WO2025101021A1 - 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 - Google Patents

무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 Download PDF

Info

Publication number
WO2025101021A1
WO2025101021A1 PCT/KR2024/017734 KR2024017734W WO2025101021A1 WO 2025101021 A1 WO2025101021 A1 WO 2025101021A1 KR 2024017734 W KR2024017734 W KR 2024017734W WO 2025101021 A1 WO2025101021 A1 WO 2025101021A1
Authority
WO
WIPO (PCT)
Prior art keywords
block
information
ack
sta
subfield
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Pending
Application number
PCT/KR2024/017734
Other languages
English (en)
French (fr)
Inventor
백선희
최진수
장인선
김건환
윤예린
차동주
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
LG Electronics Inc
Original Assignee
LG Electronics Inc
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by LG Electronics Inc filed Critical LG Electronics Inc
Publication of WO2025101021A1 publication Critical patent/WO2025101021A1/ko
Anticipated expiration legal-status Critical
Pending legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L1/00Arrangements for detecting or preventing errors in the information received
    • H04L1/12Arrangements for detecting or preventing errors in the information received by using return channel
    • H04L1/16Arrangements for detecting or preventing errors in the information received by using return channel in which the return channel carries supervisory signals, e.g. repetition request signals
    • H04L1/1607Details of the supervisory signal
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L1/00Arrangements for detecting or preventing errors in the information received
    • H04L1/12Arrangements for detecting or preventing errors in the information received by using return channel
    • H04L1/16Arrangements for detecting or preventing errors in the information received by using return channel in which the return channel carries supervisory signals, e.g. repetition request signals
    • H04L1/18Automatic repetition systems, e.g. Van Duuren systems
    • H04L1/1812Hybrid protocols; Hybrid automatic repeat request [HARQ]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L1/00Arrangements for detecting or preventing errors in the information received
    • H04L1/12Arrangements for detecting or preventing errors in the information received by using return channel
    • H04L1/16Arrangements for detecting or preventing errors in the information received by using return channel in which the return channel carries supervisory signals, e.g. repetition request signals
    • H04L1/18Automatic repetition systems, e.g. Van Duuren systems
    • H04L1/1829Arrangements specially adapted for the receiver end
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/041Key generation or derivation
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/047Key management, e.g. using generic bootstrapping architecture [GBA] without using a trusted network node as an anchor
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/04Key management, e.g. using generic bootstrapping architecture [GBA]
    • H04W12/047Key management, e.g. using generic bootstrapping architecture [GBA] without using a trusted network node as an anchor
    • H04W12/0471Key exchange
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/10Integrity
    • H04W12/106Packet or message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W84/00Network topologies
    • H04W84/02Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
    • H04W84/10Small scale networks; Flat hierarchical networks
    • H04W84/12WLAN [Wireless Local Area Networks]

