Method and apparatus for transmitting or receiving protected control frame in wireless LAN system

WO2025188140A8PCT designated stage Publication Date: 2025-10-02LG ELECTRONICS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2025/099536
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-21
Filing Date
2025-03-04
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing wireless LAN systems lack effective methods for generating and verifying security keys to protect control frames and MAC headers, which are crucial for ensuring secure communication in advanced wireless environments.

Method used

A method and device for generating and verifying security keys for control frames and MAC headers in wireless LAN systems, using a security protocol based on a security key or a random value generated by a first station, and applying it to transmit and receive protected control frames.

Benefits of technology

Enhances the security of control frames and MAC headers in wireless LAN systems, providing secure communication and protection against unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2025099536_02102025_PF_FP_ABST
    Figure KR2025099536_02102025_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a method and apparatus for transmitting or receiving a protected control frame in a wireless LAN system. The method according to an embodiment of the present disclosure may comprise the steps of: generating, by a first station (STA), a control frame on the basis of a security protocol; and transmitting, by the first STA, the control frame to a second STA. Here, the security protocol may be applied to the control frame on the basis of a security key for the control frame, and the security key for the control frame may be configured on the basis of at least one of a security key for another type of frame or a random value generated by the first STA.
Need to check novelty before this filing date? Find Prior Art

Description

Method and device for transmitting or receiving protected control frames in a wireless LAN system

[0001] The present disclosure relates to a method and device for transmitting or receiving a protected control frame in a wireless local area network (WLAN) system.

[0002] New technologies have been introduced for wireless local area networks (WLANs) to improve transmission rates, increase bandwidth, enhance reliability, reduce errors, and reduce latency. Among WLAN technologies, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 series of standards can be referred to as Wi-Fi. For example, recently introduced technologies for WLANs include enhancements for Very High Throughput (VHT) in the 802.11ac standard and enhancements for High Efficiency (HE) in the IEEE 802.11ax standard.

[0003] To provide a more advanced wireless communication environment, improved technologies for Extremely High Throughput (EHT) are being discussed. For example, technologies for Multiple Input Multiple Output (MIMO), which supports increased bandwidth, efficient utilization of multiple bands, and increased spatial streams, and for coordination of multiple access points (APs), are being studied. In particular, various technologies are being studied to support low latency or real-time traffic. Furthermore, new technologies are being discussed to support ultra-high reliability (UHR), including improvements or extensions of EHT technology.

[0004] The technical problem of the present disclosure is to provide a method and device for transmitting or receiving a protected control frame in a wireless LAN system.

[0005] The technical problem of the present disclosure is to provide a method and device for generating a security key for protecting a control frame and / or a MAC (medium access control) header in a wireless LAN system.

[0006] The technical problems to be achieved in the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by a person having ordinary skill in the technical field to which the present disclosure belongs from the description below.

[0007] A method according to one aspect of the present disclosure may include: generating a control frame based on a security protocol by a first station (STA); and transmitting the control frame to a second STA by the first STA. Here, the security protocol may be applied to the control frame based on a security key for the control frame, and the security key for the control frame may be configured based on at least one of a security key for another type of frame or a random value generated by the first STA.

[0008] A method according to an additional aspect of the present disclosure may include the steps of: receiving, by a second station (STA), a control frame based on a security protocol from a first STA; and performing verification and decoding on the control frame, by the second STA. Here, the control frame may be verified and decoded based on a security key for the control frame, and the security key for the control frame may be configured based on at least one of a security key for another type of frame or a random value generated by the first STA.

[0009] According to the present disclosure, a method and device for transmitting or receiving a protected control frame in a wireless LAN system can be provided.

[0010] According to the present disclosure, a method and device for generating a security key for protecting a control frame and / or a medium access control (MAC) header in a wireless LAN system can be provided.

[0011] The effects that can be obtained from the present disclosure are not limited to the effects mentioned above, and other effects that are not mentioned will be clearly understood by a person having ordinary skill in the art to which the present disclosure pertains from the description below.

[0012] The accompanying drawings, which are incorporated in and are part of the detailed description to aid in understanding the present disclosure, provide embodiments of the present disclosure and, together with the detailed description, describe the technical features of the present disclosure.

[0013] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.

[0014] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.

[0015] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.

[0016] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.

[0017] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.

[0018] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.

[0019] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.

[0020] FIG. 8 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.

[0021] FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure may be applied.

[0022] Figure 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.

[0023] Figure 11 shows an example of the format of conventional AAD.

[0024] Figure 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.

[0025] FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.

[0026] Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.

[0027] Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.

[0028] FIG. 16 is a diagram for explaining the operation of the first STA according to the present disclosure.

[0029] FIG. 17 is a diagram for explaining the operation of a second STA according to the present disclosure.

[0030] FIG. 18 illustrates CGTK KDE formats according to an embodiment of the present disclosure.

[0031] FIG. 19 illustrates CPTK KDE formats according to an embodiment of the present disclosure.

[0032] FIG. 20 is a diagram illustrating an example of a transmitting STA operation according to an embodiment of the present disclosure.

[0033] FIG. 21 is a diagram illustrating an example of a receiving STA operation according to an embodiment of the present disclosure.

[0034] FIG. 22 is a diagram for explaining another example of a transmitting STA operation according to an embodiment of the present disclosure.

[0035] FIG. 23 is a diagram for explaining another example of a receiving STA operation according to an embodiment of the present disclosure.

[0036] Figure 24 illustrates an overall operation flowchart of PPDU transmission and reception according to an embodiment of the present disclosure.

[0037] Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. The detailed description set forth below, together with the accompanying drawings, is intended to explain exemplary embodiments of the present disclosure and is not intended to represent the only embodiments in which the present disclosure may be practiced. The following detailed description includes specific details to provide a thorough understanding of the present disclosure. However, one of ordinary skill in the art will appreciate that the present disclosure may be practiced without these specific details.

[0038] In some cases, to avoid obscuring the concepts of the present disclosure, known structures and devices may be omitted or illustrated in block diagram form focusing on the core functions of each structure and device.

[0039] In the present disclosure, when a component is said to be "connected," "coupled," or "connected" to another component, this may include not only a direct connection but also an indirect connection in which another component exists between them. Furthermore, the terms "comprises" or "has" in the present disclosure specify the presence of the mentioned features, steps, operations, elements, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, elements, components, and / or groups thereof.

[0040] In this disclosure, terms such as “first,” “second,” etc. are used only to distinguish one component from another and are not used to limit the components, and do not limit the order or importance between the components unless specifically stated otherwise. Accordingly, within the scope of this disclosure, a first component in one embodiment may be referred to as a second component in another embodiment, and similarly, a second component in one embodiment may be referred to as a first component in another embodiment.

[0041] The terminology used herein is for the purpose of describing particular embodiments and is not intended to limit the scope of the claims. As used in the description of the embodiments and the appended claims, the singular forms "a," "an," and "the" are intended to include the plural forms as well, unless the context clearly dictates otherwise. The term "and / or" as used herein may refer to any one of the associated enumerated items, or is meant to refer to and encompass any and all possible combinations of two or more of them. Furthermore, the use of " / " between words in this disclosure has the same meaning as "and / or" unless otherwise stated.

[0042] The examples of the present disclosure can be applied to various wireless communication systems. For example, the examples of the present disclosure can be applied to a wireless LAN system. For example, the examples of the present disclosure can be applied to a wireless LAN based on the IEEE 802.11a / g / n / ac / ax / be standards. Furthermore, the examples of the present disclosure can be applied to a wireless LAN based on the newly proposed IEEE 802.11bn (or UHR) standard. Additionally, the examples of the present disclosure can be applied to a wireless LAN based on the next-generation standard after IEEE 802.11bn. Furthermore, the examples of the present disclosure can be applied to a cellular wireless communication system. For example, the examples of the present disclosure can be applied to a cellular wireless communication system based on the LTE (Long Term Evolution) series of technologies and the 5G NR (New Radio) series of technologies of the 3rd Generation Partnership Project (3GPP) standard.

[0043] Below, technical features to which examples of the present disclosure can be applied are described.

[0044] FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.

[0045] The first device (100) and the second device (200) illustrated in FIG. 1 may be replaced with various terms such as a terminal, a wireless device, a WTRU (Wireless Transmit Receive Unit), a UE (User Equipment), an MS (Mobile Station), a UT (user terminal), an MSS (Mobile Subscriber Station), an MSS (Mobile Subscriber Unit), an SS (Subscriber Station), an AMS (Advanced Mobile Station), a WT (Wireless terminal), or simply a user. In addition, the first device (100) and the second device (200) may be replaced with various terms such as an access point (AP), a BS (Base Station), a fixed station, a Node B, a BTS (Base Transceiver System), a network, an AI (Artificial Intelligence) system, an RSU (road side unit), a repeater, a router, a relay, a gateway, etc.

[0046] The devices (100, 200) illustrated in FIG. 1 may also be referred to as stations (STAs). For example, the devices (100, 200) illustrated in FIG. 1 may be referred to by various terms such as transmitting device, receiving device, transmitting STA, and receiving STA. For example, the STAs (110, 200) may perform an AP (access point) role or a non-AP role. That is, in the present disclosure, the STAs (110, 200) may perform the functions of an AP and / or a non-AP. When the STAs (110, 200) perform an AP function, they may simply be referred to as APs, and when the STAs (110, 200) perform a non-AP function, they may simply be referred to as STAs. In addition, in the present disclosure, the APs may also be referred to as AP STAs.

[0047] Referring to FIG. 1, the first device (100) and the second device (200) can transmit and receive wireless signals through various wireless LAN technologies (e.g., IEEE 802.11 series). The first device (100) and the second device (200) can include interfaces for a medium access control (MAC) layer and a physical layer (PHY) that follow the provisions of the IEEE 802.11 standard.

[0048] In addition, the first device (100) and the second device (200) may additionally support various communication standards (e.g., 3GPP LTE series, 5G NR series standards, etc.) other than wireless LAN technology. In addition, the device of the present disclosure may be implemented as various devices such as a mobile phone, a vehicle, a personal computer, an AR (Augmented Reality) device, a VR (Virtual Reality) device, etc. In addition, the STA of the present specification may support various communication services such as voice calls, video calls, data communications, autonomous driving, MTC (Machine-Type Communication), M2M (Machine-to-Machine), D2D (Device-to-Device), and IoT (Internet-of-Things).

[0049] A first device (100) includes one or more processors (102) and one or more memories (104), and may further include one or more transceivers (106) and / or one or more antennas (108). The processor (102) controls the memories (104) and / or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (102) may process information in the memories (104) to generate first information / signals, and then transmit a wireless signal including the first information / signals via the transceivers (106). Furthermore, the processor (102) may receive a wireless signal including second information / signals via the transceivers (106), and then store information obtained from signal processing of the second information / signals in the memory (104). The memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (102) and the memory (104) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (106) may be connected to the processor (102) and may transmit and / or receive wireless signals via one or more antennas (108). The transceiver (106) may include a transmitter and / or a receiver. The transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.

[0050] The second device (200) includes one or more processors (202), one or more memories (204), and may further include one or more transceivers (206) and / or one or more antennas (208). The processor (202) controls the memories (204) and / or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. For example, the processor (202) may process information in the memory (204) to generate third information / signals, and then transmit a wireless signal including the third information / signals via the transceivers (206). Furthermore, the processor (202) may receive a wireless signal including fourth information / signals via the transceivers (206), and then store information obtained from signal processing of the fourth information / signals in the memory (204). The memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software code including instructions for performing the descriptions, functions, procedures, proposals, methods, and / or operation flowcharts disclosed in the present disclosure. Here, the processor (202) and the memory (204) may be part of a communication modem / circuit / chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series). The transceiver (206) may be connected to the processor (202) and may transmit and / or receive wireless signals via one or more antennas (208). The transceiver (206) may include a transmitter and / or a receiver. The transceiver (206) may be used interchangeably with an RF unit. In the present disclosure, a device may also mean a communication modem / circuit / chip.

[0051] Hereinafter, the hardware elements of the device (100, 200) will be described in more detail. Although not limited thereto, one or more protocol layers may be implemented by one or more processors (102, 202). For example, one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC). One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and / or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in the present disclosure. One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, proposals and / or methods disclosed in the present disclosure, and provide the signals to one or more transceivers (106, 206). One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, proposals, methods and / or operational flowcharts disclosed in the present disclosure.

[0052] One or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer. One or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof. For example, one or more Application Specific Integrated Circuits (ASICs), one or more Digital Signal Processors (DSPs), one or more Digital Signal Processing Devices (DSPDs), one or more Programmable Logic Devices (PLDs), or one or more Field Programmable Gate Arrays (FPGAs) may be included in one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this disclosure may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc. The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software configured to perform one or more processors (102, 202) or stored in one or more memories (104, 204) and driven by one or more processors (102, 202). The descriptions, functions, procedures, proposals, methods and / or operation flowcharts disclosed in this disclosure may be implemented using firmware or software in the form of codes, instructions and / or sets of instructions.

[0053] One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and / or commands. The one or more memories (104, 204) may be configured as ROM, RAM, EPROM, flash memory, hard drives, registers, cache memory, computer-readable storage media, and / or combinations thereof. The one or more memories (104, 204) may be located internally and / or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.

[0054] One or more transceivers (106, 206) can transmit user data, control information, wireless signals / channels, etc., as mentioned in the methods and / or flowcharts of the present disclosure, to one or more other devices. One or more transceivers (106, 206) can receive user data, control information, wireless signals / channels, etc., as mentioned in the descriptions, functions, procedures, proposals, methods and / or flowcharts of the present disclosure, from one or more other devices. For example, one or more transceivers (106, 206) can be connected to one or more processors (102, 202) and can transmit and receive wireless signals. For example, one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals / channels, or the like, as referred to in the descriptions, functions, procedures, proposals, methods, and / or operational flowcharts disclosed in this disclosure, via one or more antennas (108, 208). In the present disclosure, one or more antennas may be multiple physical antennas or multiple logical antennas (e.g., antenna ports). One or more transceivers (106, 206) can convert received user data, control information, wireless signals / channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals / channels, etc. using one or more processors (102, 202).One or more transceivers (106, 206) may convert user data, control information, wireless signals / channels, etc. processed by one or more processors (102, 202) from baseband signals to RF band signals. For this purpose, one or more transceivers (106, 206) may include an (analog) oscillator and / or filter.

