Communication device, communication method, and program

The communication device enhances wireless communication reliability by efficiently notifying and implementing Control frame protection using Beacon and Association Request frames, preventing tampered frames from being processed.

JP2026079027APending Publication Date: 2026-05-15CANON KK
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CANON KK
Filing Date
2024-10-29
Publication Date
2026-05-15

AI Technical Summary

Technical Problem

Existing wireless communication technologies, particularly those compliant with the IEEE 802.11 standard series, lack efficient mechanisms for protecting Control frames from tampering, which can compromise communication reliability.

Method used

A communication device that functions as an access point, capable of transmitting Beacon frames containing capability information for Control frame protection, and stations that notify their support for such protection using Association Request frames, enabling tamper detection through the use of Control frame key information.

Benefits of technology

Enhances the reliability of wireless communication by efficiently notifying and implementing Control frame protection, thereby preventing tampered frames from being processed, ensuring secure and reliable data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026079027000001_ABST
    Figure 2026079027000001_ABST
Patent Text Reader

Abstract

To provide a technology for efficiently notifying information regarding the protection of control frames in wireless communication compliant with the IEEE 802.11 standard series. [Solution] A communication device that functions as an access point performing wireless communication compliant with the IEEE 802.11 standard series transmits a Beacon frame containing information about the communication device's capabilities regarding support for protection of Control frames.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a technique for efficiently notifying information related to the protection of Control frames in wireless communication compliant with the IEEE802.11 standard series.

Background Art

[0002] In recent years, with the increase in the amount of data to be communicated, the development of communication technologies such as wireless LAN (Local Area Network) has been promoted. As the main communication standards for wireless LAN, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard series is known. The IEEE802.11 standard series includes IEEE802.11a / b / g / n / ac / ax / be standards, etc. For further improvement of communication reliability, as a successor standard to the IEEE802.11be standard, the development of the IEEE802.11bn standard is in progress. In the IEEE802.11WG (Working Group) that formulates the IEEE802.11bn standard, in the UHR SG, the goals and scope of study of this standard are determined, and in TGbn, the detailed technical content to be included in this standard is planned to be defined. Note that UHR SG is an abbreviation for Ultra High Reliability Study Group. Also, TGbn is an abbreviation for Task Group bn.

[0003] In Patent Document 1, a technique called Protected Management Frame (PMF) is disclosed, which protects Management frames by encrypting frames and detecting forgery to improve communication reliability.

Prior Art Documents

Patent Documents

[0004]

Patent Document 1

[0005] This invention provides a technology for efficiently notifying information regarding the protection of Control frames in wireless communication compliant with the IEEE 802.11 standard series. [Means for solving the problem]

[0006] A communication device according to one aspect of the present invention is a communication device that functions as an access point performing wireless communication in accordance with the IEEE 802.11 standard series, and includes a first transmitting means that transmits a Beacon frame containing capability information of the communication device regarding support for protection of Control frames. [Effects of the Invention]

[0007] According to the present invention, information regarding the protection of Control frames can be efficiently notified in wireless communication compliant with the IEEE 802.11 standard series. [Brief explanation of the drawing]

[0008] [Figure 1] This is a diagram showing an example configuration of a wireless communication system. [Figure 2] This figure shows an example of the hardware configuration of a communication device. [Figure 3] This figure shows an example of the functional configuration of a communication device. [Figure 4] This figure shows an example of a communication sequence between the AP and STA. [Figure 5] This figure shows an example of the RSN Element format. [Figure 6] This figure shows an example of the format for an RSN Extension Element. [Figure 7] This figure shows an example of the format for an RSN Extension Element. [Figure 8] This figure shows examples of KDE selectors and CIGTK KDE formats. [Figure 9] This figure shows an example of the format for a Control MIC Element. [Figure 10] This figure shows an example of the processing flow when setting key information, which is performed by the AP. [Figure 11] This figure shows an example of the protection processing flow for Control frames executed by AP. [Figure 12] This figure shows an example of the processing flow when setting key information, which is performed by STA. [Figure 13] This figure shows an example of the protection processing flow for Control frames performed by STA. [Figure 14] This figure shows an example sequence in multilink communication between AP and STA. [Figure 15] This figure shows examples of KDE selectors and MLO CIGTK KDE formats. [Modes for carrying out the invention]

[0009] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims. While the embodiments describe multiple features, not all of these features are essential to the invention, and the features may be combined in any way. Furthermore, in the attached drawings, identical or similar configurations are given the same reference numerals, and redundant descriptions are omitted.

[0010] (System Configuration) Figure 1 shows an example configuration of a wireless communication system according to this embodiment. This wireless communication system is configured to include, for example, one access point (AP) 101 and one non-AP station (Non-AP STA or station, hereinafter referred to as STA) 102. The network 110 formed by AP 101 indicates the range in which AP 101 and STA 102 can communicate. That is, within the range of network 110, STA 102 can receive signals transmitted by AP 101, and signals transmitted by STA 102 can be received by AP 101. AP 101 and STA 102 are wireless communication devices capable of performing wireless communication compliant with the IEEE 802.11 series standards, including the IEEE 802.11bn standard. IEEE stands for Institute of Electrical and Electronics Engineers. The IEEE 802.11bn standard is the successor standard to IEEE 802.11be, targeting a maximum transmission speed of 46.08 Gbps. The IEEE 802.11bn standard emphasizes high-reliability communication, low-latency communication, and improved throughput during congestion as its primary features. The IEEE 802.11bn standard is also sometimes referred to as the UHR standard. UHR may stand for Ultra High Reliability. Wireless frames communicated using the IEEE 802.11bn standard may be called UHR (Ultra High Reliability) PPDUs. PPDU stands for Physical Layer (PHY) Protocol Data Unit. In this embodiment, wireless frames communicated based on the IEEE 802.11 series standards may be referred to as PPDUs. PPDUs may include UHR-PPDUs. The names IEEE 802.11bn and UHR are merely convenient designations based on the goals to be achieved and the main features outlined during the development of these standards. Therefore, these names may change once the standard's development is complete. On the other hand, the specifications and accompanying claims are essentially applicable to all standards that could be successors to the IEEE 802.11be standard.

[0011] The IEEE 802.11 series standards may include IEEE 802.11a / b / g / n / ac / ax / be standards. These standards may be referred to as legacy standards. That is, in addition to the IEEE 802.11bn standard, AP101 and STA102 may support one or more of the legacy standards. In addition, in addition to the IEEE 802.11 series standards, AP101 and STA102 may support other communication standards such as Bluetooth (registered trademark), NFC, UWB, ZigBee, and MBOA. Note that UWB is an abbreviation for Ultra Wide Band, MBOA is an abbreviation for Multi Band OFDM Alliance, and NFC is an abbreviation for Near Field Communication. UWB includes wireless USB, wireless 1394, WiNET, etc. In addition, AP101 and STA102 may support the communication standards of wired communication such as wired LAN.

