Electronic device for providing audio service, and operation method thereof

WO2026205952A1PCT designated stage Publication Date: 2026-10-01SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2026/004679
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-06-02
Filing Date
2026-03-24
Publication Date
2026-10-01

Smart Images

  • Figure KR2026004679_01102026_PF_FP_ABST
    Figure KR2026004679_01102026_PF_FP_ABST
Patent Text Reader

Abstract

According to one embodiment of the present disclosure, an electronic device (101) comprises: a communication circuit (190); one or more processors (120) including processing circuitry; and a memory (130) for storing instructions, wherein, when executed individually or collectively by the one or more processors, the instructions instruct the electronic device to: generate a first session key on the basis of a first broadcast code; use at least one broadcast isochronous stream (BIS) to transmit, through the communication circuit, first data encrypted on the basis of the first session key; identify an event for generating a second session key while transmitting the first data through the at least one BIS; identify, on the basis of the event, a second broadcast code to be used to generate the second session key, and an instant to which the second session key is to be applied; transmit, through the communication circuit, first information including the second broadcast code and second information related to the instant to which the second session key is to be applied, at least the second broadcast code included in the first information being encrypted using the first session key; generate the second session key on the basis of the second broadcast code; and, after transmitting the first information and the second information, use the at least one BIS to transmit, through the communication circuit, second data encrypted on the basis of the second session key from the instant. Other embodiments are possible.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic device providing audio services and method of operation thereof

[0001] The present disclosure relates to an electronic device for providing audio services and a method of operating the same.

[0002] With the recent advancement of information and communication technology, various wireless communication technologies and services are being developed. In particular, Bluetooth, one of the short-range communication methods, is being actively used, and electronic devices utilizing Bluetooth are also widely used. Specifically, a pair of earbuds that can be worn on each of a user's ears are widely used as ear-wearable devices. Ear-wearable devices can provide various functions. For example, an ear-wearable device can use a microphone to input and verify the user's voice, transmit audio data related to the user's voice to an electronic device (e.g., a smartphone), and use a speaker to output the audio data received from the electronic device.

[0003] Bluetooth methods may include Bluetooth legacy (or Bluetooth classic) methods and / or Bluetooth low energy (BLE) methods. An external electronic device (e.g., ear wearable device) providing low energy audio (LE Audio) services based on the BLE method can establish a communication link independently of an electronic device (e.g., smartphone) and transmit and / or receive data with the external electronic device through the established communication link.

[0004] Audio services based on the BLE method can be provided via a connection-based connected isochronous stream (CIS) or a non-connection-based broadcast isochronous stream (BIS). When audio services are provided via a CIS, electronic devices can receive audio services by establishing BLE links with each other and establishing CISs based on the established BLE links.

[0005] In contrast, when audio services are provided via BIS, electronic devices can receive audio services broadcast via BIS without establishing BLE links with each other. However, since BIS is based on a broadcast method, it may be impossible to transmit or receive encryption-related information through a secure channel when audio services are provided via BIS. Therefore, when audio services are provided via BIS, a broadcast source device can encrypt data based on an encryption key generated based on a broadcast code (e.g., a password) that applies commonly to multiple BIS channels (e.g., multiple audio channels), and broadcast sink devices can decrypt the data encrypted based on the broadcast code.

[0006] Broadcast codes can be configured, for example, through a user interface (UI), and because they are relatively short (e.g., 4 to 16 octets), they can be vulnerable to malicious security attacks. If broadcast codes are exposed to such malicious security attacks, not only can the transmission and reception of audio data for audio services be disrupted by an attacker, but the audio service itself can also be disrupted, such as by changing the channel map and / or terminating the BIG, if control data for audio services, such as a broadcast isochronous group (BIG) control protocol data unit (PDU), is transmitted by an attacker.

[0007] According to one embodiment of the present disclosure, an electronic device (101) may include a communication circuit (190), one or more processors (120) including a processing circuitry, and a memory (130) for storing instructions.

[0008] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by one or more processors, the electronic device may cause the first session key to be generated based on a first broadcast code.

[0009] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the first data encrypted based on the first session key to be transmitted through the communication circuit via at least one broadcast isochronous stream (BIS).

[0010] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause an event to be detected for generating a second session key while transmitting the first data through the at least one BIS.

[0011] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause, based on the event, to identify a second broadcast code to be used to generate the second session key and an instance to which the second session key will be applied.

[0012] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the first information including the second broadcast code and the second information associated with the instance to which the second session key is applied to be transmitted through the communication circuit.

[0013] According to one embodiment of the present disclosure, at least the second broadcast code included in the first information can be encrypted using the first session key.

[0014] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the second session key to be generated based on the second broadcast code.

[0015] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the second data encrypted based on the second session key from the instance to be transmitted through the at least one BIS via the communication circuit after transmitting the first information and the second information.

[0016] According to one embodiment of the present disclosure, a method of an electronic device (101) may include an operation of generating a first session key based on a first broadcast code.

[0017] According to one embodiment of the present disclosure, the method may include the operation of transmitting a first data encrypted based on the first session key through at least one broadcast isochronous stream (BIS).

[0018] According to one embodiment of the present disclosure, the method may include an operation of checking an event for generating a second session key while transmitting the first data through the at least one BIS.

[0019] According to one embodiment of the present disclosure, the method may include, based on the event, a second broadcast code to be used to generate the second session key and an operation to identify the instance to which the second session key will be applied.

[0020] According to one embodiment of the present disclosure, the method may include the operation of transmitting first information including the second broadcast code and second information associated with the instance to which the second session key is applied.

[0021] According to one embodiment of the present disclosure, at least the second broadcast code included in the first information can be encrypted using the first session key.

[0022] According to one embodiment of the present disclosure, the method may include the operation of generating the second session key based on the second broadcast code.

[0023] According to one embodiment of the present disclosure, the method may include, after transmitting the first information and the second information, transmitting second data encrypted based on the second session key from the instant through the at least one BIS.

[0024] According to one embodiment of the present disclosure, a storage medium for storing at least one instruction readable by a computer may be provided.

[0025] According to one embodiment of the present disclosure, the at least one instruction may cause the electronic device (101) to perform at least one operation when executed individually or collectively by one or more processors (120) including processing circuitry of the electronic device (101).

[0026] According to one embodiment of the present disclosure, the at least one operation may include an operation to generate a first session key based on a first broadcast code.

[0027] According to one embodiment of the present disclosure, the at least one operation may include transmitting the first data encrypted based on the first session key through at least one broadcast isochronous stream (BIS).

[0028] According to one embodiment of the present disclosure, the at least one operation may include checking an event for generating a second session key while transmitting the first data through the at least one BIS.

[0029] According to one embodiment of the present disclosure, the at least one operation may include, based on the event, a second broadcast code to be used to generate the second session key and an operation to identify the instance to which the second session key will be applied.

[0030] According to one embodiment of the present disclosure, the at least one operation may include transmitting first information including the second broadcast code and second information associated with the instance to which the second session key is to be applied.

[0031] According to one embodiment of the present disclosure, at least the second broadcast code included in the first information can be encrypted using the first session key.

[0032] According to one embodiment of the present disclosure, the at least one operation may include an operation to generate the second session key based on the second broadcast code.

[0033] According to one embodiment of the present disclosure, the at least one operation may include, after transmitting the first information and the second information, transmitting the second data encrypted based on the second session key from the instant through the at least one BIS.

[0034] FIG. 1 is a block diagram schematically illustrating an electronic device in a network environment according to one embodiment.

[0035] FIG. 2 is a schematic diagram illustrating connections between electronic devices based on the Bluetooth method in a wireless communication network according to one embodiment.

[0036] FIG. 3 is a block diagram schematically illustrating an external electronic device in a wireless communication network according to one embodiment.

[0037] Figure 4 is a diagram illustrating the format of BIGInfo.

[0038] FIG. 5 is a flowchart schematically illustrating the operation process of an electronic device according to one embodiment.

[0039] FIG. 6 is a diagram illustrating the operation of changing a session key in a wireless communication network according to one embodiment.

[0040] FIG. 7 is a diagram illustrating the operation of transmitting session key change information in a wireless communication network according to one embodiment.

[0041] FIG. 8 is a diagram illustrating the operation of transmitting encrypted BIS data based on a changed session key in a wireless communication network according to one embodiment.

[0042] FIG. 9 is a flowchart schematically illustrating the operation process of an electronic device according to one embodiment.

[0043] FIG. 10 is a diagram illustrating the operation of setting a session key change function for a BIS service in a wireless communication network according to one embodiment.

[0044] FIG. 11 is a diagram illustrating an operation to transmit information indicating whether a session key change function is supported for a BIS service in a wireless communication network according to one embodiment.

[0045] FIG. 12 is a diagram illustrating the operation of starting a BIS service in a wireless communication network according to one embodiment.

[0046] FIG. 13 is a diagram illustrating the operation of changing a session key in a wireless communication network according to one embodiment.

[0047] FIG. 14 is a diagram illustrating the operation of transmitting session key change information in a wireless communication network according to one embodiment.

[0048] FIG. 15 is a diagram illustrating the operation of transmitting session key change information in a wireless communication network according to one embodiment.

[0049] FIG. 16a is a diagram illustrating the operation of providing session key change information in the form of a UX in a wireless communication network according to one embodiment.

[0050] FIG. 16b is a diagram illustrating the operation of providing session key change information in the form of a UX in a wireless communication network according to one embodiment.

[0051] An embodiment of the present disclosure will be described in detail below with reference to the attached drawings. In describing an embodiment of the present disclosure, if it is determined that a detailed description of related known functions or configurations could unnecessarily obscure the essence of the embodiment, such detailed description will be omitted. Furthermore, the terms described below are defined considering the functions in an embodiment of the present disclosure, and these may vary depending on the intentions or conventions of the user or operator. Therefore, their definitions should be based on the content throughout this specification.

[0052] It should be noted that technical terms used in this specification are used merely to describe specific embodiments and are not intended to limit the embodiments of this disclosure. Alternatively, unless specifically defined otherwise in this specification, technical terms used in this specification shall be interpreted in the sense generally understood by those skilled in the art to which this disclosure pertains, and shall not be interpreted in an overly broad or overly narrow sense. Furthermore, if a technical term used in this specification is an incorrect technical term that fails to accurately express the spirit of this disclosure, it shall be understood as being replaced by a technical term that can be correctly understood by those skilled in the art. Alternatively, general terms used in an embodiment of this disclosure shall be interpreted according to their prior definitions or according to the context, and shall not be interpreted in an overly narrow sense.

[0053] Alternatively, singular expressions used in this specification include plural expressions unless the context clearly indicates otherwise. In this application, terms such as "composed of" or "comprising" should not be interpreted as necessarily including all of the various components or operations described in the specification, and should be interpreted as meaning that some of the components or operations may not be included, or that additional components or operations may be included.

[0054] Alternatively, terms including ordinal numbers, such as first, second, etc., as used herein may be used to describe various components, but said components shall not be limited by said terms. Such terms are used solely for the purpose of distinguishing one component from another. For example, without departing from the scope of the present disclosure, the first component may be named the second component, and similarly, the second component may be named the first component.

[0055] When it is stated that one component is "connected" or "connected" to another component, it may be directly connected or connected to that other component, or there may be other components in between. On the other hand, when it is stated that one component is "directly connected" or "directly connected" to another component, it should be understood that there are no other components in between.

