Communication apparatus, control method, and storage medium
By generating and transmitting management frames containing specific RSNEs in the communication device, the interconnection reduction problem caused by inappropriate PMF settings when switching from 6GHz to other frequency bands is solved, and the effect of improving interconnection of communication devices is achieved.
Patent Information
- Application Number
- CN202510227359.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2020-03-17
- Filing Date
- 2021-02-24
- Publication Date
- 2025-05-13
AI Technical Summary
When switching the frequency band from the 6GHz band to other frequency bands, the PMF settings in the prior art are inappropriate, resulting in a decrease in interconnectivity between communication devices.
A communication device is designed, including a build unit, a generator unit and a transmission unit. When the frequency band is switched to a frequency band other than 6 GHz, the generation unit generates a robust secure network element (RSNE) containing a set value "1" in the MFPC field and a set value "0" in the MFPR field to improve interconnectivity by transmission management frames.
By transmitting management frames and properly setting the encrypted information, interconnectivity between communication devices in the case of frequency band switching is improved.
Smart Images

Figure CN119996145A_ABST
Abstract
Description
[0001] This application is a divisional application of an invention patent application with an application date of February 24, 2021, an application number of 202180019348.3 (international application number PCT / JP2021 / 006723), and an invention name of “Communication equipment, control method and storage medium”. Technical Field
[0002] The invention relates to frame protection by communication equipment. Background Art
[0003] In wireless communication conforming to the Institute of Electrical and Electronics Engineers (IEEE) 802.11 series standards, a technology called Protected Management Frame (PMF) is known in which management frames are encrypted and transmitted. The IEEE 802.1 series standards are wireless communication standards discussed in the IEEE and include at least one of the IEEE802.11a / b / g / n / ac / ax / be standards. In the case of using the 2.4 GHz band and the 5 GHz band as frequency bands, the use of PMF is optional.
[0004] exist The Alliance developed the IEEE 802.11ax standard as a certification program for compliant In the 2010 Mobile Communications Conference, in addition to the 2.4 GHz band and the 5 GHz band that have been used so far, the use of the 6 GHz band as a frequency band is discussed. Communication in the 6 GHz band that requires PMF is also discussed.
[0005] PTL-1 discusses a technique for performing security settings when establishing wireless communications.
[0006] Reference List
[0007] Patent Literature
[0008] PTL1: Japanese Patent Application Laid-Open No. 2012-089926 Summary of the invention
[0009] Technical issues
[0010] In the 2.4 GHz band and the 5 GHz band, the use of PMF is optional. Therefore, if the frequency band to be used is switched from the 2.4 GHz band to the 5 GHz band, or from the 5 GHz band to the 2.4 GHz band, there is no need to change the PMF setting. However, in the case of switching the frequency band to be used from the 6 GHz band that requires PMF to other bands, it is necessary to properly perform the PMF setting to establish a connection with other communication devices that do not use PMF. This may result in reduced interconnectivity.
[0011] In view of the above description, the present invention is intended to improve interconnectivity between communication devices when switching the frequency band from the 6 GHz band to other frequency bands.
[0012] Problem Solution
[0013] In order to achieve the above-mentioned objectives, the communication device according to the present invention includes: an establishment unit, which is used to establish a wireless network in a predetermined frequency band; a generation unit, which is used to generate a management frame that complies with the IEEE802.11 series standards and includes a robust security network element (RSNE) with a value of "1" in the MFPC field and a value of "0" in the MFPR field when switching the frequency band of the wireless network established by the establishment unit from the 6 GHz band to other frequency bands; and a transmission unit, which is used to transmit the management frame generated by the generation unit.
[0014] Beneficial effects of the invention
[0015] According to the present invention, in the case of switching the frequency band from the 6 GHz band to other frequency bands, interconnectivity can be improved by transmitting a management frame in which information related to encryption of the management frame is appropriately set. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] Figure 1 The configuration of the network to which the communication device 102 belongs is illustrated.
[0017] Figure 2 is a diagram illustrating the hardware configuration of the communication device 102 .
[0018] Figure 3 is a flowchart illustrating processing performed when the frequency band to be used by the communication device 102 is switched.
[0019] Figure 4 1 is a sequence diagram illustrating an example of processing performed when the frequency band to be used by the communication device 102 is switched from the 6 GHz band to the 2.4 GHz band or the 5 GHz band.
[0020] Figure 5 Illustration of the frame format of a robust security network element.
[0021] Figure 6 The frame format of the Robust Security Network Capability field is illustrated.
[0022] Figure 7 FIG. 2 is a diagram showing a connection correspondence table regarding protected management frames. DETAILED DESCRIPTION
[0023] Exemplary embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Note that the components described in the following exemplary embodiments are only examples, and the present invention is not limited to the components shown in the drawings.
[0024] Figure 1 The configuration of a network in which a communication device 102 according to an exemplary embodiment participates is illustrated. The communication device 102 is an access point (AP) having a function of establishing a network 101. The network 101 is a wireless network. The communication device 103 is a station (STA) having a function of participating in the network 101. Each communication device complies with the Institute of Electrical and Electronics Engineers (IEEE) 802.11ax standard and can perform wireless communication that complies with the IEEE 802.11ax standard via the network 101. Each communication device can establish communication in a frequency band of a 2.4 GHz band, a 5 GHz band, and a 6 GHz band. The frequency bands to be used by each communication device are not limited to these frequency bands. For example, any other frequency band, such as a 60 GHz band, may also be used.
[0025] This exemplary embodiment illustrates an example in which communication devices 102 and 103 establish wireless communication in accordance with the IEEE 802.11ax standard. However, this exemplary embodiment is not limited to this standard. Communication devices 102 and 103 can establish wireless communication in accordance with the IEEE 802.11be standard, which is a standard following the IEEE 802.11ax standard. In the IEEE 802.11be standard, as in the IEEE 802.11ax standard, communication can be established in the 2.4 GHz band, the 5 GHz band, and the 6 GHz band.
