Radio communication system, radio communication apparatus, and radio communication method
Abstract
Problem to be solved.To provide a wireless communication device capable of wireless communication while ensuring a minimum security level by encryption predetermined by a communication group. In a communication system, a first wireless communication device belonging to a communication group receives a connection request frame including a notification security level from a second wireless communication device outside the communication group. The first wireless communication device stores a standard security level peculiar to the wireless communication group selected from an encryption method including non-encryption and a security level determined depending on the strength thereof. In the first wireless communication device, the notification security level is compared with the standard security level, and the connection refusal that denies the connection with the second wireless communication device or the connection permission that allows the connection with the second wireless communication device is described. The response frame is generated and transmitted to the second wireless communication device. [Selection diagram] Fig. 1
Term
Term ended
Projected expiry passed 26 December 2022, 3.7 years ago.
- Priority
- Filed
- Published
- Projected expiry
- Today
25 claims: 6 independent, 19 dependent
- 1通知セキュリティレベルが記述された第1のフィールドを有する第1の送信フレームを通信グループ外の無線通信装置から受信する受信部と、非暗号化を含む暗号化方法及び暗号化の強さに依存するセキュリティレベルから選定され、前記無線通信グループに割り当てられた基準セキュリティレベルを記憶するメモリ部と、前記通知セキュリティレベルを前記基準セキュリティレベルと比較して前記無線通信グループ外の無線通信装置との接続拒否或いは接続許可を決定し、決定された接続拒否或いは接続許可が記載される第2のフィールドを有する第2の送信フレームを発生するフレーム発生部と、及びこの第2の送信フレームを前記無線通信グループ外の無線通信装置に向けて送信する送信部と、を具備することを特徴とする前記無線通信グループに属する無線通信装置。
- 2前記基準セキュリティレベルは、第1、第2及び第3のセキュリティレベルから選定され、前記第1のセキュリティレベルが非暗号化に相当し、前記第2のセキュリティレベルが第1の暗号化における第1の暗号化の強さに相当し、前記第3のセキュリティレベルが前記第1の暗号化における第2の暗号化の強さに相当することを特徴とする請求項1の無線通信装置。
- 3前記フレーム発生部は、前記通知セキュリティレベルが前記基準セキュリティレベルよりも低ければ接続拒否を決定し、前記通知セキュリティレベルが前記基準セキュリティレベルよりも低くなければ接続許可を決定することを特徴とする請求項1の無線通信装置。
- 4前記接続許可の場合には、前記メモリ部が前記無線通信グループ外の無線通信装置のアドレス及び前記通知セキュリティレベルを保持することを特徴とする請求項1の無線通信装置。
- 5前記第2の通信フレームは、前記無線通信グループを特定するアドレスが記述された第3のフィールドを含むことを特徴とする請求項1の無線通信装置。
- 6無線通信グループに属する第1の無線通信装置及びこの無線通信グループ外の第2の無線通信装置から構成される無線通信システムにおいて、前記第1の無線通信装置は、通知セキュリティレベルが記述された第1のフィールドを有する第1の送信フレームを前記第2の無線通信装置から受信する受信部と、非暗号化を含む暗号化方法及び暗号化の強さに依存するセキュリティレベルから選定され、前記無線通信グループに割り当てられた基準セキュリティレベルを記憶する第1のメモリ部と、前記通知セキュリティレベルを前記基準セキュリティレベルと比較して前記第2の無線通信装置との接続拒否或いは接続許可を決定し、決定された接続拒否或いは接続許可が記載される第2のフィールドを有する第2の送信フレームを発生する第1のフレーム発生部と、及びこの第2の送信フレームを前記第2の無線通信装置に向けて送信する送信部と、を具備することを特徴とする無線通信システム。
