Communication apparatus, control method, storage medium, and program product
By implementing a link establishment unit in the communication device, determining whether the wireless communication device supports multi-link communication based on the received signal, and establishing a link with a communication unit whose security strength meets the predetermined conditions, the problem of increased vulnerabilities caused by low-security strength links in multi-link communication is solved, and the security strength guarantee of data communication is achieved.
Patent Information
- Application Number
- CN202411883179.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-12-19
- Publication Date
- 2025-06-24
AI Technical Summary
In multi-link communication, there is concern that vulnerabilities are increased due to low security strength links.
By implementing the link establishment unit in the communication device, it is determined whether the wireless communication device supports multi-link communication based on the received signal, and establishes a link with a communication unit whose security strength meets the predetermined conditions to ensure the security strength of data communication.
It is realized that the security strength of data communication is equal to or higher than a certain level in multi-link communication, reducing the risk of vulnerability due to low security strength links.
Smart Images

Figure CN120201592A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to a communication device capable of multi-link communication, a control method thereof, a storage medium storing its control program, and a computer program product thereof. Background Art
[0002] Communication technologies such as wireless local area network (LAN) are evolving. As a main communication standard for wireless LAN, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard series is known. The IEEE 802.11 standard series includes IEEE 802.11a / b / g / n / ac / ax standards. For example, in IEEE 802.11ax, the following technology is standardized: in addition to using OFDMA (Orthogonal Frequency Division Multiple Access) to achieve a peak throughput of up to 9.6 gigabits per second (Gbps), the communication speed is also increased in a congested situation (for example, see Japanese Unexamined Patent Application Publication No. 2018-050133A (a counterpart patent of US20180084584A1)).
[0003] In addition, a task group for developing IEEE 802.11be as a subsequent standard has been established, which aims to further increase throughput, improve frequency utilization efficiency, and improve communication latency. In IEEE 802.11be, for example, the following multi-link communication is studied: in the multi-link communication, one access point (AP) establishes multiple links with one station (STA) via multiple different frequency channels and communicates in parallel.
[0004] In the existing IEEE 802.11 standard series, the STA is connected to the AP and performs data communication with the AP through a single link. On the other hand, in IEEE 802.11be, the STA establishes two or more links with the AP and uses the established two or more links to perform data communication simultaneously, thereby achieving an increase in throughput. In IEEE 802.11be, in order to expand the available frequency band, support for the 6 GHz frequency band is also studied. Two or more links can be selected from the same frequency band (any one of the Sub-GHz band, 2.4 GHz band, 3.6 GHz band, 4.9 and 5 GHz bands, 60 GHz band, and 6 GHz band), or can be selected from different frequency bands.
[0005] In such a configuration where two or more links can be established with the AP, when a link with low security strength is included in the established links, there is a concern that the vulnerability increases due to this link. Summary of the Invention
[0006] Embodiments of the present disclosure provide a communication device, a control method thereof, a storage medium storing its control program, and a computer program product, which can achieve data communication with a security strength equal to or higher than a certain level.
[0007] According to an embodiment of the present disclosure, a communication device performs wireless communication with a wireless communication device that complies with the IEEE 802.11 series of standards and supports multi-link communication. The communication device includes: a receiving unit configured to receive a signal including information required for a communication connection for performing wireless communication from the wireless communication device; and a link establishment unit configured to establish a link with the wireless communication device based on the signal. When the signal includes predetermined information indicating that the wireless communication device supports multi-link communication, the link establishment unit establishes at least one link with at least one communication unit among a plurality of communication units belonging to the wireless communication device and operating via different frequency channels and having a security strength that satisfies a predetermined condition.
[0008] Further features will become apparent from the following description of exemplary embodiments with reference to the drawings. Description of the Drawings
[0009] Figure 1 is a configuration diagram showing an example of a communication system including an STA (Station) as a communication device according to the present embodiment.
[0010] Figure 2 is a sequence diagram showing Figure 1 the multi-link communication between the STA and the AP in
[0011] Figure 3 is a diagram showing an example of the RNR element included in a frame transmitted by a subordinate AP that supports multi-link communication.
[0012] Figure 4 is a schematic diagram showing Figure 1 the hardware configuration of the STA in
[0013] Figure 5 is a diagram showing Figure 1 an example of the functional configuration of the STA in
[0014] Figure 6 is a diagram showing Figure 1 the process of the link establishment control process performed by the STA in
[0015] Figure 7 is a diagram showing Figure 6 the process of the determination process in S608 in
[0016] Figure 8 is a diagram showing Figure 1Flowchart of another process of link establishment control processing performed by the STA in
[0017] Figure 9 is a flowchart showing Figure 8 the process of the determination processing in S808 in Detailed implementation manners
[0018] Hereinafter, some exemplary embodiments according to the present disclosure will be described in detail with reference to the accompanying drawings.
[0019] Figure 1 is a configuration diagram showing an example of a communication system including an STA (Station) 102 as a communication device according to this embodiment. The communication system includes the STA 102 and an AP (Access Point) 101 as a wireless communication device. In Figure 1 it, the circle 100 indicates the network formed by the AP 101. For example, when the STA 102 exists in the area indicated by the circle 100, the STA 102 can receive frames (signals) such as beacons or probe responses sent from the AP 101.
