Method and apparatus for supporting protection of control frames in a wireless lan system

By introducing a BIP-based integrity verification mechanism into the WLAN system to protect block-ACK frames, the problem of insufficient control frame integrity verification in the existing technology is solved, thereby improving the reliability and security of communication.

CN122460120APending Publication Date: 2026-07-24LG ELECTRONICS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
LG ELECTRONICS INC
Filing Date
2024-10-28
Publication Date
2026-07-24

AI Technical Summary

Technical Problem

Existing WLAN systems lack effective protection mechanisms for control frames, especially insufficient integrity verification of block-ACK frames, which affects communication reliability and security.

Method used

By introducing a BIP-based integrity verification mechanism into the WLAN system, the integrity of block-ACK frames is verified using key information, ensuring the matching of the frame's protection information with the frame body.

Benefits of technology

It effectively protects control frames in WLAN systems, improves communication reliability and security, and ensures the integrity of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122460120A_ABST
    Figure CN122460120A_ABST
Patent Text Reader

Abstract

A method and apparatus for supporting protection of control frames in a wireless local area network (WLAN) system are disclosed. A method performed by a first STA in a WLAN system according to an embodiment of the present disclosure can include confirming key information related to protection of a block acknowledgement (ACK) frame, receiving a block-ACK frame to which protection is applied from a second STA, and performing an integrity check on the block-ACK frame based on the key information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to a method and apparatus for supporting protection of control frames in a wireless local area network (WLAN) system. Background Technology

[0002] New technologies have been introduced for Wireless LANs (WLANs) to improve transmission rates, increase bandwidth, enhance reliability, reduce errors, and decrease latency. Within WLAN technology, the IEEE 802.11 series of standards can be referred to as Wi-Fi. For example, recent technologies introduced into WLAN include the Ultra High Throughput (VHT) enhancement of the 802.11 ac standard and the High Efficiency (HE) enhancement of the IEEE 802.11 ax standard.

[0003] To provide a more advanced wireless communication environment, improved techniques for Extremely High Throughput (EHT) are being discussed. For example, techniques for MIMO and multiple access point (AP) coordination that support increased bandwidth, efficient use of multiple frequency bands, and increased spatial flow are being investigated. Specifically, various techniques are being explored to support low latency or real-time traffic. Furthermore, new technologies to support Ultra-High Reliability (UHR), including improvements or extensions to EHT techniques, are being discussed. Summary of the Invention

[0004] Technical issues

[0005] The technical problem of this disclosure is to provide a method and apparatus for supporting the protection of control frames in a WLAN system.

[0006] The technical objective of this disclosure is to provide a method and apparatus for supporting BIP-based integrity verification of block-ACK (BlockAck, BA) frames in a WLAN system.

[0007] The technical objectives to be achieved by this disclosure are not limited to those described above, and other technical objectives not described herein will be clearly understood by those skilled in the art through the following description.

[0008] Technical solution

[0009] A method performed by a first station (STA) in a wireless local area network (WLAN) system according to one aspect of this disclosure may include: confirming key information related to protection for a block acknowledgment (block-ACK) frame; receiving a block-ACK frame with the protection applied from a second STA; and performing an integrity check on the block-ACK frame based on the key information. Here, the block-ACK frame may include protection-related information for the integrity check, and the integrity check may be performed based on a comparison between a first message integrity code (MIC) value calculated using key information belonging to at least one field of the frame body within the block-ACK frame and a second MIC value included in the protection-related information.

[0010] A method performed by a second station (STA) in a wireless local area network (WLAN) system according to an additional aspect of this disclosure may include: confirming key information related to protection for a block-ACK frame; configuring a block-ACK frame, based on the key information, including protection-related information for integrity verification of the block-ACK frame; and sending a block-ACK frame to a first STA to which the protection is applied.

[0011] Technical effect

[0012] According to various embodiments of this disclosure, a method and apparatus for supporting the protection of control frames in a wireless LAN system can be provided.

[0013] According to various embodiments of this disclosure, a method and apparatus for supporting BIP-based integrity verification of block-ACK (BlockAck, BA) frames in a WLAN system can be provided.

[0014] The effects achievable by this disclosure are not limited to those described above, and those skilled in the art can clearly understand other effects not described herein through the following description. Attached Figure Description

[0015] The accompanying drawings, which are included as part of the detailed description of this disclosure, provide embodiments of the disclosure and, together with the detailed description, describe the technical features of the disclosure.

[0016] Figure 1 A configuration block diagram of a wireless communication device according to an embodiment of the present disclosure is illustrated.

[0017] Figure 2 This is a diagram illustrating an exemplary structure of a WLAN system to which this disclosure can be applied.

[0018] Figure 3This is a diagram used to illustrate the link establishment process that can be applied to this disclosure.

[0019] Figure 4 This is a diagram used to illustrate the backoff processing that can be applied to this disclosure.

[0020] Figure 5 This is a diagram illustrating the CSMA / CA-based frame transmission operation that can be applied to this disclosure.

[0021] Figure 6 This is a diagram illustrating an example of a frame structure that can be used in a WLAN system to which this disclosure may be applied.

[0022] Figure 7 This is a diagram illustrating an example of a PPDU as defined in the IEEE 802.11 standard of this disclosure.

[0023] Figure 8 This is a diagram illustrating an exemplary format of the block-ACK frame to which the present disclosure can be applied.

[0024] Figure 9 Examples of BIP MMPDU formats applicable to this disclosure are shown.

[0025] Figure 10 An example of a protection information field / subfield format according to an embodiment of this disclosure is illustrated.

[0026] Figure 11 This illustrates an example of a block-ACK frame configuration that supports integrity verification according to an embodiment of this disclosure.

[0027] Figure 12 This represents another example of a block-ACK frame configuration that supports integrity verification according to an embodiment of this disclosure.

[0028] Figure 13 This represents another example of a block-ACK frame configuration that supports integrity verification according to an embodiment of this disclosure.

[0029] Figure 14 An example is provided of the operation of the transmitting STA that supports integrity verification of block-ACK frames according to this disclosure.

[0030] Figure 15 This illustrates the operation of a receiving STA that supports integrity verification of block-ACK frames according to this disclosure.

[0031] Figure 16 This is a diagram illustrating an example of a method performed by a first STA according to this disclosure.

[0032] Figure 17This is a diagram illustrating an example of a method performed by a second STA according to this disclosure. Detailed Implementation

[0033] In the following, embodiments according to this disclosure will be described in detail with reference to the accompanying drawings. The detailed description disclosed with reference to the drawings is intended to describe exemplary embodiments of this disclosure and not to represent the only embodiments in which this disclosure can be implemented. The following detailed description includes specific details to provide a complete understanding of this disclosure. However, those skilled in the art will recognize that this disclosure can be implemented without these specific details.

[0034] In some cases, known structures and devices may be omitted, or they may be shown in block diagram form based on the core functions of each structure and device in order to prevent ambiguity in the concepts of this disclosure.

[0035] In this disclosure, when an element is referred to as “connected,” “combined,” or “linked” to another element, it can include both indirect and direct connections between the two elements. Furthermore, in this disclosure, the terms “comprising” or “having” specify the presence of the mentioned features, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, stages, operations, components, elements, and / or groups thereof.

[0036] In this disclosure, terms such as "first" and "second" are used only to distinguish one element from another and are not used to limit the elements. Unless otherwise stated, they do not limit the order or importance of the elements. Therefore, within the scope of this disclosure, a first element in one embodiment may be referred to as a second element in another embodiment, and similarly, a second element in one embodiment may be referred to as a first element in another embodiment.

[0037] The terminology used in this disclosure is for the purpose of describing particular embodiments and not for limiting the claims. As used in the description of embodiments and the appended claims, the singular form is intended to include the plural form unless the context clearly indicates otherwise. The term “and / or” as used in this disclosure may refer to one of the associated enumerations, or is intended to refer to and include any and all possible combinations of two or more of them. Furthermore, unless otherwise stated, the “ / ” between words in this disclosure has the same meaning as “and / or”.

[0038] The examples disclosed herein can be applied to various wireless communication systems. For example, the examples disclosed herein can be applied to wireless LAN systems. For example, the examples disclosed herein can be applied to wireless LANs based on the IEEE 802.11a / g / n / ac / ax standards. Furthermore, the examples disclosed herein can be applied to wireless LANs based on the newly proposed IEEE 802.11be (or EHT) standard. The examples disclosed herein can be applied to wireless LANs based on the IEEE 802.11be version 2 standard, corresponding to the additional enhancements of the IEEE 802.11be version 1 standard. Additionally, the examples disclosed herein can be applied to wireless LANs based on next-generation standards after IEEE 802.11be. Furthermore, the examples disclosed herein can be applied to cellular wireless communication systems. For example, it can be applied to cellular wireless communication systems based on 3GPP standards using Long Term Evolution (LTE) technology and 5G New Radio (NR) technology.

[0039] The technical features that can be applied to examples of this disclosure will be described below.

[0040] Figure 1 A block diagram illustrating a wireless communication device according to an embodiment of the present disclosure is shown.

[0041] Figure 1 The first device 100 and the second device 200 illustrated herein can be replaced by various terms such as terminal, wireless device, wireless transceiver unit (WTRU), user equipment (UE), mobile station (MS), user terminal (UT), mobile subscriber station (MSS), mobile subscriber unit (MSU), subscriber station (SS), advanced mobile station (AMS), wireless terminal (WT), or simply user. Furthermore, the first device 100 and the second device 200 include access point (AP), base station (BS), fixed station, node B, base transceiver system (BTS), and network. It can be replaced by various terms such as artificial intelligence (AI) system, roadside unit (RSU), repeater, router, relay, and gateway.

[0042] Figure 1 The devices 100 and 200 illustrated herein may be referred to as stations (STAs). For example, Figure 1The devices 100 and 200 illustrated herein may be referred to by various terms such as transmitting device, receiving device, transmitting STA, and receiving STA. For example, STA 110 and 200 may perform an access point (AP) role or a non-AP role. That is, in this disclosure, STA 110 and 200 may perform AP and / or non-AP functions. When STA 110 and 200 perform AP functions, they may simply be referred to as APs, and when STA 110 and 200 perform non-AP functions, they may simply be referred to as STAs. Alternatively, in this disclosure, AP may also be referred to as AP STA.

[0043] Reference Figure 1 The first device 100 and the second device 200 can transmit and receive radio signals via various wireless LAN technologies (e.g., IEEE 802.11 series). The first device 100 and the second device 200 may include interfaces for the Media Access Control (MAC) layer and Physical Layer (PHY) conforming to the IEEE 802.11 standard.

[0044] In addition to wireless LAN technology, the first device 100 and the second device 200 can also support various communication standards (e.g., 3GPP LTE series, 5G NR series standards, etc.). Furthermore, the devices disclosed herein can be implemented in various devices such as mobile phones, vehicles, personal computers, augmented reality (AR) devices, and virtual reality (VR) devices. Additionally, the STA of this specification can support various communication services such as voice calls, video calls, data communication, autonomous driving, machine-type communication (MTC), machine-to-machine (M2M), device-to-device (D2D), and IoT (Internet of Things).

[0045] The first device 100 may include one or more processors 102 and one or more memories 104, and may additionally include one or more transceivers 106 and / or one or more antennas 108. The processors 102 may control the memories 104 and / or the transceivers 106, and may be configured to implement the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure. For example, the processor 102 may transmit a wireless signal including the first information / signal via the transceivers 106 after generating first information / signal by processing information in the memories 104. Additionally, the processor 102 may receive a wireless signal including second information / signal via the transceivers 106, and then store information obtained through signal processing of the second information / signal in the memories 104. The memories 104 may be connected to the processor 102 and may store various information related to the operation of the processor 102. For example, the memories 104 may store software code including instructions for performing all or part of the processing controlled by the processor 102 or for performing the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure. Here, processor 102 and memory 104 may be part of a communication modem / circuit / chip designed to implement wireless LAN technology (e.g., IEEE 802.11 series). Transceiver 106 may be connected to processor 102 and may transmit and / or receive wireless signals via one or more antennas 108. Transceiver 106 may include a transmitter and / or a receiver. Transceiver 106 may be used with an RF (radio frequency) unit. In this disclosure, wireless device may refer to a communication modem / circuit / chip.

[0046] The second device 200 may include one or more processors 202 and one or more memories 204, and may additionally include one or more transceivers 206 and / or one or more antennas 208. The processors 202 may control the memories 204 and / or the transceivers 206, and may be configured to implement the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure. For example, the processors 202 may generate third information / signals by processing information in the memories 204, and then transmit a wireless signal including the third information / signals via the transceivers 206. Additionally, the processors 202 may receive wireless signals including fourth information / signals via the transceivers 206, and then store information obtained through signal processing of the fourth information / signals in the memories 204. The memories 204 may be connected to the processors 202 and may store various information related to the operation of the processors 202. For example, the memories 204 may store software code including instructions for performing all or part of the processing controlled by the processors 202 or for performing the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure. Here, processor 202 and memory 204 may be part of a communication modem / circuit / chip designed to implement wireless LAN technology (e.g., IEEE 802.11 series). Transceiver 206 may be connected to processor 202 and may transmit and / or receive wireless signals via one or more antennas 208. Transceiver 206 may include a transmitter and / or a receiver. Transceiver 206 may be used with an RF unit. In this disclosure, apparatus may refer to a communication modem / circuit / chip.

