Communication device, communication method, and program

The communication device efficiently protects Control frames in IEEE 802.11 standard wireless communication by attaching a tamper detection code, enhancing reliability and security by detecting and discarding tampered frames.

WO2026094779A1PCT designated stage Publication Date: 2026-05-07CANON KK
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
CANON KK
Filing Date
2025-10-23
Publication Date
2026-05-07

AI Technical Summary

Technical Problem

Existing wireless communication technologies, particularly those compliant with the IEEE 802.11 standard series, face challenges in efficiently protecting Control frames from tampering, which can compromise communication reliability and security.

Method used

A communication device is designed to efficiently notify and implement protection of Control frames by attaching a tamper detection code using Control frame key information, enabling efficient detection and discard of tampered frames.

Benefits of technology

Enhances communication reliability by ensuring the integrity of Control frames, thereby improving overall security and reducing the impact of malicious attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure JP2025037348_07052026_PF_FP_ABST
    Figure JP2025037348_07052026_PF_FP_ABST
Patent Text Reader

Abstract

A communication device which functions as an access point for executing wireless communication conforming to the IEEE 802.11 standard series transmits a beacon frame including capability information of the communication device related to control frame protection support.
Need to check novelty before this filing date? Find Prior Art

Description

Communication device, communication method, and program

[0001] The present invention relates to a technique for efficiently notifying information regarding protection of Control frames in wireless communication compliant with the IEEE 802.11 standard series.

[0002] In recent years, with the increase in the amount of data to be communicated, the development of communication technologies such as wireless LAN (Local Area Network) has been progressing. As the main communication standards for wireless LAN, the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard series is known. The IEEE 802.11 standard series includes IEEE 802.11a / b / g / n / ac / ax / be standards, etc. For further improvement of communication reliability, the development of the IEEE 802.11bn standard is underway as a successor standard to the IEEE 802.11be standard. In the IEEE 802.11 WG (Working Group) that formulates the IEEE 802.11bn standard, in the UHR SG, the goals and scope of study of this standard are determined, and in TGbn, the detailed technical content to be included in this standard is planned to be defined. Note that UHR SG is an abbreviation for Ultra High Reliability Study Group. Also, TGbn is an abbreviation for Task Group bn.

[0003] In Patent Document 1, a technique called Protected Management Frame (PMF) is disclosed, which protects Management frames by encrypting frames and detecting forgery in order to improve communication reliability.

[0004] Japanese Patent Application Laid-Open No. 2021-150722

[0005] The present invention provides a technique for efficiently notifying information regarding protection of Control frames in wireless communication compliant with the IEEE 802.11 standard series.

[0006] A communication device according to one aspect of the present invention is a communication device that functions as an access point performing wireless communication in accordance with the IEEE 802.11 standard series, and includes a first transmitting means for transmitting a Beacon frame containing capability information of the communication device regarding support for protection of Control frames.

[0007] According to the present invention, information regarding the protection of Control frames can be efficiently notified in wireless communication compliant with the IEEE 802.11 standard series.

[0008] This diagram shows an example of the configuration of a wireless communication system. This diagram shows an example of the hardware configuration of a communication device. This diagram shows an example of the functional configuration of a communication device. This diagram shows an example of the sequence in communication between AP and STA. This diagram shows an example of the format of an RSN Element. This diagram shows an example of the format of an RSN Extension Element. This diagram shows an example of the format of an RSN Extension Element. This diagram shows an example of the format of KDE selectors and CIGTK KDE. This diagram shows an example of the format of a Control MIC Element. This diagram shows an example of the processing flow when setting key information performed by AP. This diagram shows an example of the processing flow for protecting Control frames performed by AP. This diagram shows an example of the processing flow when setting key information performed by STA. This diagram shows an example of the processing flow for protecting Control frames performed by STA. This diagram shows an example of the sequence in multilink communication between AP and STA. This diagram shows examples of KDE selectors and MLO CIGTK KDE formats.

[0009] The embodiments will be described in detail below with reference to the attached drawings. Note that the following embodiments do not limit the invention as defined in the claims. While the embodiments describe multiple features, not all of these features are essential to the invention, and the features may be combined in any way. Furthermore, in the attached drawings, identical or similar configurations are given the same reference numerals, and redundant descriptions are omitted.

[0010] (System Configuration) Figure 1 shows an example of the configuration of the wireless communication system according to this embodiment. This wireless communication system is configured to include, for example, one access point (AP) 101 and one non-AP station (Non-AP STA or station, hereinafter referred to as STA) 102. The network 110 formed by AP 101 indicates the range in which AP 101 and STA 102 can communicate. That is, within the range of network 110, STA 102 can receive signals transmitted by AP 101, and signals transmitted by STA 102 can be received by AP 101. AP 101 and STA 102 are wireless communication devices capable of performing wireless communication in accordance with the IEEE 802.11 series standards, including the IEEE 802.11bn standard. IEEE stands for Institute of Electrical and Electronics Engineers. The IEEE 802.11bn standard is the successor to IEEE 802.11be, which aims for a maximum transmission speed of 46.08 Gbps. The main features of the IEEE 802.11bn standard are high-reliability communication, low-latency communication, and improved throughput during congestion. The IEEE 802.11bn standard can also be called the UHR standard. UHR can be an abbreviation for Ultra High Reliability. Wireless frames communicating using the IEEE 802.11bn standard can be called UHR (Ultra High Reliability) PPDUs. PPDU stands for Physical Layer (PHY) Protocol Data Unit. In this embodiment, wireless frames communicated based on the IEEE 802.11 series standards may be referred to as PPDUs. PPDUs may include UHR-PPDUs. The names IEEE 802.11bn and UHR are for convenience, based on the goals to be achieved and the main features outlined in the development of these standards. Therefore, these names may change once the standards are finalized. On the other hand, this specification and the appended claims are essentially applicable to all standards that may succeed the IEEE 802.11be standard.

[0011] The IEEE 802.11 series standards may include the IEEE 802.11a / b / g / n / ac / ax / be standards. These standards may be called legacy standards. That is, AP101 and STA102 may support one or more legacy standards in addition to the IEEE 802.11bn standard. In addition to the IEEE 802.11 series standards, AP101 and STA102 may also support other communication standards such as Bluetooth®, NFC, UWB, ZigBee, and MBOA. UWB stands for Ultra Wide Band, MBOA stands for Multi Band OFDM Alliance, and NFC stands for Near Field Communication. UWB includes wireless USB, wireless 1394, WiNET, etc. Additionally, AP101 and STA102 may support wired communication standards such as wired LAN.

