Communication method and communication device
By receiving and utilizing frames sent by the second device for security protection and information identification, the problem of high energy consumption of AMP devices is solved, achieving low-energy and high-efficiency secure communication.
Patent Information
- Application Number
- PCT/CN2024/097858
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-06-06
- Publication Date
- 2025-12-11
AI Technical Summary
The limited energy harvesting efficiency and energy storage capacity of ambient energy supply equipment (AMP equipment) result in high energy consumption, making it difficult to meet energy-saving requirements.
The first device receives frames sent by the second device and uses these frames for security protection and identification information, thereby reducing the energy consumption of the AMP device and achieving secure communication.
It reduces the energy consumption of AMP devices, improves security and communication efficiency, and reduces safety-related operational failures caused by energy constraints.
Smart Images

Figure CN2024097858_11122025_PF_FP_ABST
Abstract
Description
Communication method and communication device TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, and more particularly, to a communication method and a communication device. BACKGROUND
[0002] With the development of technology, the requirement for energy saving of terminal devices is higher and higher. For example, since the energy harvesting efficiency and energy storage capability of ambient powered (AMP) devices are limited, it is necessary to reduce the energy consumption of the AMP devices as much as possible.
[0003] SUMMARY
[0004] The present application provides a communication method and a communication device. Each aspect involved in the present application is introduced below.
[0005] In a first aspect, a communication method is provided, comprising: receiving, by a first device, a first frame sent by a second device, the first frame being used for discovering a basic service set (BSS) or for triggering the first device to send or receive a data frame; wherein the first frame is further used for determining first information, the first information being used for security protection of frames sent and received by the first device.
[0006] In a second aspect, a communication method is provided, comprising: sending, by a second device, a first frame to a first device, the first frame being used for discovering a BSS or for triggering the first device to send or receive a data frame; wherein the first frame is further used for determining first information, the first information being used for security protection of frames sent and received by the first device.
[0007] In a third aspect, a communication device is provided, the communication device being a first device, comprising: a receiving unit, configured to receive a first frame sent by a second device, the first frame being used for discovering a BSS or for triggering the first device to send or receive a data frame; wherein the first frame is further used for determining first information, the first information being used for security protection of frames sent and received by the first device.
[0008] In a fourth aspect, a communication device is provided, the communication device being a second device, comprising: a sending unit, configured to send a first frame to a first device, the first frame being used for discovering a BSS or for triggering the first device to send or receive a data frame; wherein the first frame is further used for determining first information, the first information being used for security protection of frames sent and received by the first device.
[0009] In a fifth aspect, a communication device is provided, which comprises a processor, a memory, and a transceiver, the memory is configured to store one or more computer programs, the processor is configured to invoke the computer programs in the memory and control the transceiver to receive or send signals, so that the communication device performs part or all steps in the method of the first aspect.
[0010] In a sixth aspect, a communication device is provided, which comprises a processor, a memory, and a transceiver, the memory is configured to store one or more computer programs, the processor is configured to invoke the computer programs in the memory and control the transceiver to receive or send signals, so that the communication device performs part or all steps in the method of the second aspect.
[0011] In a seventh aspect, the embodiments of the present application provide a communication system, which comprises the first device and / or the second device described above. In some implementations, the system can further comprise other devices interacting with the first device and / or the second device in the schemes provided by the embodiments of the present application.
[0012] In an eighth aspect, the embodiments of the present application provide a computer readable storage medium, which stores a computer program, and the computer program causes a communication device to perform part or all steps in the methods of the aspects described above.
[0013] In a ninth aspect, the embodiments of the present application provide a computer program product, which comprises a non-transitory computer readable storage medium storing a computer program, and the computer program is operable to cause a communication device, for example, the first device or the second device to perform part or all steps in the methods of the aspects described above. In some implementations, the computer program product can be a software installation package.
[0014] In a tenth aspect, the embodiments of the present application provide a chip, which comprises a memory and a processor, and the processor can invoke and run a computer program from the memory to implement part or all steps described in the methods of the aspects described above.
[0015] In the embodiments of the present application, the second device sends the first frame to the first device, and the first device determines the first information based on the first frame, so as to protect the frames sent and received by the first device, thereby reducing the difficulty of the first device to obtain and maintain the first information and reducing the failure of security-related operations caused by energy limitation of the first device. BRIEF DESCRIPTION OF DRAWINGS
[0016] FIG. 1 is a schematic diagram of a communication system to which the embodiments of the present application are applied.
[0017] Figure 2 is a schematic diagram of a physical layer protocol data unit to which embodiments of the application are applicable.
[0018] Figure 3 is a schematic diagram of a medium access control frame to which embodiments of the application are applicable.
[0019] Figure 4 is a schematic flow diagram of an active scanning based access procedure to which embodiments of the application are applicable.
[0020] Figure 5 is a schematic flow diagram of a passive scanning based access procedure to which embodiments of the application are applicable.
[0021] Figure 6 is a schematic flow diagram of a 4-way handshake procedure to which embodiments of the application are applicable.
[0022] Figure 7 is a schematic diagram of an uplink transmission resource indicated by a first frame to which embodiments of the application are applicable.
[0023] Figure 8 is a schematic diagram of a downlink transmission resource indicated by a first frame to which embodiments of the application are applicable.
[0024] Figure 9 is a schematic flow diagram of a communication method according to an embodiment of the application.
[0025] Figure 10 is a schematic diagram of an association between a transmission resource indicated by a first frame and a secret key according to an embodiment of the application.
[0026] Figure 11 is a schematic diagram of an association between a transmission resource indicated by a first frame and a PN according to an embodiment of the application.
[0027] Figure 12 is a schematic block diagram of a communication device according to an embodiment of the application.
[0028] Figure 13 is a schematic block diagram of a communication device according to another embodiment of the application.
[0029] Figure 14 is a schematic block diagram of an apparatus for communication according to an embodiment of the application. DETAILED DESCRIPTION
[0030] The technical solutions in the application will be described below with reference to the accompanying drawings. To facilitate understanding, first, the communication terminology and communication procedures that can be involved in the embodiments of the application will be introduced with reference to Figures 1 to 6.
[0031] Communication system
[0032] The technical solutions of the embodiments of the present application can be applied to various communication systems, for example, a wireless local area network (WLAN), a wireless fidelity (WiFi), a high performance radio local area network (HIPELAN), a wide area network (WAN), a cellular network, or other communication systems. For example, the technical solutions provided in the embodiments of the present application can be applied to a communication system using an 802.11 standard. For example, the 802.11 standard includes but is not limited to an 802.11a standard, an 802.11g standard, an 802.11ba, and a next-generation 802.11 standard.
[0033] FIG. 1 shows a schematic diagram of a communication system to which the embodiments of the present application are applicable. As shown in FIG. 1, the communication devices in the communication system 100 can include a first device 110 and a second device 120.
[0034] In some scenarios, for example, in a WiFi system, the first device 110 can be a station (STA), and the second device 120 can be an access point (AP). The AP is used to create a wireless network and provide wireless network services for the STA. The STA can access the network through the AP.
[0035] The AP can be a device in a wireless network. The AP can be a communication server, a router, a switch, a bridge, or the like, or the AP can include various forms of macro base stations, micro base stations, relay stations, and the like. Of course, the AP can also be a chip, a circuit, or a processing system in these various forms of devices, so as to implement the methods and functions of the embodiments of the present application. The AP can be applied to various scenarios, for example, a sensor node in a smart city, such as a smart water meter, a smart electricity meter, a smart air detection node; a smart device in a smart home, such as a smart camera, a projector, a display screen, a television, a sound box, a refrigerator, a washing machine, and the like; a node in the Internet of Things; an entertainment terminal, such as an AR, a VR, and the like wearable device; a smart device in a smart office, such as a printer, a projector, and the like; a vehicle networking device in vehicle networking; and some infrastructure in daily life, such as a vending machine, a self-service navigation station in a supermarket, a self-service checkout device, a self-service ordering machine, and the like.
[0036] A STA can be a device that has a wireless transceiver function, such as supporting the 802.11 series of protocols, and communicates with an AP or other STAs. For example, a STA is any user communication device that allows a user to communicate with an AP and thus a WLAN network. For example, a STA includes a user equipment (UE), a mobile station (MS), a mobile terminal (MT), an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile terminal, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device, etc.
[0037] A STA can also be a device that provides voice and / or data connectivity to a user, such as a handheld device with a wireless connection function, a car device, etc. For example, a STA includes a mobile phone, a tablet computer, a notebook computer, a palm computer, a mobile internet device (MID), a wearable device, a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in smart grid, a wireless terminal in transportation safety, a wireless terminal in smart city, a wireless terminal in smart home, a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with a wireless communication function, a computing device or other processing device connected to a wireless modem, a car device, a wearable device, a terminal device in a 5G network, or a terminal device in a future evolved public land mobile network (PLMN), etc. Embodiments of the present application are not limited thereto.
[0038] The STA can also be a wearable device. The wearable device can also be referred to as a smart wearable device, which is a general term for devices that are designed and developed by applying wearable technology to daily wear, such as glasses, gloves, watches, clothing, and shoes. For example, the wearable device includes a smart watch or smart glasses, and focuses on a certain application function, such as a smart bracelet or smart jewelry that needs to be used in cooperation with other devices, such as a smart phone.
[0039] The STA can also be a terminal device in an Internet of Things (IoT) system. The IoT is an important part of future information technology development, and its main technical feature is to connect objects through communication technology and network, so as to realize the intelligent network of human-machine interconnection and object-object interconnection.
[0040] The STA can also be a device in a vehicle-to-everything (V2X) system. The communication mode in the V2X system is collectively referred to as V2X, where X can represent any object. For example, the V2X communication includes vehicle-to-vehicle (V2V) communication, vehicle-to-infrastructure (V2I) communication, vehicle-to-pedestrian (V2P) communication, vehicle-to-network (V2N) communication, and the like.
[0041] In addition, the STA can also include a smart printer, a train detector, a gas station sensor, and the like, and the main functions thereof include collecting data, receiving control information and downlink data of the AP, and transmitting electromagnetic waves to transmit data to the AP.
[0042] The AP in the embodiments of the present application can be a device for communicating with the STA. The AP can be a network device or a terminal device in a wireless local area network, and the AP can be used for communicating with the STA through the wireless local area network.
[0043] From the perspective of the communication mode supported by the AP, in some implementation manners, the AP can be a device that supports the 802.11 mode. Further, the AP can also be a device that supports multiple current and future WLAN modes of the 802.11 family, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, 802.11ba, and 802.11a.
[0044] From the perspective of the communication standards supported by the STA, in some implementations, the STA is a device that can support the 802.11 standard. The STA can also support multiple current and future WLAN standards of the 802.11 family, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, 802.11ba, and 802.11a.
[0045] It should be understood that the specific forms of the STA and the AP in the embodiments of the present application are not specially limited, and are only illustratively described herein.
[0046] In addition, the technical solutions implemented by the present application can also be used in other scenarios outside the WiFi system. For example, in some other scenarios, the first device 110 can be a terminal device, and the second device 120 can be a network device. The network device can be a device that communicates with the terminal device. The network device can provide communication coverage for a specific geographic area and can communicate with terminal devices located within the coverage area.
[0047] The terminal device can also be referred to as a user equipment (UE), an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile station (MS), a mobile terminal (MT), a remote station, a remote terminal, a mobile device, a user terminal, a terminal device, a wireless communication device, a user agent, or a user apparatus. The terminal device, for example, can be a device that provides voice and / or data connectivity to a user, and can be used to connect people, things, and machines, such as household appliances, sensors, electronic tags, etc. with wireless connectivity. The terminal device can also be a wireless terminal in a smart home, a wireless terminal in an IWSN, a wireless terminal in smart logistics and smart warehousing, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, etc.