[0055] For example, one of the STAs (100, 200) may perform the intended operation of an AP, and the other of the STAs (100, 200) may perform the intended operation of a non-AP STA. For example, the transceivers (106, 206) of FIG. 1 may perform transmission and reception operations of signals (e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a / b / g / n / ac / ax / be / bn, etc.). In addition, in the present disclosure, operations in which various STAs generate transmission and reception signals or perform data processing or calculations in advance for transmission and reception signals may be performed in the processors (102, 202) of FIG. 1. For example, an example of an operation for generating a transmission / reception signal or performing data processing or operation in advance for a transmission / reception signal may include 1) an operation for determining / obtaining / configuring / computing / decoding / encoding bit information of a field (SIG (signal), STF (short training field), LTF (long training field), Data, etc.) included in a PPDU, 2) an operation for determining / configuring / obtaining time resources or frequency resources (e.g., subcarrier resources) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 3) an operation for determining / configuring / obtaining a specific sequence (e.g., a pilot sequence, an STF / LTF sequence, an extra sequence applied to SIG) used for a field (SIG, STF, LTF, Data, etc.) included in a PPDU, 4) a power control operation and / or a power saving operation applied to an STA, 5) an operation related to determining / obtaining / configuring / computing / decoding / encoding an ACK signal, etc. Additionally, in the examples below, various information (e.g., information related to fields / subfields / control fields / parameters / power, etc.) used by various STAs for determining / acquiring / configuring / computing / decoding / encoding transmission / reception signals can be stored in the memory (104, 204) of FIG. 1.

[0056] Hereinafter, downlink (DL) refers to a link for communication from an AP STA to a non-AP STA, and downlink PPDUs / packets / signals, etc. can be transmitted and received through the downlink. In downlink communication, the transmitter may be part of an AP STA, and the receiver may be part of a non-AP STA. Uplink (UL) refers to a link for communication from a non-AP STA to an AP STA, and uplink PPDUs / packets / signals, etc. can be transmitted and received through the uplink. In uplink communication, the transmitter may be part of a non-AP STA, and the receiver may be part of an AP STA.

[0057] FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.

[0058] The structure of a wireless LAN system can be composed of multiple components. Through the interaction of multiple components, a wireless LAN that supports transparent STA mobility to the upper layer can be provided. A Basic Service Set (BSS) corresponds to a basic building block of a wireless LAN. FIG. 2 illustrates, by way of example, the existence of two BSSs (BSS1 and BSS2) and the inclusion of two STAs as members of each BSS (STA1 and STA2 are included in BSS1, and STA3 and STA4 are included in BSS2). The oval representing a BSS in FIG. 2 can also be understood as representing a coverage area in which STAs included in the corresponding BSS maintain communication. This area can be referred to as a Basic Service Area (BSA). When an STA moves outside of a BSA, it cannot directly communicate with other STAs within the BSA.

[0059] If we do not consider the DS illustrated in Figure 2, the most basic type of BSS in a wireless LAN is an Independent BSS (IBSS). For example, an IBSS can have a minimal form consisting of only two STAs. For example, assuming other components are omitted, BSS1 consisting of only STA1 and STA2, or BSS2 consisting of only STA3 and STA4, can be representative examples of an IBSS, respectively. Such a configuration is possible when the STAs can communicate directly without an AP. Furthermore, in this type of WLAN, a LAN can be configured when needed rather than being planned in advance, and this can be called an ad-hoc network. Since an IBSS does not include an AP, there is no centralized management entity. That is, in an IBSS, STAs are managed in a distributed manner. In IBSS, all STAs can be mobile STAs, and access to distributed systems (DS) is not permitted, forming a self-contained network.

[0060] An STA's membership in a BSS can dynamically change, for example, when an STA is turned on or off, or when an STA enters or leaves a BSS area. To become a member of a BSS, an STA can join the BSS using a synchronization process. To access all services in the BSS infrastructure, an STA must be associated with the BSS. This association can be dynamically established and may involve the use of a Distribution System Service (DSS).

[0061] In a wireless LAN, the direct STA-to-STA distance can be limited by PHY performance. While this distance limit may be sufficient in some cases, communication between STAs over longer distances may be required in other cases. To support extended coverage, a distributed system (DS) can be configured.

[0062] DS refers to a structure in which BSSs are interconnected. Specifically, a BSS may exist as an extended component of a network composed of multiple BSSs, as illustrated in Figure 2. DS is a logical concept and can be specified by the characteristics of a distributed system medium (DSM). In this regard, the Wireless Medium (WM) and DSM can be logically distinguished. Each logical medium is used for a different purpose and by different components. These media are neither limited to being identical nor limited to being different. This logical difference between multiple media explains the flexibility of the WLAN architecture (DS architecture or other network architectures). In other words, the WLAN architecture can be implemented in various ways, and the physical characteristics of each implementation can independently specify the WLAN architecture.

[0063] A DS can support mobile devices by providing seamless integration of multiple BSSs and the logical services necessary to handle addresses to destinations. Additionally, a DS may further include a component called a portal, which acts as a bridge for connecting wireless LANs to other networks (e.g., IEEE 802.X).

[0064] An AP is an entity that enables access to a DS through a WM for associated non-AP STAs and also has the functionality of an STA. Data movement between a BSS and a DS can be performed through an AP. For example, STA2 and STA3 illustrated in FIG. 2 have the functionality of an STA and provide the function of allowing associated non-AP STAs (STA1 and STA4) to access the DS. In addition, since all APs are basically STAs, all APs are addressable entities. The address used by an AP for communication on a WM and the address used by an AP for communication on a DSM do not necessarily have to be the same. A BSS consisting of an AP and one or more STAs can be referred to as an infrastructure BSS.

[0065] Data transmitted from one of the STA(s) associated with an AP to the STA address of that AP may always be received on an uncontrolled port and processed by an IEEE 802.1X port access entity. In addition, if the controlled port is authenticated, the transmitted data (or frame) may be forwarded to the DS.

[0066] In addition to the structure of the DS described above, an extended service set (ESS) may be established to provide wider coverage.

[0067] An ESS is a network of arbitrary size and complexity, consisting of DSs and BSSs. An ESS may correspond to a set of BSSs connected to a DS. However, an ESS does not include a DS. An ESS network is characterized by appearing as an IBSS at the Logical Link Control (LLC) layer. STAs within an ESS can communicate with each other, and mobile STAs can move from one BSS to another (within the same ESS) transparently to the LLC. APs within an ESS may have the same SSID (service set identification). The SSID is distinct from the BSSID, which is the identifier of the BSS.

[0068] In a wireless LAN system, no assumptions are made about the relative physical locations of BSSs, and all of the following configurations are possible: BSSs can be partially overlapping, which is commonly used to provide continuous coverage. BSSs can also be physically disconnected, and there is no logical distance limit between them. BSSs can also be physically co-located, which can be used to provide redundancy. Furthermore, one (or more) IBSS or ESS networks can physically co-exist with one (or more) ESS networks. This can occur in cases where an ad-hoc network operates at the same location as an ESS network, where physically overlapping wireless networks are configured by different organizations, or where two or more different access and security policies are required at the same location.

[0069] FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.

[0070] For an STA to set up a link to a network and transmit and receive data, it must first discover the network, perform authentication, establish an association, and go through security authentication procedures. The link setup process can also be referred to as the session initiation process or session setup process. Furthermore, the discovery, authentication, association, and security setup processes of the link setup process can be collectively referred to as the association process.

[0071] In step S310, the STA may perform a network discovery operation. This network discovery operation may include scanning operations by the STA. That is, for the STA to access a network, it must search for available networks. Before joining a wireless network, the STA must identify compatible networks. The process of identifying networks in a specific area is called scanning.

[0072] Scanning methods include active scanning and passive scanning. Figure 3 illustrates a network discovery operation including an active scanning process as an example. In active scanning, an STA performing scanning transmits a probe request frame to discover any APs in the vicinity while moving between channels and waits for a response. The responder transmits a probe response frame in response to the STA that transmitted the probe request frame. Here, the responder may be the STA that last transmitted a beacon frame in the BSS of the channel being scanned. In the BSS, the AP transmits the beacon frame, so the AP becomes the responder. In the IBSS, the STAs within the IBSS take turns transmitting beacon frames, so the responder is not fixed. For example, an STA that transmits a probe request frame on channel 1 and receives a probe response frame on channel 1 can store BSS-related information included in the received probe response frame and move to the next channel (e.g., channel 2) to perform scanning (i.e., transmitting and receiving probe requests / responses on channel 2) in the same manner.

[0073] Although not shown in Figure 3, the scanning operation can also be performed in a passive scanning manner. In passive scanning, the STA performing the scanning moves between channels and waits for a beacon frame. A beacon frame is one of the management frames defined in IEEE 802.11. It announces the existence of a wireless network and is periodically transmitted so that the STA performing the scanning can find the wireless network and participate in the wireless network. In the BSS, the AP performs the role of periodically transmitting the beacon frame, and in the IBSS, the STAs within the IBSS take turns transmitting the beacon frame. When the STA performing the scanning receives a beacon frame, it stores the information about the BSS included in the beacon frame and moves to another channel, recording the beacon frame information on each channel. The STA receiving the beacon frame stores the BSS-related information included in the received beacon frame and moves to the next channel to perform scanning on the next channel in the same manner. Comparing active scanning and passive scanning, active scanning has the advantage of lower delay and power consumption than passive scanning.

[0074] After the STA discovers the network, an authentication process may be performed in step S320. This authentication process may be referred to as the first authentication process to clearly distinguish it from the security setup operation of step S340 described below.

[0075] The authentication process involves the STA sending an authentication request frame to the AP, and the AP responding by sending an authentication response frame to the STA. The authentication frame used for the authentication request / response corresponds to a management frame.

[0076] The authentication frame may include information such as an authentication algorithm number, an authentication transaction sequence number, a status code, a challenge text, a Robust Security Network (RSN), and a Finite Cyclic Group. These are just some examples of information that may be included in an authentication request / response frame, and may be replaced with other information or include additional information.

[0077] An STA can send an authentication request frame to an AP. The AP can determine whether to grant authentication to the STA based on the information contained in the received authentication request frame. The AP can provide the result of the authentication process to the STA via an authentication response frame.

[0078] After the STA is successfully authenticated, an association process may be performed in step S330. The association process includes a process in which the STA transmits an association request frame to the AP, and in response, the AP transmits an association response frame to the STA.

[0079] For example, the association request frame may include information about various capabilities, a beacon listen interval, a service set identifier (SSID), supported rates, supported channels, an RSN, a mobility domain, supported operating classes, a Traffic Indication Map Broadcast request, interworking service capabilities, etc. For example, the association response frame may include information about various capabilities, a status code, an Association ID (AID), supported rates, an Enhanced Distributed Channel Access (EDCA) parameter set, a Received Channel Power Indicator (RCPI), a Received Signal to Noise Indicator (RSNI), a mobility domain, a timeout interval (e.g., an association comeback time), overlapping BSS scan parameters, a TIM broadcast response, a Quality of Service (QoS) map, etc. These are just some examples of information that may be included in a combined request / response frame, and may be replaced by other information or include additional information.

[0080] After the STA successfully joins the network, a security setup process may be performed in step S340. The security setup process in step S340 may be referred to as an authentication process through a Robust Security Network Association (RSNA) request / response, the authentication process in step S320 may be referred to as a first authentication process, and the security setup process in step S340 may also be referred to simply as an authentication process.

[0081] The security setup process of step S340 may include, for example, a process of establishing a private key through a four-way handshaking using an Extensible Authentication Protocol over LAN (EAPOL) frame. Furthermore, the security setup process may be performed according to a security method not defined in the IEEE 802.11 standard.

[0082] FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.

[0083] In wireless LAN systems, the basic access mechanism of MAC (Medium Access Control) is Carrier Sense Multiple Access with Collision Avoidance (CSMA / CA). The CSMA / CA mechanism, also known as the Distributed Coordination Function (DCF) of the IEEE 802.11 MAC, essentially employs a "listen before talk" access mechanism. According to this type of access mechanism, the AP and / or STA may perform a Clear Channel Assessment (CCA) to sense the wireless channel or medium for a predetermined time period (e.g., a DCF Inter-Frame Space (DIFS)) before starting transmission. If the sensing result determines that the medium is in an idle state, the AP and / or STA may start transmitting frames through the medium. On the other hand, if the medium is detected to be occupied or busy, the AP and / or STA may not start its own transmission, but may wait for a delay period (e.g., a random backoff period) for medium access before attempting to transmit frames. By applying a random backoff period, multiple STAs are expected to attempt to transmit frames after waiting for different periods of time, thereby minimizing collisions.

[0084] In addition, the IEEE 802.11 MAC protocol provides the Hybrid Coordination Function (HCF). The HCF is based on the DCF and the Point Coordination Function (PCF). The PCF is a polling-based synchronous access method that periodically polls all receiving APs and / or STAs to ensure that they receive data frames. In addition, the HCF has the Enhanced Distributed Channel Access (EDCA) and the HCF Controlled Channel Access (HCCA). The EDCA is a contention-based access method for a provider to provide data frames to multiple users, while the HCCA uses a non-contention-based channel access method that utilizes a polling mechanism. In addition, the HCF includes a medium access mechanism to improve the Quality of Service (QoS) of the wireless LAN, and can transmit QoS data in both the Contention Period (CP) and the Contention Free Period (CFP).

[0085] Referring to Fig. 4, an operation based on a random backoff period is described. When a medium that was occupied / busy changes to an idle state, multiple STAs can attempt to transmit data (or frames). To minimize collisions, each STA can select a random backoff count, wait for the corresponding slot time, and then attempt transmission. The random backoff count has a pseudo-random integer value and can be determined as one of the values ​​in the range of 0 to CW. Here, CW is a contention window parameter value. The CW parameter is given an initial value of CWmin, but can take a value doubled in case of transmission failure (e.g., when an ACK for a transmitted frame is not received). When the CW parameter value becomes CWmax, data transmission can be attempted while maintaining the CWmax value until data transmission is successful, and if data transmission is successful, it is reset to the CWmin value. The CW, CWmin, and CWmax values ​​are 2. n It is desirable to set it to -1 (n=0, 1, 2, ...).

[0086] Once the random backoff process begins, the STA continues to monitor the medium while counting down the backoff slots according to the determined backoff count value. If the medium is monitored as occupied, the countdown stops and waits. When the medium becomes idle, the remaining countdown resumes.

[0087] In the example of FIG. 4, when a packet to be transmitted reaches the MAC of STA3, STA3 can immediately transmit a frame if it confirms that the medium is idle for DIFS. The remaining STAs monitor the medium for occupied / busy states and wait. In the meantime, data to be transmitted may also occur in each of STA1, STA2, and STA5, and each STA can count down the backoff slot according to a random backoff count value selected by each STA after waiting for DIFS if the medium is monitored as idle. Assume that STA2 selects the smallest backoff count value and STA1 selects the largest backoff count value. In other words, this example shows a case where the remaining backoff time of STA5 is shorter than the remaining backoff time of STA1 when STA2 finishes the backoff count and starts frame transmission. STA1 and STA5 briefly stop counting down and wait while STA2 occupies the medium. When STA2's occupation ends and the medium becomes idle again, STA1 and STA5 wait for DIFS and then resume the backoff count that they had stopped. That is, they can start transmitting frames after counting down the remaining backoff slots equal to the remaining backoff time. Since STA5's remaining backoff time is shorter than STA1's, STA5 starts transmitting frames. While STA2 occupies the medium, STA4 may also have data to transmit. From STA4's perspective, when the medium becomes idle, it waits for DIFS, counts down according to its selected random backoff count value, and then starts transmitting frames. In the example of Figure 4, the remaining backoff time of STA5 coincidentally matches the random backoff count value of STA4, in which case a collision may occur between STA4 and STA5. If a collision occurs, neither STA4 nor STA5 will receive an ACK, resulting in a failure in data transmission.In this case, STA4 and STA5 can select a random backoff count value and perform a countdown after doubling the CW value. STA1 waits while the medium is occupied by transmissions from STA4 and STA5, and when the medium becomes idle, it waits for DIFS and can start transmitting frames after the remaining backoff time elapses.