[0026] Although the communication devices 102 and 103 comply with the IEEE 802.11ax standard, the communication devices 102 and 103 may comply with at least one of the legacy standards that are standards prior to the IEEE 802.11ax standard. The legacy standards are the IEEE 802.11a / b / g / n / ac standards. Each communication device may also comply not only with the legacy standards but also with the standards that succeed the IEEE 802.11ax standard. The standard that succeeds the IEEE 802.11ax standard is the IEEE 802.11be standard. Another option is that each communication device may comply with the standards that succeed the IEEE 802.11be and subsequent standards. In this exemplary embodiment, at least one of the IEEE 802.11a / b / g / n / ac / ax / be standards is referred to as the IEEE 802.11 series of standards. The communication devices 102 and 103 may comply not only with the IEEE 802.11 series of standards but also with other communication standards, such as Near Field Communication (NFC), Ultra Wideband (UWB), Zigbee, and Multi-Band Orthogonal Frequency Division Multiplexing (OFDM) Alliance (MBOA). Examples of UWB include wireless Universal Serial Bus (USB), wireless 1394, and WiNET. Each communication device may also be compatible with a communication standard for wired communication such as a wired local area network (LAN).
[0027] The communication device 102 supports protected management frames (PMF). PMF is a function for establishing communication by encrypting management frames using a pairwise transient key (PTK). Specific examples of management frames to be encrypted include deauthentication frames, disassociation frames, and action frames. Each of these management frames is called a robust management frame. PTK is key information for unicast communication.
[0028] The communication device 102 performs PMF to encrypt the robust management frame, thereby preventing disconnection due to, for example, a disassociation transmitted from other communication devices by spoofing.
[0029] The communication device 102 transmits a management frame including information indicating the PMF mode set in the communication device 102, thereby enabling notification related to the PMF mode set in the communication device 102 to be provided to other communication devices. Specific examples of the management frame including information indicating the PMF mode include a beacon frame, a probe response frame, and an association response frame. Figure 5 and Figure 6 A frame format for the communication device 102 to provide information indicating the PMF mode is described.
[0030] The communication device 102 can set three modes as PMF modes. The first mode is PMF mandatory mode (PMFRequired mode), which is used to establish a connection only with a communication device that can perform PMF. The second mode is PMF enabled mode (PMF Enabled mode), which is used to establish a connection with two types of communication devices (i.e., a communication device that can perform PMF and a communication device that cannot perform PMF). The third mode is PMF disabled mode (PMF Disabled mode), in which the PMF function of the communication device 102 is disabled. Examples of communication devices that cannot perform PMF may include communication devices that do not support PMF and communication devices that support PMF but have a configuration that disables the PMF function.
[0031] Figure 7The diagram shows a correspondence table indicating the PMF mode and information indicating whether a connection can be established. An AP with PMF disable set cannot connect to a STA with PMF enforced set, and PMF enforced means that PMF is required. An AP with PMF enable set can connect to any one of a STA with PMF disable set, a STA with PMF enable set, and a STA with PMF enforced set. In the case where an AP with PMF enable set is connected to a STA with PMF enforced set, robust management frames are encrypted and communicated. On the contrary, in the case where an AP with PMF enable set is connected to a STA with PMF disable set, robust management frames are not encrypted. An AP with PMF enforced support set cannot connect to a STA with PMF disable set.
[0032] like Figure 7 As shown in , the STAs that can connect to the AP vary depending on the PMF mode set in the AP.
[0033] In the IEEE 802.11 series of standards, when the AP and the STA establish communication in the 2.4 GHz band or the 5 GHz band, PMF may or may not be performed. Therefore, even if the frequency band to be used is switched from the 2.4 GHz band to the 5 GHz band, or from the 5 GHz band to the 2.4 GHz band when the communication device 102 establishes the network 101, there is no need to change the PMF setting. In contrast, in the case of establishing communication in the 6 GHz band, the AP and the STA need to perform PMF. Therefore, in the case of switching the frequency band to be used to the 6 GHz band when the communication device 102 with the PMF setting disabled establishes the network 101, the communication device 102 cannot establish communication with other communication devices unless the PMF setting of PMF mandatory is performed. In the case of switching the frequency band to be used by the communication device 102 with the PMF setting enabled to the 6 GHz band, the communication device 102 can connect with other communication devices with PMF disabled set unless the PMF setting is changed to PMF mandatory. In the case where the frequency band to be used by the communication device 102 is switched from the 6 GHz band to the 2.4 GHz band or the 5 GHz band, unless the PMF setting is enabled, the communication device 102 cannot be connected to other communication devices for which PMF disable is set. Therefore, this may result in reduced connectivity. As described above, in the case where the frequency band to be used by the communication device 102 is switched between the 6 GHz band and the 2.4 GHz band or the 5 GHz band, an inappropriate PMF setting may cause inconvenience to the user.
[0034] To establish a wireless network, the communication device 102 needs to set the authentication method to be used. Specific examples of authentication methods include open, WPA-protected access (WPA), WPA2, and WPA3. Open is an authentication method defined as an open system authentication in the IEEE 802.11 series of standards. In this authentication method, the AP that receives an authentication request from the STA must transmit an authentication success message. In this authentication method, authentication will never fail, so no substantial authentication processing is performed. WPA is a The standard for authentication methods established by the Alliance. WPA2 is the standard that succeeded WPA and supports new encryption methods that are not supported in WPA, and has improved security compared to WPA. WPA3 is the standard that succeeded WPA2. In WPA3, security is further improved.
[0035] In compliance with the IEEE 802.11ax standard certification program , a configuration that requires WPA3 as an authentication method for communication in the 6 GHz band is discussed. In the 2.4 GHz band and the 5 GHz band, any authentication method can be used. In the case of switching the frequency band to be used, the communication device 102 needs to appropriately set the authentication method as well as the PMF. For example, when the frequency band to be used by the communication device 102 is switched from the 6 GHz band to the 2.4 GHz band or the 5 GHz band, if only WPA3 continues to be used as the authentication method, a connection with a STA that only supports WPA2 cannot be established, which may cause inconvenience to the user.
