Communication device, control method thereof, and program
The communication device enhances security in Multi-Link configurations by establishing links only with APs of sufficient strength, ensuring secure data communication.
Patent Information
- Application Number
- JP2023217086
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-07-03
AI Technical Summary
In Multi-Link communication configurations where multiple links with an AP are established, the presence of a link with low security strength increases vulnerability.
A communication device that establishes links only with affiliated APs having a security strength exceeding a predetermined threshold, based on information received in frames indicating support for Multi-Link communication.
Ensures data communication with a security strength equal to or higher than a certain level by selectively linking with APs of sufficient security, thereby reducing vulnerability.
Smart Images

Figure 2025100013000001_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a communication device, a control method thereof, and a program.
Background Art
[0002] The development of communication technologies such as wireless LAN (Local Area Network) is underway. As the main communication standards for wireless LAN, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard series is known. The IEEE 802.11 standard series includes standards such as IEEE 802.11a / b / g / n / ac / ax. For example, in IEEE 802.11ax, technologies for improving the communication speed under congested conditions in addition to a high peak throughput of up to 9.6 gigabits per second (Gbps) using OFDMA (Orthogonal Frequency-Division Multiple Access) have been standardized (see, for example, Patent Document 1). Note that OFDMA is an abbreviation for Orthogonal frequency-division multiple access.
[0003] In addition, a task group for formulating IEEE 802.11be, a successor standard aiming for further throughput improvement, frequency utilization efficiency improvement, and communication latency improvement, has been established. In IEEE 802.11be, for example, Multi-Link communication in which one AP (Access Point) establishes a plurality of links with one STA (Station) via different frequency channels and communicates in parallel is being studied.
[0004] In the conventional IEEE 802.11 standard series, the STA connected to the AP and performed data communication with the AP over a single link. On the other hand, in IEEE 802.11be, the STA can establish two or more links with the AP and perform data communication simultaneously over the established two or more links, thereby achieving throughput improvement. Also, in IEEE 802.11be, support for the 6 GHz band is also being considered to expand the available frequency bands. Note that two or more links may be selected from two or more of the same frequency bands (any of the sub-GHz band, 2.4 GHz band, 3.6 GHz band, 4.9 and 5 GHz bands, 60 GHz band, and 6 GHz band), or may be selected from different frequency bands respectively.
Prior Art Documents
Patent Documents
[0005]
Patent Document 1
Summary of the Invention
Problems to be Solved by the Invention
[0006] In a configuration where two or more links can be established with the AP in this way, if a link with low security strength is included among the established links, there is a concern that the vulnerability will increase due to this link.
[0007] An object of the present invention is to provide a communication device, a control method thereof, and a program that can realize data communication with a security strength equal to or higher than a certain level.
Means for Solving the Problems
[0008] In order to achieve the above object, a communication device according to the present invention is a communication device that performs wireless communication with a wireless communication device compliant with a standard of the IEEE802.11 series and corresponding to Multi-Link communication, the communication device including means for receiving a signal including information necessary for a communication connection for performing the wireless communication from the wireless communication device, and means for establishing a link with the wireless communication device based on the signal. When the signal includes predetermined information indicating that the wireless communication device supports the Multi-Link communication, the means for establishing the link establishes a link with a communication means among a plurality of communication means included in the wireless communication device and operating on different frequency channels, the communication means having a security strength satisfying a predetermined condition.
Advantages of the Invention
[0009] According to the present invention, data communication with a security strength equal to or higher than a certain level can be realized.
Brief Description of the Drawings
[0010]
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
Embodiments for Carrying Out the Invention
[0011] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings.
[0012] FIG. 1 is a configuration diagram showing an example of a communication system including an STA102 as a communication device according to the present embodiment. This communication system is composed of an STA102 and an AP (access point) 101 as a wireless communication device. In FIG. 1, a circle 100 indicates a network formed by the AP101. For example, when the STA102 exists within the area indicated by the circle 100, the STA102 can receive frames (signals) such as Beacons and Probe Responses transmitted from the AP101.
[0013] The STA102 participates in the network configured by the AP101, and the AP101 and the STA102 can perform wireless communication compliant with the IEEE802.11be (EHT) standard. EHT is an abbreviation for Extremely High Throughput. Note that EHT may also be interpreted as an abbreviation for Extreme High Throughput. Both the AP101 and the STA102 can communicate in a plurality of frequency bands such as the 2.4 GHz band, 5 GHz band, and 6 GHz band. Note that the frequency bands in which the AP101 and the STA102 can communicate are not limited to these, and for example, a configuration that can communicate in other frequency bands such as the 60 GHz band may also be possible. Also, both the AP101 and the STA102 can communicate using bandwidths of 20 GHz, 40 MHz, 80 MHz, 160 MHz, and 320 MHz. Note that the bandwidths used by the AP101 and the STA102 are not limited to these, and for example, other bandwidths such as 240 MHz and 4 MHz may also be used.
