Method and device for supporting protection of control frame in wireless LAN system

The implementation of BIP-based integrity checks within Block ACK Request frames in wireless LAN systems addresses vulnerabilities by securing control frames, enhancing reliability and preventing unauthorized access.

WO2025143891A1PCT designated stage expired Publication Date: 2025-07-03LG ELECTRONICS INC
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/021313
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-11-25
Filing Date
2024-12-27
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Existing wireless LAN systems lack protection mechanisms for control frames, particularly for Block ACK Request (BAR) frames, which can be vulnerable to attacks leading to data transmission degradation and power waste.

Method used

Implement an integrity check based on Broadcast/Multicast Integrity Protocol (BIP) for Block ACK Request (BAR) frames by including protection-related information at various locations within the frame, such as the BAR control or information fields, to ensure secure transmission.

Benefits of technology

Enhances the security and integrity of control frames, preventing unauthorized access and ensuring reliable data transmission by verifying the integrity of Block ACK Request frames.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024021313_03072025_PF_FP_ABST
    Figure KR2024021313_03072025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a method and a device for supporting protection of a control frame in a wireless LAN system. The method according to an embodiment of the present disclosure may comprise the steps of: receiving, by a first station (STA), a block ACK request frame based on an integrity protocol from a second STA; and performing, by the first STA, an integrity check on the block ACK request frame. Here, the integrity protocol is applied to at least one field belonging to a frame body in the block ACK request frame, and protection-related information for the integrity check may be included in different positions in the block ACK request frame on the basis of the configuration of the field to which the integrity protocol is applied.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for supporting protection of control frames in a wireless LAN system

[0001] The present disclosure relates to a method and device for supporting protection of a control frame in a wireless local area network (WLAN) system.

[0002] New technologies have been introduced for wireless local area networks (WLANs) to improve transmission rates, increase bandwidth, enhance reliability, reduce errors, and reduce latency. Among WLAN technologies, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 series of standards can be referred to as Wi-Fi. For example, recently introduced technologies for WLANs include enhancements for Very High Throughput (VHT) in the 802.11ac standard and enhancements for High Efficiency (HE) in the IEEE 802.11ax standard.

[0003] To provide a more advanced wireless communication environment, improved technologies for Extremely High Throughput (EHT) are being discussed. For example, technologies for Multiple Input Multiple Output (MIMO), which supports increased bandwidth, efficient utilization of multiple bands, and increased spatial streams, and for multi-access point (AP) coordination are being studied. In particular, various technologies are being studied to support low latency or real-time traffic. Furthermore, new technologies are being discussed to support ultra-high reliability (UHR), including improvements or extensions of EHT technology.

[0004] The technical problem of the present disclosure is to provide a method and device for supporting protection of a control frame in a wireless LAN system.

[0005] The technical problem of the present disclosure is to provide a method and device for supporting an integrity check based on BIP (Broadcast / multicast integrity protocol) for a Block ACK Request (BAR) frame in a wireless LAN system.

[0006] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by a person having ordinary skill in the technical field to which the present disclosure belongs from the description below.

[0007] A method according to one aspect of the present disclosure may include the steps of: receiving, by a first station (STA), a block-ACK request frame based on an integrity protocol from a second STA; and performing, by the first STA, an integrity check on the block-ACK request frame. Here, the integrity protocol is applied to at least one field belonging to a frame body within the block-ACK request frame, and protection-related information for the integrity check may be included at different locations within the block-ACK request frame based on a configuration of a field to which the integrity protocol is applied.

[0008] A method according to an additional aspect of the present disclosure may include: generating, by a second station (STA), a block-ACK request frame based on an integrity protocol; and transmitting, by the second STA, the block-ACK request frame to a first STA. Here, the integrity protocol is applied to at least one field belonging to a frame body within the block-ACK request frame, and protection-related information for the integrity check may be included at different locations within the block-ACK request frame based on a configuration of a field to which the integrity protocol is applied.

[0009] According to various embodiments of the present disclosure, a method and device for supporting protection for a control frame in a wireless LAN system may be provided.

[0010] According to various embodiments of the present disclosure, a method and device for supporting BIP-based integrity check for a block-ACK request (BAR) frame in a wireless LAN system may be provided.

[0011] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.

[0012] The accompanying drawings, which are incorporated in and are part of the detailed description to aid in understanding the present disclosure, provide embodiments of the present disclosure and, together with the detailed description, describe the technical features of the present disclosure.

[0013] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.

[0014] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.

[0015] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.

[0016] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.

[0017] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.

[0018] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.

[0019] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.

[0020] FIG. 8 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.

[0021] FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure may be applied.

[0022] Figure 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.

[0023] Figure 11 shows an example of the format of conventional AAD.

[0024] Figure 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.

[0025] FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.

[0026] Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.

[0027] Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.

[0028] FIG. 16 is a diagram illustrating an exemplary format of a block-ACK request frame to which the present disclosure can be applied.

[0029] FIG. 17 illustrates a protection information field / subfield format according to an embodiment of the present disclosure.

[0030] FIG. 18 illustrates an example of a block-ACK request frame configuration supporting integrity check according to an embodiment of the present disclosure.

[0031] FIG. 19 illustrates another example of a block-ACK request frame configuration supporting integrity checking according to an embodiment of the present disclosure.

[0032] FIG. 20 illustrates another example of a block-ACK request frame configuration supporting integrity checking according to an embodiment of the present disclosure.

[0033] FIG. 21 illustrates the operation of a transmitting STA that supports integrity check for a block-ACK request frame according to the present disclosure.

[0034] FIG. 22 illustrates the operation of a receiving STA that supports integrity checking for a block-ACK request frame according to the present disclosure.

[0035] FIG. 23 is a drawing for explaining an example of a method performed by a first STA according to the present disclosure.

[0036] FIG. 24 is a diagram illustrating an example of a method performed by a second STA according to the present disclosure.

[0037] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to explain exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the present disclosure may be practiced. The following detailed description includes specific details to provide a thorough understanding of the present disclosure. However, one of ordinary skill in the art will appreciate that the present disclosure may be practiced without these specific details.

[0038] In some cases, to avoid obscuring the concepts of the present disclosure, known structures and devices may be omitted or illustrated in block diagram form focusing on the core functions of each structure and device.

[0039] In the present disclosure, when a component is said to be "connected," "coupled," or "connected" to another component, this may include not only a direct connection but also an indirect connection in which another component exists between them. Furthermore, the terms "comprises" or "has" in the present disclosure specify the presence of the mentioned features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof.

[0040] In this disclosure, terms such as “first,” “second,” etc. are used only to distinguish one component from another and are not used to limit the components, and do not limit the order or importance between the components unless specifically stated otherwise. Accordingly, within the scope of this disclosure, a first component in one embodiment may be referred to as a second component in another embodiment, and similarly, a second component in one embodiment may be referred to as a first component in another embodiment.

[0041] The terminology used herein is for the purpose of describing particular embodiments and is not intended to limit the scope of the claims. As used in the description of the embodiments and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. The term "and / or" as used herein may refer to any one of the associated enumerated items, or is meant to refer to and encompass any and all possible combinations of two or more of them. Furthermore, the use of " / " between words in this disclosure has the same meaning as "and / or" unless otherwise stated.

[0042] The examples of the present disclosure can be applied to various wireless communication systems. For example, the examples of the present disclosure can be applied to a wireless LAN system. For example, the examples of the present disclosure can be applied to a wireless LAN based on the IEEE 802.11a / g / n / ac / ax / be standards. Furthermore, the examples of the present disclosure can be applied to a wireless LAN based on the newly proposed IEEE 802.11bn (or UHR) standard. Additionally, the examples of the present disclosure can be applied to a wireless LAN based on the next-generation standard after IEEE 802.11bn. Furthermore, the examples of the present disclosure can be applied to a cellular wireless communication system. For example, the examples of the present disclosure can be applied to a cellular wireless communication system based on the LTE (Long Term Evolution) series of technologies and the 5G NR (New Radio) series of technologies of the 3rd Generation Partnership Project (3GPP) standard.

[0043] Below, technical features to which examples of the present disclosure can be applied are described.

[0044] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.

[0045] The first device (100) and the second device (200) illustrated in FIG. 1 may be replaced with various terms such as a terminal, a wireless device, a WTRU (Wireless Transmit Receive Unit), a UE (User Equipment), an MS (Mobile Station), a UT (user terminal), an MSS (Mobile Subscriber Station), an MSS (Mobile Subscriber Unit), an SS (Subscriber Station), an AMS (Advanced Mobile Station), a WT (Wireless terminal), or simply a user. In addition, the first device (100) and the second device (200) may be replaced with various terms such as an access point (AP), a BS (Base Station), a fixed station, a Node B, a BTS (Base Transceiver System), a network, an AI (Artificial Intelligence) system, an RSU (road side unit), a repeater, a router, a relay, a gateway, etc.

[0046] The devices (100, 200) illustrated in FIG. 1 may also be referred to as stations (STAs). For example, the devices (100, 200) illustrated in FIG. 1 may be referred to by various terms such as transmitting device, receiving device, transmitting STA, and receiving STA. For example, the STAs (110, 200) may perform an AP (access point) role or a non-AP role. That is, in the present disclosure, the STAs (110, 200) may perform the functions of an AP and / or a non-AP. When the STAs (110, 200) perform an AP function, they may simply be referred to as APs, and when the STAs (110, 200) perform a non-AP function, they may simply be referred to as STAs. In addition, in the present disclosure, the APs may also be referred to as AP STAs.

[0047] Referring to FIG. 1, the first device (100) and the second device (200) can transmit and receive wireless signals through various wireless LAN technologies (e.g., IEEE 802.11 series). The first device (100) and the second device (200) can include interfaces for a medium access control (MAC) layer and a physical layer (PHY) that follow the provisions of the IEEE 802.11 standard.

[0048] In addition, the first device (100) and the second device (200) may additionally support various communication standards (e.g., 3GPP LTE series, 5G NR series standards, etc.) other than wireless LAN technology. In addition, the device of the present disclosure may be implemented as various devices such as a mobile phone, a vehicle, a personal computer, an AR (Augmented Reality) device, a VR (Virtual Reality) device, etc. In addition, the STA of the present specification may support various communication services such as voice calls, video calls, data communications, autonomous driving, MTC (Machine-Type Communication), M2M (Machine-to-Machine), D2D (Device-to-Device), and IoT (Internet-of-Things).

[0049] A first device (100) includes one or more processors (102) and one or more memories (104), and may further include one or more transceivers (106) and / or one or more antennas (108). The processor (102) controls the memories (104) and / or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (102) may process information in the memories (104) to generate first information / signals, and then transmit a wireless signal including the first information / signals via the transceivers (106). Furthermore, the processor (102) may receive a wireless signal including second information / signals via the transceivers (106), and then store information obtained from signal processing of the second information / signals in the memory (104). The memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (102) and the memory (104) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (106) may be connected to the processor (102) and may transmit and / or receive wireless signals via one or more antennas (108). The transceiver (106) may include a transmitter and / or a receiver. The transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.

[0050] The second device (200) includes one or more processors (202), one or more memories (204), and may further include one or more transceivers (206) and / or one or more antennas (208). The processor (202) controls the memories (204) and / or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (202) may process information in the memory (204) to generate third information / signals, and then transmit a wireless signal including the third information / signals via the transceivers (206). Furthermore, the processor (202) may receive a wireless signal including fourth information / signals via the transceivers (206), and then store information obtained from signal processing of the fourth information / signals in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via one or more antennas (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.

[0051] Hereinafter, the hardware elements of the device (100, 200) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (102, 202). For example, one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC). One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and / or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, proposals and / or methods disclosed in the present disclosure, and provide the signals to one or more transceivers (106, 206). One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed in the present disclosure.

[0052] One or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. One or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this disclosure may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software configured to perform one or more processors (102, 202) or stored in one or more memories (104, 204) and driven by one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software in the form of codes, instructions and / or sets of instructions.

[0053] One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (104, 204) may be configured as ROM, RAM, EPROM, flash memory, hard drives, registers, cache memory, computer-readable storage media, and / or combinations thereof. The one or more memories (104, 204) may be located internally and / or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.

[0054] One or more transceivers (106, 206) can transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or flowcharts of the present disclosure, to one or more other devices. One or more transceivers (106, 206) can receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts of the present disclosure, from one or more other devices. For example, one or more transceivers (106, 206) can be coupled to one or more processors (102, 202) and can transmit and receive wireless signals. For example, one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals / channels, or the like, as referred to in the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure, via one or more antennas (108, 208). In the present disclosure, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers (106, 206) can convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (102, 202).One or more transceivers (106, 206) may convert user data, control information, wireless signals / channels, etc. processed by one or more processors (102, 202) from baseband signals to RF band signals. For this purpose, one or more transceivers (106, 206) may include an (analog) oscillator and / or filter.