[0047] The hardware elements of devices 100 and 200 will be described in more detail below. Not limited thereto, one or more protocol layers may be implemented by one or more processors 102 and 202. For example, one or more processors 102 and 202 may implement one or more layers (e.g., functional layers such as PHY and MAC). One or more processors 102 and 202 may generate one or more PDUs (Protocol Data Units) and / or one or more SDUs (Service Data Units) according to the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts disclosed in this disclosure. One or more processors 102 and 202 may generate messages, control information, data, or information according to the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts disclosed in this disclosure. One or more processors 102 and 202 may generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data, or information according to the functions, processes, suggestions, and / or methods disclosed in this disclosure to provide them to one or more transceivers 106 and 206. One or more processors 102, 202 may receive signals (e.g., baseband signals) from one or more transceivers 106, 206 and obtain PDUs, SDUs, messages, control information, data or information, in accordance with the description, functions, processes, suggestions, methods and / or operation flowcharts included in this disclosure.

[0048] One or more processors 102, 202 may be referred to as controllers, microcontrollers, microprocessors, or microcomputers. One or more processors 102, 202 may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more ASICs (Application-Specific Integrated Circuits), one or more DSPs (Digital Signal Processors), one or more DSPDs (Digital Signal Processing Devices), one or more PLDs (Programmable Logic Devices), or one or more FPGAs (Field-Programmable Gate Arrays) may be included in one or more processors 102, 202. The descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure may be implemented using firmware or software, and the firmware or software may be implemented to include modules, processes, functions, etc. Firmware or software configured to execute the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure may be included in one or more processors 102, 202, or may be stored in one or more memories 104, 204 and driven by one or more processors 102, 202. The descriptions, functions, processes, suggestions, methods and / or operation flowcharts included in this disclosure may be implemented using firmware or software in the form of code, instructions and / or instruction sets.

[0049] One or more memories 104, 204 may be connected to one or more processors 102, 202 and may store data, signals, messages, information, programs, code, instructions, and / or commands in various forms. One or more memories 104, 204 may be configured with ROM, RAM, EPROM, flash memory, hard disk drive, registers, cache memory, computer-readable storage media, and / or combinations thereof. One or more memories 104, 204 may be located internally and / or externally to one or more processors 102, 202. Furthermore, one or more memories 104, 204 may be connected to one or more processors 102, 202 via various technologies such as wired or wireless connections.

[0050] One or more transceivers 106, 206 can transmit user data, control information, wireless signals / channels, etc., mentioned in the methods and / or operation flowcharts of this disclosure to one or more other devices. One or more transceivers 106, 206 can receive user data, control information, wireless signals / channels, etc., mentioned in the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure from one or more other devices. For example, one or more transceivers 106, 206 can be connected to one or more processors 102, 202 and can transmit and receive wireless signals. For example, one or more processors 102, 202 can control one or more transceivers 106, 206 to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors 102, 202 can control one or more transceivers 106, 206 to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers 106, 206 may be connected to one or more antennas 108, 208, and one or more transceivers 106, 206 may be configured to transmit and receive user data, control information, wireless signals / channels, etc., mentioned in the descriptions, functions, processes, suggestions, methods, and / or operation flowcharts included in this disclosure, via one or more antennas 108, 208. In this disclosure, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers 106, 206 may convert received wireless signals / channels, etc., from RF band signals into baseband signals for processing using one or more processors 102, 202. One or more transceivers 106, 206 may convert user data, control information, wireless signals / channels, etc., processed using one or more processors 102, 202, from baseband signals into RF band signals. Therefore, one or more transceivers 106, 206 may include (analog) oscillators and / or filters.

[0051] For example, one of STAs 100 and 200 can perform the expected operation of an AP, and the other of STAs 100 and 200 can perform the expected operation of a non-AP STA. For example, Figure 1 Transceivers 106 and 206 can perform transmission and reception operations of signals (e.g., packet or physical layer protocol data units (PPDUs) conforming to IEEE 802.11a / b / g / n / ac / ax / be / bn). Additionally, in this disclosure, the various STAs can generate transmit / receive signals or perform data processing or calculations on the transmit / receive signals in advance by [the relevant entity / component]. Figure 1Processors 102 and 202 perform the following operations: For example, examples of generating transmit / receive signals or performing data processing or computations on transmit / receive signals in advance may include: 1) determining / acquiring / configuring / computing / decoding / encoding bit information of fields (signals (SIG), short training field (STF), long training field (LTF), data, etc.) included in the PPDU; 2) determining / configuring / acquiring time or frequency resources (e.g., subcarrier resources) for the fields (SIG, STF, LTF, data, etc.) included in the PPDU; 3) determining / configuring / acquiring specific sequences (e.g., pilot sequences, STF / LTF sequences, additional sequences applied to SIG) for the fields (SIG, STF, LTF, data, etc.) included in the PPDU action; 4) power control operations and / or power saving operations applied to the STA; 5) operations related to determining / acquiring / configuring / computing / decoding / encoding of the ACK signal. Additionally, in the example below, various information used by different STAs to determine / acquire / configure / calculate / decode / encode transmitted and received signals (e.g., information related to fields / subfields / control fields / parameters / power, etc.) can be stored. Figure 1 In memory 104 and 204.

[0052] In the following text, downlink (DL) can refer to a link used for communication from an AP STA to a non-AP STA, and DL PPDU / packets / signals can be sent and received via DL. In DL communication, the transmitter can be part of an AP STA, and the receiver can be part of a non-AP STA. Uplink (UL) can refer to a link used for communication from a non-AP STA to an AP STA, and UL PPDU / packets / signals can be sent and received via UL. In UL communication, the transmitter can be part of a non-AP STA, and the receiver can be part of an AP STA.

[0053] Figure 2 This is a diagram illustrating an exemplary structure of a wireless LAN system to which this disclosure can be applied.

[0054] A wireless LAN system can be structured by multiple components. These components interact to provide STA mobility support that is transparent to upper layers. The Basic Service Set (BSS) corresponds to the basic building blocks of a wireless LAN. Figure 2 An example is shown where there are two BSSs (BSS1 and BSS2), and two STAs included as members of each BSS (STA1 and STA2 are included in BSS1, and STA3 and STA4 are included in BSS2). Figure 2The ellipse representing the BSS can also be interpreted as representing the coverage area within the corresponding BSS where STAs maintain communication. This area can be called the Basic Service Area (BSA). When a STA moves outside the BSA, it cannot communicate directly with other STAs within the BSA.

[0055] If we do not consider Figure 2 The DS shown in the diagram represents the most basic BSS type in a wireless LAN: the Independent BSS (IBSS). For example, an IBSS can have a minimal form containing only two STAs. For instance, assuming other components are omitted, BSS1 containing only STA1 and STA2, or BSS2 containing only STA3 and STA4, can respectively correspond to representative examples of IBSS. This configuration is possible when STAs can communicate directly without an AP. Furthermore, in this type of wireless LAN, it is not pre-configured but can be configured as needed, and this can be called an ad-hoc network. Since an IBSS does not include an AP, there is no centralized management entity. That is, in an IBSS, STAs are managed in a distributed manner. In an IBSS, all STAs can consist of mobile STAs and are not allowed to access the Distributed System (DS), thus forming a self-contained network.

[0056] Membership of an STA in a BSS can be dynamically changed by opening or closing an STA, or by entering or leaving a BSS zone. To become a member of a BSS, an STA can join the BSS using a synchronization process. To access all services of the BSS infrastructure, an STA must be associated with the BSS. This association can be dynamically established and may include the use of Distributed System Services (DSS).

[0057] Direct STA-to-STA distance in a wireless LAN may be limited by PHY performance. In some cases, this distance limitation may be sufficient, but in others, longer distances between STAs may be required for communication. Distributed systems (DS) can be configured to support extended coverage.

[0058] DS refers to the structure of BSS interconnection. Specifically, such as... Figure 2As shown, a BSS can exist as an extension of a network composed of multiple BSSs. A DS is a logical concept and can be specified through the characteristics of the Distributed System Medium (DSM). At this point, the Wireless Medium (WM) and the DSM can be logically separated. Each logical medium is used for a different purpose and by different components. These media are not limited to being the same, nor are they limited to being different. In this way, the flexibility of a wireless LAN architecture (DS architecture or other network architectures) can be interpreted as multiple media being logically different. That is, a wireless LAN architecture can be implemented in various ways, and the corresponding wireless LAN architecture can be independently specified by the physical characteristics of each implementation.

[0059] The DS can support mobile devices by providing seamless integration of multiple BSSs and offering the logical services necessary for addressing to the destination. Additionally, the DS may include a component called a portal, which acts as a bridge between the wireless LAN and other networks, such as IEEE 802.X.

[0060] AP enables access to DS via WM for associated non-AP STAs, and refers to entities that also have STA functionality. Data movement between BSS and DS can be performed through AP. For example, Figure 2 STA2 and STA3, shown in the diagram, have the functionality of STAs and provide the ability for associated non-AP STAs (STA1 and STA4) to access the DS. Furthermore, since all APs essentially correspond to STAs, all APs are addressable entities. The address used by an AP for communication on the WM is not necessarily the same as the address used by the AP for communication on the DSM. A BSS consisting of APs and one or more STAs can be referred to as an infrastructure BSS.

[0061] Data sent from one of the STAs associated with the AP to the corresponding STA address of the AP can always be received on an uncontrolled port and can be processed by the IEEE 802.1X port access entity. Alternatively, when the controlled port is authenticated, the transmitted data (or frames) can be delivered to the DS.

[0062] In addition to the DS structure described above, Extended Service Sets (ESS) can also be configured to provide wide coverage.

[0063] An ESS (Service Set Identity) refers to a network of arbitrary size and complexity consisting of DS (Service Controller) and BSS (Service Set Service). An ESS can correspond to a set of BSSs connected to a DS. However, an ESS does not include the DS. An ESS network is characterized as an IBSS (Integrated Service Set Service) within the Logical Link Control (LLC) layer. STAs included in an ESS can communicate with each other, and a moving STA can transparently move from one BSS to another (within the same ESS) to the LLC. APs included in an ESS can have the same Service Set Identity (SSID). The SSID is distinguished from the BSSID, which serves as the identifier for the BSS.

[0064] Wireless LAN systems make no assumptions about the relative physical locations of BSSs, and all of the following forms are possible. BSSs can partially overlap, a form commonly used to provide continuous coverage. Additionally, BSSs may not be physically connected, and logically, there is no limit to the distance between BSSs. Furthermore, BSSs can be physically located in the same location, which can be used to provide redundancy. Additionally, one (or more) IBSS or ESS networks can physically exist in the same space as one (or more) ESS networks. This can correspond to the form of ESS networks when an ad hoc network operates in a location where an ESS network exists, when physically overlapping wireless networks are configured by different organizations, or when two or more different access and security policies are required in the same location, etc.

[0065] Figure 3 This is a diagram illustrating the link establishment process that can be applied to this disclosure.

[0066] In order for a STA to establish a link with the network and send / receive data, it first discovers the network, performs authentication, establishes an association, and performs authentication processing for security. The link establishment process can also be called session initiation processing or session establishment processing. Furthermore, the discovery, authentication, association, and security establishment processes of the link establishment process can be collectively referred to as association processing.

[0067] In step S310, the STA can perform a network discovery operation. The network discovery operation may include a scanning operation by the STA. That is, in order for the STA to access a network, it needs to find networks it can participate in. The STA should identify compatible networks before participating in a wireless network, and the process of identifying networks existing in a specific area is called scanning.

[0068] Scanning schemes include active scanning and passive scanning. Figure 3An exemplary network discovery operation including active scanning processing is illustrated. In active scanning, the STA performing the scan sends a probe request frame to discover which APs are present around it as the channel moves and awaits a response. The responder sends a probe response frame as a response to the probe request frame to the STA that sent the probe request frame. Here, the responder may be the STA that last sent a beacon frame in the BSS of the channel being scanned. In the BSS, the AP becomes the responder because it sends a beacon frame, and in the IBSS, the STAs in the IBSS rotate to send beacon frames, so the responder is not constant. For example, an STA that sends a probe request frame on channel 1 and receives a probe response frame on channel 1 may store the BSS-related information included in the received probe response frame and may move to the next channel (e.g., channel 2) and perform a scan in the same manner (i.e., sending and receiving probe requests / responses on channel 2).

