Method and device for transmitting or receiving protected control frame in wireless LAN system
By encrypting and integrity-checking block ACK request frames using CCMP or GCMP protocols, the security vulnerabilities in wireless LAN systems are addressed, ensuring secure and reliable data transmission.
Patent Information
- Application Number
- PCT/KR2024/021291
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-12-27
- Publication Date
- 2025-07-03
AI Technical Summary
Existing wireless LAN systems lack confidentiality and integrity protection for block ACK request frames, which can be exploited by attackers to disrupt data transmission and reception.
Implementing encryption and integrity checks for block ACK request frames using Counter Mode with cipher-block chaining message authentication code protocol (CCMP) or Galois/Counter Mode protocol (GCMP) to ensure confidentiality and integrity, utilizing keys such as PTK, GTK, IGTK, or BIGTK for individually or group-addressed frames.
Enhances security by protecting block ACK request frames, preventing unauthorized access and ensuring reliable data transmission and reception, applicable to wireless LAN systems including IEEE 802.11 standards and beyond.
Smart Images

Figure KR2024021291_03072025_PF_FP_ABST
Abstract
Description
Method and device for transmitting or receiving protected control frames in a wireless LAN system
[0001] The present disclosure relates to a method and device for transmitting or receiving a protected control frame in a wireless local area network (WLAN) system.
[0002] New technologies have been introduced for wireless local area networks (WLANs) to improve transmission rates, increase bandwidth, enhance reliability, reduce errors, and reduce latency. Among WLAN technologies, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 series of standards can be referred to as Wi-Fi. For example, recently introduced technologies for WLANs include enhancements for Very High Throughput (VHT) in the 802.11ac standard and enhancements for High Efficiency (HE) in the IEEE 802.11ax standard.
[0003] To provide a more advanced wireless communication environment, improved technologies for Extremely High Throughput (EHT) are being discussed. For example, technologies for Multiple Input Multiple Output (MIMO), which supports increased bandwidth, efficient utilization of multiple bands, and increased spatial streams, and for coordination of multiple access points (APs), are being studied. In particular, various technologies are being studied to support low latency or real-time traffic. Furthermore, new technologies are being discussed to support ultra-high reliability (UHR), including improvements or extensions of EHT technology.
[0004] The technical problem of the present disclosure is to provide a method and device for transmitting or receiving a protected control frame in a wireless LAN system.
[0005] The technical problem of the present disclosure is to provide a method and device for supporting confidentiality and integrity based on CCMP (Counter Mode with cipher-block chaining message authentication code protocol) / GCMP (Galois / Counter Mode protocol) for a block ACK (acknowledgement) request frame in a wireless LAN system.
[0006] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present disclosure belongs from the description below.
[0007] A method according to one aspect of the present disclosure may include: generating, by a first station (STA), a block ACK (acknowledgement) request frame based on an encryption protocol; and transmitting, by the first STA, the block ACK request frame to a second STA. Here, the block ACK request frame includes encrypted information based on the encryption protocol, and the encrypted information may be based on a block ACK request control field and a block ACK request information field within a frame body of the block ACK request frame.
[0008] A method according to an additional aspect of the present disclosure may include the steps of: receiving, by a second station (STA), a block ACK (acknowledgement) request frame based on an encryption protocol from a first STA; and performing, by the second STA, decryption and integrity check on the block ACK request frame. Here, the block ACK request frame includes encrypted information based on the encryption protocol, and the encrypted information may be based on a block ACK request control field and a block ACK request information field within a frame body of the block ACK request frame.
[0009] According to the present disclosure, a method and device for supporting confidentiality and integrity based on CCMP (Counter Mode with cipher-block chaining message authentication code protocol) / GCMP (Galois / Counter Mode protocol) for a block ACK (acknowledgement) request frame in a wireless LAN system can be provided.
[0010] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0011] The accompanying drawings, which are incorporated in and are part of the detailed description to aid in understanding the present disclosure, provide embodiments of the present disclosure and, together with the detailed description, describe the technical features of the present disclosure.
[0012] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
[0013] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
[0014] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.
[0015] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.
[0016] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.
[0017] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.
[0018] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.
[0019] FIG. 8 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.
[0020] FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure may be applied.
[0021] Figure 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.
[0022] Figure 11 shows an example of the format of conventional AAD.
[0023] Figure 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.
[0024] FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.
[0025] Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.
[0026] Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.
[0027] FIG. 16 illustrates exemplary formats of a block ACK request frame to which the present disclosure can be applied.
[0028] FIG. 17 is a diagram for explaining the operation of the first STA according to the present disclosure.
[0029] FIG. 18 is a diagram for explaining the operation of a second STA according to the present disclosure.
[0030] FIG. 19 illustrates an example of an encryption protocol MPDU format for a block-ACK request frame according to the present disclosure.
[0031] FIG. 20 illustrates another example of an encryption protocol MPDU format for a block-ACK request frame according to the present disclosure.
[0032] FIG. 21 illustrates the operation of a transmitting STA that supports protection for a block-ACK request frame according to the present disclosure.
[0033] FIG. 22 illustrates the operation of a receiving STA that supports protection for a block-ACK request frame according to the present disclosure.
[0034] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to explain exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the present disclosure may be practiced. The following detailed description includes specific details to provide a thorough understanding of the present disclosure. However, one of ordinary skill in the art will appreciate that the present disclosure may be practiced without these specific details.
[0035] In some cases, to avoid obscuring the concepts of the present disclosure, known structures and devices may be omitted or illustrated in block diagram form focusing on the core functions of each structure and device.
[0036] In the present disclosure, when a component is said to be "connected," "coupled," or "connected" to another component, this may include not only a direct connection but also an indirect connection in which another component exists between them. Furthermore, the terms "comprises" or "has" in the present disclosure specify the presence of the mentioned features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof.
[0037] In this disclosure, terms such as “first,” “second,” etc. are used only to distinguish one component from another and are not used to limit the components, and do not limit the order or importance between the components unless specifically stated otherwise. Accordingly, within the scope of this disclosure, a first component in one embodiment may be referred to as a second component in another embodiment, and similarly, a second component in one embodiment may be referred to as a first component in another embodiment.
[0038] The terminology used herein is for the purpose of describing particular embodiments and is not intended to limit the scope of the claims. As used in the description of the embodiments and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. The term "and / or" as used herein may refer to any one of the associated enumerated items, or is meant to refer to and encompass any and all possible combinations of two or more of them. Furthermore, the use of " / " between words in this disclosure has the same meaning as "and / or" unless otherwise stated.
[0039] The examples of the present disclosure can be applied to various wireless communication systems. For example, the examples of the present disclosure can be applied to a wireless LAN system. For example, the examples of the present disclosure can be applied to a wireless LAN based on the IEEE 802.11a / g / n / ac / ax / be standards. Furthermore, the examples of the present disclosure can be applied to a wireless LAN based on the newly proposed IEEE 802.11bn (or UHR) standard. Additionally, the examples of the present disclosure can be applied to a wireless LAN based on the next-generation standard after IEEE 802.11bn. Furthermore, the examples of the present disclosure can be applied to a cellular wireless communication system. For example, the examples of the present disclosure can be applied to a cellular wireless communication system based on the LTE (Long Term Evolution) series of technologies and the 5G NR (New Radio) series of technologies of the 3rd Generation Partnership Project (3GPP) standard.
[0040] Below, technical features to which examples of the present disclosure can be applied are described.
[0041] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
[0042] The first device (100) and the second device (200) illustrated in FIG. 1 may be replaced with various terms such as a terminal, a wireless device, a WTRU (Wireless Transmit Receive Unit), a UE (User Equipment), an MS (Mobile Station), a UT (user terminal), an MSS (Mobile Subscriber Station), an MSS (Mobile Subscriber Unit), an SS (Subscriber Station), an AMS (Advanced Mobile Station), a WT (Wireless terminal), or simply a user. In addition, the first device (100) and the second device (200) may be replaced with various terms such as an access point (AP), a BS (Base Station), a fixed station, a Node B, a BTS (Base Transceiver System), a network, an AI (Artificial Intelligence) system, an RSU (road side unit), a repeater, a router, a relay, a gateway, etc.
[0043] The devices (100, 200) illustrated in FIG. 1 may also be referred to as stations (STAs). For example, the devices (100, 200) illustrated in FIG. 1 may be referred to by various terms such as transmitting device, receiving device, transmitting STA, and receiving STA. For example, the STAs (110, 200) may perform an AP (access point) role or a non-AP role. That is, in the present disclosure, the STAs (110, 200) may perform the functions of an AP and / or a non-AP. When the STAs (110, 200) perform an AP function, they may simply be referred to as APs, and when the STAs (110, 200) perform a non-AP function, they may simply be referred to as STAs. In addition, in the present disclosure, the APs may also be referred to as AP STAs.
[0044] Referring to FIG. 1, the first device (100) and the second device (200) can transmit and receive wireless signals through various wireless LAN technologies (e.g., IEEE 802.11 series). The first device (100) and the second device (200) can include interfaces for a medium access control (MAC) layer and a physical layer (PHY) that follow the provisions of the IEEE 802.11 standard.
[0045] In addition, the first device (100) and the second device (200) may additionally support various communication standards (e.g., 3GPP LTE series, 5G NR series standards, etc.) other than wireless LAN technology. In addition, the device of the present disclosure may be implemented as various devices such as a mobile phone, a vehicle, a personal computer, an AR (Augmented Reality) device, a VR (Virtual Reality) device, etc. In addition, the STA of the present specification may support various communication services such as voice calls, video calls, data communications, autonomous driving, MTC (Machine-Type Communication), M2M (Machine-to-Machine), D2D (Device-to-Device), and IoT (Internet-of-Things).
[0046] A first device (100) includes one or more processors (102) and one or more memories (104), and may further include one or more transceivers (106) and / or one or more antennas (108). The processor (102) controls the memories (104) and / or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (102) may process information in the memories (104) to generate first information / signals, and then transmit a wireless signal including the first information / signals via the transceivers (106). Furthermore, the processor (102) may receive a wireless signal including second information / signals via the transceivers (106), and then store information obtained from signal processing of the second information / signals in the memory (104). The memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (102) and the memory (104) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (106) may be connected to the processor (102) and may transmit and / or receive wireless signals via one or more antennas (108). The transceiver (106) may include a transmitter and / or a receiver. The transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.
[0047] The second device (200) includes one or more processors (202), one or more memories (204), and may further include one or more transceivers (206) and / or one or more antennas (208). The processor (202) controls the memories (204) and / or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (202) may process information in the memory (204) to generate third information / signals, and then transmit a wireless signal including the third information / signals via the transceivers (206). Furthermore, the processor (202) may receive a wireless signal including fourth information / signals via the transceivers (206), and then store information obtained from signal processing of the fourth information / signals in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via one or more antennas (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.
[0048] Hereinafter, the hardware elements of the device (100, 200) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (102, 202). For example, one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC). One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and / or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, proposals and / or methods disclosed in the present disclosure, and provide the signals to one or more transceivers (106, 206). One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed in the present disclosure.
[0049] One or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. One or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this disclosure may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software configured to perform one or more processors (102, 202) or stored in one or more memories (104, 204) and driven by one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software in the form of codes, instructions and / or sets of instructions.
[0050] One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (104, 204) may be configured as ROM, RAM, EPROM, flash memory, hard drives, registers, cache memory, computer-readable storage media, and / or combinations thereof. The one or more memories (104, 204) may be located internally and / or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.
[0051] One or more transceivers (106, 206) can transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or flowcharts of the present disclosure, to one or more other devices. One or more transceivers (106, 206) can receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts of the present disclosure, from one or more other devices. For example, one or more transceivers (106, 206) can be coupled to one or more processors (102, 202) and can transmit and receive wireless signals. For example, one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals / channels, or the like, as referred to in the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure, via one or more antennas (108, 208). In the present disclosure, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers (106, 206) can convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (102, 202).One or more transceivers (106, 206) may convert user data, control information, wireless signals / channels, etc. processed by one or more processors (102, 202) from baseband signals to RF band signals. For this purpose, one or more transceivers (106, 206) may include an (analog) oscillator and / or filter.
[0052] For example, one of the STAs (100, 200) may perform the intended operation of an AP, and the other of the STAs (100, 200) may perform the intended operation of a non-AP STA. For example, the transceivers (106, 206) of FIG. 1 may perform transmission and reception operations of signals (e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a / b / g / n / ac / ax / be / bn, etc.). In addition, in the present disclosure, operations in which various STAs generate transmission and reception signals or perform data processing or calculations in advance for transmission and reception signals may be performed in the processors (102, 202) of FIG. 1. For example, an example of an operation for generating a transmission / reception signal or performing data processing or operation in advance for a transmission / reception signal may include 1) an operation for determining / obtaining / configuring / computing / decoding / encoding bit information of a field (SIG (signal), STF (short training field), LTF (long training field), Data, etc.) included in a PPDU, 2) an operation for determining / configuring / obtaining time resources or frequency resources (e.g., subcarrier resources) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 3) an operation for determining / configuring / obtaining a specific sequence (e.g., a pilot sequence, an STF / LTF sequence, an extra sequence applied to SIG) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 4) a power control operation and / or a power saving operation applied to an STA, 5) an operation related to determining / obtaining / configuring / computing / decoding / encoding an ACK signal, etc. Additionally, in the examples below, various information (e.g., information related to fields / subfields / control fields / parameters / power, etc.) used by various STAs for determining / acquiring / configuring / computing / decoding / encoding transmission / reception signals can be stored in the memory (104, 204) of FIG. 1.