[0056] Hereinafter, an embodiment according to the present disclosure will be described in detail with reference to the attached drawings. Identical or similar components regardless of drawing symbols are given the same reference number, and redundant descriptions thereof will be omitted. Alternatively, in describing an embodiment of the present disclosure, if it is determined that a detailed description of related prior art may obscure the essence of the present disclosure, such detailed description will be omitted. Furthermore, it should be noted that the attached drawings are intended only to facilitate an easy understanding of the concept of the present disclosure and should not be interpreted as limiting the concept of the present disclosure. The concept of the present disclosure should be interpreted as extending to all modifications, equivalents, and substitutions in addition to the attached drawings.

[0057] Hereinafter, in one embodiment of the present disclosure, an electronic device will be described, but the electronic device may be referred to as a terminal, mobile station, mobile equipment (ME), user equipment (UE), user terminal (UT), subscriber station (SS), wireless device, handheld device, or access terminal (AT). Alternatively, in one embodiment of the present disclosure, the electronic device may be a device equipped with communication functions, such as a mobile phone, personal digital assistant (PDA), smartphone, wireless modem, or laptop.

[0058] Alternatively, in specifically describing an embodiment of the present disclosure, reference will be made to the Bluetooth specifications defined by the Bluetooth Special Interest Group (SIG), but the main points of the present disclosure may be applied to other communication systems having similar technical backgrounds with slight modifications without significantly departing from the scope of the present disclosure, and this will be possible at the judgment of a person with technical knowledge skilled in the technical field of the present disclosure.

[0059] FIG. 1 is a block diagram schematically illustrating an electronic device (101) in a network environment (100) according to one embodiment.

[0060] Referring to FIG. 1, in a network environment (100), an electronic device (101) may communicate with an electronic device (102) through a first network (198) (e.g., a short-range wireless communication network) or with an electronic device (104) or a server (108) through a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) through a server (108). According to one embodiment, the electronic device (101) may include a processor (120), memory (130), input module (150), sound output module (155), display module (160), audio module (170), sensor module (176), interface (177), connection terminal (178), haptic module (179), camera module (180), power management module (188), battery (189), communication module (190), subscriber identification module (196), or antenna module (197). In some embodiments, at least one of these components (e.g., connection terminal (178)) may be omitted from the electronic device (101), or one or more other components may be added. In some embodiments, some of these components (e.g., sensor module (176), camera module (180), or antenna module (197)) may be integrated into a single component (e.g., display module (160)).

[0061] The processor (120) can control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) by executing software (e.g., a program (140)), and can perform various data processing or operations. According to one embodiment, as at least part of the data processing or operations, the processor (120) can store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in volatile memory (132), process the commands or data stored in volatile memory (132), and store the resulting data in non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or an auxiliary processor (123) that can operate independently or together with it (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor). For example, if the electronic device (101) includes a main processor (121) and an auxiliary processor (123), the auxiliary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a designated function. The auxiliary processor (123) may be implemented separately from the main processor (121) or as part thereof.

[0062] The auxiliary processor (123) may control at least some of the functions or states associated with at least one component of the electronic device (101) (e.g., display module (160), sensor module (176), or communication module (190)) on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. According to one embodiment, the auxiliary processor (123) (e.g., image signal processor or communication processor) may be implemented as part of another functionally related component (e.g., camera module (180) or communication module (190)). According to one embodiment, the auxiliary processor (123) (e.g., neural network processing unit) may include a hardware structure specialized for processing an artificial intelligence model. The artificial intelligence model may be generated through machine learning. Such learning may be performed, for example, on the electronic device (101) itself where the artificial intelligence is performed, or through a separate server (e.g., server (108)). The learning algorithm may include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model may include a plurality of artificial neural network layers.An artificial neural network may be a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to the hardware structure, the artificial intelligence model may include a software structure, either additionally or substantially.

[0063] The memory (130) can store various data used by at least one component of the electronic device (101) (e.g., processor (120) or sensor module (176)). The data may include, for example, input data or output data for software (e.g., program (140)) and related commands. The memory (130) may include volatile memory (132) or non-volatile memory (134).

[0064] The program (140) may be stored as software in memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0065] The input module (150) can receive commands or data to be used for a component of the electronic device (101) (e.g., processor (120)) from outside the electronic device (101) (e.g., user). The input module (150) may include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0066] The sound output module (155) can output a sound signal to the outside of the electronic device (101). The sound output module (155) may include, for example, a speaker or a receiver. The speaker may be used for general purposes, such as multimedia playback or recording playback. The receiver may be used to receive incoming calls. According to one embodiment, the receiver may be implemented separately from the speaker or as part thereof.

[0067] The display module (160) can visually provide information to an external (e.g., user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling said device. According to one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of the force generated by said touch.

[0068] The audio module (170) can convert sound into an electrical signal or, conversely, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150) or output sound through the sound output module (155) or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphones) connected directly or wirelessly to the electronic device (101).

[0069] The sensor module (176) can detect the operating state of the electronic device (101) (e.g., power or temperature) or the external environmental state (e.g., user state) and generate an electrical signal or data value corresponding to the detected state. According to one embodiment, the sensor module (176) may include, for example, a gesture sensor, a gyroscope sensor, a barometric pressure sensor, a magnetic sensor, an accelerometer sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biosensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0070] The interface (177) may support one or more specified protocols that can be used for the electronic device (101) to be connected directly or wirelessly to an external electronic device (e.g., electronic device (102)). According to one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0071] The connection terminal (178) may include a connector through which the electronic device (101) can be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0072] The haptic module (179) can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that the user can perceive through tactile or kinesthetic senses. According to one embodiment, the haptic module (179) may include, for example, a motor, a piezoelectric element, or an electric stimulation device.

[0073] The camera module (180) can capture still images and video. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0074] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least part of a power management integrated circuit (PMIC).

[0075] The battery (189) can supply power to at least one component of the electronic device (101). According to one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0076] The communication module (190) can support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between an electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may include one or more communication processors that operate independently of the processor (120) (e.g., application processor) and support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., cellular communication module, short-range wireless communication module, or GNSS (global navigation satellite system) communication module) or a wired communication module (194) (e.g., LAN (local area network) communication module, or power line communication module). The corresponding communication module among these communication modules can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, Wi-Fi (wireless fidelity) direct, or IrDA (infrared data association)) or a second network (199) (e.g., a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules may be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can identify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) using subscriber information (e.g., International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module (196).

[0077] The wireless communication module (192) can support 5G networks and next-generation communication technologies following 4G networks, for example, new radio access technology. NR access technology can support high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and connection of multiple terminals (massive machine type communications (mMTC)), or high reliability and low latency (ultra-reliable and low-latency communications (URLLC)). The wireless communication module (192) can support a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate, for example. The wireless communication module (192) can support various technologies for securing performance in the high-frequency band, such as beamforming, massive MIMO (multiple-input and multiple-output), full-dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large-scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), external electronic device (e.g., electronic device (104)), or network system (e.g., second network (199)). According to one embodiment, the wireless communication module (192) may support a Peak data rate (e.g., 20 Gbps or more) for eMBB realization, loss coverage (e.g., 164 dB or less) for mMTC realization, or U-plane latency (e.g., downlink (DL) and uplink (UL) each 0.5 ms or less, or round trip 1 ms or less) for URLLC realization.

[0078] An antenna module (197) can transmit a signal or power to or from an external source (e.g., an external electronic device). According to one embodiment, the antenna module (197) may include an antenna comprising a radiator made of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). According to one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as a first network (198) or a second network (199), may be selected from the plurality of antennas, for example, by a communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. According to some embodiments, in addition to the radiator, other components (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as part of the antenna module (197).

[0079] According to one embodiment, the antenna module (197) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent to a first surface (e.g., bottom surface) of the printed circuit board and capable of supporting a specified high frequency band (e.g., mmWave band), and a plurality of antennas (e.g., array antennas) disposed on or adjacent to a second surface (e.g., top surface or side surface) of the printed circuit board and capable of transmitting or receiving a signal of the specified high frequency band.

[0080] At least some of the above components can be connected to each other via a communication method between peripheral devices (e.g., bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)) and exchange signals (e.g., commands or data) with each other.

[0081] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) through a server (108) connected to a second network (199). Each of the external electronic devices (102, or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations performed on the electronic device (101) may be performed on one or more of the external electronic devices (102, 104, or 108). For example, if the electronic device (101) needs to perform a function or service automatically or in response to a request from a user or another device, the electronic device (101) may request one or more external electronic devices to perform at least part of the function or service instead of performing the function or service itself or additionally. One or more external electronic devices that receive the above request may execute at least part of the requested function or service, or additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may provide the result as is or additionally processed as at least part of the response to the request. For this purpose, for example, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used. The electronic device (101) may provide ultra-low latency services using, for example, distributed computing or mobile edge computing. In one embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server using machine learning and / or neural networks. According to one embodiment, the external electronic device (104) or the server (108) may be included within a second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0082] FIG. 2 is a schematic diagram illustrating connections between electronic devices based on the Bluetooth method in a wireless communication network according to one embodiment.

[0083] Referring to FIG. 2, an electronic device (101) (e.g., the electronic device (101) of FIG. 1) may be connected wirelessly and / or wired to a plurality of external electronic devices. A plurality of external electronic devices (e.g., the electronic device (102) or the electronic device (104) of FIG. 1) may include an external electronic device (200).

[0084] For example, the electronic device (101) may be a smartphone. The external electronic device (200) may be an ear-wearable device and / or a speaker. The external electronic device (200) may include a first earbud (e.g., left earbud) and / or a second earbud (e.g., right earbud).

[0085] In one embodiment, the electronic device (101) and the external electronic device (200) may provide an audio service based on a Bluetooth method. In one embodiment, the Bluetooth method may include a Bluetooth legacy (or Bluetooth classic) method and / or a Bluetooth low energy (BLE) method.

[0086] According to one embodiment, an electronic device (101) and an external electronic device (200) may establish a connection (e.g., a communication link) with each other and transmit and / or receive data to each other through the established connection. For example, the electronic device (101) and the external electronic device (200) may establish a communication link based on at least one of a Wi-Fi method and / or a Bluetooth method, but the method by which the electronic device (101) and the external electronic device (200) establish a communication link is not limited to only at least one of a Wi-Fi method and / or a Bluetooth method.

[0087] According to one embodiment, the electronic device (101) can operate as a broadcast source device.

[0088] In one embodiment, the external electronic device (200) can operate as a broadcast sink device.

[0089] According to one embodiment, an electronic device (101) that is a broadcast source device can transmit synchronization information (SyncInfo) at the start of a broadcast isochronous stream (BIS) service. In one embodiment, the synchronization information (SyncInfo) can be transmitted via an AUX_ADV_IND protocol data unit (PDU) transmitted based on extended advertising (EA).

[0090] According to one embodiment, an external electronic device (200) can perform a scan operation to obtain synchronization information (SyncInfo) contained in an AUX_ADV_IND PDU transmitted from an electronic device (101). Based on the obtained synchronization information (SyncInfo), the external electronic device (200) can receive BIG information (BIGInfo), which is information related to a broadcast isochronous group (BIG), through periodic advertising (PA) performed by the electronic device (101). In one embodiment, BIGInfo may be included in an additional controller advertising data (ACAD) field included in an auxiliary synchronization indication (AUX_SYNC_IND) PDU. A detailed description of the AUX_SYNC_IND PDU and BIGInfo is specified in the Bluetooth Core Specification v6.0 provided by the Bluetooth SIG's Core Specification Working Group; therefore, redundant explanations will be omitted here.

[0091] An external electronic device (200) that receives BIGInfo can synchronize with BIS provided by the electronic device (101) based on BIGInfo, receive audio data through the synchronized BIS, and output the received audio data.

[0092] In FIG. 2, the case in which an electronic device (101) and an external electronic device (200) establish a connection is described as an example, but the electronic device (101) can establish a connection not only with the external electronic device (200) but also with at least one other external electronic device.