[0069] Although not in Figure 3 As shown, scanning can be performed passively. In passive scanning, the STA performing the scan waits for beacon frames while moving through the channel. Beacon frames are one of the management frames defined in IEEE 802.11 and are sent periodically to notify of the existence of a wireless network and allow the STA performing the scan to find and participate in the wireless network. In the BSS, the AP periodically sends beacon frames, and in the IBSS, the STA within the IBSS rotates to send beacon frames. When the STA performing the scan receives a beacon frame, it stores the BSS information included in the beacon frame and records the beacon frame information for each channel while moving to another channel. The STA receiving the beacon frame can store the BSS-related information included in the received beacon frame, move to the next channel, and perform scanning in the next channel in the same manner. Comparing active and passive scanning, active scanning has the advantages of less latency and less power consumption.

[0070] After the STA discovers the network, an authentication process can be performed in step S320. To clearly distinguish it from the security establishment operation in step S340, which will be described later, this authentication process can be referred to as the first authentication process.

[0071] The authentication process includes the following steps: the STA sends an authentication request frame to the AP, and in response, the AP sends an authentication response frame to the STA. The authentication frame used for the authentication request / response corresponds to the management frame.

[0072] An authentication frame includes the authentication algorithm number, authentication transaction sequence number, status code, challenge text, robust security network (RSN), and finite circular group. These correspond to some examples of information that can be included in the authentication request / response frame and can be replaced with other information, or additional information may be included.

[0073] A STA can send an authentication request frame to an AP. The AP can determine whether to allow the corresponding STA's authentication based on the information included in the received authentication request frame. The AP can then provide the STA with the authentication processing result via an authentication response frame.

[0074] After the STA is successfully authenticated, the association process can be performed in step S330. The association process includes the following steps: the STA sends an association request frame to the AP, and in response, the AP sends an association response frame to the STA.

[0075] For example, an association request frame may include information related to various capabilities, beacon listening intervals, service set identifiers (SSIDs), supported rates, supported channels, RSNs, mobility domains, supported operation classes, traffic indication mapping broadcast requests (TIM broadcast requests), interoperability capabilities, etc. Similarly, an association response frame may include information related to various capabilities, status codes, association IDs (AIDs), supported rates, enhanced distributed channel access (EDCA) parameter sets, received channel power indicators (RCPIs), received signal-to-noise ratio indicators (RSNIs), mobility domains, timeout intervals (e.g., association recovery time), overlapping BSS scan parameters, TIM broadcast responses, quality of service (QoS) mappings, etc. These correspond to some examples of information that can be included in association request / response frames and may be replaced with other information, or additional information may be included.

[0076] After the STA successfully associates with the network, a security establishment process can be performed in step S340. The security establishment process in step S340 can be referred to as the authentication process via a Robust Secure Network Association (RSNA) request / response, the authentication process in step S320 is referred to as the first authentication process, and the security establishment process in step S340 can also be simply referred to as the authentication process.

[0077] The secure establishment process in step S340 may include, for example, the process of establishing a private key using a four-way handshake via Extensible Authentication Protocol (EAPOL) frames over the LAN. Alternatively, the secure establishment process may be performed according to a security scheme not defined in the IEEE 802.11 standard.

[0078] Figure 4 This is a diagram illustrating the fallback process that can be applied to this disclosure.

[0079] In wireless LAN systems, the basic access mechanism for Media Access Control (MAC) is Carrier Sensing Multiple Access with Collision Avoidance (CSMA / CA). Also known as the Distributed Coordination Function (DCF) of IEEE 802.11 MAC, CSMA / CA essentially employs a "listen-before-talk" access mechanism. Under this type of access mechanism, before commencing transmission, the AP and / or STA can perform explicit channel assessment (CCA) of the sensing radio channel or medium during a predetermined time interval (e.g., the DCF inter-frame interval (DIFS)). As a result of the sensing, if it is determined that the medium is idle, frame transmission begins via the corresponding medium. Conversely, if the medium is detected to be occupied or busy, the corresponding AP and / or STA does not begin its own transmission and can set a delay period for medium access (e.g., a random backoff period) and attempt frame transmission after waiting. By applying a random backoff period, collisions can be minimized because multiple STAs are expected to attempt frame transmission after waiting for different time periods.

[0080] In addition, the IEEE 802.11 MAC protocol provides a Hybrid Coordination Function (HCF). HCF is based on DCF and Point Coordination Function (PCF). PCF is a polling-based synchronous access method, meaning that all receiving APs and / or STAs periodically poll to receive data frames. Furthermore, HCF includes Enhanced Distributed Channel Access (EDCA) and HCF Control Channel Access (HCCA). EDCA is a contention-based access method that provides data frames to multiple users, while HCCA uses a non-contention-based channel access method that utilizes a polling mechanism. Additionally, HCF includes a media access mechanism for improving the QoS (Quality of Service) of wireless LANs and can transmit QoS data during contention periods (CP) and contention-free periods (CFP).

[0081] Reference Figure 4This section describes the operation based on a random backoff period. When an occupied / busy medium becomes idle, multiple STAs can attempt to transmit data (or frames). As a method to minimize collisions, each STA can individually select a random backoff count and attempt to transmit after waiting for the corresponding time slot. The random backoff count has a pseudo-random integer value and can be determined as one of the values ​​ranging from 0 to CW. Here, CW is the contention window parameter value. The CW parameter is assigned an initial value of CWmin, but can take a value twice as large as in the event of transmission failure (e.g., when no ACK is received for the transmitted frame). When the CW parameter value reaches CWmax, data transmission can be attempted while maintaining the CWmax value until successful data transmission, and when successful, the CWmin value is reset. The values ​​of CW, CWmin, and CWmax are preferably set to 2. n -1 (n=0, 1, 2, ...).

[0082] When random backoff processing begins, the STA continuously monitors the medium during the backoff time slot countdown based on the determined backoff count value. When monitoring the medium for occupancy, it stops the countdown and waits, and restarts the remainder of the countdown when the medium becomes idle.

[0083] exist Figure 4 In the example, when the packet to be sent arrives at STA 3's MAC, STA 3 can send the frame immediately after confirming that the medium has been idle for up to DIFS. The remaining STAs monitor and wait for the medium to be occupied / busy. Meanwhile, the data to be sent can also occur in each of STA 1, STA 2, and STA 5, and when the medium is detected as idle, each STA waits for up to DIFS, and then performs a countdown for the backoff slot based on a random backoff count value chosen by each STA. Assume STA 2 chooses the minimum backoff count value, and STA 1 chooses the maximum backoff count value. That is, the example illustrates the case where STA 5's remaining backoff time is shorter than STA 1's remaining backoff time when STA 2 completes its backoff count and begins frame transmission. STA 1 and STA 5 temporarily stop the countdown and wait while STA 2 occupies the medium. When STA 2's occupancy ends and the medium becomes idle again, STA 1 and STA 5 wait for DIFS and restart the stopped backoff count. In other words, frame transmission can begin after a countdown for the remaining backoff slot based on the remaining backoff time. Since STA5 has a shorter remaining backoff time than STA1, STA5 begins frame transmission. Data to be transmitted can also occur in STA4 while STA2 is occupying the medium. From STA4's perspective, when the medium becomes idle, STA4 can wait for DIFS, then execute a countdown based on a random backoff count value selected by STA4, and begin transmitting frames. Figure 4 The example illustrates a scenario where the remaining backoff time of STA5 accidentally conflicts with the random backoff count value of STA4. In this case, a collision may occur between STA4 and STA5. When a collision occurs, neither STA4 nor STA5 receives an ACK, so data transmission fails. In this situation, STA4 and STA5 can double the CW value, select a random backoff count value, and begin a countdown. While the medium is occupied due to the transmissions of STA4 and STA5, STA1 waits; when the medium becomes idle, STA1 waits for DIFS, and then begins frame transmission after the remaining backoff time has elapsed.

[0084] As in Figure 4 In the example, data frames are frames used to send data forwarded to higher layers and can be sent after a backoff performed after DIFS, starting from when the medium becomes idle. Additionally, management frames are frames used to exchange management information that has not been forwarded to higher layers and are sent after a backoff performed after an IFS such as DIFS or Point Coordination Function IFS (PIFS). Subtypes of management frames include beacons, association requests / responses, reassociation requests / responses, probe requests / responses, authentication requests / responses, etc. Control frames are frames used to control access to the medium. Subtypes of control frames include request to send (RTS), clear send (CTS), acknowledge (ACK), power-saving polling (PS-Poll), block ACK (BlockAck), block ACK request (BlockACKReq), empty data packet advertisement (NDP advertisement), and triggers, etc. If a control frame is not a response frame to the previous frame, it is sent after a backoff performed after DIFS; if it is a response frame to the previous frame, it is sent without a backoff performed after short IFS (SIFS). The type and subtype of a frame can be identified by the type field and subtype field in the Frame Control (FC) field.

[0085] The Quality of Service (QoS) ST can perform a backoff following the Arbitration IFS (AIFS) for the Access Class (AC) to which the frame belongs (i.e., AIFS where i is a value determined by the AC) before the frame can be transmitted. Here, the frame that can use AIFS can be a data frame, management frame, or control frame, rather than a response frame.

[0086] Figure 5 This is a diagram illustrating the CSMA / CA-based frame transmission operation that can be applied to this disclosure.

[0087] As mentioned above, in addition to physical carrier sensing of the medium directly sensed by the STA, the CSMA / CA mechanism also includes virtual carrier sensing. Virtual carrier sensing aims to compensate for problems such as hidden node issues that may occur during medium access. For virtual carrier sensing, the STA's MAC can use the Network Allocation Vector (NAV). The NAV is a value that indicates to other STAs the remaining time until the medium is available for current use or for STAs authorized to use the medium. Therefore, a value set to NAV corresponds to the period during which the STA sending the frame plans to use the medium, and during the corresponding period, STAs receiving the NAV value are prohibited from accessing the medium. For example, the NAV can be configured based on the value of the "Duration" field in the frame's MAC header.

[0088] exist Figure 5 In the example, it is assumed that STA1 intends to send data to STA2, and STA3 is in a position that can eavesdrop on some or all of the frames sent and received between STA1 and STA2.

[0089] To reduce the likelihood of transmission conflicts among multiple STAs in CSMA / CA-based frame transmission operations, a mechanism using RTS / CTS frames can be applied. Figure 5 In the example, when STA1 is transmitting, as a result of carrier sensing by STA3, it can be determined that the medium is in an idle state. That is, STA1 can correspond to a hidden node with respect to STA3. Alternatively, in Figure 5 In the example, it can be determined that while STA2 is transmitting, the carrier sensing result medium of STA3 is in an idle state. That is, STA2 can correspond to a hidden node with respect to STA3. By exchanging RTS / CTS frames before performing data transmission and reception between STA1 and STA2, STAs outside the transmission range of either STA1 or STA2, or STAs outside the carrier sensing range of transmissions from STA1 or STA3, can avoid attempting to occupy the channel during data transmission and reception between STA1 and STA2.

[0090] Specifically, STA1 can determine whether a channel is in use through carrier sensing. Regarding physical carrier sensing, STA1 can determine the channel occupancy / idle status based on the energy level or signal correlation detected in the channel. Alternatively, regarding virtual carrier sensing, STA1 can use a Network Allocation Vector (NAV) timer to determine the channel occupancy status.

[0091] When the channel is idle during DIFS, STA1 can send an RTS frame to STA2 after performing backoff. When STA2 receives the RTS frame, STA2 can send a CTS frame to STA1 after SIFS as a response to the RTS frame.

[0092] If STA3 cannot eavesdrop on CTS frames from STA2 but can eavesdrop on RTS frames from STA1, STA3 can use the duration information included in the RTS frame to set the NAV timer for the subsequent consecutive frame transmission period (e.g., SIFS+CTS frame+SIFS+data frame+SIFS+ACK frame). Alternatively, if STA3 can eavesdrop on CTS frames from STA2, STA3 can also use the duration information included in the CTS frame to set the NAV timer for the subsequent consecutive frame transmission period (e.g., SIFS+data frame+SIFS+ACK frame) even though STA3 cannot eavesdrop on RTS frames from STA1. That is, if STA3 can eavesdrop on one or more RTS frames or CTS frames from STA1 or STA2, STA3 can set the NAV accordingly. When STA3 receives a new frame before the NAV timer expires, STA3 can update the NAV timer using the duration information included in the new frame. STA3 does not attempt channel access until the NAV timer expires.

[0093] When STA1 receives a CTS frame from STA2, STA1 can send a data frame to STA2 after SIFS, starting from the time point when the CTS frame reception is complete. When STA2 successfully receives the data frame, STA2 can send an ACK frame to STA1 after SIFS as a response to the data frame. When the NAV timer expires, STA3 can determine whether the channel is in use through carrier sensing. If STA3 determines that the channel is not in use by other terminals during DIFS after the NAV timer expires, STA3 can attempt channel access after the contention window (CW) for random backoff has passed.

[0094] Figure 6 This is a diagram illustrating an example of a frame structure that can be used in a WLAN system to which this disclosure may be applied.