Definitions

  • the present disclosure relates to a method and device for supporting protection for a control frame in a wireless local area network (WLAN) system.
  • WLAN wireless local area network
  • Wi-Fi wireless LAN
  • VHT Very High-Throughput
  • HE High Efficiency
  • EHT Extremely High Throughput
  • technologies for MIMO (Multiple Input Multiple Output) and multi-access point (AP) coordination that support increased bandwidth, efficient utilization of multiple bands, and increased spatial streams are being studied, and in particular, various technologies are being studied to support low latency or real-time traffic.
  • new technologies are being discussed to support ultra-high reliability (UHR), including improvements or extensions of EHT technologies.
  • the technical problem of the present disclosure is to provide a method and device supporting protection for a control frame in a wireless LAN system.
  • the technical problem of the present disclosure is to provide a method and device for supporting an integrity check based on BIP (Broadcast/multicast integrity protocol) for a Block-ACK (BA) frame in a wireless LAN system.
  • BIP Broadcast/multicast integrity protocol
  • BA Block-ACK
  • a method performed by a first station (STA) in a wireless local area network (WLAN) system may include: verifying key information related to protection for a block acknowledgment (ACK) frame; receiving a block ACK frame to which the protection has been applied from a second STA; and performing integrity verification on the block ACK frame based on the key information.
  • the protection-related information for the integrity verification may be included in a specific each TID AID Info field among a plurality of each TID AID Info fields included in a block ACK information field in the block ACK frame.
  • a method performed by a second station (STA) in a wireless local area network (WLAN) system may include: verifying key information related to protection for a block-ACK frame; configuring a block-ACK frame including protection-related information for integrity verification of the block-ACK frame based on the key information; and transmitting the block-ACK frame to which the protection has been applied to a first STA.
  • the protection-related information may be included in a specific each TID AID information field among a plurality of each TID AID information (Per TID AID Info) fields included in a block-ACK information field in the block-ACK frame.
  • a method and device supporting protection for a control frame in a wireless LAN system can be provided.
  • a method and device for supporting BIP-based integrity check for a block-ACK (BlockAck, BA) frame in a wireless LAN system can be provided.
  • FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
  • FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
  • FIG. 12 illustrates another example of a block-ACK frame configuration supporting integrity checking according to an embodiment of the present disclosure.
  • FIG. 17 is a drawing for explaining an example of a method performed by a first STA according to the present disclosure.
  • first in one embodiment
  • second component in another embodiment
  • first component in another embodiment may be referred to as a first component in another embodiment
  • the examples of the present disclosure can be applied to various wireless communication systems.
  • the examples of the present disclosure can be applied to a wireless LAN system.
  • the examples of the present disclosure can be applied to a wireless LAN based on IEEE 802.11a/g/n/ac/ax/be standards.
  • the examples of the present disclosure can be applied to a wireless LAN based on a newly proposed IEEE 802.11bn (or UHR) standard.
  • the examples of the present disclosure can be applied to a wireless LAN based on a next-generation standard after IEEE 802.11bn.
  • the examples of the present disclosure can be applied to a cellular wireless communication system.
  • the examples of the present disclosure can be applied to a cellular wireless communication system based on a Long Term Evolution (LTE) series technology of the 3rd Generation Partnership Project (3GPP) standard and a New Radio (5G NR) series technology.
  • LTE Long Term Evolution
  • 3GPP 3rd Generation Partnership Project
  • 5G NR New Radio
  • FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
  • the first device (100) and the second device (200) illustrated in FIG. 1 may be replaced with various terms such as a terminal, a wireless device, a Wireless Transmit Receive Unit (WTRU), a User Equipment (UE), a Mobile Station (MS), a user terminal (UT), a Mobile Subscriber Station (MSS), a Mobile Subscriber Unit (MSS), a Subscriber Station (SS), an Advanced Mobile Station (AMS), a Wireless terminal (WT), or simply a user.
  • WTRU Wireless Transmit Receive Unit
  • UE User Equipment
  • MS Mobile Station
  • UT a Mobile Subscriber Station
  • MSS Mobile Subscriber Unit
  • SS Subscriber Station
  • AMS Advanced Mobile Station
  • WT Wireless terminal
  • first device (100) and the second device (200) may be replaced with various terms such as an access point (AP), a base station (BS), a fixed station, a Node B, a base transceiver system (BTS), a network, an Artificial Intelligence (AI) system, a road side unit (RSU), a repeater, a router, a relay, a gateway, etc.
  • AP access point
  • BS base station
  • BTS base transceiver system
  • AI Artificial Intelligence
  • RSU road side unit
  • RSU repeater
  • router a relay
  • gateway a gateway
  • the devices (100, 200) illustrated in FIG. 1 may also be referred to as stations (STAs).
  • STAs stations
  • the devices (100, 200) illustrated in FIG. 1 may be referred to by various terms such as a transmitting device, a receiving device, a transmitting STA, and a receiving STA.
  • the STAs (110, 200) may perform an AP (access point) role or a non-AP role. That is, the STAs (110, 200) in the present disclosure may perform functions of an AP and/or a non-AP.
  • the STAs (110, 200) When the STAs (110, 200) perform an AP function, they may simply be referred to as APs, and when the STAs (110, 200) perform a non-AP function, they may simply be referred to as STAs.
  • the APs in the present disclosure may also be indicated as AP STAs.
  • the first device (100) and the second device (200) can transmit and receive wireless signals through various wireless LAN technologies (e.g., IEEE 802.11 series).
  • the first device (100) and the second device (200) can include interfaces for a medium access control (MAC) layer and a physical layer (PHY) that follow the regulations of the IEEE 802.11 standard.
  • MAC medium access control
  • PHY physical layer
  • the first device (100) and the second device (200) may additionally support various communication standards (for example, standards of 3GPP LTE series, 5G NR series, etc.) other than wireless LAN technology.
  • the device of the present disclosure may be implemented as various devices such as a mobile phone, a vehicle, a personal computer, an Augmented Reality (AR) device, and a Virtual Reality (VR) device.
  • the STA of the present specification may support various communication services such as a voice call, a video call, a data communication, autonomous driving, MTC (Machine-Type Communication), M2M (Machine-to-Machine), D2D (Device-to-Device), and IoT (Internet-of-Things).
  • a first device (100) includes one or more processors (102) and one or more memories (104), and may additionally include one or more transceivers (106) and/or one or more antennas (108).
  • the processor (102) controls the memories (104) and/or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, suggestions, methods, and/or operational flowcharts disclosed in the present disclosure.
  • the processor (102) may process information in the memory (104) to generate first information/signal, and then transmit a wireless signal including the first information/signal via the transceiver (106).
  • the processor (102) may receive a wireless signal including second information/signal via the transceiver (106), and then store information obtained from signal processing of the second information/signal in the memory (104).
  • the memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software codes including instructions for performing the descriptions, functions, procedures, proposals, methods, and/or operation flowcharts disclosed in the present disclosure.
  • the processor (102) and the memory (104) may be part of a communication modem/circuit/chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series).
  • the transceiver (106) may be connected to the processor (102) and may transmit and/or receive wireless signals via one or more antennas (108).
  • the transceiver (106) may include a transmitter and/or a receiver.
  • the transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit.
  • a device may also mean a communication modem/circuit/chip.
  • the second device (200) includes one or more processors (202), one or more memories (204), and may additionally include one or more transceivers (206) and/or one or more antennas (208).
  • the processor (202) may control the memories (204) and/or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, suggestions, methods, and/or operational flowcharts disclosed in this disclosure.
  • the processor (202) may process information in the memory (204) to generate third information/signal, and then transmit a wireless signal including the third information/signal via the transceiver (206).
  • the processor (202) may receive a wireless signal including fourth information/signal via the transceiver (206), and then store information obtained from signal processing of the fourth information/signal in the memory (204).
  • the memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software codes including instructions for performing the descriptions, functions, procedures, proposals, methods, and/or operational flowcharts disclosed in the present disclosure.
  • the processor (202) and the memory (204) may be part of a communication modem/circuit/chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series).
  • the transceiver (206) may be connected to the processor (202) and may transmit and/or receive wireless signals via one or more antennas (208).
  • the transceiver (206) may include a transmitter and/or a receiver.
  • the transceiver (206) may be used interchangeably with an RF unit.
  • a device may also mean a communication modem/circuit/chip.
  • one or more protocol layers may be implemented by one or more processors (102, 202).
  • one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC).
  • One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and/or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and/or operational flowcharts disclosed in this disclosure.
  • PDUs Protocol Data Units
  • SDUs Service Data Units
  • One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, suggestions, methods and/or operational flowcharts disclosed in this disclosure.
  • signals e.g., baseband signals
  • the one or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer.
  • the one or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof.
  • ASICs Application Specific Integrated Circuits
  • DSPs Digital Signal Processors
  • DSPDs Digital Signal Processing Devices
  • PLDs Programmable Logic Devices
  • FPGAs Field Programmable Gate Arrays
  • the descriptions, functions, procedures, suggestions, methods, and/or operational flowcharts disclosed in this disclosure may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc.
  • the descriptions, functions, procedures, suggestions, methods and/or operational flowcharts disclosed in this disclosure may be implemented using firmware or software configured to perform one or more of the following: included in one or more processors (102, 202), or stored in one or more memories (104, 204) and driven by one or more of the processors (102, 202).
  • the descriptions, functions, procedures, suggestions, methods and/or operational flowcharts disclosed in this disclosure may be implemented using firmware or software in the form of codes, instructions and/or sets of instructions.
  • one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals/channels, and the like, as described in the description, function, procedure, proposal, method, and/or operational flowchart, etc.
  • one or more antennas may be multiple physical antennas, or multiple logical antennas (e.g., antenna ports).
  • One or more transceivers (106, 206) may convert received user data, control information, wireless signals/channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals/channels, etc. using one or more processors (102, 202).
  • One or more transceivers (106, 206) may convert processed user data, control information, wireless signals/channels, etc. from baseband signals to RF band signals using one or more processors (102, 202).
  • one or more transceivers (106, 206) may include an (analog) oscillator and/or filter.
  • one of the STAs (100, 200) may perform the intended operation of an AP, and the other of the STAs (100, 200) may perform the intended operation of a non-AP STA.
  • the transceivers (106, 206) of FIG. 1 may perform transmission and reception operations of signals (e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a/b/g/n/ac/ax/be/bn, etc.).
  • signals e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a/b/g/n/ac/ax/be/bn, etc.
  • operations of various STAs generating transmission and reception signals or performing data processing or calculations in advance for transmission and reception signals may be performed in the processors (102, 202) of FIG. 1.
  • an example of an operation for generating a transmit/receive signal or performing data processing or calculation in advance for a transmit/receive signal may include: 1) an operation for determining/acquiring/configuring/computing/decoding/encoding bit information of a field (SIG (signal), STF (short training field), LTF (long training field), Data, etc.) included in a PPDU, 2) an operation for determining/configuring/acquiring time resources or frequency resources (e.g., subcarrier resources) used for the fields (SIG, STF, LTF, Data, etc.) included in a PPDU, 3) an operation for determining/configuring/acquiring specific sequences (e.g., pilot sequences, STF/LTF sequences, extra sequences applied to SIG) used for the fields (SIG, STF, LTF, Data, etc.) included in a PPDU, 4) a power control operation and/or a power saving operation applied to an STA, 5) an operation related to determining/acquiring/acquiring/
  • various information e.g., information related to fields/subfields/control fields/parameters/power, etc.
  • various information e.g., information related to fields/subfields/control fields/parameters/power, etc.
  • various STAs for determining/acquiring/configuring/computing/decoding/encoding transmission/reception signals can be stored in the memory (104, 204) of FIG. 1.
  • downlink means a link for communication from an AP STA to a non-AP STA, and downlink PPDU/packet/signal, etc. can be transmitted and received through the downlink.
  • a transmitter may be part of an AP STA, and a receiver may be part of a non-AP STA.
  • Uplink (UL) means a link for communication from a non-AP STA to an AP STA, and uplink PPDU/packet/signal, etc. can be transmitted and received through the uplink.
  • a transmitter may be part of a non-AP STA, and a receiver may be part of an AP STA.
  • FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
  • a wireless LAN supporting transparent STA mobility to a higher layer can be provided through the interaction of multiple components.
  • a BSS Basic Service Set
  • FIG. 2 illustrates an example in which two BSSs (BSS1 and BSS2) exist and two STAs are included as members of each BSS (STA1 and STA2 are included in BSS1, and STA3 and STA4 are included in BSS2).
  • An ellipse representing a BSS in FIG. 2 can also be understood as representing a coverage area in which STAs included in the corresponding BSS maintain communication. This area can be referred to as a BSA (Basic Service Area). If an STA moves out of the BSA, it cannot directly communicate with other STAs within the corresponding BSA.
  • BSA Basic Service Area
  • an IBSS can have a minimal form consisting of only two STAs.
  • BSS1 consisting of only STA1 and STA2
  • BSS2 consisting of only STA3 and STA4
  • This configuration is possible when STAs can communicate directly without an AP.
  • a LAN can be configured when needed rather than being planned in advance, and this can be called an ad-hoc network.
  • an IBSS does not include an AP, there is no centralized management entity that performs management functions. That is, in an IBSS, STAs are managed in a distributed manner. In IBSS, all STAs can be mobile STAs, and access to distributed systems (DS) is not permitted, forming a self-contained network.
  • DS distributed systems
  • the membership of an STA in a BSS can be dynamically changed by the STA turning on or off, the STA entering or leaving the BSS area, etc.
  • an STA can join the BSS using a synchronization process.
  • an STA In order to access all services of the BSS infrastructure, an STA must be associated with a BSS. This association can be dynamically established and may include the use of a Distribution System Service (DSS).
  • DSS Distribution System Service
  • the direct STA-to-STA distance may be limited by the PHY performance. In some cases, this distance limitation may be sufficient, but in some cases, communication between STAs over longer distances may be required.
  • a distributed system may be configured.
  • DS refers to a structure in which BSSs are interconnected.
  • a BSS may exist as an extended component of a network composed of multiple BSSs, as shown in FIG. 2.
  • DS is a logical concept and can be specified by the characteristics of a distributed system medium (DSM).
  • DSM distributed system medium
  • WM wireless medium
  • DSM distributed system medium
  • Each logical medium is used for a different purpose and is used by different components. These media are neither limited to being the same nor limited to being different.
  • the flexibility of a wireless LAN structure can be explained in that multiple media are logically different.
  • a wireless LAN structure can be implemented in various ways, and each wireless LAN structure can be independently specified by the physical characteristics of each implementation example.
  • a DS can support mobile devices by providing seamless integration of multiple BSSs and providing logical services necessary to handle addresses to destinations.
  • a DS can further include a component called a portal that acts as a bridge for connecting wireless LANs to other networks (e.g., IEEE 802.X).
  • An AP is an entity that enables access to a DS through a WM for associated non-AP STAs, and also has the functionality of an STA. Data movement between a BSS and a DS can be performed through an AP.
  • STA2 and STA3 illustrated in FIG. 2 have the functionality of an STA, and provide a function that allows associated non-AP STAs (STA1 and STA4) to access the DS.
  • all APs are basically STAs, all APs are addressable entities.
  • the address used by an AP for communication on a WM and the address used by an AP for communication on a DSM need not necessarily be the same.
  • a BSS consisting of an AP and one or more STAs can be called an infrastructure BSS.
  • Data transmitted from one of the STA(s) associated with an AP to the STA address of that AP is always received on an uncontrolled port and can be processed by an IEEE 802.1X port access entity.
  • the transmitted data (or frame) can be forwarded to the DS.
  • an Extended Service Set may be established to provide wider coverage.
  • An ESS is a network of arbitrary size and complexity consisting of DS and BSS.
  • An ESS may correspond to a set of BSSs connected to a DS. However, an ESS does not include a DS.
  • An ESS network is characterized by being seen as an IBSS in the LLC (Logical Link Control) layer. STAs included in an ESS can communicate with each other, and mobile STAs can move from one BSS to another BSS (within the same ESS) transparently to the LLC.
  • APs included in an ESS may have the same SSID (service set identification). The SSID is distinct from the BSSID, which is an identifier of the BSS.
  • the BSSs can be partially overlapped, which is a common configuration used to provide continuous coverage.
  • the BSSs can be physically unconnected, and logically there is no limit to the distance between the BSSs.
  • the BSSs can be physically co-located, which can be used to provide redundancy.
  • one (or more) IBSS or ESS networks can physically co-exist in the same space as one (or more) ESS networks. This can correspond to ESS network configurations such as cases where ad-hoc networks operate at locations where ESS networks exist, cases where physically overlapping wireless networks are configured by different organizations, or cases where two or more different access and security policies are required at the same location.
  • FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.
  • the link setup process may also be referred to as a session initiation process or a session setup process.
  • the discovery, authentication, association, and security setup processes of the link setup process may be collectively referred to as the association process.
  • the STA may perform a network discovery operation.
  • the network discovery operation may include a scanning operation of the STA. That is, in order for the STA to access the network, it must find a network that it can participate in. The STA must identify a compatible network before participating in the wireless network, and the process of identifying networks existing in a specific area is called scanning.
  • FIG. 3 illustrates a network discovery operation including an active scanning process as an example.
  • active scanning an STA performing scanning transmits a probe request frame to search for APs in the vicinity while moving between channels and waits for a response thereto.
  • a responder transmits a probe response frame to the STA that transmitted the probe request frame as a response to the probe request frame.
  • the responder may be an STA that last transmitted a beacon frame in the BSS of the channel being scanned.
  • the AP transmits a beacon frame, so the AP becomes the responder, and in the IBSS, the STAs within the IBSS take turns transmitting beacon frames, so the responder is not fixed.
  • an STA that transmits a probe request frame on channel 1 and receives a probe response frame on channel 1 can store BSS-related information included in the received probe response frame and move to the next channel (e.g., channel 2) to perform scanning (i.e., transmitting and receiving probe request/response on channel 2) in the same manner.
  • the next channel e.g., channel 2
  • scanning i.e., transmitting and receiving probe request/response on channel 2
  • the authentication process includes the STA sending an authentication request frame to the AP, and the AP sending an authentication response frame to the STA in response.
  • the authentication frame used for the authentication request/response corresponds to a management frame.
  • the authentication frame may include information such as an authentication algorithm number, an authentication transaction sequence number, a status code, a challenge text, a Robust Security Network (RSN), a Finite Cyclic Group, etc. These are just some examples of information that may be included in an authentication request/response frame, and may be replaced by other information or may include additional information.
  • RSN Robust Security Network
  • the STA may transmit an authentication request frame to the AP.
  • the AP may determine whether to allow authentication for the STA based on information included in the received authentication request frame.
  • the AP may provide the result of the authentication processing to the STA through an authentication response frame.
  • an association process may be performed in step S330.
  • the association process includes a process in which the STA transmits an association request frame to the AP, and in response, the AP transmits an association response frame to the STA.
  • the association request frame may include information about various capabilities, a beacon listen interval, a service set identifier (SSID), supported rates, supported channels, RSN, mobility domains, supported operating classes, a Traffic Indication Map Broadcast request, interworking service capabilities, etc.
  • the association response frame may include information about various capabilities, a status code, an Association ID (AID), supported rates, an Enhanced Distributed Channel Access (EDCA) parameter set, a Received Channel Power Indicator (RCPI), a Received Signal to Noise Indicator (RSNI), a mobility domain, a timeout interval (e.g., association comeback time), overlapping BSS scan parameters, a TIM broadcast response, a Quality of Service (QoS) map, etc.
  • AID Association ID
  • EDCA Enhanced Distributed Channel Access
  • RCPI Received Channel Power Indicator
  • RSNI Received Signal to Noise Indicator
  • timeout interval e.g., association comeback time
  • overlapping BSS scan parameters e.g., TIM broadcast response
  • a security setup process may be performed in step S340.
  • the security setup process of step S340 may be referred to as an authentication process through a Robust Security Network Association (RSNA) request/response
  • the authentication process of step S320 may be referred to as a first authentication process
  • the security setup process of step S340 may be referred to simply as an authentication process.
  • RSNA Robust Security Network Association
  • the security setup process of step S340 may include a process of performing private key setup, for example, through 4-way handshaking via an Extensible Authentication Protocol over LAN (EAPOL) frame. Additionally, the security setup process may be performed according to a security method not defined in the IEEE 802.11 standard.
  • EAPOL Extensible Authentication Protocol over LAN
  • FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.
  • the basic access mechanism of MAC is the CSMA/CA (Carrier Sense Multiple Access with Collision Avoidance) mechanism.
  • the CSMA/CA mechanism is also called the Distributed Coordination Function (DCF) of IEEE 802.11 MAC, and basically adopts the "listen before talk" access mechanism.
  • DCF Distributed Coordination Function
  • the AP and/or STA may perform a Clear Channel Assessment (CCA) to sense the wireless channel or medium for a predetermined time period (e.g., a DCF Inter-Frame Space (DIFS)) before starting transmission. If the sensing result determines that the medium is in an idle state, the AP and/or STA may start transmitting frames through the medium.
  • CCA Clear Channel Assessment
  • DIFS DCF Inter-Frame Space
  • the AP and/or STA may not start its own transmission, but may wait for a delay period (e.g., a random backoff period) for medium access and then attempt to transmit frames.
  • a delay period e.g., a random backoff period
  • the IEEE 802.11 MAC protocol provides a Hybrid Coordination Function (HCF).
  • the HCF is based on the DCF and the Point Coordination Function (PCF).
  • the PCF is a polling-based synchronous access method in which all receiving APs and/or STAs periodically poll to receive data frames.
  • the HCF has EDCA (Enhanced Distributed Channel Access) and HCCA (HCF Controlled Channel Access).
  • EDCA is a contention-based access method in which a provider provides data frames to multiple users, and HCCA uses a non-contention-based channel access method using a polling mechanism.
  • the HCF includes a medium access mechanism for improving the QoS (Quality of Service) of a wireless LAN, and can transmit QoS data in both a contention period (CP) and a contention-free period (CFP).
  • QoS Quality of Service
  • a random backoff period When an occupied/busy medium changes to an idle state, multiple STAs may attempt to transmit data (or frames). As a measure to minimize collisions, each STA may select a random backoff count, wait for a corresponding slot time, and then attempt to transmit.
  • the random backoff count has a pseudo-random integer value and may be determined as one of the values in the range of 0 to CW.
  • CW is a contention window parameter value.
  • the CW parameter is initially given CWmin, but may take a double value in case of a transmission failure (e.g., when an ACK for a transmitted frame is not received).
  • the STA continues to monitor the medium while counting down the backoff slots according to the determined backoff count value. If the medium is monitored as occupied, the countdown stops and waits, and when the medium becomes idle, the remaining countdown is resumed.
  • STA3 when a packet to be transmitted reaches the MAC of STA3, STA3 can check that the medium is idle for DIFS and transmit the frame right away. The remaining STAs monitor whether the medium is occupied/busy and wait. In the meantime, data to be transmitted may also occur in each of STA1, STA2, and STA5, and each STA can perform a countdown of the backoff slot according to a random backoff count value selected by each STA after waiting for DIFS when the medium is monitored as idle. Assume that STA2 selects the smallest backoff count value and STA1 selects the largest backoff count value.
  • this example shows a case where the remaining backoff time of STA5 is shorter than the remaining backoff time of STA1 when STA2 finishes the backoff count and starts frame transmission.
  • STA1 and STA5 briefly stop the countdown and wait while STA2 occupies the medium.
  • STA1 and STA5 resume the stopped backoff count after waiting for DIFS. That is, they can start frame transmission after counting down the remaining backoff slots by the remaining backoff time. Since the remaining backoff time of STA5 is shorter than that of STA1, STA5 starts frame transmission. While STA2 occupies the medium, STA4 may also have data to transmit.
  • STA4 From STA4's perspective, when the medium becomes idle, it waits for DIFS, performs a countdown according to the random backoff count value it selected, and starts frame transmission.
  • the remaining backoff time of STA5 coincidentally matches the random backoff count value of STA4, and in this case, a collision may occur between STA4 and STA5. If a collision occurs, neither STA4 nor STA5 will receive an ACK, resulting in a failure in data transmission. In this case, STA4 and STA5 can select a random backoff count value and perform a countdown after doubling the CW value.
  • STA1 waits while the medium is occupied by transmissions from STA4 and STA5, and when the medium becomes idle, it waits for DIFS, and then starts transmitting frames after the remaining backoff time has elapsed.
  • a data frame is a frame used for transmitting data forwarded to a higher layer, and can be transmitted after a backoff performed after DIFS elapses from when the medium becomes idle.
  • a management frame is a frame used for exchanging management information that is not forwarded to a higher layer, and is transmitted after a backoff performed after an IFS such as DIFS or PIFS (Point coordination function IFS) elapses.
  • Subtype frames of the management frame include a beacon, an association request/response, a re-association request/response, a probe request/response, and an authentication request/response.
  • a control frame is a frame used to control access to the medium.
  • the subtype frames of the control frame include RTS (Request-To-Send), CTS (Clear-To-Send), ACK (Acknowledgment), PS-Poll (Power Save-Poll), Block ACK (BlockAck), Block ACK Request (BlockACKReq), NDP notification (null data packet announcement), and Trigger. If the control frame is not a response frame to the previous frame, it is transmitted after the backoff performed after the DIFS (DIFS), and if it is a response frame to the previous frame, it is transmitted without the backoff performed after the SIFS (short IFS).
  • DIFS DIFS
  • SIFS short IFS
  • a QoS (Quality of Service) STA can transmit a frame after a backoff performed after the AIFS (arbitration IFS) for the access category (AC) to which the frame belongs, that is, AIFS[i] (where i is a value determined by the AC), has elapsed.
  • AIFS aromatic IFS
  • the frames for which AIFS[i] can be used can be data frames, management frames, and also control frames that are not response frames.
  • FIG. 5 is a diagram for explaining a CSMA/CA-based frame transmission operation to which the present disclosure can be applied.
  • the CSMA/CA mechanism includes virtual carrier sensing in addition to physical carrier sensing in which an STA directly senses the medium.
  • Virtual carrier sensing is intended to complement problems that may occur in medium access, such as the hidden node problem.
  • the MAC of the STA may utilize a Network Allocation Vector (NAV).
  • NAV Network Allocation Vector
  • the NAV is a value that indicates to other STAs the remaining time until the medium becomes available, by an STA that is currently using or has the right to use the medium. Therefore, the value set as NAV corresponds to the period during which the medium is scheduled to be used by the STA transmitting the corresponding frame, and the STA that receives the NAV value is prohibited from accessing the medium during the corresponding period.
  • the NAV may be set based on the value of the "duration" field of the MAC header of the frame.
  • STA1 wants to transmit data to STA2, and STA3 is in a position to overhear part or all of the frames transmitted and received between STA1 and STA2.
  • a mechanism using RTS/CTS frames may be applied.
  • STA3 may determine that the carrier sensing result of the medium is idle. That is, STA1 may correspond to a hidden node to STA3.
  • STA2 may transmitting, STA3 may determine that the carrier sensing result of the medium is idle. That is, STA2 may correspond to a hidden node to STA3.
  • STAs outside the transmission range of either STA1 or STA2, or STAs outside the carrier sensing range for transmission from STA1 or STA3 may not attempt to occupy the channel during data transmission and reception between STA1 and STA2.
  • STA1 can determine whether a channel is occupied through carrier sensing.
  • STA1 can determine a channel occupied idle state based on energy magnitude or signal correlation detected in the channel.
  • STA1 can determine a channel occupied state using a network allocation vector (NAV) timer.
  • NAV network allocation vector
  • STA1 can transmit an RTS frame to STA2 after performing a backoff if the channel is idle during DIFS.
  • STA2 can transmit a CTS frame, which is a response to the RTS frame, to STA1 after SIFS if it receives the RTS frame.
  • STA3 can set a NAV timer for the subsequently transmitted frame transmission period (e.g., SIFS + CTS frame + SIFS + data frame + SIFS + ACK frame) using the duration information included in the RTS frame.
  • STA3 can set a NAV timer for the subsequently transmitted frame transmission period (e.g., SIFS + data frame + SIFS + ACK frame) using the duration information included in the CTS frame.
  • STA3 can overhear one or more of the RTS or CTS frames from one or more of STA1 or STA2, it can set a NAV accordingly.
  • STA3 can update the NAV timer using the duration information contained in the new frame if it receives a new frame before the NAV timer expires. STA3 does not attempt to access the channel until the NAV timer expires.
  • STA1 receives a CTS frame from STA2, it can transmit a data frame to STA2 after SIFS from the time when reception of the CTS frame is completed. If STA2 successfully receives the data frame, it can transmit an ACK frame in response to the data frame to STA1 after SIFS.
  • STA3 can determine whether the channel is in use through carrier sensing if the NAV timer expires. If STA3 determines that the channel is not in use by other terminals during DIFS after the expiration of the NAV timer, it can attempt channel access after a contention window (CW) following a random backoff has elapsed.
  • CW contention window
  • FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.
  • PPDU PHY layer Protocol Data Unit
  • a basic PPDU may include a Short Training Field (STF), a Long Training Field (LTF), a SIGNAL (SIG) field, and a Data field.
  • STF Short Training Field
  • LTF Long Training Field
  • SIG SIGNAL
  • PPDU format may consist of only a Legacy-STF (L-STF), a Legacy-LTF (L-LTF), a Legacy-SIG (Legacy-SIG) field, and a Data field.
  • RL-SIG RL-SIG
  • U-SIG non-legacy SIG field
  • non-legacy STF non-legacy LTF
  • xx-SIG xx-SIG
  • xx-LTF e.g., xx represents HT, VHT, HE, EHT, etc.
  • STF is a signal for signal detection, AGC (Automatic Gain Control), diversity selection, precise time synchronization, etc.
  • LTF is a signal for channel estimation, frequency error estimation, etc. STF and LTF can be said to be signals for OFDM physical layer synchronization and channel estimation.
  • the SIG field may include various information related to PPDU transmission and reception.
  • the L-SIG field may consist of 24 bits and may include a 4-bit Rate field, a 1-bit Reserved bit, a 12-bit Length field, a 1-bit Parity field, and a 6-bit Tail field.
  • the RATE field may include information about a modulation and coding rate of data.
  • the 12-bit Length field may include information about the length or time duration of the PPDU.
  • the value of the 12-bit Length field may be determined based on the type of the PPDU. For example, for a non-HT, HT, VHT, or EHT PPDU, the value of the Length field may be determined as a multiple of 3.
  • the value of the Length field can be determined as a multiple of 3 + 1 or a multiple of 3 + 2.
  • the data field may include a SERVICE field, a Physical layer Service Data Unit (PSDU), a PPDU TAIL bit, and, if necessary, padding bits.
  • PSDU Physical layer Service Data Unit
  • PPDU TAIL bit may be used to return the encoder to the 0 state.
  • padding bit may be used to adjust the length of the data field to a predetermined unit.
  • MAC PDU is defined according to various MAC frame formats, and the basic MAC frame consists of a MAC header, frame body, and FCS (Frame Check Sequence).
  • MAC frame consists of MAC PDU and can be transmitted/received through PSDU of the data part of PPDU format.
  • the MAC header includes a Frame Control field, a Duration/ID field, an Address field, etc.
  • the Frame Control field may include control information required for frame transmission/reception.
  • the Duration/ID field may be set to a time for transmitting the corresponding frame, etc.
  • the Address subfields may indicate a receiver address, a transmitter address, a destination address, and a source address of the frame, and some Address subfields may be omitted. For specific details of each subfield of the MAC header, including the Sequence Control, QoS Control, and HT Control subfields, refer to the IEEE 802.11 standard document.
  • Null-Data PPDU (NDP) format refers to a PPDU format that does not include a data field. That is, NDP refers to a frame format that includes a PPDU preamble (i.e., L-STF, L-LTF, L-SIG fields, and additionally, non-legacy SIG, non-legacy STF, non-legacy LTF if present) in a general PPDU format, and does not include the remaining part (i.e., data field).
  • a PPDU preamble i.e., L-STF, L-LTF, L-SIG fields, and additionally, non-legacy SIG, non-legacy STF, non-legacy LTF if present
  • FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.
  • the basic PPDU format (IEEE 802.11a/g) includes L-LTF, L-STF, L-SIG, and Data fields.
  • the basic PPDU format can also be called a non-HT PPDU format (Fig. 7(a)).
  • the HT PPDU format (IEEE 802.11n) additionally includes HT-SIG, HT-STF, and HT-LFT(s) fields in the basic PPDU format.
  • the HT PPDU format illustrated in Fig. 7(b) may be referred to as an HT-mixed format.
  • an HT-greenfield format PPDU may be defined, which corresponds to a format that does not include L-STF, L-LTF, and L-SIG, and consists of HT-GF-STF, HT-LTF1, HT-SIG, one or more HT-LTF, and Data fields (not illustrated).
  • VHT PPDU format includes VHT SIG-A, VHT-STF, VHT-LTF, and VHT-SIG-B fields in addition to the basic PPDU format (Fig. 7(c)).
  • HE PPDU format (IEEE 802.11ax) additionally includes RL-SIG (Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), and PE (Packet Extension) fields in the basic PPDU format (Fig. 7(d)).
  • RL-SIG Repeated L-SIG
  • HE-SIG-A HE-SIG-B
  • HE-STF HE-LTF(s)
  • PE Packet Extension
  • some fields may be excluded or their lengths may vary.
  • the HE-SIG-B field is included in a HE PPDU format for multi-users (MUs), and the HE PPDU format for single users (SUs) does not include the HE-SIG-B.
  • a HE trigger-based (TB) PPDU format does not include the HE-SIG-B, and the length of the HE-STF field may vary to 8us.
  • a HE ER (Extended Range) SU PPDU format does not include the HE-SIG-B field, and the length of the HE-SIG-A field may vary to 16us.
  • RL-SIG can be configured identically to L-SIG. The receiving STA can know that the received PPDU is a HE PPDU or an EHT PPDU, described later, based on the presence of RL-SIG.
  • the EHT PPDU format may include the EHT MU (multi-user) PPDU of Fig. 7(e) and the EHT TB (trigger-based) PPDU of Fig. 7(f).
  • the EHT PPDU format is similar to the HE PPDU format in that it includes an RL-SIG following an L-SIG, but it may include a U (universal)-SIG, an EHT-SIG, an EHT-STF, and an EHT-LTF following the RL-SIG.
  • the EHT MU PPDU in Fig. 7(e) corresponds to a PPDU that carries one or more data (or PSDU) for one or more users. That is, the EHT MU PPDU can be used for both SU transmission and MU transmission.
  • the EHT MU PPDU can correspond to a PPDU for one receiving STA or multiple receiving STAs.
  • the EHT TB PPDU of Fig. 7(f) omits EHT-SIG compared to the EHT MU PPDU.
  • An STA that has received a trigger for UL MU transmission e.g., a trigger frame or TRS (triggered response scheduling)
  • TRS triggered response scheduling
  • the L-STF, L-LTF, L-SIG, RL-SIG, U-SIG (Universal SIGNAL), and EHT-SIG fields can be encoded and modulated and mapped based on a predetermined subcarrier frequency interval (e.g., 312.5 kHz) so that even legacy STAs can attempt to demodulate and decode them. These can be referred to as pre-EHT modulated fields.
  • the EHT-STF, EHT-LTF, Data, and PE fields can be encoded and modulated and mapped based on a predetermined subcarrier frequency interval (e.g., 78.125 kHz) so that they can be demodulated and decoded by an STA that successfully decodes a non-legacy SIG (e.g., U-SIG and/or EHT-SIG) and obtains the information included in the corresponding fields.
  • a predetermined subcarrier frequency interval e.g., 78.125 kHz
  • a non-legacy SIG e.g., U-SIG and/or EHT-SIG
  • EHT modulated fields e.g., U-SIG and/or EHT-SIG
  • the L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, and HE-SIG-B fields may be referred to as pre-HE modulation fields, and the HE-STF, HE-LTF, Data, and PE fields may be referred to as HE modulation fields.
  • the L-STF, L-LTF, L-SIG, and VHT-SIG-A fields may be referred to as pre-VHT modulation fields
  • the VHT STF, VHT-LTF, VHT-SIG-B, and Data fields may be referred to as VHT modulation fields.
  • the U-SIG included in the EHT PPDU format of Fig. 7 can be configured based on, for example, two symbols (e.g., two consecutive OFDM symbols).
  • Each symbol (e.g., OFDM symbol) for the U-SIG can have a duration of 4us, and the U-SIG can have a total duration of 8us.
  • Each symbol of the U-SIG can be used to transmit 26 bits of information.
  • each symbol of the U-SIG can be transmitted and received based on 52 data tones and 4 pilot tones.
  • U-SIG can be configured in 20MHz units. For example, when an 80MHz PPDU is configured, the same U-SIG can be replicated in 20MHz units. That is, four identical U-SIGs can be included in an 80MHz PPDU. When the bandwidth exceeds 80MHz, for example, for a 160MHz PPDU, the U-SIG of the first 80MHz unit and the U-SIG of the second 80MHz unit can be different.
  • a uncoded bits can be transmitted, and a first symbol of U-SIG (e.g., U-SIG-1 symbol) can transmit the first X bits of information out of the total A bits of information, and a second symbol of U-SIG (e.g., U-SIG-2 symbol) can transmit the remaining Y bits of information out of the total A bits of information.
  • the A bits of information e.g., 52 uncoded bits
  • the tail field can be used to terminate the trellis of the convolutional decoder and can be set to 0, for example.
  • the A bit information transmitted by U-SIG can be divided into version-independent bits and version-dependent bits.
  • U-SIG may be included in a new PPDU format (e.g., UHR PPDU format) not shown in FIG. 7, and in the format of the U-SIG field included in the EHT PPDU format and the format of the U-SIG field included in the UHR PPDU format, the version-independent bits may be the same, and some or all of the version-dependent bits may be different.
  • the size of the version-independent bits of U-SIG can be fixed or variable.
  • the version-independent bits can be assigned only to U-SIG-1 symbols, or to both U-SIG-1 symbols and U-SIG-2 symbols.
  • the version-independent bits and the version-dependent bits can be called by various names, such as the first control bit and the second control bit.
  • the version-independent bits of U-SIG may include a 3-bit PHY version identifier, which may indicate the PHY version (e.g., EHT, UHR, etc.) of the transmitted and received PPDU.
  • the version-independent bits of U-SIG may include a 1-bit UL/DL flag field. The first value of the 1-bit UL/DL flag field relates to UL communication, and the second value of the UL/DL flag field relates to DL communication.
  • the version-independent bits of U-SIG may include information about the length of a TXOP (transmission opportunity) and information about a BSS color ID.
  • the version-dependent bits of the U-SIG may contain information that directly or indirectly indicates the type of the PPDU (e.g., SU PPDU, MU PPDU, TB PPDU, etc.).
  • the U-SIG may further include information about bandwidth, information about an MCS technique applied to a non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.), information indicating whether a dual carrier modulation (DCM) technique (e.g., a technique for achieving an effect similar to frequency diversity by reusing the same signal on two subcarriers) is applied to the non-legacy SIG, information about the number of symbols used for the non-legacy SIG, information about whether the non-legacy SIG is generated over the entire band, etc.
  • DCM dual carrier modulation
  • Some of the information required for PPDU transmission and reception may be included in the U-SIG and/or the non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.).
  • information about the type of non-legacy LTF/STF e.g., EHT-LTF/EHT-STF or UHR-LTF/UHR-STF, etc.
  • information about the length of the non-legacy LTF and the cyclic prefix (CP) length e.g., EHT-LTF/EHT-STF or UHR-LTF/UHR-STF, etc.
  • information about the length of the non-legacy LTF and the cyclic prefix (CP) length e.g., information about the guard interval (GI) applied to the non-legacy LTF
  • information about the preamble puncturing applicable to the PPDU e.g., information about the resource unit (RU) allocation, etc.
  • RU resource unit
  • Preamble puncturing may mean transmission of a PPDU in which no signal is present in one or more frequency units within the bandwidth of the PPDU.
  • the size of the frequency unit (or the resolution of the preamble puncturing) may be defined as 20 MHz, 40 MHz, etc.
  • preamble puncturing may be applied to a PPDU bandwidth greater than a predetermined size.
  • non-legacy SIGs such as HE-SIG-B, EHT-SIG, etc. may include control information for the receiving STA.
  • the non-legacy SIG may be transmitted through at least one symbol, and one symbol may have a length of 4 us.
  • Information about the number of symbols used for EHT-SIG may be included in a previous SIG (e.g., HE-SIG-A, U-SIG, etc.).
  • Non-legacy SIGs such as HE-SIG-B, EHT-SIG, etc.
  • HE-SIG-B may contain common fields and user-specific fields. Common fields and user-specific fields may be coded separately.
  • the common field may be omitted.
  • the common field may be omitted, and multiple STAs may receive a PPDU (e.g., a data field of a PPDU) over the same frequency band.
  • a PPDU e.g., a data field of a PPDU
  • multiple users may receive a PPDU (e.g., a data field of a PPDU) over different frequency bands.
  • the number of user-specific fields can be determined based on the number of users.
  • One user block field can include at most two user fields.
  • Each user field can be associated with an MU-MIMO allocation or associated with a non-MU-MIMO allocation.
  • the common field may include CRC bits and Tail bits, the length of the CRC bits may be determined as 4 bits, the length of the Tail bits may be determined as 6 bits and may be set to 000000.
  • the common field may include RU allocation information.
  • the RU allocation information may include information about the location of RUs to which multiple users (i.e., multiple receiving STAs) are allocated.
  • An RU may include multiple subcarriers (or tones). An RU may be used when transmitting signals to multiple STAs based on the OFDMA technique. An RU may also be defined when transmitting signals to one STA. Resources may be allocated in RU units for non-legacy STFs, non-legacy LTFs, and Data fields.
  • an applicable size of RU can be defined.
  • the RU may be defined identically or differently for the applicable PPDU format (e.g., HE PPDU, EHT PPDU, UHR PPDU, etc.).
  • the RU arrangements of HE PPDU and EHT PPDU may be different.
  • the applicable RU size, RU number, RU position, DC (direct current) subcarrier position and number, null subcarrier position and number, guard subcarrier position and number, etc. for each PPDU bandwidth can be referred to as a tone plan.
  • a tone plan for a wide bandwidth can be defined in the form of multiple repetitions of a tone plan for a low bandwidth.
  • RUs of different sizes can be defined, such as 26-tone RU, 52-tone RU, 106-tone RU, 242-tone RU, 484-tone RU, 996-tone RU, 2 ⁇ 996-tone RU, 4 ⁇ 996-tone RU, etc.
  • a multiple RU is distinct from multiple individual RUs and corresponds to a group of subcarriers consisting of multiple RUs.
  • one MRU can be defined as 52+26-tones, 106+26-tones, 484+242-tones, 996+484-tones, 996+484+242-tones, 2 ⁇ 996+484-tones, 3 ⁇ 996-tones, or 3 ⁇ 996+484-tones.
  • multiple RUs constituting one MRU may or may not be consecutive in the frequency domain.
  • the specific size of the RU may be reduced or expanded. Therefore, the specific size of each RU (i.e., the number of corresponding tones) in the present disclosure is not limited and is exemplary. In addition, within a given bandwidth (e.g., 20, 40, 80, 160, 320 MHz, ...) in the present disclosure, the number of RUs may vary depending on the RU size.
  • each field in the PPDU formats of FIG. 7 are exemplary, and the scope of the present disclosure is not limited by the names.
  • the examples of the present disclosure can be applied not only to the PPDU format exemplified in FIG. 7, but also to a new PPDU format in which some fields are excluded and/or some fields are added based on the PPDU formats of FIG. 7.
  • Block-ACK (BlockACK, BA) frame
  • FIG. 8 is a diagram showing an exemplary format of a block-ACK frame to which the present disclosure can be applied.
  • the Block-ACK (BlockAck, BA) mechanism is a method for increasing channel efficiency by transmitting multiple acknowledgements in a single frame.
  • a first STA e.g., an AP
  • a second STA(s) that has received the Block-ACK request frame can transmit a Block-ACK frame including acknowledgements for multiple MPDUs based on the request.
  • a block-ACK frame may include a BA control field and a BA information field in the frame body.
  • the BA control field may include BA type indicating the type of block-ACK frame (e.g., compressed, multi-STA, etc.), management ACK information, TID information (TID_INFO), etc.
  • BA type indicating the type of block-ACK frame (e.g., compressed, multi-STA, etc.), management ACK information, TID information (TID_INFO), etc.
  • the BA Information field may be based on the type of block-ACK frame (i.e., block-ACK frame variant type) indicated by the BA Type field/subfield in the BA Control Information.