[0093] FIG. 3 is a block diagram schematically illustrating an external electronic device in a wireless communication network according to one embodiment.

[0094] Referring to FIG. 3, an external electronic device (200) (e.g., the electronic device (102) of FIG. 1, or the external electronic device (200)) may be a device that implements a Bluetooth method (e.g., Bluetooth legacy method, and / or BLE method). The external electronic device (200) may include a communication circuit (302) that transmits and / or receives signals using one or more antennas (301) with an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2), for example, a peer device and / or other external electronic device.

[0095] The external electronic device (200) may include a processor (304) comprising processing circuitry that can be implemented with one or more single-core processors or one or more multi-core processors, and a memory (306) that stores instructions for the operation of the external electronic device (200).

[0096] The external electronic device (200) may include an interface module (308) that provides a wired and / or wireless interface for communicating with components outside the network.

[0097] According to one embodiment, the external electronic device (200) may include a plurality of communication circuits, one of which may be a communication circuit based on a Wi-Fi method, and another of which may be a communication circuit based on a Bluetooth method, for example, a BLE method. According to one embodiment, the plurality of communication circuits may include a communication circuit (302), and the communication circuit (302) may be a communication circuit based on a Wi-Fi method or a communication circuit based on a BLE method.

[0098] According to one embodiment, the external electronic device (200) may not separately include a communication circuit based on the Wi-Fi method and a communication circuit based on the BLE method, but may include a single communication circuit capable of supporting both the Wi-Fi method and the BLE method. According to one embodiment, the single communication circuit capable of supporting both the Wi-Fi method and the BLE method may be the communication circuit (302).

[0099] Bluetooth methods may include Bluetooth legacy (or Bluetooth classic) methods and / or Bluetooth low energy (BLE) methods. An electronic device providing audio services based on the BLE method (e.g., electronic device (101) of FIG. 1 or FIG. 2) (e.g., a smartphone) may independently establish a connection (e.g., a communication link) with each of a plurality of external electronic devices (e.g., electronic device (102) or electronic device (104) of FIG. 1, or external electronic device (200) of FIG. 2), and transmit and / or receive data with the plurality of external electronic devices through the established connection.

[0100] Figure 4 is a diagram illustrating the format of BIGInfo.

[0101] Referring to FIG. 4, BIGInfo may be included in the ACAD field of the AUX_SYNC_IND PDU transmitted during PA operation. The length of BIGInfo may be 33 octets for unencrypted BIG and 57 octets for encrypted BIG.

[0102] In one embodiment, the BIG_Offset field contains the time from the beginning of the packet containing BIGInfo to the BIG anchor point described by BIGInfo. The value of the BIG_Offset field is a time unit indicated by the BIG_Offset_Units bit, and the actual time offset can be determined by multiplying the value of BIG_Offset by the time unit indicated by the BIG_Offset_Units bit. The time offset may be greater than 600 μs.

[0103] In one embodiment, when the BIG_Offset_Units bit is set, the time unit indicated by the BIG_Offset_Units bit is 300 μs, and when the BIG_Offset_Units bit is not set, the time unit indicated by the BIG_Offset_Units bit may be 30 μs. The BIG_Offset_Units bit may not be set when the time offset is less than 491,460 μs.

[0104] In one embodiment, the BIG anchor point may not be earlier than the time offset and may not be later than one unit after the start of the associated packet.

[0105] In one embodiment, the ISO_Interval field may indicate the time between two adjacent BIG anchor points and may be in units of 1.25 ms. The value of the ISO_Interval field may be between 4 and 3200 (i.e., between 5 ms and 4 s).

[0106] In one embodiment, the NSE (number of subevent) field may indicate the number of subevents per BIS in each BIG event. The value of the NSE field may be between 1 and 31 and may be an integer multiple of BN.

[0107] In one embodiment, the BN field, PTO field, and IRC field can control which data is transmitted in each BIG event. The value of the BN field may be between 1 and 7, the value of the PTO field may be between 0 and 15, and the value of the IRC field may be between 1 and 15.

[0108] In one embodiment, the Sub_Interval field may indicate the time between the start of two consecutive sub-events of each BIS, and may be in microseconds.

[0109] In one embodiment, the BIS_Spacing field may indicate the time between the start of corresponding sub-events in adjacent BISs in the BIG, and may be in microseconds. Additionally, if a control sub-event exists, the BIS_Spacing field may indicate the time between the start of the first sub-event of the last BIS and the start of the control sub-event, and may be in microseconds.

[0110] In one embodiment, the Num_BIS field may indicate the number of BISs in BIG.

[0111] In one embodiment, the Max_PDU field may indicate the maximum number of data octets (including, if necessary, a message integrity check (MIC)) that can be transmitted in each BIS data PDU in the BIG. The value of the Max_PDU field may be between 1 and 251 octets.

[0112] In one embodiment, the SeedAccessAddress field may indicate a seed access address (SAA) for the BIG. The access address for the BIS may be derived from the SAA and may be a random number satisfying the following conditions.

[0113] SAA 19 = SAA 15

[0114] SAA 22 = SAA 16 ≠ SAA 15

[0115] SAA 25 = 0

[0116] SAA 23 = 1

[0117] For any pair of BIGs transmitted by the same device, SAA 15 to SSA 0 may differ in at least two bits.

[0118] In one embodiment, the SDU_Interval field may be a value between 0x0000FF and 0x0FFFFF, and may be in microseconds.

[0119] In one embodiment, the Max_SDU field may indicate the maximum size of a service data unit (SDU) in a BIG. The value of the Max_SDU field may be between 1 and 4095 octets.

[0120] In one embodiment, the BaseCRCInit field may indicate a BaseCRCInit value. For every broadcast isochronous PDU, a shift register included in the cyclic redundancy check (CRC) generator may be pre-set to a BaseCRCInit value from the BIGInfo data of the top two octets and a BIS_Number for a specific BIS of the bottom octet.

[0121] In one embodiment, the ChM field may include a channel map indicating used and unused data channels. All channels are represented by bits placed according to a data channel index, where the least significant bit (LSB) represents data channel index 0 and the bit at position 36 represents data channel index 36. A bit value of 0 indicates that the channel is not in use, and a bit value of 1 indicates that the channel is in use. Bits at positions 37, 38, and 39 may be reserved for future use.

[0122] In one embodiment, the PHY field may indicate the PHY used by BIG, and the value of the PHY field may be as shown in Table 1 below.

[0123]

[0124]

[0125] In one embodiment, the bisPayloadCount field may be used for the first sub-event of the BIG event indicated by the BIG_Offset field. For each BIS, the payloads may be numbered starting from 0 in the provided order. This number may be used as the value of the bisPayloadCounter for the PDU containing the corresponding payload, for example, as the field value of the bisPayloadCount field.

[0126] In one embodiment, the Framing field can be set when the BIG transmits framed data.

[0127] In one embodiment, if BIG is encrypted, the group initialization vector (GIV) field may contain GIV parameters. For example, the GIV parameters may be 64-bit parameters.

[0128] In one embodiment, if BIG is encrypted, the GSKD field may include a GSKD parameter. For example, the GSKD parameter may be a 128-bit parameter.

[0129] In one embodiment, a session key used to encrypt audio data transmitted via BIS may be generated based on a broadcast code, GIV parameters, and GSKD parameters. In one embodiment, to change the session key, the broadcast code may be changed, or at least one of the broadcast code, GIV parameters, and GSKD parameters may be changed. A detailed description of BIGInfo is specified in Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group; therefore, redundant descriptions are omitted here.

[0130] Meanwhile, the BIG control procedure may be used for a broadcast source device to transmit information related to the BIG, such as BIGInfo, to a broadcast sink device. In each BIG control procedure, a single BIG control PDU may be transmitted during a control sub-event included in the BIG event. Each BIG control PDU needs to be transmitted during a set number (e.g., 6) of consecutive BIG events, and may be transmitted during other BIG events after the set number of consecutive BIG events. The other BIG events after the set number of consecutive BIG events may not need to be consecutive. The BIG control procedure may be terminated when the BIG control PDU is retransmitted for the last time. For a given BIG, only one BIG control procedure may be performed at a time.

[0131] In one embodiment, the BIS PDU may be a BIS data PDU or a BIG control PDU. The BIS data PDU may be used to transmit isochronous data, and the BIG control PDU may be used to transmit control information for the BIG.

[0132] In one embodiment, the header field included in the BIS PDU may be implemented as, for example, 16 bits and may be represented as shown in Table 2 below, and the logical link identifier (LLID) field, control subevent sequence number (CSSN) field, control subevent transmission flag (CSTF) field, RFU (reserved for future use) field, and length field may be represented as shown in Table 3 below.

[0133] Table 2

[0134]

[0135] Table 3

[0136]

[0137] A detailed description of the format of the BIS PDU header fields is specified in the Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group; therefore, redundant explanations will be omitted here.

[0138] The format of the payload field included in the BIG control PDU can be expressed as shown in Table 4 below.

[0139] Table 4

[0140]

[0141] The field value of the length field included in the header field of the BIG control PDU does not need to be set to, for example, "0b00000000". The Opcode field can be used to identify the type of the BIG control PDU as shown in Table 5 below.

[0142] Table 5

[0143]

[0144] The control data (CtrData) field included in the BIG control PDU can be specified by the Opcode field, and the length of the control data field for a given Opcode can be fixed.

[0145] If a Broadcast Sink Device receives an unsupported or RFU BIG control PDU, it may ignore the received unsupported or RFU BIG control PDU. Additionally, if a Broadcast Sink Device receives a BIG control PDU where the field value of the length field is invalid or the control data field is invalid, it may apply implementation-specific interpretations to the data. For example, implementation-specific interpretations may be applied, such as ignoring additional data if the length corresponding to the value set in the length field is too long, or using the nearest allowed value if the field value of the control data field falls outside the set range. If such procedures are not continued, the received BIG control PDU may be ignored.

[0146] In one embodiment, when the type of the BIG control PDU is BIG_CHANNEL_MAP_IND PDU, the control data field can be represented as shown in Table 6 below.

[0147] Table 6

[0148]

[0149] In Table 6, the ChM field may be set to a channel map indicating the data channels in use and the data channels not in use, and the Instant field may be set to a value indicating the time when the channel map set in the ChM field is to be implemented. In one embodiment, the Instant field may be set to a value of bigEventCounter corresponding to the time when the channel map set in the ChM field is to be implemented. A BIG channel map update procedure may be used to transmit a new channel map for all BISs included in the BIG. A broadcast source device may initiate the BIG channel map update procedure by transmitting a BIG_CHANNEL_MAP_IND PDU. The broadcast source device may not need to initiate the next instance of the BIG channel map update procedure until the value of a counter corresponding to the Instant field included in the control data field, e.g., bigEventCounter, is passed. In one embodiment, bigEventCounter may be implemented as, for example, a 39-bit counter, and each BIG may have a bigEventCounter associated with each BIG. bigEventCounter is set to "0" for the first BIG event of the BIG and can be incremented by 1 for each BIG. The broadcast source device and the broadcast sink device may need to use a new channel map from the point in time corresponding to the field value of the Instant field. In one embodiment, the broadcast source device needs to update the ChM field of BIGInfo and transmit the updated BIGInfo at the nearest future periodic advertising event on the relevant periodic advertising train.

[0150] In one embodiment, when the type of the BIG control PDU is BIG_TERMINATE_IND PDU, the control data field can be represented as shown in Table 7 below.

