Methods, devices, apparatuses, and computer-readable storage media for communication

CN120499644BActive Publication Date: 2026-09-22HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510939028.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-03
Publication Date
2026-09-22
Estimated Expiration
2043-04-03

Smart Images

  • Figure CN120499644B_ABST
    Figure CN120499644B_ABST
Patent Text Reader

Abstract

Exemplary embodiments of the present invention relate to a method, a device, an apparatus and a computer readable storage medium for communication. In some embodiments, a first security frame can be generated, the first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a super block-based time structure, wherein the block-based time structure or the super block-based time structure comprises a plurality of blocks, each of the plurality of blocks comprises a plurality of rounds, each of the plurality of rounds comprises a plurality of time slots, the first security frame is protected by a first nonce, the first nonce is constructed according to identification information associated with the first security frame, a round index and a block index, the round index is an index of the first round, the block index is an index of the first block. Therefore, a security operation can be performed, and it can be guaranteed that the communication is secure.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The original application has the application number 202380070073.5 and the original application date is April 3, 2023. The entire contents of the original application are incorporated herein by reference. Technical Field

[0002] Exemplary embodiments of the present invention generally relate to the field of telecommunications, and more particularly to methods, apparatus, devices and computer-readable storage media for communication. Background Technology

[0003] One of the main objectives of the enhancement is to improve the accuracy of ranging measurements in IEEE 802.15.4z. Block-based or superblock-based time structures can be used for ranging.

[0004] A secure operation called Authenticated Encryption with Associated Data (AEAD) is proposed for ranging. A crucial input to the AEAD operation is a unique random number. However, how to construct this random number requires further investigation. Summary of the Invention

[0005] Overall, exemplary embodiments of the present invention provide a scheme for secure frames in ultra-wideband.

[0006] In a first aspect, a method is provided, comprising: generating a first secure frame, the first secure frame to be transmitted in a time slot within a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, wherein the block-based time structure or the superblock-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, each of the plurality of rounds includes a plurality of time slots, wherein the first secure frame is protected by a first random number constructed based on identification information associated with the first secure frame, a round index, and a block index, the round index being an index of the first round, and the block index being an index of the first block; and transmitting the first secure frame. Therefore, secure operations can be performed, and secure communication can be guaranteed.

[0007] In some examples, the identification information includes a time slot index, which is the index of the time slot in which the first security frame was transmitted. Since the first security frame is transmitted in a specific time slot, the first random number can be used to protect the first security frame.

[0008] In some examples, the first random number includes a first field with a first number of bits, the first field carrying the slot index. In some examples, the first number is determined based on the number of the plurality of slots in each round, or the first number is a first predefined number. Predefining the first number simplifies the agreement between the transmitter and receiver. When the first number is variable, there may be some remaining bits in the first random number, which can be used for other information.

[0009] In some examples, the identification information includes a first packet number (PN), wherein the first PN is the packet number of the first security frame. Since the first PN is specific to the first security frame, a first random number can be used to protect the first security frame.

[0010] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0011] In some examples, the first random number includes: a second field with a second number of bits carrying the round index; and a third field with a third number of bits carrying the block index.

[0012] In some examples, the second quantity is determined based on the number of the plurality of wheels in each block, or the second quantity is a second predefined quantity. In some examples, the third quantity is a third predefined quantity.

[0013] In some examples, the sum of the first quantity, the second quantity, and the third quantity equals a predefined total quantity.

[0014] Therefore, a first random number can be constructed by including identification information, a round index, and a block index. This first random number can then be used to protect the first security frame.

[0015] In some examples, the first random number includes a fourth field with a fourth number of bits, carrying a period index, which is an index of a period comprising multiple blocks, wherein the first block is within the multiple blocks. Therefore, the period index can also be used to construct the first random number, and correspondingly, the security key can be used for a longer period.

[0016] In some examples, the first random number includes a first block indicator that indicates that the first security frame is sent according to the block-based time structure or the superblock-based time structure.

[0017] In some examples, the first security frame includes the block index and the round index. Therefore, the first security frame can include both a block index and a round index, allowing the receiver to correctly construct the random number used to deprotect the device.

[0018] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index. When the block index or round index is a default value, the block index or round index may not be sent, thus reducing signaling overhead.

[0019] In some examples, the first secure frame includes a first security indicator to indicate that the first secure frame is secure. Therefore, the security of a frame can be determined based on the security indicator.

[0020] In some examples, the method further includes: generating a second secure frame to be sent, the second secure frame being protected by a second random number constructed according to a second PN, wherein the second PN is the packet number of the second secure frame; and sending the second secure frame. Therefore, the PN can be used to construct a random number for a frame that is not based on a block-based time structure or a superblock-based time structure.

[0021] In some examples, the second random number includes a field with a predefined number of octet bytes that carries the second PN.

[0022] In some examples, the second random number includes a second block indicator that indicates that the second secure frame is sent outside the block-based time structure or the superblock-based time structure.

[0023] In some examples, the second security frame includes a PN field carrying the second PN.

[0024] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0025] In some examples, the second security frame includes a security payload, wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second timeslot index presence indicator indicating whether a second timeslot index is included.

[0026] In some examples, the secure payload includes the block index if the second block index presence indicator indicates that the second block index is included; the secure payload includes the round index if the second round index presence indicator indicates that the second round index is included; and the secure payload includes the time slot index if the second time slot index presence indicator indicates that the second time slot index is included.

[0027] In some examples, at least one of the second block index presence indicator, the second round index presence indicator, or the second time slot index presence indicator indicates that the corresponding index is not included, and implicitly indicates that the corresponding index is the default index.

[0028] In a second aspect, a method is provided, comprising: receiving a first security frame, the first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, wherein the block-based time structure or the superblock-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, and each of the plurality of rounds includes a plurality of time slots; and deprotecting the first security frame according to a first random number, wherein the first random number is constructed based on identification information associated with the first security frame, a round index, and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0029] In some examples, the identification information includes a time slot index, which is the index of the time slot in which the first security frame was transmitted.

[0030] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the slot index. In some examples, the first number is determined based on the number of the plurality of slots in each round, or the first number is a first predefined number.

[0031] In some examples, the identification information includes a first packet number (PN), wherein the first PN is the packet number of the first secure frame. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0032] In some examples, the first random number includes: a second field with a second number of bits carrying the round index; and a third field with a third number of bits carrying the block index.

[0033] In some examples, the second quantity is determined based on the number of the plurality of wheels in each block, or the second quantity is a second predefined quantity. In some examples, the third quantity is a third predefined quantity.

[0034] In some examples, the sum of the first quantity, the second quantity, and the third quantity equals a predefined total quantity.

[0035] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a periodic index, which is an index of a period comprising a plurality of blocks, wherein the first block is in the plurality of blocks.

[0036] In some examples, the first random number includes a first block indicator that indicates that the first security frame is sent according to the block-based time structure or the superblock-based time structure.

[0037] In some examples, the first security frame includes the block index and carries the round index.

[0038] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0039] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0040] In some examples, the method further includes: receiving a second security frame that is not transmitted according to the block-based time structure or the superblock-based time structure; and deprotecting the second security frame according to a second random number constructed based on a second PN, wherein the second PN is the packet number of the second security frame.

[0041] In some examples, the second random number includes a field with a predefined number of octet bytes that carries the second PN.

[0042] In some examples, the second random number includes a second block indicator that indicates that the second frame is transmitted outside the block-based time structure or the superblock-based time structure.

[0043] In some examples, the second security frame includes a PN field carrying the second PN.

[0044] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0045] In some examples, the second security frame includes a security payload, wherein deprotecting the second security frame includes deprotecting the security payload according to the second random number, and wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second timeslot index presence indicator indicating whether a second timeslot index is included.

[0046] In some examples, the secure payload includes the block index if the second block index presence indicator indicates that the second block index is included; the secure payload includes the round index if the second round index presence indicator indicates that the second round index is included; and the secure payload includes the time slot index if the second time slot index presence indicator indicates that the second time slot index is included.

[0047] In some examples, the method further includes: determining that the corresponding index is a default index based on at least one of the second block index existence indicator, the second round index existence indicator, or the second time slot index existence indicator indicating that the corresponding index is not included.

[0048] In a third aspect, an apparatus is provided, comprising: a generation module for generating a first security frame, the first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, wherein the block-based time structure or the superblock-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, each of the plurality of rounds includes a plurality of time slots, wherein the first security frame is protected by a first random number, the first random number being constructed based on identification information associated with the first security frame, a round index, and a block index, the round index being an index of the first round, and the block index being an index of the first block; and a transmission module for transmitting the first security frame.

[0049] The apparatus may include various modules for implementing the method described in the first aspect, which will not be listed here for the sake of brevity.

[0050] In a fourth aspect, an apparatus is provided, comprising: a receiving module for receiving a first security frame, the first security frame to be transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, wherein the block-based time structure or the superblock-based time structure includes a plurality of blocks, each of the plurality of blocks includes a plurality of rounds, and each of the plurality of rounds includes a plurality of time slots; and a deprotection module for deprotecting the first security frame according to a first random number, wherein the first random number is constructed based on identification information associated with the first security frame, a round index, and a block index, wherein the round index is an index of the first round, and the block index is an index of the first block.

[0051] The apparatus may include various modules for implementing the method described in the first aspect, which will not be listed here for the sake of brevity.

[0052] In a fifth aspect, a method is provided, comprising: generating a first secure frame to be transmitted in a block-based time structure or a superblock-based time structure, wherein the first secure frame is protected by a first random number constructed based on a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being a packet number of the first secure frame; and transmitting the first secure frame.

[0053] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0054] In some examples, the first random number includes: a first field having a first number of bits carrying the first BPN; and a second field having a second number of bits carrying the first PN.

[0055] In some examples, the first security frame includes a first PN field carrying the first PN.

[0056] In some examples, the first security frame indicates the first BPN.

[0057] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0058] In some examples, if the BPN presence indicator indicates that the BPN field is included, then the first security frame includes the BPN field carrying the first BPN.

[0059] In some examples, if the BPN presence indicator indicates that the BPN field is not included, then the first security frame indicates that the first BPN is the default number.

[0060] In some examples, the method further includes storing the first BPN associated with a first communication direction between the initiator and the responder.

[0061] In some examples, the method further includes sending a second security frame that includes a second PN, the second PN being smaller than the PN included in the preceding frame of the third security frame.

[0062] In some examples, the method further includes sending a third security frame that includes a second BPN.

[0063] In a sixth aspect, a method is provided, comprising: receiving a first secure frame transmitted in a block-based time structure or a superblock-based time structure; and deprotecting the first secure frame according to a first random number, wherein the first random number is constructed based on a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being the packet number of the first secure frame.

[0064] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0065] In some examples, the first random number includes: a first field having a first number of bits carrying the first BPN; and a second field having a second number of bits carrying the first PN.

[0066] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0067] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0068] In some examples, if the BPN presence indicator indicates that the BPN field is included, then the first security frame includes the BPN field carrying the first BPN.

[0069] In some examples, if the BPN presence indicator indicates that the BPN field is not included, then the first security frame indicates that the first BPN is the default number.

[0070] In some examples, the method further includes storing the first BPN associated with a first communication direction between the initiator and the responder.

[0071] In some examples, the method further includes: receiving a second security frame that includes a second PN; and updating the first BPN by incrementing by 1 based on the determination that the second PN is less than the PN included in the previous frame of the third security frame.

[0072] In some examples, the method further includes: receiving a third security frame that includes a second BPN; and replacing the first BPN with the second BPN.

[0073] In a seventh aspect, an apparatus is provided, comprising: a generation module for generating a first secure frame to be transmitted in a block-based time structure or a superblock-based time structure, wherein the first secure frame is protected by a first random number constructed based on a first base packet number (BPN) and a first packet number (PN); the first BPN is associated with an initiator and a responder, and the first PN is a packet number of the first secure frame; and a transmission module for transmitting the first secure frame.

[0074] The apparatus may include various modules for implementing the method of the fifth aspect, which will not be listed here for the sake of brevity.

[0075] In an eighth aspect, an apparatus is provided, comprising: a receiving module for receiving a first secure frame transmitted in a block-based time structure or a superblock-based time structure; and a deprotection module for deprotecting the first secure frame according to a first random number, wherein the first random number is constructed based on a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being the packet number of the first secure frame.

[0076] The apparatus may include various modules for implementing the method of the sixth aspect, which will not be listed here for the sake of brevity.

[0077] In a ninth aspect, a communication device is provided, comprising: a processor configured to, together with a transceiver, at least perform the methods described in the first aspect, the second aspect, the fifth aspect, or the sixth aspect.

[0078] In a tenth aspect, a system is provided, comprising: the apparatus described in the third aspect and the apparatus described in the fourth aspect.

[0079] In the eleventh aspect, a system is provided, comprising: the apparatus described in the seventh aspect and the apparatus described in the eighth aspect.

[0080] In a twelfth aspect, a non-transitory computer-readable medium is provided, comprising program instructions for causing an apparatus to perform at least the methods described in the first, second, fifth, or sixth aspects.

[0081] In a thirteenth aspect, a computer program including instructions is provided that, when executed by a device, causes the device to perform at least the method described in the first aspect, the second aspect, the fifth aspect, or the sixth aspect.

[0082] It should be understood that the summary section is not intended to identify key or essential features of the embodiments of the invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description

[0083] Some exemplary embodiments will now be described with reference to the accompanying drawings, in which:

[0084] Figure 1A A schematic diagram of a block-based time structure is shown;

[0085] Figure 1B A schematic diagram of the time structure based on superblocks is shown;

[0086] Figure 1C A schematic diagram of an MMS ranging session is shown;

[0087] Figure 1D A schematic diagram of the compressed PSDU format is shown;

[0088] Figure 1E A schematic diagram of the format of only compressed header IE frames is shown;

[0089] Figure 1F A schematic diagram of the format of random numbers is shown;

[0090] Figure 2A Exemplary communication systems that can implement some embodiments of the present invention are shown;

[0091] Figure 2B Another exemplary communication system that can implement some embodiments of the present invention is shown;

[0092] Figure 3 Signaling diagrams illustrating communication processes are provided, along with some exemplary embodiments of the present invention.

[0093] Figure 4 A schematic diagram of an exemplary NBA-MMS ranging session in a block-based temporal structure provided by some exemplary embodiments of the present invention is shown;

[0094] Figure 5 The diagram illustrates a signaling process for an exemplary MMS ranging session, provided by some exemplary embodiments of the present invention.

[0095] Figure 6A A schematic diagram of the format of the SOR frame provided by some exemplary embodiments of the present invention is shown;

[0096] Figure 6B The illustration shows a schematic diagram of the format for protecting random numbers of frames transmitted in an external block structure, provided by some exemplary embodiments of the present invention.

[0097] Figure 7A A schematic diagram of the format of a POLL frame provided by some exemplary embodiments of the present invention is shown;

[0098] Figure 7B A schematic diagram of the format for protecting random numbers of frames within a block structure, provided by some exemplary embodiments of the present invention, is shown.

[0099] Figure 7C Examples of constructing random numbers for protecting compressed frames are shown, provided by some exemplary embodiments of the present invention;

[0100] Figure 8 A schematic diagram of another format for protecting random numbers within a block structure, provided by some exemplary embodiments of the present invention, is shown.

[0101] Figure 9 A schematic diagram illustrating the format of a secure SOR frame provided by some exemplary embodiments of the present invention is shown;

[0102] Figure 10A An exemplary session between the initiator and the responder 1 provided by some exemplary embodiments of the present invention is illustrated;

[0103] Figure 10B An exemplary session between the initiator and the responder 2 provided by some exemplary embodiments of the present invention is shown;

[0104] Figure 11A The diagram illustrates a time structure including a period provided by some exemplary embodiments of the present invention;

[0105] Figure 11B A schematic diagram illustrating the format of another secure SOR frame provided by some exemplary embodiments of the present invention is shown;

[0106] Figure 11C A schematic diagram of another format for protecting random numbers within a block structure, provided by some exemplary embodiments of the present invention, is shown.

[0107] Figure 12AThe illustration shows a schematic diagram of random number construction based on a superblock time structure provided by some exemplary embodiments of the present invention;

[0108] Figure 12B The illustration shows a schematic diagram of random number construction based on a superblock time structure provided by some exemplary embodiments of the present invention;

[0109] Figure 13 A schematic diagram of another exemplary MMS ranging session in a block-based temporal structure provided by some exemplary embodiments of the present invention is shown;

[0110] Figure 14 The diagram illustrates a signaling process for another exemplary MMS ranging session, provided by some exemplary embodiments of the present invention.

[0111] Figure 15A A schematic diagram illustrating the format of random numbers for protecting frames provided by some exemplary embodiments of the present invention is shown;

[0112] Figure 15B A schematic diagram illustrating another format of random numbers for protecting frames provided by some exemplary embodiments of the present invention is shown;

[0113] Figure 16A A schematic diagram illustrating the format of a secure RPRT frame provided by some exemplary embodiments of the present invention is shown;

[0114] Figure 16B A schematic diagram illustrating the format of an ADV-POLL frame provided by some exemplary embodiments of the present invention is shown;

[0115] Figure 17 The illustration shows exemplary sessions between initiator 1 and responder 2 provided by some exemplary embodiments of the present invention;

[0116] Figure 18 Signaling diagrams illustrating communication processes are provided, along with some exemplary embodiments of the present invention.

