Communication method and station

By encrypting or digesting AIDs in BA frames, the communication method safeguards privacy correlation information, preventing unauthorized access and leakage in communication systems.

JP7780014B2Active Publication Date: 2025-12-03GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024527376
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2021-11-12
Publication Date
2025-12-03
Estimated Expiration
2041-11-12

AI Technical Summary

Technical Problem

In existing communication systems, privacy correlation information of stations (STAs) is easily traced by unauthorized users, leading to serious privacy leakage issues due to unencrypted identity identifier information in control frames like Multi-STA BA frames.

Method used

Implement a communication method that encrypts or uses message digest algorithms to protect privacy correlation information, such as AIDs, within BA frames, ensuring only authorized STAs can identify and process the information by matching encrypted or digested AIDs with their own identities.

Benefits of technology

Prevents unauthorized access to privacy information by encrypting or digesting AIDs in BA frames, thereby enhancing user privacy by preventing tracking and information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007780014000001
    Figure 0007780014000001
  • Figure 0007780014000002
    Figure 0007780014000002
  • Figure 0007780014000003
    Figure 0007780014000003
Patent Text Reader

Abstract

The present application provides a communication method and station, where the method includes a first station (STA) receiving a block acknowledgement (BA) frame, the BA frame carrying first information and / or privacy-protected correlation information, and the first information is used to identify the privacy-protected correlation information. The present application can enhance privacy protection.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Detailed Description of the Invention The present application relates to the field of communications, and more particularly to a communication method and station. [Background technology]

[0002] In related technologies, the privacy correlation information of stations (STAs) is easily traced by unauthorized users, causing serious privacy leakage issues. 。 Summary of the Invention

[0003] Examples of the present application teeth Communication method and station provide .

[0004] The communication method provided in the embodiment of the present application includes: a first STA receiving a block acknowledgement BA frame, the BA frame carrying first information and / or correlation information of protected privacy, and the first information being used to identify the correlation information of protected privacy.

[0005] Another communication method provided in an embodiment of the present application includes a second STA sending a BA frame, the BA frame carrying first information and / or correlation information of protected privacy, and the first information is used to identify the correlation information of protected privacy.

[0006] The STA provided in the embodiment of the present application includes a first receiving module, which is used to receive a BA frame, and the BA frame carries first information and / or correlation information of protected privacy, and the first information is used to identify the correlation information of protected privacy.

[0007] The station STA provided in the embodiment of the present application includes a first transmitting module, which is used to transmit a BA frame, and the BA frame carries first information and / or correlation information of protected privacy, and the first information is used to identify the correlation information of protected privacy.

[0008] The station provided in the embodiment of the present application includes a processor and a memory, the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory so as to cause the first station to perform the above-mentioned communication method.

[0009] The chip provided in the embodiment of the present application is used to realize the above communication method.

[0010] Specifically, the chip includes a processor, which is used to retrieve and run a computer program from a memory to cause a device to which the chip is attached to perform the above-described communication method.

[0011] The computer-readable storage medium provided in the embodiments of the present application is used to store a computer program, which, when run on a device, causes the device to perform the above communication method.

[0012] The computer program product provided in the embodiments of the present application includes computer program instructions, which cause a computer to perform the above-mentioned communication method.

[0013] The computer program provided in the embodiments of the present application causes the computer to perform the above communication method when run on the computer. [Brief explanation of the drawings]

[0014] [Figure 1]1 is a schematic diagram of an application scene of an embodiment of the present application;

[0015] [Figure 2] A schematic diagram of the frame format of a Multi-STA BA frame.

[0016] [Figure 3] 1 is a flowchart illustrating a communication method according to an embodiment of the present application.

[0017] [Figure 4] 4 is a flowchart illustrating another communication method according to an embodiment of the present application.

[0018] [Figure 5] 1 is a flowchart of an implementation of a BA frame protection mechanism according to an embodiment of the present application;

[0019] [Figure 6] FIG. 2 is a structural schematic diagram of an associated request frame according to an embodiment of the present application;

[0020] [Figure 7] FIG. 10 is a structural schematic diagram of another related request frame according to an embodiment of the present application;

[0021] [Figure 8] FIG. 10 is a structural schematic diagram of another related request frame according to an embodiment of the present application;

[0022] [Figure 9] 1 is a schematic diagram of a frame format after protecting a Multi-STA BA frame according to the present application.

[0023] [Figure 10] 10 is a schematic diagram of another frame format after protecting a Multi-STA BA frame according to the present application.

[0024] [Figure 11]1 is a schematic diagram of a frame format after protecting a Multi-STA BA frame according to the present application.

[0025] [Figure 12] 10 is a schematic diagram of another frame format after protecting a Multi-STA BA frame according to the present application.

[0026] [Figure 13] 10 is a schematic diagram of another frame format after protecting a Multi-STA BA frame according to the present application.

[0027] [Figure 14] 1 is a schematic diagram of an implementation of encryption or decryption for a Multi-STA BA frame according to the present application;

[0028] [Figure 15] 4 is a flowchart illustrating another communication method according to an embodiment of the present application.

[0029] [Figure 16] 1 is a structural schematic diagram of an STA according to an embodiment of the present application;

[0030] [Figure 17] FIG. 10 is a structural schematic diagram of another STA according to an embodiment of the present application;

[0031] [Figure 18] 18 is a schematic structural diagram of a communication device 1800 according to an embodiment of the present application;

[0032] [Figure 19] FIG. 19 is a schematic structural diagram of a chip 1900 according to an embodiment of the present application. DETAILED DESCRIPTION OF THE INVENTION

[0033] Hereinafter, the technical solutions in the embodiments of the present application will be described with reference to the drawings in the embodiments of the present application.

[0034] Furthermore, the terms "first," "second," etc. used in the description of the embodiments, claims, and drawings of the present application are intended to distinguish between similar objects, and are not intended to describe a particular order or chronological sequence. Objects described by "first" and "second" simultaneously may be the same or different.

[0035] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as Wireless Local Area Networks (WLAN), Wireless Fidelity (WiFi), and other communication systems.

[0036] 1, an embodiment of the present application may be applied to a communication system 100. The communication system 100 may include an access point (AP) 110 and a station (STA) 120 that accesses a network via the access point 110.

[0037] In some scenarios, an AP is also called an AP STA, that is, in a sense, an AP is also an STA.

[0038] In some scenarios, the STA is also called a non-AP STA.

[0039] Communication in communication system 100 may be communication between an AP and a non-AP STA, communication between a non-AP STA and a non-AP STA, or communication between a STA and a peer STA, where a peer STA is a device that communicates between a STA and a terminal, for example, the peer STA may be an AP or a non-AP STA.

[0040] An AP is a bridge that connects wired and wireless networks, and its main role is to connect clients of each wireless network and then access the wireless network to Ethernet. An AP device can be a terminal device (e.g., a mobile phone) or a network device (e.g., a router) with a WiFi chip.

[0041] It should be understood that the role of an STA in a communication system is not absolute. For example, in some scenarios, when a mobile phone is connected to a router, the mobile phone is a non-AP STA, and when the mobile phone is used as a hotspot for other mobile phones, the mobile phone plays the role of an AP.

[0042] The AP and non-AP STA may be devices applied to the Internet of Vehicles, nodes of the Internet of Things (IoT), sensors, etc. in the Internet of Things (IoT), smart cameras, smart remote controls, smart water meters, smart electricity meters, etc. in smart homes, and sensors in smart cities.

[0043] In some embodiments, the non-AP STAs may support the 802.11be technology. The non-AP STAs may also support multiple current and future wireless local area networks (WLAN) technologies of the 802.11 family, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.

[0044] In some embodiments, the AP may be a device that supports the 802.11be standard. The AP may also be a device that supports multiple current and future WLAN standards of the 802.11 family, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.

[0045] In an embodiment of the present application, the STA may be a mobile phone, a tablet, a computer, a virtual reality (VR) device, an augmented reality (AR) device, a wireless device in industrial control, a set-top box, a wireless device in self driving, an in-vehicle communication device, a wireless device in remote medical, a wireless device in a smart grid, a wireless device in transportation safety, a wireless device in a smart city, or a wireless device in a smart home, a wireless communication chip / ASIC / SOC / , etc. that supports WLAN / WiFi technology.

[0046] The frequency bands that WLAN technology can support may include, but are not limited to, low frequency bands (eg, 2.4 GHz, 5 GHz, 6 GHz) and high frequency bands (eg, 60 GHz).

[0047] FIG. 1 illustrates one AP STA and two non-AP STAs as an example, and alternatively, the communication system 100 may include multiple AP STAs and other numbers of non-AP STAs, and embodiments of the present application are not limited thereto.

[0048] It should be understood that the terms "system" and "network" are always used interchangeably herein. The term "and / or" used herein describes only the relationship between related objects and indicates that three types of relationships can exist. For example, A and / or B can represent three cases: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " used herein generally indicates that the related objects before and after it are in an "or" relationship.

[0049] It should be understood that the "indication" described in the embodiments of the present application may be a direct indication, an indirect indication, or a reference to an association relationship. For example, "A indicates B" can indicate that A directly indicates B (e.g., B can be obtained through A), or that A indirectly indicates B (e.g., A indicates C, and B can be obtained through C), or that there is an association relationship between A and B.

[0050] In describing the embodiments of the present application, the term "correspondence" can indicate that there is a direct or indirect correspondence between the two, or that there is an association between the two, or it can refer to the relationship between "indicating" and "being indicated", or the relationship between "arranging" and "arranged", etc.

[0051] In order to facilitate understanding of the technical solutions of the embodiments of the present application, the following describes related arts of the embodiments of the present application, which can be arbitrarily combined with the technical solutions of the embodiments of the present application as alternative solutions, and all of them are included in the protection scope of the embodiments of the present application.

[0052] An STA is a station in a wireless network, and one STA may be a central node of the wireless network, i.e., an access point (AP), or a node connected to the wireless network, i.e., a non-AP STA. Hereinafter, a non-AP STA is abbreviated as STA, and an AP STA is abbreviated as AP. Privacy correlation information according to the present application includes, for example, STA identity identifier information such as an association identifier (AID) of the STA. Hereinafter, the related technology of the present application will be introduced using an AID as an example.

[0053] When a STA is associated with an AP, the STA obtains its own AID from the AP. Thereafter, when the AP transmits a control frame (e.g., a BA frame) to the STA, the AP carries information that needs to be transmitted to the STA, and this information carries the AID of the STA. In this way, when the STA receives a control frame and identifies that the AID in this information is the same as its own AID or corresponds to its own AID, it can confirm that this information was transmitted to the STA by the AP and extract this information for subsequent processing.

