Encrypted aggregation frame receiving method and device, storage medium and WiFi equipment
By independently processing decryption and storage operations and performing storage predictions when receiving subframes, the processing performance bottleneck of WIFI devices when receiving aggregated encrypted frames is solved, and system performance and communication reliability are improved.
Patent Information
- Application Number
- CN202510375324.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-06-24
AI Technical Summary
WIFI devices face processing performance bottlenecks when receiving aggregated encrypted frames, especially in high data rate transmission scenarios, where the decryption process may become a key factor limiting system performance.
By independent of the decryption operation and the storage operation, it is not associated with the generation of BLOCKACK, and a storage prediction is made when receiving the subframe, ensuring that the subframe has sufficient storage space to receive.
It effectively avoids the bottleneck problem of completing all subframe processing within SIFS time, reduces the risk that decryption process becomes a key factor in limiting system performance, and improves the reliability and throughput of wireless LAN communication.
Smart Images

Figure CN120201419A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of wireless communication, and in particular, to a method, apparatus, storage medium, and WiFi device for receiving encrypted aggregated frames. Background Art
[0002] With the rapid development of wireless communication technology, WIFI (Wireless Fidelity) has become an indispensable part of modern life. It realizes wireless data transmission between devices according to the IEEE 802.11 series protocol standards. However, while pursuing higher data transmission rates and lower latency, WIFI devices face a series of technical challenges during the data processing process, especially when processing aggregated encrypted data frames.
[0003] See Figure 1 As shown, it is a timing diagram for receiving encrypted aggregated frames provided by the prior art. During the process of a WIFI device receiving aggregated CCMP (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol) encrypted data frames, the WIFI device needs to perform a series of operations on each sub-frame, including verification, decryption, and storage. The verification process involves verifying the legitimacy of the sub-frame and the compliance of the frame structure and content. The decryption process is used to decrypt the encrypted data frame into plaintext. The storage process stores the data into the lower-layer Media Access Control (LMAC) memory through a Direct Memory Access (DMA) channel.
[0004] According to the provisions of the 802.11 protocol, after the WIFI device finishes processing the last sub-frame, it needs to complete the response within a certain length of the inter-frame interval, that is, the WIFI device can only perform verification, decryption, and storage operations within the time interval of the duration of the current encrypted data frame + SIFS. This time limit poses strict requirements on the processing speed of the WIFI device, especially when processing aggregated frames containing multiple sub-frames. The aggregated frame technology aims to improve data transmission efficiency by transmitting multiple data sub-frames at once to reduce transmission overhead, but at the same time increases the complexity of processing for WIFI devices.
[0005] However, in practical applications, the WIFI device faces many challenges when processing these sub-frames. First, although the verification processing ability and DMA transmission ability of the hardware are usually much greater than the WIFI bandwidth and do not pose a bottleneck, the CCMP decryption ability is relatively weak, and its processing speed may only be slightly higher than or close to the WIFI bandwidth, which poses a potential bottleneck for completing the processing of all sub-frames within the SIFS time. Especially in high data rate transmission scenarios, the decryption process may become a key factor restricting system performance.
[0006] In addition, the physical layer (PHY) demodulation of WIFI devices processes data in units of symbols, while CCMP decryption processes data in units of 16 bytes (blocks) as the minimum unit. This mismatch in data processing methods results in non-uniform data transmission, but rather an intermittent burst characteristic. When the end time point of PHY demodulation happens to encounter a large amount of data bursts that require LMAC decryption, and LMAC decryption is waiting for the last few bytes to complete a decryption block, the superposition of such adverse situations may further extend the data processing time. Coupled with the demodulation delay of the PHY itself, it is very likely that the last or the last few sub-frames (especially short data frames) in the aggregated frame will fail to be received.
