Communication method, communication device and communication system

By carrying identification information in the wireless frame to identify the device's encrypted transmission capability, and encrypting the control and management frames, the problem of frame tampering in Wi-Fi technology is solved, thus improving the reliability and security of communication.

WO2026011366A1PCT designated stage Publication Date: 2026-01-15BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/104816
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-10
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

In existing Wi-Fi technology, the lack of encryption of control and management frames makes them vulnerable to tampering by attackers, affecting communication reliability and the transmission process.

Method used

By carrying identification information in the radio frame to identify the device's encrypted transmission capability, encrypted transmission of control and management frames is achieved, thereby improving communication reliability.

Benefits of technology

It effectively prevents attackers from tampering with the content of control frames and management frames, thereby improving the reliability and security of the communication process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024104816_15012026_PF_FP_ABST
    Figure CN2024104816_15012026_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure relate to a communication method, a communication device and a communication system. The communication method comprises: a first device determining a first radio frame, wherein the first radio frame comprises first identification information, the first identification information is used for identifying support capability information of the first device performing encryption and transmission on a second radio frame, and a frame type of the second radio frame comprises at least one of a control frame and a management frame; and sending the first radio frame. The embodiments of the present disclosure provide a mechanism supporting frame encryption.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods, communication equipment and communication systems Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a communication method, communication device and communication system. Background Technology

[0002] With the continuous development of Wireless Fidelity (Wi-Fi) technology, researchers have proposed the next generation of Wi-Fi technology: Ultra High Reliability (UHR), which aims to improve the reliability of WLAN connections, reduce latency, increase manageability, and increase throughput.

[0003] To ensure the reliability of communication, attackers may forge or tamper with frames containing a large amount of communication information, such as control frames and management frames. For example, in existing Wi-Fi technology, some control frames are transmitted as Class 1 frames without encryption, such as basic trigger frames. If these frames are attacked, it will affect the entire transmission process, such as causing communication interruption or transmission failure. Therefore, a mechanism that supports frame encryption is needed.

[0004] Summary of the Invention

[0005] This disclosure provides a communication method, communication device, and communication system to provide a mechanism that supports frame encryption.

[0006] In a first aspect, embodiments of this disclosure provide a communication method executed by a first device, the method comprising:

[0007] A first wireless frame is determined; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of the second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame;

[0008] Send the first wireless frame.

[0009] Secondly, this disclosure also provides a communication method executed by a second device, the method comprising:

[0010] Receive a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame.

[0011] Thirdly, embodiments of this disclosure also provide a communication device, the communication device including a first device, comprising:

[0012] A determining module is configured to determine a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame;

[0013] The transmitting module is used to transmit the first wireless frame.

[0014] Fourthly, embodiments of this disclosure also provide a communication device, which is a second device, comprising:

[0015] A receiving module is configured to receive a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; and the frame type of the second wireless frame includes at least one of control frame and management frame.

[0016] Fifthly, embodiments of this disclosure also provide a communication device, the communication device including a first device, comprising:

[0017] One or more processors;

[0018] The communication device is used to execute the communication method described in the first aspect of the present disclosure.

[0019] Sixthly, embodiments of this disclosure also provide a communication device, which is a second device, comprising:

[0020] One or more processors;

[0021] The communication device is used to execute the communication method described in the second aspect of the embodiments of this disclosure.

[0022] In a seventh aspect, embodiments of this disclosure also provide a communication system, including a first device and a second device;

[0023] The first device is used to determine a first wireless frame; wherein the first wireless frame includes first identification information, which is used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame; and the first wireless frame is transmitted.

[0024] The second device is used to receive the first wireless frame.

[0025] Eighthly, embodiments of this disclosure also provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the communication method as described in the first aspect of this disclosure, or to perform the communication method as described in the second aspect of this disclosure.

[0026] In this embodiment of the present disclosure, the first device determines and sends a first wireless frame; the first identification information carried in the first wireless frame identifies the first device's ability to encrypt and transmit a second wireless frame; the frame type of the second wireless frame includes at least one of control frames and management frames; thus, during the communication between the first device and the second device, the second wireless frame, whose frame type includes at least one of control frames and management frames, can be encrypted and transmitted, preventing the second wireless frame from being forged or tampered with by an attacker, and improving the reliability of the communication process.

[0027] Additional aspects and advantages of embodiments of this disclosure will be set forth in part in the description which follows, and will become apparent from the description or may be learned by practice of this disclosure. Attached Figure Description

[0028] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.

[0029] Figure 1 is a schematic diagram of the architecture of the communication system provided in an embodiment of this disclosure;

[0030] Figure 2 is one of the interactive schematic diagrams of the communication method provided in the embodiments of this disclosure;

[0031] Figure 3 is a second interactive schematic diagram of the communication method provided in the embodiments of this disclosure;

[0032] Figure 4 is a flowchart illustrating one of the communication methods provided in this embodiment of the present disclosure;

[0033] Figure 5 is a second schematic flowchart of the communication method provided in this embodiment of the present disclosure;

[0034] Figure 6 is a schematic diagram of the structure of the first device proposed in an embodiment of this disclosure;

[0035] Figure 7 is a schematic diagram of the structure of the second device proposed in an embodiment of this disclosure;

[0036] Figure 8 is a schematic diagram of the structure of the terminal proposed in an embodiment of this disclosure;

[0037] Figure 9 is a schematic diagram of the chip structure proposed in an embodiment of this disclosure. Detailed Implementation

[0038] This disclosure presents a communication method, communication device, and communication system.

[0039] In a first aspect, embodiments of this disclosure provide a communication method executed by a first device, the method comprising:

[0040] A first wireless frame is determined; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of the second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame;

[0041] Send the first wireless frame.

[0042] In the above embodiment, the first device determines and sends a first wireless frame; the first identification information carried in the first wireless frame identifies: the first device's support capability information for encrypted transmission of the second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame; thus, during the communication between the first device and the second device, the second wireless frame, whose frame type includes at least one of control frame and management frame, can be encrypted and transmitted, preventing the second wireless frame from being forged and tampered with by attackers, and improving the reliability of the communication process.

[0043] In conjunction with some embodiments of the first aspect, in some embodiments, the first radio frame includes a robust secure network extension RSNEX information element, wherein the first identification information is carried in the Extended RSN capabilities field of the RSNEX information element.

