WO2025101024A1 - 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 - Google Patents
무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 Download PDFInfo
- Publication number
- WO2025101024A1 WO2025101024A1 PCT/KR2024/017743 KR2024017743W WO2025101024A1 WO 2025101024 A1 WO2025101024 A1 WO 2025101024A1 KR 2024017743 W KR2024017743 W KR 2024017743W WO 2025101024 A1 WO2025101024 A1 WO 2025101024A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- frame
- subfield
- aad
- sta
- field
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Images
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L1/00—Arrangements for detecting or preventing errors in the information received
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L1/00—Arrangements for detecting or preventing errors in the information received
- H04L1/12—Arrangements for detecting or preventing errors in the information received by using return channel
- H04L1/16—Arrangements for detecting or preventing errors in the information received by using return channel in which the return channel carries supervisory signals, e.g. repetition request signals
- H04L1/1607—Details of the supervisory signal
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L1/00—Arrangements for detecting or preventing errors in the information received
- H04L1/12—Arrangements for detecting or preventing errors in the information received by using return channel
- H04L1/16—Arrangements for detecting or preventing errors in the information received by using return channel in which the return channel carries supervisory signals, e.g. repetition request signals
- H04L1/18—Automatic repetition systems, e.g. Van Duuren systems
- H04L1/1812—Hybrid protocols; Hybrid automatic repeat request [HARQ]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L1/00—Arrangements for detecting or preventing errors in the information received
- H04L1/12—Arrangements for detecting or preventing errors in the information received by using return channel
- H04L1/16—Arrangements for detecting or preventing errors in the information received by using return channel in which the return channel carries supervisory signals, e.g. repetition request signals
- H04L1/18—Automatic repetition systems, e.g. Van Duuren systems
- H04L1/1829—Arrangements specially adapted for the receiver end
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
- H04W12/037—Protecting confidentiality, e.g. by encryption of the control plane, e.g. signalling traffic
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/04—Key management, e.g. using generic bootstrapping architecture [GBA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/10—Integrity
- H04W12/106—Packet or message integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W84/00—Network topologies
- H04W84/02—Hierarchically pre-organised networks, e.g. paging networks, cellular networks, WLAN [Wireless Local Area Network] or WLL [Wireless Local Loop]
- H04W84/10—Small scale networks; Flat hierarchical networks
- H04W84/12—WLAN [Wireless Local Area Networks]
Definitions
- the present disclosure relates to a method and device for transmitting or receiving a protected control frame in a wireless local area network (WLAN) system.
- WLAN wireless local area network
- Wi-Fi wireless LAN
- VHT Very High-Throughput
- HE High Efficiency
- EHT Extremely High Throughput
- technologies for MIMO (Multiple Input Multiple Output) and multi-access point (AP) coordination that support increased bandwidth, efficient utilization of multiple bands, and increased spatial streams are being studied, and in particular, various technologies are being studied to support low latency or real-time traffic.
- new technologies are being discussed to support ultra-high reliability (UHR), including improvements or extensions of EHT technologies.
- the technical problem of the present disclosure is to provide a method and device for transmitting or receiving a protected control frame in a wireless LAN system.
- the technical problem of the present disclosure is to provide a method and device for supporting encryption/decryption/integrity check based on additional authentication data (AAD) for a block ACK (acknowledgement) frame in a wireless LAN system.
- AAD additional authentication data
- a method may include the steps of: receiving, by a first station (STA), a protected block ACK (acknowledgement) (BA) frame from a second STA based on a specific protocol; generating, by the first STA, additional authentication data (AAD) based on the BA frame; and performing, by the first STA, at least one of decryption or integrity check on the BA frame based on the AAD.
- the AAD may be based on one or more fields included in a medium access control (MAC) header of the BA frame, or may be based on one or more subfields included in the MAC header of the BA frame and one or more subfields included in a BA control field or a BA information field of the BA frame.
- MAC medium access control
- a method may include: generating, by a second station (STA), additional authentication data (AAD) for a block ACK (acknowledgement) (BA) frame based on a specific protocol; and transmitting, by the second STA, a protected BA frame to a first STA based on the AAD.
- the AAD may be based on one or more fields included in a medium access control (MAC) header of the BA frame, or on one or more subfields included in the MAC header of the BA frame and one or more subfields included in a BA control field or a BA information field of the BA frame.
- MAC medium access control
- a method and device for supporting encryption/decryption/integrity check based on additional authentication data (AAD) for a block ACK (acknowledgement) frame in a wireless LAN system can be provided.
- FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
- FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
- FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.
- FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.
- FIG. 5 is a diagram for explaining a CSMA/CA-based frame transmission operation to which the present disclosure can be applied.
- FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.
- FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.
- FIG. 8 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.
- FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure can be applied.
- FIG. 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.
- Figure 11 shows an example of the format of conventional AAD.
- FIG. 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.
- FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.
- Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.
- Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.
- FIG. 16 illustrates exemplary formats of block ACK frames to which the present disclosure can be applied.
- FIG. 17 is a diagram for explaining the operation of the first STA according to the present disclosure.
- FIG. 18 is a diagram for explaining the operation of a second STA according to the present disclosure.
- FIG. 19 illustrates examples of AAD configuration for protecting block ACK frames according to an embodiment of the present disclosure.
- first in one embodiment
- second component in another embodiment
- first component in another embodiment may be referred to as a first component in another embodiment
- the examples of the present disclosure can be applied to various wireless communication systems.
- the examples of the present disclosure can be applied to a wireless LAN system.
- the examples of the present disclosure can be applied to a wireless LAN based on IEEE 802.11a/g/n/ac/ax/be standards.
- the examples of the present disclosure can be applied to a wireless LAN based on a newly proposed IEEE 802.11bn (or UHR) standard.
- the examples of the present disclosure can be applied to a wireless LAN based on a next-generation standard after IEEE 802.11bn.
- the examples of the present disclosure can be applied to a cellular wireless communication system.
- the examples of the present disclosure can be applied to a cellular wireless communication system based on a Long Term Evolution (LTE) series technology of the 3rd Generation Partnership Project (3GPP) standard and a New Radio (5G NR) series technology.
- LTE Long Term Evolution
- 3GPP 3rd Generation Partnership Project
- 5G NR New Radio
- FIG. 1 illustrates a block diagram of a wireless communication device according to one embodiment of the present disclosure.
- the first device (100) and the second device (200) illustrated in FIG. 1 may be replaced with various terms such as a terminal, a wireless device, a Wireless Transmit Receive Unit (WTRU), a User Equipment (UE), a Mobile Station (MS), a user terminal (UT), a Mobile Subscriber Station (MSS), a Mobile Subscriber Unit (MSS), a Subscriber Station (SS), an Advanced Mobile Station (AMS), a Wireless terminal (WT), or simply a user.
- WTRU Wireless Transmit Receive Unit
- UE User Equipment
- MS Mobile Station
- UT a Mobile Subscriber Station
- MSS Mobile Subscriber Unit
- SS Subscriber Station
- AMS Advanced Mobile Station
- WT Wireless terminal
- first device (100) and the second device (200) may be replaced with various terms such as an access point (AP), a base station (BS), a fixed station, a Node B, a base transceiver system (BTS), a network, an Artificial Intelligence (AI) system, a road side unit (RSU), a repeater, a router, a relay, a gateway, etc.
- AP access point
- BS base station
- BTS base transceiver system
- AI Artificial Intelligence
- RSU road side unit
- RSU repeater
- router a relay
- gateway a gateway
- the devices (100, 200) illustrated in FIG. 1 may also be referred to as stations (STAs).
- STAs stations
- the devices (100, 200) illustrated in FIG. 1 may be referred to by various terms such as a transmitting device, a receiving device, a transmitting STA, and a receiving STA.
- the STAs (110, 200) may perform an AP (access point) role or a non-AP role. That is, the STAs (110, 200) in the present disclosure may perform functions of an AP and/or a non-AP.
- the STAs (110, 200) When the STAs (110, 200) perform an AP function, they may simply be referred to as APs, and when the STAs (110, 200) perform a non-AP function, they may simply be referred to as STAs.
- the APs in the present disclosure may also be indicated as AP STAs.
- the first device (100) and the second device (200) can transmit and receive wireless signals through various wireless LAN technologies (e.g., IEEE 802.11 series).
- the first device (100) and the second device (200) can include interfaces for a medium access control (MAC) layer and a physical layer (PHY) that follow the regulations of the IEEE 802.11 standard.
- MAC medium access control
- PHY physical layer
- the first device (100) and the second device (200) may additionally support various communication standards (for example, standards of 3GPP LTE series, 5G NR series, etc.) other than wireless LAN technology.
- the device of the present disclosure may be implemented as various devices such as a mobile phone, a vehicle, a personal computer, an Augmented Reality (AR) device, and a Virtual Reality (VR) device.
- the STA of the present specification may support various communication services such as a voice call, a video call, a data communication, autonomous driving, MTC (Machine-Type Communication), M2M (Machine-to-Machine), D2D (Device-to-Device), and IoT (Internet-of-Things).
- a first device (100) includes one or more processors (102) and one or more memories (104), and may additionally include one or more transceivers (106) and/or one or more antennas (108).
- the processor (102) controls the memories (104) and/or the transceivers (106), and may be configured to implement the descriptions, functions, procedures, suggestions, methods, and/or operational flowcharts disclosed in the present disclosure.
- the processor (102) may process information in the memory (104) to generate first information/signal, and then transmit a wireless signal including the first information/signal via the transceiver (106).
- the processor (102) may receive a wireless signal including second information/signal via the transceiver (106), and then store information obtained from signal processing of the second information/signal in the memory (104).
- the memory (104) may be connected to the processor (102) and may store various information related to the operation of the processor (102). For example, the memory (104) may perform some or all of the processes controlled by the processor (102), or may store software codes including instructions for performing the descriptions, functions, procedures, proposals, methods, and/or operation flowcharts disclosed in the present disclosure.
- the processor (102) and the memory (104) may be part of a communication modem/circuit/chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series).
- the transceiver (106) may be connected to the processor (102) and may transmit and/or receive wireless signals via one or more antennas (108).
- the transceiver (106) may include a transmitter and/or a receiver.
- the transceiver (106) may be used interchangeably with an RF (Radio Frequency) unit.
- a device may also mean a communication modem/circuit/chip.
- the second device (200) includes one or more processors (202), one or more memories (204), and may additionally include one or more transceivers (206) and/or one or more antennas (208).
- the processor (202) may control the memories (204) and/or the transceivers (206), and may be configured to implement the descriptions, functions, procedures, suggestions, methods, and/or operational flowcharts disclosed in this disclosure.
- the processor (202) may process information in the memory (204) to generate third information/signal, and then transmit a wireless signal including the third information/signal via the transceiver (206).
- the processor (202) may receive a wireless signal including fourth information/signal via the transceiver (206), and then store information obtained from signal processing of the fourth information/signal in the memory (204).
- the memory (204) may be connected to the processor (202) and may store various information related to the operation of the processor (202). For example, the memory (204) may perform some or all of the processes controlled by the processor (202), or may store software codes including instructions for performing the descriptions, functions, procedures, proposals, methods, and/or operational flowcharts disclosed in the present disclosure.
- the processor (202) and the memory (204) may be part of a communication modem/circuit/chip designed to implement a wireless LAN technology (e.g., IEEE 802.11 series).
- the transceiver (206) may be connected to the processor (202) and may transmit and/or receive wireless signals via one or more antennas (208).
- the transceiver (206) may include a transmitter and/or a receiver.
- the transceiver (206) may be used interchangeably with an RF unit.
- a device may also mean a communication modem/circuit/chip.
- one or more protocol layers may be implemented by one or more processors (102, 202).
- one or more processors (102, 202) may implement one or more layers (e.g., functional layers such as PHY, MAC).
- One or more processors (102, 202) may generate one or more Protocol Data Units (PDUs) and/or one or more Service Data Units (SDUs) according to the descriptions, functions, procedures, proposals, methods, and/or operational flowcharts disclosed in this disclosure.
- PDUs Protocol Data Units
- SDUs Service Data Units
- One or more processors (102, 202) may generate messages, control information, data, or information according to the descriptions, functions, procedures, proposals, methods, and/or operational flowcharts disclosed in this disclosure.
- One or more processors (102, 202) can generate signals (e.g., baseband signals) including PDUs, SDUs, messages, control information, data or information according to the functions, procedures, suggestions and/or methodologies disclosed in this disclosure, and provide the signals to one or more transceivers (106, 206).
- One or more processors (102, 202) can receive signals (e.g., baseband signals) from one or more transceivers (106, 206) and obtain PDUs, SDUs, messages, control information, data or information according to the descriptions, functions, procedures, suggestions, methods and/or operational flowcharts disclosed in this disclosure.
- signals e.g., baseband signals
- the one or more processors (102, 202) may be referred to as a controller, a microcontroller, a microprocessor, or a microcomputer.
- the one or more processors (102, 202) may be implemented by hardware, firmware, software, or a combination thereof.
- ASICs Application Specific Integrated Circuits
- DSPs Digital Signal Processors
- DSPDs Digital Signal Processing Devices
- PLDs Programmable Logic Devices
- FPGAs Field Programmable Gate Arrays
- the descriptions, functions, procedures, suggestions, methods, and/or operational flowcharts disclosed in this disclosure may be implemented using firmware or software, and the firmware or software may be implemented to include modules, procedures, functions, etc.
- the descriptions, functions, procedures, suggestions, methods and/or operational flowcharts disclosed in this disclosure may be implemented using firmware or software configured to perform one or more of the following: included in one or more processors (102, 202), or stored in one or more memories (104, 204) and driven by one or more of the processors (102, 202).
- the descriptions, functions, procedures, suggestions, methods and/or operational flowcharts disclosed in this disclosure may be implemented using firmware or software in the form of codes, instructions and/or sets of instructions.
- One or more memories (104, 204) may be coupled to one or more processors (102, 202) and may store various forms of data, signals, messages, information, programs, codes, instructions, and/or commands.
- the one or more memories (104, 204) may be comprised of ROM, RAM, EPROM, flash memory, hard drives, registers, cache memory, computer readable storage media, and/or combinations thereof.
- the one or more memories (104, 204) may be located internally and/or externally to the one or more processors (102, 202). Additionally, the one or more memories (104, 204) may be coupled to the one or more processors (102, 202) via various technologies, such as wired or wireless connections.
- One or more transceivers (106, 206) can transmit user data, control information, wireless signals/channels, etc., as mentioned in the methods and/or flowcharts of the present disclosure, to one or more other devices.
- One or more transceivers (106, 206) can receive user data, control information, wireless signals/channels, etc., as mentioned in the descriptions, functions, procedures, suggestions, methods and/or flowcharts of the present disclosure, from one or more other devices.
- one or more transceivers (106, 206) can be coupled to one or more processors (102, 202) and can transmit and receive wireless signals.
- one or more processors (102, 202) can control one or more transceivers (106, 206) to transmit user data, control information, or wireless signals to one or more other devices. Additionally, one or more processors (102, 202) may control one or more transceivers (106, 206) to receive user data, control information, or wireless signals from one or more other devices. Additionally, one or more transceivers (106, 206) may be coupled to one or more antennas (108, 208), and one or more transceivers (106, 206) may be configured to transmit and receive user data, control information, wireless signals/channels, and the like, as described in the description, function, procedure, proposal, method, and/or operational flowchart, etc.
- one or more antennas may be multiple physical antennas, or multiple logical antennas (e.g., antenna ports).
- One or more transceivers (106, 206) may convert received user data, control information, wireless signals/channels, etc. from RF band signals to baseband signals in order to process the received user data, control information, wireless signals/channels, etc. using one or more processors (102, 202).
- One or more transceivers (106, 206) may convert processed user data, control information, wireless signals/channels, etc. from baseband signals to RF band signals using one or more processors (102, 202).
- one or more transceivers (106, 206) may include an (analog) oscillator and/or filter.
- one of the STAs (100, 200) may perform the intended operation of an AP, and the other of the STAs (100, 200) may perform the intended operation of a non-AP STA.
- the transceivers (106, 206) of FIG. 1 may perform transmission and reception operations of signals (e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a/b/g/n/ac/ax/be/bn, etc.).
- signals e.g., packets or PPDUs (Physical layer Protocol Data Units) according to IEEE 802.11a/b/g/n/ac/ax/be/bn, etc.
- operations of various STAs generating transmission and reception signals or performing data processing or calculations in advance for transmission and reception signals may be performed in the processors (102, 202) of FIG. 1.
- an example of an operation for generating a transmit/receive signal or performing data processing or calculation in advance for a transmit/receive signal may include: 1) an operation for determining/acquiring/configuring/computing/decoding/encoding bit information of a field (SIG (signal), STF (short training field), LTF (long training field), Data, etc.) included in a PPDU, 2) an operation for determining/configuring/acquiring time resources or frequency resources (e.g., subcarrier resources) used for the fields (SIG, STF, LTF, Data, etc.) included in a PPDU, 3) an operation for determining/configuring/acquiring specific sequences (e.g., pilot sequences, STF/LTF sequences, extra sequences applied to SIG) used for the fields (SIG, STF, LTF, Data, etc.) included in a PPDU, 4) a power control operation and/or a power saving operation applied to an STA, 5) an operation related to determining/acquiring/acquiring/
- downlink means a link for communication from an AP STA to a non-AP STA, and downlink PPDU/packet/signal, etc. can be transmitted and received through the downlink.
- a transmitter may be part of an AP STA, and a receiver may be part of a non-AP STA.
- Uplink (UL) means a link for communication from a non-AP STA to an AP STA, and uplink PPDU/packet/signal, etc. can be transmitted and received through the uplink.
- a transmitter may be part of a non-AP STA, and a receiver may be part of an AP STA.
- FIG. 2 is a diagram showing an exemplary structure of a wireless LAN system to which the present disclosure can be applied.
- a wireless LAN supporting transparent STA mobility to a higher layer can be provided through the interaction of multiple components.
- a BSS Basic Service Set
- FIG. 2 illustrates an example in which two BSSs (BSS1 and BSS2) exist and two STAs are included as members of each BSS (STA1 and STA2 are included in BSS1, and STA3 and STA4 are included in BSS2).
- An ellipse representing a BSS in FIG. 2 can also be understood as representing a coverage area in which STAs included in the corresponding BSS maintain communication. This area can be referred to as a BSA (Basic Service Area). If an STA moves out of the BSA, it cannot directly communicate with other STAs within the corresponding BSA.
- BSA Basic Service Area
- an IBSS can have a minimal form consisting of only two STAs.
- BSS1 consisting of only STA1 and STA2
- BSS2 consisting of only STA3 and STA4
- This configuration is possible when STAs can communicate directly without an AP.
- a LAN can be configured when needed rather than being planned in advance, and this can be called an ad-hoc network.
- an IBSS does not include an AP, there is no centralized management entity that performs management functions. That is, in an IBSS, STAs are managed in a distributed manner. In IBSS, all STAs can be mobile STAs, and access to distributed systems (DS) is not permitted, forming a self-contained network.
- DS distributed systems
- the membership of an STA in a BSS can be dynamically changed by the STA turning on or off, the STA entering or leaving the BSS area, etc.
- an STA can join the BSS using a synchronization process.
- an STA In order to access all services of the BSS infrastructure, an STA must be associated with a BSS. This association can be dynamically established and may include the use of a Distribution System Service (DSS).
- DSS Distribution System Service
- the direct STA-to-STA distance may be limited by the PHY performance. In some cases, this distance limitation may be sufficient, but in some cases, communication between STAs over longer distances may be required.
- a distributed system may be configured.
- DS refers to a structure in which BSSs are interconnected.
- a BSS may exist as an extended component of a network composed of multiple BSSs, as shown in FIG. 2.
- DS is a logical concept and can be specified by the characteristics of a distributed system medium (DSM).
- DSM distributed system medium
- WM wireless medium
- DSM distributed system medium
- Each logical medium is used for a different purpose and is used by different components. These media are neither limited to being the same nor limited to being different.
- the flexibility of a wireless LAN structure can be explained in that multiple media are logically different.
- a wireless LAN structure can be implemented in various ways, and each wireless LAN structure can be independently specified by the physical characteristics of each implementation example.
- a DS can support mobile devices by providing seamless integration of multiple BSSs and providing logical services necessary to handle addresses to destinations.
- a DS can further include a component called a portal that acts as a bridge for connecting wireless LANs to other networks (e.g., IEEE 802.X).
- An AP is an entity that enables access to a DS through a WM for associated non-AP STAs, and also has the functionality of an STA. Data movement between a BSS and a DS can be performed through an AP.
- STA2 and STA3 illustrated in FIG. 2 have the functionality of an STA, and provide a function that allows associated non-AP STAs (STA1 and STA4) to access the DS.
- all APs are basically STAs, all APs are addressable entities.
- the address used by an AP for communication on a WM and the address used by an AP for communication on a DSM need not necessarily be the same.
- a BSS consisting of an AP and one or more STAs can be called an infrastructure BSS.
- Data transmitted from one of the STA(s) associated with an AP to the STA address of that AP is always received on an uncontrolled port and can be processed by an IEEE 802.1X port access entity.
- the transmitted data (or frame) can be forwarded to the DS.
- an Extended Service Set may be established to provide wider coverage.
- An ESS is a network of arbitrary size and complexity consisting of DS and BSS.
- An ESS may correspond to a set of BSSs connected to a DS. However, an ESS does not include a DS.
- An ESS network is characterized by being seen as an IBSS in the LLC (Logical Link Control) layer. STAs included in an ESS can communicate with each other, and mobile STAs can move from one BSS to another BSS (within the same ESS) transparently to the LLC.
- APs included in an ESS may have the same SSID (service set identification). The SSID is distinct from the BSSID, which is an identifier of the BSS.
- the BSSs can be partially overlapped, which is a common configuration used to provide continuous coverage.
- the BSSs can be physically unconnected, and logically there is no limit to the distance between the BSSs.
- the BSSs can be physically co-located, which can be used to provide redundancy.
- one (or more) IBSS or ESS networks can physically co-exist in the same space as one (or more) ESS networks. This can correspond to ESS network configurations such as cases where ad-hoc networks operate at locations where ESS networks exist, cases where physically overlapping wireless networks are configured by different organizations, or cases where two or more different access and security policies are required at the same location.
- FIG. 3 is a diagram for explaining a link setup process to which the present disclosure can be applied.
- the link setup process may also be referred to as a session initiation process or a session setup process.
- the discovery, authentication, association, and security setup processes of the link setup process may be collectively referred to as the association process.
- the STA may perform a network discovery operation.
- the network discovery operation may include a scanning operation of the STA. That is, in order for the STA to access the network, it must find a network that it can participate in. The STA must identify a compatible network before participating in the wireless network, and the process of identifying networks existing in a specific area is called scanning.
- FIG. 3 illustrates a network discovery operation including an active scanning process as an example.
- active scanning an STA performing scanning transmits a probe request frame to search for APs in the vicinity while moving between channels and waits for a response thereto.
- a responder transmits a probe response frame to the STA that transmitted the probe request frame as a response to the probe request frame.
- the responder may be an STA that last transmitted a beacon frame in the BSS of the channel being scanned.
- the AP transmits a beacon frame, so the AP becomes the responder, and in the IBSS, the STAs within the IBSS take turns transmitting beacon frames, so the responder is not fixed.
- an STA that transmits a probe request frame on channel 1 and receives a probe response frame on channel 1 can store BSS-related information included in the received probe response frame and move to the next channel (e.g., channel 2) to perform scanning (i.e., transmitting and receiving probe request/response on channel 2) in the same manner.
- the next channel e.g., channel 2
- scanning i.e., transmitting and receiving probe request/response on channel 2
- the scanning operation can also be performed in a passive scanning manner.
- passive scanning an STA performing scanning moves through channels and waits for a beacon frame.
- a beacon frame is one of the management frames defined in IEEE 802.11, and is periodically transmitted to notify the existence of a wireless network and to enable an STA performing scanning to find a wireless network and participate in the wireless network.
- an AP In a BSS, an AP periodically transmits a beacon frame, and in an IBSS, STAs in the IBSS take turns transmitting beacon frames.
- an STA performing scanning receives a beacon frame, it stores information about the BSS included in the beacon frame and moves to another channel, recording beacon frame information on each channel.
- An STA receiving a beacon frame stores information related to the BSS included in the received beacon frame, moves to the next channel, and performs scanning on the next channel in the same manner. Comparing active scanning and passive scanning, active scanning has the advantage of lower delay and power consumption than passive scanning.
- step S320 After the STA discovers the network, an authentication process may be performed in step S320.
- This authentication process may be referred to as a first authentication process to clearly distinguish it from the security setup operation of step S340 described below.
- the authentication process includes the STA sending an authentication request frame to the AP, and the AP sending an authentication response frame to the STA in response.
- the authentication frame used for the authentication request/response corresponds to a management frame.
- the authentication frame may include information such as an authentication algorithm number, an authentication transaction sequence number, a status code, a challenge text, a Robust Security Network (RSN), a Finite Cyclic Group, etc. These are just some examples of information that may be included in an authentication request/response frame, and may be replaced by other information or may include additional information.
- RSN Robust Security Network
- the STA may transmit an authentication request frame to the AP.
- the AP may determine whether to allow authentication for the STA based on information included in the received authentication request frame.
- the AP may provide the result of the authentication processing to the STA through an authentication response frame.
- an association process may be performed in step S330.
- the association process includes a process in which the STA transmits an association request frame to the AP, and in response, the AP transmits an association response frame to the STA.
- the association request frame may include information about various capabilities, a beacon listen interval, a service set identifier (SSID), supported rates, supported channels, RSN, mobility domains, supported operating classes, a Traffic Indication Map Broadcast request, interworking service capabilities, etc.
- the association response frame may include information about various capabilities, a status code, an Association ID (AID), supported rates, an Enhanced Distributed Channel Access (EDCA) parameter set, a Received Channel Power Indicator (RCPI), a Received Signal to Noise Indicator (RSNI), a mobility domain, a timeout interval (e.g., association comeback time), overlapping BSS scan parameters, a TIM broadcast response, a Quality of Service (QoS) map, etc.
- AID Association ID
- EDCA Enhanced Distributed Channel Access
- RCPI Received Channel Power Indicator
- RSNI Received Signal to Noise Indicator
- timeout interval e.g., association comeback time
- overlapping BSS scan parameters e.g., TIM broadcast response
- a security setup process may be performed in step S340.
- the security setup process of step S340 may be referred to as an authentication process through a Robust Security Network Association (RSNA) request/response
- the authentication process of step S320 may be referred to as a first authentication process
- the security setup process of step S340 may be referred to simply as an authentication process.
- RSNA Robust Security Network Association
- the security setup process of step S340 may include a process of performing private key setup, for example, through 4-way handshaking via an Extensible Authentication Protocol over LAN (EAPOL) frame. Additionally, the security setup process may be performed according to a security method not defined in the IEEE 802.11 standard.
- EAPOL Extensible Authentication Protocol over LAN
- FIG. 4 is a diagram for explaining a backoff process to which the present disclosure can be applied.
- the basic access mechanism of MAC is the CSMA/CA (Carrier Sense Multiple Access with Collision Avoidance) mechanism.
- the CSMA/CA mechanism is also called the Distributed Coordination Function (DCF) of IEEE 802.11 MAC, and basically adopts the "listen before talk" access mechanism.
- DCF Distributed Coordination Function
- the AP and/or STA may perform a Clear Channel Assessment (CCA) to sense the wireless channel or medium for a predetermined time period (e.g., a DCF Inter-Frame Space (DIFS)) before starting transmission. If the sensing result determines that the medium is in an idle state, the AP and/or STA may start transmitting frames through the medium.
- CCA Clear Channel Assessment
- DIFS DCF Inter-Frame Space
- the AP and/or STA may not start its own transmission, but may wait for a delay period (e.g., a random backoff period) for medium access and then attempt to transmit frames.
- a delay period e.g., a random backoff period
- the IEEE 802.11 MAC protocol provides a Hybrid Coordination Function (HCF).
- the HCF is based on the DCF and the Point Coordination Function (PCF).
- the PCF is a polling-based synchronous access method in which all receiving APs and/or STAs periodically poll to receive data frames.
- the HCF has EDCA (Enhanced Distributed Channel Access) and HCCA (HCF Controlled Channel Access).
- EDCA is a contention-based access method in which a provider provides data frames to multiple users, and HCCA uses a non-contention-based channel access method using a polling mechanism.
- the HCF includes a medium access mechanism for improving the QoS (Quality of Service) of a wireless LAN, and can transmit QoS data in both a contention period (CP) and a contention-free period (CFP).
- QoS Quality of Service
- a random backoff period When an occupied/busy medium changes to an idle state, multiple STAs may attempt to transmit data (or frames). As a measure to minimize collisions, each STA may select a random backoff count, wait for a corresponding slot time, and then attempt to transmit.
- the random backoff count has a pseudo-random integer value and may be determined as one of the values in the range of 0 to CW.
- CW is a contention window parameter value.
- the CW parameter is initially given CWmin, but may take a double value in case of a transmission failure (e.g., when an ACK for a transmitted frame is not received).
- the STA continues to monitor the medium while counting down the backoff slots according to the determined backoff count value. If the medium is monitored as occupied, the countdown stops and waits, and when the medium becomes idle, the remaining countdown is resumed.
- STA3 when a packet to be transmitted reaches the MAC of STA3, STA3 can check that the medium is idle for DIFS and transmit the frame right away. The remaining STAs monitor whether the medium is occupied/busy and wait. In the meantime, data to be transmitted may also occur in each of STA1, STA2, and STA5, and each STA can perform a countdown of the backoff slot according to a random backoff count value selected by each STA after waiting for DIFS when the medium is monitored as idle. Assume that STA2 selects the smallest backoff count value and STA1 selects the largest backoff count value.
- this example shows a case where the remaining backoff time of STA5 is shorter than the remaining backoff time of STA1 when STA2 finishes the backoff count and starts frame transmission.
- STA1 and STA5 briefly stop the countdown and wait while STA2 occupies the medium.
- STA1 and STA5 resume the stopped backoff count after waiting for DIFS. That is, they can start frame transmission after counting down the remaining backoff slots by the remaining backoff time. Since the remaining backoff time of STA5 is shorter than that of STA1, STA5 starts frame transmission. While STA2 occupies the medium, STA4 may also have data to transmit.
- STA4 From STA4's perspective, when the medium becomes idle, it waits for DIFS, performs a countdown according to the random backoff count value it selected, and starts frame transmission.
- the remaining backoff time of STA5 coincidentally matches the random backoff count value of STA4, and in this case, a collision may occur between STA4 and STA5. If a collision occurs, neither STA4 nor STA5 will receive an ACK, resulting in a failure in data transmission. In this case, STA4 and STA5 can select a random backoff count value and perform a countdown after doubling the CW value.
- STA1 waits while the medium is occupied by transmissions from STA4 and STA5, and when the medium becomes idle, it waits for DIFS, and then starts transmitting frames after the remaining backoff time has elapsed.
- a data frame is a frame used for transmitting data forwarded to a higher layer, and can be transmitted after a backoff performed after DIFS elapses from when the medium becomes idle.
- a management frame is a frame used for exchanging management information that is not forwarded to a higher layer, and is transmitted after a backoff performed after an IFS such as DIFS or PIFS (Point coordination function IFS) elapses.
- Subtype frames of the management frame include a beacon, an association request/response, a re-association request/response, a probe request/response, and an authentication request/response.
- a control frame is a frame used to control access to the medium.
- the subtype frames of the control frame include RTS (Request-To-Send), CTS (Clear-To-Send), ACK (Acknowledgment), PS-Poll (Power Save-Poll), Block ACK (BlockAck), Block ACK Request (BlockACKReq), NDP notification (null data packet announcement), and Trigger. If the control frame is not a response frame to the previous frame, it is transmitted after the backoff performed after the DIFS (DIFS), and if it is a response frame to the previous frame, it is transmitted without the backoff performed after the SIFS (short IFS).
- DIFS DIFS
- SIFS short IFS
- a QoS (Quality of Service) STA can transmit a frame after a backoff performed after the AIFS (arbitration IFS) for the access category (AC) to which the frame belongs, that is, AIFS[i] (where i is a value determined by the AC), has elapsed.
- AIFS aromatic IFS
- the frames for which AIFS[i] can be used can be data frames, management frames, and also control frames that are not response frames.
- FIG. 5 is a diagram for explaining a CSMA/CA-based frame transmission operation to which the present disclosure can be applied.
- the CSMA/CA mechanism includes virtual carrier sensing in addition to physical carrier sensing in which an STA directly senses the medium.
- Virtual carrier sensing is intended to complement problems that may occur in medium access, such as the hidden node problem.
- the MAC of the STA may utilize a Network Allocation Vector (NAV).
- NAV Network Allocation Vector
- the NAV is a value that indicates to other STAs the remaining time until the medium becomes available, by an STA that is currently using or has the right to use the medium. Therefore, the value set as NAV corresponds to the period during which the medium is scheduled to be used by the STA transmitting the corresponding frame, and the STA that receives the NAV value is prohibited from accessing the medium during the corresponding period.
- the NAV may be set based on the value of the "duration" field of the MAC header of the frame.
- STA1 wants to transmit data to STA2, and STA3 is in a position to overhear part or all of the frames transmitted and received between STA1 and STA2.
- a mechanism using RTS/CTS frames may be applied.
- STA3 may determine that the carrier sensing result of the medium is idle. That is, STA1 may correspond to a hidden node to STA3.
- STA2 may transmitting, STA3 may determine that the carrier sensing result of the medium is idle. That is, STA2 may correspond to a hidden node to STA3.
- STAs outside the transmission range of either STA1 or STA2, or STAs outside the carrier sensing range for transmission from STA1 or STA3 may not attempt to occupy the channel during data transmission and reception between STA1 and STA2.
- STA1 can determine whether a channel is occupied through carrier sensing.
- STA1 can determine a channel occupied idle state based on energy magnitude or signal correlation detected in the channel.
- STA1 can determine a channel occupied state using a network allocation vector (NAV) timer.
- NAV network allocation vector
- STA1 can transmit an RTS frame to STA2 after performing a backoff if the channel is idle during DIFS.
- STA2 can transmit a CTS frame, which is a response to the RTS frame, to STA1 after SIFS if it receives the RTS frame.
- STA3 can set a NAV timer for the subsequently transmitted frame transmission period (e.g., SIFS + CTS frame + SIFS + data frame + SIFS + ACK frame) using the duration information included in the RTS frame.
- STA3 can set a NAV timer for the subsequently transmitted frame transmission period (e.g., SIFS + data frame + SIFS + ACK frame) using the duration information included in the CTS frame.
- STA3 can overhear one or more of the RTS or CTS frames from one or more of STA1 or STA2, it can set a NAV accordingly.
- STA3 can update the NAV timer using the duration information contained in the new frame if it receives a new frame before the NAV timer expires. STA3 does not attempt to access the channel until the NAV timer expires.
- STA1 receives a CTS frame from STA2, it can transmit a data frame to STA2 after SIFS from the time when reception of the CTS frame is completed. If STA2 successfully receives the data frame, it can transmit an ACK frame in response to the data frame to STA1 after SIFS.
- STA3 can determine whether the channel is in use through carrier sensing if the NAV timer expires. If STA3 determines that the channel is not in use by other terminals during DIFS after the expiration of the NAV timer, it can attempt channel access after a contention window (CW) following a random backoff has elapsed.
- CW contention window
- FIG. 6 is a drawing for explaining an example of a frame structure used in a wireless LAN system to which the present disclosure can be applied.
- the PHY layer can prepare an MPDU (MAC PDU) to be transmitted by an instruction or primitive (meaning a set of instructions or parameters) from the MAC layer. For example, when a command requesting the start of transmission of the PHY layer is received from the MAC layer, the PHY layer can switch to transmission mode and transmit information (e.g., data) provided from the MAC layer in the form of a frame. In addition, when the PHY layer detects a valid preamble of the received frame, it monitors the header of the preamble and sends a command to the MAC layer notifying the start of reception of the PHY layer.
- MPDU MPDU
- an instruction or primitive meaning a set of instructions or parameters
- PPDU PHY layer Protocol Data Unit
- a basic PPDU may include a Short Training Field (STF), a Long Training Field (LTF), a SIGNAL (SIG) field, and a Data field.
- STF Short Training Field
- LTF Long Training Field
- SIG SIGNAL
- PPDU format may consist of only a Legacy-STF (L-STF), a Legacy-LTF (L-LTF), a Legacy-SIG (Legacy-SIG) field, and a Data field.
- RL-SIG RL-SIG
- U-SIG non-legacy SIG field
- non-legacy STF non-legacy LTF
- xx-SIG xx-SIG
- xx-LTF e.g., xx represents HT, VHT, HE, EHT, etc.
- STF is a signal for signal detection, AGC (Automatic Gain Control), diversity selection, precise time synchronization, etc.
- LTF is a signal for channel estimation, frequency error estimation, etc. STF and LTF can be said to be signals for OFDM physical layer synchronization and channel estimation.
- the SIG field may include various information related to PPDU transmission and reception.
- the L-SIG field may consist of 24 bits and may include a 4-bit Rate field, a 1-bit Reserved bit, a 12-bit Length field, a 1-bit Parity field, and a 6-bit Tail field.
- the RATE field may include information about a modulation and coding rate of data.
