Method and apparatus for security between access points in wireless LAN system
The method of generating pairwise keys between APs addresses the security gap in wireless LAN systems, enhancing data confidentiality and integrity through secure key establishment.
Patent Information
- Application Number
- PCT/KR2025/099503
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-02
- Filing Date
- 2025-02-20
- Publication Date
- 2025-08-28
AI Technical Summary
The existing wireless LAN systems lack effective methods and devices for securing data transmission and reception between access points (APs), particularly in supporting confidentiality and integrity within a specific AP set.
A method involving the generation of pairwise master keys (PMK) and pairwise transient keys (PTK) between APs, utilizing addresses and nonces to establish secure communication.
Enhances security and integrity of data transmission between APs, ensuring confidentiality and integrity within a wireless LAN system.
Smart Images

Figure KR2025099503_28082025_PF_FP_ABST
Abstract
Description
Method and device for security between access points in a wireless LAN system
[0001] The present disclosure relates to a method and device for security between access points (APs) in a wireless local area network (WLAN) system.
[0002] New technologies have been introduced for wireless local area networks (WLANs) to improve transmission rates, increase bandwidth, enhance reliability, reduce errors, and reduce latency. Among WLAN technologies, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 series of standards can be referred to as Wi-Fi. For example, recently introduced technologies for WLANs include enhancements for Very High Throughput (VHT) in the 802.11ac standard and enhancements for High Efficiency (HE) in the IEEE 802.11ax standard.
[0003] To provide a more advanced wireless communication environment, improved technologies for Extremely High Throughput (EHT) are being discussed. For example, technologies for Multiple Input Multiple Output (MIMO), which supports increased bandwidth, efficient utilization of multiple bands, and increased spatial streams, and for coordination of multiple access points (APs), are being studied. In particular, various technologies are being studied to support low latency or real-time traffic. Furthermore, new technologies are being discussed to support ultra-high reliability (UHR), including improvements or extensions of EHT technology.
[0004] The technical problem of the present disclosure is to provide a method and device for security between APs in a wireless LAN system.
[0005] An additional technical problem of the present disclosure is to provide a method and device for supporting confidentiality / integrity of data wirelessly transmitted / received between APs within a specific AP set in a wireless LAN system.
[0006] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned can be clearly understood by a person having ordinary skill in the technical field to which the present disclosure belongs from the description below.
[0007] A method according to one aspect of the present disclosure may include: obtaining a first pairwise master key (PMK) by a first access point (AP); transmitting a first message, including at least one of a first address or a first nonce of the first AP, to a second AP by the first AP; receiving a second message, including at least one of a second address or a second nonce of the second AP, from the second AP by the first AP; and generating a first pairwise transient key (PTK) by the first AP based on at least one of the first PMK, the first address, the second address, the first nonce, or the second nonce.
[0008] A method according to an additional aspect of the present disclosure may include: obtaining a first pairwise master key (PMK) by a second access point (AP); receiving, by the second AP, a first message from the first AP, the first message including at least one of a first address or a first nonce of the first AP; generating, by the second AP, a first pairwise transient key (PTK) based on at least one of the first PMK, the first address, the first nonce, the second address of the second AP, or the second nonce of the second AP; and transmitting, by the second AP, a second message including at least one of the second address or the second nonce to the first AP.
[0009] According to the present disclosure, a method and device for security between APs in a wireless LAN system can be provided.
[0010] According to the present disclosure, a method and device for supporting confidentiality / integrity of data wirelessly transmitted / received between APs within a specific AP set in a wireless LAN system can be provided.
[0011] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.
[0012] The accompanying drawings, which are incorporated in and are part of the detailed description to aid in understanding the present disclosure, provide embodiments of the present disclosure and, together with the detailed description, describe the technical features of the present disclosure.
[0013] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
[0014] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
[0015] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.
[0016] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.
[0017] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.
[0018] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.
[0019] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.
[0020] FIG. 8 is a diagram for explaining various transmission and reception techniques in a MAP environment to which the present disclosure can be applied.
[0021] FIG. 9 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.
[0022] Figure 10 is a diagram for explaining BSS transition in an existing wireless LAN system.
[0023] FIG. 11 is a drawing for explaining the operation of the first AP according to the present disclosure.
[0024] FIG. 12 is a drawing for explaining the operation of the second AP according to the present disclosure.
[0025] FIG. 13 is a diagram showing examples of identifiers of AP sets / groups according to the present disclosure.
[0026] FIG. 14 is a diagram illustrating an example of a two-way handshaking procedure according to the present disclosure.
[0027] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to explain exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the present disclosure may be practiced. The following detailed description includes specific details to provide a thorough understanding of the present disclosure. However, one of ordinary skill in the art will appreciate that the present disclosure may be practiced without these specific details.
[0028] In some cases, to avoid obscuring the concepts of the present disclosure, known structures and devices may be omitted or illustrated in block diagram form focusing on the core functions of each structure and device.
[0029] In the present disclosure, when a component is said to be "connected," "coupled," or "connected" to another component, this may include not only a direct connection but also an indirect connection in which another component exists between them. Furthermore, the terms "comprises" or "has" in the present disclosure specify the presence of the mentioned features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof.
[0030] In this disclosure, terms such as “first,” “second,” etc. are used only to distinguish one component from another and are not used to limit the components, and do not limit the order or importance between the components unless specifically stated otherwise. Accordingly, within the scope of this disclosure, a first component in one embodiment may be referred to as a second component in another embodiment, and similarly, a second component in one embodiment may be referred to as a first component in another embodiment.
[0031] The terminology used herein is for the purpose of describing particular embodiments and is not intended to limit the scope of the claims. As used in the description of the embodiments and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. The term "and / or" as used herein may refer to any one of the associated enumerated items, or is meant to refer to and encompass any and all possible combinations of two or more of them. Furthermore, the use of " / " between words in this disclosure has the same meaning as "and / or" unless otherwise stated.
[0032] The examples of the present disclosure can be applied to various wireless communication systems. For example, the examples of the present disclosure can be applied to a wireless LAN system. For example, the examples of the present disclosure can be applied to a wireless LAN based on the IEEE 802.11a / g / n / ac / ax / be standards. Furthermore, the examples of the present disclosure can be applied to a wireless LAN based on the newly proposed IEEE 802.11bn (or UHR) standard. Additionally, the examples of the present disclosure can be applied to a wireless LAN based on the next-generation standard after IEEE 802.11bn. Furthermore, the examples of the present disclosure can be applied to a cellular wireless communication system. For example, the examples of the present disclosure can be applied to a cellular wireless communication system based on the LTE (Long Term Evolution) series of technologies and the 5G NR (New Radio) series of technologies of the 3rd Generation Partnership Project (3GPP) standard.
[0033] Below, technical features to which examples of the present disclosure can be applied are described.
[0034] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
[0035] The first device (100) and the second device (200) illustrated in FIG. 1 may be replaced with various terms such as a terminal, a wireless device, a WTRU (Wireless Transmit Receive Unit), a UE (User Equipment), an MS (Mobile Station), a UT (user terminal), an MSS (Mobile Subscriber Station), an MSS (Mobile Subscriber Unit), an SS (Subscriber Station), an AMS (Advanced Mobile Station), a WT (Wireless terminal), or simply a user. In addition, the first device (100) and the second device (200) may be replaced with various terms such as an access point (AP), a BS (Base Station), a fixed station, a Node B, a BTS (Base Transceiver System), a network, an AI (Artificial Intelligence) system, an RSU (road side unit), a repeater, a router, a relay, a gateway, etc.
[0036] The devices (100, 200) illustrated in FIG. 1 may also be referred to as stations (STAs). For example, the devices (100, 200) illustrated in FIG. 1 may be referred to by various terms such as transmitting device, receiving device, transmitting STA, and receiving STA. For example, the STAs (110, 200) may perform an AP (access point) role or a non-AP role. That is, in the present disclosure, the STAs (110, 200) may perform the functions of an AP and / or a non-AP. When the STAs (110, 200) perform an AP function, they may simply be referred to as APs, and when the STAs (110, 200) perform a non-AP function, they may simply be referred to as STAs. In addition, in the present disclosure, the APs may also be referred to as AP STAs.
[0037] Referring to FIG. 1, the first device (100) and the second device (200) can transmit and receive wireless signals through various wireless LAN technologies (e.g., IEEE 802.11 series). The first device (100) and the second device (200) can include interfaces for a medium access control (MAC) layer and a physical layer (PHY) that follow the provisions of the IEEE 802.11 standard.
[0038] In addition, the first device (100) and the second device (200) may additionally support various communication standards (e.g., 3GPP LTE series, 5G NR series standards, etc.) other than wireless LAN technology. In addition, the device of the present disclosure may be implemented as various devices such as a mobile phone, a vehicle, a personal computer, an AR (Augmented Reality) device, a VR (Virtual Reality) device, etc. In addition, the STA of the present specification may support various communication services such as voice calls, video calls, data communications, autonomous driving, MTC (Machine-Type Communication), M2M (Machine-to-Machine), D2D (Device-to-Device), and IoT (Internet-of-Things).
[0039] A first device (100) includes one or more processors (102) and one or more memories (104), and may further include one or more transceivers (106) and / or one or more antennas (108). The processor (102) controls the memories (104) and / or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (102) may process information in the memories (104) to generate first information / signals, and then transmit a wireless signal including the first information / signals via the transceivers (106). Furthermore, the processor (102) may receive a wireless signal including second information / signals via the transceivers (106), and then store information obtained from signal processing of the second information / signals in the memory (104). The memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (102) and the memory (104) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (106) may be connected to the processor (102) and may transmit and / or receive wireless signals via one or more antennas (108). The transceiver (106) may include a transmitter and / or a receiver. The transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.
[0040] The second device (200) includes one or more processors (202), one or more memories (204), and may further include one or more transceivers (206) and / or one or more antennas (208). The processor (202) controls the memories (204) and / or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (202) may process information in the memory (204) to generate third information / signals, and then transmit a wireless signal including the third information / signals via the transceivers (206). Furthermore, the processor (202) may receive a wireless signal including fourth information / signals via the transceivers (206), and then store information obtained from signal processing of the fourth information / signals in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via one or more antennas (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.
[0041] Hereinafter, the hardware elements of the device (100, 200) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (102, 202). For example, one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC). One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and / or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, proposals and / or methods disclosed in the present disclosure, and provide the signals to one or more transceivers (106, 206). One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed in the present disclosure.
[0042] One or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. One or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this disclosure may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software configured to perform one or more processors (102, 202) or stored in one or more memories (104, 204) and driven by one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software in the form of codes, instructions and / or sets of instructions.
[0043] One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (104, 204) may be configured as ROM, RAM, EPROM, flash memory, hard drives, registers, cache memory, computer-readable storage media, and / or combinations thereof. The one or more memories (104, 204) may be located internally and / or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.
[0044] One or more transceivers (106, 206) can transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or flowcharts of the present disclosure, to one or more other devices. One or more transceivers (106, 206) can receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts of the present disclosure, from one or more other devices. For example, one or more transceivers (106, 206) can be coupled to one or more processors (102, 202) and can transmit and receive wireless signals. For example, one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals / channels, or the like, as referred to in the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure, via one or more antennas (108, 208). In the present disclosure, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers (106, 206) can convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (102, 202).One or more transceivers (106, 206) may convert user data, control information, wireless signals / channels, etc. processed by one or more processors (102, 202) from baseband signals to RF band signals. For this purpose, one or more transceivers (106, 206) may include an (analog) oscillator and / or filter.
[0045] For example, one of the STAs (100, 200) may perform the intended operation of an AP, and the other of the STAs (100, 200) may perform the intended operation of a non-AP STA. For example, the transceivers (106, 206) of FIG. 1 may perform transmission and reception operations of signals (e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a / b / g / n / ac / ax / be / bn, etc.). In addition, in the present disclosure, operations in which various STAs generate transmission and reception signals or perform data processing or calculations in advance for transmission and reception signals may be performed in the processors (102, 202) of FIG. 1. For example, an example of an operation for generating a transmission / reception signal or performing data processing or operation in advance for a transmission / reception signal may include 1) an operation for determining / obtaining / configuring / computing / decoding / encoding bit information of a field (SIG (signal), STF (short training field), LTF (long training field), Data, etc.) included in a PPDU, 2) an operation for determining / configuring / obtaining time resources or frequency resources (e.g., subcarrier resources) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 3) an operation for determining / configuring / obtaining a specific sequence (e.g., a pilot sequence, an STF / LTF sequence, an extra sequence applied to SIG) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 4) a power control operation and / or a power saving operation applied to an STA, 5) an operation related to determining / obtaining / configuring / computing / decoding / encoding an ACK signal, etc. Additionally, in the examples below, various information (e.g., information related to fields / subfields / control fields / parameters / power, etc.) used by various STAs for determining / acquiring / configuring / computing / decoding / encoding transmission / reception signals can be stored in the memory (104, 204) of FIG. 1.