[0044] In the above embodiments, the first identification information can be carried in the Extended RSN capabilities field of the RSNEX information element in the first wireless frame to identify the first device's ability to support encrypted transmission of the second wireless frame.

[0045] In conjunction with some embodiments of the first aspect, in some embodiments, the first identification information includes at least one identification bit;

[0046] When the parameter value of the identifier bit is set to the first parameter value, the first identifier information is used to identify that the first device supports encrypted transmission of the second wireless frame;

[0047] or

[0048] When the parameter value of the identifier bit is set to the second parameter value, the first identifier information is used to identify that the first device does not support encrypted transmission of the second wireless frame.

[0049] In the above embodiments, the parameter value of the identifier bit corresponding to the first identifier information can be used to identify the first device's ability to perform encrypted transmission of the second wireless frame.

[0050] In conjunction with some embodiments of the first aspect, in some embodiments, when the frame type of the control frame is a security control implementation frame, or the protocol version corresponding to the control frame is PV0, or the protocol version corresponding to the control frame is PV1, the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame.

[0051] In the above embodiments, it can be determined whether the first device supports encrypted transmission of the control frame by the frame type of the control frame, the protocol version corresponding to the control frame, etc.

[0052] In conjunction with some embodiments of the first aspect, in some embodiments, where the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame, the method further includes:

[0053] After encrypting the second wireless frame, the encrypted second wireless frame is sent using the communication parameters corresponding to state 4.

[0054] In the communication parameters corresponding to state 4, the first device has been authenticated by the wireless LAN and has been associated with the second device, and the wireless LAN control port is not blocked or does not exist.

[0055] If the first device has already established an association with the second device, a robust secure network connection RSNA may or may not need to be established.

[0056] In the above embodiments, by using the communication parameters corresponding to state 4 to transmit the encrypted second wireless frame, the reliability of the transmission process can be guaranteed.

[0057] In conjunction with some embodiments of the first aspect, in some embodiments, the frame type of the encrypted second wireless frame is class 3 (third type).

[0058] In the above embodiments, by determining the frame type of the encrypted second wireless frame as a third type, the security level of the encrypted wireless frame can be determined by the frame type of the encrypted second wireless frame.

[0059] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0060] Receive a third wireless frame; wherein the third wireless frame includes second identification information, the second identification information being used to identify: the second device's ability to perform encrypted transmission of a fourth wireless frame; the frame type of the fourth wireless frame includes at least one of control frame and management frame.

[0061] In the above embodiments, by receiving the third wireless frame, the second device can determine its ability to encrypt and transmit the fourth wireless frame by means of the content identified by the second identification information in the second wireless frame.

[0062] In conjunction with some embodiments of the first aspect, in some embodiments, after receiving the third radio frame, the method further includes:

[0063] The encrypted fourth wireless frame is received using the communication parameters corresponding to state 4.

[0064] In the above embodiments, by using the communication parameters corresponding to state 4 to receive the encrypted fourth wireless frame, the reliability of the transmission process can be guaranteed.

[0065] Secondly, embodiments of this disclosure provide a communication method executed by a second device, the method comprising:

[0066] Receive a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame.

[0067] In conjunction with some embodiments of the second aspect, in some embodiments, the first radio frame includes an RSNEX information element, and the first identification information is carried in the Extended RSN capabilities field of the RSNEX information element.

[0068] In conjunction with some embodiments of the second aspect, in some embodiments, the first identification information includes at least one identification bit;

[0069] When the parameter value of the identifier bit is set to the first parameter value, the first identifier information is used to identify that the first device supports encrypted transmission of the second wireless frame;

[0070] or

[0071] When the parameter value of the identifier bit is set to the second parameter value, the first identifier information is used to identify that the first device does not support encrypted transmission of the second wireless frame.

[0072] In conjunction with some embodiments of the second aspect, in some embodiments, when the frame type of the control frame is a security control implementation frame, or the protocol version corresponding to the control frame is PV0, or the protocol version corresponding to the control frame is PV1, the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame.

[0073] In conjunction with some embodiments of the second aspect, in some embodiments, where the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame, the method further includes:

[0074] The encrypted second wireless frame is received using the communication parameters corresponding to state 4.

[0075] In the communication parameters corresponding to state 4, the first device has been authenticated by the wireless LAN and has established an association with the second device, and the wireless LAN control port is not blocked or does not exist.

[0076] If the first device has already established an association with the second device, the RSNA may or may not need to be established.

[0077] In conjunction with some embodiments of the second aspect, in some embodiments, the frame type of the encrypted second wireless frame is class 3 (third type).

[0078] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0079] A third wireless frame is determined; wherein the third wireless frame includes second identification information, the second identification information being used to identify: the second device's ability to perform encrypted transmission of the fourth wireless frame; the frame type of the fourth wireless frame includes at least one of control frame and management frame;

[0080] The third wireless frame is sent.

[0081] In conjunction with some embodiments of the second aspect, in some embodiments, after sending the third radio frame, the method further includes:

[0082] After encrypting the fourth wireless frame, the encrypted fourth wireless frame is sent using the communication parameters corresponding to state 4.

[0083] Thirdly, embodiments of this disclosure also provide a communication device, the communication device including a first device, the first device including at least one of a determining module and a sending module; wherein the first device is used to execute an optional implementation of the first aspect.

[0084] Fourthly, embodiments of this disclosure also provide a communication device, which is a second device, comprising: a receiving module; wherein the second device is used to execute an optional implementation of the second aspect.

[0085] Fifthly, embodiments of this disclosure also provide a first device, comprising:

[0086] One or more processors;

[0087] The first device is used to execute an optional implementation of the first aspect.

[0088] Sixthly, embodiments of this disclosure also provide a second device, comprising:

[0089] One or more processors;

[0090] The second device is used to execute an optional implementation of the second aspect.

[0091] In a seventh aspect, embodiments of this disclosure also provide a communication system, including a first device and a second device; wherein the first device is configured to perform the optional implementation as described in the first aspect, and the second device is configured to perform the optional implementation as described in the second aspect.

[0092] Eighthly, embodiments of this disclosure also provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the optional implementation described in the first or second aspect.

[0093] Ninthly, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the optional implementations of the first or second aspect.

[0094] In a tenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in an optional implementation of the first or second aspect.

