Communication method, apparatus and system

By using link-level keys to encrypt and decrypt management frames in multi-link devices, and processing management frames directly at the MLD low MAC sublayer, the latency and bandwidth consumption issues in non-co-located architectures are resolved, and the data processing efficiency of the devices is improved.

WO2026012245A1PCT designated stage Publication Date: 2026-01-15HUAWEI TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/106398
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-10
Filing Date
2025-07-01
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

Multi-link devices experience delays in processing management frames, especially in non-co-located architectures, where round-trip delays and bandwidth consumption between the MLD high MAC sublayer and the MLD low MAC sublayer lead to increased processing latency.

Method used

The management frames are encrypted and decrypted using a link-level key, and are processed directly through the MLD low MAC sublayer, avoiding transmission to the MLD high MAC sublayer and reducing processing latency.

Benefits of technology

It effectively reduces the latency of multi-link devices in processing management frames and improves data processing efficiency, especially in non-co-located multi-link devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025106398_15012026_PF_FP_ABST
    Figure CN2025106398_15012026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed are a communication method, apparatus and system, which relate to the technical field of communications. The present application supports an institute of electrical and electronics engineers (IEEE) protocol, such as an IEEE 802.11be / Wi-Fi 7 / EHT protocol, an IEEE 802.11bn / UHR / Wi-Fi 8 protocol, an integrated mmWave / integrated millimeter wave / IMMW protocol, an IEEE 802.15 / UWB protocol, or an IEEE 802.11bf / sensing / sensing protocol. The method comprises: a first station generating a management frame, and sending the management frame to a second station, wherein the management frame comprises a first message complete check code obtained on the basis of a first key, and the first key is generated on the basis of address information related to a first link, and a KDK. Therefore, the processing delay of a multi-link device processing a management frame is reduced, thereby improving the data processing efficiency.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods, devices and systems

[0001] This application claims priority to Chinese Patent Application No. 202410927132.2, filed on July 10, 2024, entitled "Communication Method, Apparatus and System", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to a communication method, apparatus and system. Background Technology

[0003] Currently, in wireless local area network (WLAN) systems, there exists a type of multi-link device (MLD). When the MLD acts as an access point (AP), it is called an AP MLD. The AP MLD includes a lower (medium access control, MAC) sublayer and an upper (MLD upper MAC) sublayer. When the MLD acts as a non-access point (non-AP), it can be called a non-AP MLD. Typically, the MLD encrypts and protects management frames before transmitting them. However, the encryption and decryption processing of management frames by the multi-link device has a relatively long latency. Summary of the Invention

[0004] This application provides a communication method, apparatus, and system, thereby reducing the processing latency of multi-link devices in processing management frames.

[0005] In a first aspect, a communication method is provided, applied to a first multi-link device, the first multi-link device including a first station (STA), the first station establishing a first link with a second station included in a second multi-link device; the method includes: generating a management frame and sending the management frame to the second station. The management frame includes a first message integrity checksum obtained based on a first key. The first key is generated based on address information related to the first link and a key-derived key (KDK).

[0006] The first key proposed in the above technical solution is a novel link-level key. The first station uses this first key to protect management frames transmitted through the first link. Since the address information associated with the first link is a unique feature of the first link, the first key is generated based on this address information, making it unique and used to protect management frames transmitted through the first link. That is, the first station protects management frames transmitted through the first link using the first key, and correspondingly, the second station decrypts management frames transmitted through the first link using the first key. Furthermore, the generated first key also uses a KDK (Keyless Dial-Kepker) algorithm, further enhancing its security. This, in turn, improves the security of the management frames.

[0007] Furthermore, the medium access control (MAC) layer of a multi-link device is divided into a lower (MLD) MAC sublayer and an upper (MLD) MAC sublayer. The lower (MLD) MAC sublayer can be simply referred to as the lower MLD MAC sublayer, and the upper (MLD) MAC sublayer can be simply referred to as the upper MLD MAC sublayer. In this embodiment, the first station in the first multi-link device implements the function of the lower MLD MAC sublayer. The first station protects the management frames, meaning the lower MLD MAC sublayer protects the management frames, eliminating the need to transmit them to the upper MLD MAC sublayer for protection. This avoids introducing round-trip delays and bandwidth consumption between the upper and lower MLD MAC sublayers, effectively reducing the processing latency of the multi-link device in processing management frames and improving data processing efficiency.

[0008] In some embodiments, in a non-collocated AP MLD (or roaming AP MLD) architecture, the MLD high MAC sublayer and the MLD low MAC sublayer communicate via a wired interface, meaning they are geographically separated. For link-specific unicast management frames, they need to be transmitted to the MLD high MAC sublayer for encryption and decryption before being sent to the MLD lower MAC sublayer. This introduces round-trip delay, increasing the processing latency of link-specific unicast management frames and consuming bandwidth between the MLD high and low MAC sublayers.

[0009] The communication method provided in this application embodiment is particularly effective in reducing the processing latency of management frames for non-co-located multi-link devices.

[0010] Secondly, a communication method is provided, applied to a second multi-link device, the second multi-link device including a second station, the second station establishing a first link with a first station included in a first multi-link device; the method includes: receiving a management frame from the first station, the management frame including a first message complete verification code obtained based on a first key, the first key being generated based on address information and KDK related to the first link; and decrypting the management frame according to the first key.

[0011] The first key proposed in the above technical solution is a novel link-level key. Both the first and second stations can generate the first key using the same derivation method. The first station uses the first key to protect management frames transmitted through the first link, and correspondingly, the second station uses the first key to decrypt management frames transmitted through the first link. Since the address information associated with the first link is a unique feature of the first link, generating the first key based on this address information ensures its uniqueness and is used to protect management frames transmitted through the first link. Furthermore, the generated first key also utilizes KDK (Key-Distributed Key), further enhancing its security. This, in turn, improves the security of the management frames.

[0012] In this embodiment of the application, the second station in the second multi-link device is used to implement the function of the MLD low MAC sublayer. The second station decrypts the management frame, that is, the MLD low MAC sublayer decrypts the management frame, thereby reducing the processing latency of the multi-link device in processing the management frame and improving the data processing efficiency.

[0013] A multi-link device can include multiple sites. When an MLD acts as an access point (AP), it can be called an AP MLD. In this case, the sites included in the AP MLD can be referred to as APs. When an MLD acts as a non-access point (non-AP), it can be called a non-AP MLD. A non-AP MLD can also be called a station (STA) MLD. In this case, the sites included in the non-AP MLD can be referred to as STAs. That is, the APs included in an AP MLD and the STAs included in a non-AP MLD can be collectively referred to as sites.

[0014] In one possible implementation, the first multi-link device is an AP MLD and the second multi-link device is a non-AP MLD; or, the first multi-link device is a non-AP MLD and the second multi-link device is an AP MLD.

[0015] For example, taking downlink communication as an example, the first multi-link device is an AP MLD, which includes multiple sites, meaning multiple APs. For instance, the first site included in the first multi-link device is the first AP. The second multi-link device is a non-AP MLD, which includes multiple sites, meaning multiple STAs. For instance, the second site included in the second multi-link device is the first STA. In this case, the first AP included in the first multi-link device and the first STA included in the second multi-link device establish a first link. The first AP generates a management frame and sends it to the first STA.

[0016] For example, taking uplink communication as an example, the first multi-link device is a non-AP MLD, which includes multiple sites, which can refer to multiple STAs. For instance, the first site included in the first multi-link device is the first STA. The second multi-link device is an AP MLD, which includes multiple sites, which can refer to multiple APs. For instance, the second site included in the second multi-link device is the first AP. In this case, the first STA included in the first multi-link device and the first AP included in the second multi-link device establish a first link. The first STA generates a management frame and sends a management frame to the first AP.

[0017] In another possible implementation, the first key is generated based on address information and KDK associated with the first link, including: the first key is generated based on address information associated with the first link, a key derivation key, and a random number, and the address information associated with the first link includes the address of the first site and the address of the second site.

[0018] Since the address at the end of the first link is a unique feature of the first link, a first key is generated based on the address at the end of the first link, thereby obtaining the link-level key of the first link. This ensures that the first key is uniquely used by the site of the first link (such as the first AP and the first STA), thus guaranteeing the uniqueness of the first key. A time factor is added when generating the first key to further enhance its security.

[0019] In another possible implementation, the address information associated with the first link also includes the addresses of the first multi-link device and the second multi-link device.

[0020] The first key is generated based on more parameters, which reduces the possibility of the first key being stolen and cracked, and improves the security of the first key.

[0021] In another possible implementation, the first message complete checksum is calculated based on all or part of the fields of the MAC protocol data unit (MPDU) header in the management frame using the first key.

[0022] Based on the first key, all fields of the MAC protocol data unit header in the management frame are encrypted to obtain the redefined additional authentication data (AAD). Because all fields in the management frame are protected, the security of data transmitted between the first and second stations is further enhanced.

[0023] In another possible implementation, the management frame also includes a first packet number (PN) and a first key identifier (Key ID), both of which are associated with the first key.

[0024] Associating the first packet sequence number and the first key identifier with the first key, the first packet sequence number is updated each time data is transmitted between the first station and the second station. This means that the packet sequence number is different for each different data transmission between the first station and the second station, thereby improving the security of data transmission between the first station and the second station.