[0053] Hereinafter, downlink (DL) refers to a link for communication from an AP STA to a non-AP STA, and downlink PPDUs / packets / signals, etc. can be transmitted and received through the downlink. In downlink communication, the transmitter may be part of an AP STA, and the receiver may be part of a non-AP STA. Uplink (UL) refers to a link for communication from a non-AP STA to an AP STA, and uplink PPDUs / packets / signals, etc. can be transmitted and received through the uplink. In uplink communication, the transmitter may be part of a non-AP STA, and the receiver may be part of an AP STA.
[0054] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
[0055] The structure of a wireless LAN system can be composed of multiple components. Through the interaction of multiple components, a wireless LAN that supports transparent STA mobility to the upper layer can be provided. A Basic Service Set (BSS) corresponds to a basic building block of a wireless LAN. FIG. 2 illustrates, by way of example, the existence of two BSSs (BSS1 and BSS2) and the inclusion of two STAs as members of each BSS (STA1 and STA2 are included in BSS1, and STA3 and STA4 are included in BSS2). The oval representing a BSS in FIG. 2 can also be understood as representing a coverage area in which STAs included in the corresponding BSS maintain communication. This area can be referred to as a Basic Service Area (BSA). When an STA moves outside of a BSA, it cannot directly communicate with other STAs within the BSA.
[0056] If we do not consider the DS illustrated in Figure 2, the most basic type of BSS in a wireless LAN is an Independent BSS (IBSS). For example, an IBSS can have a minimal form consisting of only two STAs. For example, assuming other components are omitted, BSS1 consisting of only STA1 and STA2, or BSS2 consisting of only STA3 and STA4, can be representative examples of an IBSS, respectively. Such a configuration is possible when the STAs can communicate directly without an AP. Furthermore, in this type of WLAN, a LAN can be configured when needed rather than being planned in advance, and this can be called an ad-hoc network. Since an IBSS does not include an AP, there is no centralized management entity. That is, in an IBSS, STAs are managed in a distributed manner. In IBSS, all STAs can be mobile STAs, and access to distributed systems (DS) is not permitted, forming a self-contained network.
[0057] An STA's membership in a BSS can dynamically change, for example, when an STA is turned on or off, or when an STA enters or leaves a BSS area. To become a member of a BSS, an STA can join the BSS using a synchronization process. To access all services in the BSS infrastructure, an STA must be associated with the BSS. This association can be dynamically established and may involve the use of a Distribution System Service (DSS).
[0058] In a wireless LAN, the direct STA-to-STA distance can be limited by PHY performance. While this distance limit may be sufficient in some cases, communication between STAs over longer distances may be required in other cases. To support extended coverage, a distributed system (DS) can be configured.
[0059] DS refers to a structure in which BSSs are interconnected. Specifically, a BSS may exist as an extended component of a network composed of multiple BSSs, as illustrated in Figure 2. DS is a logical concept and can be specified by the characteristics of a distributed system medium (DSM). In this regard, the Wireless Medium (WM) and DSM can be logically distinguished. Each logical medium is used for a different purpose and by different components. These media are neither limited to being identical nor limited to being different. This logical difference between multiple media explains the flexibility of the WLAN architecture (DS architecture or other network architectures). In other words, the WLAN architecture can be implemented in various ways, and the physical characteristics of each implementation can independently specify the WLAN architecture.
[0060] A DS can support mobile devices by providing seamless integration of multiple BSSs and the logical services necessary to handle addresses to destinations. Additionally, a DS may further include a component called a portal, which acts as a bridge for connecting wireless LANs to other networks (e.g., IEEE 802.X).
[0061] An AP is an entity that enables access to a DS through a WM for associated non-AP STAs and also has the functionality of an STA. Data movement between a BSS and a DS can be performed through an AP. For example, STA2 and STA3 illustrated in FIG. 2 have the functionality of an STA and provide the function of allowing associated non-AP STAs (STA1 and STA4) to access the DS. In addition, since all APs are basically STAs, all APs are addressable entities. The address used by an AP for communication on a WM and the address used by an AP for communication on a DSM do not necessarily have to be the same. A BSS consisting of an AP and one or more STAs can be referred to as an infrastructure BSS.
[0062] Data transmitted from one of the STA(s) associated with an AP to the STA address of that AP may always be received on an uncontrolled port and processed by an IEEE 802.1X port access entity. In addition, if the controlled port is authenticated, the transmitted data (or frame) may be forwarded to the DS.
[0063] In addition to the structure of the DS described above, an extended service set (ESS) may be established to provide wider coverage.
[0064] An ESS is a network of arbitrary size and complexity, consisting of DSs and BSSs. An ESS may correspond to a set of BSSs connected to a DS. However, an ESS does not include a DS. An ESS network is characterized by appearing as an IBSS at the Logical Link Control (LLC) layer. STAs within an ESS can communicate with each other, and mobile STAs can move from one BSS to another (within the same ESS) transparently to the LLC. APs within an ESS may have the same SSID (service set identification). The SSID is distinct from the BSSID, which is the identifier of the BSS.
[0065] In a wireless LAN system, no assumptions are made about the relative physical locations of BSSs, and all of the following configurations are possible: BSSs can be partially overlapping, which is commonly used to provide continuous coverage. BSSs can also be physically disconnected, and there is no logical distance limit between them. BSSs can also be physically co-located, which can be used to provide redundancy. Furthermore, one (or more) IBSS or ESS networks can physically co-exist with one (or more) ESS networks. This can occur in cases where an ad-hoc network operates at the same location as an ESS network, where physically overlapping wireless networks are configured by different organizations, or where two or more different access and security policies are required at the same location.
[0066] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.
[0067] For an STA to set up a link and transmit and receive data on a network, it must first discover the network, perform authentication, establish an association, and complete security authentication procedures. The link setup process can also be referred to as the session initiation process or session setup process. Furthermore, the discovery, authentication, association, and security setup processes of the link setup process can be collectively referred to as the association process.
[0068] In step S310, the STA may perform a network discovery operation. This network discovery operation may include scanning operations by the STA. That is, for the STA to access a network, it must search for available networks. Before joining a wireless network, the STA must identify compatible networks. The process of identifying networks in a specific area is called scanning.
[0069] Scanning methods include active scanning and passive scanning. Figure 3 illustrates a network discovery operation including an active scanning process as an example. In active scanning, an STA performing scanning transmits a probe request frame to discover any APs in the vicinity while moving between channels and waits for a response. The responder transmits a probe response frame in response to the STA that transmitted the probe request frame. Here, the responder may be the STA that last transmitted a beacon frame in the BSS of the channel being scanned. In the BSS, the AP transmits the beacon frame, so the AP becomes the responder. In the IBSS, the STAs within the IBSS take turns transmitting beacon frames, so the responder is not fixed. For example, an STA that transmits a probe request frame on channel 1 and receives a probe response frame on channel 1 can store BSS-related information included in the received probe response frame and move to the next channel (e.g., channel 2) to perform scanning (i.e., transmitting and receiving probe requests / responses on channel 2) in the same manner.
[0070] Although not shown in Figure 3, the scanning operation can also be performed in a passive scanning manner. In passive scanning, the STA performing the scanning moves between channels and waits for a beacon frame. A beacon frame is one of the management frames defined in IEEE 802.11. It announces the existence of a wireless network and is periodically transmitted so that the STA performing the scanning can find the wireless network and participate in the wireless network. In the BSS, the AP performs the role of periodically transmitting the beacon frame, and in the IBSS, the STAs within the IBSS take turns transmitting the beacon frame. When the STA performing the scanning receives a beacon frame, it stores the information about the BSS included in the beacon frame and moves to another channel, recording the beacon frame information on each channel. The STA receiving the beacon frame stores the BSS-related information included in the received beacon frame and moves to the next channel to perform scanning on the next channel in the same manner. Comparing active scanning and passive scanning, active scanning has the advantage of lower delay and power consumption than passive scanning.
[0071] After the STA discovers the network, an authentication process may be performed in step S320. This authentication process may be referred to as the first authentication process to clearly distinguish it from the security setup operation of step S340 described below.
[0072] The authentication process involves the STA sending an authentication request frame to the AP, and the AP responding by sending an authentication response frame to the STA. The authentication frame used for the authentication request / response corresponds to a management frame.
[0073] The authentication frame may include information such as an authentication algorithm number, an authentication transaction sequence number, a status code, a challenge text, a Robust Security Network (RSN), and a Finite Cyclic Group. These are just some examples of information that may be included in an authentication request / response frame, and may be replaced with other information or include additional information.
[0074] An STA can send an authentication request frame to an AP. The AP can determine whether to grant authentication to the STA based on the information contained in the received authentication request frame. The AP can provide the result of the authentication process to the STA via an authentication response frame.
[0075] After the STA is successfully authenticated, an association process may be performed in step S330. The association process includes a process in which the STA transmits an association request frame to the AP, and in response, the AP transmits an association response frame to the STA.
[0076] For example, the association request frame may include information about various capabilities, a beacon listen interval, a service set identifier (SSID), supported rates, supported channels, an RSN, a mobility domain, supported operating classes, a Traffic Indication Map Broadcast request, interworking service capabilities, etc. For example, the association response frame may include information about various capabilities, a status code, an Association ID (AID), supported rates, an Enhanced Distributed Channel Access (EDCA) parameter set, a Received Channel Power Indicator (RCPI), a Received Signal to Noise Indicator (RSNI), a mobility domain, a timeout interval (e.g., an association comeback time), overlapping BSS scan parameters, a TIM broadcast response, a Quality of Service (QoS) map, etc. These are just some examples of information that may be included in a combined request / response frame, and may be replaced by other information or include additional information.
[0077] After the STA successfully joins the network, a security setup process may be performed in step S340. The security setup process in step S340 may be referred to as an authentication process through a Robust Security Network Association (RSNA) request / response, the authentication process in step S320 may be referred to as a first authentication process, and the security setup process in step S340 may also be referred to simply as an authentication process.
[0078] The security setup process of step S340 may include, for example, a process of establishing a private key through a four-way handshaking using an Extensible Authentication Protocol over LAN (EAPOL) frame. Furthermore, the security setup process may be performed according to a security method not defined in the IEEE 802.11 standard.
[0079] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.
[0080] In wireless LAN systems, the basic access mechanism of MAC (Medium Access Control) is Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA). The CSMA / CA mechanism, also known as the Distributed Coordination Function (DCF) of the IEEE 802.11 MAC, essentially employs a "listen before talk" access mechanism. According to this type of access mechanism, the AP and / or STA may perform a Clear Channel Assessment (CCA) to sense the wireless channel or medium for a predetermined time period (e.g., a DCF Inter-Frame Space (DIFS)) before starting transmission. If the sensing result determines that the medium is in an idle state, the AP and / or STA may start transmitting frames through the medium. On the other hand, if the medium is detected to be occupied or busy, the AP and / or STA may not start its own transmission, but may wait for a delay period (e.g., a random backoff period) for medium access before attempting to transmit frames. By applying a random backoff period, multiple STAs are expected to attempt to transmit frames after waiting for different periods of time, thereby minimizing collisions.
[0081] In addition, the IEEE 802.11 MAC protocol provides the Hybrid Coordination Function (HCF). The HCF is based on the DCF and the Point Coordination Function (PCF). The PCF is a polling-based synchronous access method that periodically polls all receiving APs and / or STAs to ensure that they receive data frames. In addition, the HCF has the Enhanced Distributed Channel Access (EDCA) and the HCF Controlled Channel Access (HCCA). The EDCA is a contention-based access method for a provider to provide data frames to multiple users, while the HCCA uses a non-contention-based channel access method that utilizes a polling mechanism. In addition, the HCF includes a medium access mechanism to improve the Quality of Service (QoS) of the wireless LAN, and can transmit QoS data in both the Contention Period (CP) and the Contention Free Period (CFP).
[0082] Referring to Fig. 4, an operation based on a random backoff period is described. When a medium that was occupied / busy changes to an idle state, multiple STAs can attempt to transmit data (or frames). To minimize collisions, each STA can select a random backoff count, wait for the corresponding slot time, and then attempt transmission. The random backoff count has a pseudo-random integer value and can be determined as one of the values in the range of 0 to CW. Here, CW is a contention window parameter value. The CW parameter is given an initial value of CWmin, but can take a value doubled in case of transmission failure (e.g., when an ACK for a transmitted frame is not received). When the CW parameter value becomes CWmax, data transmission can be attempted while maintaining the CWmax value until data transmission is successful, and if data transmission is successful, it is reset to the CWmin value. The CW, CWmin, and CWmax values are 2. n It is desirable to set it to -1 (n=0, 1, 2, ...).
[0083] Once the random backoff process begins, the STA continues to monitor the medium while counting down the backoff slots according to the determined backoff count value. If the medium is monitored as occupied, the countdown stops and waits. When the medium becomes idle, the remaining countdown resumes.