[0012] In FIG. 1, a state where one AP101 and one STA102 exist is shown, but there may be multiple AP101s or STA102s. Also, at that time, multiple STA102s may be connected to one AP101, or one STA102 may be connected to multiple AP101s. AP101 may be a wireless LAN router, a personal computer (PC), etc., but is not limited thereto. Also, STA102 may be any electronic device such as a smartphone, a tablet, a mobile phone, a PC, a video camera, a headset, a printer, a display, etc., but is not limited thereto. Also, AP101 and STA102 may be information processing devices such as wireless chips that can perform wireless communication compliant with the IEEE 802.11bn standard. In this embodiment, AP101 and STA102 may be referred to as communication device 100 without distinction.

[0013] The communication device 100 can transmit and receive wireless signals using frequency bands such as the 2.4GHz band, 3.6GHz band, 5GHz band, and 6GHz band, as well as millimeter-wave bands such as the 45GHz band and 60GHz band. The frequency bands used by the communication device 100 are not limited to these, and may include, for example, the Sub1GHz band. The communication device 100 can also communicate using frequency bandwidths of 20MHz, 40MHz, 80MHz, 160MHz, 320MHz, 540MHz, 640MHz, 1080MHz, and 2160MHz. The frequency bandwidths used by the communication device 100 are not limited to these, and may include, for example, frequency bandwidths of 240MHz or 4MHz. Note that the IEEE 802.11 standard series specifies frequency channels using a frequency bandwidth of 20MHz as basic channels in frequency bands such as the 2.4GHz, 5GHz, and 6GHz bands. Furthermore, this standard defines multiple channels available for communication in each frequency band: the 2.4GHz band, the 5GHz band, and the 6GHz band. In this standard, the communication device 100 can use one channel in combination with other adjacent channels. This use of one channel in combination with other adjacent channels may be called channel bonding. For example, channel bonding can combine a first channel with a 20MHz frequency bandwidth and a second channel with a 20MHz frequency bandwidth adjacent to the first channel to form a single 40MHz channel. Thus, a link formed as a physical path usable for data transmission between communication devices consists of one or more adjacent channels of predetermined frequency bandwidths. That is, data with a 40MHz frequency bandwidth can be transmitted in a single link formed by two adjacent channels with a 20MHz frequency bandwidth. The IEEE 802.11be standard is expected to specify 320MHz as the maximum frequency bandwidth available in a single link. The transmitted signal may be continuous or discontinuous on the frequency axis within this frequency bandwidth. For example, some frequency bands within this frequency bandwidth may not be used for signal transmission.Furthermore, the IEEE 802.11be standard is expected to define Multi-Link Operation (MLO), which allows for the parallel use of multiple links established between a pair of communication devices. AP101 and STA102 may be AP Multi-Link Devices (MLDs) and Non-AP MLDs that support MLO.

[0014] In the IEEE802.11 series standards, an OFDMA function is defined that divides one channel into multiple resource units on the frequency axis for multiple access. OFDMA is an abbreviation for Orthogonal Frequency Division Multiple Access. For example, when multiple STAs 102 are connected to the AP 101, the AP 101 divides one channel it uses into multiple resource units and assigns them to each STA 102. As an example, when two STAs 102 are connected to the AP 101 and the AP 101 transmits one PPDU using one 20 MHz channel. At this time, the AP 101 arranges two different resource units on the frequency axis within one PPDU. Each resource unit can have a bandwidth of 10 MHz. Also, each resource unit can be arranged so as not to overlap with each other on the frequency axis. The AP 101 transmits the downlink data to be sent to each STA 102 using the resource unit assigned to each STA 102. The STA 102 receives the data transmitted to itself in the resource unit assigned to itself. For example, the STA 102 can identify the resource unit assigned to itself by referring to the information on the arrangement and allocation of the resource units stored in the preamble of the PPDU. Thus, by using the OFDMA function, the AP 101 can transmit data to multiple STAs 102 in parallel. When the STA 102 transmits uplink (Uplink, hereinafter UL) data to the AP 101, first, the AP 101 transmits a Trigger frame. The Trigger frame is a type of Control frame. Information on the arrangement and allocation of resource units for UL transmission can be indicated in the Trigger frame. That is, the STA 102 can identify the resource unit to be used for its UL transmission by referring to the Trigger frame and transmit UL data using that resource unit.

[0015] The IEEE 802.11bn standard includes consideration of Control frame protection. For example, a malicious third party might continuously send tampered Control frames with the aim of attacking STA102. To protect Control frames, AP101 and STA102 need to efficiently notify each other of information regarding Control frame protection. In this embodiment, AP101 notifies STA102 of its capability to support Control frame protection using a Beacon frame. Upon receiving the Beacon frame, STA102 notifies STA102 of its capability to support Control frame protection using an Association Request frame. When AP101 and STA102 recognize that they support Control frame protection, they can add a tamper detection code when sending Control frames using the Control frame key information. The receiving communication device can calculate a tamper detection code from the Control frame key information and the data of the received Control frame, and by comparing it with the tamper detection code added to the received Control frame, it can detect whether tampering has occurred. This mechanism allows for the discarding of tampered Control frames sent by malicious third parties without processing them.

[0016] (Device configuration) Figure 2 shows an example of the hardware configuration of the communication device 100 (AP101 and STA102) in this embodiment. The communication device 100 includes a storage unit 201, a control unit 202, a function unit 203, an input unit 204, an output unit 205, a communication unit 206, and an antenna 207. There may be multiple antennas. The storage unit 201 is composed of one or more memories such as ROM or RAM, and stores various information such as computer programs for performing various operations described later, and communication parameters for wireless communication. ROM and RAM are abbreviations for Read Only Memory and Random Access Memory, respectively. In addition to memories such as ROM and RAM, the storage unit 201 may also use storage media such as flexible disks, hard disks, optical disks, magneto-optical disks, CD-ROMs, CD-Rs, magnetic tapes, non-volatile memory cards, and DVDs. Furthermore, the storage unit 201 may have multiple memories.

[0017] The control unit 202 is composed of one or more processors, such as a CPU and an MPU, and controls the entire communication device 100 by executing a computer program stored in the memory unit 201. Alternatively, the control unit 202 may control the entire communication device 100 in cooperation with the computer program stored in the memory unit 201 and the OS (Operating System). The control unit 202 also generates data and signals (wireless frames) to be transmitted in communication with other communication devices. CPU stands for Central Processing Unit, and MPU stands for Micro Processing Unit. The control unit 202 may also comprise multiple processors, such as a multi-core processor, and control the entire communication device 100 using these multiple processors. Furthermore, the control unit 202 controls the function unit 203 to perform predetermined processes such as wireless communication, imaging, printing, and projection. The function unit 203 is the hardware that enables the communication device 100 to perform predetermined processes.

[0018] The input unit 204 receives various operations from the user. The output unit 205 provides various outputs to the user via a monitor screen or speaker. Here, the output from the output unit 205 may be a display on the monitor screen, audio output via a speaker, vibration output, etc. The input unit 204 and the output unit 205 may also be implemented in a single module, such as a touch panel. Furthermore, the input unit 204 and the output unit 205 may be integrated with the communication device 100 or may be separate components.