[0046] Hereinafter, downlink (DL) refers to a link for communication from an AP STA to a non-AP STA, and downlink PPDUs / packets / signals, etc. can be transmitted and received through the downlink. In downlink communication, the transmitter may be part of an AP STA, and the receiver may be part of a non-AP STA. Uplink (UL) refers to a link for communication from a non-AP STA to an AP STA, and uplink PPDUs / packets / signals, etc. can be transmitted and received through the uplink. In uplink communication, the transmitter may be part of a non-AP STA, and the receiver may be part of an AP STA.
[0047] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
[0048] The structure of a wireless LAN system can be composed of multiple components. Through the interaction of multiple components, a wireless LAN that supports transparent STA mobility to the upper layer can be provided. A Basic Service Set (BSS) corresponds to a fundamental building block of a wireless LAN. FIG. 2 illustrates, by way of example, the existence of two BSSs (BSS1 and BSS2) and the inclusion of two STAs as members of each BSS (STA1 and STA2 are included in BSS1, and STA3 and STA4 are included in BSS2). The oval representing a BSS in FIG. 2 can also be understood as representing a coverage area in which STAs included in the corresponding BSS maintain communication. This area can be referred to as a Basic Service Area (BSA). When an STA moves outside of a BSA, it cannot directly communicate with other STAs within the BSA.
[0049] If we do not consider the DS illustrated in Figure 2, the most basic type of BSS in a wireless LAN is an Independent BSS (IBSS). For example, an IBSS can have a minimal form consisting of only two STAs. For example, assuming other components are omitted, BSS1 consisting of only STA1 and STA2, or BSS2 consisting of only STA3 and STA4, can be representative examples of an IBSS, respectively. Such a configuration is possible when the STAs can communicate directly without an AP. Furthermore, in this type of WLAN, a LAN can be configured when needed rather than being planned in advance, and this can be called an ad-hoc network. Since an IBSS does not include an AP, there is no centralized management entity. That is, in an IBSS, STAs are managed in a distributed manner. In IBSS, all STAs can be mobile STAs, and access to distributed systems (DS) is not permitted, forming a self-contained network.
[0050] An STA's membership in a BSS can dynamically change, for example, when an STA is turned on or off, or when an STA enters or leaves a BSS area. To become a member of a BSS, an STA can join the BSS using a synchronization process. To access all services in the BSS infrastructure, an STA must be associated with the BSS. This association can be dynamically established and may involve the use of a Distribution System Service (DSS).
[0051] In a wireless LAN, the direct STA-to-STA distance can be limited by PHY performance. While this distance limit may be sufficient in some cases, communication between STAs over longer distances may be required in other cases. To support extended coverage, a distributed system (DS) can be configured.
[0052] DS refers to a structure in which BSSs are interconnected. Specifically, a BSS may exist as an extended component of a network composed of multiple BSSs, as illustrated in Figure 2. DS is a logical concept and can be specified by the characteristics of a distributed system medium (DSM). In this regard, the Wireless Medium (WM) and DSM can be logically distinguished. Each logical medium is used for a different purpose and by different components. These media are neither limited to being identical nor limited to being different. This logical difference between multiple media explains the flexibility of the WLAN architecture (DS architecture or other network architectures). In other words, the WLAN architecture can be implemented in various ways, and the physical characteristics of each implementation can independently specify the WLAN architecture.
[0053] A DS can support mobile devices by providing seamless integration of multiple BSSs and the logical services necessary to handle addresses to destinations. Additionally, a DS may further include a component called a portal, which acts as a bridge for connecting wireless LANs to other networks (e.g., IEEE 802.X).
[0054] An AP is an entity that enables access to a DS through a WM for associated non-AP STAs and also has the functionality of an STA. Data movement between a BSS and a DS can be performed through an AP. For example, STA2 and STA3 illustrated in FIG. 2 have the functionality of an STA and provide the function of allowing associated non-AP STAs (STA1 and STA4) to access the DS. In addition, since all APs are basically STAs, all APs are addressable entities. The address used by an AP for communication on a WM and the address used by an AP for communication on a DSM do not necessarily have to be the same. A BSS consisting of an AP and one or more STAs can be referred to as an infrastructure BSS.
[0055] Data transmitted from one of the STA(s) associated with an AP to the STA address of that AP may always be received on an uncontrolled port and processed by an IEEE 802.1X port access entity. In addition, if the controlled port is authenticated, the transmitted data (or frame) may be forwarded to the DS.
[0056] In addition to the structure of the DS described above, an extended service set (ESS) may be established to provide wider coverage.
[0057] An ESS is a network of arbitrary size and complexity, consisting of DSs and BSSs. An ESS may correspond to a set of BSSs connected to a DS. However, an ESS does not include a DS. An ESS network is characterized by appearing as an IBSS at the Logical Link Control (LLC) layer. STAs within an ESS can communicate with each other, and mobile STAs can move from one BSS to another (within the same ESS) transparently to the LLC. APs within an ESS may have the same SSID (service set identification). The SSID is distinct from the BSSID, which is the identifier of the BSS.
[0058] In a wireless LAN system, no assumptions are made about the relative physical locations of BSSs, and all of the following configurations are possible: BSSs can be partially overlapping, which is commonly used to provide continuous coverage. BSSs can also be physically disconnected, and there is no logical distance restriction between them. BSSs can also be physically co-located, which can be used to provide redundancy. Furthermore, one (or more) IBSS or ESS networks can physically co-exist with one (or more) ESS networks. This can occur in cases where an ad-hoc network operates at the same location as an ESS network, where physically overlapping wireless networks are configured by different organizations, or where two or more different access and security policies are required at the same location.
[0059] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.
[0060] For an STA to set up a link and transmit and receive data on a network, it must first discover the network, perform authentication, establish an association, and complete security authentication procedures. The link setup process can also be referred to as the session initiation process or session setup process. Furthermore, the discovery, authentication, association, and security setup processes of the link setup process can be collectively referred to as the association process.
[0061] In step S310, the STA may perform a network discovery operation. This network discovery operation may include scanning operations by the STA. That is, for the STA to access a network, it must search for available networks. Before joining a wireless network, the STA must identify compatible networks. The process of identifying networks in a specific area is called scanning.
[0062] Scanning methods include active scanning and passive scanning. Figure 3 illustrates a network discovery operation including an active scanning process as an example. In active scanning, an STA performing scanning transmits a probe request frame to discover any APs in the vicinity while moving between channels and waits for a response. The responder transmits a probe response frame in response to the STA that transmitted the probe request frame. Here, the responder may be the STA that last transmitted a beacon frame in the BSS of the channel being scanned. In the BSS, the AP transmits the beacon frame, so the AP becomes the responder. In the IBSS, the STAs within the IBSS take turns transmitting beacon frames, so the responder is not fixed. For example, an STA that transmits a probe request frame on channel 1 and receives a probe response frame on channel 1 can store BSS-related information included in the received probe response frame and move to the next channel (e.g., channel 2) to perform scanning (i.e., transmitting and receiving probe requests / responses on channel 2) in the same manner.
[0063] Although not shown in Figure 3, the scanning operation can also be performed in a passive scanning manner. In passive scanning, the STA performing the scanning moves between channels and waits for a beacon frame. A beacon frame is one of the management frames defined in IEEE 802.11. It announces the existence of a wireless network and is periodically transmitted so that the STA performing the scanning can find the wireless network and participate in the wireless network. In the BSS, the AP performs the role of periodically transmitting the beacon frame, and in the IBSS, the STAs within the IBSS take turns transmitting the beacon frame. When the STA performing the scanning receives a beacon frame, it stores the information about the BSS included in the beacon frame and moves to another channel, recording the beacon frame information on each channel. The STA receiving the beacon frame stores the BSS-related information included in the received beacon frame and moves to the next channel to perform scanning on the next channel in the same manner. Comparing active scanning and passive scanning, active scanning has the advantage of lower delay and power consumption than passive scanning.
[0064] After the STA discovers the network, an authentication process may be performed in step S320. This authentication process may be referred to as the first authentication process to clearly distinguish it from the security setup operation of step S340 described below.
[0065] The authentication process involves the STA sending an authentication request frame to the AP, and the AP responding by sending an authentication response frame to the STA. The authentication frame used for the authentication request / response corresponds to a management frame.
[0066] The authentication frame may include information such as an authentication algorithm number, an authentication transaction sequence number, a status code, a challenge text, a Robust Security Network (RSN), and a Finite Cyclic Group. These are just some examples of information that may be included in an authentication request / response frame, and may be replaced with other information or include additional information.
[0067] An STA can send an authentication request frame to an AP. The AP can determine whether to grant authentication to the STA based on the information contained in the received authentication request frame. The AP can provide the result of the authentication process to the STA via an authentication response frame.
[0068] After the STA is successfully authenticated, an association process may be performed in step S330. The association process includes a process in which the STA transmits an association request frame to the AP, and in response, the AP transmits an association response frame to the STA.
[0069] For example, the association request frame may include information about various capabilities, a beacon listen interval, a service set identifier (SSID), supported rates, supported channels, an RSN, a mobility domain, supported operating classes, a Traffic Indication Map Broadcast request, interworking service capabilities, etc. For example, the association response frame may include information about various capabilities, a status code, an Association ID (AID), supported rates, an Enhanced Distributed Channel Access (EDCA) parameter set, a Received Channel Power Indicator (RCPI), a Received Signal to Noise Indicator (RSNI), a mobility domain, a timeout interval (e.g., an association comeback time), overlapping BSS scan parameters, a TIM broadcast response, a Quality of Service (QoS) map, etc. These are just some examples of information that may be included in a combined request / response frame, and may be replaced by other information or include additional information.
[0070] After the STA successfully joins the network, a security setup process may be performed in step S340. The security setup process in step S340 may be referred to as an authentication process through a Robust Security Network Association (RSNA) request / response, the authentication process in step S320 may be referred to as a first authentication process, and the security setup process in step S340 may also be referred to simply as an authentication process.
[0071] The security setup process of step S340 may include, for example, a process of establishing a private key through a four-way handshaking using an Extensible Authentication Protocol over LAN (EAPOL) frame. Furthermore, the security setup process may be performed according to a security method not defined in the IEEE 802.11 standard.
[0072] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.
[0073] In wireless LAN systems, the basic access mechanism of MAC (Medium Access Control) is Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA). The CSMA / CA mechanism, also known as the Distributed Coordination Function (DCF) of the IEEE 802.11 MAC, essentially employs a "listen before talk" access mechanism. According to this type of access mechanism, the AP and / or STA may perform a Clear Channel Assessment (CCA) to sense the wireless channel or medium for a predetermined time period (e.g., a DCF Inter-Frame Space (DIFS)) before starting transmission. If the sensing result determines that the medium is in an idle state, the AP and / or STA may start transmitting frames through the medium. On the other hand, if the medium is detected to be occupied or busy, the AP and / or STA may not start its own transmission, but may wait for a delay period (e.g., a random backoff period) for medium access before attempting to transmit frames. By applying a random backoff period, multiple STAs are expected to attempt to transmit frames after waiting for different periods of time, thereby minimizing collisions.
[0074] In addition, the IEEE 802.11 MAC protocol provides the Hybrid Coordination Function (HCF). The HCF is based on the DCF and the Point Coordination Function (PCF). The PCF is a polling-based synchronous access method that periodically polls all receiving APs and / or STAs to ensure that they receive data frames. In addition, the HCF has the Enhanced Distributed Channel Access (EDCA) and the HCF Controlled Channel Access (HCCA). The EDCA is a contention-based access method for a provider to provide data frames to multiple users, while the HCCA uses a non-contention-based channel access method that utilizes a polling mechanism. In addition, the HCF includes a medium access mechanism to improve the Quality of Service (QoS) of the wireless LAN, and can transmit QoS data in both the Contention Period (CP) and the Contention Free Period (CFP).