[0151] Table 7

[0152]

[0153] In Table 7, the Reason field can be used to inform the broadcast sink device why the BIG is being terminated, and the Instant field can be set to a value indicating the time when the BIG is to be terminated. In one embodiment, the Instant field can be set to a value of bigEventCounter corresponding to the time when the BIG is to be terminated. The BIG termination procedure can be used to notify all broadcast sink devices associated with the BIG that the BIG is being terminated. The broadcast source device can initiate the BIG termination procedure by sending a BIG_TERMINATE_IND PDU. The broadcast source device can terminate the BIG at the time corresponding to the Instant field (e.g., terminate the sending operation in the BIG events) and return to a standby state.

[0154] As explained above, since BIS corresponds to a connectionless-based audio service, it offers the advantage of allowing multiple users to easily broadcast audio data. However, because BIS is based on a broadcast method, it may be impossible to transmit or receive encryption-related information through a secure channel when audio services are provided via BIS. Therefore, when audio services are provided via BIS, the broadcast source device encrypts data based on an encryption key generated based on a broadcast code commonly applied to multiple BIS channels (e.g., multiple audio channels), and the broadcast sink devices can decrypt the data encrypted based on the broadcast code, thereby guaranteeing security above a configured level.

[0155] However, broadcast codes can be set based on, for example, a password entered through a user interface (UI), and because they are relatively short (e.g., 4 to 16 octets), they can be vulnerable to malicious security attacks. The password may also be referred to as a "Bluetooth privacy code" considered at the UI level. At the UI level, the broadcast code needs to be represented as a character sequence of at least 4 octets for PINUI. PINUI can be a character representation of a personal identification number (PIN) entered at the UI level.

[0156] Thus, if the broadcast code is exposed to malicious security attacks, not only can the transmission and reception of audio data for audio services be disrupted by an attacker, but if control data for audio services, such as BIG control PDUs, is transmitted by the attacker, the audio service itself may be disrupted, such as by changing the channel map or / or terminating the BIG. Currently, since the Bluetooth Core Specification provided by the Bluetooth SIG's Core Specification Working Group makes it impossible to change the session key while audio services are provided via BIS, if the broadcast code is exposed, a malicious attacker can derive the session key through the exposed broadcast code, making it impossible to avoid malicious attacks on audio services via BIS.

[0157] Accordingly, the present disclosure proposes a method in which a broadcast source device can provide an enhanced security level by periodically changing a session key. In this way, when the broadcast source device periodically changes the session key, the BIS channel (e.g., audio channel) can be protected from malicious attackers even if audio services are provided through BIS, and thus an enhanced security level can be provided.

[0158] Additionally, in the present disclosure, information related to a session key that is periodically changed is shared only with broadcast sink devices (e.g., synchronized receivers) synchronized with a broadcast source device (e.g., an isochronous broadcaster), thereby ensuring a secure session key change.

[0159] According to one embodiment of the present disclosure, an electronic device (101) may include a communication circuit (190), one or more processors (120) including a processing circuitry, and a memory (130) for storing instructions.

[0160] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by one or more processors, the electronic device may cause the first session key to be generated based on a first broadcast code.

[0161] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the first data encrypted based on the first session key to be transmitted through the communication circuit via at least one broadcast isochronous stream (BIS).

[0162] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause an event to be detected for generating a second session key while transmitting the first data through the at least one BIS.

[0163] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause, based on the event, to identify a second broadcast code to be used to generate the second session key and an instance to which the second session key will be applied.

[0164] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the first information including the second broadcast code and the second information associated with the instance to which the second session key is applied to be transmitted through the communication circuit.

[0165] According to one embodiment of the present disclosure, at least the second broadcast code included in the first information can be encrypted using the first session key.

[0166] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the second session key to be generated based on the second broadcast code.

[0167] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the second data encrypted based on the second session key from the instance to be transmitted through the at least one BIS via the communication circuit after transmitting the first information and the second information.

[0168] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the first information and the second information to be included in a BIG control protocol data unit (PDU) for a broadcast isochronous group (BIG) comprising the at least one BIS as at least part of the operation of transmitting the first information and the second information.

[0169] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the BIG control PDU to be transmitted through the communication circuit as at least part of the operation of transmitting the first information and the second information.

[0170] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the BIG control PDU to encrypt the BIG control PDU based on the first session key as at least part of the operation of transmitting the BIG control PDU.

[0171] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the encrypted BIG control PDU to be transmitted through the communication circuit as at least part of the operation of transmitting the BIG control PDU.

[0172] According to one embodiment of the present disclosure, the BIG control PDU may include information indicating that the type of the BIG control PDU is a BIG control PDU for changing a session key.

[0173] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the first group initialization vector (GIV) parameter and the second group session key derivation (GSKD) parameter used to encrypt the first data, and the first session key based on the first broadcast code, as at least part of the operation of generating the first session key based on the first broadcast code.

[0174] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the second GIV parameter and the second GSKD parameter used to encrypt the second data, and the second session key based on the second broadcast code, as at least part of the operation of generating the second session key based on the second broadcast code.

[0175] According to one embodiment of the present disclosure, the second GIV parameter may be the same as or different from the first GIV parameter.

[0176] According to one embodiment of the present disclosure, the second GSKD parameter may be the same as or different from the first GSKD parameter.

[0177] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the second GIV parameter and the second GSKD parameter to be included in a periodic advertising (PA) protocol data unit (PDU).

[0178] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the PA PDU to encrypt based on the first session key or a third session key prior to the first session key.

[0179] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the encrypted PA PDU to be transmitted through the communication circuit before transmitting the first information and the second information.

[0180] According to one embodiment of the present disclosure, the first broadcast code may include at least one of a code generated based on user input for starting a BIS service or a random code.

[0181] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the first information and the second information to be transmitted repeatedly a set number of times through the communication circuit before reaching the instance after transmitting the first information and the second information.

[0182] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause the electronic device to set a session key change function for changing the first session key to the second session key.

[0183] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by one or more processors, the electronic device may cause the electronic device to transmit information indicating whether the session key change function is supported through the communication circuit.

[0184] According to one embodiment of the present disclosure, when the instructions are executed individually or collectively by the one or more processors, the electronic device may cause information related to the second broadcast code used to generate the second session key.

[0185] FIG. 5 is a flowchart schematically illustrating the operation process of an electronic device according to one embodiment.

[0186] Referring to FIG. 5, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) (e.g., one or more processors including a processing circuit) (e.g., the processor (120) of FIG. 1) can generate a first session key based on a first broadcast code in operation 511. In one embodiment, the session key may include an encryption key used to encrypt data transmitted through the BIS (e.g., isochronous data) (e.g., audio data and / or control data). In one embodiment, the BIS may be a logical transport that enables the electronic device to transmit isochronous data. In one embodiment, the first session key may be used to encrypt the first data transmitted through at least one BIS. In one embodiment, at least one BIS may be included in the same BIG. In one embodiment, the first broadcast code may include a code (e.g., password) generated based on user input (e.g., user input in the form of text, voice, touch, and / or image) to initiate the BIS service, or a random code. Here, the random code may include a random code generated by the electronic device. In one embodiment, the electronic device obtains a password to initiate the BIS service and, based on the obtained password A first broadcast code to be applied to the BIS service can be generated. Here, the password can be generated based on user input. In one embodiment, the electronic device can obtain the password through a UI on a display module (e.g., the display module (160) of FIG. 1) or through a QR (quick response) code.In one embodiment, the electronic device may generate a broadcast code using a password based on a Bluetooth standard, for example, Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group, and thus redundant description thereof may be omitted. In one embodiment, the operation of generating a first session key based on the first broadcast code may include the operation of generating a first session key based on the first broadcast code, a first group initialization vector (GIV) parameter, and a first group session key derivation (GSKD) parameter.

[0187] The electronic device that generated the first session key can, in operation 513, transmit the first data (e.g., first isochronous data) (e.g., BIS audio data) encrypted based on the first session key through at least one BIS via a communication circuit (e.g., communication module (190) of FIG. 1).

[0188] While the electronic device is transmitting the first data encrypted based on the first session key through at least one BIS, in operation 515, it may detect an event for generating a second session key different from the first session key. In one embodiment, the second session key may be used to encrypt the second data (e.g., BIS audio data) transmitted through at least one BIS. The event for generating the second session key may be referred to as an "event for changing the session key." In one embodiment, the event for changing the session key may include an event in which a set time elapses, an event in which user input requesting to change the session key is acknowledged, and / or an event in which the audio type of the BIS data is changed. The BIS data may represent data transmitted through the BIS. In one embodiment, the event in which a set time elapses may include an event in which a set time elapses from the instant (or point in time) in which the session key (e.g., the first session key) is applied. In one embodiment, the session key may be changed periodically based on an event in which a set time elapses. In one embodiment, the first session key may represent a session key currently in use, and the second session key may represent a new session key different from the first session key, which is an existing session key.

[0189] An electronic device that has identified an event for generating a second session key may, in operation 517, identify a second broadcast code to be used to generate the second session key and an instance to which the second session key will be applied. In one embodiment, the operation of identifying a second broadcast code to be used to generate the second session key and an instance to which the second session key will be applied may include a second broadcast code to be used to generate the second session key, a second GIV parameter and / or a second GSKD parameter, and an operation of identifying an instance to which the second session key will be applied. The electronic device may generate the second session key by changing only the broadcast code from the first broadcast code to the second broadcast code, but may also generate the second session key by changing the GIV parameter and / or GSKD parameter from the first GIV parameter and / or the first GSKD parameter to the second GIV parameter and / or the second GSKD parameter.

[0190] An electronic device that has identified a second broadcast code to be used to generate a second session key and an instance to which the second session key will be applied may, in operation 521, transmit, through a communication circuit, first information including the second broadcast code and second information related to the instance to which the second session key will be applied. In one embodiment, the second broadcast code included in the first information may be encrypted using the first session key. In one embodiment, the electronic device may transmit the first information and the second information through a BIG control PDU used to transmit control information in a BIG that includes at least one BIS. In one embodiment, the electronic device may encrypt a BIG control PDU including the first information and the second information based on the first session key and transmit the encrypted BIG control PDU. In one embodiment, the BIG control PDU may further include information indicating that the type of the BIG control PDU is a BIG control PDU for changing the session key (e.g., for changing the session key from the first session key to the second session key). In operation 517, when the electronic device changes the first GIV parameter and / or the first GSKD parameter to the second GIV parameter and / or the second GSKD parameter to generate a second session key, the BIG control PDU may further include the second GIV parameter and / or the second GSKD parameter.

[0191] The electronic device that transmitted the first information and the second information may, in operation 521, generate a second session key based on the second broadcast code. In one embodiment, the operation of generating a second session key based on the second broadcast code may include the operation of generating a second session key based on the second broadcast code and the second GIV parameter and / or the second GSKD parameter. The electronic device that generated the second session key may, in operation 523, transmit a second data (e.g., second isochronous data) encrypted based on the second session key generated based on the second broadcast code through a communication circuit from the instance where the second session key is applied, via at least one BIS. Here, the at least one BIS to which the second data encrypted based on the second session key is transmitted may be the same as the at least one BIS to which the first data encrypted based on the first session key is transmitted. In one embodiment, the electronic device may provide (or output) information (e.g., a password) associated with a second broadcast code used to generate a second session key. By providing information associated with the second broadcast code in this way, it becomes possible for a user to verify information associated with the second broadcast code.

[0192] Meanwhile, in FIG. 5, an example was described in which the session key is changed from the first session key to the second session key when an event to change the session key is detected without the electronic device separately performing an operation to set a session key change function to change the session key from the first session key to the second session key; however, the operation to change the session key as described in FIG. 5 may also be performed when the session key change function is set.

[0193] FIG. 6 is a diagram illustrating the operation of changing a session key in a wireless communication network according to one embodiment.