[0019] The communication unit 206 controls wireless communication compliant with the IEEE 802.11bn standard. In addition to the IEEE 802.11bn standard, the communication unit 206 may also control wireless communication compliant with other IEEE 802.11 series standards, or wired communication such as wired LAN. The communication unit 206 controls the antenna 207 to transmit and receive signals for wireless communication generated by the control unit 202. If the communication device 100 supports the NFC standard, Bluetooth standard, etc., in addition to the IEEE 802.11bn standard, it may also control wireless communication compliant with these communication standards. Furthermore, if the communication device 100 can perform wireless communication compliant with multiple communication standards, it may be configured to have separate communication units and antennas corresponding to each communication standard. The communication device communicates data such as image data, document data, and video data with the other communication device via the communication unit 206. The antenna 207 may be configured separately from the communication unit 206, or it may be configured as a single module together with the communication unit 206.

[0020] Antenna 207 is an antenna capable of communication in the 2.4GHz band, 5GHz band, 6GHz band, etc. In this embodiment, there may be two or more antennas, and if the communication unit 206 is composed of multiple communication units, there may be an antenna corresponding to each communication unit. Alternatively, there may be different antennas for each frequency band.

[0021] Figure 3 shows a block diagram of the functional configuration of the communication device 100 (AP101 and STA102) in this embodiment. The communication device 100 may include a wireless LAN control unit 301, a frame generation unit 302, a frame analysis unit 303, a UI control unit 304, and a storage unit 305. The wireless LAN control unit 301 controls the communication unit 206 and antenna 207 for sending and receiving wireless signals with other wireless LAN devices. For example, the wireless LAN control unit 301 works in cooperation with the frame generation unit 302 and the frame processing unit 303 to perform communication control of wireless frames in accordance with the IEEE 802.11 standard series. The wireless LAN control unit 301 can perform communication control such as authentication processing, connection processing, key information distribution processing, and data communication processing of the other party's communication device.

[0022] The frame generation unit 302 generates wireless frames that include MAC frames such as Management frames, Control frames, and Data frames. MAC frames are also called MAC Protocol Data Units (MPDUs) or Aggregate MAC Protocol Data Units (A-MPDUs). When generating Management frames, the frame generation unit 302 may include information on whether or not to support protection of Control frames. The frame generation unit 302 may also perform MAC frame protection processing using key information corresponding to the type of MAC frame. For example, when encrypting a Data frame, it may use key information to encrypt it. Also, for example, if protection of Control frames is enabled, it may generate an MIC for tamper detection using key information for Control frames and attach it to the Control frame. MIC stands for Message Integrity Code and is a hash value calculated based on data and key information. MIC may also be called Message Authentication Code (MAC). Wireless frames consist of a preamble field and a data field. MAC frames such as Management frames, Control frames, and Data frames are stored in the data field. The content of wireless control by each MAC frame generated by the frame generation unit 302 may be constrained by settings stored in the storage unit 305. The frame generation unit 302 can accept settings from the user via the UI control unit 304. Wireless frames generated by the frame generation unit 302 are sent to the wireless LAN control unit 301 and can be transmitted externally by the communication unit 206 and antenna 207.

[0023] The frame analysis unit 303 analyzes the received wireless frame in cooperation with the communication unit 206, antenna 207, and wireless LAN control unit 301. When analyzing a wireless frame, the frame analysis unit 303 can determine the analysis method based on the settings stored in the storage unit 305. The frame analysis unit 303 analyzes the preamble of the received wireless frame and obtains the MAC frame from the data field. When obtaining a Management frame, such as a Beacon frame or Association Request frame, the frame analysis unit 303 can analyze the information contained in the Management frame to determine whether it supports protection of the Control frame. The frame analysis unit 303 can also perform MAC frame protection processing using key information corresponding to the type of MAC frame. For example, if the data frame is encrypted, it can perform decryption processing using the key information. The frame analysis unit 303 can also determine whether Control frame protection is enabled based on the MAC frame header information and whether MIC is attached to the Control frame. If Control frame protection is enabled, the MIC for tamper detection can be calculated using the key information for the Control frame, and tamper detection can be performed by comparing this value with the MIC attached to the Control frame.

[0024] The UI control unit 304 includes hardware related to the user interface, such as a touch panel or buttons, for receiving operations on AP101 and STA102 by a user (not shown), and a program to control them. It may also be possible to configure whether or not to support Control frame protection through user operation. Furthermore, the UI control unit 304 also has functions for presenting information to the user, such as displaying images or outputting audio.

[0025] The memory unit 305 is a storage device that may consist of ROM and RAM, etc., for storing programs and data on which the communication device operates.

[0026] (Example sequence) This section outlines the communication performed between AP101 and STA102. Figure 4 shows an example of a message sequence exchanged between AP101 and STA102.

[0027] AP101 may send a Beacon frame containing information indicating support for Control frame protection if it supports it (S401). Whether or not to support Control frame protection may be set as an initial setting of the device, or it may be set based on user input via the UI control unit 304. Information indicating support for Control frame protection may be shown, for example, in the CFP capable field of the RSN Element or RSN Extension Element described later. RSN is an abbreviation for Robust Security Network. AP101 may also indicate support for Control frame protection in Management frames other than Beacon frames, such as Probe Response frames.

[0028] Next, STA102 sends an Authentication frame for authentication (S402), and AP101 sends an Authentication frame in response (S403). The number of Authentication frames varies depending on the security method used; for example, when connecting using the WPA3 Personal method, the number of Authentication frames exchanged may increase.

[0029] Next, STA102 sends an Association Request frame to connect to AP101 (S404). In the Association Request frame, STA102 may indicate that it supports protection of the Control frame. Also, if AP101, upon receiving the Association Request frame, allows STA102's connection, it may send an Association Response frame (S405). In the Association Response frame, AP101 may indicate that it supports protection of the Control frame. Information indicating support for protection of the Control frame can be shown, for example, in the CFP capable field of the RSN Element or RSN Extension Element, as described later.

[0030] In this embodiment, the exchange of Authentication frames and the exchange of Association Request frames and Association Response frames may be collectively referred to as the connection process.

[0031] If the connection process is successful, AP101 and STA102 perform a 4-Way handshake (4WHS) process and can deliver and generate key information for protecting data frames, management frames, and control frames. First, AP101 and STA102 exchange random numbers called Anonce and Snonce in 4WHS message 1 frame (S406) and 4WHS message 2 frame (S407) to generate PMK (Pairwise Master Key) and PTK (Pairwise Temporal Key) based on these random numbers. PMK is pre-shared key information, and PTK is key information used to protect data frames sent to individual STAs. Note that 4WHS message 1 frame (S406) may separately include an Anonce for generating a PTK for control frames addressed to individual STAs (Control PTK, hereafter CPTK). Also, 4WHS message 2 frame (S407) may separately include a Snonce for generating a CPTK.