[0075] Referring to Fig. 4, an operation based on a random backoff period is described. When a medium that was occupied / busy changes to an idle state, multiple STAs can attempt to transmit data (or frames). To minimize collisions, each STA can select a random backoff count, wait for the corresponding slot time, and then attempt transmission. The random backoff count has a pseudo-random integer value and can be determined as one of the values in the range of 0 to CW. Here, CW is a contention window parameter value. The CW parameter is given an initial value of CWmin, but can take a value doubled in case of transmission failure (e.g., when an ACK for a transmitted frame is not received). When the CW parameter value becomes CWmax, data transmission can be attempted while maintaining the CWmax value until data transmission is successful, and if data transmission is successful, it is reset to the CWmin value. The CW, CWmin, and CWmax values are 2. n It is desirable to set it to -1 (n=0, 1, 2, ...).
[0076] Once the random backoff process begins, the STA continues to monitor the medium while counting down the backoff slots according to the determined backoff count value. If the medium is monitored as occupied, the countdown stops and waits. When the medium becomes idle, the remaining countdown resumes.
[0077] In the example of FIG. 4, when a packet to be transmitted reaches the MAC of STA3, STA3 can immediately transmit a frame if it confirms that the medium is idle for DIFS. The remaining STAs monitor the medium for occupied / busy states and wait. In the meantime, data to be transmitted may also occur in each of STA1, STA2, and STA5, and each STA can count down the backoff slot according to a random backoff count value selected by each STA after waiting for DIFS if the medium is monitored as idle. Assume that STA2 selects the smallest backoff count value and STA1 selects the largest backoff count value. In other words, this example shows a case where the remaining backoff time of STA5 is shorter than the remaining backoff time of STA1 when STA2 finishes the backoff count and starts frame transmission. STA1 and STA5 briefly stop counting down and wait while STA2 occupies the medium. When STA2's occupation ends and the medium becomes idle again, STA1 and STA5 wait for DIFS and then resume the backoff count that they had stopped. That is, they can start transmitting frames after counting down the remaining backoff slots equal to the remaining backoff time. Since STA5's remaining backoff time is shorter than STA1's, STA5 starts transmitting frames. While STA2 occupies the medium, STA4 may also have data to transmit. From STA4's perspective, when the medium becomes idle, it waits for DIFS, counts down according to its selected random backoff count value, and then starts transmitting frames. In the example of Figure 4, the remaining backoff time of STA5 coincidentally matches the random backoff count value of STA4, in which case a collision may occur between STA4 and STA5. If a collision occurs, neither STA4 nor STA5 will receive an ACK, resulting in a failure in data transmission.In this case, STA4 and STA5 can select a random backoff count value and perform a countdown after doubling the CW value. STA1 waits while the medium is occupied by transmissions from STA4 and STA5, and when the medium becomes idle, it waits for DIFS and can start transmitting frames after the remaining backoff time elapses.
[0078] As in the example of Fig. 4, a data frame is a frame used for transmitting data forwarded to a higher layer, and can be transmitted after a backoff performed after DIFS elapses from when the medium becomes idle. Additionally, a management frame is a frame used for exchanging management information that is not forwarded to a higher layer, and is transmitted after a backoff performed after an IFS elapses, such as DIFS or PIFS (Point coordination function IFS). Subtype frames of a management frame include a beacon, an association request / response, a re-association request / response, a probe request / response, and an authentication request / response. A control frame is a frame used to control access to the medium. The subtype frames of the control frame include Request-To-Send (RTS), Clear-To-Send (CTS), Acknowledgment (ACK), Power Save-Poll (PS-Poll), Block ACK (BlockAck), Block ACK Request (BlockACKReq), Null Data Packet Announcement (NDP), and Trigger. If the control frame is not a response frame to the previous frame, it is transmitted after a backoff performed after the DIFS (Direct Inverse Frame Stop) has elapsed, and if it is a response frame to the previous frame, it is transmitted without a backoff performed after the SIFS (short IFS). The type and subtype of the frame can be identified by the type field and subtype field in the Frame Control (FC) field.
[0079] A QoS (Quality of Service) STA can transmit a frame after a backoff performed after the AIFS (arbitration IFS) for the access category (AC) to which the frame belongs, i.e., AIFS[i] (where i is a value determined by the AC), has elapsed. Here, the frames for which AIFS[i] can be used can be data frames, management frames, and also control frames that are not response frames.
[0080] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.
[0081] As mentioned above, the CSMA / CA mechanism includes virtual carrier sensing in addition to physical carrier sensing, in which STAs directly sense the medium. Virtual carrier sensing is intended to address potential issues in medium access, such as the hidden node problem. For virtual carrier sensing, the MAC of an STA can utilize a Network Allocation Vector (NAV). The NAV is a value that an STA that is currently using or has the right to use the medium indicates to other STAs the remaining time until the medium becomes available. Therefore, the value set as NAV corresponds to the period during which the STA transmitting the frame is scheduled to use the medium, and an STA receiving the NAV value is prohibited from accessing the medium during that period. For example, the NAV can be set based on the value of the "duration" field in the MAC header of the frame.
[0082] In the example of FIG. 5, it is assumed that STA1 wants to transmit data to STA2, and STA3 is in a position to overhear some or all of the frames transmitted and received between STA1 and STA2.
[0083] In order to reduce the possibility of collisions in transmissions of multiple STAs in a CSMA / CA-based frame transmission operation, a mechanism using RTS / CTS frames may be applied. In the example of FIG. 5, while STA1 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA1 may correspond to a hidden node for STA3. Alternatively, in the example of FIG. 5, while STA2 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA2 may correspond to a hidden node for STA3. By exchanging RTS / CTS frames before performing data transmission and reception between STA1 and STA2, STAs outside the transmission range of either STA1 or STA2, or STAs outside the carrier sensing range for transmissions from STA1 or STA3, may not attempt to occupy the channel during data transmission and reception between STA1 and STA2.
[0084] Specifically, STA1 can determine whether a channel is occupied through carrier sensing. In terms of physical carrier sensing, STA1 can determine channel occupancy idleness based on the energy level or signal correlation detected in the channel. Furthermore, in terms of virtual carrier sensing, STA1 can determine the channel occupancy status using a network allocation vector (NAV) timer.
[0085] STA1 can transmit an RTS frame to STA2 after performing a backoff if the channel is idle during the DIFS. STA2 can transmit a CTS frame, which is a response to the RTS frame, to STA1 after an SIFS if it receives the RTS frame.
[0086] If STA3 cannot overhear a CTS frame from STA2 but can overhear an RTS frame from STA1, STA3 can use the duration information contained in the RTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + CTS frame + SIFS + data frame + SIFS + ACK frame). Alternatively, if STA3 cannot overhear an RTS frame from STA1 but can overhear a CTS frame from STA2, STA3 can use the duration information contained in the CTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + data frame + SIFS + ACK frame). That is, if STA3 can overhear one or more of the RTS or CTS frames from one or more of STA1 or STA2, it can set a NAV accordingly. If STA3 receives a new frame before the NAV timer expires, it can update the NAV timer using the duration information contained in the new frame. STA3 does not attempt channel access until the NAV timer expires.
[0087] If STA1 receives a CTS frame from STA2, it can transmit a data frame to STA2 after SIFS from the time when the CTS frame is completely received. If STA2 successfully receives the data frame, it can transmit an ACK frame in response to the data frame to STA1 after SIFS. STA3 can determine whether the channel is in use through carrier sensing if the NAV timer expires. If STA3 determines that the channel is not in use by another terminal during the DIFS after the NAV timer expires, it can attempt channel access after a contention window (CW) based on a random backoff has elapsed.
[0088] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.
[0089] The PHY layer can prepare an MPDU (MAC PDU) to be transmitted based on an instruction or primitive (meaning a set of instructions or parameters) from the MAC layer. For example, when a command requesting the start of transmission of the PHY layer is received from the MAC layer, the PHY layer can switch to transmission mode and transmit the information (e.g., data) provided by the MAC layer in the form of a frame. In addition, when the PHY layer detects a valid preamble of the received frame, it monitors the header of the preamble and sends a command to the MAC layer notifying the start of reception of the PHY layer.
[0090] In this way, information transmission / reception in a wireless LAN system is done in the form of frames, and for this purpose, the PHY layer Protocol Data Unit (PPDU) format is defined.
[0091] A basic PPDU may include a Short Training Field (STF), a Long Training Field (LTF), a SIGNAL (SIG) field, and a Data field. The most basic (e.g., non-HT (High Throughput) as illustrated in FIG. 7) PPDU format may consist of only the Legacy-STF (L-STF), Legacy-LTF (L-LTF), Legacy-SIG (L-SIG) fields, and a Data field. Additionally, depending on the type of PPDU format (e.g., HT-mixed format PPDU, HT-greenfield format PPDU, VHT (Very High Throughput) PPDU, etc.), additional (or different types of) RL-SIG, U-SIG, non-legacy SIG field, non-legacy STF, non-legacy LTF, (i.e., xx-SIG, xx-STF, xx-LTF (e.g., xx is HT, VHT, HE, EHT, etc.)) may be included between the L-SIG field and the data field. More specific details will be described later with reference to FIG. 7.
[0092] STF is a signal for signal detection, AGC (Automatic Gain Control), diversity selection, and precise time synchronization, while LTF is a signal for channel estimation, frequency error estimation, etc. STF and LTF can be said to be signals for synchronization and channel estimation of the OFDM physical layer.
[0093] The SIG field may include various information related to PPDU transmission and reception. For example, the L-SIG field may consist of 24 bits and may include a 4-bit Rate field, a 1-bit Reserved bit, a 12-bit Length field, a 1-bit Parity field, and a 6-bit Tail field. The RATE field may include information about the modulation and coding rate of data. For example, the 12-bit Length field may include information about the length or time duration of the PPDU. For example, the value of the 12-bit Length field may be determined based on the type of the PPDU. For example, for a non-HT, HT, VHT, or EHT PPDU, the value of the Length field may be determined as a multiple of 3. For example, for HE PPDU, the value of the Length field can be determined as a multiple of 3 + 1 or a multiple of 3 + 2.
[0094] The data field may include a SERVICE field, a Physical layer Service Data Unit (PSDU), a PPDU TAIL bit, and, if necessary, padding bits. Some bits of the SERVICE field may be used to synchronize the descrambler at the receiving end. The PSDU corresponds to a MAC PDU defined at the MAC layer and may contain data generated / used by upper layers. The PPDU TAIL bit may be used to return the encoder to a 0 state. The padding bit may be used to adjust the length of the data field to a predetermined unit.
[0095] MAC PDUs are defined according to various MAC frame formats, and a basic MAC frame consists of a MAC header, a frame body, and a Frame Check Sequence (FCS). A MAC frame is composed of MAC PDUs and can be transmitted / received through the PSDU in the data portion of the PPDU format.
[0096] The MAC header includes a Frame Control field, a Duration / ID field, an Address field, etc. The Frame Control field may include control information required for frame transmission / reception. The Duration / ID field may be set to a time for transmitting the corresponding frame, etc. The Address subfields may indicate the receiver address, transmitter address, destination address, and source address of the frame, and some Address subfields may be omitted. For specific details of each subfield of the MAC header, including the Sequence Control, QoS Control, and HT Control subfields, refer to the IEEE 802.11 standard document.
[0097] The Null-Data PPDU (NDP) format refers to a PPDU format that does not include a data field. In other words, NDP refers to a frame format that includes a PPDU preamble (i.e., L-STF, L-LTF, L-SIG fields, and, if additionally present, non-legacy SIG, non-legacy STF, and non-legacy LTF) in the general PPDU format, and does not include the remaining part (i.e., data field).
[0098] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.
[0099] Standards such as IEEE 802.11a / g / n / ac / ax use various PPDU formats. The basic PPDU format (IEEE 802.11a / g) includes L-LTF, L-STF, L-SIG, and Data fields. The basic PPDU format can also be referred to as the non-HT PPDU format (Fig. 7(a)).