[0012] Although Figure 1 shows a state where one AP101 and one STA102 exist, there may be multiple AP101s and STA102s. In that case, multiple STA102s may be connected to one AP101, or one STA102 may be connected to multiple AP101s. AP101 may be a wireless LAN router or a personal computer (PC), but is not limited to these. STA102 may be any electronic device such as a smartphone, tablet, mobile phone, PC, video camera, headset, printer, or display, but is not limited to these. AP101 and STA102 may also be information processing devices such as wireless chips capable of performing wireless communication compliant with the IEEE 802.11bn standard. In this embodiment, AP101 and STA102 may be referred to as the communication device 100 without distinction.

[0013] The communication device 100 can transmit and receive wireless signals using frequency bands such as the 2.4 GHz band, 3.6 GHz band, 5 GHz band, 6 GHz band, and millimeter wave bands such as the 45 GHz band and 60 GHz band. The frequency bands used by the communication device 100 are not limited to these and may include, for example, the Sub1 GHz band. The communication device 100 can also communicate using frequency bandwidths of 20 MHz, 40 MHz, 80 MHz, 160 MHz, 320 MHz, 540 MHz, 640 MHz, 1080 MHz, and 2160 MHz. The frequency bandwidths used by the communication device 100 are not limited to these and may include, for example, frequency bandwidths of 240 MHz or 4 MHz. Note that the IEEE 802.11 standard series specifies frequency channels using a frequency bandwidth of 20 MHz as basic channels in frequency bands such as the 2.4 GHz, 5 GHz, and 6 GHz bands. Furthermore, this standard defines multiple channels available for communication in each frequency band: the 2.4 GHz band, the 5 GHz band, and the 6 GHz band. In this standard, the communication device 100 can use one channel in combination with other adjacent channels. This use of one channel in combination with other adjacent channels may be called channel bonding. For example, channel bonding can combine a first channel with a 20 MHz frequency bandwidth and a second channel with a 20 MHz frequency bandwidth adjacent to the first channel to form a single 40 MHz channel. Thus, a link formed as a physical path usable for data transmission between communication devices consists of one or more adjacent channels with predetermined frequency bandwidths. That is, data with a 40 MHz frequency bandwidth can be transmitted in a single link formed by two adjacent channels with a 20 MHz frequency bandwidth. The IEEE 802.11be standard is expected to specify 320 MHz as the maximum frequency bandwidth available in a single link. Furthermore, the transmitted signal may be continuous or discontinuous on the frequency axis within this frequency bandwidth. For example, some frequency bands within this frequency bandwidth may not be used for signal transmission.Furthermore, the IEEE 802.11be standard is expected to specify Multi-Link Operation (MLO), which uses multiple links established between a pair of communication devices for parallel communication. AP101 and STA102 may be AP Multi-Link Device (MLD) and Non-AP MLD, respectively, which are compatible with MLO.

[0014] The IEEE 802.11 series standard specifies OFDMA functionality, which divides a single channel into multiple resource units on the frequency axis for multiple access. OFDMA is an abbreviation for Orthogonal Frequency Division Multiple Access. For example, if AP101 has multiple STA102 connected to it, AP101 divides the single channel it uses into multiple resource units and assigns them to each STA102. As an example, suppose AP101 has two STA102 connected to it and AP101 transmits one PPDU using one 20MHz channel. In this case, AP101 places two different resource units on the frequency axis within the single PPDU. Each resource unit may have a bandwidth of 10MHz. Furthermore, each resource unit may be placed so as not to overlap with each other on the frequency axis. AP101 transmits downlink data to each STA102 using the resource units assigned to each STA102. STA102 receives data transmitted to itself using the resource units assigned to it. For example, STA102 can identify the resource units assigned to it by referring to the information on the placement and assignment of resource units stored in the PPDU preamble. In this way, by using OFDMA functionality, AP101 can transmit data to multiple STA102s in parallel. When STA102 transmits uplink (UL) data to AP101, AP101 first transmits a Trigger frame. A Trigger frame is a type of Control frame. The Trigger frame may contain information on the placement and assignment of resource units for UL transmission. In other words, STA102 can identify the resource unit that it should use for UL transmission by referring to the Trigger frame, and can transmit UL data using that resource unit.

[0015] The IEEE 802.11bn standard is being developed, and the protection of Control frames is being considered. For example, a malicious third party might continuously send tampered Control frames with the aim of attacking STA102. In order to protect Control frames, AP101 and STA102 need to efficiently notify each other of information regarding Control frame protection. In this embodiment, AP101 notifies STA102 of its capability to support Control frame protection using a Beacon frame. STA102, upon receiving the Beacon frame, also notifies STA102 of its capability to support Control frame protection using an Association Request frame. If AP101 and STA102 recognize that they support Control frame protection, they can send a Control frame with a tamper detection code attached using the Control frame key information. The receiving communication device calculates the tamper detection code from the Control frame key information and the data of the received Control frame, and compares it with the tamper detection code attached to the received Control frame to detect whether tampering has occurred. This mechanism allows tampered Control frames sent by malicious third parties to be discarded without processing.

[0016] (Device Configuration) Figure 2 shows an example of the hardware configuration of the communication device 100 (AP101 and STA102) in this embodiment. The communication device 100 has a storage unit 201, a control unit 202, a function unit 203, an input unit 204, an output unit 205, a communication unit 206, and an antenna 207. There may be multiple antennas. The storage unit 201 is composed of one or more memories such as ROM and RAM, and stores various information such as computer programs for performing various operations described later, and communication parameters for wireless communication. ROM and RAM are abbreviations for Read Only Memory and Random Access Memory, respectively. In addition to memories such as ROM and RAM, storage media such as flexible disks, hard disks, optical disks, magneto-optical disks, CD-ROMs, CD-Rs, magnetic tapes, non-volatile memory cards, and DVDs may be used as the storage unit 201. Furthermore, the storage unit 201 may include multiple memory units or the like.

[0017] The control unit 202 is composed of one or more processors, such as a CPU and an MPU, and controls the entire communication device 100 by executing a computer program stored in the storage unit 201. The control unit 202 may also control the entire communication device 100 through cooperation between the computer program stored in the storage unit 201 and the OS (Operating System). The control unit 202 also generates data and signals (wireless frames) to be transmitted in communication with other communication devices. Note that CPU is an abbreviation for Central Processing Unit, and MPU is an abbreviation for Micro Processing Unit. The control unit 202 may also be equipped with multiple processors, such as a multi-core processor, and control the entire communication device 100 using multiple processors. Furthermore, the control unit 202 controls the function unit 203 to perform predetermined processes such as wireless communication, imaging, printing, and projection. The functional unit 203 is hardware for the communication device 100 to perform predetermined processing.