[0117] Figure 19 A schematic diagram of an exemplary MMS ranging session provided by some exemplary embodiments of the present invention is shown;

[0118] Figure 20 The diagram illustrates a signaling process for an exemplary MMS ranging session, provided by some exemplary embodiments of the present invention.

[0119] Figure 21A A schematic diagram illustrating the format of a security frame during the initialization and setup phases provided by some exemplary embodiments of the present invention is shown;

[0120] Figure 21BA schematic diagram illustrating the format of a security frame during a measurement period provided by some exemplary embodiments of the present invention is shown;

[0121] Figure 21C A schematic diagram illustrating the format of a secure SOR frame provided by some exemplary embodiments of the present invention is shown;

[0122] Figure 21D A schematic diagram illustrating the format of a secure PRM-REQ or PRM-RESP frame provided by some exemplary embodiments of the present invention is shown.

[0123] Figure 21E A schematic diagram illustrating the format of random numbers provided by some exemplary embodiments of the present invention is shown;

[0124] Figure 22A The illustration shows an exemplary downlink session from the initiator to the responder 1 provided by some exemplary embodiments of the present invention;

[0125] Figure 22B The illustration shows an exemplary uplink session from responder 2 to initiator provided by some exemplary embodiments of the present invention;

[0126] Figure 23 Exemplary block diagrams of communication devices provided by some embodiments of the present invention are shown;

[0127] Figure 24 An exemplary block diagram of another communication device provided by some embodiments of the present invention is shown;

[0128] Figure 25 A schematic block diagram of a device that can be used to implement some embodiments of the present invention is shown.

[0129] In all the accompanying drawings, the same or similar reference numerals denote the same or similar elements. Detailed Implementation

[0130] The principles of the invention will now be described with reference to some exemplary embodiments. It should be understood that these embodiments are described merely for illustrative purposes and to assist those skilled in the art in understanding and implementing the invention, and do not impose any limitation on the scope of the invention. The disclosure described herein can be implemented in various ways other than those described below.

[0131] Ultra-wideband (UWB) technology has been used for indoor positioning and other location services, such as access control and asset location. In addition to dedicated equipment and tags, UWB radios are becoming increasingly common in high-end smartphones. A working group is currently working on enhancing UWB technology.

[0132] UWB technology has been used in various scenarios, such as device-free sensing, downlink time difference of arrival (DL-TDOA), and long-range ranging. Multi-millisecond (MMS) ranging has been introduced to address long-range ranging scenarios. The key idea behind MMS ranging is to distribute UWB ranging frames into multiple segments, each transmitted over multiple milliseconds (ms), thus overcoming the 37 nJ / ms transmit energy limit. Narrowband-assisted (NBA) MMS ranging can be seen as an enhancement of MMS ranging, proposed by high-performance narrowband (NB) radios used to provide time synchronization for UWB radios and for control signaling. In MMS ranging, the number of segments required for ranging depends on the range to be measured and the channel conditions, and can therefore be dynamically adjusted even within the same ranging session.

[0133] Figure 1A A schematic diagram of a block-based time structure 110 is shown. (As shown...) Figure 1A As shown, each block comprises multiple wheels, and each wheel comprises multiple time slots. The block-based time structure 110 can be used for block-based ranging patterns. The block-based pattern can use a structured timeline, where the block-based time structure 110 is periodic by default. In some examples, a block may also be called a ranging block, a wheel may also be called a ranging wheel, and a time slot may also be called a ranging time slot.

[0134] A ranging wheel is a time interval with sufficient duration to complete a full distance measurement cycle involving the ERDEV set participating in ranging exchanges. A ranging time slot is a time interval with sufficient duration to transmit at least one frame. For example... Figure 1A As shown, the start of a frame can be aligned with the start of a time slot, or a transmission offset can be applied from the start of a time slot to the start of a frame.

[0135] The block-based time structure 110 can be predetermined and remains unchanged during the ranging session. It should be understood that the block-based time structure 110 may not be suitable for NBA-MMS ranging scenarios, where the wheel duration can change dynamically.

[0136] Figure 1B A schematic diagram of a superblock-based time structure 120 is shown. (As shown...) Figure 1B As shown, each superblock comprises multiple blocks. Different blocks within a superblock can have different configurations, such as block duration, round duration, slot duration, number of rounds in a block, and number of slots in a round. For example, Figure 1BThe superblock K in the equation includes block 0, block 1, and block 2, where block 0 includes 2 wheels, block 1 includes 7 wheels, and block 2 includes 3 wheels.

[0137] In some examples, different blocks within a superblock can be used for different purposes. For instance, block 0 can be used for DL-TDOA, block 1 for ranging, and block 2 for sensing. In other examples, different blocks within a superblock can be used for different scenarios within the same purpose. For example, blocks 0, 1, and 2 are all used for NBA-MMS ranging, but block 1 can be used for one-to-one ranging in good channel conditions, block 0 for one-to-many ranging, and block 2 for one-to-one ranging in poor channel conditions, etc.

[0138] Figure 1C A schematic diagram of an MMS ranging session 130 is shown. The MMS ranging session 130 includes an initialization and setup phase 131 and one or more measurement cycles 132. The MMS ranging session 130 involves an initiator and a responder. It should be understood that the initiator can be a device that initiates UWB exchange by sending a first message, while the responder can be a device that receives and responds to the first message from the initiator.

[0139] In some examples, frames are transmitted in the initialization channel during the initialization and setup phase 131, and in the ranging channel during one or more measurement periods 132. In some examples, the same channel can be used, for example, a well-known channel can be used as both the initialization channel and the ranging channel.

[0140] During the initialization and setup phase 131, the initiator and responder can negotiate the ranging configuration. Specifically, the initiator opportunistically sends Advertisement Polling (ADV-POLL) frames at its own discretion and intervals. If the responder intends to participate in the ranging session with the initiator, the responder can opportunistically listen for incoming ADV-POLL frames and respond with an Advertisement Response (ADV-RESP) frame. Once the initiator receives an ADV-RESP frame, it sends a start of ranging (SOR) frame, which provides the time offset for the start of the first measurement cycle.

[0141] The measurement cycle, also known as the distance measurement cycle, includes a control phase, a ranging phase, and an optional measurement reporting phase. The control phase (or ranging control phase) begins at the start of the distance measurement cycle. The initiator initiates the ranging control phase by sending a POLL frame to the responder at the beginning of the first ranging time slot of the ranging wheel. Upon receiving the POLL frame, the responder successfully sends a RESP frame back to the initiator. The POLL and RESP frames enable time and frequency synchronization between the initiator and the responder. In some examples, other control information may also be included in the POLL frame.

[0142] During the ranging phase, the initiator and responder can exchange zero or more UWB ranging sequence fragments (RSFs) and, optionally, one or more UWB ranging integrity fragments (RIFs). RSFs are used to perform ranging measurements, while RIFs are used to check the integrity of the ranging measurements.

[0143] The measurement report phase can begin after the initiator or responder has completed receiving all UWB segments from the ranging phase. During the measurement report phase, the initiator or responder can generate a ranging measurement report and send a ranging packet report (RPRT) frame carrying the measurement report to the peer device.

[0144] Frames in the control phase and the ranging phase are transmitted using UWB for MMS ranging. Frames in the control phase are transmitted using NB, and frames in the ranging phase are transmitted using UWB for NBA-MMS ranging.

[0145] To provide more space for the information carried in the frame, the Compressed Physical (PHY) Service Data Unit (PSDU) was introduced. Figure 1D A schematic diagram of the compressed PSDU 140 format is shown. Compressed PSDU 140 can be used in NB control frames. For example... Figure 1D As shown, the compressed PSDU 140 includes an identifier (ID) field with 1 octet, an address field with 2 octets, a payload field with variable length, and a cyclic redundancy check (CRC) field with 2 octets.

[0146] Similarly, compressed header element (IE) frames were also introduced. Figure 1E This diagram illustrates the format of IE frame 150 with only a compressed header. IE frame 150 with only a compressed header can be used for broadcast traffic. Figure 1E As shown, the compressed header IE frame 150 includes a frame control field with one or two octets, an address field with two octets, a header IE message ID field with one octet, a payload field with a variable length, and a CRC field with two octets.

[0147] Compressed PSDU 140 or header-only IE frame 150 can be carried in the 802.15.4ab physical protocol data unit (PPDU). A traditional 802.15.4 frame carried in the 802.15.4ab physical protocol data unit (PPDU) can also be used for MMS ranging, and this frame may not carry the auxiliary security header field (and therefore, the frame counter field).

[0148] As described above, AEAD secure operations are proposed. AEAD secure operations utilize a counter-mode encryption and an extension of the cipher block chain message authentication code. In addition to the security key, a crucial input to each AEAD secure operation is a unique random number. Figure 1F A schematic diagram of the format of random number 160 is shown. Random number 160 can be used in time-slotted channel hopping (TSCH) mode. Figure 1F As shown, random number 160 includes a source address field with 8 octets, a frame counter field with 4 octets, and a random number security level field with 1 octet.

[0149] If the AEAD security operation is applied to compressed PSDU or only compressed header IE frames, or 802.15.4 frames that do not carry a frame counter field, then further investigation should be conducted into how to construct random numbers.

[0150] This invention provides a scheme for secure frames in ultra-wideband (UWB). In some embodiments, secure frames can be generated based on random numbers, wherein the random numbers are constructed based on identification information associated with the secure frame, block indices associated with the rounds and blocks in which the first secure frame is sent, and round indices. Therefore, secure operations can be performed, and secure communication can be guaranteed. The principles and implementation of this invention will be described in detail below with reference to the accompanying drawings.

[0151] Figure 2A An exemplary communication system 200 is shown that can implement some embodiments of the present invention. The communication system 200 includes a controller 210, a controller 220-1, and a controller 220-2, wherein the controllers 220-1 and 220-2 may be collectively referred to as controller 220 or individually.

[0152] In this invention, controller 210 may be a device that controls UWB sessions and defines session parameters, and controller 220 may be a device that participates in UWB sessions using session parameters received from controller 210.

[0153] A UWB session can also be called a UWB exchange. When participating in a UWB session, the controller 210 can be the initiator and the controller 220 can be the responder, or the controller 220 can be the initiator and the controller 210 can be the responder.

[0154] Figure 2B Another exemplary communication system 250 is shown that can implement some embodiments of the present invention. The communication system 250 includes an initiator 260, a responder 270-1, and a responder 270-2, wherein responders 270-1 and 270-2 may be collectively referred to as responder 270 or individually.

[0155] In this invention, the initiator 260 can be a device that follows one or more instructions from the controller. The initiator 260 can initiate a UWB exchange by sending a first exchange message to the responder 270. The responder 270 can be a device that responds to the first message received from the initiator 260 and participates in the UWB exchange.

[0156] In system 250, the link from initiator 260 to responder 270 is called a downlink (DL), and the link from responder 270 to initiator 260 is called an uplink (UL). In the downlink, initiator 260 is a transmitting (TX) device (or transmitter), and responder 270 is a receiving (RX) device (or receiver). In the uplink, responder 270 is a transmitting (TX) device (or transmitter), and initiator 260 is an RX device (or receiver).

[0157] It should be understood that the controller or the controlled party can be the initiator 260; similarly, the controlled party or the controller can be the responder 270. As a specific example, the initiator 260 is the controller 210, the responder 270-1 is the controlled party 220-1, and the responder 270-2 is the controlled party 220-2. However, it should be understood that this is for illustrative purposes only and does not impose any limitation on the scope of protection.

[0158] The device in this invention, for example Figure 2A The controller 210 or the controller 220 or Figure 2B The initiator 260 or responder 270 can be a tag, mobile device, remote key, vehicle, door lock, etc. Among them, the mobile device can include, but is not limited to, smartphones, personal digital assistants (PDAs), laptops, tablets, wearable devices, Internet of Things (IoT) devices, vehicle to everything (V2X) devices, etc.

[0159] It should be understood that Figure 2A and Figure 2B The number of devices, their connections, and types shown are for illustrative purposes only and do not represent any limitation. System 200 or 250 may include any suitable number of devices adapted to implement embodiments of the present invention.

[0160] Further reference Figure 3 The diagram illustrates a signaling process 300, provided by some exemplary embodiments of the present invention. Process 300 may involve a transmitter 301 and a receiver 302. It should be understood that, see [link to documentation]. Figure 2A The transmitter 301 can be either the controller 210 or the controlled device 220, and the receiver 302 can be either the controlled device 220 or the controller 210. It should be understood that... (See also...) Figure 2B The transmitter 301 can be either the initiator 260 or the responder 270, and the receiver 302 can be either the responder 270 or the initiator 260.

[0161] Transmitter 301 generates (310) a first secure frame. The first secure frame is transmitted in a time slot (e.g., a first time slot) in a first round, wherein the first round is in a first block. A block-based time structure or a superblock-based time structure may be used, wherein each block includes multiple rounds, and each round includes multiple time slots. In some examples, in the case of a block-based time structure, different blocks include the same number of rounds, and different rounds include the same number of time slots. In other examples, in the case of a superblock-based time structure, different blocks may include the same number of rounds or different numbers of rounds, and different numbers of rounds may include the same number of time slots or different numbers of time slots. The first secure frame may be protected by a first random number, wherein the first random number is constructed based on identification information, a round index, and a block index associated with the first secure frame, wherein the round index is an index of the first round, and the block index is an index of the first block. In some embodiments, transmitter 301 may construct the first random number and then generate the first secure frame. In some examples, the identification information associated with the first secure frame may include a time slot index or a first PN, which will be described in detail below.

[0162] In some exemplary embodiments, a first security frame may be transmitted during a measurement period. In some examples, the first random number is constructed based on a slot index, a round index, and a block index. For example, the identification information includes a slot index. The slot index is the index of the first slot in which the first security frame is transmitted, the round index is the index of the first round to which the first slot belongs, and the block index is the index of the first block to which the first round belongs.

[0163] The first random number may include a first field carrying the time slot index, a second field carrying the round index, and a third field carrying the block index. The length of the first field can be equal to the first quantity, the length of the second field can be equal to the second quantity, and the length of the third field can be equal to the third quantity.

[0164] In some examples, the first quantity can be a predefined quantity, such as 8 bits, 10 bits, or other values. In some examples, the first quantity can be determined by the position of the start bit and the position of the end bit. For example, the positions of the start and end bits of the first field can be predefined. In other examples, the first quantity can be associated with the length of the first round (e.g., the number of time slots in the first round). For example, the first quantity can be... bits, where It is an integer, which can be determined by equation (1): (1) in, Refers to variables The upper limit function, i.e., not less than (≥) The smallest integer, the "wheel duration" in equation (1) refers to the time length of the first wheel, the "time slot duration" in equation (1) refers to the time length of the first time slot, the smallest integer in equation (1) refers to ...2) refers to the smallest integer in equation (3) refers to the smallest integer in equation (4) refers to the smallest integer in equation (5) refers to the smallest integer in equation (6) refers to the This is the number of time slots per round (denoted as "NumSlots"). For example, the position of the start bit of the first field can be predefined, and the position of the end bit of the first field can be determined based on... Sure.

[0165] In some examples, the second quantity can be a second predefined quantity, such as 15 bits, 13 bits, or other values. In some examples, the second quantity can be determined by the position of the start bit and the position of the end bit. For example, the positions of the start and end bits of the second field can be predefined. In other examples, the second quantity can be associated with the length of the first block (e.g., the number of rounds in the first block). For example, the second quantity can be... bits, where It is an integer, which can be determined by equation (2): (2) In equation (2), "wheel duration" refers to the time length of the first wheel, and "block duration" refers to the time length of the first block. This refers to the number of rounds per block (denoted as "NumRounds"). For example, the starting bit of the second field can be the bit after the first field, and the ending bit of the second field can be determined based on... Sure.

[0166] In some examples, the third quantity can be a predefined third quantity, such as 16 bits, 18 bits, or other values. In other examples, the third quantity can be determined based on at least one of the first and second quantities. For example, the sum of the first, second, and third quantities can equal a predefined total quantity, so the third quantity can be determined based on the predefined total quantity, the first quantity, and the second quantity. For example, the predefined total quantity can be 39 bits, 35 bits, or other values. Alternatively, the combination of the first, second, and third fields can be considered as a frame counter field, for example, with a length equal to the predefined total quantity.

[0167] In the first random number, the first field, the second field, and the third field can be consecutive, for example, the second field follows the first field, and the third field follows the second field. However, it should be understood that the present invention does not limit this aspect. For example, there can be one or more reserved bits or one or more other fields between the first field and the second field, such as the third field being located before the first field, etc. The present invention will not list them all here.

[0168] Additionally, the first random number may include a fourth field carrying a period index. The length of the fourth field may be equal to the fourth quantity. In this invention, a new period may be defined, wherein a period comprises one or more blocks. The period index is the index of the period that includes the first block. In some examples, the fourth quantity may be a fourth predefined quantity, such as 6 bits, 7 bits, 8 bits, or other values. In other examples, the fourth quantity may be determined based on at least one of the first, second, and third quantities. For example, the sum of the first, second, third, and fourth quantities may be equal to a predefined total quantity, and therefore the fourth quantity may be determined based on the predefined total quantity, the first quantity, the second quantity, and the third quantity. Alternatively, the combination of the first, second, third, and fourth fields may be considered as a frame counter field, for example, with a length equal to the predefined total quantity.

