP frame, field 2116 may include a BPN associated with an uplink transmission, i.e., BPN_UL. In the case where the security frame 2110 is a secure SOR frame, field 2116 may include a BPN associated with a downlink transmission, i.e., BPN_DL. If the secure SOR frame is broadcast or multicast, multiple BPNs associated with multiple responders may be included in the open payload. In this case, the PN may also be extracted from a separate broadcast PN space.

[0387] In some examples, security frame 2110 may include a field carrying a security level, for example, if a security level was not negotiated during session establishment 2010.

[0388] Fig.21B A schematic diagram showing the format of a security frame 2120 during a measurement period provided by some exemplary embodiments of the present invention is shown. For example, the security frame 2120 may be Fig. 20 The secure frame 2120 may be based on a compressed PSDU, a secure POLL frame sent at 2028, a secure RESP frame sent at 2030, or a secure RPRT frame sent at 2036 / 2038. The secure frame 2120 may be based on a compressed PSDU.

[0389] like Fig.21B As shown, the security frame 2120 includes a field 2121 carrying an ID, a field 2122 carrying a security indicator (e.g., Fig.21B , a field 2122 carrying a “1” in the field, a field 2123 carrying an address, a field 2124 carrying a PN, a field 2125 carrying a security payload, and a field 2126 carrying a MIC.

[0390] In some examples, the secure frame 2120 is similar to the secure RPRT frame 1610 described above, and therefore will not be described in detail for the sake of brevity.

[0391] Fig. 21C A schematic diagram showing the format of a secure SOR frame 2130 provided by some exemplary embodiments of the present invention is shown. For example, the secure frame 2130 may be based on a frame having a compressed header IE format, that is, based on a compressed header IE format.

[0392] like Fig. 21C As shown, the secure SOR frame 2130 includes a field 2131 carrying an FC, a field 2132 carrying an address, a field 2133 carrying an ID, and a field 2134 carrying a security indicator (eg, Fig. 21C The security header field 2134 includes a field 2135-1 (“1” in the frame control field), a field as a presence control field (including a field 2135-1 carrying a BPN presence indicator and a reserved field 2135-2), a field 2136 carrying a PN, a field 2137 carrying a payload, and a field 2138 carrying a MIC. It should be understood that since the BPN presence indicator is “0” in field 2135-1, there is no field carrying a BPN. The security enable field in the frame control (FC) field 2131 is set to 1 to indicate that the auxiliary security header field is not present in the MHR. In this case, the secure SOR frame 2130 does not include the BPN field, and the security level applied only involves authentication (i.e., the security level is any one of 1, 2, or 3), so the payload in field 2137 is unsecured, but includes a field 2138 carrying a MIC.

[0393] It should be noted that in the case of a k-bit field carrying a PN, a maximum of 2 bits can be protected before the BPN needs to be incremented. k For example, if k = 8 bits, then for the same BPN, a maximum of 256 frames can be protected.

[0394] In some examples, when the PN of a security frame received from a transmitter is less than the PN of a previous security frame received from the same transmitter, the locally stored BPN should be increased by 1. In some other examples, the BPN may be explicitly updated during the measurement session. For example, the BPN may be updated using a security PRM-REQ (for UL) or a security PRM-RESP (for DL).

[0395] Fig.21DA schematic diagram showing the format of a secure PRM-REQ or PRM-RESP frame 2140 provided by some exemplary embodiments of the present invention is shown. The secure frame 2140 includes an SHR field 2141 , a PHR field 2142 , and a PHY payload field 2143 .

[0396] Field 2143 includes field 2151 carrying an ID, field 2152 carrying a security indicator (e.g., Fig.21D , field 2152 carrying a "1" in the field, field 2153 carrying an address, field 2154 as a presence control field (including field 2154-1 carrying a BPN presence indicator and a reserved field 2154-2), field 2155 carrying a PN, field 2156 carrying a BPN, field 2157 carrying a security payload, and field 2158 carrying a MIC.

[0397] Fields 2154 through 2156 may be considered the open payload of the secure frame 2140. The open payload may be authenticated but not encrypted because the BPN and PN are used by the receiver to construct a random number.

[0398] In some examples, field 2143 in security frame 2140 is similar to security frame 2110 described above, and therefore will not be described in detail for the sake of brevity.

[0399] Fig.21E A schematic diagram showing the format of a random number 2150 provided by some exemplary embodiments of the present invention is shown. The random number 2150 may be used to protect a frame or to deprotect a secure frame, for example, during the process 2000.