[0036] Specific examples of the communication device 102 include a wireless LAN router and a personal computer (PC). However, the communication device 102 is not limited to these examples. Any communication device can be used as the communication device 102 as long as the communication device can perform wireless communication in accordance with the IEEE 802.11ax standard with other communication devices. Specific examples of the communication device 103 include a camera, a tablet computer, a smartphone, a PC, a mobile phone, and a video camera. However, the communication device 103 is not limited to these examples. Any communication device can be used as the communication device 103 as long as the communication device can perform wireless communication in accordance with the IEEE 802.11ax standard with other communication devices. Figure 1 The network shown in FIG. 1 is a network composed of one AP and one STA. However, the number of APs and the number of STAs are not limited to one.
[0037] Figure 2 The hardware configuration of the communication device 102 according to the present exemplary embodiment is illustrated. The communication device 102 includes a storage unit 201 , a control unit 202 , a function unit 203 , an input unit 204 , an output unit 205 , a communication unit 206 , and an antenna 207 .
[0038] The storage unit 201 is composed of one or more memories such as a read-only memory (ROM), a random access memory (RAM), and stores programs for performing various operations described below and various information such as communication parameters for wireless communication. Not only memories such as ROM and RAM can be used as the storage unit 201, but also storage media such as a floppy disk, a hard disk, an optical disk, a magneto-optical disk, a compact disk (CD)-ROM, a recordable CD (R), a magnetic tape, a nonvolatile memory card, and a digital versatile disk (DVD) can be used as the storage unit 201. The storage unit 201 may include a plurality of memories.
[0039] The control unit 202 is composed of one or more processors such as a central processing unit (CPU) or a microprocessing unit (MPU), and executes the program stored in the storage unit 201 to control the entire communication device 102. The control unit 202 can cooperate with the computer program and operating system (OS) stored in the storage unit 201 to control the entire communication device 102. The control unit 202 also generates data and signals (radio frames) transmitted in communication with other communication devices. The control unit 202 may include multiple processors (such as a multi-core processor), and the entire communication device 102 may be controlled by multiple processors.
[0040] The control unit 202 controls the function unit 203 to perform predetermined processing. The function unit 203 is hardware for the communication device 102 to perform predetermined processing. The data to be processed by the function unit 203 may be data stored in the storage unit 201 or data to be communicated with other communication devices via the communication unit 206 described below.
[0041] The input unit 204 receives various operations from the user. The output unit 205 performs various output operations on the user through the monitoring screen or the speaker. The output unit 205 can be operated as a display unit for displaying a screen or as a notification unit for providing various notifications to the user. In this case, output examples from the output unit 205 may include display on the monitoring screen, audio output through the speaker, and vibration output. The input unit 204 and the output unit 205 can be implemented as a module, such as a touch panel. The input unit 204 and the output unit 205 can be integrated with the communication device 102 or separated from the communication device 102. The input unit 204 and the output unit 205 can be devices connected to the communication device 102 via a wireless connection or a wired connection. Another option is that the output unit 205 can operate as a display control unit that causes the display unit of other communication devices that communicate with the communication device 102 via wireless communication or wired communication to perform screen display. Another option is that the output unit 205 can operate as an output control unit that, in addition to or in place of the screen display, causes the output unit (such as a speaker) of other communication devices to perform audio output. The input unit 204 can receive information input by a user through other communication devices that communicate with the communication device 102 via wireless communication or wired communication.
[0042] The communication unit 206 controls wireless communication that complies with the IEEE 802.11ax standard. The communication unit 206 can also control wireless communication that complies not only with the IEEE 802.11ax standard but also with other IEEE 802.11 series standards, and can control wired communication via a wired LAN or the like. The communication unit 206 controls the antenna 207 to transmit and receive signals generated by the control unit 202 for wireless communication. If the communication device 102 complies not only with the IEEE 802.11ax standard but also with the NFC standard, If the communication device 102 can perform wireless communication conforming to a plurality of communication standards, a communication unit and an antenna conforming to the plurality of communication standards can be provided separately. The communication device 102 communicates data such as image data, document data, and video data with the communication device 103 via the communication unit 206. The antenna 207 can be provided separately from the communication unit 206, or can be integrated into one module with the communication unit 206.
[0043] Antenna 207 is an antenna capable of establishing communication in the 2.4 GHz band, the 5 GHz band, and the 6 GHz band. In the present exemplary embodiment, communication device 102 includes one antenna, but may alternatively include a different antenna for each frequency band. If communication device 102 includes multiple antennas, communication device 102 may include a communication unit 206 corresponding to each antenna.
[0044] The communication device 103 has a hardware configuration similar to that of the communication device 102 .
[0045] Figure 3 1 is a flowchart illustrating processing performed when the communication device 102 reads out a computer program stored in the storage unit 201 into the control unit 202 and executes the computer program in a case where the frequency band to be used is switched.
[0046] When the frequency band already used is set, the communication device 102 starts the processing in the flowchart based on the instruction to switch the frequency band to be used issued from the user. The user can directly issue the instruction using the input unit 204 of the communication device 102. Another option is that the user can issue an instruction to other devices connected to the communication device 102 wirelessly or by wire. Other devices connected to the communication device 102 wirelessly or by wire can issue an instruction to display the setting screen by inputting the Internet Protocol (IP) address of the communication device 102 into the address bar on the browser. Another option is that the communication device 102 can start the processing in the flowchart based on the frequency band switching instruction from the application running on the communication device 102. Another option is that the communication device 102 can start the processing in the flowchart based on the change of the operation mode of the communication device 102. Another option is that the communication device 102 can start the processing in the flowchart based on the startup of a predetermined application.