[0084] In the example of FIG. 4, when a packet to be transmitted reaches the MAC of STA3, STA3 can immediately transmit a frame if it confirms that the medium is idle for DIFS. The remaining STAs monitor the medium for occupied / busy states and wait. In the meantime, data to be transmitted may also occur in each of STA1, STA2, and STA5, and each STA can count down the backoff slot according to a random backoff count value selected by each STA after waiting for DIFS if the medium is monitored as idle. Assume that STA2 selects the smallest backoff count value and STA1 selects the largest backoff count value. In other words, this example shows a case where the remaining backoff time of STA5 is shorter than the remaining backoff time of STA1 when STA2 finishes the backoff count and starts frame transmission. STA1 and STA5 briefly stop counting down and wait while STA2 occupies the medium. When STA2's occupation ends and the medium becomes idle again, STA1 and STA5 wait for DIFS and then resume the backoff count that they had stopped. That is, they can start transmitting frames after counting down the remaining backoff slots equal to the remaining backoff time. Since STA5's remaining backoff time is shorter than STA1's, STA5 starts transmitting frames. While STA2 occupies the medium, STA4 may also have data to transmit. From STA4's perspective, when the medium becomes idle, it waits for DIFS, counts down according to its selected random backoff count value, and then starts transmitting frames. In the example of Figure 4, the remaining backoff time of STA5 coincidentally matches the random backoff count value of STA4, in which case a collision may occur between STA4 and STA5. If a collision occurs, neither STA4 nor STA5 will receive an ACK, resulting in a failure in data transmission.In this case, STA4 and STA5 can select a random backoff count value and perform a countdown after doubling the CW value. STA1 waits while the medium is occupied by transmissions from STA4 and STA5, and when the medium becomes idle, it waits for DIFS and can start transmitting frames after the remaining backoff time elapses.
[0085] As in the example of Fig. 4, a data frame is a frame used for transmitting data forwarded to a higher layer, and can be transmitted after a backoff performed after DIFS elapses from when the medium becomes idle. Additionally, a management frame is a frame used for exchanging management information that is not forwarded to a higher layer, and is transmitted after a backoff performed after an IFS elapses, such as DIFS or PIFS (Point coordination function IFS). Subtype frames of a management frame include a beacon, an association request / response, a re-association request / response, a probe request / response, and an authentication request / response. A control frame is a frame used to control access to the medium. The subtype frames of the control frame include Request-To-Send (RTS), Clear-To-Send (CTS), Acknowledgment (ACK), Power Save-Poll (PS-Poll), Block ACK (BlockAck), Block ACK Request (BlockACKReq), Null Data Packet Announcement (NDP), and Trigger. If the control frame is not a response frame to the previous frame, it is transmitted after a backoff performed after the DIFS (Direct Inverse Frame Stop) has elapsed, and if it is a response frame to the previous frame, it is transmitted without a backoff performed after the SIFS (short IFS). The type and subtype of the frame can be identified by the type field and subtype field in the Frame Control (FC) field.
[0086] A QoS (Quality of Service) STA can transmit a frame after a backoff performed after the AIFS (arbitration IFS) for the access category (AC) to which the frame belongs, i.e., AIFS[i] (where i is a value determined by the AC), has elapsed. Here, the frames for which AIFS[i] can be used can be data frames, management frames, and also control frames that are not response frames.
[0087] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.
[0088] As mentioned above, the CSMA / CA mechanism includes virtual carrier sensing in addition to physical carrier sensing, in which STAs directly sense the medium. Virtual carrier sensing is intended to address potential issues in medium access, such as the hidden node problem. For virtual carrier sensing, the MAC of an STA can utilize a Network Allocation Vector (NAV). The NAV is a value that an STA that is currently using or has the right to use the medium indicates to other STAs the remaining time until the medium becomes available. Therefore, the value set as NAV corresponds to the period during which the STA transmitting the frame is scheduled to use the medium, and an STA receiving the NAV value is prohibited from accessing the medium during that period. For example, the NAV can be set based on the value of the "duration" field in the MAC header of the frame.
[0089] In the example of FIG. 5, it is assumed that STA1 wants to transmit data to STA2, and STA3 is in a position to overhear some or all of the frames transmitted and received between STA1 and STA2.
[0090] In order to reduce the possibility of collisions in transmissions of multiple STAs in a CSMA / CA-based frame transmission operation, a mechanism using RTS / CTS frames may be applied. In the example of FIG. 5, while STA1 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA1 may correspond to a hidden node for STA3. Alternatively, in the example of FIG. 5, while STA2 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA2 may correspond to a hidden node for STA3. By exchanging RTS / CTS frames before performing data transmission and reception between STA1 and STA2, STAs outside the transmission range of either STA1 or STA2, or STAs outside the carrier sensing range for transmissions from STA1 or STA3, may not attempt to occupy the channel during data transmission and reception between STA1 and STA2.
[0091] Specifically, STA1 can determine whether a channel is occupied through carrier sensing. In terms of physical carrier sensing, STA1 can determine channel occupancy idleness based on the energy level or signal correlation detected in the channel. Furthermore, in terms of virtual carrier sensing, STA1 can determine the channel occupancy status using a network allocation vector (NAV) timer.
[0092] STA1 can transmit an RTS frame to STA2 after performing a backoff if the channel is idle during the DIFS. STA2 can transmit a CTS frame, which is a response to the RTS frame, to STA1 after an SIFS if it receives the RTS frame.
[0093] If STA3 cannot overhear a CTS frame from STA2 but can overhear an RTS frame from STA1, STA3 can use the duration information contained in the RTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + CTS frame + SIFS + data frame + SIFS + ACK frame). Alternatively, if STA3 cannot overhear an RTS frame from STA1 but can overhear a CTS frame from STA2, STA3 can use the duration information contained in the CTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + data frame + SIFS + ACK frame). That is, if STA3 can overhear one or more of the RTS or CTS frames from one or more of STA1 or STA2, it can set a NAV accordingly. If STA3 receives a new frame before the NAV timer expires, it can update the NAV timer using the duration information contained in the new frame. STA3 does not attempt channel access until the NAV timer expires.
[0094] If STA1 receives a CTS frame from STA2, it can transmit a data frame to STA2 after SIFS from the time when the CTS frame is completely received. If STA2 successfully receives the data frame, it can transmit an ACK frame in response to the data frame to STA1 after SIFS. STA3 can determine whether the channel is in use through carrier sensing if the NAV timer expires. If STA3 determines that the channel is not in use by another terminal during the DIFS after the NAV timer expires, it can attempt channel access after a contention window (CW) based on a random backoff has elapsed.
[0095] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.
[0096] The PHY layer can prepare an MPDU (MAC PDU) to be transmitted based on an instruction or primitive (meaning a set of instructions or parameters) from the MAC layer. For example, when a command requesting the start of transmission of the PHY layer is received from the MAC layer, the PHY layer can switch to transmission mode and transmit the information (e.g., data) provided by the MAC layer in the form of a frame. In addition, when the PHY layer detects a valid preamble of the received frame, it monitors the header of the preamble and sends a command to the MAC layer notifying the start of reception of the PHY layer.
[0097] In this way, information transmission / reception in a wireless LAN system is done in the form of frames, and for this purpose, the PHY layer Protocol Data Unit (PPDU) format is defined.
[0098] A basic PPDU may include a Short Training Field (STF), a Long Training Field (LTF), a SIGNAL (SIG) field, and a Data field. The most basic (e.g., non-HT (High Throughput) as illustrated in FIG. 7) PPDU format may consist of only the Legacy-STF (L-STF), Legacy-LTF (L-LTF), Legacy-SIG (L-SIG) fields, and a Data field. Additionally, depending on the type of PPDU format (e.g., HT-mixed format PPDU, HT-greenfield format PPDU, VHT (Very High Throughput) PPDU, etc.), additional (or different types of) RL-SIG, U-SIG, non-legacy SIG field, non-legacy STF, non-legacy LTF, (i.e., xx-SIG, xx-STF, xx-LTF (e.g., xx is HT, VHT, HE, EHT, etc.)) may be included between the L-SIG field and the data field. More specific details will be described later with reference to FIG. 7.
[0099] STF is a signal for signal detection, AGC (Automatic Gain Control), diversity selection, and precise time synchronization, while LTF is a signal for channel estimation, frequency error estimation, etc. STF and LTF can be said to be signals for synchronization and channel estimation of the OFDM physical layer.
[0100] The SIG field may include various information related to PPDU transmission and reception. For example, the L-SIG field may consist of 24 bits and may include a 4-bit Rate field, a 1-bit Reserved bit, a 12-bit Length field, a 1-bit Parity field, and a 6-bit Tail field. The RATE field may include information about the modulation and coding rate of data. For example, the 12-bit Length field may include information about the length or time duration of the PPDU. For example, the value of the 12-bit Length field may be determined based on the type of the PPDU. For example, for a non-HT, HT, VHT, or EHT PPDU, the value of the Length field may be determined as a multiple of 3. For example, for HE PPDU, the value of the Length field can be determined as a multiple of 3 + 1 or a multiple of 3 + 2.
[0101] The data field may include a SERVICE field, a Physical layer Service Data Unit (PSDU), a PPDU TAIL bit, and, if necessary, padding bits. Some bits of the SERVICE field may be used to synchronize the descrambler at the receiving end. The PSDU corresponds to a MAC PDU defined at the MAC layer and may contain data generated / used by upper layers. The PPDU TAIL bit may be used to return the encoder to a 0 state. The padding bit may be used to adjust the length of the data field to a predetermined unit.
[0102] MAC PDUs are defined according to various MAC frame formats, and a basic MAC frame consists of a MAC header, a frame body, and a Frame Check Sequence (FCS). A MAC frame is composed of MAC PDUs and can be transmitted / received through the PSDU in the data portion of the PPDU format.
[0103] The MAC header includes a Frame Control field, a Duration / ID field, an Address field, etc. The Frame Control field may include control information required for frame transmission / reception. The Duration / ID field may be set to a time for transmitting the corresponding frame, etc. The Address subfields may indicate the receiver address, transmitter address, destination address, and source address of the frame, and some Address subfields may be omitted. For specific details of each subfield of the MAC header, including the Sequence Control, QoS Control, and HT Control subfields, refer to the IEEE 802.11 standard document.
[0104] The Null-Data PPDU (NDP) format refers to a PPDU format that does not include a data field. In other words, NDP refers to a frame format that includes a PPDU preamble (i.e., L-STF, L-LTF, L-SIG fields, and, if additionally present, non-legacy SIG, non-legacy STF, and non-legacy LTF) in the general PPDU format, and does not include the remaining part (i.e., data field).
[0105] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.
[0106] Standards such as IEEE 802.11a / g / n / ac / ax use various PPDU formats. The basic PPDU format (IEEE 802.11a / g) includes L-LTF, L-STF, L-SIG, and Data fields. The basic PPDU format can also be referred to as the non-HT PPDU format (Fig. 7(a)).
[0107] The HT PPDU format (IEEE 802.11n) additionally includes HT-SIG, HT-STF, and HT-LFT(s) fields in addition to the basic PPDU format. The HT PPDU format illustrated in Fig. 7(b) may be referred to as an HT-mixed format. Additionally, an HT-greenfield format PPDU may be defined, which corresponds to a format that does not include L-STF, L-LTF, and L-SIG, but consists of HT-GF-STF, HT-LTF1, HT-SIG, one or more HT-LTF, and Data fields (not illustrated).
[0108] An example of the VHT PPDU format (IEEE 802.11ac) includes VHT SIG-A, VHT-STF, VHT-LTF, and VHT-SIG-B fields in addition to the basic PPDU format (Fig. 7(c)).
[0109] An example of a HE PPDU format (IEEE 802.11ax) additionally includes RL-SIG (Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), and PE (Packet Extension) fields in addition to the basic PPDU format (Fig. 7(d)). Depending on specific examples of the HE PPDU format, some fields may be excluded or their lengths may vary. For example, the HE-SIG-B field is included in the HE PPDU format for multi-users (MUs), but the HE-SIG-B is not included in the HE PPDU format for single users (SUs). In addition, the HE trigger-based (TB) PPDU format does not include the HE-SIG-B, and the length of the HE-STF field may vary to 8 microseconds (us). The HE ER (Extended Range) SU PPDU format does not include the HE-SIG-B field, and the length of the HE-SIG-A field can vary to 16us. For example, the RL-SIG can be configured identically to the L-SIG. The receiving STA can determine that the received PPDU is a HE PPDU or an EHT PPDU, described later, based on the presence of the RL-SIG.
[0110] The EHT PPDU format may include the EHT MU (multi-user) PPDU of FIG. 7(e) and the EHT TB (trigger-based) PPDU of FIG. 7(f). The EHT PPDU format is similar to the HE PPDU format in that it includes an RL-SIG following an L-SIG, but may include a U (universal)-SIG, an EHT-SIG, an EHT-STF, and an EHT-LTF following the RL-SIG.
[0111] The EHT MU PPDU in FIG. 7(e) corresponds to a PPDU that carries one or more data (or PSDUs) for one or more users. That is, the EHT MU PPDU can be used for both SU transmission and MU transmission. For example, the EHT MU PPDU can correspond to a PPDU for one receiving STA or multiple receiving STAs.
[0112] The EHT TB PPDU of Fig. 7(f) omits the EHT-SIG compared to the EHT MU PPDU. An STA that has received a trigger for UL MU transmission (e.g., a trigger frame or TRS (triggered response scheduling)) can perform UL transmission based on the EHT TB PPDU format.