- the 12-bit Length field may include information about the length or time duration of the PPDU.
- the value of the 12-bit Length field may be determined based on the type of the PPDU. For example, for a non-HT, HT, VHT, or EHT PPDU, the value of the Length field may be determined as a multiple of 3.
- the value of the Length field can be determined as a multiple of 3 + 1 or a multiple of 3 + 2.
- the data field may include a SERVICE field, a Physical layer Service Data Unit (PSDU), a PPDU TAIL bit, and, if necessary, padding bits.
- PSDU Physical layer Service Data Unit
- PPDU TAIL bit may be used to return the encoder to the 0 state.
- padding bit may be used to adjust the length of the data field to a predetermined unit.
- MAC PDU is defined according to various MAC frame formats, and the basic MAC frame consists of a MAC header, frame body, and FCS (Frame Check Sequence).
- MAC frame consists of MAC PDU and can be transmitted/received through PSDU of the data part of PPDU format.
- the MAC header includes a Frame Control field, a Duration/ID field, an Address field, etc.
- the Frame Control field may include control information required for frame transmission/reception.
- the Duration/ID field may be set to a time for transmitting the corresponding frame, etc.
- the Address subfields may indicate a receiver address, a transmitter address, a destination address, and a source address of the frame, and some Address subfields may be omitted. For specific details of each subfield of the MAC header, including the Sequence Control, QoS Control, and HT Control subfields, refer to the IEEE 802.11 standard document.
- Null-Data PPDU (NDP) format refers to a PPDU format that does not include a data field. That is, NDP refers to a frame format that includes a PPDU preamble (i.e., L-STF, L-LTF, L-SIG fields, and additionally, non-legacy SIG, non-legacy STF, non-legacy LTF if present) in a general PPDU format, and does not include the remaining part (i.e., data field).
- a PPDU preamble i.e., L-STF, L-LTF, L-SIG fields, and additionally, non-legacy SIG, non-legacy STF, non-legacy LTF if present
- FIG. 7 is a diagram illustrating examples of PPDUs defined in the IEEE 802.11 standard to which the present disclosure can be applied.
- the basic PPDU format (IEEE 802.11a/g) includes L-LTF, L-STF, L-SIG, and Data fields.
- the basic PPDU format can also be called a non-HT PPDU format (Fig. 7(a)).
- the HT PPDU format (IEEE 802.11n) additionally includes HT-SIG, HT-STF, and HT-LFT(s) fields in the basic PPDU format.
- the HT PPDU format illustrated in Fig. 7(b) may be referred to as an HT-mixed format.
- an HT-greenfield format PPDU may be defined, which corresponds to a format that does not include L-STF, L-LTF, and L-SIG, and consists of HT-GF-STF, HT-LTF1, HT-SIG, one or more HT-LTF, and Data fields (not illustrated).
- VHT PPDU format includes VHT SIG-A, VHT-STF, VHT-LTF, and VHT-SIG-B fields in addition to the basic PPDU format (Fig. 7(c)).
- HE PPDU format (IEEE 802.11ax) additionally includes RL-SIG (Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), and PE (Packet Extension) fields in addition to the basic PPDU format (Fig. 7(d)).
- RL-SIG Repeated L-SIG
- HE-SIG-A HE-SIG-B
- HE-STF HE-LTF(s)
- PE Packet Extension
- some fields may be excluded or their lengths may vary.
- the HE-SIG-B field is included in a HE PPDU format for multi-users (MUs), and a HE PPDU format for single users (SUs) does not include the HE-SIG-B.
- a HE trigger-based (TB) PPDU format does not include the HE-SIG-B, and the length of the HE-STF field may vary to 8 microseconds (us).
- the HE ER (Extended Range) SU PPDU format does not include the HE-SIG-B field, and the length of the HE-SIG-A field can vary to 16us.
- RL-SIG can be configured identically to L-SIG.
- the receiving STA can determine that the received PPDU is a HE PPDU or an EHT PPDU described below based on the presence of RL-SIG.
- the EHT PPDU format may include the EHT MU (multi-user) PPDU of Fig. 7(e) and the EHT TB (trigger-based) PPDU of Fig. 7(f).
- the EHT PPDU format is similar to the HE PPDU format in that it includes an RL-SIG following an L-SIG, but it may include a U (universal)-SIG, an EHT-SIG, an EHT-STF, and an EHT-LTF following the RL-SIG.
- the EHT MU PPDU in Fig. 7(e) corresponds to a PPDU that carries one or more data (or PSDU) for one or more users. That is, the EHT MU PPDU can be used for both SU transmission and MU transmission.
- the EHT MU PPDU can correspond to a PPDU for one receiving STA or multiple receiving STAs.
- the EHT TB PPDU of Fig. 7(f) omits EHT-SIG compared to the EHT MU PPDU.
- An STA that has received a trigger for UL MU transmission e.g., a trigger frame or TRS (triggered response scheduling)
- TRS triggered response scheduling
- the L-STF, L-LTF, L-SIG, RL-SIG, U-SIG (Universal SIGNAL), and EHT-SIG fields can be encoded and modulated and mapped based on a predetermined subcarrier frequency interval (e.g., 312.5 kHz) so that even legacy STAs can attempt to demodulate and decode them. These can be referred to as pre-EHT modulated fields.
- the EHT-STF, EHT-LTF, Data, and PE fields can be encoded and modulated and mapped based on a predetermined subcarrier frequency interval (e.g., 78.125 kHz) so that they can be demodulated and decoded by an STA that successfully decodes a non-legacy SIG (e.g., U-SIG and/or EHT-SIG) and obtains the information included in the corresponding fields.
- a predetermined subcarrier frequency interval e.g., 78.125 kHz
- a non-legacy SIG e.g., U-SIG and/or EHT-SIG
- EHT modulated fields e.g., U-SIG and/or EHT-SIG
- the L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, and HE-SIG-B fields may be referred to as pre-HE modulation fields, and the HE-STF, HE-LTF, Data, and PE fields may be referred to as HE modulation fields.
- the L-STF, L-LTF, L-SIG, and VHT-SIG-A fields may be referred to as pre-VHT modulation fields
- the VHT STF, VHT-LTF, VHT-SIG-B, and Data fields may be referred to as VHT modulation fields.
- the U-SIG included in the EHT PPDU format of Fig. 7 can be configured based on, for example, two symbols (e.g., two consecutive OFDM symbols).
- Each symbol (e.g., OFDM symbol) for the U-SIG can have a duration of 4us, and the U-SIG can have a total duration of 8us.
- Each symbol of the U-SIG can be used to transmit 26 bits of information.
- each symbol of the U-SIG can be transmitted and received based on 52 data tones and 4 pilot tones.
- U-SIG can be configured in 20MHz units. For example, when an 80MHz PPDU is configured, the same U-SIG can be replicated in 20MHz units. That is, four identical U-SIGs can be included in an 80MHz PPDU. When the bandwidth exceeds 80MHz, for example, for a 160MHz PPDU, the U-SIG of the first 80MHz unit and the U-SIG of the second 80MHz unit can be different.
- a uncoded bits can be transmitted, and a first symbol of U-SIG (e.g., U-SIG-1 symbol) can transmit the first X bits of information out of the total A bits of information, and a second symbol of U-SIG (e.g., U-SIG-2 symbol) can transmit the remaining Y bits of information out of the total A bits of information.
- the A bits of information e.g., 52 uncoded bits
- the tail field can be used to terminate the trellis of the convolutional decoder and can be set to 0, for example.
- the A bit information transmitted by U-SIG can be divided into version-independent bits and version-dependent bits.
- U-SIG may be included in a new PPDU format (e.g., UHR PPDU format) not shown in FIG. 7, and in the format of the U-SIG field included in the EHT PPDU format and the format of the U-SIG field included in the UHR PPDU format, the version-independent bits may be the same, and some or all of the version-dependent bits may be different.
- the size of the version-independent bits of U-SIG can be fixed or variable.
- the version-independent bits can be assigned only to U-SIG-1 symbols, or to both U-SIG-1 symbols and U-SIG-2 symbols.
- the version-independent bits and the version-dependent bits can be called by various names, such as the first control bit and the second control bit.
- the version-independent bits of U-SIG may include a 3-bit PHY version identifier, which may indicate the PHY version (e.g., EHT, UHR, etc.) of the transmitted and received PPDU.
- the version-independent bits of U-SIG may include a 1-bit UL/DL flag field. The first value of the 1-bit UL/DL flag field relates to UL communication, and the second value of the UL/DL flag field relates to DL communication.
- the version-independent bits of U-SIG may include information about the length of a TXOP (transmission opportunity) and information about a BSS color ID.
- the version-dependent bits of the U-SIG may contain information that directly or indirectly indicates the type of the PPDU (e.g., SU PPDU, MU PPDU, TB PPDU, etc.).
- the U-SIG may further include information about bandwidth, information about an MCS technique applied to a non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.), information indicating whether a dual carrier modulation (DCM) technique (e.g., a technique for achieving an effect similar to frequency diversity by reusing the same signal on two subcarriers) is applied to the non-legacy SIG, information about the number of symbols used for the non-legacy SIG, information about whether the non-legacy SIG is generated over the entire band, etc.
- DCM dual carrier modulation
- Some of the information required for PPDU transmission and reception may be included in the U-SIG and/or the non-legacy SIG (e.g., EHT-SIG or UHR-SIG, etc.).
- information about the type of non-legacy LTF/STF e.g., EHT-LTF/EHT-STF or UHR-LTF/UHR-STF, etc.
- information about the length of the non-legacy LTF and the cyclic prefix (CP) length e.g., EHT-LTF/EHT-STF or UHR-LTF/UHR-STF, etc.
- information about the length of the non-legacy LTF and the cyclic prefix (CP) length e.g., information about the guard interval (GI) applied to the non-legacy LTF
- information about the preamble puncturing applicable to the PPDU e.g., information about the resource unit (RU) allocation, etc.
- RU resource unit
- Preamble puncturing may mean transmission of a PPDU in which no signal is present in one or more frequency units within the bandwidth of the PPDU.
- the size of the frequency unit (or the resolution of the preamble puncturing) may be defined as 20 MHz, 40 MHz, etc.
- preamble puncturing may be applied to a PPDU bandwidth greater than a predetermined size.
- non-legacy SIGs such as HE-SIG-B, EHT-SIG, etc. may include control information for the receiving STA.
- the non-legacy SIG may be transmitted through at least one symbol, and one symbol may have a length of 4 us.
- Information about the number of symbols used for EHT-SIG may be included in a previous SIG (e.g., HE-SIG-A, U-SIG, etc.).
- Non-legacy SIGs such as HE-SIG-B, EHT-SIG, etc.
- HE-SIG-B may contain common fields and user-specific fields. Common fields and user-specific fields may be coded separately.
- the common field may be omitted.
- the common field may be omitted, and multiple STAs may receive a PPDU (e.g., a data field of a PPDU) over the same frequency band.
- a PPDU e.g., a data field of a PPDU
- multiple users may receive a PPDU (e.g., a data field of a PPDU) over different frequency bands.
- the number of user-specific fields can be determined based on the number of users.
- One user block field can include at most two user fields.
- Each user field can be associated with an MU-MIMO allocation or associated with a non-MU-MIMO allocation.
- the common field may include CRC bits and Tail bits, the length of the CRC bits may be determined as 4 bits, the length of the Tail bits may be determined as 6 bits and may be set to 000000.
- the common field may include RU allocation information.
- the RU allocation information may include information about the location of RUs to which multiple users (i.e., multiple receiving STAs) are allocated.
- An RU may include multiple subcarriers (or tones). An RU may be used when transmitting signals to multiple STAs based on the OFDMA technique. An RU may also be defined when transmitting signals to one STA. Resources may be allocated in RU units for non-legacy STFs, non-legacy LTFs, and Data fields.
- an applicable size of RU can be defined.
- the RU may be defined identically or differently for the applicable PPDU format (e.g., HE PPDU, EHT PPDU, UHR PPDU, etc.).
- the RU arrangements of HE PPDU and EHT PPDU may be different.
- the applicable RU size, RU number, RU position, DC (direct current) subcarrier position and number, null subcarrier position and number, guard subcarrier position and number, etc. for each PPDU bandwidth can be referred to as a tone plan.
- a tone plan for a wide bandwidth can be defined in the form of multiple repetitions of a tone plan for a low bandwidth.
- RUs of different sizes can be defined, such as 26-tone RU, 52-tone RU, 106-tone RU, 242-tone RU, 484-tone RU, 996-tone RU, 2 ⁇ 996-tone RU, 4 ⁇ 996-tone RU, etc.
- a multiple RU is distinct from multiple individual RUs and corresponds to a group of subcarriers consisting of multiple RUs.
- one MRU can be defined as 52+26-tones, 106+26-tones, 484+242-tones, 996+484-tones, 996+484+242-tones, 2 ⁇ 996+484-tones, 3 ⁇ 996-tones, or 3 ⁇ 996+484-tones.
- multiple RUs constituting one MRU may or may not be consecutive in the frequency domain.
- the specific size of the RU may be reduced or expanded. Therefore, the specific size of each RU (i.e., the number of corresponding tones) in the present disclosure is not limited and is exemplary. In addition, within a given bandwidth (e.g., 20, 40, 80, 160, 320 MHz, ...) in the present disclosure, the number of RUs may vary depending on the RU size.
- each field in the PPDU formats of FIG. 7 are exemplary, and the scope of the present disclosure is not limited by the names.
- the examples of the present disclosure can be applied not only to the PPDU format exemplified in FIG. 7, but also to a new PPDU format in which some fields are excluded and/or some fields are added based on the PPDU formats of FIG. 7.
- MAP multi-access point
- MAP operation can be defined as an operation between a master AP (or sharing AP) and a slave AP (or shared AP).
- the master AP initiates and controls MAP operations for transmission and reception between multiple APs.
- the master AP groups slave APs and manages links with slave APs so that information can be shared between the slave APs.
- the master AP manages information about the BSSs that the slave APs are configuring and information about STAs that have formed associations with the BSSs.
- Slave APs can associate with the master AP and share control information, management information, and data traffic with each other. Slave APs perform the same basic functions of APs that can establish a BSS in a wireless LAN.
- an STA can associate with a slave AP or a master AP and form a BSS.
- the master AP and slave AP can perform direct transmission and reception with each other.
- the master AP and STA may not perform direct transmission and reception with each other.
- the slave AP e.g., the slave AP associated with the STA
- the slave AP can perform direct transmission and reception with the STA.
- One of the slave APs can become the master AP.
- MAP operation is a technique in which one or more APs transmit and receive information to one or more STAs.
- coordinated-time division multiple access C-TDMA
- C-OFDMA coordinated-orthogonal frequency division multiple access
- C-SR coordinated-spatial reuse
- C-BF coordinated beamforming
- C-BF coordinated beamforming
- joint beamforming techniques that cooperatively perform simultaneous transmission and reception can also be applied to the MAP operation.
- FIG. 8 is a diagram for explaining various transmission and reception techniques in a MAP environment to which the present disclosure can be applied.
- a BSS AP transmits to a BSS STA
- it can be called STX (single transmission).
- STX single transmission
- the performance of transmission and reception for users/STAs located at the cell edge is reduced due to interference with adjacent APs.
- Fig. 8(a) when AP1 and AP2 transmit to STA1 and STA2, respectively, at the same time in the same frequency bandwidth, a collision may occur on the wireless medium.
- MAP performance can be improved by reducing inter-symbol interference (ISI) through cooperation between neighboring APs, or by performing joint transmissions.
- ISI inter-symbol interference
- interference can be avoided by having AP1 transmit to STA1 in the first bandwidth and AP2 transmit to STA2 in the second bandwidth at the same time.
- the example of Fig. 8(c) shows a cooperative beamforming or nulling technique in which AP1 nulls interference to AP2 and/or STA2 while transmitting to STA1, and AP2 nulls interference to AP1 and/or STA1 while transmitting to STA2.
- JTX Joint transmission
- JRX joint reception
- the authentication process can be performed in an open system manner, and the association process can be performed.
- This process can be said to be step 0 of searching for support for a robust security network (RSN) and establishing authentication and association.
- RSSN robust security network
- step 1 of user authentication by IEEE 802.1X/EAP (extensible authentication protocol) or PSK (pre-shared key) and obtaining a pairwise master key (PMK) can be performed.
- the mutual authentication method applied here can include 802.1X/EAP, PSK, or simultaneous authentication of equals (SAE).
- the PMK can be generated from the MSK (master session key) after authentication between the STA and RADIUS (remote authentication dial-in user service).
- PSK remote authentication dial-in user service
- the AP and STA can directly set the PMK in the same way as the PSK.
- the AP and STA can directly set the PMK by using the operation value of the mutual authentication and authentication process through the SAE authentication process.
- step 2 may be performed to verify whether the other party holds the same PMK using an EAPoL-Key frame, and to generate and share an encryption key.
- Step 2 may include a process of mutually verifying PMK generation and generating and transferring a group key (e.g., a group temporal key (GTK)) through 4-way handshaking.
- a pairwise transient key (PTK), a key confirmation key (KCK), a key encryption key (KEK), and a temporal key (TK) may be generated through the 4-way handshaking.
- PMK can be generated from MSK
- PTK can be generated from PMK.
- PTK is set separately as KCK, KEK, and TK.
- GTK can be generated from AP and delivered to STA. If AP wants to generate a new GTK, it can perform handshaking with STA and deliver new GTK to STA.
- the same MSK is set between the STA and the AS based on the user authentication result between the STA and the authentication server (AS), and the AS transfers the MSK to the AP.
- the STA and the AP can verify whether they have the PMK, which is a symmetric key generated from the MSK, through 4-way handshaking.
- the authentication procedure can be replaced by mutually verifying through 4-way handshaking whether the PMK generated from the PSK set in advance between the AP and the STA is secured.
- SAE the PMK set in advance between the AP and the STA can be mutually verified through 4-way handshaking.
- the STA and the AP have the same PMK by mutually verifying that they generated the same PTK. For example, it is also possible to verify whether the PMK is secured through Message 2 and Message 3 of the 4-way handshaking. Specifically, in Message 2, the STA can transmit the KCK of the PTK it generated to the AP by including it in the Key MIC field. In Message 3, the AP can transmit the KCK of the PTK it generated to the STA by including it in the Key MIC field. Through this, the STA (AP) can verify that the AP (STA) generated the same PTK as its PTK, thereby confirming that the AP (STA) has the same PMK as itself. Meanwhile, in Message 1, the value of the Key MIC field can be set to 0, and in Message 4, the KCK value can be included in the Key MIC field.
- a secret key can be generated to encrypt data to be transmitted and received between the STA and the AP in step 2.
- a different secret key is generated for each STA associated with an AP, and another secret key is generated when the STA is re-associated with another AP.
- step 3 data encryption can be performed using TKIP (temporal key integrity protocol), CCMP (cipher-block chaining message authentication code protocol), GCMP (Galois/Counter Mode protocol), etc., and this can be referred to as step 3.
- TKIP temporary key integrity protocol
- CCMP cipher-block chaining message authentication code protocol
- GCMP Galois/Counter Mode protocol
- the aforementioned MSK, PSK, PMK, PTK, KCK, KEK, and TK correspond to pairwise keys, that is, keys that form a pair between the AP and the STA.
- the group key can be generated based on the GMK (group master key) for the AP to generate a secret key for a group-addressed frame, such as a beacon frame.
- the GMK is randomly set by the AP.
- the GTK (group temporal key) is generated from the GMK by the PRF (pseudorandom function) function, and corresponds to a one-way group key from the AP to the STA.
- FIG. 9 is a diagram illustrating a 4-way handshaking procedure to which the present disclosure can be applied.
- the STA corresponds to the side requesting authentication (supplicant), and the AP corresponds to the side performing authentication (authenticator).
- 4-way handshaking can be performed to generate and verify PTK and GTK between the AP and STA when the STA possesses or knows the PMK, and the AP possesses or knows the PMK and GMK.
- ANonce and SNonce correspond to arguments used in the PRF function used for generating PTK.
- ANonce may correspond to a random number generated by the access point (i.e., authenticator).
- SNonce may correspond to a random number generated by the STA (i.e., supplicant).
- the PRF function may correspond to a function that generates PTK based on, for example, PMK, ANonce, SNonce, MAC address of the supplicant, and MAC address of the authenticator.
- Message 1 of step S810 is transmitted from the AP to the STA in a unicast manner, and the EAPOL-key frame may include ANonce information. If the AP generates a PMK, the key data field of the EAPOL-key frame may include PMKID.
- the STA may generate a PTK based on the information received from the AP, and may generate KCK, KEK, and TK based on the PTK.
- the EAPOL-key frame may include SNonce information and a key MIC (message integrity code).
- the key MIC of the message 2 may have a value based on a KCK generated by the STA.
- the AP may generate a PTK based on information received from the STA, and may generate a KCK, a KEK, and a TK based on the PTK.
- the AP may verify whether the AP and the STA have generated the same PTK based on whether the KCK value of the PTK generated based on the value included in the message 2 and the KCK value related to the key MIC value included in the message 2 are the same.
- the AP may generate a GTK if necessary. The generation of the GTK may be generated from the GMK by the AP without the involvement of the STA.
- Message 3 of step S830 is transmitted from the AP to the STA in a unicast manner, and the EAPOL-key frame may include MIC (i.e., corresponding to the KCK value of the PTK generated by the AP) and encrypted GTK information.
- the encrypted GTK of message 3 may be encrypted based on the KEK generated by the AP and included in the key data field.
- the STA may store the PTK in the PTK-SA (PTK-Security Association) and the GTK in the GTK-SA.
- PTK-SA PTK-Security Association
- Message 4 of step S840 is transmitted from the STA to the AP in a unicast manner, and the EAPOL-key frame may include MIC information.
- the AP may store the PTK in PTK-SA and the GTK in GTK-SA.
- the virtual control port that blocks all traffic is unblocked (ubblock), and encrypted traffic can be sent and received.
- all unicast traffic can be encrypted by PTK, and all multicast/broadcast traffic can be encrypted by GTK.
- cryptographic mechanisms can include counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol (CCMP), Galois/Counter Mode protocol (GCMP), etc.
- CTR counter mode
- CBC-MAC cipher-block chaining message authentication code
- GCMP Galois/Counter Mode protocol
- RSNA security may include algorithms and procedures such as temporal key integrity protocol (TKIP), CCMP, GCMP, broadcast/multicast integrity protocol (BIP), RSNA establishment and termination procedures, and key management procedures (e.g., key distribution).
- TKIP temporal key integrity protocol
- CCMP CCMP
- GCMP GCMP
- BIP broadcast/multicast integrity protocol
- RSNA establishment and termination procedures may include IEEE 802.1X authentication, simultaneous authentication of equals (SAE) authentication, and opportunistic wireless encryption (OWE) defined in Internet Engineering Task Force (IETF) request for comments (RFC) 8110.
- SAE simultaneous authentication of equals
- OBE opportunistic wireless encryption
- CCMP counter mode (CTR) with cipher-block chaining message authentication code (CBC-MAC) protocol.
- CCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection.
- CCMP is based on CCM of AES (advanced encryption standard) encryption algorithm.
- CCM combines CTR for data confidentiality and CBC-MAC for authentication and integrity.
- CCM can protect the integrity of both MPDU data fields and selected parts of MPDU header (MAC header).
- FIG. 9 is a diagram illustrating an example of an expanded CCMP MPDU to which the present disclosure can be applied.
- CCMP-128 processing enlarges the original MPDU size by 16 octets (i.e., 8 octets for the CCMP header field and 8 octets for the MIC field).
- CCMP-256 processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the CCMP header field and 16 octets for the MIC field).
- the CCMP header field is constructed from the packet number (PN), extended initialization vector (ExtIV), and key ID subfields.
- the PN is a 48-bit PN expressed as an array of 6 octets.
- PN5 is the most significant octet of the PN, and PN0 is the least significant octet.
- the third octet of the CCMP header is reserved.
- the ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for CCMP, bits 6 (B6) and 7 (B7) are the key ID subfield, and the remaining bits of the key ID octet are reserved.
- FIG. 10 illustrates a CCMP encapsulation block diagram to which the present disclosure can be applied.
- Additional authentication data can be constructed from the MAC header of the plaintext MPDU.
- a Nonce can be constructed based on address 2 (A2) and priority of the plaintext MPDU and an incremented PN.
- the AAD and Nonce can be used for CCM encryption together with data and TK.
- a CCMP header can be constructed based on the incremented PN and key ID.
- the data and MIC which are the results of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, such as the example of FIG. 9.
- Figure 11 shows an example of the format of conventional AAD.
- FIG. 11(a) may correspond to an example of a legacy AAD construction for a PV0 MPDU.
- the FC (frame control), A1 (address 1), A2 (address 2), A3 (address 3), and SC (sequence control) fields may always be included in the legacy AAD if they are included in the MAC header.
- the length of the AAD may vary depending on the presence or absence of the QC (QoS Control) field and the A4 (address 4) field.
- the AAD length may be 22 octets, if QC is present and A4 is absent, the AAD length may be 24 octets, if QC is absent and A4 is present, the AAD length may be 28 octets, and if both QC and A4 are present, the AAD length may be 30 octets.
- the existing AAD does not include the Duration/ID field of the MAC header, nor does it include the HT control field of the MAC header. This is to prevent fields whose contents can be changed or inserted/deleted during operations such as retransmission from being included in the existing AAD.
- some subfields of the Frame Control (FC) field of the MAC header may be masked-out.
- Masking-out means that the value of the corresponding subfield/fields of the MAC header is changed to 0 to be included in the AAD.
- the subfields that are masked out in the FC field of the existing AAD are as follows:
- the three LSBs i.e., bits 4, 5, and 6) of the subtype subfield of the data frame are masked out, and bit 7 is not modified;
- the retry subfield is masked out
- the power management subfield (i.e. bit 12) is masked out
- the protected frame subfield i.e., bit 14
- is not modified i.e., left as 1
- +HTC subfield i.e. bit 15
- sequence number subfield in the sequence control (SC) field of a legacy AAD can be masked out.
- the QC field may be included in the existing AAD if one or more of the MSDU priority subfield, the QC TID (traffic identifier) subfield, the A-MSDU capable subfield, the A-MSDU present subfield, and the A-MSDU type subfield are present in the MAC header. Other subfields in the QC field of the existing AAD may be masked out.
- the end of service period (EOSP) subfield, the ACK policy indicator subfield, the TXOP limit subfield, the queue size subfield, the TXOP duration requested subfield, and the AP PS buffer state subfield may be masked out and not used in the existing AAD configuration.
- FIG. 12 illustrates a CCMP decapsulation block diagram to which the present disclosure can be applied.
- AAD can be constructed from the MAC header of the encrypted MPDU. Nonce can be constructed based on A2 and priority of the encrypted MPDU and PN. AAD and Nonce can be used for CCM decryption together with MIC, data and key. Data resulting from CCM decryption can be obtained as a plaintext MPDU through a replay check together with the MAC header. The replay check can be based on the PN and a replay counter.
- BIP provides data integrity and replay protection for group-addressed robust management frames after establishment of an integrity group temporal key security association (IGTKSA).
- BIP provides data integrity and replay protection for beacon frames after establishment of a beacon IGTKSA (BIGTKSA).
- BIP can compute an MMPDU (MAC management PDU) MIC using the IGTK or BIGTK.
- the management MIC element (MME) can be located after all other elements of the management frame body and before the FCS. That is, the MME can be included as the last element of the management frame body.
- the MME can include an element ID field, a length field, a key ID field, an IPN (IGTK packet number)/BIPN (BIGTK packet number) field, and a MIC field.
- the existing AAD for BIP can be constructed based on FC, A1, A2, A3, and the Retry subfield (bit 11), Power Management subfield (bit 12), and More Data subfield (bit 13) within FC are masked out, and other subfields may not be modified.
- GCMP is a protocol that provides data confidentiality, authentication, integrity, and replay protection.
- EHT RSNA STA can support GCMP-256.
- GCMP is based on GCM of AES (advanced encryption standard) encryption algorithm. GCM can protect the integrity of both MPDU data fields and selected parts of MPDU header (MAC header).
- AES advanced encryption standard
- FIG. 13 is a diagram illustrating an example of an expanded GCMP MPDU to which the present disclosure may be applied.
- GCMP processing enlarges the original MPDU size by 24 octets (i.e., 8 octets for the GCMP header field and 16 octets for the MIC field).
- the CCMP header field is constructed from the packet number (PN) and key ID subfields.
- the PN is a 48-bit PN expressed as an array of 6 octets.
- PN5 is the most significant octet of the PN, and PN0 is the least significant octet.
- the third octet of the GCMP header is reserved.
- the ExtIV subfield (bit 5 (B5)) of the key ID octet is always set to 1 for GCMP, bit 6 (B6) and bit 7 (B7) are the key ID subfields, and the remaining bits of the key ID octet are reserved.
- Figure 14 illustrates a GCMP encapsulation block diagram to which the present disclosure can be applied.
- Additional authentication data can be constructed from the MAC header of the plaintext MPDU.
- a Nonce can be constructed based on address 2 (A2) of the plaintext MPDU and an incremented PN.
- the AAD and Nonce can be used for GCM encryption together with data and TK.
- a GCMP header can be constructed based on the incremented PN and key ID.
- the data which is the result of CCM encryption, can form an encrypted MPDU together with the MAC header and the CCMP header, such as the example of FIG. 13.
- Figure 15 illustrates a GCMP decapsulation block diagram to which the present disclosure can be applied.
- AAD can be constructed from the MAC header of the encrypted MPDU.
- Nonce can be constructed based on A2 and PN of the encrypted MPDU.
- AAD and Nonce can be used for GCM decryption together with data and a key.
- Data resulting from GCM decryption can be obtained as a plaintext MPDU through a replay check together with the MAC header.
- the replay check can be based on the PN and a replay counter.
- a block ACK frame corresponds to a control frame and can basically contain multiple ACKs for multiple data (e.g., MPDUs).
- a block ACK frame can have a format according to various variants as described below.
- FIG. 16 illustrates exemplary formats of block ACK frames to which the present disclosure can be applied.
- the Block ACK frame format may include a frame control field, a duration field, a receiver address (RA) field, a transmitter address (TA) field, a BA control field, a BA info field, and an FCS field.
- RA receiver address
- TA transmitter address
- FCS FCS field
- the BA control field may include a BA type subfield, a no memory kept subfield, a memory configuration tag subfield, a management ACK subfield, a TID_INFO subfield, and other bit positions may be reserved.
- the BA type subfield can indicate a BlockAck frame variant as shown in Table 1.
- the No Memory Keep subfield and the Memory Settings Tag subfield of the BA Control field may be reserved when transmitted by a STA other than an EDMG STA.
- the Management ACK subfield may be reserved in BlockAck variants other than the EDMG multi-TID BlockAck variant.
- the TID_INFO subfield may be defined based on the BlockAck frame variant type.
- the BA Information field may be defined based on the BlockAck frame variant type.
- the TID_INFO subfield of the BA Control field of the compressed BlockAck variant may indicate for which TID the corresponding BlockAck frame is transmitted.
- the BA Information field of the compressed BlockAck variant may include a Block ACK Start Sequence Control subfield and a Block ACK Bitmap subfield.
- the TID_INFO subfield of the BA Control field of the extended compressed BlockAck variant may indicate for which TID the BlockAck frame is requested.
- the BA Information field of the extended BlockAck variant may include a Block ACK Start Sequence Control subfield, a Block ACK Bitmap subfield, and a RBUFCAP subfield.
- the TID_INFO subfield of the BA Control field of a multi-STA BlockAck variant may be reserved.
- the BA Info field of a multi-STA BlockAck variant may contain one or more per AID TID info subfields.
- the AID TID information subfield may contain an AID11 subfield, an ACK type subfield, and a TID subfield.
- the AID11 subfield may contain 11 least significant bits (LSBs) of the AID of a non-AP STA for which the AID TID information subfield is intended.
- the value of the AID11 subfield may be set to 0.
- the value of the AID11 subfield, 2045 may be used as an identifier of any unassociated STA.
- the ACK type subfield and the TID subfield may be set to the values of 0 and 15, respectively.
- the presence and size of the subfields in the AID TID per-information subfield may be defined according to the value of the ACK type subfield and the value of the TID subfield.
- the AID TID per-information subfield includes an AID TID information subfield, and may additionally include a Block ACK Start Sequence Control subfield and/or a Block ACK Bitmap subfield.
- the AID TID per-information subfield includes the AID TID information subfield and the RA subfield, and the remaining octets may be reserved.
- the TID_INFO subfield of the BA control field of the multi-TID variant may indicate a value that subtracts 1 from the number of TIDs for the information reported in the BA information field.
- the BA information field of the multi-TID variant may include a unit that is repeated for each TID.
- a unit may include a 2-octet per-TID information, a 2-octet block ACK start sequence control subfield, and an 8-octet block ACK bitmap subfield.
- the per-TID information subfield may include a 2-bit ACK type, a 3-bit block ACK bitmap subfield length subfield, and a 4-bit TID subfield, and the remaining bits may be reserved.
- the TID_INFO subfield of the BA Control field of the GCR BlockAck variant may indicate for which TID the corresponding BlockAck frame is transmitted.
- the BA Info field of the GCR BlockAck variant may include a 2-octet Block ACK Start Sequence Control subfield, a 6-octet GCR Group Address subfield, and an 8-octet Block ACK Bitmap subfield.
- the TID_INFO subfield of the BA Control field of the GLK-GCR BlockAck variant may indicate for which TID the corresponding BlockAck frame is transmitted.
- the BA Info field of the GLK-GCR BlockAck variant may include a 2-octet Block ACK Start Sequence Control subfield, a 6-octet GCR Group Address subfield, and an 8-octet Block ACK Bitmap subfield.
- the TID_INFO subfield of the BA Control field of an EDMG Compression Variant may indicate for which TID a BlockAck frame is requested.
- the BA Information field of an EDMG Compression Variant may include a 2-octet Block ACK Start Sequence Control subfield, a variable-length Block ACK Bitmap subfield, and a 1-octet RBUFCAP subfield.
- the TID_INFO subfield of the BA Control field of an EDMG multi-TID variant may indicate a value that is the number of TIDs for which information is reported in the BA information field minus 1.
- the BA information field of an EDMG multi-TID variant may include a unit that is repeated for each TID.
- a unit may include a 2-octet per-TID information, a 2-octet block ACK start sequence control subfield, an 8/16/32/64/128-octet block ACK bitmap subfield, and a 1-octet RBUFCAP subfield.
- the per-TID information subfield may include a 2-bit ACK type, a 3-bit block ACK bitmap subfield length subfield, a 4-bit TID subfield, and the remaining bits may be reserved.
- TKIP Temporal Key Integrity Protocol
- CCMP/GCMP Temporal Key Integrity Protocol
- GTK group temporal key
- CCMP/GCMP is a security protocol that performs encryption/decryption, and TK based on PTK can be used for SU (single-user), and TK based on GTK can be used for MU (multi-user).
- CCMP/GCMP can ensure confidentiality and integrity for data frames and management frame(s).
- BIP-based integrity check can be performed using IGTK (integrity group temporal key).
- BIP-based integrity check can be performed using BIGTK (beacon integrity group temporal key).
- a TK based on IGTK/BIGTK is used to generate a MIC (message integrity code) for the frame body of the corresponding data frame, and an integrity check based on this can be performed. That is, unlike CCMP/GCMP, BIP can guarantee the integrity of only data frames and management frame(s).
- MPDUs are constructed based on CCMP and GCMP and the way MMPDUs (management MPDUs) are constructed based on BIP have the following differences:
- the transmitting STA encrypts the data portion with CCM/GCM, transmits the encrypted data, and the receiving STA can decrypt the received encrypted data.
- the transmitting STA does not encrypt the data portion, and can perform the corresponding protocol to generate a MIC for integrity check of the data of the frame body.
- the MPDU may be configured and transmitted/received in the order of a MAC header, a CCMP/GCMP header, encrypted data, a MIC (encrypted MIC in case of CCMP), and an FCS.
- the MPDU may be configured and transmitted/received in the order of a MAC header, a management frame body including an MME (management MIC element), and an FCS.
- MME management MIC element
- the MME replaces the role of the CCMP/GCMP header, it may include information on a Key ID field, IPN/BIPN, and MIC.
- protection is supported for management frames including data frames and beacon frames among group addressed frames.
- protection is not supported for control frames, and thus control frames are transmitted and received without any encryption/decryption and/or integrity check protocols being applied.
- control frames may include ACK frames and block ACK frames.
- a transmitting STA transmits data
- a receiving STA may transmit an ACK for the corresponding data to the transmitting STA.
- an STA supports A(aggregated)-MPDU, it may configure multiple ACKs corresponding to multiple MPDUs as A-MPDUs and transmit them in the form of block ACKs.
- a block ACK frame which is a type of control frame, may be configured so that one STA transmits a block Ack, a compressed block Ack, etc., as described above with reference to FIG. 16, or may be configured so that the Acks of multiple STAs are transmitted in the form of a block Ack, a multi-STA block Ack, etc.
- a multi-STA block Ack includes Ack information for multiple STAs, and it is possible to distinguish which STA transmitted the Ack information through the AID11 subfield in the BA information field of the BlockAck frame.