[0169] The first random number includes a first block indicator, which may indicate that the first secure frame is transmitted based on a block-based time structure or a superblock-based time structure. For example, the first random number may include a field carrying the first block indicator, such as a block indicator field. In some examples, the term "block-based time structure or superblock-based time structure" may be referred to as "internal block structure." The term "internal block structure" may refer to a time period known to both the transmitter 301 and the receiver 302 regarding the block-based or superblock-based time structure. The length of the field carrying the first block indicator may be predefined, such as 1 bit, 2 bits, or other values. If the first block indicator equals a first value, it may indicate that the first secure frame is within an internal block structure. For example, the first value may be 1 or 0. In some examples, the field carrying the first block indicator may be located at a predefined position in the first random number, such as at the end of the first random number.

[0170] The first random number includes a source address. For example, the first random number may include a field carrying the source address, such as a source address field. The length of the field carrying the source address can be predefined, such as 8 octets, 10 octets, or other values. The field carrying the source address can be located at a predefined position in the first random number, such as before the first random number. The source address can be an extended address of the device initiating the first secure frame, i.e., the address of transmitter 301.

[0171] In some exemplary embodiments, a first security frame may be sent during the measurement period. As some examples, the first security frame may be any of the following: security POLL, security RESP, or security RPRT.

[0172] The first secure frame may include a first block index presence indicator and a first round index presence indicator. The first block index presence indicator indicates whether a block index exists in the first secure frame. The first round index presence indicator indicates whether a round index exists in the first secure frame. For example, the first block index presence indicator may be equal to a first value to indicate the presence of a block index in the first secure frame, or equal to a second value to indicate the absence of a block index in the first secure frame. Similarly, the first round index presence indicator may be equal to a first value to indicate the presence of a round index in the first secure frame, or equal to a second value to indicate the absence of a round index in the first secure frame. The first value may be 1 and the second value may be 0, or the first value may be 0 and the second value may be 1.

[0173] For example, the first security frame may include a first block index presence field carrying a first block index presence indicator and a first round index presence field carrying a first round index presence indicator. Alternatively, the first security frame may include an presence control field (with a predefined length, such as 1 octet) that includes the first block index presence field and the first round index presence field. In some examples, the length of the first block index presence field may be 1 bit, 2 bits, or other values, and the length of the first round index presence field may be 1 bit, 2 bits, or other values.

[0174] The first security frame may include a block index. For example, if a first block index presence indicator indicates the existence of a block index, such as the first block index presence indicator being equal to a first value, the first security frame may include a first block index field carrying the block index. Alternatively, the length of the first block index field may be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the first block index presence indicator is equal to a second value, then the first block index field is not included, i.e., the length of the first block index field is 0.

[0175] The first security frame may include a round index. For example, if a first round index existence indicator indicates the existence of a round index, such as the first round index existence indicator being equal to a first value. The first security frame may also include a first block index field carrying a block index. Alternatively, the length of the first round index field may be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the first round index existence indicator is equal to a second value, then the first round index field is not included; that is, the length of the first round index field is 0.

[0176] Alternatively, the first security frame may include an open payload that includes a first block index existence field, a first round index existence field, a first block index field (if present), and a first round index field (if present).

[0177] The first security frame may include a first security indicator. For example, the first security frame may include a field carrying the first security indicator, such as a security indicator field. The first security indicator may indicate that the first security frame is secure. For example, the length of the field carrying the first security indicator may be predefined, such as 1 bit, 2 bits, or other values.

[0178] The first security frame may also include one or more of the following: a field carrying an ID, a field carrying an address, a field carrying a security payload, and a field carrying a message integrity check (MIC). The security payload in the first security frame can be generated based on a first random number. In some examples, a security key may be used to generate the security payload in the first security frame.

[0179] Transmitter 301 sends (320) a first secure frame 322 to receiver 302. Receiver 302 receives (324) the first secure frame 322. Receiver 302 deprotects the first secure frame 322 (330). Specifically, receiver 302 deprotects the first secure frame 322 by using a random number constructed based on the round index and block index.

[0180] It should be understood that the standard for constructing random numbers by the transmitter 301 and the receiver 302 should be consistent; that is, the random number constructed by the receiver 302 should be the same as the first random number constructed by the transmitter 301 for protecting the first security frame. If the random number constructed by the receiver 302 is different from the first random number constructed by the transmitter 301 for protecting the first security frame, the attempt to deprotect the first security frame will fail.

[0181] In some embodiments, receiver 302 may construct a first random number and then deprotect the first security frame 322. The first random number constructed by receiver 302 is similar to the random number described above (i.e., the random number constructed by the transmitter), and will not be described in detail for the sake of brevity.

[0182] As previously described, the first random number may include three fields, carrying the slot index, round index, and block index, respectively. In other examples, the first random number may include two fields, one carrying one of the slot index, round index, and block index, and the other carrying a combination of the other two of the slot index, round index, and block index. For example, one field of the first random number carries the slot index, and the other field carries a function of the round index and the block index. In some other examples, the first random number may include a field carrying a value (e.g., a frame counter (FC)) that is a function of the slot index, round index, and block index. It should be understood that the first random number can also be determined based on the slot index, round index, and block index in other ways, and the present invention is not limited in this respect.

[0183] Furthermore, transmitter 301 can generate a second secure frame. This second secure frame will not be transmitted according to a block-based or superblock-based time structure; that is, it will be transmitted in a non-block-based or non-superblock-based time structure or other structure. In some examples, the terms "non-block-based time structure" or "non-block-based time structure" or "non-superblock-based time structure" may be referred to as "external block structure." The term "external block structure" may refer to a time period where the block-based or superblock-based time structure is unknown to either transmitter 301 or receiver 302.

[0184] The second secure frame may be protected by a second random number, wherein the second random number is constructed based on a second packet number (PN), which is the packet number of the second secure frame. In some embodiments, the transmitter 301 may construct the second random number and then generate the second secure frame.

[0185] In some examples, the second random number may include a field carrying a second PN. The length of the field carrying the second PN can be equal to a predefined number, such as 4 octets, 3 octets, or other values.

[0186] The second random number includes a field carrying a second block indicator, which can indicate that the second secure frame is sent in the outer block structure. The length of the field carrying the second block indicator can be predefined, such as 1 bit, 2 bits, or other values. If the second block indicator equals a second value, it indicates that the second secure frame is in the outer block structure. For example, the second value can be different from the first value of the first block indicator that indicates the first secure frame is in the inner block structure. For example, the first value is 1, and the second value is 0. Or, for example, the first value is 0, and the second value is 1. In some examples, the field carrying the second block indicator can be located at a predefined position in the second random number, such as at the end of the second random number.

[0187] The second random number includes a field carrying the source address. The length of this field can be predefined, such as 8 octets, 7 octets, or other values. The field carrying the source address can be located at a predefined position within the second random number, such as before it. The source address can be an extended address of the device initiating the second secure frame, i.e., the address of transmitter 301.

[0188] In some exemplary embodiments, the second security frame may be sent during the initialization and setup phases. As examples, the second security frame may be either a security ADV-RESP or a security SOR.

[0189] The second security frame may include a PN field carrying a second PN. The length of the PN field in the second security frame may be predefined, such as 4 octets, 3 octets, or other values.

[0190] The second security frame may include a field carrying a second security indicator. The second security indicator can indicate that the second security frame is secure. For example, the length of the field carrying the second security indicator can be predefined, such as 1 bit, 2 bits, or other values.

[0191] The second security frame may also include one or more of the following: a field carrying an ID, a field carrying an address, a field carrying a security level, a field carrying a security payload, and a field carrying a MIC. The security payload in the second security frame can be generated based on a second random number. In some examples, a security key can be used to generate the security payload in the second security frame.

[0192] In some examples, the security payload may include a second-block index existence field carrying a second-block index existence indicator, a second-round index existence field carrying a second-round index existence indicator, and a second-timeslot index existence field carrying a second-timeslot index existence indicator. The second-block index existence indicator can indicate whether a second-block index field exists. The second-round index existence indicator can indicate whether a second-round index field exists. The second-timeslot index existence indicator can indicate whether a second-timeslot index field exists.

[0193] For example, the second block index presence indicator equals a first value to indicate the presence of a second block index field in the secure payload, or equals a second value to indicate the absence of a second block index field in the secure payload. Similarly, the second round index presence indicator equals a first value to indicate the presence of a second round index field in the secure payload, or equals a second value to indicate the absence of a second round index field in the secure payload. For example, the second time slot index presence indicator equals a first value to indicate the presence of a second time slot index field in the secure payload, or equals a second value to indicate the absence of a second time slot index field in the secure payload. The first value is 1 and the second value is 0, or the first value is 0 and the second value is 1. Alternatively, the secure payload may include an presence control field (with a predefined length, such as 1 octet) that includes the second block index presence field, the second round index presence field, and the second time slot index presence field. In some examples, the length of the second block index presence field can be 1 bit, 2 bits, or other values; the length of the second round index presence field can be 1 bit, 2 bits, or other values; and the length of the second time slot index presence field can be 1 bit, 2 bits, or other values.

[0194] The security payload may include a second block index field carrying the block index. For example, if a second block index existence indicator in the second block index existence field indicates the existence of the second block index field, such as if the second block index existence indicator is equal to a first value, then a second block index field carrying the block index exists. Alternatively, the length of the second block index field can be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the second block index existence indicator is equal to a second value, i.e., the length of the second block index field is 0, then the second block index field is not included.

[0195] The security payload may include a second-round index field carrying the round index. For example, if a second-round index existence indicator in the second-round index existence field indicates the existence of the second-round index field, such as if the second-round index existence indicator equals a first value, then a second-round index field carrying the round index exists. Alternatively, the length of the second-round index field can be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the second-round index existence indicator equals a second value, i.e., the length of the second-round index field is 0, then the second-round index field is not included.

[0196] The security payload may include a second time slot index field carrying a time slot index. For example, if a second time slot index presence indicator in the second time slot index presence field indicates the presence of the second time slot index field, such as if the second time slot index presence indicator is equal to a first value, then a second time slot index field carrying a time slot index exists. Alternatively, the length of the second time slot index field can be predefined, such as 2 octets, 15 bits, or other values. It should be understood that if the second time slot index presence indicator is equal to a second value, i.e., the length of the second time slot index field is 0, then the second time slot index field is not included.

[0197] Transmitter 301 sends a second security frame to receiver 302. Receiver 302 receives the second security frame. Receiver 302 deprotects the second security frame. Specifically, receiver 302 deprotects the second security frame by generating a random number based on the second PN.

[0198] As described above, the standard for constructing random numbers by the transmitter 301 and the receiver 302 should be consistent; that is, the random number constructed by the receiver 302 should be the same as the second random number constructed by the transmitter 301 for protecting the second security frame. If the random number constructed by the receiver 302 for deprotecting the second security frame is different from the random number constructed by the transmitter 301 for protecting the second security frame, the deprotection of the second security frame will fail.

[0199] In some embodiments, receiver 302 may construct a second random number and then deprotect the second security frame. The second random number constructed by receiver 302 is similar to the random number described above (i.e., the random number constructed by the transmitter), and will not be described in detail for the sake of brevity.

[0200] When receiver 302 deprotects the second security frame, it can obtain information from the security payload of the second security frame. In some examples, if a second block index field, a second round index field, and a second time slot index field are included, the carried block index, round index, and time slot index can be obtained by receiver 302. In other examples, if at least one of the second block index field, the second round index field, and the second time slot index field is not included, receiver 302 can determine the corresponding index itself. For example, if the second block index field is not included in the security payload, receiver 302 can determine the block index as a default value, such as block index 0. Therefore, if the index is a default value (e.g., 0), it does not need to be included in the security payload, thus saving signaling overhead.

[0201] According to some embodiments described above, different random numbers can be used to protect frames during the initialization and setup phases and during the measurement period. Specifically, PN can be used to construct random numbers for protecting frames transmitted in the "outer block structure," and slot index, round index, and block index can be used to construct random numbers for protecting frames transmitted in the "inner block structure."

[0202] In some other exemplary embodiments, the first security frame generated by transmitter 301 at 310 may be transmitted during the initialization and setup phase or during the measurement period. Specifically, a block-based time structure or a superblock-based time structure may be established before or at the start of the initialization and setup phase. In this case, the frame transmitted during the initialization and setup phase is also within a block-based time structure or a superblock-based time structure.

[0203] The first random number used to protect the first secure frame is constructed based on the block index, round index, and first PN. The round index is the index of the first round in which the first secure frame was sent, and the block index is the index of the first block to which the first round belongs. The first PN is the packet number of the first secure frame. That is, the first PN is used to uniquely identify the first secure frame.

[0204] The first random number may include a first field carrying the first PN, a second field carrying the round index, and a third field carrying the block index. The length of the first field can be equal to the first quantity, the length of the second field can be equal to the second quantity, and the length of the third field can be equal to the third quantity.

[0205] In some examples, the first quantity can be a predefined quantity, such as 8 bits, 7 bits, or other values. In some examples, the first quantity can be determined by the position of the start bit and the position of the end bit. For example, the positions of the start bit and the end bit of the first field can be predefined.

[0206] In some examples, the second quantity can be a second predefined quantity, such as 15 bits, 16 bits, or other values. In some examples, the second quantity can be determined by the position of the start bit and the position of the end bit. For example, the positions of the start and end bits of the second field can be predefined. In other examples, the second quantity can be associated with the length of the first block (e.g., the number of rounds in the first block). For example, the second quantity can be... bits, where It is an integer, which can be determined by the above equation (2).

[0207] In some examples, the third quantity can be a predefined third quantity, such as 16 bits, 17 bits, or other values. In other examples, the third quantity can be determined based on at least one of the first and second quantities. For example, the sum of the first, second, and third quantities can equal a predefined total quantity, so the third quantity can be determined based on the predefined total quantity, the first quantity, and the second quantity. For example, the predefined total quantity can be 40 bits, 39 bits, or other values. Alternatively, the combination of the first, second, and third fields can be considered as a frame counter field, for example, with a length equal to the predefined total quantity.

[0208] In the first random number, the first field, the second field, and the third field can be consecutive, for example, the second field follows the first field, and the third field follows the second field. However, it should be understood that the present invention does not limit this aspect. For example, there can be one or more reserved bits between the first field and the second field, or the third field can be located before the first field. The present invention will not list them all here.

[0209] The first random number includes a field carrying the source address. The length of this field can be predefined, such as 8 octets, 7 octets, or other values. The field carrying the source address can be located in a predefined position within the first random number, such as before it. The source address can be an extended address of the device initiating the first secure frame, i.e., the address of transmitter 301.

[0210] Similarly, transmitter 301 transmits (320) a first secure frame 322, which is protected by a first random number constructed based on a first PN, a round index, and a block index. Receiver 302 may receive (324) the first secure frame 322. Receiver 302 deprotects the first secure frame 322 (330). Specifically, receiver 302 may construct a first random number based on the first PN, a round index, and a block index, and use the first random number to deprotect the first secure frame 322.

[0211] As previously described, the first random number may include three fields, carrying a first PN, a round index, and a block index, respectively. In other examples, the first random number may include two fields: one carrying one of the first PN, the round index, and the block index, and the other carrying a combination of the other two of the first PN, the round index, and the block index. For example, one field of the first random number carries the first PN, and the other field carries a function of the round index and the block index. In some other examples, the first random number may include a field carrying a value (e.g., a frame counter (FC)) that is a function of the first PN, the round index, and the block index. It should be understood that the first random number may also be determined based on the first PN, the round index, and the block index in other ways, and the present invention is not limited in this respect.

[0212] According to some embodiments described above, when a block-based time structure or a superblock-based time structure can be established before or at the start of the initialization and setup phases, PN, round index, and block index can be used to construct random numbers for protecting frames.

[0213] The above embodiments have described that the identification information associated with the first security frame may include a time slot index or a first PN. In some other examples, the identification information associated with the first security frame may include a time slot index and a first PN. In some other examples, the identification information associated with the first security frame may include a parameter or value specific to the first security frame (or unique to the first security frame). The present invention does not limit this aspect.

[0214] In this invention, the security frame is generated by protecting a compressed frame, which can be a compressed PSDU frame or a frame with the IE format of the compression header described above. Alternatively, the security frame can be generated by protecting an 802.15.4 frame that does not carry a frame counter field. Security operations can be performed using cryptographic operations such as authentication or encryption.

[0215] Figure 4 A schematic diagram of an exemplary MMS ranging session 400 in a block-based temporal structure provided by some exemplary embodiments of the present invention is shown. Figure 4 As shown, the MMS ranging session 400 includes an initialization and setup phase 401, followed by one or more measurement cycles 402.

[0216] During the initialization and setup phase 401, the responder may not be aware of the block-based time structure; therefore, the initialization and setup phase 401 is considered the “external block structure.” During one or more measurement cycles 402, both the initiator and responder participating in the MMS ranging session will be aware of the block-based time structure; therefore, one or more measurement cycles 402 are considered the “internal block structure.”

[0217] As shown in 410, during the initialization and setup phase 401, PN is used to construct random numbers. It should also be understood that the transmission duration of frames during the initialization and setup phase 401 is not necessarily limited to 1 ms.