[0018] The input unit 204 receives various operations from the user. The output unit 205 provides various outputs to the user via a monitor screen or speaker. Here, the output from the output unit 205 may be a display on the monitor screen, audio output via a speaker, vibration output, etc. The input unit 204 and the output unit 205 may be implemented in a single module, such as a touch panel. The input unit 204 and the output unit 205 may be integrated with the communication device 100 or may be separate components.

[0019] The communication unit 206 controls wireless communication in accordance with the IEEE 802.11bn standard. In addition to the IEEE 802.11bn standard, the communication unit 206 may also control wireless communication in accordance with other IEEE 802.11 series standards, or control wired communication such as wired LAN. The communication unit 206 controls the antenna 207 to transmit and receive signals for wireless communication generated by the control unit 202. If the communication device 100 supports the NFC standard, Bluetooth standard, etc., in addition to the IEEE 802.11bn standard, it may also control wireless communication in accordance with these communication standards. Furthermore, if the communication device 100 can perform wireless communication in accordance with multiple communication standards, it may be configured to have separate communication units and antennas corresponding to each communication standard. The communication device communicates data such as image data, document data, and video data with the other communication device via the communication unit 206. The antenna 207 may be configured separately from the communication unit 206, or it may be configured as a single module together with the communication unit 206.

[0020] Antenna 207 is an antenna capable of communication in the 2.4 GHz band, 5 GHz band, 6 GHz band, etc. In this embodiment, there may be two or more antennas, and if the communication unit 206 is composed of multiple communication units, there may be an antenna corresponding to each communication unit. Alternatively, there may be different antennas for each frequency band.

[0021] Figure 3 shows a block diagram of the functional configuration of the communication device 100 (AP101 and STA102) in this embodiment. The communication device 100 may be composed of a wireless LAN control unit 301, a frame generation unit 302, a frame analysis unit 303, a UI control unit 304, and a storage unit 305. The wireless LAN control unit 301 controls the communication unit 206 and antenna 207 for sending and receiving wireless signals with other wireless LAN devices. For example, the wireless LAN control unit 301 works in cooperation with the frame generation unit 302 and the frame processing unit 303 to perform wireless frame communication control in accordance with the IEEE 802.11 standard series. The wireless LAN control unit 301 can perform communication control such as authentication processing of the other party's communication device, connection processing, key information distribution processing, and data communication processing.

[0022] The frame generation unit 302 generates wireless frames, including MAC frames such as Management frames, Control frames, and Data frames. MAC frames are also called MAC Protocol Data Units (MPDUs) or Aggregate MAC Protocol Data Units (A-MPDUs). When generating Management frames, the frame generation unit 302 may include information on whether or not to support protection of Control frames. The frame generation unit 302 may also perform MAC frame protection processing using key information corresponding to the type of MAC frame. For example, when encrypting a Data frame, it may use key information to encrypt it.

[0023] Furthermore, if, for example, protection for Control frames is enabled, a MIC for tamper detection can be generated using the key information for Control frames and attached to the Control frame. MIC stands for Message Integrity Code, and is a hash value calculated based on data and key information. MIC can also be called Message Authentication Code (MAC). A wireless frame consists of a preamble field and a data field. The data field stores MAC frames such as Management frames, Control frames, and data frames. The content of wireless control by each MAC frame generated by the frame generation unit 302 may be constrained by settings stored in the storage unit 305. The frame generation unit 302 can accept settings from the user via the UI control unit 304. The wireless frame generated by the frame generation unit 302 is sent to the wireless LAN control unit 301 and can be transmitted externally by the communication unit 206 and the antenna 207.

[0024] The frame analysis unit 303 analyzes the received wireless frame in cooperation with the communication unit 206, antenna 207, and wireless LAN control unit 301. When analyzing a wireless frame, the frame analysis unit 303 can determine the analysis method based on settings stored in the storage unit 305. The frame analysis unit 303 analyzes the preamble of the received wireless frame and obtains the MAC frame from the data field. When obtaining a Management frame, such as a Beacon frame or an Association Request frame, the frame analysis unit 303 can analyze information contained in the Management frame to determine whether it supports protection of the Control frame. The frame analysis unit 303 can also perform MAC frame protection processing using key information corresponding to the type of MAC frame. For example, if the data frame is encrypted, it can perform decryption processing using the key information. Furthermore, the frame analysis unit 303 can determine whether Control frame protection is enabled based on the MAC frame header information and whether a MIC is attached to the Control frame. If Control frame protection is enabled, the unit can calculate a MIC for tamper detection using the Control frame key information, compare its value with the MIC attached to the Control frame, and perform tamper detection.

[0025] The UI control unit 304 includes hardware related to a user interface, such as a touch panel or buttons, for receiving operations on AP101 and STA102 by a user (not shown), and a program to control them. The user may be able to configure whether or not to support Control frame protection. The UI control unit 304 also has functions for presenting information to the user, such as displaying images or outputting audio.

[0026] The memory unit 305 is a storage device that may consist of ROM and RAM, etc., for storing programs and data on which the communication device operates.

[0027] (Example Sequence) The following outlines the communication performed between AP101 and STA102. Figure 4 shows an example sequence of messages exchanged between AP101 and STA102.

[0028] AP101 may transmit a Beacon frame containing information indicating support for Control frame protection if it supports Control frame protection (S401). Whether or not to support Control frame protection may be set as an initial setting of the device, or it may be set based on user input via the UI control unit 304. Information indicating support for Control frame protection may be shown, for example, in the CFP capable field of the RSN Element or RSN Extension Element described later. RSN is an abbreviation for Robust Security Network. AP101 may also indicate support for Control frame protection in Management frames other than Beacon frames, such as Probe Response frames.

[0029] Next, STA102 sends an Authentication frame for authentication (S402), and AP101 sends an Authentication frame in response (S403). The number of Authentication frames varies depending on the security method used; for example, when connecting using the WPA3 Personal method, the number of Authentication frames exchanged may increase.

[0030] Next, STA102 sends an Association Request frame to connect to AP101 (S404). In the Association Request frame, STA102 may indicate that it supports protection of Control frames. Also, if AP101, which has received the Association Request frame, permits STA102's connection, it may send an Association Response frame (S405). In the Association Response frame, AP101 may indicate that it supports protection of Control frames. Information indicating support for protection of Control frames can be shown, for example, in the CFP capable field of the RSN Element or RSN Extension Element, as described later.

[0031] In this embodiment, the exchange of Authentication frames and the exchange of Association Request frames and Association Response frames may be collectively referred to as connection processing.