[0048] The network device can be a device for communicating with the terminal device. The network device can also be an access network device or a radio access network device, for example, the network device can be a base station. The network device in the embodiments of the present application can refer to a radio access network (RAN) node or device that accesses the terminal device to the wireless network. The base station can broadly cover various names in the following or can be replaced by the following names, for example: node B (NodeB), evolved node B (eNB), next generation node B (gNB), relay station, access point, transmitting and receiving point (TRP), transmitting point (TP), master station (MeNB), auxiliary station (SeNB), multi-standard radio (MSR) node, home base station, network controller, access node, wireless node, access point (AP), transmission node, transceiver node, baseband unit (BBU), remote radio unit (RRU), active antenna unit (AAU), remote radio head (RRH), central unit (CU), distributed unit (DU), positioning node, etc. The base station can be a macro base station, a micro base station, a relay node, a donor node or the like, or a combination thereof. The base station can also refer to a communication module, modem or chip for being disposed in the foregoing device or apparatus. The base station can also be a mobile switching center and a device that undertakes the function of a base station in device-to-device (D2D), vehicle-to-everything (V2X), machine-to-machine (M2M) communication, network side device in 6G network, device that undertakes the function of a base station in future communication system, etc. The base station can support the network of the same or different access technology. The embodiments of the present application do not limit the specific technology and specific device form adopted by the network device.
[0049] The base station can be fixed or mobile. For example, a helicopter or a drone can be configured to act as a mobile base station, and one or more cells can move according to the location of the mobile base station. In other examples, the helicopter or the drone can be configured to act as a device that communicates with another base station.
[0050] In some deployments, the network device in the embodiments of the present application can refer to a CU or a DU; or the network device includes a CU and a DU. The gNB can also include an AAU.
[0051] The network device and the terminal device can be deployed on land, including indoors or outdoors, handheld or vehicle-mounted; can also be deployed on water surface; can also be deployed on aircraft, balloons and satellites in the air. The scene where the network device and the terminal device are located is not limited in the embodiments of the present application.
[0052] It should be understood that all or part of the functions of the communication device in the present application can also be implemented by software functions running on hardware, or by virtualized functions instantiated on a platform such as a cloud platform.
[0053] FIG. 1 exemplarily shows two first devices 110 and one second device 120. Optionally, the communication system 100 can include multiple second devices 120, and the communication system 100 can also include other numbers of first devices 110.
[0054] In the following, the technical solutions of the embodiments of the present application are described by taking a WIFI system as an example. It can be understood that the technical solutions of the embodiments of the present application can also be extended to other systems.
[0055] With the development of wireless communication technology, people hope to integrate wireless communication systems with logistics, manufacturing, transportation, energy and other vertical industries. For example, the wireless communication system can be integrated with the IWSN. For another example, the wireless communication system can be integrated with intelligent logistics and intelligent warehousing. For another example, the wireless communication system can be integrated with the smart home network. However, in these industries, the terminal device usually needs to have the characteristics of low cost, small size such as ultra-thin, maintenance-free, long life, etc. Therefore, in order to meet the above conditions, zero-power devices are introduced into the wireless communication system.
[0056] For example, the first device 110 shown in FIG. 1 can be a zero-power device. The first device 110 and the second device 120 can communicate by using a zero-power communication technology, and in this case, the first device 110 can be referred to as a zero-power communication device, a zero-power device, a zero-power communication terminal, a zero-power terminal, or the like. In this case, the communication system 100 can further include a power supply device for the first device 110, which can provide energy for the first device 110 by sending a power supply signal to the first device 110. For example, in a WiFi system, as shown in FIG. 1, the second device 120 can be an AP and simultaneously serve as a power supply device for the first device 110; for another example, as shown in FIG. 1, the second device 120 can be a power supply device for the first device 110, and the communication system 100 further includes an AP (not shown). The AP can control the power supply device. The power supply device can interact with the AP. The number of power supply devices can be more than one to better supply energy for the first device 110.
[0057] It should be noted that, from the perspective of energy supply mode, the zero-power device described in the embodiments of the present application can include an ambient energy-based device, such as an ambient-powered IoT (AMP IoT) device, a battery-free terminal, a maintenance-free terminal, and the like. For ease of understanding, the zero-power device and the ambient energy-based device are introduced respectively below.
[0058] Zero-power device
[0059] A zero-power terminal is a terminal device that consumes little or even no energy in the communication process. At present, the zero-power terminal has one or more of the following advantages. For example, since the zero-power terminal does not need to actively transmit signals, it does not need to construct a complex radio frequency path, such as not setting a power amplifier (PA), a radio frequency filter, or the like in the radio frequency path, to reduce the cost and size of the terminal; for another example, since the zero-power terminal does not need to actively generate high-frequency signals, it does not need a high-frequency crystal oscillator, to reduce the cost and size of the terminal; for yet another example, since the zero-power terminal can communicate with a network device by using backscatter technology, the terminal consumes less energy or even no energy in the communication process.
[0060] In the zero-power communication technology, based on the energy source of the terminal and the use mode of the energy, the zero-power terminal can be divided into three categories: a passive zero-power terminal, a semi-passive zero-power terminal, and an active zero-power terminal.
[0061] I. Passive zero-power terminal
[0062] The passive zero-power terminal usually does not need to be equipped with a battery. When the passive zero-power terminal approaches the network device, the passive zero-power terminal is in the near-field range formed by the antenna radiation of the network device. At this time, the antenna of the passive zero-power terminal can generate induced current through electromagnetic induction, the induced current can power the passive zero-power terminal, drive the low-power chip circuit of the passive zero-power terminal, realize demodulation of the forward link signal, and signal modulation of the backward link, and the like. For the backscatter link, the passive zero-power terminal can use the backscatter implementation mode to transmit signals.
[0063] Based on the above introduction, it can be seen that the passive zero-power terminal does not need to be equipped with a battery to drive, whether it is based on the transmission process of the forward link or the transmission process of the backward link, it is a truly zero-power terminal.
[0064] In some implementations, the passive zero-power terminal described above can be an electronic tag, and correspondingly, the network device can be a reader / writer of an RFID system, for reading the content in the electronic tag and / or for changing the content in the electronic tag.
[0065] II. Semi-passive zero-power terminal.
[0066] The semi-passive zero-power terminal itself also does not install a conventional battery, but can use an energy harvesting module, such as an RF energy harvesting module, to harvest radio wave energy, and at the same time store the harvested energy in an energy storage unit, such as a capacitor. After the energy storage unit obtains energy, it can power the zero-power terminal to drive the low-power chip circuit. Realize demodulation of the forward link signal, and signal modulation of the backward link, and the like. For the backscatter link, the zero-power terminal uses the backscatter implementation mode to transmit signals.
[0067] Based on the above introduction, it can be seen that the semi-passive zero-power terminal does not need to be equipped with a battery to drive, whether it is based on the transmission process of the forward link or the transmission process of the backward link, although it uses the energy stored in the capacitor in the work, but the energy comes from the radio energy harvested by the energy harvesting module, so it is also a truly zero-power terminal.
[0068] III. Active zero-power terminal
[0069] The active zero-power terminal can be equipped with a battery. The battery can power the active zero-power terminal to drive the low-power chip circuit of the active zero-power terminal. Realize demodulation of the forward link signal, and signal modulation of the backward link, and the like. For the backscatter link, the active zero-power terminal uses the backscatter implementation mode to transmit signals. Therefore, the zero-power of this type of terminal mainly reflects that the signal transmission of the backward link does not need to consume the power of the terminal itself, but uses the backscatter mode.
[0070] For the active zero-power terminal, it can be powered by the built-in battery, so that the communication distance of the active zero-power terminal can be increased, and the reliability of the communication can be improved. Therefore, the active zero-power terminal can be applied in some scenarios with relatively high requirements on the communication distance, reading delay, etc.
[0071] In some implementations, the active zero-power terminal described above can be an electronic tag, and the network device can be a radio frequency identification (RFID) reader. At this time, the built-in battery can supply power to the RFID chip in the electronic tag to increase the reading and writing distance between the RFID reader and the electronic tag. On the other hand, the built-in battery can supply power to the RFID chip in the electronic tag to shorten the reading and writing delay of the electronic tag by the RFID reader, which is beneficial to improve the reliability of the communication.
[0072] Cellular passive IoT
[0073] As described above, with the increase of applications in wireless communication networks, the types and application scenarios of connected objects are increasing, and there are higher requirements on the price and power consumption of communication terminals. Therefore, the application of battery-free and low-cost passive IoT devices becomes a key technology in cellular IoT, enriches the types and quantities of 5G network link terminals, and truly realizes the interconnection of all things. Among them, the passive IoT device can be based on zero-power technology, such as RFID technology, and extended on this basis to be applicable to cellular IoT.
[0074] Environment energy-based device
[0075] In known wireless communication systems such as NR systems and WiFi systems, environment energy-based devices are similar to passive zero-power devices or semi-passive zero-power devices in zero-power communication, and the energy required for their work is usually collected from environmental energy. The source of environmental energy can be wireless signals, solar energy, thermal energy, etc. Such devices have the advantages of low cost and battery-free, and can support low-cost and large-scale deployment and maintenance-free of IoT devices. Therefore, how to support such devices in existing wireless communication systems is studied in the current standard.
[0076] In the embodiments of the present application, the environment energy-based device includes, for example, an AMP IoT device, which can also be referred to as an AMP device, an AMP STA, an AMP terminal, or an environment IoT device, etc.
[0077] IEEE has carried out a research project on AMP devices, which are roughly divided into the following two types, each with corresponding complexity and communication capability:
[0078] 1) AMP - single IoT device: can work in the environment without or with limited energy storage capability, uses backscattering or active transmission, power consumption is less than 1 mW, for example. The coverage distance can reach 30 m in indoor scenarios and 100 m in outdoor scenarios.
[0079] 2) AMP - assisted IoT device: similar to existing devices supporting 802.11 standards, reusing existing physical layer design, can work in the environment with energy storage capability. The coverage distance can reach 30 m in indoor scenarios and 200 m in outdoor scenarios.
[0080] In addition, the environment energy harvesting supported by the zero-power terminal can also have various types, such as wireless radio frequency, solar energy, thermal energy, mechanical energy, etc. Among them, the zero-power terminal based on wireless radio frequency energy harvesting may need the network to provide a wireless radio frequency energy supply signal.
[0081] Based on the discussion of the application scenarios of AMP devices by IEEE, the AMP devices can be used in at least the following four scenarios:
[0082] Object identification, such as logistics, production line product management, and supply chain management;
[0083] Environmental monitoring, such as temperature, humidity, and harmful gas monitoring of working environment and natural environment;
[0084] Positioning, such as indoor positioning, intelligent search, and production line article positioning; and
[0085] Intelligent control, such as intelligent control of various appliances in smart home, such as turning on / off air conditioners, adjusting temperature, etc., and intelligent control of various facilities in agricultural greenhouse, such as automatic irrigation and fertilization, etc.
[0086] Information transmission in WiFi system
[0087] The information of the WIFI device is transmitted based on a physical layer protocol data unit (PPDU) frame. Generally, the PPDU frame includes a physical layer preamble, a physical layer header, and a data portion. For example, as shown in FIG. 2, in some protocols, such as the 802.11a / g standard, the physical layer portion is preceded by three portions, a short training field (STF), a long training field (LTF), and a signal, i.e., the PPDU frame carries the STF, LTF, and data portion some specific settings.
[0088] As shown in FIG. 2, the first portion is the STF, which is mainly composed of 10 short symbols (t1-t10), each of which is 0.8us, and contains many functions, mainly for implementing frame synchronization and coarse frequency synchronization. Among them, t1-t7 mainly include signal detection, automatic gain control (AGC), diversity selection, etc.; t8-t10 mainly include coarse frequency synchronization, offset estimation, timing synchronization, etc.
[0089] The second portion is the LTF, which is used to implement fine frequency synchronization and channel estimation.