[0054] 2 is a schematic diagram of the frame format of a Multi-STA BA frame, taking a Multi-STA BA frame as an example, which includes a MAC header, a BA Control field, a BA Information field, and a Frame Check Sequence (FCS). Here, the BA Information field includes one or more information (Per AID TID Info) fields identified by an association identifier (AID) and a traffic identifier (TID) tuple, and each single association identifier traffic identifier information (Per AID TID Info) field represents one<AID、TID> A tuple corresponds to the AID TID Info field. The Per AID TID Info field includes an AID TID Info field, a Block Ack Starting Sequence Control field, and a Block Ack Bitmap field, where the AID TID Info field further includes an AID11 field having a length of 11 bits for carrying the AID of the STA. Currently available reserved values ​​for AID are 2008 to 2044 and 2047, and Figure 2 shows the frame format of a Multi-STA BA frame with AID11 ≠ 2045 (since AID = 2045 has a special application, its frame format field is not considered).

[0055] As can be seen from the frame format shown in FIG. 2, the Multi-STA BA frame transmitted by the AP may contain information that needs to be transmitted to multiple STAs. Information for different STAs is carried in different Per AID TID Info fields, and the Per AID TID Info fields carry the AIDs of different STAs, which are used to identify which STAs correspond to which. After receiving the Multi-STA BA frame, a STA compares its own AID with the AIDs carried in each Per AID TID Info field. If the comparison results in a match with the AID in a certain Per AID TID Info field, the STA confirms that the information in this Per AID TID Info field (e.g., acknowledgment type (Ack Type), TID, Block Ack Bitmap, etc.) is intended for the STA, and can extract this information for further processing.

[0056] As can be seen from the above, because the frame body of a control frame such as a Multi-STA BA frame is not encrypted, identity identifier information such as the AID of the STA (identity identifier information is a type of privacy-related information) can easily be traced by unauthorized users, and the mapping relationship between the user's AID and MAC address can easily be leaked, which may reveal whether the user is in the current area.In addition, other parameter information in the frame may also leak information such as the traffic consumption status of the user's current business, posing a significant threat to the security of user privacy.As a result, control frames that carry unencrypted identity identifier information such as AID and related parameter information pose serious privacy exposure issues, such as effectively tracking users through the mapping relationship between AID and MAC address.

[0057] In response to the above problem, the present application proposes a communication method, which can be applied to, but is not limited to, the system shown in Fig. 1 as one of the options. Fig. 3 is a flowchart for implementing the communication method according to an embodiment of the present application, which includes at least a portion of the following content:

[0058] S310: A first STA receives a BA frame, which carries first information and / or correlation information of a protected privacy, and the first information is for identifying the correlation information of the protected privacy.

[0059] In some embodiments, the BA frame may include a Multi-STA BA frame.

[0060] In some embodiments, the privacy correlation information may include an AID.

[0061] For example, a first STA may receive a Multi-STA BA frame from a second STA (e.g., an AP). This Multi-STA BA frame carries information for multiple STAs, and the information for each STA includes a protected AID and first information corresponding to the STA. Here, the protected AID may include a ciphertext obtained by encrypting the AID, digest information obtained by calculating the AID using a message digest algorithm, a ciphertext obtained by encrypting the AID and other information, and / or digest information obtained by calculating the AID and other information using a message digest algorithm. The first information may include performing the encryption and / or message digest algorithms used in the above process on the AID so that the first STA can identify the protected AID. If the first STA identifies that a certain protected AID matches its own AID, i.e., if it confirms that the content of this portion of the Multi-STA BA frame including the protected AID is intended for it, it extracts the content of this portion and performs subsequent processing.

[0062] Before the first STA receives the BA frame, the first STA and the second STA can declare their protection capabilities for the BA frame, as shown in Figure 4. Figure 4 is a flowchart for realizing another communication method according to an embodiment of the present application, which may further include the following steps before the above step S310.

[0063] S410: The first STA sends protection capability information for the first STA's BA frame.

[0064] S420: The first STA receives protection capability information for the BA frame of the second STA.

[0065] The above steps S410 and S420 do not require a specific execution order, and any step may precede or be executed synchronously.

[0066] The first STA may be a non-AP STA, and the second STA may be an AP. Taking a wireless network including multiple non-AP STAs (abbreviated as STAs) as an example, each STA transmits protection capability information for its BA frame to the AP, for example, declaring that it has the capability to identify the AID to be protected, and the AP transmits protection capability information for its BA frame to each STA, for example, declaring that it has the capability to perform protection for the AID (for example, supporting encryption for the AID and / or processing for the AID by adopting a message digest algorithm).

[0067] Before the above step S310, the first STA may perform key agreement with the second STA to generate a key. This key can be used for processes such as encryption and decryption of the AID and calculation of digest information. There is no requirement for the order of execution of the key agreement step and the above steps S410 and S420, and it is sufficient to complete the key agreement before step S310.

[0068] Figure 5 is a flowchart of the implementation of the BA frame protection mechanism according to an embodiment of the present application. Figure 5 specifically illustrates an example in which the first STA is an STA, the second STA is an AP, and the BA frame is a Multi-STA BA frame, and includes the following steps:

[0069] (1) Scanning phase and authentication phase: These two phases are consistent with the traditional IEEE 802.11 process. They include the steps of an AP sending a beacon frame to a STA, the STA sending a probe request frame to the AP, and the AP returning a probe response frame to the STA. The above three steps are optional steps for a STA to discover APs in a wireless network. Furthermore, they also include the step of an authentication frame being sent between the STA and the AP to complete the authentication.

[0070] (2) Association Phase: In the association phase, the STA and the AP can each declare their own BA frame protection capabilities. In the example shown in Figure 5, the STA declares its support capability for the multi-STA BA frame protection mechanism to the AP when sending an association request. Then, the AP declares its support capability for the multi-STA BA frame protection mechanism to the STA when sending an association response.

[0071] (3) After association, when the AP needs to send a Multi-STA BA frame to a STA in the wireless network, the AP can protect the Multi-STA BA frame based on the capabilities declared by itself and the STA. For example, the AP encrypts the AID in the Multi-STA BA frame or generates a digest of the AID (for example, by using a hash algorithm to generate a digest of the AID). After receiving the protected Multi-STA BA frame, the STA uses the key to verify whether the protected AID sent by the AP matches its own AID. If there is a match, the content of this part of the Multi-STA BA frame, including the protected AID, is confirmed to be sent to the STA, and the STA can extract the content of this part for further processing.

[0072] Because a Multi-STA BA frame can contain information sent by an AP to multiple STAs, information corresponding to different STAs can carry the protected AID of the STA. After receiving the Multi-STA BA frame, a STA can compare its own AID with each protected AID in the Multi-STA BA frame to see if they match. If the comparison results in a match, the STA confirms that the information in this part of the Multi-STA BA frame carrying the protected AID belongs to the STA, and can extract and process this part of the information. For protected AIDs that do not match, the STA does not process the information in this part, since the part containing the protected AID does not belong to the STA (it may be something the AP needs to send to another STA).

[0073] In a wireless network, some STAs may have the capability to support the BA frame protection mechanism, while other STAs may not have the capability to support the BA frame protection mechanism (hereinafter referred to as BA frame protection capability). In this situation, when transmitting a multi-STA BA frame, the AP can protect the AIDs of the STAs that have the BA frame protection capability and carry the protected AIDs of the STAs in the multi-STA BA frame. At the same time, the AP does not protect the AIDs of the STAs that do not have the BA frame protection capability and carry the AIDs of the STAs in the multi-STA BA frame.

[0074] It should be noted that the present application does not limit the type of protection technique (including encryption and / or digest), as long as the corresponding key interaction is completed before transmitting the Multi-STA BA frame. Symmetric encryption algorithms and / or asymmetric encryption algorithms can be used, such as the Advanced Encryption Standard (AES) 128 algorithm, the AES 192 algorithm, the AES 256 algorithm, the Elliptic Curves Cryptography (ECC) p256 algorithm, the ECC p384 algorithm, etc. A message digest algorithm can also be used, such as a hash algorithm, a hash-based message authentication code (HMAC) algorithm, a cipher-block chaining-MAC (CBC-MAC) algorithm, or a Galois message authentication code (GMAC) algorithm. This differs from encryption-only methods in that the STA receiving the Multi-STA BA frame must use the same algorithm to calculate its own known information (e.g., its own AID, or its own AID and other information) and compare the generated digest information with each protected AID it receives. If the AIDs are the same, it indicates that the correlation information indicated by the protected AID is to be sent to the STA; if they are different, it is ignored. The present application may use the above encryption algorithm or message encryption algorithm to protect the AID, or may use an encryption algorithm and a message digest algorithm to protect the AID. For example, the AP first uses an encryption algorithm to encrypt the AID and generate a ciphertext of the AID, and then uses a message digest algorithm to calculate the AID and other information (or the ciphertext of the AID and other information) and generate digest information. The AP then carries the ciphertext of the AID, the digest information and the above other information in a Multi-STA BA frame and transmits it.After receiving the Multi-STA BA frame, the STA decrypts the ciphertext of the AID to obtain the plaintext of the AID, and then determines whether the plaintext of the AID matches its own AID, and uses the same message digest algorithm to calculate the same data (i.e., the AID and other information, or the ciphertext of the AID and other information) to generate digest information, and determines whether the digest information matches the received digest information. If the two determinations are consistent, the information indicated by the AID is identified as belonging to the STA. Because the message digest algorithm can prevent message tampering, compared to the embodiment using an encryption algorithm to protect the AID, the embodiment using a message digest algorithm to protect the AID or the embodiment using both an encryption algorithm and a message digest algorithm to protect the AID can prevent STAs from misidentifying the AID and attacks by attackers in the network.

[0075] Hereinafter, the communication method for realizing Multi-STA BA frame protection proposed in this application will be described in detail with reference to the drawings and specific embodiments.

[0076] As mentioned above, in the association stage, the present application allows the STA and the AP to declare their support capability for the multi-STA BA frame protection mechanism using Association Request and Association Response frames, respectively. In some embodiments, before the first STA receives the BA frame, the first STA further includes transmitting protection capability information for the BA frame of the first STA. Here, the first STA may be a non-AP STA (hereinafter abbreviated as STA). The first STA can transmit the protection capability information for the BA frame of the first STA to a second STA (e.g., AP). Specifically, the protection capability information for the BA frame of the first STA is carried in an Association Request frame and / or an Authentication frame transmitted by the first STA.

[0077] The manner in which the Association Request frame or the Authentication frame is employed to carry the protection capability information for the BA frame of the first STA can have at least the following manner.

[0078] Aspect 1:

[0079] The association request frame and / or the authentication frame may include an additional field for carrying protection capability information for the BA frame of the first STA. For example, the association request frame and / or the authentication frame may include a first protection capability information field, which includes the protection capability field of the first BA frame, and the protection capability field of the first BA frame may carry the protection capability information for the BA frame of the first STA.

[0080] Furthermore, the added first protection capability information field may further include at least one of a protection capability field of a first trigger frame (Trigger) and a protection capability field of a first Null Data Packet Announcement (NDPA), wherein:

[0081] A protection capability field of the first trigger frame may carry protection capability information for the trigger frame of the first STA;

[0082] The protection capability field of the first NDPA may carry protection capability information for the NDPA of the first STA.