[0032] If the connection process is successful, AP101 and STA102 perform 4-Way Handshake (4WHS) processing and can deliver and generate key information for protecting data frames, Management frames, and Control frames. First, AP101 and STA102 exchange random numbers called Anonce and Snonce in 4WHS message 1 frame (S406) and 4WHS message 2 frame (S407) to generate PMK (Pairwise Master Key) and PTK (Pairwise Temporary Key) based on these random numbers. PMK is pre-shared key information, and PTK is key information used to protect data frames sent to individual STAs. Furthermore, the 4WHS message 1 frame (S406) may separately include an Announce for generating a PTK (Control PTK, hereinafter referred to as CPTK) for a Control frame addressed to an individual STA. Alternatively, the 4WHS message 2 frame (S407) may separately include a Announce for generating a CPTK.

[0033] Next, AP101 generates a CIGTK (Control frame Integrity Group Temporary Key) KDE (Key Data Encapsulation) containing key information for protecting Control frames addressed to the STA group, stores it in a 4WHS message 3 frame, and sends it to STA102 (S408). The CIGTK may also be called CGTK (Control frame Group Temporary Key). Details of the CIGTK KDE will be described later. The key information for protecting frames addressed to the STA group is also called the group key. The 4WHS Message 3 frame may include a GTK (Group Temporal Key), which is a group key for protecting data frames; an IGTK (Integrity GTK), which is a group key for protecting Management frames; and a BIGTK (Beacon IGTK), which is a group key for protecting Beacon frames. Based on the generated PTK and the data of the 4WHS Message 3 frame received from AP101, STA102 detects tampering with the 4WHS Message 3 frame, and if it determines that no tampering has occurred, it sends a 4WHS Message 4 frame to AP101 (S409). Furthermore, the 4WHS message 3 frame (S408) may separately include an Confirm for generating the CPTK. Also, the 4WHS message 4 frame (S409) may separately include a Snonce for generating the CPTK. After the 4WHS processing frames have been exchanged, AP101 generates the CPTK from the Confirm and Snonce for the Control frame and the PMK, and sets PTK / GTK / CPTK / CIGTK as key information in the storage unit 201 and saves it. STA102 does the same, setting PTK / GTK / CPTK / CIGTK as key information in the storage unit 201 and saving it. AP101 and STA102 may also set and save IGTK and BIGTK.

[0034] Subsequently, AP101 transmits a Trigger frame, triggering the transmission of UL data from one or more STAs, including STA102 (S412). The Trigger frame transmitted here has a MIC for tamper detection added to protect the Control frame. Since the Trigger frame is a frame addressed to a group, the MIC is calculated using the CIGTK shared between AP101 and STA102 in the group 4WHS processing. If the Control frame to be transmitted is addressed to an individual STA, the MIC may be calculated using the CPTK.

[0035] When STA102 receives a Trigger frame with an attached MIC, it performs tamper detection on the Trigger frame (S413). Specifically, it calculates the MIC based on the data contained in the Trigger frame and CIGTK. Then, STA102 compares the calculated MIC with the value of the MIC contained in the Trigger frame, and determines that the frame has not been tampered with if the MIC values ​​match. If STA102 determines that the Trigger frame has not been tampered with, it transmits a UL data frame (S414), and if it determines that the frame has been tampered with, it discards the Trigger frame.

[0036] CIGTK may be configured to be updated periodically after a predetermined time has elapsed. In this case, AP101 may send a Group key handshake (GKHS) message 1 frame containing the updated CIGTK KDE to STA102 (S421). Upon receiving GKHS message 1, STA102 sends a GKHS message 2 frame to AP101 (S422) and sets and saves CIGTK in the storage unit 201. CIGTK may be updated at the same time as GTK, IGTK, and BIGTK, or at different times. The interval for CIGTK updates may be set as an initial setting of AP101, or it may be set based on user input via the UI control unit 304. Alternatively, AP101 may be configured to notify STA102 of information regarding the interval for updating CIGTK.

[0037] (Frame Format) Figure 5 shows an example of the RSN Element format used in this embodiment to indicate whether the communication device 100 supports protection of Control frames. The RSN Element may be included in the Management frame transmitted by the communication device 100. For example, if the communication device 100 is an AP, the RSN Element may be included in Management frames such as Beacon frames, Probe Response frames, Association Response frames, and Response Response frames. Furthermore, if the communication device 100 is an STA, for example, the Management frame, such as the Probe Request frame, Association Request frame, and Reassociation Request frame, may include an RSN element.

[0038] An RSN Element includes an Element ID field 501, a Length field 502 indicating the length of the RSN Element, and an RSN Capabilities field 503. The Element ID field 501 may contain a value of 48, which indicates that it is an RSN Element. The RSN Capabilities field 503 contains fields related to capability information associated with the RSN. For example, the MFPR (Management Frame Protection Required) field 511 contains information indicating whether support for Management Frame Protection is required. For example, the MFPC (Management Frame Protection Capable) field 512 contains information indicating whether Management Frame Protection is supported. A value of 1 in the MFPR field 511, or a value of 1 in the MFPC field 512, may indicate that Management Frame Protection is supported.

[0039] The CFP (Control Frame Protection) capable field 513 contains information indicating whether Control Frame Protection is supported. A value of 1 in the CFP Capable field 513 indicates that Control Frame Protection is possible and is supported. A value of 0 in the CFP Capable field 513 indicates that Control Frame Protection is not supported.

[0040] Instead of an RSN Element, an RSN Extension Element may be used to indicate whether the communication device 100 supports protection of Control frames. Figure 6 shows an example of the format of an RSN Extension Element used by the communication device 100 in this embodiment. The RSN Extension Element may be included in the Management frame transmitted by the communication device 100. For example, if the communication device 100 is an AP, the RSN Extension Element may be included in Management frames such as Beacon frames, Probe Response frames, Association Response frames, and Response Response frames. Furthermore, for example, if the communication device 100 is STA, then Management frames such as Probe Request frames, Association Request frames, and Reservation Request frames may contain RSN Extension Element. The RSN Extension Element includes an Element ID field 601, a Length field 602 indicating the length of the RSN Extension Element, and an Extended RSN Capabilities field 603. The Element ID field 601 may contain a value of 244, which indicates that it is an RSN Extension Element. The Extended RSN Capabilities field 603 contains fields related to capability information for Extended RSNs. A value of 1 in the CFP capable field 604 indicates that Control frame protection is possible and is supported. A value of 0 in the CFP capable field 604 indicates that Control frame protection is not supported.