  • the BA information field format corresponding to the compressed block-ACK may include a Block Ack Starting Sequence Control field and a Block Ack Bitmap field.
  • the Fragment Number subfield of the Block-ACK Start Sequence Control field can be defined as shown in Table 1 below.
  • the Fragment Number subfield of the block-ACK start sequence control field may be set to all 0 values.
  • the Block-ACK Bitmap subfield of the BA Information field of the compressed block-ACK frame can indicate reception status of up to 64 or 256 MSDUs and/or A-MSDUs, depending on the values of the B2-B1 bits of the Fragment Number subfield as shown in Table 1.
  • the Block-ACK Bitmap subfield of the BA Information field of the compressed block-ACK frame can indicate reception status of up to 512 or 1024 MSDUs and/or A-MSDUs, depending on the values of the B2-B1 bits of the Fragment Number subfield as shown in Table 1.
  • Each bit equal to 1 in the compressed Block-ACK Bitmap subfield acknowledges the receipt of a single MSDU or A-MSDU in sequence number order, where the first bit of the Block-ACK Bitmap subfield may correspond to an MSDU (or fragment thereof) or A-MSDU (or fragment thereof) with a sequence number that matches the Starting Sequence Number subfield of the Block-ACK Starting Sequence Control subfield.
  • the Block-ACK Bitmap subfield of the BA Information field of the compressed Block-ACK frame can indicate reception status of up to 16 or 64 MSDUs and/or A-MSDUs according to the B2-B1 bit values of the Fragment Number subfield as shown in Table 1.
  • SSN is the value of the Starting Sequence Number subfield of the Block-ACK Starting Sequence Control subfield, and an operation on the sequence number can be performed modulo 4096. If bit position n of the Block-ACK Bitmap subfield is 0, it can indicate that the MPDU was not received.
  • the BA information field format corresponding to the multi-STA block-ACK may include one or more Per AID TID Info subfields.
  • the Per AID TID Info subfield may include an AID TID Info subfield, a Block Ack Starting Sequence Control subfield, and a Block Ack Bitmap subfield.
  • the AID TID Info subfield may include an (11-bit) AID11 subfield, a (1-bit) ACK Type subfield, and a (4-bit) TID subfield.
  • the AID11 subfield is set to 0, and the value 2045 of the AID11 subfield can be used as an identifier for an unassociated STA.
  • the values of the subfields in the Per AID TID information subfield and the presence or absence of optional subfields can be defined based on Table 2 below.
  • the Fragment Number subfield encoding may indicate the length of the Block-ACK Bitmap subfield as defined in Table 3.
  • Table 3 illustrates the Fragment Number subfield encoding for multi-STA Block-Ack types.
  • the BA Information field of the multi-STA block-ACK frame contains a Block-Ack Bitmap subfield of 8 octets, 16 octets, 32 octets or 4 octets, depending on the B2-B1 bits of the Fragment Number subfield defined in Table 3, which can indicate the reception status of up to 64, 128, 256 or 32 MSDUs (or their fragments) and/or A-MSDUs (or their fragments), respectively.
  • the BA Information field of the multi-STA block-ACK frame contains a Block Ack Bitmap subfield of 64 octets or 128 octets, depending on bits B2-B1 of the Fragment Number subfield as defined in Table 3, to indicate the reception status of up to 512 or 1024 MSDUs and/or A-MSDUs, respectively.
  • Each bit equal to 1 in the Block Ack Bitmap subfield acknowledges the reception of a single MSDU or A-MSDU in sequence number order, and the first bit of the Block Ack Bitmap subfield may correspond to an MSDU (or a fragment thereof) or an A-MSDU (or a fragment thereof) having a sequence number that matches the Starting Sequence Number subfield of the Block Ack Starting Sequence Control subfield.
  • the Block-ACK Bitmap subfield of the BA Information field of a multi-STA block-ACK frame may indicate reception status of 16, 32, 64, or 8 MSDUs and/or A-MSDUs, depending on the B2-B1 bit values of the Fragment Number subfield as shown in Table 3.
  • SSN is the value of the Starting Sequence Number subfield of the Block-ACK Starting Sequence Control subfield, and an operation on a sequence number can be performed modulo 4096. If bit position n of the Block-ACK Bitmap subfield is 0, this may indicate that the MPDU was not received.
  • BIP Broadcast/Multicast Integrity Protocol
  • BIP provides integrity and replay protection for group addressed robust management frames after the establishment of the Integrity Group Temporal Key Security Association (IGTKSA) and for beacon frames after the establishment of the Beacon Integrity Group Temporal Key Security Association (BIGTKSA). BIP also provides integrity and replay protection for individually addressed and group addressed Wake Up Radio (WUR) frames.
  • IGTKSA Integrity Group Temporal Key Security Association
  • BIP also provides integrity and replay protection for individually addressed and group addressed Wake Up Radio (WUR) frames.
  • WUR Wake Up Radio
  • BIP-CMAC-128 can provide data integrity and replay protection by using AES-128 in CMAC mode with a 128-bit integrity key and a CMAC TLen value of 128 (16 octets).
  • BIP-CMAC-256 can provide data integrity and replay protection by using AES-256 in CMAC mode with a 256-bit integrity key and a CMAC TLen value of 128 (16 octets).
  • BIP can compute MMPDU (management MPDU) MIC (message integrity code) using Integrity Group Temporal Key (IGTK) or Beacon Integrity Group Temporal Key (BIGTK).
  • IGTK Integrity Group Temporal Key
  • BIP can compute MIC to protect individually addressed WUR wake-up frames using WUR Temporal Key (WTK).
  • WTK WUR Temporal Key
  • WIGTK WUR Integrity Group Temporal Key
  • the authenticator shall distribute a new IGTK and IGTK PN (IGTK packet number, IPN) whenever it distributes a new Group Temporal Key (GTK), when management frame protection is negotiated.
  • IGTK can be identified by the MAC address of the transmitting STA and the IGTK Key ID encoded in the Key ID field in the Management MIC element (MME).
  • MME Management MIC element
  • the authenticator may distribute one new BIGTK and BIPN (BIGTK packet number) whenever it distributes a new GTK.
  • the BIGTK can be identified by the MAC address of the transmitting STA and the BIGTK Key ID encoded in the Key ID field in the MME.
  • the authenticator may distribute one new WIGTK and WIPN (WIGTK packet number) whenever it distributes a new GTK.
  • WIGTK can be identified by the MAC address of the transmitting STA and the WIGTK Key ID encoded in the Key ID field in the MME.
  • Figure 9 illustrates a BIP MMPDU format that can be applied to the present disclosure.
  • BIP encapsulation i.e., BIP MPPDU format
  • BIP MPPDU format may include a MAC header (e.g., IEEE 802.11 header), a management frame body including an MME (Management MIC element), and an FCS.
  • MAC header e.g., IEEE 802.11 header
  • MME Management MIC element
  • FCS FCS
  • the MME format may include element ID information, length information, Key ID information, PN information (e.g., IPN, BIPN, WIPN, etc.), and MIC information.
  • additional authentication data (e.g., BIP AAD) utilized for BIP-based integrity check may be constructed from the MAC header.
  • the AAD may be constructed of an MPDU frame control field and address information.
  • a 20-octet BIP AAD may include a 2-octet MPDU frame control field, a 6-octet MPDU address 1 field, a 6-octet MPDU address 2 field, and a 6-octet MPDU address 3 field.
  • TKIP Temporal Key Integrity Protocol
  • CTR with CBC-MAC protocol CTR with CBC-MAC protocol
  • GCM Protocol GCM Protocol
  • individually addressed data frames e.g., unicast-based data frames
  • management frames s
  • pairwise transient key PTK
  • encryption/decryption based on TKIP/CCMP/GCMP can be performed/applied for group addressed frames (e.g., broadcast-based data frames) using a group temporal key (GTK).
  • GTK group temporal key
  • CCMP/GCMP is a security protocol that performs encryption/decryption, and in the case of a single-user (SU), a TK based on PTK can be used, and in the case of a multi-user (MU), a TK based on GTK can be used.
  • CCMP/GCMP can ensure confidentiality and integrity of data frames and management frame(s).
  • BIP-based integrity check can be performed using IGTK (integrity group temporal key).
  • BIP-based integrity check can be performed using BIGTK (beacon integrity group temporal key).
  • a TK based on IGTK/BIGTK is used to generate a MIC (message integrity code) for the frame body of the corresponding data frame, and an integrity check based on this can be performed. That is, unlike CCMP/GCMP, BIP can guarantee the integrity of only data frames and management frame(s).
  • MPDUs are constructed based on CCMP and GCMP and the way MMPDUs (management MPDUs) are constructed based on BIP have the following differences:
  • the transmitting STA encrypts the data portion with CCM/GCM, transmits the encrypted data, and the receiving STA can decrypt the received encrypted data.
  • the transmitting STA does not encrypt the data portion, and can perform the corresponding protocol to generate a MIC for integrity check of the data of the frame body.
  • the MPDU may be configured and transmitted/received in the order of a MAC header, a CCMP/GCMP header, encrypted data, a MIC (encrypted MIC in case of CCMP), and an FCS.
  • the MPDU may be configured and transmitted/received in the order of a MAC header, a management frame body including an MME (management MIC element), and an FCS.
  • MME management MIC element
  • the MME replaces the role of the CCMP/GCMP header, it may include information on a Key ID field, IPN/BIPN, and MIC.
  • protection is supported for management frames including data frames and beacon frames among group addressed frames.
  • protection is not supported for control frames, and thus control frames are transmitted and received without any encryption/decryption and/or integrity check protocols being applied.
  • ACK and Block-ACK (BlockAck, Block Ack, BA) frames correspond to a type of control frame.
  • a transmitting STA transmits data a receiving STA can transmit an ACK for the data to the transmitting STA.
  • STA(s) supporting A(aggregated)-MPDU can configure the ACK as an A-MPDU and transmit it in the form of a block-ACK.
  • a block-ACK frame belonging to a control frame can be composed of a compressed block-ACK type in which one STA transmits a block-ACK and a multi-STA block-ACK type in which ACKs of multiple STAs are transmitted in the form of block-ACKs.
  • a compressed block-ACK type in which one STA transmits a block-ACK
  • a multi-STA block-ACK type in which ACKs of multiple STAs are transmitted in the form of block-ACKs.
  • an AID11 subfield can be included in the BA information field of the block-ACK frame, and by distinguishing which STA transmitted the ACK information through the corresponding AID, ACK information for each STA can be included in the block-ACK frame. Based on this, duplicated information for each user/STA in the block-ACK frame can be omitted to reduce overhead.
  • the ACK information which confirms whether data is transmitted and received between the transmitting STA and the receiving STA, may be damaged.
  • an attack on the block-ACK frame may result in a decrease in the data transmission and reception capability and waste of power/medium.
  • the present disclosure proposes a security technique for ensuring the integrity of a block-ACK frame transmitted and received between a transmitting STA and a receiving STA.
  • the STA in this disclosure may include a non-AP STA and an AP STA.
  • the receiving STAs that receive the block-ACK frame according to the method proposed in Embodiment 1-4 may include a pre-UHR STA (e.g., a legacy STA, an EHT STA, etc.) and UHR STA(s) (e.g., non-legacy STA(s)).
  • Pre-UHR STA may mean an STA that does not support protection for block-ACK frames
  • UHR STA may mean an STA that can support protection for block-ACK frames.
  • performing an integrity check on a block-ACK frame can be interpreted as extending and applying BIP to a block-ACK frame.
  • additional provisions for control frames may be defined for the previously defined BIP, or a separate protocol based on BIP for integrity check of control frames may be newly defined.
  • the present embodiment relates to a block-ACK frame configuration method for supporting integrity check. Specifically, in order to apply BIP to a block-ACK frame, the present disclosure proposes a configuration in which protection-related information is included in a sub-form within a block-ACK frame, instead of including an MME (management MIC element) at the end of the frame body when applying BIP to a management frame.
  • MME management MIC element
  • FIG. 10 illustrates a protection information field/subfield format according to an embodiment of the present disclosure.
  • a Protection Info (sub)field format including information required for integrity check may include Key ID information, PN related information (e.g., IPN/BIPN information), and MIC information.
  • the corresponding protection information (sub)field format may be included as a sub-field of the protection information subfield within the block-ACK frame.
  • each piece of information included in the format is not limited to that shown in Fig. 10.
  • the key ID field may have a length of 2 octets for a key ID indicating IGTK or BIGTK, but may have a length of 2 bits for a key ID indicating GTK.
  • the MIC field may have a length of 8 octets, 16 octets, 64 octets, etc. Additionally, the length may be changed by additionally applying the MIC value to a separate function.
  • the key ID information may not be included in the corresponding protection information (sub)field.
  • the present disclosure is illustrated by using, but not limited to, a protection information (sub)field format as illustrated in FIG. 10, in which the information is additionally configured in a block-ACK frame. That is, the key ID, the PN related information, and/or the MIC may be separately/distributed and included in the control frame to which security is applied.
  • the information about the key ID may be located at a position preceding the protection information (sub)field configured with the PN related information and the MIC (e.g., within the BA Control field, the BA Information field, or a separate Per AID TID Info field within the block-ACK frame).
  • a block-ACK frame for integrity checking may be constructed based on one or more of the formats described below.
  • the protection information (sub)field according to the present disclosure may be located within the BA control field included in the block-ACK frame.
  • a protection information (sub)field can be included at the end of that field.
  • FIG. 11 illustrates an example of a block-ACK frame configuration supporting integrity checking according to an embodiment of the present disclosure.
  • the protection information (sub)field described in FIG. 10 may be located at the last part within the common information field.
  • the transmitting STA can apply BIP to the BA control field and transmit a block-ACK frame by adding a protection information (sub)field to the end of the field. Based on this, the receiving STA that receives the block-ACK frame can perform an integrity check on the BA control field in the block-ACK frame based on the information.
  • the MIC information included in the corresponding protection information (sub)field may correspond to the BA control field that includes the protection information (sub)field.
  • the target to which an integrity check is performed/applied based on the protection information (sub)field may correspond to the BA control field to which the corresponding (sub)field belongs.
  • the protection information (sub)field according to the present disclosure may be located within the BA information field included in the block-ACK frame.
  • a protection information (sub)field can be included at the end of the corresponding BA information field.
  • FIG. 12 illustrates another example of a block-ACK frame configuration supporting integrity checking according to an embodiment of the present disclosure.
  • FIG. 12 exemplifies a case where a protection information (sub)field is included in a BA information field in a compressed block-ACK frame
  • (b) of FIG. 12 exemplifies a case where a protection information (sub)field is included in each AID TID information (Per AID TID Info) subfield of the BA information field in a multi-STA block-ACK frame
  • the Per AID TID Info subfield may include an AID TID Info field, a Block-ACK Start Sequence Control field, and a Block-ACK Bitmap field.
  • the protection information (sub)field described in FIG. 10 may be located at the last part of each BA information field.
  • a transmitting STA can apply a BIP to each BA information field and add a protection information (sub)field to the end of the field to configure and transmit a block-ACK frame. Based on this, a receiving STA that receives the block-ACK frame can perform an integrity check on each BA information field.
  • the values of key ID and MIC constituting the protection information (sub)field included in the Per AID TID Info subfield in the multi-STA block-ACK frame may mean the PTK of the STA corresponding to the corresponding AID, and the value of MIC may be derived based on the corresponding key ID.
  • a receiving STA may derive the MIC value of the Per AID TID Info subfield by using the key information included in the key ID for the Per AID TID Info subfield, and perform integrity verification based on the same.
  • the protection information (sub)field may be located in a part other than the BA control field and the BA information field within a block-ACK frame.
  • FIG. 13 illustrates another example of a block-ACK frame configuration supporting integrity checking according to an embodiment of the present disclosure.
  • the protection information field may be located before the FCS within the block-ACK frame.
  • the transmitting STA applies the BIP to the BA control field and/or the BA information field, and may add a protection information (sub) field to the last part to set the value(s) of each subfield. That is, when the transmitting STAs transmit a block-ACK frame to the receiving STA, a block-ACK frame such as that in FIG. 13 may be configured.
  • the MIC information can be set by considering three cases.
  • the MIC information can be set by deriving MIC values for both the BA control field and the BA information field.
  • the MIC information can be set by deriving a MIC value for the BA control field.
  • the MIC information can be set by deriving a MIC value for the BA information field.
  • block-ACK frame is a multi-STA block-ACK frame type
  • MIC values for all Per AID TID Info subfields in the BA information field are set, and GTK or existing GTK, IGTK, or BIGTK may be utilized for protection of the block-ACK frame.
  • the protection information (sub)field may be configured as one of a plurality of Per AID TID Info fields constituting a BA information field in a block-ACK frame of a multi-STA block-ACK type.
  • a transmitting STA may configure a block-ACK frame by configuring/including a protection information (sub)field according to the present disclosure as one of a plurality of Per AID TID Info fields constituting a BA information field in a block-ACK frame of a multi-STA block-ACK type.
  • FIG. 14 illustrates another example of a block-ACK frame configuration supporting integrity checking according to an embodiment of the present disclosure.
  • a transmitting STA may be configured with a Per AID TID Info field including a protection information (sub)field, an AID TID Info subfield, a length-related field, a protection information (sub)field, and/or a padding/reserved subfield.
  • the AID11 subfield within the AID TID Info subfield is set to the value of a specific AID indicating that the Per AID TID Info field contains a protection information (sub)field.
  • the value of the Ack type subfield and/or the value of the TID subfield in the corresponding AID TID Info subfield may be set based on at least one of the following options.
  • the Ack Type subfield can be set to the reserved value.
  • the TID subfield may be set to a reserved value.
  • the value of the Ack Type subfield and the value of the TID subfield can be set based on the definition of the meaning of the Per AID TID Info subfield according to the presence of the optional subfield(s) when the AID11 subfield is not 2045 (e.g., the definition according to Table 2).
  • the setting of the value of the Ack Type subfield and the value of the TID subfield may not follow the definition of the meaning of the Per AID TID Info subfield according to the presence of the optional subfield(s) when the AID11 subfield is not 2045 (e.g., the definition according to Table 2).
  • the definition according to Table 2 can be extended not only for the case where the AID11 subfield is not 2045, but also for the case where the value of a particular AID is not indicative of the inclusion of a protected information (sub)field. For example, if the value of a particular AID11 is 2044, which indicates that the protected information (sub)field is included, the definition according to Table 2 can be extended/replaced by a definition for the meaning of the Per AID TID Info subfield according to the presence of the optional subfield(s) when the AID11 subfield is not 2045 and 2044.
  • the Ack Type subfield and the TID subfield can be defined to indicate at least one of the following contexts/meanings:
  • key ID information e.g., key ID subfield
  • protection information (sub)field e.g., key ID subfield
  • key ID information e.g., key ID subfield
  • protection information (sub)field e.g., key ID subfield
  • PN-related information e.g. IPN/BIPN subfield
  • protection information (sub)field e.g. IPN/BIPN subfield
  • the length-related subfield located after the aforementioned AID TID Info subfield may be configured in the form of a Block Ack Starting Sequence Control subfield within the existing Per AID TID Info field, or may be a newly defined subfield.
  • the length-related subfield is configured in the form of a Block Ack Starting Sequence Control subfield.
  • the existing Block Ack Starting Sequence Control subfield is defined to indicate the length of the Block ACK Bitmap subfield included in the corresponding Per AID TID Info field. For example, if the Block Ack Starting Sequence Control subfield exists, the length of the Block ACK Bitmap subfield and the length of the maximum number of MSDUs/A-MSDUs can be indicated using a bit combination of the Fragment Number subfield within the corresponding subfield depending on whether fragmentation level 3 exists (e.g., see Table 3).
  • the value of the Block Ack Starting Sequence Control subfield may be defined to indicate the total length including padding or reserved subfields to match the length of the protection information (sub)field and the existing block-ACK bitmap subfield, rather than the block-ACK bitmap subfield.
  • the method is applicable when the bit combination of the fragment number subfield in the Block Ack Starting Sequence Control subfield is set/defined to indicate a length of 8-octets, 16-octets, 32-octets, or 4-octets.
  • a protection information (sub)field is included in the Per AID TID subfield
  • a length-related subfield is defined as a new subfield for indicating the length of the corresponding protection information (sub)field.
  • the corresponding new subfield is referred to as a protection information length subfield, but this name is only an example and may be applied by replacing it with another name.
  • FIG. 14 illustrates that the Per AID TID Info subfield containing the protection information (sub)field is configured as the last Per AID TID Info subfield within the BA information field, this is only an example and the scope of the present disclosure is not limited thereto.
  • the MIC value/information in the block-ACK frame configured in the manner described in Example 1-4 can be derived/calculated by applying BIP to the BA control field and/or BA information field(s) based on three methods.
  • integrity verification can be performed based on one or more of the three methods described below.
  • the first method for calculating the MIC value corresponds to a method for deriving the MIC for all Per AID TID Info fields in the BA information field in the block-ACK frame.
  • the Per AID TID Info fields in the BA information field may mean Per AID TID Info fields including information that the transmitting STA transmits to the receiving STAs (i.e., the Per AID TID Info field including the AID value of the receiving STA), and the Per AID TID Info field including the protection information (sub)field is excluded when deriving the MIC.
  • the second method for calculating the MIC value corresponds to a method for deriving the MIC for the BA control field in the block-ACK frame.
  • the third method for calculating the MIC value such as the calculation range 3 of the MIC subfield illustrated in FIG. 14, corresponds to a method for deriving the Per AID TID Info field(s) including the AID of the receiving STA(s) in the BA control field and the BA information field in the block-ACK frame.
  • the third method may be a method that includes both the first method and the second method.
  • the support for BIP application to block-ACK frames can be shared by utilizing reserved bits in existing elements (e.g., RSNXE) or by defining a new (sub-)field in a new element.
  • existing elements e.g., RSNXE
  • sub- sub-
  • a 1-bit protected BlockAck support (sub-)field can be newly defined, and a value of 1 can be defined to mean/indicate that BIP application to block-ACK frames is supported, and a value of 0 can be defined to mean/indicate that BIP application to block-ACK frames is not supported.
  • both the transmitting STA and the receiving STA support BIP and support BIP application to the block-ACK frame
  • the two STAs can perform BIP application to the block-ACK frame.
  • the transmitting STA or the receiving STA supports BIP but does not support BIP application to the block-ACK frame
  • the two STAs may not perform BIP application to the block-ACK frame.
  • the cipher suite e.g., BIP-GMAC-128, BIP-GMAC-256, or BIP-CMAC-256, etc.
  • the transmitting STA and the receiving STA may negotiate an additional/separate cipher suite for the block-ACK frame.
  • this may be allowed/available only when both the transmitting STA and the receiving STA of the block-ACK frame support BIP application to the block-ACK frame. That is, for both the transmitting STA and the receiving STA, the value of the protected BlockAck support (sub)field is set to a value supporting/indicating BIP application to the block-ACK frame.
  • this may be allowed/available even if the transmitting STA of the block-ACK frame supports BIP application to the block-ACK frame, but only some of the receiving STAs support BIP application to the block-ACK frame. That is, for the transmitting STA, the value of the protected BlockAck support (sub)field is set to a value supporting/indicating BIP application to the block-ACK frame.
  • the value of the protected BlockAck support (sub)field may be set to a value that supports/indicates application of BIP to block-ACK frames, while for other receiving STA(s), the value of the protected BlockAck support (sub)field may be set to a value that indicates not to support application of BIP to block-ACK frames.
  • information regarding whether BIP application for a block-ACK frame is supported and in which format a protection information (sub)field is configured among the formats proposed in the present disclosure may be shared between a transmitting STA and a receiving STA.
  • a reserved bit in an existing element e.g., RSNXE
  • a new (sub)field in a new element e.g., a protected BlockAck mode (sub)field
  • the (sub)field may be included in a beacon frame by a transmitting STA or in a data frame by a receiving STA during a (re)association process as well as during a data transmission and reception process.
  • setting the value of the protected block-ACK mode (sub)field to 0 may mean/indicate that the block-ACK frame is not configured in at least one way and that the BIP for the block-ACK frame is not applied.
  • setting the value of the protected block-ACK mode (sub)field to 1 or more may mean/indicate that the BIP for the block-ACK frame is applied.
  • the meaning of the value of the corresponding protected block-ACK mode (sub)field can be defined as in Table 4 below.
  • Table 4 is exemplary, and at least one of the values described in Table 4 can be applied/defined, and a specific value can also be set/defined differently from the example.
  • Block-ACK mode (sub) field meaning 1 Block-ACK frame configuration based on Example 1-1 2 Block-ACK frame composition based on Example 1-2 3 Block-ACK frame composition based on examples 1-1 and 1-2 4 Block-ACK frame composition based on Example 1-3 5 Block-ACK frame configuration based on Example 1-4 6 Block-ACK frame configuration based on Example 1-4, integrity verification performed based on MIC values for BA control field and BA information field 7 Block-ACK frame configuration based on Example 1-4, integrity verification performed based on MIC value for BA control field 8 Block-ACK frame configuration based on Example 1-4, integrity verification performed based on MIC value for BA information field
  • a method for calculating a MIC value together with the configuration/format of a block-ACK frame including a protection information (sub)field according to the present disclosure through a protected block-ACK mode (sub)field may be indicated.
  • a block-ACK frame including a protection information (sub-)field is indicated through the protected block-ACK mode (sub-)field, and a method of calculating a MIC value may be separately indicated through another (sub-)field.
  • a MIC calculation range (sub-)field may be defined, and the value of the corresponding (sub-)field may be defined as in Table 5.
  • the receiving STA can recognize/verify the location where the protection information (sub)field is included in the received block-ACK frame through the protected block-ACK mode (sub)field. In addition, based on this, the receiving STA can calculate the MIC value using the value indicated by the MIC calculation range (sub)field, and thereby perform an integrity check on the block-ACK frame.
  • This embodiment relates to a method for generating MIC for BIP transmission/reception in relation to BIP application to the aforementioned block-ACK frame.
  • the type of the block-ACK frame to be transmitted and received can be indicated based on the value of the BA type subfield in the BA control field. Depending on the indicated value, the receiving STA can determine whether the corresponding block-ACK frame is an individually addressed frame or a group addressed frame.
  • the key used to set the MIC value may be used differently depending on whether it is an individually addressed frame or a group addressed frame.
  • MIC value calculation can be performed using a TK based on a PTK generated identically between the transmitting STA and the receiving STA.
  • MIC value calculation can be performed using a TK based on a GTK shared by the transmitting STA with the receiving STA.
  • BIPs For existing BIPs (e.g., BIPs applied to data frames/management frames), it is possible to utilize BIPs based on IGTK or BIGTK. In contrast, the present disclosure assumes that it is possible to utilize BIPs based on PTK/GTK.
  • the MIC value can be calculated/verified as follows:
  • the transmitting STA and the receiving STA can calculate the MIC value using the TK based on the PTK generated identically during the 4-way handshake process.
  • the transmitting STA and the receiving STA can equally utilize the PTK generated with respect to the protection of the data frame during the 4-way handshake process, or can utilize a (new) TK (e.g., new PTK/GTK) identically generated/agreed on/shared between them with respect to the protection of the corresponding block-ACK frame during the 4-way handshake process.
  • a (new) TK e.g., new PTK/GTK
  • the transmitting STA and the receiving STA can derive the MIC value using a TK based on a new TK for individually addressed block-ACK frames shared in the 4-way handshake process.
  • the new TK may be referred to as block-ACK PTK (block-ACK PTK, BAPTK), and the transmitting STA can generate and share a different BAPTK for each receiving STA. That is, different BAPTKs may be shared for receiving STA 1 and receiving STA 2.
  • the transmitting STA can generate and share a new TK for each receiving STA.
  • receiving STA 1 and receiving STA 1 may share the same new TK.
  • information about the new TK and information related to a cipher suite that can use the new TK can be shared through a new KDE (key data element) (e.g., BAPTK/BAGTK KDE) for the new TK generated and shared by the transmitting STA.
  • KDE key data element
  • the receiving STA may perform MIC verification for the received block-ACK frame using the key.
  • the key may be generated and/or shared by the transmitting STA and/or the receiving STA.
  • the receiving STA may perform MIC verification for the block-ACK frame based on a key (e.g., PTK) for integrity verification/encryption/decryption of a unicast data frame generated in advance with the transmitting STA.
  • the MIC value can be calculated/checked as follows.
  • a transmitting STA can generate an IGTK or a BIGTK and share it with a receiving STA during a 4-way handshake process, and the transmitting STA and the receiving STA can calculate a MIC value using a TK based on the IGTK or the BIGTK.
  • the transmitting STA can generate a GTK and share it with the receiving STA during the 4-way handshake process, and the transmitting STA and the receiving STA can calculate the MIC value using a TK based on the GTK.
  • the transmitting STA may generate a new GTK for the group-addressed block-ACK frame and share it with the receiving STA during the 4-way handshake process, and the transmitting STA and the receiving STA may calculate the MIC value using the TK based on the new GTK.
  • the new GTK may be referred to as a block-ACK broadcast GTK (BAGTK)
  • the transmitting STA may share the BAGTK of the same value with the receiving STAs. That is, the AP may generate and share the same BAGTK with the STAs associated with it.
  • information about the BAGTK and information related to a cipher suite that can use the BAGTK may be shared between the transmitting STA and the receiving STA through the new KDE for the BAGTK (e.g., TBGTK KDE).
  • the receiving STA may perform MIC verification for the block-ACK frame based on the key. Otherwise, the receiving STA may perform MIC verification for the block-ACK frame based on a key (e.g., GTK, IGTK, or BIGTK) for broadcast frame(s) previously shared with the transmitting STA.
  • a key e.g., GTK, IGTK, or BIGTK
  • This embodiment is about a specific method for performing protection for a block-ACK frame based on the block-ACK frame configuration proposed in the present disclosure.
  • the block-ACK frame configuration proposed in the present disclosure can be used as in the following examples.
  • the transmitting STA and/or the receiving STA may derive the MIC value through BIP using the aforementioned GTK, IGTK, BIGTK, or new TK (e.g., BAGTK) for the BA control field.
  • the transmitting STA and/or the receiving STA may derive the MIC value through BIP using the aforementioned PTK or new TK (e.g., BAPTK) for the BA information field.
  • the aforementioned PTK or new TK e.g., BAPTK
  • the transmitting STA and/or the receiving STA may use the PTK or a new TK (e.g., BAPTK) of the STA corresponding to the AID of the corresponding Per AID TID Info subfield.
  • a new TK e.g., BAPTK
  • the transmitting STA and/or the receiving STA may derive the MIC value via BIP using the aforementioned GTK, IGTK, BIGTK, or a new TK (e.g., BAGTK) for the BA control field and/or the BA information field.
  • a new TK e.g., BAGTK
  • the block-ACK frame configuration proposed in the present disclosure can be used as in the following examples.
  • the transmitting STA and/or the receiving STA may derive the MIC value through the BIP using the aforementioned PTK or a new TK (e.g., BAPTK) for the BA control field.
  • a new TK e.g., BAPTK
  • the transmitting STA and/or the receiving STA may derive the MIC value via the BIP using the aforementioned PTK or a new TK (e.g., BAPTK) for the BA information field.
  • a new TK e.g., BAPTK
  • the transmitting STA and/or the receiving STA may use the PTK or the new TK (e.g., BAPTK) of the STA corresponding to the AID of the corresponding Per AID TID Info subfield.
  • the PTK of the STA corresponding to the MAC address of the transmitting STA e.g., the receiver address (RA)
  • a new TK e.g., BAPTK
  • the transmitting STA and/or the receiving STA may derive the MIC value via the BIP using the aforementioned PTK or a new TK (e.g., BAPTK) for the BA control field and/or the BA information field.
  • the PTK or the new TK (e.g., BAPTK) of the STA corresponding to the receiver address (RA) of the corresponding block-ACK frame may be used to derive the MIC value for the BA control field and/or the BA information field.
  • protection for block-ACK frames can be performed as follows.
  • the transmitting STA and the receiving STA(s) support the use of block-ACK frames on the BIP via the protected block-ACK support (sub-)field and/or share the configuration of the protection information (sub-)field within the block-ACK frame via the protected block-ACK mode (sub-)field.
  • a receiving STA can configure additional authentication data (AAD) for a block-ACK frame based on information in the MAC header of an MPDU received from a transmitting STA (e.g., frame control field, interval field, RA field, TA field, etc.). Thereafter, the receiving STA can use the AAD to calculate a MIC value based on the MPDU. At this time, the receiving STA can derive the MIC value by performing the same process in which the transmitting STA calculates the MIC value based on the MPDU.
  • AAD additional authentication data
  • the receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the protection information (sub)field). If the two MIC values are the same, the receiving STA can follow the information in the acquired MPDU. On the other hand, if the two MIC values are not the same, the receiving STA can recognize that at least one piece of information in the acquired MPDU has been modified by a third party STA (e.g., an attacking STA) or damaged during transmission and reception, and can discard it.
  • a third party STA e.g., an attacking STA
  • FIGS. 15 and 16 The operation of an STA supporting/performing protection for a block-ACK frame according to an embodiment of the present disclosure may be as shown in FIGS. 15 and 16.
  • FIG. 15 illustrates the operation of a transmitting STA supporting integrity checking for a block-ACK frame according to the present disclosure.
  • a transmitting STA may share with a receiving STA information including whether it supports protection (e.g., integrity check) for a block-ACK frame (S1510).
  • protection e.g., integrity check
  • the transmitting STA may generate and share key(s) (e.g., PTK/GTK/BAPTK/BAGTK(s)) used for integrity check of the block-ACK frame (S1520).
  • key(s) e.g., PTK/GTK/BAPTK/BAGTK(s)
  • the transmitting STA and the receiving STA may generate/negotiate/share the same key information with each other through the key generation process, or the key information generated by the transmitting STA may be transmitted to the receiving STA.
  • the transmitting STA can apply BIP to the configured block-ACK frame (S1530).
  • the transmitting STA can derive the MIC value for the block-ACK frame using the key(s) previously shared with the receiving STA.
  • the transmitting STA may transmit a block-ACK frame including the result value/information for BIP application (S1540). For example, the transmitting STA may transmit a block-ACK frame including the derived MIC value and the ID value of the key(s) used to derive the corresponding MIC value to the receiving STA(s).
  • the transmitting STA may share/discuss in advance with the receiving STA information about the format in which information related to integrity check is configured within the transmitted block-ACK frame, or may transmit the information by including it in the block-ACK frame.
  • FIG. 16 illustrates the operation of a receiving STA supporting integrity checking for a block-ACK frame according to the present disclosure.
  • a receiving STA may share with a transmitting STA information including whether it supports protection (e.g., integrity check) for a block-ACK frame (S1610).
  • protection e.g., integrity check
  • the receiving STA can assume that the protection method has been applied to the block-ACK frame transmitted by the transmitting STA (S1620).
  • the transmitting STA and the receiving STA may generate/negotiate/share the same key information (e.g., PTK/GTK/BAPTK/BAGTK, etc.) through a key generation process, or key information generated by the transmitting STA may be transmitted to the receiving STA.
  • key information e.g., PTK/GTK/BAPTK/BAGTK, etc.
  • a receiving STA may receive a block-ACK frame transmitted from a transmitting STA and recognize that it has applied a BIP based on information regarding the structure of information for integrity checking within the block-ACK frame and/or the pre-shared key(s).
  • the receiving STA can derive the MIC value using the pre-shared/generated/agreed key(s) (e.g., PTK/GTK/BAPTK/BAGTK, etc.) and the block-ACK frame (S1630).
  • pre-shared/generated/agreed key(s) e.g., PTK/GTK/BAPTK/BAGTK, etc.
  • the receiving STA can perform integrity verification by comparing the derived MIC value with the MIC value transmitted by the transmitting STA (i.e., the MIC value according to the MIC information included in the block-ACK frame) (S1640).
  • FIGS. 17 and 18 illustrate operations performed by an STA according to the proposed method of the present disclosure described above.
  • the second STA may correspond to a transmitting STA (e.g., an AP)
  • the first STA may correspond to a receiving STA (e.g., a non-AP STA coupled to an AP).
  • FIG. 17 is a drawing for explaining an example of a method performed by a first STA according to the present disclosure.
  • the first STA can check key information related to protection for a block-ACK frame (S1710).
  • protection for the block-ACK frame may be based on an integrity check utilizing the BIP described above in the present disclosure.
  • the first STA may negotiate/share/generate key information (related to the corresponding block-ACK frame) in advance with the second STA through a 4-way handshake process. Additionally or alternatively, the first STA may also receive key information generated from the second STA.
  • the first STA can receive a block-ACK frame with the aforementioned protection applied from the second STA (S1720).
  • the first STA can perform integrity verification on the block-ACK frame based on the aforementioned key information (S1730).
  • protection-related information for integrity verification may be included in a specific per TID AID information field among a plurality of per TID AID information fields included in a block-ACK information field in the corresponding block-ACK frame.
  • the specific per TID AID information field may correspond to a per TID AID information field located last among a plurality of per TID AID information fields.
  • an AID subfield included in a specific TID AID information field may be set to a pre-defined AID value to indicate whether protection-related information is included.
  • the pre-defined AID value may be 2044.
  • a combination of a value of an ACK type subfield and a value of a TID subfield included in a specific respective TID AID information field may be set to a value indicating at least one of 1) the presence or absence of protection-related information, 2) the presence or absence of one or more subfields included in the protection-related information, or 3) the length of one or more subfields included in the protection-related information.
  • the one or more subfields included in the protection-related information may include at least one of a first subfield related to key information, a second subfield related to a packet number for a block-ACK frame, or a third subfield for MIC information for integrity verification (see, for example, FIG. 10 ).
  • the above-described integrity verification may be performed based on a comparison between a first MIC value calculated for at least one of a block-ACK control field or a block-ACK information field in a block-ACK frame and a second MIC value indicated by the third subfield.
  • a specific TID AID information field may be excluded from the calculation of the first MIC value. That is, only each TID AID information field including an AID value of a receiving STA may be applied to the calculation of the MIC value.
  • At least one of the ACK type subfield or the TID subfield included in each specific TID AID information field may be set to a reserved value.
  • the ACK type subfield and the TID subfield included in each specific TID AID information field may be defined identically to the case where the value of the AID subfield included in each TID AID information field is not set to 2045.
  • each specific TID AID information field may include a length-related subfield for indicating the length of a subfield corresponding to protection-related information.
  • the length-related subfield may be based on a previously defined subfield format, or may be a newly defined subfield for indicating the length of a subfield corresponding to protection-related information.
  • the length-related subfield may indicate 1) the length of the subfield corresponding to the protection-related information, or 2) the sum of the length of the subfield corresponding to the protection-related information and the length of the padding or reserved subfields positioned after the protection-related information.
  • information indicating whether protection for a block-ACK frame is supported may be transmitted and received between the first STA and the second STA.
  • the information indicating whether protection for a block-ACK frame is supported may be transmitted and received via at least one of a beacon frame, a probe request frame, a probe response frame, a join request frame, a join response frame, or the block-ACK frame.
  • information on at least one of a frame format based on a position of protection-related information or a range to which protection-related information is applied, for a block-ACK frame may be transmitted and received between the first STA and the second STA.
  • the method described in the example of FIG. 17 can be performed by the first device (100) of FIG. 1. That is, the first STA of FIG. 17 can be implemented by the first device (100).
  • one or more processors (102) of the first device (100) of FIG. 1 can be configured to verify key information related to protection for a block-ACK frame, receive a block-ACK frame to which protection has been applied from a second STA, and perform an integrity check for the block-ACK frame based on the key information.
  • the first STA can recognize whether protection/security has been applied to the received block-ACK frame based on information previously shared/agreed on with the second STA, and can perform an integrity check by utilizing the BIP.
  • one or more memories (104) of the first device (100) may store instructions for performing the method described in the example of FIG. 17 or the examples described below when executed by one or more processors (102).
  • FIG. 18 is a drawing for explaining an example of a method performed by a second STA according to the present disclosure.
  • the second STA can verify key information related to protection for the block-ACK frame (S1810).
  • protection for the block-ACK frame may be based on an integrity check utilizing the BIP described above in the present disclosure.
  • the second STA can construct a block-ACK frame including protection-related information for integrity verification of the block-ACK frame based on the key information (S1820).
  • the second STA can transmit a block-ACK frame with the aforementioned protection applied to the first STA (S1830).
  • protection-related information for integrity verification may be included in a specific per TID AID information field among a plurality of per TID AID information fields included in a block-ACK information field in the corresponding block-ACK frame.
  • the specific per TID AID information field may correspond to a per TID AID information field located last among a plurality of per TID AID information fields.
  • the method described in the example of FIG. 18 can be performed by the second device (200) of FIG. 1. That is, the second STA of FIG. 18 can be implemented by the second device (200).
  • one or more processors (202) of the second device (200) of FIG. 1 can be configured to verify key information related to protection for a block-ACK frame, configure a block-ACK frame including protection-related information based on the key information, and transmit the block-ACK frame to which protection has been applied to the first STA.
  • the second STA can perform an operation including information related to integrity check (e.g., a derived MIC value, key information for deriving the MIC value, a PN (Packet Number) for the corresponding block-ACK frame, etc.) by applying a BIP to the block-ACK frame based on information shared with the first STA before configuring a PPDU.
  • information related to integrity check e.g., a derived MIC value, key information for deriving the MIC value, a PN (Packet Number) for the corresponding block-ACK frame, etc.
  • one or more memories (204) of the second device (200) may store instructions for performing the method described in the example of FIG. 18 or the examples described below when executed by one or more processors (202).
  • the scope of the present disclosure includes software or machine-executable instructions (e.g., an operating system, an application, firmware, a program, etc.) that cause operations according to the various embodiments to be executed on a device or a computer, and a non-transitory computer-readable medium having such software or instructions stored thereon and executable on the device or computer.
  • Instructions that can be used to program a processing system to perform the features described in the present disclosure can be stored on/in a storage medium or a computer-readable storage medium, and a computer program product including such a storage medium can be used to implement the features described in the present disclosure.
  • the storage medium can include, but is not limited to, high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid state memory devices, and can include non-volatile memory, such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid state storage devices.
  • the memory optionally includes one or more storage devices remotely located from the processor(s).
  • the memory or alternatively the non-volatile memory device(s) within the memory comprises a non-transitory computer-readable storage medium.
  • the features described in this disclosure may be incorporated into software and/or firmware stored on any one of the machine-readable media to control the hardware of the processing system and to allow the processing system to interact with other mechanisms that utilize results according to embodiments of the present disclosure.
  • Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments/containers.
  • the method proposed in this disclosure has been described with a focus on examples applied to IEEE 802.11-based systems, but can be applied to various wireless LANs or wireless communication systems in addition to IEEE 802.11-based systems.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Security & Cryptography (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치가 개시된다. 본 개시의 일 실시예에 따른 무선 로컬 영역 네트워크(WLAN) 시스템에서의 제1 STA에 의해서 수행되는 방법은, 블록-ACK 프레임에 대한 보호와 관련된 키 정보를 확인하는 단계; 상기 보호가 적용된 블록-ACK 프레임을 제2 STA으로부터 수신하는 단계; 및 상기 키 정보에 기초하여, 상기 블록-ACK 프레임에 대한 무결성 검증을 수행하는 단계를 포함할 수 있다. 여기서, 상기 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시됨에 기초하여, 상기 무결성 검증을 위한 보호-관련 정보는 상기 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보 필드들 중 특정 각 TID AID 정보 필드에 포함될 수 있다.