[0218] During one or more measurement periods 402, the transmitter (initiator or responder) may send a single frame in only one time slot, thus each frame is uniquely associated with a specific time slot. Therefore, the time slot index, round index, and block index can be used to construct random numbers to protect the frames sent in the time slot. Since the indices are strictly increasing, it is guaranteed that the time slot index, round index, and block index used to construct the random numbers will not be repeated in the current block structure, so the frame does not need to carry any PN, as shown in 420.

[0219] Figure 5 The diagram illustrates a process 500 of an exemplary MMS ranging session provided by some exemplary embodiments of the present invention.

[0220] Process 500 begins with the controller and the controlled party performing session establishment 510. During session establishment 510, long-term session parameters such as the UWB channel number, preamble, and default block structure (e.g., number of blocks, block duration) are negotiated. (See reference...) Figure 4 The long-term session parameters include default values ​​for m and n, where m is associated with the number of slots in each round (e.g., NumSlots = m+1, as shown). Figure 4 As shown), n is associated with the number of rounds in each block (e.g., NumRounds = n+1, as shown). Figure 4 (As shown). Long-term parameters are not expected to change during the MMS ranging session. When security is enabled, the controller will also provide the controlled party with at least one security key to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders will also be provided. For the NBA-MMS ranging session, narrowband-related parameters (such as the NB channel number) can also be negotiated during session establishment (510).

[0221] Other parameters, such as the number of MMS segments and the reporting mode, can be considered short-term parameters because they may be modified during an MMS ranging session. Session establishment 510 can be performed out-of-band, such as using Bluetooth or Wi-Fi radio, or it can be performed in-band, such as using narrowband or UWB radio.

[0222] Furthermore, the roles of the initiator and responder are also assigned during session establishment (510). Figure 5The specific example shown assumes that the controller assumes the role of initiator 260 and is assigned the role of responder 270 by the controller. However, it should be understood that it is also possible for the controller to be assigned the role of initiator while assuming the role of responder.

[0223] At 522, the initiator 260 opportunistically sends ADV-POLL frames at its own discretion and intervals, while the responder 270 may opportunistically listen for incoming ADV-POLL frames. At 524, if the responder 270 intends to participate in the ranging session with the initiator 260, the responder 270 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN, which is used to construct a random number to protect the ADV-RESP frame. Figure 5 As shown, a secure ADV-RESP frame can be sent from responder 270 to initiator 260.

[0224] In step 526, once the initiator 260 receives the ADV-RESP frame, it sends a SOR frame, which provides the time offset for the start of the first distance measurement period. If security is enabled, the SOR frame carries a PN, which is used to construct a random number to protect the SOR frame. Figure 5 As shown, a secure SOR frame can be sent from the initiator 260 to the responder 270. It should be noted that the PN used for UL and the PN used for DL ​​can be used separately, that is, the PN in the uplink (responder to initiator) and downlink (initiator to responder) directions can use different numbering spaces, and the PN is incremented by 1 each time a frame carrying the PN is sent.

[0225] At 528, initiator 260 sends a safety POLL frame to responder 270 at the beginning of the first time slot of a round, wherein the beginning of the first time slot is indicated by the time offset in the SOR frame. Initiator 260 may also include other control information in responder 270's POLL frame. At 530, responder 270 sends a safety RESP frame back to initiator 260 upon successful receipt of the safety POLL frame. The POLL frame and RESP frame enable time and frequency synchronization between initiator 260 and responder 270.

[0226] During the ranging phase, the initiator 260 and the responder 270 may exchange zero or more UWB RSFs, and optionally exchange one or more UWB RIFs. The RSFs are used to perform the ranging measurement, while the RIFs are used to check the integrity of the ranging measurement. Illustratively, the exchange occurs in... Figure 5 It is shown at positions 532 and 534 in the diagram.

[0227] After the initiator 260 or responder 270 has completed receiving all UWB segments from the ranging phase, the reporting phase can begin. During the reporting phase, the initiator 260 or responder 270 can generate a ranging measurement report and send a secure RPRT frame carrying the measurement report to the peer device. Figure 5 As shown, at 536, the initiator 260 sends a secure RPRT frame to the responder 270, and at 538, the responder 270 sends a secure RPRT frame to the initiator 260.

[0228] The time slot index of the corresponding frame, as well as the round index and the block where the time slot is located, can be used to construct random numbers for protecting POLL frames, RESP frames, and RPRT frames.

[0229] This invention illustrates some exemplary formats for frames and random numbers with reference to the accompanying drawings. However, it should be noted that these examples are given for illustrative purposes only and do not impose any limitations on the invention. For example, a frame or random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying the information and the other field holding it. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the fields may be arranged in another way, such as in a different order. The invention does not limit itself in this respect.

[0230] Figure 6A A schematic diagram illustrating the format of an SOR frame 610 provided by some exemplary embodiments of the present invention is shown. For example, the SOR frame 610 may be in... Figure 5 The secure SOR frame is sent at position 526. Although SOR frame 610 is shown in compressed PSDU format, the described process can work even if the frame is carried as a compressed header ID format or even as a conventional 802.15.4 frame.

[0231] like Figure 6A As shown, the SOR frame 610 includes a field 611 carrying an ID, a field 612 carrying a security indicator, a field 613 carrying an address, a field 614 carrying a PN (Proof of Partition), a field 615 carrying a security level, a field 616 carrying a security payload, and a field 617 carrying a MIC (Security Detection and Control). When carried as a conventional 802.15.4 frame, the PN field 614 and the security level field 615 can be carried within the auxiliary security header field in the MHR (Security Header).

[0232] Fields 611 to 615 can be considered as the compressed header (CHR) of SOR frame 610, where fields 611 to 613 are mandatory, while fields 614 to 615 are optional. For example, if the frame is not secure, field 614 can be omitted. For example, if a security level has been negotiated beforehand, field 615 can be omitted.

[0233] Field 611 can indicate the identifier of SOR frame 610; for example, field 611 carries "0x22" indicating an SOR frame. Field 612 can indicate whether the frame is secure. In some examples, field 612 can be the most significant bit (MSB) of field 611, for example, carrying "1" or "0". For example, "1" indicates the frame is secure, while "0" indicates the frame is insecure. Figure 6A As shown, the total length of fields 611 and 612 can be one octet.

[0234] Field 614 can carry the packet number of SOR frame 610. In some examples, the initiator 260 can maintain a separate numbering space for each responder 270 of the secure compressed frame to ensure that the same random number is never reused by the same security key. For example, a first numbering space is associated with responder 270-1, and a second numbering space is associated with responder 270-2. Figure 6A As shown, the length of field 614 can be 4 octets. In cases where the SOR frame is addressed to multiple responders, the PN may be the same for all responders, and a separate security key negotiated for broadcast transmission is used to protect or deprotect the SOR frame.

[0235] Field 615 may indicate the security level applied to security operations performed on the frame. Alternatively, if the security level is negotiated during session establishment 510 and it is assumed that the security level is fixed for the entire ranging session, field 615 may be omitted.

[0236] When SOR frame 610 is encrypted, for example, at a security level of 5, 6, or 7, field 616 is secure (i.e., encrypted). For example, field 616 carries a secure payload.

[0237] Field 617 carries the MIC generated by the AEAD transformation process. The size of the MIC depends on the security level. For example, for a security level of 5 or 6, the length of field 617 is 4 octets or 8 octets, respectively. It is also possible that only a portion of the MIC (e.g., the least significant 16 bits) is carried in the MIC field, and the same 16 bits are used by the responder for integrity checks.

[0238] It should be understood that since the MIC can detect any errors in the frame content, the CRC field is no longer needed; that is, the MIC field can replace the CRC field.

[0239] It should be understood that Figure 6A SOR frame 610 in the example can be considered a secure SOR frame. In some other examples, if a non-secure SOR frame is used, fields 614 and 615 are not included, and the payload in field 616 is a non-secure payload.

[0240] It should also be understood that, although Figure 6A The format of the SOR frame is shown, but a similar format can be applied to the secure ADV-RESP, which will not be described further here.

[0241] Figure 6B The illustration shows a schematic diagram of the format of a random number 620 for protecting frames transmitted in an external block structure, provided by some exemplary embodiments of the present invention. For example, the random number 620 may be constructed by the initiator 260 for protecting the SOR or for deprotecting the ADV-RESP, or by the responder for protecting the ADV-RESP or for deprotecting the SOR. Alternatively, the random number 620 may be referred to as an external block-based random number.

[0242] like Figure 6B As shown, the random number 620 includes a frame 621 carrying the source address, a field 622 carrying the PN, a reserved field 623, a field 624 carrying the security level, and a field 615 carrying the block structure indicator.

[0243] Field 621 can indicate the extended address of the device that initiated the frame. It is understood that during session establishment 510, the controller and the controlled device will exchange and save the extended address of the peer device.

[0244] Field 622 can be considered a frame counter field and can be set to PN, the same value as the PN field of a secure frame. For example, if random number 620 is constructed by initiator 260 to protect a SOR frame, or by responder 270 to deprotect a SOR frame, then the PN in field 622 should be the same as the PN in field 614. The length of field 622 can be 4 octets.

[0245] Field 624 can indicate the security level, specifically the random number security level. The security level can be an integer with the same value as the security level field of the security frame. For example, if random number 620 is constructed by initiator 260 to protect the SOR frame, or by responder 270 to deprotect the SOR frame, then the security level in field 624 should be the same as the security level in field 615. However, as referenced... Figure 6AAs mentioned above, if the security level is negotiated during session establishment 510, field 615 can be omitted. In this case, the security level field 624 is set to the security level negotiated during session establishment 510.

[0246] Field 625 can indicate a block structure indicator (or simply block indicator). In some examples, field 625 can be the last bit of a random number 620, carrying either a "1" or a "0". For example, a "1" indicates that the frame is in a block structure, while a "0" indicates that the frame is sent in an outer block structure. Figure 6B As shown, since the random number 620 is used for the initialization and setup phases, the block structure indicator is 0.

[0247] It should be understood that the block structure indicator is used to ensure that the random number used to protect frames sent inside and outside the block structure is never reused. For example, if a frame is sent or received outside the block structure, the block structure indicator can be set to "0".

[0248] Figure 7A A schematic diagram illustrating the format of a POLL frame 710 provided by some exemplary embodiments of the present invention is shown. For example, the POLL frame 710 may be in... Figure 5 The security POLL frame sent at position 528.

[0249] like Figure 7A As shown, the POLL frame 710 includes a field 711 carrying an ID, a field 712 carrying a security indicator, a field 713 carrying an address, a field 714 serving as an existence control field, a field 715 carrying a block index, a field 716 carrying a round index, a field 717 carrying a security payload, and a field 718 carrying a MIC.

[0250] Fields 711 to 713 can be considered the CHR of POLL frame 710. Field 711 can indicate the identifier of POLL frame 710. Field 712 can indicate whether the frame is secure. In some examples, field 712 can be the MSB of field 711, for example, carrying "1" or "0". For example, "1" indicates that the frame is secure, while "0" indicates that the frame is insecure. Figure 7A As shown, the total length of fields 711 and 712 can be one octet.

[0251] Fields 714 to 716 can be considered as the open payload of POLL frame 710. Regardless of the security level, the open payload of a secure frame can be authenticated but not encrypted. Field 714 includes block index presence field 7142 carrying a block index presence indicator, round index presence field 7144 carrying a round index presence indicator, and reserved field 7146. (The text abruptly ends here.) Figure 7AAs shown, the length of field 714 can be 1 octet.

[0252] In some examples, the block index presence indicator equals a first value (e.g., 1) to indicate the presence of field 715, while the round index presence indicator equals a first value (e.g., 1) to indicate the presence of field 716 in the open payload. For example, field 715 can be 2 octets long, and field 716 can be 2 octets long. In other examples, the block index presence indicator equals a second value (e.g., 0) to indicate the absence of field 715, meaning field 715 has a length of 0. In still other examples, the round index presence indicator equals a second value (e.g., 0) to indicate the absence of field 716, meaning field 716 has a length of 0. For example, if the block index is a default value (e.g., 0), field 715 can be omitted. For example, if the round index is a default value (e.g., 0), field 716 can be omitted.

[0253] When the POLL frame 710 is encrypted, for example, at a security level of 5, 6, or 7, field 717 is secure (i.e., encrypted). For example, field 717 carries a secure payload. Field 718 carries a MIC generated by the AEAD transformation process. The size of the MIC depends on the security level. For example, at a security level of 5 or 6, the length of field 718 is either 4 octets or 8 octets, respectively.

[0254] Alternatively, POLL frame 710 may include a field carrying the security level, which is consistent with... Figure 6A The field 615 is similar.

[0255] It should be understood that Figure 7A The POLL frame 710 in the block can be considered a secure POLL frame. The secure POLL frame 710 is transmitted in the first time slot of the round indicated by the SOR frame (e.g., secure SOR frame 610) so that the receiver (responder 270) of the secure POLL frame 710 is synchronized with the block structure.

[0256] It should also be understood that, although Figure 7A The format of the POLL frame is shown, but a similar format can be applied to secure RESP or secure RPRT, which will not be described further here.

[0257] Figure 7BThe illustration shows a schematic diagram of the format of a random number 720 for protecting frames within a block structure, provided by some exemplary embodiments of the present invention. For example, the random number 720 may be constructed by the initiator 260 for protecting the POLL, deprotecting the secure RESP, protecting the RPRT, or deprotecting the secure RPRT, or may be constructed by the responder for deprotecting the secure POLL, protecting the RESP, deprotecting the secure RPRT, or protecting the RPRT. Alternatively, the random number 720 may be referred to as an internal block-based random number.

[0258] like Figure 7B As shown, the random number 720 includes a frame 721 carrying the source address, a field 722 carrying the slot index, a field 723 carrying the round index, a field 724 carrying the block index, and a field 725 carrying the block structure indicator.

[0259] Field 721 can indicate the extended address of the device that initiated the frame. It is understood that during session establishment 510, the controller and the controlled device will exchange and save the extended address of the peer device.

[0260] Fields 722 to 724 can be considered as frame counter fields for the random number 720. Fields 722 to 724 can be set as indices of the time slot, round, and block where a frame was sent (while being protected) or received (while being deprotected). Figure 7B As shown, the lengths of fields 722 to 724 are predefined, with a total length of 39 bits.

[0261] Field 725 can indicate a block structure indicator (or simply block indicator). In some examples, field 725 can be the last bit of a random number 720, for example, carrying either a "1" or a "0". For example, a "1" indicates that the frame is in a block structure, and a "0" indicates that the frame is sent in an outer block structure. Figure 7B As shown, since the random number 720 is used to measure the period, the block structure indicator is 1.

[0262] Alternatively, the random number 720 could include a field carrying a security level, which is consistent with... Figure 6B The field 624 is similar.

[0263] In some examples, field 724 can be split into two fields, one carrying the block index and the other reserved. In some examples, the order of fields 722 to 724 can be different, for example... Figure 7B The reverse order shown.

[0264] It should be understood that the block structure indicator is used to ensure that the random number used to protect frames sent inside and outside the block structure is never reused. For example, if a frame is sent or received in an outer block structure, the block structure indicator can be set to "0".

[0265] Figure 7C Example 730 of constructing random numbers for protecting compressed frames is shown, providing some exemplary embodiments of the present invention. (e.g.) Figure 7C As shown, if a security frame is to be sent in slot 1 of round 1 of block 1 in a block-based time structure, the random number may include field 732 carrying slot index 1, field 733 carrying round index 1, and field carrying block index 1.

[0266] It should be understood that Example 730 also applies to the responder who de-secures a frame, for example, where the secure frame is received in time slot 1 of round 1 of block 1 in a block-based time structure, and the random number is constructed in the same manner.

[0267] For reference Figures 7B to 7C As described, the lengths of the fields carrying the slot index, round index, and block index can be set to fixed values, such as 8 bits, 15 bits, and 16 bits, respectively. In this invention, there can be a single frame being transmitted within a slot to ensure that the random number for the same security key is never repeated. In this case, a larger number of frame counter values ​​may be required, and correspondingly, the frame counter space may be quickly exhausted. Therefore, if the frame counter wraps around (i.e., rolls to 0), the security key needs to be changed to ensure that the random number for the same security key is never repeated.

[0268] Table 1 below shows the increment of the frame counter value based on an internal block random number (e.g., random number 720) when a secure frame is sent or received in the first time slot of a different round in three consecutive blocks. It can be seen that the frame counter value increases by 8,388,865 each time the block index is updated. For example, for a block structure with a block duration of 96 ms, the frame counter will wrap around in 6291 seconds = 104 minutes. Table 1

[0269] Figure 8 A schematic diagram illustrating another format of random number 800 for protecting frames within a block structure, provided by some exemplary embodiments of the present invention, is shown. Alternatively, random number 820 may be referred to as an internal block-based random number.

[0270] like Figure 8As shown, random number 800 includes a frame 821 carrying the source address, a field 822 carrying the slot index, a field 823 carrying the round index, a field 824 carrying the block index, and a field 825 carrying the block structure indicator. It should be noted that random number 800 is related to... Figure 7B The random number 720 is similar, but the lengths of fields 822 to 824 are not fixed.