[0083] Taking the example of carrying protection capability information for the BA frame of the first STA in an associated request frame, Figure 6 is a schematic diagram 1 of the structure of an associated request frame according to an embodiment of the present application. As shown in Figure 6, the associated request frame includes a MAC header, an added encryption capability information field (Encryption Capability Information Element field), and an FCS field. Here, the MAC header includes a Frame Control field (which may be 2 octets in length), a Duration field (which may be 2 octets in length), an Address 1 field (which may be 6 octets in length), an Address 2 field (which may be 6 octets in length), an Address 3 field (which may be 6 octets in length), a Sequence Control field, an HT Control field (which may be 0 or 4 octets in length), etc. The length of the added Encryption Capability Information Element field is variable, and it carries the protection capability information for the BA frame of the first STA. In the example of Figure 6, the protection capability mainly refers to encryption capability, and the associated protection capability field is also called the encryption capability field. The present application does not limit the specific manner of protection, and may include encryption and / or employing a message digest algorithm to generate digest information.

[0084] The added first protection capability information field may further include a first element indicator field, which carries a designated element indicator value, the value belonging to the reserved values ​​in the current element indicator value, for identifying the first protection capability information field, where the reserved value may refer to a reserved value in the published standard. For devices complying with the published standard, the reserved value belongs to the unprocessed value. Taking the Association Request frame shown in FIG. 6 as an example, the added Encryption Capability Information Element field may include an Element ID field (which may be one octet in length), a Length field (which may be one octet in length), and an Information field (the length is configurable). Here, the Element ID field carries an element indicator value belonging to the currently reserved values, for example, any value among 2, 4, 8, 9, 17-31, 47, 49, 77, 103, 128-129, 133-136, 149-150, 155-156, 165, 173, 176, 178-180, 203, 218-219, 227, 238, 243, 245-254, and is used to indicate that the field to which the Element ID field belongs is the Encryption Capability Information Element field to be added.

[0085] As shown in FIG. 6, the Information field of the Encryption Capability Information Element field may include a Multi-STA BA Frame Encryption Capability (Multi-STA BA Encryption Enabled) field (which may be 1 bit in length) for carrying protection capability information for the first STA's Multi-STA BA frame, and may further include a Trigger Frame Encryption Enabled field and / or an NDPA Encryption Enabled field for carrying protection capability information for the first STA's trigger frame and protection capability information for the NDPA. Note that, although the Information field shown in FIG. 6 includes the above three types of capability fields, the present application is not limited thereto, and the Information field may include one or more of the above three types of capability fields for carrying corresponding protection capability information.

[0086] Aspect 2:

[0087] The association request frame and / or the authentication frame may include a field for carrying protection capability information for the BA frame of the first STA. For example, the association request frame and / or the authentication frame may include a first protection capability information field, which includes the protection capability field of the first BA frame, and the protection capability field of the first BA frame may carry the protection capability information for the BA frame of the first STA.

[0088] Furthermore, the added first protection capability information field may further include at least one of a protection capability field of a first trigger frame (Trigger) and a protection capability field of a first null data packet announcement (NDPA), wherein:

[0089] A protection capability field of the first trigger frame may carry protection capability information for the trigger frame of the first STA;

[0090] The protection capability field of the first NDPA may carry protection capability information for the NDPA of the first STA.

[0091] Taking the example of carrying protection capability information for the BA frame of the first STA in an associated request frame, Figure 7 is a structural diagram of another associated request frame according to an embodiment of the present application. As shown in Figure 7, the associated request frame includes a MAC header, an added encryption capability information field (Encryption Capability Information Element field), and an FCS field. Here, the MAC header includes a Frame Control field (which may be 2 octets in length), a Duration field (which may be 2 octets in length), an Address 1 field (which may be 6 octets in length), an Address 2 field (which may be 6 octets in length), an Address 3 field (which may be 6 octets in length), a Sequence Control field, an HT Control field (which may be 0 or 4 octets in length), etc. The length of the added Encryption Capability Information Element field is variable, and it carries the protection capability information for the BA frame of the first STA. In the example of Figure 7, the protection capability mainly refers to the encryption capability, and the associated protection capability field is also called the encryption capability field. The present application does not limit the specific manner of protection, and may include encryption and / or employing a message digest algorithm to generate digest information.

[0092] The added first protection capability information field may further include a second element indicator field and a first element indicator extension field.

[0093] As an option, the value of the second element indicator field is 255, and the first element indicator extension field carries a first element extension indicator value for identifying the first protection capability information field, which may be an element extension indicator value belonging to the currently reserved values. Taking the Association Request frame shown in Figure 7 as an example, the added Encryption Capability Information Element field may include an Element ID field (which may be 1 octet in length), a Length field (which may be 1 octet in length), an Element ID Extension field (which may be 1 octet in length), and an Information field (the length is variable). Here, the Element ID field takes the value 255, and the Element ID Extension field carries an element extension indicator value whose purpose is to belong to reserved values, such as 0, 32, 35-39, 41-43, 45-51, 55, 57-87, or 94-255, and is used to indicate that the field to which the Element ID field and the Element ID Extension field belong is the Encryption Capability Information Element field to be added.

[0094] The Information field in the Encryption Capability Information Element field in FIG. 7 is the same as the Information field in FIG. 6, and a detailed description thereof will be omitted here.

[0095] Aspect 3:

[0096] An existing Extended Capability Element in the Associated Request frame and / or the Authentication frame is added with a field for carrying protection capability information for the BA frame of the first STA. For example, the Associated Request frame and / or the Associated Authentication frame includes a first Extended Capability Element, the first Extended Capability Element references the protection capability field of the second BA frame, and the protection capability field of the second BA frame carries the protection capability information for the BA frame of the first STA.

[0097] Furthermore, another field is added to the existing extended capability element to carry the first STA's protection capability for the trigger frame and / or the protection capability for the NDPA, for example, the first extended capability element further includes at least one of a second trigger frame protection capability field and a second NDPA protection capability field, where:

[0098] a protection capability field of the second trigger frame carrying protection capability information for the trigger frame of the first STA;

[0099] The protection capability field of the second NDPA carries protection capability information for the NDPA of the first STA.

[0100] In one option, the protection capabilities field of the second BA frame, the protection capabilities field of the second trigger frame, or the protection capabilities field of the second NDPA occupies a first position of the first extended capabilities field.

[0101] As an option, the first extended capability field may further include a third element indicator field for identifying the first extended capability field.

[0102] Taking the example of carrying protection capability information for the first STA's BA frame in an associated request frame, FIG. 8 is a structural diagram of another associated request frame according to an embodiment of the present application. As shown in FIG. 8, the associated request frame includes a MAC header, an Extended Capability Element field, an x ​​field (Element x), a y field (Element y), etc. The length of the Extended Capability Element field is variable and may carry protection capability information for the first STA's BA frame, protection capability information for the first STA's trigger frame, and / or protection capability information for the first STA's NDPA. In the example of FIG. 8, protection capability mainly refers to encryption capability, and the associated protection capability field is also referred to as an encryption capability field. The present application does not limit the specific form of protection, and may include encryption and / or generating digest information using a message digest algorithm. As an option, the third element indicator field in the Extended Capability Element field (e.g., the Element ID field in FIG. 8) takes the value 127, and the Multi-STA BA Encryption Enabled field, the Trigger Encryption Enabled field, and the NDPA Encryption Enabled field carry the first STA's protection capability information for BA frames, protection capability information for trigger frames, and protection capability information for NDPA, respectively. These three fields can occupy any first position, such as B5, B35, B59, B76-B79, B83, B86, B88-Bn, or additional positions, and the first position can refer to a reserved position in the published standard. FIG. 8 takes the cases of B88, B89, and B90 as an example.Although the Extended Capability Element field shown in FIG. 8 includes the above three types of encryption capability fields, the present application is not limited to this, and the Extended Capability Element field may include one or more of the above three types of encryption capability fields to carry corresponding encryption capability information.

[0103] The above describes an embodiment in which a first STA (e.g., an STA) carries protection capability information for its BA frame in an association request frame and / or authentication frame. The present application can also adopt an association response frame or authentication frame carrying protection capability information for a second STA (e.g., an AP) BA frame. The specific frame structure can refer to the frame structure proposed in the above three embodiments. That is, to carry the AP's protection capability information, the Association Request frame in the above three embodiments is replaced with an Association Response frame. The specific frame structure is the same as the frame structure shown in Figures 6-8 above, and a detailed description thereof will be omitted here.

[0104] After the STA and the AP mutually declare their capabilities and agree on a key, the AP delivers the first information and the privacy-protected correlation information to the STA. BA frame wherein the first information is for identifying privacy-protected correlation information.

[0105] Alternatively, the BA frame may include a BA information field,

[0106] the BA information field includes at least one first protected field;

[0107] the first protected field includes a first Per AID TID Info field;

[0108] The first Per AID TID Info field carries the first information and the correlation information of the privacy to be protected.

[0109] The first information includes encryption algorithm information and / or message digest algorithm information,

[0110] the length of the privacy correlation information to be protected;

[0111] first instruction information, The first indication information is for indicating whether the first protection field includes a second Per AID TID Info field.

[0112] Here, the second Per AID TID Info field carries at least one of a BA bitmap (Block Ack Bitmap), an acknowledgment type (Ack Type), and a TID. The second Per AID TID Info field may refer to the Per AID TID Info field included in the BA information field of the existing Multi-STA BA frame.

[0113] When an AP uses a BA frame for protection, it must consider the compatibility of the BA frame with legacy stations (Legacy-STAs), i.e., devices that comply with published standards. This application mainly modifies the frame body portion of the BA frame. Taking a Multi-STA BA frame as an example, this application designs a specific frame format after protecting a Multi-STA BA frame. As shown in FIG. 9, the protected Multi-STA BA frame includes a MAC header, a BA Control field, a Duration field, an RA field, a TA field, a BA Information field, an FCS field, etc. Here, the BA Information field includes one or more first protection fields, such as the New Per AID TID Info field in FIG. 9. The New Per AID TID Info field consists of two parts: a first Per AID TID Info field and a second Per AID TID Info field. For example, the first Per AID TID Info field may be the Per AID TID Encrypted Info field in FIG. 9, and the second Per AID TID Info field may be the Per AID TID Original Info field in FIG. 9. Here, the Per AID TID Encrypted Info field is used to carry the AID to be protected, and the Per AID TID Original Info is used to carry the Block Ack Starting Sequence Control and Block Ack Bitmap information in the original Per AID TID field. A specific design of the position in the frame and the frame format of the Per AID TID Encrypted Info and Per AID TID Original Info is shown in FIG. 9.

