Accelerated key exchange in wireless networks
By transmitting the previously obtained security key as an encrypted payload in the frame during the pairing process of wireless communication devices, the key exchange delay problem is solved, improving the efficiency of pairing setup and user experience.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-05
- Publication Date
- 2026-03-27
AI Technical Summary
In existing wireless communications, the key exchange delay during device pairing is relatively long, which affects the user experience.
During the authentication process of the pairing procedure, the previously obtained security key is included as an encrypted payload in the frame for transmission, reducing the waiting time for subsequent frames.
By reducing the overall latency of key exchange, the efficiency of pairing setup and the user experience are improved.
Smart Images

Figure CN121753373A_ABST
Abstract
Description
Cross-references to related applications
[0001] This application claims priority to Indian Patent Application No. 202341057530, filed on August 28, 2023, which has been assigned to the assignee of this application and is hereby expressly incorporated herein by reference in its entirety, as fully set forth below and for all applicable purposes. Technical Field
[0002] This invention relates generally to wireless communication, and more specifically, to the exchange of security keys in wireless networks. Background Technology
[0003] A Wireless Local Area Network (WLAN) can be formed by one or more wireless access points (APs) that provide a shared wireless communication medium for use by multiple client devices (also known as wireless stations (STAs)). The basic building block of a WLAN conforming to the IEEE 802.11 family of standards is the Basic Service Set (BSS) managed by the AP. Each BSS is identified by a Basic Service Set Identifier (BSSID) advertised by the AP. The AP periodically broadcasts beacon frames to enable any STA within the AP's wireless range to establish or maintain a communication link with the WLAN.
[0004] However, in some scenarios, devices can communicate directly with each other using peer-to-peer (P2P) protocols or other such technologies. In such cases, the concept of a BSS may not exist, and peer devices can communicate with each other without assistance from an AP.
[0005] In some WLANs, devices can perform a pairing procedure before communicating with each other. In this context, device pairing typically refers to establishing a secure wireless connection between devices. Various device pairing protocols have been proposed, in which different message sequences are exchanged and different security types and / or levels are implemented. Summary of the Invention
[0006] The systems, methods, and apparatus disclosed herein each have several innovative aspects, and no single aspect is solely responsible for the desired properties disclosed herein.
[0007] One aspect provides a method for wireless communication at a first wireless node. The method includes outputting a first frame for transmission as part of an authentication process for establishing a pairing procedure with a second wireless node, wherein the first frame includes an encrypted payload having at least a first previously obtained security key; obtaining a second frame as part of the pairing procedure; and, if the second frame also includes at least the first previously obtained security key, confirming the pairing procedure.
[0008] Other aspects provide: an apparatus capable of operating to perform one or more of the methods described herein and / or other methods elsewhere, configured to perform one or more of the methods described herein and / or other methods elsewhere, or otherwise adapted to perform one or more of the methods described herein and / or other methods elsewhere; a non-transitory computer-readable medium comprising instructions that, when executed by a processor of the apparatus, cause the apparatus to perform the methods described herein and other methods elsewhere; a computer program product embodied on a computer-readable storage medium comprising: code for performing the methods described herein and other methods elsewhere; and / or an apparatus comprising components for performing the methods described herein and other methods elsewhere. By way of example, an apparatus may include a processing system, a device having a processing system, or a processing system cooperating via one or more networks.
[0009] Details of one or more specific embodiments of the subject matter described in this disclosure are set forth in the accompanying drawings and the description below. Other features, aspects, and advantages will become apparent from the description, drawings, and claims. Note that the relative dimensions in the following drawings may not be drawn to scale. Attached Figure Description
[0010] The accompanying drawings depict certain features of the various aspects described herein and should not be considered as limiting the scope of this disclosure.
[0011] Figure 1 A schematic diagram of an example wireless communication network is shown.
[0012] Figure 2 A schematic diagram of an example neighbor-aware network (NAN) in which various aspects of this disclosure can be utilized is shown.
[0013] Figure 3 A call flowchart illustrating an example process for exchanging security keys is shown.
[0014] Figure 4 A call flowchart illustrating another example process for exchanging security keys is shown.
[0015] Figure 5 The format of an example data structure for transmitting a security key as an encrypted payload is shown.
[0016] Figure 6 A flowchart illustrating an example process that can be performed by a wireless station supporting accelerated exchange of secure keys or at a wireless station supporting accelerated exchange of secure keys is shown.
[0017] Figure 7 A block diagram of an example wireless communication device that supports accelerated exchange of secure keys is shown.
[0018] The same reference numerals and names in various figures indicate the same elements. Detailed Implementation
[0019] The following description involves specific examples intended to illustrate the innovative aspects of this disclosure. However, those skilled in the art will readily recognize that the teachings herein can be applied in a variety of different ways. Some or all of the examples described can be applied in accordance with IEEE 802.11, IEEE 802.15, or Bluetooth standards as defined by the Bluetooth Special Interest Group (SIG). ® This can be implemented in any device, system, or network that transmits and receives radio frequency (RF) signals using one or more of the following standards or those published by the 3rd Generation Partnership Project (3GPP): Long Term Evolution (LTE), 3G, 4G, or 5G (New Radio (NR)). The described examples can be implemented in any device, system, or network capable of transmitting and receiving RF signals according to one or more of the following technologies or techniques: Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Orthogonal Frequency Division Multiplexing (OFDM), Frequency Division Multiple Access (FDMA), Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA), Space Division Multiple Access (SDMA), Rate Split Multiple Access (RSMA), Multi-User Shared Access (MUSA), Single-User (SU) Multiple-Input Multiple-Output (MIMO), and Multi-User (MU)-MIMO (MU-MIMO). The described examples can also be implemented using other wireless communication protocols or RF signals suitable for use in one or more of the following networks: Wireless Personal Area Network (WPAN), Wireless Local Area Network (WLAN), Wireless Wide Area Network (WWAN), Wireless Metropolitan Area Network (WMAN), or Internet of Things (IoT).