[0400] like Fig.21E As shown, the random number 2150 includes a frame 2151 carrying a source address, a field 2152 carrying a PN, and a field 2153 carrying a BPN. In some examples, fields 2152 to 2153 can be considered as a frame counter of the random number 2150. Fig.21E As shown, each length of fields 2152 to 2153 is predefined, and the total number of lengths is 40 bits.

[0401] Alternatively, the random number 720 may include a field carrying a security level. Alternatively, the field 2153 may be split into two fields, one of which carries the BPN and the other is reserved. Alternatively, the field 2152 may be located after the field 2153, i.e., the order of the fields 2152 and 2153 may be reversed.

[0402] Fig.22AAn exemplary downlink session 2210 from an initiator to a responder 1 (e.g., responder 270-1) provided by some exemplary embodiments of the present invention is shown. The value in the frame counter field (i.e., FC) is shown below the frame, and this field is used to construct a random number for protecting / deprotecting each frame.

[0403] like Fig.22A As shown, the SOR frame can be Fig.21A The secure SOR frame shown in FIG. 1 is a secure SOR frame and carries BPN=0x00 and PN=0x00. Therefore, the first POLL frame (POLL 1) is sent to responder 1 in round 0 of block 0 and carries a PN field set to 0x01, and the least significant two octets (expressed in hexadecimal) of the frame counter field used to construct a random number for protecting / unprotecting the POLL 1 frame can be calculated as 0x0001. Similarly, the 128th RPRT frame (RPRT 128) carrying PN=0xFF is sent in round 0 of block 127, and the least significant two octets (expressed in hexadecimal) of the frame counter field used to construct a random number for protecting / unprotecting the RPRT128 frame can be calculated as 0x00FF. As shown in FIG. Fig.22A As shown, the BPN associated with the downlink transmission from the initiator to the responder 1 may be explicitly updated at 2212 by the initiator by sending a PRM-RESP 1 frame carrying a BPN field set to 0x01.

[0404] Fig. 22B An exemplary uplink session 2220 from responder 2 (e.g., responder 270-2) to the initiator provided by some exemplary embodiments of the present invention is shown. The value in the frame counter field (i.e., FC) is shown below the frame, and this field is used to construct a random number for protecting / deprotecting each frame.

[0405] like Fig. 22BAs shown, the ADV-RESP frame can be a security frame carried by responder 2 and carries BPN=0x07 and PN=0x01. Therefore, the first RESP frame (RESP 1) is sent by responder 2 in round 1 of block 20 and carries a PN field set to 0x02, and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / deprotecting the RESP 1 frame can be calculated as 0x0702. Similarly, the 128th RPRT frame (RPRT 128) carrying PN=0xFF is sent by responder 2 in round n of block 227, and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / deprotecting the RPRT 128 frame can be calculated as 0x07FF. As Fig. 22B As shown, the BPN associated with the upstream transmission from responder 2 to the initiator can be explicitly updated by responder 2 at 2222 by sending a PRM-REQ 1 frame carrying a BPN field set to 0x08.

[0406] Alternatively, by defining the value of the frame counter field (i.e., FC) as equation (7), Fig.21E The same effect can also be achieved by constructing the frame counter field with a random number in , without dividing the frame counter field into PN and BPN fields: FC=PN||BPN (7)

[0407] In equation (7), “||” indicates a cascade operation.

[0408] According to reference Figures 18 to 22B In some embodiments, BPN and PN can be used to construct a random number, wherein the random number can be used to protect a frame or to deprotect a frame regardless of whether the secure frame is sent according to a block-based timing structure or a super-block-based timing structure, and therefore, AEAD security operations can be applied and secure communication between the initiator and the responder can be guaranteed.

[0409] Fig.23 FIG. 2 shows an exemplary block diagram of a communication device 2300 provided in some embodiments of the present invention. The device 2300 may be implemented at a transmitter, such as a Figure 3 The transmitter 301 or Fig.18 The transmitter 1801 in the embodiment of the present invention may be implemented as a chip or chip system in the transmitter. Fig.23 As shown, the device includes a generating module 2310 and a sending module 2320.

[0410] It should be understood that the module may be referred to as a unit or a means, and the present invention is not limited in this regard.

[0411] In some exemplary embodiments, the generation module 2310 may be used to generate a first security frame, the first security frame to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the first block. The sending module 2320 may be used to send the first security frame.