[0100] The HT PPDU format (IEEE 802.11n) additionally includes HT-SIG, HT-STF, and HT-LFT(s) fields in addition to the basic PPDU format. The HT PPDU format illustrated in Fig. 7(b) may be referred to as an HT-mixed format. Additionally, an HT-greenfield format PPDU may be defined, which corresponds to a format that does not include L-STF, L-LTF, and L-SIG, but consists of HT-GF-STF, HT-LTF1, HT-SIG, one or more HT-LTF, and Data fields (not illustrated).
[0101] An example of the VHT PPDU format (IEEE 802.11ac) includes VHT SIG-A, VHT-STF, VHT-LTF, and VHT-SIG-B fields in addition to the basic PPDU format (Fig. 7(c)).
[0102] An example of a HE PPDU format (IEEE 802.11ax) additionally includes RL-SIG (Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), and PE (Packet Extension) fields in addition to the basic PPDU format (Fig. 7(d)). Depending on specific examples of the HE PPDU format, some fields may be excluded or their lengths may vary. For example, the HE-SIG-B field is included in the HE PPDU format for multi-users (MUs), but the HE-SIG-B is not included in the HE PPDU format for single users (SUs). In addition, the HE trigger-based (TB) PPDU format does not include the HE-SIG-B, and the length of the HE-STF field may vary to 8 microseconds (us). The HE ER (Extended Range) SU PPDU format does not include the HE-SIG-B field, and the length of the HE-SIG-A field can vary to 16us. For example, the RL-SIG can be configured identically to the L-SIG. The receiving STA can determine that the received PPDU is a HE PPDU or an EHT PPDU, described later, based on the presence of the RL-SIG.
[0103] The EHT PPDU format may include the EHT MU (multi-user) PPDU of FIG. 7(e) and the EHT TB (trigger-based) PPDU of FIG. 7(f). The EHT PPDU format is similar to the HE PPDU format in that it includes an RL-SIG following an L-SIG, but may include a U (universal)-SIG, an EHT-SIG, an EHT-STF, and an EHT-LTF following the RL-SIG.
[0104] The EHT MU PPDU in FIG. 7(e) corresponds to a PPDU that carries one or more data (or PSDUs) for one or more users. That is, the EHT MU PPDU can be used for both SU transmission and MU transmission. For example, the EHT MU PPDU can correspond to a PPDU for one receiving STA or multiple receiving STAs.
[0105] The EHT TB PPDU of Fig. 7(f) omits the EHT-SIG compared to the EHT MU PPDU. An STA that has received a trigger for UL MU transmission (e.g., a trigger frame or TRS (triggered response scheduling)) can perform UL transmission based on the EHT TB PPDU format.
[0106] The L-STF, L-LTF, L-SIG, RL-SIG, U-SIG (Universal SIGNAL), and EHT-SIG fields can be encoded and modulated to allow legacy STAs to attempt demodulation and decoding, and mapped based on a predetermined subcarrier frequency interval (e.g., 312.5 kHz). These can be referred to as pre-EHT modulated fields. Next, the EHT-STF, EHT-LTF, Data, and PE fields can be encoded and modulated to allow STAs that have successfully decoded non-legacy SIGs (e.g., U-SIG and / or EHT-SIG) and obtained the information contained in the fields, and mapped based on a predetermined subcarrier frequency interval (e.g., 78.125 kHz). These can be referred to as EHT modulated fields.
[0107] Similarly, in the HE PPDU format, the L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, and HE-SIG-B fields may be referred to as pre-HE modulation fields, and the HE-STF, HE-LTF, Data, and PE fields may be referred to as HE modulation fields. Additionally, in the VHT PPDU format, the L-STF, L-LTF, L-SIG, and VHT-SIG-A fields may be referred to as pre-VHT modulation fields, and the VHT STF, VHT-LTF, VHT-SIG-B, and Data fields may be referred to as VHT modulation fields.
[0108] The U-SIG included in the EHT PPDU format of FIG. 7 can be configured based on, for example, two symbols (e.g., two consecutive OFDM symbols). Each symbol (e.g., OFDM symbol) for the U-SIG can have a duration of 4 us, and the U-SIG can have a total duration of 8 us. Each symbol of the U-SIG can be used to transmit 26 bits of information. For example, each symbol of the U-SIG can be transmitted and received based on 52 data tones and 4 pilot tones.
[0109] U-SIGs can be configured in 20MHz units. For example, when an 80MHz PPDU is configured, the same U-SIG can be duplicated in 20MHz units. That is, four identical U-SIGs can be included in an 80MHz PPDU. When the bandwidth exceeds 80MHz, for example, for a 160MHz PPDU, the U-SIGs in the first 80MHz unit and the U-SIGs in the second 80MHz unit can be different.
[0110] For example, A uncoded bits may be transmitted via U-SIG, and a first symbol of U-SIG (e.g., a U-SIG-1 symbol) may transmit the first X bits of information out of a total A bits of information, and a second symbol of U-SIG (e.g., a U-SIG-2 symbol) may transmit the remaining Y bits of information out of a total A bits of information. The A bits of information (e.g., 52 uncoded bits) may include a CRC field (e.g., a field of 4 bits in length) and a tail field (e.g., a field of 6 bits in length). The tail field may be used to terminate the trellis of the convolutional decoder and may be set to 0, for example.
[0111] The A bit information transmitted by U-SIG can be divided into version-independent bits and version-dependent bits. For example, U-SIG can be included in a new PPDU format (e.g., UHR PPDU format) not shown in FIG. 7, and in the format of the U-SIG field included in the EHT PPDU format and the format of the U-SIG field included in the UHR PPDU format, the version-independent bits can be the same, and some or all of the version-dependent bits can be different.
[0112] For example, the size of the version-independent bits of U-SIG can be fixed or variable. The version-independent bits can be assigned only to U-SIG-1 symbols, or to both U-SIG-1 symbols and U-SIG-2 symbols. The version-independent bits and the version-dependent bits can be called by various names, such as the first control bit and the second control bit.
[0113] For example, the version-independent bits of the U-SIG may include a 3-bit PHY version identifier, which may indicate the PHY version (e.g., EHT, UHR, etc.) of the transmitted and received PPDUs. The version-independent bits of the U-SIG may include a 1-bit UL / DL flag field. The first value of the 1-bit UL / DL flag field relates to UL communication, and the second value of the UL / DL flag field relates to DL communication. The version-independent bits of the U-SIG may include information about the length of a transmission opportunity (TXOP) and information about a BSS color ID.
[0114] For example, the version-dependent bits of the U-SIG may contain information that directly or indirectly indicates the type of PPDU (e.g., SU PPDU, MU PPDU, TB PPDU, etc.).
[0115] Information required for PPDU transmission and reception may be included in the U-SIG. For example, the U-SIG may further include information about bandwidth, information about the MCS technique applied to the non-legacy SIG (e.g., EHT-SIG or UHR-SIG), information indicating whether a dual carrier modulation (DCM) technique (e.g., a technique to achieve an effect similar to frequency diversity by reusing the same signal on two subcarriers) is applied to the non-legacy SIG, information about the number of symbols used for the non-legacy SIG, information about whether the non-legacy SIG is generated across the entire band, etc.
[0116] Some of the information required for transmitting and receiving a PPDU may be included in the U-SIG and / or the non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.). For example, information about the type of the non-legacy LTF / STF (e.g., EHT-LTF / EHT-STF or UHR-LTF / UHR-STF, etc.), information about the length of the non-legacy LTF and the cyclic prefix (CP) length, information about the guard interval (GI) applicable to the non-legacy LTF, information about preamble puncturing applicable to the PPDU, information about resource unit (RU) allocation, etc. may be included only in the U-SIG, may be included only in the non-legacy SIG, or may be indicated by a combination of the information included in the U-SIG and the information included in the non-legacy SIG.
[0117] Preamble puncturing may refer to the transmission of a PPDU in which no signal is present in one or more frequency units within the PPDU's bandwidth. For example, the size of the frequency unit (or the resolution of the preamble puncturing) may be defined as 20 MHz, 40 MHz, etc. For example, preamble puncturing may be applied to a PPDU bandwidth greater than a certain size.
[0118] In the example of FIG. 7, non-legacy SIGs such as HE-SIG-B and EHT-SIG may include control information for the receiving STA. The non-legacy SIG may be transmitted over at least one symbol, and each symbol may have a length of 4 us. Information regarding the number of symbols used for the EHT-SIG may be included in a previous SIG (e.g., HE-SIG-A, U-SIG, etc.).
[0119] Non-legacy SIGs, such as HE-SIG-B and EHT-SIG, may contain common fields and user-specific fields. Common and user-specific fields may be coded separately.
[0120] In some cases, common fields may be omitted. For example, in a compressed mode where non-OFDMA (orthogonal frequency multiple access) is applied, common fields may be omitted, and multiple STAs may receive PPDUs (e.g., data fields of PPDUs) over the same frequency band. In a non-compressed mode where OFDMA is applied, multiple users may receive PPDUs (e.g., data fields of PPDUs) over different frequency bands.
[0121] The number of user-specific fields can be determined based on the number of users. A single user block field can contain up to two user fields. Each user field can be associated with either MU-MIMO allocation or non-MU-MIMO allocation.
[0122] The common field may include CRC bits and Tail bits, the length of the CRC bits may be determined as 4 bits, and the length of the Tail bits may be determined as 6 bits and set to 000000. The common field may include RU allocation information. The RU allocation information may include information about the location of RUs to which multiple users (i.e., multiple receiving STAs) are allocated.
[0123] An RU can contain multiple subcarriers (or tones). RUs can be used when transmitting signals to multiple STAs based on OFDMA techniques. RUs can also be defined when transmitting signals to a single STA. Resources can be allocated on an RU basis for non-legacy STFs, non-legacy LTFs, and data fields.
[0124] Depending on the PPDU bandwidth, an applicable RU size can be defined. The RU may be defined identically or differently for the applicable PPDU format (e.g., HE PPDU, EHT PPDU, UHR PPDU, etc.). For example, in the case of an 80MHz PPDU, the RU arrangements of HE PPDU and EHT PPDU may be different. The applicable RU size, RU number, RU position, DC (direct current) subcarrier position and number, null subcarrier position and number, guard subcarrier position and number, etc. for each PPDU bandwidth can be referred to as a tone plan. For example, a tone plan for a wide bandwidth can be defined in the form of multiple repetitions of a low bandwidth tone plan.
[0125] RUs of different sizes can be defined, such as 26-ton RU, 52-ton RU, 106-ton RU, 242-ton RU, 484-ton RU, 996-ton RU, 2X996-ton RU, 4X996-ton RU, etc. A multiple RU (MRU) is distinguished from multiple individual RUs and corresponds to a group of subcarriers consisting of multiple RUs. For example, one MRU can be defined as 52+26-tons, 106+26-tons, 484+242-tons, 996+484-tons, 996+484+242-tons, 2X996+484-tons, 3X996-tons, or 3X996+484-tons. Additionally, multiple RUs constituting one MRU may or may not be consecutive in the frequency domain.
[0126] The specific size of an RU may be reduced or expanded. Therefore, the specific size of each RU (i.e., the number of corresponding tones) in the present disclosure is not limited and is exemplary. Furthermore, within a given bandwidth (e.g., 20, 40, 80, 160, 320 MHz, etc.) in the present disclosure, the number of RUs may vary depending on the RU size.
[0127] The names of each field in the PPDU formats of FIG. 7 are exemplary and the scope of the present disclosure is not limited by those names. Furthermore, the examples of the present disclosure can be applied not only to the PPDU format exemplified in FIG. 7, but also to a new PPDU format in which some fields are excluded and / or some fields are added based on the PPDU formats of FIG. 7.
[0128] Multi-Access Point (MAP) operation
[0129] Below, examples of the present disclosure for multi-access point (MAP) operation are described.
[0130] MAP operation can be defined as an operation between a master AP (or sharing AP) and a slave AP (or shared AP).
[0131] The master AP initiates and controls MAP operations for transmission and reception between multiple APs. It groups slave APs and manages links with them to enable information sharing. The master AP manages information about the BSS comprised of the slave APs and the STAs associated with that BSS.
[0132] Slave APs can associate with a master AP and share control information, management information, and data traffic. Slave APs perform the same basic functions as APs, establishing a base station service (BSS) in a wireless LAN.