[0271] For example, the lengths of field 822 (i.e., the number of the first bits), field 823 (i.e., the number of the second bits), and field 824 (i.e., the number of the third bits) can be determined based on the block-based time structure. Specifically, Figure 8 In and The value of can be determined according to equations (1) and (2), respectively. In some examples, and The value can be indicated by the initiator 260, for example, in SOR frame 610.

[0272] Alternatively, the random number 800 could include a field carrying a security level, which is consistent with... Figure 6B Field 624 in the example is similar. Alternatively, in some other examples, field 814 could be split into three fields: one carrying the block index, one carrying the security level, and one reserved.

[0273] As a concrete example, assume each block consists of 16 rounds, and each round consists of 16 time slots. Therefore, the number of time slots per round (NumSlots) = the number of rounds per block (NumRounds) = 16. Thus, M = N = 4 bits. Table 2 below shows the increment of the frame counter value based on an internal block random number (e.g., random number 800) when a secure frame is sent or received in the first time slot of a different round in three consecutive blocks. It can be seen that the frame counter value increases by 273 each time the block index is updated. For example, for a block structure with a block duration of 96 ms, the frame counter will wrap around in 3,435,974 minutes. Table 2

[0274] By comparing Table 2 with Table 1, it can be seen that using a random number of 800 can prevent the frame counter value from increasing rapidly. Therefore, there is no need to update the security key so frequently.

[0275] Alternatively, the value of the frame counter field (i.e., FC) can be defined as equation (3). Figure 8The same effect can be achieved by constructing a frame counter (FC) field for random numbers without having to divide the frame counter field into slot index, round index, and block index fields (e.g., 822 to 824): FC = Block_Index×NumRounds×NumSlots + Round_Index×NumSlots + Slot_Index (3)

[0276] In equation (3), Block_index, Round_Index and Slot_Index represent the block index, round index and slot index, respectively.

[0277] Figure 8 Random numbers in the array can also have the same characteristics as... Figure 6B The random number has the same format as the frame counter field, which is 4 octets long, and the random number includes a random number security level field.

[0278] Figure 9 A schematic diagram illustrating the format of a secure SOR frame 900 provided by some exemplary embodiments of the present invention is shown. Figure 6A Similar to the description in [the original text], the Secure SOR frame 900 includes field 616 carrying a secure payload.

[0279] Field 616 includes field 911, which serves as an existence control field; field 912, which carries a time offset; field 913, which carries a block index; field 914, which carries a round index; and field 915, which carries a time slot index. Field 911 may include field 9112, which carries a block index existence indicator; field 9114, which carries a round index existence indicator; field 9116, which carries a time slot index existence indicator; and a reserved field 9118.

[0280] When the controller is assigned to an existing block structure, the block index, round index, and slot index pointed to by the time offset field of the SOR frame may not start from zero. If the POLL frame sent at the time pointed to by the time offset field of the SOR frame does not carry the round and block indices in the open payload (e.g., ... Figure 7A As shown), if the index is encrypted, the responder will be unable to deprotect the POLL frame because it will be unable to construct random numbers. When indicating the first round assigned to the controller, in addition to the time offset of the block / round assigned in field 912, if the controller also includes the index of the block, round, and time slot pointed to by the time offset field 912, for example, in field 616 of the secure SOR frame 900. This will enable the first frame (e.g., the POLL frame) sent in the block, round, and time slot pointed to by the time offset field 912 to be encrypted.

[0281] In some other examples, if any of the indicators in the block index presence indicator in field 9112, the round index presence indicator in field 9114, or the slot index presence indicator in field 9116 do not include the corresponding index, then a default index (e.g., zero) can be applied.

[0282] Figure 10A An exemplary session 1010 between initiator 260 and responder 1 (e.g., responder 270-1) is shown, provided by some exemplary embodiments of the present invention. Figure 10B An exemplary session 1020 of initiator 260 and responder 2 (e.g., responder 270-2) provided by some exemplary embodiments of the present invention is illustrated. In both examples, the number of rounds per block (NumRounds) = 16; and the number of slots per round (Numslots) = 16. This results in the number of bits (N) for the round index = the number of bits (M) for the slot index = 4. A frame counter field used to construct a random number for protecting / unprotecting each frame is shown below the frame, for example, "Random number: FC=...".

[0283] like Figure 10A As shown, the SOR frame sent to responder 1 can be as follows: Figure 6A Given the secure SOR frame shown, responder 1 will assume that the slot index, round index, and block index are all 0. Therefore, the first POLL frame (POLL 1) sent to responder 1 is transmitted in slot 0 (0x0) of round 0 in block 0, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / unprotect the POLL 1 frame can be calculated as 0x0000. Similarly, the 128th RPRT frame (RPRT 128) is transmitted in slot 7 (0x7) of round 0 (0x0) in block 127 (0x7F), and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / unprotect the RPRT 128 frame can be calculated as 0x7F07.

[0284] like Figure 10B As shown, the SOR frame sent to responder 2 can be as follows: Figure 9The secure SOR frame shown indicates that responder 2 will learn about the existing block-based time structure and the indices of slots, rounds, and blocks by unprotecting the secure SOR frame, where the first POLL is expected, for example, "block index = 1, round index = 1, slot index = 0" shown at 1022. Therefore, the first POLL frame (POLL 1) sent to responder 2 is sent in slot 0 of round 1 of block 1, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number for protecting / unprotecting the POLL 1 frame can be calculated as 0x0110. Similarly, the 129th RPRT frame (RPRT 129) is transmitted in slot 15 (0xF) of round 1 (0x1) of block 128 (0x80), and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number for protecting / unprotecting the RPRT 128 frame can be calculated as 0x801F.

[0285] Assuming the indices of the block, round, and slot structures are always incremented, and the block structure never restarts within the same session between a pair of initiators and responders, while constructing internal block random numbers, such as random number 720 or random number 800, if the block structure restarts two or more times between the same pair of initiators and responders, the internal block random numbers may be duplicated, potentially violating security.

[0286] In some embodiments, the security key should be updated when the block structure restarts. That is, a new security key should be used whenever a new block structure is established between the same initiator and responder pair.

[0287] In other embodiments, a cycle can be defined to avoid this situation, where a cycle comprises multiple blocks. That is, a layer can be added on top of the blocks: a cycle. With the security key remaining unchanged, the cycle index increments each time the block structure is restarted between the same initiator and responder pair. Figure 11A A schematic diagram of a periodic time structure 1110 provided by some exemplary embodiments of the present invention is shown. For example... Figure 11A As shown, two cycles are illustrated, cycle 0 and cycle 1.

[0288] If the period is newly defined, the index of the period in which the secure frame is sent can also be used to construct the internal block random number. For example, the internal block random number can be constructed based on the slot index, round index, block index, and period index.

[0289] Figure 11BA schematic diagram illustrating the format of another secure SOR frame 1120 provided by some exemplary embodiments of the present invention is shown. Figure 9 Similar to the description in [the original text], the secure SOR frame 11200 includes field 616 carrying a secure payload.

[0290] Field 616 includes field 1121, which is an existence control field, and includes field 1124 carrying a block index existence indicator, field 1125 carrying a round index existence indicator, field 1126 carrying a slot index existence indicator, field 1127 carrying a periodic index existence indicator, and reserved field 1128.

[0291] Fields 1124 to 1126 can be used with Figure 9 Fields 9112 to 9116 are similar and will not be repeated here. Figure 11B In this context, assuming fields 1124 to 1126 indicate the absence of block index fields, round index fields, or time slot index fields, then... Figure 11B There is no such thing as in Figure 9 The fields corresponding to fields 913 to 915 in the table.

[0292] Field 1127 carries a periodic index presence indicator, which indicates whether field 1123 is included. For example... Figure 11B As shown, field 616 includes field 1122 carrying a time offset and field 1123 carrying a periodic index.

[0293] Alternatively, if the block index in field 1124 has an indicator of 1, it can also include a block index field carrying the block index, and... Figure 9 Similar to field 913. If the wheel index in field 1125 has an indicator of 1, then a wheel index field carrying the wheel index can also be included, similar to... Figure 9 Similar to field 914. If the slot index in field 1126 has an indicator of 1, it can also include a slot index field carrying the round index, similar to... Figure 9 Similar to field 915. That is, the security payload 616 may include presence control fields (e.g., fields 911 or 1121), fields carrying time offsets (e.g., fields 912 or 1122), and may also include zero or more of the following: block index fields, round index fields, time slot index fields, and periodic index fields, without any order restrictions. For example, the field carrying the time offset (e.g., fields 912 or 1122) may be located at the end of field 616, i.e., the last two octets.

[0294] In some examples, initiator 260 may use secure SOR frame 1120 to notify responder 270 of the periodic index each time a new block structure begins, so as to allow responder to synchronize with the periodic index.

[0295] Figure 11C The illustration shows a schematic diagram of another format of random number 1130 for protecting frames within a block structure, provided by some exemplary embodiments of the present invention. Alternatively, random number 1130 may be referred to as an internal block-based random number.

[0296] like Figure 11C As shown, random number 1130 includes: frame 1131 carrying the source address, field 1132 carrying the slot index, field 1133 carrying the round index, field 1134 carrying the block index, field 1135 carrying the period index, and field 1136 carrying the block structure indicator. It should be noted that random number 1130 is related to... Figure 8 The random number 800 is similar, except that... Figure 8 The field 824 in the data was split into Figure 11C Fields 1134 and 1135 in the index. For example, some MSBs of block index fields can be assigned to periodic indexes, such as allowing up to 64 periods of 6 bits.

[0297] Alternatively, the random number 1130 could include a field carrying a security level, which is consistent with... Figure 6B Similar to field 624. Alternatively, field 1135 can be split into two fields, one carrying a periodic index and the other reserved. In some examples, the order of fields 1132 to 1135 can be different, for example, as shown below. Figure 11C The reverse order shown.

[0298] Based on the above combination Figures 4 to 9 In some embodiments described, some security frames may include a field carrying the PN, such as SOR frames 610 or 900. Table 3 below lists some frames, some of which may require including the PN, while others may not. Table 3

[0299] Specifically, frames transmitted outside the block structure (e.g., ADV-POLL, ADV-RESP, SOR) include the PN field in the frame and use a random number based on the outer block (e.g., ... Figure 6B The random number shown is 620), while frames sent within a block structure (e.g., POLL, RESP, RPRT, PRM-RESP, PRM-REQ, ADV-HBS) do not include the PN field in the frame and use random numbers based on the internal block (e.g., such as...). Figure 7B The random number 720 shown, or as... Figure 8 The random number shown is 800.

[0300] In some examples, the operation of the protection frame can also be called the AEAD transformation, and the operation of deprotecting the security frame can also be called the inverse AEAD transformation. This invention does not limit this aspect.

[0301] Despite the above reference Figures 4 to 11C Some of the embodiments described are related to block-based temporal structures, but it should be understood that they may also be related to superblock-based temporal structures.

[0302] Figure 12A A schematic diagram 1210 illustrates the construction of random numbers in a superblock-based time structure, provided by some exemplary embodiments of the present invention. For example... Figure 12A As shown, a superblock consists of three types of blocks: Block 0 includes 2 rounds, each with 32 time slots; Block 1 includes 8 rounds, each with 8 time slots; and Block 2 includes 16 rounds, each with 16 time slots. If a frame is sent in time slot 0 of round 7 or in block 4, the random number may include field 1212 carrying "time slot index = 0", field 1214 carrying "round index = 7", and field 1216 carrying "block index = 4". Figure 12A The random numbers in the data can be internal block random numbers based on random number 720, where the length of fields 1212 to 1216 is fixed.

[0303] Figure 12B A schematic diagram 1220 illustrates the construction of random numbers in a superblock-based time structure, provided by some exemplary embodiments of the present invention. Figure 12A Similarly, a superblock consists of three types of blocks: Block 0 comprises 2 rounds, each with 32 time slots; Block 1 comprises 8 rounds, each with 8 time slots; and Block 2 comprises 16 rounds, each with 16 time slots. If a frame is sent in time slot 0 of round 7 or in block 4, the random number may include field 1222 carrying "time slot index = 0", field 1224 carrying "round index = 7", and field 1226 carrying "block index = 4".

[0304] Figure 12B The random numbers in the block can be internal block random numbers based on random number 800, where the lengths of fields 1222 to 1226 are not fixed. Specifically, the maximum number of slots in a round (Max_NumSlots) = max(32, 8, 16) = 32, so M can be determined to be 5. Therefore, the length of field 1222 is 5 bits. Specifically, the maximum number of rounds in a block (Max_NumRounds) = max(2, 8, 16) = 16, so N can be determined to be 4. Therefore, the length of field 1224 is 4 bits.

[0305] Therefore, PN can be used to construct external block random numbers, and slot indexes, round indexes, and block indexes (and optional periodic indexes) can be used to construct internal block random numbers. The frames transmitted between the initiator and the responder can be protected accordingly, thereby ensuring the security of communication.

[0306] Alternatively, the value of the frame counter field (i.e., FC) can be defined as equation (4). Figure 12A The same effect can be achieved by constructing a frame counter field for random numbers, without having to divide the frame counter field into slot index, round index, and block index fields: FC = Block_Index×Max_NumRounds×Max_NumSlots + Round_Index×Max_NumSlots + Slot_Index (4)

[0307] In equation (4), Block_index, Round_Index, and Slot_Index represent the block index, round index, and slot index, respectively. When the block index in a superblock is represented as a relative block index, the block index can be calculated according to equation (5): Block_Index = Hyper_Block_Index×NumBlocks + Relative_Block_Index (5)

[0308] In equation (5), Hyper_Block_Index is the index of the superblock, Relation_Block_Index is the relative block index, and NumBlocks is the number of blocks in the superblock.

[0309] Figure 13 A schematic diagram of another exemplary MMS ranging session 1300 in a block-based time structure provided by some exemplary embodiments of the present invention is shown. As shown in FIG1300, the MMS ranging session 1300 includes an initialization and setup phase, followed by one or more measurement cycles.

[0310] exist Figure 13 In this context, it is assumed that the block structure also exists during the initialization and setup phases. For example, the controller may establish the block structure at the very beginning of the initialization and setup phases (i.e., even before or at the start). Therefore, the initialization and setup phases, as well as one or more measurement cycles, are all within the block structure.

[0311] Because synchronization at the time slot level between initiator 260 and responder 270 may not be easy during the initialization and setup phases, the time slot index is not used to construct random numbers; however, a short PN (e.g., 1 octet long) can be used. In this case, the PN, round index, and block index can be used to construct random numbers for protecting the frame, as shown in 1310. Due to the use of the round index, it is recommended that the initialization and setup phases be completed within one round to prevent loss of synchronization due to changes in the round index. Figure 14 The diagram illustrates a signaling diagram of a process 1400 for another exemplary MMS ranging session, provided by some exemplary embodiments of the present invention.

[0312] Process 1400 begins with the controller and two slaves respectively performing session establishment 1412 and 1414. During session establishment 1412 / 1414, long-term session parameters such as the UWB channel number, preamble, and block structure (e.g., number of blocks, block duration) are negotiated. When security is enabled, the controller also provides each slave with at least one security key to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders is also provided. For NBA-MMS ranging sessions, narrowband-related parameters (e.g., NB channel number, number of MMS fragments, etc.) can also be negotiated during session establishment 1412 / 1414. Although Figure 13 The diagram illustrates the use of the same block structure for the initialization and setup phases and the measurement period, but different block structures can also be used for these phases and the measurement period. In this case, a security key can be negotiated for the initialization and setup phases, and a different security key can be negotiated for the measurement period. In this case, the PN space is also different for the initialization and setup phases and the measurement period. Furthermore, the block index of the block structure for the measurement period can start from zero at the time pointed to by the time offset of the SOR frame.

[0313] Other parameters, such as the number of MMS segments and the reporting mode, can be considered short-term parameters because they may be modified during an MMS ranging session. Session establishment 1412 / 1414 can be performed out-of-band, such as using Bluetooth or Wi-Fi radio, or it can be performed in-band, such as using narrowband or UWB radio.

[0314] Furthermore, the roles of the initiator and responder are also assigned during session establishment 1412 / 1414. Figure 14 The specific example shown assumes that the controller assumes the role of initiator 260, and is assigned the roles of responders 270-1 and 270-2. However, it should be understood that it is also possible for the controller to be assigned the role of initiator while assuming the role of responder.

[0315] At 1416, the controller (initiator 260) begins the block structure before sending the first ADV-POLL frame. For example, initiator 260 can establish block and round structures, such as defining at least the block duration and round duration. In some cases, a slot structure may also be defined, in which case the slot index can be used instead of PN for random number construction, whether inside or outside the block structure.

[0316] At 1422, initiator 260 opportunistically sends ADV-POLL frames at its own determined times and intervals, while responders 270-1 and 270-2 may opportunistically listen for incoming ADV-POLL frames. To allow responders 270-1 and 270-2 to synchronize with the block structure, the ADV-POLL frame includes the index of the round and block in which the ADV-POLL frame was sent, as well as the duration of the current round. If a time slot structure is also defined, the ADV-POLL frame also includes the time slot index of the time slot in which the ADV-POLL frame was sent.

[0317] At 1424, if responder 270-1 intends to participate in the ranging session with initiator 260, responder 270-1 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN (e.g., PN_U1), which is used to construct a random number to protect the ADV-RESP frame. Figure 14 As shown, a secure ADV-RESP frame can be sent from responder 270-1 to initiator 260.