[0114] As an option, the first Per AID TID Info field includes a protection information field and a protected AID field, where:

[0115] The protection information field carries encryption algorithm information and / or message digest algorithm information;

[0116] The protected AID field carries the privacy-protected correlation information.

[0117] Additionally, the first Per AID TID Info field may further include a Block Acknowledgment Start Sequence Control field, which is used to indicate the sum of the length of the Protection Information field and the length of the AID field being protected.

[0118] As an option, the information protection field included in the first Per AID TID Info field can be included in the first AID TID information field of the first Per AID TID Info field, and in this case, the block acknowledgement start sequence control field included in the first Per AID TID Info field is used to indicate the length of the AID field to be protected.

[0119] To identify the first and second Per AID TID Info fields, the first Per AID TID Info field in this application can carry a first AID value, which is used to identify the first Per AID TID Info field, where the first AID value belongs to the reserved AID values ​​in the published standard, and for devices that comply with the published standard, the reserved AID value belongs to the unprocessed values. The second Per AID TID Info field in this application can carry a second AID value, which is used to identify the second Per AID TID Info field, where the second AID value belongs to the reserved AID values ​​in the published standard, and for devices that comply with the published standard, the reserved AID value belongs to the unprocessed values. The second AID value may be the same as or different from the first AID value.

[0120] Taking the frame format shown in FIG. 9 as an example, the first Per AID TID Info field (i.e., the AID11 field in the Per AID TID Encrypted Info field) in the first Per AID TID Info field (i.e., the Per AID TID Encrypted Info field in FIG. 9) carries a first AID value, for example, 2038, 2039, 2047, or any value between 2008 and 2044, which is used to indicate that the Per AID TID Info field is a Per AID TID Encrypted Info field. The Per AID TID Encrypted Info field includes four parts: an AID TID Info field, a Block Ack Starting Sequence Control field, an Encryption Information field, and an Encrypted AID field. Since the Encryption Information field and the Encrypted AID field occupy the position of the Block Ack Bitmap field in the original Per AID TID Info field, the Block Ack Starting Sequence Control field can indicate the sum of the lengths of the Encryption Information field and the Encrypted AID field. For example, when encryption protection is performed on an AID, the Encryption Information field can carry an encryption method, an encryption length, and / or an Origin BA Info indicator. The Origin BA Info indicator can indicate whether a Per AID TID Original Info field is included after the Per AID TID Encrypted Info field.The Encrypted AID field may include an Encrypted Contents field, which is used to carry the ciphertext that encrypts the AID, and may further include a Padding field.

[0121] A STA capable of protecting BA frames can read the AID TID Info field in the Per AID TID Info field and find that the AID TID Info field carries a first AID value, thereby confirming that the Per AID TID Info field is a Per AID TID Encrypted Info field. Then, the STA determines whether the protected AID carried in the Per AID TID Encrypted Info field matches its own AID.

[0122] A Legacy-STA that does not have the ability to protect against BA frames will read the AID TID Info field in the Per AID TID Info field and find that the first AID value carried by the AID TID Info field does not correspond to a valid AID within the range of 1-2007, indicating that the Per AID TID Info field is not information that the Legacy-STA can process. Therefore, the Legacy-STA will ignore the subsequent corresponding information (i.e., the information in the Encryption Information field and Encrypted AID field) according to the length indicated in the Block Ack Starting Sequence Control.

[0123] The sum of the lengths of the Encryption Information and Encrypted AID fields should be selected appropriately (as indicated in the Block Ack Starting Sequence Control field) according to the output length requirements of the encryption algorithm. The sum of the lengths of the Encryption Information and Encrypted AID fields may be 4, 8, 16, 32, 64, or 128 octets. For example, if the Encryption Information field is 2 octets long, the Encrypted AID field may be 2, 6, 14, 30, 62, or 126 octets long. When the AES128 encryption algorithm is used, the ciphertext length is an integer multiple of 128 bits (i.e., 16 octets). Therefore, the minimum length of the Encrypted Contents field (i.e., A in FIG. 9) carrying the ciphertext is 16 octets. To satisfy the length requirement of the Encrypted AID field, a padding field (i.e., B in FIG. 9) of 14 octets may be used. Accordingly, the receiving terminal can determine the length of the Encrypted Contents by the Encryption Method and / or Encryption Length in the Encryption Information, and therefore can ignore the Padding field.

[0124] The AP then uses a second AID (e.g., 2038, 2039, 2047, or any value between 2008 and 2044) to indicate that the following Per AID TID Info field is a Per AID TID Original Info field, which includes the Block Ack Starting Sequence Control field and Block Ack Bitmap field in the original Per AID TID Info field.

[0125] After a STA capable of protecting BA frames determines that the protected AID in the Per AID TID Encrypted Info field matches its own AID, it reads the AID TID Info field in the following Per AID TID Info field. If the AID TID Info field contains a second AID value, the STA can confirm that the Per AID TID Info field is a Per AID TID Original Info field, and can read the information in the Per AID TID Original Info field.

[0126] If a Legacy-STA that does not have protection capabilities for BA frames reads the AID TID Info field in the Per AID TID Original Info field and finds that the second AID value carried by the AID TID Info field does not correspond to a valid AID within the 1-2007 range, the Legacy-STA will ignore the subsequent corresponding information (i.e., the information in the Block Ack Bitmap field) according to the length indicated in the Block Ack Starting Sequence Control.

[0127] The first AID value and the second AID value may be the same or different. If the first AID value and the second AID value are different, the STA receiving the Multi-STA BA frame can thereby distinguish between the Per AID TID Encrypted Info field and the Per AID TID Original Info field. If the first AID value and the second AID value are the same, when the STA receiving the Multi-STA BA frame identifies the first Per AID TID Info field carrying a reserved AID value, it determines that the Per AID TID Info field is a Per AID TID Encrypted Info field, and uses the first indication information (e.g., Origin BA Info indication bit information) in the Per AID TID Encrypted Info field to determine whether the next Per AID TID Info field carrying the same reserved AID value is a Per AID TID Original Info field. For example, when the Origin BA Info indication bit is set to 1, it indicates that the next Per AID TID Info field carrying the same reserved AID value is a Per AID TID Original Info field, and when the Origin BA Info indication bit is set to 0, it indicates that the next Per AID TID Info field carrying the same reserved AID value is not a Per AID TID Original Info field but a Per AID TID Encrypted Info field corresponding to another STA. Alternatively, when the Origin BA Info indication bit is set to 0, it indicates that the next Per AID TID Info field carrying the same reserved AID value is a Per AID TID Original Info field, and when the Origin BA Info indication bit is set to 1, it indicates that the next Per AID TID Info field carrying the same reserved AID value is not a Per AID TID Original Info field but a Per AID TID Encrypted Info field corresponding to another STA.When the STA confirms that the next Per AID TID Info field carrying the same reserved AID value is a Per AID TID Original Info field, it extracts the information in the Per AID TID Original Info field and performs subsequent processing.

[0128] 10 is a schematic diagram of another frame format of a Multi-STA BA frame after protection according to the present application. In FIG. 10, the value of the AID11 field in the Per AID TID Encrypted Info field is 2038, which is used to indicate that the field to which the AID11 field belongs is the Per AID TID Encrypted Info field, that is, it indicates that the following Encryption Information field carries the encryption method and the Encrypted AID field carries the protected AID (e.g., AID ciphertext). In FIG. 10, the value of the AID11 field in the Per AID TID Original Info field is 2039 (which may be different from the value of the AID11 field in the Per AID TID Encrypted Info field). This value is used to indicate that the field to which the AID11 field belongs is the Per AID TID Original Info field, i.e., it indicates that the subsequent Block Ack Starting Sequence Control and Block Ack Bitmap fields carry the Block Ack Starting Sequence Control and Block Ack Bitmap information in the original Per AID TID field.

[0129] Unlike the embodiment shown in Figure 9, in the embodiment shown in Figure 10, the Encryption Information field is included in the AID TID Info field (the Encryption Information field in Figure 9 is included in the Per AID TID Original Info field), occupying the positions of the existing Ack Type field and TID field in the AID TID Info field. Therefore, in the embodiment shown in Figure 10, the New Per AID TID Info field must include the Per AID TID Original Info field, and the Per AID TID Original Info field includes the Ack Type field and the TID field. Because the New Per AID TID Info field must include the Per AID TID Original Info field, there is no need to include an Origin BA Info indication in the Encryption Information field.

[0130] The other fields in the frame format shown in FIG. 10 are the same as the corresponding fields in FIG. 9, and the receiving processing mechanism is also the same as the receiving mechanism in the example of FIG. 9, so detailed description will be omitted here.

[0131] 11 is a schematic diagram of another frame format of a Multi-STA BA frame after protection according to the present application. In FIG. 11, the value of the AID11 field in the Per AID TID Encrypted Info field is 2038 (or 2047 or any value between 2008 and 2044) and is used to indicate that the field to which the AID11 field belongs is the Per AID TID Encrypted Info field, i.e., indicates that the following Encryption Information field carries the encryption method and the Encrypted AID field carries the protected AID (e.g., AID ciphertext). In FIG. 11, the value of the AID11 field in the Per AID TID Original Info field is 2038 (or any value between 2047 and 2008, which is the same value as the value of the AID11 field in the Per AID TID Encrypted Info field).

[0132] 10, in the embodiment shown in FIG. 11, the Encryption Information field is included in the AID TID Info field and occupies the positions of the existing Ack Type and TID fields in the AID TID Info field, so the New Per AID TID Info field must include the Per AID TID Original Info field, which in turn includes the Ack Type and TID fields. Because the New Per AID TID Info field must include the Per AID TID Original Info field, there is no need to include an Origin BA Info indication in the Encryption Information field.

[0133] The other fields in the frame format shown in FIG. 11 are the same as the corresponding fields in FIG. 9, and therefore will not be described in detail here.

[0134] After receiving a protected Multi-STA BA frame, if the receiving terminal determines that the value of AID11 in a Per AID TID Info field in the BA Information is a reserved AID value (e.g., 2038), it can determine that the Per AID TID Info field is a Per AID TID Encrypted Info field. If the value of AID11 in the Per AID TID Info field next to the Per AID TID Encrypted Info field is the same value (e.g., 2038), it can determine that the Per AID TID Info field is a Per AID TID Original Info field, and the Per AID TID Encrypted Info field and the Per AID TID Original Info field constitute a New Per AID TID Info field corresponding to one STA. The other contents of the receiving processing mechanism are the same as the receiving mechanism in the example of Figure 9, so detailed description will be omitted here.

[0135] 12 is a schematic diagram of another frame format of a Multi-STA BA frame after protection according to the present application. In FIG. 12, the value of the AID11 field under the Per AID TID Encrypted Info field is 2038 (or 2047 or any value between 2008 and 2044), which is used to indicate that the field to which the AID11 field belongs is the Per AID TID Encrypted Info field, and indicates that the following Encryption Info carries the encryption method and / or ciphertext length, and that the Encrypted AID carries the AID ciphertext.