[0047] The communication device 102 obtains parameters for establishing a wireless network in the frequency band to be switched (step S301). Specifically, the parameters obtained in this step are at least one of a service set identifier (SSID), an authentication method, an encryption method, key information (e.g., a pairwise master key (PMK), a PTK, and a passphrase), information related to PMF settings, and information related to the frequency band. SSID represents an identifier for identifying an AP (communication device 102). The encryption method is a method for encrypting communications between an AP (communication device 102) and an STA. PMK represents a master key on which various keys used in WPA are based. PTK is generated based on PMK. The passphrase is information for encrypting communications between an AP (communication device 102) and an STA. Only an STA that knows the passphrase set in the AP can communicate with the AP. The information related to the PMF setting is information indicating which of PMF enforcement, PMF disabling, and PMF enabling is set in the communication device 102. The information about the frequency band is information indicating which of the 2.4 GHz band, the 5 GHz band, and the 6 GHz band is set as the frequency band for establishing a wireless network by the communication device 102. In this step, the communication device 102 acquires at least information about the frequency band to be switched.
[0048] When the parameters of the wireless network to be switched are input from the user, the communication device 102 acquires the parameters. Alternatively, the communication device 102 may acquire the parameters from the storage unit 201 in the communication device 102. Alternatively, the communication device 102 may acquire the parameters from other devices via wired communication or wireless communication.
[0049] Next, the communication device 102 determines whether the 6 GHz band is currently used as the frequency band (step S302). If the 6 GHz band is not currently used as the frequency band, or if the 2.4 GHz band or the 5 GHz band is currently used, the communication device 102 determines "No" in this step, and then performs the process of step S312. On the contrary, if the 6 GHz band is currently used as the frequency band, the communication device 102 determines "Yes" in this step, and then performs the process of step S303.
[0050] The communication device 102 determines whether to switch the frequency band to the 6 GHz band (step S303). If the 6 GHz band is set as the frequency band in the parameters for the network to be switched acquired in step S301, the communication device 102 determines "yes" in this step, and then performs the processing of step S304. On the contrary, if the 2.4 GHz band or the 5 GHz band is set as the frequency band in the parameters for the network to be switched acquired in step S301, the communication device 102 determines "no" in this step, and then performs the processing of step S317.
[0051] If the 6 GHz band is set as the frequency band to be switched and the frequency band currently used, the communication device 102 maintains the PMF setting unchanged (step S304). Since the 6 GHz band is set as the frequency band to be switched and the frequency band currently used, the communication device 102 maintains the setting of PMF forced. In this case, the communication device 102 transmits the beacon, the probe response, and the association response together with the information indicating the PMF forced. The communication device 102 may use Figure 5 and Figure 6 The frame format shown in is used to provide notification related to PMF information.
[0052] Figure 5 The frame format of the Robust Security Network Element (RSNE) is illustrated. The RSNE is information included in a medium access control (MAC) frame body of at least one of a beacon, a probe response, and an association response transmitted by the communication device 102.
[0053] The RSNE includes fields for element ID, length, version, group data cipher suite, and number of paired cipher suites. The RSNE also includes fields for paired cipher suite list, number of AKM suites, AKM suite list, RSN performance, and number of PMKIDs. The RSNE also includes fields for PMKID list and group management cipher suites. The communication device 102 transmits the fields included in the RSNE in the order from element ID to the last group management cipher suite. At least one of the fields of the RSNE may be omitted, or the order of certain fields to be transmitted may be changed.
[0054] The element ID represents an identifier for identifying an information element. In the present exemplary embodiment, the element ID includes identification information indicating the RSNE.
[0055] The length is a field indicating the length of the element data. In the present exemplary embodiment, the length includes information indicating the data length of the RSNE.
[0056] The version is a field indicating version information related to the Robust Safety Network (RSN) protocol. In the present exemplary embodiment, the version includes information indicating version 1.
[0057] The group data cipher suite is a field including a cipher selector used for the wireless network to protect the group address frame. The cipher selector is represented by a combination of an organizational unique identifier (OUI) indicating the cipher and type information (suite type). For example, when TKIP is used as the cipher, the cipher selector is represented by a combination of OUI=00-0F-AC and type=2.
[0058] The number of pairwise cipher suites is a field indicating the number of pairwise cipher suite selectors included in a pairwise cipher suite list to be described below.
[0059] A pairwise cipher suite list is a field that includes one or more pairwise cipher suite selectors.
[0060] The AKM kit number is a field indicating the number of AKM kit selectors included in an AKM kit list to be described below.
[0061] The AKM suite list is a field including one or more AKM suite selectors. Each AKM suite selector represents a combination of OUI and type information indicating an AKM suite. An AKM suite is represented by a combination of an authentication method, a key management type, and a key derivation type.
[0062] Reference will be made to the following description Figure 6 The RSN performance includes information indicating the PMF setting of the communication device 102.
[0063] The PMKID number is a field including information indicating the number of PMKIDs included in a PMKID list described below.
[0064] The PMKID list is a field including information indicating one or more PMKIDs which are maintained as valid information between the communication device that has transmitted the RSNE and the destination communication device. The PMKID represents an identifier for identifying a PMK.
[0065] The Group Management Cipher Suite is a field that includes a cipher selector used for wireless networks to protect robust management frames that include group addresses.
[0066] Figure 6 The frame format of the CSN performance is illustrated.
[0067] The RSN performance includes fields for pre-authentication, unpaired, PTKSA replay counter, and GTKSA replay counter. The RSN performance also includes fields for management frame protection mandatory support (MFPR, Management Frame Protection Required) and management frame protection can support (MFPC, Management Frame Protection Capable). The RSN performance also includes fields for joint multi-band RSNA, peer key enablement (PeerKey Enabled), SPP A-MSDU can support (SPP A-MSDUCapable) and SPP A-MSDU mandatory support (SPP A-MSDU Required). The RSN performance also includes fields for PBAC and extended key ID (EKIIAF) for individually addressed frames. The communication device 102 transmits the fields included in the RSN performance in the order from pre-authentication to EKIIAF. At least one of the fields of the RSN performance can be omitted, and the order of certain fields to be transmitted can be changed.
[0068] Pre-Authentication is a field indicating whether the device that has transmitted RSNE supports the pre-authentication function. Using pre-authentication enables the STA to perform RSNA authentication with the AP before performing (re)association.
[0069] No Pairing is a field indicating whether a Wired Equivalent Privacy (WEP) default key '0' as well as a pairing key is supported.