[0088] As in the example of Fig. 4, a data frame is a frame used for transmitting data forwarded to a higher layer, and can be transmitted after a backoff performed after DIFS elapses from when the medium becomes idle. Additionally, a management frame is a frame used for exchanging management information that is not forwarded to a higher layer, and is transmitted after a backoff performed after an IFS elapses, such as DIFS or PIFS (Point coordination function IFS). Subtype frames of a management frame include a beacon, an association request / response, a re-association request / response, a probe request / response, and an authentication request / response. A control frame is a frame used to control access to the medium. The subtype frames of the control frame include Request-To-Send (RTS), Clear-To-Send (CTS), Acknowledgment (ACK), Power Save-Poll (PS-Poll), Block ACK (BlockAck), Block ACK Request (BlockACKReq), Null Data Packet Announcement (NDP), and Trigger. If the control frame is not a response frame to the previous frame, it is transmitted after a backoff performed after the DIFS (Direct Inverse Frame Stop) has elapsed, and if it is a response frame to the previous frame, it is transmitted without a backoff performed after the SIFS (short IFS). The type and subtype of the frame can be identified by the type field and subtype field in the Frame Control (FC) field.

[0089] A QoS (Quality of Service) STA can transmit a frame after a backoff performed after the AIFS (arbitration IFS) for the access category (AC) to which the frame belongs, i.e., AIFS[i] (where i is a value determined by the AC), has elapsed. Here, the frames for which AIFS[i] can be used can be data frames, management frames, and also control frames that are not response frames.

[0090] FIG. 5 is a diagram for explaining a CSMA / CA-based frame transmission operation to which the present disclosure can be applied.

[0091] As mentioned above, the CSMA / CA mechanism includes virtual carrier sensing in addition to physical carrier sensing, in which STAs directly sense the medium. Virtual carrier sensing is intended to address potential issues in medium access, such as the hidden node problem. For virtual carrier sensing, the MAC of an STA can utilize a Network Allocation Vector (NAV). The NAV is a value that an STA that is currently using or has the right to use the medium indicates to other STAs the remaining time until the medium becomes available. Therefore, the value set as NAV corresponds to the period during which the STA transmitting the frame is scheduled to use the medium, and an STA receiving the NAV value is prohibited from accessing the medium during that period. For example, the NAV can be set based on the value of the "duration" field in the MAC header of the frame.

[0092] In the example of FIG. 5, it is assumed that STA1 wants to transmit data to STA2, and STA3 is in a position to overhear some or all of the frames transmitted and received between STA1 and STA2.

[0093] In order to reduce the possibility of collisions in transmissions by multiple STAs in a CSMA / CA-based frame transmission operation, a mechanism using RTS / CTS frames may be applied. In the example of FIG. 5, while STA1 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA1 may correspond to a hidden node for STA3. Alternatively, in the example of FIG. 5, while STA2 is transmitting, STA3 may determine that the medium is idle based on carrier sensing results. That is, STA2 may correspond to a hidden node for STA3. By exchanging RTS / CTS frames before performing data transmission and reception between STA1 and STA2, STAs outside the transmission range of either STA1 or STA2, or STAs outside the carrier sensing range for transmissions from STA1 or STA3, may not attempt to occupy the channel during data transmission and reception between STA1 and STA2.

[0094] Specifically, STA1 can determine whether a channel is occupied through carrier sensing. In terms of physical carrier sensing, STA1 can determine channel occupancy idleness based on the energy level or signal correlation detected in the channel. Furthermore, in terms of virtual carrier sensing, STA1 can determine the channel occupancy status using a network allocation vector (NAV) timer.

[0095] STA1 can transmit an RTS frame to STA2 after performing a backoff if the channel is idle during the DIFS. STA2 can transmit a CTS frame, which is a response to the RTS frame, to STA1 after an SIFS if it receives the RTS frame.

[0096] If STA3 cannot overhear a CTS frame from STA2 but can overhear an RTS frame from STA1, STA3 can use the duration information contained in the RTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + CTS frame + SIFS + data frame + SIFS + ACK frame). Alternatively, if STA3 cannot overhear an RTS frame from STA1 but can overhear a CTS frame from STA2, STA3 can use the duration information contained in the CTS frame to set a NAV timer for the subsequent consecutively transmitted frame transmission period (e.g., SIFS + data frame + SIFS + ACK frame). That is, if STA3 can overhear one or more of the RTS or CTS frames from one or more of STA1 or STA2, it can set a NAV accordingly. If STA3 receives a new frame before the NAV timer expires, it can update the NAV timer using the duration information contained in the new frame. STA3 does not attempt channel access until the NAV timer expires.

[0097] If STA1 receives a CTS frame from STA2, it can transmit a data frame to STA2 after SIFS from the time when the CTS frame is completely received. If STA2 successfully receives the data frame, it can transmit an ACK frame in response to the data frame to STA1 after SIFS. STA3 can determine whether the channel is in use through carrier sensing if the NAV timer expires. If STA3 determines that the channel is not in use by another terminal during the DIFS after the NAV timer expires, it can attempt channel access after a contention window (CW) based on a random backoff has elapsed.

[0098] FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.

[0099] The PHY layer can prepare an MPDU (MAC PDU) to be transmitted based on an instruction or primitive (meaning a set of instructions or parameters) from the MAC layer. For example, when a command requesting the start of transmission of the PHY layer is received from the MAC layer, the PHY layer can switch to transmission mode and transmit the information (e.g., data) provided by the MAC layer in the form of a frame. In addition, when the PHY layer detects a valid preamble of the received frame, it monitors the header of the preamble and sends a command to the MAC layer notifying the start of reception of the PHY layer.

[0100] In this way, information transmission / reception in a wireless LAN system is done in the form of frames, and for this purpose, the PHY layer Protocol Data Unit (PPDU) format is defined.

[0101] A basic PPDU may include a Short Training Field (STF), a Long Training Field (LTF), a SIGNAL (SIG) field, and a Data field. The most basic (e.g., non-HT (High Throughput) as illustrated in FIG. 7) PPDU format may consist of only the Legacy-STF (L-STF), Legacy-LTF (L-LTF), Legacy-SIG (L-SIG) fields, and a Data field. Additionally, depending on the type of PPDU format (e.g., HT-mixed format PPDU, HT-greenfield format PPDU, VHT (Very High Throughput) PPDU, etc.), additional (or different types of) RL-SIG, U-SIG, non-legacy SIG field, non-legacy STF, non-legacy LTF, (i.e., xx-SIG, xx-STF, xx-LTF (e.g., xx is HT, VHT, HE, EHT, etc.)) may be included between the L-SIG field and the data field. More specific details will be described later with reference to FIG. 7.

[0102] STF is a signal for signal detection, AGC (Automatic Gain Control), diversity selection, and precise time synchronization, while LTF is a signal for channel estimation, frequency error estimation, etc. STF and LTF can be said to be signals for synchronization and channel estimation of the OFDM physical layer.

[0103] The SIG field may include various information related to PPDU transmission and reception. For example, the L-SIG field may consist of 24 bits and may include a 4-bit Rate field, a 1-bit Reserved bit, a 12-bit Length field, a 1-bit Parity field, and a 6-bit Tail field. The RATE field may include information about the modulation and coding rate of data. For example, the 12-bit Length field may include information about the length or time duration of the PPDU. For example, the value of the 12-bit Length field may be determined based on the type of the PPDU. For example, for a non-HT, HT, VHT, or EHT PPDU, the value of the Length field may be determined as a multiple of 3. For example, for HE PPDU, the value of the Length field can be determined as a multiple of 3 + 1 or a multiple of 3 + 2.

[0104] The data field may include a SERVICE field, a Physical layer Service Data Unit (PSDU), a PPDU TAIL bit, and, if necessary, padding bits. Some bits of the SERVICE field may be used to synchronize the descrambler at the receiving end. The PSDU corresponds to a MAC PDU defined at the MAC layer and may contain data generated / used by upper layers. The PPDU TAIL bit may be used to return the encoder to a 0 state. The padding bit may be used to adjust the length of the data field to a predetermined unit.

[0105] MAC PDUs are defined according to various MAC frame formats, and a basic MAC frame consists of a MAC header, a frame body, and a Frame Check Sequence (FCS). A MAC frame is composed of MAC PDUs and can be transmitted / received through the PSDU in the data portion of the PPDU format.

[0106] The MAC header includes a Frame Control field, a Duration / ID field, an Address field, etc. The Frame Control field may include control information required for frame transmission / reception. The Duration / ID field may be set to a time for transmitting the corresponding frame, etc. The Address subfields may indicate the receiver address, transmitter address, destination address, and source address of the frame, and some Address subfields may be omitted. For specific details of each subfield of the MAC header, including the Sequence Control, QoS Control, and HT Control subfields, refer to the IEEE 802.11 standard document.

[0107] The Null-Data PPDU (NDP) format refers to a PPDU format that does not include a data field. In other words, NDP refers to a frame format that includes a PPDU preamble (i.e., L-STF, L-LTF, L-SIG fields, and, if additionally present, non-legacy SIG, non-legacy STF, and non-legacy LTF) in the general PPDU format, and does not include the remaining part (i.e., data field).

[0108] FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.

[0109] Standards such as IEEE 802.11a / g / n / ac / ax use various PPDU formats. The basic PPDU format (IEEE 802.11a / g) includes L-LTF, L-STF, L-SIG, and Data fields. The basic PPDU format can also be referred to as the non-HT PPDU format (Fig. 7(a)).

[0110] The HT PPDU format (IEEE 802.11n) additionally includes HT-SIG, HT-STF, and HT-LFT(s) fields in addition to the basic PPDU format. The HT PPDU format illustrated in Fig. 7(b) may be referred to as an HT-mixed format. Additionally, an HT-greenfield format PPDU may be defined, which corresponds to a format that does not include L-STF, L-LTF, and L-SIG, but consists of HT-GF-STF, HT-LTF1, HT-SIG, one or more HT-LTF, and Data fields (not illustrated).

[0111] An example of the VHT PPDU format (IEEE 802.11ac) includes VHT SIG-A, VHT-STF, VHT-LTF, and VHT-SIG-B fields in addition to the basic PPDU format (Fig. 7(c)).

[0112] An example of a HE PPDU format (IEEE 802.11ax) additionally includes RL-SIG (Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), and PE (Packet Extension) fields in addition to the basic PPDU format (Fig. 7(d)). Depending on specific examples of the HE PPDU format, some fields may be excluded or their lengths may vary. For example, the HE-SIG-B field is included in the HE PPDU format for multi-users (MUs), but the HE-SIG-B is not included in the HE PPDU format for single users (SUs). In addition, the HE trigger-based (TB) PPDU format does not include the HE-SIG-B, and the length of the HE-STF field may vary to 8 microseconds (us). The HE ER (Extended Range) SU PPDU format does not include the HE-SIG-B field, and the length of the HE-SIG-A field can vary to 16us. For example, the RL-SIG can be configured identically to the L-SIG. The receiving STA can determine that the received PPDU is a HE PPDU or an EHT PPDU, described later, based on the presence of the RL-SIG.

[0113] The EHT PPDU format may include the EHT MU (multi-user) PPDU of FIG. 7(e) and the EHT TB (trigger-based) PPDU of FIG. 7(f). The EHT PPDU format is similar to the HE PPDU format in that it includes an RL-SIG following an L-SIG, but may include a U (universal)-SIG, an EHT-SIG, an EHT-STF, and an EHT-LTF following the RL-SIG.

[0114] The EHT MU PPDU in FIG. 7(e) corresponds to a PPDU that carries one or more data (or PSDUs) for one or more users. That is, the EHT MU PPDU can be used for both SU transmission and MU transmission. For example, the EHT MU PPDU can correspond to a PPDU for one receiving STA or multiple receiving STAs.

[0115] The EHT TB PPDU of Fig. 7(f) omits the EHT-SIG compared to the EHT MU PPDU. An STA that has received a trigger for UL MU transmission (e.g., a trigger frame or TRS (triggered response scheduling)) can perform UL transmission based on the EHT TB PPDU format.

[0116] The L-STF, L-LTF, L-SIG, RL-SIG, U-SIG (Universal SIGNAL), and EHT-SIG fields can be encoded and modulated to allow legacy STAs to attempt demodulation and decoding, and mapped based on a predetermined subcarrier frequency interval (e.g., 312.5 kHz). These can be referred to as pre-EHT modulated fields. Next, the EHT-STF, EHT-LTF, Data, and PE fields can be encoded and modulated to allow STAs that have successfully decoded non-legacy SIGs (e.g., U-SIG and / or EHT-SIG) and obtained the information contained in the fields, and mapped based on a predetermined subcarrier frequency interval (e.g., 78.125 kHz). These can be referred to as EHT modulated fields.

[0117] Similarly, in the HE PPDU format, the L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, and HE-SIG-B fields may be referred to as pre-HE modulation fields, and the HE-STF, HE-LTF, Data, and PE fields may be referred to as HE modulation fields. Additionally, in the VHT PPDU format, the L-STF, L-LTF, L-SIG, and VHT-SIG-A fields may be referred to as pre-VHT modulation fields, and the VHT STF, VHT-LTF, VHT-SIG-B, and Data fields may be referred to as VHT modulation fields.

[0118] The U-SIG included in the EHT PPDU format of FIG. 7 can be configured based on, for example, two symbols (e.g., two consecutive OFDM symbols). Each symbol (e.g., OFDM symbol) for the U-SIG can have a duration of 4 us, and the U-SIG can have a total duration of 8 us. Each symbol of the U-SIG can be used to transmit 26 bits of information. For example, each symbol of the U-SIG can be transmitted and received based on 52 data tones and 4 pilot tones.

[0119] U-SIGs can be configured in 20MHz units. For example, when an 80MHz PPDU is configured, the same U-SIG can be duplicated in 20MHz units. That is, four identical U-SIGs can be included in an 80MHz PPDU. When the bandwidth exceeds 80MHz, for example, for a 160MHz PPDU, the U-SIGs in the first 80MHz unit and the U-SIGs in the second 80MHz unit can be different.