[0020] The STA 102 participates in the network formed by the AP 101, and the AP 101 and the STA 102 can perform wireless communication conforming to the IEEE802.11be (EHT) standard. EHT is an abbreviation for Extremely High Throughput. EHT can be interpreted as an abbreviation for Extreme High Throughput. The AP 101 and the STA 102 can communicate in multiple frequency bands such as the 2.4 GHz band, 5 GHz band, and 6 GHz band. Note that the frequency bands in which the AP 101 and the STA 102 can communicate are not limited to this. The AP 101 and the STA 102 can communicate in another frequency band such as the 60 GHz band. In addition, the AP 101 and the STA 102 can communicate using bandwidths of 20 GHz, 40 MHz, 80 MHz, 160 MHz, 320 MHz. Note that the bandwidths used by the AP 101 and the STA 102 are not limited to this, and other bandwidths such as 240 MHz and 4 MHz can also be used.
[0021] In this embodiment, in addition to the IEEE802.11be standard, AP 101 and STA102 can also follow traditional standards that are standards prior to IEEE802.11be. In particular, AP 101 and STA 102 can correspond to at least one of the IEEE802.11a / b / g / n / ac / ax standards. In addition, in addition to the IEEE802.11 series standards such as IEEE802.11a / b / g / n / ac / ax / be, AP 101 and STA 102 can also support other communication standards such as Bluetooth (registered trademark), NFC, UWB, ZigBee, and MBOA. Note that UWB is an abbreviation for Ultra Wide Band, and MBOA is an abbreviation for Multi Band OFDM Alliance. In addition, NFC is an abbreviation for Near Field Communication. UWB includes Wireless USB, Wireless 1394, WiNET, etc., and the communication standard can also be a communication standard for wired communication such as wired LAN.
[0022] Specific examples of AP 101 include, but are not limited to, a wireless LAN router and a personal computer (PC). AP 101 can be an information processor such as a wireless chip capable of performing wireless communication conforming to the IEEE802.11be standard. Specific examples of STA 102 include, but are not limited to, a camera, a tablet computer, a smart phone, a PC, a mobile phone, a video camera, and headphones. STA102 can be an information processor such as a wireless chip capable of performing wireless communication conforming to the IEEE802.11be standard.
[0023] AP 101 and STA 102 perform multi-link communication as follows. In multi-link communication, a link is established and communication is performed via multiple frequency channels. In the IEEE802.11 series standards, the bandwidth of each channel is defined as 20MHz. The frequency channels used here are defined in the IEEE802.11 series standards, and the IEEE802.11 series standards define multiple frequency channels in each of the 2.4GHz band, 5GHz band, 6GHz band, and 60GHz band. Note that a bandwidth greater than 40MHz can be used in one channel by bonding with adjacent channels. For example, AP 101 can communicate with STA 102 by establishing link 103 via the first channel in the 5GHz band. In parallel with this, STA 102 can establish link 104 with AP 101 via the second channel in the 6GHz band to communicate. In this case, STA 102 performs multi-link communication, that is, maintains link 104 via the second channel in parallel with link 103 via the first channel.
[0024] Note that in multi-link communication, multiple links with different frequency bands can be established between communication devices. For example, in addition to link 103 in the 4 GHz band and link 104 in the 6 GHz band, AP 101 and STA 102 can also establish a third link in the 2.5 GHz band. In multi-link communication, a link can be established between communication devices via multiple different frequency channels included in the same frequency band. For example, AP 101 and STA 102 can establish a first link via channel 15 in the 6 GHz band and a second link via channel 207 in the 6 GHz band. Note that links in the same frequency band and links in different frequency bands can be mixed.
[0025] For example, in addition to establishing link 103 via channel 15 in the 6 GHz band, AP 101 and STA 102 can also establish a link via channel 36 in the 5 GHz band and a link via channel 149 in the 5 GHz band. In this way, since STA102 establishes multiple links with AP 101 via different frequency channels, even if one of the established links is congested, communication can be maintained via other links. As a result, STA 102 can prevent a decrease in throughput and communication latency during communication with AP 101.
[0026] Figure 2 is a sequence diagram showing Figure 1 multi-link communication between STA 102 and AP 101 in. Note that an AP and a STA that support multi-link communication are respectively referred to as an AP MLD and a STA MLD. AP 101 is described as AP MLD 101, and STA 102 is described as STA MLD 102. Note that MLD is an abbreviation for Multi-Link Device. In addition, an AP associated with an AP MLD and operating on different frequency channels is called an affiliated AP, and a STA associated with a STA MLD and operating on different frequency channels is called an affiliated STA. Figure 2 shows an affiliated AP1 and an affiliated STA1 operating in the 2.4 GHz band. In addition, Figure 2 shows an affiliated AP2 and an affiliated STA2 operating in the 5 GHz band. In addition, Figure 2 shows an affiliated AP3 and an affiliated STA3 operating in the 6 GHz intermediate band.
[0027] AP 101 adds a basic multi-link element indicating that the device supports multi-link communication to frames such as beacons or probe responses. The affiliated AP1, affiliated AP2, and affiliated AP3 send this frame via their respective channels.
[0028] STA 102 determines whether the transmission source of the received frame supports multi-link communication based on whether the received frame includes a basic multi-link element.