[0090] The signal portion carries information related to the data portion, such as data transmission rate, data packet length information (Length), reserved bits, and tail bits, etc.
[0091] As an example, as shown in FIG. 3, the data portion of the PPDU carries a media access control (MAC) frame, and the frame format of the MAC frame can include a MAC header, a frame body, and a frame check sequence (FCS), etc.
[0092] Device access process
[0093] As shown in FIGS. 4-6, the process of the first device 110 accessing the BSS provided by the second device 120 is described below as an example in which the first device 110 is a STA and the second device 120 is an AP. The process generally includes a scan, an authentication, an association, and the like.
[0094] First, the first device 110 performs a scan, which includes active scanning and passive scanning. In active scanning, the first device 110 sends a probe request on a channel supported by the first device 110 to detect a wireless network in the surrounding area, and the second device 120 sends a probe response upon receiving the probe request. In passive scanning, the first device 110 listens to a beacon frame periodically sent by the second device 120 in different channels to discover a wireless network. The beacon frame includes basic information and capabilities of the BSS to which the second device 120 belongs, such as a BSS identity (BSSID), a service set identity (SSID), a supported rate, an authentication method, an encryption algorithm, a beacon frame transmission interval, a used channel, and the like. FIG. 4 shows a flowchart of an access process corresponding to active scanning, and FIG. 5 shows a flowchart of an access process corresponding to passive scanning.
[0095] The first device 110 discovers a BSS and obtains information of the BSS through the scan process. The first device 110 initiates an authentication process to determine the identity of the first device 110, and only a device whose identity is authenticated can access a wireless network. For example, as shown in FIG. 4, in step 101, the first device 110 sends a probe request, and in step 102, the second device 120 sends a probe response. For another example, as shown in FIG. 5, in step 103, the first device 110 scans a beacon frame sent by the second device 120, and after scanning the beacon frame, in step 101, the first device 110 sends a probe request, and in step 102, the second device 120 sends a probe response.
[0096] The authentication process includes an authentication request and an authentication response. For example, as shown in FIGS. 4 and 5, in step 104, the first device 110 sends an authentication request, and in step 105, the second device 120 sends an authentication response upon receiving the authentication request.
[0097] The second device 120 sends an authentication response.
[0098] The first device 110 initiates an association procedure after the authentication is passed. The association procedure is a procedure of service negotiation between the first device 110 and the second device 120. The association procedure can include two steps of association request and association response. For example, as shown in FIG. 4 and FIG. 5, in step 105, the first device 110 sends an association request frame; after receiving the association request frame, in step 107, the second device 120 sends an association response frame.
[0099] 4-Way Handshake procedure
[0100] After the above-mentioned access procedure is completed, as shown in FIG. 4 and FIG. 5, the first device 110 and the second device 120 also need to securely verify and exchange a secret key through a 4-Way Handshake procedure, so as to use the secret key for subsequent communication, to verify the legitimacy of the opposite end, and thus prevent man-in-the-middle attacks.
[0101] Optionally, as shown in FIG. 6, taking the first device 110 as a supplicant (STA) and the second device 120 as an authenticator (AP) as an example, the 4-Way Handshake can include some or all of the following steps.
[0102] In step 1111 and step 1112, the first device 110 and the second device 120 respectively generate corresponding random numbers (nonces), wherein the random number generated by the authenticator (the second device 120) is denoted as ANonce, and the random number generated by the supplicant (the first device 110) is denoted as SNonce.
[0103] In step 112, the second device 120 sends an authentication key frame (EAPOL-Key) carrying ANonce. The format of the EAPOL-Key can be, for example, (0, 0, 1, 0, P, 0, 0, ANonce, 0, {}).
[0104] In step 113, the first device 110 receives the EAPOL-Key and calculates a pairwise transit key (PTK) based on ANonce and SNonce.
[0105] In step 114, the first device 110 sends an EAPOL-Key carrying SNonce, RSNE, and message integrity check (MIC) information. The format of the EAPOL-Key can be, for example, (0, 1, 0, 0, P, 0, 0, SNonce, MIC, {RSNE}).
[0106] In step 115, the second device 120 computes the PTK based on the ANonce and the SNonce, and verifies the MIC information in the EAPOL-Key frame.
[0107] In step 116, the second device 120 sends an EAPOL-Key frame carrying the ANonce, the RSNE, the MIC information, a group temporal key (GTK), and an indication of whether the temporal key is installed. If management frame protection is negotiated, the EAPOL-Key frame also carries an integrity group temporal key (IGTK); if beacon protection is negotiated, the EAPOL-Key frame also carries a beacon integrity group temporal key (BIGTK). The format of the EAPOL-Key can be, for example, (1, 1, 1, 1, P, 0, Key RSC, ANonce, MIC, {RSNE, GTK [KeyID GTK ], IGTK [KeyID IGTK ]}). GTK ],IGTK [KeyID IGTK ]}).
[0108] In step 117, the first device 110 sends an EAPOL-Key frame to confirm whether the temporal key is installed. The EAPOL-Key frame can carry the MIC information. The format of the EAPOL-Key can be, for example, (1, 1, 0, 0, P, 0, 0, 0, MIC, {}).
[0109] In step 1181, the first device 110 sets up the temporal encryption key, the MIC key, and the like, and obtains the PTK based on, for example, a temporal key integrity protocol (TKIP). In addition, the first device 110 can also set up a GTK, an IGTK, and the like, and the corresponding key identifiers are KeyID GTK and KeyID IGTK , respectively.
[0110] In step 1182, the second device 120 sets up the temporal encryption key and the MIC key, and obtains the PTK based on, for example, a TKIP.
[0111] The PTK above is a unicast key, and the GTK is a groupcast key. The PTK and the GTK are respectively used for encryption and decryption of unicast data and groupcast data. After the first device 110 and the second device 120 complete the key exchange, all unicast data frames will be protected by the PTK, and all groupcast data and broadcast data will be protected by the GTK.
[0112] In the embodiments of the present application, the first device 110 can be a zero-power device such as an AMP device, and the second device 120 can be a network device or a terminal device such as a mobile phone. The first device 110 and the second device 120 can communicate in, for example, a WiFi or cellular network. The ambient energy that can be used by the first device 110 can include, for example, wireless radio frequency energy, solar energy, thermal energy, mechanical energy, and the like. From the perspective of energy harvesting, the first device 110 can also be an energy harvesting device. For wireless radio frequency energy, the energy supply device is a device that transmits an energy supply signal. The energy supply device can be the same device as the device that transmits data, such as a base station, an AP, or the like. Alternatively, the energy supply device can be a separate energy supply device.
[0113] Logistics and warehousing are typical scenarios for AMP device applications. A large amount of goods needs to be frequently transferred, stored, loaded and unloaded, and inventoried in logistics stations or warehouses. Along with the occurrence of warehouse ordering, goods entering the warehouse, goods management, and goods leaving the warehouse, a large amount of warehousing information is generated. This information generally has the characteristics of frequent data reading operations and high latency requirements. The AMP device itself has the characteristics of extremely low cost, small size, maintenance-free, durability, and long service life. It is particularly suitable for recording, saving, and updating the information of goods in logistics and warehousing, and for constructing an AMP Internet of Things-based logistics and warehousing system. This can further reduce operating costs and significantly improve the efficiency of logistics and warehousing management, and is helpful for the realization of smart logistics and smart warehousing. The positioning scenario based on the AMP device also requires the AP or the STA to read the information stored by the AMP device, such as positioning information stored by the AMP device, so as to perform positioning based on the positioning information reported by the AMP device.
[0114] The AMP device has power consumption and complexity limitations, for example, the receiver can only support simple modulation and demodulation methods such as amplitude-shift keying (ASK), frequency-shift keying (FSK), phase shift keying (PSK), and does not support orthogonal frequency division multiplexing (OFDM). For the use of existing unlicensed spectrum, in order to ensure the fairness of channel use, if the AMP device needs to occupy the channel for data transmission, it also needs to perform corresponding clear channel assessment (CCA) to determine whether the channel is idle. At the same time, it also needs to support the carrier sense multiple access with collision avoidance (CSMA / CA) mechanism to be compatible with and coexist with existing devices. Taking a WiFi system as an example, the channel occupation of the AMP device needs to support the distributed coordination function (DCF) protocol, which requires the AMP device to detect the existing OFDM-based PPDU frame to meet the physical and virtual carrier sensing, and support the request to send / clear to send (RTS / CTS) mechanism. This is not achievable for the AMP device. Therefore, for data transmission of the AMP STA, the channel resource that can be used for data transmission needs to be indicated by the trigger of the AP. The channel resource is a part of the channel occupied by the AP through CCA. Therefore, channel access is performed by the AP or a conventional STA, and the obtained channel is shared with the AMP device for use, which can solve the problem that the AMP device cannot independently perform CCA. Here, the conventional STA refers to a terminal device such as a mobile phone that is not based on environmental energy.
[0115] Therefore, a typical process of AMP device communication can be that the network device or the terminal device triggers the AMP device to perform data transmission. Further, the data transmission or reception of the AMP device can also be triggered by the network device or the terminal device. For example, the AP can send a first frame for indicating data transmission or reception of the AMP device. The first frame can be a trigger frame, a grant frame, a paging frame, or a polling frame, etc.
[0116] In some implementations, the first frame can carry part or all of the following information:
[0117] 1) Identification (ID) information or ID group information of the AMT device.
[0118] The identification information and the group identification information can include, but are not limited to, a MAC address, an association identifier (AID), a partial AID, and the like. The ID group information can be ID information corresponding to a group of AMT devices. Further, the ID information indicated by the first frame can not correspond to a specific AMT device, but can correspond to a type of AMT device, so as to trigger the type of AMT device to report data. For example, in a logistics scenario, the AP triggers the surrounding AMT devices to report ID information through the first frame, for the identification and inventory of goods.
[0119] 2) One or more of the time domain resource, the frequency domain resource, the code domain resource, the modulation or encoding mode, the data rate, and the like used by the AMT device. For example, the AP can perform CCA on multiple channels and obtain channel occupation, and then indicate the resources on the multiple channels through the first frame for data transmission of the AMT device. Alternatively, resource multiplexing can also be performed on the same channel in a time division, frequency division, or code division manner, so as to perform data transmission of multiple AMT devices.
[0120] In the embodiments of the present application, the data transmission process of the first device 110 can include that the second device 120 triggers the data transmission or reception of the first device 110. For example, the second device 120 sends the first frame to trigger the first device 110 to send or receive the data frame, and accordingly, the first device 110 sends or receives the data frame according to the first frame. As an example, taking the second device 120 as an AP, FIG. 7 and FIG. 8 show the transmission resources of the AMT devices indicated by the first frame. In FIG. 7, the second device 120 triggers three first devices 110, i.e., AMP device 1, AMP device 2, and AMP device 3, to use time-division uplink resources to send data frames through the first frame. In FIG. 8, the second device 120 triggers three first devices 110, i.e., AMP device 1, AMP device 2, and AMP device 3, to receive data frames at different downlink transmission times (DTT) through the first frame.
[0121] Security in the transmission of frames is achieved through encryption. As mentioned above, in the access process of the first device 110, a key exchange process needs to be completed between the first device 110 and the second device 120 through scanning, authentication, association, and a 4-way handshake process, and data is encrypted through the key to enable communication. The key is obtained through the 4-way handshake process and stored in the first device 110.
[0122] Meanwhile, in order to avoid a replay attack, in the encryption process, plaintext data and a packet number (PN) and the like are assembled into an encrypted frame and MIC information through an encryption algorithm using the key. The PN is an identifier of the frame, which is constantly incremented with the sending of the frame. A new PN is created every time a new MPDU needs to be sent, and the PN of a retransmitted MPDU does not change. Therefore, the PN used in the transmission of different frames is different. In the decryption process at the receiving end, after the message integrity is verified through the MIC information, the PN obtained through decryption is compared with a locally maintained PN, so that it can be identified whether the received frame is a replay frame, thereby playing a role of replay protection. In the related art, the PN can be assigned and updated by the AP, or can also be obtained through a timing synchronization function timer (TSF timer) of the first device 110, and the first device 110 needs to locally store and maintain the PN, so as to determine whether there is a replay attack in the receiving process of the frame.