[0020] The various aspects involve wireless communication as a whole, and more specifically, technologies that can help accelerate key exchange during the pairing process.
[0021] Pairing procedures enable a pair of wireless devices to authenticate each other when they establish initial trust and to verify each other's identities after they have established a pairing relationship. Pairing can be opportunistic or password-based. For password-based pairing, devices may require additional bootstrapping to ensure they have the same password. The exact pairing mechanism can depend on the specific type of wireless network. For example, in Neighbor-Aware Networks (NANs), examples of which are found in… Figure 2As shown in the diagram, also known as Wi-Fi Sensing, the pairing process can involve the NAN pairing setup protocol and the NAN pairing verification protocol.
[0022] In a typical NAN pairing procedure, a device with NAN pairing capability generates a key called the NAN Identity Key (NIK). This NIK is then used to generate parameters called the NAN Identity Resolution Attribute (NIRA). The NIRA is included in the NAN Service Discovery Frame (SDF) to reveal the device's long-term identity to the paired peers. (See reference below.) Figure 3 In further detail, the NIK, along with other parameters (such as the lifetime indicating how long the NIK is valid), is typically exchanged in a shared key descriptor element (KDE) that is encrypted with the NAN management key encryption key (NM-KEK) of the encrypted message, which is typically exchanged only after the Pre-Associated Security Negotiation (PASN) authentication exchange.
[0023] Therefore, after PASN, an additional subsequent frame is typically required to share the NIK with the paired device. Along with the NIK and NIK lifetime, devices can also exchange various group key KDEs and their corresponding lifetime KDEs. Unfortunately, transmitting the NIK (and other keys) in a subsequent frame only after the authentication or pairing process is complete increases the latency of the pairing procedure and may affect the user experience.
[0024] However, aspects of this disclosure can help accelerate such key exchanges. For example, the NIK and / or other KDEs can be provided as an encrypted payload (“carried”) in frames sent as part of the PASN, avoiding the need to wait for additional subsequent frames. The NIK can be available at this stage, for example, allowing the device to store previously acquired NIKs if NIK caching is enabled.
[0025] Specific aspects of the subject matter described in this disclosure can be implemented to achieve one or more of the following potential advantages. In some examples, by efficiently carrying the NIK in an earlier frame (e.g., a PASN frame), the described techniques can be used to accelerate pairing setup and reduce overall latency. Therefore, the techniques can lead to better performance and an improved user experience.
[0026] Figure 1A schematic diagram of an example wireless communication network 100 is shown. Depending on some aspects, the wireless communication network 100 may be an example of a wireless local area network (WLAN) (such as a Wi-Fi network). For example, the wireless communication network 100 may be a network implementing at least one of the IEEE 802.11 family of wireless communication protocol standards (such as standards defined by the IEEE 802.11-2020 specification or its revisions, including but not limited to 802.11ay, 802.11ax, 802.11az, 802.11ba, 802.11bd, 802.11be, 802.11bf, and 802.11bn). In some other examples, the wireless communication network 100 may be an example of a cellular radio access network (RAN), such as a 5G or 6G RAN implementing one or more cellular protocols (such as those specified in one or more 3GPP standards). In some other examples, wireless communication network 100 may include a WLAN that operates in a manner interoperable with or converged with one or more cellular RANs to provide greater or enhanced network coverage to wireless communication devices within wireless communication network 100, or to enable such devices to connect to the core of the cellular network, such as to access network management capabilities and functionality provided by the cellular network core.
[0027] The wireless communication network 100 may include numerous wireless communication devices, including at least one wireless access point (AP) 102 and any number of wireless stations (STA) 104. Although Figure 1 Only one AP 102 is shown, but the wireless communication network 100 may include multiple APs 102. AP 102 may be or represent various different types of network entities, including but not limited to home networking APs, enterprise APs, single-band APs, dual-band simultaneous (DBS) APs, tri-band simultaneous (TBS) APs, standalone APs, non-standalone APs, software-enabled APs (software APs), and multi-link APs (also known as AP multi-link devices (MLDs)), as well as cellular (such as 3GPP, 4G LTE, 5G, or 6G) base stations or other cellular network nodes, such as Node Bs, evolved Node Bs (eNBs), gNBs, Transmitter Receiver Points (TRPs), or another type of equipment or apparatus included in a radio access network (RAN), including open RAN (O-RAN) network entities, such as central units (CUs), distributed units (DUs), or radio units (RUs).
[0028] Each STA in STA 104 may also be referred to as a mobile station (MS), mobile device, mobile phone, wireless phone, access terminal (AT), user equipment (UE), subscriber station (SS), or subscriber unit, etc. STA 104 may represent a variety of devices such as mobile phones, other handheld or wearable communication devices, netbooks, laptops, tablets, laptops, Chromebooks, augmented reality (AR), virtual reality (VR), mixed reality (MR), or extended reality (XR) wireless headsets or other peripherals, wireless earbuds, other wearable devices, display devices (e.g., TVs, computer monitors, or video game consoles), video game controllers, navigation systems, music or other audio or stereo devices, remote control devices, printers, kitchen appliances (including smart refrigerators) or other home appliances, remote keys (e.g., for passive keyless entry and start (PKES) systems), Internet of Things (IoT) devices, and vehicles, etc.
[0029] A single AP 102 and its associated set of STA 104s may be referred to as a Basic Service Set (BSS), which is managed by the respective AP 102. Figure 1 Additionally, an example coverage area 108 of AP 102 is shown, which may represent the Basic Service Area (BSA) of wireless communication network 100. The BSA can be identified by STA 104 and other devices via a Service Set Identifier (SSID) and a Basic Service Set Identifier (BSSID), which may be the Media Access Control (MAC) address of AP 102. AP 102 may periodically broadcast a beacon frame (“beacon”) including the BSSID to enable any STA 104 within the wireless range of AP 102 to “associate” or reassociate with AP 102 to establish or maintain a corresponding communication link 106 (also referred to hereinafter as a “Wi-Fi link”) with AP 102. For example, the beacon may include an identifier or indication of the primary channel used by the corresponding AP 102 and a Timing Synchronization Function (TSF) for establishing or maintaining timing synchronization with AP 102. AP 102 can provide access to external networks to various STAs 104 in the wireless communication network 100 via the corresponding communication link 106.