[0029] For example, when the transmission source of the frame is the subordinate AP1 belonging to AP 101, the frame includes, as Figure 3 shown, an RNR (Reduce Neighbor Report) element. STA 102 obtains information about other subordinate APs 2 and 3 belonging to the same AP 101 as the subordinate AP1 that sent the frame from the RNR element.
[0030] Based on the MLD ID included in the RNR element, it is determined whether the received frame is sent from the subordinate AP2 or subordinate AP3 belonging to the same AP 101. The MLD ID is identification information uniquely assigned to AP 101. STA 102 switches the channel to the channel indicated by the obtained information and receives frames such as beacons or probe responses sent from the subordinate APs 2 and 3. Based on the received frames, STA 102 establishes links with the subordinate AP1, subordinate AP2, and subordinate AP3 respectively. This enables STA 102 to perform multi-link communication with AP101, thereby improving the throughput of communication with AP 101.
[0031] On the other hand, if the transmission source of the frame is not an AP that supports multi-link communication, STA 102 establishes a link with the transmission source of the frame via a single frequency channel.
[0032] Figure 4 is a block diagram schematically showing Figure 1 the hardware configuration of STA 102 in Figure 4 In, STA 102 includes a storage unit 401, a controller 402, a functional unit 403, an input unit 404, an output unit 405, a communication unit 406, and an antenna 407. The storage unit 401, the controller 402, the functional unit 403, the input unit 404, the output unit 405, and the communication unit 406 are interconnected via a bus 408.
[0033] The storage unit 401 is composed of one or more memories such as ROM or RAM and stores programs for performing various operations described later and various information such as communication parameters for performing wireless communication. Note that ROM is the abbreviation of Read Only Memory, and RAM is the abbreviation of Random Access Memory. In addition to memories such as ROM or RAM, the storage unit 401 can also adopt storage media such as floppy disks, hard disks, optical disks, magneto-optical disks, CD-ROMs, CD-Rs, magnetic tapes, non-volatile memory cards, and DVDs. The storage unit 401 can include multiple storage media.
[0034] The controller 402 is composed of one or more processors such as a CPU or an MPU, and controls the entire STA 102 by executing a program stored in the storage unit 401. Note that the controller 402 can control the entire STA 102 through the cooperation between the program stored in the storage unit 401 and the OS (operating system). In addition, the controller 402 generates data or frames to be transmitted in communication with another communication device. Note that CPU is the abbreviation of Central Processing Unit, and MPU is the abbreviation of Micro Processing Unit. The controller 402 can include a multi-core processor having multiple cores, and the multi-core processor can control the entire STA 102.
[0035] The controller 402 controls the functional unit 403 to perform predetermined processing such as wireless communication, imaging, printing, and projection. The functional unit 403 is hardware used when the STA 102 performs predetermined processing.
[0036] The input unit 404 accepts various operations from the user. The output unit 405 outputs various information to the user via a monitor screen or a speaker. Here, the output of the output unit 405 can be a display on the monitor screen, audio output from the speaker, vibration output, etc. Note that both the input unit 404 and the output unit 405 can be implemented by one module such as a touch panel. The input unit 404 and the output unit 405 can be integrated with the STA 102, or can be separated from the STA 102.
[0037] The communication unit 406 controls wireless communication compliant with the IEEE802.11be standard. In addition to the IEEE802.11be standard, the communication unit 406 can also control wireless communication compliant with other IEEE802.11 series standards, and can control wired communication such as a wired LAN. The communication unit 406 controls the antenna 407 to transmit a frame for wireless communication generated by the controller 402 to an external device.
[0038] Note that if the STA 102 supports the NFC standard, the Bluetooth standard, etc. in addition to supporting the IEEE802.11be standard, the communication unit 406 can control wireless communication compliant with these communication standards. In addition, when the STA 102 can perform wireless communication compliant with multiple communication standards, the STA 102 can include dedicated communication units and antennas corresponding to each communication standard. The STA 102 transmits and receives image data, document data, video data, and other information to and from an external device such as the AP 101 via the communication unit 406. The antenna 407 can be constructed separately from the communication unit 406, or can be constructed together with the communication unit 406 as one module.
[0039] The antenna 407 enables communication in the 2.4 GHz band, 5 GHz band, and 6 GHz band. In this embodiment, the STA 102 is configured to include two antennas, but this configuration is not restrictive. For example, the STA 102 may include different antennas for different frequency bands, that is, it may include three antennas corresponding to the 2.4 GHz band, 5 GHz band, and 6 GHz band respectively. In addition, the STA 102 may also include a plurality of communication units corresponding to each antenna.
[0040] Figure 5 is a block diagram showing Figure 1 an example of the functional configuration of the STA 102 in. In Figure 5 the STA 102 includes a multi-link control module 501, a subordinate STA setting module 502, a frame generation module 503, a frame transmission and reception module 504, and a communication quality measurement module 505 as functional components.
[0041] The multi-link control module 501 (link establishment unit) controls the following processes: the communication start process of establishing one or more links for the STA 102 to perform wireless communication with the AP 101, the process of adding or deleting links after the communication starts, and the communication end process of deleting all links. Specifically, the communication start process includes an authentication process, an association process, and a four-way handshake (4WHS) process.
[0042] The subordinate STA setting module 502 selects and determines the subordinate STA in the multi-link communication set by the user through the input unit 404. The subordinate STA setting module 502 notifies the frame transmission and reception module 504 of the frequency channel to be used.