[0133] In MAP operation, an STA can associate with a slave AP or a master AP and form a BSS.
[0134] In a MAP environment, the master AP and slave APs can directly transmit and receive with each other. The master AP and STA may not be able to directly transmit and receive with each other. A slave AP (e.g., a slave AP associated with an STA) can directly transmit and receive with the STA. One of the slave APs can become the master AP.
[0135] MAP operation is a technique in which one or more APs transmit and receive information to one or more STAs. For example, coordinated-time division multiple access (C-TDMA), which divides allocations between APs along the time axis, coordinated-orthogonal frequency division multiple access (C-OFDMA), which divides allocations along the frequency axis, and coordinated-spatial reuse (C-SR) techniques that utilize spatial reuse can be applied for MAP operation. Alternatively, coordinated beamforming (C-BF) or joint beamforming techniques, which cooperatively perform simultaneous transmission and reception, can also be applied to MAP operation.
[0136] FIG. 8 is a diagram for explaining various transmission and reception techniques in a MAP environment to which the present disclosure can be applied.
[0137] As in the conventional method, when a BSS AP transmits to a BSS STA, this can be referred to as STX (single transmission). STX suffers from the problem of reduced transmission and reception performance for users / STAs located at the cell edge due to interference with neighboring APs. For example, as shown in Figure 8(a), if AP1 and AP2 transmit to STA1 and STA2, respectively, at the same time and within the same frequency bandwidth, a collision may occur on the wireless medium.
[0138] In the MAP technique, performance can be improved by reducing inter-symbol interference (ISI) through cooperation between neighboring APs, or by performing joint transmissions. For example, in the C-OFDMA method of Fig. 8(b), interference can be avoided by simultaneously transmitting to STA1 in the first bandwidth and transmitting to STA2 in the second bandwidth. The example of Fig. 8(c) shows a cooperative beamforming or nulling technique in which AP1 nulls the interference to AP2 and / or STA2 while transmitting to STA1, and AP2 nulls the interference to AP1 and / or STA1 while transmitting to STA2. Fig. 8(d) shows an AP selection method in which an AP with a good channel condition among neighboring APs performs transmission. Joint transmission (JTX) or joint reception (JRX) may be applied, in which multiple APs cooperate to transmit or receive simultaneously, as in the example of Fig. 8(e), and further, joint MU-MIMO may be supported.
[0139] RSN operation
[0140] As described with reference to Figure 3, after the discovery process between the STA and the AP, the authentication process can be performed in an open system manner, followed by an association process. This process can be considered Step 0, which involves detecting support for a robust security network (RSN) and establishing authentication and association.
[0141] If step 0 is successfully completed, step 1 of user authentication by IEEE 802.1X / EAP (extensible authentication protocol) or PSK (pre-shared key) and obtaining a pairwise master key (PMK) can be performed. The mutual authentication method applied here may include 802.1X / EAP, PSK, or simultaneous authentication of equals (SAE). For example, in the case of 802.1X / EAP authentication, PMK can be generated from MSK (master session key) after authentication between STA and RADIUS (remote authentication dial-in user service). In the case of user authentication by PSK, AP and STA can directly set PMK in the same way as PSK. In the case of user authentication by SAE, AP and STA can directly set PMK by using mutual authentication and authentication process operation value through SAE authentication process.
[0142] Following Step 1, Step 2 may be performed to verify that the other party holds the same PMK using the EAPoL-Key frame and to generate and share an encryption key. Step 2 may include a process of mutually verifying the generation of the PMK through 4-way handshaking and generating and transmitting a group key (e.g., a group temporal key (GTK)). A pairwise transient key (PTK), a key confirmation key (KCK), a key encryption key (KEK), and a temporal key (TK) may be generated through the 4-way handshaking.
[0143] Specifically, in step 1, a PMK may be generated from the MSK, and in step 2, a PTK may be generated from the PMK. Here, the PTK is configured separately as a KCK, a KEK, and a TK. A GTK may be generated from the AP and transmitted to the STA. If the AP wishes to generate a new GTK, it may perform handshaking with the STA and transmit the new GTK to the STA.
[0144] In order to verify that the STA and AP have the same PMK, in the case of 802.1X / EAP, the same MSK is set between the STA and the AS based on the user authentication result between the STA and the authentication server (AS), and the AS transmits the MSK to the AP. The STA and the AP can confirm whether they have the PMK, which is a symmetric key generated from the MSK, through 4-way handshaking. In the case of the PSK, the authentication procedure can be replaced by mutually verifying through 4-way handshaking whether the PMK generated from the PSK previously set between the AP and the STA has been secured. In the case of SAE, the PMK previously set between the AP and the STA can be mutually verified through 4-way handshaking.
[0145] It is also possible to verify whether the STA and the AP have the same PMK by mutually verifying that they generated the same PTK. For example, it is also possible to verify whether the PMK is secured through Messages 2 and 3 of the 4-way handshaking. Specifically, in Message 2, the STA can include the KCK of the PTK it generated in the Key MIC field and transmit it to the AP. In Message 3, the AP can include the KCK of the PTK it generated in the Key MIC field and transmit it to the STA. Through this, the STA (AP) can verify that the AP (STA) generated the same PTK as its own PTK, thereby confirming that the AP (STA) has the same PMK as itself. Meanwhile, in Message 1, the value of the Key MIC field may be set to 0, and in Message 4, the Key MIC field may include the KCK value.
[0146] In this way, a secret key can be generated to encrypt data to be transmitted and received between the STA and the AP in step 2. In the RSN, a different secret key is generated for each STA associated with the AP, and another secret key is generated when the STA re-associates with another AP.
[0147] Based on the TK generated as a result of the 4-way handshaking in step 2, data encryption can be performed using TKIP (temporal key integrity protocol), CCMP (cipher-block chaining message authentication code protocol), GCMP (Galois / Counter Mode protocol), etc., and this can be referred to as step 3.
[0148] The aforementioned MSK, PSK, PMK, PTK, KCK, KEK, and TK correspond to pairwise keys, that is, keys that are paired between the AP and the STA. Unlike the pairwise keys, the group key can be generated based on the group master key (GMK) for the AP to generate a secret key for group-addressed frames, such as beacon frames. The GMK is randomly set by the AP. The group temporal key (GTK) is generated from the GMK by the pseudorandom function (PRF) and corresponds to a one-way group key from the AP to the STA.
[0149] FIG. 9 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.
[0150] The STA corresponds to the side requesting authentication (supplicant), and the AP corresponds to the side performing authentication (authenticator). A four-way handshaking can be performed to generate and verify the PTK and GTK between the AP and the STA when the STA possesses or knows the PMK, and the AP possesses or knows the PMK and GMK.
[0151] ANonce and SNonce correspond to arguments used in the PRF function used to generate the PTK. ANonce may correspond to a random number generated by the access point (i.e., the authenticator). SNonce may correspond to a random number generated by the STA (i.e., the supplicant). The PRF function may correspond to a function that generates a PTK based on, for example, the PMK, ANonce, SNonce, the MAC address of the supplicant, and the MAC address of the authenticator.
[0152] Message 1 of step S910 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include ANonce information. If the AP generates a PMK, the PMKID may be included in the key data field of the EAPOL-key frame. The STA may generate a PTK based on the information received from the AP, and may generate a KCK, KEK, and TK based on the PKT.
[0153] Message 2 of step S920 is transmitted from the STA to the AP in a unicast manner, and the EAPOL-key frame may include SNonce information and a key MIC (message integrity code). For example, the key MIC of message 2 may have a value based on the KCK generated by the STA. The AP may generate a PTK based on the information received from the STA, and may generate a KCK, a KEK, and a TK based on the PTK. The AP may verify whether the AP and the STA have generated the same PTK based on whether the KCK value of the PTK generated based on the value included in message 2 and the KCK value related to the key MIC value included in message 2 are the same. In addition, the AP may generate a GTK if necessary. The generation of the GTK may be generated by the AP from the GMK without the involvement of the STA.
[0154] Message 3 of step S930 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include PTK, MIC, and encrypted GTK information. The encrypted GTK of message 3 may be generated based on the KEK generated by the AP and included in the key data field. The STA may store the PTK in the PKT-SA (PKT-Security Association) and the GTK in the GTK-SA.
[0155] Message 4 of step S940 is transmitted unicast from the STA to the AP, and the EAPOL-key frame may include MIC information. Upon completion of verification via the MIC, the AP may store the PTK in the PKT-SA and the GTK in the GTK-SA.
[0156] Once the four-way handshaking is successfully completed, the virtual control port that previously blocked all traffic is unblocked, allowing encrypted traffic to be transmitted and received. All unicast traffic can then be encrypted using PTK, and all multicast / broadcast traffic can be encrypted using GTK.
[0157] FT (fast BSS transition) operation
[0158] Figure 10 is a diagram for explaining BSS transition in an existing wireless LAN system.
[0159] In the case of the FT (fast BSS transition) method, which is a representative example of BSS transition (or roaming), various processes such as authentication request / response and re-association request / response are required between the FTO (FT originator) (or non-AP STA) and the target FTR in order to move from the current FTR (FT responder) (or current AP) to the target FTR (or target AP). That is, in the existing BSS transition method, a re-association process is required on the same mobility domain.
[0160] Additionally, after the process illustrated in Figure 10, various operational parameters, such as agreements related to BA (BlockAck) and SCS (Service Classification Service), SN, and EDCAF (EDCA function) parameters, are reset. Therefore, FTO must perform a large number of frame exchanges for FT and re-establish agreement / configuration with a new FTR. Consequently, the complexity and overhead of the FT process are high, and data loss may occur during the FT process.
[0161] In the existing authentication method, an STA that determines that roaming to a new AP is necessary must exchange a (re-)association request / response with the new AP, and can only obtain an MSK after successfully completing the STA's authentication with the new AP. In other words, the STA must begin the RSN authentication and key generation process described with reference to Figure 9 from scratch with the new AP.
[0162] To improve this, the FT method allows for the MSK acquisition process to be completed before the STA roams. For example, when an STA enters a mobility domain (MD), the initial authentication process is performed only once, and within the same MD (i.e., entities with the same MD identification information (MDID)), the encryption method derived from the initial authentication process is used. This shortens roaming time and reduces the load on the authentication server (AS).
[0163] In addition, an FT key hierarchy may be supported to support the FT method. The highest level key holder (KH) may correspond to R1KH and S1KH, and the lower level key holders may correspond to R0KH and S0KH. R1KH and S1KH may have access rights to R0KH and S0KH. R0KH and R1KH belong to the RSNA key management of the SME (station management entity) of the AP, and may be referred to as authenticator key holders. S0KH and S1KH belong to the RSNA key management of the SME of the STA, and may be referred to as supplicant key holders. R0KH and S0KH may be responsible for the calculation of PMK-R0 and PMK-R1 of the AP and STA, respectively. R1KH and S1KH can be responsible for calculating the PTK of AP and STA, respectively.
[0164] When authentication is successfully completed in the FT initial mobility domain association method, the R0KH of the AP (e.g., the current FTR) can receive the PMK and related parameters. Here, if a KH belonging to the same MDID as the STA to be associated already exists, the PMK-R0 SA (security association) and PMK-R1 SA in which the R0KH exists can be deleted, and PMK-R0 and PMK-R1 can be calculated based on the newly received PMK. After that, the S1KH of the STA and the R1KH of the AP can generate TK and GTK through 4-way handshaking, and store and manage them in each SA (e.g., PTKSA, GTKSA). Accordingly, the IEEE 802.1X controlled port between the STA and the AP is unblocked, enabling encrypted message transmission and reception.
[0165] Security between APs
[0166] As described above, after an association is established between an AP STA and a non-AP STA, an encryption key (e.g., PTK, TK derived from GTK) used in data encapsulation / decapsulation can be generated through 4-way handshaking. During this process, security parameters can be stored in a security association (SA) within the AP STA and the non-AP STA. Based on the information stored in the SA, etc., integrity and / or confidentiality can be guaranteed / supported for individually addressed data frames and / or group addressed data frames between the AP STA and the non-AP STA.