[0318] In 1426, if responder 270-2 intends to participate in the ranging session with initiator 260, responder 270-2 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN (e.g., PN_U2), which is used to construct a random number to protect the ADV-RESP frame. Figure 14 As shown, a secure ADV-RESP frame can be sent from responder 270-2 to initiator 260.

[0319] At 1428, once initiator 260 receives the ADV-RESP frame, it sends a SOR frame, which provides the time offset for the start of the first distance measurement period. The SOR frame can be broadcast, allowing both responders 270-1 and 270-2 to detect it. If security is enabled, the SOR frame carries a broadcast PN (e.g., PN_B), which is used to construct a random number to protect the SOR frame. Figure 14As shown, a secure SOR frame can be sent from initiator 260 to responders 270-1 and 270-2. It should be noted that different numbering spaces can be used for the PN (Parallel Pointer) of unicast and broadcast frames. In this case, the time offset field in the SOR frame points to the time when the first POLL frame was sent. Alternatively, the SOR frame may carry multiple time offset fields, one for each responder; or the initiator may send multiple unicast SOR frames, one for each responder; the time offset field points to the exact time when the ranging measurement period for a particular responder begins.

[0320] At 1432, initiator 260 sends a broadcast POLL frame to responders 270-1 and 270-2 at the beginning of the first time slot of a round, wherein the beginning of the first time slot is indicated by the time offset in the SOR frame. Initiator 260 may also include other control information in the POLL frames of responders 270-1 and 270-2.

[0321] At 1434, responder 270-1 sends a RESP frame back to initiator 260 upon successfully receiving the POLL frame. The POLL and RESP frames enable initiator 260 and responder 270-1 to synchronize time and frequency.

[0322] During the ranging phase, the initiator 260 and the responder 270-1 may exchange zero or more UWB RSFs, and optionally exchange one or more UWB RIFs. The RSFs are used to perform the ranging measurement, while the RIFs are used to check the integrity of the ranging measurement. Illustratively, in Figure 14 The exchange between initiator 260 and responder 270-1 is shown at positions 1436 and 1438.

[0323] After the initiator 260 or responder 270-1 has completed receiving all UWB segments from the ranging phase, the reporting phase can begin. During the reporting phase, the initiator 260 or responder 270-1 can generate a ranging measurement report and send an RPRT frame carrying the measurement report to the peer device. Figure 14 As shown, at 1440, initiator 260 sends a secure RPRT frame to responder 270-1, and at 1442, responder 270-1 sends a secure RPRT frame to initiator 260.

[0324] The processes 1452 to 1462 between initiator 260 and responder 270-2 are similar to the processes 1432 to 1442 between initiator 260 and responder 270-1, and therefore will not be described again here.

[0325] like Figure 14As shown, each of the security frames carries an appropriate PN. The PN, along with the indexes of the rounds and blocks, can be used to construct random numbers for protecting POLL, RESP, and RPRT frames.

[0326] This invention illustrates some exemplary formats for frames and random numbers with reference to the accompanying drawings. However, it should be noted that these examples are given for illustrative purposes only and do not impose any limitations on the invention. For example, a frame or random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying the information and the other field holding it. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the fields may be arranged in another way, such as in a different order. The invention does not limit itself in this respect.

[0327] Figure 15A A schematic diagram illustrating the format of a random number 1510 for protecting a frame, provided by some exemplary embodiments of the present invention, is shown. For example, the random number 1510 may be constructed by initiator 260 or responder 270-1 or 270-2.

[0328] like Figure 15A As shown, the random number 1510 includes a frame 1511 carrying the source address, a field 1512 carrying the PN, a field 1513 carrying the round index, and a field 1514 carrying the block index.

[0329] Field 1511 may indicate the extended address of the device that initiated the frame. Fields 1512 to 1514 may be considered as the frame counter random number 720.

[0330] The length of field 1512 carrying the PN can be one octet, or 8 bits. The PN can also be called a short PN. For example, the PN starts at 0 in each round and must not wrap around within a round. It should be understood that the maximum number of secure frames per round depends on the length of field 1512; for example, if field 1512 occupies 8 bits, the maximum number of secure frames per round is 256.

[0331] like Figure 15A As shown, the length of field 1513 is fixed, for example, 15 bits (8 to 22). In some other examples, the length of the field carrying the round index may not be a fixed value. Figure 15BA schematic diagram of another format of random number 1520 is shown, which includes a frame 1521 carrying the source address, a field 1522 carrying the PN, a field 1523 carrying the round index, and a field 1524 carrying the block index. The length of field 1523 is N bits, where N can be determined by the above equation (2).

[0332] Alternatively, the random number 1510 or 1520 may include a field carrying a security level, which is consistent with... Figure 6B Field 624 in the example is similar. Alternatively, fields 1514 or 1524 can be split into two fields, one carrying the block index and the other reserved. In some examples, the order of fields 1512 to 1514 or 1522 to 1524 can be another way, for example... Figure 15A or Figure 15B The reverse order shown.

[0333] Figure 16A A schematic diagram illustrating the format of a secure RPRT frame 1610 provided by some exemplary embodiments of the present invention is shown. For example, the secure RPRT frame 1610 may be in... Figure 14 Any of the frames sent in 1440, 1442, 1460, and 1462.

[0334] like Figure 16A As shown, the secure RPRT frame 1610 includes a field 1611 carrying an ID, a field 1612 carrying a security indicator, a field 1613 carrying an address, a field 1614 carrying a PN, a field 1615 carrying a security payload, and a field 1616 carrying a MIC. Fields 1611 to 1614 can be considered as the CHR of the secure RPRT frame 1610. Although the RPRT frame 1610 is shown in compressed PSDU format, the described process can still function even if the frame is carried as a compressed header ID format or even as a conventional 802.15.4 frame.

[0335] Field 1611 can indicate the identifier of a secure RPRT frame 1610. Field 1612 can indicate whether the frame is secure. In some examples, field 1612 carrying a "1" indicates that the frame is secure. Figure 16A As shown, the total length of fields 1611 and 1612 can be one octet.

[0336] Field 1614 can carry the packet number of a Secure RPRT frame 1610. (See reference) Figure 14PN_U1 can be maintained for uplink transmissions from responder 270-1 to initiator 260, and PN_D1 can be maintained for downlink transmissions from initiator 260 to responder 270-1. PN_U2 can be maintained for uplink transmissions from responder 270-2 to initiator 260, and PN_D2 can be maintained for downlink transmissions from initiator 260 to responder 270-2. For example... Figure 16A As shown, the length of field 1614 can be 1 octet.

[0337] Field 1615 carries the security payload. Field 1616 carries the MIC generated by the AEAD transformation process. The length of field 1616 can be 4 octets or 8 octets.

[0338] Alternatively, the Secure RPRT frame 1610 may include a field carrying the security level, which is consistent with... Figure 6A The field 615 is similar.

[0339] Figure 16B A schematic diagram illustrating the format of an ADV-POLL frame 1620 provided by some exemplary embodiments of the present invention is shown. For example, the ADV-POLL frame 1620 may be in... Figure 14 The frame sent at 1422.

[0340] like Figure 16B As shown, ADV-POLL frame 1620 includes a field 1621 carrying an ID, a field 1622 carrying a security indicator, a field 1623 carrying an address, a field 1624 serving as an existence control field, a field 1625 carrying a block index, a field 1626 carrying a round index, a field 1627 carrying a round duration, a field 1628 carrying a payload, and a field 1629 carrying a CRC. Fields 1621-1623 can be considered the CHR of ADV-POLL frame 1620, and fields 1624-1627 can be considered the open payload of ADV-POLL frame 1620.

[0341] Field 1621 indicates the identifier of ADV-POLL frame 1620. Field 1622 indicates whether ADV-POLL frame 1620 is secure. In some examples, field 1622 carrying a "0" indicates that ADV-POLL frame 1620 is insecure. Figure 16B As shown, the total length of fields 1621 and 1622 can be one octet.

[0342] Field 1624 includes: Block Index Existence Field 1681 carrying a Block Index Existence Indicator, Round Index Existence Field 1682 carrying a Round Index Existence Indicator, Round Duration Existence Field 1683 carrying a Round Duration Existence Indicator, and Reserved Field 1684. For example... Figure 16B As shown, the length of field 1624 can be 1 octet.

[0343] In some examples, the block index presence indicator is equal to a first value (e.g., 1) to indicate the presence of block index field 1625, the round index presence indicator is equal to a first value (e.g., 1) to indicate the presence of round index field 1626, and the round duration presence indicator is equal to a first value (e.g., 1) to indicate the presence of round duration field 1627. For example, the length of each field from 1625 to 1627 can be 2 octets.

[0344] Alternatively, the security ADV-POLL frame 1620 may include a field carrying the security level, which is consistent with... Figure 6A Field 615 is similar. Alternatively, the present invention does not limit the order of fields 1625 to 1627 and fields 1681 to 1683.

[0345] Because ADV-POLL frame 1620 is sent at the beginning of a round and includes block structure information (e.g., block index, round index, round duration in fields 1625-1627), the initiator and one or more responders can synchronize to the block structure during the initialization and setup phases.

[0346] Figure 17 An exemplary session 1700 of initiator 260 and respondent 1 (e.g., respondent 270-1) and respondent 2 (e.g., respondent 270-2) provided by some exemplary embodiments of the present invention is illustrated. Assuming the use of... Figure 15B The random number shown is 1520. As a concrete example, assume each block consists of 16 rounds, i.e., NumRounds = 16, so N = 4 can be determined.

[0347] Downlink security frames from initiator to responder 1 are shown in 1710, while downlink security frames from initiator to responder 2 are shown in 1720. The frame counter field used to construct the random number for protecting / unprotecting each frame is shown below the frame.

[0348] like Figure 17 As shown, the ADV-RESP frames from responder 1 and responder 2 are both secure frames sent in round 1 of block 6, and the PN field in both frames can be set to 0 (i.e., as shown). Figure 17As shown, PN = 0x00). The least significant 20 bits (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect ADV-RESP frames can be calculated as 0x06100. Although the FC of the two ADV-RESP frames is the same, this does not violate security because the source address field in the random number is different, and the security keys used for responder 1 and responder 2 are different. Similarly, the 128th RPRT frame (RPRT 128) with the PN field set to 0xFF is sent to responder 1 in round 0 (0x0) of block 127 (0x7F), and the least significant 20 bits (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect RPRT 128 frames can be calculated as 0x7F0FF.

[0349] Potential wraparound of the PN field in an RPRT frame is also shown at 1712 in box 127. If the wraparound of the PN field occurs within the same round, this will cause the frame counter (0x7F000) to repeat (the same counter used for POLL frames (POLL 128)) and result in the reuse of random numbers. However, this problem can be avoided as long as the limit of a maximum of 256 frames per round per device is adhered to, preventing the frame counter from repeating.

[0350] Alternatively, the value of the frame counter field (i.e., FC) can be defined as equation (6). Figure 15A or Figure 15B The same effect can be achieved by constructing a frame counter field for random numbers, without having to divide the frame counter field into PN, round index, and block index fields: FC = Block_Index×NumRounds×2 M + Round_Index×2 M + PN (6)

[0351] In equation (6), Block_index and Round_Index refer to the block index and round index, respectively, and M = the number of bits used for the PN field.

[0352] According to the combination Figures 3 to 17 In some embodiments, block indexes, round indexes, and time slot indexes / PNs can be used to construct random numbers, which can be used to protect frames or deprotect secure frames sent according to block-based or superblock-based time structures. Therefore, AEAD secure operations can be applied, and secure communication between the initiator and the responder can be guaranteed.

[0353] Further reference Figure 18The diagram illustrates a signaling process 1800, provided by some exemplary embodiments of the present invention. Process 1800 may involve a transmitter 1801 and a receiver 1802. It should be understood that, see [link to documentation]. Figure 2A The transmitter 1801 can be either the controller 210 or the controlled device 220, and the receiver 1802 can be either the controlled device 220 or the controller 210. It should be understood that... (See also...) Figure 2B The transmitter 1801 can be either the initiator 260 or the responder 270, and the receiver 1802 can be either the responder 270 or the initiator 260.

[0354] Transmitter 1801 generates (1810) a first secure frame. The first secure frame may be protected by a first random number, wherein the first random number is constructed based on a first base packet number (BPN) and a first PN. In some embodiments, transmitter 1801 may construct the first random number and then generate the first secure frame.

[0355] The first BPN is associated with both the initiator and the responder. Specifically, the first BPN is associated with the communication direction from transmitter 1801 to receiver 1802. For example, if transmitter 1801 is the initiator 260, then the first BPN is a DL BPN; if transmitter 1801 is the responder 270, then the first BPN is a DL BPN. The first PN is the packet number of the first secure frame.

[0356] The first random number comprises a first field carrying a first BPN and a second field carrying a first PN. The length of the first field can be equal to a first quantity, such as N1 bits. The length of the second field can be equal to a second quantity, such as N2 bits. For example, the total quantity of the first and second quantities can be a predefined value, such as 40 bits. The initial value of the first BPN can be stored locally in the transmitter 1801 and can be indicated to the receiver 1802, for example, during session establishment and stored locally in the receiver. Alternatively, a default value (e.g., 0) can be used as the initial value of the first BPN.

[0357] The first random number includes the source address. For example, the first random number may include a field carrying the source address, such as a source address field. The length of the field carrying the source address can be predefined, such as 8 octets, 7 octets, or other values.

[0358] In some exemplary embodiments, the first security frame may be sent during the initialization and setup phase or during the measurement cycle. In some examples, the first security frame may include a first BPN and a first PN. In other examples, the first security frame may include a first PN without a first BPN, in which case a locally stored first BPN may be used.

[0359] The first security frame may include a first security indicator. For example, the first security frame may include a field carrying the first security indicator, such as a security indicator field. The first security indicator may indicate whether the first security frame is secure. For example, the first security indicator may be "1" to indicate that the first security frame is secure. For example, the field carrying the first security indicator may be 1 bit long.

[0360] The first security frame includes a first PN field carrying a first PN. The length of the first PN field can be a predefined value, such as 1 octet.

[0361] The first security frame may include a BPN presence field carrying a BPN presence indicator. The BPN presence indicator can indicate whether a BPN field is included. For example, the BPN presence indicator can be "1" to indicate the presence of a BPN field. The first security frame may include a BPN field carrying a first BPN to allow the receiver to obtain the BPN used to deprotect that frame and subsequent security frames sent by the same initiator. In some examples, if the first BPN is equal to a default number (e.g., 0), the BPN presence indicator can be "0" to indicate that a BPN field is not included.

[0362] Transmitter 1801 sends (1820) a first security frame 1822 to receiver 1802. Receiver 1802 receives (1824) the first security frame 1822. Receiver 1802 deprotects the first security frame 1822 (1830). Specifically, receiver 1802 deprotects the first security frame 1822 by generating a random number based on the first BPN and the first PN.

[0363] Specifically, if the first security frame 1822 includes a BPN field and a first PN field, the receiver 1802 can directly obtain the first BPN and the first PN. If the BPN field is not included, a default value (such as 0) can be used as the first BPN. The receiver 1802 can also construct a random number for deprotecting the first security frame 1822 based on the first BPN and the first PN. The receiver 1802 stores the first BPN locally.

[0364] The random number constructed by receiver 1802 should be the same as the first random number used to protect the first security frame constructed by transmitter 1801. The first random number constructed by receiver 1802 is similar to the random number described above (i.e., the random number constructed by the transmitter), and will not be described in detail for the sake of brevity.

[0365] In some exemplary embodiments, transmitter 1801 may also send a second security frame to receiver 1802, wherein the second security frame includes a second PN but does not include the first BPN. Receiver 1802 may receive the second security frame and construct a second random number for deprotecting the second security frame based on the second PN and the locally stored first BPN. In some examples, if the second PN is less than the PN in the previous security frame, receiver 1802 may determine that the PN has been wrapped around and therefore should update the locally stored first BPN by incrementing by 1.

[0366] In other exemplary embodiments, transmitter 1801 may also send a third security frame to receiver 1802, wherein the third security frame includes a second BPN and a third PN. Receiver 1802 may receive the third security frame. Since the second BPN is different from the locally stored first BPN, receiver 1802 may replace the first BPN with the second BPN. That is, it locally stores the second BPN instead of the first BPN. Receiver 1802 also constructs a third random number based on the second BPN and the third PN for deprotecting the third security frame.

[0367] In this invention, the security frame is generated by protecting the compressed frame, which can be a compressed PSDU frame or a frame with the compressed header IE format described above. Security operations can be performed using cryptographic operations such as authentication or encryption.

[0368] Figure 19 A schematic diagram of an exemplary MMS ranging session 1900 provided by some exemplary embodiments of the present invention is shown. As shown in FIG1900, the MMS ranging session 1900 includes an initialization and setup phase, followed by one or more measurement cycles, wherein the initialization and setup phase is outside the block structure, while the one or more measurement cycles are inside the block structure.

[0369] exist Figure 19 In this context, the PN and the locally stored BPN can be used to construct random numbers for protecting frames, whether outside or inside the block structure, as shown in 1910. Table 4 Table 5 Table 6

[0370] Examples of BPNs stored locally at the initiator (e.g., initiator 26) are shown in Table 4, while examples of BPNs stored locally at the responders (e.g., responders 270-1 and 270-2) are shown in Tables 5 and 6, respectively. DL BPNs are used for security frames sent by the initiator to one or more responders, while UL BPNs are used for security frames sent by one or more responders to the initiator.

