Key generation method, communication apparatus and communication system

The method for generating PMK and PTK keys using random scalars and MICs addresses AMP IoT device limitations, improving key generation efficiency and reducing energy consumption.

WO2026016152A9PCT designated stage Publication Date: 2026-04-09HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-07-18
Publication Date
2026-04-09

AI Technical Summary

Technical Problem

Ambient Power (AMP) IoT devices face limitations in channel bandwidth and modulation techniques, preventing them from using legacy IEEE 802.11 protocols like probing, authentication, and security mechanisms, leading to rapid energy depletion during security key generation procedures.

Method used

A method for generating pairwise master and transient keys (PMK and PTK) using random scalars and password elements, with cross-verification through Message Integrity Codes (MICs), allowing simultaneous generation and verification of keys to reduce signaling overhead and improve efficiency.

Benefits of technology

Enhances key generation efficiency and communication reliability by minimizing signaling interactions and reducing energy consumption in AMP IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024106279_09042026_PF_FP_ABST
    Figure CN2024106279_09042026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present application provide a key generation method, a communication apparatus and a communication system, which are applicable for any ambient power IoT system, to improv key generation efficiency and communication efficiency. A first AMP STA transmits a first frame carrying first pairwise master key (PMK) materials. Accordingly, a second AMP STA receives the first frame. Then the second AMP STA transmits a second frame carrying second PMK materials, where the first PMK materials and the second PMK materials are used to generate a first PMK, a second PMK, a first pairwise transient key (PTK) and a second PTK. Accordingly, the first AMP STA receives the second frame.
Need to check novelty before this filing date? Find Prior Art

Description

KEY GENERATION METHOD, COMMUNICATION APPARATUS AND COMMUNICATION SYSTEMTECHNICAL FIELD

[0001] The present disclosure relates generally to wireless communication technology, and in particular, to a key generation method, a communication apparatus and a communication system.BACKGROUND

[0002] AMbient Power (AMP) is a new task group (IEEE 802.11bp) within the IEEE 802.11 working group that is studying the support of Ambient Power communication in IEEE 802.11 network. The goal is to address the need of ambient power-enabled Wi-Fi Internet of Things (IoT) devices (AMP IoT stations, AMP IoT STAs for short) . This group is exploring power harvesting technologies that can significantly increase the battery lifespan of the AMP IoT STAs, such as Radio Frequency (RF) Power harvesting (or backscattering) , power harvesting using light, motion, etc.

[0003] Due to the hardware restrictions and the need to lower the power consumption, it is expected that the AMP IoT STAs will operate at a much lower channel bandwidth (e.g., 4 MHz) compared to traditional 802.11 STAs that operate at channel bandwidths of 20 MHz or multiples of 20 MHz. In addition, the AMP IoT STAs may not be able to use advanced modulation techniques such as Orthogonal Frequency Division Multiplexing (OFDM) and hence not able to transmit the legacy 802.11 preamble that is present at the beginning of almost all 802.11 Presentation Protocol Data Units (PPDUs) . Due to such various limitations, it is likely that AMP IoT STAs may not be able to make use of many of the basic IEEE 802.11 protocols such as probing, Authentication, association, and security mechanisms (e.g., robust security network association (RSNA) , etc. ) .SUMMARY

[0004] Embodiments of the present disclosure provide a key generation method, a communication apparatus, a communication system, a computer-readable storage medium, a computer program product, and a computer program.

[0005] In a first aspect, the present disclosure provides a key generation method, and the method may be performed by a first station (STA) , which may be an AMP access point station (AMP AP STA) or a chip of the AMP AP STA. The AMP AP STA may be a Type A AMP STA. The method includes: transmitting a first frame carrying first pairwise master key (PMK) materials, and receiving a second frame carrying second PMK materials, where the first PMK materials and the second PMK materials are used to generate a first PMK and a first pairwise transient key (PTK) .

[0006] In some implementations, the first PMK materials comprise a first random scalar and a first password element, and the second PMK materials comprise a second random scalar and a second password element; and the first random scalar, the first password element, the second random scalar and the second password element are used to generate the first PMK.

[0007] In some implementations, the first random scalar, the second random scalar and the first PMK are used to generate the first PTK.

[0008] In some implementations, the first frame further carries a first random number, and the second frame further carries a second random number, wherein the first random number, the second random number and the first PMK are used to generate the first PTK.

[0009] In some implementations, the method further comprises transmitting a third frame carrying a first MIC, wherein the first MIC is used to verify correctness of a second PTK of a second AMP STA.

[0010] In some implementations, the method further comprises transmitting a first protected frame, wherein a first frame body field in the first protected frame is encrypted by the first PTK, and the first protected frame further comprises a first frame check sequence (FCS) field for carrying a MIC generated from the first PTK.

[0011] In some implementations, the second frame further carries a second MIC, and the second MIC is used to verify correctness of the first PTK.

[0012] In some implementations, the method further comprises receiving a second protected frame, wherein a second frame body field in the second protected frame is encrypted by the second PTK, and the second protected frame further comprises a second frame check sequence (FCS) field for carrying a MIC generated from the second PTK.

[0013] In some implementations, the method further comprises transmitting a fourth frame carrying a first PMK identifier (PMKID) and a third random number, wherein the first PMKID is used to retrieve the second PMK based on a second PMKID stored in a non-volatile memory of a second AMP STA; and receiving a fifth frame carrying a fourth random number, wherein the third random number and the fourth random number are used to generate a third PTK based on the first PMK.

[0014] In some implementations, the method further comprises transmitting a sixth frame carrying a third MIC, wherein the third MIC is used to verify correctness of a fourth PTK of the second AMP STA, wherein the third MIC is generated from the third PTK.

[0015] In some implementations, the method further comprises receiving a seventh frame carrying a second PMK identifier (PMKID) and a fifth random number, wherein the second PMKID is used to retrieve the first PMK based on a first PMKID stored in a non-volatile memory, generating a third PTK from the first PMK; and transmitting an eighth frame carrying a sixth random number, wherein the fifth random number and the sixth random number are used to generate a fourth PTK based on the second PMK.

[0016] In some implementations, the method further comprises receiving a ninth frame carrying a fourth MIC, wherein the fourth MIC is used to verify correctness of the third PTK of the first AMP STA, wherein the fourth MIC is generated from the fourth PTK.

[0017] In a second aspect, the present disclosure provides a key generation method, and the method may be performed by a second AMP STA , which may be an AMP non-access point (AMP non-AP STA) or a chip of the AMP non-AP STA. The non-AP STA may be a Type B AMP STA or a Type C AMP STA. The method includes: receiving a first frame carrying first pairwise master key (PMK) materials; and transmitting a second frame carrying second PMK materials, where the first PMK materials and the second PMK materials are used to generate a second PMK and a second pairwise transient key (PTK) .

[0018] In some implementations, the first PMK materials comprise a first random scalar and a first password element, and the second PMK materials comprise a second random scalar and a second password element; and the first random scalar, the first password element, the second random scalar and the second password element are used to generate the second PMK.

[0019] In some implementations, the first random scalar, the second random scalar and the second PMK are used to generate the second PTK.

[0020] In some implementations, the first frame further carries a first random number, and the second frame further carries a second random number, wherein the first random number, the second random number and the second PMK are used to generate the second PTK.

[0021] In some implementations, the method further comprises receiving a third frame carrying a first MIC, wherein the first MIC is used to verify correctness of the second PTK.

[0022] In some implementations, the third frame is an AMP request frame carrying partial content of an AMP Authentication confirmation frame.

[0023] In some implementations, the method further comprises receiving a first protected frame, wherein a first frame body field in the first protected frame is encrypted by the first PTK, and the first protected frame further comprises a first frame check sequence (FCS) field for carrying the first MIC.

[0024] In some implementations, the second frame further carries a second MIC, wherein the second MIC is used to  verify correctness of a first PTK of a first AMP STA.

[0025] In some implementations, the method further comprises transmitting a second protected frame, wherein a second frame body field in the second protected frame is encrypted by the second PTK, and the second protected frame further comprises a second frame check sequence (FCS) field for carrying a MIC generated from the second PTK.

[0026] In some implementations, the method further comprises receiving a fourth frame carrying a first PMK identifier (PMKID) and a third random number, wherein the first PMKID is used to retrieve the second PMK based on a second PMKID stored in a non-volatile memory, generating a fourth PTK from the second PMK; and transmitting a fifth frame carrying a fourth random number, wherein the third random number and the fourth random number are used to generate a third PTK based on the first PMK.

[0027] In some implementations, the method further comprises receiving a sixth frame carrying a third MIC, wherein the third MIC is used to verify correctness of the fourth PTK.

[0028] In some implementations, the sixth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0029] In some implementations, the method further comprises transmitting a seventh frame carrying a second PMK identifier (PMKID) and a fifth random number, wherein the second PMKID is used to retrieve the first PMK based on a first PMKID stored in a non-volatile memory of a first AMP STA; and receiving an eighth frame carrying a sixth random number, wherein the fifth random number and the sixth random number are used to generate a fourth PTK based on the second PMK.

[0030] In some implementations, the method further comprises transmitting a ninth frame carrying a fourth MIC, wherein the fourth MIC is used to verify correctness of the third PTK of a first AMP STA.

[0031] In some implementations, the ninth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0032] In a third aspect, the present disclosure provides a key generation method, and the method may be performed by a first AMP STA, which may be an AMP access point station (AMP AP STA) or a chip of the AMP AP STA. The AMP AP STA may be a Type A AMP STA. The key generation method includes: transmitting a tenth frame carrying third pairwise master key (PMK) materials and a seventh random number, where the third PMK materials are used to generate a third PMK; and receiving an eleventh frame carrying eighth random number, where the seventh random number, the eighth random number and the third PMK are used to generate a fifth PTK.

[0033] In some implementations, the method further comprises transmitting a twelfth frame carrying a fifth MIC, wherein the fifth MIC is used to verify correctness of the sixth PTK of a second AMP STA.

[0034] In some implementations, the twelfth frame is an AMP request frame carrying partial content of an AMP Authentication confirmation frame.

[0035] In some implementations, the method further comprises transmitting a third protected frame, wherein a third frame body field in the third protected frame is encrypted by the fifth PTK, and the third protected frame further comprises a third frame check sequence (FCS) field for carrying a MIC generated from the fifth PTK.

[0036] In some implementations, the eleventh frame further carries a sixth MIC, and the sixth MIC is used to verify correctness of the fifth PTK.

[0037] In some implementations, the method further comprises receiving a fourth protected frame, wherein a fourth frame body field in the fourth protected frame is encrypted by the sixth PTK, and the fourth protected frame further comprises a fourth frame check sequence (FCS) field for carrying a MIC generated from the sixth PTK.

[0038] In some implementations, the method further comprises transmitting a thirteenth frame carrying a third PMK identifier (PMKID) and a ninth random number, wherein the third PMKID is used to retrieve the fourth PMK based on a  fourth PMKID stored in a non-volatile memory of a second AMP STA; and receiving a fourteenth frame carrying a tenth random number, wherein the ninth random number the tenth random number and the third PMK are used to generate a seventh PTK.

[0039] In some implementations, the method further comprises transmitting a fifteenth frame carrying a seventh MIC, wherein the seventh MIC is used to verify correctness of an eighth PTK of the second AMP STA.

[0040] In some implementations, the method further comprises receiving a sixteenth frame carrying a fourth PMK identifier (PMKID) and an eleventh random number, wherein the fourth PMKID is used to retrieve the third PMK based on an third PMKID stored in a non-volatile memory, generating an seventh PTK from the third PMK; and transmitting a seventeenth frame carrying a twelfth random number, wherein the eleventh random number and the twelfth random number are used to generate an eighth PTK based on the fourth PMK of a second AMP STA.

[0041] In some implementations, the method further comprises receiving an eighteenth frame carrying an eighth MIC, wherein the eighth MIC is used to verify correctness of the seventh PTK.

[0042] In a fourth aspect, the present disclosure provides a key generation method, and the method may be performed by a second AMP STA , which may be an AMP non-access point (AMP non-AP STA) or a chip of the AMP non-AP STA. The AMP non-AP STA may be a Type B AMP STA or a Type C AMP STA. The method includes: receiving a tenth frame carrying third pairwise master key (PMK) materials and seventh random number, the third PMK materials is used to generate a fourth PMK; and transmitting an eleventh frame carrying eighth random number, where the seventh random number, the eighth random number and the fourth PMK are used to generate a sixth PTK.

[0043] In some implementations, the method further comprises receiving a twelfth frame carrying a fifth MIC, wherein the fifth MIC is used to verify correctness of the sixth PTK.

[0044] In some implementations, the twelfth frame is an AMP request frame carrying partial content of an AMP Authentication confirmation frame.

[0045] In some implementations, the method further comprises receiving a third protected frame, wherein a third frame body field in the third protected frame is encrypted by the fifth PTK, and the third protected frame further comprises a third frame check sequence (FCS) field for carrying a MIC generated from the fifth PTK.

[0046] In some implementations, the eleventh frame further carries a sixth MIC, wherein the sixth MIC is used to verify correctness of a fifth PTK of a first AMP STA.

[0047] In some implementations, the method further comprises transmitting a fourth protected frame, wherein a fourth frame body field in the fourth protected frame is encrypted by the sixth PTK, and the fourth protected frame further comprises a fourth frame check sequence (FCS) field for carrying a MIC from the sixth PTK.

[0048] In some implementations, the method further comprises receiving a thirteenth frame carrying a third PMK identifier (PMKID) and a ninth random number, wherein the third PMKID is used to retrieve the fourth PMK based on a fourth PMKID stored in a non-volatile memory, generating an eighth PTK from the fourth PMK; and transmitting a fourteenth frame carrying a tenth random number, wherein the ninth random number and the tenth random number are used to generate a seventh PTK based on the third PMK.

[0049] In some implementations, the method further comprises receiving a fifteenth frame carrying a seventh MIC, wherein the seventh MIC is used to verify correctness of the eighth PTK.