[0032] Next, AP101 generates a CIGTK (Control frame Integrity Group Temporal Key) KDE (Key Data Encapsulation) containing key information for protecting Control frames addressed to the STA group, stores it in a 4WHS message 3 frame, and sends it to STA102 (S408). CIGTK may also be called CGTK (Control frame Group Temporal Key). Details of CIGTK KDE will be described later. The key information for protecting frames addressed to the STA group is also called the group key. The 4WHS Message 3 frame may contain a GTK (Group Temporal Key), which is the group key for protecting data frames; an IGTK (Integrity GTK), which is the group key for protecting Management frames; and a BIGTK (Beacon IGTK), which is the group key for protecting Beacon frames. Based on the generated PTK and the data of the 4WHS message 3 frame received from AP101, STA102 detects tampering with the 4WHS message 3 frame. If it determines that no tampering has occurred, STA102 sends the 4WHS message 4 frame to AP101 (S409). The 4WHS message 3 frame (S408) may also include an Anonce for generating the CPTK. Similarly, the 4WHS message 4 frame (S409) may also include a Snonce for generating the CPTK. Once the 4WHS processing frames have been exchanged, AP101 generates the CPTK from the Anonce and Snonce for the Control frame and the PMK, and sets the PTK / GTK / CPTK / CIGTK as key information in the storage unit 201 and stores it. STA102 does the same, setting the PTK / GTK / CPTK / CIGTK as key information in the storage unit 201 and storing it. Furthermore, AP101 and STA102 can also configure and save IGTK and BIGTK settings.

[0033] Subsequently, AP101 sends a Trigger frame, triggering the transmission of UL data from one or more STAs, including STA102 (S412). The Trigger frame transmitted here has a tamper-detection MIC attached to it to protect the Control frame. Since the Trigger frame is addressed to the group, the MIC is calculated using the CIGTK shared between AP101 and STA102 in the group 4WHS processing. If the Control frame to be transmitted is addressed to an individual STA, the MIC may be calculated using the CPTK.

[0034] When STA102 receives a Trigger frame with an attached MIC, it performs tamper detection on the Trigger frame (S413). Specifically, it calculates the MIC based on the data contained in the Trigger frame and CIGTK. STA102 then compares the calculated MIC with the MIC value contained in the Trigger frame, and determines that the frame has not been tampered with if the MIC values ​​match. If STA102 determines that the Trigger frame has not been tampered with, it sends a UL data frame (S414); if it determines that the frame has been tampered with, it discards the Trigger frame.

[0035] The CIGTK may be configured to be updated periodically after a predetermined time has elapsed. In this case, AP101 may send a Group key handshake (GKHS) message 1 frame containing the updated CIGTK KDE to STA102 (S421). Upon receiving GKHS message 1, STA102 sends a GKHS message 2 frame to AP101 (S422) and sets and saves the CIGTK in the storage unit 201. The CIGTK may be updated at the same time as the GTK, IGTK, and BIGTK, or at different times. The interval for CIGTK updates may be set as an initial setting of AP101, or it may be set based on user input via the UI control unit 304. AP101 may also notify STA102 of information regarding the interval for CIGTK updates.

[0036] (Frame format) Figure 5 shows an example of the format of an RSN Element used to indicate whether the communication device 100 supports protection of Control frames in this embodiment. The RSN Element may be included in the Management frame transmitted by the communication device 100. For example, if the communication device 100 is an AP, the RSN Element may be included in Management frames such as Beacon frames, Probe Response frames, Association Response frames, and Reassociation Response frames. Also, for example, if the communication device 100 is an STA, the RSN Element may be included in Management frames such as Probe Request frames, Association Request frames, and Reassociation Request frames.

[0037] An RSN Element includes an Element ID field 501, a Length field 502 indicating the length of the RSN Element, and an RSN Capabilities field 503. The Element ID field 501 may contain a value of 48, which indicates that it is an RSN Element. The RSN Capabilities field 503 contains fields related to capability information associated with the RSN. For example, the MFPR (Management Frame Protection Required) field 511 contains information indicating whether support for Management Frame Protection is required. Also, for example, the MFPC (Management Frame Protection Capable) field 512 contains information indicating whether Management Frame Protection can be supported. A value of 1 in the MFPR field 511 or a value of 1 in the MFPC field 512 may indicate that Management Frame Protection is supported.

[0038] The CFP (Control Frame Protection) capable field 513 contains information indicating whether control frame protection is supported. A value of 1 in the CFP Capable field 513 indicates that control frame protection is possible and is supported. A value of 0 in the CFP Capable field 513 indicates that control frame protection is not supported.

[0039] Instead of an RSN Element, an RSN Extension Element may be used to indicate whether the communication device 100 supports protection of Control frames. Figure 6 shows an example of the format of an RSN Extension Element used by the communication device 100 in this embodiment. An RSN Extension Element may be included in a Management frame transmitted by the communication device 100. For example, if the communication device 100 is an AP, an RSN Extension Element may be included in Management frames such as Beacon frames, Probe Response frames, Association Response frames, and Reassociation Response frames. Also, for example, if the communication device 100 is an STA, an RSN Extension Element may be included in Management frames such as Probe Request frames, Association Request frames, and Reassociation Request frames. An RSN Extension Element includes an Element ID field 601, a Length field 602 indicating the length of the RSN Extension Element, and an Extended RSN Capabilities field 603. The Element ID field 601 may contain a value of 244, which indicates that it is an RSN Extension Element. The Extended RSN Capabilities field 603 contains fields related to capabilities associated with Extended RSN. A value of 1 in the CFP capable field 604 indicates that Control frame protection is possible and supported. A value of 0 in the CFP capable field 604 indicates that Control frame protection is not supported.

[0040] Figure 7 shows another example of the format of the RSN Extension Element used by the communication device 100 in this embodiment. In this example, the Extended RSN Capabilities field includes a CFPR (Control Frame Protection Required) field 701 and a CFPC (Control Frame Protection Capable) field 702. If the value of the CFPR field 701 is 1, it indicates that Control frame protection is required, and the connection will not be established if the communication device of the other party does not support Control frame protection. This makes it possible to connect only with communication devices of the other party that support a higher level of security. If the value of the CFPR field 701 is 0, it indicates that Control frame protection is not required. If the value of the CFPC field 702 is 1, it indicates that Control frame protection is possible and supported. If the value of the CFPC field 702 is 0, it indicates that Control frame protection is not supported. When the value of the CFPR field 701 is set to 1, the value of the CFPC field 702 is also set to 1.

[0041] Figures 5 to 7 show examples of Information Elements used to indicate whether or not Control frame protection is supported; other Information Elements besides RSN Elements and RSN Extension Elements may also be used.

[0042] Figure 8 shows an example of the format of KDE selectors and CIGTK KDE805 used by the communication device 100 in this embodiment. OUI stands for Organizationally Unique Identifier. KDE selectors are identified by the Data type value; for example, if the Data type is 16, it indicates MLO GTK KDE801, which includes the GTK of a predetermined link during multilink communication. If the Data type is 20, it indicates CIGTK KDE805. CIGTK KDE805 includes a KeyID field 810, a CIPN field 811, and a CIGTK field 812, which is a group key for protecting the Control frame. The KeyID field 810 is information indicating the key identifier. The CIPN field 811 stores the packet number used by the last Broadcast / multicast sender and is used by the receiver as an initial value for the replay counter. In Figure 8, the case where the Data type is 20 is shown as CIGTK KDE, but other values ​​may be used as long as they can be distinguished from other KDEs.