- the multi-STA block ACK frame individual information for each user is included in the BA information field, and duplicated/common information is included in the BA control field, thereby reducing overhead. If the information of the block Ack frame is exposed to a third STA (e.g., an attacker), the Ack information, which confirms whether data is transmitted and received between the transmitting STA and the receiving STA, may be damaged. Accordingly, an attack on the block Ack may reduce the data transmission and reception capability, which may lead to waste of power/memory usage.
- the present disclosure describes a novel security technique for ensuring confidentiality and integrity of block ACK frames transmitted and received between a transmitting STA and a receiving STA.
- all receiving STAs that receive the protected block ACK frame transmitted by the transmitting STA are UHR STAs (and/or STAs supporting technologies subsequent to UHR). That is, if a pre-UHR STA (e.g., an EHT STA, a HE STA, etc.) receives a protected block ACK frame according to the proposed method of the present disclosure, an error may occur during decoding of the protected block ACK frame.
- a pre-UHR STA e.g., an EHT STA, a HE STA, etc.
- examples of the present disclosure are described as representative examples of being applied to block ACK frames among control frames, the examples of the present disclosure can be extended and applied to other types of control frames other than block ACK frames.
- performing confidentiality and integrity check on a block ACK frame can be interpreted as extending and applying BIP/CCMP/GCMP to a block ACK frame.
- additional provisions for control frames may be defined for the previously defined BIP/CCMP/GCMP, or a separate protocol based on BIP/CCMP/GCMP for confidentiality and integrity check of control frames may be newly defined.
- an STA may be an AP STA or a non-AP STA.
- FIG. 17 is a diagram for explaining the operation of the first STA according to the present disclosure.
- the first STA can receive a protected block ACK (BA) frame from the second STA based on a specific protocol.
- BA protected block ACK
- step S1720 the first STA can generate AAD based on the BA frame.
- AAD can be generated based on the plain text of the received BA frame. That is, AAD can be generated based on information in the plain text state, excluding the portion where the protection information is located, falls within the calculation range of the MIC, or is encrypted, within the protected BA frame.
- AAD may be based on one or more fields included in the MAC header of the BA frame. Or, AAD may be based on one or more subfields included in the MAC header of the BA frame and one or more subfields included in the BA control field of the BA frame. Or, AAD may be based on one or more subfields included in the MAC header of the BA frame and one or more subfields included in the BA information field of the BA frame.
- AAD may be configured based on one or more subfields among the remaining fields excluding the field in which the protection information field (or subfield) is located among the MAC header, BA control field, and BA information field of the BA frame.
- the protection information (sub)field may include one or more of a key ID, a packet number (PN), or a message integrity code (MIC).
- AAD may be configured based on one or more subfields among the remaining fields excluding one or more fields corresponding to the MIC calculation range among the MAC header, BA control field, and BA information field of the BA frame.
- the field in which the protection information (sub)field is located may correspond to the MIC calculation range.
- the AAD may be configured based on one or more subfields included in the MAC header, among the remaining fields excluding the BA control field, or the AAD may be configured based on one or more subfields included in the MAC header and one or more subfields included in the BA information field.
- the AAD may be configured based on one or more subfields included in the MAC header, among the remaining fields excluding the BA information field, or the AAD may be configured based on one or more subfields included in the MAC header and one or more subfields included in the BA control field.
- the AAD may be constructed based on one or more subfields included in the MAC header, which are fields other than the BA Control field and the BA Information field.
- AAD can be configured based on whether encryption is applied to one or more of the BA control field or BA information field of the BA frame.
- the AAD when encryption is applied to the BA control field and the BA information field, the AAD may be configured based on one or more subfields included in the MAC header. For example, when encryption is applied to the BA control field, the AAD may be configured based on one or more subfields included in the MAC header, or the AAD may be configured based on one or more subfields included in the MAC header and one or more subfields included in the BA information field. For example, when encryption is applied to the BA information field, the AAD may be configured based on one or more subfields included in the MAC header, or the AAD may be configured based on one or more subfields included in the MAC header and one or more subfields included in the BA control field.
- One or more subfields included in each of the MAC header, BA control field, or BA information field of the BA frame may be included identically in the AAD, some of the subfield(s) among them may be included identically in the AAD, or specific subfield(s) may be included in the AAD with some or all of their bit values changed/set to 0 (e.g., masked out).
- the subfields used for configuring AAD may be one or more of a frame control subfield, a duration subfield, a receiver address (RA) subfield, or a transmitter address (TA) subfield.
- the subfields below the frame control subfield namely, a protocol version subfield, a type subfield, a subtype subfield, a to DS (distribution system) subfield, a from DS subfield, a more fragments subfield, a retry subfield, a power management subfield, a more data subfield, a protection frame subfield, or a +HTC subfield, may also be used for configuring AAD.
- the subfields used for configuring the AAD may be one or more of the BA type subfield, the no memory kept subfield, the memory configuration tag subfield, the management ACK subfield, the TID_INFO subfield, or the subfield(s) corresponding to bit position 0 (B0) and one or more of the bit positions B5-B8.
- the subfields used for configuring AAD may be one or more of the Block Ack starting sequence control subfield or the Block ACK bitmap subfield.
- the subfields used for AAD configuration may be one or more of the related block ACK start sequence control subfield, block ACK bitmap subfield, and RBUFCAP (receiver buffer capacity) subfield.
- the subfields used for AAD configuration may be one or more of the per TID info subfield, the block ACK start sequence control subfield, or the block ACK bitmap subfield.
- the subfields used for AAD configuration may be one or more of the AID11 subfield, the ACK type subfield, the TID subfield, the AID TID information subfield, the block ACK start sequence control subfield, the block ACK bitmap subfield, or the RA subfield.
- the subfields used for AAD configuration may be one or more of the block ACK start sequence control subfield, the GCR group address subfield, or the block ACK bitmap subfield.
- the subfields used for AAD configuration may be one or more of the block ACK start sequence control subfield, the GCR group address subfield, or the block ACK bitmap subfield.
- the first STA may perform one or more of decryption or integrity check on the BA frame.
- One or more of the decryption or integrity check for the BA frame may be performed based on key information related to protection for the BA frame and the aforementioned AAD.
- the BA frame may include ACK information for data transmitted from the first STA to the second STA.
- the key information related to protection for the BA frame may be key information that is distinct from key information for protection of the data.
- indication information indicating whether protection for a BA frame is supported, an MPDU format of a protected BA frame, or one or more of a BlockAck AAD type may be exchanged between the first STA and the second STA.
- the indication information may be included in, for example, one or more of a beacon frame, a probe request frame, a probe response frame, an association request frame, an association response frame, a re-association request frame, and a re-association response frame; or may be included in a BA control field within a BA frame; or, when a specific protocol is an encryption protocol, may be included in an encryption protocol header (for example, a CCMP header, a GCMP header) within the BA frame.
- an encryption protocol header for example, a CCMP header, a GCMP header
- the BlockAck AAD type may indicate that the AAD is constructed based on one or more fields included in the MAC header; or that the AAD is constructed based on one or more fields included in the MAC header and one or more fields included in the BA control field; or that the AAD is constructed based on one or more fields included in the MAC header and one or more fields included in the BA information field.
- the protected frame subfield in the frame control subfield of the MAC header of the BA frame may be set to a specific predefined value. Accordingly, the first STA may confirm that the BA frame is a protected BA frame.
- the method described in the example of FIG. 17 may be performed by the first device (100) of FIG. 1.
- one or more processors (102) of the first device (100) of FIG. 1 may be configured to receive a protected BA frame based on a specific protocol through one or more transceivers (106); generate an AAD based on the BA frame; and perform one or more of decryption or integrity check on the BA frame based on the AAD.
- one or more memories (104) of the first device (100) may store commands for performing the method described in the example of FIG. 17 or the examples described below when executed by one or more processors (102).
- FIG. 18 is a diagram for explaining the operation of a second STA according to the present disclosure.
- the second STA may generate AAD for the BA frame based on a specific protocol.
- AAD can be generated based on a portion of the protected BA frame from which the receiving STA can obtain information in plaintext, excluding the portion where protection information is located, or which falls within the calculation range of the MIC, or which is encrypted.
- step S1820 the second STA can transmit a protected BA frame to the first STA based on AAD.
- the configuration of the protected BA frame and the instruction information transmitted or received between the first STA and the second STA for this purpose are the same as those described in the example of Fig. 17, so redundant description is omitted.
- the method described in the example of FIG. 18 may be performed by the second device (200) of FIG. 1.
- one or more processors (202) of the second device (200) of FIG. 1 may be configured to generate an AAD for a BA frame based on a specific protocol; and transmit a protected BA frame based on the AAD through one or more transceivers (206).
- one or more memories (204) of the second device (200) may store commands for performing the method described in the example of FIG. 18 or the examples described below when executed by one or more processors (202).
- the transmitting STA may share with the receiving STA information including whether it supports protection for the block Ack frame (e.g., protection based on BIP, CCMP, or GCMP).
- the transmitting STA may generate and share key information related to protection of the block Ack frame (e.g., key(s) used for integrity check and/or encryption/decryption).
- key(s) for individually addressed frames e.g., PTK or BAPTK, collectively referred to as PTK for clarity of description
- key(s) for group addressed frames e.g., GTK, IGTK, BIGTK, or BAGTK, collectively referred to as GTK for clarity of description
- a transmitting STA may construct a block Ack frame including information to be shared with receiving STA(s).
- the block Ack frame may be in plaintext form.
- the transmitting STA may construct an AAD for the block Ack frame, and apply protection (e.g., BIP, CCMP, or GCMP) to the block Ack frame based on the security key(s) (for the block Ack frame) shared with the receiving STA.
- a transmitting STA may transmit a block Ack frame including values/information to which protection is applied (e.g., result values/information based on application of BIP, CCMP, or GCMP).
- the transmitting STA may share/discuss in advance with the receiving STA information about the format in which the BIP-related protection information (sub)field is configured in the transmitted block Ack frame, the format in which the CCMP/GCMP MPDU format is configured, how to configure AAD for the block Ack frame, etc., or may transmit the information by including the information in the block Ack frame.
- the receiving STA may share with the transmitting STA information including whether it supports protection (e.g., BIP, CCMP, or GCMP-based protection) for the block Ack frame.
- protection e.g., BIP, CCMP, or GCMP-based protection
- the transmitting STA shares key information related to protection of the block Ack frame (e.g., key(s) used for integrity check and/or encryption/decryption) and/or information about MPDU format configuration
- the receiving STA may assume that the protection scheme is applied to the block Ack frame transmitted by the transmitting STA.
- the transmitting STA and the receiving STA may generate/negotiate/share the same key information (e.g., PTK/GTK, etc.) through a key generation process, or the key information generated by the transmitting STA may be transmitted to the receiving STA.
- a receiving STA may recognize that protection is applied to a block Ack frame transmitted from a transmitting STA based on information related to a pre-shared key(s), a configuration method of information for integrity check in the block Ack frame, and/or a configuration method of CCMP/GCMP MPDU formats, and a configuration method of AAD for the block Ack frame.
- the receiving STA may configure an AAD for the block Ack frame based on the block Ack frame.
- the AAD may be utilized for decryption and integrity check.
- the receiving STA may perform decryption and/or integrity check for the block Ack frame using the configured AAD and (pre-)shared/generated/agreed key(s) (e.g., PTK/GTK, etc.).
- FIGS. 17 and 18 may correspond to some of the various examples of the present disclosure.
- various examples of the present disclosure, including the examples of FIGS. 17 and 18, will be described in more detail.
- This embodiment relates to an AAD configuration scheme for protection against block Ack frames.
- AAD can be configured based on information included in the MAC header of the transmitted frame.
- the MAC header of a block Ack frame consists of a frame control field, a duration field, a receiver address (RA) field, and a transmitter address (TA) field (see, for example, FIG. 16).
- AAD for protection against a block Ack frame can be configured by utilizing fields located before the BA control field in the block Ack frame.
- AAD can be configured utilizing the frame control field, duration field, RA field, and/or TA field within the corresponding block Ack frame.
- FIG. 19 illustrates examples of AAD configuration for protecting block Ack frames according to an embodiment of the present disclosure.
- the AAD is configured to include all four fields, i.e., a frame control field, a duration field, an RA field, and a TA field, but is not limited thereto.
- the AAD for a block Ack frame may be configured to include only a frame control field, an RA field, and a TA field.
- the values of the lower subfields may all be included in the AAD, or specific subfield(s) may be changed/set to 0 (e.g., masked out) and included.
- the lower subfields of the frame control field may include a protocol version subfield, a type subfield, a subtype subfield, a to DS subfield, a from DS subfield, a more fragments subfield, a retry subfield, a power management subfield, a more data subfield, a protection frame subfield, a +HTC subfield, etc.
- AAD for protection against a block Ack frame can be configured by utilizing fields located before the BA information field in the block Ack frame.
- AAD may be configured by additionally utilizing the BA control field in addition to the frame control field, duration field, RA field, and/or TA field within the corresponding block Ack frame.
- the AAD is configured to include all fields located before the frame control field in the block Ack frame, but is not limited thereto.
- the AAD for a block Ack frame may be configured only with the frame control field, the RA field, the TA field, and the BA control field.
- BA control fields included in AAD for a block Ack frame are examples, and one of the examples below may be applied, or a combination of multiple examples may be applied.
- the values of all fields within a BA control field can be included in the AAD without change.
- the value(s) of some (sub)field(s) within the BA Control Field may be included in the AAD without change, and all or some bit(s) of the value(s) of other specific (sub)field(s) may be changed/set to 0 (e.g., masked-out) and included in the AAD.
- the specific bit/(sub)field(s) within the BA Control Field that may be changed/set to 0 may include one or more of the following items.
- BX indicates the X-th bit position.
- B0 and B5-B8 are currently defined as reserved bits, but if specific subfield(s) are defined for some/all of those bit positions, those subfields (some/all bits of them) may be included in the AAD with their values changed/set to 0, or may not be included in the AAD, or may be included in the AAD without changing their values.
- AAD for protection of block Ack frame can be configured by utilizing fields located before BA control field and BA information field in the block Ack frame.
- AAD can be configured based on all fields except BA control field in block Ack frame.
- AAD may be configured by additionally utilizing the BA information field in addition to the frame control field, duration field, RA field, and/or TA field within the corresponding block Ack frame.
- the AAD is configured to include all of the fields located before the BA control field in the block Ack frame and the BA information field, but is not limited thereto.
- the AAD for the block Ack frame may be configured only of the frame control field, the RA field, the TA field, and the BA information field.
- Various block Ack variants may be defined, identified by a BA type subfield included in a BA control field.
- the subfields included in a block Ack frame defined according to an extended compressed block Ack variant, a compressed block Ack variant, a groupcast with retries (GCR) block Ack variant, a multi-TID (traffic identifier) block Ack variant, a general link-groupcast with retries (GLK-GCR) block Ack variant, and a multi-STA block Ack variant may vary.
- one or more of the subfields included in the block Ack frame may be included in the AAD according to the block Ack variant.
- BA information fields included in AAD for a block Ack frame according to the present disclosure, and one of the examples below may be applied, or a combination of multiple examples may be applied.
- the values of all (sub)fields included in the BA information field in the block Ack frame can be included in the AAD for the block Ack frame without change.
- the values of the Block Ack starting sequence control subfield and the Block ACK bitmap subfield, which are included in the BA information field of the compressed BlockAck variant, may be included in the AAD for the Block Ack frame without change.
- the values of the Block ACK Start Sequence Control subfield, the Block ACK Bitmap subfield, and the RBUFCAP subfield, which are included in the BA Information field of the extended BlockAck variant, may be included in the AAD for the Block Ack frame without change.
- the values of the repeating units for each TID may be included in the AAD for a block Ack frame without change.
- One or more of the per AID TID info subfields (each of which is included in the BA info field of a multi-STA BlockAck variant: AID11 subfield, ACK type subfield, and TID subfield); or the AID TID info subfield, the Block ACK Start Sequence Control subfield, and/or the Block ACK Bitmap subfield; or the values of the AID TID info subfield, and the RA subfield may be included in the AAD for a Block Ack frame without change.
- the values of the 2-octet Block ACK Start Sequence Control subfield, the 6-octet GCR Group Address subfield, and the 8-octet Block ACK Bitmap subfield, which are included in the BA Information field of the GCR BlockAck variant, may be included in the AAD for a Block Ack frame without change.
- the values of the 2-octet Block ACK Start Sequence Control subfield, the 6-octet GCR Group Address subfield, and the 8-octet Block ACK Bitmap subfield, which are included in the BA Information field of the GLK-GCR BlockAck variant, may be included in the AAD for a Block Ack frame without change.
- the value(s) of some (sub)field(s) of the BA Information field within the block Ack frame are included in the AAD without change, and all or part of the bit(s) of the value(s) of other specific (sub)field(s) may be changed/set to 0 (e.g., masked-out) and included in the AAD.
- the specific bit/(sub)field(s) within the BA Information field that may be changed/set to 0 may include one or more of the following items:
- Block Ack starting sequence control subfield and the Block ACK bitmap subfield included in the BA information field of the compressed BlockAck variant may be included in the AAD for the Block Ack frame with some/all of its bits changed/set to 0.
- Block ACK Start Sequence Control subfield may be included in the AAD for the Block Ack frame with some/all of their bits changed/set to 0.
- One or more of the repeating units for each TID included in the BA info field of a multi-TID BlockAck variant may be included in the AAD for a block Ack frame with some/all of its bits changed/set to 0.
- One or more of the per AID TID info subfields (each of which is included in the per AID TID info subfield: AID11 subfield, ACK type subfield, and TID subfield); or the AID TID info subfield, the Block ACK Start Sequence Control subfield and/or the Block ACK Bitmap subfield; or one or more of the AID TID info subfield and the RA subfield may be included in the AAD for the Block Ack frame with some/all of their bits changed/set to 0.
- One or more of the 2-octet Block ACK Start Sequence Control subfield, the 6-octet GCR Group Address subfield, and the 8-octet Block ACK Bitmap subfield, which are included in the BA Information field of the GCR BlockAck variant, may be included in the AAD for the Block Ack frame with some/all of their bits changed/set to 0.
- One or more of the 2-octet Block ACK Start Sequence Control subfield, the 6-octet GCR Group Address subfield, and the 8-octet Block ACK Bitmap subfield, which are included in the BA Information field of the GLK-GCR BlockAck variant, may be included in the AAD for a Block Ack frame with some/all of their bits changed/set to 0.
- a transmitting STA and a receiving STA(s) may share information with each other on whether protection for the block Ack frame is supported.
- the information may be shared via a specific element (e.g., an Extended RSN element (RSNXE)) in a discovery process (e.g., a beacon frame, a probe response frame, etc.) and/or a (re)association process (e.g., a (re)association request frame, a (re)association response frame, etc.).
- a specific element e.g., an Extended RSN element (RSNXE)
- a discovery process e.g., a beacon frame, a probe response frame, etc.
- a (re)association process e.g., a (re)association request frame, a (re)association response frame, etc.
- the support for protection application for Block Ack frames can be shared by utilizing a reserved bit in an existing element (e.g., RSNXE) or by defining a new (sub)field in a new element.
- a newly defined 1-bit protected Block Ack support (sub)field can be defined, where a value of 1 means/indicates that protection application for Block Ack frames is supported, and a value of 0 means/indicates that protection application for Block Ack frames is not supported.
- the two STAs may perform protection application for the block Ack frame.
- the transmitting STA and the receiving STA support protection but do not support protection application for the block Ack frame the two STAs may not perform protection application for the block Ack frame.
- the cipher suite e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, or BIP-CMAC-256, etc.
- the cipher suite e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, or BIP-CMAC-256, etc.
- the transmitting STA and the receiving STA may negotiate an additional/separate cipher suite for the block Ack frame.
- protection application for a block Ack frame may be performed even if both the transmitting STA and the receiving STA explicitly support protection application for the block Ack frame, or even if it is implied but not explicitly stated (for example, support for protection application for the block Ack frame is indirectly indicated depending on how protection-related information is configured).
- the transmitting STA may also apply protection for the block Ack frame.
- the transmitting STA and the receiving STA do not perform protection operations based on BIP, CCMP, or GCMP.
- the protected frame subfield of the frame control field in the MAC header is set to reserved for control frames.
- the value of the protected frame subfield in the frame control field of the corresponding block Ack frame is set to 1. Based on this, the receiving STA can recognize that the BA control field and/or the BA information field in the corresponding block Ack frame is protected through the value of the protected frame subfield.
- a cipher suite (e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, or BIP-CMAC-256, etc.) agreed upon between the transmitting STA and the receiving STA during the negotiation process can be used identically.
- the transmitting STA and the receiving STA may negotiate an additional/separate cipher suite for that block Ack frame.
- information related to whether protection e.g., BIP, CCPM, or GCMP
- information related to AAD configuration scheme e.g., examples in FIG. 19
- the information related to the AAD configuration scheme can be information explicitly indicating AAD configuration (e.g., information indicating one of the examples in FIG. 19) or information implicitly indicating AAD configuration.
- information implicitly indicating the AAD configuration may be information about the structure of the BIP/CCMP/GCMP MPDU format.
- information implicitly indicating the AAD configuration may be information about a location where protection-related information including a key ID, PN-related information, and/or MIC is included.
- information implicitly indicating the AAD configuration may be information about a location in a block Ack frame where encryption is applied (e.g., BA control field and/or BA information field).
- reserved bits in existing elements e.g., RSNXE
- reserved bits in BA control field e.g., BA control field
- new (sub)fields in new elements e.g., BlockAck AAD type (sub)field or protected BlockAck mode (sub)field, collectively referred to as BlockAck AAD type (sub)field for clarity of description below
- the (sub)fields may be included in a beacon frame by a transmitting STA or in a data frame by a receiving STA during the (re)association process as well as during the data transmission and reception process.
- setting the value of the BlockAck AAD type (sub)field to 0 may mean/indicate that no protection (e.g., BIP, CCMP, or GCMP) is applied to the corresponding block Ack frame.
- setting the value of the BlockAck AAD type (sub)field to 1 or greater may mean/indicate that protection is applied to the block Ack frame.
- the value of the corresponding BlockAck AAD type (sub)field may be defined as in Table 2 below.
- Table 2 is exemplary, and at least one of the values described in Table 2 may be applied/defined, and a specific value may be set/defined differently from the example.
- BlockAck AAD type (sub)field meaning 0 Protection not applied to block Ack frames 1 AAD configuration for block Ack frame based on Example 1-1 2 AAD configuration for block Ack frame based on Example 1-2 3 AAD configuration for block Ack frame based on Example 1-3 ... ...
- the reserved bit present in front of the key ID information (i.e., the key ID octet) in the CCMP header and/or the GCMP header may be utilized as a BlockAck AAD type (sub)field to share information related to whether protection (e.g., CCMP or GCMP) application for the block Ack frame is supported and the AAD configuration method related to the BIP/CCMP/GCMP MPDU format (e.g., see examples in FIG. 19).
- the information related to the AAD configuration method may be information explicitly indicating the AAD configuration (e.g., information indicating one of the examples in FIG. 19) or information implicitly indicating the AAD configuration.
- the information implicitly indicating the AAD configuration may be information about the structure of the CCMP/GCMP MPDU format.
- the information implicitly indicating the AAD configuration may be information about the location where encryption is applied in the block Ack frame (e.g., the BA control field and/or the BA information field).
- the method of encrypting/decrypting the block Ack frame may use the same cipher suite (e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, or BIP-CMAC-256) agreed upon during the negotiation process between the transmitting STA and the receiving STA, or may negotiate an additional/separate cipher suite for the block Ack frame.
- the same cipher suite e.g., CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, or BIP-CMAC-256
- the (sub)field may be included in a data frame transmitted by a transmitting STA to a receiving STA during a data transmission and reception process.
- the value of the corresponding BlockAck AAD type (sub)field may be defined as in Table 3 below.
- Table 4 is exemplary, and at least one of the values described in Table 3 may be applied/defined, and a specific value may be set/defined differently from the example.
- BlockAck AAD type (sub)field meaning 1 AAD configuration for block Ack frame based on Example 1-1 2 AAD configuration for block Ack frame based on Example 1-2 3 AAD configuration for block Ack frame based on Example 1-3 ... ...
- Example 2 This embodiment relates to a specific method for configuring AAD for a block Ack frame in relation to application of protection to the aforementioned block Ack frame.
- the AAD for a block Ack frame can be configured based on the position of the protection information (sub)field containing information such as key ID, PN (e.g., IPN/BIPN, etc.), MIC, etc., within the block Ack frame.
- the protection information sub
- PN e.g., IPN/BIPN, etc.
- MIC e.g., MIC
- the AAD for the block Ack frame can be configured based on the method of Embodiment 1-1 or Embodiment 1-2 of the present disclosure.
- the AAD for the block Ack frame can be configured based on the method of Embodiment 1-1 or Embodiment 1-3 of the present disclosure.
- the AAD for the block Ack frame can be configured based on the method of embodiment 1-1 of the present disclosure.
- the AAD for a block Ack frame may be configured based on the remaining field(s) excluding the field(s) where the protection information (sub)field related to the BIP is located or the field(s) corresponding to the calculation range of the MIC within the protection information (sub)field.
- the AAD for a block Ack frame can be configured based on whether the BA control field and/or the BA information field are encrypted.
- the AAD for the block Ack frame can be configured based on the method of embodiment 1-1 of the present disclosure.
- the AAD for the block Ack frame can be configured based on the method of Embodiment 1-1 or Embodiment 1-3 of the present disclosure.
- the AAD for the block Ack frame can be configured based on the method of Embodiment 1-1 or Embodiment 1-2 of the present disclosure.
- the AAD for a block Ack frame may be constructed based on the remaining field(s) excluding the field(s) to which CCMP-based encryption is applied.
- the AAD for a block Ack frame can be configured based on whether the BA control field and/or the BA information field are encrypted.
- the AAD for the block Ack frame can be configured based on the method of embodiment 1-1 of the present disclosure.
- the AAD for the block Ack frame can be configured based on the method of Embodiment 1-1 or Embodiment 1-3 of the present disclosure.
- the AAD for the block Ack frame can be configured based on the method of Embodiment 1-1 or Embodiment 1-2 of the present disclosure.
- the AAD for a block Ack frame may be constructed based on the remaining field(s) excluding the field(s) to which GCMP-based encryption is applied.
- This embodiment relates to a specific method for performing protection for a block Ack frame based on the block Ack frame configuration proposed in the present disclosure.
- a receiving STA can configure an AAD for a block Ack frame based on information in the block Ack frame received from a transmitting STA. Thereafter, the receiving STA can use the AAD to calculate a MIC value based on the MPDU. At this time, the receiving STA can derive the MIC value by performing the same process that the transmitting STA performed when calculating the MIC value based on the MPDU.
- the receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the protection information (sub)field). If the two MIC values are the same, the receiving STA can follow the information in the acquired MPDU. On the other hand, if the two MIC values are not the same, the receiving STA can recognize that at least one piece of information in the acquired MPDU has been modified by a third party STA (e.g., an attacking STA) or damaged during transmission and reception, and can discard it.
- a third party STA e.g., an attacking STA
- a receiving STA can configure an AAD for a block Ack frame based on information in the MAC header of an MPDU received from a transmitting STA (e.g., frame control field, duration field, RA field, TA field, etc.). Thereafter, the receiving STA can decode the MSDU using the AAD.
- information in the MAC header of an MPDU received from a transmitting STA e.g., frame control field, duration field, RA field, TA field, etc.
- a receiving STA can obtain a plaintext MPDU and an MIC value based on the MPDU as a result of decryption based on the AAD and CCMP configured by the receiving STA for the block Ack frame. At this time, the receiving STA can derive the MIC value by performing the same process that the transmitting STA performed when encrypting the MPDU.
- the receiving STA can compare the derived MIC value with the MIC value transmitted by the transmitting STA (e.g., MIC information included in the CCMP MPDU format or the GCMP MPDU format). If the two MIC values are the same, the receiving STA can follow the information in the acquired plaintext MPDU. On the other hand, if the two MIC values are not the same, the receiving STA can recognize that at least one piece of information in the acquired plaintext MPDU has been modified by a third party STA (e.g., an attacking STA) or has been damaged during transmission and reception, and can discard it.
- a third party STA e.g., an attacking STA
- the receiving STA can perform an integrity check using the MIC generated/calculated based on the plaintext derived by performing decryption on the MPDU.
- the receiving STA can first perform an integrity check using the value of the MIC field of the MPDU, and if the MIC values match, can perform decryption on the MPDU.
- Protocols such as BIP/CCMP/GCMP utilized in existing wireless LAN systems cannot provide protection for control frames such as block ACK frames.
- the present disclosure can provide a new method for configuring AAD used for transmission or reception of protected control frames when protocols such as BIP/CCMP/GCMP are applied to control frames such as block ACK frames.
- the scope of the present disclosure includes software or machine-executable instructions (e.g., an operating system, an application, firmware, a program, etc.) that cause operations according to the various embodiments to be executed on a device or a computer, and a non-transitory computer-readable medium having such software or instructions stored thereon and executable on the device or computer.
- Instructions that can be used to program a processing system to perform the features described in the present disclosure can be stored on/in a storage medium or a computer-readable storage medium, and a computer program product including such a storage medium can be used to implement the features described in the present disclosure.
- the storage medium can include, but is not limited to, high-speed random access memory, such as DRAM, SRAM, DDR RAM, or other random access solid state memory devices, and can include non-volatile memory, such as one or more magnetic disk storage devices, optical disk storage devices, flash memory devices, or other non-volatile solid state storage devices.
- the memory optionally includes one or more storage devices remotely located from the processor(s).
- the memory or alternatively the non-volatile memory device(s) within the memory comprises a non-transitory computer-readable storage medium.
- the features described in this disclosure may be incorporated into software and/or firmware stored on any one of the machine-readable media to control the hardware of the processing system and to allow the processing system to interact with other mechanisms that utilize results according to embodiments of the present disclosure.
- Such software or firmware may include, but is not limited to, application code, device drivers, operating systems, and execution environments/containers.
- the method proposed in this disclosure has been described with a focus on examples applied to IEEE 802.11-based systems, but can be applied to various wireless LANs or wireless communication systems in addition to IEEE 802.11-based systems.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치가 개시된다. 본 개시의 일 실시예에 따른 방법은, 특정 프로토콜에 기초하여 보호된 블록 ACK(acknowledgement) (BA) 프레임을 제 1 스테이션(STA)에 의해서 제 2 STA으로부터 수신하는 단계; 상기 BA 프레임에 기초하여 AAD(additional authentication data)를 상기 제 1 STA에 의해서 생성하는 단계; 및 상기 AAD에 기초하여 상기 BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상을 상기 제 1 STA에 의해서 수행하는 단계를 포함할 수 있다. 상기 AAD는, 상기 BA 프레임의 MAC(medium access control) 헤더에 포함되는 하나 이상의 필드에 기초하거나, 또는 상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 상기 BA 프레임의 BA 제어 필드 또는 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초할 수 있다.
Description
본 개시는 무선랜(Wireless Local Area Network, WLAN) 시스템에서 보호된 제어 프레임을 송신 또는 수신하는 방법 및 장치에 관한 것이다.
무선랜(WLAN)에 대해서 송신 레이트 향상, 대역폭 증가, 신뢰성 향상, 에러 감소, 레이턴시 감소 등을 위한 새로운 기술이 도입되어 왔다. 무선랜 기술 중에서, IEEE(Institute of Electrical and Electronics Engineers) 802.11 계열의 표준을 Wi-Fi라고 칭할 수 있다. 예를 들어, 최근에 무선랜에 도입된 기술은, 802.11ac 표준의 VHT(Very High-Throughput)를 위한 개선사항(enhancement), IEEE 802.11ax 표준의 HE(High Efficiency)를 위한 개선사항 등을 포함한다.
보다 향상된 무선 통신 환경을 제공하기 위해서, EHT(Extremely High Throughput)를 위한 개선 기술이 논의되고 있다. 예를 들어, 증가된 대역폭, 다중 대역의 효율적 활용, 증가된 공간 스트림을 지원하는 MIMO(Multiple Input Multiple Output), 다중 액세스 포인트(AP) 조정을 위한 기술이 연구되고 있으며, 특히 낮은 레이턴시(low latency) 또는 실시간(real time) 특성의 트래픽을 지원하기 위한 다양한 기술이 연구되고 있다. 나아가, EHT 기술의 개선 또는 확장을 포함하여, 극히 높은 신뢰성(ultra high reliability, UHR)을 지원하기 위한 새로운 기술이 논의되고 있다.
본본 개시의 기술적 과제는 무선랜 시스템에서 보호된 제어 프레임을 송신 또는 수신하는 방법 및 장치를 제공하는 것이다.
본 개시의 기술적 과제는 무선랜 시스템에서 블록 ACK(acknowledgement) 프레임에 대해서 추가 인증 데이터(additional authentication data, AAD)에 기반하는 암호화(encryption)/복호화(decryption)/무결성 검사(integrity check)를 지원하는 방법 및 장치를 제공하는 것이다.
본 개시에서 이루고자 하는 기술적 과제들은 이상에서 언급한 기술적 과제들로 제한되지 않으며, 언급하지 않은 또 다른 기술적 과제들은 아래의 기재로부터 본 개시가 속하는 기술분야에서 통상의 지식을 가진 자에게 명확하게 이해될 수 있을 것이다.
본 개시의 일 양상에 따른 방법은, 특정 프로토콜에 기초하여 보호된 블록 ACK(acknowledgement) (BA) 프레임을 제 1 스테이션(STA)에 의해서 제 2 STA으로부터 수신하는 단계; 상기 BA 프레임에 기초하여 AAD(additional authentication data)를 상기 제 1 STA에 의해서 생성하는 단계; 및 상기 AAD에 기초하여 상기 BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상을 상기 제 1 STA에 의해서 수행하는 단계를 포함할 수 있다. 상기 AAD는, 상기 BA 프레임의 MAC(medium access control) 헤더에 포함되는 하나 이상의 필드에 기초하거나, 또는 상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 상기 BA 프레임의 BA 제어 필드 또는 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초할 수 있다.
본 개시의 추가적인 양상에 따른 방법은, 특정 프로토콜에 기초하여, 블록 ACK(acknowledgement) (BA) 프레임에 대한 AAD(additional authentication data)를 제 2 스테이션(STA)에 의해서 생성하는 단계; 및 상기 AAD에 기초하여 보호된 BA 프레임을, 제 2 STA에 의해서 제 1 STA에게 송신하는 단계를 포함할 수 있다. 상기 AAD는, 상기 BA 프레임의 MAC(medium access control) 헤더에 포함되는 하나 이상의 필드에 기초하거나, 또는 상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 상기 BA 프레임의 BA 제어 필드 또는 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초할 수 있다.
본 개시에 따르면, 무선랜 시스템에서 보호된 제어 프레임을 송신 또는 수신하는 방법 및 장치가 제공될 수 있다.
본 개시에 따르면, 무선랜 시스템에서 블록 ACK(acknowledgement) 프레임에 대해서 추가 인증 데이터(additional authentication data, AAD)에 기반하는 암호화(encryption)/복호화(decryption)/무결성 검사(integrity check)를 지원하는 방법 및 장치가 제공될 수 있다.
본 개시에서 얻을 수 있는 효과는 이상에서 언급한 효과로 제한되지 않으며, 언급하지 않은 또 다른 효과들은 아래의 기재로부터 본 개시가 속하는 기술분야에서 통상의 지식을 가진 자에게 명확하게 이해될 수 있을 것이다.
본 개시에 관한 이해를 돕기 위해 상세한 설명의 일부로 포함되는, 첨부 도면은 본 개시에 대한 실시예를 제공하고, 상세한 설명과 함께 본 개시의 기술적 특징을 설명한다.
도 1은 본 개시의 일 실시예에 따른 무선 통신 장치의 블록 구성도를 예시한다.
도 2는 본 개시가 적용될 수 있는 무선랜 시스템의 예시적인 구조를 나타내는 도면이다.
도 3은 본 개시가 적용될 수 있는 링크 셋업(link setup) 과정을 설명하기 위한 도면이다.
도 4는 본 개시가 적용될 수 있는 백오프 과정을 설명하기 위한 도면이다.
도 5는 본 개시가 적용될 수 있는 CSMA/CA 기반 프레임 송신 동작을 설명하기 위한 도면이다.
도 6은 본 개시가 적용될 수 있는 무선랜 시스템에서 사용되는 프레임 구조의 예시를 설명하기 위한 도면이다.
도 7은 본 개시가 적용될 수 있는 IEEE 802.11 표준에서 정의되는 PPDU의 예시들을 도시한 도면이다.
도 8은 본 개시가 적용될 수 있는 4-웨이 핸드셰이킹 절차를 설명하기 위한 도면이다.
도 9는 본 개시가 적용될 수 있는 확대된(expanded) CCMP MPDU의 일 예시를 나타내는 도면이다.
도 10은 본 개시가 적용될 수 있는 CCMP 인캡슐레이션 블록 다이어그램을 나타낸다.
도 11은 기존(conventional) AAD의 포맷의 일 예시를 나타낸다.
도 12는 본 개시가 적용될 수 있는 CCMP 디캡슐레이션 블록 다이어그램을 나타낸다.
도 13은 본 개시가 적용될 수 있는 확대된(expanded) GCMP MPDU의 일 예시를 나타내는 도면이다.