[0055] For example, one of the STAs (100, 200) may perform the intended operation of an AP, and the other of the STAs (100, 200) may perform the intended operation of a non-AP STA. For example, the transceivers (106, 206) of FIG. 1 may perform transmission and reception operations of signals (e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a / b / g / n / ac / ax / be / bn, etc.). In addition, in the present disclosure, operations in which various STAs generate transmission and reception signals or perform data processing or calculations in advance for transmission and reception signals may be performed in the processors (102, 202) of FIG. 1. For example, an example of an operation for generating a transmission / reception signal or performing data processing or operation in advance for a transmission / reception signal may include 1) an operation for determining / obtaining / configuring / computing / decoding / encoding bit information of a field (SIG (signal), STF (short training field), LTF (long training field), Data, etc.) included in a PPDU, 2) an operation for determining / configuring / obtaining time resources or frequency resources (e.g., subcarrier resources) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 3) an operation for determining / configuring / obtaining a specific sequence (e.g., a pilot sequence, an STF / LTF sequence, an extra sequence applied to SIG) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 4) a power control operation and / or a power saving operation applied to an STA, 5) an operation related to determining / obtaining / configuring / computing / decoding / encoding an ACK signal, etc. Additionally, in the examples below, various information (e.g., information related to fields / subfields / control fields / parameters / power, etc.) used by various STAs for determining / acquiring / configuring / computing / decoding / encoding transmission / reception signals can be stored in the memory (104, 204) of FIG. 1.

[0056] Hereinafter, downlink (DL) refers to a link for communication from an AP STA to a non-AP STA, and downlink PPDUs / packets / signals, etc. can be transmitted and received through the downlink. In downlink communication, the transmitter may be part of an AP STA, and the receiver may be part of a non-AP STA. Uplink (UL) refers to a link for communication from a non-AP STA to an AP STA, and uplink PPDUs / packets / signals, etc. can be transmitted and received through the uplink. In uplink communication, the transmitter may be part of a non-AP STA, and the receiver may be part of an AP STA.

[0057] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.

[0058] The structure of a wireless LAN system can be composed of multiple components. Through the interaction of multiple components, a wireless LAN that supports transparent STA mobility to the upper layer can be provided. A Basic Service Set (BSS) corresponds to a basic building block of a wireless LAN. FIG. 2 illustrates, by way of example, the existence of two BSSs (BSS1 and BSS2) and the inclusion of two STAs as members of each BSS (STA1 and STA2 are included in BSS1, and STA3 and STA4 are included in BSS2). The oval representing a BSS in FIG. 2 can also be understood as representing a coverage area in which STAs included in the corresponding BSS maintain communication. This area can be referred to as a Basic Service Area (BSA). When an STA moves outside of a BSA, it cannot directly communicate with other STAs within the BSA.

[0059] If we do not consider the DS illustrated in Figure 2, the most basic type of BSS in a wireless LAN is an Independent BSS (IBSS). For example, an IBSS can have a minimal form consisting of only two STAs. For example, assuming other components are omitted, BSS1 consisting of only STA1 and STA2, or BSS2 consisting of only STA3 and STA4, can be representative examples of an IBSS, respectively. Such a configuration is possible when the STAs can communicate directly without an AP. Furthermore, in this type of WLAN, a LAN can be configured when needed rather than being planned in advance, and this can be called an ad-hoc network. Since an IBSS does not include an AP, there is no centralized management entity. That is, in an IBSS, STAs are managed in a distributed manner. In IBSS, all STAs can be mobile STAs, and access to distributed systems (DS) is not permitted, forming a self-contained network.

[0060] An STA's membership in a BSS can dynamically change, for example, when an STA is turned on or off, or when an STA enters or leaves a BSS area. To become a member of a BSS, an STA can join the BSS using a synchronization process. To access all services in the BSS infrastructure, an STA must be associated with the BSS. This association can be dynamically established and may involve the use of a Distribution System Service (DSS).

[0061] In a wireless LAN, the direct STA-to-STA distance can be limited by PHY performance. While this distance limit may be sufficient in some cases, communication between STAs over longer distances may be required in other cases. To support extended coverage, a distributed system (DS) can be configured.

[0062] DS refers to a structure in which BSSs are interconnected. Specifically, a BSS may exist as an extended component of a network composed of multiple BSSs, as illustrated in Figure 2. DS is a logical concept and can be specified by the characteristics of a distributed system medium (DSM). In this regard, the Wireless Medium (WM) and DSM can be logically distinguished. Each logical medium is used for a different purpose and by different components. These media are neither limited to being identical nor limited to being different. This logical difference between multiple media explains the flexibility of the WLAN architecture (DS architecture or other network architectures). In other words, the WLAN architecture can be implemented in various ways, and the physical characteristics of each implementation can independently specify the WLAN architecture.

[0063] A DS can support mobile devices by providing seamless integration of multiple BSSs and the logical services necessary to handle addresses to destinations. Additionally, a DS may further include a component called a portal, which acts as a bridge for connecting wireless LANs to other networks (e.g., IEEE 802.X).

[0064] An AP is an entity that enables access to a DS through a WM for associated non-AP STAs and also has the functionality of an STA. Data movement between a BSS and a DS can be performed through an AP. For example, STA2 and STA3 illustrated in FIG. 2 have the functionality of an STA and provide the function of allowing associated non-AP STAs (STA1 and STA4) to access the DS. In addition, since all APs are basically STAs, all APs are addressable entities. The address used by an AP for communication on a WM and the address used by an AP for communication on a DSM do not necessarily have to be the same. A BSS consisting of an AP and one or more STAs can be referred to as an infrastructure BSS.

[0065] Data transmitted from one of the STA(s) associated with an AP to the STA address of that AP may always be received on an uncontrolled port and processed by an IEEE 802.1X port access entity. In addition, if the controlled port is authenticated, the transmitted data (or frame) may be forwarded to the DS.

[0066] In addition to the structure of the DS described above, an extended service set (ESS) may be established to provide wider coverage.

[0067] An ESS is a network of arbitrary size and complexity, consisting of DSs and BSSs. An ESS may correspond to a set of BSSs connected to a DS. However, an ESS does not include a DS. An ESS network is characterized by appearing as an IBSS at the Logical Link Control (LLC) layer. STAs within an ESS can communicate with each other, and mobile STAs can move from one BSS to another (within the same ESS) transparently to the LLC. APs within an ESS may have the same SSID (service set identification). The SSID is distinct from the BSSID, which is the identifier of the BSS.

[0068] In a wireless LAN system, no assumptions are made about the relative physical locations of BSSs, and all of the following configurations are possible: BSSs can be partially overlapping, which is commonly used to provide continuous coverage. BSSs can also be physically disconnected, and there is no logical distance limit between them. BSSs can also be physically co-located, which can be used to provide redundancy. Furthermore, one (or more) IBSS or ESS networks can physically co-exist with one (or more) ESS networks. This can occur in cases where an ad-hoc network operates at the same location as an ESS network, where physically overlapping wireless networks are configured by different organizations, or where two or more different access and security policies are required at the same location.

[0069] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.

[0070] For an STA to set up a link and transmit and receive data on a network, it must first discover the network, perform authentication, establish an association, and complete security authentication procedures. The link setup process can also be referred to as the session initiation process or session setup process. Furthermore, the discovery, authentication, association, and security setup processes of the link setup process can be collectively referred to as the association process.

[0071] In step S310, the STA may perform a network discovery operation. This network discovery operation may include scanning operations by the STA. That is, for the STA to access a network, it must search for available networks. Before joining a wireless network, the STA must identify compatible networks. The process of identifying networks in a specific area is called scanning.

[0072] Scanning methods include active scanning and passive scanning. Figure 3 illustrates a network discovery operation including an active scanning process as an example. In active scanning, an STA performing scanning transmits a probe request frame to discover any APs in the vicinity while moving between channels and waits for a response. The responder transmits a probe response frame in response to the STA that transmitted the probe request frame. Here, the responder may be the STA that last transmitted a beacon frame in the BSS of the channel being scanned. In the BSS, the AP transmits the beacon frame, so the AP becomes the responder. In the IBSS, the STAs within the IBSS take turns transmitting beacon frames, so the responder is not fixed. For example, an STA that transmits a probe request frame on channel 1 and receives a probe response frame on channel 1 can store BSS-related information included in the received probe response frame and move to the next channel (e.g., channel 2) to perform scanning (i.e., transmitting and receiving probe requests / responses on channel 2) in the same manner.

[0073] Although not shown in Figure 3, the scanning operation can also be performed in a passive scanning manner. In passive scanning, the STA performing the scanning moves between channels and waits for a beacon frame. A beacon frame is one of the management frames defined in IEEE 802.11. It announces the existence of a wireless network and is periodically transmitted so that the STA performing the scanning can find the wireless network and participate in the wireless network. In the BSS, the AP performs the role of periodically transmitting the beacon frame, and in the IBSS, the STAs within the IBSS take turns transmitting the beacon frame. When the STA performing the scanning receives a beacon frame, it stores the information about the BSS included in the beacon frame and moves to another channel, recording the beacon frame information on each channel. The STA receiving the beacon frame stores the BSS-related information included in the received beacon frame and moves to the next channel to perform scanning on the next channel in the same manner. Comparing active scanning and passive scanning, active scanning has the advantage of lower delay and power consumption than passive scanning.

[0074] After the STA discovers the network, an authentication process may be performed in step S320. This authentication process may be referred to as the first authentication process to clearly distinguish it from the security setup operation of step S340 described below.

[0075] The authentication process involves the STA sending an authentication request frame to the AP, and the AP responding by sending an authentication response frame to the STA. The authentication frame used for the authentication request / response corresponds to a management frame.

[0076] The authentication frame may include information such as an authentication algorithm number, an authentication transaction sequence number, a status code, a challenge text, a Robust Security Network (RSN), and a Finite Cyclic Group. These are just some examples of information that may be included in an authentication request / response frame, and may be replaced with other information or include additional information.

[0077] An STA can send an authentication request frame to an AP. The AP can determine whether to grant authentication to the STA based on the information contained in the received authentication request frame. The AP can provide the result of the authentication process to the STA via an authentication response frame.

[0078] After the STA is successfully authenticated, an association process may be performed in step S330. The association process includes a process in which the STA transmits an association request frame to the AP, and in response, the AP transmits an association response frame to the STA.

[0079] For example, the association request frame may include information about various capabilities, a beacon listen interval, a service set identifier (SSID), supported rates, supported channels, an RSN, a mobility domain, supported operating classes, a Traffic Indication Map Broadcast request, interworking service capabilities, etc. For example, the association response frame may include information about various capabilities, a status code, an Association ID (AID), supported rates, an Enhanced Distributed Channel Access (EDCA) parameter set, a Received Channel Power Indicator (RCPI), a Received Signal to Noise Indicator (RSNI), a mobility domain, a timeout interval (e.g., an association comeback time), overlapping BSS scan parameters, a TIM broadcast response, a Quality of Service (QoS) map, etc. These are just some examples of information that may be included in a combined request / response frame, and may be replaced by other information or include additional information.

[0080] After the STA successfully joins the network, a security setup process may be performed in step S340. The security setup process in step S340 may be referred to as an authentication process through a Robust Security Network Association (RSNA) request / response, the authentication process in step S320 may be referred to as a first authentication process, and the security setup process in step S340 may also be referred to simply as an authentication process.

[0081] The security setup process of step S340 may include, for example, a process of establishing a private key through a four-way handshaking using an Extensible Authentication Protocol over LAN (EAPOL) frame. Furthermore, the security setup process may be performed according to a security method not defined in the IEEE 802.11 standard.

[0082] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.

[0083] In wireless LAN systems, the basic access mechanism of MAC (Medium Access Control) is Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA). The CSMA / CA mechanism, also known as the Distributed Coordination Function (DCF) of the IEEE 802.11 MAC, essentially employs a "listen before talk" access mechanism. According to this type of access mechanism, the AP and / or STA may perform a Clear Channel Assessment (CCA) to sense the wireless channel or medium for a predetermined time period (e.g., a DCF Inter-Frame Space (DIFS)) before starting transmission. If the sensing result determines that the medium is in an idle state, the AP and / or STA may start transmitting frames through the medium. On the other hand, if the medium is detected to be occupied or busy, the AP and / or STA may not start its own transmission, but may wait for a delay period (e.g., a random backoff period) for medium access before attempting to transmit frames. By applying a random backoff period, multiple STAs are expected to attempt to transmit frames after waiting for different periods of time, thereby minimizing collisions.

[0084] In addition, the IEEE 802.11 MAC protocol provides the Hybrid Coordination Function (HCF). The HCF is based on the DCF and the Point Coordination Function (PCF). The PCF is a polling-based synchronous access method that periodically polls all receiving APs and / or STAs to ensure that they receive data frames. In addition, the HCF has the Enhanced Distributed Channel Access (EDCA) and the HCF Controlled Channel Access (HCCA). The EDCA is a contention-based access method for a provider to provide data frames to multiple users, while the HCCA uses a non-contention-based channel access method that utilizes a polling mechanism. In addition, the HCF includes a medium access mechanism to improve the Quality of Service (QoS) of the wireless LAN, and can transmit QoS data in both the Contention Period (CP) and the Contention Free Period (CFP).

[0085] Referring to Fig. 4, an operation based on a random backoff period is described. When a medium that was occupied / busy changes to an idle state, multiple STAs can attempt to transmit data (or frames). To minimize collisions, each STA can select a random backoff count, wait for the corresponding slot time, and then attempt transmission. The random backoff count has a pseudo-random integer value and can be determined as one of the values ​​in the range of 0 to CW. Here, CW is a contention window parameter value. The CW parameter is given an initial value of CWmin, but can take a value doubled in case of transmission failure (e.g., when an ACK for a transmitted frame is not received). When the CW parameter value becomes CWmax, data transmission can be attempted while maintaining the CWmax value until data transmission is successful, and if data transmission is successful, it is reset to the CWmin value. The CW, CWmin, and CWmax values ​​are 2. n It is desirable to set it to -1 (n=0, 1, 2, ...).

[0086] Once the random backoff process begins, the STA continues to monitor the medium while counting down the backoff slots according to the determined backoff count value. If the medium is monitored as occupied, the countdown stops and waits. When the medium becomes idle, the remaining countdown resumes.