[0030] To establish a communication link 106 with AP 102, each STA 104 is configured to perform passive or active scanning operations (“scans”) on frequency channels in one or more frequency bands (e.g., 2.4 GHz, 5 GHz, 6 GHz, 45 GHz, or 60 GHz bands). To perform a passive scan, STA 104 listens for beacons transmitted by the corresponding AP 102 at periodic time intervals (referred to as the Target Beacon Transmission Time (TBTT)). To perform an active scan, STA 104 generates probe requests and transmits these requests sequentially on each channel to be scanned, and listens for probe responses from AP 102. Each STA 104 can identify, determine, detect, or select an AP 102 to associate with based on the scanning information obtained through passive or active scanning, and performs authentication and association operations to establish a communication link 106 with the selected AP 102. The selected AP 102 assigns an association identifier (AID) to STA 104 at the end of the association operation, and AP 102 uses the association identifier (AID) to track STA 104.
[0031] As wireless networks become increasingly prevalent, STA 104 may have the opportunity to choose from one of many BSSs within its range or from multiple APs 102 that together form an Extended Service Set (ESS) (comprising multiple connected BSSs). For example, wireless communication network 100 may be connected to a wired or wireless distribution system that enables multiple APs 102 to be connected in such an ESS. Therefore, STA 104 may be covered by more than one AP 102 and may be associated with different APs 102 at different times for different transmissions. Additionally, after associating with an AP 102, STA 104 may periodically scan its surroundings to find a more suitable AP 102 to associate with. For example, STA 104 moving relative to its associated AP 102 may perform a "roaming" scan to find another AP 102 with more desirable network characteristics, such as a larger Received Signal Strength Indicator (RSSI) or reduced traffic load.
[0032] In some cases, STA 104 can form a network without AP 102 or other equipment besides STA 104 itself. An example of such a network is an ad hoc network (or wireless ad hoc network). Ad hoc networks may also be referred to as mesh networks or peer-to-peer (P2P) networks. In some cases, ad hoc networks can be implemented within a larger network, such as wireless communication network 100. In such examples, while STA 104 may be able to communicate with each other via communication link 106 through AP 102, STA 104 can also communicate directly with each other via direct wireless communication link 110. Additionally, two STA 104 can communicate via direct communication link 110, regardless of whether the two STA 104 are associated with and served by the same AP 102. In such ad hoc systems, one or more STAs among STA 104 can assume the role played by AP 102 in the BSS. Such STA 104 may be referred to as the group owner (GO) and can coordinate transmissions within the ad hoc network. Examples of direct wireless communication links 110 include Wi-Fi direct connections, connections established by using Wi-Fi Tunneling Direct Link Establishment (TDLS) links, and other P2P group connections.
[0033] In some networks, AP 102 or STA 104, or both, can support applications associated with high throughput or low latency requirements, or provide lossless audio to one or more other devices. For example, AP 102 or STA 104 can support applications and use cases associated with ultra-low latency (ULL), such as ULL gaming, or streaming lossless audio and video to one or more personal audio devices (such as peripherals) or AR / VR / MR / XR headsets. In scenarios where users utilize two or more peripherals, AP 102 or STA 104 can support extended personal audio networks enabling communication with two or more peripherals. Additionally, AP 102 and STA 104 can support additional ULL applications, such as cloud-based applications with both ULL and high throughput requirements (such as VR cloud gaming).
[0034] As indicated above, in some implementations, AP 102 and STA 104 may operate and communicate (via the corresponding communication link 106) according to one or more of the IEEE 802.11 family of wireless communication protocol standards. These standards define WLAN radio and baseband protocols for the physical (PHY) layer and MAC layer. AP 102 and STA 104 transmit wireless communication to and receive wireless communication from each other in the form of PHY Protocol Data Units (PPDUs) (also referred to below as “Wi-Fi communication” or “wireless packets”).
[0035] Each PPDU is a composite structure comprising a PHY preamble and a payload in the form of a PHY Service Data Unit (PSDU). The information provided in the preamble can be used by the receiving device to decode subsequent data in the PSDU. In instances where the PPDU is transmitted over a bound or wideband channel, the preamble field may be copied and transmitted in each of the multiple component channels. The PHY preamble may include both a legacy portion (or "legacy preamble") and a non-legacy portion (or "non-legacy preamble"). The legacy preamble can be used for other purposes such as packet detection, automatic gain control, and channel estimation. The legacy preamble is also typically used to maintain compatibility with legacy equipment. The format, decoding, and information provided in the non-legacy portion of the preamble are associated with the specific IEEE 802.11 wireless communication protocol to be used to transmit the payload.
[0036] AP 102 and STA 104 in WLAN 100 can transmit PPDUs on unlicensed spectrum, which can be a portion of the spectrum including bands traditionally used by Wi-Fi technologies, such as the 2.4 GHz band, 5 GHz band, 6 GHz band, 45 GHz band, and 60 GHz band. Some examples of AP 102 and STA 104 described herein can also communicate in other bands that can support licensed or unlicensed communication. For example, AP 102 or STA 104, or both, may also be able to communicate on licensed operating bands, where multiple operators may have corresponding licenses to operate in the same or overlapping frequency ranges. Such licensed operating frequency bands may be specified or associated with frequency ranges mapped to or associated with FR1 (410MHz-7.125GHz), FR2 (24.25GHz-52.6GHz), FR3 (7.125GHz-24.25GHz), FR4a or FR4-1 (52.6GHz-71GHz), FR4 (52.6GHz-114.25GHz), and FR5 (114.25GHz-300GHz).