[0412] In some examples, the identification information includes a time slot index, which is an index of a time slot in which the first security frame is sent. In some examples, the first random number includes a first field having a first number of bits, and the first field carries the time slot index.

[0413] In some examples, the first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

[0414] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is the packet number of the first security frame. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN.

[0415] In some examples, the first amount is a first predefined amount.

[0416] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0417] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0418] In some examples, a sum of the first number, the second number, and the third number is equal to a predefined total number.

[0419] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

[0420] In some examples, the first random number includes a first block indicator indicating that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0421] In some examples, the first security frame includes the block index and the round index. In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0422] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0423] In some examples, the generating module 2310 may also be used to generate a second security frame to be sent, wherein the second security frame is protected by a second random number constructed according to a second PN, wherein the second PN is a packet number of the second security frame. The sending module 2320 may also be used to send the second security frame.

[0424] In some examples, the second random number includes a field having a predefined number of octets that carries the second PN.

[0425] In some examples, the second random number includes a second block indicator indicating that the second security frame is sent outside the block-based timing structure or the super-block-based timing structure.

[0426] In some examples, the second security frame includes a PN field carrying the second PN.

[0427] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0428] In some examples, the second security frame includes a security payload, and wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second time slot index presence indicator indicating whether a second time slot index is included.

[0429] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0430] In some examples, at least one of the second block index presence indicator, the second round index presence indicator, or the second slot index presence indicator indicates that the corresponding index is not included and implicitly indicates that the corresponding index is a default index.

[0431] The device 2300 can be used in reference Figures 3 to 17 Some embodiments are implemented at a transmitter as described.

[0432] In some other exemplary embodiments, the generating module 2310 may be used to generate a first security frame to be sent in a block-based time structure or a super-block-based time structure, wherein the first security frame is protected by a first random number constructed based on a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being a packet number of the first security frame. The sending module 2320 may be used to send the first security frame.

[0433] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0434] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0435] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0436] In some examples, the first security frame includes a BPN presence field, and the BPN presence field carries a BPN presence indicator indicating whether the BPN field is included.

[0437] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0438] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0439] In some examples, the apparatus 2300 may further include a storage module for storing a first BPN associated with a first communication direction between the initiator and the responder.

[0440] In some examples, the transmission module 2320 can be used to transmit a second security frame including a second PN that is smaller than a PN included in a previous frame of the third security frame.

[0441] In some examples, the sending module 2320 may be used to send a third security frame including a second BPN.

[0442] The device 2300 can be used in reference Figures 18 to 22B Some embodiments are implemented at a transmitter as described.

[0443] Fig.24 2400 is an exemplary block diagram of a communication device 2400 provided in some embodiments of the present invention. The device 2400 may be implemented at a receiver, such as a Figure 3 The receiver 302 or Fig.18 The receiver 1802 in the embodiment of the present invention may be implemented as a chip or chip system in the receiver. Fig.24 As shown, the device includes a receiving module 2410 and a protection release module 2420.

[0444] It should be understood that the module may be referred to as a unit or a means, and the present invention is not limited in this regard.

[0445] In some exemplary embodiments, the receiving module 2410 may be used to receive a first security frame, which is sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds; each of the multiple rounds includes multiple time slots; the deprotection module 2420 may be used to deprotect the first security frame according to a first random number, wherein the first random number is constructed based on identification information associated with the first security frame, a round index and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0446] In some examples, the identification information includes a time slot index, which is an index of a time slot in which the first security frame is sent. In some examples, the first random number includes a first field having a first number of bits, and the first field carries the time slot index.

[0447] In some examples, the first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

[0448] In some examples, the identification information includes a first packet number (PN), and wherein the first PN is a packet number of the first security frame.

[0449] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0450] In some examples, the first random number includes: a second field having a second number of bits, carrying the round index; and a third field having a third number of bits, carrying the block index.

[0451] In some examples, the second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number. In some examples, the third number is a third predefined number.

[0452] In some examples, a sum of the first number, the second number, and the third number is equal to a predefined total number.

[0453] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

[0454] In some examples, the first random number includes a first block indicator indicating that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

[0455] In some examples, the first security frame includes the block index and carries the round index.

[0456] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0457] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0458] In some examples, the receiving module 2410 may also be used to receive a second security frame, the second security frame is not sent according to the block-based time structure or the super-block-based time structure. The deprotection module 2420 may also be used to deprotect the second security frame according to a second random number, the second random number is constructed according to a second PN, wherein the second PN is a packet number of the second security frame.

[0459] In some examples, the second random number includes a field having a predefined number of octets that carries the second PN.