[0087] In the example of FIG. 4, when a packet to be transmitted reaches the MAC of STA3, STA3 can immediately transmit a frame if it confirms that the medium is idle for DIFS. The remaining STAs monitor the medium for occupied / busy states and wait. In the meantime, data to be transmitted may also occur in each of STA1, STA2, and STA5, and each STA can count down the backoff slot according to a random backoff count value selected by each STA after waiting for DIFS if the medium is monitored as idle. Assume that STA2 selects the smallest backoff count value and STA1 selects the largest backoff count value. In other words, this example shows a case where the remaining backoff time of STA5 is shorter than the remaining backoff time of STA1 when STA2 finishes the backoff count and starts frame transmission. STA1 and STA5 briefly stop counting down and wait while STA2 occupies the medium. When STA2's occupation ends and the medium becomes idle again, STA1 and STA5 wait for DIFS and then resume the backoff count that they had stopped. That is, they can start transmitting frames after counting down the remaining backoff slots equal to the remaining backoff time. Since STA5's remaining backoff time is shorter than STA1's, STA5 starts transmitting frames. While STA2 occupies the medium, STA4 may also have data to transmit. From STA4's perspective, when the medium becomes idle, it waits for DIFS, counts down according to its selected random backoff count value, and then starts transmitting frames. In the example of Figure 4, the remaining backoff time of STA5 coincidentally matches the random backoff count value of STA4, in which case a collision may occur between STA4 and STA5. If a collision occurs, neither STA4 nor STA5 will receive an ACK, resulting in a failure in data transmission.In this case, STA4 and STA5 can select a random backoff count value and perform a countdown after doubling the CW value. STA1 waits while the medium is occupied by transmissions from STA4 and STA5, and when the medium becomes idle, it waits for DIFS and can start transmitting frames after the remaining backoff time elapses.

[0088] As in the example of Fig. 4, a data frame is a frame used for transmitting data forwarded to a higher layer, and can be transmitted after a backoff performed after DIFS elapses from when the medium becomes idle. Additionally, a management frame is a frame used for exchanging management information that is not forwarded to a higher layer, and is transmitted after a backoff performed after an IFS elapses, such as DIFS or PIFS (Point coordination function IFS). Subtype frames of a management frame include a beacon, an association request / response, a re-association request / response, a probe request / response, and an authentication request / response. A control frame is a frame used to control access to the medium. The subtype frames of the control frame include Request-To-Send (RTS), Clear-To-Send (CTS), Acknowledgment (ACK), Power Save-Poll (PS-Poll), Block ACK (BlockAck), Block ACK Request (BlockACKReq), Null Data Packet Announcement (NDP), and Trigger. If the control frame is not a response frame to the previous frame, it is transmitted after a backoff performed after the DIFS (Direct Inverse Frame Stop) has elapsed, and if it is a response frame to the previous frame, it is transmitted without a backoff performed after the SIFS (short IFS). The type and subtype of the frame can be identified by the type field and subtype field in the Frame Control (FC) field.

[0089] A QoS (Quality of Service) STA can transmit a frame after a backoff performed after the AIFS (arbitration IFS) for the access category (AC) to which the frame belongs, i.e., AIFS[i] (where i is a value determined by the AC), has elapsed. Here, the frames for which AIFS[i] can be used can be data frames, management frames, and also control frames that are not response frames.

[0090] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.

[0091] As mentioned above, the CSMA / CA mechanism includes virtual carrier sensing in addition to physical carrier sensing, in which STAs directly sense the medium. Virtual carrier sensing is intended to address potential issues in medium access, such as the hidden node problem. For virtual carrier sensing, the MAC of an STA can utilize a Network Allocation Vector (NAV). The NAV is a value that an STA that is currently using or has the right to use the medium indicates to other STAs the remaining time until the medium becomes available. Therefore, the value set as NAV corresponds to the period during which the STA transmitting the frame is scheduled to use the medium, and an STA receiving the NAV value is prohibited from accessing the medium during that period. For example, the NAV can be set based on the value of the "duration" field in the MAC header of the frame.

[0092] In the example of FIG. 5, it is assumed that STA1 wants to transmit data to STA2, and STA3 is in a position to overhear some or all of the frames transmitted and received between STA1 and STA2.

[0093] In order to reduce the possibility of collisions in transmissions of multiple STAs in a CSMA / CA-based frame transmission operation, a mechanism using RTS / CTS frames may be applied. In the example of FIG. 5, while STA1 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA1 may correspond to a hidden node for STA3. Alternatively, in the example of FIG. 5, while STA2 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA2 may correspond to a hidden node for STA3. By exchanging RTS / CTS frames before performing data transmission and reception between STA1 and STA2, STAs outside the transmission range of either STA1 or STA2, or STAs outside the carrier sensing range for transmissions from STA1 or STA3, may not attempt to occupy the channel during data transmission and reception between STA1 and STA2.

[0094] Specifically, STA1 can determine whether a channel is occupied through carrier sensing. In terms of physical carrier sensing, STA1 can determine channel occupancy idleness based on the energy level or signal correlation detected in the channel. Furthermore, in terms of virtual carrier sensing, STA1 can determine the channel occupancy status using a network allocation vector (NAV) timer.

[0095] STA1 can transmit an RTS frame to STA2 after performing a backoff if the channel is idle during the DIFS. STA2 can transmit a CTS frame, which is a response to the RTS frame, to STA1 after an SIFS if it receives the RTS frame.

[0096] If STA3 cannot overhear a CTS frame from STA2 but can overhear an RTS frame from STA1, STA3 can use the duration information contained in the RTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + CTS frame + SIFS + data frame + SIFS + ACK frame). Alternatively, if STA3 cannot overhear an RTS frame from STA1 but can overhear a CTS frame from STA2, STA3 can use the duration information contained in the CTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + data frame + SIFS + ACK frame). That is, if STA3 can overhear one or more of the RTS or CTS frames from one or more of STA1 or STA2, it can set a NAV accordingly. If STA3 receives a new frame before the NAV timer expires, it can update the NAV timer using the duration information contained in the new frame. STA3 does not attempt channel access until the NAV timer expires.

[0097] If STA1 receives a CTS frame from STA2, it can transmit a data frame to STA2 after SIFS from the time when the CTS frame is completely received. If STA2 successfully receives the data frame, it can transmit an ACK frame in response to the data frame to STA1 after SIFS. STA3 can determine whether the channel is in use through carrier sensing if the NAV timer expires. If STA3 determines that the channel is not in use by another terminal during the DIFS after the NAV timer expires, it can attempt channel access after a contention window (CW) based on a random backoff has elapsed.

[0098] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.

[0099] The PHY layer can prepare an MPDU (MAC PDU) to be transmitted based on an instruction or primitive (meaning a set of instructions or parameters) from the MAC layer. For example, when a command requesting the start of transmission of the PHY layer is received from the MAC layer, the PHY layer can switch to transmission mode and transmit the information (e.g., data) provided by the MAC layer in the form of a frame. In addition, when the PHY layer detects a valid preamble of the received frame, it monitors the header of the preamble and sends a command to the MAC layer notifying the start of reception of the PHY layer.

[0100] In this way, information transmission / reception in a wireless LAN system is done in the form of frames, and for this purpose, the PHY layer Protocol Data Unit (PPDU) format is defined.

[0101] A basic PPDU may include a Short Training Field (STF), a Long Training Field (LTF), a SIGNAL (SIG) field, and a Data field. The most basic (e.g., non-HT (High Throughput) as illustrated in FIG. 7) PPDU format may consist of only the Legacy-STF (L-STF), Legacy-LTF (L-LTF), Legacy-SIG (L-SIG) fields, and a Data field. Additionally, depending on the type of PPDU format (e.g., HT-mixed format PPDU, HT-greenfield format PPDU, VHT (Very High Throughput) PPDU, etc.), additional (or different types of) RL-SIG, U-SIG, non-legacy SIG field, non-legacy STF, non-legacy LTF, (i.e., xx-SIG, xx-STF, xx-LTF (e.g., xx is HT, VHT, HE, EHT, etc.)) may be included between the L-SIG field and the data field. More specific details will be described later with reference to FIG. 7.

[0102] STF is a signal for signal detection, AGC (Automatic Gain Control), diversity selection, and precise time synchronization, while LTF is a signal for channel estimation, frequency error estimation, etc. STF and LTF can be said to be signals for synchronization and channel estimation of the OFDM physical layer.

[0103] The SIG field may include various information related to PPDU transmission and reception. For example, the L-SIG field may consist of 24 bits and may include a 4-bit Rate field, a 1-bit Reserved bit, a 12-bit Length field, a 1-bit Parity field, and a 6-bit Tail field. The RATE field may include information about the modulation and coding rate of data. For example, the 12-bit Length field may include information about the length or time duration of the PPDU. For example, the value of the 12-bit Length field may be determined based on the type of the PPDU. For example, for a non-HT, HT, VHT, or EHT PPDU, the value of the Length field may be determined as a multiple of 3. For example, for HE PPDU, the value of the Length field can be determined as a multiple of 3 + 1 or a multiple of 3 + 2.

[0104] The data field may include a SERVICE field, a Physical layer Service Data Unit (PSDU), a PPDU TAIL bit, and, if necessary, padding bits. Some bits of the SERVICE field may be used to synchronize the descrambler at the receiving end. The PSDU corresponds to a MAC PDU defined at the MAC layer and may contain data generated / used by upper layers. The PPDU TAIL bit may be used to return the encoder to a 0 state. The padding bit may be used to adjust the length of the data field to a predetermined unit.

[0105] MAC PDUs are defined according to various MAC frame formats, and a basic MAC frame consists of a MAC header, a frame body, and a Frame Check Sequence (FCS). A MAC frame is composed of MAC PDUs and can be transmitted / received through the PSDU in the data portion of the PPDU format.

[0106] The MAC header includes a Frame Control field, a Duration / ID field, an Address field, etc. The Frame Control field may include control information required for frame transmission / reception. The Duration / ID field may be set to a time for transmitting the corresponding frame, etc. The Address subfields may indicate the receiver address, transmitter address, destination address, and source address of the frame, and some Address subfields may be omitted. For specific details of each subfield of the MAC header, including the Sequence Control, QoS Control, and HT Control subfields, refer to the IEEE 802.11 standard document.

[0107] The Null-Data PPDU (NDP) format refers to a PPDU format that does not include a data field. In other words, NDP refers to a frame format that includes a PPDU preamble (i.e., L-STF, L-LTF, L-SIG fields, and, if additionally present, non-legacy SIG, non-legacy STF, and non-legacy LTF) in the general PPDU format, and does not include the remaining part (i.e., data field).

[0108] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.

[0109] Standards such as IEEE 802.11a / g / n / ac / ax use various PPDU formats. The basic PPDU format (IEEE 802.11a / g) includes L-LTF, L-STF, L-SIG, and Data fields. The basic PPDU format can also be referred to as the non-HT PPDU format (Fig. 7(a)).

[0110] The HT PPDU format (IEEE 802.11n) additionally includes HT-SIG, HT-STF, and HT-LFT(s) fields in addition to the basic PPDU format. The HT PPDU format illustrated in Fig. 7(b) may be referred to as an HT-mixed format. Additionally, an HT-greenfield format PPDU may be defined, which corresponds to a format that does not include L-STF, L-LTF, and L-SIG, but consists of HT-GF-STF, HT-LTF1, HT-SIG, one or more HT-LTF, and Data fields (not illustrated).

[0111] An example of the VHT PPDU format (IEEE 802.11ac) includes VHT SIG-A, VHT-STF, VHT-LTF, and VHT-SIG-B fields in addition to the basic PPDU format (Fig. 7(c)).

[0112] An example of a HE PPDU format (IEEE 802.11ax) additionally includes RL-SIG (Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), and PE (Packet Extension) fields in addition to the basic PPDU format (Fig. 7(d)). Depending on specific examples of the HE PPDU format, some fields may be excluded or their lengths may vary. For example, the HE-SIG-B field is included in the HE PPDU format for multi-users (MUs), but the HE PPDU format for single users (SUs) does not include the HE-SIG-B. In addition, the HE trigger-based (TB) PPDU format does not include the HE-SIG-B, and the length of the HE-STF field may vary to 8us. The HE ER (Extended Range) SU PPDU format does not include the HE-SIG-B field, and the length of the HE-SIG-A field may vary to 16us. For example, RL-SIG can be configured identically to L-SIG. The receiving STA can determine that the received PPDU is a HE PPDU or an EHT PPDU, described later, based on the presence of RL-SIG.

[0113] The EHT PPDU format may include the EHT MU (multi-user) PPDU of FIG. 7(e) and the EHT TB (trigger-based) PPDU of FIG. 7(f). The EHT PPDU format is similar to the HE PPDU format in that it includes an RL-SIG following an L-SIG, but may include a U (universal)-SIG, an EHT-SIG, an EHT-STF, and an EHT-LTF following the RL-SIG.

[0114] The EHT MU PPDU in FIG. 7(e) corresponds to a PPDU that carries one or more data (or PSDUs) for one or more users. That is, the EHT MU PPDU can be used for both SU transmission and MU transmission. For example, the EHT MU PPDU can correspond to a PPDU for one receiving STA or multiple receiving STAs.

[0115] The EHT TB PPDU of Fig. 7(f) omits the EHT-SIG compared to the EHT MU PPDU. An STA that has received a trigger for UL MU transmission (e.g., a trigger frame or TRS (triggered response scheduling)) can perform UL transmission based on the EHT TB PPDU format.