[0095] Using instructions or primitives (meaning a set of instructions or parameters) from the MAC layer, the PHY layer can prepare the MAC PDU (MPDU) to be transmitted. For example, when the PHY layer receives a command from the MAC layer requesting the start of transmission, it switches to transmit mode, configures the information (e.g., data) provided by the MAC layer in the form of a frame, and transmits it. Additionally, when the PHY layer detects a valid preamble in a received frame, it monitors the preamble header and sends a command to the MAC layer notifying the PHY layer of the start of reception.

[0096] In this way, information transmission / reception in a wireless LAN system is performed in the form of frames, and for this purpose, the PHY layer Protocol Data Unit (PPDU) format is defined.

[0097] A basic PPDU can include a Short Training Field (STF), a Long Training Field (LTF), a Signal (SIG) field, and a Data field. The most basic PPDU format (e.g., Figure 7 The non-HT (High Throughput) fields shown can consist solely of a Traditional-STF (L-STF), Traditional-LTF (L-LTF), Traditional-SIG (L-SIG) field, and a data field. Additionally, depending on the PPDU format type (e.g., HT mixed format PPDU, HT green format PPDU, VHT (Very High Throughput) PPDU, etc.), additional (or different types) RL-SIG, U-SIG, non-traditional SIG fields, non-traditional STF, non-traditional LTF (i.e., xx-SIG, xx-STF, xx-LTF (e.g., xx is HT, VHT, HE, EHT, etc.)) can be included between the L-SIG field and the data field.

[0098] STF is a signal used for signal detection, automatic gain control (AGC), diversity selection, precise time synchronization, etc., while LTF is a signal used for channel estimation and frequency error estimation. STF and LTF can be referred to as signals used for synchronization and channel estimation in the OFDM physical layer.

[0099] The SIG field can include various information related to PPDU transmission and reception. For example, the L-SIG field consists of 24 bits and can include a 4-bit rate field, a 1-bit reserved bit, a 12-bit length field, a 1-bit parity field, and a 6-bit tail field. The RATE field can include information about the modulation and coding rate of the data. For example, the 12-bit length field can include information about the length or duration of the PPDU. For example, the value of the 12-bit length field can be determined based on the type of PPDU. For example, for non-HT, HT, VHT, or EHT PPDUs, the value of the length field can be determined to be a multiple of 3. For example, for HE PPDUs, the value of the length field can be determined to be a multiple of 3+1 or 3+2.

[0100] The data field may include a service field, a physical layer service data unit (PSDU), and PPDU tail bits, and may also include padding bits if necessary. Some bits of the service field can be used for synchronization of the descrambler at the receiver. The PSDU corresponds to the MAC PDU defined in the MAC layer and may include data generated / used in the upper layer. The PPDU tail bits can be used to return the encoder to a 0 state. Padding bits can be used to adjust the length of the data field by predetermined units.

[0101] MAC PDUs are defined according to various MAC frame formats, and a basic MAC frame consists of a MAC header, a frame body, and a Frame Check Sequence (FCS). MAC frames can be composed of MAC PDUs and transmitted / received via PSDUs in the data portion of the PPDU format.

[0102] The MAC header includes a frame control field, a duration / ID field, and an address field. The frame control field can include control information required for frame transmission / reception. The duration / ID field can be set to the time used to transmit the corresponding frame, etc. For details on the sequence control, QoS control, and HT control subfields of the MAC header, refer to the IEEE 802.11 standard document.

[0103] The Narrow Data PPDU (NDP) format refers to a PPDU format that does not include the data field. In other words, NDP is a frame format that includes the PPDU preamble of the general PPDU format (i.e., the L-STF, L-LTF, L-SIG fields and other non-traditional SIG, non-traditional STF, and non-traditional LTF (if present)) and does not include the remaining part (i.e., the data field).

[0104] Figure 7 This is a diagram illustrating an example of a PPDU as defined in the IEEE 802.11 standard of this disclosure.

[0105] Various types of PPDUs have been used in standards such as IEEE 802.11a / g / n / ac / ax. The basic PPDU format (IEEE 802.11a / g) includes L-LTF, L-STF, L-SIG, and a data field. The basic PPDU format can also be referred to as a non-HT PPDU format (such as...). Figure 7 (as shown in (a)).

[0106] Compared to the basic PPDU format, the HT PPDU format (IEEE 802.11n) additionally includes the HT-SIG, HT-STF, and HT-LFT fields. Figure 7The HT PPDU format shown in (b) can be referred to as the HT hybrid format. Furthermore, an HT green format PPDU can be defined, and this corresponds to a format consisting of HT-GF-STF, HT-LTF1, HT-SIG, one or more HT-LTFs and data fields, excluding L-STF, L-LTF, and L-SIG (not shown).

[0107] Compared to the basic PPDU format, examples of the VHT PPDU format (IEEE 802.11ac) additionally include VHTSIG-A, VHT-STF, VHT-LTF, and VHT-SIG-B fields (such as...). Figure 7 (as shown in (c)).

[0108] Compared to the basic PPDU format, examples of the HE PPDU format (IEEE 802.11ax) additionally include repeated L-SIG (RL-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF, and Packet Extension (PE) fields (such as...). Figure 7 (as shown in (d)). Some fields can be excluded, or their lengths can vary depending on the detailed examples of the HE PPDU format. For example, the HE-SIG-B field is included in the HE PPDU format for multi-user (MU), but not in the HE PPDU format for single-user (SU). Furthermore, the HE-Trigger-Based (TB) PPDU format does not include HE-SIG-B, and the length of the HE-STF field can vary up to 8 μs. The Extended Range (HE ER) SU PPDU format does not include the HE-SIG-B field, and the length of the HE-SIG-A field can vary up to 16 μs. For example, RL-SIG can be configured to be the same as L-SIG. Based on the presence of RL-SIG, the receiving STA can determine whether the received PPDU is an HE PPDU or an EHT PPDU, which will be described later.

[0109] EHT PPDU format can include Figure 7 EHT MU (Multi-user) in (e) and Figure 7 The EHT TB (trigger-based) PPDU in (f). The EHT PPDU format is similar to the HE PPDU format in that it includes RL-SIG following L-SIG, but it can include U (generic)-SIG, EHT-SIG, EHT-STF and EHT-LTF following RL-SIG.

[0110] Figure 7In (e), the EHT MU PPDU corresponds to a PPDU carrying one or more data (or PSDU) for one or more users. That is, the EHT MU PPDU can be used for both SU and MU transmissions. For example, the EHT MU PPDU can correspond to a PPDU for one or more receiving STAs.

[0111] Compared to EHT MU PPDU, Figure 7 In (f), the EHT-SIG is omitted from the EHT TB PPDU. The STA that receives the trigger for UL MU transmission (e.g., trigger frame or trigger response schedule (TRS)) can perform UL transmission based on the EHT TB PPDU format.

[0112] The L-STF, L-LTF, L-SIG, RL-SIG, U-SIG (general signal), and EHT-SIG fields can be encoded and modulated so that even conventional STAs can attempt demodulation and decoding, and can be mapped based on a determined subcarrier frequency interval (e.g., 312.5 kHz). These can be referred to as pre-EHT modulated fields. Next, the EHT-STF, EHT-LTF, data, and PE fields can be encoded and modulated to be demodulated and decoded by an STA that has successfully decoded a non-conventional SIG (e.g., U-SIG and / or EHT-SIG) and obtained the information contained in that field, and can be mapped based on a determined subcarrier frequency interval (e.g., 78.125 kHz). These can be referred to as EHT modulated fields.

[0113] Similarly, in the HE PPDU format, the L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, and HE-SIG-B fields can be referred to as pre-HE modulation fields, and the HE-STF, HE-LTF, data, and PE fields can be referred to as HE modulation fields. Additionally, in the VHT PPDU format, the L-STF, L-LTF, L-SIG, and VHT-SIG-A fields can be referred to as non-VHT modulation fields, and the VHT STF, VHT-LTF, VHT-SIG-B, and data fields can be referred to as VHT modulation fields.

[0114] Included Figure 7In the EHT PPDU format, U-SIG can be configured based on, for example, two symbols (e.g., two consecutive OFDM symbols). Each symbol used for U-SIG (e.g., an OFDM symbol) can have a duration of 4 μs, and U-SIG can have a total duration of 8 μs. Each symbol of U-SIG can be used to transmit 26 bits of information. For example, each symbol of U-SIG can be transmitted and received based on 52 data tones and 4 pilot tones.

[0115] U-SIGs can be constructed in 20 MHz units. For example, if an 80 MHz PPDU is constructed, U-SIGs can be replicated. That is, the same four U-SIGs can be included in an 80 MHz PPDU. PPDUs with bandwidths exceeding 80 MHz can include different U-SIGs.

[0116] For example, A uncoded bits can be sent via U-SIG. The first symbol of U-SIG (e.g., U-SIG-1 symbol) can send the first X bits of the total A-bit information, and the second symbol of U-SIG (e.g., U-SIG-2 symbol) can send the remaining Y bits of the total A-bit information. The A-bit information (e.g., 52 uncoded bits) may include a CRC field (e.g., a 4-bit field) and a tail field (e.g., a 6-bit field). For example, the tail field can be used to terminate the lattice structure of the convolutional decoder and can be set to 0.

[0117] Bit information sent via U-SIG can be divided into version-independent bits and version-dependent bits. For example, U-SIG can be included in... Figure 7 The new PPDU format (e.g., UHR PPDU format) not shown in the figure, and may be included in the format of the U-SIG field included in the EHT PPDU format and the format of the U-SIG field included in the UHR PPDU format, the version-independent bits may be the same, and some or all of the version-related bits may be different.

[0118] For example, the size of the version-independent bits in U-SIG can be fixed or variable. Version-independent bits can be assigned only to the U-SIG-1 symbol, or to both the U-SIG-1 and U-SIG-2 symbols. Version-independent bits and version-dependent bits can be referred to by various names, such as first control bits and second control bits.

[0119] For example, the version-independent bits of U-SIG may include a 3-bit Physical Layer Version Identifier (PHY Version Identifier), which can indicate the PHY version (e.g., EHT, UHR, etc.) of the transmitted / received PPDU. The version-independent bits of U-SIG may include a 1-bit UL / DL Flag field. The first value of the 1-bit UL / DL Flag field is related to UL communication, and the second value is related to DL communication. The version-independent bits of U-SIG may include information about the length of the Transmission Opportunity (TXOP) and information about the BSS color ID.

[0120] For example, the version-related bits of U-SIG may include information that directly or indirectly indicates the type of PPDU (e.g., SUPPDU, MU PPDU, TB PPDU, etc.).

[0121] Information required for PPDU transmission and reception can be included in the U-SIG. For example, the U-SIG may also include information about bandwidth, information about the MCS technique applied to non-traditional SIGs (e.g., EHT-SIG or UHR-SIG), information indicating whether DCM (dual-carrier modulation) techniques (e.g., techniques used to achieve effects similar to frequency diversity by reusing the same signal on two subcarriers) are applied to non-traditional SIGs, information about the number of symbols used for non-traditional SIGs, and information about whether non-traditional SIGs are generated across the entire frequency band.

[0122] Some of the information required for PPDU transmission and reception may be included in U-SIG and / or non-traditional SIG (e.g., EHT-SIG or UHR-SIG). For example, information about the type of non-traditional LTF / STF (e.g., EHT-LTF / EHT-STF or UHR-LTF / UHR-STF), the length of the non-traditional LTF and the CP (cyclic prefix) length, the GI (guard interval) applicable to the non-traditional LTF, the preamble punching information applicable to the PPDU, and the resource unit (RU) allocation may be included only in U-SIG, only in non-traditional SIG, or may be indicated by a combination of information included in U-SIG and information included in non-traditional SIG.

[0123] Preamble puncturing can represent the transmission of a PPDU where no signal is present in one or more frequency units within the bandwidth of the PPDU. For example, the size of the frequency unit (or the resolution of the preamble puncturing) can be defined as 20 MHz, 40 MHz, etc. For example, preamble puncturing can be applied to PPDU bandwidths of a predetermined size or larger.

[0124] exist Figure 7In the examples, non-traditional SIGs such as HE-SIG-B and EHT-SIG can include control information for receiving STAs. Non-traditional SIGs can be transmitted on at least one symbol, and a symbol can have a length of 4 μs. Information regarding the number of symbols used for EHT-SIGs can be included in previous SIGs (e.g., HE-SIG-A, U-SIG, etc.).

[0125] Non-traditional SIGs such as HE-SIG-B and EHT-SIG can include both public and user-specific fields. These public and user-specific fields can be encoded separately.

[0126] In some cases, the common field can be omitted. For example, in compressed mode using non-OFDMA (Orthogonal Frequency Division Multiple Access), the common field can be omitted, and multiple STAs can receive PPDUs (e.g., the data field of the PPDU) through the same frequency band. In uncompressed mode using OFDMA, multiple users can receive PPDUs (e.g., the data field of the PPDU) through different frequency bands.