[0014] In addition, in this embodiment, in addition to the IEEE 802.11be standard, AP101 and STA102 may also support legacy standards that are older than the IEEE 802.11be standard. Specifically, AP101 and STA102 may support at least one of the IEEE 802.11a / b / g / n / ac / ax standards. Further, in addition to the IEEE 802.11 series standards such as IEEE 802.11a / b / g / n / ac / ax / be, AP101 and STA102 may also support other communication standards such as Bluetooth (registered trademark), NFC, UWB, ZigBee, MBOA, etc. Note that UWB is the abbreviation of Ultra Wide Band, and MBOA is the abbreviation of Multi Band OFDM Alliance. Also, NFC is the abbreviation of Near Field Communication. UWB includes wireless USB, wireless 1394, WiNET, etc. In addition, it may support the communication standards of wired communication such as wired LAN. Specific examples of AP101 include, but are not limited to, wireless LAN routers and personal computers (PCs), etc. Also, AP101 may be an information processing device such as a wireless chip that can perform wireless communication compliant with the IEEE 802.11be standard. Specific examples of STA102 include, but are not limited to, cameras, tablets, smartphones, PCs, mobile phones, video cameras, headsets, etc. Also, STA102 may be an information processing device such as a wireless chip that can perform wireless communication compliant with the IEEE 802.11be standard.
[0015] AP101 and STA102 perform Multi-Link communication that establishes a link via a plurality of frequency channels and communicates. In the IEEE802.11 series of standards, the bandwidth of each frequency channel is defined as 20 MHz. Here, a frequency channel is a frequency channel defined in the IEEE802.11 series of standards. In the IEEE802.11 series of standards, a plurality of frequency channels are defined in each frequency band of the 2.4 GHz band, 5 GHz band, 6 GHz band, and 60 GHz band. Note that by bonding with an adjacent frequency channel, a bandwidth of 40 MHz or more may be used in one frequency channel. For example, AP101 can establish and communicate a link 103 with STA102 via a first frequency channel in the 5 GHz band. STA102 can, in parallel, establish and communicate a link 104 with AP101 via a second frequency channel in the 6 GHz band. In this case, STA102 performs Multi-Link communication that maintains the link 104 via the second frequency channel in parallel with the link 103 via the first frequency channel.
[0016] In Multi-Link communication, a plurality of links with different frequency bands may be established between communication devices. For example, in addition to link 103 in the 5 GHz band and link 104 in the 6 GHz band, AP101 and STA102 may also establish a third link in the 2.4 GHz band. Also, in Multi-Link communication, a link may be established between communication devices via a plurality of different frequency channels included in the same frequency band. For example, AP101 and STA102 may use channel 15 in the 6 GHz band as the first link and, in addition, use channel 207 in the 6 GHz band as the second link. Note that links with the same frequency band and different links may be mixed. For example, in addition to link 103 on channel 36 in the 5 GHz band, AP101 and STA102 may establish a link on channel 149 in the 5 GHz band and a link on channel 15 in the 6 GHz band. In this way, by establishing a plurality of links with different frequency channels between STA102 and AP101, even if one of the established links is congested, communication can be carried out using other links. As a result, STA102 can prevent a decrease in throughput and communication delay in communication with AP101.
[0017] Figure 2 is a sequence diagram when STA102 and AP101 in Figure 1 perform Multi-Link communication. Note that the AP and STA corresponding to Multi-Link communication are called AP MLD and STA MLD respectively. In Figure 2, AP101 is described as AP MLD101, and STA102 is described as STA MLD102. Note that MLD is the abbreviation of Multi-Link Device. Also, the APs associated with AP MLD and operating on different frequency channels are called affiliated APs, and the STAs associated with STA MLD and operating on different frequency channels are called affiliated STAs. Figure 2 shows affiliated AP1 and affiliated STA1 operating in the 2.4 GHz band. Also, Figure 2 shows affiliated AP2 and affiliated STA2 operating in the 5 GHz band. Furthermore, Figure 2 shows affiliated AP3 and affiliated STA3 operating in the 6 GHz band.
[0018] AP101 adds a Basic Multi-Link element indicating that the device supports Multi-Link communication to frames such as Beacon and Probe Response. Affiliated APs 1 to 3 transmit this frame on their corresponding frequency channels.
[0019] Based on whether the received frame contains a Basic Multi-Link element, STA102 determines whether the source of this frame supports Multi-Link communication.
[0020] For example, when the source of this frame is affiliated AP1 belonging to AP101, this frame contains an RNR (Reduced Neighbor Report) element as shown in FIG. 3. STA102 acquires information on the frequency channels of other affiliated APs 2 and 3 belonging to the same AP101 as the affiliated AP1 that transmitted this frame from the RNR element. Note that whether the received frame is a frame transmitted from affiliated APs 2 and 3 belonging to the same AP101 is determined based on the MLD ID included in the RNR element. The MLD ID is identification information uniquely assigned to AP101. STA102 switches to the frequency channels indicated by the acquired information and receives frames such as Beacons and Probe ResponsAe transmitted from affiliated APs 2 and 3 respectively. STA102 establishes links with affiliated APs 1 to 3 respectively based on the received frames. Thereby, STA102 can communicate with AP101 via Multi-Link and improve the throughput in the communication with AP101.
[0021] On the other hand, when the source of this frame is not an AP supporting Multi-Link communication, STA102 establishes a link with the source of this frame on a single frequency channel.