[0095] Eleventhly, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described in the optional implementations of the first or second aspect above.

[0096] It is understood that the aforementioned communication devices, communication systems, storage media, program products, computer programs, chips, or chip systems are all used to execute the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects they can achieve can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0097] This disclosure provides communication methods, communication devices, and communication systems. In some embodiments, the terms "communication method" and "signal transmission method," "wireless frame transmission method," etc., can be used interchangeably, as can the terms "information processing system" and "communication system."

[0098] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0099] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0100] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0101] In the embodiments disclosed herein, "multiple" refers to two or more.

[0102] In some embodiments, the terms “at least one of”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0103] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of B); in some embodiments, B (execute B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, A and B (both A and B are executed). The same applies when there are more branches such as A, B, C, etc.

[0104] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execution of A regardless of B); in some embodiments, B (execution of B regardless of A); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, C, etc.

[0105] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0106] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0107] In some embodiments, the terms “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “if…”, “if…”, etc., can be used interchangeably.

[0108] In some embodiments, the terms “greater than”, “greater than or equal to”, “not less than”, “more than”, “more than or equal to”, “not less than”, “higher than”, “higher than or equal to”, “not lower than”, and “above” can be used interchangeably, as can the terms “less than”, “less than or equal to”, “not greater than”, “less than”, “less than or equal to”, “not more than”, “lower than”, “lower than or equal to”, “not higher than”, and “below”.

[0109] In some embodiments, the apparatus and device may be interpreted as physical or virtual, and their names are not limited to the names recorded in the embodiments. In some cases, they may also be understood as "equipment", "device", "circuit", "network element", "node", "function", "unit", "section", "system", "network", "chip", "chip system", "entity", "body", etc.

[0110] In some embodiments, "network" can be interpreted as devices included in the network, such as access network devices, core network devices, etc.

[0111] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0112] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0113] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0114] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0115] As shown in Figure 1, the communication system 100 includes a first device 101 and a second device 102; wherein, the first device 101 and the second device 102 can be a station (STA), an access point (AP), an access point multi-link device (AP MLD), and a non-access point multi-link device (Non-AP MLD), respectively.

[0116] In some embodiments, the site equipment includes, for example, a wireless communication chip, a wireless sensor, or a wireless communication terminal that supports WiFi communication. Optionally, the wireless communication terminal may be at least one of, but is not limited to, a mobile phone, a wearable device, an IoT device that supports WiFi communication, a car with WiFi communication capabilities, a smart car, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and a wireless terminal device in a smart home.

[0117] Specifically, the site equipment can be a terminal device or network device with a Wi-Fi chip. Optionally, the site equipment can support multiple WLAN standards such as 802.11ax, 802.11be, 802.11ac, 802.11n, 802.11g, 802.11b, 802.11a, 802.11bf, and 802.11bn, as well as the next-generation 802.11 protocol, but is not limited to these.

[0118] In some embodiments, the access point device can be an access point for mobile terminals to access a wired network. An AP acts as a bridge connecting wired and wireless networks, its main function being to connect various wireless network clients together and then connect the wireless network to the Ethernet. Specifically, an AP can be a terminal device or network device with a Wi-Fi chip. Optionally, the AP can support various WLAN standards such as 802.11ax, 802.11be, 802.11ac, 802.11n, 802.11g, 802.11b, 802.11a, 802.11bf, and 802.11bn, as well as the next-generation 802.11 protocol, but is not limited to these.

[0119] Optionally, in this embodiment of the disclosure, AP and STA can be devices that support multiple connections. For example, they can be represented as Access Point Multi-Link Device (AP MLD) and Non-Access Point Multi-Link Device (Non-AP MLD), respectively. AP MLD can represent an access point that supports multiple connection communication functions, and non-AP MLD can represent a station that supports multiple connection communication functions.

[0120] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.

[0121] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. ​​The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.

[0122] The embodiments disclosed herein can be applied to Wireless Local Area Networks (WLANs), such as LANs using the 802.11 series of protocols. In a WLAN, a Basic Service Set (BSS) is a fundamental component. An BSS network consists of site devices with some association within a specific coverage area. One type of association is where sites communicate directly with each other in a self-organizing network; this is called an Independent Basic Service Set (IBSS). Another more common scenario is that in a BSS network, there is only one central site dedicated to managing the BSS, called the Access Point (AP) device, and all other STAs in the network are associated with it. Other sites in the BSS network that are not the central site are called terminals, also known as non-AP STAs; terminals and non-AP STAs are collectively referred to as STAs. When describing STAs, it is not necessary to distinguish between APs and non-AP STAs. Within the same BSS network, due to distance, transmission power, etc., a STA cannot detect other STAs that are far away; they are each other's hidden nodes.

[0123] Figure 2 is an interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 2, the method includes:

[0124] Step 201, the first device determines a first wireless frame; wherein, the first wireless frame includes first identification information, the first identification information being used to identify: the first device's support capability information for encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame.

[0125] In current Wi-Fi applications, additional authentication data (AAD) is typically constructed to further encrypt the data frames to be transmitted, thereby ensuring the security of the data frames to be transmitted.

[0126] The AAD architecture can be shown in Table 1 below:

[0127] Among them, FC, A1, A2, A3, SC, A4, and QC correspond to the Frame Control, Address1, Address2, Address3, Sequence Control (SC), and Quality of Service Control (Qos Control) fields in the MAC header of the plaintext MPDU (Medium Access Control Sublayer PDU, MAC-level Protocol Data Unit; MAC stands for Medium Access Control; PDU stands for Protocol Data Unit).

[0128] Furthermore, the length of AAD is shown in Table 2 below, depending on whether one or more of QC and A4 are present or absent:

[0129] The structure of the MAC frame is shown in Table 3 below:

[0130] The fields other than the Frame Body and Frame Check Sequence (FCS) constitute the MAC header.

[0131] The format of the Frame Control field is shown in Table 4 below:

[0132] The Frame Control field includes the Protocol Version field, Type field, Subtype field, to DS field (Distribution System), from DS field, More fragments field, Retry field, Power Management field, More Data field, Protected Frame field, and High Throughput Indicator (+HTC) field.

[0133] In the construction of AAD, the three least significant bits (Least Significant bBt, LSB) of the Subtype field in FC (bits 4, 5, and 6 in FC) are masked out, while bit 7 in FC is not modified.