[0043] The frame generation module 503 generates a frame to be transmitted according to the settings of the subordinate STA setting module 502.
[0044] The frame transmission and reception module 504 (reception unit) receives frames such as beacons or probe responses from the target device via the frequency channel indicated by the notification received from the subordinate STA setting module 502.
[0045] The communication quality measurement module 505 measures the communication quality of frames such as beacons or probe responses received by the frame transmission and reception module 504. In the measurement of communication quality, for example, RSSI, SNR, etc. are used.
[0046] Next, the process of the STA 102 establishing a link with the AP 101 will be described.
[0047] Figure 6 is a block diagram showing Figure 1Flowchart of the process of link establishment control processing performed by the STA 102 in []. It is implemented by the controller 402 executing the program stored in the storage unit 401 Figure 6 The link establishment control processing in []. For example, when the STA102 starts attempting to connect to the AP 101 in a state where the user sets a multi-link mode for multi-link communication in the STA 102, the Figure 6 link establishment control processing in [] is executed. Alternatively, when re-determining the AP to connect to due to a poor radio wave environment or the like, this processing is executed.
[0048] In Figure 6 first, the controller 402 receives a frame such as a beacon or a probe response from the attached STA designated by the user from among the attached STA1, attached STA2, and attached STA3 (S601, reception step). For example, when the user designates the attached STA1, in S601, a frame sent from the attached STA1 operating in the same frequency channel as the attached AP1 is received.
[0049] Next, the controller 402 determines whether the STA 102 supports multi-link communication (S602).
[0050] When it is determined in S602 that the STA 102 does not support multi-link communication, the process proceeds to S603. In S603 (link establishment step), the controller 402 establishes a link with the operating attached AP1 via the same frequency channel as the attached STA1 designated by the user. Thereafter, this processing terminates.
[0051] When it is determined in S602 that the STA 102 supports multi-link communication, the process proceeds to S604. In S604, the controller 402 determines whether the frame received in S601 includes a basic multi-link element. That is, it is determined whether the AP 101 that is the transmission source of the frame received in S601 supports multi-link communication.
[0052] When it is determined in S604 that the frame received in S601 does not include a basic multi-link element, that is, when the AP 101 does not support multi-link communication, the process proceeds to S603.
[0053] When it is determined in S604 that the frame received in S601 includes a basic multi-link element, that is, when the AP 101 supports multi-link communication, the process proceeds to S605.
[0054] In S605, the controller 402 obtains information on the frequency channels of the attached AP2 and attached AP3 from the frame received in S601. The attached AP2 and attached AP3 belong to the same AP MLD (AP 101) as the attached AP1 that has sent the frame.
[0055] Then, the controller 402 switches the channel to the frequency channel indicated by the information obtained in S605 and receives frames transmitted from the subordinate AP2 and the subordinate AP3 operating via this frequency channel respectively (S606). In S606, frames transmitted from subordinate APs belonging to an AP MLD other than AP 101 can be received. Therefore, the controller 402 determines whether the transmission source of the frame received in S606 belongs to the same AP MLD as the transmission source of the frame received in S601. This determination is made based on the MLD IDs included in the frames received in S601 and S606. For example, when these MLD IDs do not match, it is determined that the transmission source of the frame received in S606 belongs to a different AP MLD from the transmission source of the frame received in S601. On the other hand, when these MLD IDs match, it is determined that the transmission source of the frame received in S606 belongs to the same AP MLD as the transmission source of the frame received in S601. In subsequent processing, among the multiple frames received in S606, only the frames transmitted from the subordinate APs belonging to the same AP MLD as the transmission source of the frame received in S601 are used.
[0056] Next, the controller 402 obtains information on the security strength of each of the subordinate AP1, subordinate AP2, and subordinate AP3 from the frames received in S601 and S606 (S607). The information on the security strength includes, for example, information indicating the security standard of the subordinate AP of the transmission source, information indicating the encryption method used in the subordinate AP of the transmission source, information indicating the authentication method used in the subordinate AP of the transmission source, and information on the mode related to the use of the AP MLD to which the subordinate AP of the transmission source belongs, but is not limited thereto.
[0057] Next, the controller 402 (determination unit) performs the quantity determination process (S608) of determining the quantity of subordinate APs whose security strength is higher than the threshold value, which will be described later. Figure 7 in
[0058] When the quantity of subordinate APs whose security strength is higher than the threshold value determined in S608 is two or more, the process proceeds to S609. In S609 (link establishment step), the controller 402 establishes a link with multiple subordinate APs determined to have a security strength higher than the threshold value among the subordinate AP1, subordinate AP2, and subordinate AP3 belonging to AP 101.
[0059] For example, when it is determined that the security strengths of all the subordinate APs, i.e., subordinate AP1, subordinate AP2, and subordinate AP3, are higher than the threshold, the controller 402 establishes links with subordinate AP1, subordinate AP2, and subordinate AP3 respectively. When it is determined that the security strengths of two of subordinate AP1, subordinate AP2, and subordinate AP3 are higher than the threshold, the controller 402 establishes links with the two subordinate APs whose security strengths are determined to be higher than the threshold respectively. Thereafter, this process terminates.