[0022] FIG. 4 is a block diagram schematically showing the hardware configuration of STA102 in FIG. 1. In FIG. 4, STA102 includes a storage unit 401, a control unit 402, a functional unit 403, an input unit 404, an output unit 405, a communication unit 406, and an antenna 407. The storage unit 401, the control unit 402, the functional unit 403, the input unit 404, the output unit 405, and the communication unit 406 are connected to each other via a bus 408.
[0023] The storage unit 401 is composed of one or more memories such as ROM and RAM, and stores programs for performing various operations described later, as well as various information such as communication parameters for wireless communication. Note that ROM is the abbreviation of Read Only Memory, and RAM is the abbreviation of Random Access Memory. In addition to memories such as ROM and RAM, storage media such as flexible disks, hard disks, optical disks, magneto-optical disks, CD-ROMs, CD-Rs, magnetic tapes, non-volatile memory cards, and DVDs may be used as the storage unit 401. Also, the storage unit 401 may include a plurality of memories and the like.
[0024] The control unit 402 is composed of one or more processors such as a CPU or an MPU, for example, and controls the entire STA102 by executing the programs stored in the storage unit 401. Note that the control unit 402 may control the entire STA102 in cooperation with the programs stored in the storage unit 401 and the OS (Operating System). Also, the control unit 402 generates data and frames to be transmitted in communication with other communication devices. Note that CPU is the abbreviation of Central Processing Unit, and MPU is the abbreviation of Micro Processing Unit. Also, the control unit 402 may include a plurality of processors such as a multi-core, and control the entire STA102 by these plurality of processors.
[0025] Also, the control unit 402 controls the functional unit 403 to execute predetermined processes such as wireless communication, imaging, printing, and projection. The functional unit 403 is hardware for the STA102 to execute predetermined processes.
[0026] The input unit 404 receives various operations from the user. The output unit 405 outputs various information to the user via a monitor screen, a speaker, etc. Here, the output by the output unit 405 may be display on the monitor screen, audio output by the speaker, vibration output, etc. Note that both the input unit 404 and the output unit 405 may be realized by one module such as a touch panel. Also, the input unit 404 and the output unit 405 may be integrated with the STA102, or may be separate entities.
[0027] The communication unit 406 controls wireless communication compliant with the IEEE802.11be standard. In addition to the IEEE802.11be standard, the communication unit 406 may also control wireless communication compliant with other IEEE802.11 series standards or wired communication such as a wired LAN. The communication unit 406 controls the antenna 407 and transmits a frame for performing wireless communication generated by the control unit 402 to an external device.
[0028] Note that when the STA102 supports standards such as NFC and Bluetooth in addition to the IEEE802.11be standard, the communication unit 406 may control wireless communication compliant with these communication standards. Also, when the STA102 can execute wireless communication compliant with multiple communication standards, the STA102 may have a configuration with individual communication units and antennas corresponding to each communication standard. The STA102 transmits and receives data such as image data, document data, and video data to and from an external device such as the AP101 via the communication unit 406. Note that the antenna 407 may be configured separately from the communication unit 406, or may be configured as one module together with the communication unit 406.
[0029] Antenna 407 is an antenna capable of communication in the 2.4 GHz band, 5 GHz band, and 6 GHz band. In this embodiment, STA102 is configured to include two antennas, but it is not limited to this configuration. For example, STA102 may be configured to include different antennas for each frequency band, that is, a configuration including three antennas corresponding to the 2.4 GHz band, 5 GHz band, and 6 GHz band respectively. Also, in a configuration where STA102 includes a plurality of antennas, it may be configured to include a plurality of communication units corresponding to each antenna.
[0030] FIG. 5 is a block diagram showing an example of the functional configuration of STA102 in FIG. 1. In FIG. 5, as a functional configuration, STA102 includes a multi-link control unit 501, an affiliated STA setting unit 502, a frame generation unit 503, a frame transmission / reception unit 504, and a communication quality measurement unit 505.
[0031] The multi-link control unit 501 controls communication start processing for establishing one or more links used by STA102 for wireless communication with AP101, link addition and deletion processing after communication starts, and communication end processing for deleting all links. The connection processing specifically consists of Authentication processing, Association processing, and 4-Way-Hand-Shake (4WHS) processing.
[0032] The affiliated STA setting unit 502 selects and determines the affiliated STA in the Multi-Link communication set by the user at the input unit 404. Also, the affiliated STA setting unit 502 notifies the frame transmission / reception unit 504 of the frequency channel to be used.
[0033] The frame generation unit 503 generates a frame to be transmitted according to the setting of the affiliated STA setting unit 502.
[0034] The frame transmission / reception unit 504 receives frames such as Beacons and Probe Responses from the counterpart device on the frequency channel indicated by the notification received from the affiliated STA setting unit 502.
[0035] The communication quality measurement unit 505 measures the communication quality of frames such as Beacons and Probe Responses received by the frame transmission / reception unit 504. In the measurement of communication quality, for example, RSSI, SNR, etc. are used.
[0036] Next, the process by which the STA 102 establishes a link with the AP 101 will be described.