[0007] To address this challenge, the WIFI device may have to forcibly stop the receiving process before replying with a block acknowledgment (BLOCKACK), discard the incompletely received sub-frames, and feedback information about the receiving failure to the other device, which directly reduces the WIFI receiving throughput. Another solution is to increase the working frequency of CCMP decryption or add decryption cores, but this will come at the cost of increased power consumption and chip area. Summary of the Invention
[0008] Embodiments of the present application provide a method, apparatus, storage medium, and WiFi device for receiving encrypted aggregated frames, which can solve the problem of processing performance bottlenecks in the prior art when a WiFi device receives an aggregated encrypted frame. The technical solutions are as follows:
[0009] In a first aspect, embodiments of the present application provide a method for receiving an encrypted aggregated frame, the method including:
[0010] Determine the reception start time t0 of the current encrypted A-MPDU to be received; wherein, the current encrypted A-MPDU is composed of multiple sub-frames;
[0011] Starting from the reception start time t0 of the current encrypted A-MPDU, perform decryption and storage operations on each of the received sub-frames in the current encrypted A-MPDU in sequence until the reception start time t2 of the next encrypted A-MPDU to stop performing decryption and storage operations;
[0012] At the receiving start time t0, start receiving each sub-frame in the current encrypted aggregated data frame in sequence: Parse the delimiter of the current sub-frame to obtain the delimiter signature, CRC, and sub-frame length, and determine whether the delimiter signature and CRC are preset values. If so, determine whether the current remaining space in the LMAC memory is sufficient according to the sub-frame length; if so, reserve the storage space for the current sub-frame in the LMAC memory, and update the current remaining space of the LMAC memory according to the sub-frame length; perform FCS check, RA check, and frame legality check on the current sub-frame. If the check is successful, determine that the current sub-frame is successfully received; if the check fails, determine that the current sub-frame reception fails, stop the decryption and storage operations performed on the current sub-frame, and release the storage space reserved for the current sub-frame in the LMAC memory, and update the current remaining space of the LMAC memory; finally, update the SSN and bitmap information according to the reception status of the current sub-frame.
[0013] When the receiving end time of the current encrypted A-MPDU arrives, generate a BLOCKACK frame according to the current SSN and bitmap information, and return the BLOCKACK frame of the current encrypted A-MPDU to the sender after the duration of SIFS.
[0014] In a second aspect, an embodiment of the present application provides a receiving device for encrypted aggregated frames, and the device includes:
[0015] A determination unit, configured to determine the receiving start time t0 of the current encrypted A-MPDU to be received; wherein, the current encrypted A-MPDU is composed of multiple sub-frames;
[0016] A decryption and storage unit, configured to start decrypting and storing each sub-frame received in the current encrypted A-MPDU in sequence at the receiving start time t0 of the current encrypted A-MPDU, and stop performing the decryption and storage operations until the receiving start time t2 of the next encrypted A-MPDU.
[0017] The pre-judgment verification unit is used to sequentially receive each sub-frame in the current encrypted aggregation data frame starting from the reception start time t0: parse the delimiter of the current sub-frame to obtain the delimiter signature, CRC, and sub-frame length, and determine whether the delimiter signature and CRC are preset values. If so, determine whether the current remaining space in the LMAC memory is sufficient according to the sub-frame length; if so, reserve the storage space for the current sub-frame in the LMAC memory, and update the current remaining space of the LMAC memory according to the sub-frame length; perform FCS verification, RA verification, and frame legality verification on the current sub-frame. If the verification is successful, it is determined that the current sub-frame is successfully received; if the verification fails, it is determined that the current sub-frame reception fails, stop the decryption and storage operations performed on the current sub-frame, and release the storage space reserved for the current sub-frame in the LMAC memory, and update the current remaining space of the LMAC memory; finally, update the SSN and bitmap information according to the reception status of the current sub-frame.
[0018] The feedback unit is used to generate a BLOCKACK frame according to the current SSN and bitmap information when the reception end time of the current encrypted A-MPDU arrives, and return the BLOCKACK frame of the current encrypted A-MPDU to the sender after the duration of SIFS.
[0019] In a third aspect, an embodiment of the present application provides a computer storage medium, which stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the above method steps.
[0020] In a fourth aspect, an embodiment of the present application provides a WiFi device, which may include: a processor and a memory; wherein, the memory stores a computer program, and the computer program is suitable for being loaded and executed by the processor to perform the above method steps.
[0021] The beneficial effects brought by the technical solutions provided by some embodiments of the present application at least include:
[0022] The decryption operation and the storage operation are separated so that they are not associated with the generation of BLOCKACK. In this way, the decryption operation and the storage operation duration of the last few sub-frames in the aggregated encrypted frame are extended from the original SIFS to at least (SIFS + the duration of sending the BLOCKACK frame + SIFS), effectively avoiding the bottleneck problem that may occur when all sub-frames are processed within the SIFS time. Especially in high data rate transmission scenarios, the risk that the decryption process becomes a key factor restricting system performance is reduced.