[0194] Referring to FIG. 6, the electronic device (101) (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster), and the external electronic device (200) (e.g., the electronic device (102) of FIG. 1 or the external electronic device (200) of FIG. 2) may operate as a broadcast sink device (or synchronized receiver). The electronic device (101) may transmit BISs (or encrypted BIS channels) containing encrypted BIS data (e.g., audio data), and the external electronic device (200) may acquire a broadcast code and be synchronized with the BISs provided by the electronic device (101).

[0195] In one embodiment, the electronic device (101) may generate a session key based on a broadcast code according to the user's intent and / or the implementation of the Bluetooth stack / application. In one embodiment, the session key may include an encryption key used to encrypt data transmitted through the BIS (e.g., audio data and / or control data). Hereinafter, for convenience of explanation, data transmitted through the BIS will be referred to as "BIS data." The electronic device (101) may transmit (e.g., broadcast) BIGInfo containing information related to services provided through the BIS (e.g., audio services) and / or encryption. After encrypting the BIS data based on the session key, the electronic device (101) may broadcast the encrypted BIS data through the BIS.

[0196] In one embodiment, the electronic device (101) may determine whether to change the session key based on user input, PHY, frequency band, audio type, and / or SW implementation. In one embodiment, the electronic device (101) may decide to change the session key when an event to change the session key is detected. In one embodiment, the event to change the session key may include an event where a set time elapses, an event where user input requesting to change the session key is detected, and / or an event where the audio type of the BIS data is changed. For example, the session key may be changed periodically, or changed by a user request, or when the audio type of the data transmitted from the BIS is changed.

[0197] In one embodiment, an electronic device (101) that decides to change the session key may change the session key from the existing session key to a new session key and transmit information related to the session key change through a secure channel. In one embodiment, the secure channel may be an encrypted BIS channel already in use by the electronic device (101) and external electronic devices (e.g., external electronic device (200)), a separate encrypted PA signal, and / or a communication link established between the electronic device (101) and each of the external electronic devices. In one embodiment, information related to the session key change may be transmitted through a BIG control PDU. Hereinafter, for convenience of explanation, information related to the session key change will be referred to as "session key change information."

[0198] In one embodiment, the session key change information may include a new broadcast code used to generate a new session key, and information related to the instance (e.g., time) to which the new session key is to be applied. The electronic device (101) may encrypt BIS data based on the new session key from that instance and transmit the encrypted BIS data through the BIS (e.g., broadcast).

[0199] In one embodiment, an external electronic device (200) can receive a PA signal broadcast from an electronic device (101) through a secure channel and synchronize with a BIS broadcast from the electronic device (101), generate a session key based on the broadcast code of the electronic device (101), and decrypt encrypted BIS data received through the BIS based on the generated session key. In this way, while receiving a service (e.g., audio service) through the BIS, information related to a new session key (e.g., session key change information) transmitted from the electronic device (101) through the secure channel can be received. Upon receiving information related to a new session key from the electronic device (101), the external electronic device (200) can decrypt encrypted BIS data based on the new session key starting from that instance.

[0200] As illustrated in FIG. 6, the electronic device (101) can detect an event to change the session key while broadcasting BIS data through the BIS. Upon detecting the event to change the session key, the electronic device (101) can decide to change the session key in operation 611 and thus change the session key from the existing session key to a new session key.

[0201] The electronic device (101) that has changed the session key may transmit information related to the new session key (e.g., session key change information) through a secure channel in operations 613 and 615. For example, the session key change information may be transmitted via a BIG control PDU. Thus, external electronic devices (e.g., external electronic device (200)) may receive the session key change information transmitted by the electronic device (101). In FIG. 6, an example is illustrated in which the external electronic device (200) is an ear bud and includes a first ear bud (e.g., left ear bud) and a second ear bud (e.g., right ear bud), so that operations 613 and 615 may be performed.

[0202] The electronic device (101) that transmitted the session key change information can, in operation 617, encrypt BIS data based on the new session key from the corresponding instance and transmit (or broadcast) the encrypted BIS data through the BIS.

[0203] The external electronic device (200) can decrypt encrypted BIS data received via BIS from the corresponding instance in operations 619 and 621 based on a new session key.

[0204] FIG. 7 is a diagram illustrating the operation of transmitting session key change information in a wireless communication network according to one embodiment.

[0205] Referring to FIG. 7, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). In one embodiment, when an event to change the session key is detected, the electronic device may decide to change the session key used to encrypt BIS data. The electronic device that decides to change the session key may determine a new broadcast code to be used to derive the new session key and an instance to which the new session key will be applied. The electronic device may transmit (e.g., broadcast) information related to the session key change, including information related to the new broadcast code and the instance to which the new session key will be applied, via a BIG control PDU. Hereinafter, for convenience of explanation, "information related to the session key change" will be referred to as "session key change information."

[0206] As illustrated in FIG. 7, the electronic device can transmit BIS audio data in BIS sub-events (711, 713, 715, 717, 721, 723, 725, 727, 731, 733, 735, 737) and transmit session key change information in control sub-events (719, 729, 739). Thus, as the electronic device transmits session key change information, an external electronic device acting as a broadcast sink device (or synchronized receiver) (e.g., the electronic device (102) of FIG. 1, or the external electronic device (200) of FIG. 2) can receive the session key change information and, based on the received session key change information, can decrypt the encrypted BIS data received in the BIS sub-events from the instance where the new session key is applied.

[0207] FIG. 7 illustrates a case where BIS sub-events (711, 713, 715, 717, 721, 723, 725, 727, 731, 733, 735, 737) are arranged based on an interleaved arrangement. In FIG. 7, BIS audio data transmitted in the BIS1 event is represented as "BIS1 Audio," BIS audio data transmitted in the BIS2 event is represented as "BIS2 Audio," and session key change information transmitted in the control sub-event is represented as "New session key info." Additionally, since session key change information is included in BIG control information, BIG control information transmitted in the control sub-event is represented as "BIG Control" in FIG. 7. BIG control information represents control information transmitted from the BIG and can be transmitted via a BIG control PDU.

[0208] FIG. 8 is a diagram illustrating the operation of transmitting encrypted BIS data based on a changed session key in a wireless communication network according to one embodiment.

[0209] Referring to FIG. 8, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). In one embodiment, the electronic device may decide to change the session key used to encrypt BIS data when an event to change the session key is detected. The electronic device that decides to change the session key may determine a new broadcast code to be used to derive the new session key and an instance to which the new session key will be applied. The electronic device may transmit (e.g., broadcast) session key change information containing information related to the new broadcast code and the instance to which the new session key will be applied via a BIG control PDU.

[0210] As illustrated in FIG. 8, the electronic device can transmit BIS audio data in BIS sub-events (810, 820, 830, 840, 850, 860) and transmit session key change information in control sub-events (811, 821, 831, 841, 851, 861). Thus, as the electronic device transmits session key change information, an external electronic device acting as a broadcast sink device (or synchronized receiver) (e.g., the electronic device (102) of FIG. 1, or the external electronic device (200) of FIG. 2) can receive the session key change information.

[0211] Then, the electronic device can transmit encrypted BIS data in BIS sub-events (881, 882, 883, 884, 885, 886) by applying the new session key from the instance (870) where the new session key is applied, and the external electronic device can decrypt the encrypted BIS data received in BIS sub-events (881, 882, 883, 884, 885, 886) based on the session key change information received from the instance (870) where the new session key is applied.

[0212] FIG. 9 is a flowchart schematically illustrating the operation process of an electronic device according to one embodiment.

[0213] Referring to FIG. 9, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) (e.g., one or more processors including a processing circuit) (e.g., the processor (120) of FIG. 1) may, in operation 911, detect an event to start (or perform) a BIS service and set basic information associated with the BIS service. The BIS service may represent a service provided through the BIS. In one embodiment, the event to perform the BIS service may include various events such as user input, the execution of an application, and / or a request from the Bluetooth stack. For example, the various events may include user input to execute broadcast audio to listen to music that the user is listening to with other users, and / or user input to execute a docent mode to transmit the user's voice to other users via broadcast audio.

[0214] In one embodiment, basic information related to the BIS service may include advertising information and BIG generation information. External electronic devices (e.g., the electronic device (102) of FIG. 1, or the external electronic device (200) of FIG. 2) may confirm that there is a BIS service performed on the electronic device based on the advertising information and synchronize with the BIS service performed on the electronic device.

[0215] In one embodiment, the advertising information may include PHY, Interval, Address type, Address, Tx Power, Service UUID (Universal Unique Identifier), Codec format, Sampling rate, Frame Duration, Broadcast_ID, and / or Broadcast_Name. PHY, Interval, Address type, Address, Tx Power, Service UUID, Broadcast_ID, and / or Broadcast_Name may be implemented similarly or substantially identically to those specified in the Bluetooth Core Specification v6.0 provided by the Bluetooth SIG’s Core Specification Working Group, specifically in the 7.8.53 LE Set Extended Advertising Parameters command, 7.8.54 LE Set Extended Advertising Data command, 7.8.61 LE Set Periodic Advertising Parameters command, and 7.8.62 LE Set Periodic Advertising Data command, and thus redundant descriptions thereof may be omitted. Among the advertising information, information specified in 7.8.53 LE Set Extended Advertising Parameters command and 7.8.54 LE Set Extended Advertising Data command may be EA information, and information specified in 7.8.61 LE Set Periodic Advertising Parameters command and 7.8.62 LE Set Periodic Advertising Data command may be PA information.

[0216] External electronic devices synchronized with a BIS service performed by an electronic device can recognize information related to BIS audio data based on BIG generation information and output BIS audio data. In one embodiment, the BIG generation information may include information used to generate a BIG containing one or more BISs, and may include information related to BIS data transmission.

[0217] In one embodiment, the BIG creation information may include a PHY to be used for transmitting BIS data, an SDU Interval, a Max SDU size, the number of BISs, a retransmission number (RTN), information related to whether encryption is supported, and a broadcast code (Broadcast_Code) used when encryption is supported. In one embodiment, the BIG creation information may be implemented similarly or substantially identically to the 7.8.103 LE Create BIG command of the Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group, and thus redundant descriptions may be omitted here.

[0218] An electronic device that has configured basic information related to the BIS service can generate a session key based on a broadcast code in operation 913. In one embodiment, the electronic device can generate a session key based on a broadcast code, a GIV, and a GSKD. In one embodiment, the GIV and GSKD can be transmitted via BIGInfo, and BIGInfo can be included in the ACAD field of the AUX_SYNC_IND PDU in the PA operation.

[0219] The electronic device that generated the session key can start the BIS service based on the generated session key and the basic information associated with the BIS service set in operation 915.

[0220] An electronic device that initiated the BIS service may, in operation 917, encrypt BIS data based on a session key and transmit (e.g., broadcast) the encrypted BIS data (e.g., isochronous data).

[0221] While transmitting the encrypted BIS data in this manner, the electronic device may check, in operation 919, whether an event to change the session key occurs. In one embodiment, the event to change the session key may include an event in which a set time elapses, an event in which user input requesting to change the session key is acknowledged, and / or an event in which the audio type of the BIS data is changed.

[0222] If, as a result of checking in operation 919, no event to change the session key occurs (operation 919-No), the electronic device may return to operation 917.

[0223] If, as a result of checking in operation 919, an event to change the session key occurs (operation 919-e), the electronic device may, in operation 921, decide to change the session key and determine a new broadcast code to be used to derive the new session key and an instance to which the new session key will be applied. The electronic device may transmit session key change information, including information related to the new broadcast code and the instance to which the new session key will be applied, via a BIG control PDU (e.g., may broadcast). Although FIG. 9 describes an example where only the broadcast code is changed to change the session key, if the GIV and GSKD are changed in addition to the broadcast code to change the session key, the session key change information may include the new broadcast code, the new GIV, the new GSKD, and information related to the instance to which the new session key will be applied. In one embodiment, the BIG control PDU may be transmitted in a control sub-event.