[0050] In some implementations, the fifteenth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0051] In some implementations, the method further comprises transmitting a sixteenth frame carrying a fourth PMK identifier (PMKID) and an eleventh random number, wherein the fourth PMKID is used to retrieve the third PMK based on an third PMKID stored in a non-volatile memory of a first AMP STA; and receiving a seventeenth frame carrying the a  twelfth random number, wherein the eleventh random number and the twelfth random number are used to generate an eighth PTK based on the fourth PMK.

[0052] In some implementations, the method further comprises transmitting an eighteenth frame carrying an eighth MIC, wherein the eighth MIC is used to verify correctness of the seventh PTK of a first AMP STA.

[0053] In some implementations, the eighteenth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0054] In some embodiments, the eighteenth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0055] In a fifth aspect, the present disclosure provides a communication apparatus. The communication apparatus includes a processor and a communication interface. The processor is connected to the communication interface. The processor is configured to execute one or more instructions, and the communication interface is configured to communicate with other network elements under the control of the processor. The processor is enabled to perform the method according to the first aspect or any one of the possible embodiments of the first aspect, or the second aspect or any one of the possible embodiments of the second aspect.

[0056] In a sixth aspect, the present disclosure provides a communication system including a first communication apparatus performing the method according to the first aspect or any one of the possible embodiments of the first aspect, and a second communication apparatus performing the method according to the second aspect or any one of the possible embodiments of the second aspect.

[0057] In a seventh aspect, the present disclosure provides a computer-readable storage medium. The computer-readable storage medium stores program codes or instructions that, when executed by a processing circuit of a computer, cause the computer to implement the method according to the first aspect or any one of the possible embodiments of the first aspect, or the second aspect or any one of the possible embodiments of the second aspect.

[0058] In a eighth aspect, the present disclosure provides a computer program product including one or more instructions, that when the computer program product is run on a computer, causing the computer to implement the method according to the first aspect or any one of the possible embodiments of the first aspect, or the second aspect or any one of the possible embodiments of the second aspect.BRIEF DESCRIPTION OF THE DRAWINGS

[0059] For ease of understanding the various described embodiments where, reference is made to the Detailed Description below, in conjunction with the following drawings in which same / similar reference numerals refer to corresponding parts throughout the figures.

[0060] FIG. 1 illustrates a schematic diagram of an application scenario in accordance with an embodiment of the present disclosure;

[0061] FIG. 2 illustrates a flow chart of a key generation method, in accordance with some embodiments of the present disclosure;

[0062] FIG. 3 illustrates a detailed example of the combined PMK and PTK generation procedure shown in FIG. 2;

[0063] FIG. 4 illustrates a procedure to derive a PTK from a PMK in accordance with some embodiments of the present disclosure;

[0064] FIG. 5 illustrates another detailed example of the combined PMK and PTK generation procedure shown in FIG. 2, in accordance with some embodiments of the present disclosure;

[0065] FIG. 6 illustrates a procedure to derive a PTK from a PMK, in accordance with some embodiments of the present disclosure;

[0066] FIG. 7 illustrates a flow chart of a GTK generation from a PTK in accordance with some embodiments of the  present disclosure;

[0067] FIG. 8 illustrates an example of a new PTK generation initiated by the first AMP STA in accordance with some embodiments of the present disclosure;

[0068] FIG. 9 illustrates an example of a new PTK generation initiated by the second AMP STA in accordance with some embodiments of the present disclosure;

[0069] FIG. 10 illustrates a format of a protected AMP frame in accordance with some embodiments of the present disclosure;

[0070] FIG. 11 illustrates the format of an AMP Authentication frame in accordance with some embodiments of the present disclosure;

[0071] FIG. 12 illustrates the format of an AMP KeyGen frame in accordance with some embodiments of the present disclosure ;

[0072] FIG. 13 illustrates an example of an AMP frame being encapsulated in an AMP Request frame in accordance with some embodiments of the present disclosure ;

[0073] FIG. 14 illustrates the format of an AMP Response frame in accordance with some embodiments of the present disclosure;

[0074] FIG. 15 illustrates an example of the CCMP encapsulation procedure in accordance with some embodiments of the present disclosure;

[0075] FIG. 16 illustrates an example of the CCMP decapsulation procedure in accordance with some embodiments of the present disclosure; and

[0076] FIG. 17 illustrates another flow chart of a key generation method, in accordance with some embodiments of the present disclosure;

[0077] FIG. 18 illustrates a detailed example of the combined PMK and PTK generation procedure shown in FIG. 17;

[0078] FIG. 19 illustrates a procedure to derive a PTK from a PMK in accordance with some embodiments of the present disclosure;

[0079] FIG. 20 illustrates the format of an AMP Authentication frame in accordance with some embodiments of the present disclosure;

[0080] FIG. 21 illustrates a block diagram of a communication apparatus, in accordance with some embodiments of the present disclosure; and

[0081] FIG. 22 illustrates a block diagram of another communication apparatus, in accordance with some embodiments of the present disclosure.DETAILED DESCRIPTION

[0082] The technical solutions described in the present disclosure are applicable to a wide range of communication networks, such as an ambient power internet of things (AMP-IoT) network, near field communication (NFC) , etc. These solutions may also be implemented in wireless fidelity (Wi-Fi) or automated manufacturing systems in smart factories.

[0083] For ease of understanding, the technical terms involved in the embodiments are first described below.

[0084] 1. AMP protected frame

[0085] An AMP frame is a frame that is cryptographically protected. Protection may refer either to Authentication in which the integrity of the content of the frame can be verified but the content itself is not encrypted, or protection may refer to encryption in which selected content of the frame is encrypted.

[0086] 2. AMP STA

[0087] An AMP STA is a 802.11 STA that can transmit and receive AMP PPDU.

[0088] An AMP STA may be further classified as:

[0089] 3. AMP AP STA

[0090] An AMP AP STA is an AP STA that can transmit and receive AMP PPDU and communicate with AMP non-AP STAs.

[0091] 4. AMP non-AP STA

[0092] An AMP non-AP STA is a non-AP STA that can transmit and receive AMP PPDU, and communicate with AMP AP or another AMP non-AP STA.

[0093] 5. AMP assisting STA

[0094] An AMP assisting STA (either AP or non-AP) is an AMP STA that provides assistance to an AMP assisted non-AP STA to communicate using the AMP protocol. The assistance may be providing energy (Wireless power) , relay service, transmitting carrier signal for RF backscattering, or the like. In the context of AMP RFID protocol, the assistance is by transmitting carrier signal to the AMP RFID tags for RF backscattering.

[0095] 6. AMP assisted non-AP STA

[0096] An AMP assisted non-AP STA is an AMP non-AP STA that can communicate using the AMP protocol using the assistance provided by an AMP assisting STA.

[0097] Based on its capabilities an AMP STA may be classified as:

[0098] 7. Type A AMP STA

[0099] A Type A AMP STA has capabilities to support legacy 802.11 protocols (e.g., 802.11b / g / n) and support their own energy source, e.g., battery.

[0100] 8. Type B AMP STA

[0101] A Type B AMP STA does not support legacy 802.11 protocols and only supports low power transceiver operations, and also possess some sort of small energy source, e.g., large capacitors, ambient power source, or the like.

[0102] 9. Type C AMP STA

[0103] A Type C AMP STA does not support legacy 802.11 protocols and only supports low power transceiver operations, and does not possess any energy source. The Type C AMP STA uses backscattering technique for their transmissions. Here, AMP RFID tag is a special sub-category of the Type C AMP STA.

[0104] In IEEE 802.11-24\178r0, it is proposed a transaction based communication for AMP in which the AMP devices do not perform the typical 802.11 procedure to join a network (Authentication, association, 4-way handshake, etc. ) . Instead, it is proposed that prior to each communication session, the two communicating AMP STAs engage in a security key generation procedure (using simultaneous Authentication of equals (SAE) ) . The security key so generated is used to encrypted the subsequent communication between the devices.

[0105] As mentioned in the background section, AMP client devices may be very simple devices with low processing power and with limited energy source. Requiring such devices to engage in a security key generation procedure such as SAE prior to every communication session will deplete their energy very fast.

[0106] To solve this problem, embodiments of the present disclosure provide the following technical solutions, which are described below with reference to the accompanying drawings.

[0107] As used where, the terms "a" , "an" and "one " are defined to mean "at least one" , that is, these terms do not exclude a plural number of items, unless stated otherwise.

[0108] Unless the context requires otherwise, throughout the description and the claims, the term "comprise" and other forms thereof such as the third-person singular form "comprises" and the present participle form "comprising" are construed as open and inclusive meanings, i.e., "including, but not limited to" . In the description, the terms such as "one  embodiment" , "some embodiments" , "exemplary embodiments" , "example" , "specific example" or "some examples" are intended to indicate that specific features, structures, materials or characteristics related to the embodiment (s) or example (s) are included in at least one embodiment or example of the present disclosure. Schematic representations of the above terms do not necessarily refer to the same embodiment (s) or examples (s) . In addition, the specific features, structures, materials or characteristics may be included in any one or more embodiments or examples in any suitable manner.

[0109] Hereafter, the terms "first" and "second" are used for descriptive purposes only, and are not to be construed as indicating or implying the relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of the present disclosure, the terms "a / the plurality of" and "multiple" means two or more unless otherwise specified.

[0110] In the description of some embodiments, the terms "coupled" and "connected" and derivatives thereof may be used. For example, the term "connected" may be used in the description of some embodiments to indicate that two or more components are in direct physical or electrical contact with each other. For another example, the term "coupled" may be used in the description of some embodiments to indicate that two or more components are in direct physical or electrical contact. However, the term "coupled" may also mean that two or more components are not in direct contact with each other, but still cooperate or interact with each other. The embodiments disclosed where are not necessarily limited to the content where.

[0111] The phrase "A and / or B" includes the following three combinations: only A, only B, and a combination of A and B.

[0112] As used where, the terms "system" and "network" may be used interchangeably in embodiments of the present disclosure. The term "and / or" describes an association relationship of associated objects, and indicates that three relationships may exist. For example, A and / or B may indicate the following three cases: only A exists, both A and B exist, and only B exists, where A and B may be singular or plural. The character " / " usually indicates an "or" relationship between associated objects. "At least one of the following items (pieces) " or an expression similar thereto indicates any combination of these items, including a single item (piece) or any combination of a plurality of items (pieces) . For example, "at least one of A, B, or C" includes A, or includes B, or includes C, or includes A and B, or includes A and C, or includes B and C, or includes A, B, and C, and "at least one of A, B, and C" may also be understood as including A, or including B, or including C, or including A and B, or including A and C, or including B and C, or including A, B, and C. In addition, unless otherwise specified, ordinal numbers such as "first" and "second" in embodiments of the present disclosure are used to distinguish between a plurality of objects, and are not used to limit a sequence, a time sequence, priorities, or importance of the plurality of objects.

[0113] As used where, the expression "based on is intended to mean "based at least partly on" , that is, this expression can mean "based solely on" or “based partially on" , and so should not be interpreted in a limited manner. More particularly, the expression "based on" could also be understood as meaning of "depending on" , "representative of" , "indicative of" , "associated with" or similar expressions.

[0114] The network architecture as well as the service scenarios described in the embodiments of the present disclosure are for the purpose of more clearly illustrating the technical solutions of the present disclosure, and do not constitute a limitation on the technical solutions of the present disclosure. A person of ordinary skill in the art will appreciate that with the evolution of network architecture and the emergence of new service scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.

[0115] In order to facilitate the understanding of the embodiments of the present disclosure, a communication system applicable to the embodiments of the present disclosure is described below in detail.

[0116] FIG. 1 illustrates a schematic diagram of an application scenario in accordance with an embodiment of the  present disclosure.

[0117] Referring to FIG. 1, as an illustrative example without limitation, a simplified schematic illustration of a communication system is provided. The communication system 100 (which may be a wireless system) includes one or more first AMP STAs (e.g., AMP AP 120 illustrated in FIG. 1) , and one or more second AMP STAs (e.g., AMP IoT STAs 160 illustrated in FIG. 1) . In addition, the communication system 100 may include one or more AMP Energizers 140, which supply energy for one or more second AMP STAs by wireless power transmission (WPT) or other means, when the one or more AMP IoT STA 160 are resource-restricted (e.g., shortage of emerge, without a battery, etc. ) STA, for example, an AMP non-AP STA or a Type B AMP STA or a Type C AMP STA.

[0118] In one instance, an AMP AP acts as the first AMP STA and initiates the generation of the security keys while AMP IoT STA1 and AMP IoT STA2 act as the second AMP STAs and participate in the security key generation. In another instance, an AMP Energizer acts as the first AMP STA and initiates the generation of the security keys while AMP IoT STA1 and AMP IoT STA2 act as the second AMP STAs and participate in the security key generation.

[0119] A flow of interaction between various network elements / devices in the above-mentioned communication system will be specifically described below by means of method embodiments. A method provided by the embodiments of the present disclosure may be applicable to the communication system and specifically applied to various scenarios mentioned in the communication system.

[0120] In general, the present disclosure provides a key generation method, and the method may be performed by a first AMP STA and a second AMP STA. In the present disclosure, the first AMP STA may be an AMP access point station (AMP AP STA) or a chip of the AMP AP STA. The AMP AP STA may be a Type A AMP STA. The second AMP STA may be an AMP non-access point (AMP non-AP STA) or a chip of the AMP non-AP STA. The AMP non-AP STA may be a Type B AMP STA or a Type C AMP STA.

[0121] FIG. 2 illustrates a flow chart of a key generation method, in accordance with some embodiments of the present disclosure. In FIG. 2, there is provided a conceptual overview of the entire security key generation procedure and the transmission of protected AMP frames using the generated keys.

[0122] Referring to FIG. 2, the method 200 includes steps S21 and S22.