[0460] In some examples, the second random number includes a second block indicator indicating that the second frame is transmitted outside of the block-based timing structure or the super-block-based timing structure.

[0461] In some examples, the second security frame includes a PN field carrying the second PN.

[0462] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0463] In some examples, the second security frame includes a security payload, wherein unprotecting the second security frame includes unprotecting the security payload based on the second random number, and wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second time slot index presence indicator indicating whether a second time slot index is included.

[0464] In some examples, if the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; if the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; if the second time slot index presence indicator indicates that the second time slot index is included, the security payload includes the time slot index.

[0465] In some examples, the deprotection module 2420 can be used to: determine that the corresponding index is a default index based on a determination that the corresponding index is not included based on at least one of the second block index existence indicator, the second round index existence indicator, or the second time slot index existence indicator.

[0466] The device 2400 can be used in reference Figures 3 to 17 Some embodiments are implemented at a receiver as described.

[0467] In some other exemplary embodiments, the receiving module 2410 may be configured to receive a first security frame, the first security frame being sent in a block-based time structure or a super-block-based time structure. The de-security module 2420 may be configured to de-protect the first security frame according to a first random number, wherein the first random number is constructed according to a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, wherein the first PN is a packet number of the first security frame.

[0468] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0469] In some examples, the first random number includes: a first field having a first number of bits, carrying the first BPN; and a second field having a second number of bits, carrying the first PN.

[0470] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0471] In some examples, the first security frame includes a BPN presence field, and the BPN presence field carries a BPN presence indicator indicating whether the BPN field is included.

[0472] In some examples, if the BPN presence indicator indicates that the BPN field is included, the first security frame includes the BPN field carrying the first BPN.

[0473] In some examples, if the BPN presence indicator indicates that the BPN field is not included, the first security frame indicates that the first BPN is a default number.

[0474] In some examples, the apparatus 2400 may further include a storage module for storing a first BPN associated with a first communication direction between the initiator and the responder.

[0475] In some examples, the receiving module 2410 may also be used to receive a second security frame including a second PN. The apparatus 2400 may also include an updating module configured to update the locally stored first BPN by increasing by 1 if the second PN is less than the PN included in the previous frame of the third security frame.

[0476] In some examples, the receiving module 2410 may also be used to receive a third security frame including a second BPN. The apparatus 2400 may also include an updating module, the updating module being used to replace the first BPN with the second BPN.

[0477] The device 2400 can be used in reference Figures 18 to 22B Some embodiments are implemented at a receiver as described.

[0478] Fig.25 2500 is a schematic block diagram of a device 2500 that can be used to implement some embodiments of the present invention. The device 250 can be considered as Figure 2A The controller 210 and the controlled 220 shown, or Figure 2BAnother exemplary implementation (eg, portion) of initiator 260 and responder 270 is shown.

[0479] As shown in the figure, the device 2500 includes a processor 2510, a memory 2520 coupled to the processor 2510, a suitable transmitter (TX) and receiver (RX) 2540 coupled to the processor 2510, and a communication interface coupled to the TX / RX 2540. The memory 2510 stores at least a portion of the program 2530. The TX / RX 2540 is used for bidirectional communication. The TX / RX 2540 has at least one antenna to facilitate communication, but in fact, the access node mentioned in the present invention may have several antennas. The communication interface may represent any interface required for communication with other network elements, such as an X2 interface for bidirectional communication between eNBs, an S1 interface for communication between a mobility management entity (MME) / serving gateway (S-GW) and an eNB, a Un interface for communication between an eNB and a relay node (RN), or a Uu interface for communication between an eNB and a terminal device.

[0480] Assume that program 2530 includes program instructions that, when executed by associated processor 2510, enable device 2500 to operate in accordance with embodiments of the present invention, as described herein with reference to Figures 3 to 24 The embodiments herein may be implemented by computer software executable by a processor 2510 of the device 2500, or by hardware, or by a combination of software and hardware. The processor 2510 may be used to implement various embodiments of the present invention. In addition, the combination of the processor 2510 and the memory 2520 may form a processing device 2550 for implementing various embodiments of the present invention.

[0481] The memory 2520 may be of any type suitable for the local technology network and may be implemented using any suitable data storage technology, such as non-transitory computer-readable storage media, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory (as non-limiting examples). Although only one memory 2520 is shown in the device 2500, there may be several physically different memory modules in the device 2500. The processor 2510 may be of any type suitable for the local technology network and may include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture (as non-limiting examples). The device 2500 may have multiple processors, such as a dedicated integrated circuit chip that is time-slave to a clock synchronized with a main processor.