- 7前記基準セキュリティレベルは、第1、第2及び第3のセキュリティレベルから選定され、前記第1のセキュリティレベルが非暗号化に相当し、前記第2のセキュリティレベルが第1の暗号化における第1の暗号化の強さに相当し、前記第3のセキュリティレベルが前記第1の暗号化における第2の暗号化の強さに相当することを特徴とする請求項6の無線通信システム。
- 8前記第1のフレーム発生部は、前記通知セキュリティレベルが前記基準セキュリティレベルよりも低ければ接続拒否を決定し、前記通知セキュリティレベルが前記基準セキュリティレベルよりも低くなければ接続許可を決定することを特徴とする請求項6の無線通信システム。
- 9前記接続許可の場合には、前記第1のメモリ部が前記第2の無線通信装置のアドレス及び前記通知セキュリティレベルを保持することを特徴とする請求項6の無線通信システム。
- 10前記第2の通信フレームは、前記無線通信グループを特定するアドレスが記述された第3のフィールドを含むことを特徴とする請求項6の無線通信システム。
- 11前記第2の無線通信装置は、前記基準セキュリティレベル及び前記第1の無線通信グループのアドレスを保持する第2のメモリ部を具備することを特徴とする請求項6の無線通信システム。
- 12接続拒否が記述される第2のフィールドを有する第2の送信フレームを前記第2の無線通信装置が受信した場合には、前記第2の無線通信装置は、第2の通知セキュリティレベルが記述された第4のフィールドを有する第3の送信フレームを前記第1の無線通信装置に送信することを特徴とする請求項6の無線通信システム。
- 13前記第1のメモリは、前記第1の無線通信装置でサポートされるセキュリティレベル及び暗号化レベルに関連する暗号化パラメータを保持し、前記基準セキュリティレベルがこのサポートされているセキュリティレベルから選定されることを特徴とする請求項6の無線通信システム。
- 14接続許可が記述される第2のフィールドを有する第2の送信フレームを前記第2の無線通信装置が受信した場合には、前記第2の無線通信装置は、暗号化データが格納されている第5のフィールドを有する第4の送信フレームを前記第1の無線通信装置に送信し、前記第1の無線通信装置が前記暗号化パラメータを用いて暗号化データを複合化することを特徴とする請求項13の無線通信システム。
- 15前記第1の送信フレームは、前記第1の無線通信装置でサポートされている複数の通知セキュリティレベルが記載された第1のフィールドを有し、前記フレーム発生部が前記通知セキュリティレベルの夫々を前記基準セキュリティレベルと比較し、前記通知セキュリティレベルの全てが前記基準セキュリティレベルよりも低ければ接続拒否を決定し、前記通知セキュリティレベルの1つが前記基準セキュリティレベルよりも低くなければ接続許可を決定することを特徴とする請求項13の無線通信システム。
- 16前記通知セキュリティレベルは、前記第2の無線通信装置がサポートする通知セキュリティレベル中の最大のレベルに相当することを特徴とする請求項6の無線通信システム。
- 17前記無線通信グループ外の第3の無線通信装置であって前記通知セキュリティレベルで前記第2の無線通信装置と通信している第3の無線通信装置を更に具備することを特徴とする請求項6の無線通信システム。
- 18前記無線通信グループに属する第3の無線通信装置であって前記基準セキュリティレベルより低くないセキュリティレベルで前記第2の無線通信装置と通信している第3の無線通信装置を更に具備することを特徴とする請求項6の無線通信システム。
- 19前記第1及び第3の無線通信装置の1つは、アクセスポイントに相当することを特徴とする請求項6の無線通信システム。
- 20前記第1及び第3の無線通信装置の1つは、無線端末に相当することを特徴とする請求項6の無線通信システム。
- 21前記第2及び第3の無線通信装置の1つは、無線端末に相当することを特徴とする請求項6の無線通信システム。
- 22前記無線通信グループ外の第3の無線通信装置であって前記通知セキュリティレベルで前記第2の無線通信装置と通信している第3の無線通信装置と、前記無線通信グループに属する第4の無線通信装置であって前記基準セキュリティレベルより低くないセキュリティレベルで前記第2の無線通信装置と通信している第4の無線通信装置を更に具備することを特徴とする請求項6の無線通信システム。
- 23前記第1の無線通信装置がビーコンフレームを第2の無線通信装置に通知して前記第1の送信フレームの送信を要求し、前記ビーコンフレームは、前記第1の無線通信装置でサポートし、前記基準セキュリティレベルより低くないセキュリティーフレームが記載されたフィールドを有することを特徴とする請求項6の無線通信システム。
- 24前記第2の無線通信装置は、前記通知セキュリティレベルを含む第2のセキュリティレベルを記憶する第2のメモリ部と、前記第2のセキュリティレベルを前記基準セキュリティレベルと比較して前記通知セキュリティレベルとして1つのセキュリティレベルを決定して前記第1の送信フレームを発生する第2のフレーム発生部と、及び及びこの第1の送信フレームを第1の無線通信装置に向けて送信する送信部と、を更に具備することを特徴とする請求項6の無線通信システム。
- 25通知セキュリティレベルが記述された第1のフィールドを有する第1の送信フレームを通信グループ外から受信し、非暗号化を含む暗号化方法及び暗号化の強さに依存するセキュリティレベルから選定され、前記無線通信グループに割り当てられた基準セキュリティレベルを記憶し、前記通知セキュリティレベルを前記基準セキュリティレベルと比較して前記無線通信グループ外の無線通信装置との接続拒否或いは接続許可を決定し、決定された接続拒否或いは接続許可が記載される第2のフィールドを有する第2の送信フレームを発生し、及びこの第2の送信フレームを前記無線通信グループ外の無線通信装置に向けて送信することを特徴とする無線通信方法。