[0025] In another possible implementation, the management frame further includes a first identifier for indicating an encryption mode; the encryption mode includes a first encryption mode and a second encryption mode; the first encryption mode protects the management frame based on a first key, and the second encryption mode protects the management frame based on both the first and second keys; when the first identifier indicates the first encryption mode, the management frame includes a first message integrity checksum obtained based on the first key; when the first identifier indicates the second encryption mode, the management frame further includes a second message integrity checksum obtained based on the second key.

[0026] In another possible implementation, the management frame also includes a second packet sequence number and a second key identifier obtained based on the second key.

[0027] This application provides two encryption modes, which enable the first and second stations to use either encryption mode to protect the transmitted management frames, thereby improving the compatibility and flexibility of the scheme.

[0028] In another possible implementation, the first identifier is located in the key identifier field of the cipher block chain message CAPTCHA protocol header in the management frame.

[0029] The first identifier is carried in the key identifier field of the cryptographic block chain message verification code protocol header, enabling the station receiving the management frame to determine the encryption mode and accurately decrypt the management frame.

[0030] In another possible implementation, the management frames include multi-link device unicast management frames and link-specific unicast management frames.

[0031] In another possible implementation, the first multi-link device is an AP multi-link device and the second multi-link device is a STA multi-link device. The method further includes sending an association request to the first site, the association request including a second identifier, the second identifier being used to indicate enabling or activating the management frame protection enhancement mode.

[0032] In another possible implementation, the first multi-link device is an AP multi-link device and the second multi-link device is a STA multi-link device. The method further includes receiving an association request from a second site, the association request including a second identifier, the second identifier being used to indicate enabling or activating the management frame protection enhancement mode.

[0033] In another possible implementation, the first multi-link device is a STA multi-link device and the second multi-link device is an AP multi-link device. The method further includes sending an association request to a second site. The association request includes a second identifier, which is used to indicate whether the management frame protection enhancement mode is enabled or activated.

[0034] In another possible implementation, the first multi-link device is a STA multi-link device and the second multi-link device is an AP multi-link device. The method further includes receiving an association request from a first site, the association request including a second identifier, the second identifier being used to indicate enabling or activating the management frame protection enhancement mode.

[0035] Stations in the STA multi-link device inform stations in the AP multi-link device that they support the unicast management frame protection enhancement mode. This allows stations in the AP multi-link device to protect management frames based on the management frame protection enhancement mode. The management frames are decrypted by the MLD low MAC sublayer, eliminating the need to transmit data to the MLD high MAC sublayer for decryption. This avoids round-trip delays and bandwidth consumption between the MLD high MAC sublayer and the MLD low MAC sublayer, reducing the processing latency of the multi-link device in processing management frames and improving data processing efficiency.

[0036] In another possible implementation, the second identifier is located in the robust secure network field of the association request.

[0037] The robust security network field in the association request carries a second identifier so that the stations in the AP multi-link device know that the stations in the STA multi-link device have management frame protection enhancement mode. The stations in the AP multi-link device protect management frames based on management frame protection enhancement mode, reducing the processing latency of multi-link devices in processing management frames and improving data processing efficiency.

[0038] Thirdly, a communication device is provided for implementing the various methods described above. This communication device includes modules, units, or means corresponding to the methods described above. These modules, units, or means can be implemented in hardware, software, or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the functions described above.

[0039] In some possible designs, the communication device may include a processing module and a transceiver module. The transceiver module, also referred to as a transceiver unit, is used to implement the transmission and / or reception functions in any of the above aspects and their possible implementations. The transceiver module may consist of transceiver circuits, transceivers, transceivers, or communication interfaces. The processing module can be used to implement the processing functions in any of the above aspects and their possible implementations.

[0040] In some possible designs, the transceiver module includes a sending module and a receiving module, which are used to implement the sending and receiving functions in any of the above aspects and any possible implementation methods.

[0041] Fourthly, a communication device is provided, comprising: a processor and a memory; the memory is used to store computer instructions, which, when executed by the processor, cause the communication device to perform any of the methods described above.

[0042] Fifthly, a communication device is provided, comprising: a processor and a communication interface; the communication interface being used to communicate with a module outside the communication device; the processor being used to execute computer programs or instructions to cause the communication device to perform the methods of any of the above aspects.

[0043] A sixth aspect provides a communication device, comprising: at least one processor; the processor being configured to execute a computer program or instructions stored in a memory to cause the communication device to perform the methods of any of the preceding aspects. The memory may be coupled to the processor, or may be independent of the processor.

[0044] The communication device in the third to sixth aspects mentioned above can be: a first multi-link device in the first aspect or any aspect or implementation thereof, or a device including the first multi-link device, or a device included in the first multi-link device, such as a first site or a chip in the first site; or the communication device in the third to sixth aspects mentioned above can be: a second multi-link device in the second aspect or any aspect or implementation thereof, or a device including the second multi-link device, or a device included in the second multi-link device, such as a second site or a chip in the second site.

[0045] In a seventh aspect, a computer-readable storage medium is provided, which stores a computer program or instructions that, when executed on a communication device, enable the communication device to perform the methods of any of the above aspects or any implementation thereof.

[0046] Eighthly, a computer program product containing instructions is provided, which, when run on a communication device, enables the communication device to execute the method of any of the above aspects or any implementation thereof.

[0047] Ninthly, a communication device (e.g., a chip or chip system) is provided, the communication device including a processor for implementing the functions involved in any of the above aspects or any implementation thereof.

[0048] In some possible designs, the communication device includes a memory for storing necessary program instructions and data.

[0049] In some possible designs, when the device is a chip system, it can be composed of chips or contain chips and other discrete components.

[0050] It is understood that when the communication device provided by any of the third to sixth aspects is a chip, the aforementioned sending action / function can be understood as an output, and the aforementioned receiving action / function can be understood as an input.

[0051] In a tenth aspect, a communication system is provided, comprising a second multi-link device for performing the method described in the second aspect and a first multi-link device for performing the method described in the first aspect.

[0052] The technical effects of any of the implementation methods in aspects three through ten can be found in the technical effects of the corresponding implementation methods in aspects one through two, and will not be repeated here.

[0053] It should be noted that any of the possible implementations of any of the above aspects can be combined, provided that the solutions do not contradict each other. Attached Figure Description

[0054] Figure 1 is a schematic diagram of a non-AP multi-link device and an AP multi-link device establishing a multi-link connection according to this application;

[0055] Figure 2 is a schematic diagram of a non-co-located AP MLD architecture provided in this application;

[0056] Figure 3 shows an application scenario of a communication system provided in this application;

[0057] Figure 4 is a schematic diagram of the composition of a communication device provided in this application;

[0058] Figure 5 is a flowchart illustrating a downlink-based communication method provided in this application;

[0059] Figure 6 is a schematic diagram of a key derivation provided in this application;

[0060] Figure 7 is a schematic diagram of the frame format of an MPDU frame provided in this application;

[0061] Figure 8 is a schematic diagram of the frame format of an encrypted MPDU frame provided in this application;

[0062] Figure 9 is a schematic diagram of a header generation encryption calculation provided in this application;

[0063] Figure 10 is a schematic diagram of another encrypted MPDU frame provided in this application;

[0064] Figure 11 is a schematic diagram of a header decryption calculation provided in this application;

[0065] Figure 12 is a flowchart illustrating another downlink-based communication method provided in this application;

[0066] Figure 13 is a flowchart illustrating an uplink-based communication method provided in this application;

[0067] Figure 14 is a schematic diagram of another communication device provided in this application. Detailed Implementation

[0068] To facilitate understanding, the main terms used in this application will be explained first.

[0069] A multi-link device (MLD) is a device with multiple radio frequency (RF) modules, each operating on different frequency bands or channels. If the channels (or frequency bands) operated by two RF modules within a multi-link device are sufficiently spaced, these two RF modules can operate independently without interference; for example, two RF modules can independently receive or transmit signals. The multiple RF modules within an MLD can establish multiple links with other devices (such as the MLD itself), enabling data transmission across these links and increasing data transfer rates.

[0070] In a multi-link device, if any two links support simultaneous transmit / receive (STR) capability, with one link transmitting a signal and the other receiving a signal, then these two links are said to support simultaneous transmit / receive (STR). Otherwise, they are said to be non-simultaneous transmit / receive (non-STR).

[0071] A multi-link device can include multiple stations (STAs). When an MLD acts as an access point (AP), it can be an AP MLD. In this case, the stations included in the AP MLD can be called APs. When an MLD acts as a non-access point (non-AP), it can be a non-AP MLD. A non-AP MLD can also be called a STA MLD. In this case, the stations included in the non-AP MLD can be called STAs. That is, the APs included in an AP MLD and the STAs included in a non-AP MLD can be collectively referred to as stations.

[0072] For example, multiple RF modules contained in an MLD can function as a site, multiple RF modules contained in an AP MLD can function as an AP, and multiple RF modules contained in a non-AP MLD can function as a STA. An AP MLD contains multiple APs, and a Non-AP MLD contains multiple STAs.