[0127] The number of user-specific fields can be determined based on the number of users. A user block field can include up to two user fields. Each user field can be associated with either a MU-MIMO allocation or a non-MU-MIMO allocation.

[0128] The common fields may include CRC bits and tail bits, where the length of the CRC bits can be determined to be 4 bits, and the length of the tail bits can be determined to be 6 bits and set to 000000. The common fields may include RU allocation information. RU allocation information may include bit settings regarding the RUs assigned to multiple users (i.e., multiple receiving STAs).

[0129] An RU can include multiple subcarriers (or tones). RUs can be used when transmitting signals to multiple STAs based on OFDMA technology. Additionally, RUs can be defined even when transmitting signals to a single STA. Resources can be allocated in units of RUs for non-traditional STFs, non-traditional LTFs, and data fields.

[0130] The appropriate RU size can be defined based on the PPDU bandwidth. RUs can be defined the same or different for the applied PPDU format (e.g., HEPPDU, EHT PPDU, UHR PPDU, etc.). For example, in the case of an 80 MHz PPDU, the RU layout for HEPPDU and EHT PPDU can be different. The appropriate RU size, number and location of RUs, DC (direct current) subcarrier locations and numbers, empty subcarrier locations and numbers, guard subcarrier locations and numbers, etc., for each PPDU bandwidth can be referred to as the tone scheme. For example, a tone scheme for high bandwidth can be defined as multiple iterations of a low-bandwidth tone scheme.

[0131] RUs of various sizes can be defined as 26-tone RUs, 52-tone RUs, 106-tone RUs, 242-tone RUs, 484-tone RUs, 996-tone RUs, 2×996-tone RUs, 3×996-tone RUs, etc. MRUs (Multiple RUs) differ from multiple individual RUs and correspond to a group of subcarriers composed of multiple RUs. For example, an MRU can be defined as 52+26 tones, 106+26 tones, 484+242 tones, 996+484 tones, 996+484+242 tones, 2×996+484 tones, 3×996 tones, or 3×996+484 tones. Furthermore, the multiple RUs constituting an MRU can be consecutive or non-consecutive in the frequency domain.

[0132] The specific size of the RU can be reduced or expanded. Therefore, the specific size of each RU in this disclosure (i.e., the number of corresponding tones) is not limiting but illustrative. In addition, in this disclosure, the number of RUs can vary depending on the RU size within a predetermined bandwidth (e.g., 20 MHz, 40 MHz, 80 MHz, 160 MHz, 320 MHz...).

[0133] Figure 7 The names of each field in the PPDU format are exemplary, and the scope of this disclosure is not limited to these names. Furthermore, the examples in this disclosure can be applied to… Figure 7 The PPDU format shown and based on Figure 7 A new PPDU format that excludes some fields and / or adds some fields, based on the PPDU format.

[0134] Block-ACK (BlockACK, BA) frame

[0135] Figure 8 This is a diagram illustrating an exemplary format of the block-ACK frame to which the present disclosure can be applied.

[0136] The block-ACK (BlockAck, BA) mechanism is a method to improve channel efficiency by including and sending multiple acknowledgment responses in a single frame. For example, a first STA (e.g., an AP) can request the reception results of multiple MPDUs via a block-ACK request frame, and a second STA that receives the block-ACK request frame can send a block-ACK frame containing acknowledgment responses for the multiple MPDUs based on the corresponding request.

[0137] like Figure 8 As shown, a block-ACK frame can include a BA control field and a BA information field in the frame body.

[0138] The BA control field may include BA type indicating the type of block-ACK frame (e.g., compressed, multi-STA, etc.), management ACK information, TID information (TID_INFO), etc.

[0139] The BA information field can be based on the type of block-ACK frame (i.e., block-ACK frame variant type) indicated by the BA type field / subfield within the BA control information.

[0140] For example, when indicating a compressed block-ACK frame type, the BA information field format corresponding to compressed block-ACK may include a block-ACK start sequence control field and a block-ACK bitmap field.

[0141] In this regard, the segment number subfield of the block-ACK start sequence control field can be defined as shown in Table 1 below.

[0142] [Table 1]

[0143] Referring to Table 1, when a compressed block-ACK frame is sent to or from a non-HE STA, the segment number subfield of the block-ACK start sequence control field can be set to the value 0.

[0144] When bit B0 of the segment number subfield is 0 and bit B3 is 0, the block-ACK bitmap subfield of the BA information field of the compressed block-ACK frame can represent the reception status of up to 64 or 256 MSDUs and / or A-MSDUs according to the bit values ​​of bits B2-B1 of the segment number subfield as indicated in Table 1. When bit B0 of the segment number subfield is 0 and bit B3 of the segment number subfield is 1, the block-ACK bitmap subfield of the BA information field of the compressed block-ACK frame can represent the reception status of up to 512 or 1024 MSDUs and / or A-MSDUs according to the bit values ​​of bits B2-B1 of the segment number subfield as shown in Table 1. In the compressed block-ACK bitmap subfield, each bit that is the same as 1 confirms the reception of a single MSDU or A-MSDU in sequence number order, and the first bit of the block-ACK bitmap subfield may correspond to an MSDU (or a segment thereof) or an A-MSDU (or a segment thereof) with a sequence number that matches the start sequence number subfield of the block-ACK start sequence control subfield.

[0145] When bit B0 of the segment number subfield is 1, the block-ACK bitmap subfield of the BA information field of the compressed block-ACK frame can represent the reception status of up to 16 or 64 MSDUs and / or A-MSDUs, according to the bit values ​​of bits B2-B1 of the segment number subfield indicated in Table 1. When the bit position of the block-ACK bitmap subfield is n (here, n=4)... When (SN-SSN)+FN) is 1, it confirms the reception of an MPDU with sequence number SN and segment number FN. Here, SSN is the value of the start sequence number subfield of the block-ACK start sequence control subfield, and operations on the sequence number can be performed modulo 4096. When bit position n of the block-ACK bitmap subfield is 0, it indicates that no MPDU has been received.

[0146] As another example, when indicating the multi-STA block-ACK frame type, the BA information field format corresponding to the multi-STA block-ACK may include one or more per-AID TID information subfields.

[0147] In this respect, when the AID11 subfield is not 2045, each AID TID information subfield may include an AID TID information subfield, a block-ACK start sequence control subfield, and a block-ACK bitmap subfield. Here, the AID TID information subfield may include an (11-bit) AID11 subfield, a (1-bit) ACK type subfield, and a (4-bit) TID subfield. As an example, when a multi-STA block-ACK frame is sent by the AP, the AID11 subfield is set to 0, and the value 2045 in the AID11 subfield can be used as an identifier for unassociated STAs.

[0148] In this regard, when the AID11 subfield is not 2045, the values ​​of subfields within each AID TID information subfield and whether optional subfields exist can be defined based on Table 2 below.

[0149] [Table 2]

[0150] In this respect, when the ACK type subfield is 0, the segment number subfield encoding can indicate the length of the block-ACK bitmap subfield as defined in Table 3. Table 3 illustrates the segment number subfield encoding for multi-STA block-ACK types.

[0151] [Table 3]

[0152] Referring to Table 3, when bit B0 and bit B3 of the segment number subfield in the block-ACK start sequence control subfield are both 0, the BA information field of the multi-STA block-ACK frame includes an 8-octet, 16-octet, 32-octet, or 4-octet block-ACK bitmap subfield, which can represent the reception status of up to 64, 128, 256, or 32 MSDUs (or their segments) and / or A-MSDUs (or their segments), respectively. When bit B0 and bit B3 of the segment number subfield in the block-ACK start sequence control subfield are both 0, the BA information field of the multi-STA block-ACK frame includes a 64-octet or 128-octet block-ACK bitmap subfield, which can represent the reception status of up to 512 or 1024 MSDUs and / or A-MSDUs, respectively. Each bit in the block-ACK bitmap subfield that is the same as 1 confirms the reception of a single MSDU or A-MSDU in sequence number order, and the first bit of the block-ACK bitmap subfield may correspond to an MSDU (or a segment thereof) or an A-MSDU (or a segment thereof) with a sequence number that matches the start sequence number subfield of the start sequence control subfield of the block-ACK start sequence control subfield.

[0153] When bit B0 of the segment number subfield is 1, according to the bit values ​​of bits B2-B1 of the segment number subfield indicated in Table 3, the block-ACK bitmap subfield of the BA information field of the multi-STA block-ACK frame can represent the reception status of up to 16, 32, 64, or 8 MSDUs and / or A-MSDUs. When the bit position of the block-ACK bitmap subfield is n (here, n=4)... When (SN-SSN)+FN) is 1, it confirms the reception of an MPDU with sequence number SN and segment number FN. Here, SSN is the value of the start sequence number subfield of the block-ACK start sequence control subfield, and operations on the sequence number can be performed modulo 4096. When bit position n of the block-ACK bitmap subfield is 0, it indicates that no MPDU has been received.

[0154] BIP (Broadcast / Multicast Integrity Protocol)

[0155] BIP provides data integrity and replay protection for group-addressed robust management frames after establishing an Integrity Group Temporary Key Security Association (IGTKSA) and for beacon frames after establishing a Beacon Integrity Group Temporary Key Security Association (BIGTKSA). Additionally, BIP provides integrity and replay protection for individually addressed and group-addressed Wake-up Radio (WUR) frames.

[0156] In this respect, BIP-CMAC-128 can provide data integrity and replay protection using AES-128 in CMAC mode with a 128-bit integrity key and a CMAC TLen value of 128 (16 octets). Furthermore, BIP-CMAC-256 can provide data integrity and replay protection using AES-256 in CMAC mode with a 256-bit integrity key and a CMAC TLen value of 128 (16 octets).

[0157] BIP can compute the Management MPDU (MMPDU) Message Integrity Code (MIC) using either the Integrity Group Temporary Key (IGTK) or the Beacon Integrity Group Temporary Key (BIGTK). Additionally, BIP can compute the MIC using the WUR Temporary Key (WTK) to protect individually addressed WUR wake-up frames. Furthermore, BIP can compute the MIC using the WIGTK (WUR Integrity Group Temporary Key) to protect broadcast or group-addressed WUR wake-up frames.

[0158] When negotiating management frame protection, the authenticator distributes a new IGTK and IGTK group number (IGTK PN, IPN) whenever a new group temporary key (GTK) is distributed. The IGTK is identified by the MAC address of the sending STA and the IGTK key ID encoded in the Key ID field within the Management MIC element (MME). Furthermore, when beacon protection is enabled, the authenticator can distribute a new BIGTK and BIGTK group number (BIPN) when distributing a new GTK. The BIGTK is identified by the MAC address of the sending STA and the BIGTK key ID encoded in the Key ID field within the MME. Additionally, when negotiating WUR frame protection, the authenticator can distribute a new WIGTK and a WIGTK group number (WIPN) when distributing the new GTK. The WIGTK is identified by the MAC address of the sending STA and the WIGTK key ID encoded in the Key ID field within the MME.

[0159] Figure 9 Examples of BIP MMPDU formats applicable to this disclosure are shown.

[0160] Reference Figure 9 BIP encapsulation (i.e., BIP MMPDU format) may include a MAC header (e.g., an IEEE 802.11 header), a management frame body including a management MIC element (MME), and an FCS.

[0161] In this respect, the MME format can include element ID information, length information, key ID information, PN information (e.g., IPN, BIPN, WIPN, etc.) and MIC information.

[0162] Additionally, Additional Authentication Data (AAD) used for BIP-based integrity verification (e.g., BIP AAD) can be constructed from the MAC header. For example, the AAD can consist of an MPDU frame control field and address information. As a specific example, a 20-octet BIP AAD may include a 2-octet MPDU frame control field, a 6-octet MPDU address 1 field, a 6-octet MPDU address 2 field, and a 6-octet MPDU address 3 field.

[0163] Methods for supporting BIP-based integrity verification for block-ACK frames (BlockAck frames)

[0164] In traditional wireless LAN systems, for individually addressed data frames (e.g., unicast-based data frames) and management frames, encryption / decryption based on the Temporary Key Integrity Protocol (TKIP), the CTR Protocol with CBC-MAC (CCMP), or the GCM Protocol (GCMP) can be performed / applied using pairwise transient keys (PTKs). Furthermore, for group-addressed frames (e.g., broadcast-based data frames), encryption / decryption based on TKIP / CCMP / GCMP can be performed / applied using a group temporary key (GTK). That is, CCMP / GCMP are secure protocols for performing encryption / decryption, where PTK-based TKs can be used in single-user (SU) scenarios, and GTK-based TKs can be used in multi-user (MU) scenarios. CCMP / GCMP ensures the confidentiality and integrity of data frames and management frames.