Description

무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
본 개시는 무선랜(Wireless Local Area Network, WLAN) 시스템에서 제어 프레임(control frame)에 대한 보호(protection)를 지원하는 방법 및 장치에 관한 것이다.
무선랜(WLAN)에 대해서 송신 레이트 향상, 대역폭 증가, 신뢰성 향상, 에러 감소, 레이턴시 감소 등을 위한 새로운 기술이 도입되어 왔다. 무선랜 기술 중에서, IEEE(Institute of Electrical and Electronics Engineers) 802.11 계열의 표준을 Wi-Fi라고 칭할 수 있다. 예를 들어, 최근에 무선랜에 도입된 기술은, 802.11ac 표준의 VHT(Very High-Throughput)를 위한 개선사항(enhancement), IEEE 802.11ax 표준의 HE(High Efficiency)를 위한 개선사항 등을 포함한다.
보다 향상된 무선 통신 환경을 제공하기 위해서, EHT(Extremely High Throughput)를 위한 개선 기술이 논의되고 있다. 예를 들어, 증가된 대역폭, 다중 대역의 효율적 활용, 증가된 공간 스트림을 지원하는 MIMO(Multiple Input Multiple Output), 다중 액세스 포인트(AP) 조정을 위한 기술이 연구되고 있으며, 특히 낮은 레이턴시(low latency) 또는 실시간(real time) 특성의 트래픽을 지원하기 위한 다양한 기술이 연구되고 있다. 나아가, EHT 기술의 개선 또는 확장을 포함하여, 극히 높은 신뢰성(ultra high reliability, UHR)을 지원하기 위한 새로운 기술이 논의되고 있다.
본 개시의 기술적 과제는 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치를 제공하는 것이다.
본 개시의 기술적 과제는 무선랜 시스템에서 블록-ACK(BlockACK, BA) 프레임에 대하여 BIP(Broadcast/multicast integrity protocol) 기반의 무결성 검사(integrity check)를 지원하는 방법 및 장치를 제공하는 것이다.
본 개시에서 이루고자 하는 기술적 과제들은 이상에서 언급한 기술적 과제들로 제한되지 않으며, 언급하지 않은 또 다른 기술적 과제들은 아래의 기재로부터 본 개시가 속하는 기술분야에서 통상의 지식을 가진 자에게 명확하게 이해될 수 있을 것이다.
본 개시의 일 양상에 따른 무선 로컬 영역 네트워크(WLAN) 시스템에서 제1 스테이션(STA)에 의해서 수행되는 방법은: 블록-ACK(block acknowledgement) 프레임에 대한 보호와 관련된 키 정보를 확인하는 단계; 상기 보호가 적용된 블록-ACK 프레임을 제2 STA으로부터 수신하는 단계; 및 상기 키 정보에 기초하여, 상기 블록-ACK 프레임에 대한 무결성 검증을 수행하는 단계를 포함할 수 있다. 여기서, 상기 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시됨에 기초하여, 상기 무결성 검증을 위한 보호-관련 정보는 상기 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함될 수 있다.
본 개시의 추가적인 양상에 따른 무선 로컬 영역 네트워크(WLAN) 시스템에서 제2 스테이션(STA)에 의해서 수행되는 방법은: 블록-ACK 프레임에 대한 보호와 관련된 키 정보를 확인하는 단계; 상기 키 정보에 기초하여, 상기 블록-ACK 프레임에 대한 무결성 검증을 위한 보호-관련 정보를 포함하는 블록-ACK 프레임을 구성하는 단계; 및 상기 보호가 적용된 블록-ACK 프레임을 제1 STA에게 송신하는 단계를 포함할 수 있다. 여기서, 상기 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시됨에 기초하여, 상기 보호-관련 정보는 상기 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함될 수 있다.
본 개시의 다양한 실시예에 따라, 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치가 제공될 수 있다.
본 개시의 다양한 실시예에 따라, 무선랜 시스템에서 블록-ACK(BlockAck, BA) 프레임에 대하여 BIP 기반의 무결성 검사를 지원하는 방법 및 장치가 제공될 수 있다.
본 개시에서 얻을 수 있는 효과는 이상에서 언급한 효과로 제한되지 않으며, 언급하지 않은 또 다른 효과들은 아래의 기재로부터 본 개시가 속하는 기술분야에서 통상의 지식을 가진 자에게 명확하게 이해될 수 있을 것이다.
본 개시에 관한 이해를 돕기 위해 상세한 설명의 일부로 포함되는, 첨부 도면은 본 개시에 대한 실시예를 제공하고, 상세한 설명과 함께 본 개시의 기술적 특징을 설명한다.
도 1은 본 개시의 일 실시예에 따른 무선 통신 장치의 블록 구성도를 예시한다.
도 2는 본 개시가 적용될 수 있는 무선랜 시스템의 예시적인 구조를 나타내는 도면이다.
도 3은 본 개시가 적용될 수 있는 링크 셋업(link setup) 과정을 설명하기 위한 도면이다.
도 4는 본 개시가 적용될 수 있는 백오프 과정을 설명하기 위한 도면이다.
도 5는 본 개시가 적용될 수 있는 CSMA/CA 기반 프레임 송신 동작을 설명하기 위한 도면이다.
도 6은 본 개시가 적용될 수 있는 무선랜 시스템에서 사용되는 프레임 구조의 예시를 설명하기 위한 도면이다.
도 7은 본 개시가 적용될 수 있는 IEEE 802.11 표준에서 정의되는 PPDU의 예시들을 도시한 도면이다.
도 8은 본 개시가 적용될 수 있는 블록-ACK 프레임의 예시적인 포맷을 나타내는 도면이다.
도 9는 본 개시에 적용될 수 있는 BIP MMPDU 포맷을 예시한다.
도 10은 본 개시의 실시예에 따른 보호 정보 필드/서브필드 포맷을 예시한다.
도 11은 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 일 예를 나타낸다.
도 12는 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 다른 예를 나타낸다.
도 13은 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 또 다른 예를 나타낸다.
도 14는 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 또 다른 예를 나타낸다.
도 15는 본 개시에 따른 블록-ACK 프레임에 대한 무결성 검사를 지원하는 송신 STA의 동작을 예시한다.
도 16은 본 개시에 따른 블록-ACK 프레임에 대한 무결성 검사를 지원하는 수신 STA의 동작을 예시한다.
도 17은 본 개시에 따른 제1 STA에 의해 수행되는 방법의 일 예시를 설명하기 위한 도면이다.
도 18은 본 개시에 따른 제2 STA에 의해 수행되는 방법의 일 예시를 설명하기 위한 도면이다.
이하, 본 개시에 따른 바람직한 실시 형태를 첨부된 도면을 참조하여 상세하게 설명한다. 첨부된 도면과 함께 이하에 개시될 상세한 설명은 본 개시의 예시적인 실시형태를 설명하고자 하는 것이며, 본 개시가 실시될 수 있는 유일한 실시형태를 나타내고자 하는 것이 아니다. 이하의 상세한 설명은 본 개시의 완전한 이해를 제공하기 위해서 구체적 세부사항을 포함한다. 그러나, 당업자는 본 개시가 이러한 구체적 세부사항 없이도 실시될 수 있음을 안다.
몇몇 경우, 본 개시의 개념이 모호해지는 것을 피하기 위하여 공지의 구조 및 장치는 생략되거나, 각 구조 및 장치의 핵심기능을 중심으로 한 블록도 형식으로 도시될 수 있다.
본 개시에 있어서, 어떤 구성요소가 다른 구성요소와 "연결", "결합" 또는 "접속"되어 있다고 할 때, 이는 직접적인 연결관계 뿐만 아니라, 그 사이에 또 다른 구성요소가 존재하는 간접적인 연결관계도 포함할 수 있다. 또한 본 개시에서 용어 "포함한다" 또는 "가진다"는 언급된 특징, 단계, 동작, 요소 및/또는 구성요소의 존재를 특정하지만, 하나 이상의 다른 특징, 단계, 동작, 요소, 구성요소 및/또는 이들의 그룹의 존재 또는 추가를 배제하지 않는다.
본 개시에 있어서, "제 1", "제 2" 등의 용어는 하나의 구성요소를 다른 구성요소로부터 구별하는 목적으로만 사용되고 구성요소들을 제한하기 위해서 사용되지 않으며, 특별히 언급되지 않는 한 구성요소들 간의 순서 또는 중요도 등을 한정하지 않는다. 따라서, 본 개시의 범위 내에서 일 실시예에서의 제 1 구성요소는 다른 실시예에서 제 2 구성요소라고 칭할 수도 있고, 마찬가지로 일 실시예에서의 제 2 구성요소를 다른 실시예에서 제 1 구성요소라고 칭할 수도 있다.
본 개시에서 사용된 용어는 특정 실시예에 대한 설명을 위한 것이며 청구범위를 제한하려는 것이 아니다. 실시예의 설명 및 첨부된 청구범위에서 사용되는 바와 같이, 단수 형태는 문맥상 명백하게 다르게 나타내지 않는 한 복수 형태도 포함하도록 의도한 것이다. 본 개시에 사용된 용어 "및/또는"은 관련된 열거 항목 중의 하나를 지칭할 수도 있고, 또는 그 중의 둘 이상의 임의의 및 모든 가능한 조합을 지칭하고 포함하는 것을 의미한다. 또한, 본 개시에서 단어들 사이의 "/"는 달리 설명되지 않는 한 "및/또는"과 동일한 의미를 가진다.
본 개시의 예시들은 다양한 무선 통신 시스템에 적용될 수 있다. 예를 들어, 본 개시의 예시들은 무선랜 시스템에 적용될 수 있다. 예를 들어, 본 개시의 예시들은 IEEE 802.11a/g/n/ac/ax/be 표준 기반 무선랜에 적용될 수 있다. 나아가, 본 개시의 예시들은 새롭게 제안되는 IEEE 802.11bn (또는 UHR) 표준 기반 무선랜에 적용될 수도 있다. 추가적으로, 본 개시의 예시들은 IEEE 802.11bn 후의 차세대 표준 기반 무선랜에 적용될 수도 있다. 또한, 본 개시의 예시들은 셀룰러 무선 통신 시스템에 적용될 수도 있다. 예를 들어, 3GPP(3rd Generation Partnership Project) 표준의 LTE(Long Term Evolution) 계열의 기술 및 5G NR(New Radio) 계열의 기술에 기반하는 셀룰러 무선 통신 시스템에 적용될 수 있다.
이하 본 개시의 예시들이 적용될 수 있는 기술적 특징에 대해서 설명한다.
도 1은 본 개시의 일 실시예에 따른 무선 통신 장치의 블록 구성도를 예시한다.
도 1에 예시된 제 1 디바이스(100)와 제 2 디바이스(200)는, 단말(Terminal), 무선 기기(wireless device), WTRU(Wireless Transmit Receive Unit), UE(User Equipment), MS(Mobile Station), UT(user terminal), MSS(Mobile Subscriber Station), MSS(Mobile Subscriber Unit), SS(Subscriber Station), AMS(Advanced Mobile Station), WT(Wireless terminal), 또는 단순히 사용자(user) 등의 다양한 용어로 대체될 수 있다. 또한, 제 1 디바이스(100)와 제 2 디바이스(200)는, 액세스 포인트(Access Point, AP), BS(Base Station), 고정국(fixed station), Node B, BTS(base transceiver system), 네트워크, AI(Artificial Intelligence) 시스템, RSU(road side unit), 리피터, 라우터, 릴레이(relay), 게이트웨이 등의 다양한 용어로 대체될 수 있다.
도 1에 예시된 디바이스(100, 200)는 스테이션(station, STA)이라 칭할 수도 있다. 예를 들어, 도 1에 예시된 디바이스(100, 200)는 송신 디바이스, 수신 디바이스, 송신 STA, 수신 STA 등의 다양한 용어로 칭할 수 있다. 예를 들어, STA(110, 200)은 AP(access Point) 역할을 수행하거나 non-AP 역할을 수행할 수 있다. 즉, 본 개시에서 STA(110, 200)은 AP 및/또는 non-AP의 기능을 수행할 수 있다. STA(110, 200)이 AP 기능을 수행하는 경우 단순히 AP라고 칭할 수도 있고, STA(110, 200)이 non-AP 기능을 수행하는 경우 단순히 STA라고 칭할 수도 있다. 또한, 본 개시에서 AP는 AP STA으로도 표시될 수 있다.
도 1을 참조하면, 제 1 디바이스(100)와 제 2 디바이스(200)는 다양한 무선랜 기술(예를 들어, IEEE 802.11 계열)을 통해 무선 신호를 송수신할 수 있다. 제 1 디바이스(100)와 제 2 디바이스(200)는 IEEE 802.11 표준의 규정을 따르는 매체 접속 제어(medium access control, MAC) 계층 및 물리 계층(physical layer, PHY)에 대한 인터페이스를 포함할 수 있다.
또한, 제 1 디바이스(100)와 제 2 디바이스(200)는 무선랜 기술 이외의 다양한 통신 표준(예를 들어, 3GPP LTE 계열, 5G NR 계열의 표준 등) 기술을 추가적으로 지원할 수도 있다. 또한 본 개시의 디바이스는 휴대 전화, 차량(vehicle), 개인용 컴퓨터, AR(Augmented Reality) 장비, VR(Virtual Reality) 장비 등의 다양한 장치로 구현될 수 있다. 또한, 본 명세서의 STA은 음성 통화, 영상 통화, 데이터 통신, 자율 주행(Autonomous-Driving), MTC(Machine-Type Communication), M2M(Machine-to-Machine), D2D(Device-to-Device), IoT(Internet-of-Things) 등의 다양한 통신 서비스를 지원할 수 있다.
제 1 디바이스(100)는 하나 이상의 프로세서(102) 및 하나 이상의 메모리(104)를 포함하며, 추가적으로 하나 이상의 송수신기(transceiver)(106) 및/또는 하나 이상의 안테나(108)을 더 포함할 수 있다. 프로세서(102)는 메모리(104) 및/또는 송수신기(106)를 제어하며, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 구현하도록 구성될 수 있다. 예를 들어, 프로세서(102)는 메모리(104) 내의 정보를 처리하여 제 1 정보/신호를 생성한 뒤, 송수신기(106)을 통해 제 1 정보/신호를 포함하는 무선 신호를 송신할 수 있다. 또한, 프로세서(102)는 송수신기(106)를 통해 제 2 정보/신호를 포함하는 무선 신호를 수신한 뒤, 제 2 정보/신호의 신호 처리로부터 얻은 정보를 메모리(104)에 저장할 수 있다. 메모리(104)는 프로세서(102)와 연결될 수 있고, 프로세서(102)의 동작과 관련한 다양한 정보를 저장할 수 있다. 예를 들어, 메모리(104)는 프로세서(102)에 의해 제어되는 프로세스들 중 일부 또는 전부를 수행하거나, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 수행하기 위한 명령어(instruction)들을 포함하는 소프트웨어 코드를 저장할 수 있다. 여기서, 프로세서(102)와 메모리(104)는 무선랜 기술(예를 들어, IEEE 802.11 계열)을 구현하도록 설계된 통신 모뎀/회로/칩의 일부일 수 있다. 송수신기(106)는 프로세서(102)와 연결될 수 있고, 하나 이상의 안테나(108)를 통해 무선 신호를 송신 및/또는 수신할 수 있다. 송수신기(106)는 송신기 및/또는 수신기를 포함할 수 있다. 송수신기(106)는 RF(Radio Frequency) 유닛과 혼용될 수 있다. 본 개시에서 디바이스는 통신 모뎀/회로/칩을 의미할 수도 있다.
제 2 디바이스(200)는 하나 이상의 프로세서(202), 하나 이상의 메모리(204)를 포함하며, 추가적으로 하나 이상의 송수신기(206) 및/또는 하나 이상의 안테나(208)를 더 포함할 수 있다. 프로세서(202)는 메모리(204) 및/또는 송수신기(206)를 제어하며, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 구현하도록 구성될 수 있다. 예를 들어, 프로세서(202)는 메모리(204) 내의 정보를 처리하여 제 3 정보/신호를 생성한 뒤, 송수신기(206)를 통해 제 3 정보/신호를 포함하는 무선 신호를 송신할 수 있다. 또한, 프로세서(202)는 송수신기(206)를 통해 제 4 정보/신호를 포함하는 무선 신호를 수신한 뒤, 제 4 정보/신호의 신호 처리로부터 얻은 정보를 메모리(204)에 저장할 수 있다. 메모리(204)는 프로세서(202)와 연결될 수 있고, 프로세서(202)의 동작과 관련한 다양한 정보를 저장할 수 있다. 예를 들어, 메모리(204)는 프로세서(202)에 의해 제어되는 프로세스들 중 일부 또는 전부를 수행하거나, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 수행하기 위한 명령어들을 포함하는 소프트웨어 코드를 저장할 수 있다. 여기서, 프로세서(202)와 메모리(204)는 무선랜 기술(예를 들어, IEEE 802.11 계열)을 구현하도록 설계된 통신 모뎀/회로/칩의 일부일 수 있다. 송수신기(206)는 프로세서(202)와 연결될 수 있고, 하나 이상의 안테나(208)를 통해 무선 신호를 송신 및/또는 수신할 수 있다. 송수신기(206)는 송신기 및/또는 수신기를 포함할 수 있다 송수신기(206)는 RF 유닛과 혼용될 수 있다. 본 개시에서 디바이스는 통신 모뎀/회로/칩을 의미할 수도 있다.
이하, 디바이스(100, 200)의 하드웨어 요소에 대해 보다 구체적으로 설명한다. 이로 제한되는 것은 아니지만, 하나 이상의 프로토콜 계층이 하나 이상의 프로세서(102, 202)에 의해 구현될 수 있다. 예를 들어, 하나 이상의 프로세서(102, 202)는 하나 이상의 계층(예를 들어, PHY, MAC과 같은 기능적 계층)을 구현할 수 있다. 하나 이상의 프로세서(102, 202)는 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들에 따라 하나 이상의 PDU(Protocol Data Unit) 및/또는 하나 이상의 SDU(Service Data Unit)를 생성할 수 있다. 하나 이상의 프로세서(102, 202)는 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들에 따라 메시지, 제어정보, 데이터 또는 정보를 생성할 수 있다. 하나 이상의 프로세서(102, 202)는 본 개시에 개시된 기능, 절차, 제안 및/또는 방법에 따라 PDU, SDU, 메시지, 제어정보, 데이터 또는 정보를 포함하는 신호(예를 들어, 베이스밴드 신호)를 생성하여, 하나 이상의 송수신기(106, 206)에게 제공할 수 있다. 하나 이상의 프로세서(102, 202)는 하나 이상의 송수신기(106, 206)로부터 신호(예를 들어, 베이스밴드 신호)를 수신할 수 있고, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들에 따라 PDU, SDU, 메시지, 제어정보, 데이터 또는 정보를 획득할 수 있다.
하나 이상의 프로세서(102, 202)는 컨트롤러, 마이크로 컨트롤러, 마이크로 프로세서 또는 마이크로 컴퓨터로 지칭될 수 있다. 하나 이상의 프로세서(102, 202)는 하드웨어, 펌웨어, 소프트웨어, 또는 이들의 조합에 의해 구현될 수 있다. 일 예로, 하나 이상의 ASIC(Application Specific Integrated Circuit), 하나 이상의 DSP(Digital Signal Processor), 하나 이상의 DSPD(Digital Signal Processing Device), 하나 이상의 PLD(Programmable Logic Device) 또는 하나 이상의 FPGA(Field Programmable Gate Arrays)가 하나 이상의 프로세서(102, 202)에 포함될 수 있다. 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들은 펌웨어 또는 소프트웨어를 사용하여 구현될 수 있고, 펌웨어 또는 소프트웨어는 모듈, 절차, 기능 등을 포함하도록 구현될 수 있다. 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들은 수행하도록 설정된 펌웨어 또는 소프트웨어는 하나 이상의 프로세서(102, 202)에 포함되거나, 하나 이상의 메모리(104, 204)에 저장되어 하나 이상의 프로세서(102, 202)에 의해 구동될 수 있다. 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들은 코드, 명령어 및/또는 명령어의 집합 형태로 펌웨어 또는 소프트웨어를 사용하여 구현될 수 있다.
하나 이상의 메모리(104, 204)는 하나 이상의 프로세서(102, 202)와 연결될 수 있고, 다양한 형태의 데이터, 신호, 메시지, 정보, 프로그램, 코드, 지시 및/또는 명령어를 저장할 수 있다. 하나 이상의 메모리(104, 204)는 ROM, RAM, EPROM, 플래시 메모리, 하드 드라이브, 레지스터, 캐쉬 메모리, 컴퓨터 판독 저장 매체 및/또는 이들의 조합으로 구성될 수 있다. 하나 이상의 메모리(104, 204)는 하나 이상의 프로세서(102, 202)의 내부 및/또는 외부에 위치할 수 있다. 또한, 하나 이상의 메모리(104, 204)는 유선 또는 무선 연결과 같은 다양한 기술을 통해 하나 이상의 프로세서(102, 202)와 연결될 수 있다.
하나 이상의 송수신기(106, 206)는 하나 이상의 다른 장치에게 본 개시의 방법들 및/또는 동작 순서도 등에서 언급되는 사용자 데이터, 제어 정보, 무선 신호/채널 등을 송신할 수 있다. 하나 이상의 송수신기(106, 206)는 하나 이상의 다른 장치로부터 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도 등에서 언급되는 사용자 데이터, 제어 정보, 무선 신호/채널 등을 수신할 수 있다. 예를 들어, 하나 이상의 송수신기(106, 206)는 하나 이상의 프로세서(102, 202)와 연결될 수 있고, 무선 신호를 송수신할 수 있다. 예를 들어, 하나 이상의 프로세서(102, 202)는 하나 이상의 송수신기(106, 206)가 하나 이상의 다른 장치에게 사용자 데이터, 제어 정보 또는 무선 신호를 송신하도록 제어할 수 있다. 또한, 하나 이상의 프로세서(102, 202)는 하나 이상의 송수신기(106, 206)가 하나 이상의 다른 장치로부터 사용자 데이터, 제어 정보 또는 무선 신호를 수신하도록 제어할 수 있다. 또한, 하나 이상의 송수신기(106, 206)는 하나 이상의 안테나(108, 208)와 연결될 수 있고, 하나 이상의 송수신기(106, 206)는 하나 이상의 안테나(108, 208)를 통해 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도 등에서 언급되는 사용자 데이터, 제어 정보, 무선 신호/채널 등을 송수신하도록 설정될 수 있다. 본 개시에서, 하나 이상의 안테나는 복수의 물리 안테나이거나, 복수의 논리 안테나(예를 들어, 안테나 포트)일 수 있다. 하나 이상의 송수신기(106, 206)는 수신된 사용자 데이터, 제어 정보, 무선 신호/채널 등을 하나 이상의 프로세서(102, 202)를 이용하여 처리하기 위해, 수신된 무선 신호/채널 등을 RF 밴드 신호에서 베이스밴드 신호로 변환(Convert)할 수 있다. 하나 이상의 송수신기(106, 206)는 하나 이상의 프로세서(102, 202)를 이용하여 처리된 사용자 데이터, 제어 정보, 무선 신호/채널 등을 베이스밴드 신호에서 RF 밴드 신호로 변환할 수 있다. 이를 위하여, 하나 이상의 송수신기(106, 206)는 (아날로그) 오실레이터 및/또는 필터를 포함할 수 있다.
예를 들어, STA(100, 200)의 하나는 AP의 의도된 동작을 수행하고, STA(100, 200)의 다른 하나는 non-AP STA의 의도된 동작을 수행할 수 있다. 예를 들어, 도 1의 송수신기(106, 206)는 신호(예를 들어, IEEE 802.11a/b/g/n/ac/ax/be/bn 등에 따르는 패킷 또는 PPDU(Physical layer Protocol Data Unit))의 송수신 동작을 수행할 수 있다. 또한, 본 개시에서 다양한 STA이 송수신 신호를 생성하거나 송수신 신호를 위해 사전에 데이터 처리나 연산을 수행하는 동작은 도 1의 프로세서(102, 202)에서 수행될 수 있다. 예를 들어, 송수신 신호를 생성하거나 송수신 신호를 위해 사전에 데이터 처리나 연산을 수행하는 동작의 일례는, 1) PPDU 내에 포함되는 필드(SIG(signal), STF(short training field), LTF(long training field), Data 등)의 비트 정보를 결정/획득/구성/연산/디코딩/인코딩하는 동작, 2) PPDU 내에 포함되는 필드(SIG, STF, LTF, Data 등)를 위해 사용되는 시간 자원이나 주파수 자원(예를 들어, 서브캐리어 자원) 등을 결정/구성/획득하는 동작, 3) PPDU 내에 포함되는 필드(SIG, STF, LTF, Data 등)를 위해 사용되는 특정한 시퀀스(예를 들어, 파일럿 시퀀스, STF/LTF 시퀀스, SIG에 적용되는 엑스트라 시퀀스) 등을 결정/구성/획득하는 동작, 4) STA에 대해 적용되는 전력 제어 동작 및/또는 파워 세이빙 동작, 5) ACK 신호의 결정/획득/구성/연산/디코딩/인코딩 등에 관련된 동작을 포함할 수 있다. 또한, 이하의 일례에서 다양한 STA이 송수신 신호의 결정/획득/구성/연산/디코딩/인코딩을 위해 사용하는 다양한 정보(예를 들어, 필드/서브필드/제어필드/파라미터/파워 등에 관련된 정보)는 도 1의 메모리(104, 204)에 저장될 수 있다.
이하에서, 하향링크(downlink, DL)는 AP STA로부터 non-AP STA로의 통신을 위한 링크를 의미하며, 하향링크를 통해 하향링크 PPDU/패킷/신호 등의 송수신될 수 있다. 하향링크 통신에서 송신기는 AP STA의 일부이고, 수신기는 non-AP STA의 일부일 수 있다. 상향링크(uplink, UL)는 non-AP STA로부터 AP STA로의 통신을 위한 링크를 의미하며, 상향링크를 통해 상향링크 PPDU/패킷/신호 등의 송수신될 수 있다. 상향링크 통신에서 송신기는 non-AP STA의 일부이고, 수신기는 AP STA의 일부일 수 있다.
도 2는 본 개시가 적용될 수 있는 무선랜 시스템의 예시적인 구조를 나타내는 도면이다.
무선랜 시스템의 구조는 복수개의 구성요소(component)들로 구성될 수 있다. 복수의 구성요소들의 상호작용에 의해 상위계층에 대해 트랜스패런트한 STA 이동성을 지원하는 무선랜이 제공될 수 있다. BSS(Basic Service Set)는 무선랜의 기본적인 구성 블록에 해당한다. 도 2에서는 2 개의 BSS(BSS1 및 BSS2)가 존재하고, 각각의 BSS의 멤버로서 2 개의 STA이 포함되는 것(STA1 및 STA2는 BSS1에 포함되고, STA3 및 STA4는 BSS2에 포함됨)을 예시적으로 도시한다. 도 2에서 BSS를 나타내는 타원은 해당 BSS에 포함된 STA들이 통신을 유지하는 커버리지 영역을 나타내는 것으로도 이해될 수 있다. 이 영역을 BSA(Basic Service Area)라고 칭할 수 있다. STA이 BSA 밖으로 이동하게 되면 해당 BSA 내의 다른 STA들과 직접적으로 통신할 수 없게 된다.
도 2에서 도시하는 DS를 고려하지 않는다면, 무선랜에서 가장 기본적인 타입의 BSS는 독립적인 BSS(Independent BSS, IBSS)이다. 예를 들어, IBSS는 2 개의 STA만으로 구성된 최소의 형태를 가질 수 있다. 예를 들어, 다른 구성요소들이 생략된 것을 가정하여, STA1 및 STA2만으로 구성된 BSS1 또는 STA3 및 STA4만으로 구성된 BSS2는 각각 IBSS의 대표적인 예시에 해당할 수 있다. 이러한 구성은 STA들이 AP 없이 직접 통신할 수 있는 경우에 가능하다. 또한, 이러한 형태의 무선랜에서 미리 계획되어서 구성되는 것이 아니라 LAN이 필요한 경우에 구성될 수 있으며, 이를 애드-혹(ad-hoc) 네트워크라고 칭할 수도 있다. IBSS는 AP를 포함하지 않기 때문에 중앙에서 관리 기능을 수행하는 개체(centralized management entity)가 없다. 즉, IBSS에서 STA들은 분산된 방식(distributed manner)으로 관리된다. IBSS에서는 모든 STA들이 이동 STA으로 이루어질 수 있으며, 분산 시스템(DS)으로의 접속이 허용되지 않아서 자기 완비적 네트워크(self-contained network)를 이룬다.
STA의 켜지거나 꺼짐, STA이 BSS 영역에 들어오거나 나감 등에 의해서, BSS에서의 STA의 멤버십이 동적으로 변경될 수 있다. BSS의 멤버가 되기 위해서는, STA은 동기화 과정을 이용하여 BSS에 조인할 수 있다. BSS 기반구조의 모든 서비스에 액세스하기 위해서는, STA은 BSS에 결합(associated)되어야 한다. 이러한 결합(association)은 동적으로 설정될 수 있고, 분산 시스템 서비스(Distribution System Service, DSS)의 이용을 포함할 수 있다.
무선랜에서 직접적인 STA-대-STA의 거리는 PHY 성능에 의해서 제한될 수 있다. 어떠한 경우에는 이러한 거리의 한계가 충분할 수도 있지만, 경우에 따라서는 보다 먼 거리의 STA 간의 통신이 필요할 수도 있다. 확장된 커버리지를 지원하기 위해서 분산 시스템(DS)이 구성될 수 있다.
DS는 BSS들이 상호 연결되는 구조를 의미한다. 구체적으로, 도 2와 같이 복수개의 BSS들로 구성된 네트워크의 확장된 형태의 구성요소로서 BSS가 존재할 수도 있다. DS는 논리적인 개념이며 분산 시스템 매체(DSM)의 특성에 의해서 특정될 수 있다. 이와 관련하여, 무선 매체(Wireless Medium, WM)와 DSM는 논리적으로 구분될 수 있다. 각각의 논리적 매체는 상이한 목적을 위해서 사용되며, 상이한 구성요소에 의해서 사용된다. 이러한 매체들이 동일한 것으로 제한되지도 않고 상이한 것으로 제한되지도 않는다. 이와 같이 복수개의 매체들이 논리적으로 상이하다는 점에서, 무선랜 구조(DS 구조 또는 다른 네트워크 구조)의 유연성이 설명될 수 있다. 즉, 무선랜 구조는 다양하게 구현될 수 있으며, 각각의 구현예의 물리적인 특성에 의해서 독립적으로 해당 무선랜 구조가 특정될 수 있다.
DS는 복수개의 BSS들의 끊김없는(seamless) 통합을 제공하고 목적지로의 어드레스를 다루는 데에 필요한 논리적 서비스들을 제공함으로써 이동 디바이스를 지원할 수 있다. 또한, DS는 무선랜과 다른 네트워크(예를 들어, IEEE 802.X)와의 연결을 위한 브리지 역할을 수행하는 포털(portal)이라는 구성요소를 더 포함할 수 있다.
AP는 결합된 non-AP STA들에 대해서 WM을 통해서 DS 로의 액세스를 가능하게 하고, STA의 기능성 또한 가지는 엔티티(entity)를 의미한다. AP를 통해서 BSS 및 DS 간의 데이터 이동이 수행될 수 있다. 예를 들어, 도 2에서 도시하는 STA2 및 STA3은 STA의 기능성을 가지면서, 결합된 non-AP STA(STA1 및 STA4)이 DS로 액세스하도록 하는 기능을 제공한다. 또한, 모든 AP는 기본적으로 STA에 해당하므로, 모든 AP는 어드레스 가능한 엔티티이다. WM 상에서의 통신을 위해 AP에 의해서 사용되는 어드레스와, DSM 상에서의 통신을 위해 AP에 의해서 사용되는 어드레스는 반드시 동일할 필요는 없다. AP와 하나 이상의 STA으로 구성되는 BSS를 인프라스트럭쳐(infrastructure BSS)라고 칭할 수 있다.
AP에 결합된 STA(들) 중의 하나로부터 해당 AP의 STA 어드레스로 송신되는 데이터는, 항상 비제어 포트(uncontrolled port)에서 수신되고 IEEE 802.1X 포트 액세스 엔티티에 의해서 처리될 수 있다. 또한, 제어 포트(controlled port)가 인증되면 송신 데이터(또는 프레임)는 DS로 전달될 수 있다.
전술한 DS의 구조에 추가적으로 넓은 커버리지를 제공하기 위한 확장된 서비스 세트(Extended Service Set, ESS)가 설정될 수도 있다.
ESS는 임의의(arbitrary) 크기 및 복잡도를 가지는 네트워크가 DS 및 BSS들로 구성된 네트워크를 의미한다. ESS는 하나의 DS에 연결된 BSS들의 집합에 해당할 수 있다. 그러나, ESS는 DS를 포함하지는 않는다. ESS 네트워크는 LLC(Logical Link Control) 계층에서 IBSS로 보이는 점이 특징이다. ESS에 포함되는 STA들은 서로 통신할 수 있고, 이동 STA들은 LLC에 트랜스패런트하게 하나의 BSS에서 다른 BSS로(동일한 ESS 내에서) 이동할 수 있다. 하나의 ESS에 포함되는 AP들은 동일한 SSID(service set identification)을 가질 수 있다. SSID는 BSS의 식별자인 BSSID와 구별된다.
무선랜 시스템에서는 BSS들의 상대적인 물리적 위치에 대해서 아무것도 가정하지 않으며, 다음과 같은 형태가 모두 가능하다. BSS들은 부분적으로 중첩될 수 있고, 이는 연속적인 커버리지를 제공하기 위해서 일반적으로 이용되는 형태이다. 또한, BSS들은 물리적으로 연결되어 있지 않을 수 있고, 논리적으로는 BSS들 간의 거리에 제한은 없다. 또한, BSS들은 물리적으로 동일한 위치에 위치할 수 있고, 이는 리던던시를 제공하기 위해서 이용될 수 있다. 또한, 하나 (또는 하나 이상의) IBSS 또는 ESS 네트워크들이 하나 (또는 하나 이상의) ESS 네트워크로서 동일한 공간에 물리적으로 존재할 수 있다. 이는 ESS 네트워크가 존재하는 위치에 애드-혹 네트워크가 동작하는 경우나, 상이한 기관(organizations)에 의해서 물리적으로 중첩되는 무선 네트워크들이 구성되는 경우나, 동일한 위치에서 2 이상의 상이한 액세스 및 보안 정책이 필요한 경우 등에서의 ESS 네트워크 형태에 해당할 수 있다.
도 3은 본 개시가 적용될 수 있는 링크 셋업(link setup) 과정을 설명하기 위한 도면이다.
STA이 네트워크에 대해서 링크를 셋업하고 데이터를 송수신하기 위해서는, 먼저 네트워크를 발견(discovery)하고, 인증(authentication)을 수행하고, 결합(association)을 맺고(establish), 보안(security)을 위한 인증 절차 등을 거쳐야 한다. 링크 셋업 과정을 세션 개시 과정, 세션 셋업 과정이라고도 칭할 수 있다. 또한, 링크 셋업 과정의 발견, 인증, 결합, 보안 설정의 과정을 통칭하여 결합 과정이라고 칭할 수도 있다.
단계 S310에서 STA은 네트워크 발견 동작을 수행할 수 있다. 네트워크 발견 동작은 STA의 스캐닝(scanning) 동작을 포함할 수 있다. 즉, STA이 네트워크에 액세스하기 위해서는 참여 가능한 네트워크를 찾아야 한다. STA은 무선 네트워크에 참여하기 전에 호환 가능한 네트워크를 식별하여야 하는데, 특정 영역에 존재하는 네트워크 식별과정을 스캐닝이라고 한다.
스캐닝 방식에는 능동적 스캐닝(active scanning)과 수동적 스캐닝(passive scanning)이 있다. 도 3에서는 예시적으로 능동적 스캐닝 과정을 포함하는 네트워크 발견 동작을 도시한다. 능동적 스캐닝에서 스캐닝을 수행하는 STA은 채널들을 옮기면서 주변에 어떤 AP가 존재하는지 탐색하기 위해 프로브 요청 프레임(probe request frame)을 송신하고 이에 대한 응답을 기다린다. 응답자(responder)는 프로브 요청 프레임을 송신한 STA에게 프로브 요청 프레임에 대한 응답으로 프로브 응답 프레임(probe response frame)을 송신한다. 여기에서, 응답자는 스캐닝되고 있는 채널의 BSS에서 마지막으로 비콘 프레임(beacon frame)을 송신한 STA일 수 있다. BSS에서는 AP가 비콘 프레임을 송신하므로 AP가 응답자가 되며, IBSS에서는 IBSS 내의 STA들이 돌아가면서 비콘 프레임을 송신하므로 응답자가 일정하지 않다. 예를 들어, 1번 채널에서 프로브 요청 프레임을 송신하고 1번 채널에서 프로브 응답 프레임을 수신한 STA은, 수신한 프로브 응답 프레임에 포함된 BSS 관련 정보를 저장하고 다음 채널(예를 들어, 2번 채널)로 이동하여 동일한 방법으로 스캐닝(즉, 2번 채널 상에서 프로브 요청/응답 송수신)을 수행할 수 있다.
도 3에서 도시하고 있지 않지만, 스캐닝 동작은 수동적 스캐닝 방식으로 수행될 수도 있다. 수동적 스캐닝에서 스캐닝을 수행하는 STA은 채널들을 옮기면서 비콘 프레임을 기다린다. 비콘 프레임은 IEEE 802.11에서 정의되는 관리 프레임(management frame) 중 하나로서, 무선 네트워크의 존재를 알리고, 스캐닝을 수행하는 STA으로 하여금 무선 네트워크를 찾아서, 무선 네트워크에 참여할 수 있도록 주기적으로 송신된다. BSS에서 AP가 비콘 프레임을 주기적으로 송신하는 역할을 수행하고, IBSS에서는 IBSS 내의 STA들이 돌아가면서 비콘 프레임을 송신한다. 스캐닝을 수행하는 STA은 비콘 프레임을 수신하면 비콘 프레임에 포함된 BSS에 대한 정보를 저장하고 다른 채널로 이동하면서 각 채널에서 비콘 프레임 정보를 기록한다. 비콘 프레임을 수신한 STA은, 수신한 비콘 프레임에 포함된 BSS 관련 정보를 저장하고 다음 채널로 이동하여 동일한 방법으로 다음 채널에서 스캐닝을 수행할 수 있다. 능동적 스캐닝과 수동적 스캐닝을 비교하면, 능동적 스캐닝이 수동적 스캐닝보다 딜레이(delay) 및 전력 소모가 작은 장점이 있다.
STA이 네트워크를 발견한 후에, 단계 S320에서 인증 과정이 수행될 수 있다. 이러한 인증 과정은 후술하는 단계 S340의 보안 셋업 동작과 명확하게 구분하기 위해서 첫 번째 인증(first authentication) 과정이라고 칭할 수 있다.
인증 과정은 STA이 인증 요청 프레임(authentication request frame)을 AP에게 송신하고, 이에 응답하여 AP가 인증 응답 프레임(authentication response frame)을 STA에게 송신하는 과정을 포함한다. 인증 요청/응답에 사용되는 인증 프레임(authentication frame)은 관리 프레임에 해당한다.