Independent claims25
383 paragraphs in 1 section, as filed
【0001】
[Technical field to which the invention belongs]
The present invention relates to a wireless communication system, a wireless communication device, and a wireless communication method, and more particularly to a wireless communication system composed of a plurality of wireless terminal devices and access points.
【0002】
[Conventional technology]
As a wireless LAN, a wireless LAN system based on IEEE802.11 (the IEEE802.11 system shall include an IEEE802.11a system, an IEEE802.11b system, etc.) is known in Non-Patent Document 1. In this wireless LAN system, a method called WEP (Wired Equivalent Privacy), which can ensure privacy in the same way as wired, is applied as an encryption method. Therefore, the security level of wireless LAN based on IEEE802.11 includes WEP mode to which WEP is applied and non-WEP mode to which WEP is not applied.
【0003】
In the actual wireless LAN product conforming to IEEE 802.11, communication is possible in either WEP mode to which the encryption method called WEP is applied or non-WEP mode to which it is not applied, and WEP is applied. In the WEP mode, there are 64-bit and 128-bit encryption modes with different encryption levels, and one of them is applied to each communication or each connection link in the wireless LAN to realize communication. Here, the higher the encryption level, the higher the security level and the stronger the encryption.
【0004】
As a form of wireless LAN in accordance with IEEE802.11, it is composed of one access point (hereinafter, also referred to as a base station) and a plurality of wireless clients (hereinafter, also referred to as terminals) connected to this access point. There is a configuration unit called BSS (Basic Service Set), and there is a system in which multiple BSSs are prepared and a network is constructed.
【0005】
The structural element that connects the BSSs is called the DS (Distribution System). The base station, that is, the access point has a function of connecting to this DS, and information is transmitted between the BSS and the DS via the access point. Therefore, the terminal can also communicate with a terminal belonging to another BSS via the access point.
【0006】
A terminal belongs to a BSS, and in order to communicate with a terminal belonging to another BSS via a base station, an authentication and association procedure is carried out with the base station. Also, when the terminal wirelessly reconnects to another access point, a reassociation procedure is executed.