[0023] By performing storage prediction, when receiving a subframe, first parse the delimiter of the current subframe to obtain the delimiter signature, CRC, and subframe length. Then, determine whether the delimiter signature and CRC are preset values, and further determine whether the current remaining space in the LMAC memory is sufficient according to the subframe length. If it is sufficient, reserve the storage space for the current subframe in the LMAC memory, and update the current remaining space in the LMAC memory according to the subframe length. This method ensures that there is definitely storage space to receive the subframe after passing the verification, thereby ensuring the accuracy of the BLOCKACK frame feedback information and avoiding the situation of subframe reception failure and inaccurate BLOCKACK frame feedback information caused by storage problems.
[0024] In this way, without significantly increasing hardware resources, by improving the processing flow or algorithm design, the decryption efficiency of the subframe can be improved, ensuring that all subframes are processed within the SIFS and accurately feeding back the reception status, thereby improving the reliability and throughput of wireless local area network communication. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained according to these drawings.
[0026] Figure 1 is a timing diagram of receiving an encrypted aggregation frame provided by the prior art;
[0027] Figure 2 is a schematic flowchart of a method for receiving an encrypted aggregation frame provided by an embodiment of the present application;
[0028] Figure 3 is a timing diagram of receiving an encrypted aggregation frame provided by an embodiment of the present application;
[0029] Figure 4 is a schematic structural diagram of a receiving device for an encrypted aggregation frame provided by the present application;
[0030] Figure 5 is a schematic structural diagram of a WiFi device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0031] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the drawings.
[0032] Please refer to Figure 2 , which is a schematic flowchart of a method for receiving an encrypted aggregation frame provided by an embodiment of the present application. AsFigure 2 As shown in the figure, the method according to the embodiment of the present application may include the following steps:
[0033] S201. Determine the reception start time t0 of the current encrypted A-MPDU to be received.
[0034] Among them, the physical layer (PHY) of the WiFi device continuously monitors the wireless channel to detect the arrival of frames. When a frame header conforming to the WiFi frame format is detected, the PHY layer notifies the media access control layer (MAC) layer.
[0035] Refer to Figure 3 In the timing diagram shown, the MAC layer determines whether it is the encrypted A-MPDU to be received according to the information in the frame header (such as frame type, destination address, etc.). If so, record the current time as the reception start time t0. The encrypted A-MPDU is composed of multiple sub-frames (MPDU), and these sub-frames have been encrypted and aggregated together at the sender to improve the transmission efficiency.
[0036] S202. Starting from the reception start time t0 of the current encrypted A-MPDU, decrypt and store each sub-frame in the received current encrypted A-MPDU in sequence until the reception start time t2 of the next encrypted A-MPDU to stop the decryption and storage operations.
[0037] Among them, starting from t0, the PHY layer of the WiFi device starts to receive the data of the encrypted A-MPDU.
[0038] The MAC layer obtains the received data from the PHY layer and parses it according to the format of the encrypted A-MPDU to separate each sub-frame.
[0039] For each sub-frame, the MAC layer first performs a decryption operation. The decryption algorithm depends on the encryption protocol (such as WPA3, WPA2, CCMP, etc.) negotiated in advance between the sender and the receiver. A key is required during the decryption process, and this key has been negotiated and determined through a security handshake protocol (such as 4-way handshake) during the association process.
[0040] The CCMP algorithm is fully known as CTR with CBC-MAC Protocol (Counter Mode with Cipher Block Chaining Message Authentication Code Protocol), or Counter Mode with Cipher Block Chaining Message Authentication Code Protocol. It is a technology of great significance in the field of information security. The CCMP algorithm is based on the AES (Advanced Encryption Standard) encryption algorithm and the authentication method of CCM (Counter-Mode / CBC-MAC). AES is a symmetric encryption algorithm widely used in various encryption scenarios, known for its strong security and high efficiency. CCM is an authentication mode that combines the counter mode and the cipher block chaining message authentication code (CBC-MAC) to provide data integrity and authenticity protection.
[0041] The decrypted sub-frame data is stored in the LMAC (Lower MAC) memory. The LMAC memory is a buffer in the MAC layer for temporarily storing received frame data.