[0123] The above-mentioned key, PN, and the like are all related to the security of data transmission of the first device 110, and in the embodiments of the present application, these information are referred to as first information. It can be understood that the first information in the embodiments of the present application can be the key, PN, and the like, and can also be other security-related information, and these information are used for security protection of the frames sent and received by the first device 110.
[0124] In the case that the first device 110 is an AMP device, due to the low complexity and low power consumption of the AMP device, especially the AMP device based on ambient energy, it is challenging to use the limited energy source to implement traditional security-related operations, such as operations including storage, update, and the like of information such as a secret key, a PN code, and the like, which are affected by the working state of the AMP device based on ambient energy. For example, the time for the AMP device to work due to energy harvesting is intermittent, and when the stored energy is exhausted, the AMP device needs to store energy harvested from the environment to support the working of the AMP device. In this process, the AMP device faces challenges in storing a secret key and storing and maintaining a local PN. When the AMP STA loses the stored secret key and PN, it will not be able to perform frame decryption and replay protection.
[0125] To this end, an embodiment of the present application provides a communication scheme, the second device 120 sends a first frame to the first device 110, and the first device 110 can determine first information based on the first frame, to be used for security protection of frames sent and received by the first device 110, thereby reducing the difficulty of the first device 110 in obtaining and maintaining the first information, and reducing the failure of security-related operations of the first device 110 due to limited energy.
[0126] FIG. 9 is a schematic flowchart of a communication method according to an embodiment of the present application. The method 200 shown in FIG. 9 can be performed by the first device 110 and the second device 120. As described above, the first device 110 can be a STA, and the second device 120 can be an AP or an energy supply device for the first device 110. The first device 110 can be an AMP device, for example; and the second device 120 can be a network device, or can also be a terminal device such as a mobile phone, and the like.
[0127] As shown in FIG. 9, the method 200 includes some or all of the following steps.
[0128] In step 210, the second device 120 sends a first frame to the first device 110.
[0129] Correspondingly, in step 220, the first device 110 receives the first frame sent by the second device 120.
[0130] The first frame is used to determine first information, and the first information is used for security protection of frames sent or received by the first device 110.
[0131] According to the embodiment of the present application, the first information is determined by the first frame, which can reduce the difficulty of the first device in obtaining and maintaining the first information, reduce the failure of security-related operations of the first device due to limited energy, and improve the reliability of data transmission.
[0132] In some implementations, the first frame can be a frame for triggering the first device 110 to transmit or receive a data frame. For example, the first frame is a trigger frame. After the first device 110 collects and stores enough energy, the first device 110 can obtain the first information from the trigger frame and transmit or receive the data frame based on the first information when the transmission or reception of the data frame is triggered based on the trigger frame. In the case that the first device 110 is not in a communication state, for example, in an energy collection state, the first device 110 does not need to store and maintain the first information, thereby facilitating to reduce the energy consumption of the first device 110 and reduce the impact on the communication process.
[0133] In some other implementations, the first frame is a frame for discovering a BSS. The BSS can be a BSS provided by an AP. For example, the first frame is a discovery frame, which can be a beacon frame transmitted by the second device 120. Alternatively, the first frame can be a frame for assisting the first device 110 to perform scanning, for example, the first frame can indicate a scanning resource of the first device 110, so that the first device 110 receives a beacon frame on the scanning resource to discover the BSS as soon as possible.
[0134] In some other implementations, the first frame is a frame for discovering a BSS. The BSS can be a BSS provided by an AP. For example, the first frame is a discovery frame, which can be a beacon frame transmitted by the second device 120. Alternatively, the first frame can be a frame for assisting the first device 110 to perform scanning, for example, the first frame can indicate a scanning resource of the first device 110, so that the first device 110 receives a beacon frame on the scanning resource to discover the BSS as soon as possible.
[0135] It should be noted that the first information is determined by using the discovery frame, considering that the time experienced from when the first device 110 monitors the discovery frame to when the first device 110 receives the trigger frame is very short, and the probability that the first device 110 cannot normally work due to energy limitation in this time is relatively low. For example, the foregoing authentication, association, 4-way handshake and other processes of the first device 110 can be more simplified. Alternatively, the first device 110 can not perform authentication, association, 4-way handshake and other processes. After the first device 110 monitors the discovery frame to discover the BSS and obtains the first information from the discovery frame, the first device 110 can quickly receive the trigger frame, and then transmit or receive the data frame based on the trigger frame using the first information.
[0136] Since the discovery frame can be periodically transmitted, after the energy of the first device 110 is recovered, the first device 110 can timely monitor the discovery frame and determine the first information from the discovery frame, so as to transmit or receive the data frame based on the first information after receiving the trigger frame. The time experienced from the discovery frame to the trigger frame can be very short, and the probability that the first device 110 loses the first information due to energy limitation in this time is relatively low, and the probability that the first device 110 causes an impact on the communication process is also relatively low.
[0137] It can be understood that, in the case that the first frame can be a discovery frame or a trigger frame, the discovery frame and the trigger frame can both be transmitted by the AP; or the discovery frame and the trigger frame are both transmitted by the powered device of the first device 110; or one of the discovery frame and the trigger frame is transmitted by the powered device of the first device 110 and the other is transmitted by the AP, which is not limited in the present application.
[0138] The first frame can include one or more of the following information, for example: identification information of the first device 110; transmission resources used by the first device 110, such as time domain, frequency domain or code domain resources; modulation or coding mode used by the first device 110; data transmission rate used by the first device 110. The first device 110 can transmit or receive the frame based on the information in the first frame, for example, as shown in FIGS. 7 and 8, the first device 110 receives or transmits the data frame using the transmission resources indicated by the first frame.
[0139] In some implementations, the first frame can also carry MIC information. The first device 110 obtains the first information by verifying the message integrity through the decrypted MIC information.
[0140] In the following, the technical solutions of the embodiments of the present application are described in detail by taking the first information including the first secret key or the first information including the PN as an example.
[0141] Embodiment 1
[0142] In embodiment 1, the first information includes the first secret key, and the first secret key is used to encrypt the data frame transmitted and received by the first device 110.
[0143] In some implementations, the first frame can carry first secret key related information, and the first secret key related information is used to determine the first secret key.
[0144] In the related art, the first device 110 can generate a pairwise master key (PMK) in the authentication process, and obtain the first secret key based on the PMK and the 4-way handshake process. In this embodiment, the first secret key related information is carried in the first frame transmitted by the second device 120, and the first device 110 can determine the first secret key based on the first secret key related information in the first frame when receiving the first frame, without going through a complex interaction process and without storing and maintaining the first secret key for a long time, thereby reducing the difficulty of the first device 110 to obtain and maintain the first secret key, which is conducive to reducing the energy consumption of the first device 110 and reducing the impact on the communication process.
[0145] The embodiments of the present application provide two implementation modes of the first secret key related information, namely the following implementation mode 1 and implementation mode 2.
[0146] Implementation mode 1
[0147] In implementation 1, the first key related information can comprise the first key. For example, the first frame can carry a key number of the first key, and the first device 110 can determine the key corresponding to the key number carried in the first frame as the first key used by the first device 110 according to the association between the key number and the key, which can be preset.
[0148] In order to ensure the security of the first key in the transmission process, in some implementations, the first key can be encrypted based on the second key.
[0149] Optionally, the second key can be determined based on one or more of the following: the authentication frame transmitted by the first device 110 in the above authentication process; the association frame transmitted by the first device 110 in the above association process; predefined information. For example, the second key is a master key (MK). That is, the second key can be a key determined in the authentication process or the association process. Of course, the second key can also be a key determined based on other predefined information, for example, in the case that the first device 110 does not perform the authentication and association processes, the second key can also be a pre-agreed key. Taking a logistics scenario as an example, for goods managed by a logistics company, the first device 110 used can be pre-written with an agreed key, and only the second device 120 of the logistics company can use the agreed second key to communicate with the first device 110 during the transportation of the goods.
[0150] The first device 110 decrypts the first frame by the second key to obtain the first key. Then, the first device 110 can encrypt the data frame it sends by the first key, and correspondingly, the AP decrypts the data frame sent by the first device 110 by using the same first key. Optionally, the second device 120 can trigger one or more first devices 110 to send or receive data frames by the first frame.
[0151] Implementation 2
[0152] In implementation 2, the first key related information can comprise second information, and the second information is used to generate the first key. That is, the first frame can not directly carry the first key, but carry information used to generate the first key, and the first device 110 can generate the first key based on the second information and use the first key to encrypt the data frame it sends.
[0153] The second information may, for example, comprise one or more of: a third key; a security-related parameter used to generate the first key; and information indicating a key derivation manner of the first key. Optionally, the third key may be the second key described above, or another key different from the second key. For example, the third key may be a master key. The security-related parameter is a parameter used to generate the first key, and may comprise one or more of, for example, an AP address, a random number, a generation parameter used to calculate the first key, an encryption manner, and the like. The encryption manner, i.e. the manner in which the key is generated, is used to determine a key derivation function. The first device 110 may calculate the target key based on the third key and the security-related parameter by using the key derivation function.
[0154] For example, taking the second device 120 as an AP, after the first device 110 receives the first frame sent by the second device 120, the first device 110 generates a random number, and uses the random number and the third key carried in the first frame to calculate the first key by using the key derivation function carried in the first frame. The first device 110 encrypts the data frame sent by it using the first key. Meanwhile, the first device 110 may also send the random number to the second device 120, so that the second device 120 calculates the first key based on the received random number and the third key by using the same key derivation function. The second device 120 decrypts the data frame sent by the first device 110 using the first key.
[0155] If the second device 120 triggers a plurality of first devices 110 to send or receive data frames by using the first frame, the plurality of first devices 110 may generate respective first keys using the second information. For example, the plurality of first devices 110 may generate respective random numbers, and use the respective random numbers and the third key to calculate respective first keys by using the key derivation function.
[0156] The embodiments of the present application do not limit the types of the first key, the second key and the third key, and for example, the first key, the second key and the third key may be PTKs.
[0157] In the embodiments of the present application, the first frame may carry a plurality of pieces of key-related information. That is, the first key-related information may be one of a plurality of pieces of key-related information carried by the first frame, wherein the plurality of pieces of key-related information are respectively used to determine a plurality of keys, for example, a plurality of first keys.
[0158] The first frame can be used to instruct a plurality of STAs to transmit or receive data frames, wherein different STAs can use different secret keys to encrypt the data frames transmitted or received by them. Therefore, in some implementations, the plurality of pieces of secret key related information can be associated with a plurality of STAs. For example, the first frame carries a plurality of pieces of secret key related information corresponding to a plurality of STAs, and the plurality of STAs respectively determine the secret keys used by them based on the corresponding secret key related information to encrypt the data frames.
[0159] The first frame can also be used to instruct a plurality of groups of STAs to transmit or receive data, wherein different groups of STAs can use different secret keys to encrypt the data frames transmitted or received by them. Therefore, in some implementations, the plurality of pieces of secret key related information can be associated with a plurality of groups of STAs. For example, the first frame carries a plurality of pieces of secret key related information corresponding to a plurality of groups of STAs, and the plurality of groups of STAs respectively determine the secret keys used by them based on the corresponding secret key related information to encrypt the data frames. Alternatively, the STAs in each group of STAs can use the same secret key.
[0160] In addition, in other implementations, the plurality of pieces of secret key related information in the first frame can also be associated with a plurality of transmission resources. Since the first frame can instruct a plurality of transmission resources to be used by STAs to transmit frames. At this time, the AP cannot determine the identity of the STA using the resource, but needs the STA to report its identity information using the resource. For example, in a logistics scenario, the AP instructs the surrounding STAs to report their identity information through the first frame for the identification and inventory of goods. In this case, the first frame can carry a plurality of pieces of secret key related information, and the plurality of pieces of secret key related information are associated with the plurality of transmission resources instructed by the first frame.