[0070] The PTKSA replay counter is a field indicating a replay counter for each PTKSA. PTKSA stands for Pairwise Transient Key Security Association, and indicates a context generated according to the result of a four-way handshake. A value "0" included in the PTKSA replay counter indicates a replay counter "1" for each PTKSA. Similarly, a value "1" included in the PTKSA replay counter indicates a replay counter "2" for each PTKSA.
[0071] The GTKSA replay counter is a field indicating a replay counter for each GTKSA. GTKSA stands for Group Temporary Key Security Association, and indicates a context generated due to successful replacement of GTK in one of the group key handshake or four-way handshake. GTK stands for Group Temporary Key. Like the PTKSA replay counter, a value "0" included in the GTKSA replay counter indicates a replay counter "1" for each GTKSA.
[0072] MFPR is a field indicating whether the RSN capability transmission device (communication device 102) is required to protect the robust management frame. A value "1" included in the MFPR indicates that the RSN capability transmission device is required to protect the robust management frame. In other cases, the MFPR includes a value "0".
[0073] MFPC is a field indicating whether the RSN capability transmission device (communication device 102) can perform protection of robust management frames. If the RSN capability transmission device can perform protection of robust management frames, a value of "1" is included in MFPC. In other cases, a value of "0" is included in MFPC.
[0074] The RSN performance transmission device (communication device 102) can use a combination of values included in MFPR and MFPC to indicate the PMF setting of the communication device 102. Specifically, the combination of MFPR=1 and MFPC=1 indicates PMF forced. The combination of MFPR=0 and MFPC=0 indicates PMF disabled. The combination of MFPR=0 and MFPC=1 indicates PMF enabled. The combination of MFPR=1 and MFPC=0 is an incorrect combination.
[0075] Joint Multi-Band RSNA is a field indicating whether the RSN capability transmission device (communication device 102) supports Joint Multi-Band RSNA.
[0076] Peer Key Enabled is a field indicating whether the RSN capability transmission device (communication device 102) supports peer key handshake.
[0077] SPP A-MSDU can support providing notification indicating whether the RSN capability transmission device (communication device 102) supports signaling and protected payload A-MSDU. SPP stands for signaling and protected payload. A-MSDU stands for aggregated MAC service data unit.
[0078] SPP A-MSDU Mandatory Support is a field indicating whether the RSN capability transmission device (communication device 102) requires signaling and protected payload A-MSDU.
[0079] PBAC stands for Protected Block Ack Agreement Capable, and is a field indicating whether PBAC is set.
[0080] EKIIAF is a field indicating whether the RSN capability transmission device (communication device 102) supports values ranging from "0" to "1" as key IDs of PTKSA and STKSA. STKSA stands for Station Inter-Link (STSL) Transient Key Security Association.
[0081] like Figure 5and Figure 6 As shown in , the communication device 102 may use a specific field in the RSN capabilities included in the RSNE to indicate the PMF setting of the communication device 102 .
[0082] Refer again Figure 3 , at step S304, the communication device 102 maintains the PMF setting of the communication device 102 unchanged. In this case, maintaining PMF is mandatory as the PMF setting of the communication device 102. The communication device 102 continuously transmits a beacon including the following RSNE: the RSNE includes RSN performance indicating MFPR=1 and MFPC=1. In addition to or instead of the beacon, the communication device 102 may also continuously transmit a probe response or an association response including a similar RSNE.
[0083] Next, the communication device 102 determines to keep the authentication method unchanged (step S305). Since the 6 GHz band is set as the band to be switched and the currently used band, the communication device 102 maintains the setting of the authentication method. In this case, WPA3 is maintained as the authentication method used by the communication device 102. The communication device 102 continuously transmits a beacon including the following RSNE: the RSNE includes a selector indicating WPA3 in the AKM suite list (OUI=00-0F-AC, suite type=8). In addition to or instead of the beacon, the communication device 102 can also continuously transmit a probe response or an association response including a similar RSNE. The communication device 102 performs the processing of step S305 and then terminates the processing in this flowchart.
[0084] Therefore, when the 6 GHz band is set as the frequency band to be switched and the frequency band currently used, the communication device 102 does not need to change the settings of the PMF setting and the authentication method. Therefore, these settings are not changed.
[0085] When the determination result in step S303 indicates "No", the communication device 102 changes the PMF setting and the authentication method (step S317). Specifically, the communication device 102 changes the PMF setting from PMF forced to PMF enabled. In addition, the communication device 102 changes the setting of the authentication method from a setting that enables only WPA3 to a setting that enables at least one of WPA3 and WPA2 (WPA3 / WPA2). In this case, the communication device 102 starts transmitting a beacon including the following RSNE: the RSNE includes RSN performance indicating MFPR=0 and MFPC=1. In addition, the communication device 102 starts transmitting a beacon including the following RSNE: the RSNE includes a selector indicating WPA2 in the AKM suite list (OUI=00-0F-AC, suite type=2) and a selector indicating WPA3. In addition to or instead of a beacon, the communication device 102 may also start transmitting a probe response or an association response including a similar RSNE.
[0086] When the frequency band to be used is switched from the 6 GHz band to other frequency bands (2.4 GHz band or 5 GHz band), the communication device 102 changes the PMF setting to PMF enabled, thereby improving interconnectivity. In other words, the communication device 102 changes the settings used by other communication devices that cannot be connected with PMF disabled, thereby enabling connection to be established with other communication devices that have PMF disabled. This improves interconnectivity. When the frequency band to be used is switched from the 6 GHz band to other frequency bands (2.4 GHz band or 5 GHz band), the communication device 102 changes the settings of the authentication method to settings for enabling both WPA3 and WPA2. This improves interconnectivity. In other words, the communication device 102 changes the settings used by other communication devices that cannot be connected and only support WPA2, thereby enabling connection to be established with other communication devices that only support WPA2. This improves interconnectivity.