[0042] See Figure 3 the timing diagram. The decryption and storage operations continue until the start time t2 of the reception of the next encrypted A-MPDU arrives. It can be seen that the time interval for the WiFi device to perform the decryption operation and the storage operation is at least the time interval between the start time of the reception of the current A-MPDU and the start time of the reception of the next A-MPUD. Compared with the prior art, the duration of performing the decryption operation and the storage operation is greatly increased, and all sub-frame decryption and storage operations can be completed without improving the hardware processing ability of the WiFi device.
[0043] S203. Starting from the reception start time t0, sequentially receive each sub-frame in the current encrypted aggregated data frame: Parse the delimiter of the current sub-frame to obtain the delimiter signature, CRC, and sub-frame length, and determine whether the delimiter signature and CRC are preset values. If so, determine whether the current remaining space in the LMAC memory is sufficient according to the sub-frame length; if so, reserve the storage space for the current sub-frame in the LMAC memory, and update the current remaining space in the LMAC memory according to the sub-frame length; perform FCS check, RA check, and frame legality check on the current sub-frame. If the check is successful, determine that the current sub-frame is successfully received; if the check fails, determine that the current sub-frame reception fails, stop the decryption and storage operations performed on the current sub-frame, release the storage space reserved for the current sub-frame in the LMAC memory, update the current remaining space of the memory; finally, update the SSN and bitmap information according to the reception status of the current sub-frame.
[0044] Among them, when starting to receive each sub-frame in the current encrypted A-MPDU at t0, the MAC layer first parses the delimiter of each sub-frame. The delimiter is the starting part of the frame and contains information such as the delimiter signature, cyclic redundancy check code (CRC), and sub-frame length.
[0045] The MAC layer determines whether the delimiter signature and CRC are preset values to confirm the integrity and correctness of the frame. If the delimiter signature and CRC match the preset values, the current sub-frame is processed continuously.
[0046] According to the sub-frame length obtained by parsing, the MAC layer determines whether there is enough remaining space in the LMAC memory to store the current sub-frame. If the space is sufficient, the storage space for the current sub-frame is reserved in the LMAC memory, and the current remaining space information of the LMAC memory is updated.
[0047] After reserving the storage space, the MAC layer performs further checks on the current sub-frame, including frame check sequence (FCS) check, receive address (RA) check, and frame legality check. The FCS check is used to detect whether an error occurs during frame transmission; the RA check is used to confirm whether the destination address of the frame matches the address of this device; the frame legality check is used to check whether the frame complies with the WiFi protocol specification.
[0048] If all checks are successful, it is determined that the current sub-frame is successfully received, and the SSN (Starting Sequence Number) and bitmap information are updated. The SSN is the starting value of the frame sequence number and is used to identify the order of the frames; the bitmap information is used to record which sub-frames have been successfully received.
[0049] If any check fails, it is determined that the current sub-frame reception fails. At this time, the MAC layer stops the decryption and storage operations (if in progress) on the current sub-frame in S202 and releases the storage space reserved for the current sub-frame in the LMAC memory. At the same time, the current remaining space information of the LMAC memory is updated, and the SSN and bitmap information are updated according to the reception status of the current sub-frame.
[0050] Furthermore, the UMAC controller can read data from the LMAC memory. After reading the data, the current remaining space information of the LMAC memory is updated. The specific process includes:
[0051] The UMAC controller of the WiFi device sends read and write instructions to the LMAC memory. The instructions contain the address of the data to be read, the data length, and the read / write operation type (read or write). After receiving the instructions, the LMAC memory first parses the instructions to determine the operation type, data address, and data length. According to the parsing results, the LMAC memory prepares for subsequent data read and write operations. The LMAC memory locates the storage unit according to the parsed data address. It reads the specified length of data from the located storage unit, and the data is transmitted to the UMAC controller through the data bus.
[0052] While reading the data or after reading is completed, the LMAC memory calculates the current remaining space. Remaining space = total storage space - occupied storage space. The occupied storage space can be updated in real time by maintaining a counter or a data structure. According to the length of the read data, the counter or data structure of the occupied storage space is updated. For example, if 100 bytes of data are read, the occupied storage space is increased by 100 bytes. The LMAC memory feeds back the updated remaining space information to the UMAC controller, which can be achieved through interrupts, status registers, or other communication methods.