[0037] Each frequency band can include multiple sub-bands and frequency channels (also referred to as sub-channels). For example, PPDUs conforming to revisions of the IEEE 802.11n, 802.11ac, 802.11ax, 802.11be, and 802.11bn standards can be transmitted on one or more of the 2.4 GHz, 5 GHz, or 6 GHz frequency bands, where each band is divided into multiple 20 MHz channels. Therefore, these PPDUs are transmitted on physical channels with a minimum bandwidth of 20 MHz, but larger channels can be formed through channel bonding. For example, PPDUs can be transmitted on physical channels with bandwidths of 40 MHz, 80 MHz, 160 MHz, 240 MHz, 320 MHz, 480 MHz, or 640 MHz by bonding multiple 20 MHz channels together.
[0038] Figure 2 A schematic diagram of an example neighbor-aware network (NAN) 200 in which various aspects of the present disclosure can be utilized is shown.
[0039] A NAN network comprises all NAN devices 204 that share a common set of NAN parameters. These parameters may include, for example, the time interval between consecutive discovery windows, the duration of the discovery window, the beacon interval, and the NAN discovery channel. A NAN cluster 210 typically refers to a set of NAN devices that share a common set of NAN parameters and are synchronized to the same discovery window schedule. A NAN cluster can be identified by a NAN cluster ID.
[0040] NAN devices can directly transmit multicast NAN service discovery frames to other NAN devices within the same NAN cluster during the discovery window. NAN devices can also directly transmit unicast NAN service discovery frames to any other NAN device within the same NAN cluster during the discovery window.
[0041] NAN devices, as part of the same NAN cluster, can participate in the NAN master election process. NAN master election is performed based on the NAN cluster. Depending on changes within the NAN cluster, such as the NAN devices as part of the cluster and their master ranks, different NAN devices can be elected as the dominant NAN device at different times. NAN devices with equal master preferences have an equal chance of becoming the NAN master. In a NAN deployment, NAN devices can play different roles, such as NAN publishers and NAN subscribers. Typically, NAN devices acting as publishers are responsible for transmitting data by forming clusters with nearby devices or creating new clusters, while NAN devices acting as subscribers receive notifications and can accept services (join a cluster) if interested.
[0042] Aspects related to accelerated key exchange for pairing
[0043] The various aspects involve wireless communication as a whole, and more specifically, technologies that can help accelerate key exchange during the pairing process.
[0044] As will be described in more detail below, previously established keys (e.g., NIK and / or group keys) may be included in the frame (carrying the frame) used to establish pairing (pre-association) between devices. For example, previously established keys may include keys previously exported during the pairing verification process and / or keys defined during the pairing setup process, and may be included in the PASN authentication frame or any other type of frame (e.g., action) used to establish pairing / pre-association between devices.
[0045] As mentioned above, the pairing process enables a pair of wireless devices to authenticate each other when they establish initial trust and to verify each other's identities after they establish a pairing relationship.
[0046] Figure 3 Example call flowchart 300 illustrates a NAN pairing involving two NAN devices (pairing initiator and pairing responder). As illustrated at 302 and 304, the example pairing can use pairing credentials, such as a password provided by the service publisher and the service subscriber. Pairing can be triggered by a pairing setup request from the service subscriber, as shown at 306.
[0047] In response, the pairing initiator can initiate pairing setup with the pairing responder and authenticate each other by proving they possess the password. To establish a pairing session, the two devices can exchange frames as part of the authentication process, which allows the devices to establish initial trust and verify each other's identities.
[0048] As illustrated, the pairing setup for cryptographic authentication can employ Pre-Associated Security Negotiation (PASN) authentication and peer-to-peer authentication synchronization (SAE) tunneling technology. PASN authentication frames can be used for the pairing setup handshake.
[0049] For example, as shown at 308, the first PASN authentication frame (PASN-M1) can be sent by the pairing initiator. The PASN-M1 frame may include NAN Information Elements (IEs) with various NAN attributes. For example, these attributes may include Device Capability Extension Attribute (DCEA), Cipher Suite Information Attribute (CSIA), and NAN Pairing Bootstrapping Attribute (NPBA), which has a pairing setting enable bit and bits indicating whether caching of the NAN Identity Key (NIK) is enabled.
[0050] As shown at 310 and 312, after receiving the PASN-M1 message, the pairing responder can transmit a pairing setup instruction to the service publisher, which can respond with a pairing setup response.
[0051] As shown at 314, the second PASN authentication frame (PASN-M2) is sent by the pairing responder. The PASN-M2 frame may include a NAN IE with various attributes, which may be the same as those included in the publish or subscribe message sent by the pairing responder (e.g., DCEA, CSIA, and / or NPBA). As shown at 316, the third PASN authentication frame is sent by the pairing initiator.
[0052] Following pre-authentication, a device with NAN pairing capability can generate a NIK, which can then be used to generate a NAN Identity Attribute (NIRA). The NIRA can be included in a NAN Service Discovery Frame (SDF) frame to reveal the device's long-term identity to the paired peer.
[0053] As illustrated at 320, after a pairing setup is established, the NIK is typically shared between the paired peers via a secure channel. The NIK, along with its lifetime, is exchanged in a Key Data Encapsulation (KDE) of a shared key descriptor. The shared key descriptor can be encrypted using an encrypted subsequent NAN management key encryption key (NM-KEK) after PASN authentication.
[0054] Therefore, as shown at 322 and 324, additional subsequent frames may be required to share the key between paired devices. Along with the NIK and NIK lifetime, devices can also exchange group keys KDE, including the Integrity Group Transient Key (IGTK), the Beacon Integrity Group Transient Key (BIGTK) KDE, and the corresponding lifetime KDE.
[0055] In some applications, where the device supports NIK caching, the peer device's NIK can be anticipated in the Pairing Confirmation Indication event for pairing confirmation. This means that in such cases, pairing confirmation for the application must be deferred until a subsequent frame containing the NIK KDE is exchanged after PASN authentication is complete. Unfortunately, this can result in considerable latency, as the subsequent frame exchange may be delayed until the Discovery Window (DW) slot.