[0134] The Retry field (bit 11 in FC) is masked;

[0135] The Power Management field (bit 12 in FC) is masked;

[0136] The More Data field (bit 13 in FC) is masked;

[0137] The Protected Frame field (bit 14 in FC) has not been modified;

[0138] When the MPDU frame includes a QoS Control field, the +HTC field is masked; otherwise, no modification is made.

[0139] Other fields in FC were not modified.

[0140] During the construction of AAD, A1, A2, A3, and A4 in the MAC header were not modified.

[0141] The Sequence Number field in the Sequence Control field is masked, while the Fragment Number field remains unchanged.

[0142] If the QoS domain includes MSDU priority, the QC TID is used for AAD construction. In non-DMG BSS environments, if the SPP a-MSDU capability subfields of the STA and its peer are equal, the A-MSDU Present field is also used for AAD construction. In DMG BSS environments, the A-MSDU Present field and the A-MSDU Type field are also used in AAD construction.

[0143] In particular, because certain fields are masked when constructing AAD, meaning these fields are not encrypted before transmitting these frames, attackers may tamper with the contents of these unencrypted fields to attack communication devices or communication processes.

[0144] Furthermore, based on the current classification of frame types, Class 1 frames can be transmitted without encryption or association. This allows attackers to potentially tamper with the content of control frames and attack communication devices or processes.

[0145] Control frames (including triggers) are classified as class 1, and management frames can include MPDU-based frames. Since control and management frames carry a lot of information, if they are attacked, it will affect the communication process. Therefore, a mechanism that supports frame encryption is needed to improve the reliability of data transmission.

[0146] Optionally, in this embodiment of the disclosure, the first device may include a site device (STA) or an access point device (AP). The first device may also support multi-link communication; that is, the first device may be a multi-link site device (non-AP MLD) or a multi-link access point device (AP MLD).

[0147] Optionally, if the first device is a STA or a non-AP MLD, the first radio frame can be an association request frame, a reassociation request frame, etc. If the first device is an AP or an AP MLD, the first radio frame can be an association response frame, a reassociation response frame, a beacon frame, etc.

[0148] Optionally, the information regarding the first device's ability to encrypt the second wireless frame may include whether the first device supports encrypting the second wireless frame or not.

[0149] Optionally, when the first device supports encrypted transmission of the second wireless frame, the second wireless frame needs to be encrypted before transmitting the encrypted second wireless frame.

[0150] Optionally, this disclosure does not limit the specific frame type of the control frame. The second radio frame can be, for example, a trigger frame or a multi-STA block ACK frame.

[0151] As mentioned above, control frames (including triggers) are classified as Class 1. Class 1 frames can be transmitted without encryption or association, which allows attackers to potentially tamper with the content of the control frames and attack the communication device or process. In this embodiment, when the first device supports encrypted transmission of control frames, all fields in the control frame can be encrypted before transmission.

[0152] This disclosure does not limit the specific frame type of the management frame. For example, the management frame may include an MPDU-based frame.

[0153] Referring to the above, when the management frame is an MPDU-based frame, some fields in the MAC header of the management frame (e.g., More Data subfield, Ack Policy Indicator subfield, Relayed Frame subfield) are not encrypted (i.e., masked out) during transmission. This allows attackers to potentially tamper with the contents of these unencrypted fields, attacking the communication device or the communication process. In this embodiment, when the first device supports encrypted transmission of management frames, certain unencrypted fields in the MAC header of the management frame can be encrypted.

[0154] Optionally, in this embodiment of the disclosure, the first radio frame includes a robust secure network extension RSNEX information element, and the first identification information is carried in the Extended RSN capabilities field of the RSNEX information element.

[0155] Referring to Table 1, the format of RSNEX information elements is as follows:

[0156] Table 5:

[0157] Referring to Table 5, in the RSNEX information element, the Element ID field occupies 1 byte, the Length field occupies 1 byte, and the Extended RSN Capabilities field occupies n bytes.

[0158] Optionally, the fields identified by the Extended RSN Capabilities field and the meaning of those fields will differ depending on the parameter values ​​of the Extended RSN Capabilities field.

[0159] The fields identified by the Extended RSN Capabilities field under different parameter values, and the meaning of these fields, can be found in Table 6 below:

[0160] Table 6:

[0161] Referring to Table 2, the RSN extension element field includes multiple bits. Bit 12 corresponds to the PBAC field. The STA device sets this bit to indicate that it can establish a protected blocking return protocol; otherwise, it sets it to 0. Bit 13 corresponds to the Extended SIG Action Protection field. The STA sets this bit to 1 when the source term dot11STAExtendedSIGActionProtectionOperationsImplemented is true; otherwise, it sets it to 0. Bit 14 corresponds to the SPP A MSDU Capable field. STAs that do not support DMG set this bit to 1 when the source term dot11SPPAMSDUCapable is true; otherwise, it sets it to 0. Bit 15 corresponds to the URNM-MFPR field. The STA sets this bit to 1 when the source term dot11RSTARequiresPMFActivated is 2; otherwise, it sets it to 0. Bit 21 corresponds to the SSID Protection field. The STA sets this field to 1 to indicate that SSID-protected exchange is supported during the four-way handshake; otherwise, the field is set to 0. Bit 22 corresponds to the Extended SIG Action Protection field. If the STA supports decrypting the ACI subfield during AAD construction, the STA sets this field to 1; otherwise, it sets it to 0. In the Extended RSN capabilities field, bits 16 through 19 and bits 23 through (8×n-1) are reserved bits, and their meanings have not yet been defined.

[0162] Based on the above description of multiple bits in the Extended RSN capabilities field, the first identification information in this embodiment can be carried in at least one bit in the reserved bits of the Extended RSN capabilities field, that is, in at least one bit in bits 16 to 19 and bits 23 to (8×n-1) of the Extended RSN capabilities field. If the device supports encryption of control frames and / or management frames, this field is set to 1; otherwise, it is set to 0.

[0163] Optionally, in this embodiment of the disclosure, the first identification information includes at least one identification bit;

[0164] When the parameter value of the identifier bit is set to the first parameter value, the first identifier information is used to identify that the first device supports encrypted transmission of the second wireless frame;

[0165] or

[0166] When the parameter value of the identifier bit is set to the second parameter value, the first identifier information is used to identify that the first device does not support encrypted transmission of the second wireless frame.