[0136] The value of the AID11 field under the Per AID TID Original Info field is 2039 (or any value between 2047 or 2008 and 2044, as long as it is different from the value of the AID11 field under the Per AID TID Encrypted Info field), and is used to indicate that the field to which the AID11 field belongs is the Per AID TID Original Info field, and indicates that the subsequent Block Ack Starting Sequence Control and Block Ack Bitmap fields are the Block Ack Starting Sequence Control and Block Ack Bitmap information in the original Per AID TID field.

[0137] In the example of Figure 12, the Encryption Information field includes an Encryption Method field, an Encryption Length field, and a Reserve field, and the lengths of the three fields may be 3 bits, 8 bits, and 5 bits, respectively, where the Encryption Method field is used to carry the algorithm information of the encryption algorithm or message digest, and the Encryption Length field is used to carry the length of the AID to be protected.

[0138] In this embodiment, the receiving process mechanism is the same as the receiving mechanism in the example of FIG. 9, so a detailed description will be omitted here.

[0139] 13 is a schematic diagram of another frame format of a Multi-STA BA frame after protection according to the present application. In FIG. 13, the value of the AID11 field in the Per AID TID Encrypted Info field is 2038 (or 2039, 2047, or any value between 2008 and 2044), which is used to indicate that the field to which the AID11 field belongs is the Per AID TID Encrypted Info field, i.e., indicates that the following Encryption Information field carries the encryption method and the Encrypted AID field carries the protected AID (e.g., AID ciphertext). In FIG. 12, the value of the AID11 field in the Per AID TID Original Info field is 2038 (or any value between 2039, 2047, or 2008 and 2044, the same value as the value of the AID11 field in the Per AID TID Encrypted Info field).

[0140] The example shown in Figure 13 is similar to the example shown in Figure 12, but differs in that the value of the AID11 field in the Per AID TID Original Info field is the same as the value of the AID11 field in the Per AID TID Encrypted Info field, and therefore the field following the Per AID TID Encrypted Info field indicates whether it is a Per AID TID Original Info field, and therefore an Origin BA Info indicator bit can be added to the Per AID TID Encrypted Info field. As shown in Figure 13, the Encryption Information field includes an Encryption Method field and / or an Encryption Length field, and further includes an Origin BA Info field, which is used to carry the Origin BA Info indicator bit. The Encrypted AID field carries the AID to be protected (e.g., AID ciphertext). For example, when the Origin BA Info indication bit is set to 0, it indicates that the next Per AID TID Info field carrying the same reserved AID value is a Per AID TID Original Info field, and when the Origin BA Info indication bit is set to 1, it indicates that the next Per AID TID Info field carrying the same reserved AID value is not a Per AID TID Original Info field but a Per AID TID Encrypted Info field corresponding to another STA.Alternatively, when the Origin BA Info indication bit is set to 1, it indicates that the next Per AID TID Info field carrying the same reserved AID value is a Per AID TID Original Info field, and when the Origin BA Info indication bit is set to 0, it indicates that the next Per AID TID Info field carrying the same reserved AID value is not a Per AID TID Original Info field but a Per AID TID Encrypted Info field corresponding to another STA.

[0141] The other fields in the frame format shown in FIG. 13 are the same as the corresponding fields in FIG. 12, and the receiving processing mechanism is also the same as the receiving mechanism in the example of FIG. 9, so detailed explanations will be omitted here.

[0142] The above describes the frame structures of several types of protected Multi-STA BA frames. In the protected Multi-STA BA frame, the AID is protected by encryption or a message digest algorithm, and the STA that receives the protected Multi-STA BA frame can determine whether the AID in the frame matches its own AID.

[0143] For example, if the first STA further carries a first AID value in a Per AID TID Info field in the BA frame after receiving the BA frame, the first STA extracts correlation information between the first information and the privacy to be protected from the Per AID TID Info field in which the first AID value is carried (e.g., the Per AID TID Encrypted Info field);

[0144] The first STA identifies the correlation information of the privacy to be protected based on the first information.

[0145] The above protection manner may include encrypting the AID, or using a message digest algorithm to perform calculations on the AID, or using a message digest algorithm to perform calculations on the AID and other information, or using a message digest algorithm to perform calculations on the ciphertext of the AID, or using a message digest algorithm to perform calculations on the ciphertext of the AID and other information, or using two or more of the above manners to protect the AID. Accordingly, the STA that receives the BA frame decrypts the AID ciphertext or uses the same message digest algorithm to perform calculations to determine whether the received AID is consistent with its own AID.

[0146] For example, the first STA may identify correlation information of privacy to be protected based on the first information by:

[0147] The first STA uses the encryption algorithm information in the first information to decrypt the protected privacy correlation information to obtain a plaintext of the privacy correlation information;

[0148] The first STA compares the plaintext of the privacy correlation information with its own privacy correlation information, and if the comparison result is a match, confirms that the Per AID TID Info field carrying the first AID value is the first Per AID TID Info field corresponding to the first STA;

[0149] and / or the first STA adopts the encryption algorithm information and / or message digest algorithm information in the first information to process its own privacy correlation information, compares the processing result with the protected privacy correlation information, and if the comparison result is consistent, verifies that the Per AID TID Info field carrying the first AID value is the first Per AID TID Info field corresponding to the first STA; Includes.

[0150] Furthermore, if a second AID value is carried in the Per AID TID Info field next to the first Per AID TID Info field corresponding to the first STA, the STA reads BA bitmap information from the next Per AID TID Info field. In this case, the first AID value and the second AID value can be different so that the STA can identify whether a Per AID TID Info field is a Per AID TID Encrypted Info field or a Per AID TID Original Info field based on the first AID value and the second AID value.

[0151] Alternatively, the present embodiment may further include identifying first indication information (e.g., the Origin BA Info indication bit) in a first Per AID TID Info field corresponding to a first STA, and if the first indication information indicates that a next Per AID TID Info field is a second Per AID TID Info field corresponding to the first STA, reading BA bitmap information from the second Per AID TID Info field corresponding to the first STA. In this case, the first AID value and the second AID value may be the same value.

[0152] When the AP protects the AID, if it adopts a mode of performing information digest calculation on the AID and other information, when the STA receives a BA frame, it can use the same message digest algorithm to calculate its own AID and the above-mentioned other information, and determine whether the calculation result matches the received result, thereby determining whether the protected AID is its own AID.

[0153] For example, the first STA may extract second information from the Per AID TID Info field following the Per AID TID Info field carrying the first AID value (e.g., the Per AID TID Encrypted Info field), and the second information may include at least one of the BA bitmap, the acknowledgement type, and the TID (e.g., information contained in the Per AID TID Original Info field).

[0154] The first STA uses the message digest algorithm information in the first information to process its own privacy correlation information and the above-mentioned second information, compares the processing result with the protected privacy correlation information, and if the comparison result is a match, confirms that the above-mentioned Per AID TID Info field carrying the first AID value is the first Per AID TID Info field corresponding to the first STA (for example, the above-mentioned Per AID TID Encrypted Info field).

[0155] Because a message digest algorithm is used to calculate the information contained in the AID and Per AID TID Original Info fields, when the AP sends a protected Multi-STA BA frame to the STA, it must contain multiple New Per AID TID Info fields, and each New Per AID TID Info field must contain a Per AID TID Encrypted Info field and a Per AID TID Original Info field. Because the Per AID TID Original Info field must be included, the Per AID TID Encrypted Info field does not need to carry the Origin BA Info indication bit.

[0156] Since a Legacy-STA does not have protection capabilities, after receiving a protected Multi-STA BA frame, it can ignore the information corresponding to the Per AID TID Info field indicated by the reserved AID value therein.

[0157] For example, the present embodiment may further include, when a first AID value or a second AID value is carried in a Per AID TID Info field in a BA frame, the first STA ignores the Per AID TID Info field in which the first AID value or the second AID value is carried.

[0158] That is, when a Legacy-STA finds that the Per AID TID Info field in a received BA frame carries a first AID value, it can confirm that the Per AID TID Info field is the Per AID TID Encrypted Info field, and when it finds that the Per AID TID Info field in a received BA frame carries a second AID value, it can confirm that the Per AID TID Info field is the Per AID TID Original Info field. Because a Legacy-STA does not support protection and cannot identify the AID in the Per AID TID Encrypted Info field, it ignores the information in the Per AID TID Encrypted Info field indicated by the first AID value and also ignores the following Per AID TID Original Info field.

[0159] Since some encryption algorithms have certain requirements for the length of the plaintext to be encrypted and certain requirements for the length of some fields in the BA frame, when encrypting the AID, the present application may perform operations such as padding certain data to meet the encryption length requirements and field length requirements.

[0160] Accordingly, the first STA adopts the encryption algorithm information in the first information to decrypt the protected privacy correlation information, and obtains the plaintext of the privacy correlation information.

[0161] The first STA verifies a valid ciphertext in the privacy-protected correlation information according to the encryption algorithm information in the first information;

[0162] The valid ciphertext is decrypted to obtain plaintext information.

[0163] The method may further include extracting effective plaintext from the plaintext information to obtain plaintext of privacy-related information.

[0164] For example, when encrypting a Multi-STA BA frame, the AP must consider the input data length requirements of the encryption algorithm, and may need to pad the input data using Padding (data padding) or Tweak (randomly disturbed data, increasing protection for the ciphertext). At the same time, to ensure compatibility with Legacy STAs, there may be a need to pad the ciphertext as well. When decrypting, the STA calculates the end position of the ciphertext according to the encryption mode and ignores the corresponding Padding and Tweak fields. Figure 14 is a schematic diagram of an implementation of encryption or decryption for a Multi-STA BA frame according to the present application.

[0165] 14 takes the AES128 encryption algorithm as an example to pad and / or tweak the Multi-STA BA frame. For an AP, the AID original text field (11 bits) of the Multi-STA BA frame is less than an integer multiple of 16 octets. First, incremental padding and / or random tweaks are performed on the original text to make it 16 octets, and then the AES128 encryption algorithm is used for encryption. To ensure compatibility between the Multi-STA BA frame and Legacy-STA, the length must also be padded to 30 octets (possible length values ​​are 2, 6, 14, 30, 62, and 126).

[0166] For the receiving STA, the processing steps are:

[0167] (1) Check the effective ciphertext field length: Because padding may exist in the received Encrypted AID field, after checking the total length of the Encryption Info and Encrypted AID using Block Ack Starting Sequence Control, it is also necessary to check the effective ciphertext length in the Encrypted AID field. For example, the Encryption Method in the Encryption Information field can be used to confirm that the encryption method is the AES128 algorithm, and therefore the length of the encrypted ciphertext is 16 octets. Therefore, the STA extracts the first 16 octets of ciphertext information from the Encrypted AID field, ignores the last 14 octets of padding, and then uses the key to decrypt the ciphertext and obtain the decrypted plaintext.