[0113] The L-STF, L-LTF, L-SIG, RL-SIG, U-SIG (Universal SIGNAL), and EHT-SIG fields can be encoded and modulated to allow legacy STAs to attempt demodulation and decoding, and mapped based on a predetermined subcarrier frequency interval (e.g., 312.5 kHz). These can be referred to as pre-EHT modulated fields. Next, the EHT-STF, EHT-LTF, Data, and PE fields can be encoded and modulated to allow STAs that have successfully decoded non-legacy SIGs (e.g., U-SIG and / or EHT-SIG) and obtained the information contained in the fields, and mapped based on a predetermined subcarrier frequency interval (e.g., 78.125 kHz). These can be referred to as EHT modulated fields.
[0114] Similarly, in the HE PPDU format, the L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, and HE-SIG-B fields may be referred to as pre-HE modulation fields, and the HE-STF, HE-LTF, Data, and PE fields may be referred to as HE modulation fields. Additionally, in the VHT PPDU format, the L-STF, L-LTF, L-SIG, and VHT-SIG-A fields may be referred to as pre-VHT modulation fields, and the VHT STF, VHT-LTF, VHT-SIG-B, and Data fields may be referred to as VHT modulation fields.
[0115] The U-SIG included in the EHT PPDU format of FIG. 7 can be configured based on, for example, two symbols (e.g., two consecutive OFDM symbols). Each symbol (e.g., OFDM symbol) for the U-SIG can have a duration of 4 us, and the U-SIG can have a total duration of 8 us. Each symbol of the U-SIG can be used to transmit 26 bits of information. For example, each symbol of the U-SIG can be transmitted and received based on 52 data tones and 4 pilot tones.
[0116] U-SIGs can be configured in 20MHz units. For example, when an 80MHz PPDU is configured, the same U-SIG can be duplicated in 20MHz units. That is, four identical U-SIGs can be included in an 80MHz PPDU. When the bandwidth exceeds 80MHz, for example, for a 160MHz PPDU, the U-SIGs in the first 80MHz unit and the U-SIGs in the second 80MHz unit can be different.
[0117] For example, A uncoded bits may be transmitted via U-SIG, and a first symbol of U-SIG (e.g., a U-SIG-1 symbol) may transmit the first X bits of information out of a total A bits of information, and a second symbol of U-SIG (e.g., a U-SIG-2 symbol) may transmit the remaining Y bits of information out of a total A bits of information. The A bits of information (e.g., 52 uncoded bits) may include a CRC field (e.g., a field of 4 bits in length) and a tail field (e.g., a field of 6 bits in length). The tail field may be used to terminate the trellis of the convolutional decoder and may be set to 0, for example.
[0118] The A bit information transmitted by U-SIG can be divided into version-independent bits and version-dependent bits. For example, U-SIG can be included in a new PPDU format (e.g., UHR PPDU format) not shown in FIG. 7, and in the format of the U-SIG field included in the EHT PPDU format and the format of the U-SIG field included in the UHR PPDU format, the version-independent bits can be the same, and some or all of the version-dependent bits can be different.
[0119] For example, the size of the version-independent bits of U-SIG can be fixed or variable. The version-independent bits can be assigned only to U-SIG-1 symbols, or to both U-SIG-1 symbols and U-SIG-2 symbols. The version-independent bits and the version-dependent bits can be called by various names, such as the first control bit and the second control bit.
[0120] For example, the version-independent bits of the U-SIG may include a 3-bit PHY version identifier, which may indicate the PHY version (e.g., EHT, UHR, etc.) of the transmitted and received PPDUs. The version-independent bits of the U-SIG may include a 1-bit UL / DL flag field. The first value of the 1-bit UL / DL flag field relates to UL communication, and the second value of the UL / DL flag field relates to DL communication. The version-independent bits of the U-SIG may include information about the length of a transmission opportunity (TXOP) and information about a BSS color ID.
[0121] For example, the version-dependent bits of the U-SIG may contain information that directly or indirectly indicates the type of PPDU (e.g., SU PPDU, MU PPDU, TB PPDU, etc.).
[0122] Information required for PPDU transmission and reception may be included in the U-SIG. For example, the U-SIG may further include information about bandwidth, information about the MCS technique applied to the non-legacy SIG (e.g., EHT-SIG or UHR-SIG), information indicating whether a dual carrier modulation (DCM) technique (e.g., a technique to achieve an effect similar to frequency diversity by reusing the same signal on two subcarriers) is applied to the non-legacy SIG, information about the number of symbols used for the non-legacy SIG, information about whether the non-legacy SIG is generated across the entire band, etc.
[0123] Some of the information required for transmitting and receiving a PPDU may be included in the U-SIG and / or the non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.). For example, information about the type of the non-legacy LTF / STF (e.g., EHT-LTF / EHT-STF or UHR-LTF / UHR-STF, etc.), information about the length of the non-legacy LTF and the cyclic prefix (CP) length, information about the guard interval (GI) applicable to the non-legacy LTF, information about preamble puncturing applicable to the PPDU, information about resource unit (RU) allocation, etc. may be included only in the U-SIG, may be included only in the non-legacy SIG, or may be indicated by a combination of the information included in the U-SIG and the information included in the non-legacy SIG.
[0124] Preamble puncturing may refer to the transmission of a PPDU in which no signal is present in one or more frequency units within the PPDU's bandwidth. For example, the size of the frequency unit (or the resolution of the preamble puncturing) may be defined as 20 MHz, 40 MHz, etc. For example, preamble puncturing may be applied to a PPDU bandwidth greater than a certain size.
[0125] In the example of FIG. 7, non-legacy SIGs such as HE-SIG-B and EHT-SIG may include control information for the receiving STA. The non-legacy SIG may be transmitted over at least one symbol, and each symbol may have a length of 4 us. Information regarding the number of symbols used for the EHT-SIG may be included in a previous SIG (e.g., HE-SIG-A, U-SIG, etc.).
[0126] Non-legacy SIGs, such as HE-SIG-B and EHT-SIG, may contain common fields and user-specific fields. Common and user-specific fields may be coded separately.
[0127] In some cases, common fields may be omitted. For example, in a compressed mode where non-OFDMA (orthogonal frequency multiple access) is applied, common fields may be omitted, and multiple STAs may receive PPDUs (e.g., data fields of PPDUs) over the same frequency band. In a non-compressed mode where OFDMA is applied, multiple users may receive PPDUs (e.g., data fields of PPDUs) over different frequency bands.
[0128] The number of user-specific fields can be determined based on the number of users. A single user block field can contain up to two user fields. Each user field can be associated with either MU-MIMO allocation or non-MU-MIMO allocation.
[0129] The common field may include CRC bits and Tail bits, the length of the CRC bits may be determined as 4 bits, and the length of the Tail bits may be determined as 6 bits and set to 000000. The common field may include RU allocation information. The RU allocation information may include information about the location of RUs to which multiple users (i.e., multiple receiving STAs) are allocated.
[0130] An RU can contain multiple subcarriers (or tones). RUs can be used when transmitting signals to multiple STAs based on OFDMA techniques. RUs can also be defined when transmitting signals to a single STA. Resources can be allocated on an RU basis for non-legacy STFs, non-legacy LTFs, and data fields.
[0131] Depending on the PPDU bandwidth, an applicable RU size can be defined. The RU may be defined identically or differently for the applicable PPDU format (e.g., HE PPDU, EHT PPDU, UHR PPDU, etc.). For example, in the case of an 80MHz PPDU, the RU arrangements of HE PPDU and EHT PPDU may be different. The applicable RU size, RU number, RU position, DC (direct current) subcarrier position and number, null subcarrier position and number, guard subcarrier position and number, etc. for each PPDU bandwidth can be referred to as a tone plan. For example, a tone plan for a wide bandwidth can be defined in the form of multiple repetitions of a low bandwidth tone plan.
[0132] RUs of different sizes can be defined, such as 26-ton RU, 52-ton RU, 106-ton RU, 242-ton RU, 484-ton RU, 996-ton RU, 2X996-ton RU, 4X996-ton RU, etc. A multiple RU (MRU) is distinguished from multiple individual RUs and corresponds to a group of subcarriers consisting of multiple RUs. For example, one MRU can be defined as 52+26-tons, 106+26-tons, 484+242-tons, 996+484-tons, 996+484+242-tons, 2X996+484-tons, 3X996-tons, or 3X996+484-tons. Additionally, multiple RUs constituting one MRU may or may not be consecutive in the frequency domain.
[0133] The specific size of an RU may be reduced or expanded. Therefore, the specific size of each RU (i.e., the number of corresponding tones) in the present disclosure is not limited and is exemplary. Furthermore, within a given bandwidth (e.g., 20, 40, 80, 160, 320 MHz, etc.) in the present disclosure, the number of RUs may vary depending on the RU size.
[0134] The names of each field in the PPDU formats of FIG. 7 are exemplary and the scope of the present disclosure is not limited by those names. Furthermore, the examples of the present disclosure can be applied not only to the PPDU format exemplified in FIG. 7, but also to a new PPDU format in which some fields are excluded and / or some fields are added based on the PPDU formats of FIG. 7.
[0135] Multi-Access Point (MAP) operation
[0136] Below, examples of the present disclosure for multi-access point (MAP) operation are described.
[0137] MAP operation can be defined as an operation between a master AP (or sharing AP) and a slave AP (or shared AP).
[0138] The master AP initiates and controls MAP operations for transmission and reception between multiple APs. It groups slave APs and manages links with them to enable information sharing. The master AP manages information about the BSS comprised of the slave APs and the STAs associated with that BSS.
[0139] Slave APs can associate with a master AP and share control information, management information, and data traffic. Slave APs perform the same basic functions as APs, establishing a base station service (BSS) in a wireless LAN.
[0140] In MAP operation, an STA can associate with a slave AP or a master AP and form a BSS.
[0141] In a MAP environment, the master AP and slave APs can directly transmit and receive with each other. The master AP and STA may not be able to directly transmit and receive with each other. A slave AP (e.g., a slave AP associated with an STA) can directly transmit and receive with the STA. One of the slave APs can become the master AP.
[0142] MAP operation is a technique in which one or more APs transmit and receive information to one or more STAs. For example, coordinated-time division multiple access (C-TDMA), which divides allocations between APs along the time axis, coordinated-orthogonal frequency division multiple access (C-OFDMA), which divides allocations along the frequency axis, and coordinated-spatial reuse (C-SR) techniques that utilize spatial reuse can be applied for MAP operation. Alternatively, coordinated beamforming (C-BF) or joint beamforming techniques, which cooperatively perform simultaneous transmission and reception, can also be applied to MAP operation.
[0143] FIG. 8 is a diagram for explaining various transmission and reception techniques in a MAP environment to which the present disclosure can be applied.
[0144] As in the conventional method, when a BSS AP transmits to a BSS STA, this can be referred to as STX (single transmission). STX suffers from the problem of reduced transmission and reception performance for users / STAs located at the cell edge due to interference with neighboring APs. For example, as shown in Figure 8(a), if AP1 and AP2 transmit to STA1 and STA2, respectively, at the same time and within the same frequency bandwidth, a collision may occur on the wireless medium.
[0145] In the MAP technique, performance can be improved by reducing inter-symbol interference (ISI) through cooperation between neighboring APs, or by performing joint transmissions. For example, in the C-OFDMA method of Fig. 8(b), interference can be avoided by simultaneously transmitting to STA1 in the first bandwidth and transmitting to STA2 in the second bandwidth. The example of Fig. 8(c) shows a cooperative beamforming or nulling technique in which AP1 nulls the interference to AP2 and / or STA2 while transmitting to STA1, and AP2 nulls the interference to AP1 and / or STA1 while transmitting to STA2. Fig. 8(d) shows an AP selection method in which an AP with a good channel condition among neighboring APs performs transmission. Joint transmission (JTX) or joint reception (JRX) may be applied, in which multiple APs cooperate to transmit or receive simultaneously, as in the example of Fig. 8(e), and further, joint MU-MIMO may be supported.
[0146] RSN operation
[0147] As described with reference to Figure 3, after the discovery process between the STA and the AP, the authentication process can be performed in an open system manner, followed by an association process. This process can be considered Step 0, which involves detecting support for a robust security network (RSN) and establishing authentication and association.
[0148] If step 0 is successfully completed, step 1 of user authentication by IEEE 802.1X / EAP (extensible authentication protocol) or PSK (pre-shared key) and obtaining a pairwise master key (PMK) can be performed. The mutual authentication method applied here may include 802.1X / EAP, PSK, or simultaneous authentication of equals (SAE). For example, in the case of 802.1X / EAP authentication, PMK can be generated from MSK (master session key) after authentication between STA and RADIUS (remote authentication dial-in user service). In the case of user authentication by PSK, AP and STA can directly set PMK in the same way as PSK. In the case of user authentication by SAE, AP and STA can directly set PMK by using mutual authentication and authentication process operation value through SAE authentication process.
[0149] Following Step 1, Step 2 may be performed to verify that the other party holds the same PMK using the EAPoL-Key frame and to generate and share an encryption key. Step 2 may include a process of mutually verifying the generation of the PMK through 4-way handshaking and generating and transmitting a group key (e.g., a group temporal key (GTK)). A pairwise transient key (PTK), a key confirmation key (KCK), a key encryption key (KEK), and a temporal key (TK) may be generated through the 4-way handshaking.
[0150] Specifically, in step 1, a PMK may be generated from the MSK, and in step 2, a PTK may be generated from the PMK. Here, the PTK is configured separately as a KCK, a KEK, and a TK. A GTK may be generated from the AP and transmitted to the STA. If the AP wishes to generate a new GTK, it may perform handshaking with the STA and transmit the new GTK to the STA.