[0043] Figure 9 shows an example of the format of a Control MIC Element attached to a Control frame, which is subject to Control frame protection. Whether a Control frame is protected can be indicated, for example, by setting the value of the Protected Frame subfield of the Frame Control field in the MAC header to 1. Alternatively, the inclusion of a Control MIC Element in the Control frame can indicate that the Control frame is protected. A Control MIC Element may include an Element ID field 901, a Length field 902 indicating the length of the Control MIC Element, an Element ID Extension field 903, a Key ID field 904, a CIPN field 905, and a MIC field 906. For example, setting the Element ID field 901 to a value of 255 and setting the Element ID Extension field 903 to a predetermined value can specify that it is a Control MIC Element. Alternatively, the Element ID field 901 may be set to a value that uniquely identifies the Control MIC Element, and the Element ID Extension field 903 may be omitted. The Key ID field 904 stores information to identify the CIGTK or CPTK used to calculate the MIC. The CIPN field 905 stores an unsigned integer for replay detection of protected Control frames. The MIC field 906 stores a Message Integirty Code calculated based on the protected Control frame for tamper detection.

[0044] (Process flow) Next, the processing flow executed by the communication device 100 as described above will be explained using Figures 10 to 13. Figure 10 shows an example of the processing flow when setting key information executed by AP101. Figure 11 shows an example of the processing flow when protecting Control frames executed by AP101. Figure 12 shows an example of the processing flow when setting key information executed by STA102. Figure 13 shows an example of the processing flow when protecting Control frames executed by STA102. Each process shown in the flowcharts of Figures 10 to 13 is executed by the processor of the control unit 202 of AP101 or STA102 executing a computer program stored in the storage unit 201. Some processes in Figures 10 to 13, such as transmission, modulation, reception, and decoding, are realized through the cooperation of the processor of the control unit 202 of each communication device and the ASIC, DSP, FPGA, etc. of the communication unit 206 and the control unit 202.

[0045] First, the process of setting key information performed by AP101 will be explained using Figure 10. For example, the control unit 202 in AP101 works in cooperation with other functional units to perform the key information setting process. AP101 first generates and transmits a Beacon frame containing an RSN Element or RSN Extension Element that indicates support for Control frame protection (S1001). For example, when using an RSN Element as shown in Figure 5 or an RSN Extension Element as shown in Figure 6, the CFP capable field is set to 1. Also, when using an RSN Extension Element as shown in Figure 7, for example, both the CFPR field and the CFPC field are set to 1, or the CFPR field is set to 0 and the CFPC field is set to 1.

[0046] Next, AP101 determines whether it has received a connection initiation frame from STA102 (S1002). For example, AP101 may determine that it has received a connection frame from STA102 if it has received an Authentication frame. If AP101 determines that it has not received a connection initiation frame from STA102 (NO in S1002), it resends a Beacon frame after a predetermined period of time has elapsed (S1001). If AP101 determines that it has received a connection initiation frame from STA102 (YES in S1002), AP101 executes the connection process with STA102 (S1003). The connection process includes Authentication and Association processes to authenticate STA102.

[0047] Next, AP101 determines whether the connection process with STA102 was successful (S1004). If AP101 determines that the connection process failed (NO in S1004), it returns to the Beacon frame transmission process (S1001). If AP101 determines that the connection process was successful (YES in S1004), it determines whether STA102 supports Control frame protection based on the RSN Element or RSN Extension Element contained in the Association Request frame received from STA102 (S1006). For example, if an RSN Element as shown in Figure 5 or an RSN Extension Element as shown in Figure 6 is used, STA102 determines that it supports Control frame protection if the CFP capable field is set to 1. Furthermore, if an RSN Extension Element like the one shown in Figure 7 is used, STA102 will determine that it supports protection of the Control frame if both the CFPR field and the CFPC field are set to 1, or if the CFPR field is set to 0 and the CFPC field is set to 1.

[0048] If AP101 determines that STA102 supports protection of Control frames (YES in S1006), it executes 4WHS, sends a 4WHS message 3 frame including GTK / CIGTK, and delivers the key information to STA102 (S1007). Subsequently, AP101 receives a 4WHS message 4 frame from STA102, generates a CPTK for the protection of Control frames sent to individual STAs, and a PTK for data frames sent to individual STAs, and sets them together with GTK / CIGTK in the storage unit 201 and saves them (S1008). If AP101 determines that STA102 does not support protection of Control frames (NO in S1006), it executes 4WHS, sends a 4WHS message 3 frame including GTK, and sends it to STA102 (S1009). Next, AP101 receives 4WHS message 4 frames from STA102, generates the PTK for the data frames (S1008) to be sent to the individual STAs, and sets and saves them together with the GTK in the storage unit 201 (S1010).

[0049] Next, we will explain the Control frame protection process performed by AP101 using Figure 11. For example, the control unit 202 in AP101 works in cooperation with other functional units to perform the Control frame protection process. The example in Figure 11 shows a case where AP101 sends a Trigger frame and receives UL data from STA102. AP101 first attempts to obtain a BSR (Buffer Status Report) from STA102 to obtain the buffer amount of the transmitted data (S1101). For example, AP101 may send a BSRP (Buffer Status Report Poll) Trigger frame and receive a frame containing a BSR from one or more STA102s. If AP101 does not receive a BSR, or if it determines that the BSR buffer amount is not greater than 0 (NO in S1102), it attempts to obtain the STA's BSR again (S1101). If AP101 determines that the BSR buffer size is greater than 0 (YES in S1102), it determines whether Control frame protection is enabled in order to generate a Trigger frame to trigger UL transmission by STA102 (S1103). If AP101 determines that Control frame protection is enabled (YES in S1103), it generates a MIC for detecting tampering with the Trigger frame based on the data of the Trigger frame and the CIGTK generated by the 4WHS process, and attaches it to the Trigger frame before sending it (S1105). In addition to attaching the MIC, it may also set the value of the Protected Frame bit in the Frame Control field of the MAC header of the Trigger frame to 1. If AP101 determines that Control frame protection is not enabled (NO in S1103), it sends the Trigger frame without attaching the MIC (S1105).

[0050] The final AP101 receives UL data via OFDMA communication from one or more STA102 units that received the Trigger frame (S1106).

[0051] Next, the process performed by STA102 when setting key information will be explained using Figure 12. For example, the control unit 202 in STA102 works in cooperation with other functional units to perform the key information setting process. First, STA102 receives a Beacon frame containing an RSN Element or RSN Extension Element that indicates support for protection of the Control frame (S1201).

[0052] Next, STA102 performs connection processing to connect with AP101 (S1202). For example, the connection processing includes Authentication processing and Association processing for STA102 authentication.

[0053] If STA102 determines that the connection process has failed (NO in S1203), it returns to the Beacon frame reception process (S1201). If STA102 determines that the connection process was successful (YES in S1203), it determines whether to support Control frame protection based on the RSN Element or RSN Extension Element included in the Association Request frame sent by STA102 (S1205). For example, if an RSN Element as shown in Figure 5 or an RSN Extension Element as shown in Figure 6 is used, STA102 determines that it supports Control frame protection if the CFP capable field is set to 1. Also, if an RSN Extension Element as shown in Figure 7 is used, STA102 determines that it supports Control frame protection if both the CFPR field and the CFPC field are set to 1, or if the CFPR field is set to 0 and the CFPC field is set to 1.