[0116] The L-STF, L-LTF, L-SIG, RL-SIG, U-SIG (Universal SIGNAL), and EHT-SIG fields can be encoded and modulated to allow legacy STAs to attempt demodulation and decoding, and mapped based on a predetermined subcarrier frequency interval (e.g., 312.5 kHz). These can be referred to as pre-EHT modulated fields. Next, the EHT-STF, EHT-LTF, Data, and PE fields can be encoded and modulated to allow STAs that have successfully decoded non-legacy SIGs (e.g., U-SIG and / or EHT-SIG) and obtained the information contained in the fields, and mapped based on a predetermined subcarrier frequency interval (e.g., 78.125 kHz). These can be referred to as EHT modulated fields.

[0117] Similarly, in the HE PPDU format, the L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, and HE-SIG-B fields may be referred to as pre-HE modulation fields, and the HE-STF, HE-LTF, Data, and PE fields may be referred to as HE modulation fields. Additionally, in the VHT PPDU format, the L-STF, L-LTF, L-SIG, and VHT-SIG-A fields may be referred to as pre-VHT modulation fields, and the VHT STF, VHT-LTF, VHT-SIG-B, and Data fields may be referred to as VHT modulation fields.

[0118] The U-SIG included in the EHT PPDU format of FIG. 7 can be configured based on, for example, two symbols (e.g., two consecutive OFDM symbols). Each symbol (e.g., OFDM symbol) for the U-SIG can have a duration of 4 us, and the U-SIG can have a total duration of 8 us. Each symbol of the U-SIG can be used to transmit 26 bits of information. For example, each symbol of the U-SIG can be transmitted and received based on 52 data tones and 4 pilot tones.

[0119] U-SIGs can be configured in 20MHz units. For example, when an 80MHz PPDU is configured, the same U-SIG can be duplicated in 20MHz units. That is, four identical U-SIGs can be included in an 80MHz PPDU. When the bandwidth exceeds 80MHz, for example, for a 160MHz PPDU, the U-SIGs in the first 80MHz unit and the U-SIGs in the second 80MHz unit can be different.

[0120] For example, A uncoded bits may be transmitted via U-SIG, and a first symbol of U-SIG (e.g., a U-SIG-1 symbol) may transmit the first X bits of information out of a total A bits of information, and a second symbol of U-SIG (e.g., a U-SIG-2 symbol) may transmit the remaining Y bits of information out of a total A bits of information. The A bits of information (e.g., 52 uncoded bits) may include a CRC field (e.g., a field of 4 bits in length) and a tail field (e.g., a field of 6 bits in length). The tail field may be used to terminate the trellis of the convolutional decoder and may be set to 0, for example.

[0121] The A bit information transmitted by U-SIG can be divided into version-independent bits and version-dependent bits. For example, U-SIG can be included in a new PPDU format (e.g., UHR PPDU format) not shown in FIG. 7, and in the format of the U-SIG field included in the EHT PPDU format and the format of the U-SIG field included in the UHR PPDU format, the version-independent bits can be the same, and some or all of the version-dependent bits can be different.

[0122] For example, the size of the version-independent bits of U-SIG can be fixed or variable. The version-independent bits can be assigned only to U-SIG-1 symbols, or to both U-SIG-1 symbols and U-SIG-2 symbols. The version-independent bits and the version-dependent bits can be called by various names, such as the first control bit and the second control bit.

[0123] For example, the version-independent bits of the U-SIG may include a 3-bit PHY version identifier, which may indicate the PHY version (e.g., EHT, UHR, etc.) of the transmitted and received PPDUs. The version-independent bits of the U-SIG may include a 1-bit UL / DL flag field. The first value of the 1-bit UL / DL flag field relates to UL communication, and the second value of the UL / DL flag field relates to DL communication. The version-independent bits of the U-SIG may include information about the length of a transmission opportunity (TXOP) and information about a BSS color ID.

[0124] For example, the version-dependent bits of the U-SIG may contain information that directly or indirectly indicates the type of PPDU (e.g., SU PPDU, MU PPDU, TB PPDU, etc.).

[0125] Information required for PPDU transmission and reception may be included in the U-SIG. For example, the U-SIG may further include information about bandwidth, information about the MCS technique applied to the non-legacy SIG (e.g., EHT-SIG or UHR-SIG), information indicating whether a dual carrier modulation (DCM) technique (e.g., a technique to achieve an effect similar to frequency diversity by reusing the same signal on two subcarriers) is applied to the non-legacy SIG, information about the number of symbols used for the non-legacy SIG, information about whether the non-legacy SIG is generated across the entire band, etc.

[0126] Some of the information required for transmitting and receiving a PPDU may be included in the U-SIG and / or the non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.). For example, information about the type of the non-legacy LTF / STF (e.g., EHT-LTF / EHT-STF or UHR-LTF / UHR-STF, etc.), information about the length of the non-legacy LTF and the cyclic prefix (CP) length, information about the guard interval (GI) applicable to the non-legacy LTF, information about preamble puncturing applicable to the PPDU, information about resource unit (RU) allocation, etc. may be included only in the U-SIG, may be included only in the non-legacy SIG, or may be indicated by a combination of the information included in the U-SIG and the information included in the non-legacy SIG.

[0127] Preamble puncturing may refer to the transmission of a PPDU in which no signal is present in one or more frequency units within the PPDU's bandwidth. For example, the size of the frequency unit (or the resolution of the preamble puncturing) may be defined as 20 MHz, 40 MHz, etc. For example, preamble puncturing may be applied to a PPDU bandwidth greater than a certain size.

[0128] In the example of FIG. 7, non-legacy SIGs such as HE-SIG-B and EHT-SIG may include control information for the receiving STA. The non-legacy SIG may be transmitted over at least one symbol, and each symbol may have a length of 4 us. Information regarding the number of symbols used for the EHT-SIG may be included in a previous SIG (e.g., HE-SIG-A, U-SIG, etc.).

[0129] Non-legacy SIGs, such as HE-SIG-B and EHT-SIG, may contain common fields and user-specific fields. Common and user-specific fields may be coded separately.

[0130] In some cases, common fields may be omitted. For example, in a compressed mode where non-OFDMA (orthogonal frequency multiple access) is applied, common fields may be omitted, and multiple STAs may receive PPDUs (e.g., data fields of PPDUs) over the same frequency band. In a non-compressed mode where OFDMA is applied, multiple users may receive PPDUs (e.g., data fields of PPDUs) over different frequency bands.

[0131] The number of user-specific fields can be determined based on the number of users. A single user block field can contain up to two user fields. Each user field can be associated with either MU-MIMO allocation or non-MU-MIMO allocation.

[0132] The common field may include CRC bits and Tail bits, the length of the CRC bits may be determined as 4 bits, and the length of the Tail bits may be determined as 6 bits and set to 000000. The common field may include RU allocation information. The RU allocation information may include information about the location of RUs to which multiple users (i.e., multiple receiving STAs) are allocated.

[0133] An RU can contain multiple subcarriers (or tones). RUs can be used when transmitting signals to multiple STAs based on OFDMA techniques. RUs can also be defined when transmitting signals to a single STA. Resources can be allocated on an RU basis for non-legacy STFs, non-legacy LTFs, and data fields.

[0134] Depending on the PPDU bandwidth, an applicable RU size can be defined. The RU may be defined identically or differently for the applicable PPDU format (e.g., HE PPDU, EHT PPDU, UHR PPDU, etc.). For example, in the case of an 80MHz PPDU, the RU arrangements of HE PPDU and EHT PPDU may be different. The applicable RU size, RU number, RU position, DC (direct current) subcarrier position and number, null subcarrier position and number, guard subcarrier position and number, etc. for each PPDU bandwidth can be referred to as a tone plan. For example, a tone plan for a wide bandwidth can be defined in the form of multiple repetitions of a low bandwidth tone plan.

[0135] RUs of different sizes can be defined, such as 26-ton RU, 52-ton RU, 106-ton RU, 242-ton RU, 484-ton RU, 996-ton RU, 2X996-ton RU, 4X996-ton RU, etc. A multiple RU (MRU) is distinguished from multiple individual RUs and corresponds to a group of subcarriers consisting of multiple RUs. For example, one MRU can be defined as 52+26-tons, 106+26-tons, 484+242-tons, 996+484-tons, 996+484+242-tons, 2X996+484-tons, 3X996-tons, or 3X996+484-tons. Additionally, multiple RUs constituting one MRU may or may not be consecutive in the frequency domain.

[0136] The specific size of an RU may be reduced or expanded. Therefore, the specific size of each RU (i.e., the number of corresponding tones) in the present disclosure is not limited and is exemplary. Furthermore, within a given bandwidth (e.g., 20, 40, 80, 160, 320 MHz, etc.) in the present disclosure, the number of RUs may vary depending on the RU size.

[0137] The names of each field in the PPDU formats of FIG. 7 are exemplary and the scope of the present disclosure is not limited by those names. Furthermore, the examples of the present disclosure can be applied not only to the PPDU format exemplified in FIG. 7, but also to a new PPDU format in which some fields are excluded and / or some fields are added based on the PPDU formats of FIG. 7.

[0138] RSN operation

[0139] As described with reference to Figure 3, after the discovery process between the STA and the AP, the authentication process can be performed in an open system manner, followed by an association process. This process can be considered Step 0, which involves detecting support for a robust security network (RSN) and establishing authentication and association.

[0140] If step 0 is successfully completed, step 1 of user authentication by IEEE 802.1X / EAP (extensible authentication protocol) or PSK (pre-shared key) and obtaining a pairwise master key (PMK) can be performed. The mutual authentication method applied here may include 802.1X / EAP, PSK, or simultaneous authentication of equals (SAE). For example, in the case of 802.1X / EAP authentication, PMK can be generated from MSK (master session key) after authentication between STA and RADIUS (remote authentication dial-in user service). In the case of user authentication by PSK, AP and STA can directly set PMK in the same way as PSK. In the case of user authentication by SAE, AP and STA can directly set PMK by using mutual authentication and authentication process operation value through SAE authentication process.

[0141] Following Step 1, Step 2 may be performed to verify that the other party holds the same PMK using the EAPoL-Key frame and to generate and share an encryption key. Step 2 may include a process of mutually verifying the generation of the PMK through 4-way handshaking and generating and transmitting a group key (e.g., a group temporal key (GTK)). A pairwise transient key (PTK), a key confirmation key (KCK), a key encryption key (KEK), and a temporal key (TK) may be generated through the 4-way handshaking.

[0142] Specifically, in step 1, a PMK may be generated from the MSK, and in step 2, a PTK may be generated from the PMK. Here, the PTK is configured separately as a KCK, a KEK, and a TK. A GTK may be generated from the AP and transmitted to the STA. If the AP wishes to generate a new GTK, it may perform handshaking with the STA and transmit the new GTK to the STA.

[0143] In order to verify that the STA and AP have the same PMK, in the case of 802.1X / EAP, the same MSK is set between the STA and the AS based on the user authentication result between the STA and the authentication server (AS), and the AS transmits the MSK to the AP. The STA and the AP can confirm whether they have the PMK, which is a symmetric key generated from the MSK, through 4-way handshaking. In the case of the PSK, the authentication procedure can be replaced by mutually verifying through 4-way handshaking whether the PMK generated from the PSK previously set between the AP and the STA has been secured. In the case of SAE, the PMK previously set between the AP and the STA can be mutually verified through 4-way handshaking.

[0144] It is also possible to verify whether the STA and the AP have the same PMK by mutually verifying that they generated the same PTK. For example, it is also possible to verify whether the PMK is secured through Messages 2 and 3 of the 4-way handshaking. Specifically, in Message 2, the STA can include the KCK of the PTK it generated in the Key MIC field and transmit it to the AP. In Message 3, the AP can include the KCK of the PTK it generated in the Key MIC field and transmit it to the STA. Through this, the STA (AP) can verify that the AP (STA) generated the same PTK as its own PTK, thereby confirming that the AP (STA) has the same PMK as itself. Meanwhile, in Message 1, the value of the Key MIC field may be set to 0, and in Message 4, the Key MIC field may include the KCK value.

[0145] In this way, a security key can be generated to encrypt data to be transmitted and received between the STA and the AP in step 2. In the RSN, a different security key is generated for each STA associated with the AP, and another security key is generated when the STA re-associates with another AP.

[0146] Based on the TK generated as a result of the 4-way handshaking in step 2, data encryption can be performed using TKIP (temporal key integrity protocol), CCMP (cipher-block chaining message authentication code protocol), GCMP (Galois / Counter Mode protocol), etc., and this can be referred to as step 3.

[0147] The aforementioned MSK, PSK, PMK, PTK, KCK, KEK, and TK correspond to pairwise keys, that is, keys that are paired between the AP and the STA. Unlike the pairwise keys, the group key can be generated based on the group master key (GMK) for the AP to generate a security key for group-addressed frames, such as beacon frames. The GMK is randomly set by the AP. The group temporal key (GTK) is generated from the GMK by the pseudorandom function (PRF) and corresponds to a one-way group key from the AP to the STA.

[0148] FIG. 8 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.

[0149] The STA corresponds to the side requesting authentication (supplicant), and the AP corresponds to the side performing authentication (authenticator). A four-way handshaking can be performed to generate and verify the PTK and GTK between the AP and the STA when the STA possesses or knows the PMK, and the AP possesses or knows the PMK and GMK.