인증 프레임은 인증 알고리즘 번호(authentication algorithm number), 인증 트랜잭션 시퀀스 번호(authentication transaction sequence number), 상태 코드(status code), 검문 텍스트(challenge text), RSN(Robust Security Network), 유한 순환 그룹(Finite Cyclic Group) 등에 대한 정보를 포함할 수 있다. 이는 인증 요청/응답 프레임에 포함될 수 있는 정보들의 일부 예시에 해당하며, 다른 정보로 대체되거나, 추가적인 정보가 더 포함될 수 있다.
STA은 인증 요청 프레임을 AP에게 송신할 수 있다. AP는 수신된 인증 요청 프레임에 포함된 정보에 기초하여, 해당 STA에 대한 인증을 허용할지 여부를 결정할 수 있다. AP는 인증 처리의 결과를 인증 응답 프레임을 통하여 STA에게 제공할 수 있다.
STA이 성공적으로 인증된 후에, 단계 S330에서 결합 과정이 수행될 수 있다. 결합 과정은 STA이 결합 요청 프레임(association request frame)을 AP에게 송신하고, 이에 응답하여 AP가 결합 응답 프레임(association response frame)을 STA에게 송신하는 과정을 포함한다.
예를 들어, 결합 요청 프레임은 다양한 캐퍼빌리티(capability)에 관련된 정보, 비콘 청취 간격(listen interval), SSID(service set identifier), 지원 레이트(supported rates), 지원 채널(supported channels), RSN, 이동성 도메인, 지원 오퍼레이팅 클래스(supported operating classes), TIM 브로드캐스트 요청(Traffic Indication Map Broadcast request), 상호동작(interworking) 서비스 캐퍼빌리티 등에 대한 정보를 포함할 수 있다. 예를 들어, 결합 응답 프레임은 다양한 캐퍼빌리티에 관련된 정보, 상태 코드, AID(Association ID), 지원 레이트, EDCA(Enhanced Distributed Channel Access) 파라미터 세트, RCPI(Received Channel Power Indicator), RSNI(Received Signal to Noise Indicator), 이동성 도메인, 타임아웃 간격(예를 들어, 결합 컴백 시간(association comeback time)), 중첩(overlapping) BSS 스캔 파라미터, TIM 브로드캐스트 응답, QoS(Quality of Service) 맵 등의 정보를 포함할 수 있다. 이는 결합 요청/응답 프레임에 포함될 수 있는 정보들의 일부 예시에 해당하며, 다른 정보로 대체되거나, 추가적인 정보가 더 포함될 수 있다.
STA이 네트워크에 성공적으로 결합된 후에, 단계 S340에서 보안 셋업 과정이 수행될 수 있다. 단계 S340의 보안 셋업 과정은 RSNA(Robust Security Network Association) 요청/응답을 통한 인증 과정이라고 할 수도 있고, 상기 단계 S320의 인증 과정을 첫 번째 인증(first authentication) 과정이라고 하고, 단계 S340의 보안 셋업 과정을 단순히 인증 과정이라고도 칭할 수도 있다.
단계 S340의 보안 셋업 과정은, 예를 들어, EAPOL(Extensible Authentication Protocol over LAN) 프레임을 통한 4-웨이(way) 핸드쉐이킹을 통해서, 프라이빗 키 셋업(private key setup)을 하는 과정을 포함할 수 있다. 또한, 보안 셋업 과정은 IEEE 802.11 표준에서 정의하지 않는 보안 방식에 따라 수행될 수도 있다.
도 4는 본 개시가 적용될 수 있는 백오프 과정을 설명하기 위한 도면이다.
무선랜 시스템에서, MAC(Medium Access Control)의 기본 액세스 메커니즘은 CSMA/CA(Carrier Sense Multiple Access with Collision Avoidance) 메커니즘이다. CSMA/CA 메커니즘은 IEEE 802.11 MAC의 분배 조정 기능(Distributed Coordination Function, DCF)이라고도 불리는데, 기본적으로 "말하기 전에 듣기(listen before talk)" 액세스 메커니즘을 채용하고 있다. 이러한 유형의 액세스 메커니즘 따르면, AP 및/또는 STA은 송신을 시작하기에 앞서, 소정의 시간구간(예를 들어, DIFS(DCF Inter-Frame Space) 동안 무선 채널 또는 매체(medium)를 센싱(sensing)하는 CCA(Clear Channel Assessment)를 수행할 수 있다. 센싱 결과, 만일 매체가 유휴 상태(idle status)인 것으로 판단되면, 해당 매체를 통하여 프레임 송신을 시작한다. 반면, 매체가 점유된(occupied) 또는 비지(busy) 상태인 것으로 감지되면, 해당 AP 및/또는 STA은 자기 자신의 송신을 시작하지 않고 매체 액세스를 위한 지연 기간(예를 들어, 랜덤 백오프 기간(random backoff period))을 설정하여 기다린 후에 프레임 송신을 시도할 수 있다. 랜덤 백오프 기간의 적용으로, 여러 STA들은 서로 다른 시간 동안 대기한 후에 프레임 송신을 시도할 것이 기대되므로, 충돌(collision)을 최소화시킬 수 있다.
또한, IEEE 802.11 MAC 프로토콜은 HCF(Hybrid Coordination Function)를 제공한다. HCF는 상기 DCF와 PCF(Point Coordination Function)를 기반으로 한다. PCF는 폴링(polling) 기반의 동기식 액세스 방식으로 모든 수신 AP 및/또는 STA이 데이터 프레임을 수신할 수 있도록 주기적으로 폴링하는 방식을 일컫는다. 또한, HCF는 EDCA(Enhanced Distributed Channel Access)와 HCCA(HCF Controlled Channel Access)를 가진다. EDCA는 제공자가 다수의 사용자에게 데이터 프레임을 제공하기 위한 액세스 방식을 경쟁 기반으로 하는 것이고, HCCA는 폴링(polling) 메커니즘을 이용한 비경쟁 기반의 채널 액세스 방식을 사용하는 것이다. 또한, HCF는 무선랜의 QoS(Quality of Service)를 향상시키기 위한 매체 액세스 메커니즘을 포함하며, 경쟁 기간(Contention Period, CP)와 비경쟁 기간(Contention Free Period, CFP) 모두에서 QoS 데이터를 송신할 수 있다.
도 4를 참조하여 랜덤 백오프 주기에 기반한 동작에 대해서 설명한다. 점유된/비지 상태이던 매체가 유휴 상태로 변경되면, 여러 STA들은 데이터(또는 프레임) 송신을 시도할 수 있다. 충돌을 최소화하기 위한 방안으로서, STA들은 각각 랜덤 백오프 카운트를 선택하고 그에 해당하는 슬롯 시간만큼 대기한 후에, 송신을 시도할 수 있다. 랜덤 백오프 카운트는 의사-랜덤 정수(pseudo-random integer) 값을 가지며, 0 내지 CW 범위의 값 중에서 하나로 결정될 수 있다. 여기서, CW는 경쟁 윈도우(Contention Window) 파라미터 값이다. CW 파라미터는 초기값으로 CWmin이 주어지지만, 송신 실패의 경우(예를 들어, 송신된 프레임에 대한 ACK을 수신하지 못한 경우)에 2 배의 값을 취할 수 있다. CW 파라미터 값이 CWmax가 되면 데이터 송신이 성공할 때까지 CWmax 값을 유지하면서 데이터 송신을 시도할 수 있고, 데이터 송신이 성공하는 경우에는 CWmin 값으로 리셋된다. CW, CWmin 및 CWmax 값은 2n-1 (n=0, 1, 2, ...)로 설정되는 것이 바람직하다.
랜덤 백오프 과정이 시작되면 STA은 결정된 백오프 카운트 값에 따라서 백오프 슬롯을 카운트 다운하는 동안에 계속하여 매체를 모니터링한다. 매체가 점유상태로 모니터링되면 카운트 다운을 멈추고 대기하고, 매체가 유휴 상태가 되면 나머지 카운트 다운을 재개한다.
도 4의 예시에서 STA3의 MAC에 송신할 패킷이 도달한 경우에, STA3는 DIFS 만큼 매체가 유휴 상태인 것을 확인하고 바로 프레임을 송신할 수 있다. 나머지 STA들은 매체가 점유/비지 상태인 것을 모니터링하고 대기한다. 그 동안 STA1, STA2 및 STA5의 각각에서도 송신할 데이터가 발생할 수 있고, 각각의 STA은 매체가 유휴상태로 모니터링되면 DIFS만큼 대기한 후에, 각자가 선택한 랜덤 백오프 카운트 값에 따라 백오프 슬롯의 카운트 다운을 수행할 수 있다. STA2가 가장 작은 백오프 카운트 값을 선택하고, STA1이 가장 큰 백오프 카운트 값을 선택한 경우를 가정한다. 즉, STA2가 백오프 카운트를 마치고 프레임 송신을 시작하는 시점에서 STA5의 잔여 백오프 시간은 STA1의 잔여 백오프 시간보다 짧은 경우를 예시한다. STA1 및 STA5는 STA2가 매체를 점유하는 동안에 잠시 카운트 다운을 멈추고 대기한다. STA2의 점유가 종료되어 매체가 다시 유휴 상태가 되면, STA1 및 STA5는 DIFS만큼 대기한 후에, 멈추었던 백오프 카운트를 재개한다. 즉, 잔여 백오프 시간만큼의 나머지 백오프 슬롯을 카운트 다운한 후에 프레임 송신을 시작할 수 있다. STA5의 잔여 백오프 시간이 STA1보다 짧았으므로 STA5이 프레임 송신을 시작하게 된다. STA2가 매체를 점유하는 동안에 STA4에서도 송신할 데이터가 발생할 수 있다. STA4의 입장에서는 매체가 유휴 상태가 되면 DIFS만큼 대기한 후, 자신이 선택한 랜덤 백오프 카운트 값에 따른 카운트 다운을 수행하고 프레임 송신을 시작할 수 있다. 도 4의 예시에서는 STA5의 잔여 백오프 시간이 STA4의 랜덤 백오프 카운트 값과 우연히 일치하는 경우를 나타내며, 이 경우, STA4와 STA5 간에 충돌이 발생할 수 있다. 충돌이 발생하는 경우에는 STA4와 STA5 모두 ACK을 받지 못하여, 데이터 송신을 실패하게 된다. 이 경우, STA4와 STA5는 CW 값을 2배로 늘린 후에 랜덤 백오프 카운트 값을 선택하고 카운트 다운을 수행할 수 있다. STA1은 STA4와 STA5의 송신으로 인해 매체가 점유 상태인 동안에 대기하고 있다가, 매체가 유휴 상태가 되면 DIFS만큼 대기한 후, 잔여 백오프 시간이 지나면 프레임 송신을 시작할 수 있다.
도 4의 예시에서와 같이, 데이터 프레임은 상위 레이어로 포워드되는 데이터의 송신을 위해 사용되는 프레임이며, 매체가 유휴 상태가 된 때로부터 DIFS 경과 후 수행되는 백오프 후 송신될 수 있다. 추가적으로, 관리 프레임은 상위 레이어에 포워드되지 않는 관리 정보의 교환을 위해 사용되는 프레임으로서, DIFS 또는 PIFS (Point coordination function IFS)와 같은 IFS 경과 후 수행되는 백오프 후 송신된다. 관리 프레임의 서브타입 프레임으로 비콘(Beacon), 결합 요청/응답(Association request/response), 재(re)-결합 요청/응답, 프로브 요청/응답(probe request/response), 인증 요청/응답(authentication request/response) 등이 있다. 제어 프레임은 매체에 액세스를 제어하기 위하여 사용되는 프레임이다. 제어 프레임의 서브 타입 프레임으로 RTS(Request-To-Send), CTS(Clear-To-Send), ACK(Acknowledgment), PS-Poll(Power Save-Poll), 블록 ACK(BlockAck), 블록 ACK 요청(BlockACKReq), NDP 공지(null data packet announcement), 트리거(Trigger) 등이 있다. 제어 프레임은 이전 프레임의 응답 프레임이 아닌 경우 DIFS 경과 후 수행되는 백오프 후 송신되고, 이전 프레임의 응답 프레임인 경우 SIFS(short IFS) 경과 후 백오프 수행 없이 송신된다. 프레임의 타입과 서브 타입은 프레임 제어(FC) 필드 내의 타입(type) 필드와 서브타입(subtype) 필드에 의해 식별될 수 있다.
QoS(Quality of Service) STA은 프레임이 속하는 액세스 카테고리(access category, AC)를 위한 AIFS(arbitration IFS), 즉 AIFS[i] (여기서, i는 AC에 의해 결정되는 값) 경과 후 수행되는 백오프 후 프레임을 송신할 수 있다. 여기서, AIFS[i]가 사용될 수 있는 프레임은 데이터 프레임, 관리 프레임이 될 수 있고, 또한 응답 프레임이 아닌 제어 프레임이 될 수 있다.
도 5는 본 개시가 적용될 수 있는 CSMA/CA 기반 프레임 송신 동작을 설명하기 위한 도면이다.
전술한 바와 같이 CSMA/CA 메커니즘은 STA이 매체를 직접 센싱하는 물리적 캐리어 센싱(physical carrier sensing) 외에 가상 캐리어 센싱(virtual carrier sensing)도 포함한다. 가상 캐리어 센싱은 숨겨진 노드 문제(hidden node problem) 등과 같이 매체 액세스에서 발생할 수 있는 문제를 보완하기 위한 것이다. 가상 캐리어 센싱을 위하여, STA의 MAC은 NAV(Network Allocation Vector)를 이용할 수 있다. NAV는 현재 매체를 사용하고 있거나 또는 사용할 권한이 있는 STA이, 매체가 이용 가능한 상태로 되기까지 남아 있는 시간을 다른 STA에게 지시(indicate)하는 값이다. 따라서 NAV로 설정된 값은 해당 프레임을 송신하는 STA에 의하여 매체의 사용이 예정되어 있는 기간에 해당하고, NAV 값을 수신하는 STA은 해당 기간동안 매체 액세스가 금지된다. 예를 들어, NAV는 프레임의 MAC 헤더(header)의 "duration" 필드의 값에 기초하여 설정될 수 있다.
도 5의 예시에서, STA1은 STA2로 데이터를 송신하고자 하고, STA3는 STA1과 STA2 간에 송수신되는 프레임의 일부 또는 전부를 오버히어링(overhearing)할 수 있는 위치에 있는 것으로 가정한다.
CSMA/CA 기반 프레임 송신 동작에서 다수의 STA의 송신의 충돌 가능성을 감소시키기 위해서, RTS/CTS 프레임을 이용하는 메커니즘이 적용될 수 있다. 도 5의 예시에서 STA1의 송신이 수행되는 동안 STA3의 캐리어 센싱 결과 매체가 유휴 상태라고 결정할 수도 있다. 즉, STA1은 STA3에게 히든 노드에 해당할 수 있다. 또는, 도 5의 예시에서 STA2의 송신이 수행되는 동안 STA3의 캐리어 센싱 결과 매체가 유휴 상태라고 결정할 수도 있다. 즉, STA2는 STA3에게 히든 노드에 해당할 수 있다. STA1과 STA2 간의 데이터 송수신을 수행하기 전에 RTS/CTS 프레임의 교환을 통해, STA1 또는 STA2 중의 하나의 송신 범위 밖의 STA, 또는 STA1 또는 STA3로부터의 송신에 대한 캐리어 센싱 범위 밖의 STA이, STA1과 STA2 간의 데이터 송수신 동안 채널 점유를 시도하지 않도록 할 수 있다.
구체적으로, STA1은 캐리어 센싱(carrier sensing)을 통해 채널이 사용되고 있는지를 결정할 수 있다. 물리적 캐리어 센싱의 측면에서, STA1은 채널에서 검출되는 에너지 크기 또는 신호 상관도(correlation)에 기초하여 채널 점유 유휴 상태를 결정할 수 있다. 또한, 가상 캐리어 센싱 측면에서, STA1은 NAV(network allocation vector) 타이머(timer)를 사용하여 채널의 점유 상태를 판단할 수 있다.
STA1은 DIFS 동안 채널이 유휴 상태인 경우 백오프 수행 후 RTS 프레임을 STA2에게 송신할 수 있다. STA2은 RTS 프레임을 수신한 경우 SIFS 후에 RTS 프레임에 대한 응답인 CTS 프레임을 STA1에게 송신할 수 있다.
STA3가 STA2으로부터의 CTS 프레임을 오버히어링할 수는 없지만 STA1으로부터의 RTS 프레임을 오버히어링할 수 있다면, STA3은 RTS 프레임에 포함된 듀레이션(duration) 정보를 사용하여 이후에 연속적으로 송신되는 프레임 송신 기간(예를 들어, SIFS + CTS 프레임 + SIFS + 데이터 프레임 + SIFS + ACK 프레임)에 대한 NAV 타이머를 설정할 수 있다. 또는, STA3가 STA3가 STA1으로부터의 RTS 프레임을 오버히어링할 수는 없지만 STA2로부터의 CTS 프레임을 오버히어링할 수 있다면, STA3는 CTS 프레임에 포함된 듀레이션 정보를 사용하여 이후에 연속적으로 송신되는 프레임 송신 기간(예를 들어, SIFS + 데이터 프레임 + SIFS + ACK 프레임)에 대한 NAV 타이머를 설정할 수 있다. 즉, STA3는 STA1 또는 STA2 중의 하나 이상으로부터의 RTS 또는 CTS 프레임 중의 하나 이상을 오버히어링할 수 있다면, 그에 따라 NAV를 설정할 수 있다. STA3은 NAV 타이머가 만료되기 전에 새로운 프레임을 수신한 경우 새로운 프레임에 포함된 듀레이션 정보를 사용하여 NAV 타이머를 갱신할 수 있다. STA3은 NAV 타이머가 만료되기 전까지 채널 액세스를 시도하지 않는다.
STA1은 STA2로부터 CTS 프레임을 수신한 경우 CTS 프레임의 수신이 완료된 시점부터 SIFS 후에 데이터 프레임을 STA2에게 송신할 수 있다. STA2는 데이터 프레임을 성공적으로 수신한 경우 SIFS 후에 데이터 프레임에 대한 응답인 ACK 프레임을 STA1에 송신할 수 있다. STA3는 NAV 타이머가 만료된 경우 캐리어 센싱을 통해 채널이 사용되고 있는지를 결정할 수 있다. STA3은 NAV 타이머의 만료 후부터 DIFS 동안 채널이 다른 단말에 의해 사용되지 않은 것으로 결정한 경우 랜덤 백오프에 따른 경쟁 윈도우(CW)가 지난 후에 채널 액세스를 시도할 수 있다.
도 6은 본 개시가 적용될 수 있는 무선랜 시스템에서 사용되는 프레임 구조의 예시를 설명하기 위한 도면이다.
MAC 계층으로부터의 명령어(instruction) 또는 프리머티브(primitive)(명령어들 또는 파라미터들의 세트를 의미함)에 의해서, PHY 계층은 송신될 MPDU(MAC PDU)를 준비할 수 있다. 예를 들어, PHY 계층의 송신 시작을 요청하는 명령어를 MAC 계층으로부터 받으면, PHY 계층에서는 송신 모드로 스위치하고 MAC 계층으로부터 제공되는 정보(예를 들어, 데이터)를 프레임의 형태로 구성하여 송신할 수 있다. 또한, PHY 계층에서는 수신되는 프레임의 유효한 프리앰블(preamble)을 검출하게 되면, 프리앰블의 헤더를 모니터링하여 PHY 계층의 수신 시작을 알려주는 명령어를 MAC 계층으로 보낸다.
이와 같이, 무선랜 시스템에서의 정보 송신/수신은 프레임의 형태로 이루어지며, 이를 위해서 PHY 계층 프로토콜 데이터 유닛(Physical layer Protocol Data Unit, PPDU) 포맷이 정의된다.
기본적인 PPDU는 STF(Short Training Field), LTF(Long Training Field), SIG(SIGNAL) 필드, 및 데이터(Data) 필드를 포함할 수 있다. 가장 기본적인(예를 들어, 도 7에서 도시하는 non-HT(High Throughput)) PPDU 포맷은 L-STF(Legacy-STF), L-LTF(Legacy-LTF), L-SIG(Legacy-SIG) 필드 및 데이터 필드만으로 구성될 수 있다. 또한, PPDU 포맷의 종류(예를 들어, HT-mixed 포맷 PPDU, HT-greenfield 포맷 PPDU, VHT(Very High Throughput) PPDU 등)에 따라서, L-SIG 필드와 데이터 필드 사이에 추가적인 (또는 다른 종류의) RL-SIG, U-SIG, 비-레거시 SIG 필드, 비-레거시 STF, 비-레거시 LTF, (즉, xx-SIG, xx-STF, xx-LTF (예를 들어, xx는 HT, VHT, HE, EHT 등)) 등이 포함될 수도 있다. 보다 구체적인 사항에 대해서는 도 7을 참조하여 후술한다.
STF는 신호 검출, AGC(Automatic Gain Control), 다이버시티 선택, 정밀한 시간 동기 등을 위한 신호이고, LTF는 채널 추정, 주파수 오차 추정 등을 위한 신호이다. STF와 LTF는 OFDM 물리계층의 동기화 및 채널 추정을 위한 신호라고 할 수 있다.
SIG 필드는 PPDU 송신 및 수신에 관련되는 다양한 정보를 포함할 수 있다. 예를 들어, L-SIG 필드는 24 비트로 구성되고, L-SIG 필드는 4-비트 레이트(Rate) 필드, 1-비트 유보(Reserved) 비트, 12-비트 길이(Length) 필드, 1-비트 패리티(Parity) 필드, 및 6-비트 테일(Tail) 필드를 포함할 수 있다. RATE 필드는 데이터의 변조 및 코딩 레이트에 대한 정보를 포함할 수 있다. 예를 들어, 12-비트 Length 필드는 PPDU의 길이 또는 시간 듀레이션에 관한 정보를 포함할 수 있다. 예를 들어, 12-비트 Length 필드의 값은 PPDU의 타입을 기초로 결정될 수 있다. 예를 들어, non-HT, HT, VHT, 또는 EHT PPDU에 대해서, Length 필드의 값은 3의 배수로 결정될 수 있다. 예를 들어, HE PPDU에 대해서, Length 필드의 값은 3의 배수 + 1 또는 3의 배수 + 2로 결정될 수 있다.
데이터 필드는 SERVICE 필드, PSDU(Physical layer Service Data Unit), PPDU TAIL 비트를 포함할 수 있고, 필요한 경우에는 패딩 비트도 포함할 수 있다. SERVICE 필드의 일부 비트는 수신단에서의 디스크램블러의 동기화를 위해 사용될 수 있다. PSDU는 MAC 계층에서 정의되는 MAC PDU에 대응하며, 상위 계층에서 생성/이용되는 데이터를 포함할 수 있다. PPDU TAIL 비트는 인코더를 0 상태로 리턴하기 위해서 이용될 수 있다. 패딩 비트는 데이터 필드의 길이를 소정의 단위로 맞추기 위해서 이용될 수 있다.
MAC PDU는 다양한 MAC 프레임 포맷에 따라서 정의되며, 기본적인 MAC 프레임은 MAC 헤더, 프레임 바디, 및 FCS(Frame Check Sequence)로 구성된다. MAC 프레임은 MAC PDU로 구성되어 PPDU 포맷의 데이터 부분의 PSDU를 통하여 송신/수신될 수 있다.
MAC 헤더는 프레임 제어(Frame Control) 필드, 듀레이션(Duration)/ID 필드, 주소(Address) 필드 등을 포함한다. 프레임 제어 필드는 프레임 송신/수신에 필요한 제어 정보들을 포함할 수 있다. 듀레이션/ID 필드는 해당 프레임 등을 송신하기 위한 시간으로 설정될 수 있다. 주소 서브필드들은 프레임의 수신자(receiver) 주소, 송신자(transmitter) 주소, 목적지(destination) 주소, 소스(source) 주소를 나타낼 수 있으며, 일부 주소 서브필드는 생략될 수도 있다. 시퀀스 제어(Sequence Control), QoS 제어(QoS Control), HT 제어(HT Control) 서브필드들을 포함하여, MAC 헤더의 각각의 서브필드들의 구체적인 내용은 IEEE 802.11 표준 문서를 참조할 수 있다.
널-데이터 PPDU(NDP) 포맷은 데이터 필드를 포함하지 않는 형태의 PPDU 포맷을 의미한다. 즉, NDP은, 일반적인 PPDU 포맷에서 PPDU 프리앰블(즉, L-STF, L-LTF, L-SIG 필드, 및 추가적으로 존재한다면 비-레거시 SIG, 비-레거시 STF, 비-레거시 LTF)을 포함하고, 나머지 부분(즉, 데이터 필드)은 포함하지 않는 프레임 포맷을 의미한다.
도 7은 본 개시가 적용될 수 있는 IEEE 802.11 표준에서 정의되는 PPDU의 예시들을 도시한 도면이다.
IEEE 802.11a/g/n/ac/ax 등의 표준에서는 다양한 형태의 PPDU가 사용되었다. 기본적인 PPDU 포맷(IEEE 802.11a/g)은 L-LTF, L-STF, L-SIG 및 Data 필드를 포함한다. 기본적인 PPDU 포맷을 non-HT PPDU 포맷이라 칭할 수도 있다(도 7(a)).
HT PPDU 포맷(IEEE 802.11n)은 HT-SIG, HT-STF, HT-LFT(s) 필드를 기본적인 PPDU 포맷에 추가적으로 포함한다. 도 7(b)에 도시된 HT PPDU 포맷은 HT-mixed 포맷이라고 칭할 수 있다. 추가적으로 HT-greenfield 포맷 PPDU가 정의될 수 있으며, 이는 L-STF, L-LTF, L-SIG를 포함하지 않고, HT-GF-STF, HT-LTF1, HT-SIG, 하나 이상의 HT-LTF, Data 필드로 구성되는 포맷에 해당한다 (미도시).
VHT PPDU 포맷(IEEE 802.11ac)의 일례는 VHT SIG-A, VHT-STF, VHT-LTF, VHT-SIG-B 필드를, 기본적인 PPDU 포맷에 추가적으로 포함한다(도 7(c)).
HE PPDU 포맷(IEEE 802.11ax)의 일례는 RL-SIG(Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), PE(Packet Extension) 필드를, 기본적인 PPDU 포맷에 추가적으로 포함한다(도 7(d)). HE PPDU 포맷의 세부 예시들에 따라 일부 필드가 제외되거나 그 길이가 달라질 수도 있다. 예를 들어, HE-SIG-B 필드는 다중 사용자(MU)를 위한 HE PPDU 포맷에 포함되고, 단일 사용자(SU)를 위한 HE PPDU 포맷에는 HE-SIG-B가 포함되지 않는다. 또한, HE 트리거-기반(trigger-based, TB) PPDU 포맷은 HE-SIG-B를 포함하지 않고, HE-STF 필드의 길이가 8us로 달라질 수 있다. HE ER(Extended Range) SU PPDU 포맷은 HE-SIG-B 필드를 포함하지 않고, HE-SIG-A 필드의 길이가 16us로 달라질 수 있다. 예를 들어, RL-SIG는 L-SIG와 동일하게 구성될 수 있다. 수신 STA은 RL-SIG의 존재를 기초로 수신 PPDU가 HE PPDU 또는 후술하는 EHT PPDU임을 알 수 있다.
EHT PPDU 포맷은 도 7(e)의 EHT MU(multi-user) 및 도 7(f)의 EHT TB(trigger-based) PPDU를 포함할 수 있다. EHT PPDU 포맷은 L-SIG에 후속하여 RL-SIG를 포함하는 것은 HE PPDU 포맷과 유사하지만, RL-SIG에 후속하여 U(universal)-SIG, EHT-SIG, EHT-STF, EHT-LTF를 포함할 수 있다.
도 7(e)의 EHT MU PPDU는 하나 이상의 사용자에 대한 하나 이상의 데이터(또는 PSDU)를 나르는(carry) PPDU에 해당한다. 즉, EHT MU PPDU는 SU 송신 및 MU 송신 모두를 위해서 사용될 수 있다. 예를 들어, EHT MU PPDU는 하나의 수신 STA 또는 복수의 수신 STA을 위한 PPDU에 해당할 수 있다.
도 7(f)의 EHT TB PPDU는 EHT MU PPDU에 비하여 EHT-SIG가 생략된다. UL MU 송신을 위한 트리거(예를 들어, 트리거 프레임 또는 TRS(triggered response scheduling))를 수신한 STA은, EHT TB PPDU 포맷에 기초하여 UL 송신을 수행할 수 있다.
L-STF, L-LTF, L-SIG, RL-SIG, U-SIG(Universal SIGNAL), EHT-SIG 필드들은, 레거시 STA에서도 복조 및 디코딩을 시도할 수 있도록 인코딩 및 변조되어 정해진 서브캐리어 주파수 간격(예를 들어, 312.5kHz)에 기반하여 매핑될 수 있다. 이들을 프리-EHT 변조(pre-EHT modulated) 필드들이라고 칭할 수 있다. 다음으로, EHT-STF, EHT-LTF, Data, PE 필드들은, 비-레거시 SIG(예를 들어, U-SIG 및/또는 EHT-SIG)를 성공적으로 디코딩하여 해당 필드에 포함된 정보를 획득한 STA에 의해서 복조 및 디코딩될 수 있도록 인코딩 및 변조되어 정해진 서브캐리어 주파수 간격(예를 들어, 78.125kHz)에 기반하여 매핑될 수 있다. 이들을 EHT 변조(EHT modulated) 필드들이라고 칭할 수 있다.
이와 유사하게, HE PPDU 포맷에서 L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, HE-SIG-B 필드들을 프리-HE 변조 필드라 칭하고, HE-STF, HE-LTF, Data, PE 필드들을 HE 변조 필드라고 칭할 수 있다. 또한, VHT PPDU 포맷에서 L-STF, L-LTF, L-SIG, VHT-SIG-A 필드들을 프리 VHT 변조 필드라고 칭하고, VHT STF, VHT-LTF, VHT-SIG-B, Data 필드들을 VHT 변조 필드라고 칭할 수 있다.
도 7의 EHT PPDU 포맷에 포함되는 U-SIG는, 예를 들어, 2개의 심볼(예를 들어, 연속하는 2 개의 OFDM 심볼)을 기초로 구성될 수 있다. U-SIG를 위한 각 심볼(예를 들어, OFDM 심볼)은 4us의 듀레이션을 가질 수 있고, U-SIG는 전체 8us의 듀레이션을 가질 수 있다. U-SIG의 각 심볼은 26 비트 정보를 송신하기 위해 사용될 수 있다. 예를 들어 U-SIG의 각 심볼은 52개의 데이터 톤과 4 개의 파일럿 톤을 기초로 송수신될 수 있다.
U-SIG는 20MHz 단위로 구성될 수 있다. 예를 들어, 80MHz PPDU가 구성되는 경우, 20MHz 단위로 동일한 U-SIG가 복제될 수 있다. 즉, 80MHz PPDU 내에 동일한 4개의 U-SIG가 포함될 수 있다. 80 MHz 대역폭을 초과하는 경우, 예를 들어, 160MHz PPDU에 대해서는 첫 번째 80MHz 단위의 U-SIG와 두 번째 80MHz 단위의 U-SIG는 상이할 수 있다.
U-SIG를 통해서는 예를 들어 A 개의 코딩되지 않은 비트(un-coded bit)가 송신될 수 있고, U-SIG의 제 1 심볼(예를 들어, U-SIG-1 심볼)은 총 A 비트 정보 중 처음 X 비트 정보를 송신하고, U-SIG의 제 2 심볼(예를 들어, U-SIG-2 심볼)은 총 A 비트 정보 중 나머지 Y 비트 정보를 송신할 수 있다. A 비트 정보(예를 들어, 52 코딩되지 않은 비트)에는 CRC 필드(예를 들어 4 비트 길이의 필드) 및 테일 필드(예를 들어 6 비트 길이의 필드)가 포함될 수 있다. 테일 필드는 컨볼루션 디코더의 트렐리스(trellis)를 종료(terminate)하기 위해 사용될 수 있고, 예를 들어 0으로 설정될 수 있다.
U-SIG에 의해 송신되는 A 비트 정보는 버전-독립적(version-independent) 비트들과 버전-종속적(version-dependent) 비트들로 구분될 수 있다. 예를 들어, 도 7에 도시하지 않은 새로운 PPDU 포맷(예를 들어, UHR PPDU 포맷)에 U-SIG가 포함될 수 있으며, EHT PPDU 포맷에 포함되는 U-SIG 필드의 포맷과, UHR PPDU 포맷에 포함되는 U-SIG 필드의 포맷에서, 버전-독립적 비트들은 동일할 수 있고, 버전-종속적 비트들은 일부 또는 전부가 상이할 수 있다.
예를 들어, U-SIG의 버전-독립적 비트들의 크기는 고정적이거나 가변적일 수 있다. 버전-독립적 비트들은 U-SIG-1 심볼에만 할당되거나, U-SIG-1 심볼 U-SIG-2 심볼 모두에 할당될 수 있다. 버전-독립적 비트들과 버전-종속적 비트들은 제 1 제어 비트 및 제 2 제어 비트 등의 다양한 명칭으로 불릴 수 있다.
예를 들어, U-SIG의 버전-독립적 비트들은 3 비트의 물리계층 버전 식별자(PHY version identifier)를 포함할 수 있으며, 이 정보는 송수신 PPDU의 PHY 버전(예를 들어, EHT, UHR 등)을 지시할 수 있다. U-SIG의 버전-독립적 비트들은 1 비트의 UL/DL 플래그(flag) 필드를 포함할 수 있다. 1-비트 UL/DL flag 필드의 제 1 값은 UL 통신에 관련되고, UL/DL flag 필드의 제 2 값은 DL 통신에 관련된다. U-SIG의 버전-독립적 비트들은 TXOP(transmission opportunity)의 길이에 관한 정보, BSS 컬러(color) ID에 관한 정보를 포함할 수 있다.
예를 들어, U-SIG의 버전-종속적 비트들은 PPDU의 타입(예를 들어, SU PPDU, MU PPDU, TB PPDU 등)을 직접적 또는 간접적으로 지시하는 정보를 포함할 수 있다.
PPDU 송수신을 위해서 필요한 정보가 U-SIG에 포함될 수 있다. 예를 들어, U-SIG는, 대역폭에 관한 정보, 비-레거시 SIG(예를 들어, EHT-SIG 또는 UHR-SIG 등)에 적용되는 MCS 기법에 대한 정보, 비-레거시 SIG에 DCM(dual carrier modulation) 기법(예를 들어, 동일한 신호를 두 개의 서브캐리어 상에서 재사용(reuse)하여 주파수 다이버시티와 유사한 효과를 달성하기 위한 기법)이 적용되는지 여부를 지시하는 정보, 비-레거시 SIG를 위해 사용되는 심볼의 개수에 대한 정보, 비-레거시 SIG가 전 대역에 걸쳐 생성되는지 여부에 대한 정보 등을 더 포함할 수 있다.
PPDU 송수신을 위해서 필요한 정보 중 일부는 U-SIG 및/또는 비-레거시 SIG(예를 들어, EHT-SIG 또는 UHR-SIG 등)에 포함될 수도 있다. 예를 들어, 비-레거시 LTF/STF(예를 들어, EHT-LTF/EHT-STF 또는 UHR-LTF/UHR-STF 등)의 타입에 대한 정보, 비-레거시 LTF의 길이 및 CP(cyclic prefix) 길이에 대한 정보, 비-레거시 LTF에 적용되는 GI(guard interval)에 대한 정보, PPDU에 적용가능한 프리앰블 펑처링(puncturing)에 대한 정보, RU(resource unit) 할당에 대한 정보 등은, U-SIG에만 포함될 수도 있고, 비-레거시 SIG에만 포함될 수도 있고, U-SIG에 포함된 정보와 비-레거시 SIG에 포함되는 정보의 조합에 의해서 지시될 수도 있다.
프리앰블 펑처링은 PPDU의 대역폭 중에서 하나 이상의 주파수 유닛에 신호가 존재(present)하지 않는 PPDU의 송신을 의미할 수 있다. 예를 들어, 주파수 유닛의 크기(또는 프리앰블 펑처링의 분해도(resolution))는 20MHz, 40MHz 등으로 정의될 수도 있다. 예를 들어, 소정의 크기 이상의 PPDU 대역폭에 대해서 프리앰블 펑처링이 적용될 수 있다.
도 7의 예시에서 HE-SIG-B, EHT-SIG 등의 비-레거시 SIG는 수신 STA을 위한 제어 정보를 포함할 수 있다. 비-레거시 SIG는 적어도 하나의 심볼을 통해 송신될 수 있고, 하나의 심볼은 4us의 길이를 가질 수 있다. EHT-SIG를 위해 사용되는 심볼의 개수에 관한 정보는 이전의 SIG(예를 들어, HE-SIG-A, U-SIG 등)에 포함될 수 있다.
HE-SIG-B, EHT-SIG 등의 비-레거시 SIG는, 공통필드(common field) 및 사용자-특정 필드(user-specific field)를 포함할 수 있다. 공통 필드 및 사용자-특정 필드는 개별적으로 코딩될 수 있다.
일부 경우에서, 공통 필드는 생략될 수도 있다. 예를 들어, 비-OFDMA(orthogonal frequency multiple access)가 적용되는 압축 모드에서 공통 필드가 생략될 수 있고, 복수의 STA은 동일한 주파수 대역을 통해 PPDU(예를 들어, PPDU의 데이터 필드)를 수신할 수 있다. OFDMA가 적용되는 비-압축 모드에서는 복수의 사용자는 상이한 주파수 대역을 통해 PPDU(예를 들어, PPDU의 데이터 필드)를 수신할 수 있다.
사용자-특정 필드의 개수는 사용자(user)의 개수를 기초로 결정될 수 있다. 하나의 사용자 블록 필드는 최대 2개의 사용자 필드(user field)를 포함할 수 있다. 각 사용자 필드(user field)는 MU-MIMO 할당에 관련되거나, 비-MU-MIMO 할당에 관련될 수 있다.
공통 필드는 CRC 비트와 Tail 비트를 포함할 수 있고, CRC 비트의 길이는 4 비트로 결정될 수 있고, Tail 비트의 길이는 6 비트로 결정되고 000000으로 설정될 수 있다. 공통 필드는 RU 할당 정보(RU allocation information)를 포함할 수 있다. RU 할당 정보는 복수의 사용자(즉, 복수의 수신 STA)이 할당되는 RU의 위치(location)에 관한 정보를 포함할 수 있다.
RU는 복수 개의 서브캐리어(또는 톤)을 포함할 수 있다. RU는 OFDMA 기법을 기초로 다수의 STA에게 신호를 송신하는 경우 사용될 수 있다. 또한 하나의 STA에게 신호를 송신하는 경우에도 RU가 정의될 수 있다. 비-레거시 STF, 비-레거시 LTF, Data 필드에 대해 RU 단위로 자원이 할당될 수 있다.
PPDU 대역폭에 따라서 적용가능한 크기의 RU가 정의될 수 있다. RU는 적용되는 PPDU 포맷(예를 들어, HE PPDU, EHT PPDU, UHR PPDU 등)에 대해서 동일하게 또는 상이하게 정의될 수도 있다. 예를 들어, 80MHz PPDU의 경우 HE PPDU와 EHT PPDU의 RU 배치가 상이할 수 있다. PPDU 대역폭 별로 적용가능한 RU의 크기, RU 개수, RU 위치, DC(direct current) 서브캐리어 위치 및 개수, 널(null) 서브캐리어 위치 및 개수, 가드 서브캐리어 위치 및 개수 등을 톤-플랜(tone-plan)이라 할 수 있다. 예를 들어, 넓은 대역폭에 대한 톤-플랜은 낮은 대역폭의 톤-플랜의 다수 반복의 형태로 정의될 수도 있다.
다양한 크기의 RU는 26-톤 RU, 52-톤 RU, 106-톤 RU, 242-톤 RU, 484-톤 RU, 996-톤 RU, 2Х996-톤 RU, 4Х996-톤 RU 등과 같이 정의될 수 있다. MRU(multiple RU)는 복수의 개별적인 RU와 구별되며, 복수의 RU로 구성되는 서브캐리어들의 그룹에 해당한다. 예를 들어, 하나의 MRU는, 52+26-톤, 106+26-톤, 484+242-톤, 996+484-톤, 996+484+242-톤, 2Х996+484-톤, 3Х996-톤, 또는 3Х996+484-톤으로 정의될 수 있다. 또한, 하나의 MRU를 구성하는 복수의 RU는 주파수 도메인에서 연속적일 수도 있고, 연속적이지 않을 수도 있다.
RU의 구체적인 크기는 축소 또는 확장될 수도 있다. 따라서, 본 개시에서 각 RU의 구체적인 크기(즉, 상응하는 톤의 개수)는 제한적이지 않으며 예시적이다. 또한, 본 개시에서 소정의 대역폭(예를 들어, 20, 40, 80, 160, 320MHz, ...) 내에서, RU의 개수는 RU 크기에 따라서 달라질 수 있다.