[0168] (2) Extracting valid plaintext information: After step (1), the decrypted plaintext contains padding or scrambling fields (Padding and Tweak fields), so the STA needs to extract the valid plaintext information. The extraction method is to identify the frame as a Multi-STA BA frame by checking the Type or SubType field in the MAC header, and determine that the encrypted data is an AID (11 bits in length). Since the Padding and Tweak fields are located at the end in Figure 14, the first 11 bits of the decrypted plaintext can be extracted as the valid AID, and the last 117 bits can be ignored.

[0169] Note that Figure 14 illustrates an example in which the Padding and Tweak fields are placed after the AID plaintext, but the Padding and Tweak fields can also be placed before the AID plaintext or at other positions, as long as they are uniformly agreed upon in the specific implementation, and the present application does not limit this.

[0170] In the embodiment of the present application, the BA frame carries the privacy correlation information to be protected and also carries first information for identifying the privacy correlation information to be protected, thereby protecting the privacy correlation information during the transport process and thereby strengthening privacy protection.

[0171] This application also provides another communication method, which can be applied to the system shown in Figure 1 as an option, but is not limited to this. Figure 15 is a flowchart illustrating another communication method according to an embodiment of this application, which includes at least a part of the following content:

[0172] S1510: A second STA transmits a BA frame, the BA frame carrying first information and correlation information of the privacy to be protected, and the first information is for identifying the correlation information of the privacy to be protected.

[0173] As an option, the BA frame includes a Multi-STA BA frame.

[0174] As an option, the privacy-related information includes AID information.

[0175] Alternatively, the BA frame may include a BA information field,

[0176] the BA information field includes at least one first protected field;

[0177] the first protected field includes a first Per AID TID Info field;

[0178] The first Per AID TID Info field carries the first information and the correlation information of the privacy to be protected.

[0179] As one option, the first information above is: encryption algorithm information and / or message digest algorithm information,

[0180] the length of the privacy correlation information to be protected;

[0181] first indication information for indicating whether the first protected field includes a second Per AID TID Info field; It includes at least one item of the above.

[0182] As an option, the second Per AID TID Info field carries at least one of a BA bitmap, an acknowledgement type Ack Type, and a TID.

[0183] As an option, the first Per AID TID Info field includes a protection information field and a protected AID field, where:

[0184] The protection information field carries encryption algorithm information and / or message digest algorithm information;

[0185] The protected AID field carries the privacy-protected correlation information.

[0186] Optionally, the first Per AID TID Info field further includes a block acknowledgement start sequence control field to indicate the length of the protection information field plus the length of the protected AID field.

[0187] As an option, the first Per AID TID Info field includes a protection information field, which includes:

[0188] The first Per AID TID Info field includes a first AID TID information field, and the first AID TID information field includes a protection information field.

[0189] Optionally, the first Per AID TID Info field further includes a Block Acknowledgement Start Sequence Control field to indicate the length of the AID field to be protected.

[0190] As an option, the first Per AID TID Info field carries a first AID value for labeling the first Per AID TID Info field.

[0191] Optionally, the second Per AID TID Info field carries a second AID value for labeling the second Per AID TID Info field.

[0192] Optionally, the second AID value is the same as or different from the first AID value.

[0193] Optionally, the method further includes the second STA receiving protection capability information for the BA frame of the first STA.

[0194] As an option, the protection capability information for the BA frame of the first STA is carried in the Association Request frame and / or Authentication frame received by the second STA.

[0195] As one option, the above-mentioned associated request frame and / or authentication frame includes a first protection capability information field, the first protection capability information field includes the protection capability field of the first BA frame, and the protection capability field of the first BA frame carries protection capability information for the BA frame of the first STA.

[0196] As an option, the first protection capability information field further includes at least one of a protection capability field of a first trigger frame and a protection capability field of a first null data packet announcement NDPA, wherein:

[0197] a protection capability field of the first trigger frame carrying protection capability information for the trigger frame of the first STA;

[0198] The protection capability field of the first NDPA carries the protection capability information for the NDPA of the first STA.

[0199] As an option, the first protection capability information field further includes a first element indicator field.

[0200] Alternatively, the first element identifier field above carries the reserved element identifier.

[0201] As an option, the above first protection capability information field further includes a second element indicator field and a first element indicator extension field.

[0202] As an alternative, the second element indicator field above takes the value 255,

[0203] The first element indicator extension field carries the reserved element extension indicator.

[0204] As one option, the above-mentioned associated request frame and / or associated authentication frame includes a first extended capability field, the first extended capability field includes a protection capability field of the second BA frame, and the protection capability field of the second BA frame carries protection capability information for the BA frame of the first STA.

[0205] As an option, the first extended capability field further includes a third element indicator field.

[0206] As an option, the first extended capability field further includes at least one of a second trigger frame protection capability field and a second NDPA protection capability field, wherein:

[0207] a protection capability field of the second trigger frame carrying protection capability information for the trigger frame of the first STA;

[0208] The protection capability field of the second NDPA carries protection capability information for the NDPA of the first STA.

[0209] As an option, the protection capabilities field of the second BA frame, the protection capabilities field of the second trigger frame, or the protection capabilities field of the second NDPA occupies a reserved position in the first extended capabilities field.

[0210] As an option, the method further includes: the second STA transmitting protection capability information for the BA frame of the second STA.

[0211] As an option, the protection capability information for the BA frame of the second STA is carried in the association response frame and / or authentication frame sent by the second STA.

[0212] As one option, the above-mentioned associated response frame and / or authentication frame includes a second protection capability information field, the second protection capability information field includes a protection capability field of a third BA frame, and the protection capability field of the third BA frame carries protection capability information for the BA frame of the second STA.

[0213] As an option, the second protection capability information field further includes at least one of a third trigger frame protection capability field and a third NDPA protection capability field, wherein:

[0214] a protection capability field of the third trigger frame carrying protection capability information for the trigger frame of the second STA;

[0215] The protection capability field of the third NDPA carries protection capability information for the NDPA of the second STA.

[0216] As an option, the second protection capability information field further includes a fourth element indicator field.

[0217] Optionally, the fourth element indicator field carries a second element indicator value for identifying a second protection capabilities information field.

[0218] As an option, the above second protection capability information field further includes a fifth element indicator field and a second element indicator extension field.

[0219] Alternatively, the fifth element indicator field above may take the value 255,

[0220] The second element indicator extension field carries a second element extension indicator value for identifying the second protection capabilities information field.

[0221] As one option, the above-mentioned associated response frame and / or authentication frame includes a second extended capabilities field, which includes a protection capabilities field of a fourth BA frame, and the protection capabilities field of the fourth BA frame carries protection capabilities information for the BA frame of the second STA.

[0222] As an option, the second extended capability field further includes a sixth element indicator field.

[0223] As an option, the second extended capability field further includes at least one of a fourth trigger frame protection capability field and a fourth NDPA protection capability field, wherein:

[0224] a protection capability field of the fourth trigger frame carrying protection capability information for the trigger frame of the second STA;

[0225] The protection capability field of the fourth NDPA carries the protection capability information for the NDPA of the second STA.

[0226] As an option, the protection capability field of the fourth BA frame, the protection capability field of the fourth trigger frame, or the protection capability field of the fourth NDPA occupies the second position of the second extended capability field.

[0227] As an option, the second STA includes an access point AP.

[0228] Optionally, the method further includes the second STA performing key agreement with the first STA to generate a key.

[0229] In the embodiment of the present application, the BA frame carries the privacy correlation information to be protected and also carries first information for identifying the privacy correlation information to be protected, thereby protecting the privacy correlation information during the transport process and thereby strengthening privacy protection.

[0230] The present embodiment also provides an STA. FIG. 16 is a structural diagram of the STA according to the present embodiment;

[0231] The device includes a first receiving module 1610, which is used to receive a block acknowledgement BA frame, and the BA frame carries first information and correlation information of the privacy to be protected, and the first information is used to identify the correlation information of the privacy to be protected.

[0232] As an option, the BA frame includes a multi-station BA frame.

[0233] Optionally, the privacy correlation information includes an association identifier AID.

[0234] Alternatively, the BA frame may include a BA information field,

[0235] the BA information field includes at least one first protected field;

[0236] the first protected field includes a single first association identifier traffic identifier information (Per AID TID Info) field;

[0237] The first Per AID TID Info field carries the first information and the correlation information of the privacy to be protected.

[0238] As one option, the first information above is:

[0239] encryption algorithm information and / or message digest algorithm information,

[0240] the length of the privacy correlation information to be protected;

[0241] first instruction information; The first indication information is for indicating whether the first protection field includes a second Per AID TID Info field.

[0242] As an option, the second Per AID TID Info field carries at least one of a BA bitmap, an acknowledgement type Ack Type, and a TID.

[0243] As an option, the first Per AID TID Info field includes a protection information field and a protected AID field, where:

[0244] The protection information field carries encryption algorithm information and / or message digest algorithm information;

[0245] The protected AID field carries the privacy-protected correlation information.

[0246] Optionally, the first Per AID TID Info field further includes a block acknowledgement start sequence control field to indicate the length of the protection information field plus the length of the protected AID field.

[0247] As an option, the first Per AID TID Info field includes a protection information field, which includes:

[0248] The first Per AID TID Info field includes a first AID TID information field, and the first AID TID information field includes a protection information field.

[0249] Optionally, the first Per AID TID Info field further includes a Block Acknowledgement Start Sequence Control field to indicate the length of the AID field to be protected.

[0250] As an option, the first Per AID TID Info field carries a first AID value for labeling the first Per AID TID Info field.

[0251] Optionally, the second Per AID TID Info field carries a second AID value for labeling the second Per AID TID Info field.

[0252] Optionally, the second AID value is the same as or different from the first AID value.

[0253] As one option, the above-mentioned STA further includes a first identification module, which, when carrying the first AID value in the Per AID TID Info field in the BA frame, is used to extract correlation information between the first information and the privacy to be protected from the Per AID TID Info field carrying the first AID value, and to perform identification on the correlation information of the privacy to be protected based on the first information.

[0254] As an option, the first identification module 1610 is

[0255] Using the encryption algorithm information in the first information, the protected privacy correlation information is decrypted to obtain a plaintext of the privacy correlation information;

[0256] The plaintext of the privacy correlation information is compared with the first STA's own privacy correlation information, and if the comparison result is a match, it is used to confirm that the Per AID TID Info field carrying the first AID value is the first Per AID TID Info field corresponding to the first STA.

[0257] As an option, the first identification module 1610 is

[0258] The encryption algorithm information and / or message digest algorithm information in the first information is used to process the first STA's own privacy correlation information, and the processing result is compared with the privacy correlation information to be protected. If the comparison result is a match, the Per AID TID Info field carrying the first AID value is used to confirm that it is the first Per AID TID Info field corresponding to the first STA.

[0259] As an option, the above-mentioned STA further includes a first reading module, which is used to read BA bitmap information from the next Per AID TID Info field of the first Per AID TID Info field corresponding to the first STA when the next Per AID TID Info field carries a second AID value.