[0150] ANonce and SNonce correspond to arguments used in the PRF function used to generate the PTK. ANonce may correspond to a random number generated by the access point (i.e., the authenticator). SNonce may correspond to a random number generated by the STA (i.e., the supplicant). The PRF function may correspond to a function that generates a PTK based on, for example, the PMK, ANonce, SNonce, the MAC address of the supplicant, and the MAC address of the authenticator.

[0151] Message 1 of step S810 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include ANonce information. If the AP generates a PMK, the PMKID may be included in the key data field of the EAPOL-key frame. The STA may generate a PTK based on the information received from the AP, and may generate a KCK, KEK, and TK based on the PTK.

[0152] Message 2 of step S820 is transmitted from the STA to the AP in a unicast manner, and the EAPOL-key frame may include SNonce information and a key MIC (message integrity code). For example, the key MIC of message 2 may have a value based on the KCK generated by the STA. The AP may generate a PTK based on the information received from the STA, and may generate a KCK, a KEK, and a TK based on the PTK. The AP may verify whether the AP and the STA have generated the same PTK based on whether the KCK value of the PTK generated based on the value included in message 2 and the KCK value related to the key MIC value included in message 2 are the same. In addition, the AP may generate a GTK if necessary. The generation of the GTK may be generated by the AP from the GMK without the involvement of the STA.

[0153] Message 3 of step S830 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include MIC (i.e., corresponding to the KCK value of the PTK generated by the AP) and encrypted GTK information. The encrypted GTK of message 3 may be encrypted based on the KEK generated by the AP and included in the key data field. The STA may store the PTK in the PTK-SA (PTK-Security Association) and the GTK in the GTK-SA.

[0154] Message 4 of step S840 is transmitted unicast from the STA to the AP, and the EAPOL-key frame may include MIC information. Upon completion of verification via the MIC, the AP may store the PTK in the PTK-SA and the GTK in the GTK-SA.

[0155] Once the four-way handshaking is successfully completed, the virtual control port that previously blocked all traffic is unblocked, allowing encrypted traffic to be transmitted and received. All unicast traffic can then be encrypted using PTK, and all multicast / broadcast traffic can be encrypted using GTK.

[0156] RSNA confidentiality and integrity protocol

[0157] For RSNA, authentication mechanisms for STAs, key management algorithms, cryptographic key establishment, cryptographic mechanisms, fast BSS transition (FT), and cryptographic encapsulation for robust management frames can be defined. For example, cryptographic mechanisms can include CCMP (counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol), GCMP (Galois / Counter Mode protocol), etc.

[0158] RSNA security may include algorithms and procedures such as temporal key integrity protocol (TKIP), CCMP, GCMP, broadcast / multicast integrity protocol (BIP), RSNA establishment and termination procedures, and key management procedures (e.g., key distribution). For example, RSNA establishment and termination procedures may include IEEE 802.1X authentication, simultaneous authentication of equals (SAE) authentication, and opportunistic wireless encryption (OWE) as defined in Internet Engineering Task Force (IETF) request for comments (RFC) 8110.

[0159] Below, we describe CCMP (counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol).

[0160] CCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection. CCMP is based on the CCM of the AES (Advanced Encryption Standard) encryption algorithm. CCM combines CTR for data confidentiality and CBC-MAC for authentication and integrity. CCM can protect the integrity of both the MPDU data field and selected portions of the MPDU header (MAC header).

[0161] FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure may be applied.

[0162] For secure PV0 (protocol version 0) MPDUs, CCMP-128 processing enlarges the original MPDU size by 16 octets (i.e., 8 octets for the CCMP header field and 8 octets for the MIC field). CCMP-256 processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the CCMP header field and 16 octets for the MIC field). The CCMP header field is constructed from the packet number (PN), extended initialization vector (ExtIV), and key ID subfields. The PN is a 48-bit PN expressed as an array of 6 octets. PN5 is the most significant octet of the PN, and PN0 is the least significant octet. The third octet of the CCMP header is reserved. The ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for CCMP, bits 6 (B6) and 7 (B7) are the key ID subfields, and the remaining bits of the key ID octet are reserved.

[0163] Figure 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.

[0164] Additional authentication data (AAD) can be constructed from the MAC header of a plaintext MPDU. A Nonce can be constructed based on the A2 (address 2) and priority of the plaintext MPDU and the incremented PN. The AAD and Nonce, together with data and the TK, can be used for CCM encryption. A CCMP header can be constructed based on the incremented PN and the key ID. The data and MIC, which are the results of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, as in the example of FIG. 9.

[0165] Figure 11 shows an example of the format of conventional AAD.

[0166] The example of Fig. 11(a) may correspond to an example of a conventional AAD construction for a PV0 MPDU. The FC (frame control), A1 (address 1), A2 (address 2), A3 (address 3), and SC (sequence control) fields may always be included in the conventional AAD if they are included in the MAC header. The length of the AAD may vary depending on the presence or absence of the QC (QoS Control) field and the A4 (address 4) field. For the conventional AAD, for example, if both QC and A4 are absent, the AAD length may be 22 octets, if QC is present and A4 is absent, the AAD length may be 24 octets, if QC is absent and A4 is present, the AAD length may be 28 octets, and if both QC and A4 are present, the AAD length may be 30 octets.

[0167] AAD is constructed from the MPDU header. Referring to Figure 11(b), the existing AAD does not include the MAC header's Duration / ID field, nor does it include the MAC header's HT control field. This is to prevent the existing AAD from including fields whose contents can be changed or inserted / deleted during operations such as retransmission.

[0168] Additionally, some subfields of the Frame Control (FC) field of the MAC header may be masked out. Masking out means that the value of the corresponding subfield / fields of the MAC header is changed to 0 to be included in the AAD.

[0169] For example, the subfields that are masked out in the FC field of the existing AAD are as follows:

[0170] The 3 LSBs (i.e., bits 4, 5 and 6) of the subtype subfield of the data frame are masked out, and bit 7 is not modified;

[0171] The retry subfield is masked out;

[0172] The power management subfield (i.e. bit 12) is masked out;

[0173] The more data subfield (i.e. bit 13) is masked out;

[0174] The protected frame subfield (i.e., bit 14) is not modified (i.e., left as 1);

[0175] +HTC subfield (i.e. bit 15) is masked-out in all data frames containing the QoS control field and is otherwise unmodified;

[0176] Other subfields of the FC field are not modified.

[0177] For example, the sequence number subfield in the sequence control (SC) field of a legacy AAD may be masked out.

[0178] Although not shown in the example of FIG. 11, if the existing AAD includes a QoS Control (QC) field, the QC field may be included in the existing AAD if one or more of the MSDU priority subfield, the QC TID (traffic identifier) ​​subfield, the A-MSDU capable subfield, the A-MSDU present subfield, and the A-MSDU type subfield are present in the MAC header. Other subfields in the QC field of the existing AAD may be masked out. That is, the end of service period (EOSP) subfield, the ACK policy indicator subfield, the TXOP limit subfield, the queue size subfield, the TXOP duration requested subfield, and the AP PS buffer state subfield may be masked out and not used in the existing AAD configuration.

[0179] Figure 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.

[0180] An AAD can be constructed from the MAC header of an encrypted MPDU. A Nonce can be constructed based on the A2 and priority of the encrypted MPDU and the PN. The AAD and Nonce, along with the MIC, data, and key, can be used for CCM decryption. The data resulting from CCM decryption can be replay-checked along with the MAC header to obtain a plaintext MPDU. The replay-check can be based on the PN and a replay counter.

[0181] Below, we explain BIP (broadcast / multicast integrity protocol).

[0182] BIP provides data integrity and replay protection for group-addressed robust management frames after establishing an integrity group temporal key security association (IGTKSA). For example, BIP provides data integrity and replay protection for beacon frames after establishing a beacon IGTKSA (BIGTKSA). BIP can use IGTK or BIGTK to compute the MAC management PDU (MMPDU) MIC. The management MIC element (MME) can be located after all other elements of the management frame body and before the FCS. That is, the MME can be included as the last element of the management frame body. The MME can include an element ID field, a length field, a key ID field, an IPN (IGTK packet number) / BIPN (BIGTK packet number) field, and a MIC field.

[0183] The existing AAD for BIP can be constructed based on FC, A1, A2, A3, and the Retry subfield (bit 11), Power Management subfield (bit 12), and More Data subfield (bit 13) within FC are masked out, and other subfields may not be modified.

[0184] Below, we describe GCMP (Galois / Counter Mode protocol).

[0185] GCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection. EHT RSNA STAs can support GCMP-256. GCMP is based on the GCM (Global Code Compatibility) of the AES (Advanced Encryption Standard) encryption algorithm. GCM can protect the integrity of both the MPDU data field and selected portions of the MPDU header (MAC header).

[0186] FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.

[0187] GCMP processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the GCMP header field and 16 octets for the MIC field). The CCMP header field is constructed from the packet number (PN) and the key ID subfield. The PN is a 48-bit PN expressed as an array of 6 octets. PN5 is the most significant octet of the PN, and PN0 is the least significant octet. The third octet of the GCMP header is reserved. The ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for GCMP, bits 6 (B6) and 7 (B7) are the key ID subfields, and the remaining bits of the key ID octet are reserved.

[0188] Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.

[0189] Additional authentication data (AAD) can be constructed from the MAC header of a plaintext MPDU. A Nonce can be constructed based on address 2 (A2) of the plaintext MPDU and an incremented PN. The AAD and Nonce, together with data and the TK, can be used for GCM encryption. A GCMP header can be constructed based on the incremented PN and key ID. The data, which is the result of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, as in the example of FIG. 13.

[0190] The configuration of the existing AAD applied to GCMP is the same as that described with reference to Fig. 11, so redundant description is omitted.

[0191] Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.

[0192] An AAD can be constructed from the MAC header of an encrypted MPDU. A Nonce can be constructed based on A2 and PN of the encrypted MPDU. The AAD and Nonce, along with data and a key, can be used for GCM decryption. The data resulting from GCM decryption can be replay-checked along with the MAC header to obtain a plaintext MPDU. The replay-check can be based on the PN and a replay counter.

[0193] Block ACK Request (BAR) frame

[0194] FIG. 16 is a diagram illustrating an exemplary format of a block-ACK request frame to which the present disclosure can be applied.

[0195] A block-ACK request frame may be used to request transmission of a block-ACK frame that includes multiple acknowledgements in a single frame, thereby increasing channel efficiency. For example, a first STA (e.g., an AP) may request reception results for multiple MPDUs via the block-ACK request frame, and a second STA(s) that has received the block-ACK request frame may transmit a block-ACK frame that includes acknowledgements for multiple MPDUs based on the request.

[0196] As illustrated in FIG. 16, a block-ACK request (BAR) frame may include a BAR control field and a BAR information field in the frame body.

[0197] The BAR control field may include BA type, TID information (TID_INFO), etc., which indicates the type of block-ACK request frame (e.g., compressed, multi-TID, groupcast with retries (GCR), etc.).

[0198] The BAR information field may be based on the type of block-ACK request frame (e.g., block-ACK request frame variant type) indicated by the BAR type field / subfield in the BAR control information.

[0199] For example, if a compressed block-ACK request frame type (e.g., compressed block-ACK frame type or extended compressed block-ACK frame type) is indicated, the BAR information field format corresponding to the compressed block-ACK request may include a Block Ack Starting Sequence Control subfield.

[0200] For example, the block-ACK starting sequence control subfield may include a fragment number subfield and a starting sequence number subfield, wherein the fragment number subfield is set to 0, and the starting sequence number subfield may include the sequence number of the first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.

[0201] For another example, when a multi-TID (multi-STA) block-ACK request frame type is indicated, the BAR information field format corresponding to the multi-TID block-ACK request may include, for each TID, a Per TID Info subfield and a Block-ACK Start Sequence Control subfield.

[0202] For example, each TID information subfield may include a 4-bit TID value subfield. In addition, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include the sequence number of the first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.

[0203] In this regard, the TID_INFO subfield of the BAR control field of the multi-TID block-ACK request frame can determine the number of TIDs present in the multi-TID block-ACK request frame, which is given as TID_INFO + 1. For example, setting the TID_INFO subfield to 2 can mean that there are three TID values ​​in the BAR information field of the multi-TID block-ACK request frame.

[0204] For another example, when a GCR block-ACK request frame type (e.g., GCR block-ACK request frame type or GLK-GCR block-ACK request frame type) is indicated, the BAR information field format corresponding to the GCR block-ACK request may include a GCR group address subfield and a block-ACK start sequence control subfield. Here, the GCR group address subfield may include a MAC address of a group for which a reception status is requested. In addition, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include a sequence number of a first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.

[0205] How to support integrity checks for Block Ack Request (BAR) frames

[0206] In the case of existing wireless LAN systems, encryption / decryption based on Temporal Key Integrity Protocol (TKIP) / CTR with CBC-MAC protocol (CCMP) / GCM Protocol (GCMP) can be performed / applied for individually addressed data frames (e.g., unicast-based data frames) and management frames(es) using a pairwise transient key (PTK). In addition, encryption / decryption based on TKIP / CCMP / GCMP can be performed / applied for group addressed frames (e.g., broadcast-based data frames) using a group temporal key (GTK). That is, CCMP / GCMP is a security protocol that performs encryption / decryption, and in the case of a single-user (SU), a TK based on a PTK can be used, and in the case of a multi-user (MU), a TK based on a GTK can be used. CCMP / GCMP can ensure confidentiality and integrity of data frames and management frame(s).