【0007】
In the wireless LAN defined by IEEE802.11, the types of frames to be exchanged are a control frame for access control, a management frame such as a beacon, and a data frame for data communication. There is (data frame). Here, a management frame is used for the processing of authentication, association, and reassociation.
【0008】
Whenever the terminal sends or receives a data frame to or from the access point, the authentication and association processing is executed before that.
【0009】
In the wireless LAN defined by IEEE 802.11, the base station is inquired whether the terminal uses WEP, which is an encryption method. That is, in an authentication request, the terminal requests the base station to use WEP, and the base station that receives this request is between the base station and the terminal if WEP can be used. Authentication frame is sent and received at. WEP can be used based on the transmission and reception of such authentication frames.
【0010】
As another form of wireless LAN defined by IEEE 802.11, there is BSS that exists independently of the existing infrastructure, and this is called IBSS (Independent Basic Service Set). In IBSS, no access point is prepared, and IBSS corresponds to a communication mode in which terminals communicate directly with each other. Further, in IBSS, the association processing is not executed, and similarly, the reassociation processing is not executed. With this IBSS, data frames can be sent and received between terminals without undergoing authentication processing.
【0011】
[Non-Patent Document 1] ISO / IEC 8802-11: 1999 (E) ANSI / IEEE Std 802.11, 1999 edition [0012]
[Problems to be Solved by the Invention]
In this way, in the conventional wireless LAN, communication data is encrypted as one of the security measures. Whether or not to use the encryption function (WEP function) for communication is requested by the side that issued the connection request, for example, the side that received the connection request from the terminal, for example, the access point. The base station that receives this request accepts the request and encrypts the data communication with the terminal if the WEP function that meets the request can be used. In addition, the security level at which communication is performed is also determined by the side that issued the connection request.
【0013】
In the future, in addition to WEP, it is presumed that multiple types of encryption methods with different levels of encryption, such as encryption methods with a higher security level than WEP, will be adopted for wireless LAN. Therefore, it is required that the security level can be finely set according to the type of encryption method, the encryption level, and the like.
【0014】
However, with conventional wireless LANs, it is not possible to create a system in which the minimum encryption level is set in advance for each BSS to ensure security, and only communication with encryption having a higher level is allowed. During communication, there is a problem that a detailed security level cannot be set according to the type of encryption method, encryption strength, and the like.
【0015】
Furthermore, since IBSS does not require authentication when transmitting a data frame, there is a problem that it is not possible to ensure the security in the system by transmitting an unencrypted data frame.
【0016】
In addition, it is not possible to secure the security level defined for each BSS in the DS communication that communicates between a plurality of BSSs in the same way that the security level predetermined for each BSS cannot be ensured. There is a problem.
【0017】
The present invention has been made in view of the above circumstances, and an object thereof is a wireless communication system and a wireless communication device capable of wireless communication while ensuring a minimum security level by encryption predetermined by a communication group. To provide a wireless communication method.
【0018】
[Means for solving problems]
According to the present invention, a receiver that receives a first transmission frame having a first field in which a notification security level is described from a wireless communication device outside the communication group, and an encryption method including unencryption and encryption. A memory unit that stores the standard security level assigned to the wireless communication group, which is selected from the security levels that depend on the strength of the wireless communication group, and the wireless communication group outside the wireless communication group by comparing the notification security level with the standard security level. A frame generator that determines connection denial or connection permission with the communication device and generates a second transmission frame having a second field in which the determined connection denial or connection permission is described, and this second transmission. Provided is a wireless communication device belonging to the wireless communication group, which comprises a transmission unit that transmits a frame to a wireless communication device outside the wireless communication group.