[0167] Optionally, an identifier bit may include a bit, i.e., one of the reserved bits in the RSN extension element field.

[0168] Optionally, the first parameter value can be "1" and the second parameter value can be "0". That is, when the parameter value of the flag bit is set to "1", the first flag information is used to indicate that the first device supports encrypted transmission of the second wireless frame; when the parameter value of the flag bit is set to "0", the first flag information is used to indicate that the first device does not support encrypted transmission of the second wireless frame.

[0169] Optionally, the first identification information may include two bits. One bit indicates whether the first device supports encrypted transmission of control frames, and the other bit indicates whether it supports encrypted transmission of management frames. For example, assuming the first bit indicates whether the first device supports encrypted transmission of control frames, and the second bit indicates whether it supports encrypted transmission of management frames, when the first identification information is "01", it indicates that the first device does not support encrypted transmission of control frames, but supports encrypted transmission of management frames. When the first identification information is "11", it indicates that the first device supports encrypted transmission of both control and management frames.

[0170] Optionally, in this embodiment of the disclosure, when the frame type of the control frame is a security control implementation frame, or when the protocol version corresponding to the control frame is PV0, or when the protocol version corresponding to the control frame is PV1, the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame.

[0171] Optionally, taking a control frame with one corresponding bit in the first identification information as an example, if the frame type of the control frame is a security control implementation frame, or the protocol version corresponding to the control frame is PV0, or the protocol version corresponding to the control frame is PV1, the parameter value of this bit is set to "1", otherwise the parameter value of this bit is set to "0". In this way, the first identification information can be used to identify whether the first device supports encrypted transmission of the second wireless frame.

[0172] Optionally, taking the example that the control frame corresponds to two bits in the first identification information, the parameter value of one bit can be used to identify whether the first device supports encrypted transmission of the control frame and associate it with the frame type of the control frame, and the parameter value of the other bit can be used to identify whether the first device supports encrypted transmission of the control frame and associate it with the protocol version corresponding to the control frame. In this way, the first identification information can be used to identify whether the first device supports encrypted transmission of the second wireless frame.

[0173] Assuming that the parameter value of the first bit of the two bits corresponding to the control frame indicates whether the first device supports encrypted transmission of the control frame and is associated with the frame type of the control frame, and the parameter value of the second bit indicates whether the first device supports encrypted transmission of the control frame and is associated with the protocol version of the control frame, then if the frame type of the control frame is a security control implementation frame, the parameter value of the first bit is set to "1" (i.e., the first parameter value); otherwise, the parameter value of the first bit is set to "0" (i.e., the second parameter value). If the protocol version corresponding to the control frame is PV0 or PV1, the parameter value of the second bit is set to "1"; otherwise, the parameter value of the second bit is set to "0".

[0174] Regardless of the situation, the specific setting method for the corresponding bit parameter value can be determined based on the source language corresponding to the control frame. Specifically: when the source language `dot11SecureControlImplemented` is true, the first device (STA or AP) sets the corresponding bit parameter value to 1; when the source language `dot11SecureControlImplemented` is false, the first device (STA or AP) sets the corresponding bit parameter value to 0; when the source language `dot11SecurePV0andPV1Implemented` is true (the protocol version of the control frame is PV0 and PV1), the first device (STA or AP) sets the corresponding bit parameter value to 1; when the source language `dot11SecurePV0andPV1Implemented` is true, the first device (STA or AP) sets the corresponding bit parameter value to 0.

[0175] Step 202: The first device sends the first wireless frame.

[0176] Step 203: The second device receives the first wireless frame sent by the first device.

[0177] Optionally, in this embodiment of the disclosure, the second device may include a site device (STA) or an access point device (AP). The second device may also support multi-link communication; that is, the second device may be a multi-link site device (non-AP MLD) or a multi-link access point device (AP MLD).

[0178] Optionally, if the first device is a STA, the second device can be an AP or a STA; if the first device is a non-AP MLD, the second device can be an AP MLD; if the first device is an AP, the second device can be an AP or a STA; if the first device is an AP MLD, the second device is a non-AP MLD.

[0179] Optionally, referring to Figure 3, after step 203, the method may further include:

[0180] Step 301: When the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame, the first device, after encrypting the second wireless frame, sends the encrypted second wireless frame using the communication parameters corresponding to state 4.

[0181] In the communication parameters corresponding to state 4, the first device has been authenticated by the wireless LAN and has been associated with the second device, and the wireless LAN control port is not blocked or does not exist.

[0182] If the first device has already established an association with the second device, a robust secure network connection RSNA may or may not need to be established.

[0183] Alternatively, state4 can be described as follows:

[0184] Srate 4:Authenticated(except DMG STAs that did not perform IEEE 802.1 1authentication,whichare unauthenticated)and associated(RSNA established or not required).The IEEE 802.1XControlled Port is unblocked,or not present.

[0185] In other words, under state 4, authentication and association have been completed, and the IEEE 802.1X-based control port is blocked or does not exist. If RSNA has been established or does not need to be established, it can be considered as already associated.

[0186] In other words, under the communication parameters corresponding to state 4, the first device has already passed the wireless LAN authentication, and the first device has established an association with the second device, and the wireless LAN control port is not blocked or does not exist.

[0187] Optionally, referring to the above, when encrypting the second radio frame, if the second radio frame is a control frame, all fields in the control frame can be encrypted before transmission. If the second radio frame is a management frame, some unencrypted fields in the MAC header of the management frame can be encrypted.

[0188] Optionally, in this embodiment of the disclosure, the encrypted second wireless frame has a frame type of Class 3.

[0189] Optionally, for class 3 type frames, frames can include those transmitted when they are authenticated, associated, and the WLAN control port is not blocked. Referring to the above, the encrypted second wireless frame is transmitted using the communication parameters corresponding to state 4. Considering that under the communication parameters corresponding to state 4, the first device has been authenticated by the WLAN, the first device has been associated with the second device, and the WLAN control port is not blocked or does not exist, the frame type of the encrypted second wireless frame can be determined as the third type, class 3.

[0190] Step 302: The second device receives the encrypted second wireless frame sent by the first device in state 4.

[0191] Optionally, after receiving the encrypted second wireless frame, the second device can decrypt the second wireless frame and then communicate with the first device based on the second wireless frame.