[0041] Figure 7 shows another example of the RSN Extension Element format used by the communication device 100 in this embodiment. In this example, the Extended RSN Capabilities field includes a CFPR (Control Frame Protection Required) field 701 and a CFPC (Control Frame Protection Capable) field 702. A value of 1 in the CFPR field 701 indicates that Control frame protection is required, and that the connection will not be established if the communication device of the other party does not support Control frame protection. This makes it possible to connect only with communication devices of the other party that support a higher level of security. A value of 0 in the CFPR field 701 indicates that Control frame protection is not required. A value of 1 in the CFPC field 702 indicates that Control frame protection is possible and is supported. A value of 0 in the CFPC field 702 indicates that Control frame protection is not supported. When the value of the CFPR field 701 is set to 1, the value of the CFPC field 702 is also set to 1.

[0042] Figures 5 to 7 are examples of Information Elements used to indicate whether or not Control frame protection is supported; other Information Elements besides RSN Element and RSN Extension Element may also be used.

[0043] Figure 8 shows an example of the format of KDE selectors and CIGTK KDE805 used by the communication device 100 in this embodiment. OUI stands for Organizationally Unique Identifier. KDE selectors are identified by the value of Data type; for example, if Data type is 16, it indicates MLO GTK KDE801, which includes the GTK of a predetermined link during multilink communication. If Data type is 20, it indicates CIGTK KDE805. CIGTK KDE805 includes KeyID field 810, CIPN field 811, and CIGTK field 812, which is a group key for protecting Control frames. KeyID field 810 is information indicating the identifier of the key. Furthermore, the CIPN field 811 stores the packet number used by the last Broadcast / multicast sender and is used by the receiver as an initial value for the replay counter. In Figure 8, the case where Data type is 20 is shown as CIGTK KDE, but other values ​​may be used as long as they can be distinguished from other KDEs.

[0044] FIG. 9 is a diagram showing an example of the format of a Control MIC Element added to a Control frame, which is the target of Control frame protection. Whether the Control frame is protected can be indicated, for example, by setting the value of the Protected Frame subfield of the Frame Control field in the MAC header to 1. Also, it may be indicated that the Control frame is protected by including a Control MIC Element in the Control frame. The Control MIC Element may include an Element ID field 901, a Length field 902 indicating the length of the Control MIC Element, an Element ID Extension field 903, a Key ID field 904, a CIPN field 905, and a MIC field 906. By setting, for example, a value of 255 in the Element ID field 901 and setting a predetermined value in the Element ID Extension field 903, it can be specified that it is a Control MIC Element. Note that a value that can uniquely identify the Control MIC Element may be set in the Element ID field 901, and the Element ID Extension field 903 may be omitted without use. Information for identifying the CIGTK or CPTK used to calculate the MIC is stored in the Key ID field 904. An unsigned integer for replay detection of the protected Control frame is stored in the CIPN field 905. A Message Integrity Code for forgery detection calculated based on the protected Control frame is stored in the MIC field 906.

[0045] (Processing Flow) Next, the processing flow executed by the communication device 100 as described above will be explained using Figures 10 to 13. Figure 10 shows an example of the processing flow when setting key information executed by AP 101. Figure 11 shows an example of the processing flow when protecting Control frames executed by AP 101. Figure 12 shows an example of the processing flow when setting key information executed by STA 102. Figure 13 shows an example of the processing flow for protecting Control frames executed by STA 102. Each process shown in the flowcharts of Figures 10 to 13 is executed by the processor of the control unit 202 of AP 101 or STA 102 executing a computer program stored in the storage unit 201. Some processes in Figures 10 to 13, such as transmission, modulation, reception, and decoding, are realized through the cooperation of the processor of the control unit 202 of each communication device, the communication unit 206, and the ASIC, DSP, FPGA, etc. of the control unit 202.

[0046] First, the process of setting key information performed by AP101 will be explained using Figure 10. For example, the control unit 202 in AP101 performs the key information setting process in cooperation with other functional units. AP101 first generates and transmits a Beacon frame containing an RSN Element or RSN Extension Element that indicates support for protection of Control frames (S1001). For example, when using an RSN Element as shown in Figure 5 or an RSN Extension Element as shown in Figure 6, the CFP capable field is set to 1. Also, when using an RSN Extension Element as shown in Figure 7, for example, both the CFPR field and the CFPC field are set to 1, or the CFPR field is set to 0 and the CFPC field is set to 1.

[0047] Next, the AP 101 determines whether it has received a connection start frame from the STA 102 (S1002). For example, when the AP 101 receives an Authentication frame, it can determine that it has received a connection frame from the STA 102. If the AP 101 determines that it has not received a connection start frame from the STA 102 (NO in S1002), after a predetermined period has elapsed, it retransmits the Beacon frame (S1001). If the AP 101 determines that it has received a connection start frame from the STA 102 (YES in S1002), the AP 101 executes a connection process with the STA 102 (S1003). The connection process includes an Authentication process and an Association process for authenticating the STA 102.

[0048] Next, the AP 101 determines whether the connection process with the STA 102 has been successful (S1004). If the AP 101 determines that the connection process has failed (NO in S1004), it returns to the Beacon frame transmission process (S1001) again. If the AP 101 determines that the connection process has been successful (YES in S1004), based on the RSN Element or RSN Extension Element included in the Association Request frame received from the STA 102, it determines whether the STA 102 indicates support for protection of the Control frame (S1006). For example, when using an RSN Element as shown in FIG. 5 or an RSN Extension Element as shown in FIG. 6, if the CF - capable field is set to 1, it is determined that the STA 102 supports protection of the Control frame. Also, for example, when using an RSN Extension Element as shown in FIG. 7, if both the CFPR field and the CFPC field are set to 1, or if the CFPR field is set to 0 and the CFPC field is set to 1, it is determined that the STA 102 supports protection of the Control frame.

[0049] If AP101 determines that STA102 supports protection of Control frames (YES in S1006), it executes 4WHS, sends a 4WHS message 3 frame including GTK / CIGTK, and delivers the key information to STA102 (S1007). Subsequently, AP101 receives a 4WHS message 4 frame from STA102, generates a CPTK for the protection of Control frames sent to individual STAs, and a PTK for data frames sent to individual STAs, and sets them together with GTK / CIGTK in the storage unit 201 and saves them (S1008). If AP101 determines that STA102 does not support protection of Control frames (NO in S1006), it executes 4WHS, sends a 4WHS message 3 frame including the GTK, and sends it to STA102 (S1009). Subsequently, AP101 receives a 4WHS message 4 frame from STA102, generates the PTK for the data frame to be sent to the individual STA (S1008), and sets and saves it together with the GTK in the storage unit 201 (S1010).