[0123] In step S21, the first AMP STA transmits a first frame carrying first pairwise master key (PMK) materials. PMK materials refer to parameters that are required to generate a master key (for example an PMK) . Accordingly, the second AMP STA receives the first frame.

[0124] In step S22, the second AMP STA transmits a second frame carrying second PMK materials, where the first PMK materials and the second PMK materials are used to generate a first PMK and a first pairwise transient key (denoted as PTK1 in FIG. 2) , and the first PMK materials and the second PMK materials are used to generate a second PMK and a second pairwise transient key (PTK) . Accordingly, the first AMP STA receives the second frame.

[0125] In general, the first PMK materials are generated by the first AMP STA, and the second PMK materials are generated by the second AMP STA. Upon receiving the second PMK materials, the first AMP STA generates the first PMK and the first PTK. Accordingly, upon receiving the first PMK materials, the second AMP STA may generate the second PMK and the second PTK (denoted as PTK2 in FIG. 2) .

[0126] Based on the above method, the transmission of the first PMK materials and the transmission of the second PMK materials can be realized in the same interaction process, and the first PMK materials and the second PMK materials may be used not only for generating the first PMK and the second PMK, but also for generating the first PTK and the second PTK. In other words, the first PMK and the second PMK, the first PTK and the second PTK may be generated together in the same process, instead of through two separate processes, and it is unnecessary to transmit dedicated parameters for generating the fist PTK and the second PTK, thereby saving signaling overhead and key generation time, and improving key generation efficiency and communication efficiency.

[0127] In some embodiments, the first PMK materials include a first random scalar and a first password element, and the second PMK materials include a second random scalar and a second password element, where the first random scalar, the first password element, the second random scalar, and the second password element are used to generate the first PMK by the first AMP STA and also used to generate the second PMK by the second AMP STA.

[0128] In this case, it is possible to use the first password element and the second random scalar in the first PMK materials, and the second random scalar and the second password element in the second PMK materials to generate the first PMK by the first AMP STA and to generate the second PMK by the second AMP STA.

[0129] In some embodiments, the first frame further carries a first random number, and the second frame further carries a second random number, where the first random number, the second random number and the first PMK are used to generate the first PTK, and the first random number, the second random number and the second PMK are used to generate the second PTK.

[0130] In this case, it is possible to use the first random number carried in the first frame and the second random number carried in the second frame in place of the first random scalar and the second random scalar, in combination with the newly generated first PMK, to generate the first PTK, and in combination with the newly generated second PMK, to generate the second PTK, so as to provide another option for generating the first PTK and the second PTK, thereby increasing flexibility of key generation.

[0131] As illustrated in FIG. 2, the first 2 message exchanges (using the first frame and the second frame) are used in an initial generation of the first master key (PMK) , the first transient key (PTK) , the second PMK and the second PTK. The procedure may be initiated after the first AMP STA has already established an initial communication with the second AMP STA (e.g., using a random access procedure) , obtained some basic information such as the second AMP STA’s identity (ID) , and verified that the second AMP STA supports protected communication.

[0132] The first AMP STA generates the first PMK materials and transmits the first frame to the second AMP STA to initiate the key generation procedure. The primary purpose of the first frame is to carry the first PMK materials (generated by the first AMP STA) required by the second AMP STA to generate the second PMK, but it optionally includes a first random number (e.g. ANonce) generated by the first AMP STA for the purpose of the second PTK generation.

[0133] Upon receiving the first frame, the second AMP STA generates the second PMK materials required to generate the first PMK and the second PMK and together with the first AMP STA’s PMK materials proceeds to generate the first PMK and the second PMK. For example, the generation of the first PMK and the second PMK may be based on SAE or pre-shared key (PSK) . Subsequently, the second AMP STA generates the second random number (e.g., SNonce) and together with the first random number (e.g., ANonce) proceeds to derive the first PTK from the first PMK and the second PTK from the second PMK. Subsequently, the second AMP STA transmits the second frame to the first AMP STA. The primary purpose of the second frame is to carry the second PMK materials (generated by the second AMP STA) required by the first AMP STA to generate the first PMK, but it also optionally includes the second random number (e.g., SNonce) generated by the second AMP STA for the purpose of the first PTK generation.

[0134] While FIG. 2 also illustrates the key generation message exchange initiated by the first AMP STA, the procedure can also be initiated by the second AMP STA. That is, the key generation procedure is symmetrical, and either a more powerful AMP STA (e.g., an AMP AP or an AMP Energizer) may initiate the procedure, or a less powerful AMP STAs (e.g., AMP RFID STAs or AMP IOT STAs) may initiate the procedure.

[0135] In some embodiments, referring to FIG. 2, the method further includes step S23.

[0136] In step S23, the first AMP STA transmits a third frame carrying a first MIC (denoted as MIC1 in FIG. 2) , where the first MIC is used to verify correctness of a second PTK of a second AMP STA. Accordingly, the second AMP STA receives the third frame.

[0137] In this case, the second AMP STA may verify the correctness of the second PTK generated by the second AMP  STA using the first MIC generated by the first AMP STA, so as to realize cross-verification of the correctness of the second PTK, thereby improving the reliability of key generation and communications.

[0138] In some implementations, the second frame further carries a second MIC (denoted as MIC2 in FIG. 2) , and the second MIC is used to verify correctness of a first PTK of the second AMP STA. The verification of the second PTK also acts as implicit verification of the second PMK.

[0139] In this case, the first AMP STA may verify the first PTK generated by the first AMP STA using the second MIC generated by the second AMP STA, which may realize cross-verification of the correctness of the first PTK, thereby improving the key generation reliability and communication reliability. To do this, the first AMP STA compares the received second MIC with the first MIC generated by the first AMP STA. If the first MIC matches the second MIC received in the second frame, it proves that the second PTK generated by the second AMP STA is the same as the first PTK generated by the first AMP STA. The verification of the first PTK also acts as implicit verification of the first PMK.

[0140] Moreover, the second AMP STA may transmit verification parameters of the second PTK (e.g., the second MIC) and PTK generation parameters (e.g., the second random number) to the first AMP STA in the same frame (e.g., the second frame) , thereby reducing the number of signaling interactions, and improving the key generation efficiency and verification efficiency.

[0141] As illustrated in FIG. 2, the second frame also further includes the second MIC that can be used by the first AMP STA to verify that the second PTK has been correctly generated by the second AMP STA. Upon receiving the second frame, the first AMP STA uses the first PMK materials, combined with the second PMK materials received from the second AMP STA, to generate the first PMK and the second PMK. The first AMP STA also uses the first random number and the second random number (e.g., ANonce and the SNonce) to generate the first PTK from the first PMK, and the second PTK from the second PMK. And the first AMP STA also uses the second MIC to verify that the second PTK has been correctly generated by the second AMP STA. Subsequently, the first AMP STA transmits the third frame that carries the confirmations for both the second PMK generation and the second PTK generation. The third frame also further includes the first MIC that can be used by the second AMP STA to verify that the first PTK has been correctly generated by the first AMP STA.

[0142] Upon receiving the second frame, the second AMP STA also uses the first MIC to verify that the first PTK has been correctly generated by the first AMP STA. Subsequently, the second AMP STA transmits another frame (not illustrated in FIG. 2) that carries the confirmations for both the first PMK generation and the first PTK generation.

[0143] At the end of this 3-way message exchange, both STAs would have generated and confirmed not only the first PMK and the first PTK, but also the second PMK and the second PTK. The first PMK and the first PMK’s identifier (e.g., a first PMKID) , and the second PMK and the second PMK’s identifier (e.g., a fourth PMKID) are stored in the first AMP STA’s non-volatile memories, and the first PMK and the first PMK’s another identifier (e.g., a second PMKID) , and the second PMK and the second PMK’s another identifier (e.g., a third PMKID) are stored in the second AMP STA’s non-volatile memories, which may be used in future PTK generations. It will be noted that the first PMK and the second PMK are not directly used to protect the AMP frames, which ensure the confidentiality of the first PMK and the second PMK, since it is unrealistic to generate a PMK (e.g. from a PTK from the PMK) in reverse even if the PTK is stolen by an attacker.

[0144] It will be noted that the third frame may be an AMP request frame or an AMP Authentication confirmation frame, which is not limited by embodiments of the present disclosure.

[0145] In some embodiments, the third frame may be an AMP request frame carrying partial content of an AMP Authentication confirmation frame.

[0146] In this case, it is possible to realize the transmission of a first signaling and a second signaling together in a way that an AMP frame (e.g., an AMP request frame) is reused to carry partial content of another signaling frame (e.g., an  AMP Authentication confirmation frame) , without separately transmitting the signaling in additional frames, thereby reducing the number of signaling interactions and thus improving key generation efficiency.

[0147] The first PTK and the second PTK are then used to protect (either encrypt or authenticate) the subsequent protected communication between the two STAs as illustrated by the first protected frame and the second protected frame in the middle of FIG. 2. Each protected AMP frame carries a unique packet number (PN) that is used to construct the Nonce used in the protection procedure as will be described later. The number of times that the first PTK and the second PTK can be used to protect the AMP frame is limited by the maximum value of PN which is constrained by the length of PN used in the Nonce, e.g., 4096 times for a 12-bit PN.

[0148] In some implementations, as illustrated in FIG. 2, the method further includes step S24.

[0149] In step S24, the first AMP STA transmits a first protected frame, where a first frame body field in the first protected frame is encrypted by the first PTK. Accordingly, the second AMP STA receives the first protected frame. Upon receiving the first protected frame, the second AMP STA may decrypt the first frame body field in the first protected frame, so as to obtain the content carried in the first frame body field.

[0150] In some implementations, the first protected frame further includes a first frame check sequence (FCS) field for carrying a MIC generated from the first PTK.

[0151] In this case, given that the frame body field of the first protected frame is encrypted by the first PTK, it may be considered to carry the MIC generated from the first PTK in an unencrypted field (e.g., an FCS field) of the first protected frame rather than in the encrypted field (e.g., the frame body field) of the first protected frame. In this way, the second AMP STA can obtain the MIC generated from the first PTK without decryption, which may simplify the operation and effectively improve the speed of verifying the correctness of the second PTK, thereby improving the key verification efficiency. The verification of the second PTK is also used as the implicit verification of the second PMK.

[0152] In some implementations, as illustrated in FIG. 2, the method further includes step S25.

[0153] In step S25, the second AMP STA transmits a second protected frame, where the second frame body field in the second protected frame is encrypted by the second PTK. Accordingly, the first AMP STA receives the second protected. Upon receiving the second protected frame, the first AMP STA may decrypt the second frame body field in the second protected frame, so as to obtain the content carried in the second frame body field.

[0154] In some embodiments, the second protected frame further includes a second frame check sequence (FCS) field for carrying a MIC generated from the second PTK.

[0155] In this case, the MIC generated from the second PTK for verifying correctness of the first PTK may also be carried in an unencrypted FCS field of the second protected frame rather than in the encrypted frame body field, so that the first AMP STA can obtain the MIC generated from the second PTK without decryption, which may simplify the operations and effectively improve the speed of verifying the correctness of the first PTK, thereby improving the key verification efficiency.

[0156] When one or both of the first PTK and the second PTK are lost (e.g., due to the second AMP STA losing power) or when the counter in the Nonce reaches its maximum value, new PTKs are negotiated (using the stored PMK and PMKID) , as illustrated in the last 6 message exchanges (using fourth frame to ninth frame) at the bottom of FIG. 2. Either one of the AMP STAs can initiate this procedure by transmitting a request frame. Referring to FIG. 2, a procedure initiated by the first AMP STA is illustrated in steps S26 to S28, and another procedure initiated by the second AMP STA is illustrated in steps S29 to S31.

[0157] In some implementations, as illustrated in FIG. 2, the method further includes steps S26 to S28.

[0158] In step S26, the first AMP STA transmits a fourth frame carrying a first PMK identifier (denoted as PMKID1 in FIG. 2) and a third random number, wherein the first PMKID is used to retrieve the second PMK based on a second PMKID stored in a non-volatile memory of a second AMP STA. Accordingly, the second AMP STA receives the fourth  frame.

[0159] In step S27, the second AMP STA transmits a fifth frame carrying a fourth random number, where the third random number and the fourth random number are used to generate a third PTK based on the first PMK. Accordingly, the first AMP STA receives the fifth frame.

[0160] In step S28, the first AMP STA transmits a sixth frame carrying the confirmations for the fourth PTK generation. Accordingly, the second AMP STA receives the sixth frame.

[0161] In this scenario, when the first AMP STA is informed that the second AMP STA has lost the previous PTK (e.g., the second PTK mentioned above) due to power outage, etc., or that the previous PTK has reached its lifespan, the first AMP STA may initiate a procedure for retrieving the first PMK and generating a new PTK, e, g., the third PTK, so as to restore the communication as soon as possible, thereby improving the user experience.

[0162] As illustrated in FIG. 2, the fourth frame transmitted by the first AMP STA is used to carry the first PMKID of the first PMK and the third random number (e.g., ANonce) . Upon receiving the fourth frame, the second AMP STA first retrieves the first PMK from the first PMKID. Then the second AMP STA also generates the fourth random number (e.g., SNonce) and together with the received third random number proceeds to derive the third PTK from the first PMK. Subsequently, the second AMP STA transmits the fifth frame carrying the fourth random number to the first AMP STA. The fifth frame also includes the third MIC (denoted as MIC3 in FIG. 2) that can be used by the first AMP STA to verify that the third PTK has been correctly generated by the second AMP STA.

[0163] Upon receiving the fifth frame, the first AMP STA uses the third random number and the fourth random number to generate the third PTK from the stored first PMK. The first AMP STA also uses the third MIC to verify that the third PTK has been correctly generated by the second AMP STA. Subsequently, the first AMP STA transmits the sixth frame that carries the confirmations for the third PTK generation.

[0164] In some implementations, as illustrated in FIG. 2, the sixth frame also carries a third MIC, where the third MIC is used to verify correctness of a fourth PTK of the second AMP STA. The third MIC is generated from the third PTK.