[0054] If STA102 determines that it supports Control frame protection (YES in S1205), it performs 4WHS processing and receives a 4WHS message 3 frame containing GTK / CIGTK from AP101 (S1206). Subsequently, STA102 sends a 4WHS message 4 frame to AP101, generates PTK / CPTK, and sets and saves them together with GTK / CIGTK in the storage unit 201 (S1207). If STA102 determines that it does not support Control frame protection (NO in S1205), it performs 4WHS processing and receives a 4WHS message 3 frame containing GTK but not CIGTK from AP101 (S1208). Subsequently, STA102 sends a 4WHS message 4 frame to AP101, generates PTK, and saves them together with GTK in the storage unit 201 (S1209).

[0055] Next, we will explain the Control frame protection process performed by STA102 using Figure 13. For example, the control unit 202 in STA102 works in cooperation with other functional units to perform the Control frame protection process. The example in Figure 13 shows a case where STA102 receives a Trigger frame, performs the Trigger frame protection process, and then transmits UL data.

[0056] STA102 first attempts to send a BSR to notify the amount of data buffered for transmission (S1301).

[0057] Next, STA102 determines whether it has received a Trigger frame from AP101 that triggers the transmission of UL data (S1302). If STA102 determines that it has not received a Trigger frame (NO in S1302), it sends a BSR to AP101 again (S1301). If STA101 determines that it has received a Trigger frame (YES in S1302), it determines whether Control frame protection is enabled (1303). Whether Control frame protection is enabled may be determined based on whether MIC is attached to the Trigger frame. Alternatively, it may be determined based on whether the value of the Protected Frame bit in the Frame Control field of the MAC header of the Trigger frame is set to 1.

[0058] If STA102 determines that Control frame protection is not enabled (NO in S1303), it will not perform tampering detection on the Trigger frame, but will instead send UL data to AP101 based on the contents of the Trigger frame (S1304) and terminate processing.

[0059] If STA102 determines that Control frame protection is enabled (YES in S1303), it performs tampering detection on the Trigger frame (S1305). Specifically, it calculates the MIC based on the data contained in the Trigger frame and the CIGTK stored in the memory unit 201 (S1305). STA102 then compares the calculated MIC with the MIC value contained in the Trigger frame. If the MIC values ​​match (YES in S1306), it determines that the received Trigger frame has not been tampered with and sends UL data to AP101 based on the contents of the Trigger frame (S1304). If the MIC values ​​do not match (NO in S1306), STA102 determines that the received Trigger frame has been tampered with, discards the Trigger frame (S1307), and sends the BSR again (S1301).

[0060] Note that while Figures 11 and 13 show examples where a Trigger frame is used as a Control frame, the Control frames subject to protection are not limited to these. For example, BlockAckReq frames or other Control frames may also be subject to protection. Furthermore, if the Control frame is addressed to an individual STA, the MIC may be generated using the CPTK generated in Figures 10 and 12, or the Control frame may be encrypted.

[0061] As described above, in this embodiment, the communication device functioning as an access point transmits a Beacon frame containing capability information regarding the communication device's support for Control frame protection. The communication device functioning as a station receives a Beacon frame containing capability information regarding support for Control frame protection. This makes it possible to efficiently notify information regarding Control frame protection. As a result, it becomes possible to distribute and generate key information used for Control frame protection and to execute Control frame protection processing.

[0062] (Variation 1) This section describes an example of multilink communication performed by AP101 and STA102, both of which support MLO. An AP that supports MLO is called an AP MLD, and a single physical device can contain multiple APs. Similarly, an STA that supports MLO is called a Non-AP MLD, and a single physical device can contain multiple STAs (Non-AP STAs). In this example, we will describe a case where AP101, an AP MLD, contains two APs (AP1 and AP2), and STA102, a Non-AP MLD, contains two STAs (STA1 and STA2).

[0063] (Example sequence) Figure 14 shows an example of a message sequence exchanged between AP101 and STA102 during multilink communication. The link used between AP1 and STA1 is referred to as Link 1, and the link used between AP2 and STA2 is referred to as Link 2. In this embodiment, the Authentication process, Association process, and 4WHS process for establishing multilink communication are collectively referred to as multilink setup.

[0064] First, AP101 generates and transmits a Beacon frame (S1401) that indicates support for Control frame protection, similar to S401 in Figure 4. Furthermore, a Basic Multi-Link element is added to this Beacon frame to indicate that AP101 supports MLO.

[0065] The processes in S1402 to S1403 are the same as those in S402 to S403 in Figure 4, so their explanation will be omitted.

[0066] STA1 sends an Association Request frame on link 1 to set up the multilink (S1404). STA1 may indicate in the Association Request frame that it supports protection of the Control frame. STA1 also adds a Basic Multi-Link element to the Association Request frame to set up the multilink. The Basic Multi-Link element contains information about the link to be set up, and may include information about link 2.

[0067] Furthermore, AP1, upon receiving an Association Request frame, may send an Association Response frame if it permits the connection of STA1 (S1405). AP1 may indicate in the Association Response frame that it supports protection of the Control frame. It may also add a Basic Multi-Link element containing information about the permitted link to the Association Response frame.

[0068] If the connection process is successful, AP1 and STA1 execute the 4WHS process to exchange and generate key information for protecting data frames, management frames, and control frames. The processes from S1406 to S1407 are the same as the processes from S406 to S407 in Figure 4, so their explanation is omitted.

[0069] AP1 generates group key information (MLO CIGTK KDE) for protecting the MLO's Control frame, stores it in a 4WHS message 3 frame, and sends it to STA1 (S1408). The MLO CIGTK KDE contains CIGTK information for multiple links. Details of the MLO CIGTK KDE will be described later. The 4WHS message 3 frame may contain the MLO GTK, which is the group key for protecting the MLO's data frame, the MLO IGTK, which is the group key for protecting the MLO's Management frame, and the MLO BIGTK, which is the group key for protecting the MLO's Beacon frame. Based on the generated PTK and the data in the 4WHS message 3 frame received from AP1, STA1 detects tampering with the 4WHS message 3 frame, and if it determines that no tampering has occurred, it sends a 4WHS message 4 frame to AP1 (S1409). Alternatively, the 4WHS message 3 frame (S1408) may include a separate Anonce for generating the CPTK. Also, the 4WHS message 4 frame (S1409) may include a separate Snonce for generating the CPTK.

[0070] Once the 4WHS processing frames have been exchanged, the AP MLD generates a CPTK from the Anonce and Snonce for the Control frame and the PMK, and sets and saves the PTK / CPTK in the memory unit 201. The PTK / CPTK can be used in common across all links. The AP MLD also sets and saves the GTK / CIGTK for AP1, which uses link 1, in the memory unit 201, and the GTK / CIGTK for AP2, which uses link 2, in the memory unit 201.