【0019】
Further, according to the present invention, in a wireless communication system composed of a first wireless communication device belonging to a wireless communication group and a second wireless communication device outside the wireless communication group, the first wireless communication device is It depends on the receiver that receives the first transmission frame having the first field in which the notification security level is described from the second wireless communication device, the encryption method including non-encryption, and the encryption strength. Connection between the first memory unit that stores the reference security level selected from the security level and assigned to the wireless communication group and the second wireless communication device by comparing the notification security level with the reference security level. A first frame generator that determines the denial or connection permission and generates a second transmission frame having a second field in which the determined connection denial or connection permission is described, and this second transmission frame. Provided is a wireless communication system including a transmission unit that transmits to the second wireless communication device.
【0020】
Further, according to the present invention, the first transmission frame having the first field in which the notification security level is described is received from outside the communication group, and depends on the encryption method including non-encryption and the encryption strength. The reference security level selected from the security levels to be used and assigned to the wireless communication group is stored, the notification security level is compared with the standard security level, and the connection with the wireless communication device outside the wireless communication group is rejected or connected. A permission is determined, a second transmission frame with a second field in which the determined connection denial or connection permission is described is generated, and this second transmission frame is sent to a wireless communication device outside the wireless communication group. A wireless communication method characterized by transmitting toward is provided.
【0021】
BEST MODE FOR CARRYING OUT THE INVENTION
Hereinafter, embodiments according to the wireless communication system of the present invention will be described with reference to the drawings.
【0022】
First, in the wireless LAN system according to the following embodiment, a plurality of types of encryption methods can be applied, the types of the encryption methods are distinguished, and the security level in which the encryption level is ranked is predetermined. If there are different levels for each of the multiple types of encryption, each encryption level for that type of encryption will be ranked according to the degree of encryption strength, and one for each. The security level is set. Therefore, even if they have the same encryption strength, different types of encryption methods are given different security levels. For example, it is assumed that there are n security levels such as enc.0, enc.1, enc.2, ..., enc. (N-1) in order from the one with the lowest encryption strength. Even if there are multiple types of encryption methods of the same strength, security levels with different ranks shall be set for each type. In this way, one type of encryption method corresponds to one security level, and even if the same type of encryption method has multiple levels due to the difference in encryption strength, each of them. The security level corresponding to the level of is determined.
【0023】
By the way, in the current wireless LAN system specified in IEEE 802.11, the lowest security level corresponds to the level without encryption, that is, the level to which WEP (Wired Equivalent Privacy) is not applied.
【0024】
In the current wireless LAN products that comply with the IEEE 802.11 regulations, even if WEP is applied, there are two levels, such as configuring WEP with 64 bits or 128 bits. Therefore, in the example of the following embodiment, 64-bit WEP with (1) "without WEP" and (2) "with WEP" is used as multiple security levels, as in the case of wireless LAN according to the current IEE802.11. The case where there are three levels of ", (3)" with WEP and using 128-bit WEP "will be described as an example. In this case, the highest security is (3) "Use 128-bit WEP with WEP", followed by (4) "Use 64-bit WEP with WEP". There is. That is, "enc.0" corresponds to (1) "without WEP", "enc.1" corresponds to (2) "with WEP and 64-bit WEP is used", and "enc.2" corresponds to ( 3) It shall correspond to "with WEP and using 128-bit WEP".
【0025】
In the following description, the case of only one type of encryption method called WEP will be described. However, even if it is an encryption method other than WEP, if a plurality of levels can be set according to the difference in the type of encryption method and the strength of security, any encryption can be set as in the following embodiment. The present invention can be applied even in the case of the encryption method.
【0026】
In the following embodiments of the present invention, the case where the present invention is applied to the wireless LAN system specified in IEE802.11 will be described. In particular, a case where the wireless communication device of the present invention is applied to a base station or a terminal constituting a wireless LAN system specified in IEE802.11 will be described.
【0027】
(First Embodiment) First, as a wireless communication system, a plurality of terminals, for example, two terminals (WL11 to WL12) and the terminals (WL11 to WL12) are wirelessly connected to the first embodiment of the present invention. A communication system in which the base station AP1 constitutes one BSS (basic service set) will be described.