[0050] Next, the Control frame protection process performed by AP101 will be explained using Figure 11. For example, the control unit 202 in AP101 works in cooperation with other functional units to perform Control frame protection. The example in Figure 11 shows a case where AP101 transmits a Trigger frame and receives UL data from STA102. AP101 first attempts to obtain a BSR (Buffer Status Report) from STA102 to obtain the buffer amount of the transmitted data (S1101). For example, AP101 can transmit a BSRP (Buffer Status Report Pol) Trigger frame and receive a frame containing a BSR from one or more STA102s. If AP101 does not receive a BSR, or if it determines that the BSR buffer size is not greater than zero (NO in S1102), it attempts to obtain the STA's BSR again (S1101). If AP101 determines that the BSR buffer size is greater than zero (YES in S1102), it determines whether Control frame protection is enabled in order to generate a Trigger frame to trigger STA102's UL transmission (S1103).

[0051] If AP101 determines that Control frame protection is enabled (YES in S1103), it generates a MIC for detecting tampering with the Trigger frame based on the data in the Trigger frame and the CIGTK generated by 4WHS processing, and attaches it to the Trigger frame before transmitting it (S1105). In addition to attaching the MIC, AP101 may also set the value of the Protected Frame bit in the Frame Control field of the MAC header of the Trigger frame to 1. If AP101 determines that Control frame protection is not enabled (NO in S1103), it transmits the Trigger frame without attaching the MIC (S1105).

[0052] The final AP101 receives UL data via OFDMA communication from one or more STA102 units that have received the Trigger frame (S1106).

[0053] Next, the process for setting key information performed by STA102 will be explained using Figure 12. For example, the control unit 202 in STA102 performs the key information setting process in cooperation with other functional units. First, STA102 receives a Beacon frame containing an RSN Element or RSN Extension Element indicating support for Control frame protection (S1201).

[0054] Next, STA102 performs connection processing to connect to AP101 (S1202). For example, the connection processing includes authentication processing and association processing for authentication of STA102.

[0055] If STA102 determines that the connection process has failed (NO in S1203), it returns to the Beacon frame reception process (S1201). If STA102 determines that the connection process has been successful (YES in S1203), it determines whether to support Control frame protection based on the RSN Element or RSN Extension Element contained in the Association Request frame sent by STA102 (S1205). For example, if an RSN Element as shown in Figure 5 or an RSN Extension Element as shown in Figure 6 is used, STA102 determines that it supports Control frame protection if the CFP capable field is set to 1. Furthermore, if an RSN Extension Element like the one shown in Figure 7 is used, STA102 determines that it supports protection of the Control frame if both the CFPR field and the CFPC field are set to 1, or if the CFPR field is set to 0 and the CFPC field is set to 1.

[0056] If STA102 determines that it supports Control frame protection (YES in S1205), it performs 4WHS processing and receives a 4WHS message 3 frame containing GTK / CIGTK from AP101 (S1206). Subsequently, STA102 sends a 4WHS message 4 frame to AP101, generates PTK / CPTK, and sets and saves them together with GTK / CIGTK in the storage unit 201 (S1207). If STA102 determines that it does not support Control frame protection (NO in S1205), it performs 4WHS processing and receives a 4WHS message 3 frame containing GTK but not CIGTK from AP101 (S1208). Next, STA102 transmits 4WHS message 4 frames to AP101, generates a PTK, and stores it together with the GTK in the storage unit 201 (S1209).

[0057] Next, using Figure 13, we will explain the Control frame protection process performed by STA102. For example, the control unit 202 in STA102 works in cooperation with other functional units to perform Control frame protection processing. The example in Figure 13 shows a case where STA102 receives a Trigger frame, performs Trigger frame protection processing, and then transmits UL data.

[0058] STA102 first attempts to send a BSR to notify the amount of data buffered for transmission (S1301).

[0059] Next, STA102 determines whether it has received a Trigger frame from AP101 that triggers the transmission of UL data (S1302). If STA102 determines that it has not received a Trigger frame (NO in S1302), it sends a BSR to AP101 again (S1301). If STA101 determines that it has received a Trigger frame (YES in S1302), it determines whether Control frame protection is enabled (1303). Whether Control frame protection is enabled may be determined based on whether MIC is attached to the Trigger frame. Alternatively, it may be determined based on whether the value of the Protected Frame bit in the Frame Control field of the MAC header of the Trigger frame is set to 1.

[0060] If STA102 determines that Control frame protection is not enabled (NO in S1303), it does not perform tampering detection on the Trigger frame, but instead sends UL data to AP101 based on the contents of the Trigger frame (S1304), and terminates processing.

[0061] If STA102 determines that Control frame protection is enabled (YES in S1303), it performs tampering detection on the Trigger frame (S1305). Specifically, it calculates MIC based on the data contained in the Trigger frame and the CIGTK stored in the memory unit 201 (S1305). Then, STA102 compares the calculated MIC with the MIC value contained in the Trigger frame, and if the MIC values ​​match (YES in S1306), it determines that the received Trigger frame has not been tampered with and transmits UL data to AP101 based on the contents of the Trigger frame (S1304). If the MIC value does not match (NO in S1306), STA102 determines that the received Trigger frame has been tampered with, discards the Trigger frame (S1307), and sends the BSR again (S1301).

[0062] Note that while Figures 11 and 13 show examples using Trigger frames as Control frames, the Control frames subject to protection are not limited to these. For example, BlockAckReq frames or other Control frames may also be subject to protection. Furthermore, if the Control frame is addressed to an individual STA, the CPTK generated in Figures 10 and 12 may be used to generate a MIC or encrypt the Control frame.

[0063] As described above, in this embodiment, the communication device functioning as an access point transmits a Beacon frame containing capability information regarding the communication device's support for Control frame protection. The communication device functioning as a station receives a Beacon frame containing capability information regarding support for Control frame protection. This makes it possible to efficiently notify information regarding Control frame protection. As a result, it becomes possible to distribute and generate key information used for Control frame protection and to execute Control frame protection processing.

[0064] (Modification 1) An example of performing multilink communication where AP101 and STA102 support MLO will be described. An AP that supports MLO is called an AP MLD, and may contain multiple APs within a single physical device. Similarly, an STA that supports MLO is called a Non-AP MLD, and may contain multiple STAs (Non-AP STAs) within a single physical device. In this embodiment, an example will be described in which AP101, which is an AP MLD, contains two APs (AP1, AP2), and STA102, which is a Non-AP MLD, contains two STAs (STA1, STA2).

[0065] (Sequence Example) Figure 14 shows an example of a message sequence exchanged between AP101 and STA102 during multilink communication. The link used between AP1 and STA1 is referred to as Link 1, and the link used between AP2 and STA2 is referred to as Link 2. In this embodiment, the Authentication process, Association process, and 4WHS process for establishing multilink communication are collectively referred to as multilink setup.