[0151] In order to verify that the STA and AP have the same PMK, in the case of 802.1X / EAP, the same MSK is set between the STA and the AS based on the user authentication result between the STA and the authentication server (AS), and the AS transmits the MSK to the AP. The STA and the AP can confirm whether they have the PMK, which is a symmetric key generated from the MSK, through 4-way handshaking. In the case of the PSK, the authentication procedure can be replaced by mutually verifying through 4-way handshaking whether the PMK generated from the PSK previously set between the AP and the STA has been secured. In the case of SAE, the PMK previously set between the AP and the STA can be mutually verified through 4-way handshaking.
[0152] It is also possible to verify whether the STA and the AP have the same PMK by mutually verifying that they generated the same PTK. For example, it is also possible to verify whether the PMK is secured through Messages 2 and 3 of the 4-way handshaking. Specifically, in Message 2, the STA can include the KCK of the PTK it generated in the Key MIC field and transmit it to the AP. In Message 3, the AP can include the KCK of the PTK it generated in the Key MIC field and transmit it to the STA. Through this, the STA (AP) can verify that the AP (STA) generated the same PTK as its own PTK, thereby confirming that the AP (STA) has the same PMK as itself. Meanwhile, in Message 1, the value of the Key MIC field may be set to 0, and in Message 4, the Key MIC field may include the KCK value.
[0153] In this way, a secret key can be generated to encrypt data to be transmitted and received between the STA and the AP in step 2. In the RSN, a different secret key is generated for each STA associated with the AP, and another secret key is generated when the STA re-associates with another AP.
[0154] Based on the TK generated as a result of the 4-way handshaking in step 2, data encryption can be performed using TKIP (temporal key integrity protocol), CCMP (cipher-block chaining message authentication code protocol), GCMP (Galois / Counter Mode protocol), etc., and this can be referred to as step 3.
[0155] The aforementioned MSK, PSK, PMK, PTK, KCK, KEK, and TK correspond to pairwise keys, that is, keys that are paired between the AP and the STA. Unlike the pairwise keys, the group key can be generated based on the group master key (GMK) for the AP to generate a secret key for group-addressed frames, such as beacon frames. The GMK is randomly set by the AP. The group temporal key (GTK) is generated from the GMK by the pseudorandom function (PRF) and corresponds to a one-way group key from the AP to the STA.
[0156] FIG. 9 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.
[0157] The STA corresponds to the side requesting authentication (supplicant), and the AP corresponds to the side performing authentication (authenticator). A four-way handshaking can be performed to generate and verify the PTK and GTK between the AP and the STA when the STA possesses or knows the PMK, and the AP possesses or knows the PMK and GMK.
[0158] ANonce and SNonce correspond to arguments used in the PRF function used to generate the PTK. ANonce may correspond to a random number generated by the access point (i.e., the authenticator). SNonce may correspond to a random number generated by the STA (i.e., the supplicant). The PRF function may correspond to a function that generates a PTK based on, for example, the PMK, ANonce, SNonce, the MAC address of the supplicant, and the MAC address of the authenticator.
[0159] Message 1 of step S810 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include ANonce information. If the AP generates a PMK, the PMKID may be included in the key data field of the EAPOL-key frame. The STA may generate a PTK based on the information received from the AP, and may generate a KCK, KEK, and TK based on the PTK.
[0160] Message 2 of step S820 is transmitted from the STA to the AP in a unicast manner, and the EAPOL-key frame may include SNonce information and a key MIC (message integrity code). For example, the key MIC of message 2 may have a value based on the KCK generated by the STA. The AP may generate a PTK based on the information received from the STA, and may generate a KCK, a KEK, and a TK based on the PTK. The AP may verify whether the AP and the STA have generated the same PTK based on whether the KCK value of the PTK generated based on the value included in message 2 and the KCK value related to the key MIC value included in message 2 are the same. In addition, the AP may generate a GTK if necessary. The generation of the GTK may be generated by the AP from the GMK without the involvement of the STA.
[0161] Message 3 of step S830 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include MIC (i.e., corresponding to the KCK value of the PTK generated by the AP) and encrypted GTK information. The encrypted GTK of message 3 may be encrypted based on the KEK generated by the AP and included in the key data field. The STA may store the PTK in the PTK-SA (PTK-Security Association) and the GTK in the GTK-SA.
[0162] Message 4 of step S840 is transmitted unicast from the STA to the AP, and the EAPOL-key frame may include MIC information. Upon completion of verification via the MIC, the AP may store the PTK in the PTK-SA and the GTK in the GTK-SA.
[0163] Once the four-way handshaking is successfully completed, the virtual control port that previously blocked all traffic is unblocked, allowing encrypted traffic to be transmitted and received. All unicast traffic can then be encrypted using PTK, and all multicast / broadcast traffic can be encrypted using GTK.
[0164] RSNA confidentiality and integrity protocol
[0165] For RSNA, authentication mechanisms for STAs, key management algorithms, cryptographic key establishment, cryptographic mechanisms, fast BSS transition (FT), and cryptographic encapsulation for robust management frames can be defined. For example, cryptographic mechanisms can include CCMP (counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol), GCMP (Galois / Counter Mode protocol), etc.
[0166] RSNA security may include algorithms and procedures such as temporal key integrity protocol (TKIP), CCMP, GCMP, broadcast / multicast integrity protocol (BIP), RSNA establishment and termination procedures, and key management procedures (e.g., key distribution). For example, RSNA establishment and termination procedures may include IEEE 802.1X authentication, simultaneous authentication of equals (SAE) authentication, and opportunistic wireless encryption (OWE) as defined in Internet Engineering Task Force (IETF) request for comments (RFC) 8110.
[0167] Below, we describe CCMP (counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol).
[0168] CCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection. CCMP is based on the CCM of the AES (Advanced Encryption Standard) encryption algorithm. CCM combines CTR for data confidentiality and CBC-MAC for authentication and integrity. CCM can protect the integrity of both the MPDU data field and selected portions of the MPDU header (MAC header).
[0169] FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure may be applied.
[0170] For secure PV0 (protocol version 0) MPDUs, CCMP-128 processing enlarges the original MPDU size by 16 octets (i.e., 8 octets for the CCMP header field and 8 octets for the MIC field). CCMP-256 processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the CCMP header field and 16 octets for the MIC field). The CCMP header field is constructed from the packet number (PN), extended initialization vector (ExtIV), and key ID subfields. The PN is a 48-bit PN expressed as an array of 6 octets. PN5 is the most significant octet of the PN, and PN0 is the least significant octet. The third octet of the CCMP header is reserved. The ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for CCMP, bits 6 (B6) and 7 (B7) are the key ID subfields, and the remaining bits of the key ID octet are reserved.
[0171] Figure 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.
[0172] Additional authentication data (AAD) can be constructed from the MAC header of a plaintext MPDU. A Nonce can be constructed based on the A2 (address 2) and priority of the plaintext MPDU and the incremented PN. The AAD and Nonce, together with data and the TK, can be used for CCM encryption. A CCMP header can be constructed based on the incremented PN and the key ID. The data and MIC, which are the results of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, as in the example of FIG. 9.
[0173] Figure 11 shows an example of the format of conventional AAD.
[0174] The example of Fig. 11(a) may correspond to an example of a conventional AAD construction for a PV0 MPDU. The FC (frame control), A1 (address 1), A2 (address 2), A3 (address 3), and SC (sequence control) fields may always be included in the conventional AAD if they are included in the MAC header. The length of the AAD may vary depending on the presence or absence of the QC (QoS Control) field and the A4 (address 4) field. For the conventional AAD, for example, if both QC and A4 are absent, the AAD length may be 22 octets, if QC is present and A4 is absent, the AAD length may be 24 octets, if QC is absent and A4 is present, the AAD length may be 28 octets, and if both QC and A4 are present, the AAD length may be 30 octets.
[0175] AAD is constructed from the MPDU header. Referring to Figure 11(b), the existing AAD does not include the MAC header's Duration / ID field, nor does it include the MAC header's HT control field. This is to prevent the existing AAD from including fields whose contents can be changed or inserted / deleted during operations such as retransmission.
[0176] Additionally, some subfields of the Frame Control (FC) field of the MAC header may be masked out. Masking out means that the value of the corresponding subfield / fields of the MAC header is changed to 0 to be included in the AAD.
[0177] For example, the subfields that are masked out in the FC field of the existing AAD are as follows:
[0178] The 3 LSBs (i.e., bits 4, 5 and 6) of the subtype subfield of the data frame are masked out, and bit 7 is not modified;
[0179] The retry subfield is masked out;
[0180] The power management subfield (i.e. bit 12) is masked out;
[0181] The more data subfield (i.e. bit 13) is masked out;
[0182] The protected frame subfield (i.e., bit 14) is not modified (i.e., left as 1);
[0183] +HTC subfield (i.e. bit 15) is masked-out in all data frames containing the QoS control field and is otherwise unmodified;
[0184] Other subfields of the FC field are not modified.
[0185] For example, the sequence number subfield in the sequence control (SC) field of a legacy AAD may be masked out.
[0186] Although not shown in the example of FIG. 11, if the existing AAD includes a QoS Control (QC) field, the QC field may be included in the existing AAD if one or more of the MSDU priority subfield, the QC TID (traffic identifier) subfield, the A-MSDU capable subfield, the A-MSDU present subfield, and the A-MSDU type subfield are present in the MAC header. Other subfields in the QC field of the existing AAD may be masked out. That is, the end of service period (EOSP) subfield, the ACK policy indicator subfield, the TXOP limit subfield, the queue size subfield, the TXOP duration requested subfield, and the AP PS buffer state subfield may be masked out and not used in the existing AAD configuration.
[0187] Figure 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.
[0188] An AAD can be constructed from the MAC header of an encrypted MPDU. A Nonce can be constructed based on the A2 and priority of the encrypted MPDU and the PN. The AAD and Nonce, along with the MIC, data, and key, can be used for CCM decryption. The data resulting from CCM decryption can be replay-checked along with the MAC header to obtain a plaintext MPDU. The replay-check can be based on the PN and a replay counter.
[0189] Below, we explain BIP (broadcast / multicast integrity protocol).
[0190] BIP provides data integrity and replay protection for group-addressed robust management frames after establishing an integrity group temporal key security association (IGTKSA). For example, BIP provides data integrity and replay protection for beacon frames after establishing a beacon IGTKSA (BIGTKSA). BIP can use IGTK or BIGTK to compute the MAC management PDU (MMPDU) MIC. The management MIC element (MME) can be located after all other elements of the management frame body and before the FCS. That is, the MME can be included as the last element of the management frame body. The MME can include an element ID field, a length field, a key ID field, an IPN (IGTK packet number) / BIPN (BIGTK packet number) field, and a MIC field.
[0191] The existing AAD for BIP can be constructed based on FC, A1, A2, A3, and the Retry subfield (bit 11), Power Management subfield (bit 12), and More Data subfield (bit 13) within FC are masked out, and other subfields may not be modified.
[0192] Below, we describe GCMP (Galois / Counter Mode protocol).
[0193] GCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection. EHT RSNA STAs can support GCMP-256. GCMP is based on the GCM (Global Code Compatibility) of the AES (Advanced Encryption Standard) encryption algorithm. GCM can protect the integrity of both the MPDU data field and selected portions of the MPDU header (MAC header).
[0194] FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.
[0195] GCMP processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the GCMP header field and 16 octets for the MIC field). The CCMP header field is constructed from the packet number (PN) and the key ID subfield. The PN is a 48-bit PN expressed as an array of 6 octets. PN5 is the most significant octet of the PN, and PN0 is the least significant octet. The third octet of the GCMP header is reserved. The ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for GCMP, bits 6 (B6) and 7 (B7) are the key ID subfields, and the remaining bits of the key ID octet are reserved.
[0196] Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.
[0197] Additional authentication data (AAD) can be constructed from the MAC header of a plaintext MPDU. A Nonce can be constructed based on address 2 (A2) of the plaintext MPDU and an incremented PN. The AAD and Nonce, together with data and the TK, can be used for GCM encryption. A GCMP header can be constructed based on the incremented PN and key ID. The data, which is the result of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, as in the example of FIG. 13.
[0198] The configuration of the existing AAD applied to GCMP is the same as that described with reference to Fig. 11, so redundant description is omitted.
[0199] Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.
[0200] An AAD can be constructed from the MAC header of an encrypted MPDU. A Nonce can be constructed based on A2 and PN of the encrypted MPDU. The AAD and Nonce, along with data and a key, can be used for GCM decryption. The data resulting from GCM decryption can be replay-checked along with the MAC header to obtain a plaintext MPDU. The replay-check can be based on the PN and a replay counter.
[0201] Block ACK Request (BAR) frame
[0202] FIG. 16 is a diagram illustrating an exemplary format of a block-ACK request frame to which the present disclosure can be applied.
[0203] A block-ACK request frame may be used to request transmission of a block-ACK frame that includes multiple acknowledgements in a single frame, thereby increasing channel efficiency. For example, a first STA (e.g., an AP) may request reception results for multiple MPDUs via the block-ACK request frame, and a second STA(s) that has received the block-ACK request frame may transmit a block-ACK frame that includes acknowledgements for multiple MPDUs based on the request.
[0204] As illustrated in FIG. 16, a block-ACK request (BAR) frame may include a BAR control field and a BAR information field in the frame body.
[0205] The BAR control field may include BAR type, TID information (TID_INFO), etc., which indicates the type of block-ACK request frame (e.g., compressed, multi-TID, groupcast with retries (GCR), etc.).