[0073] Non-AP MLDs can establish associations with multiple links of an AP MLD by exchanging multi-link association request / response frames on a single link, carrying information about multiple links. The link where the multi-link association request / response frame exchange takes place is called a transmitted link, and the other links are called non-transmitted links.

[0074] Figure 1 is a schematic diagram illustrating the multi-link establishment between a non-AP multi-link device and an AP multi-link device according to this application. As shown in Figure 1, the non-AP multi-link device includes two STAs, and the AP multi-link device includes two APs. The non-AP multi-link device can send an association request frame on link 1. Besides carrying information about the STA side of link 1, the association request frame also carries relevant information about the STA side of link 2. Link 1 is referred to as the transmission link, and link 2 is referred to as the non-transmission link. After receiving the association request frame, the AP multi-link device sends an association response frame on link 1 to the non-AP multi-link device. Besides carrying information about the AP side of link 1, the association response frame also carries relevant information about the AP side of link 2. Thus, STA 1 of the non-AP multi-link device establishes an association with AP 1 of the AP multi-link device, and STA 2 of the non-AP multi-link device establishes an association with AP 2 of the AP multi-link device.

[0075] The relevant information for the STA side of Link 2 can be located in the Basic Multi-link element field of the association request frame. The relevant information for the AP side of Link 2 can be located in the Basic Multi-link element field of the association response frame.

[0076] The frame format of the association request frame is shown in Table 1 below. The frame format of the association response frame is shown in Table 2 below.

[0077] Table 1. Frame format of associated request frames

[0078] Table 2. Frame format of associated response frames

[0079] The media access control (MAC) layer of a multi-link device is divided into a lower (MLD) MAC sublayer and an upper (MLD) MAC sublayer. The lower (MLD) MAC sublayer can be simply referred to as the lower MAC sublayer. The upper (MLD) MAC sublayer can be simply referred to as the higher MAC sublayer.

[0080] A multi-link device may include multiple multi-link device lower-layer media access control sublayers. Understandably, the functionality of these multiple multi-link device lower-layer media access control sublayers is implemented by multiple APs or multiple STAs. For example, in an AP MLD, each AP contains a multi-link device lower-layer media access control sublayer. In a non-AP MLD, each STA contains a multi-link device lower-layer media access control sublayer.

[0081] For example, as shown in Figure 1, the AP MLD includes an MLD high MAC sublayer, an MLD low MAC sublayer 1, and an MLD low MAC sublayer 2. MLD low MAC sublayer 1 serves as the MAC layer of AP1, meaning AP1 implements the functionality of MLD low MAC sublayer 1. MLD low MAC sublayer 2 serves as the MAC layer of AP2, meaning AP2 implements the functionality of MLD low MAC sublayer 2. AP1 and AP2 share the MLD high MAC sublayer.

[0082] The non-AP MLD consists of an MLD high MAC sublayer, an MLD low MAC sublayer 1, and an MLD low MAC sublayer 2. MLD low MAC sublayer 1 serves as the MAC layer for STA1, meaning STA1 implements the functionality of MLD low MAC sublayer 1. MLD low MAC sublayer 2 serves as the MAC layer for STA2, meaning STA2 implements the functionality of MLD low MAC sublayer 2. STA1 and STA2 share the MLD high MAC sublayer.

[0083] In addition to the device's MAC address (MLD MAC address), each link in a multi-link device has its own MAC address (link address). For example, the address of MLD low MAC sublayer 1 is link address1, the address of MLD low MAC sublayer 2 is link address2, and the address of MLD high MAC sublayer is MLD MAC address.

[0084] In some embodiments, after an association is established between an AP MLD and a non-AP MLD, when data is transmitted between the AP MLD and the non-AP MLD, the data can be encrypted and additional authentication data (AAD) can be constructed.

[0085] For example, a counter mode header with cipher-block chaining message authentication code protocol (CCMP) is inserted into the MAC protocol data unit (MPDU) frame format. CCMP protects certain fields in the MPDU header; these protected fields are collectively referred to as AADs.

[0086] In this embodiment of the application, the protected fields in the MPDU header may include more or fewer fields, and this embodiment of the application does not specifically limit this.

[0087] In other embodiments, the function of the MLD high MAC sublayer includes encrypting or decrypting MPDU frames. MPDU frames include management frames, control frames, and data frames. Management frames are used to manage the network and sites, and to create, maintain, and terminate connections between sites and access points.

[0088] For example, when an AP MLD or non-AP MLD transmits data, the MLD high MAC sublayer encrypts the data before transmitting it to the MLD low MAC sublayer. When an AP MLD or non-AP MLD receives data, the MLD low MAC sublayer transmits the data to the MLD high MAC sublayer, which decrypts it before transmitting the decrypted data to the upper layer (e.g., the Logical Link Control layer, LLC layer) for transmission.

[0089] For example, for a unicast management frame on a specific link, when the AP MLD or non-AP MLD sends data, the data is first generated at the MLD low MAC sublayer, then transmitted to the MLD high MAC sublayer for encryption, and finally transmitted back to the MLD low MAC sublayer for transmission. Upon receiving the data, the AP MLD or non-AP MLD transmits it to the MLD high MAC sublayer for decryption, and then transmits the decrypted data back to the MLD low MAC sublayer for processing.

[0090] 802.11bn proposes a non-collocated (NC) AP MLD (or roaming AP MLD) architecture to reduce non-AP MLD roaming time.

[0091] For example, Figure 2 is a schematic diagram of a non-co-located AP MLD architecture provided in this application. In this architecture, the MLD high MAC sublayer and MLD low MAC sublayer of the NC AP MLD communicate via a wired interface, meaning the MLD high MAC sublayer and MLD low MAC sublayer are geographically separate. That is, the functions of the MLD high MAC sublayer and the MLD low MAC sublayer are implemented by independent devices. The devices implementing the functions of the MLD high MAC sublayer and the devices implementing the functions of the MLD low MAC sublayer are connected via a wired connection for wired communication. Optionally, multiple devices implementing the functions of the MLD low MAC sublayer are connected via a wired connection for wired communication. Alternatively, one device implements the functions of multiple MLD low MAC sublayers. The devices implementing the functions of the MLD high MAC sublayer and the devices implementing the functions of the MLD low MAC sublayer belong to one NC AP MLD.

[0092] For example, as shown in Figure 2, the device implementing the high MAC sublayer function of MLD can be a Service Access Point (SAP) of a Distribution System (DS). The device implementing the low MAC sublayer function of MLD can be an Extremely High Throughput (EHT) AP MLD.

[0093] Among them, the device that implements the function of the MLD low MAC sublayer can also implement the function of the AP MLD MAC sublayer of the co-located AP MLD.

[0094] The advantage of this architecture is that the non-AP MLD is associated with the NC AP MLD. When the non-AP MLD moves from the coverage area of ​​AP MLD1 to the coverage area of ​​AP MLD2, and AP MLD1 and AP MLD2 belong to the same NC AP MLD, the non-AP MLD only needs to establish a link with AP MLD2, without needing to re-negotiate a new key (e.g., a pairwise transient key, PTK). This ensures uninterrupted data transmission during roaming.

[0095] However, for unicast management frames of a specific link, transmitting the data to the MLD high MAC sublayer for encryption or decryption introduces a round-trip delay, which increases the processing latency of unicast management frames of that specific link and occupies the bandwidth between the MLD high MAC sublayer and the MLD low MAC sublayer.

[0096] Based on this, this application provides a communication method that includes a link-level key. This link-level key is used to encrypt or decrypt unicast management frames of multi-link devices or unicast management frames of a specific link. The communication method provided in this application can also be applied to co-located AP MLDs or non-co-located AP MLDs. Encryption is performed by the AP in the AP MLD and decryption by the STA in the non-AP MLD, or vice versa. This eliminates the need to transmit data to the MLD high MAC sublayer for encryption or decryption, avoiding round-trip delays between the MLD high and low MAC sublayers and reducing bandwidth usage between them. This reduces the processing latency of management frames for multi-link devices and improves data processing efficiency. The effect of reducing the processing latency of management frames is particularly significant for non-co-located multi-link devices.

[0097] To implement the above-mentioned link-level key encryption or decryption method, this application provides related communication methods, devices, and communication systems. The implementation methods of this application embodiment will be described in detail below with reference to the accompanying drawings.

[0098] The wireless communication system applicable to the embodiments of this application can be a wireless local area network (WLAN) or a cellular network. The communication method provided in the embodiments of this application can be implemented by a communication device in the wireless communication system or a chip or processor in the communication device. The communication device can be a wireless communication device that supports parallel transmission across multiple links, for example, a multi-link device. Compared to a device that only supports single-link transmission, a multi-link device has higher transmission efficiency and higher throughput.

[0099] A multi-link device may include one or more subordinate sites. A subordinate site is a logical site that can operate on a single link. The subordinate site can be an AP or a STA. For ease of description, this application refers to a multi-link device containing a subordinate AP as a multi-link AP or a multi-link AP device or an AP MLD, and a multi-link device containing a subordinate STA as a multi-link STA or a multi-link STA device or a STA MLD or a non-AP MLD. For ease of description and consistency, "multi-link device including subordinate STA" is briefly described as "multi-link device including STA" in this application embodiment, and "multi-link device including subordinate AP" is briefly described as "multi-link device including AP" in this application embodiment. A multi-link device containing a subordinate AP is uniformly referred to as an AP MLD in this application embodiment, and a multi-link device containing a subordinate STA is uniformly referred to as a non-AP MLD in this application embodiment.