[0120] For example, A uncoded bits may be transmitted via U-SIG, and a first symbol of U-SIG (e.g., a U-SIG-1 symbol) may transmit the first X bits of information out of a total A bits of information, and a second symbol of U-SIG (e.g., a U-SIG-2 symbol) may transmit the remaining Y bits of information out of a total A bits of information. The A bits of information (e.g., 52 uncoded bits) may include a CRC field (e.g., a field of 4 bits in length) and a tail field (e.g., a field of 6 bits in length). The tail field may be used to terminate the trellis of the convolutional decoder and may be set to 0, for example.

[0121] The A bit information transmitted by U-SIG can be divided into version-independent bits and version-dependent bits. For example, U-SIG can be included in a new PPDU format (e.g., UHR PPDU format) not shown in FIG. 7, and in the format of the U-SIG field included in the EHT PPDU format and the format of the U-SIG field included in the UHR PPDU format, the version-independent bits can be the same, and some or all of the version-dependent bits can be different.

[0122] For example, the size of the version-independent bits of U-SIG can be fixed or variable. The version-independent bits can be assigned only to U-SIG-1 symbols, or to both U-SIG-1 symbols and U-SIG-2 symbols. The version-independent bits and the version-dependent bits can be called by various names, such as the first control bit and the second control bit.

[0123] For example, the version-independent bits of the U-SIG may include a 3-bit PHY version identifier, which may indicate the PHY version (e.g., EHT, UHR, etc.) of the transmitted and received PPDUs. The version-independent bits of the U-SIG may include a 1-bit UL / DL flag field. The first value of the 1-bit UL / DL flag field relates to UL communication, and the second value of the UL / DL flag field relates to DL communication. The version-independent bits of the U-SIG may include information about the length of a transmission opportunity (TXOP) and information about a BSS color ID.

[0124] For example, the version-dependent bits of the U-SIG may contain information that directly or indirectly indicates the type of PPDU (e.g., SU PPDU, MU PPDU, TB PPDU, etc.).

[0125] Information required for PPDU transmission and reception may be included in the U-SIG. For example, the U-SIG may further include information about bandwidth, information about the MCS technique applied to the non-legacy SIG (e.g., EHT-SIG or UHR-SIG), information indicating whether a dual carrier modulation (DCM) technique (e.g., a technique to achieve an effect similar to frequency diversity by reusing the same signal on two subcarriers) is applied to the non-legacy SIG, information about the number of symbols used for the non-legacy SIG, information about whether the non-legacy SIG is generated across the entire band, etc.

[0126] Some of the information required for transmitting and receiving a PPDU may be included in the U-SIG and / or the non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.). For example, information about the type of the non-legacy LTF / STF (e.g., EHT-LTF / EHT-STF or UHR-LTF / UHR-STF, etc.), information about the length of the non-legacy LTF and the cyclic prefix (CP) length, information about the guard interval (GI) applicable to the non-legacy LTF, information about preamble puncturing applicable to the PPDU, information about resource unit (RU) allocation, etc. may be included only in the U-SIG, may be included only in the non-legacy SIG, or may be indicated by a combination of the information included in the U-SIG and the information included in the non-legacy SIG.

[0127] Preamble puncturing may refer to the transmission of a PPDU in which no signal is present in one or more frequency units within the PPDU's bandwidth. For example, the size of the frequency unit (or the resolution of the preamble puncturing) may be defined as 20 MHz, 40 MHz, etc. For example, preamble puncturing may be applied to a PPDU bandwidth greater than a certain size.

[0128] In the example of FIG. 7, non-legacy SIGs such as HE-SIG-B and EHT-SIG may include control information for the receiving STA. The non-legacy SIG may be transmitted over at least one symbol, and each symbol may have a length of 4 us. Information regarding the number of symbols used for the EHT-SIG may be included in a previous SIG (e.g., HE-SIG-A, U-SIG, etc.).

[0129] Non-legacy SIGs, such as HE-SIG-B and EHT-SIG, may contain common fields and user-specific fields. Common and user-specific fields may be coded separately.

[0130] In some cases, common fields may be omitted. For example, in a compressed mode where non-OFDMA (orthogonal frequency multiple access) is applied, common fields may be omitted, and multiple STAs may receive PPDUs (e.g., data fields of PPDUs) over the same frequency band. In a non-compressed mode where OFDMA is applied, multiple users may receive PPDUs (e.g., data fields of PPDUs) over different frequency bands.

[0131] The number of user-specific fields can be determined based on the number of users. A single user block field can contain up to two user fields. Each user field can be associated with either MU-MIMO allocation or non-MU-MIMO allocation.

[0132] The common field may include CRC bits and Tail bits, the length of the CRC bits may be determined as 4 bits, and the length of the Tail bits may be determined as 6 bits and set to 000000. The common field may include RU allocation information. The RU allocation information may include information about the location of RUs to which multiple users (i.e., multiple receiving STAs) are allocated.

[0133] An RU can contain multiple subcarriers (or tones). RUs can be used when transmitting signals to multiple STAs based on OFDMA techniques. RUs can also be defined when transmitting signals to a single STA. Resources can be allocated on an RU basis for non-legacy STFs, non-legacy LTFs, and data fields.

[0134] Depending on the PPDU bandwidth, an applicable RU size can be defined. The RU may be defined identically or differently for the applicable PPDU format (e.g., HE PPDU, EHT PPDU, UHR PPDU, etc.). For example, in the case of an 80MHz PPDU, the RU arrangements of HE PPDU and EHT PPDU may be different. The applicable RU size, RU number, RU position, DC (direct current) subcarrier position and number, null subcarrier position and number, guard subcarrier position and number, etc. for each PPDU bandwidth can be referred to as a tone plan. For example, a tone plan for a wide bandwidth can be defined in the form of multiple repetitions of a low bandwidth tone plan.

[0135] RUs of different sizes can be defined, such as 26-ton RU, 52-ton RU, 106-ton RU, 242-ton RU, 484-ton RU, 996-ton RU, 2X996-ton RU, 4X996-ton RU, etc. A multiple RU (MRU) is distinguished from multiple individual RUs and corresponds to a group of subcarriers consisting of multiple RUs. For example, one MRU can be defined as 52+26-tons, 106+26-tons, 484+242-tons, 996+484-tons, 996+484+242-tons, 2X996+484-tons, 3X996-tons, or 3X996+484-tons. Additionally, multiple RUs constituting one MRU may or may not be consecutive in the frequency domain.

[0136] The specific size of an RU may be reduced or expanded. Therefore, the specific size of each RU (i.e., the number of corresponding tones) in the present disclosure is not limited and is exemplary. Furthermore, within a given bandwidth (e.g., 20, 40, 80, 160, 320 MHz, etc.) in the present disclosure, the number of RUs may vary depending on the RU size.

[0137] The names of each field in the PPDU formats of FIG. 7 are exemplary and the scope of the present disclosure is not limited by those names. Furthermore, the examples of the present disclosure can be applied not only to the PPDU format exemplified in FIG. 7, but also to a new PPDU format in which some fields are excluded and / or some fields are added based on the PPDU formats of FIG. 7.

[0138] Multi-Access Point (MAP) operation

[0139] Below, examples of the present disclosure for multi-access point (MAP) operation are described.

[0140] MAP operation can be defined as an operation between a master AP (or sharing AP) and a slave AP (or shared AP).

[0141] The master AP initiates and controls MAP operations for transmission and reception between multiple APs. It groups slave APs and manages links with them to enable information sharing. The master AP manages information about the BSS comprised of the slave APs and the STAs associated with that BSS.

[0142] Slave APs can associate with a master AP and share control information, management information, and data traffic. Slave APs perform the same basic functions as APs, establishing a base station service (BSS) in a wireless LAN.

[0143] In MAP operation, an STA can associate with a slave AP or a master AP and form a BSS.

[0144] In a MAP environment, the master AP and slave APs can directly transmit and receive with each other. The master AP and STA may not be able to directly transmit and receive with each other. A slave AP (e.g., a slave AP associated with an STA) can directly transmit and receive with the STA. One of the slave APs can become the master AP.

[0145] MAP operation is a technique in which one or more APs transmit and receive information to one or more STAs. For example, coordinated-time division multiple access (C-TDMA), which divides allocations between APs along the time axis, coordinated-orthogonal frequency division multiple access (C-OFDMA), which divides allocations along the frequency axis, and coordinated-spatial reuse (C-SR) techniques that utilize spatial reuse can be applied for MAP operation. Alternatively, coordinated beamforming (C-BF) or joint beamforming techniques, which cooperatively perform simultaneous transmission and reception, can also be applied to MAP operation.

[0146] FIG. 8 is a diagram for explaining various transmission and reception techniques in a MAP environment to which the present disclosure can be applied.

[0147] As in the conventional method, when a BSS AP transmits to a BSS STA, this can be referred to as STX (single transmission). STX suffers from the problem of reduced transmission and reception performance for users / STAs located at the cell edge due to interference with neighboring APs. For example, as shown in Figure 8(a), if AP1 and AP2 transmit to STA1 and STA2, respectively, at the same time and within the same frequency bandwidth, a collision may occur on the wireless medium.

[0148] In the MAP technique, performance can be improved by reducing inter-symbol interference (ISI) through cooperation between neighboring APs, or by performing joint transmissions. For example, in the C-OFDMA method of Fig. 8(b), interference can be avoided by simultaneously transmitting to STA1 in the first bandwidth and transmitting to STA2 in the second bandwidth. The example of Fig. 8(c) shows a cooperative beamforming or nulling technique in which AP1 nulls the interference to AP2 and / or STA2 while transmitting to STA1, and AP2 nulls the interference to AP1 and / or STA1 while transmitting to STA2. Fig. 8(d) shows an AP selection method in which an AP with a good channel condition among neighboring APs performs transmission. Joint transmission (JTX) or joint reception (JRX) may be applied, in which multiple APs cooperate to transmit or receive simultaneously, as in the example of Fig. 8(e), and further, joint MU-MIMO may be supported.

[0149] RSN operation

[0150] As described with reference to Figure 3, after the discovery process between the STA and the AP, the authentication process can be performed in an open system manner, followed by an association process. This process can be considered Step 0, which involves detecting support for a robust security network (RSN) and establishing authentication and association.

[0151] If step 0 is successfully completed, step 1 of user authentication by IEEE 802.1X / EAP (extensible authentication protocol) or PSK (pre-shared key) and obtaining a pairwise master key (PMK) can be performed. The mutual authentication method applied here may include 802.1X / EAP, PSK, or simultaneous authentication of equals (SAE). For example, in the case of 802.1X / EAP authentication, PMK can be generated from MSK (master session key) after authentication between STA and RADIUS (remote authentication dial-in user service). In the case of user authentication by PSK, AP and STA can directly set PMK in the same way as PSK. In the case of user authentication by SAE, AP and STA can directly set PMK by using mutual authentication and authentication process operation value through SAE authentication process.

[0152] Following Step 1, Step 2 may be performed to verify that the other party holds the same PMK using the EAPoL-Key frame and to generate and share an encryption key. Step 2 may include a process of mutually verifying the generation of the PMK through 4-way handshaking and generating and transmitting a group key (e.g., a group temporal key (GTK)). A pairwise transient key (PTK), a key confirmation key (KCK), a key encryption key (KEK), and a temporal key (TK) may be generated through the 4-way handshaking.

[0153] Specifically, in step 1, a PMK may be generated from the MSK, and in step 2, a PTK may be generated from the PMK. Here, the PTK is configured separately as a KCK, a KEK, and a TK. A GTK may be generated from the AP and transmitted to the STA. If the AP wishes to generate a new GTK, it may perform handshaking with the STA and transmit the new GTK to the STA.

[0154] In order to verify that the STA and AP have the same PMK, in the case of 802.1X / EAP, the same MSK is set between the STA and the AS based on the user authentication result between the STA and the authentication server (AS), and the AS transmits the MSK to the AP. The STA and the AP can confirm whether they have the PMK, which is a symmetric key generated from the MSK, through 4-way handshaking. In the case of the PSK, the authentication procedure can be replaced by mutually verifying through 4-way handshaking whether the PMK generated from the PSK previously set between the AP and the STA has been secured. In the case of SAE, the PMK previously set between the AP and the STA can be mutually verified through 4-way handshaking.

[0155] It is also possible to verify that the STA and AP have the same PMK by mutually verifying that they generated the same PTK. For example, it is also possible to verify whether the PMK is secured through Messages 2 and 3 of the 4-way handshaking. Specifically, in Message 2, the STA can send the KCK of the PTK it generated to the AP by including it in the Key MIC field. In Message 3, the AP can send the KCK of the PTK it generated to the STA by including it in the Key MIC field. Through this, the STA (AP) can verify that the AP (STA) generated the same PTK as its own PTK, thereby confirming that the AP (STA) has the same PMK as itself. Meanwhile, in Message 1, the value of the Key MIC field may be set to 0, and in Message 4, the Key MIC field may include the KCK value.

[0156] In this way, a secret key can be generated to encrypt data to be transmitted and received between the STA and the AP in step 2. In the RSN, a different secret key is generated for each STA associated with the AP, and another secret key is generated when the STA re-associates with another AP.

[0157] Based on the TK generated as a result of the 4-way handshaking in step 2, data encryption can be performed using TKIP (temporal key integrity protocol), CCMP (cipher-block chaining message authentication code protocol), GCMP (Galois / Counter Mode protocol), etc., and this can be referred to as step 3.

[0158] The aforementioned MSK, PSK, PMK, PTK, KCK, KEK, and TK correspond to pairwise keys, that is, keys that are paired between the AP and the STA. Unlike the pairwise keys, the group key can be generated based on the group master key (GMK) for the AP to generate a secret key for group-addressed frames, such as beacon frames. The GMK is randomly set by the AP. The group temporal key (GTK) is generated from the GMK by the pseudorandom function (PRF) and corresponds to a one-way group key from the AP to the STA.

[0159] FIG. 9 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.

[0160] The STA corresponds to the side requesting authentication (supplicant), and the AP corresponds to the side performing authentication (authenticator). A four-way handshaking can be performed to generate and verify the PTK and GTK between the AP and the STA when the STA possesses or knows the PMK, and the AP possesses or knows the PMK and GMK.

[0161] ANonce and SNonce correspond to arguments used in the PRF function used to generate the PTK. ANonce may correspond to a random number generated by the access point (i.e., the authenticator). SNonce may correspond to a random number generated by the STA (i.e., the supplicant). The PRF function may correspond to a function that generates a PTK based on, for example, the PMK, ANonce, SNonce, the MAC address of the supplicant, and the MAC address of the authenticator.

[0162] Message 1 of step S810 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include ANonce information. If the AP generates a PMK, the PMKID may be included in the key data field of the EAPOL-key frame. The STA may generate a PTK based on the information received from the AP, and may generate a KCK, KEK, and TK based on the PTK.