[0206] The BAR information field may be based on the type of block-ACK request frame (e.g., block-ACK request frame variant type) indicated by the BAR type field / subfield in the BAR control information.
[0207] For example, if a compressed block-ACK request frame type (e.g., compressed block-ACK frame type or extended compressed block-ACK frame type) is indicated, the BAR information field format corresponding to the compressed block-ACK request may include a Block Ack Starting Sequence Control subfield.
[0208] For example, the block-ACK starting sequence control subfield may include a fragment number subfield and a starting sequence number subfield, wherein the fragment number subfield is set to 0, and the starting sequence number subfield may include the sequence number of the first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.
[0209] For another example, when a multi-TID (multi-STA) block-ACK request frame type is indicated, the BAR information field format corresponding to the multi-TID block-ACK request may include, for each TID, a Per TID Info subfield and a Block-ACK Start Sequence Control subfield.
[0210] For example, each TID information subfield may include a 4-bit TID value subfield. In addition, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include the sequence number of the first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.
[0211] In this regard, the TID_INFO subfield of the BAR control field of the multi-TID block-ACK request frame can determine the number of TIDs present in the multi-TID block-ACK request frame, which is given as TID_INFO + 1. For example, setting the TID_INFO subfield to 2 can mean that there are three TID values in the BAR information field of the multi-TID block-ACK request frame.
[0212] For another example, when a GCR block-ACK request frame type is indicated, a BAR information field format corresponding to the GCR block-ACK request may include a GCR group address subfield and a block-ACK start sequence control subfield. Here, the GCR group address subfield may include a MAC address of a group for which a reception status is requested. In addition, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include a sequence number of a first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.
[0213] For another example, when the GLK-GCR block-ACK request frame type is indicated, the BAR information field format corresponding to the GCR-GCR block-ACK request may include a block-ACK start sequence control subfield. Here, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include a sequence number of a first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.
[0214] A method to support encryption / decryption for Block Ack Request (BAR) frames.
[0215] In the case of existing wireless LAN systems, encryption / decryption based on Temporal Key Integrity Protocol (TKIP) / CCMP / GCMP can be performed / applied using a pairwise transient key (PTK) for individually addressed data frames (e.g., unicast-based data frames) and management frame(s). In addition, encryption / decryption based on TKIP / CCMP / GCMP can be performed / applied using a group temporal key (GTK) for group addressed frames (e.g., broadcast-based data frames). That is, CCMP / GCMP is a security protocol that performs encryption / decryption, and a TK based on PTK can be used for a single-user (SU), and a TK based on GTK can be used for a multi-user (MU). CCMP / GCMP can ensure confidentiality and integrity for data frames and management frame(s).
[0216] Additionally, for group-addressed management frames(es), BIP-based integrity check can be performed using IGTK (integrity group temporal key). In particular, for beacon frames, BIP-based integrity check can be performed using BIGTK (beacon integrity group temporal key). In the case of BIP, a TK based on IGTK / BIGTK is used to generate a message integrity code (MIC) for the frame body of the corresponding data frame, and an integrity check can be performed based on this. That is, unlike CCMP / GCMP, BIP can only guarantee the integrity of data frames and management frames(es).
[0217] The way MPDUs are constructed based on CCMP and GCMP and the way MMPDUs (management MPDUs) are constructed based on BIP have the following differences:
[0218] First, in the case of CCMP / GCMP, the transmitting STA encrypts the data portion using CCM / GCM and transmits the encrypted data, and the receiving STA can decrypt the received encrypted data. In contrast, in the case of BIP, the transmitting STA does not encrypt the data portion and can perform the corresponding protocol to generate an MIC for integrity verification of the data in the frame body.
[0219] Next, for CCMP / GCMP, the MPDU can be composed and transmitted and received in the following order: MAC header, CCMP / GCMP header, encrypted data, MIC (encrypted MIC in case of CCMP), and FCS. In contrast, for BIP, the MPDU can be composed and transmitted and received in the following order: MAC header, management frame body including MME (management MIC element), and FCS. Here, since the MME takes the role of CCMP / GCMP header, it can include information on Key ID field, IPN / BIPN, and MIC.
[0220] As previously mentioned, protection is supported for management frames, including data frames and beacon frames, among group-addressed frames. However, protection is not supported for control frames, and thus control frames are transmitted and received without any encryption / decryption and / or integrity check protocols applied.
[0221] For example, ACK frame, Block-ACK (BlockAck, Block Ack, BA) frame, and Block-ACK request frame are types of control frames. When a transmitting STA transmits data, a receiving STA can transmit an ACK for the data to the transmitting STA. At this time, STA(s) that support A(aggregated)-MPDU can configure the ACK as an A-MPDU and transmit it in the form of a block-ACK.
[0222] A block-ACK request frame can be transmitted by a transmitting STA to receive a block-ACK from a receiving STA. That is, when a transmitting STA transmits a block-ACK request frame to a receiving STA, the receiving STA can transmit a block-ACK frame to the transmitting STA. Based on this, the block-ACK request frame can be used to obtain ACK information for a previous frame transmitted in a TXOP or to initialize (e.g., clear) a receive re-order buffer of the receiving STA.
[0223] In this regard, if the information in the block-ACK request frame is exposed to a third-party STA (e.g., an attack STA), the ACK information, which serves to confirm whether data is being transmitted or received between the transmitting STA and the receiving STA, can be acquired, thereby disrupting whether transmission or reception is taking place between the transmitting STA and the receiving STA. As a result, an attack on the block-ACK request frame can result in a degradation of data transmission and reception capabilities and waste of power / medium.
[0224] Taking these points into consideration, the present disclosure proposes a security technique for ensuring confidentiality and integrity of a block-ACK request frame transmitted and received between a transmitting STA and a receiving STA.
[0225] In addition, in the description of the present disclosure, it is assumed that the STA(s) transmitting and receiving the block-ACK request frame according to the present disclosure are UHR STAs (and / or beyond UHR STAs). For example, when utilizing the block-ACK request frame according to the present disclosure, it can be assumed that all receiving STAs receiving the block-ACK request frame transmitted by the AP, which is the transmitting STA, are UHR STAs. That is, if a pre-UHR STA (e.g., an EHT / HE STA, etc.) receives a block-ACK request frame configured according to the proposed method of the present disclosure, an error may occur during decoding of the block-ACK request frame.
[0226] Additionally, although the present disclosure describes a security technology for a block-ACK request frame among control frames as a representative example, the proposed method of the present disclosure can be extended and applied to other types of control frames other than the block-ACK request frame.
[0227] In the present disclosure, performing confidentiality and integrity checks on block ACK request frames can be interpreted as extending and applying CCMP / GCMP to block ACK request frames. In this regard, additional provisions for control frames may be defined for the previously defined CCMP / GCMP, or a separate protocol based on CCMP / GCMP for confidentiality and integrity checks of control frames may be newly defined.
[0228] Below, specific examples of the present disclosure that apply encryption / decryption as a method for supporting / performing protection (e.g., confidentiality and integrity check) for block-ACK request frames are described.
[0229] The names and values of fields, subfields, elements, parameters, keys, etc. proposed in this disclosure are exemplary and are not limited to the names and values. In addition, unless otherwise specified, an STA may be an AP STA or a non-AP STA.
[0230] FIG. 17 is a diagram for explaining the operation of the first STA according to the present disclosure.
[0231] In step S1710, the first STA can generate a block ACK request frame based on an encryption protocol.
[0232] In this regard, the block ACK request frame may include encrypted information based on an encryption protocol. Here, the encrypted information may be based on a block ACK request control field and a block ACK request information field within the frame body of the block ACK request frame.
[0233] According to the present disclosure, encryption for a block ACK request frame may be performed based on key information related to protection for the block ACK request frame. For example, the key information may correspond to an existing PTK applied to an existing data frame for an individually addressed block ACK request frame, or a new PTK for the block ACK request frame (e.g., a PTK distinct from the existing PTK). Alternatively, the key information may correspond to an existing GTK / IGTK / BIGTK applied to an existing broadcast for a group addressed block ACK request frame, or a new GTK for the block ACK request frame (i.e., a GTK distinct from the existing GTK / IGTK / BIGTK).
[0234] According to the present disclosure, a block ACK request frame may include MIC information calculated based on key information related to protection for the block ACK request frame. If the encryption protocol is CCMP, encryption may also be applied to the MIC information. If the encryption protocol is GCMP, encryption may not be applied to the MIC information. In addition, CCMP-128 or CCMP-256 may be applied as a cipher suite for CCMP. GCMP-128 or GCMP-256 may be applied as a cipher suite for GCMP.
[0235] According to the present disclosure, an encryption protocol header (e.g., a CCMP header or a GCMP header) included in a block ACK request frame may include a field for a key ID and a field for a packet number. In addition, the encryption protocol header may include information indicating whether protection for the block ACK request frame is supported and / or an MPDU format according to the corresponding encryption protocol (e.g., information indicating what type of MPDU format it is composed of).
[0236] When an encryption protocol is applied to a block ACK request frame, the protected frame subfield in the frame control field included in the block ACK request frame may be set to a predefined specific value.
[0237] In step S1720, the first STA may transmit a block ACK request frame to the second STA.
[0238] In this regard, information indicating whether protection for a block ACK request frame is supported between the first STA and the second STA before step S1710 may be exchanged via a management frame (e.g., a beacon frame, a probe request / response frame, a (re-)association request / response frame, etc.). And / or, information indicating an MPDU format according to an encryption protocol (i.e., information indicating what type of MPDU format it is composed of) may be exchanged between the first STA and the second STA before step S1710.
[0239] Additionally or alternatively, the block ACK request frame may include information related to a request for a block ACK for data to be received by the second STA. In this case, key information related to protection for the block ACK request frame may be distinguished from key information for protection of the aforementioned data.
[0240] The method described in the example of FIG. 17 may be performed by the first device (100) of FIG. 1. For example, one or more processors (102) of the first device (100) of FIG. 1 may be configured to generate a block ACK request frame based on an encryption protocol and transmit the block ACK request frame to the second STA via one or more transceivers. Furthermore, one or more memories (104) of the first device (100) may store commands for performing the method described in the example of FIG. 17 or the examples described below when executed by one or more processors (102).
[0241] FIG. 18 is a diagram for explaining the operation of a second STA according to the present disclosure.
[0242] In step S1810, the second STA can receive a block ACK request frame based on an encryption protocol from the first STA.
[0243] The format and detailed configuration according to the encryption protocol of the block ACK request frame are the same as those described in Fig. 17, so redundant descriptions are omitted.
[0244] In step S1820, the second STA can perform decryption and integrity check on the block ACK request frame.
[0245] For example, the second STA may perform decryption according to an encryption protocol applied to the received block ACK request frame, calculate a MIC value based on a block ACK request control field and a block ACK request information field in the block ACK request frame, and compare it with a value included in the MIC field of the received block ACK request frame to perform an integrity check.
[0246] The method described in the example of FIG. 18 may be performed by the second device (200) of FIG. 1. For example, one or more processors (202) of the second device (200) of FIG. 1 may be configured to receive a block ACK request frame based on an encryption protocol from the first STA through one or more transceivers, and to perform decryption and integrity check on the block ACK request frame. Furthermore, one or more memories (204) of the second device (200) may store commands for performing the method described in the example of FIG. 18 or the examples described below when executed by one or more processors (202).
[0247] The examples of FIGS. 17 and 18 may correspond to some of the various examples of the present disclosure. Below, various examples of the present disclosure, including the examples of FIGS. 17 and 18, are described in more detail.
[0248] Example 1
[0249] This embodiment relates to the format of a protected block ACK request frame.
[0250] The length of the key ID included in the CCMP / GCMP header added to the cipher text resulting from the application of CCMP / GCMP, the length of IPN / BIPN, and the length of the MIC in the MIC field are not limited to the previously defined values. For example, in the case of the key ID field, the key ID indicating GTK has a length of 2 bits, but the key ID indicating IGTK or BIGTK can have a length of 2 octets. In addition, the MIC field can have a length of 8 octets, 16 octets, 64 octets, etc. Additionally, the MIC length can be changed by additionally applying the MIC value to a separate function.
[0251] A block ACK request frame for applying protection according to the present disclosure may be configured based on one or more of the formats described below.
[0252] Example 1-1
[0253] To support protection for the block ACK request frame, a format can be configured that applies CCMP to the BAR control field and BAR information field included in the block ACK request frame.
[0254] The format may be for performing encryption / decryption on the BAR control field and BAR information field(s) (e.g., one or more BAR information fields) within the block ACK request frame.
[0255] Specifically, the transmitting STA may perform CCMP encryption on the BAR control field and BAR information field(s) using a key negotiated / shared with the receiving STA. During the encryption process, the AAD may be configured using the frame control field, duration field, RA field, and / or TA field corresponding to the front part of the BAR control field in the MPDU format.
[0256] For CCMP, the MIC value calculated based on the BAR control field and the BAR information field is configured in the form of ciphertext together with the BAR control field and the BAR information field.
[0257] FIG. 19 illustrates an example of an encryption protocol MPDU format for a block-ACK request frame according to the present disclosure.
[0258] Referring to FIG. 19, the CCMP MPDU format may be composed of a frame control field, a duration field, an RA field, a TA field, a CCMP header field, cipher text, and an FCS in that order. This configuration is merely an example, and the scope of the present disclosure is not limited thereto.