[0224] The electronic device that transmitted the session key change information may, in operation 923, encrypt BIS data based on the existing session key and transmit the encrypted BIS data (e.g., broadcast it).

[0225] While transmitting the encrypted BIS data in this way, the electronic device may check in operation 925 whether it has reached an instance where the new session key is applied. If, as a result of the check, it has not reached an instance where the new session key is applied (operation 925-No), the electronic device may return to operation 923.

[0226] If, as a result of checking in operation 925, an instance to which a new session key applies is reached (operation 925-e), the electronic device may, in operation 927, encrypt BIS data based on the new session key and transmit (e.g., broadcast) the encrypted BIS data (e.g., isochronous data).

[0227] The operation process of the electronic device as described in Fig. 9 can be performed repeatedly until the BIS service is terminated.

[0228] FIG. 10 is a diagram illustrating the operation of setting a session key change function for a BIS service in a wireless communication network according to one embodiment.

[0229] Referring to FIG. 10, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). In one embodiment, the electronic device may determine whether to apply a session key change function to change the session key for a BIS service based on a request from a user or application, a request from an external electronic device connected to the electronic device (e.g., the electronic device (102) of FIG. 1 or the external electronic device (200) of FIG. 2) (e.g., if the external electronic device is an earbud, the physical user interface (PUI) of the earbud), and various parameters such as PHY, Context type, bitrate, and / or MTL. In one embodiment, the electronic device may always apply the session key change function to the BIS service depending on the software implementation.

[0230] In one embodiment, the electronic device may determine whether to apply a session key change function to the BIS service based on a request from a user or application. When determining whether to apply a session key change function to the BIS service based on a request from a user or application, the electronic device may inquire with the user whether to apply a session key change function to the BIS service through a separate menu before starting the BIS service, and may determine whether to apply a session key change function to the BIS service based on user input.

[0231] In one embodiment, the electronic device may determine whether to apply a session key change function to the BIS service based on a request from an external electronic device connected to the electronic device. For example, if the external electronic device is an external electronic device (200) that is an earbud, when the electronic device is providing an audio service to the external electronic device (200) and a user inputs a setting PUI of the external electronic device (200) (e.g., a long press of the left earbud included in the external electronic device (100)), the electronic device may change the audio service provided to the external electronic device (200) to a BIS service and apply a session key change function to the BIS service.

[0232] In one embodiment, the electronic device may apply a session key change function to the BIS service when the BIS service is not performed based on LE 1M PHY or LE 2M PHY, but is performed based on a subsequent PHY, for example, HDT (higher data throughput) PHY or Higher Band.

[0233] In one embodiment, the electronic device may determine whether to apply a session key change function to the BIS service based on the audio type provided through the BIS service. For example, if the audio type provided through the BIS service is a voice type in which the user's voice is directly transmitted, the session key change function may be applied to the BIS service.

[0234] In one embodiment, the electronic device may allow the user to select, through a settings menu, whether to apply a session key change function to the BIS service provided by the electronic device.

[0235] As illustrated in FIG. 10, it may be possible to enable the user to directly input a broadcast code to be used to change the session key through a settings menu, and in this case, the electronic device may apply the session key change function to the BIS service provided by the electronic device. The screen (1000) may display a screen where the user can input a password to generate a broadcast code used to generate a session key to be applied to the BIS provided by the electronic device. In one embodiment, the user may input a password to generate a broadcast code to be applied to the BIS service through the screen (1000), and the electronic device may generate a broadcast code based on the password entered by the user. In one embodiment, the method of generating a broadcast code based on a password is specified in Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group, and therefore redundant descriptions are omitted here.

[0236] FIG. 11 is a diagram illustrating an operation to transmit information indicating whether a session key change function is supported for a BIS service in a wireless communication network according to one embodiment.

[0237] Referring to FIG. 11, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). The electronic device may transmit (or broadcast) information indicating whether a session key change function is supported for the BIS provided by the electronic device. The reason the electronic device transmits information indicating whether a session key change function is supported for the BIS provided by the electronic device may be that an external electronic device (e.g., the electronic device (102) of FIG. 1 or the external electronic device (200) of FIG. 2) is synchronized with the BIS service provided by the electronic device, but does not support a session key change function, so if the electronic device changes the session key, it may no longer be possible to synchronize with the BIS service.

[0238] In one embodiment, the electronic device may transmit (or broadcast) information indicating whether a session key change function is supported for the BIS service provided by the electronic device through a periodic advertising train. In one embodiment, the electronic device may transmit information indicating whether a session key change function is supported for the BIS service provided by the electronic device through service data corresponding to a set UUID. In one embodiment, the electronic device may explicitly add information indicating whether a session key change function is supported for the BIS service to a broadcast name corresponding to the BIS service.

[0239] For example, as shown in Table 8 below, the electronic device may transmit information indicating whether a session key change function is supported for the BIS service provided by the electronic device through a reserved bit included in the service data corresponding to the UUID of the public broadcast announcement service.

[0240] Table 8

[0241]

[0242] In Table 8, Bits 3-7 are RFUs, and thus the electronic device can transmit information indicating whether the session key change function is supported for the BIS service provided by the electronic device through any one of Bits 3-7, for example, Bit 3.

[0243] Information indicating whether a session key change function is supported for a BIS service provided by an electronic device can be transmitted as shown in FIG. 11 through a reserved bit (1100) included in the service data corresponding to the UUID of the public broadcast announcement service as shown in Table 8.

[0244] When an electronic device transmits information indicating whether the session key change function is supported for the BIS service, external electronic devices can recognize that session key change information is transmitted via the BIG control PDU, even if no separate additional information is transmitted.

[0245] In contrast, the electronic device may transmit not only information indicating whether the session key change function is supported for the BIS service, but also information regarding the method of transmitting the session key change information. When such information regarding the method of transmitting the session key change information is added, external electronic devices can recognize that the session key change information is transmitted via the encrypted PA signal.

[0246] Meanwhile, FIG. 11 describes an example in which an electronic device transmits information indicating whether a session key change function is supported for a BIS service and / or information regarding the method of transmitting session key change information via a BIG control PDU and / or an encrypted PA signal, for instance, by broadcasting information indicating whether a session key change function is supported for a BIS service and / or information regarding the method of transmitting session key change information; however, the electronic device may also transmit information indicating whether a session key change function is supported for a BIS service and / or information regarding the method of transmitting session key change information via a direct communication link between the electronic device and each external electronic device, such as a communication link created with each external electronic device and / or a communication link using a network. Additionally, even if the electronic device does not transmit information indicating whether a session key change function is supported for a BIS service and / or information regarding the method of transmitting session key change information, external electronic devices may perceive that a session key change function is supported for the BIS service provided by the electronic device.

[0247] FIG. 12 is a diagram illustrating the operation of starting a BIS service in a wireless communication network according to one embodiment.

[0248] Referring to FIG. 12, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). The electronic device may operate a periodic advertising train and broadcast BIS audio data and BIS control data. The operation of the electronic device operating a periodic advertising train is specified in Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group, and therefore redundant descriptions are omitted here. In one embodiment, the periodic advertising train may be broadcast in an unencrypted state. Alternatively, BIS audio data and BIS control data may be encrypted based on a session key, and the encrypted BIS audio data and BIS control data may be broadcast.

[0249] As illustrated in FIG. 12, the GIV and GSKD used to generate the session key, BIGInfo, may be included in the ACADs of the AUX_SYNC_IND PDUs (1200, 1240). In FIG. 12, Rn may represent audio data transmitted to an external electronic device responsible for the right channel, and Ln may represent BIS audio data transmitted to an external electronic device responsible for the left channel. In FIG. 12, the Event counter may represent a bisPayloadCounter, which may be implemented, for example, as a 39-bit counter. In one embodiment, the bisPayloadCounter may be associated with a BIS, and the value of the bisPayloadCounter may be the same for all BISs included in the BIG.

[0250] In one embodiment, an external electronic device (e.g., the electronic device (102) of FIG. 1, or the external electronic device (200) of FIG. 2) can obtain a GIV and a GSKD from the BIGInfo contained in the ACADs of the AUX_SYNC_IND PDUs (1200, 1240), and can derive a session key based on the GIV and the GSKD. The external electronic device can receive encrypted BIS data (e.g., encrypted BIS audio data and BIS control data) (1220, 1230), and can obtain BIS data by decrypting the received encrypted BIS data (1220, 1230) based on the derived session key.

[0251] FIG. 13 is a diagram illustrating the operation of changing a session key in a wireless communication network according to one embodiment.

[0252] Referring to FIG. 13, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). While providing BIS services, the electronic device may decide to change the session key. In one embodiment, when an event to change the session key is detected, the electronic device may decide to change the session key used to encrypt BIS data. The electronic device that decides to change the session key may determine a new broadcast code to be used to derive the new session key and an instance to which the new session key will be applied.

[0253] In one embodiment, the electronic device may set the instance to which the new session key is applied as a point in time after a set time (e.g., time corresponding to a fixed timer) after the existing session key is activated, a point in time corresponding to the size of the broadcast code currently in use, a point in time corresponding to a preset session key change cycle, or any random point in time. In one embodiment, the electronic device may set the instance to which the new session key is applied as a point in time after transmitting a BIG control PDU containing session key change information at least a set number of times (e.g., 6 times) consecutively. In one embodiment, the electronic device may set the instance to which the new session key is applied as a point in time corresponding to a value of bisPayloadCounter that is greater than a set value, e.g., 6 or more, than the value of bisPayloadCounter corresponding to the control sub-event that started transmitting the BIG control PDU containing session key change information. For example, the electronic device may set the point in time after at least six BIGs, including the BIG corresponding to the control sub-event that started transmitting the BIG control PDU containing session key change information, as the instance to which the new session key is applied.

[0254] In one embodiment, the electronic device may generate a new broadcast code, or generate a new GIV, or generate a new GSKD, or generate at least some of the new broadcast code, new GIV, and new GSKD, or generate all of the new broadcast code, new GIV, and new GSKD to generate a new session key. Since the electronic device may be exposed to a malicious attacker if it does not transmit the new GIV and / or new GSKD via an encrypted AUX_SYNC_IND PDU when generating the new GIV and / or new GSKD, the electronic device may generate the new GIV and / or new GSKD only when using an encrypted AUX_SYNC_IND PDU.

[0255] As illustrated in FIG. 13, the electronic device may decide to change the session key at a specific point in time (1300). For example, the electronic device may decide to change only the broadcast key to generate a new session key, which is expressed as "Broadcast_Code only" in FIG. 13. For example, the electronic device may set the point in time when the value of the BIS event counter (e.g., bisPayloadCounter) is 1209 as the instance to which the new session key is applied, which is expressed as "Instant = 1,209" in FIG. 13. In FIG. 13, BIS1 Audio and BIS2 Audio may be BIS events in which BIS audio data is transmitted.

[0256] Subsequently, the electronic device can transmit (or broadcast) session key change information via a BIG control PDU, and can also provide the session key change information to the user through a UI / UX.

[0257] FIG. 14 is a diagram illustrating the operation of transmitting session key change information in a wireless communication network according to one embodiment.

[0258] Referring to FIG. 14, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). While providing BIS services, the electronic device may decide to change the session key. In one embodiment, when an event to change the session key is detected, the electronic device may decide to change the session key used to encrypt BIS data. The electronic device that decides to change the session key may determine a new broadcast code to be used to derive the new session key and an instance to which the new session key will be applied.