[0167] In addition, as mentioned above, a multi-AP or multi-BSS may include a vertical structure of one master AP (or sharing AP) and one or more slave APs (or shared APs), or may include a horizontal parallel structure of multiple APs. In such a multi-AP / multi-BSS environment, data can be transmitted and received wirelessly (not through backhaul) between APs, but existing methods for supporting / guaranteeing data confidentiality / integrity are defined only for data transmission and reception between AP STAs and non-AP STAs. Therefore, a method for ensuring / supporting confidentiality / integrity for data transmitted wirelessly between APs within a multi-AP / multi-BSS is not defined.
[0168] For example, during the negotiation process for coordinating transmission and reception schedules over wireless media between APs within a multi-AP / multi-BSS, data may need to be transmitted and received between APs. In this case, since existing systems cannot guarantee / support confidentiality / integrity for data between APs, such data may be exposed to malicious third-party STAs. To prevent such problems, the present disclosure describes various examples of supporting confidentiality and / or integrity for data wirelessly transmitted / received between APs belonging to a specific AP set.
[0169] In various examples of the present disclosure, a particular set of APs may include APs belonging to the aforementioned multi-AP or multi-BSS, but is not limited to multi-AP or multi-BSS.
[0170] The names and values of fields, elements, parameters, keys, etc. proposed in this disclosure are exemplary and are not limited to these names and values. In addition, unless otherwise specified, an STA may be an AP STA or a non-AP STA.
[0171] FIG. 11 is a drawing for explaining the operation of the first AP according to the present disclosure.
[0172] In step S1110, the first AP can obtain the first PMK.
[0173] In some examples, the first PMK may correspond to a PMK applied to AP-to-AP transmissions or receptions with another AP (e.g., a second AP) of the first AP. The first PMK may be distinct from a second PMK applied to transmissions / receptions with one or more non-AP STAs associated with the first AP.
[0174] In some examples, the first PMK may be shared between the first AP and the second AP. For example, the first PMK may be pre-shared between the first AP and the second AP prior to the transmission of the first message in step S1120 described below. For example, the first PMK may be obtained or generated by each of the first AP and the second AP through authentication between the first AP and the second AP. For example, the first PMK may be obtained from a specific server or generated by each of the first AP and the second AP based on information obtained from a specific server.
[0175] In some examples, authentication between a first AP and a second AP may be related to whether the first AP and the second AP belong to the same AP set. Authentication may succeed between APs that belong to the same AP set, and may fail between APs that do not belong to the same AP set. Alternatively, authentication between a first AP and a second AP may be related to whether addition of the second AP (or the first AP) is allowed to the AP set to which the first AP (or the second AP) belongs. Authentication may succeed if addition is allowed, and may fail if addition is not allowed. If authentication between the first AP and the second AP is successful, the first AP and the second AP may obtain the first PMK, and if authentication fails, the first AP and the second AP may not obtain the first PMK.
[0176] In some examples, capability information of a second AP for AP-to-AP transmission or reception may be acquired by a first AP based on a beacon from the second AP. Similarly, capability information of the first AP for AP-to-AP transmission or reception may be acquired by the second AP based on a beacon from the first AP. Acquisition of the first PMK and exchange of the first message and the second message described below may be performed between APs having the capability for AP-to-AP transmission or reception.
[0177] In step S1120, the first AP may transmit a first message including at least one of the first address or the first nonce of the first AP to the second AP.
[0178] In some examples, the first address may correspond to the MAC address of the first AP, or may correspond to an address in another format. For example, based on the first AP being affiliated with a first AP-multi-link device (MLD), the first address may include the address (e.g., MAC address) of the first AP-MLD.
[0179] In some examples, the first nonce may correspond to a random number generated by the first AP.
[0180] In some examples, the first message may further include information about the first PMK. For example, the information about the first PMK may include an identifier (e.g., PMKID) for the first PMK. The information about the first PMK may also correspond to a Key Data Element (KDE).
[0181] In some examples, the first PTK may be generated by the second AP based on information included in the first message and information held by the second AP. For example, the second AP may generate the first PTK based on one or more of the first address and first nonce received via the first message, the first PMK obtained in advance, and the second address of the second AP stored by the second AP or the second nonce generated by the second AP. For example, values based on each of one or more of the first PMK, the first address, the second address, the first nonce, or the second nonce may be applied as arguments to a function for generating the PTK (e.g., a PRF function).
[0182] In some examples, the second address may correspond to the MAC address of the second AP, or may correspond to an address in another format. For example, based on the second AP belonging to a second AP-MLD, the second address may include the address (e.g., MAC address) of the second AP-MLD.
[0183] In some examples, the second nonce may correspond to a random number generated by the second AP.
[0184] In step S1130, the first AP may receive a second message from the second AP, the second message including at least one of the second address or the second nonce of the second AP.
[0185] In step S1140, the first AP may generate the first PTK based on one or more of the first PMK, the first address, the second address, the first nonce, or the second nonce.
[0186] Here, the first PMK may correspond to information previously shared between the first AP and the second AP, the first address and the first nonce may correspond to information transmitted by the first AP to the second AP via the first message, and the second address and the second nonce may correspond to information received by the first AP from the second AP via the second message. For example, values based on each of one or more of the first PMK, the first address, the second address, the first nonce, or the second nonce may be applied as arguments of a function for generating a PTK (e.g., a PRF function).
[0187] In some examples, the first PTK may correspond to a PTK that the first AP applies for AP-to-AP transmission or reception with another AP (e.g., a second AP). The first PTK may be distinct from a second PTK that the first AP applies for transmission / reception with one or more non-AP STAs with which it is associated. Furthermore, the first PTK may correspond to a PTK that the second AP applies for AP-to-AP transmission or reception with another AP (e.g., the first AP). The first PTK may be distinct from a third PTK that the second AP applies for transmission / reception with one or more non-AP STAs with which it is associated.
[0188] In some examples, the first AP may correspond to a master AP or a sharing AP of a specific AP set, and the second AP may correspond to a slave AP or a shared AP of the specific AP set. Alternatively, the first AP may correspond to a slave AP or a shared AP of a specific AP set, and the second AP may correspond to a master AP or a sharing AP of the specific AP set. Alternatively, the first AP and the second AP may correspond to slave APs or shared APs of the specific AP set.
[0189] In some examples, the first AP and the second AP may have the same multi-AP identification or the same multi-BSS identification.
[0190] In some examples, a first PTK may be generated at each of the first AP and the second AP through a two-way handshaking procedure in which a first message and a second message are exchanged between the first AP and the second AP (as opposed to a four-way handshaking procedure between an AP STA and a non-AP STA). Based on this first PTK, confidentiality / integrity may be guaranteed / supported for data frames / PPDUs transmitted and received between the first AP and the second AP.
[0191] The method described in the example of FIG. 11 can be performed by the first device (100) of FIG. 1. For example, one or more processors (102) of the first device (100) of FIG. 1 obtain a first pairwise master key (PMK); transmit a first message including at least one of a first address or a first nonce of a first access point (AP) or the first device (100) to a second device (200) via one or more transceivers (106); receive a second message including at least one of a second address or a second nonce of a second AP or the second device (200) from the second device (200) via one or more transceivers (106); And based on one or more of the first PMK, the first address, the second address, the first nonce, or the second nonce, a first pairwise transient key (PTK) may be generated. Furthermore, one or more memories (104) of the first device (100) may store instructions for performing the method described in the example of FIG. 11 or the examples described below when executed by one or more processors (102).
[0192] For example, the first device (100) may correspond to the first AP that transmits the EAPoL-Key PDU based on the EAPoL-Key frame. The first device (100) may determine the bandwidth, RU allocation, etc. of the transmission PPDU, generate the PPDU based on the determined bandwidth, and transmit the generated PPDU. Accordingly, the first device (100) may perform a request for setting up a security environment with the second device (200), an authentication request, etc., and may negotiate security parameters. For example, the first device (100) may generate and transmit a frame for generating the same security key (e.g., the first PTK) as the second device (200), and may receive and process a response thereto.
[0193] FIG. 12 is a drawing for explaining the operation of the second AP according to the present disclosure.
[0194] In step S1210, the second AP can obtain the first PMK.
[0195] In some examples, the first PMK may correspond to a PMK applied to AP-to-AP transmissions or receptions with another AP (e.g., the second AP) of the second AP. The first PMK may be distinct from a third PMK applied to transmissions / receptions with one or more non-AP STAs associated with the second AP.
[0196] In step S1220, the second AP may receive a first message from the first AP, the first message including at least one of the first address or the first nonce of the first AP.
[0197] In step S1230, the second AP may generate a first pairwise transient key (PTK) based on one or more of the first PMK, the first address, the first nonce, the second address of the second AP, or the second nonce of the second AP.
[0198] In step S1240, the second AP may transmit a second message including at least one of a second address or a second nonce to the first AP.
[0199] In the examples of FIG. 12, the specific details of the first PMK, the first address, the first nonce, the second address, the second nonce, and the first PTK are the same as those of the example of FIG. 11, so redundant descriptions are omitted.
[0200] The method described in the example of FIG. 12 may be performed by the second device (200) of FIG. 1. For example, one or more processors (202) of the second device (200) of FIG. 1 obtain a first pairwise master key (PMK); receive a first message from the first device (100) through one or more transceivers (206), the first message including at least one of a first address or a first nonce of the first access point (AP) or the first device (100); and generate a first pairwise transient key (PTK) based on at least one of the first PMK, the first address, the second address, the first nonce, or the second nonce; The second message may be configured to be transmitted to the first device (100) via one or more transceivers (206), including at least one of a second address or a second nonce of the second AP or the second device (200). Furthermore, one or more memories (204) of the second device (200) may store instructions for performing the method described in the example of FIG. 12 or the examples described below when executed by one or more processors (202).
[0201] For example, the second device (200) may correspond to a second AP that receives an EAPoL-Key PDU based on an EAPoL-Key frame. The second device (200) may receive the PPDU, obtain information about bandwidth, RU allocation, etc., and decode the PPDU based thereon. Accordingly, the second device (200) may perform a setup response, an authentication response, etc. for a secure environment with the first device (100), and may perform a consultation on security parameters. For example, the second device (200) may receive and process a frame for generating the same security key (e.g., the first PTK) as the first device (100), and generate and transmit a response thereto.
[0202] In the examples of FIGS. 11 and 12, before the first AP and the second AP each acquire the first PMK, a probe request may be transmitted from the first AP to the second AP, which may be received by the second AP. In response, a probe response may be transmitted from the second AP to the first AP, which may be received by the first AP. This probe request / response exchange process may correspond to a request and a response for setting up a secure environment for wireless data transmission and reception between the first AP and the second AP. Each of the first AP and the second AP may check the security capabilities supported by the other party through security parameters such as RSNE (RSN element) in the other party's beacon frame that have been shared in advance (e.g., overheard). For example, a second AP can compare its own security capabilities with those of the first AP and transmit information such as one authentication method, one key management method, and one unicast data frame protection method to the first AP via a probe response frame. Through this probe request / response exchange, the first AP and the second AP can share the same mutually agreed-upon security protocol for a mutually secure data transmission and reception environment.
[0203] Based on this, the first AP and the second AP can perform authentication. If mutual authentication is successful, each of the first AP and the second AP can obtain the same PMK (e.g., the first PMK, or MAPMK described below). If mutual authentication fails, the message transmission and reception process for generating the PTK (e.g., the first PTK, or MAPTK described below) between the first AP and the second AP may not be performed. Alternatively, the first AP and the second AP may additionally perform authentication again.
[0204] A first AP and a second AP, which have successfully obtained the same PMK (e.g., the first PMK, or MAPMK described below) through authentication, may exchange a first message and a second message to generate a PTK (e.g., the first PTK, or MAPTK described below) for securing transmission and reception between them. After receiving the first message, the second AP may verify the message and generate a first PTK (or MAPTK) based on information included in the first message and information it possesses. After receiving the second message, the first AP may verify the message and generate a first PTK (or MAPTK) based on information included in the second message and information it possesses, and perform verification to determine whether the first PTK is the same. By verifying that the first AP and the second AP have generated the same first PTK, the process of setting up a security environment between the first AP and the second AP may be completed. Accordingly, confidentiality / integrity of data transmitted and received between the first AP and the second AP can be guaranteed / supported.
[0205] The examples of FIGS. 11 and 12 may correspond to some of the various examples of the present disclosure. Below, various examples of the present disclosure, including the examples of FIGS. 11 and 12, will be described in more detail.