[0165] Upon receiving the sixth frame, the second AMP STA uses the third MIC to verify that the third PTK has been correctly generated by the first AMP STA. Subsequently, the second AMP STA transmits another frame (not illustrated in FIG. 2) that carries the confirmations for the third PTK generation.

[0166] In this case, the second AMP STA may verify the fourth PTK generated by the second AMP STA using the third MIC generated by the first AMP STA, which may realize cross-verification of the correctness of the fourth PTK, thereby improving the key generation reliability and communication reliability.

[0167] It will be noted that the sixth frame may be an AMP request frame or an AMP key generation (KeyGen) confirmation frame, which is not limited by embodiments of the present disclosure.

[0168] In some implementations, the sixth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0169] In this case, it is also possible to reuse the AMP request frame to carry partial content of the AMP KeyGen confirmation frame, so as to realize the transmission of a first signaling and a second signaling together to reduce the number of signaling interactions, thereby improving the key generation efficiency and communication efficiency.

[0170] In some implementations, the method further includes steps S29 to S31.

[0171] In step S29, the second AMP STA transmits a seventh frame carrying a second PMK identifier (PMKID2) and a fifth random number, wherein the second PMKID is used to retrieve the first PMK based on a first PMKID stored in a non-volatile memory. Accordingly, the first AMP STA receives the seventh frame.

[0172] In step S30, the first AMP STA transmits an eighth frame carrying a sixth random number, wherein the fifth random number and the sixth random number are used to generate a fourth PTK based on the second PMK. Accordingly,  the second AMP STA receives the eighth frame.

[0173] In step S31, the second AMP STA transmits a ninth frame carrying the confirmations for the third PTK generation. Accordingly, the first AMP STA receives the ninth frame.

[0174] In this scenario, when a resource (e.g., energy) constrained STA, for example the second AMP STA, is informed that the previous PTK has reached its lifespan, the second AMP STA may initiate another procedure for retrieving the second PMK and generating a new PTK (e.g., a fourth PTK) , so as to restore the communication as soon as possible, thereby improving the user experience.

[0175] As illustrated in FIG. 2, the seventh frame transmitted by the second AMP STA is used to carry the third PMKID of the second PMK and the fifth random number (e.g., SNonce) . Upon receiving the seventh frame, the first AMP STA generates the sixth random number (e.g., ANonce) and together with the received fifth random number proceeds to derive the third PTK from the stored second PMK. Subsequently, the first AMP STA transmits the eighth frame carrying the sixth random number to the second AMP STA. The eighth frame also includes the fourth MIC (denoted as MIC4 in FIG. 2) that can be used by the second AMP STA to verify that the fourth PTK has been correctly generated by the first AMP STA.

[0176] Upon receiving the eighth frame, the second AMP STA uses the fifth random number and the sixth random number to generate the fourth PTK from the stored second PMK. The second AMP STA also uses the fourth MIC to verify that the fourth PTK has been correctly generated by the first AMP STA. Subsequently, the second AMP STA transmits the ninth frame that carries the confirmations for the fourth PTK generation.

[0177] In some implementations, the ninth frame also carries the fourth MIC, and the fourth MIC is used to verify correctness of the third PTK of the first AMP STA. The fourth MIC is generated from the fourth PTK.

[0178] Upon receiving the ninth frame, the first AMP STA uses the fourth MIC to verify that the fourth PTK has been correctly generated by the second AMP STA. Subsequently, the first AMP STA transmits another frame (not illustrated in FIG. 2) that carries the confirmations for the fourth PTK generation.

[0179] In this case, the first AMP STA to verify the third PTK generated by the first AMP STA using the fourth MIC generated by the second AMP STA, which may realize cross-verification of the correctness of the newly generated third PTK, thereby improving the key generation reliability and communication reliability.

[0180] Since the generation of the new PTK (from the stored PMK) is a much simpler procedure compared to the generation of the initial PMK using SAE, the AMP STA’s computation burden is significantly reduced. On the contrary, if the PMK (and PMKID) were not stored and a new PMK has to be generated every time, a new communication is initiated between two AMP STAs, due to the complexity of the PMK generation procedure, the AMP STAs would be required to invest much energy and resources in this task.

[0181] It will be noted that the ninth frame may be an AMP request frame or an AMP key generation (KeyGen) confirmation frame, which is not limited by embodiments of the present disclosure.

[0182] In some implementations, the ninth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0183] In this case, it is also possible to reuse the AMP request frame to carry partial content of the AMP KeyGen confirmation frame, so as to realize the transmission of a first signaling and a second signaling together to reduce the number of signaling interactions, thereby improving the key generation efficiency and communication efficiency.

[0184] The technical solutions provided in the present disclosure are illustrated below in combination with several examples.

[0185] FIG. 3 illustrates a detailed example of the combined PMK and PTK generation procedure shown in FIG. 2. In an initial phase, the first AMP STA may not be even aware of the existence of the second AMP STA and may need to first determine the presence and identity of the second AMP STA within its radio coverage. This may be achieved by the first AMP STA initiating a random access session allowing any second AMP STA within its coverage to respond and  communicate its identifier (ID) . This is represented by the first two message exchanges (e.g., ID Request and ID Response) in FIG. 3, the ID request initiating the random access session and the second AMP STA responding with its ID. However, if the first AMP STA is already aware of the ID of the second AMP STA, this step can be omitted. Once the ID of the second AMP STA is known, the first AMP STA can perform further message exchanges to gather basic capabilities of the second AMP STA (not illustrated in FIG. 3) , or the first AMP STA can also gather such information on its own (e.g., by accessing a server that stores such information, etc. ) .

[0186] If the first AMP STA ascertains that the second AMP STA has the capability to support protected communication and the type of key generation method it supports (e.g., SAE or PSK, etc. ) , the first AMP STA proceeds to generate the first PMK materials required for the first PMK and the second PMK and additionally the first random number (denoted as ANonce in FIG. 3) required for generating the first PTK and the second PTK. If protected communication is supported, it is assumed that both AMP STAs are already pre-programmed with a common secret (e.g., with the same pre-shared password) . Assuming SAE is used for generating the first PMK (denoted as PMK1 in FIG. 3) and the second PMK (denoted as PMK2 in FIG. 3) , the first AMP STA uses the common secret to generate the first random scalar (denoted as scal1 in FIG. 3) , the first password element (denoted as elem1 in FIG. 3) to be used in its SAE-Commit message of the SAE protocol as well as the first random number (e.g., ANonce) required for generating the first PTK and the second PTK. The first AMP STA then transmits an AMP Authentication Request frame (an AMP Authentication frame with the Sub-Type field set as Request) carrying the first random scalar (scal1) , the first password element (elem1) and other parameters to be used in the SAE-Commit message as well as the first random number required for generating the first PTK and the second PTK. The AMP Authentication Request frame is a specific implementation example of the first frame in FIG. 2.

[0187] Upon receiving the AMP Authentication Request frame, the second AMP STA uses the common secret to generate the second random scalar (denoted as scal2 in FIG. 3) , the second password element (denoted as elem2 in FIG. 3) to be used in its SAE-Commit message of the SAE protocol as well as the second random number (denoted as SNonce in FIG. 3) required for generating the first PTK and the second PTK. It then proceeds to use the scal1, elem1, scal2 and elem2 to generate the second PMK using the SAE protocol. The second PMK’s identifier (denoted as PMKID2 in FIG. 3) may also be generated during the second PMK generation process for the second PMK may also be implicitly generated during the second PMK generation process, e.g., as PMKID = Truncate-128 (HMAC-SHA-256 (PMK, "AMP PMK" || First AMP STA ID || Second AMP STA ID) ) . HMAC-SHA-256 refers to a SHA-256 based hash function that generates a 256-bits long number. The second AMP STA also uses the second PMK, ANonce and SNonce to generate the second PTK. The second AMP STA then constructs an AMP Authentication Response frame (an AMP Authentication frame with the Sub-Type field set as Response) carrying the second random scalar (scal2) , the second password element (elem2) and other parameters to be used in the SAE-Commit message as well as the SNonce. The AMP Authentication Response frame is an implementation example of the second frame in FIG. 2. In addition, the second AMP STA also uses the second PTK to generate the second message integrity code (denoted as MIC2 in FIG. 3) , for example, by running the CCMP Authentication procedure over the frame body of the AMP Authentication Response frame, as will be described later, and appends the second MIC to the end of the frame body of the AMP Authentication Response frame (Sub-Type = Response) . The second AMP STA then proceeds to transmit the AMP Authentication Response frame to the first AMP STA.

[0188] Upon receiving the AMP Authentication Response frame, the first AMP STA has all the materials required to generate the first PMK. The first AMP STA then proceeds to use the scal1, elem1, scal2 and elem2 to generate the first PMK using the SAE protocol. The first PMK’s identifier (PMKID) , e.g., the first PMKID (PMKID1 for short) may also be generated during the PMK generation process, or the first PMKID may also be implicitly generated as explained earlier. The first AMP STA uses the first PMK, ANonce and SNonce to generate the first PTK. In addition, the first AMP STA also uses the first PTK to generate the MIC0 in FIG. 3 based the first PTK to verify the second MIC in the AMP authentication response frame, for example, by running the CCMP Authentication procedure over the frame body of the  AMP Authentication Response frame received from the second AMP STA except the MIC field, e.g., the MIC field of the AMP Authentication Response frame is not included as part of the frame body for the CCMP Authentication procedure. If the MIC0 is the same as the second MIC carried in the AMP Authentication frame, the first PTK are verified to be genuine and hence the first PMK is also implicitly verified to be genuine. Then the first AMP STA proceeds to store the first PMK (and its PMKID (e.g., the first PMKID) , if generated) in its non-volatile memory. If the second MIC verification fails, the key generation is aborted and an error code may be transmitted to the second AMP STA in the next message. Since the second MIC is generated using the second PTK, and the second PTK is derived from the second PMK, if the second MIC verification passes, it proves that the generation of both the second PMK and the second PTK are successful. At this phase, both AMP STAs possess a PMK and a PTK.

[0189] Either a dedicated third message is used to confirm the first PMK and the first PTK to the second AMP STA, or if the first AMP STA intends to communicate with the second AMP STA immediately, the confirmation may be piggybacked in the first AMP STA’s protected message to the second AMP STA.

[0190] If a dedicated third message is used to confirm the first PMK and the first PTK, the first AMP STA transmits an AMP Authentication Confirm frame (an AMP Authentication frame with the Sub-Type field set to Confirm) carrying SAE-Confirm materials as well as a first MIC (denoted as MIC1 in FIG. 3) to confirm the first PMK and the first PTK. The AMP Authentication Confirm frame is an implementation example of the third frame in FIG. 2. Upon receiving the AMP Authentication Confirm frame, the second AMP STA uses the SAE-Confirm materials to verify the first PMK generation while the first MIC is used to verify that the first PTK generated by the first AMP STA matches the second PTK generated by the second AMP STA. Upon verifying the first MIC successfully, the second AMP STA also stores the second PMK (and its ID, e.g., the second PMKID, if generated) in its non-volatile memory.

[0191] Instead, if the first AMP STA intends to communicate with the second AMP STA immediately after the generation of the security keys, it can piggyback the AMP Authentication Confirm frame (Sub-Type = Confirm) in another AMP frame, e.g., in the AMP Request frame whose original intention may be to request information, such as energy level from the second AMP STA. The AMP Request frame carrying the AMP Authentication Confirm frame is another implementation example of the third frame in FIG. 2. The AMP Request frame is protected (either authenticated or encrypted) using the first PTK. The reception and verification of the MIC1’ carried in the AMP Request frame not only verifies the AMP Request frame but also verifies that the first PTK generated by the first AMP STA matches the second PTK generated by the second AMP STA. Upon verifying the MIC1’s uccessfully, the second AMP STA also stores the second PMK (and the second PMK’s ID, e.g., the second PMKID, if generated) in its non-volatile memory. The second AMP STA proceeds to perform the request made by the AMP Request frame if required and transmits an AMP Response frame protected using the second PTK to the first AMP STA. The AMP Response frame also carries the MIC2’ generated using the second PTK in its FCS field. If the first STA correctly receives the protected AMP Response frame (by verifying MIC2’ ) , it also verifies to the first STA that the second PTK generated by the second STA is genuine. Hence it can be seen that by combining the PMK and PTK generation materials in the same frame exchange, the generation of both PMK and PTK can be completed at the same time, thereby reducing the message exchanges to just 3 frame exchanges. At the same time, the integrity of the PMK is protected since it is not directly used to protect any frames.

[0192] FIG. 4 illustrates a procedure to derive a PTK from a PMK, e.g., deriving the first PTK from the first PMK, or deriving the second PTK from the second PMK. It is assumed that the AMP STAs can generate the PMK using standard procedure (for example, using the SAE protocol as described in the IEEE 802.11 specification) . The PTK generation procedure is also based on the procedure described in the IEEE 802.11 specification with some minor modifications. ID1 and ID2 are identifiers (e.g., MAC address or other form of ID) of initiating and responding devices respectively. PRF is a pseudo random function (e.g., SHA family of hash algorithms) that hashes various inputs to derive a pseudorandom value. Length may be 256, 384 or 512 bits and indicates the size of the PTK. For example, if Length = 256 bits, the PTK may be generated from the PMK as:

[0193] PTK = SHA-256 (PMK, "AMP Pairwise Key expansion" , Min (ID1, ID2) || Max (ID1, ID2) || Min (ANonce, SNonce) || Max (ANonce, SNonce) ) .

[0194] The PTK is further partitioned as the Key Confirmation Key (KCK) and the Temporal Key (TK) . PTK-KCK shall be computed as the first KCK_bits bits (bits 0 to KCK_bits -1) of the PTK and is used to confirm or encrypt the security keys:

[0195] KCK= ExtractBits (PTK, 0, KCK_bits) .