[0260] As one option, the above-mentioned STA further includes a second reading module, which identifies first indication information in the first Per AID TID Info field corresponding to the first STA, and if the first indication information indicates that the next Per AID TID Info field is the second Per AID TID Info field corresponding to the first STA, is used to read BA bitmap information from the second Per AID TID Info field corresponding to the first STA.

[0261] As an option, the first identification module 1610 can be used as follows:

[0262] extracting second information including at least one of a BA bitmap, an acknowledgment type, and a TID from a Per AID TID Info field next to the Per AID TID Info field carrying the first AID value;

[0263] The message digest algorithm information in the first information is used to process the first STA's own privacy correlation information and the second information, and the processing result is compared with the protected privacy correlation information. If the comparison result is a match, the Per AID TID Info field carrying the first AID value is used to confirm that it is the first Per AID TID Info field corresponding to the first STA.

[0264] As an option, the above STA further includes a third reading module, which is used to read BA bitmap information from the following Per AID TID Info field.

[0265] Optionally, the first identification module comprises:

[0266] Identifying a valid ciphertext in the privacy-protected correlation information according to the encryption algorithm information in the first information;

[0267] Decrypt the valid ciphertext to obtain the plaintext information,

[0268] It is used to extract effective plaintext from the plaintext information and obtain the plaintext of the privacy correlation information.

[0269] As one option, the above-mentioned STA further includes a second identification module, which is used to ignore the Per AID TID Info field carrying the first AID value or the second AID value when the Per AID TID Info field in the BA frame carries the first AID value or the second AID value.

[0270] As an option, the above STA further includes a first capability declaration module, which is used to transmit protection capability information for the BA frame of the first STA.

[0271] As an option, the protection capability information for the BA frame of the first STA is carried in the Association Request frame and / or Authentication frame sent by the first STA.

[0272] As one option, the above-mentioned associated request frame and / or authentication frame includes a first protection capability information field, the first protection capability information field includes the protection capability field of the first BA frame, and the protection capability field of the first BA frame carries protection capability information for the BA frame of the first STA.

[0273] As an option, the first protection capability information field further includes at least one of a protection capability field of a first trigger frame and a protection capability field of a first null data packet announcement NDPA, wherein:

[0274] a protection capability field of the first trigger frame carrying protection capability information for the trigger frame of the first STA;

[0275] The protection capability field of the first NDPA carries the protection capability information for the NDPA of the first STA.

[0276] As an option, the first protection capability information field further includes a first element indicator field.

[0277] As an option, the first element indicator field carries a first element indicator value for identifying the first protection capabilities information field.

[0278] As an option, the above first protection capability information field further includes a second element indicator field and a first element indicator extension field.

[0279] As an alternative, the second element indicator field above takes the value 255,

[0280] The first element indicator extension field carries a first element extension indicator value for identifying the first protection capabilities information field.

[0281] As one option, the above-mentioned associated request frame and / or associated authentication frame includes a first extended capability field, the first extended capability field includes a protection capability field of the second BA frame, and the protection capability field of the second BA frame carries protection capability information for the BA frame of the first STA.

[0282] As an option, the first extended capability field further includes a third element indicator field.

[0283] As an option, the first extended capability field further includes at least one of a second trigger frame protection capability field and a second NDPA protection capability field, wherein:

[0284] a protection capability field of the second trigger frame carrying protection capability information for the trigger frame of the first STA;

[0285] The protection capability field of the second NDPA carries protection capability information for the NDPA of the first STA.

[0286] As an option, the protection capabilities field of the second BA frame, the protection capabilities field of the second trigger frame or the protection capabilities field of the second NDPA occupies the first position of the first extended capabilities field.

[0287] As an option, the above STA further includes a second receiving module, which is used to receive protection capability information for the BA frame of the second STA.

[0288] As an option, the protection capability information for the BA frame of the second STA is carried in the association response frame and / or authentication frame received by the first STA.

[0289] As one option, the above-mentioned associated response frame and / or authentication frame includes a second protection capability information field, the second protection capability information field includes a protection capability field of a third BA frame, and the protection capability field of the third BA frame carries protection capability information for the BA frame of the second STA.

[0290] As an option, the second protection capability information field further includes at least one of a third trigger frame protection capability field and a third NDPA protection capability field, wherein:

[0291] a protection capability field of the third trigger frame carrying protection capability information for the trigger frame of the second STA;

[0292] The protection capability field of the third NDPA carries protection capability information for the NDPA of the second STA.

[0293] As an option, the second protection capability information field further includes a fourth element indicator field.

[0294] Optionally, the fourth element indicator field carries a second element indicator value for identifying a second protection capabilities information field.

[0295] As an option, the above second protection capability information field further includes a fifth element indicator field and a second element indicator extension field.

[0296] Alternatively, the fifth element indicator field above may take the value 255,

[0297] The second element indicator extension field carries a second element extension indicator value for identifying the second protection capabilities information field.

[0298] As one option, the above-mentioned associated response frame and / or authentication frame includes a second extended capabilities field, which includes a protection capabilities field of a fourth BA frame, and the protection capabilities field of the fourth BA frame carries protection capabilities information for the BA frame of the second STA.

[0299] As an option, the second extended capability field further includes a sixth element indicator field.

[0300] As an option, the second extended capability field further includes at least one of a fourth trigger frame protection capability field and a fourth NDPA protection capability field, wherein:

[0301] a protection capability field of the fourth trigger frame carrying protection capability information for the trigger frame of the second STA;

[0302] The protection capability field of the fourth NDPA carries the protection capability information for the NDPA of the second STA.

[0303] As an option, the protection capability field of the fourth BA frame, the protection capability field of the fourth trigger frame, or the protection capability field of the fourth NDPA occupies the second position of the second extended capability field.

[0304] As an option, the second STA includes an access point AP.

[0305] As an option, the STA further includes a first key agreement module, which is used to perform key agreement with the second STA and generate a key.

[0306] It should be understood that the above and other operations and / or functions of modules in the exemplary STA of the present application are each for implementing the corresponding flow of the first STA in method 200 of FIG. 2, and for the sake of brevity, detailed description will be omitted here.

[0307] The present embodiment also provides an STA. Figure 17 is a structural diagram of another STA according to the present embodiment;

[0308] The device includes a first transmitting module 1710, which is used to transmit a BA frame, and the BA frame carries first information and correlation information of the privacy to be protected, and the first information is used to identify the correlation information of the privacy to be protected.

[0309] As an option, the BA frame includes a multi-station BA frame.

[0310] As an option, the privacy correlation information includes association identifier AID information.

[0311] Alternatively, the BA frame may include a BA information field,

[0312] the BA information field includes at least one first protected field;

[0313] the first protected field includes a first Per AID TID Info field;

[0314] The first Per AID TID Info field carries the first information and the correlation information of the privacy to be protected.

[0315] As one option, the first information above is:

[0316] encryption algorithm information and / or message digest algorithm information,

[0317] the length of the privacy correlation information to be protected;

[0318] and first indication information, wherein the first indication information is for indicating whether the first protection field includes a second Per AID TID Info field.

[0319] As an option, the second Per AID TID Info field carries at least one of a BA bitmap, an acknowledgement type Ack Type, and a TID.

[0320] As an option, the first Per AID TID Info field includes a protection information field and a protected AID field, where:

[0321] The protection information field carries encryption algorithm information and / or message digest algorithm information;

[0322] The protected AID field carries the privacy-protected correlation information.

[0323] Optionally, the first Per AID TID Info field further includes a block acknowledgement start sequence control field to indicate the length of the protection information field plus the length of the protected AID field.

[0324] As an option, the first Per AID TID Info field includes a protection information field, which includes:

[0325] The first Per AID TID Info field includes a first AID TID information field, and the first AID TID information field includes a protection information field.

[0326] Optionally, the first Per AID TID Info field further includes a Block Acknowledgement Start Sequence Control field to indicate the length of the AID field to be protected.

[0327] As an option, the first Per AID TID Info field carries a first AID value for labeling the first Per AID TID Info field.

[0328] As an option, the second Per AID TID Info field described above carries a second AID value to label the second Per AID TID Info field.

[0329] Optionally, the second AID value is the same as or different from the first AID value.

[0330] As an option, the above STA further includes a third receiving module, which is used to receive protection capability information for the BA frame of the first STA.

[0331] As an option, the protection capability information for the BA frame of the first STA is carried in the associated request frame and / or authentication frame received by the third receiving module.

[0332] As one option, the above-mentioned associated request frame and / or authentication frame includes a first protection capability information field, the first protection capability information field includes the protection capability field of the first BA frame, and the protection capability field of the first BA frame carries protection capability information for the BA frame of the first STA.

[0333] As an option, the first protection capability information field further includes at least one of a protection capability field of a first trigger frame and a protection capability field of a first null data packet announcement NDPA, wherein:

[0334] a protection capability field of the first trigger frame carrying protection capability information for the trigger frame of the first STA;

[0335] The protection capability field of the first NDPA carries the protection capability information for the NDPA of the first STA.

[0336] As an option, the first protection capability information field further includes a first element indicator field.

[0337] As an option, the first element indicator field carries a first element indicator value for identifying the first protection capabilities information field.

[0338] As an option, the above first protection capability information field further includes a second element indicator field and a first element indicator extension field.

[0339] As an alternative, the second element indicator field above takes the value 255,

[0340] The first element indicator extension field carries a first element extension indicator value for identifying the first protection capabilities information field.

[0341] As one option, the above-mentioned associated request frame and / or associated authentication frame includes a first extended capability field, the first extended capability field includes a protection capability field of the second BA frame, and the protection capability field of the second BA frame carries protection capability information for the BA frame of the first STA.

[0342] As an option, the first extended capability field further includes a third element indicator field.

[0343] As an option, the first extended capability field further includes at least one of a second trigger frame protection capability field and a second NDPA protection capability field, wherein:

[0344] a protection capability field of the second trigger frame carrying protection capability information for the trigger frame of the first STA;

[0345] The protection capability field of the second NDPA carries protection capability information for the NDPA of the first STA.

[0346] As an option, the protection capabilities field of the second BA frame, the protection capabilities field of the second trigger frame or the protection capabilities field of the second NDPA occupies the first position of the first extended capabilities field.

[0347] As an option, the above STA further includes a second capability declaration module, which is used to transmit protection capability information for the STA's BA frame.

[0348] As an option, the protection capability information for the BA frame of the STA is carried in the associated response frame and / or authentication frame sent by the second capability declaration module.

[0349] As one option, the above-mentioned associated response frame and / or authentication frame includes a second protection capability information field, the second protection capability information field includes a protection capability field of a third BA frame, and the protection capability field of the third BA frame carries the protection capability information for the STA's BA frame.