[0163] Message 2 of step S820 is transmitted from the STA to the AP in a unicast manner, and the EAPOL-key frame may include SNonce information and a key MIC (message integrity code). For example, the key MIC of message 2 may have a value based on the KCK generated by the STA. The AP may generate a PTK based on the information received from the STA, and may generate a KCK, a KEK, and a TK based on the PTK. The AP may verify whether the AP and the STA have generated the same PTK based on whether the KCK value of the PTK generated based on the value included in message 2 and the KCK value related to the key MIC value included in message 2 are the same. In addition, the AP may generate a GTK if necessary. The generation of the GTK may be generated by the AP from the GMK without the involvement of the STA.

[0164] Message 3 of step S830 is transmitted unicast from the AP to the STA, and the EAPOL-key frame may include MIC (i.e., corresponding to the KCK value of the PTK generated by the AP) and encrypted GTK information. The encrypted GTK of message 3 may be encrypted based on the KEK generated by the AP and included in the key data field. The STA may store the PTK in the PTK-SA (PTK-Security Association) and the GTK in the GTK-SA.

[0165] Message 4 of step S840 is transmitted unicast from the STA to the AP, and the EAPOL-key frame may include MIC information. Upon completion of verification via the MIC, the AP may store the PTK in the PTK-SA and the GTK in the GTK-SA.

[0166] Once the four-way handshaking is successfully completed, the virtual control port that previously blocked all traffic is unblocked, allowing encrypted traffic to be transmitted and received. All unicast traffic can then be encrypted using PTK, and all multicast / broadcast traffic can be encrypted using GTK.

[0167] RSNA confidentiality and integrity protocol

[0168] For RSNA, authentication mechanisms for STAs, key management algorithms, cryptographic key establishment, cryptographic mechanisms, fast BSS transition (FT), and cryptographic encapsulation for robust management frames can be defined. For example, cryptographic mechanisms can include CCMP (counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol), GCMP (Galois / Counter Mode protocol), etc.

[0169] RSNA security may include algorithms and procedures such as temporal key integrity protocol (TKIP), CCMP, GCMP, broadcast / multicast integrity protocol (BIP), RSNA establishment and termination procedures, and key management procedures (e.g., key distribution). For example, RSNA establishment and termination procedures may include IEEE 802.1X authentication, simultaneous authentication of equals (SAE) authentication, and opportunistic wireless encryption (OWE) as defined in Internet Engineering Task Force (IETF) request for comments (RFC) 8110.

[0170] Below, we describe CCMP (counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol).

[0171] CCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection. CCMP is based on the CCM of the AES (Advanced Encryption Standard) encryption algorithm. CCM combines CTR for data confidentiality and CBC-MAC for authentication and integrity. CCM can protect the integrity of both the MPDU data field and selected portions of the MPDU header (MAC header).

[0172] FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure may be applied.

[0173] For secure PV0 (protocol version 0) MPDUs, CCMP-128 processing enlarges the original MPDU size by 16 octets (i.e., 8 octets for the CCMP header field and 8 octets for the MIC field). CCMP-256 processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the CCMP header field and 16 octets for the MIC field). The CCMP header field is constructed from the packet number (PN), extended initialization vector (ExtIV), and key ID subfields. The PN is a 48-bit PN expressed as an array of 6 octets. PN5 is the most significant octet of the PN, and PN0 is the least significant octet. The third octet of the CCMP header is reserved. The ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for CCMP, bits 6 (B6) and 7 (B7) are the key ID subfields, and the remaining bits of the key ID octet are reserved.

[0174] Figure 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.

[0175] Additional authentication data (AAD) can be constructed from the MAC header of a plaintext MPDU. A Nonce can be constructed based on the A2 (address 2) and priority of the plaintext MPDU and the incremented PN. The AAD and Nonce, together with data and the TK, can be used for CCM encryption. A CCMP header can be constructed based on the incremented PN and the key ID. The data and MIC, which are the results of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, as in the example of FIG. 9.

[0176] Figure 11 shows an example of the format of conventional AAD.

[0177] The example of Fig. 11(a) may correspond to an example of a conventional AAD construction for a PV0 MPDU. The FC (frame control), A1 (address 1), A2 (address 2), A3 (address 3), and SC (sequence control) fields may always be included in the conventional AAD if they are included in the MAC header. The length of the AAD may vary depending on the presence or absence of the QC (QoS Control) field and the A4 (address 4) field. For the conventional AAD, for example, if both QC and A4 are absent, the AAD length may be 22 octets, if QC is present and A4 is absent, the AAD length may be 24 octets, if QC is absent and A4 is present, the AAD length may be 28 octets, and if both QC and A4 are present, the AAD length may be 30 octets.

[0178] AAD is constructed from the MPDU header. Referring to Figure 11(b), the existing AAD does not include the MAC header's Duration / ID field, nor does it include the MAC header's HT control field. This is to prevent the existing AAD from including fields whose contents can be changed or inserted / deleted during operations such as retransmission.

[0179] Additionally, some subfields of the Frame Control (FC) field of the MAC header may be masked out. Masking out means that the value of the corresponding subfield / fields of the MAC header is changed to 0 to be included in the AAD.

[0180] For example, the subfields that are masked out in the FC field of the existing AAD are as follows:

[0181] The 3 LSBs (i.e., bits 4, 5 and 6) of the subtype subfield of the data frame are masked out, and bit 7 is not modified;

[0182] The retry subfield is masked out;

[0183] The power management subfield (i.e. bit 12) is masked out;

[0184] The more data subfield (i.e. bit 13) is masked out;

[0185] The protected frame subfield (i.e., bit 14) is not modified (i.e., left as 1);

[0186] +HTC subfield (i.e. bit 15) is masked-out in all data frames containing the QoS control field and is otherwise unmodified;

[0187] Other subfields of the FC field are not modified.

[0188] For example, the sequence number subfield in the sequence control (SC) field of a legacy AAD may be masked out.

[0189] Although not shown in the example of FIG. 11, if the existing AAD includes a QoS Control (QC) field, the QC field may be included in the existing AAD if one or more of the MSDU priority subfield, the QC TID (traffic identifier) ​​subfield, the A-MSDU capable subfield, the A-MSDU present subfield, and the A-MSDU type subfield are present in the MAC header. Other subfields in the QC field of the existing AAD may be masked out. That is, the end of service period (EOSP) subfield, the ACK policy indicator subfield, the TXOP limit subfield, the queue size subfield, the TXOP duration requested subfield, and the AP PS buffer state subfield may be masked out and not used in the existing AAD configuration.

[0190] Figure 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.

[0191] An AAD can be constructed from the MAC header of an encrypted MPDU. A Nonce can be constructed based on the A2 and priority of the encrypted MPDU and the PN. The AAD and Nonce, along with the MIC, data, and key, can be used for CCM decryption. The data resulting from CCM decryption can be replay-checked along with the MAC header to obtain a plaintext MPDU. The replay-check can be based on the PN and a replay counter.

[0192] Below, we explain BIP (broadcast / multicast integrity protocol).

[0193] BIP provides data integrity and replay protection for group-addressed robust management frames after establishing an integrity group temporal key security association (IGTKSA). For example, BIP provides data integrity and replay protection for beacon frames after establishing a beacon IGTKSA (BIGTKSA). BIP can use IGTK or BIGTK to compute the MAC management PDU (MMPDU) MIC. The management MIC element (MME) can be located after all other elements of the management frame body and before the FCS. That is, the MME can be included as the last element of the management frame body. The MME can include an element ID field, a length field, a key ID field, an IPN (IGTK packet number) / BIPN (BIGTK packet number) field, and a MIC field.

[0194] The existing AAD for BIP can be constructed based on FC, A1, A2, A3, and the Retry subfield (bit 11), Power Management subfield (bit 12), and More Data subfield (bit 13) within FC are masked out, and other subfields may not be modified.

[0195] Below, we describe GCMP (Galois / Counter Mode protocol).

[0196] GCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection. EHT RSNA STAs can support GCMP-256. GCMP is based on the GCM (Global Code Compatibility) of the AES (Advanced Encryption Standard) encryption algorithm. GCM can protect the integrity of both the MPDU data field and selected portions of the MPDU header (MAC header).

[0197] FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.

[0198] GCMP processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the GCMP header field and 16 octets for the MIC field). The CCMP header field is constructed from the packet number (PN) and the key ID subfield. The PN is a 48-bit PN expressed as an array of 6 octets. PN5 is the most significant octet of the PN, and PN0 is the least significant octet. The third octet of the GCMP header is reserved. The ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for GCMP, bits 6 (B6) and 7 (B7) are the key ID subfields, and the remaining bits of the key ID octet are reserved.

[0199] Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.

[0200] Additional authentication data (AAD) can be constructed from the MAC header of a plaintext MPDU. A Nonce can be constructed based on address 2 (A2) of the plaintext MPDU and an incremented PN. The AAD and Nonce, together with data and the TK, can be used for GCM encryption. A GCMP header can be constructed based on the incremented PN and key ID. The data, which is the result of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, as in the example of FIG. 13.

[0201] The configuration of the existing AAD applied to GCMP is the same as that described with reference to Fig. 11, so redundant description is omitted.

[0202] Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.

[0203] An AAD can be constructed from the MAC header of an encrypted MPDU. A Nonce can be constructed based on A2 and PN of the encrypted MPDU. The AAD and Nonce, along with data and a key, can be used for GCM decryption. The data resulting from GCM decryption can be replay-checked along with the MAC header to obtain a plaintext MPDU. The replay-check can be based on the PN and a replay counter.

[0204] Block ACK Request (BAR) frame

[0205] FIG. 16 is a diagram illustrating an exemplary format of a block-ACK request frame to which the present disclosure can be applied.

[0206] A block-ACK request frame may be used to request transmission of a block-ACK frame that includes multiple acknowledgements in a single frame, thereby increasing channel efficiency. For example, a first STA (e.g., an AP) may request reception results for multiple MPDUs via the block-ACK request frame, and a second STA(s) that has received the block-ACK request frame may transmit a block-ACK frame that includes acknowledgements for multiple MPDUs based on the request.

[0207] As illustrated in FIG. 16, a block-ACK request (BAR) frame may include a BAR control field and a BAR information field in the frame body.

[0208] The BAR control field may include BAR type, TID information (TID_INFO), etc., which indicates the type of block-ACK request frame (e.g., compressed, multi-TID, groupcast with retries (GCR), etc.).

[0209] The BAR information field may be based on the type of block-ACK request frame (e.g., block-ACK request frame variant type) indicated by the BAR type field / subfield in the BAR control information.

[0210] For example, if a compressed block-ACK request frame type (e.g., compressed block-ACK frame type or extended compressed block-ACK frame type) is indicated, the BAR information field format corresponding to the compressed block-ACK request may include a Block Ack Starting Sequence Control subfield.

[0211] For example, the block-ACK starting sequence control subfield may include a fragment number subfield and a starting sequence number subfield, wherein the fragment number subfield is set to 0, and the starting sequence number subfield may include the sequence number of the first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.

[0212] For another example, when a multi-TID (multi-STA) block-ACK request frame type is indicated, the BAR information field format corresponding to the multi-TID block-ACK request may include, for each TID, a Per TID Info subfield and a Block-ACK Start Sequence Control subfield.

[0213] For example, each TID information subfield may include a 4-bit TID value subfield. In addition, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include the sequence number of the first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.

[0214] In this regard, the TID_INFO subfield of the BAR control field of the multi-TID block-ACK request frame can determine the number of TIDs present in the multi-TID block-ACK request frame, which is given as TID_INFO + 1. For example, setting the TID_INFO subfield to 2 can mean that there are three TID values ​​in the BAR information field of the multi-TID block-ACK request frame.

[0215] For another example, when a GCR block-ACK request frame type is indicated, a BAR information field format corresponding to the GCR block-ACK request may include a GCR group address subfield and a block-ACK start sequence control subfield. Here, the GCR group address subfield may include a MAC address of a group for which a reception status is requested. In addition, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include a sequence number of a first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.

[0216] For another example, when the GLK-GCR block-ACK request frame type is indicated, the BAR information field format corresponding to the GCR-GCR block-ACK request may include a block-ACK start sequence control subfield. Here, the block-ACK start sequence control subfield may include a fragment number subfield and a start sequence number subfield. Here, the fragment number subfield is set to 0, and the start sequence number subfield may include a sequence number of a first MSDU or A-MSDU in which the corresponding block-ACK request frame is transmitted.

[0217] Control frame protection based on security key

[0218] In the case of existing wireless LAN systems, encryption / decryption based on Temporal Key Integrity Protocol (TKIP) / CCMP / GCMP can be performed / applied for individually addressed data frames (e.g., unicast-based data frames) and management frame(s) using a pairwise transient key (PTK). In addition, encryption / decryption based on TKIP / CCMP / GCMP can be performed / applied for group addressed frames (e.g., broadcast-based data frames) using a group temporal key (GTK).

[0219] Additionally, for group-addressed management frames(es), BIP-based integrity checks can be performed using the integrity group temporal key (IGTK). In particular, for beacon frames, BIP-based integrity checks can be performed using the beacon integrity group temporal key (BIGTK).

[0220] As previously described, protection is supported for management frames, including data frames and beacon frames, among group-addressed frames. However, since control frames are transmitted and received without any encryption / decryption protocol, the security key used in the security protocol described above in this disclosure is not used.

[0221] For example, a trigger frame corresponding to a control frame may correspond to a frame including information on allocation of resource units (RUs), bandwidth, etc. for data transmission and reception for multiple STAs. In addition, a block ACK frame including ACK information for data transmission and reception and a block ACK request frame requesting information for transmitting an ACK may be included in the control frame.

[0222] If information of control frames of the types described above is exposed to a third STA (e.g., an attack STA), the data transmission and reception capability between the transmitting STA and the receiving STA may be reduced, resulting in waste of power / medium.

[0223] Taking these points into consideration, the present disclosure proposes a method for generating / defining a security key utilized in a security technology / protocol to ensure integrity and / or confidentiality of a control frame between a transmitting STA and a receiving STA.

[0224] The names and values ​​of fields, subfields, elements, parameters, keys, etc. proposed in this disclosure are exemplary and are not limited to the names and values. In addition, unless otherwise specified, an STA may be an AP STA or a non-AP STA.

[0225] FIG. 16 is a diagram for explaining the operation of the first STA according to the present disclosure.

[0226] In step S1610, the first STA can generate a control frame based on a security protocol.

[0227] For example, the security protocol may be one of the integrity check protocols for control frames, CCMP, or GCMP. Here, the integrity check protocol may be a security protocol based on the Galois message authentication code (GMAC) or the cipher-based message authentication code (CMAC).

[0228] In this regard, the security protocol may be applied to the control frame based on a security key for the control frame. In this case, the security key for the control frame may be configured / generated based on at least one of a security key for another type of frame (e.g., a data frame, a management frame, etc.) or a random value generated by the first STA.