[0196] The next TK_bits bits of the PTK are used as the Temporal Key (TK) use to protect unicast AMP frames. For example, KCK_bits and TK_bits may be 128 or 256, where

[0197] TK= ExtractBits (PTK, KCK_bits, TK_bits) .

[0198] In some embodiments, the first random scalar, the second random scalar and the first PMK are used to generate the first PTK and the second PTK.

[0199] In this case, it is possible to reuse the first random scalar in the first PMK materials, and the second random scalar in the second PMK materials, in combination with the newly generated first PMK to generate the first PTK, or in combination with the newly generated second PMK, to generatehe second PTK without transmitting the dedicated parameters for generating the first PTK and the second PTK, thereby saving signaling overhead and key generation time, and improving the key generation efficiency and communication efficiency.

[0200] As illustrated in FIG. 5, instead of generating and communicating a separate set of random numbers including the first random number and the second random number (e.g., ANonce, SNonce in FIG. 3) for the PTK generation, the random scalars including the first random scalar and the second scalar that are generated for the SAE-commit messages (e.g., the two random scalars used for SAE: scal1, scal2) may also be used for the PTK generation. Since the two random scalars are already communicated as part of the SAE messages, no additional Nonces need to be exchanged, thereby saving signaling overhead and key generation time, and improving key generation efficiency and communication efficiency.

[0201] Accordingly, as shown in FIG. 6, the PTK is generated from the PMK, e.g., the first PTK is genereated from the first PMK. For example, when Length = 256 bits, the PTK may be generated from the PMK as:

[0202] PTK = SHA-256 (PMK, "AMP Pairwise Key expansion" , Min (ID1, ID2) || Max (ID1, ID2) || Min (scal1, scal2) ||Max(scal1, scal2) ) . If the bit-length of scal1 and scal2 do not match the required bit-length (e.g., 256-bits) for the random number for PTK generation, prior to using the scalers for the PTK generation, the scalers need to be appropriately converted to the suitable length e.g. by truncating (if the scalers are larger than 256 bits) , or by zero padding (if the scalers are smaller than 256 bits) .

[0203] If there is a need, the first AMP STA may also generate a Group Temporal Key (GTK) for the purpose of protecting group addressed AMP frames. For AMP, GTK may be a 128 bits or 256 bits random number generated by the first AMP STA (either from the PMK or in an implementation specific manner) and communicated to one or more second AMP STAs in AMP KeyGen Transfer frames (an AMP KeyGen frames with the Sub-Type field set as Key Transfer) encrypted with the PTK-KCK as illustrated in FIG. 7, with the encryption being perform over the content of the frame body carrying the GTK, KeyID (identifier for the GTK) and the KeyReplayCounter (asequence number used to detect replayed AMP KeyGen frames) . When used to carry the GTK, the MIC is carried in the FCS field of the AMP KeyGen frame as will be described later. Upon receiving the AMP KeyGen Transfer frame, the second AMP STA decrypts the frame and verifies that the MIC is correct, in which case it stores the GTK and transmits an AMP KeyGen Confirm frame (Sub-Type = Confirm) to confirm the receipt of the GTK. Else if the MIC verification fails, the GTK is discarded. Although not shown in the figure, the first AMP STA also stores the GTK in its memory but the timing may not be tied to the message exchanges shown here since the GTK may be used for broadcast / multicast transmission to more than one AMP STAs.

[0204] The lifespan of a PTK depends on two aspects: 1) the duration that two peer AMP devices can retain the PTK in memory, 2) the maximum value that the counter used in the Nonce that is used to protect an AMP frame using the corresponding PTK (explained later) . If either of the AMP devices loses power and hence loses the generated PTK, or when the counter in the Nonce tied to the existing PTK reaches a maximum value, either of the AMP STAs can initiate the generation of a new PTK from the stored PMK.

[0205] An example of a new PTK generation initiated by the first AMP STA is illustrated in FIG. 8. Upon deciding that a new PTK is needed, the first AMP STA transmits the fourth frame (e.g., an AMP KeyGen Request frame (Sub-Type =Request) illustrated in FIG. 8) carrying the first PMKID (identifier of the first PMK, denoted as PMKID1 in FIG. 8) , KeyReplayCounter (asequence number used to detect replayed AMP KeyGen frames) and the third random number (e.g., ANonce illustrated in FIG. 8) . If the first PMKID can be implicitly generated (as explained earlier) , it is omitted in the AMP KeyGen Request frame. It should also be ensured that the KeyReplayCounter and ANonce has not been used in the past.

[0206] Upon receiving the AMP KeyGen Request frame, the second AMP STA first checks whether the first PMKID is valid (i.e., it matches the second PMKID stored by the second AMP STA in non-valotile memory) , and if so, the second AMP STA derives the fourth random number (e.g. SNonce illustrated in FIG. 8) and retrieves the stored second PMK (denoted as PMK2 in FIG. 8) corresponding to the first PMKID. The second AMP STA uses the second PMK, ANonce and SNonce to generate a PTK23.

[0207] The second AMP STA then constructs the fifth frame (e.g., an AMP KeyGen Response frame (Sub-Type =Response) ) carrying the same KeyReplayCounter as well as the SNonce. In addition, the second AMP STA also uses the PTK23 to generate a MIC23, for example by running the CCMP Authentication procedure over the frame body of the AMP KeyGen Response frame, and appends the MIC23 to the end of the frame body of the AMP KeyGen Response frame and transmits the frame.

[0208] Upon receiving the AMP KeyGen Response frame, the first AMP STA also uses the corresponding stored first PMK, ANonce and SNonce to generate a PTK13. In addition, the first AMP STA also uses the PTK13 to generate a MIC013, for example by running the CCMP Authentication procedure over the frame body of the AMP KeyGen Response frame received from the second AMP STA except the MIC field, i.e., the MIC field of the AMP KeyGen Response frame is not included as part of the frame body for the CCMP Authentication procedure. If the generated MIC013 of the first AMP STA is the same as the MIC23 carried in the AMP KeyGen Response frame, the PTK13 generation of the first AMP STA is verified to be successful and the PTK13 is stored in memory.

[0209] Either a dedicated message is used to confirm the PTK13 to the second AMP STA, or if the first AMP STA intends to immediately communicate with the second AMP STA, the confirmation may be piggybacked in the first AMP STA’s protected message to the second AMP STA. When a dedicated message (e.g., an AMP KeyGen Confirm frame (an AMP KeyGen frame with the Sub-Type field set as Confirm) as illustrated in FIG. 8) is used to confirm the PTK13 of the first AMP STA, the first AMP STA transmits the AMP KeyGen Confirm frame (an example of the sixth frame in FIG. 2) carrying the KeyReplayCounter as well as the MIC13 of the first AMP STA to confirm the PTK23 of the second AMP STA. Upon receiving the AMP KeyGen Confirm frame, the second AMP STA uses the received MIC13 to verify that the PTK23 generated by the second AMP STA matches the PTK13 generated by the first AMP STA. Upon successful verification of the MIC13 of the first AMP STA, the second AMP STA also stores the PTK23 in memory.

[0210] Instead, if the first AMP STA intends to immediately communicate with the second AMP STA after the generation of the security keys, it can piggyback the AMP KeyGen Confirm frame (Sub-Type = Confirm) in another AMP frame, e.g., in the AMP Request frame (another example of the sixth frame in FIG. 2) whose original intention may be to request information, such as payload size from the second AMP STA. The AMP Request frame is protected (either authenticated or encrypted) using the PTK13 of the first AMP STA. The reception and the verification of the MIC13 carried in the AMP Request frame not only verifies the AMP Request frame but also verifies that the PTK13 generated by  the first AMP STA matches the PTK23 generated by the second AMP STA. Upon successful verification of the MIC13, the second AMP STA also stores the PTK23 in its memory. The second AMP STA proceeds to perform the request made by the AMP Request frame and if required transmits the AMP Response frame protected using the PTK23 to the first AMP STA. The AMP Response frame also carries the MIC23’ generated using the PTK23 in its FCS field. If the first STA correctly receives the protected AMP Response frame (by verifying MIC23’ ) , it also verifies to the first STA that the PTK23 generated by the second STA is genuine. Hence it can be seen that by combining the PMK and PTK generation materials in the same frame exchange, the generation of both PMK and PTK can be completed at the same time, thereby reducing the message exchanges to just 3 frame exchanges. At the same time, the integrity of the PMK is protected since it is not directly used to protect any frames.

[0211] Another example of new PTKs generation but this time initiated by the second AMP STA is illustrated in FIG. 9. In this example the second AMP STA’s PTK may have been lost due to a power outage event, but the first AMP STA may not be aware of this. The first AMP STA transmits an AMP Request frame (e.g., to solicit the second AMP STA’s EPC) encrypted with an earlier generated PTK (e.g., the second PTK mentioned above) .

[0212] Upon receiving the AMP Request frame, the second AMP STA fails to decrypt the frame due to lack of the earlier generated PTK. In this case, the second AMP STA can initiate the generation of a new PTK (e.g., the PTK14) by transmitting the seventh frame (e.g., an AMP KeyGen Request frame as shown in FIG. 9) carrying the second PMKID (denoted as PMKID2 in FIG. 9) , KeyReplayCounter (asequence number used to detect replayed AMP KeyGen frames) and the fifth random number (denoted as SNonce in FIG. 9) to the first AMP STA. If the PMKID2 can be implicitly generated (as explained earlier) , it is omitted in the frame. It should also be ensured that the KeyReplayCounter and SNonce has not been used in the past.

[0213] Upon receiving the AMP KeyGen Request frame, the first AMP STA first checks whether the PMKID2 is valid (i.e., it matches the PMKID1 stored in the first AMP STA’s memory) , and if so, the first AMP STA derives the sixth random number (denoted as ANonce in FIG. 9) and retrieves the stored PMK1 corresponding to the first PMKID. The first AMP STA uses the PMK1, ANonce and SNonce to generate the PTK14, and subsequently, generate the MIC14. The first AMP STA then constructs the eighth frame (e.g., an AMP KeyGen Response frame (Sub-Type = Response) ) carrying the same KeyReplayCounter as well as the ANonce. In addition, the first AMP STA also uses the PTK14 to generate MIC14, for example by running the CCMP Authentication procedure over the frame body of the AMP KeyGen Response frame, and appends the MIC14 to the end of the frame body of the AMP KeyGen Response frame and transmits the AMP KeyGen Response frame.

[0214] Upon receiving the AMP KeyGen Response frame, the second AMP STA also uses the corresponding stored PMK2, ANonce and SNonce to generate the PTK24. In addition, the second AMP STA also uses the PTK24 to generate the MIC24, for example by running the CCMP Authentication procedure over the frame body of the AMP KeyGen Response frame received from the first AMP STA except the MIC field, i.e., the MIC field of the AMP KeyGen Response frame is not included as part of the frame body for the CCMP Authentication procedure. If the generated MIC24 of the second AMP STA is the same as the MIC14 carried in the AMP KeyGen Response frame, the PTK24 generation of the second AMP STA is verified to be successful and the PTK24 is stored in memory. The second AMP STA then transmits the ninth frame (e.g., an AMP KeyGen confirm frame (Sub-Type = Confirm) as illustrated in FIG. 9) carrying the KeyReplayCounter as well as the MIC24’ to confirm the PTK14 of the first AMP STA.

[0215] Upon receiving the AMP KeyGen Confirm frame, the first AMP STA uses the MIC24’ to verify that the PTK14 generated by the first AMP STA matches the PTK24 generated by the second AMP STA. Upon successful verification of the MIC24’ , the first AMP STA replaces the old PTK with the PTK14.

[0216] FIG. 10 illustrates the format of a protected AMP frame (e.g. the first protected frame and the second protected frame) . The general format of both protected and unprotected frames are the same as shown in the top of FIG. 10 and includes a MAC Header field, a Frame Body field and an FCS field.

[0217] The MAC Header field of the protected frame (e.g. the first protected frame and the second protected frame mentioned above) is the same as that of the unprotected frame except that the Protected field of the Frame Control field is always set as 1 in protected frames and the Protection Control field is present in the MAC header field. The Frame Type field specify the type of the AMP frame as shown in Table 1 below.

[0218] Table 1 -Frame Type field

[0219] Refering to FIG. 10, the Transmitter ID field is always present while the Receiver ID field is optionally present. The Length field when present indicates the size of the Frame Body field in octets. The Protection Control field carries information required for protection. The Encrypted field when 0 indicates that the frame is authenticated and when 1 indicates that the frame is encrypted. The Frame Body fields carries the payload of the frame and its format depends on the Frame Type field. When the Encrypted field is 1, the content of the Frame Body field is encrypted as described later. In unprotected AMP frames, the FCS field carries the cyclic redundancy check (CRC) , while in protected AMP frames the FCS field is used to carry the MIC (truncated 16 bits of the MIC output of the CCMP encryption procedure) .

[0220] The general format of the Frame Body field of the AMP Authentication frame and the format of the Type Dependent Payload fields for the AMP-SAE algorithm are illustrated in FIG. 11. The Frame Type field in the MAC Header is set as AMP Authentication and the Transmitter ID field, the Receiver ID field and the Length fields are present. The Transmitter ID and the Receiver ID fields carry the 12-bits identifier of the transmitting AMP STA and the receiving AMP STA respectively, while the Length field indicates the size of the Frame Body field. The Frame Body field is composed of the Sub-Type field, the Sub-Type Short Control field and a Type Dependent Payload field. This may be referred as a variant 2 frame body. The Sub-Type field specify the further classification of the frame sub types and is listed in Table 2.

[0221] Table 2 -AMP Authentication frame Sub-Type field

[0222] The Sub-Type Short Control field carries various presence bits indicating which optional fields are present in the Type Dependent Payload field. The first octet of the Type Dependent Payload field carries the Authentication algorithm field, the Authentication transaction sequence number field and the Status Code field. The format of the remainder of the Type Dependent Payload field may vary based on the Sub-Type field as well as the Authentication algorithm field.