[0087] Next, the communication device 102 determines whether information indicating PMF enforcement is received from the paired device (step S306). Specifically, the communication device 102 determines whether the RSNE included in the association request received from the STA (communication device 103) includes RSN performance indicating PMF enforcement. If an association request including an RSNE indicating PMF enforcement is received, the communication device 102 determines "yes" in this step and then performs the processing of step S307. On the contrary, if an association request including an RSNE indicating PMF enablement or PMF disablement is received, the communication device 102 determines "no" in this step and then performs the processing of step S308.
[0088] The communication device 102 changes the PMF setting of the communication device 102 to PMF force (step S307). Therefore, even in the case where the communication device 102 switches the frequency band to the 2.4 GHz band or the 5 GHz band, if the STA can perform PMF, security can be improved.
[0089] In contrast, if the determination result in step S306 indicates "No", the communication device 102 keeps the PMF setting of the communication device 102 unchanged (step S308). In this case, the communication device 102 maintains PMF enabled as the PMF setting of the communication device 102.
[0090] Next, the communication device 102 determines whether the authentication method of WPA3 is received from the paired device (step S309). Specifically, the communication device 102 determines whether the RSNE included in the association request received from the STA (communication device 103) includes RSN performance including information indicating WPA3. If an association request including information indicating WPA3 is received, the communication device 102 determines "yes" in this step, and then performs the processing of step S310. On the contrary, if the association request does not include information indicating WPA3 or only includes information indicating WPA2, for example, the communication device 102 determines "no" in this step, and then performs the processing of step S311.
[0091] The communication device 102 changes the setting of the authentication method of the communication device 102 to a setting that enables only WPA3 (step S310). Therefore, even in the case where the communication device 102 switches the frequency band to the 2.4 GHz band or the 5 GHz band, if the STA can execute WPA3, security can be further improved. After executing the process of step S310, the communication device 102 terminates the process in this flowchart.
[0092] On the contrary, if the determination result in step S309 indicates "No", the communication device 102 keeps the setting of the authentication method of the communication device 102 unchanged (step S311). In this case, the communication device 102 maintains WPA3 / WPA2 as the setting of the authentication method of the communication device 102. After executing the processing of step S311, the communication device 102 terminates the processing in this flowchart.
[0093] The communication device 102 may skip the processing of steps S306 to S311.
[0094] Even when the communication device 102 uses WPA2 or WPA3 as the authentication method, the communication device 102 can still perform the PMF function. In the case of using WPA2 as the authentication method, the PTK derived using the secure hash algorithm SHA1 is used as the PTK for encrypting the robust management frame. In contrast, in the case of using WPA3 as the authentication method, the PTK is derived using the secure hash algorithm SHA256.
[0095] The present exemplary embodiment illustrates an example in which the communication device 102 changes the PMF setting and the setting of the authentication method based on switching the frequency band from the 6 GHz band to other frequency bands. However, the present exemplary embodiment is not limited to this example. For example, if the security priority mode is enabled in the communication device 102, the communication device 102 may keep the PMF setting unchanged even when the frequency band is switched from the 6 GHz band to other frequency bands. In this case, in addition to or instead of the PMF setting, the communication device 102 may keep the setting of the authentication method unchanged. If the security priority mode is enabled and the PMF setting remains unchanged, the communication device 102 may output a warning related to interconnectivity to the user using the output unit 205. In this case, if the security priority mode is disabled, the communication device 102 performs Figure 3 Processing of step S317.
[0096] Alternatively, when the frequency band is switched from the 6 GHz band to other frequency bands, the communication device 102 may determine whether to change the PMF setting and the authentication method setting of the communication device 102 based on the PMF setting and the authentication method setting of the STA as the paired device. In this case, if the communication device 102 determines "No" in step S303, the processing of step S317 is skipped. Instead of making a determination in step S306, it is determined whether PMF disable (MFPR = 0, MFPC = 0) is received from the paired device. If an association request including information indicating PMF disable is received from the communication device 103, the communication device 102 changes the PMF setting of the communication device 102 to PMF enable. On the contrary, if an association request including information indicating PMF force or PMF enable is received from the communication device 103, the communication device 102 maintains PMF force as the PMF setting of the communication device 102. Next, instead of making a determination in step S309, the communication device 102 determines whether information indicating WPA3 as the authentication method is received from the paired device. If an association request including information indicating WPA2 but not including information indicating WPA3 is received from the communication device 103, the communication device 102 changes the setting of the authentication method of the communication device 102 to WPA3 / WPA2. Conversely, if an association request including information indicating WPA3 is received from the communication device 103, the communication device 102 maintains the setting of WPA3 as the authentication method of the communication device 102. Therefore, even when the frequency band is switched, the communication device 102 changes the PMF setting and the like according to the setting in the paired device, thereby maintaining a high security setting if the setting is supported by the paired device.
[0097] Another option is that if the communication device 102 performs AP operation and STA operation in parallel at the same time, even when the frequency band of the network established in the AP is switched from the 6 GHz band to other frequency bands, there is no need to change the PMF setting. In addition to or instead of the PMF setting, there is no need to change the setting of the authentication method. In this case, the communication device 102 can use the output unit 205 to output a warning related to interconnectivity to the user.
[0098] If the determination result in step S302 indicates "No", the communication device 102 determines whether the 6 GHz band is set as the frequency band to be switched (step S312). The processing of this step is similar to step S303. If the determination result in this step indicates "Yes", the communication device 102 performs the processing of step S315. If the determination result in this step indicates "No", the communication device 102 performs the processing of step S313.
[0099] If the 6 GHz band is not set as the frequency band to be switched and the frequency band currently used, the communication device 102 keeps the PMF setting of the communication device 102 unchanged (step S313). Specifically, the communication device 102 maintains PMF enabled as the PMF setting of the communication device 102, and does not change the PMF setting. Therefore, the communication device 102 can maintain the interconnectivity of the communication device 102.
[0100] Next, the communication device 102 keeps the setting of the authentication method of the communication device 102 unchanged (step S314). Specifically, the communication device 102 maintains WPA3 / WPA2 as the setting of the authentication method of the communication device 102, and does not change the setting of the authentication method. Therefore, the communication device 102 can maintain the interconnectivity of the communication device 102. After executing the process of step S314, the communication device 102 terminates the process in this flowchart.