[0056] However, aspects of this disclosure can help accelerate key exchange during the pairing process by including a previously established key (e.g., a cached NIK) in the frame used to establish pairing (pre-association) between devices. This can reduce overall setup latency because devices do not need to wait for additional subsequent frames.
[0057] When the device caches the key (e.g., NIK caching is enabled), the previously obtained key can be a validly carried frame that is part of the authentication process used to establish pairing. For example, the NIK and group KDE can be included as encrypted payloads in the PASN authentication frame (e.g., for pairing setup and pairing verification).
[0058] The previously acquired key may include a key previously derived during the authentication process and / or a key defined during the pairing authentication process. While this paper describes an example with reference to the NAN (WiFi Aware) protocol, the techniques presented herein can be broadly applied to any scenario involving peer-to-peer (P2P) pairing utilizing other types of protocols, such as WiFi Direct.
[0059] The techniques proposed in this article can be referenced. Figure 4 Use the example call flowchart 400 to understand.
[0060] Pairing settings are similar to those in the reference above. Figure 3 The example described begins and continues until the PASN-M1 frame is sent from the pairing initiator. However, in this example, the pairing responder includes the NAN shared key descriptor attribute (SKDA) in the PASN-M2 frame, as illustrated at 414. Similarly, the pairing initiator includes the NAN SKDA in the PASN-M3 frame, as illustrated at 416.
[0061] As illustrated at 418, one or more previously obtained keys may be included in the NAN SKDA, which may be included in the NAN IE of the PASN-M2 frame and / or PASN-M3 frame. As illustrated at 420, by providing the previously obtained keys in the PASN-M2 and PASN-M3 frames, subsequent frames are not required prior to pairing confirmation. Figure 3 (The example shown is the opposite). Therefore, the overall pairing setup latency can be reduced.
[0062] In some cases, previously obtained security keys can be encrypted based on a key encryption key (KEK) (such as a NAN-managed KEK (NM-KEK)). The encrypted payload can also include keys other than the NIK. For example, the encrypted payload can include at least one of the following: a group transient key (GTK), an integrity group transient key (IGTK), or a beacon integrity group transient key (BIGTK). The encrypted payload can also indicate the lifetime of one or more previously obtained keys, indicating how long the corresponding keys are considered valid.
[0063] Encrypted payloads can be included in IEs, such as the Extensible Authentication Protocol over LAN (EAP) (EAPOL) IE, for example, in the SKDA field of the EAPOL IE.
[0064] like Figure 5 As illustrated, the NAN SKDA 500 may include an IEEE 802.11 RSNA Key Descriptor (EAPOL) field 510. As illustrated at 512, one option is to include the KDE in such a data field, which may also be encrypted with NM-KEK.
[0065] As described above, the NAN pairing handshake uses the PASN protocol to derive the session key. When the pairing responder receives a PASN-M1 frame, it can derive the required session key, such as TK, KDK, KCK, and KEK. The pairing responder can then include the NIK (e.g., and the NIK lifetime KDE) in the NAN SKDA in the PASN-M2 frame. As described above, other KDEs (such as IGTK and BIGTK KDEs) can also be included along with their corresponding lifetime KDEs.
[0066] In some cases, the paired responder device can check the peer's capabilities to see if it supports NIK caching and whether it needs group management protection before including the corresponding KDE, since NAN CSIA and DCEA are included in the authentication frame.
[0067] Upon receiving a PASN-M2 frame, the pairing initiator can verify and process the Message Integrity Check (MIC). After successful authentication, the pairing initiator can also generate a session key and transmit a PASN-M3 frame for confirmation. Figure 4 As illustrated, the pairing initiator may also include a NAN SKDA in the NAN IE of the PASN-M3 frame. In the SKDA, the pairing initiator may include a NIK KDE and a NIK lifetime KDE. It may also additionally include an IGTK, a BIGTK, and their corresponding lifetime KDEs.
[0068] In some cases, if the pairing handshake fails, the pairing initiator and responder can ignore the peer group key.
[0069] In some cases, to maintain backward compatibility with other (e.g., vendor / legacy) devices, the pair initiator device can still initiate subsequent exchanges of frames containing the NIK and other group KDEs. For example, if the pair initiator has not yet received the SKDA (with the NIK and / or other keys) in the NAN IE of a PASN M2 frame, the pair initiator can initiate subsequent exchanges (such as...). Figure 4(As shown). If the pairing initiator device transmits a subsequent frame with the SKDA attribute, the pairing responder device can also respond with a subsequent frame containing the SKDA attribute.
[0070] As described above, for devices that support key caching, pairing setup latency can be reduced by combining the delivery of previously acquired keys with frames used in the authentication process (e.g., PASN frames). The technique presented in this paper can help avoid additional frames between device NAN pairing setup and NDP setup, and can help meet key performance indicator (KPI) requirements for various use cases.
[0071] Example Operation
[0072] Figure 6 An example of a method 600 for wireless communication at a first wireless node is shown. In some examples, the first wireless node is a station, such as... Figure 1 The STA 104. In some examples, the first wireless node is the access point, such as... Figure 1 AP102.
[0073] Method 600 begins at step 605, wherein a first frame is output for transmission as part of an authentication process for establishing a pairing procedure with a second wireless node, wherein the first frame includes an encrypted payload having at least a first previously obtained security key.
[0074] Method 600 then proceeds to step 610, where a second frame is obtained as part of the pairing procedure.
[0075] Method 600 then proceeds to step 615, where, if the second frame also includes at least the first previously obtained security key, the pairing procedure is confirmed.
[0076] In some respects, at least the first previously obtained key includes at least one of the following: a key previously exported during the pairing verification process; or a key defined during the pairing setup process.
[0077] In some respects, at least one of the first or second frames includes an authentication frame.