[0037] FIG. 6 is a flowchart showing the procedure of the link establishment control process executed by the STA 102 in FIG. 1. The link establishment control process in FIG. 6 is realized by the control unit 402 executing the program stored in the storage unit 401. The link establishment control process in FIG. 6 is executed, for example, when the STA 102 starts a connection attempt to the AP 101 in a state where the Multi-Link mode for performing Multi-Link communication is set by the user. Or it is executed when re-determining the AP to connect due to a deterioration in the radio wave environment, etc.
[0038] In FIG. 6, first, the control unit 402 receives frames such as Beacons and Probe Responses from among the affiliated STAs 1 to 3 via the affiliated STA designated by the user (S601). For example, when the user designates the affiliated STA 1, in S601, the frame transmitted from the affiliated AP 1 operating on the same frequency channel as the affiliated STA 1 is received.
[0039] Next, the control unit 402 determines whether the STA 102 supports Multi-Link communication (S602).
[0040] If it is determined in S602 that STA102 does not support Multi-Link communication, this process proceeds to S603. In S603, the control unit 402 establishes a link with an affiliated AP1 that operates on the same frequency channel as the affiliated STA1 specified by the user. Thereafter, this process ends.
[0041] If it is determined in S602 that STA102 supports Multi-Link communication, this process proceeds to S604. In S604, the control unit 402 determines whether the frame received in S601 contains a Basic Multi-Link element. That is, it determines whether the device AP101, which is the source of the frame received in S601, supports Multi-Link communication.
[0042] If it is determined in S604 that the frame received in S601 does not contain a Basic Multi-Link element, that is, if AP101 does not support Multi-Link communication, this process proceeds to S603.
[0043] If it is determined in S604 that the frame received in S601 contains a Basic Multi-Link element, that is, if AP101 supports Multi-Link communication, this process proceeds to S605.
[0044] In S605, the control unit 402 acquires information on the frequency channels of other affiliated APs 2 and 3 that belong to the same AP MLD (AP101) as the affiliated AP1 that transmitted this frame from the frame received in S601.
[0045] Next, the control unit 402 switches to the frequency channel indicated by the information acquired in S605, and receives the frames transmitted from the affiliated APs 2 and 3 operating on this frequency channel, respectively (S606). Note that in S606, it may receive frames transmitted from affiliated APs belonging to an AP MLD other than AP101. Therefore, the control unit 402 determines whether the source of the frame received in S606 belongs to the same AP MLD as the source of the frame received in S601. This determination is made based on the MLD IDs included in the frames received in S601 and S606, respectively. For example, if these MLD IDs do not match, it is determined that the source of the frame received in S606 belongs to a different AP MLD from the source of the frame received in S601. On the other hand, if these MLD IDs match, it is determined that the source of the frame received in S606 belongs to the same AP MLD as the source of the frame received in S601. In the subsequent processing, among the plurality of frames received in S606, only the frames transmitted from the affiliated APs belonging to the same AP MLD as the source of the frame received in S601 are used.
[0046] Next, the control unit 402 acquires information regarding the security strengths of the affiliated APs 1 to 3 from the frames received in S601 and S606, respectively (S607). The information regarding the security strength includes, for example, information indicating the security standard of the source affiliated AP, information indicating the encryption method used by the source affiliated AP, information indicating the authentication method used by the source affiliated AP, information on the mode indicating the usage purpose of the AP MLD to which the source affiliated AP belongs, etc., but is not limited thereto.
[0047] Next, the control unit 402 performs a determination process on the number of affiliated APs whose security strength exceeds the threshold in FIG. 7 described later (S608).
[0048] When the number of affiliated APs determined in S608 to have a security strength exceeding the threshold is plural, this process proceeds to S609. In S609, the control unit 402 establishes links with each of the plural affiliated APs determined to have a security strength exceeding the threshold among the affiliated APs 1 to 3 belonging to AP101. For example, if it is determined that the security strength of all of the affiliated APs 1 to 3 exceeds the threshold, the control unit 402 establishes links with the affiliated APs 1 to 3 respectively. Also, if it is determined that the security strength of two of the affiliated APs 1 to 3 exceeds the threshold, the control unit 402 establishes links with each of the two affiliated APs determined to have a security strength exceeding the threshold. Thereafter, this process ends.
[0049] When the number of affiliated APs determined in S608 to have a security strength exceeding the threshold is one, this process proceeds to S610. In S610, the control unit 402 establishes a link with the one affiliated AP determined to have a security strength exceeding the threshold among the affiliated APs 1 to 3 belonging to AP101. Thereafter, this process ends. Thus, in this embodiment, among the affiliated APs 1 to 3 belonging to AP101, a link is established with the affiliated AP determined to have a security strength exceeding the threshold. When establishing one link in S610, it may be possible to inquire whether to establish communication with one link having a high security strength for the user or to establish communication with a plurality of links including a link having a low security strength, and to control whether to establish one link or a plurality of links based on the instruction of the user.
[0050] If the number of affiliated APs determined in S608 to have a security strength exceeding the threshold is 0, this process proceeds to S611. In S611, the control unit 402 does not establish a link with any of the affiliated APs 1 to 3 belonging to AP101. At this time, for example, a notification indicating that no link has been established with AP101 is displayed on the output unit 405. Then, this process ends. If it is determined in S608 that there is no link satisfying the condition, the user may be asked whether to establish communication or to establish communication using one or more links including links with low security strength, and based on the user's instruction, it may be controlled whether to establish one link or not to establish a link.