【0028】
FIG. 1 schematically shows the first BSS (hereinafter, simply referred to as BSS1). The BSS1 is composed of a base station AP1 as an access point and a plurality of terminals connected to the base station AP1, for example, two wireless terminals (hereinafter referred to as terminals) WL11 and WL12 here.
【0029】
Note that FIG. 1 also shows the base station AP2 belonging to the second BSS (hereinafter, simply referred to as BSS2) different from the first BSS1 and the terminal WL13 which is not subscribed to BSS1 and BSS2.
【0030】
BSS1 has the lowest security level (enc_low) allowed there. In the wireless communication system according to this embodiment, the lowest security level (enc_low) allowed by BSS1 is the security level "enc.1". In Fig. 1, the fact that the minimum security level (enc_low) allowed is the security level "enc.1" is shown as enc_low = enc.1. It is assumed that the base station AP1 supports not only the security level "enc.1" but also the security level "enc.2" which is higher than the security level "enc.1". Therefore, the highest security level (enc_high) that can be used with BSS1 is "enc.2". In Fig. 1, the fact that the highest security level (enc_high) is "enc.2" is expressed as enc_high = enc.2. It is set in advance in the base station AP1 that the base station AP1 and the terminal or the base station connected to the base station AP1 communicate with each other at a security level of "enc.1" or higher. Similarly, it is set in advance in the base station AP1 that communication with the terminal or the base station for relaying the base station AP1 and communicating with other devices is performed at a security level of "enc.1" or higher. Has been done.
【0031】
On the other hand, the security levels of the terminal WL11 are "enc.0" and "enc.1", and the security levels of the terminal WL12 are "enc.0", "enc.1" and "enc.2". To do.
【0032】
FIG. 2 shows a block of the circuit configuration of the base station AP1 shown in FIG. In the following description, when it is not necessary to distinguish between base station AP1 and base station AP2, or when the description is common to both, it is simply referred to as base station AP.
【0033】
In FIG. 2, in the receiving unit 11, the transmitting signal from the terminal is received by the antenna 20, and the received signal is generated by a process including demodulation and decoding. The transmission unit 12 generates transmission signals to be transmitted to the terminal via the antenna 20, and these transmission signals are supplied to the antenna 20.
【0034】
The received signal from the receiving unit 11 is input to the receiving control unit 13, for example, the IEEE802.11 system (in the following description, the IEEE802.11 system is the IEEE802.11a system, the IEEE802.11b system, and the IEEE802 to be formulated in the future. .11 The system shall also be included.) Prescribed reception processing, etc. shall be implemented. The reception control unit 13 executes decryption processing corresponding to each of the plurality of security levels supported by the base station, and the received signal is decrypted and converted into composite data. This complexed data is supplied to the information processing unit 15, divided into video, audio, text and other types of data, and is subjected to necessary processing.
【0035】
Based on the data supplied from the information processing unit 15, the transmission control unit 14 generates data for broadcasting to the terminal or transmitting by unicast, or the like, which is a predetermined transmission process compliant with IEEE 802.11. To carry out. The transmission control unit 14 applies encryption processing corresponding to each of the plurality of security levels supported by the base station to the data to be transmitted. The data generated by the transmission control unit 14 is transmitted to the terminal as a transmission signal via the transmission unit 12. The security table 21 shown in FIG. 2 will be described later.
【0036】
FIG. 3 schematically shows an example of the circuit configuration of the terminals WL11, WL12, and WL13 shown in FIG. 1 in blocks. In the following description, when it is not necessary to distinguish terminals WL11, WL12, WL13, etc., or when the description is common to all terminals, it is simply referred to as terminal WL.