[0161] For example, as shown in FIG. 10, taking the second device 120 as an AP for example, the second device 120 triggers three first devices 110, i.e., AMP device 1, AMP device 2 and AMP device 3, to use time-division uplink resources to transmit data frames through the first frame, and different uplink resources correspond to different secret key related information. For example, the secret key related information corresponding to resource 1 is used to determine secret key Key 1, the secret key related information corresponding to resource 2 is used to determine secret key Key 2, and the secret key related information corresponding to resource 3 is used to determine secret key Key 3. When the first device 110 uses a certain uplink resource to transmit a data frame, it can use the secret key related information corresponding to the uplink resource to determine the secret key used by it and encrypt the data frame, for example, AMP device 1 uses secret key Key 1 to encrypt the data frame and transmits it to the second device 120 on resource 1, AMP device 2 uses secret key Key 2 to encrypt the data frame and transmits it to the second device 120 on resource 2, and AMP device 3 uses secret key Key 3 to encrypt the data frame and transmits it to the second device 120 on resource 3.
[0162] Embodiment 2
[0163] In embodiment 2, the first information includes the first PN.
[0164] In some implementations, the first frame carries first PN related information, and the first PN related information is used to determine the first PN.
[0165] In related technologies, the PN can be assigned and updated by the AP, or incremented according to the transmission of the frame. In the 802.11ba standard, the PN can also be obtained by the TSF timer of the first device 110. The first device 110 needs to maintain a certain amount of energy to store and maintain the local PN, for example, to maintain a counter of the PN, to increase the PN by 1 after each frame transmission, or to receive a management frame of the AP to obtain an update of the PN. The energy stored by the first device 110 has uncertainty, which can cause the local PN to be inaccurate, resulting in the PN maintained by the first device 110 being different from the PN maintained by the AP, and further causing the replay verification of the frames transmitted between the AP and the first device 110 to fail.
[0166] When the first device 110 has collected and stored enough energy and can communicate, the transmission resource required for frame transmission is obtained by monitoring the trigger frame. At this time, due to the previous state of no power or low power, the PN stored and maintained locally by the first device 110 can be lost or invalid, and the PN needs to be reacquired.
[0167] In this embodiment, the first frame sent by the second device 120 carries the first PN related information, and the first device 110 can acquire the first PN in time based on the first PN related information in the first frame when receiving the first frame. The first device 110 does not need to store and maintain the first PN for a long time, which is conducive to reducing the energy consumption of the first device 110 and reducing the impact on the communication process.
[0168] The embodiments of the present application provide two implementation manners of the first PN related information, namely, implementation manner 1 and implementation manner 2 described below.
[0169] Implementation manner 1
[0170] In implementation manner 1, the first PN related information includes all or part of the information in the first PN.
[0171] That is, the first frame can carry all the information in the first PN to reduce the complexity of the first device 110 acquiring the first PN; or, in order to reduce the amount of information carried by the first frame, the first frame can only carry part of the information in the first PN.
[0172] In some implementations, the first PN-related information includes a first part of the first PN, and the first PN further includes a second part, the first part of the first PN is carried in the first frame, and the second part of the first PN can be determined based on other information.
[0173] The second part of the first PN can be determined based on, for example, timestamp information received by the first device 110 in a frame and / or a TSF timer of the first device 110. Here, the timestamp information can be, for example, timestamp information carried in the first frame, or timestamp information carried in a beacon frame, or timestamp information carried in another frame. The first device 110 can maintain a local TSF timer based on the timestamp information obtained by the first device 110.
[0174] A PN has a certain length, for example, 6 bytes, i.e., 48 bits, and can be represented as PN = PN0||PN1||PN2||PN3||PN4||PN5. Further, the PN can be optionally divided into a partial packet number (PPN) and a base packet number (BPN), i.e., PN = PPN||BPN, where PPN is the least significant and BPN is the most significant. For example, PPN = PN0 and BPN = PN1||PN2||PN3||PN4||PN5.
[0175] In some implementations, the first part of the first PN is the PPN of the first PN, and the second part of the first PN is the BPN of the first PN; or the first part of the first PN is the BPN of the first PN, and the second part of the first PN is the PPN of the first PN.
[0176] For example, the PPN of the first PN can be acquired through the first frame, and the BPN of the first PN can be determined based on other information. For example, the BPN can be determined based on part of bits in the current TSF timer, such as BPN = part of bits [17:56] of the TSF timer, and the first device 110 locally maintains a TSF timer, which can be updated through the timestamp information carried in the first frame, so as to obtain the BPN. For another example, the first device 110 can directly obtain the BPN through the timestamp information carried in the first frame. For another example, the timestamp information can also be obtained through other frames, such as through a beacon frame. The first device 110 maintains a local TSF timer through the obtained timestamp information. After the first device 110 directly obtains the PPN of the first PN through the first frame and indirectly obtains the BPN of the first PN through the timestamp information or the TSF timer, the first PN is obtained according to the PPN of the first PN and the BPN of the first PN.
[0177] In other implementations, considering that the first device 110 can not need to perform a large number of frame transmissions due to a short working time, the length of the first PN can be simplified to reduce the corresponding number of bits. For example, the length of the first PN is simplified from 48 bits to 16 bits, that is, 2 bytes.
[0178] Implementation 2
[0179] In implementation 2, the first PN related information includes third information, and the third information is used to generate the first PN. That is, the first frame can not directly carry the first secret key, but carry information used to generate the first PN, and the first device 110 generates the first PN based on the third information and uses the first PN for replay verification.
[0180] In some implementations, the third information includes timestamp information and / or secret key related information in the first frame.
[0181] For example, the first device 110 takes the value of part of bits of the timestamp information in the first frame as the value of the first PN. For example, the first device 110 maintains a TSF timer through the timestamp information in the first frame, and PN = PN0||PN1||PN2||PN3||PN4||PN5 = part of bits [9:56] of the TSF timer.
[0182] For example, in the above embodiment 1, the first frame can carry the first key related information, and the first device 110 determines the first key used by the first device 110 according to the first key related information. To this end, the first PN can be determined by using the first key. In some implementations, the first PN can have a correlation with the first key, and the first device 110 determines the first PN according to the first key and the correlation. For example, the first frame carries a key number of the first key, the first device 110 obtains the first key according to the key number, and can determine the first PN corresponding to the key number according to the key number. The correlation can be preset or determined based on a certain rule.
[0183] Similarly, the first device 110 can also determine part of the information of the first PN, for example, the first part of the information described above, according to the third information in the first frame, for example, the timestamp information or the key related information.
[0184] In addition to the above implementation 1 and implementation 2, in other implementations, the first frame can also be used to initialize all or part of the information of the first PN. At this time, the first PN related information can be optionally carried in the first frame.
[0185] When the first device 110 receives the first frame, the locally maintained PN counter can be initialized to a preset value, for example, initialized to 0. Wherein, the first frame can trigger the initialization of all information of the first PN; or the first frame can trigger the initialization of part of the information of the first PN, for example, the first frame can trigger the initialization of the first part of the information of the first PN, such as the PPN, and the second part of the information of the first PN, such as the BPN, can be determined based on other information, such as the timestamp information in the frame received by the first device 110 and / or the TSF timer of the first device 110. The specific details of determining the second part of the information of the first PN can refer to the related description in the implementation 1, and will not be described here for brevity.
[0186] In the embodiments of the present application, the first frame can carry multiple pieces of PN related information. That is, the first PN related information can be one of the multiple pieces of PN related information carried by the first frame, wherein the multiple pieces of PN related information are respectively used to determine multiple PNs, for example, multiple first PNs.
[0187] The first frame can be used to indicate a plurality of STAs to transmit or receive data frames, wherein different STAs can use different PNs to perform replay verification on the received frames. Therefore, in some implementations, the plurality of pieces of PN-related information can be associated with the plurality of STAs. For example, the first frame carries a plurality of pieces of PN-related information corresponding to the plurality of STAs, and the plurality of STAs respectively determine the PNs used by themselves based on the corresponding PN-related information to perform replay verification; for another example, the plurality of STAs can also respectively determine part of the PNs used by themselves, for example, a first part of the PNs, based on the corresponding PN-related information, and determine a second part of the PNs used by themselves through other manners, and then obtain the PNs used by themselves to perform replay verification.
[0188] The first frame can also be used to indicate a plurality of groups of STAs to transmit or receive data, wherein different groups of STAs can use different PNs to perform replay verification on the received frames. Therefore, in some implementations, the plurality of pieces of PN-related information can be associated with the plurality of groups of STAs. For example, the first frame carries a plurality of pieces of PN-related information corresponding to the plurality of groups of STAs, and the plurality of groups of STAs respectively determine the PNs used by themselves based on the corresponding PN-related information to perform replay verification; for another example, the plurality of groups of STAs can also respectively determine part of the PNs used by themselves, for example, a first part of the PNs, based on the corresponding PN-related information, and determine a second part of the PNs used by themselves through other manners, and then obtain the PNs used by themselves to perform replay verification.
[0189] In addition, in other implementations, the plurality of pieces of PN-related information in the first frame can also be associated with a plurality of transmission resources. Since the first frame can also indicate a plurality of transmission resources for STAs to transmit frames, the AP cannot determine the identities of the STAs using the resources, and the STAs need to report their identity information using the resources. For example, in a logistics scenario, the AP indicates surrounding STAs to report their identity information through the first frame, for the identification and inventory of goods. In this case, the first frame can carry a plurality of pieces of PN-related information, and the plurality of pieces of PN-related information are associated with the plurality of transmission resources indicated by the first frame.
[0190] For example, as shown in FIG. 11, taking the second device 120 as an AP for example, the second device 120 triggers three first devices 110, i.e., AMP device 1, AMP device 2 and AMP device 3, to use time-division uplink resources to send data frames through a first frame, and different uplink resources correspond to different PN-related information. For example, the PN-related information corresponding to resource 1 is used to determine PN1, the PN-related information corresponding to resource 2 is used to determine PN2, and the PN-related information corresponding to resource 3 is used to determine PN3. When the first device 110 determines to use a certain uplink resource to send a data frame, it can use the PN-related information corresponding to the uplink resource to determine the PN used by it and perform replay verification on the received frame. For example, AMP device 1 uses PN1 to perform replay verification and sends a data frame on resource 1, AMP device 2 uses PN2 to perform replay verification and sends a data frame on resource 2, and AMP device 3 uses PN3 to perform replay verification and sends a data frame on resource 3. Similarly, a plurality of PN-related information can also be used to determine part of the information of a plurality of PNs, e.g., first part of information. The first device 110 determines the corresponding PN-related information according to the transmission resource used by it, and determines the first part of information of the PN based on the PN-related information. The second part of information of the PN can be determined based on the timestamp information and / or TSF timer in the frame sent by the AP, and then the PN used by it is obtained, and the PN is used to perform replay verification.
[0191] The above describes how to determine the PN, i.e., the first PN, through the first frame. The first device 110 can perform replay verification through the first PN. In other implementations, the first device 110 can also determine the PN, e.g., the second PN, through the first frame and the second frame. At this time, the first PN described above can be regarded as part of the information of the second PN, e.g., the first part of information of the second PN. The second PN further includes the second part of information, and the second part of information of the second PN is determined based on the second frame. It can be understood that the first frame is sent by the second device 120, and the second frame can be sent by the second device 120 or by other devices.
[0192] In some implementations, the first part of information of the second PN, i.e., the first PN, is the PPN of the second PN, and the second part of information of the second PN is the BPN of the second PN; or the first part of information of the second PN, i.e., the first PN, is the BPN of the second PN, and the second part of information of the second PN is the PPN of the second PN.