[0060] When the number of subordinate APs whose security strengths are determined to be higher than the threshold in S608 is one, the process proceeds to S610. In S610 (link establishment step), the controller 402 establishes a link with the one subordinate AP among subordinate AP1, subordinate AP2, and subordinate AP3 belonging to AP 101 whose security strength is determined to be higher than the threshold. Thereafter, this process terminates. As described above, in this embodiment, a link is established with the subordinate AP among subordinate AP1, subordinate AP2, and subordinate AP3 belonging to AP 101 whose security strength is determined to be higher than the threshold. In S610, the user can be asked whether to establish communication via one link with high security strength or via multiple links including links with low security strength, and based on the instruction from the user, it can be controlled whether to establish one link or multiple links.
[0061] If the number of subordinate APs whose security strengths are determined to be higher than the threshold in S608 is 0, the process proceeds to S611. In S611, the controller 402 does not establish a link with any of subordinate AP1, subordinate AP2, and subordinate AP3 belonging to AP 101. At this time, for example, a notification indicating that no link has been established with AP 101 is displayed on the output unit 405. Thereafter, this process terminates. When it is determined in S608 that there is no link satisfying the condition, the user can be asked whether not to establish communication or to establish communication via at least one link with low security strength, and based on the user's instruction, it can be controlled whether to establish at least one link or not to establish a link.
[0062] Figure 7 is a flowchart showing the process of the quantity determination process in S608. The quantity determination process in Figure 7 is performed for each frame received in S601 and S606. In this embodiment, as an example, the process for the frame received in S601 (i.e., the frame sent from subordinate AP1) will be described.
[0063] In Figure 7In [description], the controller 402 determines whether the security standard of the affiliated AP1 is WPA2 or WPA3 in S701 based on the information about the security strength obtained in S607. In this embodiment, the information about the security strength obtained in S607 includes information indicating any one of WPA3, WPA2, WPA, and WEP as the information indicating the security standard of the affiliated AP1. The security strength of the security standards from high to low is WPA3, WPA2, WPA, and WEP, and in this embodiment, the case where the threshold of the security strength of the security standard is set to WPA2 will be described as an example. The threshold related to the security strength of the security standard can be preset to a fixed value or can be changed by the user.
[0064] When it is determined in S701 that the security standard of the affiliated AP1 is WPA2 or WPA3, the controller 402 determines whether the encryption method of the affiliated AP1 is AES (S702). In this embodiment, the information about the security strength obtained in S607 includes information indicating any one of AES, TKIP, and RC4, for example, as the information indicating the encryption method used by the affiliated AP1. The security strength of the encryption methods from high to low is AES, TKIP, and RC4, and in this embodiment, the case where the threshold related to the security strength of the encryption method is set to AES will be described as an example. The threshold related to the security strength of the encryption method can be preset to a fixed value or can be changed by the user.
[0065] When it is determined in S702 that the encryption method of the affiliated AP1 is AES, the controller 402 determines whether the authentication method of the affiliated AP1 is SAE (S703). In this embodiment, the information about the security strength obtained in S607 includes information indicating any one of SAE, PSK, public key authentication, and open system authentication, for example, as the information indicating the authentication method used by the affiliated AP1. The security strength of the authentication methods from high to low is SAE, PSK, public key authentication, and open system authentication, and in this embodiment, the case where the threshold related to the security strength of the authentication method is set to SAE will be described as an example. The threshold related to the security strength of the authentication method can be preset to a fixed value or can be changed by the user.
[0066] When it is determined in S703 that the authentication method of the subordinate AP1 is SAE, the controller 402 determines whether the mode of the subordinate AP1 is enterprise (S704). In the present embodiment, the information on the security strength obtained in S607 includes, for example, "enterprise" indicating that the information is for enterprise or "personal" indicating that the information is for personal, as the information indicating the use of the AP MLD to which the subordinate AP1 belongs. The security strength of the mode is, from high to low, enterprise and personal. In the present embodiment, the case where the threshold related to the security strength of the mode is set to enterprise is described as an example. The threshold related to the security strength of the mode can be preset to a fixed value or can be changed by the user.
[0067] When it is determined in S704 that the mode of the subordinate AP1 is enterprise, the controller 402 determines that the security strength of the subordinate AP1 is higher than the threshold (S705). Thereafter, this process terminates.
[0068] When it is determined in S701 that the security standard of the subordinate AP1 is neither WPA2 nor WPA3, the process proceeds to S706. Also, when it is determined in S702 that the encryption method of the subordinate AP1 is not AES, the process proceeds to S706. Also, when it is determined in S703 that the authentication method of the subordinate AP1 is not SAE, this process proceeds to S706. Further, when it is determined in S704 that the mode of the subordinate AP1 is not enterprise, the process also proceeds to S706. In S706, the controller 402 determines that the security strength of the subordinate AP1 is lower than the threshold. Thereafter, this process terminates. In the present embodiment, the frame received in S606 is also Figure 7 processed as in, and it is determined whether the security strengths of the subordinate AP2 and AP3 are higher than the threshold.
[0069] According to the above embodiment, when the received frame includes the basic multi-link element, a link is established with the subordinate AP among the subordinate AP1, subordinate AP2, and subordinate AP3 (communication unit) whose security strength exceeds the threshold. This enables data communication with a security strength equal to or higher than a certain level.