[0259] In one embodiment, the electronic device may transmit session key change information through a secure channel, including a new broadcast code to be used to derive a new session key and information related to the instance to which the new session key will be applied. In one embodiment, the secure channel may be an encrypted BIS channel already in use by the electronic device and external electronic devices (e.g., the electronic device (102) of FIG. 1 or the external electronic device (200) of FIG. 2), a separate encrypted EA / PA signal, and / or a communication link established between each of the electronic device and the external electronic devices. In one embodiment, if the electronic device and the external electronic devices are implemented to have the same session key generation method (e.g., a session key generation algorithm), the electronic device and the external electronic devices may change the session key based on the session key generation method.

[0260] In one embodiment, session key change information may be transmitted via a BIG control PDU. The format of the payload field included in the BIG control PDU to which the session key change information is transmitted may include an Opcode field and a control data field as described in Table 4. In one embodiment, the Opcode field may be represented as shown in Table 9 below.

[0261] Table 9

[0262]

[0263] As explained in Table 5 above, the Opcode field specified in the Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group can be implemented as one octet, and among the field values ​​of the Opcode field, 0x00 indicates that the corresponding BIG control PDU is a BIG_CHANNEL_MAP_IND PDU, and among the field values ​​of the Opcode field, 0x01 indicates that the corresponding BIG control PDU is a BIG_TERMINATE_IND PDU, and among the field values ​​of the Opcode field, 0xF8 to 0xFB are reserved for future use for specification development purposes, and all other values ​​among the field values ​​of the Opcode field, excluding 0x00, 0x01, and 0xF8 to 0xFB, are reserved for future use.

[0264] Accordingly, in one embodiment of the present disclosure, as shown in Table 9, any one of all other values ​​among the field values ​​of the Opcode field excluding 0x00, 0x01, and 0xF8 to 0xFB, e.g., 0XFC, may be used to indicate that the corresponding BIG control PDU is a BIG_SESSION_KEY_CHANGE_IND PDU. In one embodiment, the BIG_SESSION_KEY_CHANGE_IND PDU may be a BIG control PDU used to use session key change information.

[0265] In one embodiment, when the type of the BIG control PDU is BIG_SESSION_KEY_CHANGE_IND PDU, the control data field can be represented as shown in Table 10 below.

[0266] Table 10

[0267]

[0268] In Table 10, the New Broadcast_Code field may be set to a value representing the new broadcast code, and the Instant field may be set to a value representing the instance to which the new session key will be applied. In one embodiment, the Instant field may be set to a value of bisPayloadCounter to which the new session key will be applied.

[0269] As illustrated in FIG. 14, the electronic device may decide to change the session key at a specific point in time. For example, the electronic device may decide to change only the broadcast key to generate a new session key at a specific point in time (e.g., specific point in time (1300) of FIG. 13) as described in FIG. 13, and may set the point in time when the value of the BIS event counter (e.g., bisPayloadCounter) is 1209 as the instance to which the new session key is applied. In this case, the electronic device may transmit session key change information through the control data field of the BIG control PDU in which the field value of the Opcode field is set to 0XFC, and the new session key may be applied from the point in time when the value of the BIS event counter (e.g., bisPayloadCounter) is 1209. In one embodiment, the electronic device may set the point in time after transmitting the BIG control PDU containing the session key change information at least a set number of times, e.g., 6 times consecutively, as the instance to which the new session key is applied. In one embodiment, the electronic device may set a point in time corresponding to a value of bisPayloadCounter that is greater than a set value, for example, 6 or more, than the value of bisPayloadCounter corresponding to the control sub-event that started transmitting a BIG control PDU containing session key change information, as the instance to which the new session key is applied. For example, the electronic device may set a point in time after at least 6 BIGs, including the BIG corresponding to the control sub-event that started transmitting a BIG control PDU containing session key change information, as the instance to which the new session key is applied.

[0270] In FIG. 14, BIS1 Audio and BIS2 Audio may be BIS events in which BIS audio data is transmitted, and BIG Control may be BIG control PDUs containing session key change information. As shown in FIG. 14, a new session key may be applied starting from the point when the value of the BIS event counter is 1209.

[0271] FIG. 15 is a diagram illustrating the operation of transmitting session key change information in a wireless communication network according to one embodiment.

[0272] Referring to FIG. 15, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). While providing BIS services, the electronic device may decide to change the session key. In one embodiment, when an event to change the session key is detected, the electronic device may decide to change the session key used to encrypt BIS data. The electronic device that decides to change the session key may determine a new broadcast code to be used to derive the new session key and an instance to which the new session key will be applied.

[0273] In one embodiment, the electronic device may transmit session key change information through a secure channel, including a new broadcast code to be used to derive a new session key and information related to the instance to which the new session key will be applied. In one embodiment, the secure channel may be an encrypted BIS channel already in use by the electronic device and external electronic devices (e.g., the electronic device (102) of FIG. 1 or the external electronic device (200) of FIG. 2), a separate encrypted EA / PA signal, and / or a communication link established between each of the electronic device and the external electronic devices. In one embodiment, if the electronic device and the external electronic devices are implemented to have the same session key generation method (e.g., a session key generation algorithm), the electronic device and the external electronic devices may change the session key based on the session key generation method.

[0274] In one embodiment, session key change information may be transmitted via an encrypted EA / PA signal. In one embodiment, the electronic device may operate an encrypted periodic advertising train based on the session key. The operation of the electronic device operating the periodic advertising train is specified in Bluetooth Core Specification v6.0 provided by the Bluetooth SIG Core Specification Working Group, and therefore redundant description thereof may be omitted here. The electronic device may transmit (or broadcast) session key change information via an encrypted AUX_SYNC_IND PDU. In one embodiment, session key change information may be transmitted via an AUX_SYNC_IND PDU. In one embodiment, the electronic device may encrypt only the AUX_SYNC_IND PDU containing BIGInfo, or encrypt all AUX_SYNC_IND PDUs.

[0275] External electronic devices need to synchronize with the electronic device's BIS to receive BIS services provided by the electronic device, and thus, external electronic devices can synchronize with the BIS based on BIGInfo received via the AUX_SYNC_IND PDU. Accordingly, the electronic device may not encrypt the AUX_SYNC_IND PDU if the AUX_SYNC_IND PDU containing BIGInfo does not contain session key change information, and may encrypt the AUX_SYNC_IND PDU only if the AUX_SYNC_IND PDU containing BIGInfo contains session key change information.

[0276] In one embodiment, the electronic device may encrypt the AUX_SYNC_IND PDU based on the currently used session key. In one embodiment, the electronic device may encrypt the AUX_SYNC_IND PDU based on a previously used session key. In one embodiment, the electronic device may encrypt the AUX_SYNC_IND PDU based on the currently used session key and the previously used session key according to a set ratio. The reason the electronic device encrypts the AUX_SYNC_IND PDU based on the previously used session key, or encrypts the AUX_SYNC_IND PDU based on the currently used session key and the previously used session key according to a set ratio, may be to enable external electronic devices that have temporarily lost synchronization with the BIS after being synchronized with the electronic device's BIS to resynchronize with the BIS based on the session key held by those devices.

[0277] As illustrated in FIG. 15, the AUX_SYNC_IND PDU (1510) may be an AUX_SYNC_IND PDU that does not contain session key change information, and therefore the AUX_SYNC_IND PDU (1510) may not be encrypted. Alternatively, the AUX_SYNC_IND PDU (1560) may be an AUX_SYNC_IND PDU that contains session key change information, and therefore the AUX_SYNC_IND PDU (1560) may be encrypted based on the session key. In FIG. 15, it is indicated that the AUX_SYNC_IND PDU (1560) is encrypted based on the session key, such as "Encrypted by using Session Key".

[0278] In FIG. 15, reference numbers 1520 and 1550 may represent encrypted BIS data (e.g., encrypted BIS audio data and BIS control data) (e.g., encrypted BIS data (1220, 1230) of FIG. 12). In FIG. 15, ADV_EXT_IND PDU (1530) and AUX_ADV_IND PDU (1540) may not be encrypted because they do not contain session key change information.

[0279] FIG. 16a is a diagram illustrating the operation of providing session key change information in the form of a UX in a wireless communication network according to one embodiment.

[0280] Referring to FIG. 16a, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may operate as a broadcast source device (or isochronous broadcaster). While providing BIS services, the electronic device may decide to change the session key. In one embodiment, when an event to change the session key is detected, the electronic device may decide to change the session key used to encrypt BIS data. The electronic device that decides to change the session key may determine a new broadcast code to be used to derive the new session key and an instance to which the new session key will be applied. In one embodiment, the electronic device may provide session key change information in the form of a UX that includes information related to the new broadcast code to be used to derive the new session key and the instance to which the new session key will be applied. Figure 16a describes, as an example, a case in which the electronic device operates as a broadcast source device and provides session key change information in the form of a UX that includes a new broadcast code to be used to derive a new session key and information related to the instance to which the new session key is applied. However, even when the electronic device operates as a broadcast assistant device, session key change information that includes a new broadcast code to be used to derive a new session key and information related to the instance to which the new session key is applied can be provided in the form of a UX.

[0281] In one embodiment, the electronic device may provide session change key information in the form of a UX such as a QR (quick response) code. In one embodiment, the electronic device may change the session key by changing the GIV and / or GSKD without changing the existing broadcast code. In this case, the electronic device may not provide session key change information in the form of a UX.

[0282] FIG. 16a illustrates an example in which session key change information is provided as a QR code (1600) along with an existing broadcast code. In FIG. 16a, an instance to which an existing broadcast code, a new broadcast code included in the session key change information, and a new session key are to be applied can be obtained through the QR code.

[0283] FIG. 16b is a diagram illustrating the operation of providing session key change information in the form of a UX in a wireless communication network according to one embodiment.

[0284] Referring to FIG. 16b, an electronic device (e.g., the electronic device (101) of FIG. 1 or FIG. 2) may provide session key change information in a UX format, including a new broadcast code to be used to derive a new session key and information related to the instance to which the new session key will be applied, in a manner similar to or substantially identical to that described in FIG. 16a. While the session key change information is provided in a QR format in FIG. 16a, the session key change information may be provided in a text format in FIG. 16b illustrates, as an example, the session key change information being provided as a changed password (1650). For example, the changed password "2025" may represent a password derived from the new broadcast codeword by the electronic device (101). For example, as described in FIG. 10, assuming the existing password is "1234", the new password derived from the new broadcast code generated by changing the existing broadcast code based on the existing password may be "2025". According to one embodiment of the present disclosure, the method of the electronic device (101) may include the operation of generating a first session key based on the first broadcast code.

[0285] According to one embodiment of the present disclosure, the method may include the operation of transmitting a first data encrypted based on the first session key through at least one broadcast isochronous stream (BIS).

[0286] According to one embodiment of the present disclosure, the method may include an operation of checking an event for generating a second session key while transmitting the first data through the at least one BIS.

[0287] According to one embodiment of the present disclosure, the method may include, based on the event, a second broadcast code to be used to generate the second session key and an operation to identify the instance to which the second session key will be applied.

[0288] According to one embodiment of the present disclosure, the method may include the operation of transmitting first information including the second broadcast code and second information associated with the instance to which the second session key is applied.

[0289] According to one embodiment of the present disclosure, at least the second broadcast code included in the first information can be encrypted using the first session key.

[0290] According to one embodiment of the present disclosure, the method may include the operation of generating the second session key based on the second broadcast code.

[0291] According to one embodiment of the present disclosure, the method may include, after transmitting the first information and the second information, transmitting second data encrypted based on the second session key from the instant through the at least one BIS.

[0292] According to one embodiment of the present disclosure, the operation of transmitting the first information and the second information may include the operation of including the first information and the second information in a BIG control protocol data unit (PDU) for a broadcast isochronous group (BIG) including the at least one BIS.