도 14는 본 개시가 적용될 수 있는 GCMP 인캡슐레이션 블록 다이어그램을 나타낸다.
도 15는 본 개시가 적용될 수 있는 GCMP 디캡슐레이션 블록 다이어그램을 나타낸다.
도 16은 본 개시가 적용될 수 있는 블록 ACK 프레임의 예시적인 포맷들을 나타낸다.
도 17은 본 개시에 따른 제 1 STA의 동작을 설명하기 위한 도면이다.
도 18은 본 개시에 따른 제 2 STA의 동작을 설명하기 위한 도면이다.
도 19는 본 개시의 실시예에 따른 블록 ACK 프레임의 보호를 위한 AAD 구성의 예시들을 나타낸다.
이하, 본 개시에 따른 바람직한 실시 형태를 첨부된 도면을 참조하여 상세하게 설명한다. 첨부된 도면과 함께 이하에 개시될 상세한 설명은 본 개시의 예시적인 실시형태를 설명하고자 하는 것이며, 본 개시가 실시될 수 있는 유일한 실시형태를 나타내고자 하는 것이 아니다. 이하의 상세한 설명은 본 개시의 완전한 이해를 제공하기 위해서 구체적 세부사항을 포함한다. 그러나, 당업자는 본 개시가 이러한 구체적 세부사항 없이도 실시될 수 있음을 안다.
몇몇 경우, 본 개시의 개념이 모호해지는 것을 피하기 위하여 공지의 구조 및 장치는 생략되거나, 각 구조 및 장치의 핵심기능을 중심으로 한 블록도 형식으로 도시될 수 있다.
본 개시에 있어서, 어떤 구성요소가 다른 구성요소와 "연결", "결합" 또는 "접속"되어 있다고 할 때, 이는 직접적인 연결관계 뿐만 아니라, 그 사이에 또 다른 구성요소가 존재하는 간접적인 연결관계도 포함할 수 있다. 또한 본 개시에서 용어 "포함한다" 또는 "가진다"는 언급된 특징, 단계, 동작, 요소 및/또는 구성요소의 존재를 특정하지만, 하나 이상의 다른 특징, 단계, 동작, 요소, 구성요소 및/또는 이들의 그룹의 존재 또는 추가를 배제하지 않는다.
본 개시에 있어서, "제 1", "제 2" 등의 용어는 하나의 구성요소를 다른 구성요소로부터 구별하는 목적으로만 사용되고 구성요소들을 제한하기 위해서 사용되지 않으며, 특별히 언급되지 않는 한 구성요소들 간의 순서 또는 중요도 등을 한정하지 않는다. 따라서, 본 개시의 범위 내에서 일 실시예에서의 제 1 구성요소는 다른 실시예에서 제 2 구성요소라고 칭할 수도 있고, 마찬가지로 일 실시예에서의 제 2 구성요소를 다른 실시예에서 제 1 구성요소라고 칭할 수도 있다.
본 개시에서 사용된 용어는 특정 실시예에 대한 설명을 위한 것이며 청구범위를 제한하려는 것이 아니다. 실시예의 설명 및 첨부된 청구범위에서 사용되는 바와 같이, 단수 형태는 문맥상 명백하게 다르게 나타내지 않는 한 복수 형태도 포함하도록 의도한 것이다. 본 개시에 사용된 용어 "및/또는"은 관련된 열거 항목 중의 하나를 지칭할 수도 있고, 또는 그 중의 둘 이상의 임의의 및 모든 가능한 조합을 지칭하고 포함하는 것을 의미한다. 또한, 본 개시에서 단어들 사이의 "/"는 달리 설명되지 않는 한 "및/또는"과 동일한 의미를 가진다.
본 개시의 예시들은 다양한 무선 통신 시스템에 적용될 수 있다. 예를 들어, 본 개시의 예시들은 무선랜 시스템에 적용될 수 있다. 예를 들어, 본 개시의 예시들은 IEEE 802.11a/g/n/ac/ax/be 표준 기반 무선랜에 적용될 수 있다. 나아가, 본 개시의 예시들은 새롭게 제안되는 IEEE 802.11bn (또는 UHR) 표준 기반 무선랜에 적용될 수도 있다. 추가적으로, 본 개시의 예시들은 IEEE 802.11bn 후의 차세대 표준 기반 무선랜에 적용될 수도 있다. 또한, 본 개시의 예시들은 셀룰러 무선 통신 시스템에 적용될 수도 있다. 예를 들어, 3GPP(3rd Generation Partnership Project) 표준의 LTE(Long Term Evolution) 계열의 기술 및 5G NR(New Radio) 계열의 기술에 기반하는 셀룰러 무선 통신 시스템에 적용될 수 있다.
이하 본 개시의 예시들이 적용될 수 있는 기술적 특징에 대해서 설명한다.
도 1은 본 개시의 일 실시예에 따른 무선 통신 장치의 블록 구성도를 예시한다.
도 1에 예시된 제 1 디바이스(100)와 제 2 디바이스(200)는, 단말(Terminal), 무선 기기(wireless device), WTRU(Wireless Transmit Receive Unit), UE(User Equipment), MS(Mobile Station), UT(user terminal), MSS(Mobile Subscriber Station), MSS(Mobile Subscriber Unit), SS(Subscriber Station), AMS(Advanced Mobile Station), WT(Wireless terminal), 또는 단순히 사용자(user) 등의 다양한 용어로 대체될 수 있다. 또한, 제 1 디바이스(100)와 제 2 디바이스(200)는, 액세스 포인트(Access Point, AP), BS(Base Station), 고정국(fixed station), Node B, BTS(base transceiver system), 네트워크, AI(Artificial Intelligence) 시스템, RSU(road side unit), 리피터, 라우터, 릴레이(relay), 게이트웨이 등의 다양한 용어로 대체될 수 있다.
도 1에 예시된 디바이스(100, 200)는 스테이션(station, STA)이라 칭할 수도 있다. 예를 들어, 도 1에 예시된 디바이스(100, 200)는 송신 디바이스, 수신 디바이스, 송신 STA, 수신 STA 등의 다양한 용어로 칭할 수 있다. 예를 들어, STA(110, 200)은 AP(access Point) 역할을 수행하거나 non-AP 역할을 수행할 수 있다. 즉, 본 개시에서 STA(110, 200)은 AP 및/또는 non-AP의 기능을 수행할 수 있다. STA(110, 200)이 AP 기능을 수행하는 경우 단순히 AP라고 칭할 수도 있고, STA(110, 200)이 non-AP 기능을 수행하는 경우 단순히 STA라고 칭할 수도 있다. 또한, 본 개시에서 AP는 AP STA으로도 표시될 수 있다.
도 1을 참조하면, 제 1 디바이스(100)와 제 2 디바이스(200)는 다양한 무선랜 기술(예를 들어, IEEE 802.11 계열)을 통해 무선 신호를 송수신할 수 있다. 제 1 디바이스(100)와 제 2 디바이스(200)는 IEEE 802.11 표준의 규정을 따르는 매체 접속 제어(medium access control, MAC) 계층 및 물리 계층(physical layer, PHY)에 대한 인터페이스를 포함할 수 있다.
또한, 제 1 디바이스(100)와 제 2 디바이스(200)는 무선랜 기술 이외의 다양한 통신 표준(예를 들어, 3GPP LTE 계열, 5G NR 계열의 표준 등) 기술을 추가적으로 지원할 수도 있다. 또한 본 개시의 디바이스는 휴대 전화, 차량(vehicle), 개인용 컴퓨터, AR(Augmented Reality) 장비, VR(Virtual Reality) 장비 등의 다양한 장치로 구현될 수 있다. 또한, 본 명세서의 STA은 음성 통화, 영상 통화, 데이터 통신, 자율 주행(Autonomous-Driving), MTC(Machine-Type Communication), M2M(Machine-to-Machine), D2D(Device-to-Device), IoT(Internet-of-Things) 등의 다양한 통신 서비스를 지원할 수 있다.
제 1 디바이스(100)는 하나 이상의 프로세서(102) 및 하나 이상의 메모리(104)를 포함하며, 추가적으로 하나 이상의 송수신기(transceiver)(106) 및/또는 하나 이상의 안테나(108)을 더 포함할 수 있다. 프로세서(102)는 메모리(104) 및/또는 송수신기(106)를 제어하며, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 구현하도록 구성될 수 있다. 예를 들어, 프로세서(102)는 메모리(104) 내의 정보를 처리하여 제 1 정보/신호를 생성한 뒤, 송수신기(106)을 통해 제 1 정보/신호를 포함하는 무선 신호를 송신할 수 있다. 또한, 프로세서(102)는 송수신기(106)를 통해 제 2 정보/신호를 포함하는 무선 신호를 수신한 뒤, 제 2 정보/신호의 신호 처리로부터 얻은 정보를 메모리(104)에 저장할 수 있다. 메모리(104)는 프로세서(102)와 연결될 수 있고, 프로세서(102)의 동작과 관련한 다양한 정보를 저장할 수 있다. 예를 들어, 메모리(104)는 프로세서(102)에 의해 제어되는 프로세스들 중 일부 또는 전부를 수행하거나, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 수행하기 위한 명령어(instruction)들을 포함하는 소프트웨어 코드를 저장할 수 있다. 여기서, 프로세서(102)와 메모리(104)는 무선랜 기술(예를 들어, IEEE 802.11 계열)을 구현하도록 설계된 통신 모뎀/회로/칩의 일부일 수 있다. 송수신기(106)는 프로세서(102)와 연결될 수 있고, 하나 이상의 안테나(108)를 통해 무선 신호를 송신 및/또는 수신할 수 있다. 송수신기(106)는 송신기 및/또는 수신기를 포함할 수 있다. 송수신기(106)는 RF(Radio Frequency) 유닛과 혼용될 수 있다. 본 개시에서 디바이스는 통신 모뎀/회로/칩을 의미할 수도 있다.
제 2 디바이스(200)는 하나 이상의 프로세서(202), 하나 이상의 메모리(204)를 포함하며, 추가적으로 하나 이상의 송수신기(206) 및/또는 하나 이상의 안테나(208)를 더 포함할 수 있다. 프로세서(202)는 메모리(204) 및/또는 송수신기(206)를 제어하며, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 구현하도록 구성될 수 있다. 예를 들어, 프로세서(202)는 메모리(204) 내의 정보를 처리하여 제 3 정보/신호를 생성한 뒤, 송수신기(206)를 통해 제 3 정보/신호를 포함하는 무선 신호를 송신할 수 있다. 또한, 프로세서(202)는 송수신기(206)를 통해 제 4 정보/신호를 포함하는 무선 신호를 수신한 뒤, 제 4 정보/신호의 신호 처리로부터 얻은 정보를 메모리(204)에 저장할 수 있다. 메모리(204)는 프로세서(202)와 연결될 수 있고, 프로세서(202)의 동작과 관련한 다양한 정보를 저장할 수 있다. 예를 들어, 메모리(204)는 프로세서(202)에 의해 제어되는 프로세스들 중 일부 또는 전부를 수행하거나, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들을 수행하기 위한 명령어들을 포함하는 소프트웨어 코드를 저장할 수 있다. 여기서, 프로세서(202)와 메모리(204)는 무선랜 기술(예를 들어, IEEE 802.11 계열)을 구현하도록 설계된 통신 모뎀/회로/칩의 일부일 수 있다. 송수신기(206)는 프로세서(202)와 연결될 수 있고, 하나 이상의 안테나(208)를 통해 무선 신호를 송신 및/또는 수신할 수 있다. 송수신기(206)는 송신기 및/또는 수신기를 포함할 수 있다 송수신기(206)는 RF 유닛과 혼용될 수 있다. 본 개시에서 디바이스는 통신 모뎀/회로/칩을 의미할 수도 있다.
이하, 디바이스(100, 200)의 하드웨어 요소에 대해 보다 구체적으로 설명한다. 이로 제한되는 것은 아니지만, 하나 이상의 프로토콜 계층이 하나 이상의 프로세서(102, 202)에 의해 구현될 수 있다. 예를 들어, 하나 이상의 프로세서(102, 202)는 하나 이상의 계층(예를 들어, PHY, MAC과 같은 기능적 계층)을 구현할 수 있다. 하나 이상의 프로세서(102, 202)는 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들에 따라 하나 이상의 PDU(Protocol Data Unit) 및/또는 하나 이상의 SDU(Service Data Unit)를 생성할 수 있다. 하나 이상의 프로세서(102, 202)는 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들에 따라 메시지, 제어정보, 데이터 또는 정보를 생성할 수 있다. 하나 이상의 프로세서(102, 202)는 본 개시에 개시된 기능, 절차, 제안 및/또는 방법에 따라 PDU, SDU, 메시지, 제어정보, 데이터 또는 정보를 포함하는 신호(예를 들어, 베이스밴드 신호)를 생성하여, 하나 이상의 송수신기(106, 206)에게 제공할 수 있다. 하나 이상의 프로세서(102, 202)는 하나 이상의 송수신기(106, 206)로부터 신호(예를 들어, 베이스밴드 신호)를 수신할 수 있고, 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들에 따라 PDU, SDU, 메시지, 제어정보, 데이터 또는 정보를 획득할 수 있다.
하나 이상의 프로세서(102, 202)는 컨트롤러, 마이크로 컨트롤러, 마이크로 프로세서 또는 마이크로 컴퓨터로 지칭될 수 있다. 하나 이상의 프로세서(102, 202)는 하드웨어, 펌웨어, 소프트웨어, 또는 이들의 조합에 의해 구현될 수 있다. 일 예로, 하나 이상의 ASIC(Application Specific Integrated Circuit), 하나 이상의 DSP(Digital Signal Processor), 하나 이상의 DSPD(Digital Signal Processing Device), 하나 이상의 PLD(Programmable Logic Device) 또는 하나 이상의 FPGA(Field Programmable Gate Arrays)가 하나 이상의 프로세서(102, 202)에 포함될 수 있다. 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들은 펌웨어 또는 소프트웨어를 사용하여 구현될 수 있고, 펌웨어 또는 소프트웨어는 모듈, 절차, 기능 등을 포함하도록 구현될 수 있다. 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들은 수행하도록 설정된 펌웨어 또는 소프트웨어는 하나 이상의 프로세서(102, 202)에 포함되거나, 하나 이상의 메모리(104, 204)에 저장되어 하나 이상의 프로세서(102, 202)에 의해 구동될 수 있다. 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도들은 코드, 명령어 및/또는 명령어의 집합 형태로 펌웨어 또는 소프트웨어를 사용하여 구현될 수 있다.
하나 이상의 메모리(104, 204)는 하나 이상의 프로세서(102, 202)와 연결될 수 있고, 다양한 형태의 데이터, 신호, 메시지, 정보, 프로그램, 코드, 지시 및/또는 명령어를 저장할 수 있다. 하나 이상의 메모리(104, 204)는 ROM, RAM, EPROM, 플래시 메모리, 하드 드라이브, 레지스터, 캐쉬 메모리, 컴퓨터 판독 저장 매체 및/또는 이들의 조합으로 구성될 수 있다. 하나 이상의 메모리(104, 204)는 하나 이상의 프로세서(102, 202)의 내부 및/또는 외부에 위치할 수 있다. 또한, 하나 이상의 메모리(104, 204)는 유선 또는 무선 연결과 같은 다양한 기술을 통해 하나 이상의 프로세서(102, 202)와 연결될 수 있다.
하나 이상의 송수신기(106, 206)는 하나 이상의 다른 장치에게 본 개시의 방법들 및/또는 동작 순서도 등에서 언급되는 사용자 데이터, 제어 정보, 무선 신호/채널 등을 송신할 수 있다. 하나 이상의 송수신기(106, 206)는 하나 이상의 다른 장치로부터 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도 등에서 언급되는 사용자 데이터, 제어 정보, 무선 신호/채널 등을 수신할 수 있다. 예를 들어, 하나 이상의 송수신기(106, 206)는 하나 이상의 프로세서(102, 202)와 연결될 수 있고, 무선 신호를 송수신할 수 있다. 예를 들어, 하나 이상의 프로세서(102, 202)는 하나 이상의 송수신기(106, 206)가 하나 이상의 다른 장치에게 사용자 데이터, 제어 정보 또는 무선 신호를 송신하도록 제어할 수 있다. 또한, 하나 이상의 프로세서(102, 202)는 하나 이상의 송수신기(106, 206)가 하나 이상의 다른 장치로부터 사용자 데이터, 제어 정보 또는 무선 신호를 수신하도록 제어할 수 있다. 또한, 하나 이상의 송수신기(106, 206)는 하나 이상의 안테나(108, 208)와 연결될 수 있고, 하나 이상의 송수신기(106, 206)는 하나 이상의 안테나(108, 208)를 통해 본 개시에 개시된 설명, 기능, 절차, 제안, 방법 및/또는 동작 순서도 등에서 언급되는 사용자 데이터, 제어 정보, 무선 신호/채널 등을 송수신하도록 설정될 수 있다. 본 개시에서, 하나 이상의 안테나는 복수의 물리 안테나이거나, 복수의 논리 안테나(예를 들어, 안테나 포트)일 수 있다. 하나 이상의 송수신기(106, 206)는 수신된 사용자 데이터, 제어 정보, 무선 신호/채널 등을 하나 이상의 프로세서(102, 202)를 이용하여 처리하기 위해, 수신된 무선 신호/채널 등을 RF 밴드 신호에서 베이스밴드 신호로 변환(Convert)할 수 있다. 하나 이상의 송수신기(106, 206)는 하나 이상의 프로세서(102, 202)를 이용하여 처리된 사용자 데이터, 제어 정보, 무선 신호/채널 등을 베이스밴드 신호에서 RF 밴드 신호로 변환할 수 있다. 이를 위하여, 하나 이상의 송수신기(106, 206)는 (아날로그) 오실레이터 및/또는 필터를 포함할 수 있다.
예를 들어, STA(100, 200)의 하나는 AP의 의도된 동작을 수행하고, STA(100, 200)의 다른 하나는 non-AP STA의 의도된 동작을 수행할 수 있다. 예를 들어, 도 1의 송수신기(106, 206)는 신호(예를 들어, IEEE 802.11a/b/g/n/ac/ax/be/bn 등에 따르는 패킷 또는 PPDU(Physical layer Protocol Data Unit))의 송수신 동작을 수행할 수 있다. 또한, 본 개시에서 다양한 STA이 송수신 신호를 생성하거나 송수신 신호를 위해 사전에 데이터 처리나 연산을 수행하는 동작은 도 1의 프로세서(102, 202)에서 수행될 수 있다. 예를 들어, 송수신 신호를 생성하거나 송수신 신호를 위해 사전에 데이터 처리나 연산을 수행하는 동작의 일례는, 1) PPDU 내에 포함되는 필드(SIG(signal), STF(short training field), LTF(long training field), Data 등)의 비트 정보를 결정/획득/구성/연산/디코딩/인코딩하는 동작, 2) PPDU 내에 포함되는 필드(SIG, STF, LTF, Data 등)를 위해 사용되는 시간 자원이나 주파수 자원(예를 들어, 서브캐리어 자원) 등을 결정/구성/획득하는 동작, 3) PPDU 내에 포함되는 필드(SIG, STF, LTF, Data 등)를 위해 사용되는 특정한 시퀀스(예를 들어, 파일럿 시퀀스, STF/LTF 시퀀스, SIG에 적용되는 엑스트라 시퀀스) 등을 결정/구성/획득하는 동작, 4) STA에 대해 적용되는 전력 제어 동작 및/또는 파워 세이빙 동작, 5) ACK 신호의 결정/획득/구성/연산/디코딩/인코딩 등에 관련된 동작을 포함할 수 있다. 또한, 이하의 일례에서 다양한 STA이 송수신 신호의 결정/획득/구성/연산/디코딩/인코딩을 위해 사용하는 다양한 정보(예를 들어, 필드/서브필드/제어필드/파라미터/파워 등에 관련된 정보)는 도 1의 메모리(104, 204)에 저장될 수 있다.
이하에서, 하향링크(downlink, DL)는 AP STA로부터 non-AP STA로의 통신을 위한 링크를 의미하며, 하향링크를 통해 하향링크 PPDU/패킷/신호 등의 송수신될 수 있다. 하향링크 통신에서 송신기는 AP STA의 일부이고, 수신기는 non-AP STA의 일부일 수 있다. 상향링크(uplink, UL)는 non-AP STA로부터 AP STA로의 통신을 위한 링크를 의미하며, 상향링크를 통해 상향링크 PPDU/패킷/신호 등의 송수신될 수 있다. 상향링크 통신에서 송신기는 non-AP STA의 일부이고, 수신기는 AP STA의 일부일 수 있다.
도 2는 본 개시가 적용될 수 있는 무선랜 시스템의 예시적인 구조를 나타내는 도면이다.
무선랜 시스템의 구조는 복수개의 구성요소(component)들로 구성될 수 있다. 복수의 구성요소들의 상호작용에 의해 상위계층에 대해 트랜스패런트한 STA 이동성을 지원하는 무선랜이 제공될 수 있다. BSS(Basic Service Set)는 무선랜의 기본적인 구성 블록에 해당한다. 도 2에서는 2 개의 BSS(BSS1 및 BSS2)가 존재하고, 각각의 BSS의 멤버로서 2 개의 STA이 포함되는 것(STA1 및 STA2는 BSS1에 포함되고, STA3 및 STA4는 BSS2에 포함됨)을 예시적으로 도시한다. 도 2에서 BSS를 나타내는 타원은 해당 BSS에 포함된 STA들이 통신을 유지하는 커버리지 영역을 나타내는 것으로도 이해될 수 있다. 이 영역을 BSA(Basic Service Area)라고 칭할 수 있다. STA이 BSA 밖으로 이동하게 되면 해당 BSA 내의 다른 STA들과 직접적으로 통신할 수 없게 된다.
도 2에서 도시하는 DS를 고려하지 않는다면, 무선랜에서 가장 기본적인 타입의 BSS는 독립적인 BSS(Independent BSS, IBSS)이다. 예를 들어, IBSS는 2 개의 STA만으로 구성된 최소의 형태를 가질 수 있다. 예를 들어, 다른 구성요소들이 생략된 것을 가정하여, STA1 및 STA2만으로 구성된 BSS1 또는 STA3 및 STA4만으로 구성된 BSS2는 각각 IBSS의 대표적인 예시에 해당할 수 있다. 이러한 구성은 STA들이 AP 없이 직접 통신할 수 있는 경우에 가능하다. 또한, 이러한 형태의 무선랜에서 미리 계획되어서 구성되는 것이 아니라 LAN이 필요한 경우에 구성될 수 있으며, 이를 애드-혹(ad-hoc) 네트워크라고 칭할 수도 있다. IBSS는 AP를 포함하지 않기 때문에 중앙에서 관리 기능을 수행하는 개체(centralized management entity)가 없다. 즉, IBSS에서 STA들은 분산된 방식(distributed manner)으로 관리된다. IBSS에서는 모든 STA들이 이동 STA으로 이루어질 수 있으며, 분산 시스템(DS)으로의 접속이 허용되지 않아서 자기 완비적 네트워크(self-contained network)를 이룬다.
STA의 켜지거나 꺼짐, STA이 BSS 영역에 들어오거나 나감 등에 의해서, BSS에서의 STA의 멤버십이 동적으로 변경될 수 있다. BSS의 멤버가 되기 위해서는, STA은 동기화 과정을 이용하여 BSS에 조인할 수 있다. BSS 기반구조의 모든 서비스에 액세스하기 위해서는, STA은 BSS에 결합(associated)되어야 한다. 이러한 결합(association)은 동적으로 설정될 수 있고, 분산 시스템 서비스(Distribution System Service, DSS)의 이용을 포함할 수 있다.
무선랜에서 직접적인 STA-대-STA의 거리는 PHY 성능에 의해서 제한될 수 있다. 어떠한 경우에는 이러한 거리의 한계가 충분할 수도 있지만, 경우에 따라서는 보다 먼 거리의 STA 간의 통신이 필요할 수도 있다. 확장된 커버리지를 지원하기 위해서 분산 시스템(DS)이 구성될 수 있다.
DS는 BSS들이 상호 연결되는 구조를 의미한다. 구체적으로, 도 2와 같이 복수개의 BSS들로 구성된 네트워크의 확장된 형태의 구성요소로서 BSS가 존재할 수도 있다. DS는 논리적인 개념이며 분산 시스템 매체(DSM)의 특성에 의해서 특정될 수 있다. 이와 관련하여, 무선 매체(Wireless Medium, WM)와 DSM는 논리적으로 구분될 수 있다. 각각의 논리적 매체는 상이한 목적을 위해서 사용되며, 상이한 구성요소에 의해서 사용된다. 이러한 매체들이 동일한 것으로 제한되지도 않고 상이한 것으로 제한되지도 않는다. 이와 같이 복수개의 매체들이 논리적으로 상이하다는 점에서, 무선랜 구조(DS 구조 또는 다른 네트워크 구조)의 유연성이 설명될 수 있다. 즉, 무선랜 구조는 다양하게 구현될 수 있으며, 각각의 구현예의 물리적인 특성에 의해서 독립적으로 해당 무선랜 구조가 특정될 수 있다.
DS는 복수개의 BSS들의 끊김없는(seamless) 통합을 제공하고 목적지로의 어드레스를 다루는 데에 필요한 논리적 서비스들을 제공함으로써 이동 디바이스를 지원할 수 있다. 또한, DS는 무선랜과 다른 네트워크(예를 들어, IEEE 802.X)와의 연결을 위한 브리지 역할을 수행하는 포털(portal)이라는 구성요소를 더 포함할 수 있다.
AP는 결합된 non-AP STA들에 대해서 WM을 통해서 DS 로의 액세스를 가능하게 하고, STA의 기능성 또한 가지는 엔티티(entity)를 의미한다. AP를 통해서 BSS 및 DS 간의 데이터 이동이 수행될 수 있다. 예를 들어, 도 2에서 도시하는 STA2 및 STA3은 STA의 기능성을 가지면서, 결합된 non-AP STA(STA1 및 STA4)이 DS로 액세스하도록 하는 기능을 제공한다. 또한, 모든 AP는 기본적으로 STA에 해당하므로, 모든 AP는 어드레스 가능한 엔티티이다. WM 상에서의 통신을 위해 AP에 의해서 사용되는 어드레스와, DSM 상에서의 통신을 위해 AP에 의해서 사용되는 어드레스는 반드시 동일할 필요는 없다. AP와 하나 이상의 STA으로 구성되는 BSS를 인프라스트럭쳐(infrastructure BSS)라고 칭할 수 있다.
AP에 결합된 STA(들) 중의 하나로부터 해당 AP의 STA 어드레스로 송신되는 데이터는, 항상 비제어 포트(uncontrolled port)에서 수신되고 IEEE 802.1X 포트 액세스 엔티티에 의해서 처리될 수 있다. 또한, 제어 포트(controlled port)가 인증되면 송신 데이터(또는 프레임)는 DS로 전달될 수 있다.
전술한 DS의 구조에 추가적으로 넓은 커버리지를 제공하기 위한 확장된 서비스 세트(Extended Service Set, ESS)가 설정될 수도 있다.
ESS는 임의의(arbitrary) 크기 및 복잡도를 가지는 네트워크가 DS 및 BSS들로 구성된 네트워크를 의미한다. ESS는 하나의 DS에 연결된 BSS들의 집합에 해당할 수 있다. 그러나, ESS는 DS를 포함하지는 않는다. ESS 네트워크는 LLC(Logical Link Control) 계층에서 IBSS로 보이는 점이 특징이다. ESS에 포함되는 STA들은 서로 통신할 수 있고, 이동 STA들은 LLC에 트랜스패런트하게 하나의 BSS에서 다른 BSS로(동일한 ESS 내에서) 이동할 수 있다. 하나의 ESS에 포함되는 AP들은 동일한 SSID(service set identification)을 가질 수 있다. SSID는 BSS의 식별자인 BSSID와 구별된다.
무선랜 시스템에서는 BSS들의 상대적인 물리적 위치에 대해서 아무것도 가정하지 않으며, 다음과 같은 형태가 모두 가능하다. BSS들은 부분적으로 중첩될 수 있고, 이는 연속적인 커버리지를 제공하기 위해서 일반적으로 이용되는 형태이다. 또한, BSS들은 물리적으로 연결되어 있지 않을 수 있고, 논리적으로는 BSS들 간의 거리에 제한은 없다. 또한, BSS들은 물리적으로 동일한 위치에 위치할 수 있고, 이는 리던던시를 제공하기 위해서 이용될 수 있다. 또한, 하나 (또는 하나 이상의) IBSS 또는 ESS 네트워크들이 하나 (또는 하나 이상의) ESS 네트워크로서 동일한 공간에 물리적으로 존재할 수 있다. 이는 ESS 네트워크가 존재하는 위치에 애드-혹 네트워크가 동작하는 경우나, 상이한 기관(organizations)에 의해서 물리적으로 중첩되는 무선 네트워크들이 구성되는 경우나, 동일한 위치에서 2 이상의 상이한 액세스 및 보안 정책이 필요한 경우 등에서의 ESS 네트워크 형태에 해당할 수 있다.
도 3은 본 개시가 적용될 수 있는 링크 셋업(link setup) 과정을 설명하기 위한 도면이다.
STA이 네트워크에 대해서 링크를 셋업하고 데이터를 송수신하기 위해서는, 먼저 네트워크를 발견(discovery)하고, 인증(authentication)을 수행하고, 결합(association)을 맺고(establish), 보안(security)을 위한 인증 절차 등을 거쳐야 한다. 링크 셋업 과정을 세션 개시 과정, 세션 셋업 과정이라고도 칭할 수 있다. 또한, 링크 셋업 과정의 발견, 인증, 결합, 보안 설정의 과정을 통칭하여 결합 과정이라고 칭할 수도 있다.
단계 S310에서 STA은 네트워크 발견 동작을 수행할 수 있다. 네트워크 발견 동작은 STA의 스캐닝(scanning) 동작을 포함할 수 있다. 즉, STA이 네트워크에 액세스하기 위해서는 참여 가능한 네트워크를 찾아야 한다. STA은 무선 네트워크에 참여하기 전에 호환 가능한 네트워크를 식별하여야 하는데, 특정 영역에 존재하는 네트워크 식별과정을 스캐닝이라고 한다.
스캐닝 방식에는 능동적 스캐닝(active scanning)과 수동적 스캐닝(passive scanning)이 있다. 도 3에서는 예시적으로 능동적 스캐닝 과정을 포함하는 네트워크 발견 동작을 도시한다. 능동적 스캐닝에서 스캐닝을 수행하는 STA은 채널들을 옮기면서 주변에 어떤 AP가 존재하는지 탐색하기 위해 프로브 요청 프레임(probe request frame)을 송신하고 이에 대한 응답을 기다린다. 응답자(responder)는 프로브 요청 프레임을 송신한 STA에게 프로브 요청 프레임에 대한 응답으로 프로브 응답 프레임(probe response frame)을 송신한다. 여기에서, 응답자는 스캐닝되고 있는 채널의 BSS에서 마지막으로 비콘 프레임(beacon frame)을 송신한 STA일 수 있다. BSS에서는 AP가 비콘 프레임을 송신하므로 AP가 응답자가 되며, IBSS에서는 IBSS 내의 STA들이 돌아가면서 비콘 프레임을 송신하므로 응답자가 일정하지 않다. 예를 들어, 1번 채널에서 프로브 요청 프레임을 송신하고 1번 채널에서 프로브 응답 프레임을 수신한 STA은, 수신한 프로브 응답 프레임에 포함된 BSS 관련 정보를 저장하고 다음 채널(예를 들어, 2번 채널)로 이동하여 동일한 방법으로 스캐닝(즉, 2번 채널 상에서 프로브 요청/응답 송수신)을 수행할 수 있다.
도 3에서 도시하고 있지 않지만, 스캐닝 동작은 수동적 스캐닝 방식으로 수행될 수도 있다. 수동적 스캐닝에서 스캐닝을 수행하는 STA은 채널들을 옮기면서 비콘 프레임을 기다린다. 비콘 프레임은 IEEE 802.11에서 정의되는 관리 프레임(management frame) 중 하나로서, 무선 네트워크의 존재를 알리고, 스캐닝을 수행하는 STA으로 하여금 무선 네트워크를 찾아서, 무선 네트워크에 참여할 수 있도록 주기적으로 송신된다. BSS에서 AP가 비콘 프레임을 주기적으로 송신하는 역할을 수행하고, IBSS에서는 IBSS 내의 STA들이 돌아가면서 비콘 프레임을 송신한다. 스캐닝을 수행하는 STA은 비콘 프레임을 수신하면 비콘 프레임에 포함된 BSS에 대한 정보를 저장하고 다른 채널로 이동하면서 각 채널에서 비콘 프레임 정보를 기록한다. 비콘 프레임을 수신한 STA은, 수신한 비콘 프레임에 포함된 BSS 관련 정보를 저장하고 다음 채널로 이동하여 동일한 방법으로 다음 채널에서 스캐닝을 수행할 수 있다. 능동적 스캐닝과 수동적 스캐닝을 비교하면, 능동적 스캐닝이 수동적 스캐닝보다 딜레이(delay) 및 전력 소모가 작은 장점이 있다.
STA이 네트워크를 발견한 후에, 단계 S320에서 인증 과정이 수행될 수 있다. 이러한 인증 과정은 후술하는 단계 S340의 보안 셋업 동작과 명확하게 구분하기 위해서 첫 번째 인증(first authentication) 과정이라고 칭할 수 있다.
인증 과정은 STA이 인증 요청 프레임(authentication request frame)을 AP에게 송신하고, 이에 응답하여 AP가 인증 응답 프레임(authentication response frame)을 STA에게 송신하는 과정을 포함한다. 인증 요청/응답에 사용되는 인증 프레임(authentication frame)은 관리 프레임에 해당한다.
인증 프레임은 인증 알고리즘 번호(authentication algorithm number), 인증 트랜잭션 시퀀스 번호(authentication transaction sequence number), 상태 코드(status code), 검문 텍스트(challenge text), RSN(Robust Security Network), 유한 순환 그룹(Finite Cyclic Group) 등에 대한 정보를 포함할 수 있다. 이는 인증 요청/응답 프레임에 포함될 수 있는 정보들의 일부 예시에 해당하며, 다른 정보로 대체되거나, 추가적인 정보가 더 포함될 수 있다.
STA은 인증 요청 프레임을 AP에게 송신할 수 있다. AP는 수신된 인증 요청 프레임에 포함된 정보에 기초하여, 해당 STA에 대한 인증을 허용할지 여부를 결정할 수 있다. AP는 인증 처리의 결과를 인증 응답 프레임을 통하여 STA에게 제공할 수 있다.
STA이 성공적으로 인증된 후에, 단계 S330에서 결합 과정이 수행될 수 있다. 결합 과정은 STA이 결합 요청 프레임(association request frame)을 AP에게 송신하고, 이에 응답하여 AP가 결합 응답 프레임(association response frame)을 STA에게 송신하는 과정을 포함한다.
예를 들어, 결합 요청 프레임은 다양한 캐퍼빌리티(capability)에 관련된 정보, 비콘 청취 간격(listen interval), SSID(service set identifier), 지원 레이트(supported rates), 지원 채널(supported channels), RSN, 이동성 도메인, 지원 오퍼레이팅 클래스(supported operating classes), TIM 브로드캐스트 요청(Traffic Indication Map Broadcast request), 상호동작(interworking) 서비스 캐퍼빌리티 등에 대한 정보를 포함할 수 있다. 예를 들어, 결합 응답 프레임은 다양한 캐퍼빌리티에 관련된 정보, 상태 코드, AID(Association ID), 지원 레이트, EDCA(Enhanced Distributed Channel Access) 파라미터 세트, RCPI(Received Channel Power Indicator), RSNI(Received Signal to Noise Indicator), 이동성 도메인, 타임아웃 간격(예를 들어, 결합 컴백 시간(association comeback time)), 중첩(overlapping) BSS 스캔 파라미터, TIM 브로드캐스트 응답, QoS(Quality of Service) 맵 등의 정보를 포함할 수 있다. 이는 결합 요청/응답 프레임에 포함될 수 있는 정보들의 일부 예시에 해당하며, 다른 정보로 대체되거나, 추가적인 정보가 더 포함될 수 있다.
STA이 네트워크에 성공적으로 결합된 후에, 단계 S340에서 보안 셋업 과정이 수행될 수 있다. 단계 S340의 보안 셋업 과정은 RSNA(Robust Security Network Association) 요청/응답을 통한 인증 과정이라고 할 수도 있고, 상기 단계 S320의 인증 과정을 첫 번째 인증(first authentication) 과정이라고 하고, 단계 S340의 보안 셋업 과정을 단순히 인증 과정이라고도 칭할 수도 있다.
단계 S340의 보안 셋업 과정은, 예를 들어, EAPOL(Extensible Authentication Protocol over LAN) 프레임을 통한 4-웨이(way) 핸드쉐이킹을 통해서, 프라이빗 키 셋업(private key setup)을 하는 과정을 포함할 수 있다. 또한, 보안 셋업 과정은 IEEE 802.11 표준에서 정의하지 않는 보안 방식에 따라 수행될 수도 있다.
도 4는 본 개시가 적용될 수 있는 백오프 과정을 설명하기 위한 도면이다.