[0053] Furthermore, the process of FCS verification includes:
[0054] The WiFi device extracts the 32-bit FCS (Frame Check Sequence) field from the received data frame, which is usually located at the end of the data frame. The WiFi device uses the same algorithm as the sender (such as CRC-32) to calculate the entire data frame (excluding the FCS field itself) to obtain a new FCS value. The extracted FCS field is compared with the locally calculated FCS value. If the two are consistent, the FCS verification passes, indicating that the data frame has not suffered an error during transmission. If they are inconsistent, the FCS verification fails, and the WiFi device may discard the data frame or request a retransmission.
[0055] The process of RA verification includes:
[0056] The WiFi device extracts the RA (Receiver Address) field from the MacHeader of the received data frame, which is the receiver address. The WiFi device reads its MAC address from its own configuration or hardware. The extracted RA address is compared with the local MAC address of the WiFi device. If the two are consistent, the RA verification passes, indicating that the data frame is sent to this WiFi device. If they are inconsistent, the RA verification fails, and the WiFi device may discard the data frame.
[0057] The process of frame legality verification includes: The WiFi device checks the PV (Protection Version) field in the MacHeader to ensure it conforms to the valid values defined in the 802.11 protocol specification. Verify whether the Duration field in the MacHeader conforms to the format and range specified by the protocol. This is usually used to indicate the duration of the Network Allocation Vector (NAV) to avoid collisions during transmission. If the data frame contains an HTC (High-Throughput Control) field (in 802.11n and later versions), the WiFi device verifies the correctness of its format and content. The WiFi device checks the A2 (Transmitter Address for BSS) field in the MacHeader to ensure it is in the list of allowed device connections. This is usually used to verify whether the sender is an authenticated and authorized device.
[0058] Combining the results of the above checks, the WiFi device makes a comprehensive judgment. If all the checks pass, the frame legality verification passes, indicating that the data frame conforms to the 802.11 protocol specification and the sender is legitimate. If any one of the checks fails, the frame legality verification fails, and the WiFi device may discard the data frame or take other appropriate measures (such as logging, sending warnings, etc.).
[0059] It should be noted that the FCS and MacHeader are usually not encrypted because they need to be verified before decryption. This means these fields can be read and verified by any device that can receive the data frame.
[0060] In summary, during the reception process, the WiFi device can ensure the correctness, legality, and security of the received data frame by performing FCS verification, RA verification, and frame legality verification. These verification processes are important steps to achieve reliable communication and data security.
[0061] S204. When the end time t1 of the reception of the current encrypted A-MPDU arrives, generate a BLOCKACK frame according to the current SSN and bitmap information, and return the BLOCKACK frame of the current encrypted A-MPDU to the sender after the duration of SIFS.
[0062] Among them, referring to Figure 3 the timing diagram shown, when the end time t1 of the reception of the current encrypted A-MPDU arrives, it means that the receiver has completed the reception processing of the encrypted A-MPDU (although the decryption and storage operations of some sub-frames may have been stopped in advance due to the arrival of t2).
[0063] The MAC layer generates a BLOCKACK frame based on the current SSN and bitmap information. The BLOCKACK frame is used to feedback to the sender which sub - frames have been successfully received and which have failed. The SSN and bitmap information jointly determine the content of the BLOCKACK frame.
[0064] After generating the BLOCKACK frame, the MAC layer needs to wait for a Short Inter - Frame Space (SIFS) duration to ensure the idle state of the wireless channel and avoid collisions with transmissions from other devices.
[0065] After the SIFS duration, the MAC layer sends the generated BLOCKACK frame back to the sender through the PHY layer. After receiving the BLOCKACK frame, the sender can understand the receiver's reception of the current encrypted A - MPDU based on the content of the frame and perform corresponding re - transmission or confirmation operations.
[0066] SIFS (Short Interframe Space) is a mechanism used to define the minimum time interval between different frames in a Wireless Local Area Network (WLAN), especially in networks adopting the IEEE 802.11 standard.
[0067] SIFS is mainly used in the following scenarios:
[0068] Responding to ACK frames: When a Station (STA) successfully receives a data frame, it needs to send an ACK (Acknowledgment) frame within a SIFS time to confirm the reception. The short duration of SIFS ensures timely response and reduces communication latency.
[0069] Sending the next frame immediately: In cases where multiple frames need to be sent continuously (for example, in a frame sequence), the sender can start sending the next frame immediately (i.e., within a SIFS time) after the previous frame is sent.