[0101] On the contrary, if the 6 GHz band is not set as the currently used band but the 6 GHz band is set as the band to be switched, the communication device 102 changes the PMF setting of the communication device 102 (step S315). Specifically, the communication device 102 changes the PMF setting of the communication device 102 from PMF enabled to PMF forced. This is because the PMF function needs to be performed in the 6 GHz band.
[0102] Next, the communication device 102 changes the setting of the authentication method of the communication device 102 (step S316). Specifically, the communication device 102 changes the setting of the authentication method of the communication device 102 from WPA3 / WPA2 to WPA3 only. This is because WPA3 needs to be used as the authentication method in the 6 GHz band. After executing the processing of step S316, the communication device 102 terminates the processing in this flowchart.
[0103] like Figure 3 As shown in , in the case where the frequency band to be used is switched from the 6 GHz band to the 2.4 GHz band or the 5 GHz band, the communication device 102 changes the PMF setting from PMF forced to PMF enabled, thereby improving interconnectivity. Similarly, the communication device 102 changes the setting of the authentication method from enabling the setting of executing only WPA3 to enabling the setting of executing both WPA3 and WPA2, thereby improving interconnectivity.
[0104] Figure 4 1 is a sequence diagram illustrating an example of processing to be performed when the communication device 102 switches the network from a network using the 6 GHz band to a network using the 2.4 GHz band or the 5 GHz band.
[0105] When switching the network from a network that has been established and uses the 6 GHz band to a network that uses the 2.4 GHz band or the 5 GHz band, the communication device 102 starts the processing in the sequence diagram.
[0106] The communication device 102 obtains the parameters of the network to be switched (step S401). Figure 3 In this case, the communication device 102 acquires information indicating that the 2.4 GHz band or the 5 GHz band is set as the frequency band of the network to be switched.
[0107] Since the 6 GHz band is set as the currently used band and the 2.4 GHz band or the 5 GHz band is set as the band to be switched, the communication device 102 changes the PMF setting and the authentication method setting of the communication device 102 (step S402). Figure 3 The communication device 102 changes the PMF setting from PMF forced to PMF enabled, and changes the authentication method from WPA3 only to WPA3 / WPA2.
[0108] Next, the communication device 102 transmits a management frame including setting information related to PMF and authentication method (step S403). Specifically, the communication device 102 transmits a beacon or a probe response including the following RSNE: the RSNE includes information indicating that PMF is mandatory (MFPR=1, MFPC=1). The RSNE transmitted in this case includes an AKM suite list, and the AKM suite list includes both a selector indicating WPA3 and a selector indicating WPA2. The communication device 102 uses the channel of the network to be switched in step S403 to transmit a management frame including setting information related to PMF and authentication method. After performing the processing of step S401, the communication device 102 establishes the network to be switched before performing the processing of step S403.
[0109] The communication device 102 receives an association request from the communication device 103 acting as an STA (step S404). In this case, the association request includes an RSNE including setting information about the PMF and authentication method of the communication device 103.
[0110] The communication device 102 changes the PMF setting and the authentication method setting of the communication device 102 based on the received setting information about the PMF and the authentication method of the communication device 103 (step S405). Figure 3 The communication device 102 may skip the processing of step S405.
[0111] The communication device 102 transmits an association response to the communication device 103 (step S406). The association response includes the following RSNE: The RSNE includes information indicating the PMF setting and the setting of the authentication method of the communication device 102. If at least one of the PMF setting and the setting of the authentication method of the communication device 102 is changed in step S405, the association response includes information indicating that the setting has been changed.
[0112] The communication devices 102 and 103 establish a wireless connection (step S407).
[0113] The communication devices 102 and 103 transmit a robust management frame based on the PMF setting (step S408). If the PMF setting of one of the communication devices 102 and 103 is PMF enabled and the PMF setting of the other of the communication devices 102 and 103 is PMF disabled, the robust management frame is transmitted without encryption. If the PMF setting of one of the communication devices 102 and 103 is PMF enabled and the PMF setting of the other of the communication devices 102 and 103 is PMF forced, the robust management frame is encrypted and transmitted.
[0114] As mentioned above, Figure 4 An example of processing to be performed when the communication device 102 switches the frequency band to be used from the 6 GHz band to the 2.4 GHz band or the 5 GHz band is illustrated. Figure 4 As shown in , the communication device 102 appropriately changes the PMF setting and the authentication method setting based on the switching of the frequency band, thereby improving the interconnectivity.
[0115] The present exemplary embodiment illustrates an example in which, in the case of switching the frequency band, the communication device 102 changes both the PMF setting and the setting of the authentication method. However, the present exemplary embodiment is not limited to this example. Only the PMF setting may be changed.
[0116] In the present exemplary embodiment, the communication device 102 establishes a new network and then transmits a management frame including setting information about the PMF and the authentication method set based on the frequency band of the network to be switched. In this case, the communication device 102 may generate a management frame including setting information about the PMF and the authentication method set based on the frequency band of the network to be switched after or before establishing the new network.
[0117] Figure 3 At least a portion or all of the flowchart of the communication device 102 shown in the figure can be implemented by hardware. In the case of implementing the flowchart by hardware, a special circuit can be generated on, for example, a field programmable gate array (FPGA) based on a computer program for implementing the steps using a predetermined compiler, and the generated special circuit can be used. Another option is that the gate array circuit can be formed and implemented as hardware, such as an FPGA. Another option is that the flowchart can be implemented by an application-specific integrated circuit (ASIC).
[0118] The present invention may also be implemented by a process in which a program for implementing one or more functions according to the exemplary embodiments described above is provided to a system or device via a network or storage medium, and one or more processors in a computer of the system or device read and execute the program. The present invention may also be implemented by a circuit (e.g., ASIC) for implementing one or more functions.
[0119] The present invention is not limited to the above exemplary embodiments, and various modifications and changes may be made without departing from the spirit and scope of the present invention. Therefore, the accompanying claims are intended to disclose the scope of the present invention.
[0120] This application claims priority from Japanese Patent Application No. 2020-046695 filed on March 17, 2020, the disclosure of which is incorporated herein by reference.