[0293] According to one embodiment of the present disclosure, the operation of transmitting the first information and the second information may include the operation of transmitting the BIG control PDU.

[0294] According to one embodiment of the present disclosure, the operation of transmitting the BIG control PDU may include the operation of encrypting the BIG control PDU based on the first session key.

[0295] According to one embodiment of the present disclosure, the operation of transmitting the BIG control PDU may include the operation of transmitting the encrypted BIG control PDU.

[0296] According to one embodiment of the present disclosure, the BIG control PDU may include information indicating that the type of the BIG control PDU is a BIG control PDU for changing a session key.

[0297] According to one embodiment of the present disclosure, the operation of generating the first session key based on the first broadcast code may include a first group initialization vector (GIV) parameter and a second group session key derivation (GSKD) parameter used to encrypt the first data, and the operation of generating the first session key based on the first broadcast code.

[0298] According to one embodiment of the present disclosure, the operation of generating the second session key based on the second broadcast code may include a second GIV parameter and a second GSKD parameter used to encrypt the second data, and the operation of generating the second session key based on the second broadcast code.

[0299] According to one embodiment of the present disclosure, the second GIV parameter may be the same as or different from the first GIV parameter.

[0300] According to one embodiment of the present disclosure, the second GSKD parameter may be the same as or different from the first GSKD parameter.

[0301] According to one embodiment of the present disclosure, the method may include the operation of including the second GIV parameter and the second GSKD parameter in a periodic advertising (PA) protocol data unit (PDU).

[0302] According to one embodiment of the present disclosure, the method may include the operation of encrypting the PA PDU based on the first session key or a third session key prior to the first session key.

[0303] According to one embodiment of the present disclosure, the method may include the operation of transmitting the encrypted PA PDU before transmitting the first information and the second information.

[0304] According to one embodiment of the present disclosure, a storage medium for storing at least one instruction readable by a computer may be provided.

[0305] According to one embodiment of the present disclosure, the at least one instruction may cause the electronic device (101) to perform at least one operation when executed individually or collectively by one or more processors (120) including processing circuitry of the electronic device (101).

[0306] According to one embodiment of the present disclosure, the at least one operation may include an operation to generate a first session key based on a first broadcast code.

[0307] According to one embodiment of the present disclosure, the at least one operation may include transmitting the first data encrypted based on the first session key through at least one broadcast isochronous stream (BIS).

[0308] According to one embodiment of the present disclosure, the at least one operation may include checking an event for generating a second session key while transmitting the first data through the at least one BIS.

[0309] According to one embodiment of the present disclosure, the at least one operation may include, based on the event, a second broadcast code to be used to generate the second session key and an operation to identify the instance to which the second session key will be applied.

[0310] According to one embodiment of the present disclosure, the at least one operation may include transmitting first information including the second broadcast code and second information associated with the instance to which the second session key is to be applied.

[0311] According to one embodiment of the present disclosure, at least the second broadcast code included in the first information can be encrypted using the first session key.

[0312] According to one embodiment of the present disclosure, the at least one operation may include an operation to generate the second session key based on the second broadcast code.

[0313] According to one embodiment of the present disclosure, the at least one operation may include, after transmitting the first information and the second information, transmitting the second data encrypted based on the second session key from the instant through the at least one BIS.

[0314] The electronic device according to one embodiment disclosed in this document may be of various forms. The electronic device may include, for example, a portable communication device (e.g., a smartphone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a home appliance. The electronic device according to the embodiment of this document is not limited to the aforementioned devices.

[0315] One embodiment of this document and the terms used therein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various modifications, equivalents, or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of said items unless the relevant context clearly indicates otherwise. In this document, each of phrases such as "A or B," "at least one of A and B," "at least one of A or B," "A, B or C," "at least one of A, B and C," and "at least one of A, B, or C" may include any one of the items listed together in the corresponding phrase, or all possible combinations thereof. Terms such as “first,” “second,” or “first” or “second” may be used simply to distinguish a component from another component and do not limit the components in any other aspect (e.g., importance or order). Where any (e.g., first) component is referred to as “coupled” or “connected” to another (e.g., second) component, with or without the terms “functionally” or “communicationally,” it means that said component may be connected to said other component directly (e.g., wired), wirelessly, or through a third component.

[0316] The term "module" as used in an embodiment of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit, for example. A module may be a component formed integrally, or a minimum unit of said component or a part thereof that performs one or more functions. For example, according to an embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0317] One embodiment of the present document may be implemented as software (e.g., program (140)) comprising one or more instructions stored in a storage medium (e.g., internal memory (136) or external memory (138)) readable by a machine (e.g., electronic device (101)). For example, a processor (e.g., processor (120)) of the machine (e.g., electronic device (101)) may call at least one of the one or more instructions stored in the storage medium and execute it. This enables the machine to be operated to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code that can be executed by an interpreter. The storage medium readable by the machine may be provided in the form of a non-transitory storage medium. Here, 'non-temporary' simply means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.

[0318] According to one embodiment, the method according to one embodiment disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or an application store (e.g., Play Store). TM It can be distributed online (e.g., downloaded or uploaded) through ) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.

[0319] According to one embodiment, each component (e.g., module or program) of the components described above may include a singular or multiple entities, and some of the multiple entities may be separated and placed in other components. According to one embodiment, one or more of the components or operations among the aforementioned components may be omitted, or one or more other components or operations may be added. Generally or additionally, multiple components (e.g., module or program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the multiple components in the same or similar manner as those performed by the corresponding component among the multiple components prior to integration. According to one embodiment, operations performed by the module, program, or other components may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

1. In an electronic device (101), Communication circuit (190); One or more processors (120) including processing circuitry; and The electronic device includes a memory (130) for storing instructions, wherein the instructions are executed individually or collectively by one or more processors: A first session key is generated based on the first broadcast code, and Through the communication circuit above, the first data encrypted based on the first session key is transmitted through at least one broadcast isochronous stream (BIS), and While transmitting the first data through the above at least one BIS, check for an event to generate a second session key, and Based on the above event, identify the second broadcast code to be used to generate the second session key and the instance to which the second session key will be applied, and Transmitting through the communication circuit the first information including the second broadcast code and the second information related to the instance to which the second session key is to be applied - wherein at least the second broadcast code included in the first information is encrypted using the first session key - , Generate the second session key based on the second broadcast code above, and The electronic device that, after transmitting the first information and the second information, causes the second data encrypted based on the second session key from the instant to be transmitted through the at least one BIS via the communication circuit.

2. In Paragraph 1, When the above instructions are executed individually or collectively by the one or more processors, the electronic device, at least as part of the operation of transmitting the first information and the second information: Including the first information and the second information in a BIG control protocol data unit (PDU) for a broadcast isochronous group (BIG) including at least one BIS, and The electronic device that causes the transmission of the BIG control PDU through the communication circuit.

3. In Paragraph 2, When the above instructions are executed individually or collectively by the one or more processors, the electronic device, at least as part of the operation of transmitting the BIG control PDU: Encrypt the BIG control PDU based on the first session key, and The electronic device that causes the encrypted BIG control PDU to be transmitted through the communication circuit.

4. In Paragraph 2 or 3, The electronic device wherein the above BIG control PDU includes information indicating that the type of the above BIG control PDU is a BIG control PDU for changing the session key.

5. In any one of paragraphs 1 through 4, When the above instructions are executed individually or collectively by the one or more processors, the electronic device, at least as part of the operation of generating the first session key based on the first broadcast code: An electronic device that causes the generation of the first session key based on the first broadcast code, the first group initialization vector (GIV) parameter and the second group session key derivation (GSKD) parameter used to encrypt the first data.

6. In Paragraph 5, When the above instructions are executed individually or collectively by the one or more processors, the electronic device, at least as part of the operation of generating the second session key based on the second broadcast code: Causing to generate the second session key based on the second GIV parameter and second GSKD parameter used to encrypt the second data, and the second broadcast code, and The above second GIV parameter is the same as or different from the above first GIV parameter, and The electronic device wherein the second GSKD parameter is the same as or different from the first GSKD parameter.

7. In Paragraph 6, When the above instructions are executed individually or collectively by the one or more processors, the electronic device: The above second GIV parameter and the above second GSKD parameter are included in a periodic advertising (PA) protocol data unit (PDU), and Encrypt the PA PDU based on the first session key or the third session key prior to the first session key, and The electronic device that causes the encrypted PA PDU to be transmitted through the communication circuit before transmitting the first information and the second information.

8. In the method of the electronic device (101), The operation of generating a first session key based on a first broadcast code; The operation of transmitting the first data encrypted based on the first session key through at least one broadcast isochronous stream (BIS); An operation to check for an event to generate a second session key while transmitting the first data through the above at least one BIS; Based on the above event, an operation to identify a second broadcast code to be used to generate the second session key and an instance to which the second session key will be applied; The operation of transmitting first information including the second broadcast code and second information related to the instance to which the second session key is to be applied - wherein at least the second broadcast code included in the first information is encrypted using the first session key - ; The operation of generating the second session key based on the second broadcast code; and The method comprising the operation of transmitting, after transmitting the first information and the second information, second data encrypted based on the second session key from the instant through the at least one BIS.

9. In Paragraph 8, The operation of transmitting the above first information and the above second information is: The operation of including the first information and the second information in a BIG control protocol data unit (PDU) for a broadcast isochronous group (BIG) including at least one BIS; and The method including the operation of transmitting the above BIG control PDU.

10. In Paragraph 9, The operation of transmitting the above BIG control PDU is: An operation to encrypt the BIG control PDU based on the first session key; and The method comprising the operation of transmitting the above-mentioned encrypted BIG control PDU.

11. In Paragraph 9 or 10, The method wherein the above BIG control PDU includes information indicating that the type of the above BIG control PDU is a BIG control PDU for changing the session key.

12. In any one of paragraphs 8 through 11, The operation of generating the first session key based on the first broadcast code is: The method comprising a first group initialization vector (GIV) parameter and a second group session key derivation (GSKD) parameter used to encrypt the first data, and an operation to generate the first session key based on the first broadcast code.

13. In Paragraph 12, The operation of generating the second session key based on the second broadcast code above is: It includes an operation to generate the second session key based on the second GIV parameter and the second GSKD parameter used to encrypt the second data, and the second broadcast code, and The above second GIV parameter is the same as or different from the above first GIV parameter, and The above method, wherein the second GSKD parameter is the same as or different from the first GSKD parameter.

14. In Paragraph 13, The operation of including the above-mentioned second GIV parameter and the above-mentioned second GSKD parameter in a periodic advertising (PA) protocol data unit (PDU); An operation to encrypt the PA PDU based on the first session key or the third session key prior to the first session key; and The method comprising the operation of transmitting the encrypted PA PDU before transmitting the first information and the second information.

15. In a storage medium storing at least one instruction readable by a computer, When the above at least one instruction is executed individually or collectively by one or more processors (120) including the processing circuitry of the electronic device (101), the electronic device causes the electronic device to perform at least one operation, and The above at least one operation is: The operation of generating a first session key based on a first broadcast code; The operation of transmitting the first data encrypted based on the first session key through at least one broadcast isochronous stream (BIS); An operation to check for an event to generate a second session key while transmitting the first data through the above at least one BIS; Based on the above event, an operation to identify a second broadcast code to be used to generate the second session key and an instance to which the second session key will be applied; The operation of transmitting first information including the second broadcast code and second information related to the instance to which the second session key is to be applied - wherein at least the second broadcast code included in the first information is encrypted using the first session key - ; The operation of generating the second session key based on the second broadcast code; and The storage medium comprising the operation of transmitting, after transmitting the first information and the second information, second data encrypted based on the second session key from the instant through the at least one BIS.