[0165] Furthermore, for group-addressed management frames, integrity checks based on BIP can be performed using the Integrity Group Temporary Key (IGTK). Specifically, in the case of beacon frames, integrity checks based on BIP can be performed using the Beacon Integrity Group Temporary Key (BIGTK). In the case of BIP, the IGTK / BIGTK-based TK is used to generate a Message Integrity Code (MIC) for the frame body of the corresponding data frame, and integrity checks can be performed based on this. That is, unlike CCMP / GCMP, BIP can ensure the integrity of only data frames and management frames.

[0166] The methods for building MPDUs based on CCMP and GCMP and the methods for building management MPDUs (MMPDUs) based on BIP have the following differences.

[0167] First, in the case of CCMP / GCMP, the sending STA encrypts the data portion using CCM / GCM, sends the encrypted data, and the receiving STA can decrypt the received encrypted data. In contrast, in the case of BIP, the sending STA does not encrypt the data portion and can execute the corresponding protocol to generate a MIC for integrity verification of the data in the frame body.

[0168] Next, in the case of CCMP / GCMP, the MPDU can be constructed and sent / received in the following order: MAC header, CCMP / GCMP header, encrypted data, MIC (or encrypted MIC in the case of CCMP), and FCS. In contrast, in the case of BIP, the MPDU can be constructed and sent / received in the following order: MAC header, management frame body including MME (management MIC element), and FCS. In this paper, since the MME replaces the role of the CCMP / GCMP header, the MME can include a key ID field, IPN / BIPN, and MIC information.

[0169] As described above, protection is supported for data frames and management frames, including beacon frames, within group-addressed frames. However, protection is not supported for control frames; therefore, control frames are sent and received without the application of protocols for encryption / decryption and / or integrity verification.

[0170] For example, ACK and Block-ACK (BlockAck, Block Ack, BA) frames correspond to the types of control frames. When a sending STA transmits data, a receiving STA can send an ACK for the corresponding data to the sending STA. In this case, a STA supporting A (aggregated)-MPDU can configure an ACK corresponding to the A-MPDU and send it in block-ACK form.

[0171] Block-ACK frames belonging to the control frame category can consist of compressed block-ACK type and multi-STA block-ACK type. In the compressed block-ACK type, one STA sends a block-ACK, while in the multi-STA block-ACK type, multiple STAs send ACKs in block-ACK format. Unlike the compressed block-ACK type, for the multi-STA block-ACK type, the AID11 subfield can be included in the BA information field of the block-ACK frame, and by distinguishing which STA sent ACK information through the corresponding AID, the ACK information for each STA can be included in the block-ACK frame. Therefore, compared to the method of sending and receiving separate block-ACK frames for each user / STA in the block-ACK frame, overhead can be reduced by including separate information in the BA information field for each user / STA and overlapping information in the BA control field.

[0172] In this respect, when the information of the block-ACK frame is exposed to a third STA (e.g., an attacking STA), the ACK information confirming whether data is being sent and received between the transmitting and receiving STAs may be corrupted. As a result, attacks on block-ACK frames can lead to a reduction in data transmission and reception capabilities and result in wasted power / medium.

[0173] With this in mind, this disclosure proposes a security technique for ensuring the integrity of block-ACK frames transmitted and received between the transmitting STA and the receiving STA.

[0174] The values / names presented in this disclosure may be changed, and the scope of this disclosure is not limited thereto. Furthermore, the STA in this disclosure may include both non-AP STAs and AP STAs.

[0175] Furthermore, in the description of this disclosure, it is assumed that the STAs that transmit and receive block-ACK frames according to this disclosure are UHR STAs (and / or STAs after UHR STAs). As an example, when utilizing a block-ACK frame according to this disclosure, it can be assumed that all receiving STAs that receive a block-ACK frame transmitted by an AP as a transmitting STA are UHR STAs. In other words, if a block-ACK frame configured according to the proposed method of this disclosure is received by a STA before UHR STAs (e.g., EHT / HE STAs, etc.), an error may occur during the decoding of the corresponding block-ACK frame.

[0176] Furthermore, although this disclosure is described using security techniques for block-ACK frames in control frames as a representative example, the methods proposed in this disclosure can be extended and applied to other types of control frames besides block-ACK frames.

[0177] In this disclosure, performing integrity checks on block-ACK frames can be interpreted as extending and applying the BIP to block-ACK frames. In this respect, for the existing definition of BIP, a separate BIP-based protocol for control frames can be defined, or a new BIP-based protocol for integrity checks of control frames can be defined.

[0178] The following sections will describe, through specific examples, methods for supporting / performing integrity checks on block-ACK frames.

[0179] Implementation Method 1

[0180] This embodiment relates to a method for configuring block-ACK frames to support integrity verification. Specifically, in order to apply BIP to block-ACK frames, this disclosure proposes a configuration in which protection-related information is included in the block-ACK frame in sub-form, rather than a method for including the management MIC element (MME) at the end of the frame body when applying BIP to management frames.

[0181] Figure 10 An example of a protection information field / subfield format according to an embodiment of this disclosure is illustrated.

[0182] Reference Figure 10 The protection information (sub) field format, which includes information required for integrity verification, may include key ID information, PN-related information (e.g., IPN / BIPN information), and MIC information.

[0183] The corresponding protection information (sub) field format can be included in the block-ACK frame as a sub-form of the protection information sub-field.

[0184] The length of each piece of information included in the corresponding format is not limited to Figure 10 The lengths shown are as follows. For example, when indicating an IGTK or BIGTK key ID, the key ID field can be 2 octets long, but when indicating a GTK key ID, the key ID field can be 2 bits long. Furthermore, the MIC field can have lengths of 8 octets, 16 octets, 64 octets, etc. Additionally, the length can be changed by applying the MIC value to a separate function.

[0185] In this respect, if the key is not required for MIC generation, the key ID information may not be included in the corresponding protection information (sub) field.

[0186] Alternatively or alternatively, although by utilizing such Figure 10 The protection information (sub) field format shown is an example of additional information configured in the block-ACK frame to describe this disclosure, but this disclosure is not limited thereto. In other words, the key ID, PN-related information, and / or MIC can be included within the control frame, and security is applied to the control frame in a separate / distributed manner. As an example, the information for the key ID can be located before the protection information (sub) field consisting of the PN-related information and the MIC (e.g., within the BA control field or BA information field within the block-ACK frame).

[0187] The block-ACK frame used for integrity verification can be configured based on one or more of the formats described below.

[0188] Implementation Method 1-1

[0189] According to this disclosure, the protection information (sub) field may be located within the BA control field included in the block-ACK frame.

[0190] For example, by applying BIP to the BA control field within a block-ACK frame, the protection information (sub) field can be included in the last part of the corresponding field.

[0191] Figure 11 This illustrates an example of a block-ACK frame configuration that supports integrity verification according to an embodiment of this disclosure.

[0192] Reference Figure 11 ,exist Figure 10 The protection information (sub) field described in the document can be located in the last part of the public information field.

[0193] In this scenario, the sending STA can apply the BIP to the BA control field and add the protection information (sub) field to the end of the corresponding field to send a block-ACK frame. Based on this, the receiving STA receiving the corresponding block-ACK frame can perform integrity checks on the BA control field within the block-ACK frame based on the corresponding information.

[0194] In this respect, the scope of calculation for the MIC information (i.e., the MIC subfield) included in the corresponding protection information (subfield) can correspond to the BA control field that includes the protection information (subfield). In other words, the target of performing / applying integrity verification based on the protection information (subfield) can correspond to the BA control field to which the corresponding (subfield) belongs.

[0195] Implementation Methods 1-2

[0196] According to this disclosure, the protection information (sub) field may be located within the BA information field included in the block-ACK frame.

[0197] For example, BIP can be applied to each BA information field within a block-ACK frame to include a protection information (sub) field in the last part of the corresponding BA information field.

[0198] Figure 12 This represents another example of a block-ACK frame configuration that supports integrity verification according to an embodiment of this disclosure.

[0199] Specifically, Figure 12 (a) illustrates a case where the protection information (sub) field is included in the BA information field within a compressed block-ACK frame, and Figure 12 (b) illustrates a case where the protection information (sub) field is included in each AID TID information subfield of the BA information field within a multi-STA block-ACK frame. Here, each AID TID information subfield may include the AID TID information field, the block-ACK start sequence control field, and the block-ACK bitmap field.

[0200] Reference Figure 12 ,exist Figure 10 The protection information (sub) field described in the document can be located in the last part of each BA information field.

[0201] For example, the sending STA can apply BIP to each BA information field and add the protection information (sub) field to the end of the corresponding field to configure and send the block-ACK frame. Based on this, the receiving STA receiving the corresponding block-ACK frame can perform integrity checks on each BA information field.

[0202] In this scenario, the key ID and MIC values ​​configured in the protection information (sub) field of each AID TID information subfield within a multi-STA block-ACK frame can refer to the PTK of the STA corresponding to the respective AID, and the MIC value can be derived based on the corresponding key ID. As an example, the receiving STA can derive the MIC value of each AID TID information subfield using the key information included in the key ID of each AID TID information subfield, and perform integrity checks based on this.

[0203] Implementation methods 1-3

[0204] According to this disclosure, the protection information (sub) field can be located in a portion of the block-ACK frame other than the BA information field and the BA control field.

[0205] Figure 13 This represents another example of a block-ACK frame configuration that supports integrity verification according to an embodiment of this disclosure.

[0206] Reference Figure 13 The protection information field can be located before the FCS within the block ACK frame.

[0207] In this scenario, the transmitting STA can apply the BIP to the BA control field and / or BA information field, and add the protection information (sub) field to the last part to configure the value of each subfield. In other words, when the transmitting STA sends a block-ACK frame to the receiving STA, it can configure as follows: Figure 13 The block-ACK frame shown.

[0208] In this regard, MIC information can be configured by considering three scenarios. As an example, MIC information can be configured by deriving MIC values ​​from both the BA control field and the BA information field. As another example, MIC information can be configured by deriving MIC values ​​from the BA control field. As yet another example, MIC information can be configured by deriving MIC values ​​from the BA information field.

[0209] If the block-ACK frame is a multi-STA block-ACK frame type, configure the MIC value of all AIDTID information subfields within the BA information field, and in this case, the GTK used to protect the block-ACK frame or existing GTK, IGTK, or BIGTK can be utilized.

[0210] Furthermore, regarding block-ACK frames that support integrity verification according to this disclosure, the sending STA and receiving STA can share information about whether or not block-ACK frames are supported (BIP). This information can be shared through specific elements (e.g., extended RSN element (RSNXE)) in the discovery process (e.g., beacon frames, probe response frames, etc.) and / or (re)association process (e.g., (re)association request frames, (re)association response frames, etc.).

[0211] In this regard, whether BIP application to block-ACK frames is supported can be shared by utilizing reserved bits within existing elements (e.g., RSNXE) or by defining new (sub)fields within new elements. For example, a new 1-bit protected block-ACK support (sub)field (protected BlockAck support (sub)field) can be defined, and it can be defined such that a value of 1 means / indicates support for applying BIP to block-ACK frames, while a value of 0 means / indicates that BIP application to block-ACK frames is not supported.

[0212] If both the transmitting and receiving STAs support BIP and the application of BIP to block-ACK frames, then both STAs can perform the application of BIP to block-ACK frames. Conversely, if either the transmitting or receiving STA supports BIP but not the application of BIP to block-ACK frames, then neither STA needs to perform the application of BIP to block-ACK frames. Additionally, when a block-ACK frame is applied to BIP, the cipher suite of the management frame (e.g., BIP-GMAC-128, BIP-GMAC-256, or BIP-CMAC-256, etc.) negotiated by the transmitting and receiving STAs during the negotiation process can be used in the same manner. Alternatively, to apply a block-ACK frame to BIP, the transmitting and receiving STAs can negotiate additional / separate cipher suites for the corresponding block-ACK frame.

[0213] Additionally or alternatively, the application of whether to support BIP to block-ACK frames and the use of the formats proposed in this disclosure can be shared between the transmitting STA and the receiving STA. Figures 11 to 13Which of the formats shown in the diagram is used to configure the information in the protection information (sub) field? At this point, to share the corresponding information, reserved bits within existing elements (e.g., RSNXE) and / or reserved bits within the BA control field and / or new (sub) fields within new elements (e.g., protected block-ACK mode (sub) field) (protected BlockAck mode (sub) field) can also be defined. The corresponding (sub) fields can be included in the beacon frame by the sending STA not only during the (re)association process but also during data transmission and reception, or by the receiving STA in the data frame.

[0214] For example, when the value of the protected block-ACK mode (sub) field is set to 0, it can mean / indicate that the block-ACK frame is configured in at least one way and that BIP is not applied to the corresponding block-ACK frame. Conversely, when the value of the protected block-ACK mode (sub) field is set to 1 or greater, it can mean / indicate that BIP is applied to the block-ACK frame.

[0215] As a specific example, when the corresponding protected block-ACK mode (sub) field can have a value greater than or equal to 1, the meaning of the value of the corresponding protected block-ACK mode (sub) field can be defined as shown in Table 4 below. Table 4 is illustrative, and at least one of the values ​​described in Table 4 can be applied / defined, and specific values ​​can be set / defined differently from the corresponding examples.