[0071] Similarly, STA102 sets and saves PTK / GTK / CPTK / CIGTK in the memory unit 201. AP101 and STA102 can also set and save IGTK or BIGTK for each link.

[0072] Subsequently, AP1 sends a Trigger frame on Link 1, triggering the transmission of UL data from one or more STAs, including STA1 (S1411). The Trigger frame transmitted here has a tamper-detection MIC attached to it to protect the Control frame. The MIC is calculated using the CIGTK for Link 1, which is shared between the AP MLD and Non-AP MLD in 4WHS processing.

[0073] When STA1 receives a Trigger frame with an attached MIC, it performs tamper detection on the Trigger frame (S1412). Specifically, it calculates the MIC based on the data contained in the Trigger frame and the CIGTK of Link 1. STA1 then compares the calculated MIC with the MIC value contained in the Trigger frame, and determines that the frame has not been tampered with if the MIC values ​​match. If it determines that the frame has not been tampered with, it sends a UL data frame (S1413); if it determines that the frame has been tampered with, it discards the Trigger frame.

[0074] Similarly, AP2 can also transmit a Trigger frame with MIC added over Link 2 (S1421). Here, MIC is calculated using the CIGTK for Link 2 shared between AP MLD and Non-AP MLD in 4WHS.

[0075] When STA2 receives a Trigger frame with MIC attached, it performs tampering detection on the Trigger frame (S1422), and if it determines that it has not been tampered with, it sends a UL data frame (S1423).

[0076] The MLO CIGTK may also be configured to be updated periodically after a predetermined time has elapsed. In this case, the AP MLD may send the GKHS message 1 frame to the Non-AP MLD, including the updated MLO CIGTK KDE (S1431). Upon receiving GKHS Message 1, the Non-AP MLD sends a GKHS message 2 frame to the AP MLD (S1432), setting and saving the CIGTK for each link in the storage unit 201.

[0077] (Frame format) Figure 15 shows an example of the format of KDE (Key Data Encapsulation) selectors and MLO CIGTK KDE1505 used by the communication device 100 in this embodiment. KDE selectors are identified by the value of Data type. For example, if Data type is 16, it indicates MLO GTK KDE1501, which includes the GTK for a given link during multilink communication. For example, if Data type is 17, it indicates MLO IGTK KDE1502, which includes the IGTK for protecting the Management frame of a given link during multilink communication. For example, if Data type is 18, it indicates MLO BIGTK KDE1503, which includes the BIGTK for protecting the Beacon frame of a given link during multilink communication. If Data type is 20, it indicates CIGTK KDE1504. CIGTK KDE1504 is a KDE used during single-link communication, not multilink communication. The contents of CIGTK KDE1504 are the same as those of CIGTK KDE805 in Figure 8, so the explanation is omitted. If the Data type is 21, it indicates MLO CIGTK KDE1505. MLO CIGTK KDE1505 contains a CIGTK for protecting the Control frame of a given link during multilink communication. MLO CIGTK KDE1505 includes a KeyID field 1510, a CIPN field 1511, a Reserved field 1512, a LinkID field 1513 that identifies the link, and CIGTK1514, which is the key for protecting the Control frame.

[0078] MLO GTK KDE1501, MLO IGTK KDE1502, MLO BIGTK KDE1503, and MLO CIGTK KDE1505 can be included in 3 frames of a 4WHS message or 1 frame of a GKHS message, depending on the number of links set up in MLO. This allows key information for protecting Control frames for multiple links to be delivered in a single frame at once, reducing communication overhead and improving communication efficiency. In Figure 15, MLO CIGTK KDE is used when the Data type is 21, but other values ​​may be used as long as they can be distinguished from other KDEs.

[0079] As described above, in this embodiment, even when the communication device supports MLO, it is possible to efficiently notify information regarding the protection of Control frames. This makes it possible to distribute and generate key information used for protecting Control frames used in each link constituting the multilink communication, and to execute the Control frame protection process.

[0080] While exemplary embodiments are presented in the detailed description above, a vast number of variations may exist. The embodiments described above are examples and are not intended to limit in any way the scope, applicability, operation, or configuration of this disclosure. Various modifications may be made to the function and arrangement of the steps and operating methods described in the exemplary embodiments, as well as to the modules and structures of the communication and information processing devices described in the exemplary embodiments, without departing from the scope of the subject matter described in the appended claims.

[0081] The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (e.g., an ASIC) that implements one or more functions.

[0082] (Summary of the embodiments) At least some of the embodiments described above can be summarized as follows:

[0083] (Item 1) A communication device that functions as an access point performing wireless communication compliant with the IEEE 802.11 standard series, A first transmitting means that transmits a Beacon frame containing capability information of the communication device regarding support for protection of Control frames, A communication device characterized by having the following features.

[0084] (Item 2) The communication device according to item 1, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Element of the Beacon frame.

[0085] (Item 3) The communication device according to item 1, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Extension Element of the Beacon frame.

[0086] (Item 4) Receiving means for receiving an Association Request frame from another communication device that functions as a station, which includes capability information of the other communication device regarding support for protection of Control frames, When the capability information of the aforementioned communication device indicates that it supports protection of Control frames, and the capability information of the other communication device indicates that it supports protection of Control frames, a first generation means generates a frame containing key information necessary for protection of Control frames, A second transmission means for transmitting the frame containing the key information to the other communication device, A communication device according to any one of items 1 to 3, characterized by having the following:

[0087] (Item 5) The communication device according to item 4, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Element of the Association Request frame.

[0088] (Item 6) The communication device according to item 4, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Extension Element of the Association Request frame.

[0089] (Item 7) The communication device according to any one of items 4 to 6, characterized in that the capability information of the communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

[0090] (Item 8) The communication device according to any one of items 4 to 7, characterized in that the capability information of the other communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and when the first information indicates that support for Control frame protection is essential and / or when the second information indicates that support for Control frame protection is possible, the other communication device supports Control frame protection.

[0091] (Item 9) A communication device according to any one of items 4 to 8, characterized in that, when the communication device and the other communication device set up a multilink, the key information includes key information for protecting Control frames used in each link included in the multilink.

[0092] (Item 10) A second generation means that, after transmitting a frame containing the key information, generates code for detecting tampering with the Control frame based on the key information and the data of the Control frame to be transmitted, A third transmission means that adds the code to the transmitted Control frame and transmits it to the other communication device, A communication device as described in any one of items 4 to 9, characterized by having the following:

[0093] (Item 11) The communication device according to any one of items 4 to 10, characterized in that the frame containing the aforementioned key information is a 4-Way handshake message 3 frame.

[0094] (Item 12) The communication device according to any one of items 4 to 10, characterized in that the frame containing the aforementioned key information is a Group key handshake message 1 frame.

[0095] (Item 13) A communication device that functions as a station performing wireless communication compliant with the IEEE 802.11 standard series, A first receiving means that receives a Beacon frame from another communication device that functions as an access point, which includes information about the capabilities of the other communication device regarding support for protection of Control frames, A communication device characterized by having the following features.

[0096] (Item 14) The communication device according to item 13, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Element of the Beacon frame.