[0482] The present invention provides a device, comprising: a processor; and a memory storing a computer program code; the memory and the computer program code are used to enable the device to execute the method implemented at the transmitter or receiver through the processor.

[0483] The present invention provides a computer-readable medium having instructions stored thereon. When the instructions are executed by a processor of a device, the device is caused to execute the method implemented at a transmitter or a receiver as described above.

[0484] In general, various embodiments of the present invention may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. Some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software, which may be performed by a controller, microprocessor, or other computing device. Although various aspects of embodiments of the present invention are shown and described as block diagrams, flow charts, or using some other graphical representations, it should be understood that the blocks, devices, systems, techniques, or methods described herein may be implemented in hardware, software, firmware, dedicated circuits or logic, general hardware or controllers or other computing devices (as non-limiting examples), or some combination thereof.

[0485] The present invention also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer executable instructions, such as instructions included in a program module, executed in a device on a target real or virtual processor to perform the above-mentioned reference Figures 3 to 24The process or method described. Typically, a program module includes a routine, program, library, object, class, component, data structure, etc. that performs a specific task or implements a specific abstract data type. In various embodiments, the functions of the program modules can be combined or split between program modules as needed. The machine executable instructions of the program modules can be executed in a local device or a distributed device. In a distributed device, the program modules can be located in a local storage medium and a remote storage medium.

[0486] The program code for implementing the method of the present invention may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer or other programmable data processing device so that the program code enables the functions / operations specified in the flow chart or block diagram to be implemented when the program code is executed by the processor or controller. The program code may be executed entirely on a machine, partially on a machine as an independent software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0487] The above program code may be embodied on a machine-readable medium, which may be any tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device or apparatus. The machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. The machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination thereof. More specific examples of machine-readable storage media would include an electrical connection with one or more wires, a portable computer floppy disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.

[0488] In addition, although operations are described in a particular order, this should not be understood as requiring such operations to be performed in the particular order shown or in sequence, or requiring all operations shown to be performed to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limitations on the scope of the invention, but should be interpreted as descriptions of features unique to a particular embodiment. In the context of a separate embodiment, certain features described in the present invention may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately in multiple embodiments or in any suitable sub-combination.

[0489] Although the invention has been described in language specific to structural features or methodological acts, it should be understood that the invention defined in the appended claims is not necessarily limited to the specific features or acts described above. Rather, the specific features and acts described above are disclosed as example forms of implementing the claims.

Claims

1. A method, characterized in that include: generating a first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure comprises a plurality of blocks, each of the plurality of blocks comprises a plurality of rounds, each of the plurality of rounds comprises a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the first block; The first security frame is sent.

2. The method according to claim 1, characterized in that The identification information includes a time slot index, where the time slot index is an index of the time slot in which the first security frame is transmitted.

3. The method according to claim 2, characterized in that The first random number comprises a first field having a first number of bits, the first field carrying the time slot index.

4. The method according to claim 3, characterized in that The first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

5. The method according to claim 1, characterized in that The identification information includes a first packet number (packet number, PN), and wherein the first PN is the packet number of the first security frame.

6. The method according to claim 5, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the first PN.

7. The method according to claim 6, characterized in that The first number is a first predefined number.

8. The method according to any one of claims 1 to 7, characterized in that The first random number includes: a second field having a second number of bits carrying the round index; A third field having a third number of bits carries the block index.

9. The method according to claim 8, characterized in that The second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number.

10. The method according to claim 8 or 9, characterized in that: The third number is a third predefined number.

11. The method according to any one of claims 8 to 10, characterized in that The sum of the first quantity, the second quantity and the third quantity is equal to a predefined total quantity.

12. The method according to any one of claims 1 to 11, characterized in that The first random number includes: A fourth field having a fourth number of bits carries a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

13. The method according to any one of claims 1 to 12, characterized in that The first random number includes a first block indicator, and the first block indicator indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

14. The method according to any one of claims 1 to 13, characterized in that The first security frame includes the block index and the round index.

15. The method according to claim 14, characterized in that The first security frame includes: A first block index existence indicator, indicating the existence of the first block index, The first round index existence indicator indicates the existence of the first round index.

16. The method according to any one of claims 1 to 15, characterized in that The first security frame includes a first security indicator to indicate that the first security frame is secure.