[0193] In some implementations, the first frame is used to trigger the first device 110 to transmit or receive a data frame, and the second frame is used to discover a BSS, for example, the first frame is a trigger frame, and the second frame is a discovery frame. In other implementations, the first frame is used to discover a BSS, and the second frame is used to trigger the first device 110 to transmit or receive a data frame, for example, the first frame is a discovery frame, and the second frame is a trigger frame. The trigger frame is used to trigger the first device 110 to transmit or receive a data frame, and can also carry identification information, transmission resources, and other information used for transmission or reception of the data frame; the discovery frame is used to discover a BSS, for example, the discovery frame can be a beacon frame.
[0194] Taking the first frame as a trigger frame and the second frame as a discovery frame as an example, the first frame can carry the first part of information of the second PN, that is, the first PN, or carry information used to generate the first PN, or the first frame can be used to trigger initialization of the first PN, and there can be an association relationship between the first PN and the transmission resources indicated by the trigger frame. The second frame can carry the second part of information of the second PN, or the second frame can be used to trigger initialization of the second part of information of the second PN.
[0195] The method embodiments of the present application are described in detail above, and the device embodiments of the present application are described in detail below. It should be understood that the description of the method embodiments corresponds to the description of the device embodiments, and therefore, the parts not described in detail can be referred to the method embodiments described above.
[0196] FIG. 12 is a schematic diagram of a communication device according to an embodiment of the present application. The communication device 300 shown in FIG. 12 can be the first device 110 described above. The communication device 300 shown in FIG. 12 can include a receiving unit 310.
[0197] The receiving unit 310 is configured to receive a first frame sent by the second device 120, the first frame being used to discover a BSS or to trigger the first device 110 to transmit or receive a data frame; and the first frame is further used to determine first information, the first information being used to protect a frame transmitted and received by the first device 110.
[0198] In some implementations, the first information includes a first key, and the first key is used to encrypt a data frame transmitted and received by the first device.
[0199] In some implementations, the first frame carries first key-related information, and the first key-related information is used to determine the first key.
[0200] In some implementations, the first key-related information includes the first key.
[0201] In some implementations, the first key is encrypted based on a second key.
[0202] In some embodiments, the second key is determined based on one or more of the following: an authentication frame transmitted by the first device 110 in an authentication procedure; an association frame transmitted by the first device 110 in an association procedure; predefined information.
[0203] In some embodiments, the first key related information comprises second information, which is used to generate the first key.
[0204] In some embodiments, the second information comprises one or more of the following: a third key; a security related parameter used to generate the first key; information used to indicate a key derivation manner of the first key.
[0205] In some embodiments, the first key related information is one of a plurality of key related information carried by the first frame, and the plurality of key related information are respectively used to determine a plurality of keys.
[0206] In some embodiments, the plurality of key related information are associated with a plurality of stations; or, the plurality of key related information are associated with a plurality of groups of stations; or, the plurality of key related information are associated with a plurality of transmission resources.
[0207] In some embodiments, the first frame carries MIC information.
[0208] In some embodiments, the first frame is a trigger frame.
[0209] In some embodiments, the first key is a PTK.
[0210] In some embodiments, the first information comprises a first PN.
[0211] In some embodiments, the first frame carries first PN related information, which is used to determine the first PN.
[0212] In some embodiments, the first PN related information comprises all or part of information of the first PN.
[0213] In some embodiments, the first PN related information comprises first part of information of the first PN, and the first PN further comprises second part of information, which is determined based on timestamp information in a frame received by the first device 110 and / or a TSF timer of the first device 110.
[0214] In some embodiments, the first part of the first PN is a PPN of the first PN, and the second part of the first PN is a BPN of the first PN; or the first part of the first PN is a BPN of the first PN, and the second part of the first PN is a PPN of the first PN.
[0215] In some embodiments, the first PN-related information comprises third information, and the third information is used to generate the first PN.
[0216] In some embodiments, the third information comprises timestamp information and / or key-related information in the first frame.
[0217] In some embodiments, the first PN-related information is one of a plurality of PN-related information carried by the first frame, and the plurality of PN-related information are respectively used to determine a plurality of PNs.
[0218] In some embodiments, the plurality of PN-related information are associated with a plurality of stations; the plurality of PN-related information are associated with a plurality of groups of stations; the plurality of PN-related information are associated with a plurality of transmission resources.
[0219] In some embodiments, the first frame is used to initialize all or part of information in the first PN.
[0220] In some embodiments, the first PN is a first part of a second PN, the second PN further comprises a second part, and the second part of the second PN is determined based on a second frame received by the first device 110.
[0221] In some embodiments, the first frame is used to trigger the first device 110 to send or receive a data frame, and the second frame is used to discover the BSS; or the first frame is used to discover the BSS, and the second frame is used to trigger the first device 110 to send or receive a data frame.
[0222] In some embodiments, the first part of the second PN is a PPN of the second PN, and the second part of the second PN is a BPN of the second PN; or the first part of the second PN is a BPN of the second PN, and the second part of the second PN is a PPN of the second PN.
[0223] In some embodiments, the first frame comprises one or more of the following: identification information of the first device 110; transmission resource used by the first device 110; modulation or coding mode used by the first device 110; data transmission rate used by the first device 110.
[0224] In some embodiments, the first frame is a trigger frame; or, the first frame is a beacon frame for discovering the BSS.
[0225] In some embodiments, the first device 110 is a STA, and the second device 120 is an AP or a power supplying device of the first device 110.
[0226] In some embodiments, the first device 110 is an AMP device.
[0227] Fig. 13 is a schematic diagram of a communication device according to another embodiment of the present application. The communication device 400 shown in Fig. 13 can be the second device 120 described above. The communication device 400 shown in Fig. 13 includes a sending unit 410.
[0228] The sending unit 410 is configured to send a first frame to the first device 110, the first frame being used for discovering a BSS or triggering the first device 110 to send or receive a data frame; and the first frame is further used for determining first information, the first information being used for security protection of frames sent and received by the first device 110.
[0229] In some embodiments, the first information includes a first key, the first key being used for encrypting data frames sent and received by the first device 110.
[0230] In some embodiments, the first frame carries first key related information, the first key related information being used for determining the first key.
[0231] In some embodiments, the first key related information includes the first key.
[0232] In some embodiments, the first key is encrypted based on a second key.
[0233] In some embodiments, the second key is determined based on one or more of the following: an authentication frame transmitted by the first device 110 in an authentication process; an association frame transmitted by the first device 110 in an association process; and predefined information.
[0234] In some embodiments, the first key related information includes second information, the second information being used for generating the first key.
[0235] In some embodiments, the second information includes one or more of the following: a third key; security related parameters used for generating the first key; and information indicating a key derivation manner of the first key.
[0236] In some embodiments, the first key-related information is one of a plurality of key-related information carried by the first frame, and the plurality of key-related information are respectively used to determine a plurality of keys.
[0237] In some embodiments, the plurality of key-related information are associated with a plurality of stations; or the plurality of key-related information are associated with a plurality of groups of stations; or the plurality of key-related information are associated with a plurality of transmission resources.
[0238] In some embodiments, the first frame carries MIC information.
[0239] In some embodiments, the first frame is a trigger frame.
[0240] In some embodiments, the first key is a PTK.
[0241] In some embodiments, the first information includes a first PN.
[0242] In some embodiments, the first frame carries first PN-related information, and the first PN-related information is used to determine the first PN.
[0243] In some embodiments, the first PN-related information includes all or part of information in the first PN.
[0244] In some embodiments, the first PN-related information includes first part information of the first PN, and the first PN further includes second part information, and the second part information of the first PN is determined based on timestamp information in a frame received by the first device 110 and / or a TSF timer of the first device 110.
[0245] In some embodiments, the first part information of the first PN is PPN of the first PN, and the second part information of the first PN is BPN of the first PN; or the first part information of the first PN is BPN of the first PN, and the second part information of the first PN is PPN of the first PN.
[0246] In some embodiments, the first PN-related information includes third information, and the third information is used to generate the first PN.
[0247] In some embodiments, the third information includes timestamp information and / or key-related information in the first frame.
[0248] In some embodiments, the first PN-related information is one of a plurality of PN-related information carried by the first frame, and the plurality of PN-related information are respectively used to determine a plurality of PNs.
[0249] In some embodiments, the plurality of pieces of PN-related information is associated with a plurality of stations; the plurality of pieces of PN-related information is associated with a plurality of groups of stations; the plurality of pieces of PN-related information is associated with a plurality of transmission resources.
[0250] In some embodiments, the first frame is used to initialize all or part of the information in the first PN.
[0251] In some embodiments, the first PN is a first part of information of a second PN, the second PN further comprises a second part of information, and the second part of information of the second PN is determined based on a second frame received by the first device 110.
[0252] In some embodiments, the first frame is used to trigger the first device 110 to transmit or receive a data frame, and the second frame is used to discover the BSS; or, the first frame is used to discover the BSS, and the second frame is used to trigger the first device 110 to transmit or receive a data frame.
[0253] In some embodiments, the first part of information of the second PN is a PPN of the second PN, and the second part of information of the second PN is a BPN of the second PN; or, the first part of information of the second PN is a BPN of the second PN, and the second part of information of the second PN is a PPN of the second PN.
[0254] In some embodiments, the first frame comprises one or more of the following: identification information of the first device 110; a transmission resource used by the first device 110; a modulation or coding mode used by the first device 110; a data transmission rate used by the first device 110.
[0255] In some embodiments, the first frame is a trigger frame; or, the first frame is a beacon frame used to discover the BSS.
[0256] In some embodiments, the first device 110 is a STA, and the second device 120 is an AP or a powered device of the first device 110.
[0257] In some embodiments, the first device 110 is an AMP device.
[0258] It can be understood that the receiving unit 310 may, for example, be a transceiver 530. In addition, the communication device 300 may, optionally, further comprise a memory 520, as shown in FIG. 14.
[0259] Similarly, the sending unit 410 may, for example, be a transceiver 530. In addition, the communication device 400 may, optionally, further comprise a memory 520, as shown in FIG. 14.
[0260] FIG. 14 is a schematic structural diagram of an apparatus for communication according to an embodiment of the present application. The dashed line in FIG. 14 indicates that the unit or module is optional. The apparatus can be used to implement the communication method described in the above method embodiments. The apparatus can be, for example, a chip, a terminal device, or a network device.
[0261] As shown in FIG. 14, the apparatus 500 can include one or more processors 510. The processor 510 can support the apparatus 500 to implement the method described in the above method embodiments. The processor 510 can be a general purpose processor or a dedicated processor. For example, the processor 510 can be a central processing unit (CPU). Alternatively, the processor 510 can also be other general purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic, discrete hardware components, etc. The general purpose processor can be a microprocessor or the processor can also be any conventional processor.
[0262] The apparatus 500 can also include one or more memories 520. The memory 520 stores a program that can be executed by the processor 510, so that the processor 510 performs the method described in the above method embodiments. The memory 520 can be independent of the processor 510 or integrated in the processor 510.
[0263] The apparatus 500 can also include a transceiver 530. The processor 510 can communicate with other devices or chips through the transceiver 530. For example, the processor 510 can perform data transmission and reception with other devices or chips through the transceiver 530.
[0264] An embodiment of the present application provides a communication system. The system includes the first device 110 and / or the second device 120 described above. In some implementations, the system further includes other devices that interact with the first device 110 and / or the second device 120.
[0265] An embodiment of the present application further provides a computer readable storage medium for storing a program. The computer readable storage medium can be applied in the terminal or network device provided by the embodiments of the present application, and the program causes the computer to execute the method performed by the first device 110 or the second device 120 in the various embodiments of the present application.
[0266] The embodiment of the present application further provides a computer program product. The computer program product comprises a program. The computer program product can be applied to the terminal or the network device provided by the embodiment of the present application, and the program causes the computer to execute the method performed by the first device 110 or the second device 120 in the various embodiments of the present application.