[0207] Additionally, for group-addressed management frames(es), BIP-based integrity check can be performed using IGTK (integrity group temporal key). In particular, for beacon frames, BIP-based integrity check can be performed using BIGTK (beacon integrity group temporal key). In the case of BIP, a TK based on IGTK / BIGTK is used to generate a message integrity code (MIC) for the frame body of the corresponding data frame, and an integrity check can be performed based on this. That is, unlike CCMP / GCMP, BIP can only guarantee the integrity of data frames and management frames(es).

[0208] The way MPDUs are constructed based on CCMP and GCMP and the way MMPDUs (management MPDUs) are constructed based on BIP have the following differences:

[0209] First, in the case of CCMP / GCMP, the transmitting STA encrypts the data portion using CCM / GCM and transmits the encrypted data, and the receiving STA can decrypt the received encrypted data. In contrast, in the case of BIP, the transmitting STA does not encrypt the data portion and can perform the corresponding protocol to generate an MIC for integrity verification of the data in the frame body.

[0210] Next, for CCMP / GCMP, the MPDU can be composed and transmitted and received in the following order: MAC header, CCMP / GCMP header, encrypted data, MIC (encrypted MIC in case of CCMP), and FCS. In contrast, for BIP, the MPDU can be composed and transmitted and received in the following order: MAC header, management frame body including MME (management MIC element), and FCS. Here, since the MME takes the role of CCMP / GCMP header, it can include information on Key ID field, IPN / BIPN, and MIC.

[0211] As previously mentioned, protection is supported for management frames, including data frames and beacon frames, among group-addressed frames. However, protection is not supported for control frames, and thus control frames are transmitted and received without any encryption / decryption and / or integrity check protocols applied.

[0212] For example, ACK frame, Block-ACK (BlockAck, Block Ack, BA) frame, and Block-ACK request frame are types of control frames. When a transmitting STA transmits data, a receiving STA can transmit an ACK for the data to the transmitting STA. At this time, STA(s) that support A(aggregated)-MPDU can configure the ACK as an A-MPDU and transmit it in the form of a block-ACK.

[0213] A block-ACK request frame can be transmitted by a transmitting STA to receive a block-ACK from a receiving STA. That is, when a transmitting STA transmits a block-ACK request frame to a receiving STA, the receiving STA can transmit a block-ACK frame to the transmitting STA. Based on this, the block-ACK request frame can be used to obtain ACK information for a previous frame transmitted in a TXOP or to initialize (e.g., clear) a receive re-order buffer of the receiving STA.

[0214] In this regard, if the information in the block-ACK request frame is exposed to a third-party STA (e.g., an attack STA), the ACK information, which serves to confirm whether data is being transmitted or received between the transmitting STA and the receiving STA, can be acquired, thereby disrupting whether transmission or reception is taking place between the transmitting STA and the receiving STA. As a result, an attack on the block-ACK request frame can result in a degradation of data transmission and reception capabilities and waste of power / medium.

[0215] Taking these points into consideration, the present disclosure proposes a security technique for ensuring the integrity of a block-ACK request frame transmitted and received between a transmitting STA and a receiving STA.

[0216] The values / names proposed in this disclosure may be changed, and the scope of this disclosure is not limited thereto. Furthermore, the STA in this disclosure may include a non-AP STA and an AP STA.

[0217] In addition, in the description of the present disclosure, it is assumed that the STA(s) transmitting and receiving the block-ACK request frame according to the present disclosure are UHR STAs (and / or beyond UHR STAs). For example, when utilizing the block-ACK request frame according to the present disclosure, it can be assumed that all receiving STAs receiving the block-ACK request frame transmitted by the AP, which is the transmitting STA, are UHR STAs. That is, if a pre-UHR STA (e.g., an EHT / HE STA, etc.) receives a block-ACK request frame configured according to the proposed method of the present disclosure, an error may occur during decoding of the block-ACK request frame.

[0218] Additionally, although the present disclosure describes a security technology for a block-ACK request frame among control frames as a representative example, the proposed method of the present disclosure can be extended and applied to other types of control frames other than the block-ACK request frame.

[0219] In the present disclosure, performing an integrity check on a block-ACK request frame can be interpreted as extending and applying the BIP to the block-ACK request frame. In this regard, additional provisions for control frames may be defined for the previously defined BIP, or a separate protocol based on the BIP for integrity checks of control frames may be newly defined.

[0220] Below, methods for supporting / performing integrity checks for block-ACK request frames are described through specific examples.

[0221] Example 1

[0222] The present embodiment relates to a method for configuring a block-ACK request frame to support integrity verification. Specifically, the present disclosure proposes a configuration in which protection-related information is included in a sub-form within the block-ACK request frame, instead of including an MME (management MIC element) at the end of the frame body when applying a BIP to a management frame, in order to apply a BIP to the block-ACK request frame.

[0223] FIG. 17 illustrates a protection information field / subfield format according to an embodiment of the present disclosure.

[0224] Referring to FIG. 17, the Protection Info (sub)field format including information required for integrity check may include Key ID information, PN related information (e.g., IPN / BIPN information), and MIC information.

[0225] The corresponding protection information (sub)field format may be included as a sub-field of the protection information subfield within the block-ACK request frame.

[0226] The length of each piece of information included in the format is not limited to that shown in FIG. 17. For example, the key ID field may have a length of 2 octets for a key ID indicating IGTK or BIGTK, but may have a length of 2 bits for a key ID indicating GTK. In addition, the MIC field may have a length of 8 octets, 16 octets, 64 octets, etc. Additionally, the length may be changed by additionally applying the MIC value to a separate function.

[0227] In this regard, if the key does not need to be used for MIC generation, the key ID information may not be included in the corresponding protection information (sub)field.

[0228] Additionally or alternatively, the present disclosure illustrates, but is not limited to, the case where the information is additionally configured in the block-ACK request frame by utilizing the protection information (sub)field format as illustrated in FIG. 17. That is, the key ID, PN-related information, and / or MIC may be included separately / distributed within the control frame to which security is applied. For example, information about the key ID may be located at a position preceding the protection information (sub)field consisting of the PN-related information and the MIC (e.g., within the BAR Control field or the BAR Information field within the block-ACK request frame).

[0229] A block-ACK request frame for integrity checking may be constructed based on one or more of the formats described below.

[0230] Example 1-1

[0231] The protection information (sub)field according to the present disclosure may be located within the BAR control field included in the block-ACK request frame.

[0232] For example, by applying BIP to the BAR Control field in the block-ACK request frame, a protection information (sub)field can be included at the end of the field.

[0233] FIG. 18 illustrates an example of a block-ACK request frame configuration supporting integrity check according to an embodiment of the present disclosure.

[0234] Referring to FIG. 18, the protection information (sub) field described in FIG. 17 may be located at the last part within the common information field.

[0235] In this case, the transmitting STA can apply BIP to the BAR control field and transmit a block-ACK request frame by adding a protection information (sub)field to the end of the field. Based on this, the receiving STA that receives the block-ACK request frame can perform an integrity check on the BAR control field within the block-ACK request frame based on the information.

[0236] In this regard, the MIC information included in the corresponding protection information (sub)field, i.e., the calculation range of the MIC subfield, may correspond to the BAR control field that includes the protection information (sub)field. In other words, the target for which an integrity check is performed / applied based on the protection information (sub)field may correspond to the BAR control field to which the (sub)field belongs.

[0237] Example 1-2

[0238] The protection information (sub)field according to the present disclosure may be located within the BAR information field included in the block-ACK request frame.

[0239] For example, by applying BIP to the BAR information field(s) within a block-ACK request frame, a protection information (sub)field may be included at the end of each BAR information field.

[0240] FIG. 19 illustrates another example of a block-ACK request frame configuration supporting integrity checking according to an embodiment of the present disclosure.

[0241] Specifically, (a) of FIG. 19 illustrates a case where a protection information (sub)field is included in a BAR information field in a compressed block-ACK request frame, and (b) of FIG. 19 illustrates a case where a protection information (sub)field is included in a BAR information field for each TID in a multi-TID block-ACK request frame. Here, the BAR information field for each TID may include a per TID information (Per TID Info) subfield and a block-ACK start sequence control field.

[0242] Referring to FIG. 19, the protection information (sub) field described in FIG. 17 may be located at the last part within each BAR information field.

[0243] For example, a transmitting STA can apply a BIP to a BAR information field containing information about each TID, and add a protection information (sub)field to the end of the field to construct and transmit a block-ACK request frame. Through each protection information (sub)field, a receiving STA that receives the block-ACK request frame can perform an integrity check on each BAR information field.

[0244] For example, the key ID constituting the protection information (sub)field included in the BAR information field in the multi-TID block-ACK request frame may mean the PTK of the STA corresponding to the BAR information field, and the STA may derive the MIC value based on this. The STA may perform an integrity check based on a comparison between the derived MIC value and the value of the MIC information in the protection information (sub)field included in the BAR information field.

[0245] Example 1-3

[0246] The protection information (sub)field according to the present disclosure may be located in a part other than the BAR control field and the BAR information field within the block-ACK request frame.

[0247] FIG. 20 illustrates another example of a block-ACK request frame configuration supporting integrity checking according to an embodiment of the present disclosure.

[0248] Referring to FIG. 20, the protection information field may be located before the FCS within the block-ACK request frame.

[0249] In this case, the transmitting STA applies BIP to the BAR control field and / or BAR information field, and may add a protection information (sub) field to the last part to set the value(s) of each subfield. Based on this, when the transmitting STA(s) transmits a block-ACK request frame to the receiving STA, a block-ACK request frame as shown in FIG. 20 may be configured.

[0250] In this regard, the MIC information can be set by considering three cases. For example, the MIC information can be set by deriving MIC values ​​for both the BAR control field and the BAR information field. For another example, the MIC information can be set by deriving the MIC value for the BAR control field. For another example, the MIC information can be set by deriving the MIC value for the BAR information field.

[0251] If the block-ACK request frame is a multi-TID block-ACK request frame type, the number of TIDs included in the BAR information field (e.g., N) may be transmitted / indicated by the BAR control field. Based on this, the receiving STA can recognize that the protection information (sub)field is located after N sets (e.g., N BAR information field formats) containing each TID information (Per TID Info) subfield in the BAR information field.

[0252] Additionally, with respect to a block-ACK request frame supporting integrity check according to the present disclosure, transmitting STA(s) and receiving STA(s) may share information with each other regarding whether BIP is supported for the block-ACK request frame. The information may be shared through a specific element (e.g., an Extended RSN element (RSNXE)) in a discovery process (e.g., a beacon frame, a probe response frame, etc.) and / or a (re)association process (e.g., a (re)association request frame, a (re)association response frame, etc.).

[0253] In this regard, whether BIP application for block-ACK request frames is supported can be shared by utilizing reserved bits in existing elements (e.g., RSNXE) or by defining new (sub)fields in new elements. For example, a newly defined 1-bit protected BlockAckReq support (sub)field can be defined such that a value of 1 means / indicates that BIP application for block-ACK request frames is supported, and a value of 0 means / indicates that BIP application for block-ACK request frames is not supported.

[0254] If both the transmitting STA and the receiving STA support BIP and support BIP application to the block-ACK request frame, the two STAs can perform BIP application to the block-ACK request frame. Conversely, if the transmitting STA or the receiving STA supports BIP but does not support BIP application to the block-ACK request frame, the two STAs may not perform BIP application to the block-ACK request frame. Additionally, when applying BIP to the block-ACK request frame, the cipher suite of the management frame agreed upon by the transmitting STA and the receiving STA during the negotiation process (e.g., BIP-GMAC (galois message authentication code)-128, BIP-GMAC-256, or BIP-CMAC (cipher-based message authentication code)-256, etc.) may be used identically. Alternatively, in order to apply an integrity protocol (e.g., a separate integrity protocol for control frames) to the block-ACK request frame, the transmitting STA and the receiving STA may negotiate an additional / separate cipher suite (e.g., control integrity protocol (CIP)-GMAC-128, CIP-GMAC-256, CIP-CMAC-128, CIP-CMAC-256, etc.) for the block-ACK request frame.

[0255] Additionally or alternatively, information regarding whether BIP application for a block-ACK request frame is supported and in which format among the formats proposed in the present disclosure (e.g., the formats illustrated in FIGS. 18 to 20) the protection information (sub)field is configured may be shared between the transmitting STA and the receiving STA. In this regard, for sharing the information, a reserved bit in an existing element (e.g., RSNXE), and / or a reserved bit(s) in a BA control field, and / or a new (sub)field in a new element (e.g., a protected BlockAckReq mode (sub)field) may be defined. The (sub)field may be included in a beacon frame by the transmitting STA or in a data frame by the receiving STA during the (re)association process as well as during the data transmission and reception process.

[0256] For example, setting the value of the Protected Block-ACK Request Mode (sub)field to 0 may mean / indicate that the block-ACK request frame is not configured in at least one way and that the BIP for the block-ACK request frame is not applied. Conversely, setting the value of the Protected Block-ACK Request Mode (sub)field to 1 or greater may mean / indicate that the BIP for the block-ACK request frame is applied.

[0257] As a specific example, if the corresponding protected block-ACK request mode (sub)field can have a value of 1 or more, the meaning of the value of the corresponding protected block-ACK request mode (sub)field can be defined as in Table 1 below. Table 1 is exemplary, and at least one of the values ​​described in Table 1 can be applied / defined, and the specific value can be set / defined differently from the example.