[0066] First, AP101 generates and transmits a Beacon frame (S1401) that indicates support for Control frame protection, similar to S401 in Figure 4. Furthermore, a Basic Multi-Link element is added to this Beacon frame to indicate that AP101 supports MLO.

[0067] The processes in S1402 to S1403 are the same as those in S402 to S403 in Figure 4, so their explanation is omitted.

[0068] STA1 sends an Association Request frame on link 1 to set up the multilink (S1404). STA1 may indicate in the Association Request frame that it supports protection of the Control frame. In addition, STA1 adds a Basic Multi-Link element to the Association Request frame to set up the multilink. The Basic Multi-Link element contains information about the link to be set up, and may include information about link 2.

[0069] Furthermore, AP1, upon receiving an Association Request frame, may send an Association Response frame if it permits the connection of STA1 (S1405). AP1 may indicate in the Association Response frame that it supports protection of the Control frame. It may also add a Basic Multi-Link element containing information about the permitted link to the Association Response frame.

[0070] If the connection process is successful, AP1 and STA1 perform 4WHS processing to exchange and generate key information for protecting data frames, Management frames, and Control frames. The processing in S1406 to S1407 is the same as the processing in S406 to S407 in Figure 4, so the explanation is omitted.

[0071] AP1 generates group key information (MLO CIGTK KDE) for protecting MLO Control frames, stores it in a 4WHS message 3 frame, and sends it to STA1 (S1408). MLO CIGTK KDE contains CIGTK information for multiple links. Details of MLO CIGTK KDE will be described later. The 4WHS message 3 frame may contain MLO GTK, which is the group key for protecting MLO data frames; MLO IGTK, which is the group key for protecting MLO Management frames; and MLO BIGTK, which is the group key for protecting MLO Beacon frames. Based on the generated PTK and the data of the 4WHS message 3 frame received from AP1, STA1 detects tampering with the 4WHS message 3 frame. If it determines that no tampering has occurred, STA1 sends the 4WHS message 4 frame to AP1 (S1409). The 4WHS message 3 frame (S1408) may also include an Anonce for generating the CPTK. The 4WHS message 4 frame (S1409) may also include a Snonce for generating the CPTK.

[0072] Once the 4WHS processing frames have been exchanged, the AP MLD generates a CPTK from the Anonce / Sonce and PMK for the Control frame, and sets and saves the PTK / CPTK in the storage unit 201. The PTK / CPTK can be used in common across all links. The AP MLD also sets and saves the GTK / CIGTK for AP1, which uses link 1, in the storage unit 201, and the GTK / CIGTK for AP2, which uses link 2, in the storage unit 201.

[0073] Similarly, STA102 sets and saves PTK / GTK / CPTK / CIGTK in the storage unit 201. AP101 and STA102 can also set and save IGTK and BIGTTK for each link.

[0074] Subsequently, AP1 transmits a Trigger frame over Link 1, triggering the transmission of UL data from one or more STAs, including STA1 (S1411). The Trigger frame transmitted here has a tamper-detection MIC added to it to protect the Control frame. The MIC is calculated using the CIGTK for Link 1, which is shared between the AP MLD and Non-AP MLD via 4WHS processing.

[0075] When STA1 receives a Trigger frame with an attached MIC, it performs tamper detection on the Trigger frame (S1412). Specifically, it calculates the MIC based on the data contained in the Trigger frame and the CIGTK of link 1. Then, STA1 compares the calculated MIC with the value of the MIC contained in the Trigger frame, and determines that the frame has not been tampered with if the MIC values ​​match. If it determines that the frame has not been tampered with, it transmits the UL data frame (S1413), and if it determines that the frame has been tampered with, it discards the Trigger frame.

[0076] Similarly, AP2 can also transmit a Trigger frame with MIC added over Link 2 (S1421). Here, MIC is calculated using the CIGTK for Link 2, which is shared between AP MLD and Non-AP MLD in 4WHS.

[0077] When STA2 receives a Trigger frame with MIC attached, it performs tampering detection on the Trigger frame (S1422), and if it determines that the frame has not been tampered with, it transmits a UL data frame (S1423).

[0078] Alternatively, the MLO CIGTK may be updated periodically after a predetermined time has elapsed. In this case, the AP MLD may send the GKHS message 1 frame to the Non-AP MLD, including the MLO CIGTK KDE which contains the updated MLO CIGTK (S1431). Upon receiving GKHS Message 1, the Non-AP MLD sends a GKHS message 2 frame to the AP MLD (S1432), and sets and saves the CIGTK for each link in the storage unit 201.

[0079] (Frame Format) Figure 15 shows an example of the format of KDE (Key Data Encapsulation) selectors and MLO CIGTK KDE1505 used by the communication device 100 in this embodiment. KDE selectors are identified by the Data type value; for example, if Data type is 16, it indicates MLO GTK KDE1501, which includes the GTK for a predetermined link during multilink communication. Also, for example, if Data type is 17, it indicates MLO IGTK KDE1502, which includes the IGTK for protecting the Management frame of a predetermined link during multilink communication. For example, if Data type is 18, it indicates MLO BIGTK KDE1503, which includes BIGTK for protecting Beacon frames on a predetermined link during multilink communication. If Data type is 20, it indicates CIGTK KDE1504. CIGTK KDE1504 is a KDE used during single-link communication, not multilink communication. The contents of CIGTK KDE1504 are the same as those of CIGTK KDE805 in Figure 8, so the explanation is omitted. If Data type is 21, it indicates MLO CIGTK KDE1505. MLO CIGTK KDE1505 includes CIGTK for protecting Control frames on a predetermined link during multilink communication. The MLO CIGTK KDE1505 includes a KeyID field 1510, a CIPN field 1511, a Reserved field 1512, a LinkID field 1513 that identifies the link, and a CIGTK 1514 which is the key for protecting the Control frame.

[0080] MLO GTK KDE1501, MLO IGTK KDE1502, MLO BIGTK KDE1503, and MLO CIGTK KDE1505 can be included in 3 frames of 4WHS messages or 1 frame of GKHS messages, depending on the number of links set up with MLO. This allows key information for protecting Control frames for multiple links to be delivered in a single frame at once, reducing communication overhead and improving communication efficiency. In Figure 15, MLO CIGTK KDE is used when Data type is 21, but other values ​​may be used as long as they can be distinguished from other KDEs.