도 7의 PPDU 포맷들에서 각각의 필드의 명칭은 예시적인 것이며, 그 명칭에 의해서 본 개시의 범위가 제한되지 않는다. 또한, 본 개시의 예시들은, 도 7에서 예시하는 PPDU 포맷은 물론, 도 7의 PPDU 포맷들을 기반으로 일부 필드가 제외되거나 및/또는 일부 필드가 추가되는 형태의 새로운 PPDU 포맷에도 적용될 수 있다.
블록-ACK(BlockACK, BA) 프레임
도 8은 본 개시가 적용될 수 있는 블록-ACK 프레임의 예시적인 포맷을 나타내는 도면이다.
블록-ACK(BlockAck, BA) 메커니즘은 하나의 프레임에 복수의 확인 응답을 포함시켜 전송함으로써 채널 효율성을 증대시키는 방식이다. 예를 들어, 제1 STA(예를 들어, AP)는 블록-ACK 요청 프레임을 통해 다수의 MPDU에 대한 수신 결과를 요청할 수 있으며, 블록-ACK 요청 프레임을 수신한 제2 STA(들)은 해당 요청에 기초하여 다수의 MPDU에 대한 확인 응답을 포함하는 블록-ACK 프레임을 송신할 수 있다.
도 8에 도시된 바와 같이, 블록-ACK 프레임은 프레임 바디에 BA 제어(BA control) 필드 및 BA 정보(BA information) 필드를 포함할 수 있다.
BA 제어 필드는 블록-ACK 프레임의 유형(예를 들어, 압축된(compressed), 다중-STA(multi-STA) 등)을 지시하는 BA 유형(BA type), 관리 ACK(management Ack) 정보, TID 정보(TID_INFO) 등을 포함할 수 있다.
BA 정보 필드는 BA 제어 정보 내 BA 유형 필드/서브필드에 의해 지시되는 블록-ACK 프레임의 유형(즉, 블록-ACK 프레임 배리언트 유형)에 기초할 수 있다.
예를 들어, 압축된 블록-ACK 프레임 유형이 지시되는 경우, 압축된 블록-ACK에 상응하는 BA 정보 필드 포맷은 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 필드 및 블록-ACK 비트맵(Block Ack Bitmap) 필드를 포함할 수 있다.
이와 관련하여, 블록-ACK 시작 시퀀스 제어 필드의 조각 개수(Fragment Number) 서브필드는 아래의 표 1과 같이 정의될 수 있다.
Figure PCTKR2024017734-appb-img-000001
표 1을 참조하면, 만일, 압축된 블록-ACK 프레임이 non-HE STA로 전송되거나, non-HE STA로부터 전송되는 경우, 블록-ACK 시작 시퀀스 제어 필드의 조각 개수(Fragment Number) 서브필드는 모두 0 값으로 세팅될 수 있다.
조각 개수(Fragment Number) 서브필드의 B0 비트가 0이고 B3 비트가 0이면, 압축된 블록-ACK 프레임의 BA 정보 필드의 블록-ACK 비트맵 서브필드는 표 1에 표시된 조각 개수(Fragment Number) 서브필드의 B2-B1 비트 값에 따라 최대 64개 또는 256개의 MSDU 및/또는 A-MSDU의 수신 상태를 나타낼 수 있다. 조각 개수(Fragment Number) 서브필드의 B0 비트가 0이고 조각 개수(Fragment Number) 서브필드의 B3 비트가 1인 경우, 압축된 블록-ACK 프레임의 BA 정보 필드의 블록-ACK 비트맵 서브필드는 표 1에 표시된 대로 조각 개수(Fragment Number) 서브필드의 B2-B1 비트의 값에 따라 최대 512개 또는 1024개의 MSDU 및/또는 A-MSDU의 수신 상태를 나타낼 수 있다. 압축된 블록-ACK 비트맵 서브필드에서 1과 동일한 각 비트는 시퀀스 번호 순서대로 단일 MSDU 또는 A-MSDU의 수신을 확인하며, 블록-ACK 비트맵 서브필드의 첫번째 비트는 블록-ACK 시작 시퀀스 제어 서브필드의 시작 시퀀스 번호(Starting Sequence Number) 서브필드와 일치하는 시퀀스 번호를 가진 MSDU(또는 그 조각) 또는 A-MSDU(또는 그 조각)에 해당할 수 있다.
조각 개수(Fragment Number) 서브필드의 B0 비트가 1이면, 압축된 블록-ACK 프레임의 BA 정보 필드의 블록-ACK 비트맵 서브필드는 표 1에 표시된 조각 개수(Fragment Number) 서브필드의 B2-B1 비트 값에 따라 최대 16개 또는 64개의 MSDU 및/또는 A-MSDU의 수신 상태를 나타낼 수 있다. 블록-ACK 비트맵 서브필드의 비트 위치 n (여기서, n=4*(SN-SSN)+FN)이 1이면, 이는 시퀀스 번호 값 SN과 조각 번호 값 FN이 있는 MPDU의 수신을 확인할 수 있다. 여기서, SSN은 블록-ACK 시작 시퀀스 제어 서브필드의 시작 시퀀스 번호(Starting Sequence Number) 서브필드의 값이며, 시퀀스 번호에 대한 연산은 모듈로(modulo) 4096으로 수행될 수 있다. 블록-ACK 비트맵 서브필드의 비트 위치 n이 0이면 MPDU가 수신되지 않았음을 나타낼 수 있다.
다른 예를 들어, 다중-STA(multi-STA) 블록-ACK 프레임 유형이 지시되는 경우, 다중-STA 블록-ACK에 상응하는 BA 정보 필드 포맷은 하나 이상의 Per AID TID 정보(Per AID TID Info) 서브필드를 포함할 수 있다.
이와 관련하여, AID11 서브필드가 2045가 아닌 경우, Per AID TID 정보 서브필드는 AID TID 정보(AID TID Info) 서브필드, 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드 및 블록-ACK 비트맵(Block Ack Bitmap) 서브필드를 포함할 수 있다. 여기서, AID TID 정보 서브필드는 (11-비트) AID11 서브필드, (1-비트) ACK 유형(ACK Type) 서브필드, (4-비트) TID 서브필드를 포함할 수 있다. 일 예로, 다중 STA 블록-ACK 프레임이 AP에 의해 전송되는 경우 AID11 서브필드는 0으로 세팅되며, AID11 서브필드의 2045 값은 결합되지 않은 STA(unassociated STA)를 위한 식별자로서 사용될 수 있다.
이와 관련하여, AID11 서브필드가 2045가 아닌 경우, Per AID TID 정보 서브필드 내 서브필드의 값과 선택적 서브필드의 존재 여부 등은 아래의 표 2에 기초하여 정의될 수 있다.
Figure PCTKR2024017734-appb-img-000002
이와 관련하여, Ack 유형 서브필드가 0인 경우, 조각 개수 서브필드 인코딩(Fragment Number subfield encoding)은 표 3에 정의된 바와 같이 블록-ACK 비트맵 서브필드의 길이를 지시할 수 있다. 표 3은 다중 STA 블록-Ack 유형에 대한 조각 개수 서브필드 인코딩을 예시한다.
Figure PCTKR2024017734-appb-img-000003
표 3을 참조하면, 블록-Ack 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드의 조각 개수(Fragment Number) 서브필드의 B0 비트가 0이고, B3 비트가 0인 경우, 다중 STA 블록-ACK 프레임의 BA 정보 필드에는 표 3에 정의된 조각 개수(Fragment Number) 서브필드의 B2-B1 비트에 따라 8옥텟, 16옥텟, 32옥텟 또는 4옥텟의 블록-Ack 비트맵 서브필드가 포함되며, 이를 통해 각각 최대 64, 128, 256 또는 32개의 MSDU(또는 그 조각) 및/또는 A-MSDU(또는 그 조각)의 수신 상태를 나타낼 수 있다. 블록-Ack 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드의 조각 개수(Fragment Number) 서브필드의 B0 비트가 0이고 B3 비트가 1인 경우, 다중 STA 블록-ACK 프레임의 BA 정보 필드에는 표 3에 정의된 조각 개수(Fragment Number) 서브필드의 B2-B1 비트에 따라 64옥텟 또는 128옥텟의 블록-Ack 비트맵 서브필드가 포함되며, 이를 통해 각각 최대 512 또는 1024개의 MSDU 및/또는 A-MSDU의 수신 상태를 나타낼 수 있다. 블록-ACK 비트맵(Block Ack Bitmap) 서브필드에서 1과 동일한 각 비트는 시퀀스 번호 순서대로 단일 MSDU 또는 A-MSDU의 수신을 확인하며, 블록-ACK 비트맵 서브필드의 첫번째 비트는 블록-ACK 시작 시퀀스 제어 서브필드의 시작 시퀀스 번호(Starting Sequence Number) 서브필드와 일치하는 시퀀스 번호를 가진 MSDU(또는 그 조각) 또는 A-MSDU(또는 그 조각)에 해당할 수 있다.
조각 개수(Fragment Number) 서브필드의 B0 비트가 1이면, 다중 STA 블록-ACK 프레임의 BA 정보 필드의 블록-ACK 비트맵 서브필드는 표 3에 표시된 조각 개수(Fragment Number) 서브필드의 B2-B1 비트 값에 따라 16, 32, 64, 또는 8개의 MSDU 및/또는 A-MSDU의 수신 상태를 나타낼 수 있다. 블록-ACK 비트맵 서브필드의 비트 위치 n (여기서, n=4*(SN-SSN)+FN)이 1이면, 이는 시퀀스 번호 값 SN과 조각 번호 값 FN이 있는 MPDU의 수신을 확인할 수 있다. 여기서, SSN은 블록-ACK 시작 시퀀스 제어 서브필드의 시작 시퀀스 번호(Starting Sequence Number) 서브필드의 값이며, 시퀀스 번호에 대한 연산은 모듈로(modulo) 4096으로 수행될 수 있다. 블록-ACK 비트맵 서브필드의 비트 위치 n이 0이면 MPDU가 수신되지 않았음을 나타낼 수 있다.
BIP(Broadcast/Multicast Integrity Protocol)
BIP는 IGTKSA(Integrity Group Temporal Key Security Association) 설립(establishment) 후 그룹 어드레스된 강력한 관리 프레임(group addressed robust management frames)과 BIGTKSA(Beacon Integrity Group Temporal Key Security Association) 설립 후 비콘 프레임에 대하여, 데이터 무결성 및 재생 보호(integrity and replay protection)를 제공한다. 또한, BIP는 개별 어드레스된(individually addressed) 및 그룹 어드레스된(group addressed) WUR(Wake Up Radio) 프레임에 대한 무결성 및 재생 보호를 제공한다.
이와 관련하여, BIP-CMAC-128은 128-비트 무결성 키와 128(16-옥텟)의 CMAC TLen 값을 갖춘 CMAC 모드의 AES-128을 사용하여 데이터 무결성 및 재생 보호를 제공할 수 있다. 또한, BIP-CMAC-256은 256-비트 무결성 키와 128(16-옥텟)의 CMAC TLen 값을 갖춘 CMAC 모드의 AES-256을 사용하여 데이터 무결성 및 재생 보호를 제공할 수 있다.
BIP는 IGTK(Integrity Group Temporal Key) 또는 BIGTK(Beacon Integrity Group Temporal Key)를 사용하여 MMPDU(management MPDU) MIC(message integrity code)를 계산할 수 있다. 또한, BIP는 WTK(WUR Temporal Key)를 사용하여 개별 어드레스된 WUR 웨이크업 프레임을 보호하기 위해 MIC를 계산할 수 있다. 또한, BIP는 WIGTK(WUR Integrity Group Temporal Key)를 사용하여 브로드캐스트 또는 그룹 어드레스된 WUR 웨이크업 프레임을 보호하기 위한 MIC를 계산할 수 있다.
인증자(authenticator)는 관리 프레임 보호가 협상되면, 새로운 GTK(Group Temporal Key)를 배포할 때마다 새로운 IGTK 및 IGTK PN(IGTK packet number, IPN)을 배포해야 한다. 여기서, IGTK는 전송 STA의 MAC 어드레스와 MME(Management MIC element) 내 키 ID 필드(Key ID field)에 인코딩된 IGTK 키 ID(IGTK Key ID)에 의해 식별될 수 있다. 또한, 비콘 보호가 활성화된 경우, 인증자는 새로운 GTK를 배포할 때 하나의 새로운 BIGTK 및 BIPN(BIGTK packet number)을 배포할 수 있다. 여기서, BIGTK는 전송 STA의 MAC 어드레스와 MME 내 키 ID 필드에 인코딩된 BIGTK 키 ID(BIGTK Key ID)에 의해 식별될 수 있다. 또한, WUR 프레임 보호가 협상된 경우, 인증자는 새로운 GTK를 배포할 때 하나의 새로운 WIGTK 및 WIPN(WIGTK packet number)을 배포할 수 있다. 여기서, WIGTK는 전송 STA의 MAC 어드레스와 MME 내 키 ID 필드에 인코딩된 WIGTK 키 ID(WIGTK Key ID)에 의해 식별될 수 있다.
도 9는 본 개시에 적용될 수 있는 BIP MMPDU 포맷을 예시한다.
도 9를 참조하면, BIP 캡슐화(BIP encapsulation) 즉, BIP MPPDU 포맷은 MAC 헤더(예를 들어, IEEE 802.11 헤더), MME(Management MIC element)를 포함하는 관리 프레임 바디, 및 FCS를 포함할 수 있다.
이와 관련하여, MME 포맷은 요소 ID(element ID) 정보, 길이(length) 정보, 키 ID(Key ID) 정보, PN 정보(예를 들어, IPN, BIPN, WIPN 등), 및 MIC 정보를 포함할 수 있다.
추가적으로, BIP 기반의 무결성 검사를 위해 활용되는 AAD(additional authentication data)(예를 들어, BIP AAD)는 MAC 헤더로부터 구성될 수 있다. 예를 들어, AAD는 MPDU 프레임 제어 필드(MPDU frame control field) 및 어드레스 정보로 구성될 수 있다. 구체적인 예로, 20-옥텟의 BIP AAD는 2-옥텟의 MPDU 프레임 제어 필드, 6-옥텟의 MPDU 어드레스 1 필드, 6-옥텟의 MPDU 어드레스 2 필드, 및 6-옥텟의 MPDU 어드레스 3 필드를 포함할 수 있다.
블록-ACK 프레임(BlockAck frame)에 대하여 BIP 기반의 무결성 검사를 지원하는 방법
기존 무선랜 시스템의 경우, 개별 어드레스된 데이터 프레임(예를 들어, 유니캐스트 기반 데이터 프레임) 및 관리 프레임(들)에 대해, PTK(pairwise transient key)를 이용하여 TKIP(Temporal Key Integrity Protocol)/CCMP(CTR with CBC-MAC protocol)/GCMP(GCM Protocol)에 기초하는 암호화(encryption)/복호화(decryption)가 수행/적용될 수 있다. 또한, 그룹 어드레스된 프레임(예를 들어, 브로드캐스트 기반 데이터 프레임)에 대해, GTK(group temporal key)를 이용하여 TKIP/CCMP/GCMP에 기초하는 암호화/복호화가 수행/적용될 수 있다. 즉, CCMP/GCMP는 암호화/복호화를 수행하는 보안 프로토콜로서, SU(single-user)의 경우 PTK를 기반으로 하는 TK가 사용되며, MU(multi-user)의 경우에는 GTK를 기반으로 하는 TK가 사용될 수 있다. CCMP/GCMP는 데이터 프레임 및 관리 프레임(들)에 대한 기밀성(confidentiality) 및 무결성(integrity)을 보장할 수 있다.
또한, 그룹 어드레스된 관리 프레임(들)에 대하여, IGTK(integrity group temporal key)를 이용하여 BIP 기반의 무결성 검사가 수행될 수 있다. 특히, 비콘 프레임의 경우, BIGTK(beacon integrity group temporal key)를 이용하여 BIP 기반의 무결성 검사가 수행될 수 있다. BIP의 경우, IGTK/BIGTK을 기반으로 한 TK을 사용하여 해당 데이터 프레임의 프레임 바디(frame body)에 대한 MIC(message integrity code)을 생성하며, 이에 기초하는 무결성 검사가 수행될 수 있다. 즉, BIP는, CCMP/GCMP와 달리, 데이터 프레임 및 관리 프레임(들)에 대한 무결성만 보장할 수 있다.
CCMP 및 GCMP에 기반하는 MPDU를 구성하는 방식과 BIP에 기반하는 MMPDU(management MPDU)를 구성하는 방식은 다음과 같은 차이점을 가진다.
먼저, CCMP/GCMP의 경우, 송신 STA은 CCM/GCM으로 데이터 부분에 대한 암호화를 진행하며, 암호화된 데이터를 송신하고, 수신 STA은 수신한 암호화된 데이터를 복호화할 수 있다. 이와 달리, BIP의 경우, 송신 STA은 데이터 부분의 암호화를 진행하지 않으며, 프레임 바디(frame body)의 데이터의 무결성 검사를 위한 MIC을 생성하기 위해 해당 프로토콜을 수행할 수 있다.
다음으로, CCMP/GCMP의 경우, MPDU는 MAC 헤더, CCMP/GCMP 헤더, 암호화된 데이터, MIC (CCMP의 경우 암호화된 MIC), 및 FCS의 순서로 구성 및 송수신될 수 있다. 이와 달리, BIP의 경우, MAC 헤더, MME(management MIC element)를 포함하는 관리 프레임 바디, 및 FCS의 순서로 구성 및 송수신될 수 있다. 여기서, MME는 CCMP/GCMP 헤더의 역할을 대신하기 때문에, 키 ID 필드(Key ID field), IPN/BIPN, MIC의 정보를 포함할 수 있다.
전술한 바와 같이, 그룹 어드레스된 프레임 중 데이터 프레임 및 비콘 프레임을 포함한 관리 프레임에 대해서는 보호(protection)가 지원된다. 다만, 제어 프레임(control frame)에 대해서는 보호가 지원되지 않으며, 이에 따라 제어 프레임은 어떠한 암호화/복호화 및/또는 무결성 검사를 위한 프로토콜이 적용되지 않은 상태로 송수신된다.
예를 들어, ACK 및 블록-ACK(BlockAck, Block Ack, BA) 프레임은 제어 프레임의 한 유형에 해당한다. 송신 STA가 데이터를 송신하면, 수신 STA은 해당 데이터에 대한 ACK을 송신 STA에게 송신할 수 있다. 이때, A(aggregated)-MPDU를 지원하는 STA(들)은 해당 ACK을 A-MPDU로 구성하여 블록-ACK 형태로 송신할 수 있다.
제어 프레임에 속하는 블록-ACK 프레임은 하나의 STA이 블록-ACK을 송신하는 압축된 블록-ACK 유형과 다수의 STA의 ACK을 블록-ACK 형태로 송신하는 다중 STA 블록-ACK 유형으로 구성될 수 있다. 압축된 블록-ACK 유형과 달리 다중 STA 블록-ACK 유형의 경우, 블록-ACK 프레임의 BA 정보 필드 내에 AID11 서브필드가 포함될 수 있으며, 해당 AID를 통해 어떤 STA이 전송한 ACK 정보인지 구별함으로써 블록-ACK 프레임에 각 STA에 대한 ACK 정보가 포함될 수 있다. 이를 기반으로 하여, 블록-ACK 프레임에서 각 사용자/STA 별로 중복되는 정보는 오버헤드를 감소시키기 위해 생략될 수 있다.
이와 관련하여, 블록-ACK 프레임의 정보가 제3의 STA(예를 들어, 공격(attack) STA)에게 노출이 된다면, 송신 STA과 수신 STA 간의 데이터 송수신 여부를 확인시켜주는 역할인 ACK 정보가 훼손될 수 있다. 그 결과, 블록-ACK 프레임에 대한 공격은 데이터 송수신 능력의 저하 및 이로 인한 전력(power)/매체(medium)의 낭비가 발생할 수 있다.
이러한 점을 고려하여, 본 개시에서는 송신 STA과 수신 STA 간에 송수신되는 블록-ACK 프레임의 무결성을 확보하기 위한 보안 기술을 제안한다.
본 개시에서 제안되는 값/명칭은 변경될 수 있으며, 본 개시의 범위는 이에 한정되지 않는다. 또한, 본 개시에서의 STA은 비-AP STA(non-AP STA) 및 AP STA을 포함할 수 있다.
본 개시의 설명에서, 송신 STA인 AP에 의해 송신되는 본 개시의 실시예 1-1 내지 실시예 1-3에서 제안되는 방식에 따른 블록-ACK 프레임을 수신하는 수신 STA들은 모두 UHR STA(및/또는 beyond UHR STA)임이 가정된다. 즉, 만일 본 개시의 제안 방법에 따라 구성된 블록-ACK 프레임을 UHR 이전 STA(pre-UHR STA)(예를 들어, EHT/HE STA 등)이 수신한 경우, 해당 블록-ACK 프레임에 대한 디코딩 시 오류가 발생할 수 있다. 이와 달리, 실시예 1-4에서 제안되는 방식에 따른 블록-ACK 프레임을 수신하는 수신 STA들은 Pre-UHR STA(예를 들어, 레거시 STA, EHT STA 등)와 UHR STA(들)(예를 들어, 비-레거시 STA(들))을 포함할 수 있다. 이와 관련하여, Pre-UHR STA은 블록-ACK 프레임에 대한 보호를 지원하지 않는 STA을 의미하고, UHR STA은 블록-ACK 프레임에 대한 보호를 지원 가능한 STA을 의미할 수 있다.
추가적으로, 본 개시에서는 제어 프레임 중 블록-ACK 프레임에 대한 보안 기술을 대표적인 예시로 하여 설명하지만, 본 개시의 제안 방법은 블록-ACK 프레임 이외의 다른 유형의 제어 프레임에 대해서도 확장하여 적용될 수 있다.
본 개시에서, 블록-ACK 프레임에 대해 무결성 검사를 수행한다는 것은 블록-ACK 프레임에 대해 BIP를 확장하여 적용하는 것으로 해석될 수 있다. 이와 관련하여, 기존에 정의된 BIP에 대하여 제어 프레임을 위한 사항이 추가적으로 정의되거나, 제어 프레임의 무결성 검사를 위한 BIP를 기반으로 하는 별도의 프로토콜이 새롭게 정의될 수도 있다.
이하에서는 블록-ACK 프레임에 대하여 무결성 검사를 지원/수행하기 위한 방법들을 구체적인 예시들을 통해 설명한다.
실시예 1
본 실시예는 무결성 검사를 지원하기 위한 블록-ACK 프레임 구성 방안에 대한 것이다. 구체적으로, 본 개시에서는 블록-ACK 프레임에 대해 BIP를 적용하기 위하여, 관리 프레임에 대하여 BIP를 적용할 때 프레임 바디의 마지막에 MME(management MIC element)를 포함시키는 방식 대신에, 보호 관련 정보를 블록-ACK 프레임 내에 하위 형태로 포함하는 구성을 제안한다.
도 10은 본 개시의 실시예에 따른 보호 정보 필드/서브필드 포맷을 예시한다.
도 10을 참조하면, 무결성 검사를 위해 필요한 정보들을 포함하는 보호 정보 (서브)필드 포맷(Protection Info (sub)field format)은 키 ID(Key ID) 정보, PN 관련 정보(예를 들어, IPN/BIPN 정보), MIC 정보를 포함할 수 있다.
해당 보호 정보 (서브)필드 포맷은 블록-ACK 프레임 내에 보호 정보 서브필드 하위 형태로 포함될 수 있다.
해당 포맷에 포함되는 각 정보의 길이는 도 10에 도시된 것에 한정되지 않는다. 예를 들어, 키 ID 필드는 IGTK 또는 BIGTK를 지시하는 키 ID의 경우 2-옥텟의 길이를 가지지만, GTK를 지시하는 키 ID의 경우 2-비트의 길이를 가질 수 있다. 또한, MIC 필드의 경우, 8-옥텟, 16-옥텟, 64-옥텟 등의 길이를 가질 수 있다. 추가적으로, MIC 값을 별도의 함수(function)에 추가적으로 적용하여 길이가 변경될 수도 있다.
이와 관련하여, 만일 MIC 생성을 위해 키가 사용될 필요가 없는 경우, 키 ID 정보는 해당 보호 정보 (서브)필드에 포함되지 않을 수도 있다.
추가적으로 또는 대안적으로, 본 개시에서는 도 10에 도시된 바와 같은 보호 정보 (서브)필드 포맷을 활용하여, 해당 정보가 블록-ACK 프레임에 추가적으로 구성되는 것을 예시하여 설명되지만, 이에 한정되지 않는다. 즉, 키 ID, PN 관련 정보, 및/또는 MIC는 보안이 적용되는 제어 프레임 내에 분리/분산되어 포함될 수도 있다. 일 예로, 본 실시예에 따른 블록-ACK 프레임 구조에서, 키 ID에 대한 정보는 PN 관련 정보 및 MIC로 구성되는 보호 정보 (서브)필드보다 앞선 위치(예를 들어, 블록-ACK 프레임 내 BA 제어 필드(BA Control field), BA 정보 필드(BA Information field) 또는 별도의 각 AID TID 정보 필드(Per AID TID Info field) 내)에 위치할 수 있다.
무결성 검사를 위한 블록-ACK 프레임은 이하 설명되는 포맷들 중 하나 이상에 기초하여 구성될 수 있다.
실시예 1-1
본 개시에 따른 보호 정보 (서브)필드는 블록-ACK 프레임에 포함되는 BA 제어 필드 내에 위치할 수 있다.
예를 들어, 블록-ACK 프레임 내 BA 제어 필드(BA Control field)에 BIP를 적용하여, 해당 필드의 마지막 부분에 보호 정보 (서브)필드가 포함될 수 있다.
도 11은 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 일 예를 나타낸다.
도 11을 참조하면, 도 10에서 설명된 보호 정보 (서브)필드는 공통 정보 필드 내 마지막 부분에 위치할 수 있다.
이 경우, 송신 STA은 BA 제어 필드에 BIP를 적용하며, 해당 필드의 마지막에 보호 정보 (서브)필드를 추가하여 블록-ACK 프레임을 송신할 수 있다. 이에 기초하여, 해당 블록-ACK 프레임을 수신한 수신 STA은 해당 정보에 기초하여, 블록-ACK 프레임 내 BA 제어 필드에 대한 무결성 검사를 수행할 수 있다.
이와 관련하여, 해당 보호 정보 (서브)필드에 포함되는 MIC 정보 즉, MIC 서브필드의 계산 범위는 보호 정보 (서브)필드가 포함되는 BA 제어 필드에 해당할 수 있다. 즉, 보호 정보 (서브)필드에 기반하여 무결성 검사가 수행/적용되는 대상은 해당 (서브)필드가 속한 BA 제어 필드에 해당할 수 있다.
실시예 1-2
본 개시에 따른 보호 정보 (서브)필드는 블록-ACK 프레임에 포함되는 BA 정보 필드 내에 위치할 수 있다.
예를 들어, 블록-ACK 프레임 내 각 BA 정보 필드에 대해 BIP를 적용하여, 해당 BA 정보 필드의 마지막 부분에 보호 정보 (서브)필드가 포함될 수 있다.
도 12는 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 다른 예를 나타낸다.
구체적으로, 도 12의 (a)는 압축된 블록-ACK 프레임 내 BA 정보 필드에 보호 정보 (서브)필드가 포함되는 경우를 예시하고, 도 12의 (b)는 다중 STA 블록-ACK 프레임 내 BA 정보 필드의 각 AID TID 정보(Per AID TID Info) 서브필드에 보호 정보 (서브)필드가 포함되는 경우를 예시한다. 여기서, Per AID TID Info 서브필드는 AID TID Info 필드, 블록-ACK 시작 시퀀스 제어 필드, 및 블록-ACK 비트맵 필드를 포함할 수 있다.
도 12를 참조하면, 도 10에서 설명된 보호 정보 (서브)필드는 각 BA 정보 필드 내 마지막 부분에 위치할 수 있다.
예를 들어, 송신 STA은 각 BA 정보 필드에 BIP를 적용하며, 해당 필드의 마지막에 보호 정보 (서브)필드를 추가하여 블록-ACK 프레임을 구성 및 송신할 수 있다. 이에 기초하여, 해당 블록-ACK 프레임을 수신한 수신 STA은 각 BA 정보 필드에 대한 무결성 검사를 수행할 수 있다.
이와 관련하여, 다중 STA 블록-ACK 프레임 내 Per AID TID Info 서브필드에 포함되는 보호 정보 (서브)필드를 구성하는 키 ID 및 MIC의 값은 해당 AID에 상응하는 STA의 PTK를 의미할 수 있고, 해당 키 ID를 기반으로 하여 MIC의 값이 도출될 수도 있다. 일 예로, 수신 STA은 Per AID TID Info 서브필드에 대하여 키 ID에 포함되는 키 정보를 사용하여 Per AID TID Info 서브필드의 MIC 값을 도출할 수 있으며, 이에 기초하여 무결성 검증을 수행할 수 있다.
실시예 1-3
본 개시에 따른 보호 정보 (서브)필드는 블록-ACK 프레임 내에서 BA 제어 필드 및 BA 정보 필드 이외의 부분에 위치할 수 있다.
도 13은 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 또 다른 예를 나타낸다.
도 13을 참조하면, 보호 정보 필드는 블록-ACK 프레임 내에서 FCS 이전에 위치할 수 있다.
이 경우, 송신 STA은 BA 제어 필드 및/또는 BA 정보 필드에 BIP를 적용하며, 마지막 부분에 보호 정보 (서브)필드를 추가하여 각 서브필드의 값(들)을 설정할 수 있다. 즉, 송신 STA들이 수신 STA에게 블록-ACK 프레임을 송신하는 경우, 도 13과 같은 블록-ACK 프레임이 구성될 수 있다.
이와 관련하여, MIC 정보는 3가지의 경우를 고려하여 설정될 수 있다. 일 예로, MIC 정보는 BA 제어 필드 및 BA 정보 필드 모두에 대한 MIC 값을 도출하여 설정될 수 있다. 다른 예로, MIC 정보는 BA 제어 필드에 대한 MIC 값을 도출하여 설정될 수 있다. 또 다른 예로, MIC 정보는 BA 정보 필드에 대한 MIC 값을 도출하여 설정될 수 있다.
만일 블록-ACK 프레임이 다중 STA 블록-ACK 프레임 유형인 경우, BA 정보 필드 내 모든 Per AID TID Info 서브필드들에 대한 MIC 값을 설정하며, 이때 블록-ACK 프레임의 보호를 위한 GTK 또는 기존의 GTK, IGTK, 또는 BIGTK가 활용될 수도 있다.
실시예 1-4
본 개시에 따른 보호 정보 (서브)필드는 다중 STA 블록-ACK 유형의 블록-ACK 프레임 내 BA 정보 필드를 구성하는 다수의 각 AID TID 정보 필드(Per AID TID Info field)들 중 하나로 구성될 수 있다.
즉, 송신 STA은 본 개시에 따른 보호 정보 (서브)필드를 다중 STA 블록-ACK 유형의 블록-ACK 프레임 내 BA 정보 필드를 구성하는 다수의 Per AID TID Info 필드들 중 하나로 구성/포함하여 블록-ACK 프레임을 구성할 수 있다.
도 14는 본 개시의 실시예에 따른 무결성 검사를 지원하는 블록-ACK 프레임 구성의 또 다른 예를 나타낸다.
도 14를 참조하면, 송신 STA은 보호 정보 (서브)필드를 포함하는 Per AID TID Info 필드를 AID TID Info 서브필드, 길이 관련 필드(length-related field), 보호 정보 (서브)필드, 및/또는 패딩(padding)/보류된(reserved) 서브필드를 포함하여 구성될 수 있다.
이와 관련하여, 보호 정보 (서브)필드를 포함하는 Per AID TID Info 필드에서, AID TID Info 서브필드 내 AID11 서브필드는 해당 Per AID TID Info 필드에 보호 정보 (서브)필드가 포함되었음을 지시하는 특정 AID의 값으로 세팅된다.
이때, 해당 AID TID Info 서브필드 내 Ack 유형 서브필드의 값 및/또는 TID 서브필드의 값은 다음 옵션들 중 적어도 하나에 기반하여 세팅될 수 있다.
옵션 1) Ack 유형 서브필드는 보류된(reserved) 값으로 세팅될 수 있다.
옵션 2) TID 서브필드는 보류된(reserved) 값으로 세팅될 수 있다.
옵션 3) Ack 유형 서브필드의 값 및 TID 서브필드의 값은, AID11 서브필드가 2045가 아닌 경우에 선택적 서브필드(optional subfield)(들)의 존재에 따른 Per AID TID Info 서브필드가 가지는 의미에 대한 정의(예를 들어, 표 2에 따른 정의)를 기반으로 하여 세팅될 수 있다.
옵션 4) Ack 유형 서브필드의 값 및 TID 서브필드의 값의 세팅은, AID11 서브필드가 2045가 아닌 경우에 선택적 서브필드(optional subfield)(들)의 존재에 따른 Per AID TID Info 서브필드가 가지는 의미에 대한 정의(예를 들어, 표 2에 따른 정의)를 따르지 않을 수 있다.
다시 말해, 표 2에 따른 정의는, AID11 서브필드가 2045이 아닌 경우 뿐만 아니라 보호 정보 (서브)필드가 포함되어 있음을 지시하는 특정 AID의 값이 아닌 경우에 대해서도 확장될 수 있다. 예를 들어, 보호 정보 (서브)필드가 포함되어 있음을 지시하는 특정 AID11의 값이 2044인 경우, 표 2에 따른 정의는 AID11 서브필드가 2045 및 2044가 아닌 경우에 선택적 서브필드(optional subfield)(들)의 존재에 따른 Per AID TID Info 서브필드가 가지는 의미에 대한 정의로 확장/대체될 수 있다.
이때, Ack 유형 서브필드 및 TID 서브필드는 다음 사항(context)들/의미들 중 적어도 하나의 사항/의미를 지시하도록 정의될 수 있다.
- 보호 정보 (서브)필드의 존재 여부
- 보호 정보 (서브)필드 내 키 ID 정보(예를 들어, 키 ID 서브필드)의 존재 여부
- 보호 정보 (서브)필드 내 키 ID 정보(예를 들어, 키 ID 서브필드)의 길이
- 보호 정보 (서브)필드 내 PN 관련 정보(예를 들어, IPN/BIPN 서브필드)의 존재 여부
- 보호 정보 (서브)필드 내 PN 관련 정보(예를 들어, IPN/BIPN 서브필드)의 길이
- 보호 정보 (서브)필드 내 MIC 정보(예를 들어, MIC 서브필드)의 존재 여부
- 보호 정보 (서브)필드 내 MIC 정보(예를 들어, MIC 서브필드)의 길이
전술한 AID TID Info 서브필드 이후에 위치하는 길이 관련(length-related) 서브필드는, 기존 Per AID TID Info 필드 내 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드의 형태로 구성되거나, 새롭게 정의되는 서브필드일 수도 있다.
먼저, 길이 관련 서브필드가 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드의 형태로 구성되는 경우에 대해 설명한다.
기존 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드는 해당 Per AID TID Info 필드에 포함되는 블록-ACK 비트맵 서브필드의 길이를 지시하도록 정의된다. 예를 들어, 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드가 존재하는 경우, 조각 레벨 3(Fragmentation level 3)의 여부에 따라 해당 서브필드 내 조각 개수(Fragment Number) 서브필드의 비트 조합을 이용하여, 블록-ACK 비트맵 서브필드의 길이 및 MSDU/A-MSDU의 최대 개수의 길이가 지시될 수 있다(예를 들어, 표 3 참고).
이와 달리, Per AID TID Info 필드에서 보호 정보 (서브)필드를 포함하는 것을 지시하는 AID 값이 세팅되는 경우, 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드의 값은 블록-ACK 비트맵 서브필드가 아닌, 보호 정보 (서브)필드 및 기존 블록-ACK 비트맵 서브필드의 길이를 맞추기 위한 패딩(padding) 또는 보류된(reserved) 서브필드를 포함한 총 길이를 지시하도록 정의될 수 있다.
일 예로, 보호 정보 (서브)필드가 16-옥텟의 길이를 가진 경우, 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드 내 조각 개수(fragment number) 서브필드의 비트 조합은 16-옥텟을 지시하도록 세팅될 수 있다. 다른 예로, 보호 정보 (서브)필드가 24-옥텟의 길이를 가진 경우, 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드 내 조각 개수(fragment number) 서브필드의 비트 조합은 32-옥텟을 지시하도록 세팅되고, 보호 정보 (서브)필드 이후에 8-옥텟의 길이를 갖는 패딩 또는 보류된 서브필드가 해당 Per AID TID Info 필드에 포함될 수 있다.
해당 방식은 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드 내 조각 개수(fragment number) 서브필드의 비트 조합이 8-옥텟, 16-옥텟, 32-옥텟, 또는 4-옥텟의 길이를 지시하도록 설정/정의되는 경우에 적용 가능한 방식에 해당한다.
만일, 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드 내 조각 개수(fragment number) 서브필드의 비트 조합이 24-옥텟의 길이를 지시할 수 있다면, 보호 정보 (서브)필드 이후에 패딩(padding) 또는 보류된(reserved) 서브필드는 해당 Per AID TID Info 필드에 포함되지 않을 수 있다.
또한, 기존 블록-ACK 비트맵 서브필드의 길이는 64-옥텟 또는 128-옥텟으로 지시될 수도 있다. 이에 기초하여, 블록-ACK 시작 시퀀스 제어(Block Ack Starting Sequence Control) 서브필드 내 조각 개수(fragment number) 서브필드의 조합을 통해 64-옥텟 또는 128-옥텟의 길이가 지시되는 경우, 보호 정보 (서브)필드 이후에 위치하는 패딩(padding) 또는 보류된(reserved) 서브필드를 통해 기존 블록-ACK 비트맵 서브필드의 길이를 맞출 수 있다.
다음으로, Per AID TID 서브필드 내에 보호 정보 (서브)필드가 포함되는 경우, 길이 관련 서브필드가 해당 보호 정보 (서브)필드의 길이를 지시하기 위한 신규 서브필드로 정의되는 경우에 대해 설명한다. 본 개시에서는 설명의 명료성을 위하여 해당 신규 서브필드를 보호 정보 길이 서브필드로 지칭하지만, 해당 명칭은 일 예시일 뿐 다른 명칭으로 대체하여 적용될 수 있다.
일 예로, 보호 정보 길이 서브필드가 1-비트인 경우, 해당 서브필드가 0으로 세팅됨은 보호 정보 (서브)필드의 길이가 16-옥텟임을 지시하고, 해당 서브필드가 1로 세팅됨은 보호 정보 (서브)필드의 길이가 24-옥텟임을 지시할 수도 있다. 다른 예로, 보호 정보 길이 서브필드는 3-비트 이상의 길이를 가지도록 정의될 수 있으며, 이 경우, 해당 서브필드는 다양한 길이의 값(예를 들어, 2-옥텟, 4-옥텟 6-옥텟, 8-옥텟, 16-옥텟, 24-옥텟, 32-옥텟 등)을 지시하도록 정의될 수 있다.
또한, 도 14에 도시된 바와 같이, 보호 정보 (서브)필드 내 키 ID 정보/서브필드는 2-옥텟으로 구성되고, PN 관련 정보/서브필드는 6-옥텟으로 구성되고, MIC 정보/서브필드는 8-옥텟 또는 16-옥텟으로 구성될 수 있으나, 이는 일 예시에 해당하며 본 개시의 범위가 이에 한정되는 것은 아니다.
이와 관련하여, MIC 정보/서브필드의 길이가 8-옥텟인 경우, 키 ID 정보/서브필드는 2-옥텟이고 PN 관련 정보/서브필드는 6-옥텟이므로, 보호 정보 (서브)필드는 16-옥텟의 길이를 가진다. 이와 달리, MIC 정보/서브필드의 길이가 16-옥텟인 경우, 키 ID 정보/서브필드는 2-옥텟이고 PN 관련 정보/서브필드는 6-옥텟이므로, 보호 정보 (서브)필드는 24-옥텟의 길이를 가진다.