[0070] In the above embodiment, based on the received frame, it is determined whether the security strength of the subordinate AP that has sent the frame exceeds the threshold. This enables control to establish a link only with the subordinate APs among the subordinate APs that have sent the frame and whose security strength exceeds the threshold.
[0071] In the above embodiment, based on the information indicating the security standard of the relevant subordinate AP included in the received frame, it is determined whether the security strength of the subordinate AP that has sent the frame exceeds the threshold. Therefore, it is possible to easily determine whether the security strength of the subordinate AP that has sent the frame exceeds the threshold based on the security standard of the relevant subordinate AP.
[0072] In the above embodiments, based on the information indicating the encryption method of the relevant subordinate AP included in the received frame, it is determined whether the security strength of the subordinate AP that has sent the frame exceeds a threshold. Therefore, based on the encryption method used by the relevant subordinate AP, it is easy to determine whether the security strength of the subordinate AP that has sent the frame exceeds a threshold.
[0073] In the above embodiments, based on the information indicating the authentication method used by the relevant subordinate AP included in the received frame, it is determined whether the security strength of the subordinate AP that has sent the frame exceeds a threshold. Therefore, based on the authentication method used by the relevant subordinate AP, it is easy to determine whether the security strength of the subordinate AP that has sent the frame exceeds a threshold.
[0074] In the above embodiments, based on the information about the mode indicating the use of the AP to which the relevant subordinate AP belongs included in the received frame, it is determined whether the security strength of the subordinate AP that has sent the frame exceeds a threshold. Therefore, based on the use of the AP to which the relevant subordinate AP belongs, it is easy to determine whether the security strength of the subordinate AP that has sent the frame exceeds a threshold.
[0075] In the above embodiments, when the received frame includes a basic multi-link element, a link is established with two or more subordinate APs among Subordinate AP1, Subordinate AP2, and Subordinate AP3 whose security strength exceeds a threshold. This achieves multi-link communication with a security strength equal to or higher than a certain level.
[0076] In the above embodiments, when the received frame includes a basic multi-link element, a link is established with one subordinate AP among Subordinate AP1, Subordinate AP2, and Subordinate AP3 whose security strength exceeds a threshold. This can prevent multi-link communication that may be very vulnerable.
[0077] In this embodiment, when the number of subordinate APs whose security strength is determined to be higher than the threshold in S608 is 0, a link can be established in S612 with the subordinate AP having the highest security strength among Subordinate AP1, Subordinate AP2, and Subordinate AP3 to which AP 101 belongs.
[0078] In this embodiment, in Figure 7In the process of, the security strength can be determined by the frequency band. For example, when the transmission source of the received frame operates in the 6 GHz frequency band, it is determined that the security strength of the transmission source is higher than the threshold. This is because the security standard of WPA3 is determined to be used in the 6 GHz frequency band. On the other hand, when the transmission source of the received frame operates in a frequency band other than the 5 GHz frequency band, 2.4 GHz frequency band, or 6 GHz frequency band, it is determined that the security level of the transmission source is lower than the threshold. Therefore, based on the frequency band in which the relevant affiliated AP operates, it is easy to determine whether the security strength of the affiliated AP that has sent the frame exceeds the threshold. That is, for example, when two links can be established in the 6 GHz frequency band and one link can be established in the 4 GHz frequency band, the STA selects the two links in the 6 GHz frequency band and establishes a communication connection.
[0079] The criteria for determining a high security strength can be dynamically changed according to the device settings of the STA. For example, when the security strength of the STA can be set from the operation unit of the STA and the device setting of the security strength is set to "high", the threshold of the security strength increases so that communication is established only through the WPA3 link.
[0080] Next, the process of adding a link with AP 101 to the STA 102 that has already established a link with AP 101 will be described.
[0081] Figure 8 It shows Figure 1 Another process flow chart of the link establishment control process performed by the STA 102 in. Figure 8 The link establishment control process in is similar to Figure 6 The link establishment control process in, and the following description will focus on the differences from Figure 6 The link establishment control process in. Similar to the above Figure 6 The link establishment control process in, Figure 8 The link establishment control process in is also implemented by the controller 402 executing the program stored in the storage unit 401. For example, when the STA102 receives a mode change instruction from the user to change the mode from the single-link mode for single-link communication to the multi-link mode, or when it is determined that multi-link communication can be performed due to the surrounding radio wave environment, etc., the Figure 8 Link establishment control process in is executed. Here, as an example, it is assumed that the STA 102 has already established a link with one of the affiliated APs 1, 2, and 3 belonging to the AP 101 (for example, affiliated AP1) in the single-link mode.
[0082] In Figure 8In this case, the process in S801 similar to the process in S601 described above is performed. In this case, the user should specify the subordinate AP1 that operates in the same channel as the subordinate STA 1 with which the link has been established. Next, the processes in S802 to S807 that are the same as the processes in S602 to S607 described above are performed.
[0083] Next, the controller 402 performs the Figure 9 quantity determination process (S808) for determining the number of subordinate APs whose security strength is higher than the threshold value described later. In S808, this process is performed on the frames received in S806, that is, the frames sent from the subordinate APs 2 and 3 other than the subordinate AP1 with which the link has been established.