[0100] A multi-link device can include multiple logical sites, each of which operates on a single link.

[0101] This application supports IEEE protocols, such as IEEE 802.11be / Wi-Fi 7 / EHT, IEEE 802.11bn / UHR / Wi-Fi 8, Integrated mmWave / IMMW, IEEE 802.15 / UWB, or IEEE 802.11bf / sensing.

[0102] Multilink devices can communicate wirelessly with other multilink devices by following the 802.11 series of protocols. For example, they can communicate with other devices by following extremely high throughput (EHT) sites or by following sites based on or compatible with 802.11be. Of course, other devices can be multilink devices or not.

[0103] Exemplary examples show that the multi-link device in this application can be a single-antenna device or a multi-antenna device. For example, it can be a device with two or more antennas. This application does not limit the number of antennas included in the multi-link device. In the embodiments of this application, the multi-link device can allow services of the same access type to be transmitted on different links, and even allow the same data packets to be transmitted on different links; alternatively, it can disallow services of the same access type to be transmitted on different links, but allow services of different access types to be transmitted on different links.

[0104] For example, a multi-link device is a device with wireless communication capabilities. This device can be a complete device or a chip or processing system installed in a complete device. The device with these chips or processing systems installed can implement the methods and functions of the embodiments of this application under the control of these chips or processing systems.

[0105] For example, the non-AP MLD in this application embodiment has wireless transceiver functionality, can support the 802.11 series of protocols, and can communicate with the AP MLD. For example, a non-AP MLD is any user communication device that allows users to communicate with the AP and thus with the WLAN. For example, a non-AP MLD can be a network-connected user device such as a tablet, desktop, laptop, notebook computer, ultra-mobile personal computer (UMPC), handheld computer, netbook, personal digital assistant (PDA), or mobile phone; or an IoT node in the Internet of Things (IoT); or an in-vehicle communication device in the Internet of Vehicles (IoV). A non-AP MLD can also be the chip and processing system in these terminals.

[0106] The AP MLD in this application embodiment is a device that provides services to a non-AP MLD and can support the 802.11 series of protocols. For example, the AP MLD can be a communication server, router, switch, bridge, or other communication entity. Alternatively, the AP MLD can include various forms of macro base stations, micro base stations, relay stations, etc. Of course, the AP MLD can also be the chip and processing system in these various forms of devices, thereby realizing the methods and functions of the embodiments of this application.

[0107] Understandably, the multi-link devices in this application embodiment can support high-speed, low-latency transmission. With the continuous evolution of wireless LAN application scenarios, multi-link devices can also be applied to more scenarios, such as sensor nodes in smart cities (e.g., smart water meters, smart electricity meters, smart air quality monitoring nodes), smart devices in smart homes (e.g., smart cameras, projectors, displays, televisions, speakers, refrigerators, washing machines, etc.), nodes in the Internet of Things (IoT), entertainment terminals (e.g., AR, VR wearable devices), smart devices in smart offices (e.g., printers, projectors, etc.), vehicle-to-everything (V2X) devices, and some infrastructure in daily life scenarios (e.g., vending machines, supermarket self-service navigation kiosks, self-checkout machines, self-service ordering machines, etc.). This application embodiment does not impose special restrictions on the specific forms of AP MLD and non-AP MLD; these are merely illustrative examples. The 802.11 protocol can be a protocol that supports or is compatible with 802.11be.

[0108] In this embodiment of the application, the frequency band in which the multi-link device operates may include one or more of the following: sub 1GHz, 2.4GHz, 5GHz, 6GHz and high frequency 60GHz, such as 2.4GHz, 5GHz and 6GHz. This embodiment of the application does not specifically limit this.

[0109] While this application primarily illustrates embodiments using a network deploying the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard as an example, those skilled in the art will readily understand that the various aspects of this application can be extended to other networks employing various standards or protocols, such as Bluetooth, high-performance radio LAN (HIPER LAN) (a wireless standard similar to IEEE 802.11, primarily used in Europe), wide area networks (WANs), WLANs, personal area networks (PANs), or other networks now known or to be developed in the future. Therefore, regardless of the coverage area and wireless access protocol used, the various aspects provided in this application can be applied to any suitable wireless network.

[0110] Figure 3 illustrates a communication system 300 used in an embodiment of this application, taking a wireless local area network as an example. The communication system 300 includes multiple wireless access points 310 and multiple stations 320.

[0111] A wireless access point (AP) is an access point for a wireless network. As a routing device in a wireless local area network (WLAN), it has functions such as multi-user access, data encryption, data decryption, and multi-rate transmission. Wireless access points are mainly used in broadband homes, buildings, campuses, industrial parks, warehouses, factories, and other places that require wireless networks.

[0112] A station (STA) is a device connected to a wireless local area network (WLAN) via a wireless access point. Stations can communicate with other stations within the WLAN, wireless access points, or devices outside the wireless network.

[0113] Each STA within the coverage area of ​​an AP can communicate with each other, and each STA can also communicate with the AP.

[0114] A Basic Service Set (BSS) comprises multiple sites connected to the same Access Point (AP). A BSS may or may not include an AP. The Basic Service Set Identifier (BSSID) is a unique identifier for the BSS. The BSSID has the same format as a MAC address and is generally the MAC address of the AP, used to identify the AP managing the BSS.

[0115] An extended service set (ESS) refers to a set of services formed by two or more BSSs in a wireless LAN interconnected with a backbone network, typically a wired LAN, through their access point devices. An ESS includes multiple BSSs, thereby extending the coverage of the wireless network.

[0116] In some embodiments, the ESS includes multiple wireless access points with partial overlap in coverage cells to enable seamless roaming between sites.

[0117] An overlapping BSS (OBSS) refers to another BSS that overlaps with the current BSS channel or frequency band. The OBSS may be on the same channel or on a different channel.

[0118] In some embodiments, the wireless access point can be an AP multi-link device. The site can be a STA multi-link device. The AP multi-link device and the STA multi-link device can establish multiple links for data transmission. For example, Figure 1 illustrates the process of establishing multiple links between a non-AP multi-link device and an AP multi-link device.

[0119] It should be noted that the scenario diagram shown in this application embodiment is illustrated by taking an AP MLD including 2 APs and a non-AP MLD including 2 STAs as an example. Of course, an AP MLD may include more APs and a non-AP MLD may include more STAs. This application embodiment does not make specific limitations on this.

[0120] In addition, in the embodiments of this application, AP1 can also be called the first AP, AP2 can also be called the second AP, STA1 can also be called the first STA, STA2 can also be called the second STA, link 1 can also be called the first link, and link 2 can also be called the second link. This is explained uniformly here and will not be repeated below.

[0121] Optionally, the communication system may further include a relay device, through which the AP multi-link device and the STA multi-link device communicate. Further details are omitted here. Those skilled in the art will understand that the wireless communication device structure shown in the figures does not constitute a limitation on the wireless communication device, and may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0122] In practical implementation, both the AP multi-link device and the STA multi-link device shown in Figure 3 can adopt the composition structure shown in Figure 4, or include the components shown in Figure 4. Figure 4 is a schematic diagram of the composition of a communication device provided in this application. The communication device 400 can be an access point device or a chip or system-on-a-chip in an access point device; it can also be a site device or a chip or system-on-a-chip in a site device. As shown in Figure 4, the communication device 400 includes a processor 401, a communication interface 402, and a communication line 403.

[0123] Furthermore, the communication device 400 may also include a memory 404. The processor 401, memory 404, and communication interface 402 can be connected via a communication line 403.

[0124] The processor 401 can be a central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 401 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.

[0125] In this embodiment, processor 401 is used to encrypt or decrypt management frames based on link-level keys.

[0126] Communication interface 402 is used to communicate with other devices or other communication networks. These other communication networks can be Ethernet, radio access network (RAN), wireless local area network (WLAN), etc. Communication interface 402 can be a module, circuit, transceiver, or any device capable of enabling communication.

[0127] In this embodiment of the application, the communication interface 402 is used to send or receive encrypted management frames.

[0128] Communication line 403 is used to transmit information between the components included in communication device 400.

[0129] Memory 404 is used to store instructions. These instructions can be computer programs.

[0130] In this embodiment, memory 404 is used to store link-level keys for encrypting or decrypting management frames. Optionally, memory 404 is also used to store multi-link device-level keys for encrypting or decrypting management frames.

[0131] The memory 404 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions; it can also be a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions; it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.

[0132] It should be noted that the memory 404 can exist independently of the processor 401, or it can be integrated with the processor 401. The memory 404 can be used to store instructions, program code, or some data, etc. The memory 404 can be located inside or outside the communication device 400, without limitation. The processor 401 is used to execute the instructions stored in the memory 404 to implement the communication method provided in the following embodiments of this application.

[0133] In one example, processor 401 can be a multi-core (multi-CPU) processor, such as CPU0 and CPU1 in Figure 4.