[0051] Figure 7 is a flowchart showing the procedure of the determination process of S608 in Figure 6. Note that the determination process in Figure 7 is executed for the frames received in S601 and S606, respectively. In the present embodiment, as an example, the process for the frame received in S601, that is, the frame transmitted from the affiliated AP1, will be described.
[0052] In Figure 7, based on the information regarding the security strength acquired in S607, the control unit 402 determines whether the security standard of the affiliated AP1 is WPA2 or WPA3 (S701). Note that in the present embodiment, the information regarding the security strength acquired in S607 includes information indicating any one of, for example, WPA3, WPA2, WPA, and WEP as the information indicating the security standard of the affiliated AP1. The security strength of the security standards is strong in the order of WPA3, WPA2, WPA, and WEP. In the present embodiment, as an example, the case where the threshold regarding the security strength of the security standard is set to WPA2 will be described. Regarding the threshold regarding the security strength of the security standard, a fixed value may be set in advance, or it may be a configuration that can be changed by the user.
[0053] In S701, when it is determined that the security standard of the affiliated AP1 is WPA2 or WPA3, the control unit 402 determines whether the encryption method of the affiliated AP1 is AES (S702). In this embodiment, the information on the security strength obtained in S607 includes information indicating the encryption method used in the affiliated AP1, for example, information indicating any one of AES, TKIP, and RC4. The security strength of the encryption methods is in the order of AES, TKIP, and RC4. In this embodiment, as an example, the case where the threshold value for the security strength of the encryption method is set to AES will be described. Regarding the threshold value for the security strength of the encryption method, a fixed value may be set in advance, or it may be a configuration that can be changed by the user.
[0054] In S702, when it is determined that the encryption method of the affiliated AP1 is AES, the control unit 402 determines whether the authentication method of the affiliated AP1 is SAE (S703). In this embodiment, the information on the security strength obtained in S607 includes information indicating the authentication method used in the affiliated AP1, for example, information indicating any one of SAE, PSK, shared key authentication, and open system authentication. The security strength of the authentication methods is in the order of SAE, PSK, shared key authentication, and open system authentication. In this embodiment, as an example, the case where the threshold value for the security strength of the authentication method is set to SAE will be described. Regarding the threshold value for the security strength of the authentication method, a fixed value may be set in advance, or it may be a configuration that can be changed by the user.
[0055] In S703, when it is determined that the authentication method of the affiliated AP1 is SAE, the control unit 402 determines whether the mode of the affiliated AP1 is Enterprise (S704). In this embodiment, in the information regarding the security strength acquired in S607, as information indicating the usage of the AP MLD to which the affiliated AP1 belongs, for example, either "Enterprise" indicating for enterprise use or "Personal" indicating for personal use is included. The security strength of the mode is stronger in the order of Enterprise and Personal. In this embodiment, as an example, the case where the threshold value regarding the security strength of the mode is set to Enterprise will be described. Regarding the threshold value regarding the security strength of the mode, a fixed value may be set in advance, or it may be a configuration that can be changed by the user.
[0056] In S704, when it is determined that the mode of the affiliated AP1 is Enterprise, the control unit 402 determines that the security strength of the affiliated AP1 exceeds the threshold value (S705). Then, this process ends.
[0057] In S701, when it is determined that the security standard of the affiliated AP1 is neither WPA2 nor WPA3, this process proceeds to S706. Also, in S702, when it is determined that the encryption method of the affiliated AP1 is not AES, this process also proceeds to S706. Further, in S703, when it is determined that the authentication method of the affiliated AP1 is not SAE, this process also proceeds to S706. Additionally, in S704, when it is determined that the mode of the affiliated AP1 is not Enterprise, this process also proceeds to S706. In S706, the control unit 402 determines that the security strength of the affiliated AP1 is below the threshold value. Then, this process ends. In this embodiment, the process of FIG. 7 is also performed on the frame received in S606, and for the affiliated APs 2 and 3 as well, it is determined whether their security strength exceeds the threshold value.
[0058] According to the above-described embodiments, when the received frame includes a Basic Multi-Link element, a link is established with an affiliated AP among affiliated APs 1 to 3 (communication means) whose security strength exceeds a threshold value. Thereby, data communication with a certain level or higher security strength can be realized.
[0059] Also, in the above-described embodiments, based on the received frame, it is determined whether or not the security strength of the affiliated AP that transmitted the frame exceeds a threshold value. Thereby, control can be performed to establish a link only with an affiliated AP whose security strength exceeds a threshold value among the affiliated APs that transmitted the frame.
[0060] Also, in the above-described embodiments, based on the information included in the received frame that indicates the security standard of the affiliated AP that transmitted the frame, it is determined whether or not the security strength of the affiliated AP exceeds a threshold value. Thereby, based on the security standard of the affiliated AP that transmitted the frame, it is possible to easily determine whether or not the security strength of the affiliated AP exceeds a threshold value.
[0061] Also, in the above-described embodiments, based on the information included in the received frame that indicates the encryption method used by the affiliated AP that transmitted the frame, it is determined whether or not the security strength of the affiliated AP exceeds a threshold value. Thereby, based on the encryption method used by the affiliated AP that transmitted the frame, it is possible to easily determine whether or not the security strength of the affiliated AP exceeds a threshold value.