[0070] The duration of SIFS is fixed and relatively short, usually 10 microseconds (μs) or 20 microseconds (depending on the specific physical layer and modulation method). This duration is short enough to ensure that a response or the next frame can be sent quickly after receiving a frame, thus improving the network efficiency and throughput.
[0071] This application specifically includes the following beneficial effects:
[0072] Decouple the decryption operation and the storage operation so that they are not associated with the generation of BLOCKACK. In this way, the decryption operation and the storage operation duration of the last few sub-frames in the aggregated encrypted frame are extended from the original SIFS to at least (SIFS + BLOCKACK frame transmission duration + SIFS), effectively avoiding the bottleneck problem that may occur when all sub-frames are processed within the SIFS time. Especially in high data rate transmission scenarios, the risk that the decryption process becomes a key factor restricting system performance is reduced.
[0073] By performing storage prediction, when receiving a sub-frame, first parse the delimiter of the current sub-frame to obtain the delimiter signature, CRC, and sub-frame length. Then, determine whether the delimiter signature and CRC are preset values, and further determine whether the current remaining space in the LMAC memory is sufficient according to the sub-frame length. If it is sufficient, reserve the storage space for the current sub-frame in the LMAC memory, and update the current remaining space in the LMAC memory according to the sub-frame length. This method ensures that there must be storage space to receive the sub-frame after passing the verification, thereby ensuring the accuracy of the BLOCKACK frame feedback information and avoiding the situation of sub-frame reception failure and inaccurate BLOCKACK frame feedback information caused by storage problems.
[0074] In this way, without significantly increasing hardware resources, by improving the processing flow or algorithm design, the decryption efficiency of sub-frames can be improved, ensuring that all sub-frames are processed within SIFS and accurately feeding back the reception status, thereby improving the reliability and throughput of wireless local area network communication.
[0075] The following is an apparatus embodiment of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the apparatus embodiment of the present application, please refer to the method embodiment of the present application.
[0076] Please refer to Figure 4 , which shows a schematic structural diagram of a receiving apparatus for an encrypted aggregation frame provided by an exemplary embodiment of the present application, hereinafter referred to as apparatus 4. This apparatus 4 can be implemented as all or part of a WiFi device through software, hardware, or a combination of both. Apparatus 4 includes: a determination unit 401, a decryption and storage unit 402, a prediction and verification unit 403, and a feedback unit 404.
[0077] The determination unit 401 is configured to determine the reception start time t0 of the current encrypted A-MPDU to be received; wherein, the current encrypted A-MPDU is composed of multiple sub-frames;
[0078] The decryption storage unit 402 is used to start decrypting and storing each sub-frame in the received current encrypted A-MPDU in sequence starting from the reception start time t0 of the current encrypted A-MPDU, and stop performing the decryption and storage operations until the reception start time t2 of the next encrypted A-MPDU;
[0079] The pre-judgment verification unit 403 is used to sequentially receive each sub-frame in the current encrypted aggregated data frame starting from the reception start time t0: parse the delimiter of the current sub-frame to obtain the delimiter signature, CRC, and sub-frame length, and determine whether the delimiter signature and CRC are preset values. If so, determine whether the current remaining space in the LMAC memory is sufficient according to the sub-frame length; if so, reserve the storage space for the current sub-frame in the LMAC memory, and update the current remaining space in the LMAC memory according to the sub-frame length; perform FCS verification, RA verification, and frame legality verification on the current sub-frame. If the verification is successful, determine that the current sub-frame is successfully received; if the verification fails, determine that the current sub-frame reception fails, stop the decryption and storage operations performed on the current sub-frame, and release the storage space reserved for the current sub-frame in the LMAC memory, and update the current remaining space in the LMAC memory; finally, update the SSN and bitmap information according to the reception status of the current sub-frame;
[0080] The feedback unit 404 is used to generate a BLOCKACK frame according to the current SSN and bitmap information when the reception end time of the current encrypted A-MPDU arrives, and return the BLOCKACK frame of the current encrypted A-MPDU to the sender after the duration of SIFS.
[0081] In one or more possible embodiments, the pre-judgment verification unit 403 is further used to execute:
[0082] In response to the read and write instructions of the UMAC controller to the LMAC memory, read data from the LMAC memory, and update the current remaining space in the LMAC memory according to the length of the read data.