[0229] For example, for individually addressed control frames and group addressed control frames, a method may be applied in which a security key for the control frame is constructed / generated based on a security key for another type of frame, or a method may be applied in which a security key for the control frame is constructed / generated based on a random number generated by the first SAT. For another example, a method may be applied in which a security key for the control frame is constructed / generated based on a security key for another type of frame, and a method may be applied in which a security key for the control frame is constructed / generated based on a random number generated by the first SAT for group addressed control frames, or vice versa.

[0230] Additionally, the security key for another type of frame may be at least one of PTK, GTK, IGTK, or BIGTK generated through a 4-way handshake process between the first STA and the second STA.

[0231] For example, if the control frame corresponds to an individually addressed control frame, the security key for the control frame may be the PTK. Additionally, if the control frame corresponds to a group addressed control frame, the security key for the control frame may be one of the GTK, the IGTK, or the BIGTK.

[0232] For another example, if the control frame corresponds to an individually addressed control frame, the security key for the control frame may be constructed by concatenating a first portion of the PTK and a first portion of the GTK. Furthermore, if the control frame corresponds to a group addressed control frame, the security key for the control frame may be constructed by concatenating a second portion of the PTK and a second portion of the GTK.

[0233] Additionally, the random number generated by the first STA may correspond to at least one of a PMK (e.g., a control PMK) or a GMK (e.g., a control GMK) generated by the first STA for the control frame. If a security key for the control frame is configured based on the random number, the security key for the control frame may correspond to a PTK (e.g., a control PTK) based on the PMK or a GTK (e.g., a control GTK) based on the GMK, and may be included in a KDE (key data encapsulation) format by the first STA and shared with the second STA. For example, the KDE format may be shared through a specific message (e.g., message 3) within a 4-way handshake procedure between the first STA and the second STA.

[0234] In this regard, the KDE format may include a control frame, an identifier (ID), a packet number, and information about the security key for the control frame. At this time, the security key for the control frame may be included in the KDE format in a packaged / encrypted state. If the first STA corresponds to an STA belonging to an AP MLD (multi-link device) and the second STA corresponds to an STA belonging to a non-AP MLD, the KDE format may further include information about a link ID for which the security key for the control frame is used. In addition, the packet number included in the KDE format may correspond to a packet number for the control frame at the time when the security key for the control frame is shared.

[0235] Thereafter, in step S1620, the first STA can transmit the control frame generated / configured as described above to the second STA.

[0236] The method described in the example of FIG. 16 may be performed by the first device (100) of FIG. 1. For example, one or more processors (102) of the first device (100) of FIG. 1 may be configured to generate a control frame based on a security protocol and transmit the control frame to the second STA via one or more transceivers. Furthermore, one or more memories (104) of the first device (100) may store commands for performing the method described in the example of FIG. 16 or the examples described below when executed by one or more processors (102).

[0237] FIG. 17 is a diagram for explaining the operation of a second STA according to the present disclosure.

[0238] In step S1710, the second STA may receive a control frame based on a security protocol from the first STA. Thereafter, in step S1720, the second STA may perform verification and decoding on the received control frame.

[0239] In this regard, the control frame can be verified and decoded based on a security key for the control frame. Furthermore, the security key for the control frame can be configured based on at least one of a security key for another type of frame or a random value generated by the first STA.

[0240] The specific configurations for generating / configuring security keys for control frames, security keys for other types of frames, KDE format for sharing security keys for control frames, security protocols, etc. are the same as those described in Fig. 16, so redundant descriptions are omitted.

[0241] The method described in the example of FIG. 17 may be performed by the second device (200) of FIG. 1. For example, one or more processors (202) of the second device (200) of FIG. 1 may be configured to receive a control frame based on a security protocol from the first STA through one or more transceivers, and to perform verification and decoding on the control frame. Furthermore, one or more memories (204) of the second device (200) may store commands for performing the method described in the example of FIG. 17 or the examples described below when executed by one or more processors (202).

[0242] The examples of FIGS. 16 and 17 may correspond to some of the various examples of the present disclosure. Below, various examples of the present disclosure, including the examples of FIGS. 16 and 17, will be described in more detail.

[0243] Example 1

[0244] Unlike data frames and management frames, control frames in existing wireless LAN systems do not support protection of the data within them. However, this disclosure assumes that a security protocol is applied to control frames. Specifically, this disclosure proposes various methods for generating a security key used when a security protocol is applied to a control frame.

[0245] In this regard, it is assumed, but not limited to, that the security key generated by the proposed method of the present disclosure is used to protect control frames. In other words, the security key(s) generated by the proposed method of the present disclosure may be used / applied to protect control frames and / or other portions within the frame defined at the MAC layer. For example, the security key(s) may be used / applied when a security protocol (e.g., CCMP, GCMP, BIP, etc.) is utilized to protect the MAC header.

[0246] In the present disclosure, the security key used for individually addressed control frames is referred to as a CPTK (control PTK) to distinguish it from the existing PTK. In addition, the security key used for group addressed control frames is referred to as a CGTK (control GTK) or CIGTK (control IGTK) to distinguish it from the existing GTK / IGTK / BIGTK.

[0247] For example, individually addressed control frames may include compressed block ACK frames, trigger frames, compressed block ACK request frames, multi-TID block ACK request frames, etc. When a security protocol based on CCMP, GCMP, or BIP is applied to the control frames, the CPTK according to the proposed method of the present disclosure may be utilized. In addition, group addressed control frames may include multi-STA block ACK frames, trigger frames, etc. When a security protocol based on CCMP, GCMP, or BIP is applied to the control frames, the CGTK according to the proposed method of the present disclosure may be utilized.

[0248] The aforementioned CPTK and CGTK can be generated based on at least one of the specific methods described below. While the proposed method of the present disclosure is described based on a 4-way handshake procedure, it is not limited thereto and can also be utilized in a 2-way handshake procedure.

[0249] Example 1-1

[0250] This embodiment is about a method of utilizing a security key generated through a 4-way handshake between an AP and a non-AP STA (e.g., see the description of FIG. 8).

[0251] Specifically, the PTK is defined to be used to protect existing individually addressed data frames. Regarding the protection of control frames, the PTK can be used when a security protocol is applied to individually addressed control frames.

[0252] GTK is defined to be used to protect existing group-addressed data frames. Regarding the protection of control frames, GTK can be used when a security protocol is applied to group-addressed control frames.

[0253] IGTK is defined to be used for protecting existing management frames. Regarding the protection of control frames, the IGTK can be used when a security protocol is applied to group-addressed control frames.

[0254] BIGTK is defined to be used for protecting beacon frames, which are a type of existing management frame. Regarding the protection of control frames, the BIGTK can be used when a security protocol is applied to group-addressed control frames.

[0255] Example 1-2

[0256] This embodiment relates to a method for generating a CPTK and a CGTK by utilizing a PTK and / or GTK generated through a 4-way handshake between an AP and a non-AP STA (e.g., see the description of FIG. 8).

[0257] Specifically, the PTK generated as a result of the 4-way handshake can be divided into multiple keys, such as KCK, KEK, and TK, by dividing them into bits of a certain length. At this time, TK can be utilized to protect individually addressed data frames. Furthermore, in the case of GTK, TK corresponding to a certain length of bits can be utilized to protect group addressed data frames.

[0258] In this regard, the TK of PTK and the TK of GTK can be divided into a certain portion (e.g., 1 / n), and the TK of PTK and the TK of GTK can be concatenated to generate the TK of CPTK and the TK of CGTK.

[0259] For example, if the protection of the control frame is performed based on a cipher suite using a TK having a length of 256 bits, the TK of the CPTK and the TK of the CGTK can be generated in the following manner when the TK of the PTK and the TK of the GTK have a length of 256 bits. Specifically, the TK of the CPTK can be generated / set by concatenating the front part of the TK of the PTK divided in half and the front part of the TK of the GTK divided in half. In addition, the TK of the CGTK can be generated / set by concatenating the rear part of the TK of the PTK divided in half and the rear part of the TK of the GTK divided in half.

[0260] In relation to that method, CPTK and CGTK can also be generated by replacing GTK with IGTK or BIGTK.

[0261] Example 1-3

[0262] This embodiment describes a method for generating a CGTK based on a value randomly generated by an AP.

[0263] Specifically, in a 4-way handshake procedure (e.g., see the description of FIG. 8), the AP may generate a GTK based on a randomly generated value, GMK, and share the GTK with the STA to perform protection for group-addressed data frames. The AP may include GTK / IGTK / BIGTK(s) in message 3 (e.g., see step S830 of FIG. 8) in the 4-way handshake procedure. At this time, the GTK / IGTK / BIGTK(s) may be included in a key data element / encapsulation (KDE) corresponding to each key, which may be wrapped / encrypted based on a KEK composed of some bits of the PTK. The wrapped / encrypted KDE format may be included in a key data field in message 3 and transmitted to the STA(s).

[0264] Based on this method, the present disclosure proposes a method in which an AP includes a CGTK based on a randomly generated value (e.g., CGMK) in a CGTK KDE format and transmits it to STA(s) that support protection for control frames. In this case, as in GTK / IGTK / BIGTK-based methods, the CGTK KDE including the CGTK can be shared via message 3 in a form packed / encrypted based on a KEK.

[0265] In this regard, the CGTK KDE based on the proposed method of the present disclosure can be configured in a form as shown in Fig. 18.

[0266] FIG. 18 illustrates CGTK KDE formats according to an embodiment of the present disclosure.

[0267] Figure 18 (a) illustrates a general CGTK KDE format, and Figure 18 (b) illustrates an MLO CGTK KDE format for multi-link operation (MLO).

[0268] Referring to (a) of Fig. 18, the CGTK KDE format may include a key ID field, a packet number (PN) field, and a CGTK field. The format illustrated in (a) of Fig. 18 is an example, and the configuration and order of the included fields / information are not limited thereto.

[0269] The Key ID field may include a value / information for a Key ID corresponding to the CGTK. The PN field may include a PN value for a control frame at the time of sharing the CGTK with the AP, as a value used for replay protection. In this regard, the transmitting STA may include a value higher than the value as the PN value of a subsequent control frame (e.g., a subsequent control frame). The CGTK field may include a value (e.g., CGTK) utilized when applying security to a group-addressed control frame.

[0270] Referring to (b) of Fig. 18, the MLO CGTK KDE format may include a key ID field, a packet number (PN) field, a link ID field, and a CGTK field. The format illustrated in (b) of Fig. 18 is an example, and the configuration and order of the included fields / information are not limited thereto.

[0271] In this regard, the MLO CGTK KDE format can be used for CGTK between an AP MLD (multi-link device) and a STA MLD (e.g., a non-AP MLD). For example, in relation to MLO, the MLO CGTK KDE format can be transmitted and received between an STA (e.g., an AP) affiliated with an AP MLD and an STA (e.g., a non-AP STA) affiliated with a STA MLD.

[0272] The Key ID field may contain a value / information for a Key ID corresponding to a CGTK. The PN field may contain a PN value for a control frame at the time of sharing the AP MLD and CGTK, as a value used for replay protection. The CGTK field may contain a value (e.g., CGTK) utilized when applying security to group-addressed control frames.

[0273] Additionally, the Link ID field may include a value indicating the ID of the link for which the CGTK is utilized. In other words, based on the MLD format, the KDE format may be configured so that the CGTK can be used on a link-by-link basis (e.g., at the link level). In this case, the CGTK may be configured to use different values ​​for each link.

[0274] For example, if the link ID field is 4 bits long, it may contain a value corresponding to the link ID. Alternatively, if the link ID field is 8 bits long, each bit may correspond to / map to each link, and whether the CGTK is utilized may be indicated through the value of the nth bit corresponding to / mapped to each link (e.g., 0 or 1).

[0275] Example 1-4

[0276] This embodiment describes a method for generating a CPTK based on a value randomly generated by an AP.

[0277] Specifically, in a 4-way handshake procedure (e.g., see the description of FIG. 8), the AP generates a GTK based on a randomly generated value, GMK, and shares the GTK with the STA to perform protection for group-addressed data frames. In the case of the existing PTK, the AP and the STA share their respective Nonce values ​​and key MIC values ​​through Message 1 and Message 2 (e.g., see Steps S810 and S820 of FIG. 8) to generate the same PTK between them.

[0278] In contrast, as in the GTK method, the present disclosure proposes a method of deriving and sharing a CPTK by setting a value randomly generated by the AP as a control PMK (CPMK) in relation to the CPTK for protection of a control frame.

[0279] In this case, a new KDE (hereinafter, CPTK KDE) needs to be defined for CPTK to be shared in KDE format, such as in a GTK / IGTK / BIGTK-based manner, and the CPTK KDE based on the proposed method of the present disclosure can be configured in a form as shown in FIG. 19.

[0280] FIG. 19 illustrates CPTK KDE formats according to an embodiment of the present disclosure.

[0281] Figure 19 (a) illustrates a general CPTK KDE format, and Figure 19 (b) illustrates an MLO CPTK KDE format for multi-link operation (MLO).

[0282] Referring to (a) of Fig. 19, the CPTK KDE format may include a key ID field, a packet number (PN) field, and a CPTK field. The format illustrated in (a) of Fig. 19 is an example, and the configuration and order of the included fields / information are not limited thereto.

[0283] The Key ID field may include a value / information regarding the Key ID corresponding to the CPTK. The PN field may include a PN value for the control frame at the time of sharing the CPTK with the AP, as a value used for replay protection. In this regard, the transmitting STA may include a value higher than that value as the PN value of a subsequent control frame (e.g., a subsequent control frame). The CPTK field may include a value (e.g., a CPTK) utilized when applying security to individually addressed control frames.

[0284] Referring to (b) of Fig. 19, the MLO CPTK KDE format may include a key ID field, a packet number (PN) field, a link ID field, and a CPTK field. The format illustrated in (b) of Fig. 19 is an example, and the configuration and order of the included fields / information are not limited thereto.

[0285] In this regard, the MLO CPTK KDE format can be used for CPTK between an AP MLD and a STA MLD (e.g., a non-AP MLD). For example, in relation to MLO, the MLO CPTK KDE format can be transmitted and received between an STA (e.g., an AP) belonging to an AP MLD and an STA (e.g., a non-AP STA) belonging to a STA MLD.

[0286] The Key ID field may contain a value / information for the Key ID corresponding to the CPTK. The PN field may contain a PN value for the control frame at the time of sharing the AP MLD and CPTK, as a value used for replay protection. The CPTK field may contain a value (e.g., CPTK) used when applying security to individually addressed control frames.

[0287] Additionally, the Link ID field may include a value indicating the ID of the link for which the CPTK is utilized. In other words, based on the MLD format, the KDE format may be configured so that the CPTK can be used on a link-by-link basis (e.g., at the link level). In this case, the CPTK may be configured to use different values ​​for each link.

[0288] For example, if the link ID field is 4 bits long, it may contain a value corresponding to the link ID. Alternatively, if the link ID field is 8 bits long, each bit may correspond to / map to each link, and the value of the nth bit corresponding to / mapped to each link (e.g., 0 or 1) may indicate whether the corresponding CPTK is utilized.