[0259] In this regard, the CCMP header field may include information about PN (packet number) related values (e.g., PN0, PN1, PN2, PN3, PN4, PN5, etc.) and / or key ID.
[0260] As mentioned above, when CCMP is applied, the MIC value can be calculated based on the BAR control field and the BAR information field. The MIC value calculated in this way can be encrypted together with the BAR control field and the BAR information field and included in the CCMP MPDU in the form of ciphertext. In other words, CCMP-based encryption can be applied to the entire frame body (e.g., the BAR control field and the BAR information field) of the block ACK request frame before encryption, as well as the MIC information.
[0261] Example 1-2
[0262] To support protection for block ACK request frames, a format can be configured that applies GCMP to the BAR control field and BAR information field included in the block ACK request frame.
[0263] The format may be for performing encryption / decryption on the BAR control field and BAR information field(s) (e.g., one or more BAR information fields) within the block ACK request frame.
[0264] Specifically, the transmitting STA may perform GCMP encryption on the BAR control field and BAR information field(s) using a key negotiated / shared with the receiving STA. During the encryption process, the AAD may be configured using the frame control field, duration field, RA field, and / or TA field corresponding to the front part of the BAR control field in the MPDU format.
[0265] In the case of GCMP, the MIC value calculated based on the BAR control field and the BAR information field is not encrypted, unlike in the case of the CCMP described above (e.g., Example 1-1).
[0266] FIG. 20 illustrates another example of an encryption protocol MPDU format for a block-ACK request frame according to the present disclosure.
[0267] Referring to FIG. 20, the GCMP MPDU format may be composed of a frame control field, a duration field, an RA field, a TA field, a GCMP header field, a cipher text, an MIC field, and an FCS in that order. This configuration is merely an example, and the scope of the present disclosure is not limited thereto.
[0268] In this regard, the GCMP header field may include information about PN (packet number) related values (e.g., PN0, PN1, PN2, PN3, PN4, PN5, etc.) and / or key ID.
[0269] As described above, when GCMP is applied, the MIC value can be calculated based on the BAR control field and the BAR information field, and encryption is not applied to the MIC value. The BAR control field and the BAR information field can be encrypted and included in the corresponding GCMP MPDU format in the form of ciphertext. That is, GCMP-based encryption can be applied to the entire frame body (e.g., the BAR control field and the BAR information field) of the block ACK request frame before encryption, excluding the MIC information.
[0270] Example 1-3
[0271] This embodiment relates to a signaling method for whether encryption / protection is supported for a block ACK request frame.
[0272] In relation to a block ACK request frame supporting protection according to the present disclosure, transmitting STA(s) and receiving STA(s) may share / exchange information with each other regarding whether encryption (e.g., encryption based on CCMP or GCMP) for the block ACK request frame is supported. The information may be shared / exchanged via a specific element (e.g., RSNXE (RSN extension element)) in a discovery process (e.g., beacon frame, probe response frame, etc.) and / or a (re-)association process (e.g., (re-)association request frame, (re-)association response frame, etc.).
[0273] In this regard, whether CCMP or GCMP application for block ACK request frames is supported can be shared by utilizing reserved bits in existing elements (e.g., RSNXE) or by defining new (sub)fields in new elements. For example, a newly defined 1-bit protected block ACK request support (sub)field can be defined, and a value of 1 can be defined to mean / indicate that CCMP or GCMP application for block ACK request frames is supported, and a value of 0 can be defined to mean / indicate that CCMP or GCMP application for block ACK request frames is not supported.
[0274] If both the transmitting STA and the receiving STA support encryption and support applying encryption to the block ACK request frame, the two STAs can perform encryption application to the block ACK request frame. Conversely, if the transmitting STA and the receiving STA support encryption but do not support applying encryption to the block ACK request frame, the two STAs may not perform encryption to the block ACK request frame. Additionally, when encrypting the block ACK request frame, the cipher suite (e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, etc.) negotiated between the transmitting STA and the receiving STA during the negotiation process may be used identically. Alternatively, in order to encrypt the block ACK request frame, the transmitting STA and the receiving STA may negotiate an additional / separate cipher suite for the block ACK request frame.
[0275] Additionally or alternatively, in the case of existing wireless LAN systems, the transmitting STA and the receiving STA do not perform encryption / decryption operations based on CCMP or GCMP for the block ACK request frame, which is a type of control frame. In this regard, the protected frame subfield of the frame control field in the MAC header is set to reserved for control frames.
[0276] In contrast, when the BAR control field and / or the BAR information field are encrypted / decrypted based on CCMP or GCMP for the block ACK request frame according to various examples of the present disclosure, the value of the protected frame subfield in the frame control field of the corresponding block ACK request frame is set to 1. Based on this, the receiving STA can recognize that the BAR control field and / or the BAR information field in the corresponding block ACK request frame is encrypted through the value of the protected frame subfield. In this regard, when encrypting the block ACK request frame, the cipher suite (e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, etc.) negotiated between the transmitting STA and the receiving STA during the consultation process can be used in the same manner. Alternatively, in order to encrypt the block ACK request frame, the transmitting STA and the receiving STA may negotiate an additional / separate cipher suite for the corresponding block ACK request frame.
[0277] Additionally or alternatively, information may be shared between the transmitting STA and the receiving STA regarding whether encryption (i.e., CCMP or GCMP-based encryption) is supported for the block ACK request frame and / or the configuration of the CCMP / GCMP MPDU format according to any of the various examples of the present disclosure.
[0278] For example, information regarding whether encryption / decryption is supported and based on what method (e.g., the composition of the CCMP / GCMP MPDU format) during the (re-)association process may be indicated as a result of the agreement. Additionally or alternatively, this may be utilized to indicate the encryption / decryption mode for the block-ACK request frame exchanged during the data transmission and reception process after the (re-)association process.
[0279] In this regard, reserved bits in existing elements (e.g., RSNXE) and / or new (sub)fields (e.g., protected block ack request mode (sub)field) in new elements may be defined for sharing the relevant information. In this case, the method of encrypting / decrypting the block ACK request frame may use the same cipher suite (e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, etc.) agreed upon by the transmitting STA and the receiving STA during the consultation process, or an additional / separate cipher suite for the block ACK request frame may be agreed upon.
[0280] As described above, the (sub)field may be included in a beacon frame by a transmitting STA or in a data frame by a receiving STA not only during the (re-)association process but also during the data transmission and reception process. For example, setting the value of the Protected Block ACK Request Mode (sub)field to 0 may mean / indicate that CCMP or GCMP-based encryption is not applied to the block ACK request frame. Conversely, setting the value of the Protected Block ACK Request Mode (sub)field to 1 or more may mean / indicate that CCMP or GCMP-based encryption is applied to the block ACK request frame.
[0281] As a specific example, whether CCMP / GCMP encryption is applied depending on the value of the corresponding protected block ACK request mode (sub) field can be defined as in Table 1 below. Table 1 is an example, and at least one of the values described in Table 1 can be applied / defined, and the specific value can be set / defined differently from the example.
[0282] Meaning of the value of the protected block ACK request mode (sub) field in the existing element / new element 0 CCMP / GCMP is not applied to the block ACK request frame 1 Block ACK request frame configuration based on Example 1-1 2 Block ACK request frame configuration based on Example 1-2......
[0283] Additionally or alternatively, the reserved bits present in front of the key ID information (i.e., the key ID octet) in the CCMP header and / or GCMP header may be utilized as a protected block ACK request mode (sub)field to share information about whether encryption (i.e., CCMP or GCMP-based encryption) for the block ACK request frame is supported and according to which example among the various examples of the present disclosure the CCMP / GCMP MPDU format is configured. In this case, the method of encrypting / decrypting the block ACK request frame may use the same cipher suite (e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, etc.) agreed upon during the consultation process between the transmitting STA and the receiving STA, or an additional / separate cipher suite for the block ACK request frame may be agreed upon.
[0284] The corresponding (sub)field may be included in a data frame transmitted by a transmitting STA to a receiving STA during a data transmission / reception process. For example, setting the value of the protected block ACK request mode (sub)field to 0 may mean / indicate that CCMP or GCMP-based encryption is not applied to the corresponding block ACK request frame. Conversely, setting the value of the protected block ACK request mode (sub)field to 1 or more may mean / indicate that CCMP or GCMP-based encryption is applied to the block ACK request frame.
[0285] As a specific example, whether CCMP / GCMP encryption is applied depending on the value of the corresponding protected block ACK request mode (sub) field can be defined as in Table 2 below. Table 2 is an example, and at least one of the values described in Table 2 can be applied / defined, and the specific value can be set / defined differently from the example.
[0286] Meaning of the value of the Protected Block ACK Request Mode (Sub) field in the CCMP / GCMP header 0 CCMP / GCMP is not applied to the block ACK request frame 1 Block ACK request frame configuration based on Example 1-1 2 Block ACK request frame configuration based on Example 1-2......
[0287] Example 2
[0288] This embodiment relates to a method for generating an MIC for CCMP / GCMP transmission / reception in relation to the application of encryption to the aforementioned block ACK request frame.
[0289] For a block ACK request frame, the type (or variant) of the block ACK request frame being transmitted and received may be indicated based on the value of the BAR type subfield within the BAR control field. Depending on the indicated value, the receiving STA can determine whether the block ACK request frame is an individually addressed frame or a group addressed frame.
[0290] In this regard, when applying CCMP or GCMP to a block ACK request frame, the key used to calculate / set the MIC value may be used differently depending on whether it is an individually addressed frame or a group addressed frame.
[0291] For example, for individually addressed data frames, MIC value calculation may be performed using a TK based on a PTK generated identically between the transmitting STA and the receiving STA. Conversely, for group addressed data frames, MIC value calculation may be performed using a TK based on a GTK shared by the transmitting STA with the receiving STA.
[0292] For existing CCMP / GCMP (e.g., CCMP / GCMP applied to data frames / management frames), BIP utilization based on IGTK or BIGTK is possible, but CCMP and GCMP utilization based on IGTK or BIGTK is not possible. In contrast, the present disclosure assumes that CCMP and / or GCMP utilization based on PTK / GTK / IGTK / BIGTK is possible.
[0293] Below, we specifically describe how keys are used to calculate and verify MIC values for individually addressed block ACK request frames and / or group addressed block ACK request frames.
[0294] First, for individually addressed block ACK request frames, the MIC value can be calculated / verified as follows.
[0295] For example, a transmitting STA and a receiving STA can calculate an MIC value using a TK based on a PTK that is identically generated during a 4-way handshake process. For example, a transmitting STA and a receiving STA can equally use a PTK generated in relation to protection for a data frame during a 4-way handshake process for applying CCMP / GCMP to a block ACK frame. That is, a transmitting STA and a receiving STA can calculate an MIC value for a block ACK request frame using a TK based on a PTK generated in relation to protection for a unicast data frame during a 4-way handshake process.
[0296] As another example, the transmitting STA and the receiving STA may calculate the MIC value for the block ACK request frame using a TK based on a new key (e.g., a key distinct from the key (PTK) for the data frame) that is identically generated / agreed / shared between them during the 4-way handshake process for protection of the block ACK request frame.
[0297] The new key described above may be a key distinct from multiple STAs, or may be a common key for multiple STAs. For example, a transmitting STA may generate and share different new keys for a first receiving STA and a second receiving STA. Alternatively, the transmitting STA may generate and share the same new key for the first receiving STA and a second receiving STA. Here, a new KDE (key data element) generated by the transmitting STA and for the new key may include information related to the new key and a cipher suite that can use the new key, and may be shared with the receiving STA(s). For example, the new key may be referred to as a BARPTK (block ack request PTK) or a group BARPTK (group block ack request PTK).
[0298] If the receiving STA and the transmitting STA have generated or shared a new key for protecting the block ACK request frame, the MIC check can be performed on the received block ACK request frame using the generated / shared key. If the receiving STA and the transmitting STA have not generated or shared a new key for protecting the block ACK request frame, the MIC check can be performed on the received block ACK request frame using a key for encryption / decryption of unicast data frames (e.g., PTK).
[0299] Next, for group addressed block ACK request frames, the MIC value can be calculated / verified as follows.
[0300] For example, a transmitting STA can generate an IGTK or a BIGTK and share it with a receiving STA during a 4-way handshake process, and the transmitting STA and the receiving STA can use the IGTK or the TK based on the BIGTK to calculate the MIC value for a block ACK request frame.
[0301] As another example, a transmitting STA can generate a GTK and share it with a receiving STA during a 4-way handshake process, and the transmitting STA and the receiving STA can use a TK based on the GTK to calculate a MIC value for a block ACK request frame.
[0302] As another example, a transmitting STA can generate a new GTK (e.g., a key that is distinct from the existing IGTK / BIGTK / GTK) for a group-addressed block ACK request frame during a 4-way handshake process and share it with a receiving STA, and the transmitting STA and the receiving STA can calculate an MIC value using a TK based on the new GTK. Here, the new GTK can be referred to as a block ACK request broadcast GTK (BARGTK), and the transmitting STA can share a BARGTK of the same value with the receiving STAs. That is, an AP can generate and share the same BARGTK with its associated STAs. In addition, information about the BARGTK and information related to a cipher suite that can use the BARGTK can be shared between the transmitting STA and the receiving STA through the new KDE for the BARGTK (e.g., the BARGTK KDE).