[0083] In one or more possible embodiments, passing the FCS verification means that the received 32-bit FCS is consistent with the locally calculated one;
[0084] Passing the RA verification means that the RA address in the MacHeader is consistent with the MAC address of the WiFi device of the receiving party;
[0085] The passing of frame legality verification indicates that the PV type, Duration, and HTC format in the MacHeader conform to the 802.11 protocol specification, and the A2 address in the MacHeader is in the list of allowed device connections; FCS and MacHeader are not encrypted.
[0086] In one or more possible embodiments, the CCMP algorithm is used to encrypt the A-MPDU.
[0087] In one or more possible embodiments, the duration of SIFS is 10 microseconds or 20 microseconds.
[0088] It should be noted that when the device 4 provided in the above embodiments executes the method for receiving encrypted aggregated frames, only the above division of each functional module is used for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the above functions. In addition, the receiving device for encrypted aggregated frames provided in the above embodiments and the embodiments of the method for receiving encrypted aggregated frames belong to the same concept. The implementation process is shown in the method embodiments and will not be elaborated here.
[0089] The serial numbers of the embodiments of the present application are only for description and do not represent the advantages and disadvantages of the embodiments.
[0090] The embodiments of the present application also provide a computer storage medium, which can store multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the method steps of the embodiments as described above Figure 2 as shown, and the specific execution process can be referred to Figure 2 the specific description of the embodiments as shown, and will not be elaborated here.
[0091] The present application also provides a computer program product, which stores at least one instruction, and the at least one instruction is loaded and executed by the processor to implement the method for receiving encrypted aggregated frames as described in each of the above embodiments.
[0092] Please refer to Figure 5 , which is a schematic structural diagram of a WiFi device provided by the embodiments of the present application. As Figure 5 shown, the WiFi device 500 may include: at least one processor 501, at least one network interface 504, a user interface 503, a memory 505, and at least one communication bus 502.
[0093] Among them, the communication bus 502 is used to realize the connection and communication between these components.
[0094] Among them, the user interface 503 may include a display screen and a camera. Optionally, the user interface 503 may further include a standard wired interface and a wireless interface.
[0095] Among them, the network interface 504 may optionally include a WI-FI interface.
[0096] Among them, the processor 501 may include one or more processing cores. The processor 501 connects various parts within the entire WiFi device 500 through various interfaces and circuits. By running or executing instructions, programs, code sets, or instruction sets stored in the memory 505, and by invoking the data stored in the memory 505, the processor 501 performs various functions of the WiFi device 500 and processes data. Optionally, the processor 501 may be implemented in at least one of the following hardware forms: digital signal processing (DSP), field-programmable gate array (FPGA), and programmable logic array (PLA). The processor 501 may integrate one or a combination of several of the following: a central processing unit (CPU), a graphics processing unit (GPU), and a modem. Among them, the CPU mainly processes the operating system, the user interface, and application programs, etc.; the GPU is responsible for rendering and drawing the content to be displayed on the display screen; the modem is used to process wireless communications. It can be understood that the above-mentioned modem may not be integrated into the processor 501 and may be implemented separately by a single chip.
[0097] Among them, the memory 505 may include a random access memory (RAM) and may also include a read-only memory. Optionally, the memory 505 includes a non-transitory computer-readable storage medium. The memory 505 can be used to store instructions, programs, code, code sets, or instruction sets. The memory 505 may include a program storage area and a data storage area. Among them, the program storage area may store instructions for implementing the operating system, instructions for at least one function (such as a touch function, a sound playback function, an image playback function, etc.), instructions for implementing the above-mentioned various method embodiments, etc.; the data storage area may store the data involved in the above-mentioned various method embodiments. Optionally, the memory 505 may further be at least one storage device located far from the aforementioned processor 501. Such as Figure 5As shown, the memory 505, which is a computer storage medium, may include an operating system, a network communication module, a user interface module, and application programs.
[0098] In Figure 5 In the WiFi device 500 shown, the user interface 503 is mainly used to provide an interface for the user to input data and obtain the data input by the user; while the processor 501 can be used to call the application programs stored in the memory 505 and specifically execute the method as Figure 2 shown, and the specific process can be referred to Figure 2 shown, which will not be elaborated here.
[0099] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disc, a read-only memory, or a random access memory, etc.
[0100] The above-disclosed are only the preferred embodiments of the present application. Of course, the scope of rights of the present application cannot be limited thereby. Therefore, equivalent changes made according to the claims of the present application still fall within the scope covered by the present application.