[0134] As an alternative implementation, the communication device 400 may include multiple processors, for example, in addition to the processor 401 in FIG4, it may also include a processor 407.

[0135] As an optional implementation, the communication device 400 also includes an output device 405 and an input device 406. For example, the input device 406 is a device such as a keyboard, mouse, microphone, or joystick, and the output device 405 is a device such as a display screen or speaker.

[0136] It should be noted that the communication device 400 can be a desktop computer, a portable computer, a web server, a mobile phone, a tablet computer, a wireless terminal, an embedded device, a chip system, or a device with a similar structure to that shown in Figure 4. Furthermore, the composition shown in Figure 4 does not constitute a limitation on the communication device. In addition to the components shown in Figure 4, the communication device may include more or fewer components than shown, or combine certain components, or have different component arrangements.

[0137] In this embodiment of the application, the chip system may be composed of chips or may include chips and other discrete devices.

[0138] Furthermore, the actions, terms, etc., involved in the various embodiments of this application can be referenced interchangeably without limitation. The message names or parameter names in the messages exchanged between the various devices in the embodiments of this application are merely examples, and other names may be used in specific implementations without limitation.

[0139] The communication method provided in the embodiments of this application will now be described with reference to Figure 1 and Figures 5 to 13 below.

[0140] It should be noted that in the following embodiments of this application, the message names, parameter names, or information names between network elements are just examples. Other names may also be used in other embodiments. The communication method provided in this application does not specifically limit these names.

[0141] It is understood that in the embodiments of this application, each network element may execute some or all of the steps in the embodiments of this application. These steps or operations are merely examples, and the embodiments of this application may also execute other operations or variations thereof. Furthermore, the steps may be executed in different orders as presented in the embodiments of this application, and it is not necessary to execute all the operations in the embodiments of this application.

[0142] Figure 5 is a flowchart illustrating a communication method provided in this application. This method is illustrated using the interaction between a STA multi-link device and an AP multi-link device as an example. The entity executing the actions of the STA multi-link device in this method can also be a device / module within the STA multi-link device, such as the STA within the STA multi-link device. Similarly, the entity executing the actions of the AP multi-link device in this method can also be a device / module within the AP multi-link device, such as the AP within the AP multi-link device. This application does not specifically limit this. For example, as shown in Figure 5, taking downlink communication as an example, for instance, the first multi-link device is an AP MLD, and the first multi-link device includes multiple sites, which can refer to multiple APs. For example, the first site included in the first multi-link device is the first AP. The second multi-link device is a non-AP MLD, and the second multi-link device includes multiple sites, which can refer to multiple STAs. For example, the second site included in the second multi-link device is the first STA. The first AP and the first STA establish a first link, and the first AP and the first STA can transmit data through the first link. This application does not limit the number of links established by the first multi-link device and the second multi-link device. Optionally, the first multi-link device and the second multi-link device can establish more than two links. For example, the first multi-link device further includes a second AP, and the second multi-link device further includes a second STA. The second AP and the second STA establish a second link, and the second AP and the second STA can transmit data through the second link. Specifically, for downlink communication, the second AP can encrypt the management frames it sends according to the link-level key provided in this application, and the second STA can decrypt the management frames it receives according to the link-level key used by the second AP. It should be noted that the link-level key used by the AP on each link is different. The communication method steps provided in this application embodiment are as follows.

[0143] Step 510: The first AP generates a management frame.

[0144] After the first AP establishes a first link with the first STA, the first AP can send data to the first STA through the first link. For example, the first AP can send an MPDU frame to the first STA through the first link.

[0145] To enhance data security, the first AP can encrypt the MPDU frame before transmission. Based on frame type classification, MPDU frames include data frames, control frames, and management frames. In this embodiment, the encryption and decryption of MPDU frames as management frames is primarily explained.

[0146] The first AP encrypts the management frame using the first key and then sends it to the first STA via the first link. The management frame includes a first message integrity checksum obtained based on the first key. For example, the first message integrity checksum is a message integrity code (MIC). The MIC is a hash value calculated for a set of data that needs to be protected, used to prevent data tampering.

[0147] Before the first AP and the first STA transmit data through the first link, the first AP and the first STA negotiate and obtain a first key. The first key can be a link-level key. The first AP and the first STA can encrypt or decrypt data transmitted through the first link based on the first key.

[0148] In some embodiments, the first key is generated based on at least one of the address information associated with the first link and the key-derived key (KDK).

[0149] For example, the first key is generated based on address information associated with the first link. This address information includes the address of the first AP and the address of the first STA. The address of the first AP can refer to the link address at the AP end of the first link. The address of the first STA can refer to the link address at the STA end of the first link.

[0150] For example, the first key is generated based on KDK. That is, the first AP derives the first key based on KDK.

[0151] For example, the first key is generated based on the address information and KDK associated with the first link.

[0152] Since the address information associated with the first link is a unique feature of the first link, the first key is generated based on the address information associated with the first link, making the first key unique. In addition, the use of KDK to generate the first key further enhances the security of the first key, thereby improving the security of the management frame.

[0153] The following describes two methods for deriving the first key.

[0154] In the first possible derivation method, the first key is generated based on address information, KDK, and random numbers associated with the first link.

[0155] The first AP generates the first key based on the KDK, the address of the first AP, the address of the first STA, and a random number.

[0156] For example, the first key satisfies the following formula (1).

[0157] CPTK=KDF-Hash-Length(KDK,“MLO Management protection key”||min(BSSID,STA_MAC_Address)||max(BSSID,STA_MAC_Address)||min(ANonce,SNonce)||max(ANonce,SNonce)) formula (1)

[0158] The first key can be a control pairwise transient key (CPTK).

[0159] KDF-Hash-Length represents the function that uses a hash algorithm to derive the key.

[0160] KDK represents the corresponding part of PTK. For example, as shown in Figure 6, PTK can be derived based on the pairwise master key (PMK). PTK includes the key-confimation key (KCK), key-encryption key (KEK), temporary key (TK), and KDK.

[0161] For example, PTK satisfies the following formula (2).

[0162] PTK=PRF-Length(PMK,“Pairwise key expansion”||min(AA,SPA)||min(ANonce,SNonce)||max(ANonce,SNonce)) formula (2)

[0163] KCK is used by IEEE Std 802.1X-2020 to provide data source authenticity in 4-way handshake and group key handshake messages.

[0164] KEK: The EAPOL-Key frame uses KEK to provide data confidentiality in the 4-way handshake and group key handshake messages.

[0165] TK: Used for encryption of unicast data frames and unicast management frames.

[0166] KDK: Used to derive other new unicast keys, such as the WUR temporal key (WTK) for unicast wake-up radio (WUR) frame protection and the CPTK mentioned here.

[0167] BSSID represents the link address of the corresponding AP.

[0168] STA_MAC_Address represents the link address of the corresponding STA end of the link.

[0169] ANonce represents a random number generated by the authenticator.

[0170] SNonce represents a random number generated by the requester.

[0171] In the second possible derivation method, the first key is generated based on address information associated with the first link, the KDK, and a random number. The address information associated with the first link also includes the addresses of the AP multi-link devices and the STA multi-link devices.

[0172] The first AP generates a first key based on the KDK, the address of the first AP, the address of the first STA, the address of the AP multi-link device, the address of the STA multi-link device, and a random number.

[0173] The address of an AP multi-link device can refer to the MAC address of the AP MLD. The address of a STA multi-link device can refer to the MAC address of the STA MLD.

[0174] For example, the first key satisfies the following formula (3).

[0175] CPTK=KDF-Hash-Length(KDK,“MLO Management protection key”||min(AA,SPA)||max(AA,SPA)||min(BSSID,STA_MAC_Address)||max(BSSID,STA_MAC_Address)||min(ANonce,SNonce)||max(ANonce,SNonce)) Formula (3)

[0176] Here, the Authenticator address (AA) represents the MAC address of the NC AP MLD.

[0177] The Requester Address (SPA) represents the MAC Address of the Non-AP MLD.

[0178] The management frame described in this application may refer to an MPDU frame of management frame type. In some embodiments, the first message integrity check code is calculated based on all or part of the fields of the MPDU header in the management frame using a first key.

[0179] For example, Figure 7 is a schematic diagram of the frame format of an MPDU frame provided in this application. As shown in Figure 7, an MPDU frame includes an MPDU frame header, a frame body, and a frame check sequence (FCS). The MPDU frame header can also be called a MAC header.

[0180] The MPDU frame header includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, QoS Control, and High Throughput Control (HT Control).

[0181] The frame control fields include Protocol Version, Type, Subtype, To DS, From DS, More Fragments, Retry, Power Management, More Data, Protected Frame, and Control Presence (+HTC HT).

[0182] Different values ​​for the type indicate the type of MPDU frame. MPDU frames can be divided into data frames (Type=10), management frames (Type=00), and control frames (Type=01).

[0183] The sequence control field includes two subfields: Fragment Number and Sequence Number.

[0184] The QoS control fields include the Traffic Identifier (TID) and the A-MSDU Present.

[0185] In the first possible example, the first AP protects certain fields of the MPDU frame header in the management frame based on a first key. These fields include address 1, address 2, address 3, fragment number, QoS control, protocol version, type, destination DS, destination DS, and more fragments.