[0097] (Item 15) The communication device according to item 13, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Extension Element of the Beacon frame.

[0098] (Item 16) A transmission means for transmitting an Association Request frame containing information about the capabilities of the communication device regarding support for protection of Control frames, When the capability information of the aforementioned communication device indicates that it supports protection of Control frames, and the capability information of the other communication device indicates that it supports protection of Control frames, a second receiving means receives a frame containing key information necessary for protection of Control frames from the other communication device. A communication device according to any one of items 13 to 15, characterized by having the following:

[0099] (Item 17) The communication device according to item 16, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Element of the Association Request frame.

[0100] (Item 18) The communication device according to item 16, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Extension Element of the Association Request frame.

[0101] (Item 19) The communication device according to any one of items 16 to 18, characterized in that the capability information of the communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

[0102] (Item 20) The communication device according to any one of items 16 to 19, characterized in that the capability information of the other communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the other communication device supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

[0103] (Item 21) A communication device according to any one of items 16 to 20, characterized in that, when the communication device and the other communication device set up a multilink, the key information includes key information for protecting Control frames used in each link included in the multilink.

[0104] (Item 22) A third receiving means for receiving a Control frame containing a first code for detecting tampering with the Control frame generated based on the key information, A calculation means for calculating a second code for tamper detection based on the key information and the data of the received Control frame, A detection means for detecting whether the received Control frame has been tampered with by comparing the first code and the second code, A communication device as described in any one of items 16 to 21, characterized by having the following:

[0105] (Item 23) The communication device according to any one of items 16 to 22, characterized in that the frame containing the aforementioned key information is a 4-Way handshake message 3 frame.

[0106] (Item 24) The communication device according to any one of items 16 to 22, characterized in that the frame containing the aforementioned key information is a Group key handshake message 1 frame.

[0107] (Item 25) A communication method in a communication device that functions as an access point performing wireless communication compliant with the IEEE 802.11 standard series, A transmission step of transmitting a Beacon frame containing information about the capabilities of the communication device regarding support for protection of Control frames, A communication method characterized by having the following features.

[0108] (Item 26) A communication method in a communication device that functions as a station performing wireless communication compliant with the IEEE 802.11 standard series, A first receiving step of receiving a Beacon frame from another communication device that functions as an access point, which includes information about the capabilities of the other communication device regarding support for protection of Control frames, A communication method characterized by having the following features.

[0109] (Item 27) A program to operate a computer as a communication device as described in any one of items 1 through 12.

[0110] (Item 28) A program to operate a computer as a communication device as described in any one of items 13 through 24.

[0111] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention. [Explanation of Symbols]

[0112] 101 AP 102 STA 301 Wireless LAN Control Unit 302 Frame generation unit 303 Frame Analysis Unit 304 UI ​​Control Unit 305 Storage section

Claims

1. A communication device that functions as an access point performing wireless communication compliant with the IEEE 802.11 standard series, A first transmission means for transmitting a Beacon frame containing capability information of the communication device regarding support for protection of Control frames, A communication device characterized by having the following features.

2. The communication device according to claim 1, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Element of the Beacon frame.

3. The communication device according to claim 1, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Extension Element of the Beacon frame.

4. Receiving means for receiving an Association Request frame from another communication device that functions as a station, which includes capability information of the other communication device regarding support for protection of Control frames, When the capability information of the aforementioned communication device indicates that it supports protection of Control frames, and the capability information of the other communication device indicates that it supports protection of Control frames, a first generation means generates a frame containing key information necessary for protection of Control frames, A second transmission means for transmitting the frame containing the key information to the other communication device, The communication device according to claim 1, characterized by having the following features.

5. The communication device according to claim 4, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Element of the Association Request frame.

6. The communication device according to claim 4, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Extension Element of the Association Request frame.

7. The communication device according to claim 4, wherein the capability information of the communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device indicates that it supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

8. The communication device according to claim 4, wherein the capability information of the other communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device indicates that the other communication device supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

9. The communication device according to claim 4, characterized in that, when the communication device and the other communication device set up a multilink, the key information includes key information for protecting Control frames used in each link included in the multilink.

10. A second generation means that, after transmitting a frame containing the key information, generates a code for detecting tampering with the Control frame based on the key information and the data of the transmitted Control frame, A third transmission means that adds the aforementioned code to the transmitted Control frame and transmits it to the other communication device, The communication device according to claim 4, characterized by having the following:

11. The communication device according to claim 4, characterized in that the frame containing the key information is a 4-Way Handshake Message 3 frame.

12. The communication device according to claim 4, characterized in that the frame containing the key information is a Group key handshake message 1 frame.

13. A communication device that functions as a station performing wireless communication compliant with the IEEE 802.11 standard series, A first receiving means that receives a Beacon frame from another communication device that functions as an access point, which includes capability information of the other communication device regarding support for protection of Control frames, A communication device characterized by having the following features.

14. The communication device according to claim 13, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Element of the Beacon frame.

15. The communication device according to claim 13, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Extension Element of the Beacon frame.

16. A transmission means for transmitting an Association Request frame containing capability information of the communication device regarding support for protection of Control frames, When the capability information of the aforementioned communication device indicates that it supports protection of Control frames, and the capability information of the other communication device indicates that it supports protection of Control frames, a second receiving means receives a frame containing key information necessary for protection of Control frames from the other communication device, The communication device according to claim 13, characterized by having the following features.

17. The communication device according to claim 16, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Element of the Association Request frame.

18. The communication device according to claim 16, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Extension Element of the Association Request frame.

19. The capability information of the communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible, characterized in that the communication device supports Control frame protection.

20. The capability information of the other communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device according to claim 16 is characterized in that it indicates that the other communication device supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

21. The communication device according to claim 16, characterized in that, when the communication device and the other communication device set up a multilink, the key information includes key information for protecting Control frames used in each link included in the multilink.

22. A third receiving means for receiving a Control frame containing a first code for detecting tampering with a Control frame generated based on the aforementioned key information, A calculation means for calculating a second code for tamper detection based on the key information and the data of the received Control frame, A detection means for detecting whether the received Control frame has been tampered with by comparing the first code and the second code, The communication device according to claim 16, characterized by having the following:

23. The communication device according to claim 16, characterized in that the frame containing the key information is a 4-Way Handshake Message 3 frame.

24. The communication device according to claim 16, characterized in that the frame containing the key information is a Group key handshake message 1 frame.

25. A communication method in a communication device that functions as an access point performing wireless communication compliant with the IEEE 802.11 standard series, A transmission step of transmitting a Beacon frame containing information about the capabilities of the communication device regarding support for protection of Control frames, A communication method characterized by having the following features.

26. A communication method in a communication device that functions as a station performing wireless communication compliant with the IEEE 802.11 standard series, A first receiving step of receiving a Beacon frame from another communication device that functions as an access point, which includes capability information of the other communication device regarding support for protection of Control frames, A communication method characterized by having the following features.

27. A program for operating a computer as a communication device according to any one of claims 1 to 12.

28. A program for operating a computer as a communication device according to any one of claims 13 to 24.