[0371] Figure 20 The diagram illustrates a signaling diagram of an exemplary MMS ranging session 2000 provided by some exemplary embodiments of the present invention.

[0372] Similar to some of the embodiments described above, process 2000 begins with the controller and the controlled party performing session establishment 2010. During session establishment 2010, it is assumed that security keys and security levels will be exchanged, and long-term session parameters such as UWB channel number, preamble, and block structure (e.g., number of blocks, block duration) will be negotiated. These long-term parameters are not expected to change during the MMS ranging session. When security is enabled, the controller will also provide each controlled party with at least one security key to protect unicast frames (i.e., frames exchanged between the responder and the initiator). If security is also enabled for broadcast frames, a separate security key shared by all responders will also be provided. For the NBA-MMS ranging session, narrowband-related parameters (e.g., NB channel number, number of MMS fragments, etc.) may also be negotiated during session establishment 2010. Other parameters such as the number of MMS fragments and reporting mode can be considered short-term parameters because they may be modified during the MMS ranging session. Session establishment 2010 can be performed out-of-band, such as using Bluetooth or Wi-Fi radio, or in-band, such as using narrowband or UWB radio.

[0373] Furthermore, the roles of the initiator and responder were also assigned during session establishment in 2010. Figure 20 The specific example shown assumes that the controller assumes the role of initiator 260 and is assigned the role of responder 270 by the controller. However, it should be understood that it is also possible for the controller to be assigned the role of initiator while assuming the role of responder.

[0374] In 2022, the initiator 260 may send ADV-POLL frames at its own discretion and at intervals, while the responder 270 may listen for incoming ADV-POLL frames at its own discretion.

[0375] In 2024, if responder 270 intends to participate in a ranging session with initiator 260, responder 270 responds with an ADV-RESP frame. If security is enabled, the ADV-RESP frame carries a PN and a BPN associated with the uplink transmission; the PN and BPN (UL) are used to construct a random number to protect the ADV-RESP frame. Figure 20 As shown, a secure ADV-RESP frame can be sent from responder 270 to initiator 260.

[0376] Once the initiator 260 has received the ADV-RESP frame, it stores the BPN (UL) locally. In 2026, the initiator 260 sends a SOR frame, which provides the time offset for the start of the first distance measurement period. If security is enabled, the SOR frame carries the PN and the BPN associated with the downlink transmission; the PN and BPN (DL) are used to construct a random number to protect the SOR frame. Figure 20 As shown, a secure SOR frame can be sent from the initiator 260 to the responder 270. Once the responder 270 receives the SOR frame, it stores the BPN (DL) locally. It should be noted that the PN in the uplink (responder to initiator) and downlink (initiator to responder) directions can use different numbering spaces.

[0377] In 2028, initiator 260 sends a POLL frame to responder 270 at the beginning of the first time slot of a round, where the beginning of the first time slot is indicated by the time offset in the SOR frame. Initiator 260 may also include other control information in responder 270's POLL frame. In 2030, responder 270 sends a RESP frame back to initiator 260 upon successfully receiving the POLL frame. The POLL and RESP frames enable time and frequency synchronization between initiator 260 and responder 270.

[0378] During the ranging phase, the initiator 260 and the responder 270 may exchange zero or more UWB RSFs, and optionally exchange one or more UWB RIFs. The RSFs are used to perform the ranging measurement, while the RIFs are used to check the integrity of the ranging measurement. Illustratively, the exchange occurs in... Figure 20 It is shown at positions 2032 and 2034 in the diagram.

[0379] After the initiator 260 or responder 270 has completed receiving all UWB segments from the ranging phase, the reporting phase can begin. During the reporting phase, the initiator 260 or responder 270 can generate a ranging measurement report and send an RPRT frame carrying the measurement report to the peer device. Figure 20As shown, in 2036, initiator 260 sends a secure RPRT frame to responder 270, and in 2038, responder 270 sends a secure RPRT frame to initiator 260.

[0380] Each of the secure POLL, secure RESP, and secure RPRT frames carries a PN. The carried PN and the locally stored BPN can be used to construct random numbers for protecting / unprotecting POLL, RESP, and RPRT frames.

[0381] In addition, such as Figure 20 As shown, PRM-RESP frames and PRM-REQ frames can be exchanged between the initiator 260 and the responder 270. The initiator 260 can send a secure PRM-RESP frame that includes the new BPN (i.e., the new BPN (DL)). The responder 270 can send a secure PRM-REQ frame that includes the new BPN (i.e., the new BPN (UL)). Therefore, the locally stored BPN can be updated.

[0382] This invention illustrates some exemplary formats for frames and random numbers with reference to the accompanying drawings. However, it should be noted that these examples are given for illustrative purposes only and do not impose any limitations on the invention. For example, a frame or random number may include multiple fields, one or more fields may be omitted in some cases, and one or more fields not shown may be included. For example, two or more fields may be combined into one field. For example, a field may be replaced by one or more different fields. For example, a field carrying information may be split into two fields, one field carrying the information and the other field holding it. For example, each length (in octets or bits) may be a fixed value or an adjusted value. For example, the fields may be arranged in another way, such as in a different order. The invention does not limit itself in this respect.

[0383] Figure 21A The diagram illustrates the format of a security frame 2110 during the initialization and setup phases provided by some exemplary embodiments of the present invention. For example, the security frame 2110 may be... Figure 20 The secure ADV-RESP frame sent in 2024 or the secure SOR frame sent in 2026. The secure frame 2110 can be based on a compressed PSDU, a compressed header ID format, or even a traditional 802.15.4 frame format. In this case, the security enable field in the frame control (FC) field is set to 1 to indicate that the secondary security header field is not present in the MHR.

[0384] like Figure 21AAs shown, the security frame 2110 includes a field 2111 carrying an ID, a field 2112 carrying a security indicator, a field 2113 carrying an address, a field 2114 serving as an presence control field (including a field 2114-1 carrying a BPN presence indicator and a reserved field 2114-2), a field 2115 carrying a PN, a field 2116 carrying a BPN, a field 2117 carrying a security payload, and a field 2118 carrying a MIC.

[0385] Field 2112 can indicate whether a frame is secure. In some examples, field 2112 can carry a "1" to indicate that the field is secure. In other examples, field 2112 can carry a "0" to indicate that the field is insecure, for example, field 2115 may be omitted.

[0386] Fields 2114 to 2116 can be considered as the open payload of security frame 2110. The open payload can be authenticated but not encrypted because the BPN and PN are used by the receiver to construct random numbers.

[0387] In the case that security frame 2110 is a secure ADV-RESP frame, field 2116 may include the BPN associated with the uplink transmission, i.e., BPN_UL. In the case that security frame 2110 is a secure SOR frame, field 2116 may include the BPN associated with the downlink transmission, i.e., BPN_DL. If the secure SOR frame is broadcast or multicast, multiple BPNs associated with multiple responders may be included in the open payload. In this case, the PN may also be extracted from a separate broadcast PN space.

[0388] In some examples, security frame 2110 may include a field carrying the security level, for example, if the security level is not negotiated during session establishment 2110.

[0389] Figure 21B A schematic diagram illustrating the format of a security frame 2120 during a measurement period provided by some exemplary embodiments of the present invention is shown. For example, the security frame 2120 may be... Figure 20 The secure frame 2120 can be a secure POLL frame sent at 2028, a secure RESP frame sent at 2030, or a secure RPRT frame sent at 2036 / 2038. Secure frame 2120 can be based on a compressed PSDU.

[0390] like Figure 21B As shown, security frame 2120 includes a field 2121 carrying an ID and a field carrying a security indicator (e.g., Figure 21B The fields 2122 ("1"), 2123 (address), 2124 (PN), 2125 (security payload), and 2126 (MIC) are included.

[0391] In some examples, security frame 2120 is similar to the security RPRT frame 1610 described above, so for the sake of brevity, it will not be described in detail.

[0392] Figure 21C A schematic diagram illustrating the format of a secure SOR frame 2130 provided by some exemplary embodiments of the present invention is shown. For example, the secure frame 2130 may be based on a frame with a compressed header IE format, i.e., a format based on a compressed header IE.

[0393] like Figure 21C As shown, the secure SOR frame 2130 includes a field 2131 carrying the FC, a field 2132 carrying the address, a field 2133 carrying the ID, and a field carrying a security indicator (e.g., ...). Figure 21C The fields 2134 (with a "1"), the fields that are presence control fields (including field 2135-1 carrying the BPN presence indicator and reserved field 2135-2), field 2136 carrying the PN, field 2137 carrying the payload, and field 2138 carrying the MIC. It should be understood that since the BPN presence indicator in field 2135-1 is "0", there is no field carrying the BPN. The security enable field in frame control (FC) field 2131 is set to 1 to indicate that the secondary security header field is not present in the MHR. In this case, the secure SOR frame 2130 does not include the BPN field, and the applied security level only involves authentication (i.e., security level is any one of 1, 2, or 3), therefore the payload in field 2137 is insecure, but field 2138 carrying the MIC is included.

[0394] It should be noted that when carrying a k-bit field containing the PN, a maximum of 2 bits can be protected before incrementing the BPN. k A compressed frame. For example, if k = 8 bits, then for the same BPN, a maximum of 256 frames can be protected.

[0395] In some examples, the locally stored BPN should be incremented by 1 when the PN of a security frame received from the transmitter is less than the PN of a previous security frame received from the same transmitter. In other examples, the BPN can be explicitly updated during the measurement session. For example, the BPN can be updated using Security PRM-REQ (for UL) or Security PRM-RESP (for DL).

[0396] Figure 21DA schematic diagram illustrating the format of a secure PRM-REQ or PRM-RESP frame 2140 provided by some exemplary embodiments of the present invention is shown. The secure frame 2140 includes an SHR field 2141, a PHR field 2142, and a PHY payload field 2143.

[0397] Field 2143 includes field 2151 carrying an ID, and field 2151 carrying a security indicator (e.g., Figure 21D The fields 2152 ("1"), 2153 (carrying address), 2154 (including field 2154-1 carrying BPN presence indicator and reserved field 2154-2) (as presence control field), 2155 (carrying PN), 2156 (carrying BPN), 2157 (carrying security payload), and 2158 (carrying MIC).

[0398] Fields 2154 to 2156 can be considered as the open payload of security frame 2140. The open payload can be authenticated but not encrypted because the BPN and PN are used by the receiver to construct random numbers.

[0399] In some examples, field 2143 in security frame 2140 is similar to that in security frame 2110 described above, so for the sake of brevity, it will not be described in detail.

[0400] Figure 21E A schematic diagram illustrating the format of a random number 2150 provided by some exemplary embodiments of the present invention is shown. The random number 2150 can be used to protect or deprotect a security frame, for example, during process 2000.

[0401] like Figure 21E As shown, random number 2150 includes frame 2151 carrying the source address, field 2152 carrying the PN, and field 2153 carrying the BPN. In some examples, fields 2152 to 2153 can be considered as a frame counter for random number 2150. Figure 21E As shown, the length of each field from 2152 to 2153 is predefined, and the total length is 40 bits.

[0402] Alternatively, the random number 720 may include a field carrying the security level. Alternatively, field 2153 may be split into two fields, one carrying the BPN and the other reserved. Alternatively, field 2152 may follow field 2153, meaning the order of fields 2152 and 2153 can be reversed.

[0403] Figure 22AAn exemplary downlink session 2210 from the initiator to the responder 1 (e.g., responder 270-1) provided by some exemplary embodiments of the present invention is illustrated. The value in the frame counter field (i.e., FC) is shown below the frame; this field is used to construct a random number for protecting / deprotecting each frame.

[0404] like Figure 22A As shown, an SOR frame can be as follows: Figure 21A The security SOR frame shown carries BPN = 0x00 and PN = 0x00. Therefore, the first POLL frame (POLL 1) is sent to responder 1 in round 0 of block 0, carrying a PN field set to 0x01, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the POLL 1 frame can be calculated as 0x0001. Similarly, the 128th RPRT frame (RPRT 128) carrying PN = 0xFF is sent in round 0 of block 127, and the least significant two octets (in hexadecimal) of the frame counter field used to construct the random number used to protect / deprotect the RPRT 128 frame can be calculated as 0x00FF. Figure 22A As shown, the BPN associated with the downlink transmission from the initiator to the responder 1 can be explicitly updated by the initiator in 2212 by sending a PRM-RESP 1 frame carrying a BPN field set to 0x01.

[0405] Figure 22B An exemplary uplink session 2220 from responder 2 (e.g., responder 270-2) to initiator is shown, provided by some exemplary embodiments of the present invention. The value in the frame counter field (i.e., FC) is shown below the frame; this field is used to construct a random number for protecting / deprotecting each frame.

[0406] like Figure 22BAs shown, an ADV-RESP frame can be a secure frame carried by responder 2, carrying BPN = 0x07 and PN = 0x01. Therefore, the first RESP frame (RESP 1) is sent by responder 2 in round 1 of block 20, carrying a PN field set to 0x02, and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / unprotecting the RESP 1 frame can be calculated as 0x0702. Similarly, the 128th RPRT frame (RPRT 128) carrying PN = 0xFF is sent by responder 2 in round n of block 227, and the least significant two octets (in hexadecimal) of the frame counter field used to construct a random number for protecting / unprotecting the RPRT 128 frame can be calculated as 0x07FF. Figure 22B As shown, the BPN associated with the uplink transmission from responder 2 to initiator can be explicitly updated by responder 2 in 2222 by sending a PRM-REQ1 frame carrying a BPN field set to 0x08.

[0407] Alternatively, the value of the frame counter field (i.e., FC) can be defined as equation (7). Figure 21E The same effect can be achieved by constructing a frame counter field for random numbers without having to divide the frame counter field into PN and BPN fields: FC = PN || BPN (7)

[0408] In equation (7), "||" represents a cascading operation.

[0409] According to the reference Figures 18 to 22B In some embodiments, BPN and PN can be used to construct random numbers, which can be used to protect or deprotect frames, regardless of whether the secure frame is sent according to a block-based or superblock-based time structure. Therefore, AEAD secure operations can be applied, and secure communication between the initiator and the responder can be guaranteed.

[0410] Figure 23 An exemplary block diagram of a communication device 2300 provided in some embodiments of the present invention is shown. The device 2300 may be implemented at a transmitter, such as... Figure 3 Transmitter 301 or Figure 18 The transmitter 1801 in the example, or implemented as a chip or chip system within the transmitter. For example... Figure 23 As shown, the device includes a generation module 2310 and a transmission module 2320.

[0411] It should be understood that this module may be referred to as a unit or means, and the present invention does not limit this in this respect.

[0412] In some exemplary embodiments, generation module 2310 can be used to generate a first security frame, which is to be transmitted in a time slot within a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, wherein the block-based time structure or the superblock-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, each of the multiple rounds includes multiple time slots, wherein the first security frame is protected by a first random number, which is constructed based on identification information, a round index, and a block index associated with the first security frame, wherein the round index is an index of the first round, and the block index is an index of the first block. Transmission module 2320 can be used to transmit the first security frame.

[0413] In some examples, the identification information includes a time slot index, which is an index of the time slot in which the first secure frame was transmitted. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index.

[0414] In some examples, the first quantity is determined based on the number of the plurality of time slots in each round, or the first quantity is a first predefined quantity.

[0415] In some examples, the identification information includes a first packet number (PN), wherein the first PN is the packet number of the first secure frame. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN.

[0416] In some examples, the first quantity is a first predefined quantity.

[0417] In some examples, the first random number includes: a second field with a second number of bits carrying the round index; and a third field with a third number of bits carrying the block index.

[0418] In some examples, the second quantity is determined based on the number of the plurality of wheels in each block, or the second quantity is a second predefined quantity. In some examples, the third quantity is a third predefined quantity.

[0419] In some examples, the sum of the first quantity, the second quantity, and the third quantity equals a predefined total quantity.

[0420] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a periodic index, which is an index of a period comprising a plurality of blocks, wherein the first block is in the plurality of blocks.

[0421] In some examples, the first random number includes a first block indicator that indicates that the first security frame is sent according to the block-based time structure or the superblock-based time structure.

[0422] In some examples, the first security frame includes the block index and the round index. In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0423] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0424] In some examples, the generation module 2310 can also be used to generate a second secure frame to be sent, wherein the second secure frame is protected by a second random number constructed according to a second PN, wherein the second PN is the packet number of the second secure frame. The sending module 2320 can also be used to send the second secure frame.

[0425] In some examples, the second random number includes a field with a predefined number of octet bytes that carries the second PN.

[0426] In some examples, the second random number includes a second block indicator that indicates that the second secure frame is sent outside the block-based time structure or the superblock-based time structure.

[0427] In some examples, the second security frame includes a PN field carrying the second PN.

[0428] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0429] In some examples, the second security frame includes a security payload, wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second timeslot index presence indicator indicating whether a second timeslot index is included.

[0430] In some examples, the secure payload includes the block index if the second block index presence indicator indicates that the second block index is included; the secure payload includes the round index if the second round index presence indicator indicates that the second round index is included; and the secure payload includes the time slot index if the second time slot index presence indicator indicates that the second time slot index is included.