[0289] In relation to the aforementioned methods, to prevent replay attacks, the receiving STA can verify the packet number (PN) value within the frame. In existing wireless LAN systems, when using IGTK, verification of the frame is performed based on the integrity PN (IPN), and when using BIGTK, verification of the frame is performed based on the beacon integrity PN (BIPN).

[0290] In this regard, the present disclosure proposes a method for performing verification on a control frame based on at least one of the values ​​as in the following examples when a security key for the control frame is used.

[0291] For example, a PN defined in an existing wireless LAN system may be utilized. Specifically, when a security protocol is applied to a data frame using a PTK / GTK, verification of the frame may be performed based on the PN. Based on this, when a security protocol for integrity and / or confidentiality of a control frame is applied using a CPTK and / or CGTK, the transmitting STA may include the PN in the control frame, which may be used for replay protection. In other words, a receiving STA may verify the control frame based on the PN value included in the control frame for which a security protocol for integrity and / or confidentiality based on a CPTK or CGTK is utilized.

[0292] For another example, an IPN defined in an existing wireless LAN system may be utilized. Specifically, when a security protocol is applied to a management frame using the IGTK, verification of the frame may be performed based on the IPN. Based on this, when a security protocol for integrity and / or confidentiality of a control frame is applied using the CPTK and / or CGTK, the transmitting STA may include the IPN in the control frame, which may be used for replay protection. In other words, the receiving STA may verify the control frame based on the IPN value included in the control frame for which the security protocol for integrity and / or confidentiality based on the CPTK or CGTK is utilized.

[0293] As another example, the BIPN defined in the existing wireless LAN system can be utilized. Specifically, when a security protocol is applied to a beacon frame using the BIGTK, verification of the frame can be performed based on the BIPN. Based on this, when a security protocol for integrity and / or confidentiality of a control frame is applied using the CPTK and / or CGTK, the transmitting STA can include the BIPN in the control frame, which can be used for replay protection. In other words, the receiving STA can verify the control frame based on the BIPN value included in the control frame for which the security protocol for integrity and / or confidentiality based on the CPTK or CGTK is utilized.

[0294] As another example, a newly defined CPN (control PN) may be utilized to protect control frames. Specifically, when a security protocol for integrity and / or confidentiality of a control frame is applied using a CPTK and / or a CGTK, the transmitting STA may include the CPN in the control frame, which may be used for replay protection. That is, based on the CPN value included in the control frame for which a security protocol for integrity and / or confidentiality based on a CPTK or CGTK is utilized, the receiving STA may verify the control frame.

[0295] When a CPTK and / or CGTK is generated using the proposed method of the present disclosure, the AP needs to share with the STA, through a separate method / signaling, information related to the packet number for the control frame defined by one of the aforementioned methods. For example, information related to the packet number of the control frame used so far may be shared during the 4-way handshake process, before the 4-way handshake process, or after the 4-way handshake process.

[0296] Example 2

[0297] This embodiment is about a specific method for performing protection for a control frame based on the proposed method of the present disclosure.

[0298] The situations described below in this embodiment assume that (all) transmitting STAs and receiving STA(s) share a common understanding of whether they support the use of control frames over BIP, CCMP, or GCMP and / or how control frames resulting from security being applied to the control frames are constructed (e.g., BIP, CCMP / GCMP MPDU format).

[0299] Example 2-1

[0300] First, we describe the specific operation in a situation where (all) transmitting STAs and receiving STA(s) support the use of protection of control frames through an integrity check protocol based on BIP for control frames.

[0301] The receiving STA and the transmitting STA(s) may generate a security key for the control frame using the PTK and GTK generated through the 4-way handshake (e.g., based on Embodiment 1-1 and / or Embodiment 1-2). Additionally or alternatively, the receiving STA and the transmitting STA(s) may establish a security key for the control frame based on the information shared about the CPTK and / or CGTK during the 4-way handshake (e.g., based on Embodiment 1-3 and / or Embodiment 1-4).

[0302] A transmitting STA can use the security key for the control frame to generate a MIC for some or all of the information contained in the frame body within the MPDU. Based on this, the transmitting STA can transmit a control frame that includes the security key for the control frame used to generate the MIC, a value indicating the packet number of the control frame, and the generated MIC value.

[0303] A receiving STA can configure an AAD for a control frame based on information in the control frame received from the transmitting STA. Thereafter, using the AAD and the security key for the control frame, the receiving STA can calculate a MIC based on the corresponding MPDU. At this time, the receiving STA can derive the MIC value by performing the same process as the transmitting STA uses to calculate the MIC based on the corresponding MPDU.

[0304] The receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the control frame). If the two MIC values ​​are the same, the receiving STA can follow the information in the acquired MPDU. Conversely, if the two MIC values ​​are not the same, the receiving STA can recognize that at least one piece of information in the acquired MPDU has been modified by a third party STA (e.g., an attacking STA) or has been damaged during transmission and reception, and can discard it.

[0305] Additionally, the receiving STA can compare the PN value of the control frame it has with the PN value in the control frame received from the transmitting STA. If the PN value in the received control frame is greater than the PN value in the control frame held by the receiving STA, the receiving STA can follow the information in the acquired MPDU. Conversely, if the PN value in the received control frame is less than or equal to the PN value in the control frame held by the receiving STA, the receiving STA can recognize it as a replay attack and discard it.

[0306] Example 2-2

[0307] Next, we describe specific operations in a situation where (all) transmitting STAs and receiving STA(s) support the protection utilization of control frames through a security protocol based on CCMP or GCMP.

[0308] The receiving STA and the transmitting STA(s) may generate a security key for the control frame using the PTK and GTK generated through the 4-way handshake (e.g., based on Embodiment 1-1 and / or Embodiment 1-2). Additionally or alternatively, the receiving STA and the transmitting STA(s) may establish a security key for the control frame based on the information shared about the CPTK and / or CGTK during the 4-way handshake (e.g., based on Embodiment 1-3 and / or Embodiment 1-4).

[0309] The transmitting STA can configure the AAD for the control frame based on the information in the MAC header of the MPDU it has configured (e.g., the frame control field, duration field, RA field, TA field, etc.). Afterwards, encryption for the MDSU can be performed using the security key for the AAD and the control frame. The transmitting STA can configure the MPDU and transmit it by including the MAC header, CCMP / GCMP header, cipher text, (encrypted) MIC, and FCS.

[0310] A receiving STA can configure an AAD for a control frame based on information in the MAC header of the MPDU received from the transmitting STA. Thereafter, the receiving STA can decrypt the MSDU using the AAD and the security key for the control frame.

[0311] A receiving STA can obtain a plaintext MPDU and an MIC value based on the MPDU by performing decryption based on CCMP using the AAD configured by the receiving STA for the control frame and the security key for the control frame. At this time, the receiving STA can derive the MIC value by performing the same encryption process for the MPDU as the transmitting STA.

[0312] The receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the control frame). If the two MIC values ​​are the same, the receiving STA can follow the information in the acquired plaintext MPDU. Conversely, if the two MIC values ​​are not the same, the receiving STA can recognize that at least one piece of information in the acquired plaintext MPDU has been modified by a third party STA (e.g., an attacking STA) or has been damaged during transmission and reception, and can discard it.

[0313] For CCMP, where the MIC is encrypted, the receiving STA can perform an integrity check using the MIC generated / calculated based on the plaintext derived by decrypting the MPDU. For GCMP, where the MIC is not encrypted, the receiving STA can first perform an integrity check using the value of the MIC field of the MPDU, and if the MIC values ​​match, decrypt the MPDU.

[0314] Additionally, the receiving STA can compare the PN value of the control frame it has with the PN value in the control frame received from the transmitting STA. If the PN value in the received control frame is greater than the PN value in the control frame held by the receiving STA, the receiving STA can follow the information in the acquired MPDU. Conversely, if the PN value in the received control frame is less than or equal to the PN value in the control frame held by the receiving STA, the receiving STA can recognize it as a replay attack and discard it.

[0315] Example 3

[0316] This embodiment is about a specific method for performing protection on a MAC header based on the proposed method of the present disclosure.

[0317] The situations described below in this embodiment assume that (all) transmitting STAs and receiving STA(s) share a common understanding of whether they support the use of MAC headers over BIP, CCMP, or GCMP and / or how frames resulting from security being applied to MAC headers (e.g., BIP, CCMP / GCMP MPDU formats) are constructed.

[0318] Example 3-1

[0319] First, we describe the specific operation in a situation where (all) transmitting STAs and receiving STA(s) support the protection utilization of the MAC header through an integrity check protocol based on a BIP for the MAC header.

[0320] The receiving STA and transmitting STA(s) may generate a security key for the MAC header using the PTK and GTK generated through the 4-way handshake (e.g., based on Embodiment 1-1 and / or Embodiment 1-2). Additionally or alternatively, the receiving STA and transmitting STA(s) may set a security key for the MAC header based on information shared about the CPTK and / or CGTK during the 4-way handshake (e.g., based on Embodiment 1-3 and / or Embodiment 1-4).

[0321] A transmitting STA can use a security key for the MAC header to generate a MIC for some or all of the information contained in the MAC header within the MPDU. Based on this, the transmitting STA can transmit a frame containing the security key for the MAC header used to generate the MIC, a value indicating the packet number of the MAC header, and the generated MIC value.

[0322] A receiving STA can configure an AAD for the MAC header based on the information in the MAC header within the MPDU received from the transmitting STA. Thereafter, using the security key for the AAD and MAC header, the receiving STA can calculate a MIC based on the MAC header. At this time, the receiving STA can derive the MIC value by performing the same process as the transmitting STA uses to calculate the MIC based on the MAC header.

[0323] The receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the MAC header / frame). If the two MIC values ​​are the same, the receiving STA can follow the information in the acquired MAC header. Conversely, if the two MIC values ​​are not the same, the receiving STA can recognize that at least one piece of information in the acquired MAC header has been modified by a third party STA (e.g., an attacking STA) or has been corrupted during transmission / reception, and can discard it.

[0324] Additionally, the receiving STA can compare the PN value of the MAC header it has with the PN value of the MAC header received from the transmitting STA. If the PN value of the received MAC header is greater than the PN value of the MAC header held by the receiving STA, the receiving STA can follow the information of the acquired MAC header. Conversely, if the PN value of the received MAC header is less than or equal to the PN value of the MAC header held by the receiving STA, the receiving STA can recognize it as a replay attack and discard it.

[0325] Example 3-2

[0326] Next, we describe specific operations in a situation where (all) transmitting STAs and receiving STA(s) support the protection utilization of MAC headers through a security protocol based on CCMP or GCMP.

[0327] The receiving STA and transmitting STA(s) may generate a security key for the MAC header using the PTK and GTK generated through the 4-way handshake (e.g., based on Embodiment 1-1 and / or Embodiment 1-2). Additionally or alternatively, the receiving STA and transmitting STA(s) may set a security key for the MAC header based on information shared about the CPTK and / or CGTK during the 4-way handshake (e.g., based on Embodiment 1-3 and / or Embodiment 1-4).

[0328] A transmitting STA can configure an AAD for a MAC header based on some or all of the information in the MAC header of the MPDU it constructs. Then, encryption can be performed on the MAC header using the security key for the AAD and MAC header. The transmitting STA can transmit an MPDU composed of a MAC header for sharing, a CCMP / GCMP header of the MAC header, ciphertext, (encrypted) MIC, and FCS.

[0329] A receiving STA can configure an AAD for a MAC header based on information in the MAC header for sharing of an MPDU received from a transmitting STA. Thereafter, the receiving STA can decrypt the encrypted MAC header using the security key for the AAD and MAC header.

[0330] The receiving STA can obtain the MAC header in plaintext form and the MIC value based on the MAC header by performing decryption based on CCMP using the AAD and security key configured by the receiving STA for the MAC header. At this time, the receiving STA can derive the MIC value by performing the same encryption process for the MAC header as the transmitting STA.

[0331] The receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the MAC header / frame). If the two MIC values ​​are the same, the receiving STA can follow the information in the acquired plaintext MAC header. Conversely, if the two MIC values ​​are not the same, the receiving STA can recognize that at least one piece of information in the acquired plaintext MAC header has been modified by a third party STA (e.g., an attacking STA) or has been corrupted during transmission / reception, and can discard it.

[0332] For CCMP, where the MIC is encrypted, the receiving STA can perform an integrity check using the MIC generated / calculated based on the plaintext derived by decrypting the MAC header. For GCMP, where the MIC is not encrypted, the receiving STA can first perform an integrity check using the value of the MIC field in the MAC header, and if the MIC values ​​match, decrypt the MAC header.

[0333] In addition, the receiving STA can compare the PN value of the MAC header it has with the PN value in the CCMP / GCMP header of the MAC header received from the transmitting STA. If the PN value in the CCMP / GCMP header of the received MAC header is greater than the PN value in the MAC header held by the receiving STA, the receiving STA can follow the information in the acquired MAC header. Conversely, if the PN value in the CCMP / GCMP header of the received MAC header is less than or equal to the PN value in the MAC header held by the receiving STA, the receiving STA can recognize it as a replay attack and discard it.

[0334] Example 4

[0335] This embodiment relates to specific operations of a transmitting STA (e.g., an AP, an STA belonging to an AP MLD) and a receiving STA (e.g., a non-AP STA, an STA belonging to a non-AP MLD) according to the proposed method of the present disclosure.

[0336] In relation to this operation, it is assumed that the transmitting STA supports security application for control frames.

[0337] For example, FIGS. 20 and 21 illustrate the operation of a transmitting STA and the operation of a receiving STA based on a security key generated through the method described in Embodiment 1-1 and / or Embodiment 1-2 described above. In other words, FIGS. 20 and 21 relate to the operation of generating a security key for a control frame based on an existing security key.

[0338] FIG. 20 is a diagram illustrating an example of a transmitting STA operation according to an embodiment of the present disclosure.

[0339] Referring to Figure 20, a transmitting STA may transmit a message requesting confirmation of whether a receiving STA supports security application for control frames (S2010). For example, the request may be performed during the (re)association process or in a separate process at a later time.

[0340] Thereafter, the transmitting STA can receive a response message to the message of step S2010 from the receiving STA, and can check whether security application for the control frame of the receiving STA is supported through the response message (S2020).

[0341] If the receiving STA supports security application for control frames (e.g., if the transmitting STA receives a message including a response that the receiving STA supports security application for control frames), the transmitting STA may generate a security key for the control frame using an existing security key (S2030). For example, the transmitting STA and the receiving STA may generate a security key (e.g., CPTK, CGTK) for the control frame based on the proposed method of the present disclosure using the PTK and / or GTK that they equally have after the 4-way handshake procedure.

[0342] If a security key for a control frame is generated, the transmitting STA can transmit a control frame (e.g., a control frame with security applied, a protected control frame) obtained as a result of applying security to the control frame using the security key (S2040).