17. The method according to any one of claims 1 to 16, characterized in that Also includes: Generate a second security frame to be sent, the second security frame is protected by a second random number constructed according to a second PN, wherein the second PN is a packet number of the second security frame; The second security frame is sent.

18. The method according to claim 17, characterized in that The second random number includes a field having a predefined number of octets, the field carrying the second PN.

19. The method according to claim 17 or 18, characterized in that The second random number includes a second block indicator indicating that the second security frame is transmitted outside the block-based timing structure or the super-block-based timing structure.

20. The method according to any one of claims 17 to 19, characterized in that The second security frame includes a PN field carrying the second PN.

21. The method according to any one of claims 17 to 20, characterized in that The second security frame includes a second security indicator to indicate that the second security frame is secure.

22. The method according to any one of claims 17 to 21, characterized in that The second security frame comprises a security payload, and wherein the security payload comprises: The second block index existence indicator indicates whether the second block index is included. The second round index existence indicator indicates whether the second round index is included. The second time slot index existence indicator indicates whether the second time slot index is included.

23. The method according to claim 22, characterized in that If the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; If the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; If the second slot index presence indicator indicates that the second slot index is included, the security payload includes the slot index.

24. The method according to claim 22, characterized in that At least one of the second block index presence indicator, the second round index presence indicator, or the second slot index presence indicator indicates that a corresponding index is not included, and implicitly indicates that the corresponding index is a default index.

25. A method, characterized in that include: Receiving a first security frame, the first security frame is sent in a time slot in a first round belonging to a first block according to a block-based timing structure or a super-block-based timing structure, wherein the block-based timing structure or the super-block-based timing structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds; each of the plurality of rounds includes a plurality of time slots; The first security frame is unprotected according to a first random number, wherein the first random number is constructed according to identification information associated with the first security frame, a round index, and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

26. The method according to claim 25, characterized in that The identification information includes a time slot index, where the time slot index is an index of the time slot in which the first security frame is transmitted.

27. The method according to claim 26, characterized in that The first random number comprises a first field having a first number of bits, the first field carrying the time slot index.

28. The method according to claim 27, characterized in that The first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

29. The method according to claim 25, characterized in that The identification information includes a first packet number (packet number, PN), and wherein the first PN is the packet number of the first security frame.

30. The method according to claim 29, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the first PN.

31. The method according to claim 30, characterized in that The first number is a first predefined number.

32. The method according to any one of claims 25 to 31, characterized in that The first random number includes: a second field having a second number of bits carrying the round index; A third field having a third number of bits carries the block index.

33. The method according to claim 32, characterized in that The second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number.

34. The method according to claim 32 or 33, characterized in that The third number is a third predefined number.

35. The method according to any one of claims 32 to 34, characterized in that The sum of the first quantity, the second quantity and the third quantity is equal to a predefined total quantity.

36. The method according to any one of claims 25 to 35, characterized in that The first random number includes: A fourth field having a fourth number of bits carries a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

37. The method according to any one of claims 25 to 36, characterized in that The first random number includes a first block indicator, and the first block indicator indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

38. The method according to any one of claims 25 to 37, characterized in that The first security frame includes the block index and carries the round index.

39. The method according to claim 38, characterized in that The first security frame includes: A first block index existence indicator, indicating the existence of the first block index, The first round index existence indicator indicates the existence of the first round index.

40. The method according to any one of claims 25 to 39, characterized in that The first security frame includes a first security indicator to indicate that the first security frame is secure.

41. The method according to any one of claims 25 to 40, characterized in that Also includes: receiving a second security frame, the second security frame not being sent according to the block-based timing structure or the super-block-based timing structure; The second security frame is unprotected according to a second random number, where the second random number is constructed according to a second PN, wherein the second PN is a packet number of the second security frame.

42. The method according to claim 41, characterized in that The second random number includes a field having a predefined number of octets, the field carrying the second PN.

43. The method according to claim 41 or 42, characterized in that The second random number includes a second block indicator indicating that the second frame is transmitted outside the block-based timing structure or the super-block-based timing structure.

44. The method according to any one of claims 41 to 43, characterized in that The second security frame includes a PN field carrying the second PN.

45. The method according to any one of claims 41 to 44, characterized in that The second security frame includes a second security indicator to indicate that the second security frame is secure.

46. ​​The method according to any one of claims 41 to 45, characterized in that The second security frame comprises a security payload, wherein deprotecting the second security frame comprises deprotecting the security payload according to the second random number, and wherein the security payload comprises: The second block index existence indicator indicates whether the second block index is included. The second round index existence indicator indicates whether the second round index is included. The second time slot index existence indicator indicates whether the second time slot index is included.