[0062] In the above-described embodiment, based on the information included in the received frame that indicates the authentication method used by the affiliated AP that transmitted the frame, it is determined whether the security strength of the affiliated AP exceeds a threshold value. Thereby, based on the authentication method used by the affiliated AP that transmitted the frame, it is possible to easily determine whether the security strength of the affiliated AP exceeds the threshold value.
[0063] In the above-described embodiment, based on the information included in the received frame that indicates the mode of the usage purpose of the AP to which the affiliated AP that transmitted the frame belongs, it is determined whether the security strength of the affiliated AP exceeds a threshold value. Thereby, based on the usage purpose of the AP to which the affiliated AP that transmitted the frame belongs, it is possible to easily determine whether the security strength of the affiliated AP exceeds the threshold value.
[0064] In the above-described embodiment, when the received frame includes a Basic Multi-Link element, among affiliated APs 1 to 3, links are established with two or more affiliated APs whose security strength exceeds the threshold value. Thereby, it is possible to realize Multi-Link communication with a certain level or higher of security strength.
[0065] In the above-described embodiment, when the received frame includes a Basic Multi-Link element, among affiliated APs 1 to 3, a link is established with one affiliated AP whose security strength exceeds the threshold value. Thereby, it is possible to prevent Multi-Link communication with a high risk of increased vulnerability from being performed.
[0066] In addition, in this embodiment, when the number of affiliated APs determined in S608 to have a security strength exceeding the threshold is 0, in S612, among affiliated APs 1 to 3 belonging to AP101, a link may be established with the affiliated AP having the highest security strength.
[0067] Also, in this embodiment, in the process of FIG. 7, the security strength may be determined by frequency band. For example, when the frequency band in which the source of the received frame operates is the 6 GHz band, it is determined that the security strength of this source exceeds the threshold. This is because it is determined to use the WPA3 security standard at 6 GHz. On the other hand, when the frequency band in which the source of the received frame operates is the 5 GHz band, 2.4 GHz band, or other frequency bands, it is determined that the security strength of this source is below the threshold. Thereby, based on the frequency band in which the affiliated AP that transmitted the frame operates, it is possible to easily determine whether or not the security strength of the affiliated AP exceeds the threshold. That is, for example, when there are two links available in the 6 GHz band and one link in the 2.4 GHz band, the STA selects the two links in the 6 GHz band to establish a communication connection.
[0068] The criterion for determining that the security strength is high may be dynamically changed according to the device settings of the STA. For example, the security strength of the STA can be set from the operation unit of the STA. When the device setting for the security strength is "high", the threshold for the security strength is increased so that communication is established only through a WPA3 link.
[0069] Next, the process in which STA102, which has already established a link with AP101, adds a link with AP101 will be described.
[0070] FIG. 8 is a flowchart showing another procedure of the link establishment control process executed by the STA102 in FIG. 1. The link establishment control process in FIG. 8 is a process similar to the link establishment control process in FIG. 6 described above. Hereinafter, the content different from the link establishment control process in FIG. 6 described above will be described in particular. The link establishment control process in FIG. 8 is also realized by the control unit 402 executing the program stored in the storage unit 401, similar to the link establishment control process in FIG. 6 described above. The link establishment control process in FIG. 8 is executed, for example, when the STA102 receives a mode change instruction from the user to change from the Single-Link mode for performing Single-Link communication to the Multi-Link mode, or when it is determined that Multi-Link communication is executable due to the surrounding radio wave environment or the like. Here, as an example, in the Single-Link mode, it is assumed that the STA102 has established a link with one of the affiliated APs 1 to 3 belonging to the AP101, for example, the affiliated AP1.
[0071] In FIG. 8, S801, which is the same process as S601 described above, is performed. Here, it is assumed that the affiliated STA1 operating on the same frequency channel as the affiliated AP1 with which the link has already been established has been designated by the user. Next, S802 to S807, which are the same processes as S602 to S607 described above, are performed.
[0072] Next, the control unit 402 performs a process of determining the number of affiliated APs whose security strength exceeds the threshold in FIG. 9 to be described later (S808). In S808, processing is performed on the frame received in S806, specifically, the frame transmitted from the affiliated APs 2 and 3 other than the affiliated AP1 with which the link has already been established.
[0073] When the number of affiliated APs determined in S808 to have a security strength exceeding the threshold is plural, this process proceeds to S809. In S809, the control unit 402 establishes links with the plural affiliated APs determined in S808 to have a security strength exceeding the threshold, specifically, affiliated APs 2 and 3 belonging to AP101. That is, in addition to the link with affiliated AP1 that has already been established, a link with affiliated AP2 and a link with affiliated AP3 are added. Thereafter, this process ends.
[0074] When the number of affiliated APs determined in S808 to have a security strength exceeding the threshold is one, this process proceeds to S810. In S810, the control unit 402 establishes a link with the one affiliated AP determined to have a security strength exceeding the threshold among affiliated APs 2 and 3 belonging to the AP101 that transmitted the frame that was the processing target in S808. For example, when it is determined in S808 that the security strength of affiliated AP2 belonging to AP101 exceeds the threshold, in addition to the link with affiliated AP1 that has already been established, a link with affiliated AP2 is added. Thereafter, this process ends.