[0084] When the number of subordinate APs whose security strength is determined to be higher than the threshold value in S808 is two or more, the process proceeds to S809. In S809, the controller 402 establishes links with multiple subordinate APs (that is, the subordinate APs 2 and 3 belonging to the AP 101) whose security strength is determined to be higher than the threshold value in S808. That is, in addition to the already established link with the subordinate AP1, links with the subordinate AP2 and the subordinate AP3 are added. After that, this process terminates.
[0085] When the number of subordinate APs whose security strength is determined to be higher than the threshold value in S808 is 1, the process proceeds to S810. In S810, the controller 402 establishes a link with one subordinate AP whose security strength is determined to be higher than the threshold value among the subordinate APs 2 and 3 belonging to the AP 101 that has sent the frame processed in S808. For example, when it is determined in S808 that the security strength of the subordinate AP2 belonging to the AP 101 is higher than the threshold value, in addition to the already established link with the subordinate AP1, a link with the subordinate AP2 is added. After that, this process terminates.
[0086] When the number of subordinate APs whose security strength is determined to be higher than the threshold value in S808 is 0, the process proceeds to S811. In S811, the controller 402 does not add a link with the AP 101. That is, the establishment of the link with the subordinate AP1 is maintained as it is. At this time, for example, a notification indicating that multi-link communication with the AP 101 has not been performed is displayed on the output unit 405. After that, this process terminates.
[0087] Figure 9 is a flowchart showing the Figure 8 process of the quantity determination process in S808. The quantity determination process in Figure 9 is performed for each frame received in S806 as described above. In this embodiment, as an example, the process for the frame received in S806 and sent from the subordinate AP2 will be described.
[0088] In Figure 9 it, the controller 402 determines whether the security strength of the security standard of the secondary AP2 is equal to or higher than the security strength of the security standard of the secondary AP1 (S901).
[0089] When it is determined in S901 that the security strength of the security standard of the secondary AP2 is equal to or higher than the security strength of the security standard of the secondary AP1, the process proceeds to S902. In S902, the controller 402 determines whether the security strength of the encryption method of the secondary AP2 is equal to or higher than the security strength of the encryption method of the secondary AP1.
[0090] When it is determined in S902 that the security strength of the encryption method of the secondary AP2 is equal to or higher than the security strength of the encryption method of the secondary AP1, the process proceeds to S903. In S903, the controller 402 determines whether the security strength of the authentication method of the secondary AP2 is equal to or higher than the security strength of the authentication method of the secondary AP1.
[0091] When it is determined in S903 that the security strength of the authentication method of the secondary AP2 is equal to or higher than the security strength of the authentication method of the secondary AP1, the process proceeds to S904. In S904, the controller 402 determines whether the security strength of the mode of the secondary AP2 is equal to or higher than the security strength of the mode of the secondary AP1.
[0092] When it is determined in S904 that the security strength of the mode of the secondary AP2 is equal to or higher than the security strength of the mode of the secondary AP1, the controller 402 determines that the security strength of the secondary AP2 exceeds the threshold (S905). Thereafter, this process terminates.
[0093] When it is determined in S901 that the security strength of the security standard of the secondary AP2 is less than the security strength of the security standard of the secondary AP1, the process proceeds to S906. Additionally, when it is determined in S902 that the security strength of the encryption method of the secondary AP2 is less than the security strength of the encryption method of the secondary AP1, the process proceeds to S906. Additionally, when it is determined in S903 that the security strength of the authentication method of the secondary AP2 is less than the security strength of the authentication method of the secondary AP1, the process proceeds to S906. Furthermore, when it is determined in S904 that the security strength of the mode of the secondary AP2 is less than the security strength of the mode of the secondary AP1, the process also proceeds to S906.
[0094] In S906, the controller 402 determines that the security strength of the secondary AP2 is lower than the threshold. Thereafter, this process terminates. In this embodiment, the frame of the secondary AP3 received in S806 is also Figure 8 subjected to the quantity determination process in, and it is determined whether the security strength of the secondary AP3 exceeds the threshold.
[0095] In the above embodiments, a link with an affiliated AP whose security strength exceeds a threshold is additionally established. This achieves multi-link communication with a security strength equal to or higher than a certain level.
[0096] Note that the determination from S901 to S904 above can be made based on a preset threshold in the same way as the quantity determination process in the above Figure 7 , rather than using the security strength of the affiliated AP1 as a benchmark.
[0097] A storage medium recording program code for implementing the above functions can be provided to a system or device, and a computer (CPU or MPU) of the system or device can read and execute the program code stored in the recording medium. In this case, the program code read from the storage medium itself implements the functions of the above embodiments, and the storage medium storing the program code constitutes the above device.
[0098] For example, a floppy disk, hard disk, optical disk, magneto-optical disk, CD-ROM, CD-R, magnetic tape, non-volatile memory card, ROM, DVD, etc. can be used as the storage medium for providing the program code.
[0099] In addition, the above functions can be implemented not only by executing the program code read by the computer, but also by causing the OS operating on the computer to execute part or all of the actual processing based on the instructions of the program code. OS is the abbreviation of operating system.
[0100] Furthermore, the program code read from the storage medium can be written into a memory provided in a function expansion board inserted into the computer or a function expansion unit connected to the computer. Then, based on the instructions of the program code, the CPU provided in the function expansion board or function expansion unit can execute part or all of the actual processing to implement the above functions.