무선랜 시스템에서, MAC(Medium Access Control)의 기본 액세스 메커니즘은 CSMA/CA(Carrier Sense Multiple Access with Collision Avoidance) 메커니즘이다. CSMA/CA 메커니즘은 IEEE 802.11 MAC의 분배 조정 기능(Distributed Coordination Function, DCF)이라고도 불리는데, 기본적으로 "말하기 전에 듣기(listen before talk)" 액세스 메커니즘을 채용하고 있다. 이러한 유형의 액세스 메커니즘 따르면, AP 및/또는 STA은 송신을 시작하기에 앞서, 소정의 시간구간(예를 들어, DIFS(DCF Inter-Frame Space) 동안 무선 채널 또는 매체(medium)를 센싱(sensing)하는 CCA(Clear Channel Assessment)를 수행할 수 있다. 센싱 결과, 만일 매체가 유휴 상태(idle status)인 것으로 판단되면, 해당 매체를 통하여 프레임 송신을 시작한다. 반면, 매체가 점유된(occupied) 또는 비지(busy) 상태인 것으로 감지되면, 해당 AP 및/또는 STA은 자기 자신의 송신을 시작하지 않고 매체 액세스를 위한 지연 기간(예를 들어, 랜덤 백오프 기간(random backoff period))을 설정하여 기다린 후에 프레임 송신을 시도할 수 있다. 랜덤 백오프 기간의 적용으로, 여러 STA들은 서로 다른 시간 동안 대기한 후에 프레임 송신을 시도할 것이 기대되므로, 충돌(collision)을 최소화시킬 수 있다.
또한, IEEE 802.11 MAC 프로토콜은 HCF(Hybrid Coordination Function)를 제공한다. HCF는 상기 DCF와 PCF(Point Coordination Function)를 기반으로 한다. PCF는 폴링(polling) 기반의 동기식 액세스 방식으로 모든 수신 AP 및/또는 STA이 데이터 프레임을 수신할 수 있도록 주기적으로 폴링하는 방식을 일컫는다. 또한, HCF는 EDCA(Enhanced Distributed Channel Access)와 HCCA(HCF Controlled Channel Access)를 가진다. EDCA는 제공자가 다수의 사용자에게 데이터 프레임을 제공하기 위한 액세스 방식을 경쟁 기반으로 하는 것이고, HCCA는 폴링(polling) 메커니즘을 이용한 비경쟁 기반의 채널 액세스 방식을 사용하는 것이다. 또한, HCF는 무선랜의 QoS(Quality of Service)를 향상시키기 위한 매체 액세스 메커니즘을 포함하며, 경쟁 기간(Contention Period, CP)와 비경쟁 기간(Contention Free Period, CFP) 모두에서 QoS 데이터를 송신할 수 있다.
도 4를 참조하여 랜덤 백오프 주기에 기반한 동작에 대해서 설명한다. 점유된/비지 상태이던 매체가 유휴 상태로 변경되면, 여러 STA들은 데이터(또는 프레임) 송신을 시도할 수 있다. 충돌을 최소화하기 위한 방안으로서, STA들은 각각 랜덤 백오프 카운트를 선택하고 그에 해당하는 슬롯 시간만큼 대기한 후에, 송신을 시도할 수 있다. 랜덤 백오프 카운트는 의사-랜덤 정수(pseudo-random integer) 값을 가지며, 0 내지 CW 범위의 값 중에서 하나로 결정될 수 있다. 여기서, CW는 경쟁 윈도우(Contention Window) 파라미터 값이다. CW 파라미터는 초기값으로 CWmin이 주어지지만, 송신 실패의 경우(예를 들어, 송신된 프레임에 대한 ACK을 수신하지 못한 경우)에 2 배의 값을 취할 수 있다. CW 파라미터 값이 CWmax가 되면 데이터 송신이 성공할 때까지 CWmax 값을 유지하면서 데이터 송신을 시도할 수 있고, 데이터 송신이 성공하는 경우에는 CWmin 값으로 리셋된다. CW, CWmin 및 CWmax 값은 2n-1 (n=0, 1, 2, ...)로 설정되는 것이 바람직하다.
랜덤 백오프 과정이 시작되면 STA은 결정된 백오프 카운트 값에 따라서 백오프 슬롯을 카운트 다운하는 동안에 계속하여 매체를 모니터링한다. 매체가 점유상태로 모니터링되면 카운트 다운을 멈추고 대기하고, 매체가 유휴 상태가 되면 나머지 카운트 다운을 재개한다.
도 4의 예시에서 STA3의 MAC에 송신할 패킷이 도달한 경우에, STA3는 DIFS 만큼 매체가 유휴 상태인 것을 확인하고 바로 프레임을 송신할 수 있다. 나머지 STA들은 매체가 점유/비지 상태인 것을 모니터링하고 대기한다. 그 동안 STA1, STA2 및 STA5의 각각에서도 송신할 데이터가 발생할 수 있고, 각각의 STA은 매체가 유휴상태로 모니터링되면 DIFS만큼 대기한 후에, 각자가 선택한 랜덤 백오프 카운트 값에 따라 백오프 슬롯의 카운트 다운을 수행할 수 있다. STA2가 가장 작은 백오프 카운트 값을 선택하고, STA1이 가장 큰 백오프 카운트 값을 선택한 경우를 가정한다. 즉, STA2가 백오프 카운트를 마치고 프레임 송신을 시작하는 시점에서 STA5의 잔여 백오프 시간은 STA1의 잔여 백오프 시간보다 짧은 경우를 예시한다. STA1 및 STA5는 STA2가 매체를 점유하는 동안에 잠시 카운트 다운을 멈추고 대기한다. STA2의 점유가 종료되어 매체가 다시 유휴 상태가 되면, STA1 및 STA5는 DIFS만큼 대기한 후에, 멈추었던 백오프 카운트를 재개한다. 즉, 잔여 백오프 시간만큼의 나머지 백오프 슬롯을 카운트 다운한 후에 프레임 송신을 시작할 수 있다. STA5의 잔여 백오프 시간이 STA1보다 짧았으므로 STA5이 프레임 송신을 시작하게 된다. STA2가 매체를 점유하는 동안에 STA4에서도 송신할 데이터가 발생할 수 있다. STA4의 입장에서는 매체가 유휴 상태가 되면 DIFS만큼 대기한 후, 자신이 선택한 랜덤 백오프 카운트 값에 따른 카운트 다운을 수행하고 프레임 송신을 시작할 수 있다. 도 4의 예시에서는 STA5의 잔여 백오프 시간이 STA4의 랜덤 백오프 카운트 값과 우연히 일치하는 경우를 나타내며, 이 경우, STA4와 STA5 간에 충돌이 발생할 수 있다. 충돌이 발생하는 경우에는 STA4와 STA5 모두 ACK을 받지 못하여, 데이터 송신을 실패하게 된다. 이 경우, STA4와 STA5는 CW 값을 2배로 늘린 후에 랜덤 백오프 카운트 값을 선택하고 카운트 다운을 수행할 수 있다. STA1은 STA4와 STA5의 송신으로 인해 매체가 점유 상태인 동안에 대기하고 있다가, 매체가 유휴 상태가 되면 DIFS만큼 대기한 후, 잔여 백오프 시간이 지나면 프레임 송신을 시작할 수 있다.
도 4의 예시에서와 같이, 데이터 프레임은 상위 레이어로 포워드되는 데이터의 송신을 위해 사용되는 프레임이며, 매체가 유휴 상태가 된 때로부터 DIFS 경과 후 수행되는 백오프 후 송신될 수 있다. 추가적으로, 관리 프레임은 상위 레이어에 포워드되지 않는 관리 정보의 교환을 위해 사용되는 프레임으로서, DIFS 또는 PIFS (Point coordination function IFS)와 같은 IFS 경과 후 수행되는 백오프 후 송신된다. 관리 프레임의 서브타입 프레임으로 비콘(Beacon), 결합 요청/응답(Association request/response), 재(re)-결합 요청/응답, 프로브 요청/응답(probe request/response), 인증 요청/응답(authentication request/response) 등이 있다. 제어 프레임은 매체에 액세스를 제어하기 위하여 사용되는 프레임이다. 제어 프레임의 서브 타입 프레임으로 RTS(Request-To-Send), CTS(Clear-To-Send), ACK(Acknowledgment), PS-Poll(Power Save-Poll), 블록 ACK(BlockAck), 블록 ACK 요청(BlockACKReq), NDP 공지(null data packet announcement), 트리거(Trigger) 등이 있다. 제어 프레임은 이전 프레임의 응답 프레임이 아닌 경우 DIFS 경과 후 수행되는 백오프 후 송신되고, 이전 프레임의 응답 프레임인 경우 SIFS(short IFS) 경과 후 백오프 수행 없이 송신된다. 프레임의 타입과 서브 타입은 프레임 제어(FC) 필드 내의 타입(type) 필드와 서브타입(subtype) 필드에 의해 식별될 수 있다.
QoS(Quality of Service) STA은 프레임이 속하는 액세스 카테고리(access category, AC)를 위한 AIFS(arbitration IFS), 즉 AIFS[i] (여기서, i는 AC에 의해 결정되는 값) 경과 후 수행되는 백오프 후 프레임을 송신할 수 있다. 여기서, AIFS[i]가 사용될 수 있는 프레임은 데이터 프레임, 관리 프레임이 될 수 있고, 또한 응답 프레임이 아닌 제어 프레임이 될 수 있다.
도 5는 본 개시가 적용될 수 있는 CSMA/CA 기반 프레임 송신 동작을 설명하기 위한 도면이다.
전술한 바와 같이 CSMA/CA 메커니즘은 STA이 매체를 직접 센싱하는 물리적 캐리어 센싱(physical carrier sensing) 외에 가상 캐리어 센싱(virtual carrier sensing)도 포함한다. 가상 캐리어 센싱은 숨겨진 노드 문제(hidden node problem) 등과 같이 매체 액세스에서 발생할 수 있는 문제를 보완하기 위한 것이다. 가상 캐리어 센싱을 위하여, STA의 MAC은 NAV(Network Allocation Vector)를 이용할 수 있다. NAV는 현재 매체를 사용하고 있거나 또는 사용할 권한이 있는 STA이, 매체가 이용 가능한 상태로 되기까지 남아 있는 시간을 다른 STA에게 지시(indicate)하는 값이다. 따라서 NAV로 설정된 값은 해당 프레임을 송신하는 STA에 의하여 매체의 사용이 예정되어 있는 기간에 해당하고, NAV 값을 수신하는 STA은 해당 기간동안 매체 액세스가 금지된다. 예를 들어, NAV는 프레임의 MAC 헤더(header)의 "duration" 필드의 값에 기초하여 설정될 수 있다.
도 5의 예시에서, STA1은 STA2로 데이터를 송신하고자 하고, STA3는 STA1과 STA2 간에 송수신되는 프레임의 일부 또는 전부를 오버히어링(overhearing)할 수 있는 위치에 있는 것으로 가정한다.
CSMA/CA 기반 프레임 송신 동작에서 다수의 STA의 송신의 충돌 가능성을 감소시키기 위해서, RTS/CTS 프레임을 이용하는 메커니즘이 적용될 수 있다. 도 5의 예시에서 STA1의 송신이 수행되는 동안 STA3의 캐리어 센싱 결과 매체가 유휴 상태라고 결정할 수도 있다. 즉, STA1은 STA3에게 히든 노드에 해당할 수 있다. 또는, 도 5의 예시에서 STA2의 송신이 수행되는 동안 STA3의 캐리어 센싱 결과 매체가 유휴 상태라고 결정할 수도 있다. 즉, STA2는 STA3에게 히든 노드에 해당할 수 있다. STA1과 STA2 간의 데이터 송수신을 수행하기 전에 RTS/CTS 프레임의 교환을 통해, STA1 또는 STA2 중의 하나의 송신 범위 밖의 STA, 또는 STA1 또는 STA3로부터의 송신에 대한 캐리어 센싱 범위 밖의 STA이, STA1과 STA2 간의 데이터 송수신 동안 채널 점유를 시도하지 않도록 할 수 있다.
구체적으로, STA1은 캐리어 센싱(carrier sensing)을 통해 채널이 사용되고 있는지를 결정할 수 있다. 물리적 캐리어 센싱의 측면에서, STA1은 채널에서 검출되는 에너지 크기 또는 신호 상관도(correlation)에 기초하여 채널 점유 유휴 상태를 결정할 수 있다. 또한, 가상 캐리어 센싱 측면에서, STA1은 NAV(network allocation vector) 타이머(timer)를 사용하여 채널의 점유 상태를 판단할 수 있다.
STA1은 DIFS 동안 채널이 유휴 상태인 경우 백오프 수행 후 RTS 프레임을 STA2에게 송신할 수 있다. STA2은 RTS 프레임을 수신한 경우 SIFS 후에 RTS 프레임에 대한 응답인 CTS 프레임을 STA1에게 송신할 수 있다.
STA3가 STA2으로부터의 CTS 프레임을 오버히어링할 수는 없지만 STA1으로부터의 RTS 프레임을 오버히어링할 수 있다면, STA3은 RTS 프레임에 포함된 듀레이션(duration) 정보를 사용하여 이후에 연속적으로 송신되는 프레임 송신 기간(예를 들어, SIFS + CTS 프레임 + SIFS + 데이터 프레임 + SIFS + ACK 프레임)에 대한 NAV 타이머를 설정할 수 있다. 또는, STA3가 STA3가 STA1으로부터의 RTS 프레임을 오버히어링할 수는 없지만 STA2로부터의 CTS 프레임을 오버히어링할 수 있다면, STA3는 CTS 프레임에 포함된 듀레이션 정보를 사용하여 이후에 연속적으로 송신되는 프레임 송신 기간(예를 들어, SIFS + 데이터 프레임 + SIFS + ACK 프레임)에 대한 NAV 타이머를 설정할 수 있다. 즉, STA3는 STA1 또는 STA2 중의 하나 이상으로부터의 RTS 또는 CTS 프레임 중의 하나 이상을 오버히어링할 수 있다면, 그에 따라 NAV를 설정할 수 있다. STA3은 NAV 타이머가 만료되기 전에 새로운 프레임을 수신한 경우 새로운 프레임에 포함된 듀레이션 정보를 사용하여 NAV 타이머를 갱신할 수 있다. STA3은 NAV 타이머가 만료되기 전까지 채널 액세스를 시도하지 않는다.
STA1은 STA2로부터 CTS 프레임을 수신한 경우 CTS 프레임의 수신이 완료된 시점부터 SIFS 후에 데이터 프레임을 STA2에게 송신할 수 있다. STA2는 데이터 프레임을 성공적으로 수신한 경우 SIFS 후에 데이터 프레임에 대한 응답인 ACK 프레임을 STA1에 송신할 수 있다. STA3는 NAV 타이머가 만료된 경우 캐리어 센싱을 통해 채널이 사용되고 있는지를 결정할 수 있다. STA3은 NAV 타이머의 만료 후부터 DIFS 동안 채널이 다른 단말에 의해 사용되지 않은 것으로 결정한 경우 랜덤 백오프에 따른 경쟁 윈도우(CW)가 지난 후에 채널 액세스를 시도할 수 있다.
도 6은 본 개시가 적용될 수 있는 무선랜 시스템에서 사용되는 프레임 구조의 예시를 설명하기 위한 도면이다.
MAC 계층으로부터의 명령어(instruction) 또는 프리머티브(primitive)(명령어들 또는 파라미터들의 세트를 의미함)에 의해서, PHY 계층은 송신될 MPDU(MAC PDU)를 준비할 수 있다. 예를 들어, PHY 계층의 송신 시작을 요청하는 명령어를 MAC 계층으로부터 받으면, PHY 계층에서는 송신 모드로 스위치하고 MAC 계층으로부터 제공되는 정보(예를 들어, 데이터)를 프레임의 형태로 구성하여 송신할 수 있다. 또한, PHY 계층에서는 수신되는 프레임의 유효한 프리앰블(preamble)을 검출하게 되면, 프리앰블의 헤더를 모니터링하여 PHY 계층의 수신 시작을 알려주는 명령어를 MAC 계층으로 보낸다.
이와 같이, 무선랜 시스템에서의 정보 송신/수신은 프레임의 형태로 이루어지며, 이를 위해서 PHY 계층 프로토콜 데이터 유닛(Physical layer Protocol Data Unit, PPDU) 포맷이 정의된다.
기본적인 PPDU는 STF(Short Training Field), LTF(Long Training Field), SIG(SIGNAL) 필드, 및 데이터(Data) 필드를 포함할 수 있다. 가장 기본적인(예를 들어, 도 7에서 도시하는 non-HT(High Throughput)) PPDU 포맷은 L-STF(Legacy-STF), L-LTF(Legacy-LTF), L-SIG(Legacy-SIG) 필드 및 데이터 필드만으로 구성될 수 있다. 또한, PPDU 포맷의 종류(예를 들어, HT-mixed 포맷 PPDU, HT-greenfield 포맷 PPDU, VHT(Very High Throughput) PPDU 등)에 따라서, L-SIG 필드와 데이터 필드 사이에 추가적인 (또는 다른 종류의) RL-SIG, U-SIG, 비-레거시 SIG 필드, 비-레거시 STF, 비-레거시 LTF, (즉, xx-SIG, xx-STF, xx-LTF (예를 들어, xx는 HT, VHT, HE, EHT 등)) 등이 포함될 수도 있다. 보다 구체적인 사항에 대해서는 도 7을 참조하여 후술한다.
STF는 신호 검출, AGC(Automatic Gain Control), 다이버시티 선택, 정밀한 시간 동기 등을 위한 신호이고, LTF는 채널 추정, 주파수 오차 추정 등을 위한 신호이다. STF와 LTF는 OFDM 물리계층의 동기화 및 채널 추정을 위한 신호라고 할 수 있다.
SIG 필드는 PPDU 송신 및 수신에 관련되는 다양한 정보를 포함할 수 있다. 예를 들어, L-SIG 필드는 24 비트로 구성되고, L-SIG 필드는 4-비트 레이트(Rate) 필드, 1-비트 유보(Reserved) 비트, 12-비트 길이(Length) 필드, 1-비트 패리티(Parity) 필드, 및 6-비트 테일(Tail) 필드를 포함할 수 있다. RATE 필드는 데이터의 변조 및 코딩 레이트에 대한 정보를 포함할 수 있다. 예를 들어, 12-비트 Length 필드는 PPDU의 길이 또는 시간 듀레이션에 관한 정보를 포함할 수 있다. 예를 들어, 12-비트 Length 필드의 값은 PPDU의 타입을 기초로 결정될 수 있다. 예를 들어, non-HT, HT, VHT, 또는 EHT PPDU에 대해서, Length 필드의 값은 3의 배수로 결정될 수 있다. 예를 들어, HE PPDU에 대해서, Length 필드의 값은 3의 배수 + 1 또는 3의 배수 + 2로 결정될 수 있다.
데이터 필드는 SERVICE 필드, PSDU(Physical layer Service Data Unit), PPDU TAIL 비트를 포함할 수 있고, 필요한 경우에는 패딩 비트도 포함할 수 있다. SERVICE 필드의 일부 비트는 수신단에서의 디스크램블러의 동기화를 위해 사용될 수 있다. PSDU는 MAC 계층에서 정의되는 MAC PDU에 대응하며, 상위 계층에서 생성/이용되는 데이터를 포함할 수 있다. PPDU TAIL 비트는 인코더를 0 상태로 리턴하기 위해서 이용될 수 있다. 패딩 비트는 데이터 필드의 길이를 소정의 단위로 맞추기 위해서 이용될 수 있다.
MAC PDU는 다양한 MAC 프레임 포맷에 따라서 정의되며, 기본적인 MAC 프레임은 MAC 헤더, 프레임 바디, 및 FCS(Frame Check Sequence)로 구성된다. MAC 프레임은 MAC PDU로 구성되어 PPDU 포맷의 데이터 부분의 PSDU를 통하여 송신/수신될 수 있다.
MAC 헤더는 프레임 제어(Frame Control) 필드, 듀레이션(Duration)/ID 필드, 주소(Address) 필드 등을 포함한다. 프레임 제어 필드는 프레임 송신/수신에 필요한 제어 정보들을 포함할 수 있다. 듀레이션/ID 필드는 해당 프레임 등을 송신하기 위한 시간으로 설정될 수 있다. 주소 서브필드들은 프레임의 수신자(receiver) 주소, 송신자(transmitter) 주소, 목적지(destination) 주소, 소스(source) 주소를 나타낼 수 있으며, 일부 주소 서브필드는 생략될 수도 있다. 시퀀스 제어(Sequence Control), QoS 제어(QoS Control), HT 제어(HT Control) 서브필드들을 포함하여, MAC 헤더의 각각의 서브필드들의 구체적인 내용은 IEEE 802.11 표준 문서를 참조할 수 있다.
널-데이터 PPDU(NDP) 포맷은 데이터 필드를 포함하지 않는 형태의 PPDU 포맷을 의미한다. 즉, NDP은, 일반적인 PPDU 포맷에서 PPDU 프리앰블(즉, L-STF, L-LTF, L-SIG 필드, 및 추가적으로 존재한다면 비-레거시 SIG, 비-레거시 STF, 비-레거시 LTF)을 포함하고, 나머지 부분(즉, 데이터 필드)은 포함하지 않는 프레임 포맷을 의미한다.
도 7은 본 개시가 적용될 수 있는 IEEE 802.11 표준에서 정의되는 PPDU의 예시들을 도시한 도면이다.
IEEE 802.11a/g/n/ac/ax 등의 표준에서는 다양한 형태의 PPDU가 사용되었다. 기본적인 PPDU 포맷(IEEE 802.11a/g)은 L-LTF, L-STF, L-SIG 및 Data 필드를 포함한다. 기본적인 PPDU 포맷을 non-HT PPDU 포맷이라 칭할 수도 있다(도 7(a)).
HT PPDU 포맷(IEEE 802.11n)은 HT-SIG, HT-STF, HT-LFT(s) 필드를 기본적인 PPDU 포맷에 추가적으로 포함한다. 도 7(b)에 도시된 HT PPDU 포맷은 HT-mixed 포맷이라고 칭할 수 있다. 추가적으로 HT-greenfield 포맷 PPDU가 정의될 수 있으며, 이는 L-STF, L-LTF, L-SIG를 포함하지 않고, HT-GF-STF, HT-LTF1, HT-SIG, 하나 이상의 HT-LTF, Data 필드로 구성되는 포맷에 해당한다 (미도시).
VHT PPDU 포맷(IEEE 802.11ac)의 일례는 VHT SIG-A, VHT-STF, VHT-LTF, VHT-SIG-B 필드를, 기본적인 PPDU 포맷에 추가적으로 포함한다(도 7(c)).
HE PPDU 포맷(IEEE 802.11ax)의 일례는 RL-SIG(Repeated L-SIG), HE-SIG-A, HE-SIG-B, HE-STF, HE-LTF(s), PE(Packet Extension) 필드를, 기본적인 PPDU 포맷에 추가적으로 포함한다(도 7(d)). HE PPDU 포맷의 세부 예시들에 따라 일부 필드가 제외되거나 그 길이가 달라질 수도 있다. 예를 들어, HE-SIG-B 필드는 다중 사용자(MU)를 위한 HE PPDU 포맷에 포함되고, 단일 사용자(SU)를 위한 HE PPDU 포맷에는 HE-SIG-B가 포함되지 않는다. 또한, HE 트리거-기반(trigger-based, TB) PPDU 포맷은 HE-SIG-B를 포함하지 않고, HE-STF 필드의 길이가 8 마이크로초(us)로 달라질 수 있다. HE ER(Extended Range) SU PPDU 포맷은 HE-SIG-B 필드를 포함하지 않고, HE-SIG-A 필드의 길이가 16us로 달라질 수 있다. 예를 들어, RL-SIG는 L-SIG와 동일하게 구성될 수 있다. 수신 STA은 RL-SIG의 존재를 기초로 수신 PPDU가 HE PPDU 또는 후술하는 EHT PPDU임을 알 수 있다.
EHT PPDU 포맷은 도 7(e)의 EHT MU(multi-user) 및 도 7(f)의 EHT TB(trigger-based) PPDU를 포함할 수 있다. EHT PPDU 포맷은 L-SIG에 후속하여 RL-SIG를 포함하는 것은 HE PPDU 포맷과 유사하지만, RL-SIG에 후속하여 U(universal)-SIG, EHT-SIG, EHT-STF, EHT-LTF를 포함할 수 있다.
도 7(e)의 EHT MU PPDU는 하나 이상의 사용자에 대한 하나 이상의 데이터(또는 PSDU)를 나르는(carry) PPDU에 해당한다. 즉, EHT MU PPDU는 SU 송신 및 MU 송신 모두를 위해서 사용될 수 있다. 예를 들어, EHT MU PPDU는 하나의 수신 STA 또는 복수의 수신 STA을 위한 PPDU에 해당할 수 있다.
도 7(f)의 EHT TB PPDU는 EHT MU PPDU에 비하여 EHT-SIG가 생략된다. UL MU 송신을 위한 트리거(예를 들어, 트리거 프레임 또는 TRS(triggered response scheduling))를 수신한 STA은, EHT TB PPDU 포맷에 기초하여 UL 송신을 수행할 수 있다.
L-STF, L-LTF, L-SIG, RL-SIG, U-SIG(Universal SIGNAL), EHT-SIG 필드들은, 레거시 STA에서도 복조 및 디코딩을 시도할 수 있도록 인코딩 및 변조되어 정해진 서브캐리어 주파수 간격(예를 들어, 312.5kHz)에 기반하여 매핑될 수 있다. 이들을 프리-EHT 변조(pre-EHT modulated) 필드들이라고 칭할 수 있다. 다음으로, EHT-STF, EHT-LTF, Data, PE 필드들은, 비-레거시 SIG(예를 들어, U-SIG 및/또는 EHT-SIG)를 성공적으로 디코딩하여 해당 필드에 포함된 정보를 획득한 STA에 의해서 복조 및 디코딩될 수 있도록 인코딩 및 변조되어 정해진 서브캐리어 주파수 간격(예를 들어, 78.125kHz)에 기반하여 매핑될 수 있다. 이들을 EHT 변조(EHT modulated) 필드들이라고 칭할 수 있다.
이와 유사하게, HE PPDU 포맷에서 L-STF, L-LTF, L-SIG, RL-SIG, HE-SIG-A, HE-SIG-B 필드들을 프리-HE 변조 필드라 칭하고, HE-STF, HE-LTF, Data, PE 필드들을 HE 변조 필드라고 칭할 수 있다. 또한, VHT PPDU 포맷에서 L-STF, L-LTF, L-SIG, VHT-SIG-A 필드들을 프리 VHT 변조 필드라고 칭하고, VHT STF, VHT-LTF, VHT-SIG-B, Data 필드들을 VHT 변조 필드라고 칭할 수 있다.
도 7의 EHT PPDU 포맷에 포함되는 U-SIG는, 예를 들어, 2개의 심볼(예를 들어, 연속하는 2 개의 OFDM 심볼)을 기초로 구성될 수 있다. U-SIG를 위한 각 심볼(예를 들어, OFDM 심볼)은 4us의 듀레이션을 가질 수 있고, U-SIG는 전체 8us의 듀레이션을 가질 수 있다. U-SIG의 각 심볼은 26 비트 정보를 송신하기 위해 사용될 수 있다. 예를 들어 U-SIG의 각 심볼은 52개의 데이터 톤과 4 개의 파일럿 톤을 기초로 송수신될 수 있다.
U-SIG는 20MHz 단위로 구성될 수 있다. 예를 들어, 80MHz PPDU가 구성되는 경우, 20MHz 단위로 동일한 U-SIG가 복제될 수 있다. 즉, 80MHz PPDU 내에 동일한 4개의 U-SIG가 포함될 수 있다. 80 MHz 대역폭을 초과하는 경우, 예를 들어, 160MHz PPDU에 대해서는 첫 번째 80MHz 단위의 U-SIG와 두 번째 80MHz 단위의 U-SIG는 상이할 수 있다.
U-SIG를 통해서는 예를 들어 A 개의 코딩되지 않은 비트(un-coded bit)가 송신될 수 있고, U-SIG의 제 1 심볼(예를 들어, U-SIG-1 심볼)은 총 A 비트 정보 중 처음 X 비트 정보를 송신하고, U-SIG의 제 2 심볼(예를 들어, U-SIG-2 심볼)은 총 A 비트 정보 중 나머지 Y 비트 정보를 송신할 수 있다. A 비트 정보(예를 들어, 52 코딩되지 않은 비트)에는 CRC 필드(예를 들어 4 비트 길이의 필드) 및 테일 필드(예를 들어 6 비트 길이의 필드)가 포함될 수 있다. 테일 필드는 컨볼루션 디코더의 트렐리스(trellis)를 종료(terminate)하기 위해 사용될 수 있고, 예를 들어 0으로 설정될 수 있다.
U-SIG에 의해 송신되는 A 비트 정보는 버전-독립적(version-independent) 비트들과 버전-종속적(version-dependent) 비트들로 구분될 수 있다. 예를 들어, 도 7에 도시하지 않은 새로운 PPDU 포맷(예를 들어, UHR PPDU 포맷)에 U-SIG가 포함될 수 있으며, EHT PPDU 포맷에 포함되는 U-SIG 필드의 포맷과, UHR PPDU 포맷에 포함되는 U-SIG 필드의 포맷에서, 버전-독립적 비트들은 동일할 수 있고, 버전-종속적 비트들은 일부 또는 전부가 상이할 수 있다.
예를 들어, U-SIG의 버전-독립적 비트들의 크기는 고정적이거나 가변적일 수 있다. 버전-독립적 비트들은 U-SIG-1 심볼에만 할당되거나, U-SIG-1 심볼 U-SIG-2 심볼 모두에 할당될 수 있다. 버전-독립적 비트들과 버전-종속적 비트들은 제 1 제어 비트 및 제 2 제어 비트 등의 다양한 명칭으로 불릴 수 있다.
예를 들어, U-SIG의 버전-독립적 비트들은 3 비트의 물리계층 버전 식별자(PHY version identifier)를 포함할 수 있으며, 이 정보는 송수신 PPDU의 PHY 버전(예를 들어, EHT, UHR 등)을 지시할 수 있다. U-SIG의 버전-독립적 비트들은 1 비트의 UL/DL 플래그(flag) 필드를 포함할 수 있다. 1-비트 UL/DL flag 필드의 제 1 값은 UL 통신에 관련되고, UL/DL flag 필드의 제 2 값은 DL 통신에 관련된다. U-SIG의 버전-독립적 비트들은 TXOP(transmission opportunity)의 길이에 관한 정보, BSS 컬러(color) ID에 관한 정보를 포함할 수 있다.
예를 들어, U-SIG의 버전-종속적 비트들은 PPDU의 타입(예를 들어, SU PPDU, MU PPDU, TB PPDU 등)을 직접적 또는 간접적으로 지시하는 정보를 포함할 수 있다.
PPDU 송수신을 위해서 필요한 정보가 U-SIG에 포함될 수 있다. 예를 들어, U-SIG는, 대역폭에 관한 정보, 비-레거시 SIG(예를 들어, EHT-SIG 또는 UHR-SIG 등)에 적용되는 MCS 기법에 대한 정보, 비-레거시 SIG에 DCM(dual carrier modulation) 기법(예를 들어, 동일한 신호를 두 개의 서브캐리어 상에서 재사용(reuse)하여 주파수 다이버시티와 유사한 효과를 달성하기 위한 기법)이 적용되는지 여부를 지시하는 정보, 비-레거시 SIG를 위해 사용되는 심볼의 개수에 대한 정보, 비-레거시 SIG가 전 대역에 걸쳐 생성되는지 여부에 대한 정보 등을 더 포함할 수 있다.
PPDU 송수신을 위해서 필요한 정보 중 일부는 U-SIG 및/또는 비-레거시 SIG(예를 들어, EHT-SIG 또는 UHR-SIG 등)에 포함될 수도 있다. 예를 들어, 비-레거시 LTF/STF(예를 들어, EHT-LTF/EHT-STF 또는 UHR-LTF/UHR-STF 등)의 타입에 대한 정보, 비-레거시 LTF의 길이 및 CP(cyclic prefix) 길이에 대한 정보, 비-레거시 LTF에 적용되는 GI(guard interval)에 대한 정보, PPDU에 적용가능한 프리앰블 펑처링(puncturing)에 대한 정보, RU(resource unit) 할당에 대한 정보 등은, U-SIG에만 포함될 수도 있고, 비-레거시 SIG에만 포함될 수도 있고, U-SIG에 포함된 정보와 비-레거시 SIG에 포함되는 정보의 조합에 의해서 지시될 수도 있다.
프리앰블 펑처링은 PPDU의 대역폭 중에서 하나 이상의 주파수 유닛에 신호가 존재(present)하지 않는 PPDU의 송신을 의미할 수 있다. 예를 들어, 주파수 유닛의 크기(또는 프리앰블 펑처링의 분해도(resolution))는 20MHz, 40MHz 등으로 정의될 수도 있다. 예를 들어, 소정의 크기 이상의 PPDU 대역폭에 대해서 프리앰블 펑처링이 적용될 수 있다.
도 7의 예시에서 HE-SIG-B, EHT-SIG 등의 비-레거시 SIG는 수신 STA을 위한 제어 정보를 포함할 수 있다. 비-레거시 SIG는 적어도 하나의 심볼을 통해 송신될 수 있고, 하나의 심볼은 4us의 길이를 가질 수 있다. EHT-SIG를 위해 사용되는 심볼의 개수에 관한 정보는 이전의 SIG(예를 들어, HE-SIG-A, U-SIG 등)에 포함될 수 있다.
HE-SIG-B, EHT-SIG 등의 비-레거시 SIG는, 공통필드(common field) 및 사용자-특정 필드(user-specific field)를 포함할 수 있다. 공통 필드 및 사용자-특정 필드는 개별적으로 코딩될 수 있다.
일부 경우에서, 공통 필드는 생략될 수도 있다. 예를 들어, 비-OFDMA(orthogonal frequency multiple access)가 적용되는 압축 모드에서 공통 필드가 생략될 수 있고, 복수의 STA은 동일한 주파수 대역을 통해 PPDU(예를 들어, PPDU의 데이터 필드)를 수신할 수 있다. OFDMA가 적용되는 비-압축 모드에서는 복수의 사용자는 상이한 주파수 대역을 통해 PPDU(예를 들어, PPDU의 데이터 필드)를 수신할 수 있다.
사용자-특정 필드의 개수는 사용자(user)의 개수를 기초로 결정될 수 있다. 하나의 사용자 블록 필드는 최대 2개의 사용자 필드(user field)를 포함할 수 있다. 각 사용자 필드(user field)는 MU-MIMO 할당에 관련되거나, 비-MU-MIMO 할당에 관련될 수 있다.
공통 필드는 CRC 비트와 Tail 비트를 포함할 수 있고, CRC 비트의 길이는 4 비트로 결정될 수 있고, Tail 비트의 길이는 6 비트로 결정되고 000000으로 설정될 수 있다. 공통 필드는 RU 할당 정보(RU allocation information)를 포함할 수 있다. RU 할당 정보는 복수의 사용자(즉, 복수의 수신 STA)이 할당되는 RU의 위치(location)에 관한 정보를 포함할 수 있다.
RU는 복수 개의 서브캐리어(또는 톤)을 포함할 수 있다. RU는 OFDMA 기법을 기초로 다수의 STA에게 신호를 송신하는 경우 사용될 수 있다. 또한 하나의 STA에게 신호를 송신하는 경우에도 RU가 정의될 수 있다. 비-레거시 STF, 비-레거시 LTF, Data 필드에 대해 RU 단위로 자원이 할당될 수 있다.
PPDU 대역폭에 따라서 적용가능한 크기의 RU가 정의될 수 있다. RU는 적용되는 PPDU 포맷(예를 들어, HE PPDU, EHT PPDU, UHR PPDU 등)에 대해서 동일하게 또는 상이하게 정의될 수도 있다. 예를 들어, 80MHz PPDU의 경우 HE PPDU와 EHT PPDU의 RU 배치가 상이할 수 있다. PPDU 대역폭 별로 적용가능한 RU의 크기, RU 개수, RU 위치, DC(direct current) 서브캐리어 위치 및 개수, 널(null) 서브캐리어 위치 및 개수, 가드 서브캐리어 위치 및 개수 등을 톤-플랜(tone-plan)이라 할 수 있다. 예를 들어, 넓은 대역폭에 대한 톤-플랜은 낮은 대역폭의 톤-플랜의 다수 반복의 형태로 정의될 수도 있다.
다양한 크기의 RU는 26-톤 RU, 52-톤 RU, 106-톤 RU, 242-톤 RU, 484-톤 RU, 996-톤 RU, 2Х996-톤 RU, 4Х996-톤 RU 등과 같이 정의될 수 있다. MRU(multiple RU)는 복수의 개별적인 RU와 구별되며, 복수의 RU로 구성되는 서브캐리어들의 그룹에 해당한다. 예를 들어, 하나의 MRU는, 52+26-톤, 106+26-톤, 484+242-톤, 996+484-톤, 996+484+242-톤, 2Х996+484-톤, 3Х996-톤, 또는 3Х996+484-톤으로 정의될 수 있다. 또한, 하나의 MRU를 구성하는 복수의 RU는 주파수 도메인에서 연속적일 수도 있고, 연속적이지 않을 수도 있다.