[0350] As an option, the second protection capability information field further includes at least one of a third trigger frame protection capability field and a third NDPA protection capability field, wherein:

[0351] A protection capability field of the third trigger frame carries the protection capability information of the STA for the trigger frame;

[0352] The third NDPA protection capability field carries the STA's protection capability information for the NDPA.

[0353] As an option, the second protection capability information field further includes a fourth element indicator field.

[0354] Optionally, the fourth element indicator field carries a second element indicator value for identifying a second protection capabilities information field.

[0355] As an option, the above second protection capability information field further includes a fifth element indicator field and a second element indicator extension field.

[0356] Alternatively, the fifth element indicator field above may take the value 255,

[0357] The second element indicator extension field carries a second element extension indicator value for identifying the second protection capabilities information field.

[0358] As one option, the above-mentioned associated response frame and / or authentication frame includes a second extended capabilities field, which includes a protection capabilities field of a fourth BA frame, and the protection capabilities field of the fourth BA frame carries the STA's protection capabilities information for the BA frame.

[0359] As an option, the second extended capability field further includes a sixth element indicator field.

[0360] As an option, the second extended capability field further includes at least one of a fourth trigger frame protection capability field and a fourth NDPA protection capability field, wherein:

[0361] a protection capability field of the fourth trigger frame carrying protection capability information for the trigger frame of the STA;

[0362] The fourth NDPA protection capability field carries the protection capability information of the STA for the NDPA.

[0363] As an option, the protection capability field of the fourth BA frame, the protection capability field of the fourth trigger frame, or the protection capability field of the fourth NDPA occupies the second position of the second extended capability field.

[0364] As an option, the STA includes an access point AP.

[0365] As an option, the STA further includes a second key agreement module, which is used to perform key agreement with the first STA and generate a key.

[0366] It should be understood that the above and other operations and / or functions of the modules in the terminal device of the embodiment of the present application are each for realizing the corresponding flow of the second STA in method 1500 of FIG. 15, and for the sake of brevity, detailed description will be omitted here.

[0367] In addition, the functions described by each module (sub-module, unit, or component, etc.) in the STA 1600 and STA 1700 in the embodiments of the present application may be realized by different modules (sub-modules, units, or components, etc.) or by the same module (sub-module, unit, or component, etc.). For example, the first transmitting module and the second transmitting module may be different modules or the same module, both of which can realize corresponding functions in the embodiments of the present application. In addition, the transmitting module and the receiving module in the embodiments of the present application may be realized by a transceiver of the device, and part or all of each of the other modules may be realized by a processor of the device.

[0368] 18 is a schematic structural diagram of a communication device 1800 according to an embodiment of the present application. The communication device 1800 shown in FIG. 18 includes a processor 710, which can call and run a computer program from a memory to implement the method in the embodiment of the present application.

[0369] 18, the communication device 1800 may further include a memory 720. The processor 710 may call and run a computer program from the memory 720 to implement the method of the present invention.

[0370] Here, the memory 720 may be a separate component separate from the processor 710 or may be integrated within the processor 710.

[0371] As an option, as shown in FIG. 18, the communication device 1800 may further include a transceiver 730, and the processor 710 may control the transceiver 730 to communicate with other devices, specifically to transmit information or data to other devices or receive information or data transmitted from other devices.

[0372] Here, the transceiver 730 may include a transmitter and a receiver, and may further include an antenna, and the number of antennas may be one or more.

[0373] As an option, the communication device 1800 may be a STA of the embodiments of the present application, and the communication device 1800 may implement the corresponding flow implemented by the STA in each method of the embodiments of the present application, and for the sake of brevity, detailed description will be omitted here.

[0374] 19 is a schematic structural diagram of a chip 1900 according to an embodiment of the present application. The chip 1900 shown in FIG. 19 includes a processor 810, which can call and run a computer program from a memory to implement the method according to the embodiment of the present application.

[0375] 19, the chip 1900 may further include a memory 820. Here, the processor 810 may call and run a computer program from the memory 820 to implement the method of the embodiment of the present application.

[0376] Here, the memory 820 may be a separate component independent of the processor 810 or may be integrated into the processor 810.

[0377] As an option, the chip 1900 may further include an input interface 830. Here, the processor 810 may control the input interface 830 to communicate with other devices or chips, and specifically, may obtain information or data transmitted from other devices or chips.

[0378] Optionally, the chip 1900 may further include an output interface 840. Here, the processor 810 may control the output interface 840 to communicate with other devices or chips, specifically, to output information or data to other devices or chips.

[0379] As an option, the chip can be applied to the STA in the embodiments of the present application, and the chip can implement the corresponding flow implemented by the STA in each method of the embodiments of the present application, and for the sake of brevity, detailed description will be omitted here.

[0380] The chips mentioned in the embodiments of this application may also be called system level chips, system chips, chip systems, or system-on-chips.

[0381] The processor referred to above may be a general-purpose processor, a digital signal processor (DSP), a field programmable gate array (FPGA), an application specific integrated circuit (ASIC) or other programmable logic component, a transistor logic component, a discrete hardware component, etc. Here, the general-purpose processor referred to above may be a microprocessor, or any general processor, etc.

[0382] The memory mentioned above may be volatile or nonvolatile, or may include both volatile and nonvolatile memory. Here, the nonvolatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory may be random access memory (RAM).

[0383] It should be understood that the above memory is an exemplary illustration and not a limitation, and that, for example, the memory in the embodiments of the present application may be static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDR SDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (synch link DRAM, SLDRAM), and direct memory bus random access memory (Direct Rambus RAM, DR RAM), etc. That is, the memory in the embodiments of the present application is intended to include, but is not limited to, these and any other suitable types of memory.

[0384] The above embodiments may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented in software, they may be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed by a computer, they generate the flow or functionality described in whole or in part in the embodiments of the present application. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions may be stored on a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) methods. The computer-readable storage medium may be any available medium accessible by a computer, or may include a data storage device, such as a server or data center, integrated with one or more available media. The available media may be magnetic media (e.g., floppy disks, hard disks, tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid state disks (SSDs)).

[0385] In various embodiments of the present application, the order of the numbers of the above steps does not mean the order of execution. The order of execution of each step should be determined by its function and built-in logic, and it should be understood that this does not limit the implementation process of the embodiments of the present invention.

[0386] As can be clearly understood by those skilled in the art, for convenience and conciseness of explanation, the specific operating processes of the systems, devices and units described above can refer to the corresponding processes in the above method embodiments, and detailed explanations will be omitted here.

[0387] The above are merely specific embodiments of the present application, but the scope of protection of the present application is not limited thereto, and any changes or substitutions that can be easily conceived by anyone skilled in the art within the technical scope disclosed in the present application are included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. receiving a block acknowledgement (BA) frame from a first station (STA), the BA frame carrying first information and privacy-protected correlation information, the first information being used to identify the privacy-protected correlation information; The BA frame includes a BA information field; the BA information field includes at least one first protection field; the first protected field includes a first single association identifier traffic identifier information Per AID TID Info field; the first Per AID TID Info field carries correlation information between the first information and the protected privacy; Here, the first information is used to identify the correlation information of the privacy to be protected, When a Per AID TID Info field in the BA frame carries a first AID value, the first STA extracts the first information and the privacy-protected correlation information from the Per AID TID Info field carrying the first AID value; The first STA performs identification on the correlation information of the privacy to be protected based on the first information; Including, Communication method.

2. The BA frame includes a multi-station Multi-STA BA frame. The method of claim 1.

3. The first AID value ranges from 2008 to 2044 to indicate that the Per AID TID Info field is a Per AID TID Encrypted Info field. The method of claim 1.

4. The first information is encryption algorithm information and / or message digest algorithm information; the length of the privacy correlation information to be protected; and The method of claim 1.

5. the first Per AID TID Info field carries a first AID value, and the first AID value is used to identify the first Per AID TID Info field; The method of claim 1.

6. The first STA performing identification on the correlation information of the protected privacy based on the first information, The first STA performs processing on its own privacy correlation information by employing encryption algorithm information and / or a first algorithm in the first information, and compares the processing result with the protected privacy correlation information; if the comparison result is a match, confirming that the Per AID TID Info field carrying a first AID value is the first Per AID TID Info field corresponding to the first STA; wherein the first algorithm includes at least one of a Hash algorithm, an HMAC algorithm, a CBC-MAC algorithm, and a GMAC algorithm. The method of claim 1.

7. The method further comprising: the first STA transmitting protection capability information for the first STA's BA frame; Here, the protection capability information for the BA frame of the first STA is carried in an associated request frame and / or an authentication frame transmitted by the first STA, the associated request frame and / or the associated authentication frame includes a first extended capability field, and the first extended capability field indicates protection capability for at least one of the BA frame, the trigger frame, and the NDPA frame. The method of claim 1.

8. The method further comprising transmitting an associated request frame and / or an associated authentication frame; wherein the association request frame and / or the association authentication frame includes a first extended capability field, and the first extended capability field indicates a protection capability of the first STA for at least one of the BA frame, the trigger frame, and the NDPA frame; The method of claim 1.

9. The method further comprising: the first STA receiving protection capability information for a BA frame of the second STA; Here, the protection capability information for the BA frame of the second STA is carried in an association response frame and / or an authentication frame received by the first STA, the association response frame and / or the authentication frame includes a second extended capability field, and the second extended capability field indicates protection capability for at least one of the BA frame, the trigger frame, and the NDPA frame. The method of claim 1.

10. a second station STA transmitting a block acknowledgement BA frame, the BA frame carrying first information and privacy-protected correlation information, the first information being used to identify the privacy-protected correlation information; The BA frame includes a BA information field; the BA information field includes at least one first protection field; the first protected field includes a first single association identifier traffic identifier information Per AID TID Info field; the first Per AID TID Info field carries the first information and the protected privacy correlation information, where if the Per AID TID Info field in the BA frame carries a first AID value, the Per AID TID Info field carrying the first AID value is used to extract the first information and the protected privacy correlation information, and identifies the protected privacy correlation information based on the first information; Communication method.

11. The BA frame includes a multi-station Multi-STA BA frame. The method of claim 10.

12. The first AID value ranges from 2008 to 2044 to indicate that the Per AID TID Info field is a Per AID TID Encrypted Info field. The method of claim 10.

13. The first information is encryption algorithm information and / or message digest algorithm information; the length of the privacy correlation information to be protected; and The method of claim 10.

14. The first Per AID TID Info field carries a first AID value, and the first AID value is used to identify the first Per AID TID Info field. The method of claim 10.

15. The method further comprising the second STA performing key agreement with the first STA to generate a key. The method of claim 10.

16. A method comprising: Station STA.

17. A method comprising: a module for performing the steps of the method according to any one of claims 10 to 15; Station STA.

Citation Information

Patent Citations

  • Methods of assigning addressing identifiers, access points, stations and communication systems

    JP2017515353A

  • COMMUNICATIONS APPARATUS AND METHOD FOR SECURE LOW POWER TRANSMISSIONS - Patent application

    JP2020523809A