[0267] The embodiment of the present application further provides a computer program. The computer program can be applied to the terminal or the network device provided by the embodiment of the present application, and the computer program causes the computer to execute the method performed by the first device 110 or the second device 120 in the various embodiments of the present application.
[0268] It should be understood that the terms "system" and "network" can be used interchangeably in the present application. In addition, the terms used in the present application are only used to explain the specific embodiments of the present application, and are not intended to limit the present application. The terms "first", "second", "third", and "fourth" and the like in the specification and claims of the present application and the drawings are used to distinguish different objects, and are not used to describe a particular order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion.
[0269] In the embodiments of the present application, the "indication" mentioned can be direct indication, or indirect indication, or can be an indication of an associated relationship. For example, A indicates B, which can mean that B can be obtained by A; or A indirectly indicates B, for example, A indicates C, and B can be obtained by C; or A and B have an associated relationship.
[0270] In the embodiments of the present application, "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that determining B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0271] In the embodiments of the present application, the term "corresponding" can mean that there is a direct or indirect corresponding relationship between the two, or can mean that there is an associated relationship between the two, or can mean an indication and being indicated, configuration and being configured, and the like.
[0272] In the embodiments of the present application, "predefined" or "preconfigured" can be realized by pre-storing corresponding codes, tables or other ways that can be used to indicate related information in devices, for example, including AP and STA, and the present application does not limit the specific implementation manner. For example, predefinition can mean definition in a protocol.
[0273] The term "and / or" in the embodiments of the present application is only used to describe the association relationship of the associated objects, and can represent three relationships, for example, A and / or B can represent three cases of A alone, A and B together, and B alone. In addition, the character " / " in this paper generally represents an "or" relationship between the front and rear associated objects.
[0274] In the embodiments of the present application, "including" can mean directly including or indirectly including. Alternatively, "including" mentioned in the embodiments of the present application can be replaced by "indicating" or "used to determine". For example, A includes B can be replaced by A indicates B, or A is used to determine B.
[0275] In various embodiments of the present application, the size of the serial number of the above processes does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0276] In the embodiments of the present application, the "protocol" can refer to a standard protocol in the communication field, for example, it can include WiFi protocol and related protocols applied to future WiFi communication systems, which are not limited in the present application.
[0277] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other ways. For example, the device embodiments described above are only schematic, for example, the division of the units is only a logical function division, and actual implementation can have another division manner, for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the units shown or discussed can be indirect coupling or communication connection through some interface, device or unit, and can be electrical, mechanical or other forms.
[0278] The units described as separate components can or can not be physically separated, and the components shown as units can or can not be physical units, that is, they can be located in one place, or can be distributed on a plurality of network units. According to actual needs, part or all of the units can be selected to achieve the purpose of the embodiments of the present application.
[0279] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit.
[0280] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware or any combination thereof. When implemented by software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of the present application are generated. The computer can be a general purpose computer, a special purpose computer, a computer network, or other programmable apparatus. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another computer readable storage medium, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (such as infrared, wireless, microwave, etc.). The computer readable storage medium can be any available medium that can be read by a computer or a data storage device such as a server, data center, etc. integrated with one or more available media sets. The available media can be magnetic media such as floppy disk, hard disk, magnetic tape, etc., or optical media such as digital video disc (DVD), or semiconductor media such as solid state disk (SSD), etc.
[0281] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or replacements within the technical range disclosed in the present application, which should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A communication method characterized by comprising: Comprising: A first device receives a first frame sent by a second device, the first frame being used for discovering a basic service set (BSS) or for triggering the first device to transmit or receive a data frame; The first frame is further used for determining first information, the first information being used for security protection of frames transmitted and received by the first device.
2. The method of claim 1, wherein, The first information comprises a first key, the first key being used for encrypting data frames transmitted and received by the first device.
3. The method of claim 2, wherein, The first frame carries first key-related information, the first key-related information being used for determining the first key.
4. The method of claim 3, wherein, The first key-related information comprises the first key.
5. The method of claim 4, wherein, The first key is encrypted based on a second key.
6. The method of claim 5, wherein, The second key is determined based on one or more of the following: An authentication frame transmitted by the first device in an authentication procedure; An association frame transmitted by the first device in an association procedure; Predefined information.
7. The method of claim 3, wherein, The first key-related information comprises second information, the second information being used for generating the first key.
8. The method of claim 7, wherein, The second information comprises one or more of the following: A third key; Security-related parameters used for generating the first key; Information used for indicating a key derivation manner of the first key.
9. The method according to any one of claims 3 to 8, characterized in that, The first key-related information is one of a plurality of key-related information carried by the first frame, the plurality of key-related information being respectively used for determining a plurality of keys.
10. The method of claim 9, wherein: The plurality of key-related information is associated with a plurality of stations; or The plurality of key-related information is associated with a plurality of groups of stations; or The plurality of key-related information is associated with a plurality of transmission resources.
11. The method according to any one of claims 2 to 10, characterized in that, The first frame carries message integrity check (MIC) information.
12. The method according to any one of claims 2 to 11, characterized in that, The first frame is a trigger frame.
13. The method according to any one of claims 2 to 12, characterized in that, The first key is a pairwise transmission key (PTK).
14. The method according to any one of claims 1 to 13, characterized in that, The first information comprises a first packet number (PN).
15. The method of claim 14, wherein, The first frame carries first PN-related information, the first PN-related information being used for determining the first PN.
16. The method of claim 15, wherein, The first PN-related information comprises all or part of information of the first PN.
17. The method of claim 16, wherein, The first PN-related information comprises a first part of information of the first PN, the first PN further comprising a second part of information, the second part of information of the first PN being determined based on timestamp information in a frame received by the first device and / or a time synchronization function (TSF) timer of the first device.
18. The method of claim 17, wherein: The first part of information of the first PN is a partial packet number (PPN) of the first PN, and the second part of information of the first PN is a basic packet number (BPN) of the first PN; or The first part of information of the first PN is a BPN of the first PN, and the second part of information of the first PN is a PPN of the first PN. The first PN-related information comprises third information, the third information being used for generating the first PN.
19. The method of claim 15, wherein, The third information comprises timestamp information and / or key-related information in the first frame.
20. The method of claim 19, wherein, The first PN-related information is one of a plurality of PN-related information carried by the first frame, the plurality of PN-related information being respectively used for determining a plurality of PNs.
21. The method of any one of claims 15-20, wherein, 22. The method of claim 21, wherein the plurality of pieces of PN-related information are associated with a plurality of stations.
23. The method of claim 21, wherein the plurality of pieces of PN-related information are associated with a plurality of groups of stations.
24. The method of claim 21, wherein the plurality of pieces of PN-related information are associated with a plurality of transmission resources.
25. The method of claim 21, wherein the first frame is used to initialize all or part of the first PN.
23. The method of claim 14, wherein, 26. The method of claim 21, wherein the first PN is a first part of a second PN, the second PN further comprises a second part, and the second part of the second PN is determined based on a second frame received by the first device.
24. The method of any one of claims 14-23, wherein, 27. The method of claim 24, wherein the first frame is used to trigger the first device to transmit or receive a data frame, and the second frame is used to discover the BSS; or 28. The method of claim 24, wherein the first frame is used to discover the BSS, and the second frame is used to trigger the first device to transmit or receive a data frame.
29. The method of claim 24 or 25, wherein the first part of the second PN is a PPN of the second PN, and the second part of the second PN is a BPN of the second PN; or 30. The method of claim 24 or 25, wherein the first part of the second PN is a BPN of the second PN, and the second part of the second PN is a PPN of the second PN.
31. The method of claim 24, wherein the first frame comprises one or more of:
32. The method of claim 24, wherein the first frame is a trigger frame; or 33. The method of claim 24, wherein the first frame is a beacon frame used to discover the BSS.
34. The method of claim 24, wherein the first device is a station (STA), and the second device is an access point (AP) or a power-enabling device of the first device.
27. The method of any one of claims 14 to 26, wherein, 35. The method of claim 24, wherein the first device is an ambient-powered (AMP) device.
36. The method of claim 24, comprising:
37. The method of claim 24, wherein the first frame is used to discover a basic service set (BSS) or to trigger the first device to transmit or receive a data frame.
38. The method of claim 24, wherein the first frame is further used to determine first information used to secure frames transmitted and received by the first device.
39. The method of claim 24, wherein the first information comprises a first key used to encrypt data frames transmitted and received by the first device.
40. The method of claim 24, wherein the first frame carries first key-related information used to determine the first key.
41. The method of claim 24, wherein the first key-related information comprises the first key.
42. The method of claim 24, wherein the first key is encrypted based on a second key.
29. The method of any one of claims 1 to 28, wherein, 43. The method of claim 24, wherein the second key is determined based on one or more of:
30. The method of any one of claims 1 to 29, wherein, 44. The method of claim 24, wherein the second key is determined based on a predefined information.
31. A method of communication, comprising:
45. The method of claim 24, wherein the first key-related information comprises second information used to generate the first key.
46. The method of claim 24, wherein the second information comprises one or more of:
47. The method of claim 24, wherein the second information comprises a third key.
32. The method of claim 31, wherein, 48. The method of claim 24, wherein the second information comprises a security-related parameter used to generate the first key.
33. The method of claim 32, wherein, 49. The method of claim 24, wherein the second information comprises information used to indicate a key derivation method of the first key.
34. The method of claim 33, wherein, 35. The method of claim 34, wherein, 36. The method of claim 35, wherein, 37. The method of claim 33, wherein, 38. The method of claim 37, wherein, 39. The method of any one of claims 33-38, wherein, The first key-related information is one of a plurality of key-related information carried by the first frame, and the plurality of key-related information are respectively used to determine a plurality of keys.
40. The method of claim 39, wherein the first key-related information is associated with a plurality of stations. The plurality of key-related information are associated with a plurality of stations; or The plurality of key-related information are associated with a plurality of stations; or The plurality of key-related information are associated with a plurality of transmission resources.
41. The method of any one of claims 32-40, wherein, The first frame carries message integrity check (MIC) information.
42. The method of any one of claims 32-41, wherein, The first frame is a trigger frame.
43. The method of any one of claims 32-42, wherein, The first key is a pairwise transmission key (PTK).
44. The method of any one of claims 31-43, wherein, The first information comprises a first packet number (PN).
45. The method of claim 44, wherein, The first frame carries first PN-related information, and the first PN-related information is used to determine the first PN.
46. The method of claim 45, wherein, The first PN-related information comprises all or part of information in the first PN.
47. The method of claim 46, wherein, The first PN-related information comprises first part information of the first PN, and the first PN further comprises second part information, and the second part information of the first PN is determined based on timestamp information in a frame received by the first device and / or a time synchronization function (TSF) timer of the first device.
48. The method of claim 47, wherein the first part information of the first PN is part of a packet number (PPN) of the first PN, and the second part information of the first PN is a basic packet number (BPN) of the first PN. The first part information of the first PN is a BPN of the first PN, and the second part information of the first PN is a PPN of the first PN. The first PN-related information comprises third information, and the third information is used to generate the first PN. The third information comprises timestamp information in the first frame and / or key-related information.
49. The method of claim 45, wherein, The first PN-related information is one of a plurality of PN-related information carried by the first frame, and the plurality of PN-related information are respectively used to determine a plurality of PNs.
50. The method of claim 49, wherein, 52. The method of claim 51, wherein the plurality of PN-related information are associated with a plurality of stations.
51. The method of any one of claims 45-50, wherein, The plurality of PN-related information are associated with a plurality of stations; or The plurality of PN-related information are associated with a plurality of transmission resources. The first frame is used to initialize all or part of information in the first PN. The first PN is first part information of a second PN, and the second PN further comprises second part information, and the second part information of the second PN is determined based on a second frame received by the first device.