47. The method according to claim 46, characterized in that If the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; If the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; If the second slot index presence indicator indicates that the second slot index is included, the security payload includes the slot index.

48. The method according to claim 46, characterized in that Also includes: According to a determination that at least one of the second block index presence indicator, the second round index presence indicator, or the second time slot index presence indicator indicates that the corresponding index is not included, it is determined that the corresponding index is a default index.

49. A device, characterized in that include: a generating module, configured to generate a first security frame, the first security frame to be sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, and the block index is an index of the first block; A sending module is used to send the first security frame.

50. The device according to claim 49, characterized in that The identification information includes a time slot index, where the time slot index is an index of the time slot in which the first security frame is transmitted.

51. The device according to claim 50, characterized in that The first random number comprises a first field having a first number of bits, the first field carrying the time slot index.

52. The device according to claim 51, characterized in that The first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

53. The device according to claim 49, characterized in that The identification information includes a first packet number (packet number, PN), and wherein the first PN is the packet number of the first security frame.

54. The device according to claim 53, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the first PN.

55. The device according to claim 54, characterized in that The first number is a first predefined number.

56. The device according to any one of claims 49 to 55, characterized in that The first random number includes: a second field having a second number of bits carrying the round index; A third field having a third number of bits carries the block index.

57. The device according to claim 56, characterized in that The second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number.

58. The device according to claim 56 or 57, characterized in that The third number is a third predefined number.

59. The device according to any one of claims 56 to 58, characterized in that The sum of the first quantity, the second quantity and the third quantity is equal to a predefined total quantity.

60. The device according to any one of claims 49 to 59, characterized in that The first random number includes: A fourth field having a fourth number of bits carries a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

61. The device according to any one of claims 49 to 60, characterized in that The first random number includes a first block indicator, and the first block indicator indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

62. The device according to any one of claims 49 to 61, characterized in that The first security frame includes the block index and the round index.

63. The device according to claim 62, characterized in that The first security frame includes: A first block index existence indicator, indicating the existence of the first block index, The first round index existence indicator indicates the existence of the first round index.

64. The device according to any one of claims 49 to 63, characterized in that The first security frame includes a first security indicator to indicate that the first security frame is secure.

65. The device according to any one of claims 49 to 64, characterized in that: The generating module is further used to generate a second security frame to be sent, wherein the second security frame is protected by a second random number constructed according to a second PN, wherein the second PN is a packet number of the second security frame; The sending module is further configured to send the second security frame.

66. The device according to claim 65, characterized in that The second random number includes a field having a predefined number of octets, the field carrying the second PN.

67. The device according to claim 65 or 66, characterized in that The second random number includes a second block indicator indicating that the second security frame is transmitted outside the block-based timing structure or the super-block-based timing structure.

68. The device according to any one of claims 65 to 67, characterized in that The second security frame includes a PN field carrying the second PN.

69. The device according to any one of claims 65 to 68, characterized in that The second security frame includes a second security indicator to indicate that the second security frame is secure.

70. The device according to any one of claims 65 to 69, characterized in that The second security frame comprises a security payload, and wherein the security payload comprises: The second block index existence indicator indicates whether the second block index is included. The second round index existence indicator indicates whether the second round index is included. The second time slot index existence indicator indicates whether the second time slot index is included.

71. The device according to claim 70, characterized in that If the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; If the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; If the second slot index presence indicator indicates that the second slot index is included, the security payload includes the slot index.

72. The device according to claim 70, characterized in that At least one of the second block index presence indicator, the second round index presence indicator, or the second slot index presence indicator indicates that a corresponding index is not included, and implicitly indicates that the corresponding index is a default index.

73. A device, characterized in that include: A receiving module, configured to receive a first security frame, wherein the first security frame is sent in a time slot in a first round belonging to a first block according to a block-based time structure or a super-block-based time structure, wherein the block-based time structure or the super-block-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, and each of the plurality of rounds includes a plurality of time slots; A deprotection module is used to deprotect the first security frame according to a first random number, wherein the first random number is constructed according to identification information, a round index and a block index associated with the first security frame, wherein the round index is an index of the first round, and the block index is an index of the first block.

74. The device according to claim 73, characterized in that The identification information includes a time slot index, where the time slot index is an index of the time slot in which the first security frame is transmitted.

75. The device according to claim 74, characterized in that The first random number comprises a first field having a first number of bits, the first field carrying the time slot index.