[0081] As described above, in this embodiment, even when the communication device supports MLO, it is possible to efficiently notify information regarding the protection of Control frames. This makes it possible to distribute and generate key information used for protecting Control frames used in each link constituting the multilink communication, and to execute the Control frame protection process.

[0082] While exemplary embodiments are presented in the detailed description above, a vast number of variations may exist. The embodiments described above are examples and are not intended to limit in any way the scope, applicability, operation, or configuration of this disclosure. Various modifications may be made to the function and arrangement of the steps and operating methods described in the exemplary embodiments, as well as to the modules and structures of the communication and information processing devices described in the exemplary embodiments, without departing from the scope of the subject matter described in the appended claims.

[0083] The present invention can also be realized by supplying a program that implements one or more of the functions of the above-described embodiments to a system or device via a network or storage medium, and by having one or more processors in the computer of that system or device read and execute the program. It can also be realized by a circuit (for example, an ASIC) that implements one or more functions.

[0084] The invention is not limited to the embodiments described above, and various modifications and variations are possible without departing from the spirit and scope of the invention. Accordingly, claims are attached to disclose the scope of the invention.

[0085] This application claims priority based on Japanese Patent Application No. 2024-190174, filed on 29 October 2024, and all of its contents are incorporated herein by reference.

[0086] 101 AP 102 STA 301 Wireless LAN control unit 302 Frame generation unit 303 Frame analysis unit 304 UI ​​control unit 305 Storage unit

Claims

1. A communication device that functions as an access point performing wireless communication in accordance with the IEEE 802.11 standard series, comprising: a first transmitting means for transmitting a Beacon frame containing capability information of the communication device regarding support for protection of Control frames.

2. The communication device according to claim 1, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Element of the Beacon frame.

3. The communication device according to claim 1, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Extension Element of the Beacon frame.

4. A communication device according to any one of claims 1 to 3, comprising: a receiving means for receiving an Association Request frame from another communication device functioning as a station, which includes capability information of the other communication device regarding support for protection of Control frames; a first generating means for generating a frame containing key information necessary for protection of Control frames when the capability information of the communication device indicates that it supports protection of Control frames, and the capability information of the other communication device indicates that it supports protection of Control frames; and a second transmitting means for transmitting the frame containing the key information to the other communication device.

5. The communication device according to claim 4, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Element of the Association Request frame.

6. The communication device according to claim 4, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Extension Element of the Association Request frame.

7. The communication device according to any one of claims 4 to 6, characterized in that the capability information of the communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

8. The communication device according to any one of claims 4 to 7, characterized in that the capability information of the other communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and when the first information indicates that support for Control frame protection is essential and / or when the second information indicates that support for Control frame protection is possible, the other communication device supports Control frame protection.

9. The communication device according to any one of claims 4 to 8, characterized in that, when the communication device and the other communication device set up a multilink, the key information includes key information for protecting Control frames used in each link included in the multilink.

10. A communication device according to any one of claims 4 to 9, comprising: a second generation means for generating a code for detecting tampering with a Control frame based on the key information and the data of the Control frame to be transmitted, after transmitting a frame containing the key information; and a third transmission means for adding the code to the Control frame to be transmitted and transmitting it to the other communication device.

11. The communication device according to any one of claims 4 to 10, characterized in that the frame containing the key information is a 4-Way Handshake Message 3 frame.

12. The communication device according to any one of claims 4 to 10, characterized in that the frame containing the key information is a Group key handshake message 1 frame.

13. A communication device that functions as a station performing wireless communication in accordance with the IEEE 802.11 standard series, comprising: a first receiving means for receiving a Beacon frame from another communication device that functions as an access point, the Beacon frame containing capability information of the other communication device regarding support for protection of Control frames.

14. The communication device according to claim 13, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Element of the Beacon frame.

15. The communication device according to claim 13, characterized in that the capability information of the other communication device is included in the Robust Security Network (RSN) Extension Element of the Beacon frame.

16. A communication device according to any one of claims 13 to 15, comprising: a transmitting means for transmitting an Association Request frame containing capability information of the communication device regarding support for protection of Control frames; and a second receiving means for receiving a frame containing key information necessary for protection of Control frames from the other communication device when the capability information of the communication device indicates that it supports protection of Control frames, and the capability information of the other communication device indicates that it supports protection of Control frames.

17. The communication device according to claim 16, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Element of the Association Request frame.

18. The communication device according to claim 16, characterized in that the capability information of the communication device is included in the Robust Security Network (RSN) Extension Element of the Association Request frame.

19. The communication device according to any one of claims 16 to 18, characterized in that the capability information of the communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and the communication device indicates that it supports Control frame protection when the first information indicates that support for Control frame protection is essential and / or the second information indicates that support for Control frame protection is possible.

20. The communication device according to any one of claims 16 to 19, characterized in that the capability information of the other communication device includes first information indicating whether support for Control frame protection is essential and / or second information indicating whether support for Control frame protection is possible, and when the first information indicates that support for Control frame protection is essential and / or when the second information indicates that support for Control frame protection is possible, the other communication device supports Control frame protection.

21. The communication device according to any one of claims 16 to 20, characterized in that, when the communication device and the other communication device set up a multilink, the key information includes key information for protecting Control frames used in each link included in the multilink.

22. A communication device according to any one of claims 16 to 21, comprising: a third receiving means for receiving a Control frame containing a first code for detecting tampering with a Control frame generated based on the key information; a calculation means for calculating a second code for detecting tampering based on the key information and the data of the received Control frame; and a detection means for detecting whether the received Control frame has been tampered with by comparing the first code and the second code.

23. The communication device according to any one of claims 16 to 22, characterized in that the frame containing the key information is a 4-Way Handshake Message 3 frame.

24. The communication device according to any one of claims 16 to 22, characterized in that the frame containing the key information is a Group key handshake message 1 frame.

25. A communication method in a communication device that functions as an access point performing wireless communication in accordance with the IEEE 802.11 standard series, comprising: a transmission step of transmitting a Beacon frame containing capability information of the communication device regarding support for protection of Control frames.

26. A communication method in a communication device that functions as a station performing wireless communication in accordance with the IEEE 802.11 standard series, comprising: a first receiving step of receiving a Beacon frame from another communication device that functions as an access point, the Beacon frame containing capability information of the other communication device regarding support for protection of Control frames.

27. A program for operating a computer as a communication device according to any one of claims 1 to 12.

28. A program for causing a computer to operate as a communication device according to any one of claims 13 to 24.

Citation Information

Patent Citations

  • Apparatus, system, and method for prioritizing management frames of a wireless network.

    JP2013509133A

  • Communication method and station

    WO2023082209A1

  • Authentication method and apparatus, device, and storage medium

    WO2024026735A1