Claims
1. A method for receiving an encrypted aggregate frame, characterized in that: include: Determine a receiving start time t0 of a current encrypted A-MPDU to be received; wherein the current encrypted A-MPDU is composed of a plurality of subframes; Starting from the reception start time t0 of the current encrypted A-MPDU, decrypting and storing each subframe in the received current encrypted A-MPDU in sequence until the reception start time t2 of the next encrypted A-MPDU stops performing the decryption and storage operations; At the receiving start time t0, each subframe in the current encrypted aggregate data frame is received in sequence: the delimiter of the current subframe is parsed to obtain the delimiter signature, CRC and subframe length, and it is determined whether the delimiter signature and CRC are preset values. If yes, whether the current remaining space of the LMAC memory is sufficient according to the subframe length; if yes, storage space for the current subframe is reserved in the LMAC memory, and the current remaining space of the LMAC memory is updated according to the subframe length; FCS check, RA check and frame legitimacy check are performed on the current subframe. If the check succeeds, it is determined that the current subframe is successfully received; if the check fails, it is determined that the current subframe has failed to be received, and the decryption and storage operations performed on the current subframe are stopped, and the storage space reserved for the current subframe in the LMAC memory is released, and the current remaining space of the LMAC memory is updated; finally, the SSN and bitmap information are updated according to the receiving status of the current subframe; When the reception end time of the current encrypted A-MPDU arrives, a BLOCKACK frame is generated according to the current SSN and bitmap information, and the BLOCKACK frame of the current encrypted A-MPDU is returned to the sender after the SIFS duration.
2. The method according to claim 1, characterized in that Also includes: In response to the read and write instructions of the UMAC controller to the LMAC memory, data is read from the LMAC memory, and the current remaining space of the LMAC memory is updated according to the length of the read data.
3. The method according to claim 1, characterized in that FCS check passes, indicating that the received 32-bit FCS is consistent with the locally calculated one; RA verification passed means that the RA address in MacHeader is consistent with the MAC address of the WiFi device of the receiver; The frame validity check passes, indicating that the PV type, Duration, and HTC format in the MacHeader comply with the 802.11 protocol specification, and the A2 address in the MacHeader is in the list of allowed device connections; FCS and MacHeader are not encrypted.
4. The method according to claim 1, characterized in that: The A-MPDU is encrypted using the CCMP algorithm.
5. The method according to claim 1, characterized in that The duration of SIFS is 10 microseconds or 20 microseconds.
6. A receiving device for an encrypted aggregate frame, characterized in that: include: A determination unit, configured to determine a receiving start time t0 of a current encrypted A-MPDU to be received; wherein the current encrypted A-MPDU is composed of a plurality of subframes; a decryption storage unit, configured to sequentially decrypt and store each subframe in the received current encrypted A-MPDU starting at a reception start time t0 of the current encrypted A-MPDU, and stop performing the decryption and storage operations at a reception start time t2 of a next encrypted A-MPDU; A pre-judgment verification unit is used to sequentially receive each subframe in the current encrypted aggregate data frame starting from the receiving start time t0: parse the delimiter of the current subframe to obtain the delimiter signature, CRC and subframe length, determine whether the delimiter signature and CRC are preset values, and if so, determine whether the current remaining space of the LMAC memory is sufficient according to the subframe length; if so, reserve storage space for the current subframe in the LMAC memory, and update the current remaining space of the LMAC memory according to the subframe length; perform FCS check, RA check and frame legitimacy check on the current subframe, and if the check succeeds, determine that the current subframe is successfully received; if the check fails, determine that the current subframe fails to be received, stop the decryption and storage operations performed on the current subframe, and release the storage space reserved for the current subframe in the LMAC memory, and update the current remaining space of the LMAC memory; finally, update the SSN and bitmap information according to the reception status of the current subframe; The feedback unit is used to generate a BLOCKACK frame according to the current SSN and bitmap information when the reception end time of the current encrypted A-MPDU arrives, and return the BLOCKACK frame of the current encrypted A-MPDU to the sender after the SIFS duration.
7. A computer storage medium, characterized in that: The computer storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor and executing the method steps according to any one of claims 1 to 5.
8. A WiFi device, characterized in that: include: A processor and a memory; wherein the memory stores a computer program, and the computer program is suitable for being loaded by the processor and executing the method steps as claimed in any one of claims 1 to 5.
Citation Information
Cited By
Short-distance communication receiving method and system
CN120710635A