[0186] Understandably, the first AP does not protect the fields in the MPDU frame header of the management frame other than subtype, retry, power management, more data, protected frame, and control presence, based on the first key.

[0187] In the second possible example, the first AP protects all fields of the MAC protocol data unit header in the management frame based on the first key.

[0188] Understandably, the first AP protects the frame control, duration, address 1, address 2, address 3, sequence control, QoS control, and HT control in the MPDU frame header of the unicast management frame based on the first key.

[0189] It should be understood that the new AAD obtained by the first AP protecting all fields of the MAC protocol data unit header in the management frame based on the first key is different from the AAD obtained by the first AP protecting only some fields of the MAC protocol data unit header in the management frame based on the first key.

[0190] It should be noted that after the first AP protects some or all fields of the MPDU frame header in the management frame based on the first key, the management frame also includes the first packet sequence number and the first key identifier. Both the first packet sequence number and the first key identifier are associated with the first key.

[0191] For example, Figure 8 is a schematic diagram of the frame format of an encrypted MPDU frame provided in this application. As shown in Figure 8, the MAC header can refer to the MPDU frame header, and the MAC header includes the fields of the MPDU frame header. A CCMP header is inserted on the basis of the MPDU frame format.

[0192] The CCMP header includes a packet number (PN) and a key identifier (Key ID). The packet number is 6 bytes long, corresponding to PN0-PN5 from the least significant byte to the most significant byte. The third byte of the CCMP header is reserved. The ExtIV bit in the key identifier is always set to 1, and bits 6-7 of the Key ID are the Key ID subfield; the other bits are reserved.

[0193] Understandably, both the packet sequence number and the key identifier correspond to a newly derived link-level key (e.g., CPTK). For example, each time the first AP sends a new MPDU frame, the packet sequence number can be incremented by one, thereby improving the security of the management frames sent by the first AP and preventing interception. When the packet sequence number reaches its maximum value, i.e., when the packet sequence number is exhausted, the first AP and the first STA renegotiate the key, update the first key, and encrypt the data transmitted between the first AP and the first STA according to the new key.

[0194] The first AP protects some or all fields of the MAC protocol data unit header in the management frame based on the first key, calculates the MIC, and then encrypts the data and MIC according to the first key to obtain the management frame. The management frame contains ciphertext and the encrypted MIC.

[0195] In other words, both MIC calculation and encryption use a newly derived link-level key (e.g., CPTK) instead of the previous multi-link device-level key (e.g., PTK). Furthermore, when calculating the MIC, the transmitter address (TA) and receiver address (RA) also use the corresponding link addresses. For example, the link address of the STA on the first link and the link address of the AP on the first link.

[0196] For example, Figure 9 illustrates a schematic diagram of the encrypted computation for generating a header according to this application. Input parameters include a plaintext MPDU, a transient key (TK), a PN, and a Key ID. Output parameters include a CCMP header and a MIC. The AAD is constructed based on the MAC header. The random number is constructed based on address 2, priority, and PN. The CCMP header is constructed from PN and Key ID. The AAD, random number, data, and TK are used as input, and an encryption algorithm (e.g., Advanced Encryption Standard (AES) block encryption) is used to generate encrypted data. The encrypted data includes ciphertext and an authentication field. For example, the authentication field is the encrypted MIC. This process can be called CCM originator processing (CTR with CBC-MAC originator processing). The plaintext MPDU contains the data, i.e., the data to be sent. CCM provides integrity protection for the fields contained in the AAD. CCM performs block encryption and authentication on the data to obtain encrypted data.

[0197] In the above CCM initiation process, some or all fields of the MAC header in the plaintext MPDU (e.g., AAD) are protected based on the first key, the MIC is calculated, and then the data and MIC are encrypted according to the first key to obtain the encrypted data contained in the encrypted MPDU.

[0198] This application does not limit the encryption algorithm used in the process of encrypting the management frame.

[0199] The above embodiments illustrate the process of encrypting management frames based on link-level keys.

[0200] The encryption method for management frames provided in this application can support the protection of management frames using both link-level keys and multi-link device-level keys.

[0201] In some embodiments, the management frame further includes a first identifier, which indicates an encryption mode. The encryption mode includes a first encryption mode and a second encryption mode. The first encryption mode protects the management frame based on a link-level key. The second encryption mode protects the management frame based on both a link-level key and a multi-link device-level key.

[0202] Optionally, the first identifier can be located in the Key ID field of the CCMP header. The first identifier can be 1 bit. For example, a value of 1 for the first identifier indicates a first encryption mode; a value of 0 for the first identifier indicates a second encryption mode. Similarly, a value of 0 for the first identifier indicates a first encryption mode; a value of 1 for the first identifier indicates a second encryption mode.

[0203] For example, the link-level key includes a first key. With the first identifier indicating a first encryption mode, the first AP encrypts the management frame based on the first key. For example, the management frame includes a first message integrity checksum obtained based on the first key.

[0204] For example, a link-level key includes a first key. A multi-link device-level key includes a second key. When a first identifier indicates a second encryption mode, the first AP encrypts the management frame based on the first and second keys. The management frame includes a first message integrity checksum obtained based on the first key and a second message integrity checksum obtained based on the second key.

[0205] Optionally, the management frame may also include a second packet sequence number and a second key identifier obtained based on the second key.

[0206] For example, Figure 10 shows a schematic diagram of another encrypted MPDU frame provided in this application. The encrypted MPDU frame includes a MAC header, a CCMP header, data, a MIC, and a frame check sequence. The CCMP header includes a second packet sequence number and a second key identifier. The second message integrity check (MIC) is obtained by protecting some or all fields of the MAC header in the management frame based on a multi-link device-level key. The data and MIC contained in the MPDU frame are calculated based on the multi-link device-level key for the data and the second message integrity check (MIC). The data contained in the MPDU frame is ciphertext. The MIC contained in the MPDU frame is an encrypted MIC.

[0207] The MPDU frame also includes a new security header. The new security header carries the first packet sequence number PN' corresponding to the link-level key, the first key identifier key ID', and the first message integrity check code MIC' obtained by protecting some or all fields of the MAC frame header in the management frame based on the link-level key.

[0208] The management frames in this application include multi-link device-level (MLD) unicast management frames and link-specific unicast management frames.

[0209] Unicast management frames for specific links include frames such as Very High Throughput (VHT), High Efficiency (HE), Extremely High Throughput (EHT), Compressed Beamforming, or Channel Quality Indication (CQI).

[0210] Multi-link device-level unicast management frames include association request frames.

[0211] Step 520: The first AP sends a management frame to the first STA. Correspondingly, the first STA receives the management frame from the first AP.

[0212] After the first AP generates a management frame, it sends the management frame to the first STA through the first link.

[0213] It should be noted that addresses 1, 2, and 3 in the MPDU header of the unicast management frame are shown in Table 3 below.

[0214] Table 3

[0215] The receiving address can be the link address that sends data, and the sending address can be the link address that receives data. The BSSID indicates the address of the AP to which the AP device belongs (or is also called the access or associated AP).

[0216] In this embodiment, the management frame includes a receiving address (RA), a transmitting address (SA), and a BSSID. The receiving address can be the address of the first STA. The transmitting address can be the address of the first AP. The BSSID can be the address of the first AP.

[0217] Step 530: The first STA decrypts the management frame using the first key.

[0218] Before the first AP and the first STA transmit data through the first link, the first STA can also generate a first key based on the derived method of the first AP's first key generation. Refer to the explanation of step 510 above for the method of generating the first key.

[0219] At this point, both the first AP and the first STA possess the first key. This allows the first STA to encrypt or decrypt data transmitted through the first link using the first key.

[0220] After receiving the management frame, the first STA decrypts it using the first key, enabling the first STA to perform relevant management operations.

[0221] For example, Figure 11 illustrates a schematic diagram of the decryption calculation of a header provided in this application. Input parameters include an encrypted MPDU, a key, and a replay counter. Output parameters include an error-free plaintext frame body. The AAD is constructed based on the MAC header. The random number is constructed based on address 2, priority, and PN. The AAD, random number, ciphertext, and TK are used as input and decrypted using an algorithm to obtain a plaintext MPDU; this process can be called CCM reception processing. The acquired MAC header and the data obtained from CCM reception processing are concatenated to form a plaintext MPDU. Replaying the MPDU is prevented by verifying that the PN in the plaintext MPDU is greater than the replay counter maintained for the session. The encrypted MPDU includes encrypted data in the frame body but does not include the MIC. The MIC can refer to the encrypted MIC in the encrypted MPDU. MIC checking is performed by comparing the MIC in the encrypted MPDU with the recalculated MIC; only if the MIC check is successful is the plaintext frame body returned.

[0222] During the CCM receiving and processing process described above, the ciphertext is decrypted based on the first key.

[0223] Optionally, the management frame also includes a first identifier, which indicates an encryption mode. The first STA can also identify the value of the first identifier to determine the encryption mode. When the first identifier indicates a first encryption mode, the first STA decrypts the management frame based on a first key. When the first identifier indicates a second encryption mode, the first STA decrypts the management frame based on a first key and a second key.