[0192] Step 303, the second device determines a third radio frame; wherein the third radio frame includes second identification information, the second identification information being used to identify: the second device's support capability information for encrypted transmission of a fourth radio frame; the frame type of the fourth radio frame includes at least one of control frame and management frame.

[0193] Optionally, the description of the third radio frame can be found in the description of the first radio frame described above, and the description of the fourth radio frame can be found in the description of the second radio frame described above, and will not be repeated here.

[0194] Step 304: The second device sends the third wireless frame.

[0195] Step 305: The first device receives the third wireless frame sent by the second device.

[0196] Step 306: When the second identification information is used to identify that the second device supports encrypted transmission of the fourth wireless frame, the second device, after encrypting the fourth wireless frame, sends the encrypted fourth wireless frame using the communication parameters corresponding to state 4.

[0197] Optionally, the implementation of step 306 can refer to step 301 above, and will not be repeated here.

[0198] Step 307: The first device receives the encrypted fourth wireless frame using the communication parameters corresponding to state 4.

[0199] Optionally, after the first device receives the encrypted first wireless frame, it can decrypt the second wireless frame and then communicate with the second device based on the fourth wireless frame.

[0200] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "bit", "data", "program", and "chip" can be used interchangeably.

[0201] In some embodiments, terms such as “moment,” “point in time,” “time,” and “time location” can be used interchangeably, as can terms such as “duration,” “segment,” “time window,” “window,” and “time.”

[0202] In some embodiments, terms such as wireless access scheme and waveform can be used interchangeably.

[0203] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.

[0204] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (boolean), or by a comparison of numerical values ​​(e.g., a comparison with a predetermined value), but is not limited thereto.

[0205] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the receiver to respond to the sent content.

[0206] The communication methods involved in the embodiments of this disclosure may include the foregoing steps and at least one of the embodiments. For example, step 201 can be implemented as an independent embodiment, step 202 can be implemented as an independent embodiment, step 203 can be implemented as an independent embodiment, step 301 can be implemented as an independent embodiment, step 302 can be implemented as an independent embodiment, step 303 can be implemented as an independent embodiment, step 304 can be implemented as an independent embodiment, step 305 can be implemented as an independent embodiment, step 306 can be implemented as an independent embodiment, and step 307 can be implemented as an independent embodiment; the combination of steps 201 and 202 can be implemented as an independent embodiment, the combination of steps 201, 202, 203 and 301 can be implemented as an independent embodiment, the combination of steps 201, 202, 203 and 301 and 302 can be implemented as an independent embodiment, the combination of steps 303 and 304 can be implemented as an independent embodiment, and steps 303, 304 and 307 can be implemented as an independent embodiment. The combination of steps 5 can be implemented as an independent embodiment; the combination of steps 303, 304, 305, and 306 can be implemented as an independent embodiment; the combination of steps 303, 304, 305, 306, and 307 can be implemented as an independent embodiment; the combination of steps 201, 202, 203, 301, 302, 303, and 304 can be implemented as an independent embodiment; the combination of steps 201, 202, 203, 301, and 304 can be implemented as an independent embodiment. 02. The combination of steps 303, 304 and 305 can be implemented as an independent embodiment. The combination of steps 201, 202, 203, 301, 302, 303, 304, 305 and 306 can be implemented as an independent embodiment. The combination of steps 201, 202, 203, 301, 302, 303, 304, 305, 306 and 307 can be implemented as an independent embodiment, but is not limited thereto.

[0207] In some embodiments, other optional implementations described before or after the specification corresponding to FIG2 may be referred to.

[0208] Figure 4 is a flowchart illustrating one of the communication methods according to an embodiment of the present disclosure.

[0209] As shown in Figure 4, the above method can be applied to the first device 101, and the method includes:

[0210] Step 401, the first device 101 determines the first wireless frame; wherein, the first wireless frame includes first identification information, the first identification information being used to identify: the first device 101's support capability information for encrypted transmission of the second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame.

[0211] Optionally, in this embodiment of the disclosure, the first radio frame includes a robust secure network extension RSNEX information element, and the first identification information is carried in the Extended RSN capabilities field of the RSNEX information element.

[0212] Optionally, in this embodiment of the disclosure, the first identification information includes at least one identification bit;

[0213] When the parameter value of the identifier bit is set to the first parameter value, the first identifier information is used to identify that the first device 101 supports encrypted transmission of the second wireless frame;

[0214] or

[0215] When the parameter value of the identifier bit is set to the second parameter value, the first identifier information is used to identify that the first device 101 does not support encrypted transmission of the second wireless frame.

[0216] Optionally, in this embodiment of the disclosure, when the frame type of the control frame is a security control implementation frame, or when the protocol version corresponding to the control frame is PV0, or when the protocol version corresponding to the control frame is PV1, the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame.

[0217] The optional implementation of step 401 can be found in the optional implementation of step 201 in Figure 2 and other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0218] Step 402: Send the first wireless frame.

[0219] Optionally, in this embodiment of the disclosure, when the first identification information is used to identify that the first device 101 supports encrypted transmission of the second wireless frame, after step 402, the method further includes:

[0220] After encrypting the second wireless frame, the encrypted second wireless frame is sent using the communication parameters corresponding to state 4.

[0221] In the communication parameters corresponding to state 4, the first device 101 has been authenticated by the wireless local area network and has been associated with the second device 102, and the wireless local area network control port is not blocked or does not exist.

[0222] If the first device 101 has already established an association with the second device 102, the robust secure network connection RSNA has been established or does not need to be established.

[0223] Optionally, in this embodiment of the disclosure, the encrypted second wireless frame has a frame type of Class 3.

[0224] Optionally, in this embodiment of the disclosure, after step 402, the method further includes:

[0225] Receive a third wireless frame; wherein the third wireless frame includes second identification information, the second identification information being used to identify: the second device 102's ability to perform encrypted transmission of a fourth wireless frame; the frame type of the fourth wireless frame includes at least one of control frame and management frame.

[0226] Optionally, in this embodiment of the disclosure, after receiving the third wireless frame, the method further includes:

[0227] The encrypted fourth wireless frame is received using the communication parameters corresponding to state 4.