[0206] Although the embodiments described below use the generation of a security key for data transmission and reception between APs within a multi-AP / multi-BSS as a representative example, the embodiments described below can be equally applied to other specific AP sets / groups to which security support between APs is applicable, and are not limited to multi-AP / multi-BSS. Through this, data transmission and reception for wireless schedule coordination between APs belonging to a specific AP set / group can be performed in a secure environment without the intervention of a third-party STA.
[0207] Additionally, although the examples of the present disclosure assume that one AP and other APs generating security keys in a multi-AP / multi-BSS environment are within a range / distance where they can receive (or overhear) each other's beacon frames, the examples of the present disclosure may also be applied to cases where they can confirm each other's capabilities in other ways or anticipate / assume the capabilities without actually confirming them.
[0208] In addition, although the examples described below use security key names such as PTK, TK, and GTK as representative examples, the examples described below can be equally applied to security keys of other names used for the corresponding functions / roles.
[0209] Example 1
[0210] This embodiment relates to a method for identifying a specific AP set / group. For example, the specific AP set / group in this disclosure may correspond to an AP set / group that supports data transmission and reception between APs.
[0211] The aforementioned FT (fast BSS transition) operation is only allowed for STAs and APs existing in the same MD (mobility domain) within the ESS, and whether they belong to the same MD can be identified through the MDID (mobility domain ID). For example, if APs have the same MDID, it can indicate that they belong to the same AP set / group. In this way, the existing MDID can be reused as an identifier of the AP set / group of the present disclosure. In this case, the value of the MDID indicating a specific AP set / group can be set to a value that does not overlap with the value of the existing MDID used by legacy APs / STAs.
[0212] FIG. 13 is a diagram showing examples of identifiers of AP sets / groups according to the present disclosure.
[0213] The example of Fig. 13(a) can identify the same MD within the same ESS with the same MDID. If a specific AP set / group according to the present disclosure is identified by an MDID, one MD can be identical to or correspond to one AP set / group.
[0214] As in the example of Fig. 13(b), one AP set / group may include one or more ESSs. For example, one AP set / group may be a multi-AP (MAP) set. Or, one AP set / group may be a multi-BSS. In this case, since the existing MDID is limited to one ESS, a new identifier can be defined to identify a range including multiple ESSs. The new identifier may be a MAP-ID that identifies a MAP set (or a multi-BSS ID that identifies a multi-BSS). Each of the APs belonging to the same MAP set (or multi-BSS) may have the same MAP-ID (or multi-BSS ID). Accordingly, the AP set / group to which each AP belongs can be identified.
[0215] In the example of Fig. 13(a), similarly to the example of Fig. 13(b), by replacing the MDID with a MAP-ID or multi-BSS ID, identification can also be performed by an AP set / group unit according to the present disclosure instead of an MD.
[0216] Example 2
[0217] This embodiment relates to an authentication method between APs.
[0218] The authentication procedure between APs can be defined differently from the authentication procedure between AP STAs and non-AP STAs. First, authentication methods between AP STAs and non-AP STAs include open system authentication, IEEE 802.1X, FT (Fast BSS Transition), and SAE (Simultaneous Authentication of Equals). As a method that is distinct from these, a new method for APs belonging to an AP set / group according to the present disclosure to authenticate each other is described.
[0219] For example, a first AP can overhear the beacon frame of a second AP to determine the security capabilities supported by the second AP. The second AP can also overhear the beacon frame of the first AP to determine the security capabilities supported by the first AP. This security capability verification process can be performed in advance before authentication between the first and second APs.
[0220] Next, to mutually agree on the security parameters supported by the first and second APs, frames containing information about the authentication and key management (AKM) suite can be transmitted and received. These frames may include probe request / probe response frames, but the information may also be transmitted and received through frames with other names / formats. Here, information about the cipher suite for unicast / broadcast transmitted and received data, such as AKM suite information, may be included within the RSNE.
[0221] Through this mutual agreement process, the first AP and the second AP can agree on the method of mutual authentication (or authentication type), the method of key management (or key management type), the method of key generation (or key derivation type), and / or the method of data protection (or cipher suite). As a result, the first AP and the second AP can apply / perform the same authentication method, key management method, key generation method, and data protection method.
[0222] Based on this, the authentication process can be performed.
[0223] For example, during the authentication process between the first AP and the second AP, the authentication procedure may be performed according to an open system method and / or IEEE 802.1X (e.g., Wi-Fi Protected Access (WPA)2 / 3-enterprise). When the authentication is successfully completed, the first AP and the second AP may each obtain the same MSK from the IEEE 802.1X authentication server and generate the same PMK. Furthermore, all other AP(s) belonging to the same AP set / group as the first and / or second AP may also obtain the same PMK (or obtain the same MSK and generate the same PMK) from the IEEE 802.1X authentication server.
[0224] As another example, the authentication process between the first and second APs may be performed based on the SAE. Upon successful authentication, the first and second APs can each obtain a PSK and generate an identical PMK from it.
[0225] As another example, the authentication process between AP 1 and AP 2 may be performed via FT. In this case, based on the values obtained as a result of successful authentication, AP 1 and AP 2 can each generate / set the same PMK.
[0226] As described above, through various authentication methods, the first and second APs can each ultimately acquire the same PMK. Since this PMK is for data transmission and reception between APs, it may be referred to as a MAPMK to distinguish it from the PMK for data transmission and reception between the AP and non-AP STAs. The scope of the present disclosure is not limited by the term "MAPMK" and may include a common / identical PMK shared between APs.
[0227] The authentication process between APs may also include verifying whether they belong to the same AP set / group. For example, this may be the case when the MAP group between APs is determined in advance, or when authenticating between APs in fixed locations. For example, identification information (e.g., MDID, MAP-ID, multi-BSS ID, etc.) that can prove belonging to the same AP set / group may be used for authentication between such APs. For example, if the MAP-ID is included in the beacon frame, the APs can check the value in the other AP's beacon frame, and if it is the same as their own MAP-ID, the two APs can complete the authentication process through an open system manner, or the authentication process may be omitted. In this case, the APs can perform IEEE 802.1X, FT, or SAE for generating a common PMK, or they can generate / set a common PMK based on a separate value obtained / shared in the process of belonging to a specific AP set / group (e.g., MAP set).
[0228] As another example, the authentication process between APs may include an AP belonging to a specific AP set / group authenticating another AP (i.e., checking whether it can be added to said specific AP set / group). This may be the case, for example, for authentication of a mobile AP. For example, any authentication method (e.g., IEEE 802.1X authentication method) above may be applied for such AP-to-AP authentication. Upon successful completion of the authentication, the APs may have the same AP set / group identification information (e.g., the same MAP-ID) and may generate / establish a common PMK based on the values obtained as a result of the authentication.
[0229] Example 3
[0230] This embodiment relates to a method for generating a secret key after initial association between APs.
[0231] In the present disclosure, a secret key may be generated through a handshaking process between APs belonging to the same AP set / group. This secret key corresponds to a secret key for unicast data frames transmitted / received between APs. For example, this secret key may correspond to one of the PTKs. In the present disclosure, the PTK for data transmission / reception between APs may be referred to as MAPTK to distinguish it from the PTK for data transmission / reception between the AP and non-AP STAs. The scope of the present disclosure is not limited by the term MAPTK, and may include a common / identical PTK generated based on a common / identical PMK shared between APs.
[0232] In the present disclosure, the MAPTK, a secret key generated through handshaking between APs, can be used to protect unicast data frames between the first AP and the second AP that performed the handshaking. The format of data wirelessly transmitted and received between APs may be based on a previously defined format, but is not limited thereto, and examples of the present disclosure can also be applied to new data formats. For example, the format of a message wirelessly transmitted and received to generate a secret key between the first AP and the second AP may be based on the EAPoL-key frame used in the 4-way handshaking of FIG. 9 described above, but is not limited thereto, and the message may be transmitted and received via another frame.
[0233] For example, if the first AP and the second AP successfully perform authentication based on the IEEE 802.1X or SAE method, the MAPTK can be generated by the first AP and the second AP through a two-way handshaking procedure between the APs.
[0234] Examples of the present disclosure for information included in the first message and the second message of a two-way handshaking are described below.
[0235] In the examples below, it is assumed that APs belonging to the same AP set / group have obtained / held the same PMK (e.g., MAPMK). For example, APs may obtain (or generate) the same MAPMK by performing an authentication process, or APs located within the same ESS may be preset to have the same MAPMK. The present disclosure does not limit the method by which APs obtain the same MAPMK, and assumes that APs have obtained / held the same MAPMK through any arbitrary procedure / setting. Accordingly, APs can each generate a PTK (e.g., MAPTK) based on the MAPMK through the process described below.
[0236] FIG. 14 is a diagram illustrating an example of a two-way handshaking procedure according to the present disclosure.
[0237] In step S1410, the first AP (AP1) can transmit a first message to the second AP (AP2).
[0238] For example, the first message may include a first nonce (AP1 Nonce) of the first AP. For example, the first nonce of the first AP may correspond to a random nonce value generated by the first AP.
[0239] For example, the first message may include a key replay counter. The key replay counter corresponds to a value indicating the number of (request / response) frames transmitted and received for key generation between the first AP and the second AP, and may be used to prevent replay attacks. In the example of the drawing, it is assumed that the key replay counter of the first message is set to a value of n.
[0240] For example, a first message may include a key data element (KDE). A KDE may include one or more elements. Alternatively, one or more KDEs may be included in the first message. Examples of elements that may be included in a KDE include the following.
[0241] The PMKID may correspond to the identification information of the PMK generated by the first AP, or an element containing information about the PMKID. For example, the PMKID may correspond to the identification information of a MAPMK previously acquired / held. For example, in a two-way handshaking process for generating a MAPTK between APs, the PMKID may be generated based on the following formula.
[0242] PMKID = Truncate-NNN(HMAC-SHA-XXX(PMK, "PMK Name" || AP1's MAC address || AP2's MAC address))
[0243] Here, Truncate-NNN(x) may correspond to a function that truncates x to reduce the length to NNN. The value of NNN may be applied as a different value (e.g., 128, 256, 384, ...) depending on the AKM suite applied between the first AP and the second AP.
[0244] HMAC-SHA-XXX corresponds to a function that applies a specific hash algorithm, and the value of XXX can be applied as a different value (e.g., 128, 256, 384, ...) depending on the AKM suite applied between the first AP and the second AP. "PMK Name" can correspond to a string. AP1's MAC address can correspond to the MAC address of the first AP. AP2's MAC address can correspond to the MAC address of the second AP. PMK in the formula can correspond to MAPMK.
[0245] The MLD MAC address KDE may correspond to a KDE including the MAC address of the AP MLD to which the first AP belongs, when the first AP is an AP MLD (or when the first AP belongs to an AP MLD). In this case, the MAC address in the examples described above may correspond to the MAC address of the AP MLD. For example, the PMKID calculation formula described above, PMKID = Truncate-NNN(HMAC-SHA-XXX(PMK, "PMK Name" || AP-MLD1's MAC address || AP-MLD2's MAC address)), may be applied. Here, AP-MLD1 may correspond to the AP MLD to which the first AP belongs, and AP-MLD2 may correspond to the AP MLD to which the second AP belongs.
[0246] The second AP, which has received the first message including such information, can verify the first message by comparing the value of the key replay counter (KRC) included in the first message with the KRC value held by the second AP in step S1420. For example, if the value of the KRC transmitted by the first AP is less than or equal to the value of the KRC held by the second AP, the first message can be discarded as it is determined to be invalid.
[0247] If the first message is valid, in step S1430, the second AP may generate a MAPTK based on the first nonce of the first AP included in the first message (e.g., AP1 Nonce), information of the first AP (e.g., MAC address of the first AP), a second nonce which is a random nonce value generated by the second AP (e.g., AP2 Nonce), and / or information of the second AP (e.g., MAC address of the second AP).
[0248] In step S1440, the second AP (AP2) can transmit a second message to the first AP (AP1).
[0249] For example, the second message may include a second nonce (AP2 Nonce) of the second AP. For example, the second nonce of the second AP may correspond to a random nonce value generated by the second AP. Additionally, the second nonce included in the second message may be set to the same value as the second nonce value used by the second AP when generating the MAPTK in step S1430.