[0216] [Table 4]

[0217] Referring to Table 4, the protected block-ACK mode (sub) field can indicate the method for calculating the MIC value and the configuration / format of the block-ACK frame including the protected information (sub) field according to this disclosure.

[0218] However, the scope of this disclosure is not limited thereto, and the protected block-ACK mode (sub) field can indicate only the configuration / format of the block-ACK frame including the protected information (sub) field according to this disclosure, and the method used to calculate the MIC value can be indicated separately by another (sub) field. For example, the MIC calculation range (sub) field can be defined, and the values ​​of the corresponding (sub) fields can be defined as shown in Table 5.

[0219] [Table 5]

[0220] In other words, the receiving STA can identify / confirm the location of the protected information (sub) field included in the received block-ACK frame by using the protected block-ACK mode (sub) field. Furthermore, based on this, the corresponding receiving STA can calculate the MIC value using the value indicated by the MIC calculation range (sub) field, and thereby perform integrity checks on the block-ACK frame.

[0221] Implementation Method 2

[0222] This embodiment relates to a method for generating a MIC for BIP transmission / reception in relation to the application of the aforementioned BIP to block-ACK frame.

[0223] For block-ACK frames, the type of the transmitted and received block-ACK frame can be indicated by the value of the BA type subfield within the BA control field. Based on the indicated value, the receiving STA can confirm whether the corresponding block-ACK frame is a single-addressed frame or a group-addressed frame.

[0224] In this respect, when BIP is applied to block-ACK frames, the key used to configure the MIC value can be used differently depending on whether the frame is a individually addressed frame or a group-addressed frame.

[0225] For example, in the case of a separately addressed data frame, the MIC value can be calculated using a TK based on the PTK generated identically between the transmitting STA and the receiving STA. On the other hand, in the case of a group-addressed data frame, the MIC value can be calculated using a TK based on the GTK shared by the transmitting STA and the receiving STA.

[0226] In the case of conventional BIPs (e.g., BIPs applied to data frames / management frames), the use of IGTK or BIGTK-based BIPs is possible. In contrast, in this disclosure, it is assumed that the use of PTK / GTK-based BIPs is possible.

[0227] The key usage method for calculating and checking the MIC value of individually addressed block-ACK frames and / or group-addressed block-ACK frames will be described in detail below.

[0228] First, for a separately addressed block-ACK frame, the MIC value can be calculated / verified as follows.

[0229] The sending STA and receiving STA can calculate the MIC value by using a TK based on the PTK generated identically during the 4-way handshake process. For example, regarding the application of BIP to block-ACK frames, the sending STA and receiving STA can identically utilize the PTK generated during the 4-way handshake process for the protection of data frames, or they can mutually identically generate / negotiate / share a (new) TK (e.g., a new PTK / GTK) using the protection of the corresponding block-ACK frame during the 4-way handshake process.

[0230] Alternatively, the sending STA and receiving STA can calculate the MIC value using a TK based on a new PTK used for separately addressed block-ACK frames shared during the four-way handshake process. For example, the corresponding new TK can be called block-ACKPTK (block-ACK PTK, BAPTK), and the sending STA can generate and share different BAPTKs for each receiving STA. In other words, receiving STA 1 and receiving STA 2 can share different BAPTKs. Furthermore, for example, when deriving the MIC using a new TK (e.g., BAPTK, BAGTK) for block-ACK frames, the sending STA can generate a new TK and share it with each receiving STA. In other words, receiving STA 1 and receiving STA 2 can share the same new TK. In this case, information about the corresponding new TK, information related to the cryptography that can use the corresponding new TK, etc., can be shared through a new key data element (KDE) for the new TK generated and shared by the sending STA (e.g., BAPTK / BAGTK KDE).

[0231] When a key (e.g., a new TK) is available to protect the block-ACK frame, the receiving STA can use the corresponding key to perform MIC verification on the received block-ACK frame. At this point, the corresponding key can be generated and / or shared by the sending STA and / or the receiving STA. Otherwise, the receiving STA can perform MIC verification on the block-ACK frame based on a key (e.g., a PTK) previously generated by the sending STA for integrity verification / encryption / decryption of unicast data frames.

[0232] Next, for group-addressed block-ACK frames, the MIC value can be calculated / checked as follows.

[0233] The sending STA can generate an IGTK or BIGTK during the four-way handshake process and share the IGTK or BIGTK with the receiving STA. The sending STA and the receiving STA can calculate the MIC value by using the TK based on the corresponding IGTK or the corresponding BIGTK.

[0234] Alternatively, the sending STA may generate a GTK during the four-way handshake process and share the GTK with the receiving STA, and the sending STA and the receiving STA may calculate the MIC value by using a TK based on the corresponding GTK.

[0235] Alternatively, the sending STA can generate a new GTK for the group-addressed block-ACK frame during the four-way handshake process and share this new GTK with the receiving STA. The sending and receiving STAs can then calculate the MIC value using a TK based on the corresponding new GTK. Here, the new GTK can be referred to as the block-ACK broadcast GTK (BAGTK), and the sending STA can share the same BAGTK value with the receiving STA. In other words, the AP can generate the same BAGTK and share it with the STAs associated with it. Furthermore, the sending and receiving STAs can share information about the BAGTK and related cipher suites that can use the corresponding BAGTK through a new KDE (e.g., TBGTK KDE).

[0236] If the receiving STA receives a key (e.g., BAGTK) from the sending STA for protecting the block-ACK frame, it can perform MIC verification on the block-ACK frame based on the corresponding key. Otherwise, the receiving STA can perform MIC verification on the block-ACK frame based on a key (e.g., GTK, IGTK, or BIGTK) of the broadcast frame that has been shared with the sending STA in advance.

[0237] Implementation Method 3

[0238] This embodiment relates to a specific method for performing block-ACK frame protection based on the block-ACK frame configuration proposed in this disclosure.

[0239] First, when the block-ACK frame is a group-addressed block-ACK frame, the block-ACK frame configuration proposed in this disclosure can be used as shown in the example below.

[0240] For example, for the block-ACK frame configuration described in implementation 1-1 (for example, refer to...) Figure 11 The sending STA and / or receiving STA can derive the MIC value via BIP using the aforementioned GTK, IGTK, or BIGTK or a new TK (e.g., BAGTK) for the BA control field. Additionally, for the block-ACK frame configuration described in embodiments 1-2 (e.g., refer to...), Figure 12In (a) and (b)), the sending STA and / or receiving STA can derive the MIC value via BIP using the aforementioned PTK or new TK (e.g., BAPTK) for the BA information field. In this case, for Figure 12 (b) In order to derive the MIC value for each AID TID information subfield within the BA information field, the sending STA and / or receiving STA may use the PTK or a new TK (e.g., BAPTK) of the STA corresponding to the AID of the respective per AIDTID information subfield. Alternatively, as Figure 12 As shown in (a), for compressed block-ACK frames that do not include a subfield containing AID (e.g., AID11 subfield), the PTK or new TK (e.g., BAPTK) of the STA corresponding to the MAC address (e.g., RA) of the sending STA can be used.

[0241] As another example, for the block-ACK frame configuration described in embodiments 1-3 (e.g., refer to...), Figure 13 The sending STA and / or receiving STA can derive the MIC value via BIP using the aforementioned GTK, IGTK, or BIGTK or a new TK (e.g., BAGTK) for the BA control field and / or BA information field.

[0242] Next, when the block-ACK frame is a separately addressed block-ACK frame, the block-ACK frame configuration proposed in this disclosure can be used as shown in the following example.

[0243] For example, for the block-ACK frame configuration described in implementation 1-1 (see, for example, see...) Figure 11 The sending STA and / or receiving STA can derive the MIC value via BIP using the aforementioned PTK or new TK (e.g., BAPTK) for the BA control field.

[0244] As another example, for the block-ACK frame configuration described in implementations 1-2 (e.g., refer to...), Figure 12 In (a) and (b)), the sending STA and / or receiving STA can derive the MIC value via BIP using the aforementioned PTK or new TK (e.g., BAPTK) for the BA information field. In this case, for Figure 12 (b) In order to derive the MIC value for each AID TID information subfield within the BA information field, the sending STA and / or receiving STA may use the PTK or a new TK (e.g., BAPTK) of the STA corresponding to the AID of the respective per-AID TID information subfield. Alternatively, as Figure 12As shown in (a), for compressed block-ACK frames that do not include a subfield containing AID (e.g., AID11 subfield), the PTK or new TK (e.g., BAPTK) of the STA corresponding to the MAC address of the sending STA (e.g., the receiver address (RA)) can be used.

[0245] As another example, for the block-ACK frame configuration described in embodiments 1-3 (e.g., refer to...), Figure 13 The sending STA and / or receiving STA can derive the MIC value via BIP using the aforementioned PTK or new TK (e.g., BAPTK) for the BA control field and / or BA information field. In this case, to derive the MIC value for the BA control field and / or BA information field, the PTK or new TK (e.g., BAPTK) of the STA corresponding to the receiver address (RA) of the corresponding block-ACK frame can be used.

[0246] Based on the method proposed in this disclosure, protection for block-ACK frames can be performed as follows.

[0247] For the exemplary cases described below, it is assumed that the sending STA and the receiving STA support the use of block-ACK frames on the BIP through the protected block-ACK support (sub) field, and / or share a method for configuring the protection information (sub) field within the block-ACK frame through the protected block-ACK mode (sub) field.

[0248] The receiving STA can configure Additional Authentication Data (AAD) for block-ACK frames based on information from the MAC header of the MPDU received from the sending STA (e.g., frame control field, duration field, RA field, TA field, etc.). Subsequently, the receiving STA can calculate the MIC value based on the MPDU using the corresponding AAD. In this case, the receiving STA can derive the MIC value by performing the same process as the sending STA in calculating the MIC value based on the corresponding MPDU.

[0249] Subsequently, the receiving STA can compare the derived MIC value with the MIC value sent by the sending STA (e.g., MIC information included in the protection information (sub) field). If the two MIC values ​​are the same, the receiving STA can follow the information in the obtained MPDU. Conversely, if the two MIC values ​​are different, the receiving STA can identify that at least one piece of information in the obtained MPDU has been modified by a third STA (e.g., an attacking STA) or has been corrupted during transmission / reception, and can discard that information.

[0250] According to embodiments of this disclosure, the operation of a STA that supports / performs protection against block-ACK frames can be as follows: Figure 14 and 15 As shown.

[0251] Figure 14 An example is provided of the operation of the sending STA that supports integrity verification of block ACK frames according to this disclosure.

[0252] Reference Figure 14 The transmitting STA can share information with the receiving STA regarding whether protection (e.g., integrity check) for block-ACK frames is supported (S1410).

[0253] In this scenario, when both the sending STA and the receiving STA apply security to the block-ACK frame, the sending STA can generate and share a key (e.g., PTK / GTK / BAPTK / BAGTK) for integrity verification of the block-ACK frame S1420. At this point, the sending STA and the receiving STA can generate / negotiate / share the same key information through a key generation process, or the key information generated by the sending STA can be delivered to the receiving STA.

[0254] Based on the corresponding key, the transmitting STA can apply the BIP to the configured block-ACK frame S1430. At this point, the transmitting STA can derive the MIC value for the block-ACK frame using a key previously shared with the receiving STA.

[0255] The sending STA can send a block-ACK frame S1440 that includes the result value / information for the BIP application. For example, the sending STA can send a block-ACK frame to the receiving STA that includes the derived MIC value and the ID value of the key used to derive the corresponding MIC value.

[0256] Regarding the above process, the sending STA can share / negotiate with the receiving STA in advance which format to use to configure the information related to integrity verification in the block-ACK frame being sent, or the corresponding information can be sent by including it in the block-ACK frame.

[0257] Figure 15 The operation of a receiving STA supporting integrity verification for block-ACK frames according to this disclosure is illustrated.

[0258] Reference Figure 15 The receiving STA can share information S1510 with the sending STA regarding whether protection (e.g., integrity check) for block-ACK frames is supported.

[0259] In this case, when the receiving STA shares the key for integrity verification of the block-ACK frame with the sending STA, the receiving STA can assume that the protection method is applied to the block-ACK frame S1520 sent by the sending STA.

[0260] In this respect, the sending STA and the receiving STA can generate / negotiate / share the same key information (e.g., PTK / GTK / BAPTK / BAGTK, etc.) through a key generation process, or the key information generated by the sending STA can be delivered to the receiving STA.

[0261] For example, the receiving STA can receive a block-ACK frame sent from the transmitting STA and identify that it is applied to BIP based on information related to the method of configuring information for integrity verification within the block-ACK frame and / or a pre-shared key.

[0262] Based on this, when receiving a block-ACK frame, the receiving STA can deduce the MIC value by using the block-ACK frame and the previously shared / generated / negotiated key (e.g., PTK / GTK / BAPTK / BAGTK, etc.).