RU의 구체적인 크기는 축소 또는 확장될 수도 있다. 따라서, 본 개시에서 각 RU의 구체적인 크기(즉, 상응하는 톤의 개수)는 제한적이지 않으며 예시적이다. 또한, 본 개시에서 소정의 대역폭(예를 들어, 20, 40, 80, 160, 320MHz, ...) 내에서, RU의 개수는 RU 크기에 따라서 달라질 수 있다.
도 7의 PPDU 포맷들에서 각각의 필드의 명칭은 예시적인 것이며, 그 명칭에 의해서 본 개시의 범위가 제한되지 않는다. 또한, 본 개시의 예시들은, 도 7에서 예시하는 PPDU 포맷은 물론, 도 7의 PPDU 포맷들을 기반으로 일부 필드가 제외되거나 및/또는 일부 필드가 추가되는 형태의 새로운 PPDU 포맷에도 적용될 수 있다.
다중 액세스 포인트(MAP) 동작
이하에서는 다중 액세스 포인트(MAP) 동작에 대한 본 개시의 예시들에 대해서 설명한다.
MAP 동작은 마스터 AP(또는 공유하는(sharing) AP) 및 슬레이브 AP(또는 공유받는(shared) AP) 간의 동작으로 정의될 수 있다.
마스터 AP는 다수의 AP 간의 송수신을 위한 MAP 동작을 개시(initiate)하고 제어(control)하는 역할을 한다. 마스터 AP는 슬레이브 AP를 그룹화하고, 슬레이브 AP들 간 정보를 공유할 수 있도록 슬레이브 AP들과의 링크를 관리한다. 마스터 AP는 슬레이브 AP들이 구성하고 있는 BSS의 정보와, 해당 BSS에 결합(association)을 맺은 STA들의 정보를 관리한다.
슬레이브 AP는 마스터 AP와 결합을 맺고, 서로 제어 정보, 관리 정보, 데이터 트래픽을 공유할 수 있다. 슬레이브 AP는 무선랜에서의 BSS를 수립(establish)할 수 있는 AP의 기본적인 기능을 동일하게 수행한다.
MAP 동작에서의 STA은 슬레이브 AP 또는 마스터 AP와 결합을 맺고 BSS를 구성할 수 있다.
MAP 환경에서, 마스터 AP와 슬레이브 AP는 서로 직접적인 송수신을 수행할 수 있다. 마스터 AP와 STA은 서로 직접적인 송수신을 수행하지 못할 수도 있다. 슬레이브 AP(예를 들어, STA과 결합을 맺은 슬레이브 AP)는 STA과 직접적인 송수신을 수행할 수 있다. 슬레이브 AP들 중의 하나가 마스터 AP가 될 수 있다.
MAP 동작은, 하나 이상의 AP들이 하나 이상의 STA에게 정보를 전송 및 수신하는 기법이다. 예를 들어, AP 간 할당을 시간축으로 나누는 C-TDMA (coordinated-time division multiple access), 주파수축으로 나누는 C-OFDMA(coordinated-orthogonal frequency division multiple access), 공간 재사용을 이용하는 C-SR(coordinated-spatial reuse) 기법 등이 MAP 동작을 위해 적용될 수 있다. 또는, MAP 동작은 협력하여 동시에 송수신을 수행하는 협력 빔포밍(coordinated beamforming, C-BF) 또는 조인트 빔포밍(joint beamforming) 기법도 적용될 수 있다.
도 8은 본 개시가 적용될 수 있는 MAP 환경에서의 다양한 송수신 기법을 설명하기 위한 도면이다.
기존 방식과 같이 BSS AP가 BSS STA에게 송신을 수행하는 것을 STX(single transmission)이라고 칭할 수 있다. STX에서는 인접 AP와의 간섭(interference)으로 인해 셀 에지(edge)에 위치한 사용자/STA들에 대한 송수신의 성능이 떨어지는 문제가 있다. 예를 들어, 도 8(a)와 같이 AP1과 AP2가 동일한 주파수 대역폭에서 동일한 시간에 각각 STA1 및 STA2에 대한 송신을 수행하는 경우 무선 매체 상에서 충돌이 발생할 수 있다.
MAP 기법에서는 이웃 AP들간의 협력을 통해서 심볼간 간섭(ISI)을 줄이거나, 함께 송신을 수행하는 방법 등을 통해 성능을 개선할 수 있다. 예를 들어, 도 8(b)의 C-OFDMA 방식에서는 동일한 시간에 AP1은 제 1 대역폭에서 STA1에게 송신을 수행하고, AP2는 제 2 대역폭에서 STA2에게 송신을 수행함으로써 간섭을 회피할 수 있다. 도 8(c)의 예시에서는 AP1이 STA1으로의 송신을 수행하면서 AP2 및/또는 STA2에게 미치는 간섭을 널링(nulling)하고, AP2가 STA2로의 송신을 수행하면서 AP1 및/또는 STA1에게 미치는 간섭을 널링하는 협력 빔포밍 또는 널링 기법을 나타낸다. 도 8(d)에서는 인접한 AP들 중에서 채널 상태가 좋은 AP가 송신을 수행하는 AP 선택 방식을 나타낸다. 도 8(e)의 예시와 같이 다수의 AP가 협력하여 동시에 송신 또는 수신하는 조인트 송신(JTX) 또는 조인트 수신(JRX)이 적용될 수도 있으며, 나아가 조인트 MU-MIMO가 지원될 수도 있다.
RSN 동작
도 3을 참조하여 설명한 바와 같이, STA과 AP 간의 발견(discovery) 과정 이후 인증(authentication) 과정은 오픈 시스템 방식으로 수행될 수 있고, 결합(association) 과정이 수행될 수 있다. 이러한 과정은 RSN(robust security network) 지원 여부를 탐색하고 인증 및 결합을 맺는 단계 0라고 할 수 있다.
단계 0이 성공적으로 완료되면, IEEE 802.1X/EAP(extensible authentication protocol) 또는 PSK(pre-shared key)에 의한 사용자 인증 및 PMK(pairwise master key)를 확보하는 단계 1이 수행될 수 있다. 여기서 적용되는 상호 인증 방식은 802.1X/EAP, PSK, 또는 SAE(simultaneous authentication of equals) 등을 포함할 수 있다. 예를 들어, 802.1X/EAP 인증 방식의 경우에는 STA과 RADIUS(remote authentication dial-in user service) 간의 인증 후, MSK(master session key)로부터 PMK가 생성될 수 있다. PSK에 의한 사용자 인증 방식의 경우, AP와 STA은 PSK와 동일하게 PMK를 직접 설정할 수 있다. SAE에 의한 사용자 인증 방식의 경우, AP와 STA은 SAE 인증 과정을 통해서 상호 인증 및 인증 과정의 연산 값을 이용하여 PMK를 직접 설정할 수 있다.
단계 1에 후속하여 EAPoL-Key 프레임을 사용하여 상대방이 동일한 PMK를 보유하는지 확인하고, 암호키를 생성 및 공유하는 단계 2가 수행될 수 있다. 단계 2는 4-웨이 핸드셰이킹(4-way handshaking)을 통해서, PMK 생성을 상호 확인하고, 그룹 키(예를 들어, GTK(group temporal key))를 생성 및 전달하는 과정을 포함할 수 있다. 4-웨이 핸드셰이킹을 통하여 PTK(pairwise transient key), KCK(key confirmation key), KEK(key encryption key), TK(temporal key)가 생성될 수 있다.
구체적으로, 단계 1에서 MSK로부터 PMK가 생성되고, 단계 2에서 PMK로부터 PTK가 생성될 수 있다. 여기서, PTK는 KCK, KEK, TK로 분리되어 설정된다. GTK는 AP로부터 생성되어 STA에게 전달될 수 있다. AP가 새로운 GTK를 생성하고자 하는 경우 STA과의 핸드셰이킹을 수행하고 STA에게 새로운 GTK를 전달할 수도 있다.
STA과 AP가 상호 동일한 PMK를 보유하는지 확인하기 위해서, 802.1X/EAP의 경우에는 STA과 인증 서버(AS) 간의 사용자 인증 결과에 의해서 STA과 AS 간에 동일한 MSK가 설정되고, AS는 AP에게 해당 MSK를 전달한다. STA과 AP는 MSK로부터 생성되는 대칭키인 PMK의 보유 여부를 4-웨이 핸드셰이킹을 통해 서로 확인할 수 있다. PSK의 경우, AP와 STA 간에 사전에 설정된 PSK로부터 생성되는 PMK의 확보 여부를 4-웨이 핸드셰이킹을 통해 상호 검증함으로써 인증 절차를 대신할 수 있다. SAE의 경우 AP와 STA 간에 사전에 설정된 PMK를 4-웨이 핸드셰이킹을 통해 상호 검증할 수 있다.
동일한 PTK를 생성했음을 STA과 AP가 상호 검증함으로써 동일한 PMK를 보유하는지 확인할 수도 있다. 예를 들어, 4-웨이 핸드셰이킹의 메시지 2 및 메시지 3을 통해서 PMK 확보 여부를 확인할 수도 있다. 구체적으로, 메시지 2에서 STA은 자신이 생성한 PTK의 KCK를 키 MIC 필드(Key MIC field(에 포함해서 AP에게 송신할 수 있다. 메시지 3에서 AP는 자신이 생성한 PTK의 KCK의 키 MIC 필드에 포함해서 STA에게 송신할 수 있다. 이를 통해서 STA(AP)은 AP(STA)가 자신의 PTK와 동일한 PTK를 생성했음을 검증하여 AP(STA)가 자신과 동일한 PMK를 보유하는 것을 확인할 수 있다. 한편, 메시지 1에서는 키 MIC 필드의 값이 0으로 설정될 수 있고, 메시지 4에서는 키 MIC 필드에 KCK 값이 포함될 수 있다.
이와 같이, 단계 2에서 STA과 AP 간에 송수신될 데이터를 암호화하기 위한 비밀키가 생성될 수 있다. RSN에서는 AP에게 결합된 STA마다 다른 비밀키가 생성되고, STA이 다른 AP와 재-결합되는 경우 또 다른 비밀키가 생성된다.
단계 2의 4-웨이 핸드셰이킹의 결과로서 생성된 TK에 기초하여, TKIP(temporal key integrity protocol), CCMP(cipher-block chaining message authentication code protocol), GCMP(Galois/Counter Mode protocol) 등을 이용하여 데이터에 대한 암호화가 수행될 수 있으며, 이를 단계 3이라고 칭할 수 있다.
전술한 MSK, PSK, PMK, PTK, KCK, KEK, TK는 페어와이즈(pairwise), 즉, AP와 STA 간에 쌍을 이루는 키에 해당한다. 페어와이즈 키와 달리 그룹 키는, 비콘 프레임과 같이 AP가 그룹-어드레시된 프레임에 대한 비밀키 생성을 위해서 GMK(group master key)에 기초하여 생성될 수 있다. GMK는 AP가 랜덤하게 설정한다. GTK(group temporal key)는 GMK로부터 PRF(pseudorandom function) 함수에 의해서 생성되며, AP로부터 STA으로의 단방향 그룹 키에 해당한다.
도 9는 본 개시가 적용될 수 있는 4-웨이 핸드셰이킹 절차를 설명하기 위한 도면이다.
STA은 인증을 요청하는 측(supplicant)에 해당하고, AP는 인증을 하는 측(authenticator)에 해당한다. 4-웨이 핸드셰이킹은, STA이 PMK를 보유 또는 알고 있고, AP가 PMK 및 GMK를 보유 또는 알고 있는 경우에, AP 및 STA 간에 PTK 및 GTK를 생성 및 확인하기 위해서 수행될 수 있다.
ANonce 및 SNonce는 PTK 생성을 위해서 사용되는 PRF 함수에서 사용되는 인자에 해당한다. ANonce는 액세스 포인트(즉, authenticator)에 의해서 생성되는 난수(random number)에 해당할 수 있다. SNonce는 STA(즉, supplicant)에 의해서 생성되는 난수에 해당할 수 있다. PRF 함수는, 예를 들어, PMK, ANonce, SNonce, supplicant의 MAC 어드레스, authenticator의 MAC 어드레스에 기초하여 PTK를 생성하는 함수에 해당할 수 있다.
단계 S810의 메시지 1은 AP로부터 STA에게 유니캐스트 방식으로 송신되며, EAPOL-key 프레임은 ANonce 정보를 포함할 수 있다. AP가 PMK를 생성한 경우, EAPOL-key 프레임의 키 데이터 필드에 PMKID가 포함될 수 있다. STA은 AP로부터 수신한 정보에 기초하여 PTK를 생성할 수 있고, PTK에 기초하여 KCK, KEK, TK를 생성할 수 있다.
단계 S820의 메시지 2는 STA으로부터 AP에게 유니캐스트 방식으로 송신되며, EAPOL-key 프레임은 SNonce 정보 및 키 MIC(message integrity code)를 포함할 수 있다. 예를 들어, 메시지 2의 키 MIC는 STA이 생성한 KCK에 기초하는 값을 가질 수 있다. AP는 STA로부터 수신한 정보에 기초하여 PTK를 생성할 수 있고, PTK에 기초하여 KCK, KEK, TK를 생성할 수 있다. AP는 메시지 2에 포함된 값에 기초하여 생성한 PTK의 KCK 값과, 메시지 2에 포함된 키 MIC 값에 관련된 KCK 값이 동일한지 여부에 따라서, AP와 STA이 동일한 PTK를 생성한 것인지 검증할 수 있다. 또한, AP는 필요한 경우 GTK를 생성할 수 있다. GTK의 생성은 STA의 관여 없이 AP에 의해서 GMK로부터 생성될 수 있다.
단계 S830의 메시지 3는 AP로부터 STA에게 유니캐스트 방식으로 송신되며, EAPOL-key 프레임은 MIC(즉, AP가 생성한 PTK의 KCK 값에 해당), 암호화된 GTK 정보를 포함할 수 있다. 메시지 3의 암호화된 GTK는 AP가 생성한 KEK에 기초하여 암호화되어 키 데이터 필드에 포함될 수 있다. STA은 PTK를 PTK-SA(PTK-Security Association)에 저장하고, GTK를 GTK-SA에 저장할 수 있다.
단계 S840의 메시지 4는 STA으로부터 AP에게 유니캐스트 방식으로 송신되며, EAPOL-key 프레임은 MIC 정보를 포함할 수 있다. MIC를 통하여 검증 완료되면, AP는 PTK를 PTK-SA에 저장하고, GTK를 GTK-SA에 저장할 수 있다.
이와 같이 4-웨이 핸드셰이킹이 성공적으로 완료되면, 모든 트래픽을 블락(block)하는 가상 제어 포트가 언블락(ubblock)되고 암호화된 트래픽이 송수신될 수 있다. 이후 모든 유니캐스트 트래픽은 PTK에 의해서 암호화되고, 모든 멀티캐스트/브로드캐스트 트래픽은 GTK에 의해서 암호화될 수 있다.
RSNA 기밀성(confidentiality) 및 무결성(integrity) 프로토콜
RSNA에 대해서, STA들에 대한 인증 메커니즘, 키 관리 알고리즘, 암호 키 수립(cryptographic key establishment), 암호 메커니즘, FT(fast BSS transition), 강인한(robust) 관리 프레임에 대한 암호 인캡슐레이션 등이 정의될 수 있다. 예를 들어, 암호 메커니즘은, CCMP(counter mode(CTR) with cipher-block chaining message authentication code(CBC-MAC) protocol), GCMP(Galois/Counter Mode protocol) 등을 포함할 수 있다.
RSNA 보안은 TKIP(temporal key integrity protocol), CCMP, GCMP, BIP(broadcast/multicast integrity protocol), RSNA 수립 및 종료(termination) 절차, 키 관리 절차(예를 들어, 키 분배) 등의 알고리즘 및 절차를 포함할 수 있다. 예를 들어, RSNA 수립 및 종료 절차는, IEEE 802.1X 인증, SAE(simultaneous authentication of equals) 인증, IETF(internet engineering task force) RFC(request for comments) 8110에서 정의되는 OWE(opportunistic wireless encryption) 등을 포함할 수 있다.
이하에서는 CCMP(counter mode(CTR) with cipher-block chaining message authentication code(CBC-MAC) protocol)에 대해서 설명한다.
CCMP는 데이터 기밀성(confidentiality), 인증, 무결성(integrity), 및 리플레이 보호(replay protection) 등을 제공하는 프로토콜이다. CCMP는 AES(advanced encryption standard) 암호화 알고리즘의 CCM에 기초한다. CCM은 데이터 기밀성에 대한 CTR 및 인증 및 무결성에 대한 CBC-MAC를 조합한다. CCM은 MPDU 데이터 필드 및 MPDU 헤더(MAC 헤더)의 선택된 부분 양자 모두에 대한 무결성을 보호할 수 있다.
도 9는 본 개시가 적용될 수 있는 확대된(expanded) CCMP MPDU의 일 예시를 나타내는 도면이다.
보안 PV0(protocol version 0) MPDU에 대해서, CCMP-128 프로세싱은 원래의 MPDU 크기를 16 옥텟(즉, CCMP 헤더 필드에 대한 8 옥텟 및 MIC 필드에 대한 8 옥텟)만큼 확대시킨다. CCMP-256 프로세싱은 원래의 MPDU 크기를 24 옥텟(즉, CCMP 헤더 필드에 대한 8 옥텟, MIC 필드에 대한 16 옥텟)만큼 확대시킨다. CCMP 헤더 필드는 PN(packet number), ExtIV (extended initialization vector), 및 키 ID 서브필드로부터 구성(construct)된다. PN은 6 옥텟의 어레이로서 표현되는 48-비트 PN이다. PN5는 PN의 최상위(most significant) 옥텟이고, PN0은 최하위(least significant) 옥텟이다. CCMP 헤더의 세 번째 옥텟은 유보된다. 키 ID 옥텟의 ExtIV 서브필드(비트 5(B5))는 CCMP에 대해서 항상 1로 세팅되고, 비트 6(B6) 및 비트 7(B7)은 키 ID 서브필드이고, 키 ID 옥텟의 나머지 비트들은 유보된다.
도 10은 본 개시가 적용될 수 있는 CCMP 인캡슐레이션 블록 다이어그램을 나타낸다.
평문(plaintext) MPDU의 MAC 헤더로부터 AAD(additional authentication data)가 구성(construct)될 수 있다. 평문 MPDU의 A2(address 2) 및 우선순위(priority)와, 증가(increment)된 PN에 기초하여 Nonce가 구성될 수 있다. AAD 및 Nonce는, 데이터 및 TK와 함께 CCM 암호화(encryption)에 사용될 수 있다. 증가된 PN 및 키 ID에 기초하여 CCMP 헤더가 구성될 수 있다. CCM 암호화의 결과물인 데이터 및 MIC는, MAC 헤더 및 CCMP 헤더와 함께, 도 9의 예시와 같은 암호화된 MPDU를 구성할 수 있다.
도 11은 기존(conventional) AAD의 포맷의 일 예시를 나타낸다.
도 11(a)의 예시는 PV0 MPDU에 대한 기존 AAD 구성(construction)의 예시에 해당할 수 있다. FC(frame control), A1(address 1), A2(address 2), A3(address 3), SC(sequence control) 필드들은, MAC 헤더에 포함되다면, 기존 AAD에 항상 포함될 수 있다. AAD의 길이는 QC(QoS Control) 필드 및 A4(address 4) 필드의 존재(present) 또는 부재(absent)에 따라서 달라질 수 있다. 기존 AAD에 대해서, 예를 들어, QC 및 A4가 모두 부재하면 AAD 길이는 22 옥텟이고, QC가 존재하고 A4가 부재하면 AAD 길이는 24 옥텟이고, QC가 부재하고 A4가 존재하면 AAD 길이는 28 옥텟이고, QC 및 A4가 모두 존재하면 AAD 길이는 30 옥텟일 수 있다.
AAD는 MPDU 헤더로부터 구성된다. 도 11(b)를 참조하여, 기존 AAD는 MAC 헤더의 듀레이션/ID 필드를 포함하지 않고, MAC 헤더의 HT 제어 필드도 포함하지 않는다. 이는, 재전송과 같은 동작 동안 내용이 변경되거나 삽입/삭제될 수 있는 필드가 기존 AAD에 포함되지 않도록 하기 위함이다.
또한, MAC 헤더의 프레임 제어(FC) 필드의 일부 서브필드들은 마스크 아웃될(masked-out) 수 있다. 마스크-아웃은 MAC 헤더의 해당 서브필드/필드의 값을 0으로 변경하여 AAD에 포함됨을 의미한다.
예를 들어, 기존 AAD의 FC 필드에서 마스크-아웃되는 서브필드들은 다음과 같다:
데이터 프레임의 서브타입(subtype) 서브필드의 3 LSB (즉, 비트 4, 5 및 6)는 마스크-아웃되고, 비트 7은 수정되지 않고;
리트라이(retry) 서브필드는 마스크-아웃되고;
전력 관리(power management) 서브필드(즉, 비트 12)는 마스크 아웃되고;
모어 데이터(more data) 서브필드(즉, 비트 13)는 마스크-아웃 되고;
보호되는 프레임(protected frame) 서브필드(즉, 비트 14)는 수정되지 않고(즉, 1로서 남겨짐(left));
+HTC 서브필드(즉, 비트 15)는, QoS 제어 필드를 포함하는 모든 데이터 프레임에서 마스크-아웃되고, 그 외의 경우에는 수정되지 않으며;
FC 필드의 다른 서브필드들은 수정되지 않는다.
예를 들어, 기존 AAD의 시퀀스 제어(SC) 필드에서 시퀀스 번호(sequence number) 서브필드는 마스크-아웃될 수 있다.
도 11의 예시에서 도시하지는 않지만, 기존 AAD에 QoS 제어(QC) 필드가 포함되는 경우, QC 필드는 MSDU 우선순위(priority) 서브필드, QC TID(traffic identifier) 서브필드, A-MSDU 캐퍼블(capable) 서브필드, A-MSDU 존재(present) 서브필드, A-MSDU 타입 서브필드 중의 하나 이상이 MAC 헤더에 존재하는 경우, 기존 AAD에 포함될 수 있다. 기존 AAD의 QC 필드에서 그 외의 서브필드들은 마스크-아웃될 수 있다. 즉, EOSP(end of service period) 서브필드, ACK 정책 지시자(ACK policy indicator) 서브필드, TXOP 제한(limit) 서브필드, 큐 크기(queue size) 서브필드, TXOP 듀레이션 요청됨(duration requested) 서브필드, 및 AP PS 버퍼 상태(power save buffer state) 서브필드는 마스크-아웃되고 기존 AAD 구성에 사용되지 않을 수 있다.
도 12는 본 개시가 적용될 수 있는 CCMP 디캡슐레이션 블록 다이어그램을 나타낸다.
암호화된 MPDU의 MAC 헤더로부터 AAD가 구성될 수 있다. 암호화된 MPDU의 A2 및 우선순위와, PN에 기초하여 Nonce가 구성될 수 있다. AAD 및 Nonce는, MIC, 데이터 및 키와 함께 CCM 복호화(decryption)에 사용될 수 있다. CCM 복호화의 결과물인 데이터는, MAC 헤더와 함께 리플레이 체크(replay check)를 거쳐 평문 MPDU가 획득될 수 있다. 리플레이 체크는 PN 및 리플레이 카운터(replay counter)에 기초할 수 있다.
이하에서는 BIP(broadcast/multicast integrity protocol)에 대해서 설명한다.
BIP는 IGTKSA(integrity group temporal key security association) 수립 후 그룹 어드레스된 강인한 관리 프레임에 대한 데이터 무결성 및 리플레이 보호를 제공한다. 예를 들어, BIP는 BIGTKSA(beacon IGTKSA) 수립 후 비콘 프레임에 대한 데이터 무결성 및 리플레이 보호를 제공한다. BIP는 IGTK 또는 BIGTK를 사용하여 MMPDU(MAC management PDU) MIC를 계산할 수 있다. MME(management MIC element)는 관리 프레임 바디의 다른 모든 요소 뒤 및 FCS 앞에 위치할 수 있다. 즉, MME는 관리 프레임 바디의 마지막 요소로서 포함될 수 있다. MME는 요소 ID 필드, 길이 필드, 키 ID 필드, IPN(IGTK packet number)/BIPN(BIGTK packet number) 필드, 및 MIC 필드를 포함할 수 있다.
BIP에 대한 기존 AAD는 FC, A1, A2, A3에 기반하여 구성될 수 있으며, FC 내의 리트라이 서브필드(비트 11), 전력 관리 서브필드(비트 12), 및 모어 데이터 서브필드(비트 13)은 마스크-아웃되고, 다른 서브필드들은 수정되지 않을 수 있다.
이하에서는 GCMP(Galois/Counter Mode protocol)에 대해서 설명한다.
GCMP는 데이터 기밀성(confidentiality), 인증, 무결성(integrity), 및 리플레이 보호(replay protection) 등을 제공하는 프로토콜이다. EHT RSNA STA는 GCMP-256을 지원할 수 있다. GCMP는 AES(advanced encryption standard) 암호화 알고리즘의 GCM에 기초한다. GCM은 MPDU 데이터 필드 및 MPDU 헤더(MAC 헤더)의 선택된 부분 양자 모두에 대한 무결성을 보호할 수 있다.
도 13은 본 개시가 적용될 수 있는 확대된(expanded) GCMP MPDU의 일 예시를 나타내는 도면이다.
GCMP 프로세싱은 원래의 MPDU 크기를 24 옥텟(즉, GCMP 헤더 필드에 대한 8 옥텟 및 MIC 필드에 대한 16 옥텟)만큼 확대시킨다. CCMP 헤더 필드는 PN(packet number) 및 키 ID 서브필드로부터 구성(construct)된다. PN은 6 옥텟의 어레이로서 표현되는 48-비트 PN이다. PN5는 PN의 최상위(most significant) 옥텟이고, PN0은 최하위(least significant) 옥텟이다. GCMP 헤더의 세 번째 옥텟은 유보된다. 키 ID 옥텟의 ExtIV 서브필드(비트 5(B5))는 GCMP에 대해서 항상 1로 세팅되고, 비트 6(B6) 및 비트 7(B7)은 키 ID 서브필드이고, 키 ID 옥텟의 나머지 비트들은 유보된다.
도 14는 본 개시가 적용될 수 있는 GCMP 인캡슐레이션 블록 다이어그램을 나타낸다.
평문(plaintext) MPDU의 MAC 헤더로부터 AAD(additional authentication data)가 구성(construct)될 수 있다. 평문 MPDU의 A2(address 2)와, 증가(increment)된 PN에 기초하여 Nonce가 구성될 수 있다. AAD 및 Nonce는, 데이터 및 TK와 함께 GCM 암호화(encryption)에 사용될 수 있다. 증가된 PN 및 키 ID에 기초하여 GCMP 헤더가 구성될 수 있다. CCM 암호화의 결과물인 데이터는, MAC 헤더 및 CCMP 헤더와 함께, 도 13의 예시와 같은 암호화된 MPDU를 구성할 수 있다.
GCMP에 적용되는 기존 AAD의 구성은 도 11을 참조하여 설명한 바와 동일하므로, 중복되는 설명은 생략한다.
도 15는 본 개시가 적용될 수 있는 GCMP 디캡슐레이션 블록 다이어그램을 나타낸다.
암호화된 MPDU의 MAC 헤더로부터 AAD가 구성될 수 있다. 암호화된 MPDU의 A2와, PN에 기초하여 Nonce가 구성될 수 있다. AAD 및 Nonce는, 데이터 및 키와 함께 GCM 복호화(decryption)에 사용될 수 있다. GCM 복호화의 결과물인 데이터는, MAC 헤더와 함께 리플레이 체크(replay check)를 거쳐 평문 MPDU가 획득될 수 있다. 리플레이 체크는 PN 및 리플레이 카운터(replay counter)에 기초할 수 있다.
블록 ACK 프레임
블록 ACK 프레임은 제어 프레임에 해당하며, 기본적으로 다수의 데이터(예를 들어, MPDU)에 대한 다수의 ACK을 포함할 수 있다. 블록 ACK 프레임은 후술하는 바와 같은 다양한 배리언트(variant)에 따른 포맷을 가질 수 있다.
도 16은 본 개시가 적용될 수 있는 블록 ACK 프레임의 예시적인 포맷들을 나타낸다.
블록 ACK(BlockAck) 프레임 포맷은, 프레임 제어 필드, 듀레이션 필드, RA(receiver address) 필드, TA(transmitter address) 필드, BA 제어(BA control) 필드, BA 정보(BA info) 필드, FCS 필드를 포함할 수 있다.
BA 제어 필드는, BA 타입 서브필드, 메모리 킵 없음(no memory kept) 서브필드, 메모리 설정 태그(memory configuration tag) 서브필드, 관리 ACK(management ACK) 서브필드, TID_INFO 서브필드를 포함할 수 있고, 그 외의 비트 위치는 유보될(reserved) 수 있다.
BA 타입 서브필드는 표 1과 같이 BlockAck 프레임 배리언트를 지시할 수 있다.
| BA 타입 | BlockAck 프레임 배리언트 |
| 0 | 유보됨 |
| 1 | 확장된 압축(extended compressed) |
| 2 | 압축(compressed) |
| 3 | 유보됨 |
| 4-5 | 유보됨 |
| 6 | GCR(groupcast with retries) |
| 7 | EDMG(enhanced directional multi-gigabit) 멀티-TID(traffic identifier) |
| 8 | EDMG 압축(compressed) |
| 9 | 유보됨 |
| 10 | GLK-GCR(general link-groupcast with retries) |
| 11 | 멀티-STA |
| 12-15 | 유보됨 |
BA 제어 필드의 메모리 킵 없음 서브필드 및 메모리 설정 태그 서브필드는 EDMG STA이 아닌 STA에 의해서 송신되는 경우에는 유보될 수 있다. 관리 ACK 서브필드는 EDMG 멀티-TID BlockAck 배리언트 이외의 BlockAck 배리언트에서는 유보될 수 있다. TID_INFO 서브필드는 BlockAck 프레임 배리언트 타입에 기반하여 정의될 수 있다. BA 정보 필드는 BlockAck 프레임 배리언트 타입에 기반하여 정의될 수 있다.
압축 BlockAck 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 해당 BlockAck 프레임이 어떤 TID에 대해서 송신되는 것인지를 나타낼 수 있다. 압축 BlockAck 배리언트의 BA 정보 필드는, 블록 ACK 시작 시퀀스 제어 서브필드 및 블록 ACK 비트맵 서브필드를 포함할 수 있다.
확장된 압축 BlockAck 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 BlockAck 프레임이 어떤 TID에 대해서 요청되는 것인지를 나타낼 수 있다. 확장된 BlockAck 배리언트의 BA 정보 필드는, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드 및 RBUFCAP 서브필드를 포함할 수 있다.
멀티-STA BlockAck 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 유보될 수 있다. 멀티-STA BlockAck 배리언트의 BA 정보 필드는, 하나 이상의 AID TID 당 정보(per AID TID info) 서브필드를 포함할 수 있다.
AID TID 정보 서브필드는 AID11 서브필드, ACK 타입 서브필드, TID 서브필드를 포함할 수 있다.
AID11 서브필드는 AID TID 당 정보 서브필드가 의도되는 non-AP STA의 AID의 11 LSB(least significant bit)를 포함할 수 있다. AP로 송신되는 멀티-STA BlockAck 프레임에서는 AID11 서브필드의 값은 0으로 세팅될 수 있다. AID11 서브필드의 값으로서 2045는, 임의의 미결합된(any unassociated) STA의 식별자로서 사용될 수 있다. AID11 서브필드의 값이 2045로 세팅되는 경우, ACK 타입 서브필드 및 TID 서브필드는 각각 0 및 15의 값으로 세팅될 수 있다.
AID11 서브필드의 값이 2045가 아닌 경우, AID TID 당 정보 서브필드 내의 서브필드들의 존재 여부 및 크기는 ACK 타입 서브필드의 값 및 TID 서브필드의 값에 따라서 정의될 수 있다. 예를 들어, AID11 서브필드의 값이 2045가 아닌 경우, AID TID 당 정보 서브필드에는 AID TID 정보 서브필드가 포함되고, 블록 ACK 시작 시퀀스 제어 서브필드 및/또는 블록 ACK 비트맵 서브필드가 추가적으로 포함될 수 있다.
AID11 서브필드의 값이 2045인 경우, AID TID 당 정보 서브필드는, AID TID 정보 서브필드 및 RA 서브필드를 포함하고, 나머지 옥텟은 유보될 수 있다.
도 16에서 도시하지 않지만, 멀티-TID 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 BA 정보 필드에서 보고되는 정보에 대한 TID의 개수에서 1을 감산한 값을 나타낼 수 있다. 멀티-TID 배리언트의 BA 정보 필드는, 각각의 TID에 대해서 반복되는 단위를 포함할 수 있다. 하나의 단위는, 2-옥텟 TID 당 정보, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 및 8-옥텟 블록 ACK 비트맵 서브필드를 포함할 있다. TID 당 정보 서브필드는 2-비트 ACK 타입, 3-비트 블록 ACK 비트맵 서브필드 길이 서브필드, 4-비트 TID 서브필드를 포함하고, 나머지 비트들은 유보될 수 있다.
GCR BlockAck 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 해당 BlockAck 프레임이 어떤 TID에 대해서 송신되는 것인지를 나타낼 수 있다. GCR BlockAck 배리언트의 BA 정보 필드는, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 6-옥텟 GCR 그룹 어드레스 서브필드, 및 8-옥텟 블록 ACK 비트맵 서브필드를 포함할 수 있다.
GLK-GCR BlockAck 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 해당 BlockAck 프레임이 어떤 TID에 대해서 송신되는 것인지를 나타낼 수 있다. GLK-GCR BlockAck 배리언트의 BA 정보 필드는, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 6-옥텟 GCR 그룹 어드레스 서브필드, 및 8-옥텟 블록 ACK 비트맵 서브필드를 포함할 수 있다.
EDMG 압축 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 BlockAck 프레임이 어떤 TID에 대해서 요청되는 것인지를 나타낼 수 있다. EDMG 압축 배리언트의 BA 정보 필드는, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 가변 길이의 블록 ACK 비트맵 서브필드, 및 1-옥텟 RBUFCAP 서브필드를 포함할 수 있다.
EDMG 멀티-TID 배리언트의 BA 제어 필드의 TID_INFO 서브필드는 BA 정보 필드에서 보고되는 정보에 대한 TID의 개수에서 1을 감산한 값을 나타낼 수 있다. EDMG 멀티-TID 배리언트의 BA 정보 필드는, 각각의 TID에 대해서 반복되는 단위를 포함할 수 있다. 하나의 단위는, 2-옥텟 TID 당 정보, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 8/16/32/64/128-옥텟 블록 ACK 비트맵 서브필드, 및 1-옥텟 RBUFCAP 서브필드를 포함할 있다. TID 당 정보 서브필드는 2-비트 ACK 타입, 3-비트 블록 ACK 비트맵 서브필드 길이 서브필드, 4-비트 TID 서브필드를 포함하고, 나머지 비트들은 유보될 수 있다.
보호된 제어 프레임
기존 무선랜 시스템의 경우, 개별 어드레스된 데이터 프레임(예를 들어, 유니캐스트 기반 데이터 프레임) 및 관리 프레임(들)에 대해, PTK(pairwise transient key)를 이용하여 TKIP(Temporal Key Integrity Protocol)/CCMP/GCMP에 기초하는 암호화/복호화가 수행/적용될 수 있다. 또한, 그룹 어드레스된 프레임(예를 들어, 브로드캐스트 기반 데이터 프레임)에 대해, GTK(group temporal key)를 이용하여 TKIP/CCMP/GCMP에 기초하는 암호화/복호화가 수행/적용될 수 있다. 즉, CCMP/GCMP는 암호화/복호화를 수행하는 보안 프로토콜로서, SU(single-user)의 경우 PTK를 기반으로 하는 TK가 사용되며, MU(multi-user)의 경우에는 GTK를 기반으로 하는 TK가 사용될 수 있다. CCMP/GCMP는 데이터 프레임 및 관리 프레임(들)에 대한 기밀성(confidentiality) 및 무결성(integrity)을 보장할 수 있다.
또한, 그룹 어드레스된 관리 프레임(들)에 대하여, IGTK(integrity group temporal key)를 이용하여 BIP 기반의 무결성 검사가 수행될 수 있다. 특히, 비콘 프레임의 경우, BIGTK(beacon integrity group temporal key)를 이용하여 BIP 기반의 무결성 검사가 수행될 수 있다. BIP의 경우, IGTK/BIGTK을 기반으로 한 TK을 사용하여 해당 데이터 프레임의 프레임 바디(frame body)에 대한 MIC(message integrity code)을 생성하며, 이에 기초하는 무결성 검사가 수행될 수 있다. 즉, BIP는, CCMP/GCMP와 달리, 데이터 프레임 및 관리 프레임(들)에 대한 무결성만 보장할 수 있다.
CCMP 및 GCMP에 기반하는 MPDU를 구성하는 방식과 BIP에 기반하는 MMPDU(management MPDU)를 구성하는 방식은 다음과 같은 차이점을 가진다.