[0223] The Authentication algorithm field specifies the algorithm used for Authentication and PMK generation and listed in Table 3.

[0224] Table 3 -Authentication algorithm field

[0225] When AMP-SAE is used as the Authentication algorithm for PMK generation, the Type Dependent Payload field carried in the AMP Authentication Request or Response frames is shown in the middle of FIG. 11, and the Type Dependent Payload field carried in the AMP Authentication Confirm frame is shown in the bottom of FIG. 11. The Authentication algorithm field is set as AMP-SAE. In Request and Response frames, the Authentication transaction sequence number field is set as 0 (Commit) In Confirm frames, the Authentication transaction sequence number field is set as 1 (Confirm) . The Status Code field carries the status related to the Authentication algorithm and is listed in Table 4.

[0226] Table 4 -Status Code field

[0227] In Request and Response frames, the Algo dependent Content field carries the parameters required for the SAE-Commit message while in Confirm frame, the field carries the parameters required for the SAE-Confirm message. The Nonce and the MIC fields are optionally present as needed. The Nonce field carries either the ANonce or the SNonce and the MIC field carries the MIC used to verify the PTK.

[0228] The general format of the Frame Body field of the AMP KeyGen frame and the format of the Type Dependent Payload fields for sub types are illustrated in FIG. 12. The Frame Type field in the MAC Header is set as AMP KeyGen and the Transmitter ID field, the Receiver ID field and the Length fields are present. The Transmitter ID and the Receiver ID fields carry the 12-bits identifier of the transmitting AMP STA and the receiving AMP STA respectively, while the Length field indicates the size of the Frame Body field. The Frame Body field is composed of the Sub-Type field, the Sub-Type Short Control field and a Type Dependent Payload field. The Sub-Type field specify the further classification of  the frame sub types and is listed in Table 5.

[0229] Table 5 -AMP KeyGen frame Sub-Type field

[0230] The Sub-Type Short Control field carries various presence bits indicating which optional fields are present in the Type Dependent Payload field. The four octets of the Type Dependent Payload field carry the Key Replay Counter field. The format of the remainder of the Type Dependent Payload field may vary based on the Sub-Type field.

[0231] In Request and Response frames, the PMKID, Nonce and the MIC fields are optionally present as needed. The PMKID field carries the PMIKD, the Nonce field carries either the ANonce or the SNonce and the MIC field carries the MIC used to verify the PTK. In KeyTransfer frame the GTK Info field is present and carries the GTK, the GTK-length field indicating the length of the GTK (Length of GTK = 2GTK-length) while the KeyID field carries the Key ID corresponding to the GTK. Since the Frame Body is encrypted, the MIC field is not present in the Frame Body but is carried in the FCS field. In Confirm frame, the GTK Info field is not present and the MIC field is carried in the Frame Body if the AMP KeyGen frame is not protected.

[0232] The general format of the Frame Body field of the AMP Request frame and the format of the Type Dependent Payload field are illustrated in FIG. 13. FIG. 13 also illustrates an example of another AMP frame being encapsulated in the AMP Request frame within the AMP Command field. The Frame Type field in the MAC Header is set as AMP Request and the Receiver ID field and the Length fields are optionally present when needed.

[0233] The Frame Body field of the AMP Request frame is composed of the Sub-Type field, the Sub-Type Long Control field and a Type Dependent Payload field. This may be referred as a variant 3 frame body. The Sub-Type field is set as 0, while the Sub-Type Long field carries the presence bits to indicate whether the Response Control field and the AMP Command field are present in the Type Dependent Payload field. The Response Control field carries the Response Type field which indicates the type of response that is solicited by the AMP Request frame. One or more AMP Command field may be present, each field encapsulating one AMP frame within the AMP Request frame. The AMP Command field is comprised of the Type field, the Length field and the AMP Command Data field. The Type field carries the Frame Type of the encapsulated AMP frame, and the Length field indicates the length of the frame body of the encapsulated frame while the entire frame body is carried within the AMP Command Data field. For example, FIG. 13 illustrates the AMP Request frame encapsulating the AP Authentication Confirm frame (Sub-Type = Confirm) when the AMP Request frame is used to carry the SAE-Confirm message and to confirm the PTK. When used to confirm the PTK, the AMP Request frame may be protected and the MIC carried in the FCS field is also used to confirm the correct generation of PTK.

[0234] The general format of the Frame Body field of the AMP Response frame and the format of the Type Dependent Payload field are illustrated in FIG. 14. The Frame Type field in the MAC Header is set as AMP Response and the Receiver ID field and the Length fields are optionally present when needed. The AMP Response frame is used to respond to the AMP Request frame and carries the information solicited by the AMP Request frame. Similar to the AMP Request frame, the AMP Response frame may also carry one or more AMP Command field, each field encapsulating one AMP frame within the AMP Response frame. If used to confirm the PTK, the AMP Response frame may be protected and the MIC carried in the FCS field is also used to confirm the correct generation of PTK.

[0235] The CCMP encapsulation procedure illustrated in FIG. 15 may be used to protect AMP frames. The important  fields of the MAC Header field are used to constructed the AAD used in the CCMP encapsulation and decapsulation procedure. The Nonce used for the CCMP encapsulation and decapsulation procedure is composed of the Transmitter ID carrying the ID of the transmitting AMP STA and a PN carrying a monotonically incrementing counter. The size of the PN field determines the lifespan of the PTK used in the encapsulation, e.g., a 12 bit PN restricts the PTK reuse to 4096 times. The CCMP encapsulation is primarily based on the IEEE 802.11 specification, except that it is also used for Authentication in which case the CCM encryption is used to generate the MIC but the original data (the frame body) is carried the AMP frame instead of the encrypted data.

[0236] The CCMP decapsulation procedure illustrate in FIG. 16 may be used to receive protected AMP frames. The CCMP decapsulation is primarily based on the IEEE 802.11 specification, except that for authenticated AMP frame, the CCM decryption is only used to verify the MIC (i.e., decrypted data is discarded) .

[0237] Alternatively, CCMP encryption may be used to verify the MIC carried in a received authenticated AMP frame, i.e., the received authenticated AMP frame is passed to the CCM encryption procedure to generate the encrypted MIC, which is compared with the MIC carried in the authenticated frame. If the two MICs match, the MIC field and the Protection Control field are removed to generate the plaintext AMP frame.

[0238] Another flow of interaction between various network elements / devices in the above-mentioned communication system will be specifically described below by means of method embodiments. Another method provided by the embodiments of the present disclosure may be applicable to the communication system and specifically applied to various scenarios mentioned in the communication system.

[0239] In general, the present disclosure provides a key generation method, and the method may be performed by a first AMP STA and a second AMP STA. In the present disclosure, the first AMP STA may be an AMP access point station (AMP AP STA) or a chip of the AMP AP STA. The AMP AP STA may be a Type A AMP STA. The second AMP STA may be an AMP non-access point (AMP non-AP STA) or a chip of the AMP non-AP STA. The AMP non-AP STA may be a Type B AMP STA or a Type C AMP STA.

[0240] FIG. 17 illustrates the conceptual overview of the entire security key generation procedure and the transmission of protected AMP frames using the generated keys.

[0241] Referring to FIG. 17, the method includes steps S41 and S42.

[0242] In step S41, the first AMP STA transmits a tenth frame carrying third pairwise master key (PMK) materials and a seventh random number. Accordingly, the second AMP STA receives the tenth frame.

[0243] In step S42, the second AMP STA transmits an eleventh frame carrying an eighth random number, where the third PMK materials are used to generate a third PMK (denoted as PMK3 in FIG. 17) and a fourth PMK (denoted as PMK4 in FIG. 17) , the seventh random number, the eighth random number and the third PMK are used to generate a fifth PTK (denoted as PTK5 in FIG. 17) , and the seventh random number, the eighth random number and the fourth PMK are used to generate a sixth PTK (denoted as PTK6 in FIG. 17) . Accordingly, the first AMP STA receives the eleventh frame.

[0244] Based on the above method, the transmission of the third PMK materials, the transmission of the seventh random number and the transmission of the eighth random number can be realized in the same interaction process, where the third PMK materials are used for generating the third PMK, and the seventh random number and the eighth random number are used for generating the fifth PTK. In other words, the third PMK and the fifth PTK may be generated together in the same process, instead of through two separate processes, and it is unnecessary to transmit dedicated parameters for generating the fifth PTK, thereby saving signaling overhead and key generation time, and improving key generation efficiency and communication efficiency.

[0245] In some embodiments, the third PMK materials include NumRepetition, PMK-length and Hash Control which are used for generating the third PMK based on a pre-shared key (PSK) .

[0246] In some embodiments, the method further includes step S43.

[0247] In step S43, the first AMP STA transmits a twelfth frame carrying a fifth MIC, wherein the fifth MIC is used to verify correctness of the sixth PTK of the second AMP STA, which in turn is used to verify the correctness of the fouth PMK. Accordingly, the second AMP STA receives the twelfth frame.

[0248] In this case, the second AMP STA to verify the correctness of the sixth PTK generated by the second AMP STA using the fifth MIC generated by the first AMP STA, so as to realize cross-verification of the correctness of the sixth PTK, thereby improving the reliability of key generation and communications.

[0249] It will be noted that the twelfth frame may be an AMP request frame or an AMP Authentication confirmation frame, which is not limited by embodiments of the present disclosure.

[0250] In some embodiments, the twelfth frame is an AMP request frame carrying partial content of an AMP Authentication confirmation frame.

[0251] In this case, it is possible to realize the transmission of a first signaling and a second signaling together in a way that an AMP frame (i.e., an AMP request frame) is reused to carry partial content of another signaling frame (i.e., an AMP Authentication confirmation frame) , without separately transmitting the signaling in additional frames, thereby reducing the number of signaling interactions and thus improving key generation efficiency.

[0252] In some embodiments, the eleventh frame further carries a sixth MIC (denoted as MIC6 in FIG. 17) , where the sixth MIC is used to verify correctness of the fifth PTK.

[0253] In this case, the first AMP STA may verify the fifth PTK generated by the second AMP STA using the sixth MIC generated by the second AMP STA, which may realize cross-verification of the correctness of the fifth PTK, thereby improving the key generation reliability and communication reliability.

[0254] Moreover, the second AMP STA may transmit verification parameters of the fifth PTK (i.e., the sixth MIC) and PTK generation parameters (e.g., the eighth random number) to the first AMP STA in the same frame (e.g., the eleventh frame) , thereby reducing the number of signaling interactions, and improving the key generation efficiency and verification efficiency.

[0255] As mentioned earlier, the traditional Authentication algorithm used in mainstream IEEE 802.11 such as SAE may be computationally too heavy for some classes of AMP STAs. For such resource constrained AMP STAs, simpler methods to generate a PMK may be preferred. For example, a pre-shared key (PSK) based PMK generation as described below may be used. A unique pre-shared key, for example a 256-bits key, is pre-programmed on each of the two peer AMP STAs that need to use protected communication. As an example of the method illustrated in FIG. 17, the PMK and PTK generation procedure illustrated in FIG. 18 is very similar to the procedure described for FIG. 3, except that the AMP Authentication Request frame's Authentication algorithm field specify AMP-PSK instead of AMP-SAE. In addition, in the AMP Authentication Request frame, the first AMP STA also communicates the third PMK materials required to generate a third PMK (PMK3) and a fourth PMK (PMK4) : NumRepetition, PMK-length, Hash Control, as well as the seventh random number (e.g., ANonce illustrated in FIG. 18) used to generated a fifth PTK (PTK5) and a sixth PTK (PTK6) .

[0256] Upon receiving the AMP Authentication Request frame, using a suitable Password-Based Key Derivation Function (PBKDF) , the string "Hash-string || transmitter's ID || receiver's ID" are hashed 2NumRepetition times using the PSK, to produce a PMK-length bits Pairwise Master Key (PMK) . The hash function to be used for the PMKDF and the Hash-string is specified in the AMP Authentication Request frame. Subsequently, the second AMP STA generates the eighth random number (e.g., SNonce illustrated in FIG. 18) required for the fifth PTK's generation and the sixth PTK's generation. The second AMP STA then proceeds to use the third PMK materials to generate the PMK4 using the PSK protocol. Then PMKIDs, e.g., a PMKID4 corresponding to the PMK4, may be implicitly generated when PSK is used, e.g., as PMKID = Truncate-128 (HMAC-SHA-256 (PMK, "AMP PSK PMK" || transmitter's ID || receiver's ID) . The rest of the procedure is the same as described for FIG. 3 except that if a dedicated AMP Authentication Confirm frame (Sub-Type =Confirm) is transmitted to confirm the fifth PTK, and the MIC5’ carried in the frame body is generated over the string  "Hash-string || transmitter's ID || receiver's ID" .

[0257] The third PMK and the fourth PMK are generated using the PSK, the fifth PTK from the third PMK, or the sixth PTK from the fourth PMK as shown in FIG. 19. For example, if SHA-256 is specified as the hash function to be used for the PBKDF, and PMK-length = 256,

[0258] PMK = 2NumRepetition times (SHA-256 (PSK, Hash-string || transmitter's ID || receiver's ID) ) .

[0259] The format of the Type Dependent Payload fields of the AMP Authentication frame for the AMP-PSK algorithm is illustrated in FIG. 20. The general format of the Frame Body field of the AMP Authentication frame as well as the format of the Sub-Type Short Control field is the same as that illustrated in FIG. 11. The first octet of the Type Dependent Payload field carries the Authentication algorithm field, the Authentication transaction sequence number field and the Status Code field. The format of the remainder of the Type Dependent Payload field may vary based on the Sub-Type field as well as the Authentication algorithm field.

[0260] When AMP-PSK is used as the Authentication algorithm for PMK generation, the Type Dependent Payload field carried in the AMP Authentication Request or Response frames is shown in the top of FIG. 20, and the Type Dependent Payload field carried in the AMP Authentication Confirm frame is shown in the bottom of FIG. 20. The Authentication algorithm field is set as AMP-PSK, the Authentication transaction sequence number field is reserved and the Status Code field carries the status related to the Authentication algorithm as listed in Table 4.