[0224] Optionally, when the first AP establishes the first link with the first STA, the first STA may also inform the first AP that the first STA supports protecting management frames by negotiating a new link-level key (such as CPTK).

[0225] For example, as shown in Figure 12, prior to step 510, this application further includes the following steps. Step 540: The first STA sends an association request to the first AP. Accordingly, the first AP receives the association request from the first STA.

[0226] The association request includes a second identifier, which indicates whether the management frame protection enhancement mode is enabled or activated. That is, the first STA supports protecting management frames by negotiating a new link-level key (e.g., CPTK).

[0227] The second identifier is located in the robust secure network field of the association request.

[0228] Optionally, the second identifier can be 1 bit. For example, a value of 1 indicates that the management frame protection enhancement mode is enabled or turned on; a value of 0 indicates that the management frame protection enhancement mode is disabled or turned off. Similarly, a value of 0 indicates that the management frame protection enhancement mode is enabled or turned on; a value of 1 indicates that the management frame protection enhancement mode is disabled or turned off.

[0229] The communication method provided in this application offers a link-level key, whereby each AP or STA in an AP multi-link device or STA multi-link device can generate a link-level key for encrypting or decrypting management frames. Especially for non-co-located AP MLDs, there is no need to transmit data to the MLD high MAC sublayer for encryption or decryption; instead, the MLD low MAC sublayer encrypts or decrypts unicast management frames. This avoids round-trip delays and bandwidth consumption between the MLD high and low MAC sublayers, reducing processing latency for management frames in multi-link devices and improving data processing efficiency.

[0230] The above embodiment uses downlink communication as an example for illustration. For uplink communication, the method by which the STA generates the first key is the same as the method by which the AP generates the first key. The method by which the STA encrypts the management frame is the same as the method by which the AP encrypts the management frame, as described in step 510 above. The method by which the AP decrypts the management frame is the same as the method by which the STA decrypts the management frame, as described in step 530 above. For example, as shown in Figure 13, taking uplink communication as an example, for instance, the first multi-link device is a non-AP MLD, and the first multi-link device includes multiple sites, which can refer to multiple STAs. For example, the first site included in the first multi-link device is the first STA. The second multi-link device is an AP MLD, and the second multi-link device includes multiple sites, which can refer to multiple APs. For example, the second site included in the second multi-link device is the first AP. Step 1310: The first STA generates a management frame. Step 1320: The first STA sends a management frame to the first AP. Correspondingly, the first AP receives the management frame from the first STA. Step 1330: The first AP decrypts the management frame according to the first key.

[0231] The difference between uplink and downlink communication lies in the sending address, receiving address, and BSSID included in the data sent by the first STA to the first AP. For example, when the first STA generates a management frame and sends it to the first AP, the receiving address in the management frame can be the address of the first AP. The sending address can be the address of the first STA. The BSSID can be the address of the first AP.

[0232] The embodiments of this application do not limit the number of links established by the first multi-link device and the second multi-link device. Optionally, the first multi-link device and the second multi-link device can establish more than two links. For example, the first multi-link device further includes a second AP, and the second multi-link device further includes a second STA. The second AP and the second STA establish a second link, and the second AP and the second STA can transmit data through the second link. For uplink communication, the second STA can also encrypt the management frames it sends according to the link-level key provided in this application, and the second AP can decrypt the management frames it receives according to the link-level key used by the second STA. It should be noted that the link-level key used by the STA end of each link is different.

[0233] It should be noted that after multiple APs in an AP MLD and multiple STAs in an STA MLD establish multiple links, the APs and STAs corresponding to each link can negotiate their own link-level keys. The link-level keys negotiated by the APs and STAs for different links are different. For example, a first multi-link device includes a first AP and a second AP, and a second multi-link device includes a first STA and a second STA. The first AP establishes a first link with the first STA, and the first AP and the first STA can transmit data through the first link. The second AP establishes a second link with the second STA, and the second AP and the second STA can transmit data through the second link. The first AP and the first STA negotiate a first key, and the second AP and the second STA negotiate a second key. For downlink communication, the first AP can encrypt the management frames it sends according to the link-level key provided in this application, and the first AP transmits the encrypted management frames through the first link. The first STA decrypts the management frames it receives according to the link-level key used by the first AP. Similarly, the second AP can encrypt the management frames it sends according to the link-level key provided in this application, and the second AP transmits the encrypted management frames through the first link. The second STA decrypts the management frames it receives according to the link-level key used by the second AP. For uplink communication, the first STA can encrypt its sent management frames using the link-level key provided in this application. The first STA transmits the encrypted management frames through the first link, and the first AP decrypts the received management frames using the link-level key used by the first STA. Similarly, the second STA can encrypt its sent management frames using the link-level key provided in this application. The second STA transmits the encrypted management frames through the first link, and the second AP decrypts the received management frames using the link-level key used by the second STA. Thus, the AP and STA corresponding to each link can encrypt and transmit management frames using the negotiated link-level key, improving the security of the management frames.

[0234] The above embodiments are all illustrative examples of encrypting and decrypting management frames. The communication method provided in this application can also be applied to data frames or control frames, and this application is not limited thereto.

[0235] The above mainly describes the solutions provided by the embodiments of this application from the perspective of network element interaction. Correspondingly, the embodiments of this application also provide a communication device for implementing the various methods described above. This communication device can be an AP multi-link device in the above method embodiments, or a device containing the above AP multi-link device, or a component usable in an AP multi-link device; or, this communication device can be a STA multi-link device in the above method embodiments, or a device containing the above STA multi-link device, or a component usable in a STA multi-link device; or, this communication device can be a relay device in the above method embodiments, or a device containing the above relay device, or a component usable in a relay device. It is understood that, in order to achieve the above functions, the communication device includes hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should readily recognize that, in conjunction with the units and algorithm steps of the various examples described in the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0236] This application embodiment can divide the communication device into functional modules according to the above method embodiment. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be understood that the module division in this application embodiment is illustrative and is only a logical functional division. In actual implementation, there may be other division methods.

[0237] For example, Figure 14 is a schematic diagram of a communication device 1400 provided in this application. The communication device includes a transceiver module 1410 and optionally a processing module 1420. The transceiver module 1410, also known as a transceiver unit, is used to implement the transceiver function. For example, it can be a transceiver circuit, a transceiver, a transceiver device, or a communication interface.

[0238] Taking the communication device 1400 as an example of the AP multi-link device in the above method embodiment, one possible implementation is as follows:

[0239] Processing module 1420 is used to generate a management frame, which includes a first message complete checksum obtained based on a first key. The first key is generated based on address information and KDK associated with the first link. For example, processing module 1420 is used to execute step 510 in Figure 5.

[0240] The transceiver module 1410 is used to send management frames to the first STA. For example, the transceiver module 1410 is used to perform step 520 in Figure 5.

[0241] Taking the communication device 1400 as an example of the STA multi-link device in the above method embodiment, one possible implementation is as follows:

[0242] The transceiver module 1410 is used to receive management frames from the first AP.

[0243] Processing module 1420 is used to decrypt the management frame according to the first key. For example, processing module 1420 is used to perform step 530 in FIG5.

[0244] The transceiver module 1410 is also configured to send an association request to the first AP. The association request includes a second identifier, which indicates whether the management frame protection enhancement mode is enabled or activated. For example, the transceiver module 1410 is configured to perform step 540 in FIG12.

[0245] Taking the communication device 1400 as an example of the STA multi-link device in the above method embodiment, one possible implementation is as follows:

[0246] Processing module 1420 is also used to generate management frames. For example, processing module 1420 is used to perform step 1310 in FIG13.

[0247] The transceiver module 1410 is also used to send management frames to the first AP. For example, the transceiver module 1410 is used to perform step 1320 in Figure 13.

[0248] Taking the communication device 1400 as an example of the AP multi-link device in the above method embodiment, one possible implementation is as follows:

[0249] The transceiver module 1410 is also used to receive management frames from the first STA.

[0250] Processing module 1420 is used to decrypt the management frame according to the first key. For example, processing module 1420 is used to perform step 1330 in FIG13.

[0251] Optionally, the communication device 1400 may also include a storage module 1430 for storing link-level keys and multi-link device-level keys.

[0252] All relevant content of each step involved in the above method embodiments can be referred to in the functional description of the corresponding functional module, and will not be repeated here. Optionally, the communication device 1400 may further include a storage module, which can be used to store instructions and / or data, and the processing module 1420 can read the instructions and / or data in the storage module.

[0253] In this embodiment, the communication device 1400 is presented in an integrated manner, divided into various functional modules. Here, "module" can refer to a specific ASIC, circuitry, a processor and memory executing one or more software or firmware programs, integrated logic circuitry, and / or other devices that can provide the aforementioned functions. In a simplified embodiment, those skilled in the art will recognize that the communication device can take the form of the communication device 400 shown in FIG. 4.

[0254] For example, the processor 401 in the communication device 400 shown in Figure 4 can call the computer execution instructions stored in the memory 404 to make the communication device 400 execute the communication method in the above method embodiment.