76. The device according to claim 75, characterized in that The first number is determined according to the number of the plurality of time slots in each round, or the first number is a first predefined number.

77. The device according to claim 73, characterized in that The identification information includes a first packet number (packet number, PN), and wherein the first PN is the packet number of the first security frame.

78. The device according to claim 77, characterized in that The first random number includes a first field having a first number of bits, the first field carrying the first PN.

79. The device according to claim 78, characterized in that The first number is a first predefined number.

80. The device according to any one of claims 73 to 79, characterized in that The first random number includes: a second field having a second number of bits carrying the round index; A third field having a third number of bits carries the block index.

81. The device according to claim 80, characterized in that The second number is determined according to the number of the plurality of rounds in each block, or the second number is a second predefined number.

82. The device according to claim 80 or 81, characterized in that The third number is a third predefined number.

83. The device according to any one of claims 80 to 82, characterized in that The sum of the first quantity, the second quantity and the third quantity is equal to a predefined total quantity.

84. The device according to any one of claims 73 to 83, characterized in that The first random number includes: A fourth field having a fourth number of bits carries a period index, the period index being an index of a period including a plurality of blocks, wherein the first block is among the plurality of blocks.

85. The device according to any one of claims 73 to 84, characterized in that The first random number includes a first block indicator, and the first block indicator indicates that the first security frame is transmitted according to the block-based timing structure or the super-block-based timing structure.

86. The device according to any one of claims 73 to 85, characterized in that The first security frame includes the block index and carries the round index.

87. The device according to claim 86, characterized in that The first security frame includes: A first block index existence indicator, indicating the existence of the first block index, The first round index existence indicator indicates the existence of the first round index.

88. The device according to any one of claims 73 to 87, characterized in that The first security frame includes a first security indicator to indicate that the first security frame is secure.

89. The device according to any one of claims 73 to 88, characterized in that: The receiving module is further configured to receive a second safety frame, wherein the second safety frame is not sent according to the block-based time structure or the super-block-based time structure; The deprotection module is further used to deprotect the second security frame according to a second random number, where the second random number is constructed according to a second PN, wherein the second PN is a packet number of the second security frame.

90. The device according to claim 89, characterized in that The second random number includes a field having a predefined number of octets, the field carrying the second PN.

91. The device according to claim 89 or 90, characterized in that The second random number includes a second block indicator indicating that the second frame is transmitted outside the block-based timing structure or the super-block-based timing structure.

92. The device according to any one of claims 89 to 91, characterized in that The second security frame includes a PN field carrying the second PN.

93. The device according to any one of claims 89 to 92, characterized in that The second security frame includes a second security indicator to indicate that the second security frame is secure.

94. The device according to any one of claims 89 to 93, characterized in that The second security frame comprises a security payload, wherein deprotecting the second security frame comprises deprotecting the security payload according to the second random number, and wherein the security payload comprises: The second block index existence indicator indicates whether the second block index is included. The second round index existence indicator indicates whether the second round index is included. The second time slot index existence indicator indicates whether the second time slot index is included.

95. The device according to claim 94, characterized in that If the second block index presence indicator indicates that the second block index is included, the security payload includes the block index; If the second round index presence indicator indicates that the second round index is included, the security payload includes the round index; If the second slot index presence indicator indicates that the second slot index is included, the security payload includes the slot index.

96. The device according to claim 94, characterized in that The deprotection module is used for: According to a determination that at least one of the second block index presence indicator, the second round index presence indicator, or the second slot index presence indicator indicates that the corresponding index is not included, it is determined that the corresponding index is a default index.

97. A communication device, characterized in that: include: A processor, configured to perform, together with a transceiver, a method according to any one of claims 1 to 24 or 25 to 48.

98. A communication system, characterized in that: include: An apparatus according to any one of claims 49 to 72; An apparatus as claimed in any one of claims 73 to 96.

99. A computer readable medium, characterized in that The computer-readable medium stores instructions, which, when executed by a processor of a device, cause the device to perform a method according to any one of claims 1 to 24 or 25 to 48.

100. A computer instruction product, characterized in that: The computer instruction product stores computer executable instructions, and when the computer executable instructions are executed by a processor of a device, the device is caused to perform a method according to any one of claims 1 to 24 or 25 to 48.

Citation Information

Cited By

  • Method, equipment and device for communication and computer readable storage medium

    CN120499644A

  • Methods, devices, apparatuses, and computer-readable storage media for communication

    CN120499644B