먼저, CCMP/GCMP의 경우, 송신 STA은 CCM/GCM으로 데이터 부분에 대한 암호화를 진행하며, 암호화된 데이터를 송신하고, 수신 STA은 수신한 암호화된 데이터를 복호화할 수 있다. 이와 달리, BIP의 경우, 송신 STA은 데이터 부분의 암호화를 진행하지 않으며, 프레임 바디(frame body)의 데이터의 무결성 검사를 위한 MIC을 생성하기 위해 해당 프로토콜을 수행할 수 있다.
다음으로, CCMP/GCMP의 경우, MPDU는 MAC 헤더, CCMP/GCMP 헤더, 암호화된 데이터, MIC (CCMP의 경우 암호화된 MIC), 및 FCS의 순서로 구성 및 송수신될 수 있다. 이와 달리, BIP의 경우, MAC 헤더, MME(management MIC element)를 포함하는 관리 프레임 바디, 및 FCS의 순서로 구성 및 송수신될 수 있다. 여기서, MME는 CCMP/GCMP 헤더의 역할을 대신하기 때문에, 키 ID 필드(Key ID field), IPN/BIPN, MIC의 정보를 포함할 수 있다.
전술한 바와 같이, 그룹 어드레스된 프레임 중 데이터 프레임 및 비콘 프레임을 포함한 관리 프레임에 대해서는 보호(protection)가 지원된다. 다만, 제어 프레임(control frame)에 대해서는 보호가 지원되지 않으며, 이에 따라 제어 프레임은 어떠한 암호화/복호화 및/또는 무결성 검사를 위한 프로토콜이 적용되지 않은 상태로 송수신된다.
다양한 종류의 제어 프레임은 ACK 프레임 및 블록 ACK 프레임을 포함할 수 있다. 예를 들어, 송신 STA이 데이터를 송신하면 수신 STA은 해당 데이터에 대하여 ACK을 송신 STA에게 송신할 수 있다. 만약 A(aggregated)-MPDU를 지원하는 STA은 다수의 MPDU에 대한 대응하는 다수의 ACK을 A-MPDU로서 구성하여 블록 ACK 형태로 송신할 수 있다. 제어 프레임의 일종인 블록 ACK 프레임은, 도 16을 참조하여 전술한 바와 같이 하나의 STA이 블록 Ack, 압축 블록 Ack 등을 송신하도록 구성되거나, 다수의 STA의 Ack을 블록 Ack, 멀티-STA 블록 Ack 등의 형태로 송신하도록 구성될 수 있다. 압축 블록 Ack과는 다르게 멀티-STA 블록 Ack의 경우 다수의 STA에 대한 Ack 정보를 포함하고, BlockAck 프레임의 BA 정보 필드 내의 AID11 서브필드를 통해서 어떤 STA이 전송한 Ack 정보인지 구별할 수 있다. 이를 통해, BlockAck 프레임에서 각 사용자에 대해서 개별적인 BlockAck 프레임이 송수신되는 방식에 비해, 멀티-STA 블록 ACK 프레임에서는 각 사용자에 대해서 개별적인 정보들은 BA 정보 필드 내에 포함되고, 중복/공통되는 정보들은 BA 제어 필드에 포함하여 오버헤드를 줄일 수 있다. 만약 해당 블록 Ack 프레임의 정보가 제3의 STA(예를 들어, 공격자)에게 노출이 된다면, 송신 STA과 수신 STA간의 데이터 송수신 여부를 확인시켜주는 역할인 Ack 정보가 훼손될 수 있다. 이에 따라, 블록 Ack에 대한 공격은 데이터 송수신 능력을 저하시키고, 이로 인한 전력/매 사용의 낭비로 이어질 수 있다.
이러한 점을 고려하여, 본 개시에서는 송신 STA과 수신 STA 간에 송수신되는 블록 ACK 프레임의 기밀성 및 무결성을 확보하기 위한 새로운 보안 기술에 대해서 설명한다.
또한, 본 개시의 설명에서, 송신 STA에 의해 송신되는 보호된 블록 ACK 프레임을 수신하는 수신 STA들은 모두 UHR STA(및/또는 UHR에 후속하는 기술을 지원하는 STA)임이 가정된다. 즉, 만일 본 개시의 제안 방법에 따라 보호된 블록 ACK 프레임을 UHR 전 STA(pre-UHR STA)(예를 들어, EHT STA, HE STA 등)이 수신한 경우, 보호된 블록 ACK 프레임에 대한 디코딩 시 오류가 발생할 수 있다.
추가적으로, 본 개시의 예시들은 제어 프레임 중 블록 ACK 프레임에 대해서 적용되는 것을 대표적인 예시로서 설명하지만, 본 개시의 예시들은 블록 ACK 프레임 이외의 다른 타입의 제어 프레임에 대해서도 확장하여 적용될 수 있다.
본 개시에서, 블록 ACK 프레임에 대해 기밀성 및 무결성 검사를 수행한다는 것은 블록 ACK 프레임에 대해 BIP/CCMP/GCMP를 확장하여 적용하는 것으로 해석될 수 있다. 이와 관련하여, 기존에 정의된 BIP/CCMP/GCMP에 대하여 제어 프레임을 위한 사항이 추가적으로 정의되거나, 제어 프레임의 기밀성 및 무결성 검사를 위한 BIP/CCMP/GCMP를 기반으로 하는 별도의 프로토콜이 새롭게 정의될 수도 있다.
이하에서는 블록 ACK 프레임에 대한 보호(즉, 기밀성 및 무결성 검사)를 지원/수행하는 본 개시의 구체적인 예시들에 대해서 설명한다. 본 개시에서 제안하는 필드, 서브필드, 요소, 파라미터, 키 등의 명칭 및 값들은 예시적인 것이며 그 명칭 및 값으로 제한되지 않는다. 또한, 별도로 구분하지 않는 한, STA은 AP STA일 수도 있고 non-AP STA일 수도 있다.
도 17은 본 개시에 따른 제 1 STA의 동작을 설명하기 위한 도면이다.
단계 S1710에서 제 1 STA은 특정 프로토콜에 기초하여 보호된 블록 ACK(BA) 프레임을 제 2 STA으로부터 수신할 수 있다.
단계 S1720에서 제 1 STA은 BA 프레임에 기초하여 AAD를 생성할 수 있다.
AAD는 수신된 BA 프레임의 평문(plain text)에 기초하여 생성될 수 있다. 즉, 보호된 BA 프레임 내의, 보호 정보가 위치하거나, MIC의 계산 범위에 해당하거나, 암호화된 부분을 제외하고, 평문 상태의 정보에 기초하여 AAD가 생성될 수 있다.
AAD는, BA 프레임의 MAC 헤더에 포함되는 하나 이상의 필드에 기초할 수 있다. 또는 AAD는 BA 프레임의 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 BA 프레임의 BA 제어 필드에 포함되는 하나 이상의 서브필드에 기초할 수 있다. 또는 AAD는 BA 프레임의 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 BA 프레임의 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초할 수 있다.
BA 프레임의 보호에 적용되는 특정 프로토콜이 BIP 등의 무결성 프로토콜인 경우, BA 프레임의 MAC 헤더, BA 제어 필드, 및 BA 정보 필드 중에서 보호 정보 필드(또는 서브필드)가 위치하는 필드를 제외한 나머지 필드 중의 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다. 예를 들어, 보호 정보 (서브)필드는, 키 ID, 패킷 번호(PN), 또는 MIC(message integrity code) 중의 하나 이상을 포함할 수 있다.
BA 프레임의 보호에 적용되는 특정 프로토콜이 BIP 등의 무결성 프로토콜인 경우, BA 프레임의 MAC 헤더, BA 제어 필드, 및 BA 정보 필드 중에서 MIC 계산 범위에 해당하는 하나 이상의 필드를 제외한 나머지 필드 중의 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다. 예를 들어, 보호 정보 (서브)필드가 위치하는 필드는 MIC 계산 범위에 해당할 수 있다.
예를 들어, 보호 정보 (서브)필드가 위치하는 또는 MIC 계산 범위에 해당하는 필드가 BA 제어 필드인 경우, BA 제어 필드를 제외한 나머지 필드들 중에서, MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성되거나, 또는 MAC 헤더에 포함되는 하나 이상의 서브필드 및 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다. 예를 들어, 보호 정보 (서브)필드가 위치하는 또는 MIC 계산 범위에 해당하는 필드가 BA 정보 필드인 경우, BA 정보 필드를 제외한 나머지 필드들 중에서, MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성되거나, 또는 MAC 헤더에 포함되는 하나 이상의 서브필드 및 BA 제어 필드에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다. 예를 들어, 보호 정보 (서브)필드가 위치하는 또는 MIC 계산 범위에 해당하는 필드가 BA 제어 필드도 아니고 BA 정보 필드도 아닌 (예를 들어, BA 정보 필드와 FCS 필드 사이의 특정 필드인) 경우, BA 제어 필드 및 BA 정보 필드를 제외한 나머지 필드인, MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다.
BA 프레임의 보호에 적용되는 특정 프로토콜이 CCMP, GCMP 등의 암호화 프로토콜인 경우, BA 프레임의 BA 제어 필드 또는 BA 정보 필드 중의 하나 이상에 대한 암호화 적용 여부에 기반하여 AAD가 구성될 수 있다.
예를 들어, BA 제어 필드 및 BA 정보 필드에 암호화가 적용되는 경우, MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다. 예를 들어, BA 제어 필드에 암호화가 적용되는 경우, MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성되거나, 또는 MAC 헤더에 포함되는 하나 이상의 서브필드 및 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다. 예를 들어, BA 정보 필드에 암호화가 적용되는 경우, MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성되거나, 또는 MAC 헤더에 포함되는 하나 이상의 서브필드 및 BA 제어 필드에 포함되는 하나 이상의 서브필드에 기초하여 AAD가 구성될 수 있다.
BA 프레임의 상기 MAC 헤더, BA 제어 필드, 또는 BA 정보 필드 중의 하나 이상의 각각에 포함되는 하나 이상의 서브필드가, AAD에 동일하게 포함될 수도 있고, 그 중의 일부 서브필드(들)은 AAD에 동일하게 포함될 수도 있고, 특정 서브필드(들)은 그 비트 값의 일부 또는 전부가 0으로 변경/세팅되어(예를 들어, 마스크-아웃되어) AAD에 포함될 수도 있다.
MAC 헤더에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, 프레임 제어 서브필드, 듀레이션 서브필드, 수신자 어드레스(RA) 서브필드, 또는 송신자 어드레스(TA) 서브필드 중 하나 이상일 수 있다. 나아가, 프레임 제어 서브필드의 하위 서브필드들인, 프로토콜 버전(protocol version) 서브필드, 타입(type) 서브필드, 서브타입(subtype) 서브필드, to DS(distribution system) 서브필드, from DS 서브필드, 모어 프래그먼트(more fragments) 서브필드, 재시도(retry) 서브필드, 전력 관리(power management) 서브필드, 모어 데이터(more data) 서브필드, 보호 프레임(protection frame) 서브필드, 또는 +HTC 서브필드 중의 하나 이상이 AAD 구성에 이용될 수도 있다.
BA 제어 필드에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, BA 타입 서브필드, 메모리 킵 없음(no memory kept) 서브필드, 메모리 설정 태그(memory configuration tag) 서브필드, 관리 ACK(management ACK) 서브필드, TID_INFO 서브필드, 또는 비트 위치 0(B0) 및 B5-B8 중의 하나 이상의 비트 위치에 대응하는 서브필드(들) 중의 하나 이상일 수 있다.
압축 BlockAck 배리언트의 BA 정보 필드에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, 블록 ACK 시작 시퀀스 제어(Block Ack starting sequence control) 서브필드, 또는 블록 ACK 비트맵 서브필드 중 하나 이상일 수 있다.
확장된 BlockAck 배리언트의 BA 정보 필드에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, 관련되는, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드, RBUFCAP(receiver buffer capacity) 서브필드 중의 하나 이상일 수 있다.
멀티-TID(traffic identifier) BlockAck 배리언트의 BA 정보 필드에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, TID 당 정보(per TID info) 서브필드, 블록 ACK 시작 시퀀스 제어 서브필드, 또는 블록 ACK 비트맵 서브필드 중의 하나 이상일 수 있다.
멀티-STA BlockAck 배리언트의 BA 정보 필드에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, AID11 서브필드, ACK 타입 서브필드, TID 서브필드, AID TID 정보 서브필드, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드, 또는 RA 서브필드 중의 하나 이상일 수 있다.
GCR(groupcast with retries) BlockAck 배리언트의 BA 정보 필드에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, 블록 ACK 시작 시퀀스 제어 서브필드, GCR 그룹 어드레스 서브필드, 또는 블록 ACK 비트맵 서브필드 중의 하나 이상일 수 있다.
GLK-GCR(general link-groupcast with retries) BlockAck 배리언트의 BA 정보 필드에 포함되는 서브필드들 중 AAD 구성에 이용되는 서브필드는, 블록 ACK 시작 시퀀스 제어 서브필드, GCR 그룹 어드레스 서브필드, 또는 블록 ACK 비트맵 서브필드 중의 하나 이상일 수 있다.
단계 S1730에서 제 1 STA은 BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상을 수행할 수 있다.
BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상은, BA 프레임에 대한 보호와 관련된 키 정보 및 전술한 AAD에 기초하여 수행될 수 있다. 예를 들어, BA 프레임은 제 1 STA으로부터 제 2 STA에게 송신된 데이터에 대한 ACK 정보를 포함할 수 있다. 여기서, BA 프레임에 대한 보호와 관련된 키 정보는, 데이터에 대한 보호를 위한 키 정보와 구별되는 키 정보일 수 있다.
전술한 단계 S1710 전에 제 1 STA와 제 2 STA 간에, BA 프레임에 대한 보호의 지원 여부, 보호된 BA 프레임의 MPDU 포맷, 또는 BlockAck AAD 타입 중의 하나 이상을 지시하는 지시 정보가 교환될 수 있다. 이러한 지시 정보는, 예를 들어, 비콘 프레임, 프로브 요청 프레임, 프로브 응답 프레임, 결합 요청 프레임, 결합 응답 프레임, 재-결합 요청 프레임, 재-결합 응답 프레임 중의 하나 이상에 포함될 수도 있고; 또는 BA 프레임 내 BA 제어 필드에 포함될 수도 있고; 또는, 특정 프로토콜이 암호화 프로토콜인 경우에는 BA 프레임 내 암호화 프로토콜 헤더(예를 들어, CCMP 헤더, GCMP 헤더)에 포함될 수도 있다.
예를 들어, BlockAck AAD 타입은, AAD가 MAC 헤더에 포함되는 하나 이상의 필드에 기초하여 구성됨을 지시하거나; 또는 AAD가 MAC 헤더에 포함되는 하나 이상의 필드 및 BA 제어 필드에 포함되는 하나 이상의 필드에 기초하여 구성됨을 지시하거나; 또는 AAD가 MAC 헤더에 포함되는 하나 이상의 필드 및 BA 정보 필드에 포함되는 하나 이상의 필드에 기초하여 구성됨을 지시할 수 있다.
예를 들어, BA 프레임에 대해 특정 프로토콜이 적용되는 경우, BA 프레임의 MAC 헤더의 프레임 제어 서브필드 내 보호된 프레임(protected frame) 서브필드는 미리 정의된 특정 값으로 세팅될 수 있다. 이에 따라, 제 1 STA은 BA 프레임이 보호된 BA 프레임임을 확인할 수도 있다.
도 17의 예시에서 설명하는 방법은 도 1의 제 1 디바이스(100)에 의해서 수행될 수 있다. 예를 들어, 도 1의 제 1 디바이스(100)의 하나 이상의 프로세서(102)는 특정 프로토콜에 기초하여 보호된 BA 프레임을 하나 이상의 송수신기(106)를 통하여 수신하고; BA 프레임에 기초하여 AAD를 생성하고; 및 AAD에 기초하여 BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상을 수행하도록 설정될 수 있다. 나아가, 제 1 디바이스(100)의 하나 이상의 메모리(104)는 하나 이상의 프로세서(102)에 의해서 실행되는 경우 도 17의 예시 또는 후술하는 예시들에서 설명하는 방법을 수행하기 위한 명령들을 저장할 수 있다.
도 18은 본 개시에 따른 제 2 STA의 동작을 설명하기 위한 도면이다.
단계 S1810에서 제 2 STA은 특정 프로토콜에 기초하여, BA 프레임에 대한 AAD를 생성할 수 있다.
송신 STA인 제 2 STA의 BA 프레임에 대한 AAD의 생성은 도 17의 수신 STA인 제 1 STA의 BA 프레임에 대한 AAD의 생성과 동일하므로, 중복되는 설명은 생략한다. 즉, BA 프레임에 대해서 특정 프로토콜에 기초한 보호가 적용되는 경우, 보호된 BA 프레임에서, 보호 정보가 위치하거나, MIC의 계산 범위에 해당하거나, 암호화된 부분을 제외하고, 수신 STA측에서 평문 상태의 정보를 획득할 수 있는 부분에 기초하여 AAD가 생성될 수 있다.
단계 S1820에서 제 2 STA은 AAD에 기초하여 보호된 BA 프레임을 제 1 STA에게 송신할 수 있다.
보호된 BA 프레임의 구성 및 이를 위하여 제 1 STA과 제 2 STA 간에 송신 또는 수신되는 지시 정보 등에 대해서는 도 17의 예시에서 설명한 내용과 동일하므로, 중복되는 설명은 생략한다.
도 18의 예시에서 설명하는 방법은 도 1의 제 2 디바이스(200)에 의해서 수행될 수 있다. 예를 들어, 도 1의 제 2 디바이스(200)의 하나 이상의 프로세서(202)는 특정 프로토콜에 기초하여, BA 프레임에 대한 AAD를 생성하고; 및 AAD에 기초하여 보호된 BA 프레임을 하나 이상의 송수신기(206)를 통하여 송신하도록 설정될 수 있다. 나아가, 제 2 디바이스(200)의 하나 이상의 메모리(204)는 하나 이상의 프로세서(202)에 의해서 실행되는 경우 도 18의 예시 또는 후술하는 예시들에서 설명하는 방법을 수행하기 위한 명령들을 저장할 수 있다.
도 17 및 도 18의 예시에서, 송신 STA은 블록 Ack 프레임에 대한 보호(예를 들어, BIP, CCMP, 또는 GCMP 기반의 보호)를 지원하는지에 대한 정보를 포함하여 수신 STA에게 공유할 수 있다. 여기서, 송신 STA과 수신 STA(들)이 모두 블록 Ack 프레임에 대한 보안을 적용하는 경우에 한하여, 송신 STA은 블록 Ack 프레임의 보호와 관련된 키 정보(예를 들어, 무결성 검사 및/또는 암호화/복호화를 위해 사용되는 키(들))를 생성 및 공유할 수 있다. 예를 들어, 블록 Ack 프레임의 무결성 검사 및/또는 암호화/복호화와 관련하여, 개별적 어드레스된 프레임(individually addressed frame)을 위한 키(들)(예를 들어, PTK 또는 BAPTK, 설명의 명료성을 위해 PTK로 통칭함) 및/또는 그룹 어드레스된 프레임(group addressed frame)을 위한 키(들)(예를 들어, GTK, IGTK, BIGTK, 또는 BAGTK, 설명의 명료성을 위해 GTK로 통칭함)이 생성 및 공유될 수 있다. 송신 STA은 수신 STA(들)에게 공유할 정보를 포함하는 블록 Ack 프레임을 구성할 수 있다. 여기서, 해당 블록 Ack 프레임은 평문 형태에 해당할 수 있다. 이에 기초하여, 송신 STA은 블록 Ack 프레임을 위한 AAD를 구성하며, 수신 STA과 공유한 (블록 Ack 프레임을 위한) 보안 키(들)에 기초하여 해당 블록 Ack 프레임에 대해 보호(예를 들어, BIP, CCMP, 또는 GCMP)를 적용할 수 있다. 송신 STA은 보호가 적용된 값/정보(예를 들어, BIP, CCMP, 또는 GCMP 적용에 기초하는 결과 값/정보)를 포함하는 블록 Ack 프레임을 송신할 수 있다. 전술한 과정과 관련하여, 송신 STA은 송신되는 블록 Ack 프레임 내에서 BIP 관련 보호 정보 (서브)필드를 어떠한 포맷으로 구성하는지, CCMP/GCMP MPDU 포맷을 어떠한 포맷으로 구성하는지, 블록 Ack 프레임에 대한 AAD를 어떻게 구성할 것인지 등에 대한 정보를 수신 STA과 사전에 공유/협의하거나, 블록 Ack 프레임에 해당 정보를 포함하여 송신할 수도 있다.
도 17 및 도 18의 예시에서, 수신 STA은 블록 Ack 프레임에 대한 보호(예를 들어, BIP, CCMP, 또는 GCMP 기반의 보호)를 지원하는지에 대한 정보를 포함하여 송신 STA에게 공유할 수 있다. 여기서, 송신 STA과 블록 Ack 프레임의 보호와 관련된 키 정보(예를 들어, 무결성 검사 및/또는 암호화/복호화를 위해 사용되는 키(들)) 및/또는 MPDU 포맷 구성에 대한 정보를 공유하는 경우, 수신 STA은 송신 STA에 의해 송신된 블록 Ack 프레임에 보호 방식이 적용되었음을 가정할 수 있다. 이와 관련하여, 송신 STA과 수신 STA은 키 생성 과정을 통해 상호 간 동일한 키 정보(예를 들어, PTK/GTK 등)를 생성/협의/공유하거나, 송신 STA에 의해 생성된 키 정보가 수신 STA에게 전달될 수도 있다. 예를 들어, 수신 STA은 송신 STA으로부터 송신된 블록 Ack 프레임을 수신하여 사전에 공유된 키(들), 블록 Ack 프레임 내 무결성 검사를 위한 정보의 구성 방식에 관련된 정보, 및/또는 CCMP/GCMP MPDU 포맷의 구성 방식, 블록 Ack 프레임에 대한 AAD의 구성 방식에 대한 정보를 기반으로 해당 블록 Ack 프레임에 보호가 적용되었음을 인지할 수 있다. 블록 Ack 프레임을 수신하였을 때, 수신 STA은 해당 블록 Ack 프레임에 기초하여 블록 Ack 프레임을 위한 AAD를 구성할 수 있다. 해당 AAD는 복호화 및 무결성 검사를 위해 활용될 수 있다. 이후, 수신 STA은 구성된 AAD 및 (사전에) 공유/생성/협의된 키(들)(예를 들어, PTK/GTK 등) 등을 사용하여 해당 블록 Ack 프레임에 대한 복호화 및/또는 무결성 검사를 수행할 수 있다.
도 17 및 도 18의 예시들은 본 개시의 다양한 예시들 중의 일부에 대응할 수 있다. 이하에서는 도 17 및 도 18의 예시를 포함하는 본 개시의 다양한 예시들에 대해서 보다 구체적으로 설명한다.
실시예 1
본 실시예는 블록 Ack 프레임에 대한 보호를 위한 AAD 구성 방안에 대한 것이다.
전술한 BIP, CCMP, 및 GCMP의 경우, 송신되는 프레임의 MAC 헤더(MAC header)에 포함되는 정보에 기반하여 AAD가 구성될 수 있다.
이와 관련하여, 일반 프레임의 MAC 헤더와 달리, 블록 Ack 프레임의 MAC 헤더는 프레임 제어(frame control) 필드, 듀레이션(duration) 필드, RA(receiver address) 필드, 및 TA(transmitter address) 필드로 구성된다(예를 들어, 도 16 참조).
이하에서는, 전술한 블록 Ack 프레임의 MAC 헤더에 기초하여, 블록 Ack 프레임에 대해 BIP, CCMP, 및/또는 GCMP를 적용할 때 AAD를 구성하는 구체적인 방식들을 설명한다. 본 개시에 따른 AAD를 구성함에 있어, 이하 제안되는 방식들 중 최소한 하나의 방식 또는 하나 이상의 방식들이 사용될 수 있다.
실시예 1-1
블록 Ack 프레임에 대한 보호를 위한 AAD는, 해당 블록 Ack 프레임 내 BA 제어 필드 전에 위치하는 필드들을 활용하여 구성될 수 있다.
구체적으로, AAD는 해당 블록 Ack 프레임 내 프레임 제어 필드, 듀레이션 필드, RA 필드, 및/또는 TA 필드를 활용하여 구성될 수 있다.
도 19는 본 개시의 실시예에 따른 블록 Ack 프레임의 보호를 위한 AAD 구성의 예시들을 나타낸다.
도 19(a)를 참조하면, AAD가 4가지 필드들, 즉, 프레임 제어 필드, 듀레이션 필드, RA 필드, 및 TA 필드를 모두 포함하여 구성되는 경우가 예시되지만, 이에 한정되지 않는다. 예를 들어, 블록 Ack 프레임을 위한 AAD는 프레임 제어 필드, RA 필드, 및 TA 필드만으로 구성될 수도 있다.
이와 관련하여, 프레임 제어 필드의 경우, 하위 서브필드들의 값이 모두 AAD에 포함되거나, 특정 서브필드(들)은 0으로 변경/세팅(예를 들어, 마스크-아웃)되어 포함될 수도 있다. 일 예로, 프레임 제어 필드의 하위 서브필드는 프로토콜 버전(protocol version) 서브필드, 타입(type) 서브필드, 서브타입(subtype) 서브필드, 분산 시스템에게로(to DS) 서브필드, 분산 시스템으로부터(from DS) 서브필드, 모어 프래그먼트(more fragments) 서브필드, 재시도(retry) 서브필드, 전력 관리(power management) 서브필드, 모어 데이터(more data) 서브필드, 보호 프레임(protection frame) 서브필드, +HTC 서브필드 등을 포함할 수 있다.
실시예 1-2
블록 Ack 프레임에 대한 보호를 위한 AAD는, 해당 블록 Ack 프레임 내 BA 정보 필드 전에 위치하는 필드들을 활용하여 구성될 수 있다.
구체적으로, AAD는 해당 블록 Ack 프레임 내 프레임 제어 필드, 듀레이션 필드, RA 필드, 및/또는 TA 필드 뿐만 아니라, BA 제어 필드를 추가적으로 활용하여 구성될 수 있다.
도 19(b)를 참조하면, AAD가 블록 Ack 프레임 내 프레임 제어 필드 전에 위치하는 필드들을 모두 포함하여 구성되는 경우가 예시되지만, 이에 한정되지 않는다. 예를 들어, 블록 Ack 프레임을 위한 AAD는 프레임 제어 필드, RA 필드, TA 필드, 및 BA 제어 필드만으로 구성될 수도 있다.
이하에서는 블록 Ack 프레임을 위한 AAD에 포함되는 BA 제어 필드의 예시들을 설명하며, 이하의 예시들 중의 하나가 적용되거나, 또는 복수의 예시들의 조합이 적용될 수도 있다.
예를 들어, BA 제어 필드 내의 모든 필드들의 값들이 변경 없이 AAD에 포함될 수 있다.
다른 예시로서, BA 제어 필드 내 일부 (서브)필드(들)의 값(들)은 변경 없이 AAD에 포함되고, 다른 특정 (서브)필드(들)의 값(들)의 전부 또는 일부 비트(들)이 0으로 변경/세팅(예를 들어, 마스크-아웃)되어 AAD에 포함될 수 있다. 0 값으로 변경/세팅될 수 있는 BA 제어 필드 내 특정 비트/(서브)필드(들)는, 아래의 항목들 중 하나 또는 복수를 포함할 수 있다. BX는 X 번째 비트 위치를 의미한다.
- B0 (유보된 비트)
- B1 부터 B4 까지의 BA 타입 서브필드
- B5 부터 B8 까지의 (유보된 비트)
- B9 의 메모리 킵 없음(no memory kept) 서브필드
- B10 의 메모리 설정 태그(memory configuration tag) 서브필드
- B11 의 관리 ACK(management ACK) 서브필드
- B12 부터 B15 까지의 TID_INFO 서브필드
B0 및 B5-B8은 현재 유보된 비트로 정의되어 있으나, 해당 비트 위치의 일부/전부에 특정 서브필드(들)이 정의되는 경우, 해당 서브필드(의 일부/전부 비트)는 그 값이 0으로 변경/세팅되어 AAD에 포함되거나, 또는 AAD에 포함되지 않거나, 또는 그 값의 변경 없이 AAD에 포함될 수도 있다.
실시예 1-3
블록 Ack 프레임에 대한 보호를 위한 AAD는, 해당 블록 Ack 프레임 내 BA 제어 필드 전에 위치하는 필드들 및 BA 정보 필드를 활용하여 구성될 수 있다. 예를 들어, 블록 Ack 프레임 내 BA 제어 필드를 제외한 모든 필드들을 기반으로 AAD가 구성될 수 있다.
구체적으로, AAD는 해당 블록 Ack 프레임 내 프레임 제어 필드, 듀레이션 필드, RA 필드, 및/또는 TA 필드 뿐만 아니라, BA 정보 필드를 추가적으로 활용하여 구성될 수 있다.
도 19(c)를 참조하면, AAD가 블록 Ack 프레임 내 BA 제어 필드 전에 위치하는 필드들, 및 BA 정보 필드를 모두 포함하여 구성되는 경우가 예시되지만, 이에 한정되지 않는다. 예를 들어, 블록 Ack 프레임을 위한 AAD는 프레임 제어 필드, RA 필드, TA 필드, 및 BA 정보 필드만으로 구성될 수도 있다.
BA 제어 필드에 포함되는 BA 타입 서브필드에 의해서 식별되는 다양한 블록 Ack 배리언트가 정의될 수 있다. 예를 들어, 표 1을 참조하여 설명한 바와 같이, 확장된 압축(extended compressed) 블록 Ack 배리언트, 압축(compressed) 블록 Ack 배리언트, GCR(groupcast with retries) 블록 Ack 배리언트, 멀티-TID(traffic identifier) 블록 Ack 배리언트, GLK-GCR(general link-groupcast with retries) 블록 Ack 배리언트, 멀티-STA 블록 Ack 배리언트에 따라서 정의되는 블록 Ack 프레임에 포함되는 서브필드들이 달라질 수 있다. 본 개시에서는 블록 Ack 배리언트에 따라서 블록 Ack 프레임에 포함되는 서브필드들 중에서 하나 또는 복수의 서브필드들이 AAD에 포함될 수 있다.
이하에서는 본 개시에 따른 블록 Ack 프레임을 위한 AAD에 포함되는 BA 정보 필드의 예시들을 설명하며, 이하의 예시들 중의 하나가 적용되거나, 또는 복수의 예시들의 조합이 적용될 수도 있다.
실시예 1-3-1
블록 Ack 프레임 내의 BA 정보 필드에 포함되는 모든 (서브)필드들의 값들이 변경 없이, 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
압축 BlockAck 배리언트의 BA 정보 필드에 포함되는, 블록 ACK 시작 시퀀스 제어(Block Ack starting sequence control) 서브필드 및 블록 ACK 비트맵 서브필드의 값들이 변경 없이 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
확장된 BlockAck 배리언트의 BA 정보 필드에 포함되는, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드, 및 RBUFCAP 서브필드의 값들이 변경 없이 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
멀티-TID BlockAck 배리언트의 BA 정보 필드에 포함되는, 각각의 TID에 대해서 반복되는 단위(하나의 단위에 포함되는 2-옥텟 TID 당 정보(per TID info) 서브필드, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 8-옥텟 블록 ACK 비트맵 서브필드)의 값들이 변경 없이 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
멀티-STA BlockAck 배리언트의 BA 정보 필드에 포함되는, 하나 이상의 AID TID 당 정보(per AID TID info) 서브필드(각각의 AID TID 당 정보 서브필드에 포함되는: AID11 서브필드, ACK 타입 서브필드, 및 TID 서브필드); 또는 AID TID 정보 서브필드, 블록 ACK 시작 시퀀스 제어 서브필드 및/또는 블록 ACK 비트맵 서브필드; 또는 AID TID 정보 서브필드, 및 RA 서브필드의 값들이 변경 없이 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
GCR BlockAck 배리언트의 BA 정보 필드에 포함되는, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 6-옥텟 GCR 그룹 어드레스 서브필드, 및 8-옥텟 블록 ACK 비트맵 서브필드의 값들이 변경 없이 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
GLK-GCR BlockAck 배리언트의 BA 정보 필드에 포함되는, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 6-옥텟 GCR 그룹 어드레스 서브필드, 및 8-옥텟 블록 ACK 비트맵 서브필드의 값들이 변경 없이 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
실시예 1-3-2
블록 Ack 프레임 내의 BA 정보 필드의 일부 (서브)필드(들)의 값(들)은 변경 없이 AAD에 포함되고, 다른 특정 (서브)필드(들)의 값(들)의 전부 또는 일부 비트(들)이 0으로 변경/세팅(예를 들어, 마스크-아웃)되어 AAD에 포함될 수 있다. 0 값으로 변경/세팅될 수 있는 BA 정보 필드 내 특정 비트/(서브)필드(들)는, 아래의 항목들 중 하나 또는 복수를 포함할 수 있다.
압축 BlockAck 배리언트의 BA 정보 필드에 포함되는, 블록 ACK 시작 시퀀스 제어(Block Ack starting sequence control) 서브필드 및 블록 ACK 비트맵 서브필드 중 하나 이상은, 그 일부/전부 비트의 값이 0으로 변경/세팅되어 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
확장된 BlockAck 배리언트의 BA 정보 필드에 포함되는, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드, 및 RBUFCAP 서브필드 중 하나 이상은, 그 일부/전부 비트의 값이 0으로 변경/세팅되어 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
멀티-TID BlockAck 배리언트의 BA 정보 필드에 포함되는, 각각의 TID에 대해서 반복되는 단위(하나의 단위에 포함되는 2-옥텟 TID 당 정보(per TID info) 서브필드, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 8-옥텟 블록 ACK 비트맵 서브필드) 중 하나 이상은, 그 일부/전부 비트의 값이 0으로 변경/세팅되어 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
멀티-STA BlockAck 배리언트의 BA 정보 필드에 포함되는, 하나 이상의 AID TID 당 정보(per AID TID info) 서브필드(각각의 AID TID 당 정보 서브필드에 포함되는: AID11 서브필드, ACK 타입 서브필드, 및 TID 서브필드); 또는 AID TID 정보 서브필드, 블록 ACK 시작 시퀀스 제어 서브필드 및/또는 블록 ACK 비트맵 서브필드; 또는 AID TID 정보 서브필드, 및 RA 서브필드 중 하나 이상은, 그 일부/전부 비트의 값이 0으로 변경/세팅되어 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
GCR BlockAck 배리언트의 BA 정보 필드에 포함되는, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 6-옥텟 GCR 그룹 어드레스 서브필드, 및 8-옥텟 블록 ACK 비트맵 서브필드 중 하나 이상은, 그 일부/전부 비트의 값이 0으로 변경/세팅되어 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
GLK-GCR BlockAck 배리언트의 BA 정보 필드에 포함되는, 2-옥텟 블록 ACK 시작 시퀀스 제어 서브필드, 6-옥텟 GCR 그룹 어드레스 서브필드, 및 8-옥텟 블록 ACK 비트맵 서브필드 중 하나 이상은, 그 일부/전부 비트의 값이 0으로 변경/세팅되어 블록 Ack 프레임을 위한 AAD에 포함될 수 있다.
실시예 1-4
본 개시에 따른 블록 Ack 프레임에 대한 보호(예를 들어, BIP, CCMP, 또는 GCMP)의 적용과 관련하여, 송신 STA과 수신 STA(들)은 블록 Ack 프레임에 대한 보호의 지원 여부에 대한 정보를 서로 공유할 수 있다. 해당 정보는 디스커버리 과정(예를 들어, 비콘 프레임, 프로브 응답 프레임 등) 및/또는 (재)결합 과정(예를 들어, (재)결합 요청 프레임, (재)결합 응답 프레임 등)에서 특정 요소(예를 들어, RSNXE(Extended RSN element))를 통해 공유될 수 있다.
이와 관련하여, 기존 요소(element)(예를 들어, RSNXE) 내 유보된 비트를 활용하거나, 신규 요소 내 신규 (서브)필드를 정의하여, 블록 Ack 프레임에 대한 보호 적용의 지원 여부가 공유될 수 있다. 예를 들어, 1-비트의 보호된 블록 Ack 지원 (서브)필드(protected BlockAck support (sub)field)가 새롭게 정의될 수 있으며, 1 값은 블록 Ack 프레임에 대한 보호 적용을 지원함을 의미/지시하고, 0 값은 블록 Ack 프레임에 대한 보호 적용을 지원하지 않음을 의미/지시하도록 정의될 수 있다.