【0037】
The terminal WL includes an antenna 100, a receiving unit 101 that receives a received signal via the antenna 100, a receiving control unit 105 that controls the receiving unit 101, a transmitting unit 107 that transmits a transmitting signal via the antenna 100, and the transmitting unit 107. It is composed of a transmission control unit 106 for controlling the above, an information processing unit 108 for generating or processing received data, for example, displaying on a display unit (not shown), and a security table 110.
【0038】
The information processing unit 108 receives data from the wired network 109 connected to the information processing unit 108, or creates transmission data based on the data generated by the user's operation. When the transmission of the transmission data is instructed by the user and a transmission request is generated, the transmission data receives the transmission request and passes the transmission data to the transmission unit 107. In the transmission unit 107, this transmission data is converted into digital data defined by the standard, for example, an IP packet is converted into a MAC frame (medium access control frame) specified by IEEE802.11, and the MAC frame as digital data is converted. It is converted into a radio signal of a predetermined frequency, for example, 2.4 GHz, and transmitted as radio waves from the antenna 100.
【0039】
On the other hand, the received signal received by the antenna 100 is converted into a MAC frame as digital data by the receiving unit 101, and the received data is extracted from the information field in the MAC frame and sent to the information processing unit 108. The information processing unit 108 performs processing such as displaying received data on a display. The information processing unit 108 may perform various types of information processing in addition to the above. The security table 110 will be described later.
【0040】
As shown in Fig. 4, the MAC frame specified by IEEE802.11 contains a maximum of 30 bytes of MAC header containing various control information, a data field (frame body) containing up to 2312 bytes of data, and data. It consists of a frame check sequence (FCS) field to check if it was sent correctly. The MAC header contains a frame control field that stores information that controls the MAC frame, the duration until the terminal can send data, or the ID of the terminal called the association ID in IEEE 802.11. Contains the Duration / ID field that describes. If the BSS has a base station AP, the MAC address of the base station AP is described as the ID of this BSS. Further, in the MAC header, a field of address 1 to a field of address 4 and a sequence control field are prepared. When a data frame is sent from one access point to another, addresses 1 to 4 are assigned as follows. That is, the MAC address of the final destination (Destination Address) in the communication system is described in the field of address 1, and the MAC address of the source (Source Address) in the communication system is described in the field of address 2. In the field of address 3, the MAC address of the destination that directly sends the MAC frame is described, and in the field of address 4, the MAC address of the source that directly sends the MAC frame is described.
【0041】
The frame control of the MAC frame is provided with a protocol version field that describes the protocol version, followed by a type field and a subtype field. There are three types of MAC frames, and these types are described in the type field (2 bits) in the frame control. Also, the subtypes of that type are shown in more detail in the subtype field (4 bits). That is, there are (1) management frame, (2) control frame for access control, and (3) data frame for data communication as types. (1) The management frame includes a beacon, an authentication frame, an association frame, an association request frame, an association response frame, and the like as subtypes. In addition, (2) control frames include ACK (Acknowledgment), RTS (Return To Send), and CTS (Clear To) as subtypes. There is a control frame such as Send). The subtype field (4 bits) shows in more detail the subtypes in a particular type of MAC frame as described above.
【0042】
The frame control includes a To DS field (1 bit) and a From DS field (1 bit). These are used when the MAC frame is a data frame, and in other types of frames, for example, authentication or association frames, "0" is always written and used. Not done. When the MAC frame is a data frame, if the data destination is a wired LAN, access point or DS, 1 bit is described in this To DS field, and the data source is a wired LAN, access point or DS. If so, a bit of 1 is written in this From DS field. Frame controls include reserved fields, WEP fields, and order fields. Other fields such as field) are further prepared. Information can be written by the user to a reserve field that is not yet specified. As shown in FIG. 4, some fields are reserved according to either the frame type and subtype or the frame type and subtype. In the embodiment of the present invention, the encryption level may be described in this reserve field as described later. This encryption level is determined according to the attributes of the transmitted data. For content data that requires confidentiality, a high encryption level is set, and the encryption level is described in this reserve field. This reserve field encryption level may be used when handshaking between the access point and the terminal. If WEP is used, 1 bit is set in the WEP field.