[0075] When the number of affiliated APs determined in S808 to have a security strength exceeding the threshold is zero, this process proceeds to S811. In S811, the control unit 402 does not add a link with AP101. That is, the establishment of the link with affiliated AP1 is maintained as it is. At this time, for example, a notification indicating that Multi-Link communication is not performed with AP101 is displayed on the output unit 405. Thereafter, this process ends.
[0076] FIG. 9 is a flowchart showing the procedure of the determination process of S808 in FIG. 8. Note that the determination process in FIG. 9 is executed for each frame received in S806 as described above. In the present embodiment, as an example, the process for the frame received in S806 and transmitted from the affiliated AP2 will be described.
[0077] In FIG. 9, the control unit 402 determines whether the security strength of the security standard of the affiliated AP2 is equal to or greater than that of the affiliated AP1 (S901).
[0078] If it is determined in S901 that the security strength of the security standard of the affiliated AP2 is equal to or greater than that of the affiliated AP1, this process proceeds to S902. In S902, the control unit 402 determines whether the security strength of the encryption method of the affiliated AP2 is equal to or greater than that of the affiliated AP1.
[0079] If it is determined in S902 that the security strength of the encryption method of the affiliated AP2 is equal to or greater than that of the affiliated AP1, this process proceeds to S903. In S903, the control unit 402 determines whether the security strength of the authentication method of the affiliated AP2 is equal to or greater than that of the affiliated AP1.
[0080] If it is determined in S903 that the security strength of the authentication method of the affiliated AP2 is equal to or greater than that of the affiliated AP1, this process proceeds to S904. In S904, the control unit 402 determines whether the security strength of the mode of the affiliated AP2 is equal to or greater than that of the affiliated AP1.
[0081] If it is determined in S904 that the security strength of the mode of the affiliated AP2 is equal to or greater than that of the affiliated AP1, the control unit 402 determines that the security strength of the affiliated AP2 exceeds the threshold (S905). Then, this process ends.
[0082] In S901, if it is determined that the security strength of the security standard of the affiliated AP2 is less than that of the affiliated AP1, this process proceeds to S906. Also, in S902, if it is determined that the security strength of the encryption method of the affiliated AP2 is less than that of the affiliated AP1, this process also proceeds to S906. Further, in S903, if it is determined that the security strength of the authentication method of the affiliated AP2 is less than that of the affiliated AP1, this process also proceeds to S906. Moreover, in S904, if it is determined that the security strength of the mode of the affiliated AP2 is less than that of the affiliated AP1, this process also proceeds to S906. In S906, the control unit 402 determines that the security strength of the affiliated AP2 is below the threshold value. Thereafter, this process ends. In this embodiment, the determination process of FIG. 8 is also performed on the frame of the affiliated AP3 received in S806, and for the affiliated AP3 as well, it is determined whether its security strength exceeds the threshold value.
[0083] In the above-described embodiment, a link with an affiliated AP whose security strength exceeds the threshold value is additionally established. Thereby, Multi-Link communication with a certain level or higher of security strength can be realized.
[0084] Note that in the determinations of S901 to S904 described above, instead of using the security strength of the affiliated AP1 as a reference, it may be performed based on the set threshold value as in the determination process of FIG. 7 described above.
[0085] A recording medium storing the program code of software for realizing the above functions may be supplied to a system or apparatus, and a computer (CPU, MPU) of the system or apparatus may read and execute the program code stored in the recording medium. In this case, the program code itself read from the storage medium realizes the functions of the above-described embodiments, and the storage medium storing the program code constitutes the above-described apparatus.
[0086] As the storage medium for supplying the program code, for example, a flexible disk, a hard disk, an optical disk, a magneto-optical disk, a CD-ROM, a CD-R, a magnetic tape, a non-volatile memory card, a ROM, a DVD, etc. can be used.
[0087] Also, by executing the program code read by the computer, not only the above functions are realized, but also based on the instructions of the program code, the OS running on the computer performs part or all of the actual processing to realize the above functions. OS is an abbreviation for Operating System.
[0088] Furthermore, the program code read from the storage medium is written into the memory provided in a function expansion board inserted into the computer or a function expansion unit connected to the computer. Then, based on the instructions of the program code, the CPU provided in the function expansion board or the function expansion unit performs part or all of the actual processing to realize the above functions.