[0431] In some examples, at least one of the second block index presence indicator, the second round index presence indicator, or the second time slot index presence indicator indicates that the corresponding index is not included, and implicitly indicates that the corresponding index is the default index.

[0432] Device 2300 can be used in reference Figures 3 to 17 Some embodiments are implemented at the transmitter described.

[0433] In some other exemplary embodiments, the generation module 2310 can be used to generate a first secure frame to be transmitted in a block-based time structure or a superblock-based time structure, wherein the first secure frame is protected by a first random number constructed based on a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being the packet number of the first secure frame. The transmission module 2320 can be used to transmit the first secure frame.

[0434] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0435] In some examples, the first random number includes: a first field having a first number of bits carrying the first BPN; and a second field having a second number of bits carrying the first PN.

[0436] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0437] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0438] In some examples, if the BPN presence indicator indicates that the BPN field is included, then the first security frame includes the BPN field carrying the first BPN.

[0439] In some examples, if the BPN presence indicator indicates that the BPN field is not included, then the first security frame indicates that the first BPN is the default number.

[0440] In some examples, the device 2300 may also include a storage module for storing a first BPN associated with a first communication direction between the initiator and the responder.

[0441] In some examples, the sending module 2320 may be used to send a second security frame that includes a second PN, the second PN being smaller than the PN included in the preceding frame of the third security frame.

[0442] In some examples, the sending module 2320 can be used to send a third security frame that includes a second BPN.

[0443] Device 2300 can be used in reference Figures 18 to 22B Some embodiments are implemented at the transmitter described.

[0444] Figure 24 An exemplary block diagram of a communication device 2400 provided in some embodiments of the present invention is shown. The device 2400 may be implemented at a receiver, such as... Figure 3 Receiver 302 or Figure 18 The receiver 1802 in the receiver, or implemented as a chip or chip system within the receiver. For example... Figure 24 As shown, the device includes a receiving module 2410 and a protection release module 2420.

[0445] It should be understood that this module may be referred to as a unit or means, and the present invention does not limit this in this respect.

[0446] In some exemplary embodiments, the receiving module 2410 may be used to receive a first security frame, which is transmitted in a time slot in a first round belonging to a first block according to a block-based time structure or a superblock-based time structure, wherein the block-based time structure or the superblock-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, and each of the multiple rounds includes multiple time slots; the deprotection module 2420 may be used to deprotect the first security frame according to a first random number, wherein the first random number is constructed based on identification information, a round index, and a block index associated with the first security frame, wherein the round index is the index of the first round, and the block index is the index of the first block.

[0447] In some examples, the identification information includes a time slot index, which is an index of the time slot in which the first secure frame was transmitted. In some examples, the first random number includes a first field having a first number of bits, the first field carrying the time slot index.

[0448] In some examples, the first quantity is determined based on the number of the plurality of time slots in each round, or the first quantity is a first predefined quantity.

[0449] In some examples, the identification information includes a first packet number (PN), wherein the first PN is the packet number of the first security frame.

[0450] In some examples, the first random number includes a first field having a first number of bits, the first field carrying the first PN. In some examples, the first number is a first predefined number.

[0451] In some examples, the first random number includes: a second field with a second number of bits carrying the round index; and a third field with a third number of bits carrying the block index.

[0452] In some examples, the second quantity is determined based on the number of the plurality of wheels in each block, or the second quantity is a second predefined quantity. In some examples, the third quantity is a third predefined quantity.

[0453] In some examples, the sum of the first quantity, the second quantity, and the third quantity equals a predefined total quantity.

[0454] In some examples, the first random number includes: a fourth field having a fourth number of bits, carrying a periodic index, which is an index of a period comprising a plurality of blocks, wherein the first block is in the plurality of blocks.

[0455] In some examples, the first random number includes a first block indicator that indicates that the first security frame is sent according to the block-based time structure or the superblock-based time structure.

[0456] In some examples, the first security frame includes the block index and carries the round index.

[0457] In some examples, the first security frame includes: a first block index presence indicator indicating the presence of the first block index; and a first round index presence indicator indicating the presence of the first round index.

[0458] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0459] In some examples, the receiving module 2410 can also be used to receive a second secure frame that is not transmitted according to the block-based time structure or the superblock-based time structure. The deprotection module 2420 can also be used to deprotect the second secure frame according to a second random number constructed based on a second PN, wherein the second PN is the packet number of the second secure frame.

[0460] In some examples, the second random number includes a field with a predefined number of octet bytes that carries the second PN.

[0461] In some examples, the second random number includes a second block indicator that indicates that the second frame is transmitted outside the block-based time structure or the superblock-based time structure.

[0462] In some examples, the second security frame includes a PN field carrying the second PN.

[0463] In some examples, the second security frame includes a second security indicator to indicate that the second security frame is secure.

[0464] In some examples, the second security frame includes a security payload, wherein deprotecting the second security frame includes deprotecting the security payload according to the second random number, and wherein the security payload includes: a second block index presence indicator indicating whether a second block index is included; a second round index presence indicator indicating whether a second round index is included; and a second timeslot index presence indicator indicating whether a second timeslot index is included.

[0465] In some examples, the secure payload includes the block index if the second block index presence indicator indicates that the second block index is included; the secure payload includes the round index if the second round index presence indicator indicates that the second round index is included; and the secure payload includes the time slot index if the second time slot index presence indicator indicates that the second time slot index is included.

[0466] In some examples, the deprotection module 2420 may be used to: determine that the corresponding index is a default index based on at least one of the second block index existence indicator, the second round index existence indicator, or the second time slot index existence indicator indicating that the corresponding index is not included.

[0467] Device 2400 can be used in reference Figures 3 to 17 Some embodiments are implemented at the described receiver.

[0468] In some other exemplary embodiments, the receiving module 2410 may be used to receive a first secure frame, which is transmitted in a block-based time structure or a superblock-based time structure. The de-security module 2420 may be used to de-protect the first secure frame according to a first random number, wherein the first random number is constructed based on a first base packet number (BPN) and a first packet number (PN), the first BPN being associated with an initiator and a responder, and the first PN being the packet number of the first secure frame.

[0469] In some examples, the first security frame includes a first security indicator to indicate that the first security frame is secure.

[0470] In some examples, the first random number includes: a first field having a first number of bits carrying the first BPN; and a second field having a second number of bits carrying the first PN.

[0471] In some examples, the first security frame includes a first PN field carrying the first PN. In some examples, the first security frame indicates a first BPN.

[0472] In some examples, the first security frame includes a BPN presence field that carries a BPN presence indicator indicating whether a BPN field is included.

[0473] In some examples, if the BPN presence indicator indicates that the BPN field is included, then the first security frame includes the BPN field carrying the first BPN.

[0474] In some examples, if the BPN presence indicator indicates that the BPN field is not included, then the first security frame indicates that the first BPN is the default number.

[0475] In some examples, the device 2400 may also include a storage module for storing a first BPN associated with a first communication direction between the initiator and the responder.

[0476] In some examples, receiving module 2410 can also be used to receive a second security frame that includes a second PN. Apparatus 2400 may also include an update module configured to update a locally stored first BPN by incrementing it by 1 if the second PN is less than the PN included in the preceding frame of the third security frame.

[0477] In some examples, the receiving module 2410 can also be used to receive a third security frame that includes a second BPN. The apparatus 2400 may also include an update module for replacing the first BPN with the second BPN.

[0478] Device 2400 can be used in reference Figures 18 to 22B Some embodiments are implemented at the described receiver.

[0479] Figure 25 A schematic block diagram of a device 2500 that can be used to implement some embodiments of the present invention is shown. Device 250 can be considered as follows: Figure 2A The controller 210 and the controlled device 220 shown, or as... Figure 2BAnother exemplary implementation (e.g., partial) of the initiator 260 and responder 270 shown.

[0480] As shown in the figure, device 2500 includes a processor 2510, a memory 2520 coupled to the processor 2510, suitable transmitters (TX) and receivers (RX) 2540 coupled to the processor 2510, and a communication interface coupled to the TX / RX 2540. The memory 2510 stores at least a portion of a program 2530. The TX / RX 2540 is used for bidirectional communication. The TX / RX 2540 has at least one antenna to facilitate communication, but in practice, the access node mentioned in this invention may have several antennas. The communication interface can represent any interface required for communication with other network elements, such as an X2 interface for bidirectional communication between eNBs, an S1 interface for communication between a mobility management entity (MME) / serving gateway (S-GW) and an eNB, an Un interface for communication between an eNB and a relay node (RN), or a Uu interface for communication between an eNB and a terminal device.

[0481] Assuming program 2530 includes program instructions that, when executed by the associated processor 2510, enable device 2500 to operate according to an embodiment of the invention, as referenced herein. Figures 3 to 24 The embodiments discussed herein can be implemented by computer software executable by the processor 2510 of device 2500, or by hardware, or by a combination of software and hardware. The processor 2510 can be used to implement various embodiments of the invention. Furthermore, a combination of the processor 2510 and the memory 2520 can form a processing apparatus 2550 for implementing various embodiments of the invention.

[0482] Memory 2520 can be of any type suitable for the local technology network and can be implemented using any suitable data storage technology, such as non-transitory computer-readable storage media, semiconductor-based memory devices, magnetic memory devices and systems, optical memory devices and systems, fixed memory, and removable memory (as non-limiting examples). Although only one memory 2520 is shown in device 2500, several physically different memory modules may exist in device 2500. Processor 2510 can be of any type suitable for the local technology network and can include one or more of a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), and a processor based on a multi-core processor architecture (as non-limiting examples). Device 2500 can have multiple processors, such as application-specific integrated circuit chips that are time-dependent on a clock synchronized with the main processor.

[0483] The present invention provides an apparatus comprising: a processor; and a memory storing computer program code; the memory and the computer program code being configured to cause the apparatus to perform the methods described above implemented at the transmitter or receiver via the processor.

[0484] The present invention provides a computer-readable medium storing instructions that, when executed by a processor of a device, cause the device to perform the method described above implemented at a transmitter or receiver.

[0485] In general, various embodiments of the present invention can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. Some aspects can be implemented in hardware, while others can be implemented in firmware or software, which can be executed by a controller, microprocessor, or other computing device. Although various aspects of embodiments of the present invention are shown and described as block diagrams, flowcharts, or using some other graphical representation, it should be understood that the blocks, apparatuses, systems, techniques, or methods described herein can be implemented in hardware, software, firmware, dedicated circuitry or logic, general-purpose hardware or controllers or other computing devices (as non-limiting examples), or some combination thereof.

[0486] The present invention also provides at least one computer program product tangibly stored on a non-transitory computer-readable storage medium. The computer program product includes computer-executable instructions that execute in a device on a target real or virtual processor, such as instructions included in a program module, to perform the functions described above. Figures 3 to 24The process or method described herein. Typically, a program module includes routines, programs, libraries, objects, classes, components, data structures, etc., that perform specific tasks or implement specific abstract data types. In various embodiments, the functionality of a program module can be combined or split among program modules as needed. The machine-executable instructions of a program module can execute on a local device or a distributed device. In a distributed device, the program module can reside on local storage media and remote storage media.

[0487] The program code used to implement the methods of the present invention can be written in any combination of one or more programming languages. This program code can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor or controller, the program code enables the functions / operations specified in the flowchart or block diagram to be implemented. The program code can be executed entirely on a single machine, partially on a machine as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0488] The aforementioned program code may be embodied on a machine-readable medium, which may be any tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. More specific examples of machine-readable storage media will include electrical connections having one or more wires, portable computer floppy disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disc read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0489] Furthermore, although operations are described in a specific order, this should not be construed as requiring such operations to be performed in the specific order shown or sequentially, or requiring the execution of all operations shown to achieve the desired result. In some cases, multitasking and parallel processing may be advantageous. Similarly, while some specific implementation details are included in the discussion above, these should not be construed as limiting the scope of the invention, but rather as descriptions of features specific to particular embodiments. In the context of a single embodiment, certain features described herein may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented individually in multiple embodiments or in any suitable sub-combination.

[0490] Although the invention has been described in language specific to structural features or methodological actions, it should be understood that the invention as defined in the appended claims is not necessarily limited to the specific features or actions described above. In fact, the disclosure of the aforementioned specific features and actions serves as illustrative examples of implementing the claims.

Claims

1. A method, characterized in that, include: A first security frame is generated, which is to be transmitted in a time slot in a first round belonging to the first block according to a block-based time structure or a superblock-based time structure, wherein the block-based time structure or the superblock-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, each of the multiple rounds includes multiple time slots, wherein the first security frame is protected by a first random number, which is constructed based on identification information, a round index, and a block index associated with the first security frame, wherein the round index is the index of the first round, and the block index is the index of the first block; Send the first security frame.

2. The method according to claim 1, characterized in that, The identification information includes a time slot index, which is the index of the time slot in which the first security frame was sent.

3. The method according to claim 2, characterized in that, The first random number includes a first field having a first number of bits, the first field carrying the time slot index.

4. The method according to claim 3, characterized in that, The first quantity is determined based on the number of the plurality of time slots in each round, or the first quantity is a first predefined quantity.

5. The method according to claim 1, characterized in that, The identification information includes a first packet number PN, wherein the first PN is the packet number of the first security frame.

6. The method according to claim 5, characterized in that, The first random number includes a first field having a first number of bits, the first field carrying the first PN.

7. The method according to claim 6, characterized in that, The first quantity is the first predefined quantity.

8. The method according to any one of claims 3 to 4 or 6 to 7, characterized in that, The first random number includes: A second field, having a second number of bits, carries the round index; A third field, having a third number of bits, carries the block index.

9. The method according to claim 8, characterized in that, The second quantity is determined based on the number of the plurality of wheels in each block, or the second quantity is a second predefined quantity.

10. The method according to claim 8, characterized in that, The third quantity is a third predefined quantity.

11. The method according to claim 8, characterized in that, The sum of the first quantity, the second quantity, and the third quantity equals the predefined total quantity.

12. The method according to any one of claims 1 to 7 or 9 to 11, characterized in that, The first random number includes: A fourth field, having a fourth number of bits, carries a periodic index, which is an index of a period comprising multiple blocks, wherein the first block is in the multiple blocks.

13. The method according to any one of claims 1 to 7 or 9 to 11, characterized in that, The first random number includes a first block indicator, which indicates that the first security frame is sent according to the block-based time structure or the superblock-based time structure.

14. The method according to any one of claims 1 to 7 or 9 to 11, characterized in that, The first security frame includes the block index and the round index.

15. The method according to claim 14, characterized in that, The first security frame includes: The first index exists as an indicator, indicating the existence of the first index. The first-round index exists as an indicator, indicating the existence of the first-round index.

16. The method according to any one of claims 1 to 7 or 9 to 11, characterized in that, The first security frame includes a first security indicator to indicate that the first security frame is secure.

17. The method according to any one of claims 1 to 7 or 9 to 11, characterized in that, Also includes: A second security frame to be sent is generated, the second security frame being protected by a second random number constructed according to a second PN, wherein the second PN is the packet number of the second security frame; Send the second security frame.

18. The method according to claim 17, characterized in that, The second random number includes a field with a predefined number of octet bytes, the field carrying the second PN.

19. The method according to claim 17, characterized in that, The second random number includes a second block indicator that indicates the second security frame is sent outside the block-based time structure or the superblock-based time structure.

20. An apparatus, characterized in that, include: A generation module is configured to generate a first security frame, which is to be transmitted in a time slot within a first round belonging to a first block according to a block-based time structure or a superblock-based time structure. The block-based time structure or the superblock-based time structure includes multiple blocks, each of the multiple blocks includes multiple rounds, and each of the multiple rounds includes multiple time slots. The first security frame is protected by a first random number, which is constructed based on identification information, a round index, and a block index associated with the first security frame. The round index is the index of the first round, and the block index is the index of the first block. The sending module is used to send the first security frame.

21. The apparatus according to claim 20, characterized in that, The identification information includes a time slot index, which is the index of the time slot in which the first security frame was sent.

22. The apparatus according to claim 21, characterized in that, The first random number includes a first field having a first number of bits, the first field carrying the time slot index.

23. The apparatus according to claim 22, characterized in that, The first quantity is determined based on the number of the plurality of time slots in each round, or the first quantity is a first predefined quantity.

24. The apparatus according to claim 20, characterized in that, The identification information includes a first packet number PN, wherein the first PN is the packet number of the first security frame.

25. The apparatus according to claim 24, characterized in that, The first random number includes a first field having a first number of bits, the first field carrying the first PN.

26. The apparatus according to claim 25, characterized in that, The first quantity is the first predefined quantity.

27. The apparatus according to any one of claims 20 to 26, characterized in that, The first random number includes: A second field, having a second number of bits, carries the round index; A third field, having a third number of bits, carries the block index; The second quantity is determined based on the number of the plurality of wheels in each block, or the second quantity is a second predefined quantity.

28. The apparatus according to claim 27, characterized in that, The third quantity is a third predefined quantity.

29. A computer-readable medium, characterized in that, The computer-readable medium stores instructions that, when executed by a processor of the device, cause the device to perform the method according to any one of claims 1 to 19.

30. A computer instruction product, characterized in that, The computer instruction product stores computer-executable instructions that, when executed by the processor of the device, cause the device to perform the method according to any one of claims 1 to 19.

Citation Information

Patent Citations

  • Security frames in uwband

    CN119968873A