[0261] In Authentication Request and Response frames, the Algo dependent Content field carries the parameters required for the PMK generation using PSK. The NumRepetition field indicates the number of repetitions (= 2NumRepetition) for the PBKDF hashing, PMK-length specify the length of the PMK (e.g., length of PMK = 2PMK-length) while the Hash Control field specify the hash function type (see Table-6 ) , and the Hash-string to be used in the PBKDF (length of Hash-string = 2Hash-string-length) . The Nonce and the MIC fields are optionally present as needed. The Nonce field carries either the ANonce or the SNonce, and the MIC field carries the MIC used to verify the PTK.

[0262] Table 6 –Hash Function Type field

[0263] In some extremely simple AMP STAs such as RFID tags, it is also possible that the intermediate PMK generation procedure is skipped altogether, and each time a new PTK is required, the new PTK is directly generated from the PSK. For example, if SHA-128 is chosen as the hash function:

[0264] PTK = 2NumRepetition times (SHA-128 (PSK, Hash-string || Min (ID1, ID2) || Max (ID1, ID2) || Min (ANonce, SNonce) || Max (ANonce, SNonce) )

[0265] Hash-string = "AMP Direct PSK PTK"

[0266] Here, ID1 = transmitter's ID, ID2 = receiver's ID

[0267] In this case, the AMP STAs do not need to store the PMK.

[0268] Referring to FIG. 17, after the third PMK, the fourth PMK, the fifth PTK, and the sixth PTK are generated, the third PMK, the fourth PMK, the fifth PTK, and the sixth PTK are also used for protected communications, updating PTKs, etc.

[0269] In some embodiments, the method further includes step S44.

[0270] In step S44, the first AMP STA transmits a third protected frame, where a third frame body field in the third protected frame is encrypted by the fifth PTK, and the third protected frame further includes a third frame check sequence (FCS) field for carrying a MIC generated from the fifth PTK. Accordingly, the second AMP STA receives the third protected frame.

[0271] In this case, given that the frame body field of the third protected frame is encrypted by the fifth PTK, it may be considered to carry the MIC generated from the fifth PTK in an unencrypted field (e.g., an FCS field) of the third protected frame rather than in the encrypted field (i.e., the frame body field) of the third protected frame. In this way, the second AMP STA can obtain the MIC generated from the fifth PTK without decryption, which may simplify the operation and effectively improve the speed of verifying the correctness of the sixth PTK, thereby improving the key verification efficiency. The verification of the sixth PTK is also used as the implicit verification of the fourth PMK.

[0272] In some embodiments, the method further includes step S45.

[0273] In step S45, the second AMP STA transmits a fourth protected frame, where a fourth frame body field in the fourth protected frame is encrypted by the sixth PTK, and the fourth protected frame further includes a fourth frame check sequence (FCS) field for carrying a MIC generated from the sixth PTK. Accordingly, the first AMP STA receives the fourth protected frame.

[0274] In this case, the MIC generated from the sixth PTK may also be carried in an unencrypted FCS field of the fourth protected frame rather than in the encrypted frame body field, so that the first AMP STA can obtain the MIC generated from the sixth PTK without decryption, which may simplify the operations and effectively improve the speed of verifying the correctness of the fifth PTK, thereby improving the key verification efficiency.

[0275] It will be noted that the implementation of the third protected frame may refer to the implementation of the first protected frame, and the implementation of the fourth protected frame may refer to the implementation of the second protected frame described above, which will not be repeated here.

[0276] In some embodiments, the method further includes steps S46 and S47.

[0277] In step S46, the first AMP STA transmits a thirteenth frame carrying a third PMK identifier (denoted as PMKID3 in FIG. 17) and a ninth random number, wherein the third PMKID is used to retrieve the fourth PMK based on a fourth PMKID stored in a non-volatile memory. Accordingly, the second AMP STA receives the fourteenth frame.

[0278] In step S47, the second AMP STA transmits a fourteenth frame carrying a tenth random number, where the tenth random number and the third PMK are used to generate a seventh PTK (denoted as PTK7 in FIG. 17) . Accordingly, the first AMP STA receives the fourteenth frame.

[0279] In this scenario, when the first AMP STA is informed that the second AMP STA has lost the previous PTK (e.g., the sixth PTK mentioned above) due to power outage, etc., or the previous PTK has reached its lifespan, the first AMP STA may initiate a procedure for retrieving the third PMK and generating a new PTK (e.g. the seventh PTK) so as to restore the communication as soon as possible, thereby improving the user experience.

[0280] In some embodiments, the method further includes step S48.

[0281] In step S48, the first AMP STA transmits a fifteenth frame carrying a seventh MIC, where the seventh MIC is used to verify correctness of an eighth PTK of the second AMP STA. Accordingly, the second AMP STA receives the fifteenth frame.

[0282] In this case, the second AMP STA may verify the eighth PTK generated by the second AMP STA using the seventh MIC generated by the first AMP STA, which may realize cross-verification of the correctness of the eighth PTK, thereby improving the key generation reliability and communication reliability.

[0283] It will be noted that the fifteenth frame may be an AMP request frame or an AMP key generation (KeyGen)  confirmation frame, which is not limited by embodiments of the present disclosure.

[0284] In some embodiments, the fifteenth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0285] In this case, it is possible to realize the transmission of a first signaling and a second signaling together in a way that an AMP frame (i.e., an AMP request frame) is reused to carry partial content of another signaling frame (i.e., a KeyGen confirmation frame) , without separately transmitting the signaling in additional frames, thereby reducing the number of signaling interactions and thus improving key generation efficiency.

[0286] In some embodiments, the method further includes steps S49 and S50.

[0287] In step S49, the second AMP STA transmits a sixteenth frame carrying a fourth PMK identifier (denoted as PMKID4 in FIG. 17) and an eleventh random number, wherein the fourth PMKID is used to retrieve the third PMK based on an third PMKID stored in a non-volatile memory. Accordingly, the first AMP STA receives the sixteenth frame.

[0288] In step S50, the first AMP STA transmits a seventeenth frame carrying a twelfth random number, a seventeenth frame carrying a twelfth random number, wherein the eleventh random number and the twelfth random number are used to generate an eighth PTK (denoted as PTK8 in FIG. 17) based on the fourth PMK of a second AMP STA. Accordingly, the second AMP STA receives the seventeenth frame.

[0289] In this scenario, when a resource (e.g., energy) constrained STA, for example, the second AMP STA, is informed that the previous PTK has reached its lifespan, the second AMP STA may initiate another procedure for retrieving the fourth PMK and generating a new PTK (e.g., an eighth PTK) , so as to restore the communication as soon as possible, thereby improving the user experience.

[0290] In some embodiments, the method further includes step S51.

[0291] In step S51, the second AMP STA transmits an eighteenth frame carrying an eighth MIC (denoted as MIC8 in FIG. 17) , where the eighth MIC is derived from the eighth PTK and used to verify correctness of a seventh PTK. Accordingly, the first AMP STA receives the eighteenth frame.

[0292] In this case, the first AMP STA may verify the seventh PTK generated by the first AMP STA using the eighth MIC generated by the second AMP STA, which may realize cross-verification of the correctness of the newly generated seventh PTK, thereby improving the key generation reliability and communication reliability.

[0293] It will be noted that the eighteenth frame may be an AMP request frame or an AMP key generation (KeyGen) confirmation frame, which is not limited by embodiments of the present disclosure.

[0294] In some embodiments, the eighteenth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.

[0295] In this case, it is possible to realize the transmission of signaling and a second signaling together in a way that an AMP frame (i.e., an AMP request frame) is reused to carry partial content of another signaling frame (i.e., a KeyGen confirmation frame) , without separately transmitting the signaling in additional frames, thereby reducing the number of signaling interactions and thus improving key generation efficiency.

[0296] It will be noted that the implementation of the seventh PTK’s generation and verification may refer to the implementation of the third PTK’s generation and verification illustrated in steps S26 to S28 above, and the implementation of the eighth PTK’s generation and verification may refer to the implementation of the fourth PTK’s generation and verification illustrated in steps S29 to S31 described above, which will not be repeated here.

[0297] The present disclosure encompasses various embodiments, including not only method embodiments, but also other embodiments such as apparatus embodiments and embodiments related to non-transitory computer-readable storage media. Embodiments may incorporate, individually or in combinations, the features disclosed herein.

[0298] In some aspects of the present disclosure, there is provided a communication apparatus / chipset system including  means (e.g., at least one processor) to implement a method implemented by (or at) an AMP non-AP STA (e.g., the second AMP STA) of the present disclosure. The communication apparatus / chipset system may be the AMP non-AP STA or a module / component in the AMP non-AP STA. In details, the at least one processor may execute instructions stored in a computer-readable storage medium to implement the method.

[0299] In some aspects of the present disclosure, there is provided a communication apparatus / chipset system including means (e.g., at least one processor) to implement the method implemented by (or at) an AMP AP STA (e.g., the first AMP STA) of the present disclosure. The communication apparatus / chipset system may be the AMP AP STA or a module / component in the AMP AP STA. In details, the at least one processor may execute instructions stored in a computer-readable storage medium to implement the method.

[0300] A communication apparatus 2100, as shown in FIG. 21, includes a processor 2101 and a communication interface 2102. The processor 2101 is connected to the communication interface 2102. The processor 2101 is configured to cause the communication apparatus 2100 to perform any of the methods described above, and the communications interface 2102, i.e., a transceiver, is configured to communicate with other network elements under the control of the processor 2101. In some examples, the communication apparatus 2100 may further include a memory 2103, which is configured to store apparatus program code (or instructions) and / or data.

[0301] In some examples, the communication interface 2102 is an interface circuit configured to communicate with another component. For example, the interface circuit may communicate a signal to other apparatus / system such as a radio frequency processing apparatus, or processor system.

[0302] In some embodiments, there is provided a communication apparatus to perform any of the methods in the embodiments of the present disclosure. The communication apparatus may include corresponding modules or units configured to implement methods and / or embodiments described herein. In some embodiments, as shown in FIG. 22, a communication apparatus 2200 includes a transmitting unit 2201, a receiving unit 2202 and a processing unit 2203. In some examples, the communication apparatus 2200 may further include a storage unit 2204 configured to store apparatus program code (or instructions) and / or data.

[0303] For the function and realization of the transmitting unit 2201, the receiving unit 2202, the processing unit 2203 and the storage unit 2204, reference may be made to the description of the relevant units or modules described above, which will not be repeated here.

[0304] In some aspects of the present disclosure, there is provided a communication system including at least one of an apparatus in (or at) an AMP AP STA of the present disclosure, or an apparatus in (or at) an AMP non-AP STA of the present disclosure, as described above.

[0305] In some aspects of the present disclosure, there is provided a communication method performed by a system including at least one of an apparatus in (or at) an AMP AP STA of the present disclosure, and an apparatus in (or at) an AMP non-AP STA of the present disclosure.

[0306] In some aspects of the present disclosure, there is provided a computer program including program code (or instructions) . The program code (or instructions) , when executed by a processor, may cause the processor to implement a communication method of the present disclosure.

[0307] In some aspects of the present disclosure, there is provided a non-transitory computer-readable storage medium storing program code or instructions, when executed by a processor, may cause the processor to implement a method of the present disclosure.

[0308] The solutions described in the present disclosure are applicable to an ambient power IoT network.

[0309] It will be appreciated that any module, component, or device disclosed where that executes instructions may include, or otherwise have access to, a non-transitory computer / processor-readable storage medium or media for storage of information, such as computer / processor-readable instructions, data structures, program modules and / or other data. A  non-exhaustive list of examples of non-transitory computer / processor readable storage media includes magnetic tape, magnetic disk storage or other magnetic storage devices, optical disks such as compact disc read-only memory (CD-ROM) , digital video discs or digital versatile discs (i.e., DVDs) , Blu-ray DiscTM, or other optical storage, volatile and non-volatile, removable and non-removable media implemented in any method or technology, random-access memory (RAM) , read-only memory (ROM) , electrically erasable programmable read-only memory (EEPROM) , flash memory and other memory technology. Any such non-transitory computer / processor-readable storage media may be part of a device / apparatus or accessible or connectable thereto. Computer / processor-readable / executable instructions to implement a method, an application or a module described where may be stored or otherwise held by such non-transitory computer / processor readable storage media.

[0310] It will be noted that the message in the present disclosure may be replaced with information, which may be carried in one single message, or be carried in more than one separate messages.

[0311] Without special noting, the terms "apparatus" and "device" are used exchangeable, and the terms "identity" and "identifier" are used exchangeable.

[0312] In the present disclosure, the word "a" or "an" when used in conjunction with the term "comprising" or "including" in the claims and / or the specification may mean "one " , but it is also consistent with the meaning of "one or more" , "at least one" , and "one or more than one" unless the content clearly dictates otherwise. Similarly, the word "another" may mean at least a second one or more unless the content clearly dictates otherwise.

[0313] In the present disclosure, the words "first" , "second" , etc., when used before a same term (e.g., AMP STA, or an operating step) do not mean an order or a sequence of the term. For example, the "first AMP STA " and the "second AMP STA " , means two different AMP STAs without specially indicated, and similarly, the "first step" and the "second step" means two different operating steps without specially indicated, but does not mean the first step have to happen before the second step. The real order depends on the logic of the two steps.

[0314] The terms "coupled" , "coupling" or "connected" as used where can have several different meanings depending on the context in which these terms are used. For example, as used where, the terms "coupled" , "coupling" , or "connected" can indicate that two elements or devices are directly connected to one another or connected to one another through one or more intermediate elements or devices via a mechanical element depending on the particular context.