[0303] If the receiving STA has received a key (e.g., BARGTK) for protecting the block ACK request frame from the transmitting STA, the receiving STA may perform an MIC check on the block ACK request frame based on the key. Otherwise, the receiving STA may perform an MIC check on the block ACK request frame based on a key (e.g., GTK, IGTK, or BIGTK) for broadcast frames previously shared with the transmitting STA.
[0304] Example 3
[0305] The present embodiment relates to a specific method for performing protection (i.e., encryption and integrity check) on a block ACK request frame based on the block ACK request frame configuration according to the present disclosure.
[0306] First, if the block ACK request frame is a group-addressed block ACK request frame, the configuration of the block ACK request frame can be used as follows to derive the MIC value.
[0307] For example, in the case of the block ACK request frame configuration described in Example 1-1 (e.g., see FIG. 19), the transmitting STA and / or the receiving STA may perform encryption / decryption via CCMP using GTK, IGTK, BIGTK, or BARGTK for the BAR control field and the BAR information field, and derive the MIC value.
[0308] For another example, in the case of the block ACK request frame configuration described in Example 1-2 (e.g., see FIG. 20), the transmitting STA and / or the receiving STA may perform encryption / decryption via GCMP using GTK, IGTK, BIGTK, or BARGTK for the BAR control field and the BAR information field, and derive the MIC value.
[0309] Next, if the block ACK request frame is an individually addressed block ACK request frame, the configuration of the block request ACK frame can be used as follows to derive the MIC value.
[0310] For example, in the case of the block ACK request frame configuration described in Example 1-1 (e.g., see FIG. 19), the transmitting STA and / or the receiving STA may perform encryption / decryption via CCMP using the aforementioned PTK or BAPTK or group BARPTK for the BAR control field and the BAR information field, and derive the MIC value.
[0311] For another example, in the case of the block ACK request frame configuration described in Example 1-2 (e.g., see FIG. 20), the transmitting STA and / or the receiving STA may perform encryption / decryption via GCMP using the aforementioned PTK or BARPTK or group BARPTK for the BAR control field and the BAR information field, and derive the MIC value.
[0312] Based on various examples of the present disclosure, protection for block ACK request frames can be performed as follows.
[0313] For the example situations described below, it is assumed that the transmitting STA and the receiving STA(s) support the use of block ACK request frames over CCMP or GCMP via the protected block ACK request support (sub)field and / or share the configuration method of the CCMP / GCMP MPDU format of the block ACK request frames via the protected block ACK request mode (sub)field.
[0314] A receiving STA can configure an AAD for a block ACK request frame based on information in the MAC header of the MPDU received from the transmitting STA (e.g., frame control field, duration field, RA field, TA field, etc.). Thereafter, the receiving STA can decode the MSDU using the AAD.
[0315] The receiving STA can obtain a plaintext MPDU and an MIC value based on the MPDU, which are the result of decryption based on the AAD and CCMP configured by the receiving STA for the block ACK request frame. At this time, the receiving STA can derive the MIC value by performing the same encryption process for the MPDU as the transmitting STA.
[0316] The receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the CCMP MPDU format or the GCMP MPDU format). If the two MIC values are the same, the receiving STA can follow the information in the acquired plaintext MPDU. Conversely, if the two MIC values are not the same, the receiving STA can recognize that at least one piece of information in the acquired plaintext MPDU has been modified by a third party STA (e.g., an attacking STA) or has been damaged during transmission and reception, and can discard it.
[0317] For CCMP, where the MIC is encrypted, the receiving STA can perform an integrity check using the MIC generated / calculated based on the plaintext derived by decrypting the MPDU. For GCMP, where the MIC is not encrypted, the receiving STA can first perform an integrity check using the value of the MIC field of the MPDU, and if the MIC values match, decrypt the MPDU.
[0318] The operation of an STA supporting / performing protection for a block-ACK request frame according to an embodiment of the present disclosure may be as shown in FIGS. 21 and 22.
[0319] FIG. 21 illustrates the operation of a transmitting STA that supports protection for a block-ACK request frame according to the present disclosure.
[0320] Referring to FIG. 21, a transmitting STA may share with a receiving STA information including whether it supports protection (e.g., confidentiality and integrity check) for a block-ACK request frame (S2110).
[0321] At this time, if both the transmitting STA and the receiving STA(s) apply security to the block-ACK request frame, the transmitting STA may generate and share key(s) (e.g., PTK / GTK / BARPTK / BARGTK(s)) used for confidentiality and integrity check of the block-ACK request frame (S2120). In this regard, the transmitting STA and the receiving STA may generate / negotiate / share the same key information through the key generation process, or the key information generated by the transmitting STA may be transmitted to the receiving STA.
[0322] Based on the key(s), the transmitting STA may apply CCMP or GCMP to the configured block-ACK request frame (S2130). In this regard, the transmitting STA may derive the MIC value for the block-ACK request frame using the key(s) previously shared with the receiving STA.
[0323] The transmitting STA may transmit a block-ACK request frame including result values / information for CCMP or GCMP application (S2140).
[0324] In relation to the above-described process, the transmitting STA may share / consult with the receiving STA in advance information on how to configure the CCMP / GCMP MPDU format in the transmitted block-ACK request frame, or may include the information in the block-ACK request frame and transmit it.
[0325] FIG. 22 illustrates the operation of a receiving STA that supports protection for a block-ACK request frame according to the present disclosure.
[0326] Referring to FIG. 22, the receiving STA may share with the transmitting STA information including whether it supports protection (e.g., confidentiality and integrity check) for the block-ACK request frame (S2210).
[0327] At this time, if the key(s) used for confidentiality and integrity check of the transmitting STA and the block-ACK request frame are shared, the receiving STA can assume that a protection method has been applied to the block-ACK request frame transmitted by the transmitting STA (S2220).
[0328] In this regard, the transmitting STA and the receiving STA may generate / negotiate / share the same key information (e.g., PTK / GTK / BARPTK / BARGTK, etc.) through a key generation process, or key information generated by the transmitting STA may be transmitted to the receiving STA.
[0329] For example, a receiving STA may receive a block-ACK request frame transmitted from a transmitting STA and recognize that CCMP or GCMP has been applied based on information related to the pre-shared key(s) and / or the composition of the CCMP / GCMP MPDU format in the block-ACK request frame.
[0330] Based on this, when a block-ACK request frame is received, the receiving STA can perform decryption by applying the block-ACK request frame to CCMP or GCMP based on the pre-shared / generated / agreed key(s) (e.g., PTK / GTK / BARPTK / BARGTK, etc.) (S2230).
[0331] Thereafter, the receiving STA can perform an integrity check by comparing the MIC value derived based on the decrypted block-ACK request frame with the MIC value transmitted by the transmitting STA (i.e., the MIC information / value included in the block-ACK request frame) (S2240).
[0332] Protocols such as CCMP / GCMP utilized in existing wireless LAN systems cannot provide protection for control frames such as block ACK request frames. The present disclosure defines protocols such as CCMP / GCMP for control frames such as block ACK request frames, thereby providing a new method for transmitting or receiving protected control frames.
[0333] The embodiments described above are combinations of components and features of the present disclosure in a predetermined form. Each component or feature should be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, it is also possible to form embodiments of the present disclosure by combining some components and / or features. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment. It is self-evident that claims that do not have an explicit citation relationship in the patent claims may be combined to form embodiments or incorporated as new claims through post-application amendments.
[0334] It will be apparent to those skilled in the art that the present disclosure may be embodied in other specific forms without departing from the essential characteristics of the present disclosure. Therefore, the above detailed description should not be construed as limiting in any respect, but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the scope of equivalents of the present disclosure are intended to be included within the scope of the present disclosure.
[0335] The scope of the present disclosure includes software or machine-executable instructions (e.g., an operating system, an application, firmware, a program, etc.) that cause operations according to the methods of various embodiments to be executed on a device or a computer, and a non-transitory computer-readable medium having such software or instructions stored thereon and executable on the device or computer. Instructions that can be used to program a processing system to perform the features described in the present disclosure can be stored on / in a storage medium or a computer-readable storage medium, and a computer program product including such a storage medium can be used to implement the features described in the present disclosure. The storage medium can include, but is not limited to, high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid state memory devices, and can include non-volatile memory, such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid state storage devices. The memory optionally includes one or more storage devices remotely located from the processor(s). The memory or, alternatively, the non-volatile memory device(s) within the memory comprise a non-transitory computer-readable storage medium. The features described in this disclosure may be incorporated into software and / or firmware stored on any of the machine-readable media, which may control the hardware of the processing system and allow the processing system to interact with other mechanisms that utilize results according to embodiments of the present disclosure. Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments / containers.
[0336] The method proposed in this disclosure has been described with a focus on examples applied to IEEE 802.11-based systems, but can be applied to various wireless LANs or wireless communication systems in addition to IEEE 802.11-based systems.
Claims
1. A step of generating a block ACK (acknowledgement) request frame based on an encryption protocol by the first station (STA); and A step of transmitting the block ACK request frame to the second STA by the first STA, The above block ACK request frame contains encrypted information based on the above encryption protocol, A method wherein the encrypted information is based on a block ACK request control field and a block ACK request information field in the frame body of the block ACK request frame.
2. In paragraph 1, A method in which encryption of the above block ACK request frame is performed based on key information related to protection of the above block ACK request frame.
3. In paragraph 1, A method wherein the block ACK request frame includes MIC (message integrity code) information calculated based on key information related to protection for the block ACK request frame.
4. In paragraph 1, Based on the fact that the above encryption protocol corresponds to CCMP (counter mode with cipher-block chaining message authentication code protocol), CCMP-128 or CCMP-256 is used as a cipher suite for the CCMP. A method wherein GCMP-128 or GCMP-256 is used as a cipher suite for the GCMP, based on the above specific encryption protocol corresponding to GCMP (galois / counter mode protocol).
5. In paragraph 1, A method wherein the encrypted information is further based on MIC information related to protection for the block ACK request frame, based on the above encryption protocol corresponding to CCMP.
6. In paragraph 1, A method wherein the above block ACK request frame includes an encryption protocol header including a first field for a key identifier and a second field for a packet number.
7. In paragraph 6, A method wherein the encryption protocol header further includes information on whether protection for the block ACK request frame is supported or at least one of the MPDU (MAC protocol data unit) formats according to the encryption protocol in the block ACK request frame.
8. In paragraph 1, A method in which information indicating whether protection for the block ACK request frame is supported is exchanged between the first STA and the second STA.
9. In paragraph 8, A method in which information indicating whether protection for the above block ACK request frame is supported is exchanged through at least one of a beacon frame, a probe request frame, a probe response frame, an association request frame, an association response frame, a re-association request frame, a re-association response frame, or the block ACK request frame.
10. In paragraph 1, A method in which a protected frame subfield in a frame control field included in the block ACK request frame is set to a predefined specific value based on the application of the encryption protocol to the block ACK request frame.
11. In paragraph 1, A method in which information on an MPDU format according to the encryption protocol is exchanged between the first STA and the second STA.
12. In paragraph 11, A method wherein information indicating an MPDU format according to the above encryption protocol is included in at least one of an association request frame, an association response frame, a re-association request frame, a re-association response frame, a beacon frame, or a data frame.
13. In paragraph 1, Based on the above block ACK request frame corresponding to an individually addressed control frame, key information related to protection for the block ACK request frame is based on a pairwise transient key (PTK) for the first STA and the second STA, A method wherein, based on the above block ACK request frame corresponding to a group addressed control frame, key information related to protection for the block ACK request frame is based on a group temporal key (GTK) for the first STA and the second STA.
14. In paragraph 1, The above block ACK request frame includes information related to a request for a block ACK for data to be received by the second STA, A method wherein key information related to protection for the above block ACK request frame is distinct from key information for protection of the above data.
15. One or more transmitters / receivers; and comprising one or more processors coupled to said one or more transceivers; One or more of the above processors: By the first station (STA), a block ACK (acknowledgement) request frame is generated based on an encryption protocol; By the above first STA, the block ACK request frame is set to be transmitted to the second STA, The above block ACK request frame contains encrypted information based on the above encryption protocol, A device wherein the encrypted information is based on a block ACK request control field and a block ACK request information field in the frame body of the block ACK request frame.
16. A step of receiving a block ACK (acknowledgement) request frame based on an encryption protocol from a first STA by a second station (STA); and A step of performing decryption and integrity check on the block ACK request frame by the second STA is included. The above block ACK request frame contains encrypted information based on the above encryption protocol, A method wherein the encrypted information is based on a block ACK request control field and a block ACK request information field in the frame body of the block ACK request frame.
17. One or more transmitters / receivers; and comprising one or more processors coupled to said one or more transceivers; One or more of the above processors: By a second station (STA), a block ACK (acknowledgement) request frame based on an encryption protocol is received from a first STA; By the above second STA, decryption and integrity check for the block ACK request frame are set to be performed, The above block ACK request frame contains encrypted information based on the above encryption protocol, A device wherein the encrypted information is based on a block ACK request control field and a block ACK request information field in the frame body of the block ACK request frame.
18. One or more processors; and A processing device comprising one or more computer memories operatively connected to said one or more processors and storing instructions for performing a method according to any one of claims 1 to 14 based on execution by said one or more processors.
19. One or more non-transitory computer-readable media storing one or more instructions that are executed by one or more processors to perform a method according to any one of claims 1 to 14.
Citation Information
Patent Citations
Crepe and its manufacturing method
KR1020230170168A
Method for predicting the rate of recovery from trauma after surgery by using feedback information
KR102606619B1