만일 송신 STA 및 수신 STA이 모두 보호를 지원하고 블록 Ack 프레임에 대한 보호 적용을 지원하는 경우, 2개의 STA들은 블록 Ack 프레임에 대한 보호 적용을 수행할 수도 있다. 이와 달리, 송신 STA 및 수신 STA이 보호를 지원하지만 블록 Ack 프레임에 대한 보호 적용을 지원하지 않는 경우, 2개의 STA들은 블록 Ack 프레임에 대한 보호 적용을 수행하지 않을 수 있다. 추가적으로, 블록 Ack 프레임에 대한 보호를 적용하는 경우, 송신 STA과 수신 STA이 협상(negotiation) 과정에서 협의한 암호 스위트(cipher suite)(예를 들어, CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, 또는 BIP-CMAC-256 등)가 동일하게 사용될 수 있다. 또는, 블록 Ack 프레임에 대한 보호를 적용하기 위하여, 송신 STA과 수신 STA은 해당 블록 Ack 프레임을 위한 추가적인/별도의 암호 스위트를 협상할 수도 있다. 또는, 송신 STA 및 수신 STA이 모두 블록 Ack 프레임에 대한 보호 적용을 지원함을 명시하는 경우는 물론, 명시하지 않고 암시하는 경우(예를 들어, 보호에 관련된 정보가 구성되는 방식에 따라서 블록 Ack 프레임에 대한 보호 적용이 지원됨이 간접적으로 지시되는 경우)에도, 블록 Ack 프레임에 대한 보호 적용이 수행될 수도 있다. 또는, 블록 Ack 프레임의 수신 STA이 다수인 경우, 그 중의 일부 STA이 블록 Ack 프레임에 대한 보호 적용을 지원하지만 다른 일부 STA이 블록 Ack 프레임에 대한 보호 적용을 지원하지 않는 경우에도, 송신 STA은 블록 Ack 프레임에 대한 보호를 적용할 수도 있다.
추가적으로 또는 대안적으로, 기존 무선랜 시스템의 경우, 제어 프레임의 한 타입인 블록 Ack 프레임에 대하여, 송신 STA 및 수신 STA은 BIP, CCMP, 또는 GCMP을 기반으로 하는 보호 동작을 수행하지 않는다. 이러한 점에서, MAC 헤더 내 프레임 제어 필드의 보호된 프레임 서브필드(protected frame subfield)는 제어 프레임의 경우 유보됨(reserved)으로 세팅된다.
이와 달리, 본 개시에서 제안하는 방법에 따라 블록 Ack 프레임에 대하여 BIP, CCMP, 또는 GCMP을 적용하여 BA 제어 필드 및/또는 BA 정보 필드가 보호되는 경우, 해당 블록 Ack 프레임의 프레임 제어 필드 내 보호된 프레임 서브필드의 값은 1로 세팅된다. 이에 기초하여, 수신 STA은 보호된 프레임 서브필드의 값을 통해 해당 블록 Ack 프레임 내 BA 제어 필드 및/또는 BA 정보 필드가 보호되어 있음을 인지할 수 있다. 이와 관련하여, 블록 Ack 프레임을 보호하는 경우, 송신 STA과 수신 STA이 협상 과정에서 협의한 암호 스위트(cipher suite)(예를 들어, CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, 또는 BIP-CMAC-256 등)가 동일하게 사용될 수 있다. 또는, 블록 Ack 프레임을 보호하기 위하여, 송신 STA과 수신 STA은 해당 블록 Ack 프레임을 위한 추가적인/별도의 암호 스위트를 협상할 수도 있다.
추가적으로 또는 대안적으로, 송신 STA와 수신 STA 간에, 블록 Ack 프레임에 대한 보호(예를 들어, BIP, CCPM, 또는 GCMP) 적용의 지원 여부 및 BIP/CCMP/GCMP MPDU 포맷과 관련된 AAD 구성 방식(예를 들어, 도 19의 예시들)과 관련된 정보가 공유될 수 있다. 예를 들어, AAD 구성 방식과 관련된 정보는 AAD 구성을 명시적으로 지시하는 정보(예를 들어, 도 19의 예시들 중 하나를 지시하는 정보)이거나, AAD 구성을 암시적으로 지시하는 정보일 수 있다.
이와 관련하여, AAD 구성을 암시적으로 지시하는 정보는, BIP/CCMP/GCMP MPDU 포맷의 구조에 대한 정보일 수 있다. 일 예로, BIP의 경우, AAD 구성을 암시적으로 지시하는 정보는, 키 ID, PN 관련 정보, 및/또는 MIC를 포함하는 보호-관련 정보가 포함되는 위치에 대한 정보일 수 있다. 다른 예로, CCMP/GCMP의 경우, AAD 구성을 암시적으로 지시하는 정보는, 블록 Ack 프레임 내 암호화가 적용되는 위치(예를 들어, BA 제어 필드 및/또는 BA 정보 필드)에 대한 정보일 수 있다.
전술한 정보의 공유를 위하여, 기존 요소(예를 들어, RSNXE) 내 유보된 비트, BA 제어 필드 내 유보된 비트, 및/또는 신규 요소 내 신규 (서브)필드(예를 들어, BlockAck AAD 타입 (서브)필드(BlockAck AAD type (sub)field) 또는 보호된 블록 Ack 모드 (서브)필드)(protected BlockAck mode (sub)field, 이하 설명의 명료성을 위해 BlockAck AAD 타입 (서브)필드로 통칭함)가 정의될 수도 있다. 해당 (서브)필드는 (재)결합 과정 뿐만 아니라, 데이터 송수신 과정에서 송신 STA에 의해 비콘 프레임에 포함되거나, 수신 STA에 의해 데이터 프레임에 포함될 수 있다.
예를 들어, BlockAck AAD 타입 (서브)필드의 값이 0으로 세팅됨은, 해당 블록 Ack 프레임에 대한 보호(예를 들어, BIP, CCMP, 또는 GCMP)가 적용되지 않는 것을 의미/지시할 수 있다. 이와 달리, BlockAck AAD 타입 (서브)필드의 값이 1 이상으로 세팅됨은, 블록 Ack 프레임에 대한 보호가 적용되는 것을 의미/지시할 수 있다.
구체적인 예로, 해당 BlockAck AAD 타입 (서브)필드가 1 이상의 값으로 설정되는 경우, 해당 BlockAck AAD 타입 (서브)필드의 값은 하기 표 2와 같이 정의될 수 있다. 표 2은 예시적인 것으로, 표 2에서 설명되는 값들 중 적어도 하나의 값이 적용/정의될 수 있으며, 구체적인 값은 해당 예시와 다르게 세팅/정의될 수도 있다.
| BlockAck AAD 타입 (서브)필드의 값 | 의미 |
| 0 | 블록 Ack 프레임에 보호 적용되지 않음 |
| 1 | 실시예 1-1에 기초하여 블록 Ack 프레임을 위한 AAD 구성 |
| 2 | 실시예 1-2에 기초하여 블록 Ack 프레임을 위한 AAD 구성 |
| 3 | 실시예 1-3에 기초하여 블록 Ack 프레임을 위한 AAD 구성 |
| ... | ... |
추가적으로 또는 대안적으로, CCMP 헤더 및/또는 GCMP 헤더 내 키 ID 정보(즉, 키 ID 옥텟) 앞 부분에 존재하는 유보된 비트(reserved bit)를 BlockAck AAD 타입 (서브)필드로서 활용하여, 블록 Ack 프레임에 대한 보호(예를 들어, CCMP, 또는 GCMP) 적용의 지원 여부 및 BIP/CCMP/GCMP MPDU 포맷과 관련된 AAD 구성 방식(예를 들어, 도 19의 예시들 참고)과 관련된 정보가 공유될 수 있다. 예를 들어, AAD 구성 방식과 관련된 정보는 AAD 구성을 명시적으로 지시하는 정보(예를 들어, 도 19의 예시들 중 하나를 지시하는 정보)이거나, AAD 구성을 암시적으로 지시하는 정보일 수 있다. 이와 관련하여, AAD 구성을 암시적으로 지시하는 정보는, CCMP/GCMP MPDU 포맷의 구조에 대한 정보일 수 있다. 일 예로, AAD 구성을 암시적으로 지시하는 정보는, 블록 Ack 프레임 내 암호화가 적용되는 위치(예를 들어, BA 제어 필드 및/또는 BA 정보 필드)에 대한 정보일 수 있다.
여기서, 블록 Ack 프레임을 암호화/복호화하는 방식은, 송신 STA과 수신 STA이 협상 과정에서 협의한 암호 스위트(cipher suite)(예를 들어, CCMP-128, CCMP-256, GCMP-128, GCMP-256, BIP-GMAC-128, BIP-GMAC-256, 또는 BIP-CMAC-256등)를 동일하게 사용하거나, 블록 Ack 프레임을 위한 추가적인/별도의 암호 스위트를 협상할 수도 있다.
해당 (서브)필드는 데이터 송수신 과정에서 송신 STA에 의해 수신 STA에게 송신되는 데이터 프레임에 포함될 수 있다.
구체적인 예로, 해당 BlockAck AAD 타입 (서브)필드가 1 이상의 값으로 설정되는 경우, 해당 BlockAck AAD 타입 (서브)필드의 값은 하기 표 3과 같이 정의될 수 있다. 표 4는 예시적인 것으로, 표 3에서 설명되는 값들 중 적어도 하나의 값이 적용/정의될 수 있으며, 구체적인 값은 해당 예시와 다르게 세팅/정의될 수도 있다.
| BlockAck AAD 타입 (서브)필드의 값 | 의미 |
| 1 | 실시예 1-1에 기초하여 블록 Ack 프레임을 위한 AAD 구성 |
| 2 | 실시예 1-2에 기초하여 블록 Ack 프레임을 위한 AAD 구성 |
| 3 | 실시예 1-3에 기초하여 블록 Ack 프레임을 위한 AAD 구성 |
| ... | ... |
실시예 2본 실시예는 전술한 블록 Ack 프레임에 대한 보호 적용과 관련하여, 해당 블록 Ack 프레임을 위한 AAD를 구성하는 구체적인 방안에 대한 것이다.
먼저, 블록 Ack 프레임에 대한 보호를 위하여 BIP를 적용하는 경우에서의 AAD 구성 방식에 대해 설명한다.
이와 관련하여, 블록 Ack 프레임을 위한 AAD는 키 ID, PN(예를 들어, IPN/BIPN 등), MIC 등의 정보를 포함하는 보호 정보 (서브)필드의 블록 Ack 프레임 내 위치에 기초하여 구성될 수 있다.
예를 들어, 보호 정보 (서브)필드가 블록 Ack 프레임의 BA 정보 필드 내에 위치하는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1 또는 실시예 1-2의 방식에 기반하여 구성될 수 있다.
다른 예를 들어, 보호 정보 (서브)필드가 블록 Ack 프레임의 BA 제어 필드 내에 위치하는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1 또는 실시예 1-3의 방식에 기반하여 구성될 수 있다.
또 다른 예를 들어, 보호 정보 (서브)필드가 블록 Ack 프레임의 BA 제어 필드 및 BA 정보 필드 외에 위치하는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1의 방식에 기반하여 구성될 수 있다.
전술한 예시들을 참조하면, 블록 Ack 프레임을 위한 AAD는 BIP와 관련된 보호 정보 (서브)필드가 위치하는 필드 또는 보호 정보 (서브)필드 내 MIC의 계산 범위에 해당하는 필드(들)을 제외한 나머지 필드(들)에 기초하여 구성되는 것이 효율적일/바람직할 수 있다.
다음으로, 블록 Ack 프레임에 대한 보호를 위하여 CCMP를 적용하는 경우에서의 AAD 구성 방식에 대해 설명한다.
이와 관련하여, 블록 Ack 프레임을 위한 AAD는 BA 제어 필드 및/또는 BA 정보 필드의 암호화 여부에 기초하여 구성될 수 있다.
예를 들어, CCMP 기반의 암호화가 블록 Ack 프레임 내 BA 제어 필드 및 BA 정보 필드에 적용되는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1의 방식에 기반하여 구성될 수 있다.
다른 예를 들어, CCMP 기반의 암호화가 블록 Ack 프레임 내 BA 제어 필드에 적용되는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1 또는 실시예 1-3의 방식에 기반하여 구성될 수 있다.
또 다른 예를 들어, CCMP 기반의 암호화가 블록 Ack 프레임 내 BA 정보 필드에 적용되는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1 또는 실시예 1-2의 방식에 기반하여 구성될 수 있다.
전술한 예시들을 참조하면, 블록 Ack 프레임을 위한 AAD는 CCMP 기반의 암호화가 적용되는 필드(들)을 제외한 나머지 필드(들)에 기초하여 구성되는 것이 효율적일/바람직할 수 있다.
다음으로, 블록 Ack 프레임에 대한 보호를 위하여 GCMP를 적용하는 경우에서의 AAD 구성 방식에 대해 설명한다.
이와 관련하여, 블록 Ack 프레임을 위한 AAD는 BA 제어 필드 및/또는 BA 정보 필드의 암호화 여부에 기초하여 구성될 수 있다.
예를 들어, GCMP 기반의 암호화가 블록 Ack 프레임 내 BA 제어 필드 및 BA 정보 필드에 적용되는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1의 방식에 기반하여 구성될 수 있다.
다른 예를 들어, GCMP 기반의 암호화가 블록 Ack 프레임 내 BA 제어 필드에 적용되는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1 또는 실시예 1-3의 방식에 기반하여 구성될 수 있다.
또 다른 예를 들어, GCMP 기반의 암호화가 블록 Ack 프레임 내 BA 정보 필드에 적용되는 경우, 블록 Ack 프레임을 위한 AAD는 본 개시의 실시예 1-1 또는 실시예 1-2의 방식에 기반하여 구성될 수 있다.
전술한 예시들을 참조하면, 블록 Ack 프레임을 위한 AAD는 GCMP 기반의 암호화가 적용되는 필드(들)을 제외한 나머지 필드(들)에 기초하여 구성되는 것이 효율적일/바람직할 수 있다.
실시예 3
본 실시예는 본 개시에서 제안하는 블록 Ack 프레임 구성에 기초하여 블록 Ack 프레임에 대한 보호를 수행하는 구체적인 방안에 대한 것이다.
후술하는 예시 상황들에 대하여, 모든 송신 STA 및 수신 STA(들)이 보호된 블록 Ack 지원 (서브)필드를 통해 BIP, CCMP, 또는 GCMP 상에서 블록 Ack 프레임의 활용을 지원하는 경우 및/또는 보호된 블록 Ack 모드 (서브)필드를 통해 블록 Ack 프레임 내 BIP, CCMP/GCMP MPDU 포맷의 구성 방식을 공유하는 경우가 가정된다.
먼저, 모든 송신 STA 및 수신 STA(들)이 보호된 블록 Ack 지원 (서브)필드를 통해 블록 Ack 프레임에 대한 BIP 기반의 보호 적용을 지원하는 상황에서의 STA 동작을 설명한다.
예를 들어, 수신 STA은 송신 STA으로부터 수신한 블록 Ack 프레임의 정보에 기반하여 해당 블록 Ack 프레임을 위한 AAD를 구성할 수 있다. 이후, 수신 STA은 해당 AAD를 이용하여 해당 MPDU를 기반으로 MIC 값을 산출할 수 있다. 이때, 수신 STA은 송신 STA이 해당 MPDU를 기반으로 MIC 값을 산출할 때 수행했던 과정을 동일하게 수행하여 MIC 값을 도출할 수 있다.
이후, 수신 STA은 도출된 MIC 값과 송신 STA에 의해 송신된 MIC 값(예를 들어, 보호 정보 (서브)필드에 포함되는 MIC 정보)을 비교할 수 있다. 만일 두 개의 MIC 값이 동일하다면, 수신 STA은 획득한 MPDU의 정보를 따를 수 있다. 이와 달리, 두 개의 MIC 값이 동일하지 않다면, 수신 STA이 획득한 MPDU 내 적어도 하나의 정보가 제3의 다른 STA(예를 들어, 공격 STA)에 의해 변경되거나, 송수신 중에 손상되었음을 인지할 수 있으며, 이를 폐기(discard)할 수 있다.
다음으로, 모든 송신 STA 및 수신 STA(들)이 보호된 블록 Ack 지원 (서브)필드를 통해 블록 Ack 프레임에 대한 CCMP/GCMP 기반의 보호 적용을 지원하는 상황에서의 STA 동작을 설명한다.
예를 들어, 수신 STA은 송신 STA으로부터 수신한 MPDU의 MAC 헤더의 정보(예를 들어, 프레임 제어 필드, 듀레이션 필드, RA 필드, TA 필드 등)에 기초하여 블록 Ack 프레임을 위한 AAD를 구성할 수 있다. 이후, 수신 STA은 해당 AAD를 사용하여, MSDU에 대한 복호화를 진행할 수 있다.
수신 STA은 블록 Ack 프레임을 위해 자신이 구성한 AAD와 CCMP를 기반으로 복호화를 수행한 결과인 평문 형태의 MPDU 및 해당 MPDU를 기반으로 하는 MIC 값을 획득할 수 있다. 이때, 수신 STA은 송신 STA이 해당 MPDU를 암호화할 때 수행했던 과정을 동일하게 수행하여 MIC 값을 도출할 수 있다.
수신 STA은 도출된 MIC 값과 송신 STA에 의해 송신된 MIC 값(예를 들어, CCMP MPDU 포맷 또는 GCMP MPDU 포맷에 포함되는 MIC 정보)을 비교할 수 있다. 만일 두 개의 MIC 값이 동일하다면, 수신 STA은 획득한 평문 형태의 MPDU의 정보를 따를 수 있다. 이와 달리, 두 개의 MIC 값이 동일하지 않다면, 수신 STA이 획득한 평문 형태의 MPDU 내 적어도 하나의 정보가 제3의 다른 STA(예를 들어, 공격 STA)에 의해 변경되거나, 송수신 중에 손상되었음을 인지할 수 있으며, 이를 폐기(discard)할 수 있다.
MIC 가 암호화되는 CCMP의 경우, 수신 STA은 MPDU에 대한 복호화를 수행하여 도출된 평문 기반으로 생성/계산된 MIC를 이용하여 무결성 검사를 수행할 수 있다. MIC가 암호화되지 않는 GCMP의 경우, 수신 STA은 MPDU의 MIC 필드의 값을 이용하여 먼저 무결성 검사를 수행하고, MIC 값이 일치하는 경우에 MPDU에 대한 복호화를 수행할 수 있다.
기존의 무선랜 시스템에서 활용되는 BIP/CCMP/GCMP 등의 프로토콜은 블록 ACK 프레임과 같은 제어 프레임에 대한 보호를 제공할 수 없다. 본 개시에서는 블록 ACK 프레임과 같은 제어 프레임에 대해서 BIP/CCMP/GCMP 등의 프로토콜이 적용되는 경우 보호된 제어 프레임의 송신 또는 수신에 이용되는 AAD를 구성하는 새로운 방안을 제공할 수 있다.
이상에서 설명된 실시예들은 본 개시의 구성요소들과 특징들이 소정 형태로 결합된 것들이다. 각 구성요소 또는 특징은 별도의 명시적 언급이 없는 한 선택적인 것으로 고려되어야 한다. 각 구성요소 또는 특징은 다른 구성요소나 특징과 결합되지 않은 형태로 실시될 수 있다. 또한, 일부 구성요소들 및/또는 특징들을 결합하여 본 개시의 실시예를 구성하는 것도 가능하다. 본 개시의 실시예들에서 설명되는 동작들의 순서는 변경될 수 있다. 어느 실시예의 일부 구성이나 특징은 다른 실시예에 포함될 수 있고, 또는 다른 실시예의 대응하는 구성 또는 특징과 교체될 수 있다. 특허청구범위에서 명시적인 인용 관계가 있지 않은 청구항들을 결합하여 실시예를 구성하거나 출원 후의 보정에 의해 새로운 청구항으로 포함시킬 수 있음은 자명하다.
본 개시는 본 개시의 필수적 특징을 벗어나지 않는 범위에서 다른 특정한 형태로 구체화될 수 있음은 당업자에게 자명하다. 따라서, 상술한 상세한 설명은 모든 면에서 제한적으로 해석되어서는 아니 되고 예시적인 것으로 고려되어야 한다. 본 개시의 범위는 첨부된 청구항의 합리적 해석에 의해 결정되어야 하고, 본 개시의 등가적 범위 내에서의 모든 변경은 본 개시의 범위에 포함된다.
본 개시의 범위는 다양한 실시예의 방법에 따른 동작이 장치 또는 컴퓨터 상에서 실행되도록 하는 소프트웨어 또는 머신-실행가능한 명령들(예를 들어, 운영체제, 애플리케이션, 펌웨어(firmware), 프로그램 등), 및 이러한 소프트웨어 또는 명령 등이 저장되어 장치 또는 컴퓨터 상에서 실행 가능한 비-일시적 컴퓨터-판독가능 매체(non-transitory computer-readable medium)를 포함한다. 본 개시에서 설명하는 특징을 수행하는 프로세싱 시스템을 프로그래밍하기 위해 사용될 수 있는 명령은 저장 매체 또는 컴퓨터 판독가능 저장 매체 상에/내에 저장될 수 있고, 이러한 저장 매체를 포함하는 컴퓨터 프로그램 제품을 이용하여 본 개시에서 설명하는 특징이 구현될 수 있다. 저장 매체는 DRAM, SRAM, DDR RAM 또는 다른 랜덤 액세스 솔리드 스테이트 메모리 디바이스와 같은 고속 랜덤 액세스 메모리를 포함할 수 있지만, 이에 제한되지 않으며, 하나 이상의 자기 디스크 저장 디바이스, 광 디스크 저장 장치, 플래시 메모리 디바이스 또는 다른 비-휘발성 솔리드 스테이트 저장 디바이스와 같은 비-휘발성 메모리를 포함할 수 있다. 메모리는 선택적으로 프로세서(들)로부터 원격에 위치한 하나 이상의 저장 디바이스를 포함한다. 메모리 또는 대안적으로 메모리 내의 비-휘발성 메모리 디바이스(들)는 비-일시적 컴퓨터 판독가능 저장 매체를 포함한다. 본 개시에서 설명하는 특징은, 머신 판독가능 매체 중 임의의 하나에 저장되어 프로세싱 시스템의 하드웨어를 제어할 수 있고, 프로세싱 시스템이 본 개시의 실시예에 따른 결과를 활용하는 다른 메커니즘과 상호작용하도록 하는 소프트웨어 및/또는 펌웨어에 통합될 수 있다. 이러한 소프트웨어 또는 펌웨어는 애플리케이션 코드, 디바이스 드라이버, 운영 체제 및 실행 환경/컨테이너를 포함할 수 있지만 이에 제한되지 않는다.
본 개시에서 제안하는 방법은 IEEE 802.11 기반 시스템에 적용되는 예를 중심으로 설명하였으나, IEEE 802.11 기반 시스템 이외에도 다양한 무선랜 또는 무선 통신 시스템에 적용하는 것이 가능하다.
Claims (24)
- 특정 프로토콜에 기초하여 보호된 블록 ACK(acknowledgement) (BA) 프레임을 제 1 스테이션(STA)에 의해서 제 2 STA으로부터 수신하는 단계;상기 BA 프레임에 기초하여 AAD(additional authentication data)를 상기 제 1 STA에 의해서 생성하는 단계; 및상기 AAD에 기초하여 상기 BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상을 상기 제 1 STA에 의해서 수행하는 단계를 포함하고,상기 AAD는, 상기 BA 프레임의 MAC(medium access control) 헤더에 포함되는 하나 이상의 필드에 기초하거나, 또는 상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 상기 BA 프레임의 BA 제어 필드 또는 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초하는, 방법.
- 제 1 항에 있어서,상기 BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상은, 상기 BA 프레임에 대한 보호와 관련된 키 정보 및 상기 AAD에 기초하여 수행되는, 방법.
- 제 1 항에 있어서,상기 특정 프로토콜이 무결성 프로토콜임에 기초하여,상기 AAD는, 상기 BA 프레임의 상기 MAC 헤더, 상기 BA 제어 필드, 및 상기 BA 정보 필드 중에서, 보호 정보 필드가 위치하는 필드를 제외한, 또는 MIC(message integrity code) 계산 범위에 해당하는 하나 이상의 필드를 제외한, 나머지 필드 중의 하나 이상의 서브필드에 기초하여 구성되는, 방법.
- 제 3 항에 있어서,상기 보호 정보 필드는, 키 ID(identifier), 패킷 번호(PN), 또는 상기 MIC 중의 하나 이상을 포함하는, 방법.
- 제 1 항에 있어서,상기 특정 프로토콜이 암호화 프로토콜임에 기초하여:상기 AAD는, 상기 BA 프레임의 상기 BA 제어 필드 또는 상기 BA 정보 필드 중의 하나 이상에 대한 암호화 적용 여부에 기반하여 구성되는, 방법.
- 제 5 항에 있어서,상기 BA 프레임의 상기 BA 제어 필드 및 상기 BA 정보 필드에 암호화가 적용됨에 기초하여, 상기 AAD는 상기 MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 구성되는, 방법.
- 제 5 항에 있어서,상기 BA 프레임의 상기 BA 제어 필드에 암호화가 적용됨에 기초하여, 상기 AAD는 상기 MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 구성되거나, 또는 상기 MAC 헤더에 포함되는 하나 이상의 서브필드 및 상기 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초하여 구성되는, 방법.
- 제 5 항에 있어서,상기 BA 프레임의 상기 BA 정보 필드에 암호화가 적용됨에 기초하여, 상기 AAD는 상기 MAC 헤더에 포함되는 하나 이상의 서브필드에 기초하여 구성되거나, 또는 상기 MAC 헤더에 포함되는 하나 이상의 서브필드 및 상기 BA 제어 필드에 포함되는 하나 이상의 서브필드에 기초하여 구성되는, 방법.
- 제 1 항에 있어서,상기 BA 프레임의 상기 MAC 헤더, 상기 BA 제어 필드, 또는 상기 BA 정보 필드 중의 하나 이상의 각각에 포함되는 하나 이상의 서브필드는, 상기 AAD에 동일하게 포함되는, 방법.
- 제 1 항에 있어서,상기 BA 프레임의 상기 MAC 헤더, 상기 BA 제어 필드, 또는 상기 BA 정보 필드 중의 하나 이상의 각각에 포함되는 하나 이상의 서브필드 중, 특정 하나 이상의 서브필드의 일부 또는 전부 비트 값이 0으로 세팅되어 상기 AAD에 포함되는, 방법.
- 제 1 항에 있어서,상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드는,프레임 제어 서브필드, 듀레이션 서브필드, 수신자 어드레스(RA) 서브필드, 또는 송신자 어드레스(TA) 서브필드 중의 하나 이상을 포함하는, 방법.
- 제 11 항에 있어서,상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드는,상기 프레임 제어 서브필드에 포함되는, 프로토콜 버전(protocol version) 서브필드, 타입(type) 서브필드, 서브타입(subtype) 서브필드, to DS(distribution system) 서브필드, from DS 서브필드, 모어 프래그먼트(more fragments) 서브필드, 재시도(retry) 서브필드, 전력 관리(power management) 서브필드, 모어 데이터(more data) 서브필드, 보호 프레임(protection frame) 서브필드, 또는 +HTC 서브필드 중의 하나 이상을 더 포함하는, 방법.
- 제 1 항에 있어서,상기 BA 프레임의 상기 BA 제어 필드에 포함되는 하나 이상의 서브필드는:BA 타입 서브필드, 메모리 킵 없음(no memory kept) 서브필드, 메모리 설정 태그(memory configuration tag) 서브필드, 관리 ACK(management ACK) 서브필드, TID_INFO 서브필드, 또는 비트 위치 0(B0) 및 B5-B8 중의 하나 이상의 비트 위치에 대응하는 하나 이상의 서브필드 중의 하나 이상을 포함하는, 방법.
- 제 1 항에 있어서,상기 BA 프레임의 상기 BA 정보 필드에 포함되는 하나 이상의 서브필드는:압축 BlockAck 배리언트에 관련되는, 블록 ACK 시작 시퀀스 제어(Block Ack starting sequence control) 서브필드, 블록 ACK 비트맵 서브필드;확장된 BlockAck 배리언트에 관련되는, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드, RBUFCAP 서브필드;멀티-TID(traffic identifier) BlockAck 배리언트에 관련되는, TID 당 정보(per TID info) 서브필드, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드;멀티-STA BlockAck 배리언트에 관련되는, AID11 서브필드, ACK 타입 서브필드, TID 서브필드, AID TID 정보 서브필드, 블록 ACK 시작 시퀀스 제어 서브필드, 블록 ACK 비트맵 서브필드, RA 서브필드;GCR(groupcast with retries) BlockAck 배리언트에 관련되는, 블록 ACK 시작 시퀀스 제어 서브필드, GCR 그룹 어드레스 서브필드, 블록 ACK 비트맵 서브필드;GLK-GCR(general link-groupcast with retries) BlockAck 배리언트에 관련되는, 블록 ACK 시작 시퀀스 제어 서브필드, GCR 그룹 어드레스 서브필드, 블록 ACK 비트맵 서브필드중의 하나 이상을 포함하는, 방법.
- 제 1 항에 있어서,상기 제 1 STA와 상기 제 2 STA 간에, 상기 BA 프레임에 대한 보호의 지원 여부, 상기 보호된 BA 프레임의 MPDU(MAC protocol data unit) 포맷, 또는 BlockAck AAD 타입 중의 하나 이상을 지시하는 지시 정보가 교환되는, 방법.
- 제 15 항에 있어서,상기 지시 정보는,비콘 프레임, 프로브 요청 프레임, 프로브 응답 프레임, 결합 요청 프레임, 결합 응답 프레임, 재-결합 요청 프레임, 재-결합 응답 프레임 중의 하나 이상에 포함되거나, 또는상기 BA 프레임 내 BA 제어 필드에 포함되거나, 또는상기 특정 프로토콜이 암호화 프로토콜임에 기초하여, 상기 BA 프레임 내 암호화 프로토콜 헤더에 포함되는, 방법.
- 제 15 항에 있어서,상기 BlockAck AAD 타입은:상기 AAD가 상기 BA 프레임의 MAC 헤더에 포함되는 하나 이상의 필드에 기초하여 구성됨;상기 AAD가 상기 BA 프레임의 MAC 헤더에 포함되는 하나 이상의 필드 및 상기 BA 제어 필드에 포함되는 하나 이상의 필드에 기초하여 구성됨; 또는상기 AAD가 상기 BA 프레임의 MAC 헤더에 포함되는 하나 이상의 필드 및 상기 BA 정보 필드에 포함되는 하나 이상의 필드에 기초하여 구성됨중의 하나를 지시하는, 방법.
- 제 1 항에 있어서,상기 BA 프레임에 대해 상기 특정 프로토콜이 적용됨에 기초하여, 상기 MAC 헤더의 프레임 제어(frame control) 서브필드 내 보호된 프레임(protected frame) 서브필드는 미리 정의된 특정 값으로 세팅되는, 방법.
- 제 1 항에 있어서,상기 BA 프레임은 상기 제 1 STA으로부터 상기 제 2 STA에게 송신된 데이터에 대한 ACK 정보를 포함하고,상기 BA 프레임에 대한 보호와 관련된 키 정보는, 상기 데이터에 대한 보호를 위한 키 정보와 구별되는, 방법.
- 하나 이상의 송수신기; 및상기 하나 이상의 송수신기와 연결된 하나 이상의 프로세서를 포함하고,상기 하나 이상의 프로세서는:특정 프로토콜에 기초하여 보호된 블록 ACK(acknowledgement) (BA) 프레임을 상기 하나 이상의 송수신기를 통하여 수신하고;상기 BA 프레임에 기초하여 AAD(additional authentication data)를 생성하고; 및상기 AAD에 기초하여 상기 BA 프레임에 대한 복호화 또는 무결성 검사 중의 하나 이상을 수행하도록 설정되며,상기 AAD는, 상기 BA 프레임의 MAC(medium access control) 헤더에 포함되는 하나 이상의 필드에 기초하거나, 또는 상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 상기 BA 프레임의 BA 제어 필드 또는 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초하는, 장치.
- 특정 프로토콜에 기초하여, 블록 ACK(acknowledgement) (BA) 프레임에 대한 AAD(additional authentication data)를 제 2 스테이션(STA)에 의해서 생성하는 단계; 및상기 AAD에 기초하여 보호된 BA 프레임을, 제 2 STA에 의해서 제 1 STA에게 송신하는 단계를 포함하고,상기 AAD는, 상기 BA 프레임의 MAC(medium access control) 헤더에 포함되는 하나 이상의 필드에 기초하거나, 또는 상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 상기 BA 프레임의 BA 제어 필드 또는 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초하는, 방법.
- 하나 이상의 송수신기; 및상기 하나 이상의 송수신기와 연결된 하나 이상의 프로세서를 포함하고,상기 하나 이상의 프로세서는:특정 프로토콜에 기초하여, 블록 ACK(acknowledgement) (BA) 프레임에 대한 AAD(additional authentication data)를 생성하고; 및상기 AAD에 기초하여 보호된 BA 프레임을, 상기 하나 이상의 송수신기를 통하여 송신하도록 설정되며,상기 AAD는, 상기 BA 프레임의 MAC(medium access control) 헤더에 포함되는 하나 이상의 필드에 기초하거나, 또는 상기 BA 프레임의 상기 MAC 헤더에 포함되는 하나 이상의 서브필드, 및 상기 BA 프레임의 BA 제어 필드 또는 BA 정보 필드에 포함되는 하나 이상의 서브필드에 기초하는, 장치.
- 하나 이상의 프로세서; 및상기 하나 이상의 프로세서에 동작 가능하게 연결되고, 상기 하나 이상의 프로세서에 의해 실행됨에 기반하여, 제 1 항 내지 제 19 항 중 어느 한 항에 따른 방법을 수행하기 위한 명령들을 저장하는 하나 이상의 컴퓨터 메모리를 포함하는, 프로세싱 장치.
- 하나 이상의 프로세서에 의해서 실행되어 제 1 항 내지 제 19 항 중 어느 한 항에 따른 방법을 수행하도록 제어하는 하나 이상의 명령을 저장하는 하나 이상의 비-일시적(non-transitory) 컴퓨터 판독가능 매체.
Applications Claiming Priority (4)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR20230154821 | 2023-11-09 | ||
| KR10-2023-0154821 | 2023-11-09 | ||
| KR20240001747 | 2024-01-04 | ||
| KR10-2024-0001747 | 2024-01-04 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025101024A1 true WO2025101024A1 (ko) | 2025-05-15 |
Family
ID=95696453
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2024/017743 Pending WO2025101024A1 (ko) | 2023-11-09 | 2024-11-11 | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 |
Country Status (1)
| Country | Link |
|---|---|
| WO (1) | WO2025101024A1 (ko) |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220132306A1 (en) * | 2020-10-23 | 2022-04-28 | Apple Inc. | Protected High-Throughput Control Subfield |
-
2024
- 2024-11-11 WO PCT/KR2024/017743 patent/WO2025101024A1/ko active Pending
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20220132306A1 (en) * | 2020-10-23 | 2022-04-28 | Apple Inc. | Protected High-Throughput Control Subfield |
Non-Patent Citations (4)
| Title |
|---|
| ALFRED ASTERJADHI (QUALCOMM INC.): "Thoughts on Secure Control frames", IEEE DRAFT; 11-23-0312-00-0UHR-THOUGHTS-ON-SECURE-CONTROL-FRAMES, IEEE-SA MENTOR, PISCATAWAY, NJ USA, vol. 802.11 UHR, no. 0, 14 May 2023 (2023-05-14), Piscataway, NJ USA, pages 1 - 12, XP068203160 * |
| LIWEN CHU (NXP): "security enhancement follow up", IEEE DRAFT; 11-23-1102-00-0UHR-SECURITY-ENHANCEMENT-FOLLOW-UP, IEEE-SA MENTOR, PISCATAWAY, NJ USA, vol. 802.11 UHR, no. 0, 14 September 2023 (2023-09-14), Piscataway, NJ USA, pages 1 - 10, XP068205267 * |
| PATIL, Abhishek et al. Resolution for CIDs related to Protected BA Procedure. IEEE 802.11-22/0082r3. 20 January 2022. * |
| PATIL, ABHISHEK, MALINEN JOUNI, CHERIAN GEORGE, ASTERJADHI ALFRED: " MAC header protection.", IEEE 802.11-23/0356R1, 9 May 2023 (2023-05-09), pages 1 - 10, XP093313602 * |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2017034081A1 (ko) | 무선 통신 시스템의 데이터 전송 방법 및 장치 | |
| WO2016137064A1 (ko) | 무선 통신 시스템의 송수신 장치 및 방법 | |
| WO2023136692A1 (ko) | 무선랜 시스템에서 협력적 센싱 방법 및 장치 | |
| WO2025089897A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2024186058A1 (ko) | 무선랜 시스템에서 멀티-링크 디바이스에 기초한 로밍 방법 및 장치 | |
| WO2024186059A1 (ko) | 무선랜 시스템에서 멀티-링크 디바이스에 기초한 로밍 방법 및 장치 | |
| WO2025101024A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2025089896A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2025147145A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2025143883A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2025143879A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2025147144A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025143891A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025188141A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2025188140A1 (ko) | 무선랜 시스템에서 보호된 제어 프레임 송신 또는 수신 방법 및 장치 | |
| WO2025048620A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025048617A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025053739A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025101021A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025101023A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025042209A1 (ko) | 무선랜 시스템에서 강화된 보안에 대한 방법 및 장치 | |
| WO2025053740A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025048468A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2025089899A1 (ko) | 무선랜 시스템에서 제어 프레임에 대한 보호를 지원하는 방법 및 장치 | |
| WO2024144340A1 (ko) | 무선랜 시스템에서 다중 액세스 포인트 동작 기반 보안 키 관련 정보 송신 또는 수신 방법 및 장치 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24889210 Country of ref document: EP Kind code of ref document: A1 |