[0078] In some respects, at least one of the first or second frames includes a pre-associative security negotiation (PASN) frame.
[0079] In some respects, the first and second frames are associated with pairing settings or pairing verification.
[0080] In some aspects, method 600 also includes encrypting at least a first previously obtained security key based on a key encryption key (KEK), wherein the encrypted payload includes the encrypted first previously obtained security key.
[0081] In some respects, at least the first previously obtained security key included the Neighbor-Aware Network (NAN) Identity Key (NIK).
[0082] In some respects, the encrypted payload also includes one or more second, previously obtained security keys.
[0083] In some respects, one or more second previously obtained security keys include at least one of the following: group transient key (GTK), integrity group transient key (IGTK), or beacon integrity group transient key (BIGTK).
[0084] In some respects, the first frame also indicates the lifetime of at least one of a first previously acquired security key or one or more second previously acquired security keys.
[0085] In some respects, the encrypted payload is included in the information element (IE).
[0086] In some respects, IE includes Extensible Authentication Protocol over LAN (EAP) (EAPOL) IE.
[0087] In some respects, the encrypted payload is included in the shared key descriptor attribute (SKDA) field of EAPOL IE.
[0088] In some cases, the first frame is output for transmission before the second frame is received.
[0089] In some cases, after obtaining the second frame, the first frame is output for transmission.
[0090] In one respect, method 600 or any aspect thereof may be made by means of a device (such as...) Figure 7 The wireless communication device 700 is used to perform the method 600, and the device includes various components that are operable to perform the method 600, configured to perform the method 600, or adapted to perform the method 600. The wireless communication device 700 is described in more detail below.
[0091] It should be noted that Figure 6 This is merely one example of a method, and other methods consistent with this disclosure, including fewer steps, additional steps, or alternative steps, are possible.
[0092] Example communication device
[0093] Figure 7Various aspects of an example wireless communication device 700 are described. In some aspects, the wireless communication device 700 is a station, such as... Figure 1 The STA 104. In some respects, the wireless communication device 700 is an access point, such as... Figure 1 AP 102.
[0094] Wireless communication device 700 may include one or more chips, SoCs, chipsets, packages, components, or devices that individually or collectively constitute or include a processing system. The processing system may interface with other components of wireless communication device 700 and typically processes information (such as inputs or signals) received from and outputs information (such as outputs or signals) to such other components. In some aspects, an example chip may include a processing system, a first interface for outputting or transmitting information, and a second interface for receiving or acquiring information. For example, the first interface may refer to an interface between the chip's processing system and a transmitting component, enabling device 700 to transmit information output from the chip. In such examples, the second interface may refer to an interface between the chip's processing system and a receiving component, enabling device 700 to receive information, which is then passed to the processing system. In some such examples, the first interface may also, for example, acquire information from the transmitting component, and the second interface may also, for example, output information to the receiving component.
[0095] The processing system includes processor (or “processing”) circuitry in the form of one or more processors, microprocessors, processing units (such as central processing units (CPUs), graphics processing units (GPUs), or digital signal processors (DSPs)), processing blocks, application-specific integrated circuits (ASICs), programmable logic devices (PLDs) (such as field-programmable gate arrays (FPGAs)), or other discrete gate or transistor logic components or circuits (all of which may be individually referred to herein as “processors” or collectively as “processors” or “processor circuitry”). One or more of these processors may be individually or collectively configured to perform the various functions or operations described herein. The processing system may also include memory circuitry in the form of one or more memory devices, memory blocks, memory elements, or other discrete gate or transistor logic components or circuitry, each of which may include tangible storage media such as random access memory (RAM) or read-only memory (ROM) or combinations thereof (all of which may be individually referred to herein as “memory” or collectively as “memory” or “memory circuitry”). One or more of these memories may be coupled to one or more processors and may store processor-executable code, individually or collectively, which, when executed by one or more processors, configures one or more processors to perform the various functions or operations described herein. Additionally or alternatively, in some examples, one or more processors may be pre-configured to perform the various functions or operations described herein without software configuration. The processing system may also include or be coupled to one or more modems (such as a Wi-Fi (e.g., IEEE compliant) modem or a cellular (e.g., 3GPP 4G LTE, 5G, or 6G compliant) modem). In some embodiments, one or more processors of the processing system include or implement one or more modems. The processing system may also include or be coupled to multiple radio components (collectively, “radio components”), multiple RF chains, or multiple transceivers, each of which may in turn be coupled to one or more antennas. In some embodiments, one or more processors of the processing system include or implement one or more of the radio components, RF chains, or transceivers.
[0096] In some examples, the wireless communication device 700 can be configured to, for example, in a STA, such as a reference Figure 1 The described STA 104 is used or configured in STAs such as references Figure 1The STA 104 described herein is used. In some other examples, the wireless communication device 700 may be an STA that includes such a processing system and other components including multiple antennas. The wireless communication device 700 is capable of transmitting and receiving wireless communications, for example, in the form of wireless packets. For example, the wireless communication device 700 may be configured to transmit and receive packets in the form of physical layer PPDUs and MPDUs conforming to one or more of the IEEE 802.11 wireless communication protocol standard family, or be configured to transmit and receive packets in the form of physical layer PPDUs and MPDUs conforming to one or more of the IEEE 802.11 wireless communication protocol standard family. In some other examples, the wireless communication device 700 may be configured to transmit and receive signals and communications conforming to one or more 3GPP specifications (including those for 5G NR or 6G), or be configured to transmit and receive signals and communications conforming to one or more 3GPP specifications (including those for 5G NR or 6G). In some examples, the wireless communication device 700 also includes one or more application processors or may be coupled to such application processors, which may also be coupled to one or more other memories. In some examples, the wireless communication device 700 also includes a user interface (UI) (such as a touchscreen or keypad) and a display, which can be integrated with the UI to form a touchscreen display coupled to the processing system. In some examples, the wireless communication device 700 may also include one or more sensors coupled to the processing system, such as, for example, one or more inertial sensors, accelerometers, temperature sensors, pressure sensors, or altitude sensors.