해당 방식 즉, 실시예 1-4에서 설명되는 방식은, 본 개시에서 제안한 실시예 1-1, 실시예 1-2, 및 실시예 1-3와 달리, 블록-ACK 프레임 내 BA 정보 필드에 UHR STA(및/또는 beyond-UHR STA) 뿐만 아니라 Pre-UHR STA를 위한 Per AID TID Info 서브필드(들)도 함께 구성되는 경우에도 사용 가능한 방식에 해당한다. 예를 들어, UHR STA(및/또는 beyond-UHR STA)(들)은 AID11 서브필드의 값을 통해 보호 정보 (서브)필드가 포함된 Per AID TID Info 서브필드임을 인지할 수 있다. 반면, Pre-UHR STA(들)은 AID11 서브필드의 값이 자신의 AID11의 값과 다르기 때문에, 보호 정보 (서브)필드가 포함된 Per AID TID Info 서브필드를 무시할 수 있다.
추가적으로, 도 14에서는 보호 정보 (서브)필드가 포함된 Per AID TID Info 서브필드가 BA 정보 필드 내 마지막 Per AID TID Info 서브필드로 구성되는 것으로 도시하고 있으나, 이는 일 예시에 해당하며 본 개시의 범위가 이에 한정되는 것은 아니다.
추가적으로, 실시예 1-4에서 설명된 방식으로 구성된 블록-ACK 프레임 내 MIC 값/정보는 3가지 방식을 기반으로 하여 BA 제어 필드 및/또는 BA 정보 필드(들)에 BIP를 적용하여 도출/계산될 수 있다. 이 경우, 후술하는 3가지 방식 중 하나 이상의 방식을 기반으로 하여 무결성 검증이 수행될 수 있다.
예를 들어, 도 14에 도시된 MIC 서브필드의 계산 범위 1과 같이, MIC 값 산출을 위한 제1 방식은 블록-ACK 프레임 내 BA 정보 필드 내 모든 Per AID TID Info 필드들에 대해 MIC를 도출하는 방식에 해당한다. 이때, BA 정보 필드 내 Per AID TID Info 필드들은 송신 STA가 수신 STA들에게 전달하는 정보를 포함하는 Per AID TID Info 필드(즉, 수신 STA의 AID 값을 포함하는 Per AID TID Info 필드)들을 의미할 수 있으며, 보호 정보 (서브)필드를 포함하는 Per AID TID Info 필드는 MIC 도출 시 제외된다. 다른 예를 들어, 도 14에 도시된 MIC 서브필드의 계산 범위 2와 같이, MIC 값 산출을 위한 제2 방식은 블록-ACK 프레임 내 BA 제어 필드에 대해 MIC를 도출하는 방식에 해당한다. 또 다른 예를 들어, 도 14에 도시된 MIC 서브필드의 계산 범위 3과 같이, MIC 값 산출을 위한 제3 방식은 블록-ACK 프레임 내 BA 제어 필드 및 BA 정보 필드 내 수신 STA(들)의 AID를 포함하는 Per AID TID Info 필드(들)에 대해 도출하는 방식에 해당한다. 즉, 제3 방식은 제1 방식 및 제2 방식을 모두 포함하는 방식일 수 있다.
추가적으로, 본 개시에 따른 무결성 검사를 지원하는 블록-ACK 프레임과 관련하여, 송신 STA(들)과 수신 STA(들)은 블록-ACK 프레임에 대한 BIP의 지원 여부에 대한 정보를 서로 공유할 수 있다. 해당 정보는 디스커버리 과정(예를 들어, 비콘 프레임, 프로브 응답 프레임 등) 및/또는 (재)결합 과정(예를 들어, (재)결합 요청 프레임, (재)결합 응답 프레임 등)에서 특정 요소(예를 들어, RSNXE(Extended RSN element))를 통해 공유될 수 있다.
이와 관련하여, 기존 요소(element)(예를 들어, RSNXE) 내 보류된 비트를 활용하거나, 신규 요소 내 신규 (서브)필드를 정의하여, 블록-ACK 프레임에 대한 BIP 적용의 지원 여부가 공유될 수 있다. 예를 들어, 1-비트의 보호된 블록-ACK 지원 (서브)필드(protected BlockAck support (sub)field)가 새롭게 정의될 수 있으며, 1 값은 블록-ACK 프레임에 대한 BIP 적용을 지원함을 의미/지시하고, 0 값은 블록-ACK 프레임에 대한 BIP 적용을 지원하지 않음을 의미/지시하도록 정의될 수 있다.
만일 송신 STA 및 수신 STA이 모두 BIP를 지원하고 블록-ACK 프레임에 대한 BIP 적용을 지원하는 경우, 2개의 STA들은 블록-ACK 프레임에 대한 BIP 적용을 수행할 수 있다. 이와 달리, 송신 STA 또는 수신 STA이 BIP를 지원하지만 블록-ACK 프레임에 대한 BIP 적용을 지원하지 않는 경우, 2개의 STA들은 블록-ACK 프레임에 대한 BIP 적용을 수행하지 않을 수 있다. 추가적으로, 블록-ACK 프레임을 BIP에 적용하는 경우, 송신 STA과 수신 STA이 협상(negotiation) 과정에서 협의한 관리 프레임의 암호 스위트(cipher suite)(예를 들어, BIP-GMAC-128, BIP-GMAC-256, 또는 BIP-CMAC-256 등)가 동일하게 사용될 수 있다. 또는, 블록-ACK 프레임을 BIP에 적용하기 위하여, 송신 STA과 수신 STA은 해당 블록-ACK 프레임을 위한 추가적인/별도의 암호 스위트를 협상할 수도 있다.
예를 들어, 본 개시의 실시예 1-1, 실시예 1-2, 및/또는 실시예 1-3에서 제안하는 포맷으로 블록-ACK 프레임을 구성하는 경우, 이는, 해당 블록-ACK 프레임의 송신 STA 및 수신 STA 모두 블록-ACK 프레임에 대한 BIP 적용을 지원하는 경우에만 허용될/사용 가능할 수 있다. 즉, 해당 송신 STA과 수신 STA 모두에 대하여, 보호된 블록-ACK 지원 (서브)필드(protected BlockAck support (sub)field)의 값은 블록-ACK 프레임에 대한 BIP 적용을 지원하는/지시하는 값으로 세팅된다.
다른 예를 들어, 본 개시의 실시예 1-4에서 제안하는 포맷으로 블록-ACK 프레임을 구성하는 경우, 이는, 해당 블록-ACK 프레임의 송신 STA는 블록-ACK 프레임에 대한 BIP 적용을 지원하지만 수신 STA들 중 일부 STA들만 블록-ACK 프레임에 대한 BIP 적용을 지원하는 경우에도 허용될/사용 가능할 수 있다. 즉, 해당 송신 STA에 대해서, 보호된 블록-ACK 지원 (서브)필드(protected BlockAck support (sub)field)의 값은 블록-ACK 프레임에 대한 BIP 적용을 지원하는/지시하는 값으로 세팅된다. 이와 달리, 일부 수신 STA(들)에 대해서 보호된 블록-ACK 지원 (서브)필드(protected BlockAck support (sub)field)의 값은 블록-ACK 프레임에 대한 BIP 적용을 지원하는/지시하는 값으로 세팅되지만, 다른 일부 수신 STA(들)에 대해서는 보호된 블록-ACK 지원 (서브)필드(protected BlockAck support (sub)field)의 값은 블록-ACK 프레임에 대한 BIP 적용을 지원하지 않음을 지시하는 값으로 세팅될 수 있다.
추가적으로 또는 대안적으로, 송신 STA와 수신 STA 간에, 블록-ACK 프레임에 대한 BIP 적용의 지원 여부 및 본 개시에서 제안하는 포맷들(예를 들어, 도 11 내지 도 14에 도시된 포맷) 중 어떤 포맷으로 보호 정보 (서브)필드가 구성되는지에 대한 정보가 공유될 수 있다. 이와 관련하여, 해당 정보의 공유를 위하여, 기존 요소(예를 들어, RSNXE) 내 보류된 비트, 및/또는 BA 제어 필드 내 보류된 비트(들), 및/또는 신규 요소 내 신규 (서브)필드(예를 들어, 보호된 블록-ACK 모드 (서브)필드)(protected BlockAck mode (sub)field)가 정의될 수도 있다. 해당 (서브)필드는 (재)결합 과정 뿐만 아니라, 데이터 송수신 과정에서 송신 STA에 의해 비콘 프레임에 포함되거나, 수신 STA에 의해 데이터 프레임에 포함될 수 있다.
예를 들어, 보호된 블록-ACK 모드 (서브)필드의 값이 0으로 세팅됨은, 적어도 하나의 방식으로 블록-ACK 프레임을 구성하지 않으며, 해당 블록-ACK 프레임에 대한 BIP가 적용되지 않는 것을 의미/지시할 수 있다. 이와 달리, 보호된 블록-ACK 모드 (서브)필드의 값이 1 이상으로 세팅됨은, 블록-ACK 프레임에 대한 BIP가 적용되는 것을 의미/지시할 수 있다.
구체적인 예로, 해당 보호된 블록-ACK 모드 (서브)필드가 1 이상의 값을 가질 수 있는 경우, 해당 보호된 블록-ACK 모드 (서브)필드의 값의 의미는 하기 표 4와 같이 정의될 수 있다. 표 4는 예시적인 것으로, 표 4에서 설명되는 값들 중 적어도 하나의 값이 적용/정의될 수 있으며, 구체적인 값은 해당 예시와 다르게 세팅/정의될 수도 있다.
보호된 블록-ACK 모드 (서브)필드의 값 의미
1 실시예 1-1에 기초한 블록-ACK 프레임 구성
2 실시예 1-2에 기초한 블록-ACK 프레임 구성
3 실시예 1-1 및 실시예 1-2에 기초한 블록-ACK 프레임 구성
4 실시예 1-3에 기초한 블록-ACK 프레임 구성
5 실시예 1-4에 기초한 블록-ACK 프레임 구성
6 실시예 1-4에 기초한 블록-ACK 프레임 구성, BA 제어 필드 및 BA 정보 필드에 대한 MIC 값을 기반으로 무결성 검증 수행
7 실시예 1-4에 기초한 블록-ACK 프레임 구성, BA 제어 필드에 대한 MIC 값을 기반으로 무결성 검증 수행
8 실시예 1-4에 기초한 블록-ACK 프레임 구성, BA 정보 필드에 대한 MIC 값을 기반으로 무결성 검증 수행
표 4를 참조하면, 보호된 블록-ACK 모드 (서브)필드를 통해 본 개시에 따른 보호 정보 (서브)필드가 포함되는 블록-ACK 프레임의 구성/포맷과 함께 MIC 값을 산출하는 방식이 지시될 수 있다.
다만, 본 개시의 범위는 이에 제한되지 않으며, 보호된 블록-ACK 모드 (서브)필드를 통해 본 개시에 따른 보호 정보 (서브)필드가 포함되는 블록-ACK 프레임의 구성/포맷만이 지시되고, 다른 (서브)필드를 통해 MIC 값을 산출하는 방식이 별도로 지시될 수 있다. 예를 들어, MIC 산출 범위 (서브)필드(MIC calculation range (sub)field)가 정의될 수 있으며, 해당 (서브)필드의 값은 표 5와 같이 정의될 수 있다.
MIC 산출 범위 (서브)필드의 값 의미
a BA 제어 필드 및 BA 정보 필드에 대한 MIC 값 산출
b BA 제어 필드에 대한 MIC 값 산출
c BA 정보 필드에 대한 MIC 값 산출
... 보류됨
즉, 수신 STA은 보호된 블록-ACK 모드 (서브)필드를 통해 수신한 블록-ACK 프레임 내에서 보호 정보 (서브)필드가 포함된 위치를 인지/확인할 수 있다. 또한, 이에 기초하여, 해당 수신 STA은 MIC 산출 범위 (서브)필드에 의해 지시되는 값을 이용하여 MIC 값을 산출할 수 있으며, 이를 통해 블록-ACK 프레임에 대한 무결성 검사를 수행할 수 있다.
실시예 2
본 실시예는 전술한 블록-ACK 프레임에 대한 BIP 적용과 관련하여, BIP 송신/수신을 위한 MIC 생성 방안에 대한 것이다.
블록-ACK 프레임의 경우, BA 제어 필드 내 BA 유형(BA type) 서브필드의 값에 따라, 송수신되는 블록-ACK 프레임의 유형이 지시될 수 있다. 지시되는 값에 따라, 수신 STA은 해당 블록-ACK 프레임이 개별 어드레스된 프레임(individually addressed frame)인지, 그룹 어드레스된 프레임(group addressed frame)인지 확인할 수 있다.
이와 관련하여, 블록-ACK 프레임에 대하여 BIP를 적용할 때, MIC 값의 설정에 사용되는 키(key)는 개별 어드레스된 프레임의 경우와 그룹 어드레스된 프레임의 경우에 따라 다르게 사용될 수 있다.
예를 들어, 개별 어드레스된 데이터 프레임의 경우, 송신 STA과 수신 STA 간에 동일하게 생성된 PTK를 기반으로 하는 TK를 사용하여 MIC 값 산출이 수행될 수 있다. 반면, 그룹 어드레스된 데이터 프레임의 경우, 송신 STA이 수신 STA에게 공유한 GTK를 기반으로 하는 TK를 사용하여 MIC 값 산출이 수행될 수 있다.
기존 BIP(예를 들어, 데이터 프레임/관리 프레임에 적용되는 BIP)의 경우 IGTK 또는 BIGTK를 기반으로 하는 BIP 활용이 가능하다. 이와 달리, 본 개시에서는, PTK/GTK를 기반으로 하는 BIP 활용이 가능함을 가정한다.
이하에서는, 개별 어드레스된 블록-ACK 프레임 및/또는 그룹 어드레스된 블록-ACK 프레임에 대한 MIC 값을 산출 및 검사하기 위한 키 사용 방식에 대해 구체적으로 설명한다.
먼저, 개별 어드레스된 블록-ACK 프레임의 경우, MIC 값은 다음과 같이 산출/검증될 수 있다.
송신 STA과 수신 STA은, 4-웨이 핸드쉐이크(4-way handshake) 과정에서 동일하게 생성된 PTK를 기반으로 하는 TK를 사용하여 MIC 값을 산출할 수 있다. 예를 들어, 블록-ACK 프레임에 대한 BIP 적용과 관련하여, 송신 STA 및 수신 STA은 4-웨이 핸드쉐이크 과정에서 데이터 프레임에 대한 보호와 관련하여 생성된 PTK를 동일하게 활용하거나, 4-웨이 핸드쉐이크 과정에서 해당 블록-ACK 프레임에 대한 보호와 관련하여 상호 간에 동일하게 생성/협의/공유된 (신규) TK(예를 들어, 신규 PTK/GTK)를 활용할 수 있다.
대안적으로, 송신 STA 및 수신 STA은 4-웨이 핸드쉐이크 과정에서 공유되는 개별 어드레스된 블록-ACK 프레임을 위한 신규 TK를 기반으로 하는 TK를 사용하여 MIC 값을 산출할 수 있다. 예를 들어, 해당 신규 TK는 블록-ACK PTK(블록-ACK PTK, BAPTK)로 지칭될 수 있으며, 송신 STA은 각 수신 STA 별로 다른 BAPTK를 생성하여 공유할 수 있다. 즉, 수신 STA 1과 수신 STA 2에 대해 서로 다른 BAPTK가 공유될 수 있다. 또한, 예를 들어, 블록-ACK 프레임에 대해 신규 TK(일 예로, BAPTK, BAGTK)를 사용하여 MIC를 도출하는 경우, 송신 STA은 각 수신 STA에게 신규 TK를 생성하여 공유할 수 있다. 즉, 수신 STA 1과 수신 STA 1은 동일한 신규 TK를 공유할 수도 있다. 이때, 송신 STA에 의해 생성 및 공유되는 신규 TK를 위한 신규 KDE(key data element)(예를 들어, BAPTK/BAGTK KDE)를 통해, 해당 신규 TK에 대한 정보 및 해당 신규 TK를 사용할 수 있는 암호 스위트(cipher suite)에 관련된 정보 등이 공유될 수 있다.
블록-ACK 프레임의 보호를 위한 키(예를 들어, 신규 TK)가 존재하는 경우, 수신 STA는 해당 키를 이용하여 수신한 블록-ACK 프레임에 대한 MIC 검증을 수행할 수 있다. 이와 관련하여, 해당 키는 송신 STA 및/또는 수신 STA에 의해 생성 및/또는 공유될 수 있다. 그렇지 않은 경우, 수신 STA는 송신 STA와 사전에 생성된 유니캐스트 데이터 프레임의 무결성 검증/암호화/복호화를 위한 키(예를 들어, PTK)에 기반하여 블록-ACK 프레임에 대한 MIC 검증을 수행할 수 있다.
다음으로, 그룹 어드레스된 블록-ACK 프레임의 경우, MIC 값은 다음과 같이 산출/검사될 수 있다.
송신 STA은 4-웨이 핸드쉐이크 과정에서 IGTK 또는 BIGTK를 생성하여 수신 STA에게 공유할 수 있으며, 송신 STA 및 수신 STA은 해당 IGTK 또는 해당 BIGTK을 기반으로 하는 TK를 사용하여 MIC 값을 산출할 수 있다.
대안적으로, 송신 STA은 4-웨이 핸드쉐이크 과정에서 GTK를 생성하여 수신 STA에게 공유할 수 있으며, 송신 STA 및 수신 STA은 해당 GTK를 기반으로 하는 TK를 사용하여 MIC 값을 산출할 수 있다.
대안적으로, 송신 STA은 4-웨이 핸드쉐이크 과정에서 그룹 어드레스된 블록-ACK 프레임을 위한 신규 GTK를 생성하여 수신 STA에게 공유할 수 있으며, 송신 STA 및 수신 STA은 해당 신규 GTK를 기반으로 하는 TK를 사용하여 MIC 값을 산출할 수 있다. 여기서, 신규 GTK는 블록-ACK 브로드캐스트 GTK(BAGTK)로 지칭할 수 있으며, 송신 STA은 수신 STA들에게 동일한 값의 BAGTK를 공유할 수 있다. 즉, AP는 자신과 결합된 STA들에게 동일한 BAGTK를 생성하여 공유할 수 있다. 또한, 송신 STA와 수신 STA 간에, 해당 BAGTK를 위한 신규 KDE(예를 들어, TBGTK KDE)를 통해, BAGTK에 대한 정보 및 해당 BAGTK를 사용할 수 있는 암호 스위트(cipher suite)에 관련된 정보 등이 공유될 수 있다.
수신 STA은 송신 STA으로부터 블록-ACK 프레임의 보호를 위한 키(예를 들어, BAGTK)를 전달 받았다면, 해당 키에 기반하여 블록-ACK 프레임에 대한 MIC 검증을 수행할 수 있다. 그렇지 않은 경우, 수신 STA은 송신 STA과 사전에 공유된 브로드캐스트 프레임(들)을 위한 키(예를 들어, GTK, IGTK 또는 BIGTK)에 기반하여 블록-ACK 프레임에 대한 MIC 검증을 수행할 수 있다.
실시예 3
본 실시예는 본 개시에서 제안하는 블록-ACK 프레임 구성에 기초하여 블록-ACK 프레임에 대한 보호를 수행하는 구체적인 방안에 대한 것이다.
먼저, 블록-ACK 프레임이 그룹 어드레스된 블록-ACK 프레임인 경우, 본 개시에서 제안하는 블록-ACK 프레임 구성은 다음 예시들과 같이 사용될 수 있다.
예를 들어, 실시예 1-1에서 설명된 블록-ACK 프레임 구성(예를 들어, 도 11 참고)의 경우, 송신 STA 및/또는 수신 STA은 BA 제어 필드에 대하여 전술한 GTK, IGTK, BIGTK, 또는 신규 TK(예를 들어, BAGTK)를 사용하여 BIP를 통해 MIC 값을 도출할 수 있다. 추가적으로, 실시예 1-2에서 설명된 블록-ACK 프레임 구성(예를 들어, 도 12의 (a) 및 (b) 참고)의 경우, 송신 STA 및/또는 수신 STA은 BA 정보 필드에 대하여 전술한 PTK 또는 신규 TK(예를 들어, BAPTK)를 사용하여 BIP를 통해 MIC 값을 도출할 수 있다. 이때, 도 12의 (b)의 경우, BA 정보 필드 내 Per AID TID Info 서브필드에 대한 MIC 값을 도출하기 위하여, 송신 STA 및/또는 수신 STA은 해당 Per AID TID Info 서브필드의 AID에 상응하는 STA의 PTK 또는 신규 TK(예를 들어, BAPTK)를 사용할 수 있다. 대안적으로, 도 12의 (a)와 같이, AID를 포함하는 서브필드(예를 들어, AID11 서브필드)가 포함되지 않는 압축된 블록-ACK 프레임의 경우, 송신 STA의 MAC 어드레스(예를 들어, RA)에 상응하는 STA의 PTK 또는 신규 TK(예를 들어, BAPTK)를 사용할 수 있다.
다른 예를 들어, 실시예 1-3 및/또는 실시예 1-4에서 설명된 블록-ACK 프레임 구성(예를 들어, 도 13, 도 14 참고)의 경우, 송신 STA 및/또는 수신 STA은 BA 제어 필드 및/또는 BA 정보 필드에 대하여 전술한 GTK, IGTK, BIGTK, 또는 신규 TK(예를 들어, BAGTK)를 사용하여 BIP를 통해 MIC 값을 도출할 수 있다.
다음으로, 블록-ACK 프레임이 개별 어드레스된 블록-ACK 프레임인 경우, 본 개시에서 제안하는 블록-ACK 프레임 구성은 다음 예시들과 같이 사용될 수 있다.
예를 들어, 실시예 1-1에서 설명된 블록-ACK 프레임 구성(예를 들어, 도 11 참고)의 경우, 송신 STA 및/또는 수신 STA은 BA 제어 필드에 대하여 전술한 PTK 또는 신규 TK(예를 들어, BAPTK)를 사용하여 BIP를 통해 MIC 값을 도출할 수 있다.
다른 예를 들어, 실시예 1-2에서 설명된 블록-ACK 프레임 구성(예를 들어, 도 12의 (a) 및 (b) 참고)의 경우, 송신 STA 및/또는 수신 STA은 BA 정보 필드에 대하여 전술한 PTK 또는 신규 TK(예를 들어, BAPTK)를 사용하여 BIP를 통해 MIC 값을 도출할 수 있다. 이때, 도 12의 (b)의 경우, BA 정보 필드 내 Per AID TID Info 서브필드에 대한 MIC 값을 도출하기 위하여, 송신 STA 및/또는 수신 STA은 해당 Per AID TID Info 서브필드의 AID에 상응하는 STA의 PTK 또는 신규 TK(예를 들어, BAPTK)를 사용할 수 있다. 대안적으로, 도 12의 (a)와 같이, AID를 포함하는 서브필드(예를 들어, AID11 서브필드)가 포함되지 않는 압축된 블록-ACK 프레임의 경우, 송신 STA의 MAC 어드레스(예를 들어, 수신자 어드레스(RA))에 상응하는 STA의 PTK 또는 신규 TK(예를 들어, BAPTK)가 사용될 수 있다.
또 다른 예를 들어, 실시예 1-3 및/또는 실시예 1-4에서 설명된 블록-ACK 프레임 구성(예를 들어, 도 13, 도 14 참고)의 경우, 송신 STA 및/또는 수신 STA은 BA 제어 필드 및/또는 BA 정보 필드에 대하여 전술한 PTK 또는 신규 TK(예를 들어, BAPTK)를 사용하여 BIP를 통해 MIC 값을 도출할 수 있다. 이때, BA 제어 필드 및/또는 BA 정보 필드에 대한 MIC 값을 도출하기 위하여, 해당 블록-ACK 프레임의 수신자 어드레스(RA)에 상응하는 STA의 PTK 또는 신규 TK(예를 들어, BAPTK)가 사용될 수 있다.
본 개시에서 제안하는 방식들에 기반하여 블록-ACK 프레임에 대한 보호는 다음과 같이 수행될 수 있다.
후술하는 예시 상황들에 대하여, 송신 STA과 수신 STA(들)이 보호된 블록-ACK 지원 (서브)필드를 통해 BIP 상에서 블록-ACK 프레임의 활용을 지원하는 상황 및/또는 보호된 블록-ACK 모드 (서브)필드를 통해 블록-ACK 프레임 내 보호 정보 (서브)필드의 구성 방식을 공유하는 상황이 가정된다.
수신 STA은 송신 STA으로부터 수신한 MPDU의 MAC 헤더의 정보(예를 들어, 프레임 제어 필드, 구간 필드, RA 필드, TA 필드 등)에 기초하여 블록-ACK 프레임을 위한 AAD(additional authentication data)를 구성할 수 있다. 이후, 수신 STA은 해당 AAD를 사용하여, MPDU를 기반으로 MIC 값을 산출할 수 있다. 이때, 수신 STA은 송신 STA이 해당 MPDU를 기반으로 MIC 값을 산출하는 과정을 동일하게 수행하여 MIC 값을 도출할 수 있다.
이후, 수신 STA은 도출된 MIC 값과 송신 STA에 의해 송신된 MIC 값(예를 들어, 보호 정보 (서브)필드에 포함되는 MIC 정보)을 비교할 수 있다. 만일 두 개의 MIC 값이 동일하다면, 수신 STA은 획득한 MPDU의 정보를 따를 수 있다. 이와 달리, 두 개의 MIC 값이 동일하지 않다면, 수신 STA이 획득한 MPDU 내 적어도 하나의 정보가 제3의 다른 STA(예를 들어, 공격 STA)에 의해 변경되거나, 송수신 중에 손상되었음을 인지할 수 있으며, 이를 폐기(discard)할 수 있다.
본 개시의 실시예에 따른 블록-ACK 프레임에 대한 보호를 지원/수행하는 STA의 동작은 도 15 및 도 16과 같을 수 있다.
도 15는 본 개시에 따른 블록-ACK 프레임에 대한 무결성 검사를 지원하는 송신 STA의 동작을 예시한다.
도 15를 참조하면, 송신 STA은 블록-ACK 프레임에 대한 보호(예를 들어, 무결성 검사)를 지원하는지에 대한 정보를 포함하여 수신 STA와 공유할 수 있다(S1510).
이때, 송신 STA과 수신 STA(들)이 모두 블록-ACK 프레임에 대한 보안을 적용하는 경우에, 송신 STA은 블록-ACK 프레임의 무결성 검사를 위해 사용되는 키(들)(예를 들어, PTK/GTK/BAPTK/BAGTK(들))을 생성 및 공유할 수 있다(S1520). 이와 관련하여, 송신 STA과 수신 STA은 키 생성 과정을 통해 상호 간 동일한 키 정보를 생성/협의/공유하거나, 송신 STA에 의해 생성된 키 정보가 수신 STA에게 전달될 수도 있다.
해당 키(들)에 기반하여, 송신 STA은 구성한 블록-ACK 프레임에 BIP를 적용할 수 있다(S1530). 이와 관련하여, 송신 STA은 수신 STA와 사전에 공유된 키(들)을 사용하여 블록-ACK 프레임에 대한 MIC 값을 도출할 수 있다.
송신 STA은 BIP 적용에 대한 결과 값/정보를 포함하는 블록-ACK 프레임을 송신할 수 있다(S1540). 예를 들어, 송신 STA은 도출한 MIC 값과 해당 MIC 값을 도출하기 위해 사용된 키(들)의 ID 값을 포함하는 블록-ACK 프레임을 수신 STA(들)에게 송신할 수 있다.
전술한 과정과 관련하여, 송신 STA은 송신되는 블록-ACK 프레임 내에서 무결성 검사와 관련된 정보를 어떠한 포맷으로 구성하는지에 대한 정보를 수신 STA과 사전에 공유/협의하거나, 블록-ACK 프레임에 해당 정보를 포함하여 송신할 수도 있다.
도 16은 본 개시에 따른 블록-ACK 프레임에 대한 무결성 검사를 지원하는 수신 STA의 동작을 예시한다.
도 16을 참조하면, 수신 STA은 블록-ACK 프레임에 대한 보호(예를 들어, 무결성 검사)를 지원하는지에 대한 정보를 포함하여 송신 STA에게 공유할 수 있다(S1610).
이때, 송신 STA과 블록-ACK 프레임의 무결성 검사를 위해 사용되는 키(들)을 공유하는 경우, 수신 STA은 송신 STA에 의해 송신된 블록-ACK 프레임에 보호 방식이 적용되었음을 가정할 수 있다(S1620).
이와 관련하여, 송신 STA과 수신 STA은 키 생성 과정을 통해 상호 간 동일한 키 정보(예를 들어, PTK/GTK/BAPTK/BAGTK 등)를 생성/협의/공유하거나, 송신 STA에 의해 생성된 키 정보가 수신 STA에게 전달될 수도 있다.
예를 들어, 수신 STA은 송신 STA으로부터 송신된 블록-ACK 프레임을 수신하여 사전에 공유된 키(들) 및/또는 블록-ACK 프레임 내 무결성 검사를 위한 정보의 구성 방식에 관련된 정보를 기반으로 BIP에 적용되었음을 인지할 수 있다.
이에 기초하여, 블록-ACK 프레임을 수신하였을 때, 수신 STA은 사전에 공유/생성/협의된 키(들)(예를 들어, PTK/GTK/BAPTK/BAGTK 등) 및 블록-ACK 프레임을 사용하여 MIC 값을 도출할 수 있다(S1630).
이후, 수신 STA은 도출한 MIC 값과 송신 STA에 의해 송신된 MIC 값(즉, 블록-ACK 프레임 내에 포함되는 MIC 정보에 따른 MIC 값) 간의 비교를 통해, 무결설 검증을 수행할 수 있다(S1640).
이하에서, 도 17 및 도 18은 전술한 본 개시의 제안 방법에 따른 STA에 의해 수행되는 동작을 예시한다. 도 17 및 도 18에서, 제2 STA은 송신 STA(예를 들어, AP)에 해당하고, 제1 STA은 수신 STA(예를 들어, AP에 결합된 비(non)-AP STA)에 해당할 수 있다.
도 17은 본 개시에 따른 제1 STA에 의해 수행되는 방법의 일 예시를 설명하기 위한 도면이다.
도 17을 참조하면, 제1 STA은 블록-ACK 프레임에 대한 보호와 관련된 키 정보를 확인할 수 있다(S1710).
여기서, 블록-ACK 프레임에 대한 보호는 본 개시에서 전술한 BIP를 활용하는 무결성 검사에 기초하는 것일 수 있다.
이와 관련하여, 본 개시에서 전술한 바와 같이, 제1 STA은 4-웨이 핸드쉐이크 과정을 통해 제2 STA과 (해당 블록-ACK 프레임과 관련된) 키 정보를 사전에 협상/공유/생성할 수 있다. 추가적으로 또는 대안적으로, 제1 STA은 제2 STA로부터 생성된 키 정보를 전달 받을 수도 있다.
제1 STA은 전술한 보호가 적용된 블록-ACK 프레임을 제2 STA으로부터 수신할 수 있다(S1720).
이후, 제1 STA은 전술한 키 정보에 기초하여, 블록-ACK 프레임에 대한 무결성 검증을 수행할 수 있다(S1730).
이와 관련하여, 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시되는 경우, 무결성 검증을 위한 보호-관련 정보는 해당 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함될 수 있다. 일 예로, 특정 각 TID AID 정보 필드는 다수의 각 TID AID 정보 필드들 중에서 마지막에 위치한 각 TID AID 정보 필드에 해당할 수 있다.
본 개시의 실시예에 따라, 특정 각 TID AID 정보 필드에 포함되는 AID 서브필드는 보호-관련 정보의 포함 여부를 지시하기 위해 기-정의된 AID 값으로 세팅될 수 있다. 일 예로, 기-정의된 AID 값은 2044일 수 있다.
또한, 본 개시의 실시예에 따라, 특정 각 TID AID 정보 필드에 포함되는 ACK 유형 서브필드의 값 및 TID 서브필드의 값의 조합은, 1) 보호-관련 정보의 존재 여부, 2) 보호-관련 정보에 포함되는 하나 이상의 서브필드의 존재 여부, 또는 3) 보호-관련 정보에 포함되는 하나 이상의 서브필드의 길이 중 적어도 하나를 지시하는 값으로 세팅될 수 있다. 여기서, 보호-관련 정보에 포함되는 하나 이상의 서브필드는 키 정보와 관련된 제1 서브필드, 블록-ACK 프레임을 위한 패킷 번호(packet number)와 관련된 제2 서브필드, 또는 무결성 검증을 위한 MIC 정보에 대한 제3 서브필드 중 적어도 하나를 포함할 수 있다(예를 들어, 도 10 참고).
전술한 무결성 검증은 블록-ACK 프레임 내 블록-ACK 제어 필드 또는 블록-ACK 정보 필드 중 적어도 하나에 대하여 산출되는 제1 MIC 값과 상기 제3 서브필드에 의해 지시되는 제2 MIC 값 간의 비교에 기초하여 수행될 수 있다. 이때, 블록-ACK 정보 필드가 제1 MIC 값의 산출에 적용되는 경우, 특정 각 TID AID 정보 필드는 제1 MIC 값의 산출에서 제외될 수 있다. 즉, 수신 STA의 AID 값를 포함하는 각 TID AID 정보 필드만 MIC 값의 산출에 적용될 수 있다.
또한, 본 개시의 실시예에 따라, 특정 각 TID AID 정보 필드에 포함되는 ACK 유형 서브필드 또는 TID 서브필드 중 적어도 하나는 보류된(reserved) 값으로 세팅될 수 있다.
또한, 본 개시의 실시예에 따라, 특정 각 TID AID 정보 필드에 포함되는 ACK 유형 서브필드 및 TID 서브필드는 각 TID AID 정보 필드에 포함되는 AID 서브필드의 값이 2045로 세팅되지 않는 경우와 동일하게 정의될 수 있다.
또한, 본 개시의 실시예에 따라, 특정 각 TID AID 정보 필드는 보호-관련 정보에 해당하는 서브필드의 길이의 지시를 위한 길이-관련 서브필드를 포함할 수 있다. 여기서, 해당 길이-관련 서브필드는 기존에 정의된 서브필드 포맷에 기반하거나, 또는 보호-관련 정보에 해당하는 서브필드의 길이를 지시하기 위해 새롭게 정의되는 서브필드일 수 있다.
예를 들어, 길이-관련 서브필드가 기-정의된 블록-ACK 시작 시퀀스 제어 서브필드 포맷으로 구성되는 경우, 해당 길이-관련 서브필드는, 1) 보호-관련 정보에 해당하는 서브필드의 길이를 지시하거나, 2) 보호-관련 정보에 해당하는 서브필드의 길이와 보호-관련 정보 이후에 위치하는 패딩 또는 보류된 서브필드의 길이의 합을 지시할 수 있다.
또한, 본 개시의 실시예에 따라, 제1 STA와 제2 STA 간에, 블록-ACK 프레임에 대한 보호의 지원 여부를 나타내는 정보가 송수신될 수 있다. 일 예로, 블록-ACK 프레임에 대한 보호의 지원 여부를 나타내는 정보는, 비콘 프레임, 프로브 요청 프레임, 프로브 응답 프레임, 결합 요청 프레임, 결합 응답 프레임, 또는 상기 블록-ACK 프레임 중 적어도 하나를 통해 송수신될 수 있다.
또한, 본 개시의 실시예에 따라, 제1 STA와 상기 제2 STA 간에, 블록-ACK 프레임에 대하여, 보호-관련 정보의 위치에 기초하는 프레임 포맷 또는 보호-관련 정보가 적용되는 범위 중 적어도 하나에 대한 정보가 송수신될 수 있다.
도 17의 예시에서 설명하는 방법은 도 1의 제1 디바이스(100)에 의해서 수행될 수 있다. 즉, 도 17의 제1 STA은 제1 디바이스(100)로 구현될 수 있다. 예를 들어, 도 1의 제1 디바이스(100)의 하나 이상의 프로세서(102)는 블록-ACK 프레임에 대한 보호와 관련된 키 정보(key information)를 확인하고, 보호가 적용된 블록-ACK 프레임을 제2 STA으로부터 수신하며, 키 정보에 기초하여 블록-ACK 프레임에 대한 무결성 검사(integrity check)을 수행하도록 설정될 수 있다. 이와 관련하여, 제1 STA은 제2 STA과 사전에 공유된/협의된 정보에 기반하여 수신한 블록-ACK 프레임에 대해 보호/보안(Security)이 적용되었는지 여부를 인지하며, BIP를 활용하여 무결성 검사를 진행할 수 있다.
나아가, 제1 디바이스(100)의 하나 이상의 메모리(104)는 하나 이상의 프로세서(102)에 의해서 실행되는 경우 도 17의 예시 또는 후술하는 예시들에서 설명하는 방법을 수행하기 위한 명령들을 저장할 수 있다.
도 18은 본 개시에 따른 제2 STA에 의해 수행되는 방법의 일 예시를 설명하기 위한 도면이다.
도 18을 참조하면, 제2 STA은 블록-ACK 프레임에 대한 보호와 관련된 키 정보(key information)를 확인할 수 있다(S1810).
여기서, 블록-ACK 프레임에 대한 보호는 본 개시에서 전술한 BIP를 활용하는 무결성 검사에 기초하는 것일 수 있다.
제2 STA은 해당 키 정보에 기초하여, 블록-ACK 프레임에 대한 무결성 검증을 위한 보호-관련 정보를 포함하는 블록-ACK 프레임을 구성할 수 있다(S1820).
제2 STA은 전술한 보호가 적용된 블록-ACK 프레임을 제1 STA에게 송신할 수 있다(S1830).
이와 관련하여, 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시되는 경우, 무결성 검증을 위한 보호-관련 정보는 해당 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함될 수 있다. 일 예로, 특정 각 TID AID 정보 필드는 다수의 각 TID AID 정보 필드들 중에서 마지막에 위치한 각 TID AID 정보 필드에 해당할 수 있다.
블록-ACK 프레임에 대한 보호, 키 정보, 보호-관련 정보의 구성, 보호-관련 정보가 포함되는 각 AID TID 정보 필드 및 이에 포함되는 서브필드에 대한 구체적 구성, MIC 값의 산출 등에 대한 내용은 도 17에서 설명된 내용과 동일/유사하므로, 이에 대한 구체적인 설명은 생략된다.
도 18의 예시에서 설명하는 방법은 도 1의 제2 디바이스(200)에 의해서 수행될 수 있다. 즉, 도 18의 제2 STA은 제2 디바이스(200)로 구현될 수 있다. 예를 들어, 도 1의 제2 디바이스(200)의 하나 이상의 프로세서(202)는 블록-ACK 프레임에 대한 보호와 관련된 키 정보(key information)를 확인하고, 키 정보에 기초하여 보호-관련 정보를 포함하는 블록-ACK 프레임을 구성하며, 보호가 적용된 블록-ACK 프레임을 제1 STA에게 송신하도록 설정될 수 있다. 이와 관련하여, 제2 STA은 PPDU를 구성하기 전 제1 STA과 공유한 정보를 기반으로 블록-ACK 프레임에 BIP를 적용하여 무결성 검사와 관련된 정보(예를 들어, 도출한 MIC 값, MIC 값을 도출하기 위한 키 정보, 해당 블록-ACK 프레임을 위한 PN(Packet Number) 등)를 포함하는 동작을 수행할 수 있다.
나아가, 제2 디바이스(200)의 하나 이상의 메모리(204)는 하나 이상의 프로세서(202)에 의해서 실행되는 경우 도 18의 예시 또는 후술하는 예시들에서 설명하는 방법을 수행하기 위한 명령들을 저장할 수 있다.
이상에서 설명된 실시예들은 본 개시의 구성요소들과 특징들이 소정 형태로 결합된 것들이다. 각 구성요소 또는 특징은 별도의 명시적 언급이 없는 한 선택적인 것으로 고려되어야 한다. 각 구성요소 또는 특징은 다른 구성요소나 특징과 결합되지 않은 형태로 실시될 수 있다. 또한, 일부 구성요소들 및/또는 특징들을 결합하여 본 개시의 실시예를 구성하는 것도 가능하다. 본 개시의 실시예들에서 설명되는 동작들의 순서는 변경될 수 있다. 어느 실시예의 일부 구성이나 특징은 다른 실시예에 포함될 수 있고, 또는 다른 실시예의 대응하는 구성 또는 특징과 교체될 수 있다. 특허청구범위에서 명시적인 인용 관계가 있지 않은 청구항들을 결합하여 실시예를 구성하거나 출원 후의 보정에 의해 새로운 청구항으로 포함시킬 수 있음은 자명하다.
본 개시는 본 개시의 필수적 특징을 벗어나지 않는 범위에서 다른 특정한 형태로 구체화될 수 있음은 당업자에게 자명하다. 따라서, 상술한 상세한 설명은 모든 면에서 제한적으로 해석되어서는 아니 되고 예시적인 것으로 고려되어야 한다. 본 개시의 범위는 첨부된 청구항의 합리적 해석에 의해 결정되어야 하고, 본 개시의 등가적 범위 내에서의 모든 변경은 본 개시의 범위에 포함된다.
본 개시의 범위는 다양한 실시예의 방법에 따른 동작이 장치 또는 컴퓨터 상에서 실행되도록 하는 소프트웨어 또는 머신-실행가능한 명령들(예를 들어, 운영체제, 애플리케이션, 펌웨어(firmware), 프로그램 등), 및 이러한 소프트웨어 또는 명령 등이 저장되어 장치 또는 컴퓨터 상에서 실행 가능한 비-일시적 컴퓨터-판독가능 매체(non-transitory computer-readable medium)를 포함한다. 본 개시에서 설명하는 특징을 수행하는 프로세싱 시스템을 프로그래밍하기 위해 사용될 수 있는 명령은 저장 매체 또는 컴퓨터 판독가능 저장 매체 상에/내에 저장될 수 있고, 이러한 저장 매체를 포함하는 컴퓨터 프로그램 제품을 이용하여 본 개시에서 설명하는 특징이 구현될 수 있다. 저장 매체는 DRAM, SRAM, DDR RAM 또는 다른 랜덤 액세스 솔리드 스테이트 메모리 디바이스와 같은 고속 랜덤 액세스 메모리를 포함할 수 있지만, 이에 제한되지 않으며, 하나 이상의 자기 디스크 저장 디바이스, 광 디스크 저장 장치, 플래시 메모리 디바이스 또는 다른 비-휘발성 솔리드 스테이트 저장 디바이스와 같은 비-휘발성 메모리를 포함할 수 있다. 메모리는 선택적으로 프로세서(들)로부터 원격에 위치한 하나 이상의 저장 디바이스를 포함한다. 메모리 또는 대안적으로 메모리 내의 비-휘발성 메모리 디바이스(들)는 비-일시적 컴퓨터 판독가능 저장 매체를 포함한다. 본 개시에서 설명하는 특징은, 머신 판독가능 매체 중 임의의 하나에 저장되어 프로세싱 시스템의 하드웨어를 제어할 수 있고, 프로세싱 시스템이 본 개시의 실시예에 따른 결과를 활용하는 다른 메커니즘과 상호작용하도록 하는 소프트웨어 및/또는 펌웨어에 통합될 수 있다. 이러한 소프트웨어 또는 펌웨어는 애플리케이션 코드, 디바이스 드라이버, 운영 체제 및 실행 환경/컨테이너를 포함할 수 있지만 이에 제한되지 않는다.
본 개시에서 제안하는 방법은 IEEE 802.11 기반 시스템에 적용되는 예를 중심으로 설명하였으나, IEEE 802.11 기반 시스템 이외에도 다양한 무선랜 또는 무선 통신 시스템에 적용하는 것이 가능하다.