[0255] Specifically, the functions / implementation processes of the transceiver module 1410 and processing module 1420 in Figure 14 can be implemented by the processor 401 in the communication device 400 shown in Figure 4 calling computer execution instructions stored in the memory 404. Alternatively, the functions / implementation processes of the processing module 1420 in Figure 14 can be implemented by the processor 401 in the communication device 400 shown in Figure 4 calling computer execution instructions stored in the memory 404, and the functions / implementation processes of the transceiver module 1410 in Figure 14 can be implemented by the communication interface 402 in the communication device 400 shown in Figure 4.

[0256] Since the communication device provided in this application embodiment can execute the above communication method, the technical effects it can obtain can be referred to the above method embodiment, and will not be repeated here.

[0257] It should be understood that one or more of the above modules or units can be implemented by software, hardware, or a combination of both. When any of the above modules or units are implemented by software, the software exists as computer program instructions and is stored in memory. The processor can be used to execute the program instructions and implement the above method flow. The processor can be built into a SoC (System-on-a-Chip) or ASIC, or it can be a separate semiconductor chip. In addition to the core that executes software instructions for computation or processing, the processor may further include necessary hardware accelerators, such as field-programmable gate arrays (FPGAs), PLDs (Programmable Logic Devices), or logic circuits that implement dedicated logic operations.

[0258] When the above modules or units are implemented in hardware, the hardware can be any one or any combination of a CPU, microprocessor, digital signal processing (DSP) chip, microcontroller unit (MCU), artificial intelligence processor, ASIC, SoC, FPGA, PLD, application-specific digital circuit, hardware accelerator, or non-integrated discrete device, which can run the necessary software or perform the above method flow independently of software.

[0259] Optionally, embodiments of this application also provide a communication device (e.g., the communication device may be a chip or a chip system), which includes a processor for implementing the methods in any of the above method embodiments. In one possible design, the communication device further includes a memory. The memory is used to store necessary program instructions and data, and the processor can call the program code stored in the memory to instruct the communication device to execute the methods in any of the above method embodiments. Of course, the memory may not be included in the communication device. When the communication device is a chip system, it may be composed of chips or may include chips and other discrete devices; embodiments of this application do not specifically limit this.

[0260] Optionally, embodiments of this application also provide a computer-readable storage medium storing a computer program or instructions that, when run on a communication device, enable the communication device to execute the methods of any of the above-described method embodiments or any implementation thereof.

[0261] Optionally, embodiments of this application also provide a communication system, which includes the network device and the terminal device described in the above method embodiments.

[0262] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented using software programs, implementation can be, in whole or in part, in the form of a computer program product. This computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the flow or function according to the embodiments of this application is generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, computer instructions can be transmitted from one website, computer, server, or data center to another via wired (e.g., coaxial cable, fiber optic, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device containing one or more servers, data centers, etc., that can be integrated with the medium. The available media can be magnetic media (e.g., floppy disks, hard disks, magnetic tapes), optical media (e.g., DVDs), or semiconductor media (e.g., solid-state disks, SSDs).

[0263] Although this application has been described herein in conjunction with various embodiments, those skilled in the art, by reviewing the accompanying drawings, the disclosure, and the appended claims, will understand and implement other variations of the disclosed embodiments in carrying out the claimed application. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple instances. A single processor or other unit can implement several functions listed in the claims. While different dependent claims may recite certain measures, this does not mean that these measures cannot be combined to produce good results.

[0264] Although this application has been described in conjunction with specific features and embodiments, it is obvious that various modifications and combinations can be made thereto without departing from the scope of this application. Accordingly, this specification and drawings are merely exemplary illustrations of this application as defined by the appended claims, and are considered to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from the spirit and scope of this application. Thus, if such modifications and modifications of this application fall within the scope of the claims of this application and their equivalents, this application is also intended to include such modifications and modifications.

[0265] In the description of this application, unless otherwise stated, " / " indicates that the objects before and after are in an "or" relationship. For example, A / B can mean A or B. "And / or" in this application is merely a description of the relationship between the related objects, indicating that there can be three relationships. For example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. A and B can be singular or plural.

[0266] In the description of this application, unless otherwise stated, "multiple" means two or more. "At least one of the following or similar expressions" refers to any combination of these items, including any combination of single or multiple items. For example, at least one of a, b and / or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0267] Furthermore, to facilitate a clear description of the technical solutions in the embodiments of this application, the terms "first" and "second" are used in the embodiments of this application to distinguish identical or similar items with substantially the same function and effect. Those skilled in the art will understand that the terms "first" and "second" do not limit the quantity or execution order, and the terms "first" and "second" are not necessarily different.

[0268] In the embodiments of this application, the words "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design solutions. Specifically, the use of the words "exemplarily" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.

[0269] It is understood that the term "embodiment" used throughout the specification means that a specific feature, structure, or characteristic related to an embodiment is included in at least one embodiment of this application. Therefore, throughout the specification, various embodiments do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. It is understood that in the various embodiments of this application, the sequence number of each process does not imply the order of execution; the execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0270] It is understood that some optional features in the embodiments of this application can be implemented independently in certain scenarios without relying on other features, such as the current solution on which they are based, to solve the corresponding technical problems and achieve the corresponding effects. Alternatively, they can be combined with other features as needed in certain scenarios. Correspondingly, the apparatus given in the embodiments of this application can also implement these features or functions, which will not be elaborated here.

[0271] In this application, unless otherwise specified, the same or similar parts between the various embodiments can be referred to each other. In the various embodiments of this application, unless otherwise specified or logically conflicting, the terminology and / or descriptions between different embodiments are consistent and can be mutually referenced. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships. The following embodiments of this application do not constitute a limitation on the scope of protection of this application.

Claims

1. A communication method, characterized in that, Applied to a first multi-link device, the first multi-link device including a first site, the first site establishing a first link with a second site included in a second multi-link device; the method includes: Generate a management frame, the management frame including a first message complete verification code obtained based on a first key, the first key being generated based on address information related to the first link and a key derivation key KDK; The management frame is sent to the second station.

2. A communication method, characterized in that, Applied to a second multi-link device, the second multi-link device including a second site, the second site establishing a first link with a first site included in a first multi-link device; the method includes: Receive a management frame from the first site, the management frame including a first message complete checksum obtained based on a first key, the first key being generated based on address information associated with the first link and a key derivation key KDK; The management frame is decrypted using the first key.

3. The method according to claim 1 or 2, characterized in that, The first key is generated based on the address information associated with the first link and the key derivation key KDK, including: The first key is generated based on address information associated with the first link, the key-derived key, and a random number. The address information associated with the first link includes the address of the first site and the address of the second site.

4. The method according to claim 3, characterized in that, The address information related to the first link also includes the address of the first multi-link device and the address of the second multi-link device.

5. The method according to any one of claims 1-4, characterized in that, The first message complete checksum is calculated based on the first key from all or part of the fields of the MAC protocol data unit header in the management frame.

6. The method according to any one of claims 1-5, characterized in that, The management frame also includes a first packet sequence number and a first key identifier, both of which are associated with the first key.

7. The method according to any one of claims 1-6, characterized in that, The management frame further includes a first identifier, which is used to indicate an encryption mode. The encryption mode includes a first encryption mode and a second encryption mode. The first encryption mode is to protect the management frame based on a first key, and the second encryption mode is to protect the management frame based on a first key and a second key. When the first identifier indicates the first encryption mode, the management frame includes the first message complete checksum obtained based on the first key; When the first identifier indicates the second encryption mode, the management frame also includes a second message integrity check code obtained based on the second key.

8. The method according to claim 7, characterized in that, The first identifier is located in the key identifier field of the cryptographic block chain message verification code protocol header in the management frame.

9. The method according to any one of claims 1-8, characterized in that, The first multi-link device is an access point (AP) multi-link device, and the second multi-link device is a site (STA) multi-link device; Alternatively, the first multi-link device may be a STA multi-link device, and the second multi-link device may be an AP multi-link device.

10. The method according to any one of claims 2-8, characterized in that, The first multi-link device is an access point (AP) multi-link device, the second multi-link device is a site (STA) multi-link device, and the method further includes: Send an association request to the first site. The association request includes a second identifier, which is used to indicate whether the management frame protection enhancement mode is enabled or activated.

11. The method according to any one of claims 1, 3-8, characterized in that, The first multi-link device is an access point (AP) multi-link device, the second multi-link device is a site (STA) multi-link device, and the method further includes: Receive an association request from the second site, the association request including a second identifier, the second identifier being used to indicate enabling or activating the management frame protection enhancement mode.

12. The method according to claim 10 or 11, characterized in that, The second identifier is located in the robust secure network field of the association request.

13. A communication device, characterized in that, include: A functional unit for performing the method as described in any one of claims 1-12; wherein the action performed by the functional unit is implemented by hardware or by hardware executing corresponding software.

14. A communication device, characterized in that, The communication device includes a processor; the processor is configured to run computer programs or instructions, or to use logic circuitry to cause the communication device to implement the method as described in any one of claims 1-12.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions or programs that, when executed on a computer, cause the communication device to perform the method as described in any one of claims 1-12.

Citation Information

Patent Citations

  • Secure medium access control (MAC) header

    EP4293963A1

  • Communication method and communication apparatus

    WO2023036081A1

  • Authentication method and apparatus, device, and storage medium

    WO2024026735A1

  • Communication method and communication apparatus

    WO2024131809A1