[0101] Other embodiments
[0102] The various embodiments of the present disclosure can also be implemented by a computer of a system or apparatus that reads and executes computer-executable instructions (e.g., one or more programs) recorded on a storage medium (which may also be more fully referred to as a "non-transitory computer-readable storage medium") to perform the functions of one or more of the above-described embodiments and / or includes one or more circuits (e.g., an application specific integrated circuit (ASIC)) for performing the functions of one or more of the above-described embodiments. Moreover, embodiments of the present invention can be implemented by a method of, for example, reading and executing the computer-executable instructions from the storage medium by the computer of the system or apparatus to perform the functions of one or more of the above-described embodiments and / or controlling the one or more circuits to perform the functions of one or more of the above-described embodiments. The computer may include one or more processors (e.g., a central processing unit (CPU), a microprocessing unit (MPU)), and may include a network of separate computers or separate processors to read and execute the computer-executable instructions. The computer-executable instructions may be provided to the computer, for example, from a network or the storage medium. The storage medium may include, for example, a hard disk, a random access memory (RAM), a read-only memory (ROM), the memory of a distributed computing system, an optical disc (such as a compact disc (CD), a digital versatile disc (DVD), or a Blu-ray disc (BD) TM ), a flash device, and one or more of a memory card, etc.
[0103] Embodiments of the present invention can also be implemented by the following method, that is, by providing software (a program) that performs the functions of the above-described embodiments to a system or apparatus via a network or various storage media, and the method of the computer or the central processing unit (CPU), the microprocessing unit (MPU) of the system or apparatus reading and executing the program.
[0104] Although the various embodiments of the present disclosure have been described with reference to exemplary embodiments, it should be understood that the present invention is not limited to the disclosed exemplary embodiments. The scope of the appended claims should be accorded the broadest interpretation so as to cover all such variations and equivalent structures and functions.
[0105] This application claims the benefit of Japanese Patent Application No. 2023-217086, filed on December 22, 2023, the entire contents of which are incorporated herein by reference.
Claims
1. A communication device for wirelessly communicating with a wireless communication device that complies with the IEEE 802.11 series of standards and supports multi-link communication, the communication device comprising: a receiving unit configured to receive a signal including information required for a communication connection for wireless communication from a wireless communication device; as well as a link establishing unit configured to establish a link with the wireless communication device based on the signal, Wherein, when the signal includes predetermined information indicating that the wireless communication device supports multi-link communication, the link establishment unit establishes at least one link with at least one communication unit among a plurality of communication units belonging to the wireless communication device and operating via different frequency channels, the security strength of which meets predetermined conditions.
2. The communication device according to claim 1, further comprising a determination unit configured to determine whether a security strength of a communication unit of the wireless communication device exceeds a threshold value, in, The receiving unit receives a signal from each of the plurality of communication units, and The determination unit determines, based on the signal, whether the security strength of the communication unit that has sent the signal exceeds a threshold.
3. The communication device according to claim 2, wherein: The determination unit determines whether the security strength of the communication unit exceeds a threshold value based on information included in the signal and indicating a security standard of the communication unit that has transmitted the signal.
4. The communication device according to claim 2 or 3, wherein: The determination unit determines whether the security strength of the communication unit exceeds a threshold value based on information included in the signal and indicating an encryption method used by the communication unit that has transmitted the signal.
5. The communication device according to claim 2 or 3, wherein: The determination unit determines whether the security strength of the communication unit exceeds a threshold value based on information included in the signal and indicating an authentication scheme used by the communication unit that has transmitted the signal.
6. The communication device according to claim 2 or 3, wherein: The determination unit determines whether the security strength of the communication unit that has transmitted the signal exceeds a threshold value based on information included in the signal and related to a predetermined pattern indicating a usage of the wireless communication device.
7. The communication device according to claim 2, wherein: The determination unit determines whether the security strength of the communication unit exceeds a threshold value based on information included in the signal and indicating a frequency band in which the communication unit that has transmitted the signal operates.
8. The communication device according to any one of claims 2, 3 and 7, wherein: In a case where the determination unit determines that the security strength of the two or more communication units exceeds a threshold value, the link establishment unit establishes a link with the two or more communication units.
9. The communication device according to any one of claims 2, 3 and 7, wherein: In a case where the determination unit determines that the security strength of one communication unit exceeds a threshold, the link establishment unit establishes a link with the one communication unit.
10. A control method for a communication device, wherein the communication device performs wireless communication with a wireless communication device that complies with the IEEE 802.11 series of standards and supports multi-link communication, the control method comprising: A receiving step of receiving a signal including information required for a communication connection for wireless communication from a wireless communication device; as well as a link establishment step, establishing a link with a wireless communication device based on the signal, Wherein, when the signal includes predetermined information indicating that the wireless communication device supports multi-link communication, at least one link is established in the link establishment step with at least one communication unit among a plurality of communication units belonging to the wireless communication device and operating via different frequency channels and whose security strength meets predetermined conditions. 11 . A computer-readable storage medium storing a program for causing a computer to execute the control method of a communication device according to claim 10 . 12 . A computer program product comprising a program for causing a computer to execute the control method of a communication device according to claim 10 .
Citation Information
Patent Citations
Communication device, control method, and program
JP2018050133A
Communication apparatus, control method, and storage medium
US20180084584A1