[0343] FIG. 21 is a diagram illustrating an example of a receiving STA operation according to an embodiment of the present disclosure.

[0344] Referring to Figure 21, a receiving STA may receive a message from a transmitting STA requesting confirmation of support for security application for control frames (S2110). For example, the request may be made during the (re)association process or in a separate process at a later time.

[0345] Thereafter, the receiving STA may transmit a response message to the message of step S2010 to the transmitting STA, and the response message may include information on whether the receiving STA supports security application for the control frame (S2120).

[0346] If the receiving STA supports security application for control frames (e.g., if the receiving STA transmits a message including a response indicating that it supports security application for control frames), the receiving STA may generate a security key for the control frame using an existing security key (S2130). For example, the transmitting STA and the receiving STA may generate a security key (e.g., CPTK, CGTK) for the control frame based on the proposed method of the present disclosure using the PTK and / or GTK that they both have after the 4-way handshake procedure.

[0347] If a security key is generated for a control frame, the receiving STA can verify and decode the secured control frame based on the security key (S2140). If the control frame is verified as valid, the receiving STA can accept the values / information contained in the control frame.

[0348] As another example, FIGS. 22 and 23 illustrate the operation of a transmitting STA and the operation of a receiving STA based on a security key generated through the method described in Embodiments 1-3 and / or 1-4 described above. In other words, FIGS. 22 and 23 relate to the operation of generating / deriving a security key for a control frame based on a value randomly generated by the transmitting STA.

[0349] FIG. 22 is a diagram for explaining another example of a transmitting STA operation according to an embodiment of the present disclosure.

[0350] Referring to Figure 22, a transmitting STA may transmit a message requesting confirmation of whether a receiving STA supports security application for control frames (S2210). For example, the request may be performed during the (re)association process or in a separate process at a later time.

[0351] Thereafter, the transmitting STA can receive a response message to the message of step S2210 from the receiving STA, and can check whether security application for the control frame of the receiving STA is supported through the response message (S2220).

[0352] If the receiving STA supports security application for control frames (e.g., if the transmitting STA receives a message including a response that the receiving STA supports security application for control frames), the transmitting STA may generate / set a security key (e.g., CPTK, CGTK) for the control frame based on randomly generated value(s) (e.g., CPMK, CGMK) and share / transmit it to the receiving STA in a packaged / encrypted state (S2230). For example, the transmitting STA may share the generated / set security key in a packaged / encrypted state in a 4-way handshake message. Specifically, based on the proposed method of the present disclosure, the transmitting STA may include the security key for the control frame in the form of KDE in message 3 in the 4-way handshake process and transmit it to the receiving STA.

[0353] If a security key for a control frame is generated / shared, the transmitting STA can transmit a control frame (e.g., a control frame with security applied, a protected control frame) obtained as a result of applying security to the control frame using the security key (S2240).

[0354] FIG. 23 is a diagram for explaining another example of a receiving STA operation according to an embodiment of the present disclosure.

[0355] Referring to Figure 23, a receiving STA may receive a message from a transmitting STA requesting confirmation of whether security application for control frames is supported (S2310). For example, the request may be made during the (re)association process or in a separate process at a later time.

[0356] Thereafter, the receiving STA may transmit a response message to the message of step S2310 to the transmitting STA, and the response message may include information on whether security application for the control frame of the receiving STA is supported (S2320).

[0357] If the receiving STA supports security application for control frames (e.g., if the receiving STA sends a message including a response indicating that it supports security application for control frames), the receiving STA can obtain a security key for the control frame based on the packaged / encrypted format received from the transmitting STA (S2330). For example, the receiving STA can obtain the security key for the control frame in a packaged / encrypted state within the message received during the 4-way handshake process. Specifically, the receiving STA can obtain the CPTK and / or CGTK included in Message 3 and set them as the security key for the control frame.

[0358] If a security key for a control frame is generated / obtained / set, the receiving STA can verify and decode the secured control frame based on the security key (S2340). If the control frame is verified as valid, the receiving STA can accept the values / information contained in the control frame.

[0359] Additionally, the operation of applying security to a control frame described through FIGS. 20 to 23 can be extended to apply security to a MAC header (e.g., see Example 3).

[0360] Figure 24 illustrates an overall operation flowchart of PPDU transmission and reception according to an embodiment of the present disclosure.

[0361] Referring to FIG. 24, the PPDU transmission and reception may be performed between a transmitting STA and a receiving STA based on the proposed method(s) described above in the present disclosure. Some of the steps (or sub-steps) illustrated in FIG. 24 may be omitted or modified.

[0362] For example, a transmitting STA can configure BW and RU allocation (e.g., puncturing patterns, etc.), and allocate multiple RUs to specific users / STAs based on multiple RU aggregation combinations (S10). In this regard, the transmitting STA can perform channel access operations.

[0363] A transmitting STA may configure a PPDU (S20). For example, the PPDU may be a SU / MU PPDU based on an EHT variant, a UHR variant, etc. For example, the PPDU may include EHT-SIG, UHR-SIG, etc. in the SIG part. In this regard, the transmitting STA may configure the PPDU based on the BW, RU allocation, multi-RU set, etc. determined through step S10. For example, the U-SIG included in the PPDU may include n-bit (e.g., 4-bit) information for BW and puncturing pattern, and the common field of the EHT / UHR-SIG may include m-bit (e.g., 8-bit) information for RU allocation, multi-RU set, etc.

[0364] At this time, before configuring the corresponding PPDU, the transmitting STA may generate a security key for the control frame based on information shared during a 4-way handshake process with the receiving STA (e.g., an existing security key, PTK, GTK, etc.). Additionally or alternatively, the transmitting STA may set a security key for the control frame based on shared information about the CPTK and / or GPTK during the 4-way handshake process (e.g., a value randomly generated by the transmitting STA). Using the security key for the corresponding control frame, security may be applied to the control frame. The transmitting STA may perform an operation of applying / including the value / information derived / generated as a result to the control frame.

[0365] The transmitting STA may transmit the PPDU configured through step S20 to the receiving STA (S30). During the execution of this step, the transmitting STA may perform at least one of the following operations: CSD, spatial mapping, IDFT / IFFT operation, and GI insertion.

[0366] In this regard, the U-SIG and EHT / UHR SIG within a PPDU can be transmitted based on multiple OFDM symbols. For example, one OFDM symbol can contain 26-bit information. The 26-bit information can include the 4-bit BW information described above. Instead of the 26-bit information, any m-bit information can be used.

[0367] For 26-bit information, BCC coding with 1 / 2 sub-efficiency can be applied. Interleaving by an interleaver can be applied to BCC coded bits (e.g., 52 bits). Constellation mapping by a constellation mapper can be performed on the interleaved 52 bits. Specifically, a BPSK module can be applied to generate 52 BPSK symbols. The 52 BSPK symbols can be matched to the remaining frequency range (-28 to +28) excluding the DC tone and pilot tones (-21, -7, +7, +21). Thereafter, the corresponding PPDU can be transmitted to the receiving STA through phase rotation, CSD, spatial mapping, IDFT / IFFT operations, etc.

[0368] The receiving STA can receive all or part of the transmitted PPDU as described above (S40).

[0369] The sub-steps of step S40 may be determined based on the aforementioned step S30. In other words, step S40 may perform operations for restoring the results of the CSD, spatial mapping, IDFT / IFFT operations, GI insertion operations, etc. applied in step S30.

[0370] A receiving STA can obtain information about the BW, RU allocation, multi-RU set, etc. of the PPDU by decoding information contained in the U-SIG or EHT / UHR-SIG included in the PPDU (S50). Through this, the receiving STA can complete decoding of other fields / symbols of the received PPDU.

[0371] As a result, the receiving STA can decode the data field included in the PPDU through step S50. Thereafter, the receiving STA can perform a processing operation to transmit the data decoded from the data field to a higher layer (e.g., MAC layer). In addition, if the upper layer instructs the PHY layer to generate a signal in response to the data transmitted to the upper layer, the receiving STA can perform a subsequent operation.

[0372] For the data acquired through step S50, the receiving STA can generate a security key for the control frame based on information previously shared with the transmitting STA during a 4-way handshake process (e.g., an existing security key, PTK, GTK, etc.). Additionally or alternatively, the receiving STA can obtain information about a security key for the control frame based on shared information about the CPTK and / or GPTK during the 4-way handshake process (e.g., a value randomly generated by the transmitting STA). The receiving STA can recognize whether security is applied to the received control frame and can perform verification on the control frame using the security key for the control frame.

[0373] Protocols such as CCMP / GCMP, utilized in existing wireless LAN systems, cannot provide protection for control frames such as block ACK request frames. The present disclosure defines protocols such as CCMP / GCMP for control frames such as block ACK request frames, thereby providing a novel method for transmitting or receiving protected control frames. Furthermore, the proposed method of the present disclosure allows the generation and / or sharing of security keys used to secure control frames.

[0374] The embodiments described above are combinations of components and features of the present disclosure in a predetermined form. Each component or feature should be considered optional unless explicitly stated otherwise. Each component or feature may be implemented without being combined with other components or features. Furthermore, it is also possible to form embodiments of the present disclosure by combining some components and / or features. The order of operations described in the embodiments of the present disclosure may be changed. Some components or features of one embodiment may be included in another embodiment or may be replaced with corresponding components or features of another embodiment. It is self-evident that claims that do not have an explicit citation relationship in the patent claims may be combined to form embodiments or incorporated as new claims through post-application amendments.

[0375] It will be apparent to those skilled in the art that the present disclosure may be embodied in other specific forms without departing from the essential characteristics thereof. Therefore, the above detailed description should not be construed as limiting in any respect, but rather as illustrative. The scope of the present disclosure should be determined by a reasonable interpretation of the appended claims, and all modifications within the scope of equivalents of the present disclosure are intended to be included within the scope of the present disclosure.

[0376] The scope of the present disclosure includes software or machine-executable instructions (e.g., an operating system, an application, firmware, a program, etc.) that cause operations according to the methods of various embodiments to be executed on a device or a computer, and a non-transitory computer-readable medium having such software or instructions stored thereon and executable on the device or computer. Instructions that can be used to program a processing system to perform the features described in the present disclosure can be stored on / in a storage medium or a computer-readable storage medium, and a computer program product including such a storage medium can be used to implement the features described in the present disclosure. The storage medium can include, but is not limited to, high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid state memory devices, and can include non-volatile memory, such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid state storage devices. The memory optionally includes one or more storage devices remotely located from the processor(s). The memory or, alternatively, the non-volatile memory device(s) within the memory comprise a non-transitory computer-readable storage medium. The features described in this disclosure may be incorporated into software and / or firmware stored on any of the machine-readable media, which may control the hardware of the processing system and allow the processing system to interact with other mechanisms that utilize results according to embodiments of the present disclosure. Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments / containers.

[0377] The method proposed in this disclosure has been described with a focus on examples applied to IEEE 802.11-based systems, but can be applied to various wireless LANs or wireless communication systems in addition to IEEE 802.11-based systems.

Claims

1. A step of generating a control frame based on a security protocol by the first station (STA); and A step of transmitting the control frame to the second STA by the first STA, The above security protocol is applied to the control frame based on a security key for the control frame, A method wherein the security key for the control frame is configured based on at least one of a security key for another type of frame or a random value generated by the first STA.

2. In paragraph 1, The above other type of frame is either a data frame or a management frame.

3. In paragraph 1, A method wherein the security key for the above different type of frame is at least one of a pairwise transient key (PTK), a group temporal key (GTK), an integrity GTK (IGTK), or a beacon integrity GTK (BIGTK) generated through a 4-way handshake process between the first STA and the second STA.

4. In paragraph 3, A method wherein the security key for the control frame is the PTK, based on the fact that the control frame corresponds to an individually addressed control frame.

5. In paragraph 3, A method wherein, based on the control frame being a group addressed control frame, the security key for the control frame is one of the GTK, the IGTK, or the BIGTK.

6. In paragraph 3, Based on the fact that the above control frame corresponds to an individually addressed control frame, the security key for the control frame is constructed by concatenating a first part of the PTK and a first part of the GTK, A method wherein, based on the control frame corresponding to a group-addressed control frame, a security key for the control frame is constructed by concatenating a second part of the PTK and a second part of the GTK.

7. In paragraph 1, The random number corresponds to at least one of a pairwise master key (PMK) or a group master key (GMK) generated by the first STA for the control frame, A method in which a security key for the control frame corresponds to at least one of a PTK based on the PMK or a GTK based on the GMK, and is included in a KDE (key data encapsulation) format by the first STA and shared with the second STA.

8. In paragraph 7, A method wherein the above KDE format comprises the control frame including an identifier of a security key, a packet number, and information about the security key for the control frame.

9. In paragraph 8, A method wherein the KDE format further includes information on a link ID for which a security key for the control frame is used, based on the fact that the first STA corresponds to an STA belonging to an AP MLD (multi-link device) and the second STA corresponds to an STA belonging to a non-AP MLD.

10. In paragraph 8, The above packet number corresponds to the packet number for the control frame at the time when the security key for the control frame is shared.

11. In paragraph 7, A method wherein the above KDE format is shared through a specific message within a 4-way handshake procedure between the first STA and the second STA.

12. In paragraph 1, The above security protocol corresponds to one of an integrity check protocol for the control frame, CCMP (counter mode with cipher-block chaining message authentication code protocol), or GCMP (galois / counter mode protocol), The above integrity verification protocol is a method based on GMAC (galois message authentication code) or CMAC (cipher-based message authentication code).

13. One or more transmitters and receivers; and comprising one or more processors connected to said one or more transceivers, One or more of the above processors: By the first station (STA), a control frame is generated based on a security protocol; By the first STA, the control frame is set to be transmitted to the second STA, The above security protocol is applied to the control frame based on a security key for the control frame, A device wherein the security key for the control frame is configured based on at least one of a security key for another type of frame or a random value generated by the first STA.

14. A step of receiving a control frame based on a security protocol from a first STA by a second station (STA); and A step of performing verification and decoding on the control frame by the second STA, The above control frame is verified and decoded based on a security key for the above control frame, A method wherein the security key for the control frame is configured based on at least one of a security key for another type of frame or a random value generated by the first STA.

15. One or more transmitters and receivers; and comprising one or more processors connected to said one or more transceivers, One or more of the above processors: By the second station (STA), a control frame based on a security protocol is received from the first STA; By the second STA, verification and decoding of the control frame are set to be performed, The above control frame is verified and decoded based on a security key for the above control frame, A device wherein the security key for the control frame is configured based on at least one of a security key for another type of frame or a random value generated by the first STA.

16. One or more processors; and A processing device comprising one or more computer memories operatively connected to said one or more processors and storing instructions for performing a method according to any one of claims 1 to 12 based on execution by said one or more processors.

17. One or more non-transitory computer-readable media storing one or more instructions that are executed by one or more processors to control the performance of a method according to any one of claims 1 to 12.