[0250] For example, the second message may include a key replay counter. The key replay counter corresponds to a value indicating the number of (request / response) frames transmitted and received for key generation between the first AP and the second AP, and may be used to prevent replay attacks. In the example of the drawing, it is assumed that the value of the key replay counter of the second message is set to the same value n as the value of the key replay counter of the first message.
[0251] For example, the second message may include a message integrity code (MIC). The MIC may be set to the KCK (e.g., MAKCK) value of the MAPTK generated by the second AP in step S1430. This MIC may be used to verify the identity between the MAPTK generated by the second AP in step S1430 and the MAPTK generated by the first AP in step S1460.
[0252] For example, the second message may include a key data element (KDE). A KDE may include one or more elements. Alternatively, one or more KDEs may be included in the second message. Examples of elements that may be included in a KDE include the following.
[0253] For example, the RSNE of the second AP may be included in the KDE of the second message.
[0254] For example, the RSNXE (RSN extended element) of the second AP may be included in the KDE of the second message.
[0255] For example, a multi-band element of a second AP may be included in the KDE of a second message.
[0256] For example, the MLD MAC address of the second AP may be included in the KDE. This may correspond to a KDE that includes the MAC address of the AP MLD to which the second AP belongs, if the second AP is an AP MLD.
[0257] The first AP, which receives the second message including such information, can verify the second message by comparing the value of the key replay counter (KRC) included in the second message with the KRC value held by the first AP in step S1450. For example, whether the second message is valid can be determined based on whether the KRC value included in the second message is identical to the KRC value n included in the first message by the first AP. If the KRC value of the second message is set to the value n such that the value n is identical to the KRC value n included in the first message, the second message can be determined to be valid. If it is invalid, the first AP can discard the second message.
[0258] If the second message is valid, in step S1460, the first AP may generate a MAPTK based on the first nonce of the first AP (e.g., AP1 Nonce) held by the first AP (or included in the first message), information of the first AP (e.g., MAC address of the first AP), a second nonce included in the second message (e.g., AP2 Nonce), and / or information of the second AP (e.g., MAC address of the second AP).
[0259] In step S1470, the first AP can derive a KCK (e.g., MAKCK) from the MAPTK it generated, and verify the MAPTK it generated by comparing the derived MAKCK value with the key MIC value included in the second message to see if they are the same. If the derived MAKCK value is the same as the key MIC value included in the second message, the generated MAPTK can be verified as valid. If an invalid MAPTK is generated, the second message can be discarded. The generated MAPTK can also be discarded.
[0260] Some or all of the information examples included in the first message in the examples described above may be included in the first message, or one or more pieces of information not included in the examples may be further included in the first message. Similarly, some or all of the information examples included in the second message in the examples described above may be included in the second message, or one or more pieces of information not included in the examples may be further included in the second message.
[0261] Example 4
[0262] This embodiment is about a MAPTK generation / derivation method.
[0263] When APs within a specific AP set / group perform two-way handshaking to generate a MAPTK for data transmission and reception between APs according to the examples of the present disclosure, the MAPTK may be generated based on the following formula.
[0264] MAPTK = PRF-Length(PMK, "Pairwise key expansion", Min(AP1's Address, AP2's Address) || MAX(AP1's Address, AP2's Address) || Min(AP1's Nonce, AP2's Nonce) || Max(AP1's Nonce, AP2's Nonce))
[0265] Here, the PRF-Length(x) function corresponds to a function that outputs pseudorandom bits of a length corresponding to the value of Length (e.g., 128, 192, 256, 384, 512, 704, etc.).
[0266] The string value "Pairwise key expansion" is only an example and can be replaced with any other string value.
[0267] AP1 corresponds to the first AP in the above examples or the AP that transmits the first message and receives the second message in two-way handshaking, and may be replaced with another name that signifies this (e.g., requesting AP, etc.).
[0268] AP1 corresponds to the second AP or the AP that receives the first message and transmits the second message in the two-way handshaking in the examples described above, and may be replaced with another name that signifies this (e.g., responding AP, etc.).
[0269] PMK in the formula may correspond to MAPMK.
[0270] If AP1 belongs to AP-MLD1, the AP'1 address in the formula can be replaced with AP-MLD1's address (e.g., the MAC address of AP-MLD1). Additionally or alternatively, if AP2 belongs to AP-MLD2, the AP'2 address in the formula can be replaced with AP-MLD2's address (e.g., the MAC address of AP-MLD2).
[0271] When MAPTK is generated in the above manner, three keys, KCK, KEK, and TK, can be derived based on MAPTK. To distinguish it from KCK, KEK, and TK derived from PTK for transmission and reception between existing APs and non-AP STAs, it can also be expressed that MAKCK, MAKEK, and MATK are derived from MAPTK for transmission and reception between APs. The method itself of deriving KCK, KEK, and TK from PTK can be identically applied to the method of deriving MAKCK, MAKEK, and MATK from MAPTK.
[0272] The scope of the present disclosure is not limited to specific names for keys, and the keys may be expressed by other names with the same meaning. For example, in the examples described above, MAPMK, MAPTK, MAKCK, MAKEK, and MATK, which are generated / applied as security keys for data transmission and reception between APs, may be expressed by other names such as PMK_MA, PTK_MA, KCK_MA, KEK_MA, and TK_MA, respectively, and the examples of the present disclosure may be equally applied.
[0273] While existing wireless LAN systems support security between APs and STAs, they do not provide a method for supporting security between APs. According to the present disclosure, a security key-based operation can be provided that supports confidentiality / integrity for data transmission / reception between APs within a specific AP set / group.
[0274] The embodiments described above are combinations of components and features of the present disclosure in a predetermined form. Each component or feature should be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, it is also possible to form embodiments of the present disclosure by combining some components and / or features. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment. It is self-evident that claims that do not have an explicit citation relationship in the patent claims may be combined to form embodiments or incorporated as new claims through post-application amendments.
[0275] It will be apparent to those skilled in the art that the present disclosure may be embodied in other specific forms without departing from the essential characteristics of the present disclosure. Therefore, the above detailed description should not be construed as limiting in any respect, but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the scope of equivalents of the present disclosure are intended to be included within the scope of the present disclosure.
[0276] The scope of the present disclosure includes software or machine-executable instructions (e.g., an operating system, an application, firmware, a program, etc.) that cause operations according to the methods of various embodiments to be executed on a device or a computer, and a non-transitory computer-readable medium having such software or instructions stored thereon and executable on the device or computer. Instructions that can be used to program a processing system to perform the features described in the present disclosure can be stored on / in a storage medium or a computer-readable storage medium, and a computer program product including such a storage medium can be used to implement the features described in the present disclosure. The storage medium can include, but is not limited to, high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid state memory devices, and can include non-volatile memory, such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid state storage devices. The memory optionally includes one or more storage devices remotely located from the processor(s). The memory or, alternatively, the non-volatile memory device(s) within the memory comprise a non-transitory computer-readable storage medium. The features described in this disclosure may be incorporated into software and / or firmware stored on any of the machine-readable media, which may control the hardware of the processing system and allow the processing system to interact with other mechanisms that utilize results according to embodiments of the present disclosure. Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments / containers.
[0277] The method proposed in this disclosure has been described with a focus on examples applied to IEEE 802.11-based systems, but can be applied to various wireless LANs or wireless communication systems in addition to IEEE 802.11-based systems.
Claims
1. A step of obtaining a first PMK (pairwise master key) by a first access point (AP); A step of transmitting a first message including at least one of a first address or a first nonce of the first AP to a second AP by the first AP; A step of receiving a second message from the second AP, the second message including at least one of a second address or a second nonce of the second AP; and A method comprising the step of generating a first pairwise transient key (PTK) by the first AP based on at least one of the first PMK, the first address, the second address, the first nonce, or the second nonce.
2. In paragraph 1, A method wherein the first PMK is shared between the first AP and the second AP.
3. In paragraph 1, A method wherein the first PMK is obtained or generated in each of the first AP and the second AP through authentication between the first AP and the second AP or based on information obtained from a specific server.
4. In paragraph 3, The above authentication is related to whether the first AP and the second AP belong to the same AP set, or A method wherein the above authentication is related to whether the addition of the second AP is allowed to the AP set to which the first AP belongs.
5. In paragraph 1, A method in which the first PTK is generated at the second AP based on information included in the first message.
6. In paragraph 5, A method wherein the first message includes information about the first PMK.
7. In paragraph 1, A method wherein the first AP stores a second PMK and a second PTK that are distinct from the first PMK and the first PTK.
8. In paragraph 7, A method wherein the second PMK and the second PTK are applied to transmission or reception between the first AP and one or more STAs associated with the first AP, respectively.
9. In paragraph 1, A method wherein the second AP stores a third PMK and a third PTK that are distinct from the first PMK and the first PTK.
10. In paragraph 9, A method wherein the third PMK and the third PTK are applied to transmission or reception between the second AP and one or more STAs associated with the second AP, respectively.
11. In paragraph 1, Based on the first AP being affiliated to the first AP-multi-link device (MLD), the first address includes the address of the first AP-MLD, A method wherein the second address includes an address of the second AP-MLD, based on the second AP belonging to the second AP-MLD.
12. In paragraph 1, Capability information of the second AP for AP-to-AP transmission or reception is obtained by the first AP based on a beacon from the second AP, A method in which capability information of the first AP for the AP-to-AP transmission or reception is acquired by the second AP based on a beacon from the first AP.
13. In paragraph 1, The above first AP corresponds to a master AP or a sharing AP of a specific AP set, A method wherein the second AP corresponds to a slave AP or a shared AP of the specific AP set.
14. In paragraph 1, The above first AP corresponds to a slave AP or shared AP of a specific AP set, A method wherein the second AP corresponds to a master AP or a sharing AP of the specific AP set.
15. In paragraph 1, A method wherein the first AP and the second AP correspond to slave APs or shared APs of a specific AP set.
16. In paragraph 1, A method wherein the first AP and the second AP have the same multi-AP identification information or the same multi-BSS identification information.
17. In paragraph 1, A method wherein the first PTK is generated in each of the first AP and the second AP through a two-way handshaking procedure in which the first message and the second message are exchanged between the first AP and the second AP.
18. One or more transmitters and receivers; and comprising one or more processors connected to said one or more transceivers, One or more of the above processors: Obtain the first PMK (pairwise master key); Transmitting a first message including at least one of a first address or a first nonce of a first access point (AP) to a second AP via the at least one transceiver; Receiving a second message including at least one of a second address or a second nonce of the second AP from the second AP through the at least one transceiver; and A first AP device configured to generate a first pairwise transient key (PTK) based on at least one of the first PMK, the first address, the second address, the first nonce, or the second nonce.
19. A step of obtaining a first PMK (pairwise master key) by a second access point (AP); A step of receiving, by the second AP, a first message from the first AP, the first message including at least one of a first address of the first AP or a first nonce; A step of generating a first pairwise transient key (PTK) by the second AP based on at least one of the first PMK, the first address, the first nonce, the second address of the second AP, or the second nonce of the second AP; and A method comprising the step of transmitting a second message, comprising at least one of the second address or the second nonce, to the first AP by the second AP.
20. One or more transmitters and receivers; and comprising one or more processors connected to said one or more transceivers, One or more of the above processors: Step of obtaining the first PMK (pairwise master key); Receiving a first message including at least one of a first address or a first nonce of a first access point (AP) from the first AP via the at least one transceiver; Generating a first pairwise transient key (PTK) based on at least one of the first PMK, the first address, the first nonce, the second address of the second AP, or the second nonce of the second AP; A second AP device configured to transmit a second message including at least one of the second address or the second nonce to the first AP via the at least one transceiver.
21. One or more processors; and A processing device comprising one or more computer memories operatively connected to said one or more processors and storing instructions for performing a method according to any one of claims 1 to 17 based on execution by said one or more processors.
22. One or more non-transitory computer-readable media storing one or more instructions that are executed by one or more processors to control the performance of a method according to any one of claims 1 to 17.
Citation Information
Patent Citations
System and method to provide fast mobility in a residential wi-fi network environment
US20170353983A1
Methods and systems for authentic interoperability
US20180084416A1
Exchanging message authentication codes for additional security in a communication system
WO2018175930A1
Roaming method and system
WO2023093277A1