[0258] Meaning of the value of the protected block-ACK request mode (sub) field 1 Block-ACK request frame configuration based on embodiment 1-1 2 Block-ACK request frame configuration based on embodiment 1-2 3 Block-ACK request frame configuration based on embodiment 1-1 and embodiment 1-2 4 Block-ACK request frame configuration based on embodiment 1-3 5 Block-ACK request frame configuration based on embodiment 1-3, MIC value calculation for BAR control field and BAR information field 6 Block-ACK request frame configuration based on embodiment 1-3, MIC value calculation for BAR control field 7 Block-ACK request frame configuration based on embodiment 1-3, MIC value calculation for BAR information field

[0259] Referring to Table 1, a method for calculating an MIC value together with the configuration / format of a block-ACK request frame including a protection information (sub)field according to the present disclosure through a protected block-ACK request mode (sub)field may be indicated.

[0260] However, the scope of the present disclosure is not limited thereto, and only the configuration / format of a block-ACK request frame including a protection information (sub)field according to the present disclosure is indicated through a protected block-ACK request mode (sub)field, and a method for calculating an MIC value may be separately indicated through another (sub)field. For example, a MIC calculation range (sub)field may be defined, and the value of the corresponding (sub)field may be defined as in Table 2.

[0261] Meaning of the values ​​of the MIC calculation range (sub)fields aCalculate MIC values ​​for the BAR control field and BAR information field bCalculate MIC values ​​for the BAR control field cCalculate MIC values ​​for the BAR information field... Reserved

[0262] For example, a receiving STA can recognize / verify the location of the protection information (sub)field within the received block-ACK request frame through the protected block-ACK request mode (sub)field. Furthermore, based on this, the receiving STA can calculate the MIC value using the value indicated by the MIC calculation range (sub)field, thereby performing an integrity check on the block-ACK request frame.

[0263] Example 2

[0264] This embodiment relates to a method for generating an MIC for BIP transmission / reception in relation to BIP application to the aforementioned block-ACK request frame.

[0265] In the case of a block-ACK request frame, the type of the block-ACK request frame to be transmitted and received may be indicated based on the value of the BAR type subfield in the BAR control field. Depending on the indicated value, the receiving STA can determine whether the corresponding block-ACK request frame is an individually addressed frame or a group addressed frame. For example, a compressed block-ACK request frame type (e.g., (a) of FIG. 19) and a multi-TID block-ACK request frame type (e.g., (b) of FIG. 19) may correspond to individually addressed frames.

[0266] In this regard, when applying BIP to a block-ACK request frame, the key used to set the MIC value may be used differently depending on whether it is an individually addressed frame or a group addressed frame.

[0267] For example, for individually addressed data frames, MIC value calculation may be performed using a TK based on a PTK generated identically between the transmitting STA and the receiving STA. Conversely, for group addressed data frames, MIC value calculation may be performed using a TK based on a GTK shared by the transmitting STA with the receiving STA.

[0268] For existing BIPs (e.g., BIPs applied to data frames / management frames), BIPs based on IGTK or BIGTK can be utilized. In contrast, the present disclosure assumes that BIPs based on PTK / GTK can be utilized.

[0269] Below, we specifically describe how keys are used to calculate and check MIC values ​​for individually addressed block-ACK request frames and / or group addressed block-ACK request frames.

[0270] First, for individually addressed block-ACK request frames, the MIC value can be calculated / verified as follows.

[0271] The transmitting STA and the receiving STA can calculate the MIC value using a TK based on the PTK generated identically during the 4-way handshake process. For example, in relation to the application of BIP to a block-ACK request frame, the transmitting STA and the receiving STA can equally utilize the PTK generated in relation to the protection of the data frame during the 4-way handshake process, or can utilize a (new) TK (e.g., a new PTK / GTK) that is identically generated / agreed on / shared between them in relation to the protection of the control frame (e.g., a block-ACK request frame) during the 4-way handshake process.

[0272] Alternatively, the transmitting STA and the receiving STA can derive the MIC value using a TK based on a new TK for the individually addressed block-ACK request frame shared in the 4-way handshake process. For example, the new TK may be referred to as a block-ACK request PTK (block-ACK request PTK, BARPTK), and the transmitting STA can generate and share a different BARPTK for each receiving STA. That is, different BARPTKs may be shared for receiving STA 1 and receiving STA 2. In addition, for example, when the MIC is derived using a new TK (e.g., BARPTK, BARGTK) for the block-ACK request frame, the transmitting STA can generate and share a new TK for each receiving STA. That is, receiving STA 1 and receiving STA 1 may share the same new TK. At this time, information about the new TK and information related to a cipher suite that can use the new TK can be shared through a new KDE (key data element) (e.g., BARPTK / BARGTK KDE) for the new TK generated and shared by the transmitting STA.

[0273] If there is a key (e.g., a new TK) for protecting the block-ACK request frame, the receiving STA can perform MIC verification on the received block-ACK request frame using the key. In this regard, the key may be generated and / or shared by the transmitting STA and / or the receiving STA. Otherwise, the receiving STA can perform MIC verification on the block-ACK request frame based on a key (e.g., a PTK) for integrity check / encryption / decryption of a unicast data frame generated in advance with the transmitting STA.

[0274] Next, for group addressed block-ACK request frames, the MIC value can be calculated / checked as follows.

[0275] A transmitting STA can generate an IGTK or a BIGTK and share it with a receiving STA during a 4-way handshake process, and the transmitting STA and the receiving STA can calculate an MIC value using a TK based on the IGTK or the BIGTK.

[0276] Alternatively, the transmitting STA can generate a GTK and share it with the receiving STA during the 4-way handshake process, and the transmitting STA and the receiving STA can calculate the MIC value using a TK based on the GTK.

[0277] Alternatively, the transmitting STA may generate a new GTK for the group-addressed block-ACK request frame and share it with the receiving STA during the 4-way handshake process, and the transmitting STA and the receiving STA may calculate the MIC value using a TK based on the new GTK. Here, the new GTK may be referred to as a block-ACK request broadcast GTK (BARGTK), and the transmitting STA may share a BARGTK of the same value with the receiving STAs. That is, the AP may generate and share the same BARGTK with the STAs associated with it. In addition, information about the BARGTK and information related to a cipher suite that can use the BARGTK may be shared between the transmitting STA and the receiving STA through the new KDE for the BARGTK (e.g., the BARGTK KDE).

[0278] If the receiving STA has received a key (e.g., BARGTK) for protecting the block-ACK request frame from the transmitting STA, the receiving STA may perform MIC verification for the block-ACK request frame based on the key. Otherwise, the receiving STA may perform MIC verification for the block-ACK request frame based on a key (e.g., GTK, IGTK, or BIGTK) for broadcast frame(s) previously shared with the transmitting STA.

[0279] Example 3

[0280] This embodiment is a specific method for performing protection for a block-ACK request frame based on the block-ACK request frame configuration proposed in the present disclosure.

[0281] First, if the block-ACK request frame is a group-addressed block-ACK request frame, the block-ACK request frame configuration proposed in the present disclosure can be used as in the following examples.

[0282] For example, in the case of the block-ACK request frame configuration described in Embodiment 1-1 (e.g., see FIG. 18), the transmitting STA and / or the receiving STA may derive the MIC value through the BIP using the aforementioned GTK, IGTK, BIGTK, or new TK (e.g., BARGTK) for the BAR control field. Additionally, in the case of the block-ACK request frame configuration described in Embodiment 1-2 (e.g., see FIG. 19 (a) and (b)), the transmitting STA and / or the receiving STA may derive the MIC value through the BIP using the aforementioned PTK or new TK (e.g., BARPTK) for the BAR information field. In this regard, the PTK or new TK (e.g., BARPTK) of the STA corresponding to the MAC address (e.g., receiver address (RA)) of the transmitting STA may be utilized.

[0283] For another example, for the block-ACK request frame configuration described in Example 1-3 (e.g., see FIG. 20), the transmitting STA and / or the receiving STA may derive the MIC value via BIP using the aforementioned GTK, IGTK, BIGTK, or new TK (e.g., BARGTK) for the BAR control field and / or the BAR information field.

[0284] Next, when the block-ACK request frame is an individually addressed block-ACK request frame, the block-ACK request frame configuration proposed in the present disclosure can be used as in the following examples.

[0285] For example, in the case of the block-ACK request frame configuration described in Example 1-1 (e.g., see FIG. 18), the transmitting STA and / or the receiving STA may derive the MIC value through the BIP using the aforementioned PTK or a new TK (e.g., BARPTK) for the BAR control field.

[0286] For another example, in the case of the block-ACK request frame configuration described in Embodiment 1-2 (e.g., see (a) and (b) of FIG. 19), the transmitting STA and / or the receiving STA may derive the MIC value via BIP using the aforementioned PTK or a new TK (e.g., BARPTK) for the BAR information field. In this regard, the PTK or the new TK (e.g., BARPTK) of the STA corresponding to the MAC address (e.g., receiver address (RA)) of the transmitting STA may be used.

[0287] For another example, in the case of the block-ACK request frame configuration described in Embodiment 1-3 (e.g., see FIG. 20), the transmitting STA and / or the receiving STA may derive the MIC value via BIP using the aforementioned PTK or new TK (e.g., BARPTK) for the BAR control field and / or BAR information field. At this time, the PTK or new TK (e.g., BARPTK) of the STA corresponding to the receiver address (RA) of the corresponding block-ACK request frame may be used to derive the MIC value for the BAR control field and / or BAR information field.

[0288] Based on the methods proposed in this disclosure, protection for block-ACK request frames can be performed as follows.

[0289] For the example situations described below, it is assumed that the transmitting STA and the receiving STA(s) support the use of block-ACK request frames on the BIP via the protected block-ACK request support (sub)field and / or share the configuration of the protection information (sub)field within the block-ACK request frame via the protected block-ACK request mode (sub)field.

[0290] The receiving STA can configure additional authentication data (AAD) for the block-ACK request frame based on information in the MAC header of the MPDU received from the transmitting STA (e.g., frame control field, interval field, RA field, TA field, etc.). Thereafter, the receiving STA can utilize the AAD when calculating the MIC value based on the MPDU. At this time, the receiving STA can derive the MIC value by performing the same process that the transmitting STA performed when calculating the MIC value based on the MPDU.

[0291] Thereafter, the receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the protection information (sub)field). If the two MIC values ​​are the same, the receiving STA can follow the information in the acquired MPDU. Conversely, if the two MIC values ​​are not the same, the receiving STA can recognize that at least one piece of information in the acquired MPDU has been modified by a third party STA (e.g., an attacking STA) or has been damaged during transmission and reception, and can discard it.

[0292] The operation of an STA supporting / performing protection for a block-ACK request frame according to an embodiment of the present disclosure may be as shown in FIGS. 21 and 22.

[0293] FIG. 21 illustrates the operation of a transmitting STA that supports integrity check for a block-ACK request frame according to the present disclosure.

[0294] Referring to FIG. 21, a transmitting STA may share with a receiving STA information including whether it supports protection (e.g., integrity check) for a block-ACK request frame (S2110).

[0295] At this time, if both the transmitting STA and the receiving STA(s) apply security to the block-ACK request frame, the transmitting STA may generate and share key(s) (e.g., PTK / GTK / BARPTK / BARGTK(s)) used for integrity check of the block-ACK request frame (S2120). In this regard, the transmitting STA and the receiving STA may generate / negotiate / share the same key information through the key generation process, or the key information generated by the transmitting STA may be transmitted to the receiving STA.

[0296] Based on the key(s), the transmitting STA can apply the BIP to the configured block-ACK request frame (S2130). In this regard, the transmitting STA can derive the MIC value for the block-ACK request frame using the key(s) previously shared with the receiving STA.

[0297] The transmitting STA may transmit a block-ACK request frame containing the result value / information regarding the BIP application (S2140). For example, the transmitting STA may transmit a block-ACK request frame containing the derived MIC value and the ID value of the key(s) used to derive the MIC value to the receiving STA(s).

[0298] In relation to the above-described process, the transmitting STA may share / discuss in advance with the receiving STA information on the format in which information related to integrity check is to be configured within the transmitted block-ACK request frame, or may include the information in the block-ACK request frame and transmit it.

[0299] FIG. 22 illustrates the operation of a receiving STA that supports integrity checking for a block-ACK request frame according to the present disclosure.

[0300] Referring to FIG. 22, the receiving STA may share with the transmitting STA information including whether it supports protection (e.g., integrity check) for the block-ACK request frame (S2210).

[0301] At this time, if the key(s) used for integrity check of the transmitting STA and the block-ACK request frame are shared, the receiving STA can assume that the protection method has been applied to the block-ACK request frame transmitted by the transmitting STA (S2220).

[0302] In this regard, the transmitting STA and the receiving STA may generate / negotiate / share the same key information (e.g., PTK / GTK / BARPTK / BARGTK, etc.) through a key generation process, or key information generated by the transmitting STA may be transmitted to the receiving STA.

[0303] For example, a receiving STA may receive a block-ACK request frame transmitted from a transmitting STA and recognize that it has applied a BIP based on information regarding the pre-shared key(s) and / or the way information for integrity checking is structured within the block-ACK request frame.

[0304] Based on this, when a block-ACK request frame is received, the receiving STA can derive the MIC value using the pre-shared / generated / agreed key(s) (e.g., PTK / GTK / BARPTK / BARGTK, etc.) and the block-ACK request frame (S2230).

[0305] Thereafter, the receiving STA can perform integrity verification by comparing the derived MIC value with the MIC value transmitted by the transmitting STA (i.e., the MIC value according to the MIC information included in the block-ACK request frame) (S2240).