[0097] Wireless communication device 700 includes an output component 702, an acquisition component 704, an authentication component 706, and an encryption component 708. A portion of one or more of components 702, 704, 706, and 708 can be implemented at least partially in hardware or firmware. For example, the output component 702 can be implemented at least partially by a processor or modem. In some examples, a portion of one or more of components 702, 704, 706, and 708 can be implemented at least partially by a processor and software in the form of processor-executable code stored in memory. According to certain aspects, the components for output, acquisition, authentication, and / or encryption can be implemented as follows: Figure 7 One or more processors and / or one or more components.
[0098] Example Terms
[0099] Specific implementation examples are described in the following numbered clauses:
[0100] Clause 1: A method for wireless communication at a first wireless node, the method comprising: outputting a first frame for transmission as part of an authentication process for establishing a pairing procedure with a second wireless node, wherein the first frame includes an encrypted payload having at least a first previously obtained security key; obtaining a second frame as part of the pairing procedure; and acknowledging the pairing procedure if the second frame also includes at least the first previously obtained security key.
[0101] Clause 2: The method according to Clause 1, wherein the at least first previously obtained key includes at least one of the following: a key previously exported during the pairing verification process; or a key defined during the pairing setup process.
[0102] Clause 3: The method according to any one of Clauses 1 to 2, wherein at least one of the first frame or the second frame includes an authentication frame.
[0103] Clause 4: The method according to any one of Clauses 1 to 3, wherein at least one of the first frame or the second frame includes a pre-associative security negotiation (PASN) frame.
[0104] Clause 5: The method according to any one of Clauses 1 to 4, wherein the first frame and the second frame are associated with pairing settings or pairing verification.
[0105] Clause 6: The method according to any one of Clauses 1 to 5 further comprises: encrypting the at least first previously obtained security key based on a key encryption key (KEK), wherein the encrypted payload includes the encrypted first previously obtained security key.
[0106] Clause 7: The method according to any one of Clauses 1 to 6, wherein at least the first previously obtained security key includes a Neighbor-Aware Network (NAN) Identity Key (NIK).
[0107] Clause 8: The encrypted payload, according to any one of Clauses 1 to 7, further includes one or more second previously obtained security keys.
[0108] Clause 9: The method described in Clause 8, wherein the one or more second previously obtained security keys include at least one of the following: a group transient key (GTK), an integrity group transient key (IGTK), or a beacon integrity group transient key (BIGTK).
[0109] Clause 10: The method according to Clause 8, wherein the first frame further indicates the lifetime of at least one of the first previously obtained security key or the one or more second previously obtained security keys.
[0110] Clause 11: The method according to any one of Clauses 1 to 10, wherein the encrypted payload is included in the information element (IE).
[0111] Clause 12: The method described in Clause 11, wherein the IE includes Extensible Authentication Protocol over LAN (EAP) (EAPOL) IE.
[0112] Clause 13: The method described in Clause 12, wherein the encrypted payload is included in the shared key descriptor attribute (SKDA) field of the EAPOLIE.
[0113] Clause 14: The method according to any one of Clauses 1 to 13, wherein: the first frame is output for transmission before the second frame is obtained.
[0114] Clause 15: The method according to any one of Clauses 1 to 14, wherein: after obtaining the second frame, the first frame is output for transmission.
[0115] Clause 16: An apparatus comprising: a memory including executable instructions; and a processor configured to execute the executable instructions and cause the apparatus to perform a method according to any one of Clauses 1 to 15.
[0116] Clause 17: An apparatus comprising components for performing the method according to any one of Clauses 1 to 15.
[0117] Clause 18: A non-transitory computer-readable medium comprising executable instructions that, when executed by a processor of a device, cause the device to perform a method according to any one of Clauses 1 to 15.
[0118] Clause 19: A computer program product embodied on a computer-readable storage medium, the computer-readable storage medium including code for performing the method according to any one of Clauses 1 to 15.
[0119] Clause 20: A wireless station comprising: at least one transceiver; a memory including executable instructions; and a processor configured to execute the executable instructions and cause the wireless station to perform a method according to any one of Clauses 1 to 15, wherein the at least one transceiver is configured to transmit the first frame and receive the second frame.
[0120] As used herein, the term "determine" encompasses a wide variety of actions, and therefore, "determine" can include calculation, computation, processing, derivation, estimation, investigation, searching (such as by searching in a table, database, or other data structure), reasoning, probing, or measurement, etc. Additionally, "determine" can include receiving (such as receiving information), accessing (such as accessing data stored in memory), or sending (such as sending information), etc. Furthermore, "determine" can include parsing, selecting, obtaining, choosing, building, and other similar actions.
[0121] As used herein, the phrase “at least one of” or “one or more of” a list of items refers to any combination of those items, including a single member. For example, “at least one of a, b, or c” is intended to cover: a, b, c, ab, ac, bc, and abc. As used herein, “or” is intended to be interpreted as inclusive unless otherwise explicitly stated. For example, “a or b” could include only a, only b, or a combination of a and b. Furthermore, as used herein, the phrase referring to “one” or “a” element means one or more such elements that act individually or collectively to perform the described function. Additionally, “set” refers to one or more items, and “subset” refers to less than the entire set but not empty.
[0122] As used herein, "processor," "at least one processor," or "one or more processors" generally refers to a single processor configured to perform one or more operations, or multiple processors configured to collectively perform one or more operations. In the case of multiple processors, the execution of one or more operations may be divided among different processors, but one processor may perform multiple operations, and multiple processors may collectively perform a single operation. Similarly, "memory," "at least one memory," or "one or more memory" generally refers to a single memory configured to store data and / or instructions, or multiple memories configured to collectively store data and / or instructions.