Claims (20)

  1. 무선 로컬 영역 네트워크(WLAN) 시스템에서 제1 스테이션(STA)에 의해서 수행되는 방법에 있어서, 상기 방법은:
    블록-ACK(block acknowledgement) 프레임에 대한 보호와 관련된 키 정보를 확인하는 단계;
    상기 보호가 적용된 블록-ACK 프레임을 제2 STA으로부터 수신하는 단계; 및
    상기 키 정보에 기초하여, 상기 블록-ACK 프레임에 대한 무결성 검증을 수행하는 단계를 포함하며,
    상기 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시됨에 기초하여, 상기 무결성 검증을 위한 보호-관련 정보는 상기 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함되는, 방법.
  2. 제1항에 있어서,
    상기 특정 각 TID AID 정보 필드에 포함되는 AID 서브필드는 상기 보호-관련 정보의 포함 여부를 지시하기 위해 기-정의된 AID 값으로 세팅되는, 방법.
  3. 제2항에 있어서,
    상기 기-정의된 AID 값은 2044인, 방법.
  4. 제1항에 있어서,
    상기 특정 각 TID AID 정보 필드에 포함되는 ACK 유형 서브필드의 값 및 TID 서브필드의 값의 조합은, 상기 보호-관련 정보의 존재 여부, 상기 보호-관련 정보에 포함되는 하나 이상의 서브필드의 존재 여부, 또는 상기 보호-관련 정보에 포함되는 하나 이상의 서브필드의 길이 중 적어도 하나를 지시하는 값으로 세팅되는, 방법.
  5. 제1항에 있어서,
    상기 보호-관련 정보에 포함되는 하나 이상의 서브필드는 상기 키 정보와 관련된 제1 서브필드, 상기 블록-ACK 프레임을 위한 패킷 번호(packet number)와 관련된 제2 서브필드, 또는 상기 무결성 검증을 위한 MIC 정보에 대한 제3 서브필드 중 적어도 하나를 포함하는, 방법.
  6. 제5항에 있어서,
    상기 무결성 검증은 상기 블록-ACK 프레임 내 블록-ACK 제어 필드 또는 블록-ACK 정보 필드 중 적어도 하나에 대하여 산출되는 제1 MIC 값과 상기 제3 서브필드에 의해 지시되는 제2 MIC 값 간의 비교에 기초하여 수행되는, 방법.
  7. 제6항에 있어서,
    상기 블록-ACK 정보 필드가 상기 제1 MIC 값의 산출에 적용됨에 기초하여, 상기 특정 각 TID AID 정보 필드는 상기 제1 MIC 값의 산출에서 제외되는, 방법.
  8. 제1항에 있어서,
    상기 특정 각 TID AID 정보 필드에 포함되는 ACK 유형 서브필드 또는 TID 서브필드 중 적어도 하나는 보류된(reserved) 값으로 세팅되는, 방법.
  9. 제1항에 있어서,
    상기 특정 각 TID AID 정보 필드에 포함되는 ACK 유형 서브필드 및 TID 서브필드는 각 TID AID 정보 필드에 포함되는 AID 서브필드의 값이 2045로 세팅되지 않는 경우와 동일하게 정의되는, 방법.
  10. 제1항에 있어서,
    상기 특정 각 TID AID 정보 필드는 상기 보호-관련 정보에 해당하는 서브필드의 길이의 지시를 위한 길이-관련 서브필드를 포함하는, 방법.
  11. 제10항에 있어서,
    상기 길이-관련 서브필드가 기-정의된 블록-ACK 시작 시퀀스 제어 서브필드 포맷으로 구성됨에 기초하여, 상기 길이-관련 서브필드는,
    상기 보호-관련 정보에 해당하는 서브필드의 길이를 지시하거나,
    상기 보호-관련 정보에 해당하는 서브필드의 길이와 상기 보호-관련 정보 이후에 위치하는 패딩 또는 보류된 서브필드의 길이의 합을 지시하는, 방법.
  12. 제10항에 있어서,
    상기 특정 각 TID AID 정보 필드는 다수의 각 TID AID 정보 필드들 중에서 마지막에 위치한 각 TID AID 정보 필드에 해당하는, 방법.
  13. 제1항에 있어서,
    상기 제1 STA와 상기 제2 STA 간에, 상기 블록-ACK 프레임에 대한 보호의 지원 여부를 나타내는 정보가 송수신되며
    상기 정보는 비콘 프레임, 프로브 요청 프레임, 프로브 응답 프레임, 결합 요청 프레임, 결합 응답 프레임, 또는 상기 블록-ACK 프레임 중 적어도 하나를 통해 송수신되는, 방법.
  14. 제1항에 있어서,
    상기 제1 STA와 상기 제2 STA 간에, 상기 블록-ACK 프레임에 대하여, 상기 보호-관련 정보의 위치에 기초하는 프레임 포맷 또는 상기 보호-관련 정보가 적용되는 범위 중 적어도 하나에 대한 정보가 송수신되는, 방법.
  15. 제1항에 있어서,
    상기 블록-ACK 프레임에 대한 보호는 BIP(broadcast/multicast integrity protocol)를 활용하는 무결성 검증에 기초하는, 방법.
  16. 무선 로컬 영역 네트워크(WLAN) 시스템에서의 제1 스테이션(STA) 장치에 있어서, 상기 장치는:
    하나 이상의 송수신기; 및
    상기 하나 이상의 송수신기와 연결된 하나 이상의 프로세서를 포함하고,
    상기 하나 이상의 프로세서는:
    블록-ACK(block acknowledgement) 프레임에 대한 보호와 관련된 키 정보를 확인하고;
    상기 보호가 적용된 블록-ACK 프레임을 제2 STA으로부터 수신하고;
    상기 키 정보에 기초하여, 상기 블록-ACK 프레임에 대한 무결성 검증을 수행하도록 설정하되,
    상기 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시됨에 기초하여, 상기 무결성 검증을 위한 보호-관련 정보는 상기 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함되는, 장치.
  17. 무선 로컬 영역 네트워크(WLAN) 시스템에서 제2 스테이션(STA)에 의해서 수행되는 방법에 있어서, 상기 방법은:
    블록-ACK 프레임에 대한 보호와 관련된 키 정보를 확인하는 단계;
    상기 키 정보에 기초하여, 상기 블록-ACK 프레임에 대한 무결성 검증을 위한 보호-관련 정보를 포함하는 블록-ACK 프레임을 구성하는 단계; 및
    상기 보호가 적용된 블록-ACK 프레임을 제1 STA에게 송신하는 단계를 포함하되,
    상기 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시됨에 기초하여, 상기 보호-관련 정보는 상기 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함되는, 방법.
  18. 무선 로컬 영역 네트워크(WLAN) 시스템에서의 제2 스테이션(STA) 장치에 있어서, 상기 장치는:
    하나 이상의 송수신기; 및
    상기 하나 이상의 송수신기와 연결된 하나 이상의 프로세서를 포함하고,
    상기 하나 이상의 프로세서는:
    블록-ACK 프레임에 대한 보호와 관련된 키 정보를 확인하고;
    상기 키 정보에 기초하여, 상기 블록-ACK 프레임에 대한 무결성 검증을 위한 보호-관련 정보를 포함하는 블록-ACK 프레임을 구성하고;
    상기 보호가 적용된 블록-ACK 프레임을 제1 STA에게 송신하도록 설정하되,
    상기 블록-ACK 프레임이 다중 STA를 위한 블록-ACK 유형으로 지시됨에 기초하여, 상기 보호-관련 정보는 상기 블록-ACK 프레임 내 블록-ACK 정보 필드에 포함되는 다수의 각 TID AID 정보(Per TID AID Info) 필드들 중 특정 각 TID AID 정보 필드에 포함되는, 장치.
  19. 무선 로컬 영역 네트워크(WLAN) 시스템에서 스테이션(STA)을 제어하도록 설정되는 프로세싱 장치에 있어서, 상기 프로세싱 장치는:
    하나 이상의 프로세서; 및
    상기 하나 이상의 프로세서에 동작 가능하게 연결되고, 상기 하나 이상의 프로세서에 의해 실행됨에 기반하여, 제1항 내지 제15항 중의 어느 한 항에 따른 방법을 수행하는 명령들을 저장하는 하나 이상의 컴퓨터 메모리를 포함하는, 프로세싱 장치.
  20. 하나 이상의 명령을 저장하는 하나 이상의 비-일시적(non-transitory) 컴퓨터 판독가능 매체로서,
    상기 하나 이상의 명령은 하나 이상의 프로세서에 의해서 실행되어, 무선랜 시스템에서 장치가 제1항 내지 제15항 중의 어느 한 항에 따른 방법을 수행하도록 제어하는, 컴퓨터 판독가능 매체.
PCT/KR2024/017734 2023-11-09 2024-11-11 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 Pending WO2025101021A1 (ko)

Applications Claiming Priority (6)

Application Number Priority Date Filing Date Title
KR10-2023-0154820 2023-11-09
KR20230154820 2023-11-09
KR20240003690 2024-01-09
KR10-2024-0003690 2024-01-09
KR10-2024-0134040 2024-10-02
KR20240134040 2024-10-02

Publications (1)

Publication Number Publication Date
WO2025101021A1 true WO2025101021A1 (ko) 2025-05-15

Family

ID=95695945

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/KR2024/017734 Pending WO2025101021A1 (ko) 2023-11-09 2024-11-11 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치

Country Status (1)

Country Link
WO (1) WO2025101021A1 (ko)

Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090327694A1 (en) * 2005-06-16 2009-12-31 Kapil Sood Methods and apparatus for providing integrity protection for management and control traffic of wireless communication networks

Patent Citations (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090327694A1 (en) * 2005-06-16 2009-12-31 Kapil Sood Methods and apparatus for providing integrity protection for management and control traffic of wireless communication networks

Non-Patent Citations (4)

* Cited by examiner, † Cited by third party
Title
ABHISHEK PATIL (QUALCOMM): "LB258: Resolution for CIDs related to protected BA", IEEE DRAFT; 11-22-0082-03-000M-LB258-RESOLUTION-FOR-CIDS-RELATED-TO-PROTECTED-BA, vol. 802.11m, no. 3, 21 January 2022 (2022-01-21), US, pages 1 - 11, XP068188551 *
ALFRED ASTERJADHI (QUALCOMM INC.): "Thoughts on Secure Control frames", IEEE DRAFT; 11-23-0312-00-0UHR-THOUGHTS-ON-SECURE-CONTROL-FRAMES, vol. 802.11 UHR, no. 0, 14 May 2023 (2023-05-14), US, pages 1 - 12, XP068203160 *
LIWEN CHU (NXP): "enhanced security discussion", IEEE DRAFT; 11-23-0352-01-0UHR-ENHANCED-SECURITY-DISCUSSION, vol. 802.11 UHR, no. 1, 5 June 2023 (2023-06-05), US, pages 1 - 7, XP068203600 *
PO-KAI HUANG (INTEL): "Trigger frame protection", IEEE DRAFT; 11-23-0286-00-0UHR-TRIGGER-FRAME-PROTECTION, vol. 802.11 UHR, no. 0, 13 March 2023 (2023-03-13), US, pages 1 - 8, XP068201542 *

Similar Documents

Publication Publication Date Title
WO2017034081A1 (ko) 무선 통신 시스템의 데이터 전송 방법 및 장치
WO2023136692A1 (ko) 무선랜 시스템에서 협력적 센싱 방법 및 장치
WO2025089897A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025005562A1 (ko) 무선랜 시스템에서 세컨더리 채널 액세스 방법 및 장치
WO2024186058A1 (ko) 무선랜 시스템에서 멀티-링크 디바이스에 기초한 로밍 방법 및 장치
WO2024186059A1 (ko) 무선랜 시스템에서 멀티-링크 디바이스에 기초한 로밍 방법 및 장치
WO2025101021A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025053740A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025048620A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025089899A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025101023A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025053739A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025048468A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025048617A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025143891A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025147144A1 (ko) 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치
WO2025143879A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025147145A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025101024A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025089896A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025143883A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025188141A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025188140A1 (ko) 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치
WO2025042209A1 (ko) 무선랜 시스템에서 강화된 보안에 대한 방법 및 장치
WO2025147004A1 (ko) 무선랜 시스템에서 릴레이 동작을 위한 방법 및 장치

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24889207

Country of ref document: EP

Kind code of ref document: A1