[0306] Hereinafter, FIGS. 23 and 24 illustrate operations performed by an STA according to the proposed method of the present disclosure described above. In FIGS. 23 and 24 , the second STA may correspond to a transmitting STA (e.g., an AP), and the first STA may correspond to a receiving STA (e.g., a non-AP STA coupled to an AP).

[0307] FIG. 23 is a drawing for explaining an example of a method performed by a first STA according to the present disclosure.

[0308] Referring to FIG. 23, the first STA may receive a block-ACK request frame based on an integrity protocol (e.g., an integrity protocol for BIP or control frames) from the second STA (S2310).

[0309] In this regard, the integrity protocol may be applied to at least one field belonging to the frame body within the block-ACK request frame.

[0310] For example, the integrity protocol may be applied to the Block-ACK Request Control field and / or the Block-ACK Request Information field within the Block-ACK Request frame.

[0311] The first STA can perform an integrity check on the received block-ACK request frame (S2320).

[0312] In this regard, protection-related information for the integrity check (e.g., the protection information (sub)field described above in the present disclosure) may be included / exist in different locations within the block-ACK request frame based on the configuration of the field to which the integrity protocol is applied.

[0313] According to the present disclosure, the protection-related information may include MIC information calculated based on key information related to protection for a block-ACK request frame.

[0314] For example, if an integrity protocol is applied to the Block-ACK Request Control field within a Block-ACK Request frame, protection-related information may be included within the Block-ACK Request Control field. In this case, MIC information may be calculated based on a portion of the Block-ACK Request Control field excluding the protection-related information (e.g., see FIG. 18).

[0315] For another example, if an integrity protocol is applied to the block-ACK request information field within a block-ACK request frame, protection-related information may be included within the block-ACK request information field. In this case, the MIC information may be calculated based on the portion of the block-ACK request information field excluding the protection-related information (e.g., see FIG. 19). In this regard, if the block-ACK request frame includes block-ACK request information for multiple TIDs (e.g., in the case of a multi-TID block-ACK request frame type), protection-related information may be (individually) included within the block-ACK request information field for each TID.

[0316] For another example, when the integrity protocol is applied to the block-ACK request control field and the block-ACK request information field within the block-ACK request frame, the protection-related information may be included in a part other than the block-ACK request control field and the block-ACK request information field within the block-ACK request frame. In this case, the MIC information may be calculated based on at least one of the block-ACK request control field and the block-ACK request information field (e.g., see FIG. 20). In this regard, information indicating the scope applicable to the calculation of the corresponding MIC information may be exchanged between the first STA and the second STA.

[0317] Additionally, according to the present disclosure, information regarding whether an integrity protocol is supported for a block-ACK request frame may be exchanged between a first STA and a second STA. For example, the information may be exchanged via at least one of a beacon frame, a probe request frame, a probe response frame, a join request frame, a join response frame, or a block-ACK request frame.

[0318] Additionally, according to the present disclosure, information regarding the configuration of fields to which the integrity protocol is applied may be exchanged between the first STA and the second STA. For example, the information may be included in the Block-ACK Request Control field within the frame body of the Block-ACK Request frame.

[0319] Additionally, according to the present disclosure, the integrity check may be performed based on key information related to protection for the block-ACK request frame, and the key information may be included in the protection-related information. For example, if the block-ACK request frame corresponds to an individually addressed frame, the key information may be based on the PTK for the first STA and the second STA. As another example, if the block-ACK request frame corresponds to a group addressed frame, the key information may be based on the GTK for the first STA and the second STA.

[0320] Additionally, according to the present disclosure, if the aforementioned integrity protocol corresponds to a specific integrity protocol for a block-ACK request frame (e.g., an integrity protocol for a control frame), the cipher suite for the specific integrity protocol (e.g., a cipher suite negotiated for the specific integrity protocol) may be based on GMAC or CMAC.

[0321] The method described in the example of FIG. 23 can be performed by the first device (100) of FIG. 1. That is, the first STA of FIG. 23 can be implemented by the first device (100). For example, one or more processors (102) of the first device (100) of FIG. 1 can be configured to receive a block-ACK request frame based on an integrity protocol and perform an integrity check on the block-ACK request frame.

[0322] In this regard, the first STA may determine whether protection / security has been applied to the received block-ACK request frame based on information previously shared / agreed with the second STA, and may perform an integrity check based on the BIP. For example, one or more processors (102) may parse a MAC frame obtained through PHY decoding of a data field of a PPDU received through one or more transceivers (106). The one or more processors (102) may derive MIC information based on the BIP for the parsed MAC frame, and may perform an integrity check by comparing the MIC information transmitted by the transmitting STA with the derived MIC information.

[0323] Furthermore, one or more memories (104) of the first device (100) may store instructions for performing the method described in the example of FIG. 23 or the examples described above when executed by one or more processors (102).

[0324] FIG. 24 is a diagram illustrating an example of a method performed by a second STA according to the present disclosure.

[0325] Referring to FIG. 24, the second STA can generate a block-ACK request frame based on an integrity protocol (e.g., BIP) (S2410).

[0326] In this regard, the integrity protocol may be applied to at least one field belonging to the frame body within the block-ACK request frame.

[0327] For example, the integrity protocol may be applied to the Block-ACK Request Control field and / or the Block-ACK Request Information field within the Block-ACK Request frame.

[0328] The second STA can transmit the generated block-ACK request frame to the first STA (S2420).

[0329] In this regard, protection-related information for the integrity check (e.g., the protection information (sub)field described above in the present disclosure) may be included / exist in different locations within the block-ACK request frame based on the configuration of the field to which the integrity protocol is applied.

[0330] Specific details regarding protection-related information in the block-ACK request frame, the location of protection-related information according to the configuration of the field to which the integrity protocol is applied, the method of calculating MIC information, information on whether the integrity protocol is supported for the block-ACK request frame, information on the configuration of the field to which the integrity protocol is applied (and / or the MIC calculation range), key information related to protection for the block-ACK request frame, cipher suite, etc. are the same / similar to those described in FIG. 23, and therefore, a detailed description thereof is omitted.

[0331] The method described in the example of FIG. 24 can be performed by the second device (200) of FIG. 1. That is, the second STA of FIG. 24 can be implemented by the second device (200). For example, one or more processors (202) of the second device (200) of FIG. 1 can be configured to generate a block-ACK request frame based on an integrity protocol and transmit the generated block-ACK request frame.

[0332] In this regard, the second STA may perform an operation of applying a BIP to a block-ACK request frame based on information shared with the first STA before configuring a PPDU to include information related to integrity check (e.g., a derived MIC value, key information for deriving the MIC value, PN (Packet Number) for the corresponding block-ACK request frame, etc.).

[0333] Furthermore, one or more memories (204) of the second device (200) may store instructions for performing the method described in the example of FIG. 24 or the examples described above when executed by one or more processors (202).

[0334] Integrity protocols such as BIP utilized in existing wireless LAN systems cannot provide protection for control frames such as block ACK request frames. The present disclosure defines an integrity protocol such as BIP for control frames such as block ACK request frames, thereby providing a new method for transmitting or receiving protected control frames.

[0335] The embodiments described above are combinations of components and features of the present disclosure in a predetermined form. Each component or feature should be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, it is also possible to form embodiments of the present disclosure by combining some components and / or features. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment. It is self-evident that claims that do not have an explicit citation relationship in the patent claims may be combined to form embodiments or incorporated as new claims through post-application amendments.

[0336] It will be apparent to those skilled in the art that the present disclosure may be embodied in other specific forms without departing from the essential characteristics thereof. Therefore, the above detailed description should not be construed as limiting in any respect, but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the scope of equivalents of the present disclosure are intended to be included within the scope of the present disclosure.

[0337] The scope of the present disclosure includes software or machine-executable instructions (e.g., an operating system, an application, firmware, a program, etc.) that cause operations according to the methods of various embodiments to be executed on a device or a computer, and a non-transitory computer-readable medium having such software or instructions stored thereon and executable on the device or computer. Instructions that can be used to program a processing system to perform the features described in the present disclosure can be stored on / in a storage medium or a computer-readable storage medium, and a computer program product including such a storage medium can be used to implement the features described in the present disclosure. The storage medium can include, but is not limited to, high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid state memory devices, and can include non-volatile memory, such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid state storage devices. The memory optionally includes one or more storage devices remotely located from the processor(s). The memory or, alternatively, the non-volatile memory device(s) within the memory comprise a non-transitory computer-readable storage medium. The features described in this disclosure may be incorporated into software and / or firmware stored on any of the machine-readable media, which may control the hardware of the processing system and allow the processing system to interact with other mechanisms that utilize results according to embodiments of the present disclosure. Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments / containers.

[0338] The method proposed in this disclosure is described with a focus on examples applied to IEEE 802.11-based systems, but can be applied to various wireless LANs or wireless communication systems in addition to IEEE 802.11-based systems.

Claims

1. A step of receiving a block-ACK request frame based on an integrity protocol from a second STA by a first station (STA); and A step of performing an integrity check on the block-ACK request frame by the first STA, The above integrity protocol is applied to at least one field belonging to the frame body within the above block-ACK request frame, A method wherein the protection-related information for the above integrity check is included at different locations within the block-ACK request frame based on the configuration of the fields to which the integrity protocol is applied.

2. In paragraph 1, A method wherein the above protection-related information includes MIC (message integrity code) information calculated based on key information related to protection for the block-ACK request frame.

3. In paragraph 2, Based on the above integrity protocol being applied to the Block-ACK Request Control field within the Block-ACK Request frame, The above protection related information is included in the block-ACK request control field, A method wherein the above MIC information is calculated based on a portion excluding the protection-related information within the block-ACK request control field.

4. In paragraph 2, Based on the above integrity protocol being applied to the block-ACK request information field within the block-ACK request frame, The above protection related information is included in the block-ACK request information field, A method wherein the above MIC information is calculated based on a portion of the block-ACK request information field excluding the protection-related information.

5. In paragraph 4, Based on the above block-ACK request frame including block-ACK request information fields for multiple TIDs, A method wherein the above protection related information is included within the block-ACK request information field for each TID.

6. In paragraph 2, Based on the above integrity protocol being applied to the block-ACK request control field and the block-ACK request information field within the block-ACK request frame, The above protection-related information is included in a part other than the block-ACK request control field and the block-ACK request information field within the block-ACK request frame, A method wherein the MIC information is calculated based on at least one of the block-ACK request control field and the block-ACK request information field.

7. In paragraph 6, A method in which information indicating a range applicable to the calculation of the MIC information is exchanged between the first STA and the second STA.

8. In paragraph 1, A method in which information on whether an integrity protocol is supported for the block-ACK request frame is exchanged between the first STA and the second STA.

9. In paragraph 8, A method in which information on whether the integrity protocol is supported for the above block-ACK request frame is exchanged via at least one of a beacon frame, a probe request frame, a probe response frame, an association request frame, an association response frame, or the above block-ACK request frame.

10. In paragraph 1, A method in which information on the configuration of a field to which the integrity protocol is applied is exchanged between the first STA and the second STA.

11. In paragraph 10, A method wherein information on the configuration of fields to which the above integrity protocol is applied is included in a block-ACK request control field within the frame body.

12. In paragraph 1, The above integrity check is performed based on key information related to protection for the above block-ACK request frame, A method wherein the above key information is included in the above protection-related information.

13. In paragraph 12, Based on the above block-ACK request frame corresponding to an individually addressed frame, the key information is based on a pairwise transient key (PTK) for the first STA and the second STA, A method wherein the key information is based on a GTK (group temporal key) for the first STA and the second STA, based on the fact that the block-ACK request frame corresponds to a group addressed frame.

14. In paragraph 1, A method, wherein the cipher suite for the specific integrity protocol is based on GMAC (galois message authentication code) or CMAC (cipher-based message authentication code), based on the integrity protocol corresponding to a specific integrity protocol for the block-ACK request frame.

15. One or more transmitters / receivers; and comprising one or more processors coupled to said one or more transceivers; One or more of the above processors: By a first station (STA), a block-ACK request frame based on an integrity protocol is received from a second STA; By the above first STA, an integrity check is set to be performed on the block-ACK request frame, The above integrity protocol is applied to at least one field belonging to the frame body within the above block-ACK request frame, A device wherein the protection-related information for the above integrity check is included at different locations within the block-ACK request frame based on the configuration of the fields to which the integrity protocol is applied.

16. A step of generating a block-ACK request frame based on an integrity protocol by a second station (STA); and A step of transmitting the block-ACK request frame to the first STA by the second STA, The above integrity protocol is applied to at least one field belonging to the frame body within the above block-ACK request frame, A method wherein the protection-related information for the above integrity check is included at different locations within the block-ACK request frame based on the configuration of the fields to which the integrity protocol is applied.

17. One or more transmitters / receivers; and comprising one or more processors coupled to said one or more transceivers; One or more of the above processors: By the second station (STA), a block-ACK request frame is generated based on the integrity protocol; By the second STA, the block-ACK request frame is set to be transmitted to the first STA, The above integrity protocol is applied to at least one field belonging to the frame body within the above block-ACK request frame, A device wherein the protection-related information for the above integrity check is included at different locations within the block-ACK request frame based on the configuration of the fields to which the integrity protocol is applied.

18. One or more processors; and A processing device comprising one or more computer memories operatively connected to said one or more processors and storing instructions for performing a method according to any one of claims 1 to 14 based on execution by said one or more processors.

19. One or more non-transitory computer-readable media storing one or more instructions that are executed by one or more processors to perform a method according to any one of claims 1 to 14.

Citation Information

Patent Citations

  • Pattern roller for special makeup

    KR102344169B1