[0228] The communication method involved in the embodiments of this disclosure may include the foregoing steps and at least one of the embodiments. For example, step 41 may be implemented as a separate embodiment, step 402 may be implemented as a separate embodiment, and the combination of steps 401 and 402 may be implemented as a separate embodiment, but is not limited thereto.

[0229] In some embodiments, other optional implementations may be described before or after the specification corresponding to Figure 4.

[0230] Figure 5 is a second schematic flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0231] As shown in Figure 5, the above method can be applied to the second device 102, and the method includes:

[0232] Step 501, the second device 102 receives the first wireless frame; wherein, the first wireless frame includes first identification information, the first identification information being used to identify: the first device 101's support capability information for encrypted transmission of the second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame.

[0233] Optionally, in this embodiment of the disclosure, the first radio frame includes an RSNEX information element, and the first identification information is carried in the Extended RSN capabilities field of the RSNEX information element.

[0234] Optionally, in this embodiment of the disclosure, the first identification information includes at least one identification bit;

[0235] When the parameter value of the identifier bit is set to the first parameter value, the first identifier information is used to identify that the first device 101 supports encrypted transmission of the second wireless frame;

[0236] or

[0237] When the parameter value of the identifier bit is set to the second parameter value, the first identifier information is used to identify that the first device 101 does not support encrypted transmission of the second wireless frame.

[0238] Optionally, in this embodiment of the disclosure, when the frame type of the control frame is a security control implementation frame, or when the protocol version corresponding to the control frame is PV0, or when the protocol version corresponding to the control frame is PV1, the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame.

[0239] The optional implementation of step 501 can be found in the optional implementations of steps 201 to 203 in Figure 2, as well as other related parts in the embodiments involved in Figure 2, which will not be repeated here.

[0240] Optionally, in this embodiment of the disclosure, when the first identification information is used to identify that the first device 101 supports encrypted transmission of the second wireless frame, after step 501, the method further includes:

[0241] The encrypted second wireless frame is received using the communication parameters corresponding to state 4.

[0242] In the communication parameters corresponding to state 4, the first device 101 has been authenticated by the wireless local area network and has established an association with the second device 102, and the wireless local area network control port is not blocked or does not exist.

[0243] If the first device 101 has already established an association with the second device 102, the RSNA may or may not need to be established.

[0244] Optionally, in this embodiment of the disclosure, the encrypted second wireless frame has a frame type of Class 3.

[0245] Optionally, in this embodiment of the disclosure, after step 501, the method further includes:

[0246] A third wireless frame is determined; wherein the third wireless frame includes second identification information, the second identification information being used to identify: the second device 102's ability to perform encrypted transmission of the fourth wireless frame; the frame type of the fourth wireless frame includes at least one of control frame and management frame;

[0247] The third wireless frame is sent.

[0248] Optionally, in this embodiment of the disclosure, after sending the third radio frame, the method further includes:

[0249] After encrypting the fourth wireless frame, the encrypted fourth wireless frame is sent using the communication parameters corresponding to state 4.

[0250] This disclosure also provides an apparatus for implementing any of the above methods. For example, an apparatus is provided that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Alternatively, another apparatus is provided that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.

[0251] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0252] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0253] Figure 6 is a schematic diagram of the structure of one of the first devices proposed in this disclosure. As shown in Figure 6, the first device 600 may include at least one of a determining module 601, a sending module 602, etc.

[0254] In some embodiments, the determining module 601 is configured to determine a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; and the frame type of the second wireless frame includes at least one of control frames and management frames.

[0255] In some embodiments, the sending module 602 is used to send the first wireless frame.

[0256] Optionally, the determining module 601 is used to execute at least one of the communication steps (e.g., steps 201, 401, but not limited thereto) executed by the first device 101 in any of the above methods, which will not be described in detail here. The sending module 602 is used to execute at least one of the sending and receiving steps (e.g., steps 202, 301, 305, 307, 402, but not limited thereto) executed by the first device 101 in any of the above methods, which will not be described in detail here.

[0257] Figure 7 is a schematic diagram of the structure of a second device proposed in an embodiment of this disclosure. As shown in Figure 7, the second device may include a receiving module 701.

[0258] In some embodiments, the receiving module 701 is configured to receive a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; and the frame type of the second wireless frame includes at least one of control frames and management frames.

[0259] Optionally, the receiving module 701 is used to perform at least one of the sending and receiving steps (e.g., steps 203, 302, 304, 306, 501, but not limited thereto) performed by the second device 102 in any of the above methods, which will not be described in detail here.

[0260] The second device 700 may include a determining module, which is used to perform at least one of the communication steps (such as step 303, but not limited thereto) performed by the second device 102 in any of the above methods, which will not be described in detail here.

[0261] Figure 8 is a schematic diagram of the structure of a terminal 800 (e.g., a user equipment) proposed in an embodiment of this disclosure. The terminal 800 may be a chip, chip system, or processor that supports network devices in implementing any of the above methods, or it may be a chip, chip system, or processor that supports a terminal in implementing any of the above methods. The terminal 800 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0262] As shown in Figure 8, terminal 800 includes one or more processors 801. Processor 801 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Terminal 800 is used to execute any of the above methods.

[0263] In some embodiments, terminal 800 further includes one or more memories 802 for storing instructions. Optionally, all or part of the memories 802 may be located outside of terminal 800.

[0264] In some embodiments, the terminal 800 further includes one or more transceivers 804. When the terminal 800 includes one or more transceivers 804, the transceivers 804 perform at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps 202, 203, 301, 302, 304, 305, 306, 307, 402, 501, but not limited thereto), and the processor 801 performs at least one of other steps (e.g., steps 201, 303, 401, but not limited thereto).

[0265] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.

[0266] In some embodiments, terminal 800 may include one or more interface circuits 803. Optionally, interface circuit 803 is connected to memory 802, and interface circuit 803 can be used to receive signals from memory 802 or other devices, and can be used to send signals to memory 802 or other devices. For example, interface circuit 803 can read instructions stored in memory 802 and send the instructions to processor 801.

[0267] The terminal 800 described in the above embodiments may be a user equipment or other communication device, but the scope of the terminal 800 described in this disclosure is not limited thereto, and the structure of the terminal 800 may not be limited by FIG8. The communication device may be an independent device or a part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or chip, or chip system or subsystem; (2) a set of one or more ICs, optionally, the IC set may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0268] Figure 9 is a schematic diagram of the structure of the chip 900 proposed in an embodiment of this disclosure. For cases where the terminal 800 can be a chip or a chip system, please refer to the schematic diagram of the chip 900 shown in Figure 9, but it is not limited thereto.