Claims
1. A communication device, comprising: an establishing unit, the establishing unit being used to establish a wireless network in a predetermined frequency band; a generating unit, the generating unit being configured to generate a management frame including the following robust security network element RSNE and complying with the IEEE802.11 series standard when the frequency band of the wireless network established by the establishing unit is switched from the 6 GHz frequency band to other frequency bands: the RSNE including a value of "1" in the MFPC field and a value of "0" in the MFPR field; as well as A transmission unit, wherein the transmission unit is used to transmit the management frame generated by the generation unit.
2. The communication device according to claim 1, wherein: In case the frequency band of the wireless network established by the establishment unit is switched from the other frequency bands to the 6 GHz frequency band, the generation unit generates a management frame including the following RSNE: the RSNE includes a value of "1" in the MFPC field and includes a value of "1" in the MFPR field.
3. The communication device according to claim 1, wherein: In case of switching the frequency band of the wireless network established by the establishment unit from the 6 GHz frequency band to the other frequency bands, the generation unit generates a management frame including the following RSNE: the RSNE includes a WPA2 selector in an Authentication and Key Management AKM suite list.
4. The communication device according to claim 3, wherein: In case that the frequency band of the wireless network established by the establishing unit is switched from the other frequency bands to the 6 GHz frequency band, the generating unit generates a management frame including the following RSNE: the RSNE including the WPA3 selector in the AKM suite list.
5. The communication device according to claim 1, further comprising a determining unit configured to determine whether other management frames including the following RSNEs are received from other communication devices: the RSNEs including a value of "0" in the MFPC field and a value of "0" in the MFPR field, in, In the case where the frequency band of the wireless network established by the establishment unit is switched from the 6 GHz frequency band to the other frequency bands, the generation unit generates the management frame including the following RSNE based on the determination unit determining that the other management frame is received: the RSNE includes a value of "1" in the MFPC field and a value of "0" in the MFPR field, and the generation unit generates the management frame including the following RSNE based on the determination unit determining that the other management frame is not received: the RSNE includes a value of "1" in the MFPC field and a value of "1" in the MFPR field.
6. The communication device according to claim 5, in, The determining unit further determines whether another management frame including the following RSNE is received: the RSNE including the WPA3 selector in the AKM suite list, and Wherein, in the case of switching the frequency band of the wireless network established by the establishment unit from the 6 GHz frequency band to the other frequency bands, the generation unit generates a management frame including the following RSNE based on the determination by the determination unit that the other management frame is received: the RSNE does not include a WPA2 selector but includes a WPA3 selector in the AKM suite list, and the generation unit generates a management frame including the following RSNE based on the determination by the determination unit that the other management frame is not received: the RSNE includes a WPA2 selector in the AKM suite list.
7. The communication device according to claim 5, wherein: The other management frame is an association request.
8. The communication device according to claim 1, wherein: In the case of transmitting a management frame including the RSNE including a value of '1' in the MFPC field and a value of '1' in the MFPR field to other communication devices, a robust management frame to be communicated with the other communication devices is encrypted.
9. The communication device according to claim 8, wherein: The robust management frame is at least one of a deauthentication frame, a disassociation frame, and an action frame.
10. The communication device according to claim 1, wherein: The management frame generated by the generating unit is at least one of a beacon frame, a probe response frame, and an association response frame.
11. The communication device according to claim 1, wherein: The other frequency band is one of a 2.4 GHz frequency band and a 5 GHz frequency band.
12. The communication device according to any one of claims 1 to 11, wherein: The transmission unit transmits the management frame generated by the generation unit in the frequency channel where the wireless network in the other frequency band is established.
13. A communication device, comprising: an acquisition unit, configured to acquire information indicating a frequency band to be used when the communication device provides a wireless network; as well as a transmission control unit configured to, in a case where the communication device provides a wireless network in a frequency band of the 6 GHz frequency band based on the information, perform control to transmit a management frame including a robust security network element RSNE including a value of "1" in the MFPR field in the frequency band of the 6 GHz frequency band; Wherein, in a case where the communication device provides a wireless network in a frequency band of 2.4 GHz band based on the information, the transmission control unit performs control to transmit a management frame including an RSNE including a value of '0' in an MFPR field in the frequency band of 2.4 GHz band.
14. The communication device according to claim 13, in, The acquiring unit acquires information indicating the frequency band from a memory of the communication device; and The communication device further includes a providing unit for providing a setting screen for accepting a user operation to change a frequency band to be used when the communication device provides a wireless network for a web browser of an external device.
15. The communication device according to claim 13, in, The acquiring unit acquires information indicating the frequency band from a memory of the communication device; and The communication device further includes a display unit for displaying a setting screen for accepting a user operation to change a frequency band to be used when the communication device provides a wireless network.
16. A method for controlling a communication device, the method comprising: Establishing a wireless network in a predetermined frequency band; In case that the frequency band of the wireless network established in the establishing step is switched from the 6 GHz band to other frequency bands, generating a management frame conforming to the IEEE 802.11 series standard including the following robust security network element RSNE: the RSNE includes a value of "1" in the MFPC field and a value of "0" in the MFPR field; and The generated management frame is transmitted.
17. A method for controlling a communication device, the method comprising: In the case where the communication device provides a wireless network, acquiring information indicating a frequency band to be used; Executive control, to transmit, in a case where the communication device provides a wireless network in a frequency band of the 6 GHz frequency band based on the information, a management frame including a robust security network element RSNE including a value of '1' in the MFPR field in the frequency band of the 6 GHz frequency band; In the case where the communication device provides a wireless network in a frequency band of 2.4 GHz band based on the information, a management frame including an RSNE including a value of '0' in the MFPR field in the frequency band of 2.4 GHz band is transmitted.
18. A non-volatile computer-readable storage medium storing a program for causing a computer to function as each unit of the communication device according to any one of claims 1 to 12.
Citation Information
Patent Citations
Radio communication device and peripheral device having the same
JP2012089926A
Arithmetic apparatus and medical information processing system
JP2020046695A