55. The method of claim 54, wherein the first frame is used to trigger the first device to send or receive a data frame, and the second frame is used to discover the BSS; or 53. The method of claim 44, wherein, The first frame is used to discover the BSS, and the second frame is used to trigger the first device to send or receive a data frame.
54. The method of any one of claims 44-53, wherein, 56. The method of claim 54 or 55, wherein the first part information of the second PN is a PPN of the second PN, and the second part information of the second PN is a BPN of the second PN. The first part information of the second PN is a BPN of the second PN, and the second part information of the second PN is a PPN of the second PN. The first part of the information of the second PN is a BPN of the second PN, and the second part of the information of the second PN is a PPN of the second PN.
57. The method of any one of claims 44-56, wherein, The first frame comprises one or more of the following: identification information of the first device; transmission resource used by the first device; modulation or coding mode used by the first device; data transmission rate used by the first device.
58. The method of any of claims 44-57, wherein, the first frame is a trigger frame; or the first frame is a beacon frame used for discovering the BSS.
59. The method of any one of claims 31-58, wherein, The first device is a station (STA), and the second device is an access point (AP) or a power supply device of the first device.
60. The method of any one of claims 31-59, wherein, The first device is an ambient-powered (AMP) device.
61. A communications device, characterized by The communication device is a first device, comprising: a receiving unit configured to receive a first frame sent by a second device, the first frame being used for discovering a basic service set (BSS) or for triggering the first device to send or receive a data frame; wherein the first frame is further used to determine first information, the first information being used for security protection of frames sent and received by the first device.
62. The apparatus of claim 61, wherein, The first information comprises a first key, the first key being used for encrypting data frames sent and received by the first device.
63. The apparatus of claim 62, wherein, The first frame carries first key-related information, the first key-related information being used for determining the first key.
64. The apparatus of claim 63, wherein, The first key-related information comprises the first key.
65. The apparatus of claim 64, wherein, The first key is encrypted based on a second key.
66. The apparatus of claim 65, wherein, The second key is determined based on one or more of the following: an authentication frame transmitted by the first device in an authentication process; an association frame transmitted by the first device in an association process; predefined information.
67. The apparatus of claim 63, wherein, The first key-related information comprises second information, the second information being used for generating the first key.
68. The apparatus of claim 67, wherein, The second information comprises one or more of the following: a third key; security-related parameters used for generating the first key; information used for indicating a key derivation mode of the first key.
69. The apparatus of any one of claims 63-68, wherein, The first key-related information is one of a plurality of pieces of key-related information carried by the first frame, and the plurality of pieces of key-related information are respectively used for determining a plurality of keys.
70. The device of claim 69, wherein, the plurality of pieces of key-related information are associated with a plurality of stations; or the plurality of pieces of key-related information are associated with a plurality of groups of stations; or the plurality of pieces of key-related information are associated with a plurality of transmission resources.
71. The apparatus of any one of claims 62-70, wherein, The first frame carries message integrity check (MIC) information.
72. The apparatus of any one of claims 62-71, wherein, The first frame is a trigger frame.
73. The apparatus of any one of claims 62-72, wherein, The first key is a pairwise transmission key (PTK).
74. The apparatus of any one of claims 61-73, wherein, The first information comprises a first packet number (PN).
75. The apparatus of claim 74, wherein, The first frame carries first PN-related information, the first PN-related information being used for determining the first PN.
76. The apparatus of claim 75, wherein, The first PN-related information comprises all or part of the information of the first PN. The first PN-related information comprises all or part of the information of the first PN.
77. The apparatus of claim 76, wherein, The first PN-related information comprises first part information of the first PN, the first PN further comprises second part information, and the second part information of the first PN is determined based on timestamp information in a frame received by the first device and / or a time synchronization function (TSF) timer of the first device.
78. The device of claim 77, wherein, the first part information of the first PN is a partial packet number (PPN) of the first PN, and the second part information of the first PN is a basic packet number (BPN) of the first PN; or, the first part information of the first PN is a BPN of the first PN, and the second part information of the first PN is a PPN of the first PN.
79. The apparatus of claim 75, wherein, The first PN-related information comprises third information, and the third information is used to generate the first PN.
80. The apparatus of claim 79, wherein, The third information comprises timestamp information in the first frame and / or key-related information.
81. The apparatus of any one of claims 75-80, wherein, The first PN-related information is one of a plurality of PN-related information carried by the first frame, and the plurality of PN-related information are respectively used to determine a plurality of PNs.
82. The device of claim 81, wherein, the plurality of PN-related information are associated with a plurality of stations; the plurality of PN-related information are associated with a plurality of groups of stations; the plurality of PN-related information are associated with a plurality of transmission resources.
83. The apparatus of claim 74, wherein, The first frame is used to initialize all or part of information in the first PN.
84. The apparatus of any one of claims 74-83, wherein, The first PN is first part information of a second PN, the second PN further comprises second part information, and the second part information of the second PN is determined based on a second frame received by the first device.
85. The device of claim 84, wherein, the first frame is used to trigger the first device to transmit or receive a data frame, and the second frame is used to discover the BSS; or the first frame is used to discover the BSS, and the second frame is used to trigger the first device to transmit or receive a data frame.
86. The device of claim 84 or 85, wherein, the first part information of the second PN is a PPN of the second PN, and the second part information of the second PN is a BPN of the second PN; or, the first part information of the second PN is a BPN of the second PN, and the second part information of the second PN is a PPN of the second PN.
87. The apparatus of any one of claims 74-86, wherein, The first frame comprises one or more of: identification information of the first device; a transmission resource used by the first device; a modulation or coding mode used by the first device; a data transmission rate used by the first device.
88. The device of any one of claims 74-87, wherein, the first frame is a trigger frame; or the first frame is a beacon frame used to discover the BSS.
89. The apparatus of any one of claims 61-88, wherein, The first device is a station (STA), and the second device is an access point (AP) or a power supply device of the first device.
90. The apparatus of any one of claims 61-89, wherein, The first device is an ambient power supply (AMP) device.
91. A communications device, characterized by The communication device is a second device, and the second device comprises: The sending unit is configured to send a first frame to a first device, the first frame being used for discovering a basic service set (BSS) or triggering the first device to send or receive a data frame; The first frame is further used for determining first information, the first information being used for security protection of frames sent and received by the first device.
92. The apparatus of claim 91, wherein, The first information comprises a first key, the first key being used for encrypting data frames sent and received by the first device.
93. The apparatus of claim 92, wherein, The first frame carries first key-related information, the first key-related information being used for determining the first key.
94. The apparatus of claim 93, wherein, The first key-related information comprises the first key.
95. The apparatus of claim 94, wherein, The first key is encrypted based on a second key.
96. The apparatus of claim 95, wherein, The second key is determined based on one or more of the following: an authentication frame transmitted by the first device in an authentication process; an association frame transmitted by the first device in an association process; predefined information.
97. The apparatus of claim 93, wherein, The first key-related information comprises second information, the second information being used for generating the first key.
98. The apparatus of claim 97, wherein, The second information comprises one or more of the following: a third key; security-related parameters used for generating the first key; information used for indicating a key derivation manner of the first key.
99. The apparatus of any one of claims 93-98, wherein, The first key-related information is one of a plurality of key-related information carried by the first frame, the plurality of key-related information being respectively used for determining a plurality of keys.
100. The device of claim 99, wherein: the plurality of key-related information is associated with a plurality of stations; or the plurality of key-related information is associated with a plurality of groups of stations; or the plurality of key-related information is associated with a plurality of transmission resources.
101. The apparatus of any one of claims 92-100, wherein, The first frame carries message integrity check (MIC) information.
102. The apparatus of any one of claims 92-101, wherein, The first frame is a trigger frame.
103. The apparatus of any one of claims 92-102, wherein, The first key is a pairwise transmission key (PTK).
104. The apparatus of any one of claims 91-103, wherein, The first information comprises a first packet number (PN).
105. The apparatus of claim 104, wherein, The first frame carries first PN-related information, the first PN-related information being used for determining the first PN.
106. The apparatus of claim 105, wherein, The first PN-related information comprises all or part of information in the first PN.
107. The apparatus of claim 106, wherein, The first PN-related information comprises first part information of the first PN, the first PN further comprising second part information, the second part information of the first PN being determined based on timestamp information in a frame received by the first device and / or a time synchronization function (TSF) timer of the first device.
108. The device of claim 107, wherein: the first part information of the first PN is a partial packet number (PPN) of the first PN, and the second part information of the first PN is a basic packet number (BPN) of the first PN; or the first part information of the first PN is a BPN of the first PN, and the second part information of the first PN is a PPN of the first PN. The first PN-related information comprises third information, the third information being used for generating the first PN.
109. The apparatus of claim 105, wherein, The third information comprises timestamp information and / or key-related information in the first frame.
110. The apparatus of claim 109, wherein, 111. The apparatus of any one of claims 105-110, wherein, The first PN-related information is one of a plurality of PN-related information carried by the first frame, and the plurality of PN-related information are respectively used to determine a plurality of PNs.
112. The device of claim 111, wherein, the plurality of PN-related information are associated with a plurality of stations; the plurality of PN-related information are associated with a plurality of groups of stations; the plurality of PN-related information are associated with a plurality of transmission resources.
113. The apparatus of claim 104, wherein, the first frame is used to initialize all or part of the first PN.
114. The apparatus of any one of claims 104-113, wherein, the first PN is a first part of a second PN, the second PN further comprises a second part, and the second part of the second PN is determined based on a second frame received by the first device.
115. The device of claim 114, wherein, the first frame is used to trigger the first device to transmit or receive a data frame, and the second frame is used to discover the BSS; or the first frame is used to discover the BSS, and the second frame is used to trigger the first device to transmit or receive a data frame.
116. The device of claim 114 or 115, wherein, the first part of the second PN is a PPN of the second PN, and the second part of the second PN is a BPN of the second PN; or the first part of the second PN is a BPN of the second PN, and the second part of the second PN is a PPN of the second PN. the first frame comprises one or more of: identification information of the first device; 117. The apparatus of any one of claims 104-116, wherein, a transmission resource used by the first device; a modulation or coding scheme used by the first device; a data transmission rate used by the first device.
118. The device of any of claims 104-117, wherein, the first frame is a trigger frame; or the first frame is a beacon frame used to discover the BSS. the first device is a station (STA), and the second device is an access point (AP) or a power- friendly device of the first device. the first device is an ambient-powered (AMP) device.
119. The apparatus of any one of claims 91 to 118, wherein, a transceiver, a memory, and a processor, the memory is configured to store a program, the processor is configured to invoke the program in the memory and control the transceiver to receive or transmit a signal, so that the communication device performs the method of any of claims 1-30 or the method of any of claims 31-60.
120. The apparatus of any one of claims 91 to 119, wherein, a processor configured to invoke a program from a memory, so that the apparatus performs the method of any of claims 1-30 or the method of any of claims 31-60.
121. A communications device, characterized by a processor configured to invoke a program from a memory, so that the chip performs the method of any of claims 1-30 or the method of any of claims 31-60.
122. An apparatus, comprising: a program is stored thereon, the program causes a computer to perform the method of any of claims 1-30 or the method of any of claims 31-60.
123. A chip, characterized by 124. A computer-readable storage medium, characterized in that, 125. A computer program product, characterized in that, comprising a program causing a computer to perform the method of any one of claims 1 to 30, or the method of any one of claims 31 to 60.
126. A computer program characterised in that, The computer program causes a computer to perform the method of any one of claims 1 to 30, or the method of any one of claims 31 to 60.
Citation Information
Patent Citations
Method and apparatus for transmitting and receiving frame supporting short MAC header in wireless LAN system
CN105917597A
Anti-replay secure communication processing method and device
CN109120608A
System and method for secure and quick wake up of a station
CN110024448A
Frame Structure for Medium Access in Body Area Networks (BAN)
US20100202354A1
Wireless communication apparatus, communication method, and communication system
US20180176952A1