[0269] Chip 900 includes one or more processors 901, which are used to perform any of the above methods.

[0270] In some embodiments, chip 900 further includes one or more 903s. Optionally, interface circuitry 903 is connected to memory 902, and interface circuitry 903 can be used to receive signals from memory 902 or other devices, and interface circuitry 903 can be used to send signals to memory 902 or other devices. For example, interface circuitry 903 can read instructions stored in memory 902 and send the instructions to processor 901.

[0271] In some embodiments, the interface circuit 903 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps 202, 203, 301, 302, 304, 305, 306, 307, 402, 501, but not limited thereto), and the processor 901 performs at least one of other steps (e.g., steps 201, 303, 401, but not limited thereto).

[0272] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.

[0273] In some embodiments, chip 900 further includes one or more memories 902 for storing instructions. Optionally, all or part of the memories 902 may be located outside of chip 900.

[0274] This disclosure also proposes a storage medium storing instructions that, when executed on a terminal 800, cause the terminal 800 to perform any of the methods described above. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0275] This disclosure also proposes a program product that, when executed by terminal 800, causes terminal 800 to perform any of the above methods. Optionally, the program product is a computer program product.

[0276] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method, characterized in that, Performed by a first device, the method includes: A first wireless frame is determined; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of the second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame; Send the first wireless frame.

2. The communication method according to claim 1, characterized in that, The first radio frame includes a robust secure network extension RSNEX information element, and the first identification information is carried in the Extended RSN capabilities field of the RSNEX information element.

3. The communication method according to claim 1 or 2, characterized in that, When the frame type of the control frame is a security control implementation frame, or when the protocol version corresponding to the control frame is PV0, or when the protocol version corresponding to the control frame is PV1, the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame.

4. The communication method according to any one of claims 1 to 3, characterized in that, When the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame, the method further includes: After encrypting the second wireless frame, the encrypted second wireless frame is sent using the communication parameters corresponding to state 4. In the communication parameters corresponding to state 4, the first device has been authenticated by the wireless LAN and has been associated with the second device, and the wireless LAN control port is not blocked or does not exist. If the first device has already been associated with the second device, a robust secure network connection RSNA may or may not need to be established.

5. The communication method according to claim 4, characterized in that, The encrypted second wireless frame is of type 3.

6. The communication method according to any one of claims 1 to 5, characterized in that, The method further includes: Receive a third wireless frame; wherein the third wireless frame includes second identification information, the second identification information being used to identify: the second device's support capability information for encrypted transmission of a fourth wireless frame; the frame type of the fourth wireless frame includes at least one of control frame and management frame.

7. The communication method according to claim 6, characterized in that, After receiving the third wireless frame, the method further includes: The encrypted fourth wireless frame is received using the communication parameters corresponding to state 4.

8. A communication method, characterized in that, Performed by a second device, the method includes: Receive a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame.

9. The communication method according to claim 8, characterized in that, The first radio frame includes an RSNEX information element, and the first identification information is carried in the Extended RSN capabilities field of the RSNEX information element.

10. The communication method according to claim 8 or 9, characterized in that, When the frame type of the control frame is a security control implementation frame, or when the protocol version corresponding to the control frame is PV0, or when the protocol version corresponding to the control frame is PV1, the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame.

11. The communication method according to any one of claims 8 to 10, characterized in that, When the first identification information is used to identify that the first device supports encrypted transmission of the second wireless frame, the method further includes: The encrypted second wireless frame is received using the communication parameters corresponding to state 4. In the communication parameters corresponding to state 4, the first device has been authenticated by the wireless LAN and has been associated with the second device, and the wireless LAN control port is not blocked or does not exist. If the first device has already established an association with the second device, an RSNA may or may not need to be established.

12. The communication method according to claim 11, characterized in that, The encrypted second wireless frame is of type 3.

13. The communication method according to any one of claims 8 to 12, characterized in that, The method further includes: A third wireless frame is determined; wherein the third wireless frame includes second identification information, the second identification information being used to identify: the second device's ability to perform encrypted transmission of the fourth wireless frame; the frame type of the fourth wireless frame includes at least one of control frame and management frame; The third wireless frame is sent.

14. The communication method according to claim 13, characterized in that, After sending the third radio frame, the method further includes: After encrypting the fourth wireless frame, the encrypted fourth wireless frame is sent using the communication parameters corresponding to state 4.

15. A communication device, characterized in that, The communication device includes a first device, comprising: A determining module is configured to determine a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame; The transmitting module is used to transmit the first wireless frame.

16. A communication device, characterized in that, The communication device is a second device, including: A receiving module is configured to receive a first wireless frame; wherein the first wireless frame includes first identification information, the first identification information being used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; and the frame type of the second wireless frame includes at least one of control frame and management frame.

17. A communication device, characterized in that, The communication device includes a first device, comprising: One or more processors; The communication device is used to perform the communication method according to any one of claims 1 to 7.

18. A communication device, characterized in that, The communication device is a second device, including: One or more processors; The communication device is used to perform the communication method according to any one of claims 7 to 14.

19. A communication system, characterized in that, Including the first device and the second device; The first device is used to determine a first wireless frame; wherein the first wireless frame includes first identification information, which is used to identify: the first device's ability to perform encrypted transmission of a second wireless frame; the frame type of the second wireless frame includes at least one of control frame and management frame; and the first wireless frame is transmitted. The second device is used to receive the first wireless frame.

20. A storage medium storing instructions, characterized in that, When the instruction is executed on the communication device, the communication device performs the communication method as described in any one of claims 1 to 7, or performs the communication method as described in any one of claims 8 to 14.

21. A program product, characterized in that, When the program product is executed by a communication device, the communication device performs the communication method as described in any one of claims 1 to 7, or performs the communication method as described in any one of claims 8 to 14.

Citation Information

Patent Citations

  • Method and system for WLAN multi-link management frame addressing

    CN116965074A

  • Method for closing WI-FI hotspot network, access point equipment and station equipment

    CN117044256A

  • Communication method and station

    WO2023082208A1

  • Wireless communication method and device

    WO2023236216A1