[0263] Subsequently, the receiving STA can perform integrity check S1540 by comparing the derived MIC value with the MIC value sent by the transmitting STA (i.e., the MIC value based on the MIC information included in the block-ACK frame).

[0264] In the following text, Figure 16 and Figure 17 An example is illustrated of the operations performed by the STA according to the method proposed in this disclosure. Figure 16 and Figure 17 In this context, the second STA may correspond to the transmitting STA (e.g., AP), and the first STA may correspond to the receiving STA (e.g., a non-AP STA associated with the AP).

[0265] Figure 16 This is a diagram used to illustrate an example of a method performed by a first STA according to this disclosure.

[0266] Reference Figure 16 The first STA can confirm the key information S1610 related to the protection of the block-ACK frame.

[0267] Here, protection for block-ACK frames can be based on integrity checks that utilize the BIP described above in this disclosure.

[0268] In this regard, the first STA can negotiate / share / generate key information with the second STA in advance through a four-way handshake process (related to the corresponding block-ACK frame). Alternatively, the first STA can receive key information generated by the second STA.

[0269] For example, when a block-ACK frame corresponds to a single addressing frame, the key information may include a key (e.g., a temporary key) based on a pairwise transient key (PTK) (e.g., PTK / BAPTK, etc.) for the first STA and the second STA. On the other hand, when a block-ACK frame corresponds to a group addressing frame, the key information may include a key (e.g., a temporary key) based on a group temporary key (GTK) (e.g., GTK / BAGTK, etc.) for the first STA and the second STA.

[0270] The first STA can receive the block-ACK frame S1620 with the above protection applied from the second STA.

[0271] Subsequently, the first STA can perform integrity verification S1630 on the block ACK frame based on the aforementioned key information.

[0272] In this respect, the block-ACK frame may include protection-related information for integrity verification. In this case, integrity verification can be performed based on a comparison between a first Message Integrity Code (MIC) value calculated using corresponding key information for at least one field belonging to the frame body within the block-ACK frame and a second MIC value included in the protection-related information. As an example, the corresponding protection-related information may include at least one of a first field related to the key information, a second field related to the block number of the block-ACK frame, or a third field related to the second MIC value.

[0273] According to embodiments of this disclosure, the aforementioned at least one field may correspond to at least one of the block-ACK control field or the block-ACK information field. The aforementioned protection-related information may be included within the block-ACK control field, may be included within the block-ACK information field, or may be included in a portion other than the block-ACK control field and the block-ACK information field. If the block-ACK frame includes ACK information for multiple STAs (e.g., a multi-STA block-ACK frame) and the protection-related information is included within the block-ACK information field, then the protection-related information may be included in each AIDTID information subfield within the block-ACK information field.

[0274] In this respect, information regarding locations, including protection-related information, can be sent and received between the first STA and the second STA. As an example, the corresponding information can be included in the block-ACK control field.

[0275] When protection-related information is included in the block-ACK control field, the range of fields applied to the calculation of the first MIC value can correspond to the block-ACK control field. Furthermore, when protection-related information is included in the block-ACK information field, the range of fields applied to the calculation of the first MIC value can correspond to the block-ACK information field. Additionally, when protection-related information is included in a portion other than the block-ACK control field and the block-ACK information field, information representing the range of fields applied to the calculation of the first MIC value can be sent and received. As an example, the field range can be one of a first range including the block-ACK control field, a second range including the block-ACK information field, or a third range including both the block-ACK control field and the block-ACK information field.

[0276] Additionally, information indicating whether protection against block-ACK frames is supported can be sent and received between the first STA and the second STA. As an example, this information can be sent and received via at least one of a beacon frame, probe request frame, probe response frame, association request frame, association response frame, or block-ACK frame.

[0277] exist Figure 16 The methods described in the examples can be derived from... Figure 1 The first device 100 is used to perform this. In other words, Figure 16 The first STA can be implemented as a first device 100. For example, Figure 1 One or more processors 102 of the first device 100 can be configured to verify key information related to protection for the block-ACK frame, receive a protected block-ACK frame from the second STA, and perform integrity checks on the block-ACK frame based on the key information. In this respect, the first STA can identify whether protection / security is applied to the received block-ACK frame based on information previously shared / negotiated with the second STA, and can perform integrity checks by utilizing BIP.

[0278] Furthermore, when executed by one or more processors 102, one or more memories 104 of the first device 100 may store information for execution in... Figure 16 The instructions for the methods described in the examples or examples described below.

[0279] Figure 17 This is a diagram illustrating an example of a method performed by a second STA according to this disclosure.

[0280] Reference Figure 17 The second STA can confirm the key information S1710 related to the protection of the block-ACK frame.

[0281] Here, protection for block-ACK frames can be based on integrity verification using the BIP described above in this disclosure.

[0282] The second STA can configure a block-ACK frame S1720, which includes protection-related information for integrity verification of the block-ACK frame, based on the corresponding key information.

[0283] The second STA can send a block-ACK frame S1730 with the above protection applied to the first STA.

[0284] In this respect, due to the specific details used to protect block-ACK frames, key information, configuration and / or location of protection-related information, methods used to configure / indicate the corresponding configuration and / or location, field ranges used to calculate MIC values, and whether protection for block-ACK frames is supported, etc., Figure 16 The descriptions are the same / similar to those in the text, so detailed descriptions of them have been omitted.

[0285] Figure 17 The method described in the example can be derived from Figure 1 The second device 200 performs this action. In other words, Figure 17 The second STA can be implemented as a second device 200. For example, Figure 1 One or more processors 202 of the second device 200 can be configured to verify key information related to protection for the block-ACK frame, configure a block-ACK frame including protection-related information based on the key information, and send the protected block-ACK frame to the first STA. In this respect, prior to configuring the PPDU, the second STA can perform operations including information related to integrity verification (e.g., the derived MIC value, key information for deriving the MIC value, the block number (PN) for the corresponding block-ACK frame, etc.) by applying the BIP to the block-ACK frame based on information shared with the first STA.

[0286] Furthermore, when executed by one or more processors 202, one or more memories 204 of the second device 200 may store information for execution in... Figure 17 The instructions for the methods described in the examples or examples described below.

[0287] The above embodiments combine the elements and features of this disclosure in a predetermined form. Unless otherwise expressly stated, each element or feature should be considered optional. Each element or feature may be implemented without being combined with other elements or features. Furthermore, embodiments of this disclosure may include combinations of some elements and / or features. The order of operations described in embodiments of this disclosure may be changed. Some elements or features of one embodiment may be included in other embodiments, or may be replaced by corresponding elements or features of other embodiments. Obviously, embodiments may include claims that are not explicitly referenced in the claims, or may be included as new claims after the application has been amended.

[0288] It will be apparent to those skilled in the art that this disclosure may be implemented in other specific forms without departing from its essential characteristics. Therefore, the above detailed description should not be construed as restrictive in every respect, but rather as illustrative. The scope of this disclosure should be determined by a reasonable interpretation of the appended claims, and all variations within the equivalent scope of this disclosure are included within its scope.

[0289] The scope of this disclosure includes software or machine-executable commands (e.g., operating systems, applications, firmware, programs, etc.) that operate in a device or computer according to methods of various embodiments, as well as non-transitory computer-readable media that cause software or commands to be stored and executable in a device or computer. Commands that can be used to program a processing system to perform the features described in this disclosure can be stored in a storage medium or a computer-readable storage medium, and the features described in this disclosure can be implemented by using a computer program product including such a storage medium. The storage medium may include, but is not limited to, high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid-state storage devices, and may include non-volatile memory, such as one or more disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid-state storage devices. The memory may optionally include one or more storage devices located remotely from the processor. The memory, or alternatively, the non-volatile memory devices in the memory include non-transitory computer-readable storage media. The features described in this disclosure can be stored in any machine-readable medium to control the hardware of a processing system and can be integrated into software and / or firmware that allows the processing system to interact with other mechanisms using the results of embodiments of this disclosure. Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments / containers.

[0290] Industrial applicability

[0291] The method presented in this disclosure is primarily described based on examples applied to IEEE 802.11-based systems, but can be applied to various WLAN or wireless communication systems other than IEEE 802.11-based systems.

Claims

1. A method performed by a first STA in a wireless local area network (WLAN) system, the method comprising: Confirm the key information related to the protection of the block acknowledgment (block-ACK) frame; Receive the block-ACK frame with the protection applied from the second STA; as well as Based on the key information, an integrity check is performed on the block-ACK frame. The block-ACK frame includes protection-related information for the integrity verification, and The integrity check is performed by comparing a first message integrity code (MIC) value calculated using key information for at least one field of the frame body belonging to the block-ACK frame with a second MIC value included in the protection-related information.

2. The method according to claim 1, wherein, The at least one field corresponds to at least one of the block-ACK control field or the block-ACK information field, and The protection-related information is included in the following fields: The block-ACK control field, The block-ACK information field, or The part other than the block-ACK control field and the block-ACK information field.

3. The method according to claim 2, wherein, Between the first STA and the second STA, information regarding the location, including the protection-related information, is transmitted and received.

4. The method according to claim 3, wherein, The information is included in the block-ACK control field.

5. The method according to claim 2, wherein, The block-ACK frame includes ACK information for multiple STAs, and the protection-related information is included in the block-ACK information field. The protection-related information is included in each AID TID information subfield within the block-ACK information field.

6. The method according to claim 2, wherein, Based on the fact that the protection-related information is included in the block-ACK control field, the field range applied to the calculation of the first MIC value corresponds to the block-ACK control field, and Wherein, the protection-related information is included in the block-ACK information field, and the field range applied to the calculation of the first MIC value corresponds to the block-ACK information field.

7. The method according to claim 2, wherein, Based on the fact that the protection-related information is included in the portion other than the block-ACK control field and the block-ACK information field, information representing the range of fields applied to the calculation of the first MIC value is sent and received.

8. The method according to claim 7, wherein, The field range is one of a first range including the block-ACK control field, a second range including the block-ACK information field, or a third range including both the block-ACK control field and the block-ACK information field.

9. The method according to claim 1, wherein, The protection-related information includes at least one of a first field related to the key information, a second field related to the block number of the block-ACK frame, or a third field related to the second MIC value.

10. The method according to claim 1, wherein, Between the first STA and the second STA, information indicating whether the protection for the block-ACK frame is supported is transmitted and received.

11. The method according to claim 10, wherein, The information indicating whether the protection for the block-ACK frame is supported is sent and received via at least one of a beacon frame, probe request frame, probe response frame, association request frame, association response frame, or the block-ACK frame.

12. The method according to claim 1, wherein, Since the block-ACK frame corresponds to a separate addressing frame, the key information is based on the pairwise transient key PTK for the first STA and the second STA, and Wherein, the block-ACK frame corresponds to a group addressing frame, and the key information is based on the group temporary key GTK for the first STA and the second STA.

13. The method according to claim 1, wherein, The protection for the block-ACK frame is based on integrity verification using the Broadcast / Multicast Integrity Protocol (BIP).

14. The method according to claim 1, wherein, The second STA is an access point (AP), and The first STA is a non-AP STA associated with the AP.

15. A first station (STA) device in a wireless local area network (WLAN) system, the device comprising: One or more transceivers; as well as One or more processors, said one or more processors being connected to said one or more transceivers, The one or more processors are configured to: Confirm the key information related to the protection of the block acknowledgment (block-ACK) frame; Receive the block-ACK frame with the protection applied from the second STA; and Based on the key information, an integrity check is performed on the block-ACK frame. The block-ACK frame includes protection-related information for the integrity verification, and The integrity check is performed by comparing a first message integrity code (MIC) value calculated using key information for at least one field of the frame body belonging to the block-ACK frame with a second MIC value included in the protection-related information.

16. A method performed by a second station (STA) in a wireless local area network (WLAN) system, the method comprising: Confirm the key information related to the protection of the block acknowledgment (block-ACK) frame; Based on the key information, configure a block-ACK frame that includes protection-related information for integrity verification of the block-ACK frame; as well as Send a block-ACK frame with the protection applied to the first STA.

17. A second STA device in a wireless local area network (WLAN) system, the device comprising: One or more transceivers; as well as One or more processors, said one or more processors being connected to said one or more transceivers, The one or more processors are configured to: Confirm the key information related to the protection of the block acknowledgment (block-ACK) frame; Based on the key information, configure a block-ACK frame that includes protection-related information for integrity verification of the block-ACK frame; and Send a block-ACK frame with the protection applied to the first STA.

18. A processing apparatus configured as a control station STA in a wireless local area network (WLAN) system, the processing apparatus comprising: One or more processors; as well as One or more computer memories, operatively connected to one or more processors, and storing instructions that, based on execution by one or more processors, perform the method according to any one of claims 1 to 14.

19. One or more non-transitory computer-readable media, said one or more non-transitory computer-readable media for storing one or more instructions, wherein: The one or more instructions, executed by one or more processors, control the device to perform the method according to any one of claims 1 to 14 in a wireless local area network system.