[0089] Note that the disclosure of this embodiment includes the following configurations and methods. (Configuration 1) A communication device that performs wireless communication with a wireless communication device compliant with a standard of the IEEE 802.11 series and supporting Multi-Link communication, comprising means for receiving a signal including information necessary for a communication connection for performing the wireless communication from the wireless communication device, and means for establishing a link with the wireless communication device based on the signal, wherein when the signal includes predetermined information indicating that the wireless communication device supports the Multi-Link communication, the means for establishing the link establishes a link with a communication means among a plurality of communication means provided in the wireless communication device and operating on different frequency channels, the security strength of which satisfies a predetermined condition. (Configuration 2) The communication device according to Configuration 1, further comprising means for determining whether the security strength of the communication means of the wireless communication device exceeds a threshold value, wherein the receiving means receives the signal from each of the plurality of communication means, and the determining means determines whether the security strength of the communication means that transmitted the signal exceeds the threshold value based on the signal. (Configuration 3) The communication device according to Configuration 2, wherein the determining means determines whether the security strength of the communication means exceeds the threshold value based on information included in the signal and indicating the security standard of the communication means that transmitted the signal. (Configuration 4) The communication device according to Configuration 2 or 3, wherein the determining means determines whether the security strength of the communication means exceeds the threshold value based on information included in the signal and indicating the encryption method used by the communication means that transmitted the signal. (Configuration 5) The communication device according to any one of Configurations 2 to 4, wherein the determining means determines whether the security strength of the communication means exceeds the threshold value based on information included in the signal and indicating the authentication method used by the communication means that transmitted the signal. (Configuration 6) The determining means determines whether or not the security strength of the communication means that transmitted the signal exceeds a threshold value based on information included in the signal and indicating a predetermined mode indicating the usage of the wireless communication device, according to any one of Configurations 2 to 5. (Configuration 7) The determining means determines whether or not the security strength of the communication means exceeds a threshold value based on information included in the signal and indicating the frequency band in which the communication means that transmitted the signal operates, according to Configuration 2. (Configuration 8) When two or more communication means are determined by the determining means to have a security strength exceeding the threshold value, the link establishing means establishes a link with the two or more communication means, according to any one of Configurations 2 to 7. (Configuration 9) When one communication means is determined by the determining means to have a security strength exceeding the threshold value, the link establishing means establishes a link with the one communication means, according to any one of Configurations 2 to 8.
Explanation of Reference Numerals
[0090] 101 AP 102 STA 402 Control Unit 406 Communication Unit 501 Multi-Link Control Unit 504 Frame Transmitting / Receiving Unit
Claims
1. A communication device that performs wireless communication with a wireless communication device compliant with a standard of the IEEE 802.11 series and compliant with a standard corresponding to Multi-Link communication, means for receiving a signal including information necessary for a communication connection for performing the wireless communication from the wireless communication device, means for establishing a link with the wireless communication device based on the signal, wherein when the signal includes predetermined information indicating that the wireless communication device supports the Multi-Link communication, the means for establishing the link establishes a link with a communication means among a plurality of communication means provided in the wireless communication device and operating on different frequency channels, the communication means satisfying a predetermined condition for security strength. The communication device is characterized by this.
2. further comprising means for determining whether the security strength of the communication means of the wireless communication device exceeds a threshold value, the receiving means receives the signal from each of the plurality of communication means, the determining means determines, based on the signal, whether the security strength of the communication means that transmitted the signal exceeds a threshold value. The communication device according to claim 1 is characterized by this.
3. the determining means determines, based on information included in the signal and indicating the security standard of the communication means that transmitted the signal, whether the security strength of the communication means exceeds a threshold value. The communication device according to claim 2 is characterized by this.
4. the determining means determines, based on information included in the signal and indicating the encryption method used by the communication means that transmitted the signal, whether the security strength of the communication means exceeds a threshold value. The communication device according to claim 2 is characterized by this.
5. the determining means determines, based on information included in the signal and indicating the authentication method used by the communication means that transmitted the signal, whether the security strength of the communication means exceeds a threshold value. The communication device according to claim 2 is characterized by this.
6. the determining means determines, based on information included in the signal and indicating a predetermined mode of the usage purpose of the wireless communication device, whether the security strength of the communication means that transmitted the signal exceeds a threshold value. The communication device according to claim 2 is characterized by this.
7. The determining means determines whether the security strength of the communication means exceeds a threshold value based on information included in the signal indicating the frequency band in which the communication means that transmitted the signal operates, according to the communication device described in claim 2.
8. When the determining means determines that the security strength of two or more communication means exceeds the threshold value, the means for establishing the link establishes a link with the two or more communication means, according to the communication device described in claim 2.
9. When the determining means determines that the security strength of one communication means exceeds the threshold value, the means for establishing the link establishes a link with the one communication means, according to the communication device described in claim 2.
10. A control method for a communication device that performs wireless communication with a wireless communication device compliant with the IEEE 802.11 series of standards corresponding to Multi-Link communication, receiving a signal including information necessary for a communication connection for performing the wireless communication from the wireless communication device; establishing a link with the wireless communication device based on the signal, wherein when the signal includes predetermined information indicating that the wireless communication device supports Multi-Link communication, the step of establishing the link is to establish a link with a communication means whose security strength satisfies a predetermined condition among a plurality of communication means provided in the wireless communication device and operating on different frequency channels, according to the control method for a communication device.
11. A program for causing a computer to execute a control method for a communication device that performs wireless communication with a wireless communication device compliant with the IEEE 802.11 series of standards corresponding to Multi-Link communication, wherein the control method for the communication device includes receiving a signal including information necessary for a communication connection for performing the wireless communication from the wireless communication device; establishing a link with the wireless communication device based on the signal, and when the signal includes predetermined information indicating that the wireless communication device supports Multi-Link communication, the step of establishing the link is to establish a link with a communication means whose security strength satisfies a predetermined condition among a plurality of communication means provided in the wireless communication device and operating on different frequency channels, according to the program.
Citation Information
Patent Citations
Communication device, control method, and program
JP2018050133A