[0315] Note that the expression "at least one of A or B" , as used where, is interchangeable with the expression "A and / or B" .It refers to a list in which A, or B, or both A and B may be selected. Similarly, "at least one of A, B, or C" , as used where, is interchangeable with "A and / or B and / or C" or "A, B, and / or C" . It refers to a list in which A or B or C, or both A and B, or both A and C, or both B and C, or all of A, B and C, may be selected. The same principle applies for longer lists having a same format.

[0316] The term "receive" , "detect" and "decode" as used where can have several different meanings depending on the context in which these terms are used. For example, without special note, the term "receive" may indicate that information is received successfully by the receiving node, which means a receiving side correctly detect and decode it. In this scenario, "receive" may cover "detect" and "decode" or may indicates same thing, e.g., "receiving paging" means decoding paging correctly and obtaining the paging successfully, and accordingly, "the receiving side not receive paging" means the receiving side does not detect and / or decoding the paging. For example, "paging being not received" means the receiving side tries to detect and / or decoding the paging, but not obtain the paging successfully. The term "receive" may sometimes indicate that a signal arrives at the receiving side, but does not mean the information in the signal is detected and decoded correctly, then the receiving side need perform detecting and decoding on the signal to obtain the information carried in the signal. In this scenario, "receive" , "detect" and "decode" may indicate different procedure at receiving side to obtain the information.

[0317] Although the present disclosure refers to illustrative embodiments, this is not intended to be construed in a  limiting sense. Various modifications and combinations of the illustrative embodiments, as well as other embodiments of the disclosure, will be apparent to persons skilled in the art upon reference to the description. When combining two or more embodiments, not all the features in the embodiments to be combined are necessary for the combination.

[0318] Features disclosed where in the context of any particular embodiments may also or instead be implemented in other embodiments. Method embodiments, for example, may also or instead be implemented in apparatus, system, and / or computer program product embodiments. In addition, although embodiments are described primarily in the context of methods and apparatus, other implementations are also contemplated, as instructions stored on one or more non-transitory computer-readable media, for example. Such media could store programming or instructions to perform any of various methods consistent with the present disclosure.

Claims

1.A key generation method, comprising:transmitting a first frame carrying first pairwise master key (PMK) materials; andreceiving a second frame carrying second PMK materials, wherein the first PMK materials and the second PMK materials are used to generate a first PMK and a first pairwise transient key (PTK) .2.The method of claim 1, wherein the first PMK materials comprise a first random scalar and a first password element, and the second PMK materials comprise a second random scalar and a second password element; andthe first random scalar, the first password element, the second random scalar and the second password element are used to generate the first PMK.3.The method of claim 2, wherein the first random scalar, the second random scalar and the first PMK are used to generate the first PTK.4.The method of claim 2, wherein the first frame further carries a first random number, and the second frame further carries a second random number, wherein the first random number, the second random number and the first PMK are used to generate the first PTK.5.The method of any one of claims 1 to 4, further comprising: transmitting a third frame carrying a first message integrity code (MIC) , wherein the first MIC is used to verify correctness of a second PTK of a second AMP STA.6.The method of any one of claims 1 to 5, further comprising: transmitting a first protected frame, wherein a first frame body field in the first protected frame is encrypted by the first PTK, and the first protected frame further comprises a first frame check sequence (FCS) field for carrying a MIC generated from the first PTK.7.The method of any one of claims 1 to 6, wherein the second frame further carries a second MIC, and the second MIC is used to verify correctness of the first PTK.8.The method of any one of claims 1 to 4, further comprising: receiving a second protected frame, wherein a second frame body field in the second protected frame is encrypted by the second PTK, and the second protected frame further comprises a second frame check sequence (FCS) field for carrying a MIC generated from the second PTK.9.The method of any one of claims 1 to 8, further comprising:transmitting a fourth frame carrying a first PMK identifier (PMKID) and a third random number, wherein the first PMKID is used to retrieve a second PMK based on a second PMKID stored in a non-volatile memory of a second AMP STA; andreceiving a fifth frame carrying a fourth random number, wherein the third random number and the fourth random number are used to generate a third PTK based on the first PMK.10.The method of claim 9, further comprising: transmitting a sixth frame carrying a third MIC, wherein the third MIC is used to verify correctness of a fourth PTK of the second AMP STA, wherein the third MIC is generated from the third PTK.11.The method of any one of claims 1 to 8, further comprising:receiving a seventh frame carrying a second PMK identifier (PMKID) and a fifth random number, wherein the second PMKID is used to retrieve the first PMK based on a first PMKID stored in a non-volatile memory, generating a third PTK from the first PMK; andtransmitting an eighth frame carrying a sixth random number, wherein the fifth random number and the sixth random number are used to generate a fourth PTK based on the second PMK.12.The method of claim 11, further comprising: receiving a ninth frame carrying a fourth MIC, wherein the fourth MIC is used to verify correctness of the third PTK of the first AMP STA, wherein the fourth MIC is generated from the fourth PTK.13.A key generation method, comprising:receiving a first frame carrying first pairwise master key (PMK) materials; andtransmitting a second frame carrying second PMK materials, wherein the first PMK materials and the second PMK materials are used to generate a second PMK and a second pairwise transient key (PTK) .14.The method of claim 13, wherein the first PMK materials comprise a first random scalar and a first password element, and the second PMK materials comprise a second random scalar and a second password element; andthe first random scalar, the first password element, the second random scalar and the second password element are used to generate the second PMK.15.The method of claim 14, wherein the first random scalar, the second random scalar and the second PMK are used to generate the second PTK.16.The method of claim 14, wherein the first frame further carries a first random number, and the second frame further carries a second random number, wherein the first random number, the second random number and the second PMK are used to generate the second PTK.17.The method of any one of claims 13 to 16, further comprising: receiving a third frame carrying a first MIC, wherein the first MIC is used to verify correctness of the second PTK.18.The method of claim 5 or 14, wherein the third frame is an AMP request frame carrying partial content of an AMP Authentication confirmation frame.19.The method of any one of claims 13 to 18, further comprising: receiving a first protected frame, wherein a first frame body field in the first protected frame is encrypted by a first PTK, and the first protected frame further comprises a first frame check sequence (FCS) field for carrying the first MIC.20.The method of any one of claims 13 to 16, wherein the second frame further carries a second MIC, wherein the second MIC is used to verify correctness of a first PTK of a first AMP STA.21.The method of claim 20, further comprising: transmitting a second protected frame, wherein a second frame body field in the second protected frame is encrypted by the second PTK, and the second protected frame further comprises a second frame check sequence (FCS) field for carrying a MIC generated from the second PTK.22.The method of any one of claims 13 to 21, further comprising:receiving a fourth frame carrying a first PMK identifier (PMKID) and a third random number, wherein the first PMKID is used to retrieve the second PMK based on a second PMKID stored in a non-volatile memory, generating a fourth PTK from the second PMK; andtransmitting a fifth frame carrying a fourth random number, wherein the third random number and the fourth random number are used to generate a third PTK based on the first PMK.23.The method of claim 22, further comprising: receiving a sixth frame carrying a third MIC, wherein the third MIC is used to verify correctness of the fourth PTK.24.The method of claim 10 or 23, wherein the sixth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.25.The method of any one of claims 13 to 21, further comprising:transmitting a seventh frame carrying a second PMK identifier (PMKID) and a fifth random number, wherein the second PMKID is used to retrieve a first PMK based on a first PMKID stored in a non-volatile memory of a first AMP STA; andreceiving an eighth frame carrying a sixth random number, wherein the fifth random number and the sixth random number are used to generate a fourth PTK based on the second PMK.26.The method of claim 25, further comprising: transmitting a ninth frame carrying a fourth MIC, wherein the fourth MIC is used to verify correctness of the third PTK of a first AMP STA.27.The method of claim 12 or 23, wherein the ninth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.28.A key generation method, comprising:transmitting a tenth frame carrying third pairwise master key (PMK) materials and seventh random number, wherein the third PMK materials are used to generate a third PMK; andreceiving an eleventh frame carrying eighth random number, wherein the seventh random number, the eighth random number and the third PMK are used to generate a fifth PTK.29.The method of claim 28, further comprising: transmitting a twelfth frame carrying a fifth MIC, wherein the fifth MIC is used to verify correctness of the sixth PTK of a second AMP STA.30.The method of claim 29, wherein the twelfth frame is an AMP request frame carrying partial content of an AMP Authentication confirmation frame.31.The method of any one of claims 28 or 30, further comprising: transmitting a third protected frame, wherein a third frame body field in the third protected frame is encrypted by the fifth PTK, and the third protected frame further comprises a third frame check sequence (FCS) field for carrying a MIC generated from the fifth PTK.32.The method of any one of claims 28 to 31, wherein the eleventh frame further carries a sixth MIC, and the sixth MIC is used to verify correctness of the fifth PTK.33.The method of any one of claims 28 to 30, further comprising: receiving a fourth protected frame, wherein a fourth frame body field in the fourth protected frame is encrypted by the sixth PTK, and the fourth protected frame further comprises a fourth frame check sequence (FCS) field for carrying a MIC generated from the sixth PTK.34.The method of any one of claims 28 to 33, further comprising:transmitting a thirteenth frame carrying a third PMK identifier (PMKID) and a ninth random number, wherein the third PMKID is used to retrieve the fourth PMK based on a fourth PMKID stored in a non-volatile memory of a second AMP STA; andreceiving a fourteenth frame carrying a tenth random number, wherein the ninth random number the tenth random number and the third PMK are used to generate a seventh PTK.35.The method of claim 34, further comprising: transmitting a fifteenth frame carrying a seventh MIC, wherein the seventh MIC is used to verify correctness of an eighth PTK of the second AMP STA.36.The method of any one of claims 28 to 33, further comprising:receiving a sixteenth frame carrying a fourth PMK identifier (PMKID) and an eleventh random number, wherein the fourth PMKID is used to retrieve the third PMK based on an third PMKID stored in a non-volatile memory, generating an seventh PTK from the third PMK; andtransmitting a seventeenth frame carrying a twelfth random number, wherein the eleventh random number and the twelfth random number are used to generate an eighth PTK based on the fourth PMK of a second AMP STA.37.The method of claim 36, further comprising: receiving an eighteenth frame carrying an eighth MIC, wherein the eighth MIC is used to verify correctness of the seventh PTK.38.A key generation method, comprising:receiving a tenth frame carrying third pairwise master key (PMK) materials and a seventh random number, wherein the third PMK materials are used to generate a third PMK; andtransmitting an eleventh frame carrying an eighth random number, wherein the seventh random number, the eighth random number and the fourth PMK are used to generate a sixth PTK.39.The method of claim 38, further comprising: receiving a twelfth frame carrying a fifth MIC, wherein the fifth MIC is used to verify correctness of the sixth PTK.40.The method of claim 39, wherein the twelfth frame is an AMP request frame carrying partial content of an AMP Authentication confirmation frame.41.The method of any one of claims 38 to 40, further comprising: receiving a third protected frame, wherein a third frame body field in the third protected frame is encrypted by the fifth PTK, and the third protected frame further comprises a third frame check sequence (FCS) field for carrying a MIC generated from the fifth PTK.42.The method of any one of claims 38 to 41, wherein the eleventh frame further carries a sixth MIC, wherein the sixth MIC is used to verify correctness of a fifth PTK of a first AMP STA.43.The method of any one of claims 38 to 40, further comprising: transmitting a fourth protected frame, wherein a fourth frame body field in the fourth protected frame is encrypted by the sixth PTK, and the fourth protected frame further comprises a fourth frame check sequence (FCS) field for carrying a MIC generated from the sixth PTK.44.The method of any one of claims 38 to 43, further comprising:receiving a thirteenth frame carrying a third PMK identifier (PMKID) and a ninth random number, wherein the third PMKID is used to retrieve the fourth PMK based on a fourth PMKID stored in a non-volatile memory, generating an eighth PTK from the fourth PMK; andtransmitting a fourteenth frame carrying a tenth random number, wherein the ninth random number and the tenth random number are used to generate a seventh PTK based on the third PMK.45.The method of claim 44, further comprising: receiving a fifteenth frame carrying a seventh MIC, wherein the seventh MIC is used to verify correctness of the eighth PTK.46.The method of claim 45, wherein the fifteenth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.47.The method of any one of claims 38 to 43, further comprising:transmitting a sixteenth frame carrying a fourth PMK identifier (PMKID) and an eleventh random number, wherein the fourth PMKID is used to retrieve the third PMK based on an third PMKID stored in a non-volatile memory of a first AMP STA; andreceiving a seventeenth frame carrying the a twelfth random number, wherein the eleventh random number and the twelfth random number are used to generate an eighth PTK based on the fourth PMK.48.The method of claim 47, further comprising: transmitting an eighteenth frame carrying an eighth MIC, wherein the eighth MIC is used to verify correctness of the seventh PTK of a first AMP STA.49.The method of claim 37 or 48, wherein the eighteenth frame is an AMP request frame carrying partial content of an AMP key generation (KeyGen) confirmation frame.50.A communication apparatus, comprising:a communication interface configured to communicate with other network elements under a control of at least one processor; andthe at least one processor configured to cause the communication apparatus to implement the method of any one of claims 1 to 12, or the method of any one of claims 13 to 27, or the method of any one of claims 28 to 37, or the method of any one of claims 38 to 49.51.A computer-readable storage medium having stored thereon computer program code program codes or instructions that, when program codes program codes or instructions are executed by a processing circuit of a computer, cause the computer to implement the method of any one of claims 1 to 12, or the method of any one of claims 13 to 27, or the method of any one of claims 28 to 37, or the method of any one of claims 38 to 49.52.A computer program product having instructions that, when executed by a computer, cause the computer to implement the method of any one of claims 1 to 12, or the method of any one of claims 13 to 27, or the method of any one of claims 28 to 37, or the method of any one of claims 38 to 49.53.A communication system, comprising:a first apparatus for implementing the method of any one of claims 1 to 12, or the method of any one of claims 28 to 37; anda second apparatus for implementing the method of any one of claims 13 to 27, or the method of any one of claims 38 to 49.