[0123] As used herein, unless otherwise explicitly indicated, “based on” is intended to be interpreted in an inclusive sense. For example, unless otherwise explicitly indicated, “based on” may be used interchangeably with “at least partially based on,” “associated with,” “associated with,” or “according to.” Specifically, unless the phrase in the context means “based on only one” or an equivalent, whether it is “based on one” or “at least partially based on one,” it may be based solely on “one” or based on a combination of “one” and one or more other factors, conditions, or information.
[0124] The various exemplary components, logic units, logic blocks, modules, circuits, operations, and algorithmic processes described in conjunction with the examples disclosed herein can be implemented as electronic hardware, firmware, software, or a combination of hardware, firmware, or software, including the structures disclosed in this specification and their structural equivalents. This interchangeability of hardware, firmware, and software has been generally described in terms of its functionality and exemplified in the various exemplary components, blocks, modules, circuits, and processes described above. Whether such functionality is implemented in hardware, firmware, or software depends on the specific application and the design constraints imposed on the overall system.
[0125] Various modifications to the examples described in this disclosure will be apparent to those skilled in the art, and the general principles defined herein may be applied to other examples without departing from the spirit or scope of this disclosure. Therefore, the claims are not intended to be limited to the examples shown herein, but are to be granted the widest scope consistent with this disclosure, the principles disclosed herein, and the novel features.
[0126] Additionally, the various features described in this specification in the context of individual examples may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple examples. Thus, although features may be described above as functioning in a particular combination, and even initially claimed in this way, one or more features from the claimed combination may be removed from the combination in some cases, and the claimed combination may involve sub-combinations or variations of sub-combinations.
[0127] Similarly, although operations are depicted in a specific order in the diagrams, this should not be construed as requiring such operations to be performed in the specific order shown or in sequential order, or to perform all illustrated operations to achieve the desired result. Furthermore, the accompanying drawings may schematically depict one or more example processes in the form of flowcharts or flow diagrams. However, other operations not depicted may be incorporated into the schematically illustrated example processes. For example, one or more additional operations may be performed before, after, simultaneously with, or between any of the illustrated operations. In some cases, multitasking and parallel processing may be advantageous. Moreover, the separation of various system components in the examples described above should not be construed as requiring such separation in all examples, but rather should be understood as meaning that the described program components and systems can generally be integrated together in a single software product or encapsulated in multiple software products.
Claims
1. An apparatus for wireless communication, the apparatus comprising: At least one memory, the at least one memory including computer-executable instructions; and one or more processors, said one or more processors being configured to execute said computer-executable instructions and cause said device to: The first frame is output to be sent as part of an authentication process for establishing a pairing procedure with a wireless node, wherein the first frame includes an encrypted payload having at least a first previously obtained security key; Obtain the second frame as part of the pairing procedure; and If the second frame also includes at least the first previously obtained security key, the pairing procedure is confirmed.
2. The apparatus of claim 1, wherein the at least first previously obtained key comprises at least one of the following: The key previously exported during the pairing verification process; or The key defined during the pairing setup process.
3. The apparatus of claim 1, wherein at least one of the first frame or the second frame comprises an authentication frame.
4. The apparatus of claim 1, wherein at least one of the first frame or the second frame comprises a pre-associative security negotiation (PASN) frame.
5. The apparatus of claim 1, wherein the first frame and the second frame are associated with pairing settings or pairing verification.
6. The apparatus according to claim 1, wherein: The one or more processors are further configured to execute the computer-executable instructions and cause the device to encrypt the at least first previously obtained security key based on a key encryption key (KEK). The encrypted payload includes a first previously obtained security key that is encrypted.
7. The apparatus of claim 1, wherein the at least first previously obtained security key includes a Neighbor Aware Network (NAN) Identity Key (NIK).
8. The apparatus of claim 1, wherein the encrypted payload further comprises one or more second previously obtained security keys.
9. The apparatus of claim 8, wherein the one or more second previously obtained security keys include at least one of the following: a group transient key (GTK), an integrity group transient key (IGTK), or a beacon integrity group transient key (BIGTK).
10. The apparatus of claim 8, wherein the first frame further indicates the lifetime of at least one of the first previously obtained security key or the one or more second previously obtained security keys.
11. The apparatus of claim 1, wherein the encrypted payload is included in an information element (IE).
12. The apparatus of claim 11, wherein the IE includes Extensible Authentication Protocol over LAN (EAP) (EAPOL) IE.
13. The apparatus of claim 12, wherein the encrypted payload is included in the shared key descriptor attribute (SKDA) field of the EAPOL IE.
14. The apparatus according to claim 1, wherein: Before obtaining the second frame, the first frame is output for transmission.
15. The apparatus according to claim 1, wherein: After obtaining the second frame, the first frame is output for transmission.
16. A method for performing wireless communication at a first wireless node, the method comprising: The first frame is output to be sent as part of an authentication process for establishing a pairing procedure with a second wireless node, wherein the first frame includes an encrypted payload having at least a first previously obtained security key; Obtain the second frame as part of the pairing procedure; and If the second frame also includes at least the first previously obtained security key, the pairing procedure is confirmed.
17. The method of claim 16, wherein the at least first previously obtained key comprises at least one of the following: The key previously exported during the pairing verification process; or The key defined during the pairing setup process.
18. The method of claim 16, wherein at least one of the first frame or the second frame comprises an authentication frame.
19. The method of claim 16, wherein at least one of the first frame or the second frame comprises a pre-associative security negotiation (PASN) frame.
20. A first wireless station, the first wireless station comprising: At least one transceiver; At least one memory, the at least one memory including computer-executable instructions; and one or more processors, said one or more processors being configured to execute said computer-executable instructions and cause the first wireless station to: As part of the authentication process for establishing a pairing procedure with the second wireless station, a first frame is transmitted via the at least one transceiver, wherein the first frame includes an encrypted payload having at least a first previously obtained security key; Receive a second frame via the at least one transceiver as part of the pairing procedure; and If the second frame also includes at least the first previously obtained security key, the pairing procedure is confirmed.