【0043】
BSS1 will be described again with reference to FIG.
【0044】
In BSS1 shown in FIG. 1, it is predetermined that communication is executed at the minimum security level (here, "enc.1") predetermined for this BSS1. That is, each of the base station AP1 and the terminals WL11 to WL12 constituting BSS1 has a security level of "enc.1" or "enc.1" or higher within the range of the security level supported by the base station AP1. Communication is performed at the security level of.
【0045】
Each of the base station AP1 and the terminals WL11 to WL12 is provided with a storage unit, and the storage unit is provided with a security table. In the security table of the base station AP1, which is the security level supported by the base station AP1 itself, which is the lowest security level in BSS1 among these security levels, and each of the terminals WL11 to WL12 supports it. What the security level is is memorized. Further, preferably, information necessary for encryption / decryption of each security level, such as an encryption key or seed information for generating an encryption key (information necessary for such encryption / decryption). Here, simply referred to as a cryptographic parameter) is also preferably stored in this security table. In addition, each of the terminals WL11 to WL12 also has a storage unit that stores the security table, the lowest security level among the security levels supported by BSS1, the security level supported by other terminals, and each. Cryptographic parameters and the like corresponding to the security level are stored in the security table.
【0046】
As shown in FIG. 5, in the security table 21 of the base station AP1, the security level supported by the BSS1 to which the base station AP1 belongs and the security level of all the terminals WL11 to WL12 belonging to the BSS1 are encrypted at each security level. -It is registered in advance together with the encryption parameters that are the data required for compounding. Further, in this security table 21, the security level set as the lowest security level in BSS1 to which the base station AP1 belongs is registered so as to be identifiable. In FIG. 5, a "" mark indicating the lowest level is recorded for the security level enc.1.
【0047】
As an example, in the case of WEP, the encryption parameters are assumed to be the private key (key1, key2) and IV (Initialization Vector) specified in IEEE 802.11. In the following description, the security level and the cryptographic parameters corresponding to this security level may be referred to as security information.
【0048】
FIG. 6 shows the registered contents of the security table 110 of the terminals WL11 to WL12 in BSS1. As shown in FIG. 6, the security information possessed by each terminal in BSS1 and the base station AP1 is registered in advance in the security table on the terminal side. As shown in FIG. 6, as the security information corresponding to the base station AP1, only the lowest level security information preset in the BSS1 to which the base station AP1 belongs may be registered. Further, the security table 110 on the terminal side may be exactly the same as the security table 21 on the base station side shown in FIG.
【0049】
Further, the security level of the base station AP1 and each terminal registered in the security table shown in FIGS. 5 and 6 may be higher than the minimum level predetermined by BSS1. Further, as for the security information corresponding to each terminal, only the security level used in the actual communication may be registered in BSS1. That is, when each terminal is directly linked to the access point, it is security information about the access point, or when it is directly linked to the terminal, it is security information about the terminal, which is supported by the terminal in BSS. Each terminal can hold the security information in the security table.
【0050】
The security tables shown in FIGS. 5 and 6 are set at the time of initial setting of BSS1. At the time of initial setting, for example, a table in the format shown in FIGS. 5 and 6 may be displayed as a setting screen, and setting items may be input on this screen. In the tables shown in FIGS. 5 and 6, AP1, WL1 and WL2 are identified by the MAC addresses of the base station AP1 and the terminals WL1 and WL2, respectively.
【0051】
The security tables shown in FIGS. 5 and 6 do not have to have any information written at the time of initialization. However, if the access point AP1 and the terminals WL1 and WL2 are linked in the unencrypted mode as described later with reference to FIG. 7, security information can be written. That is, the access point AP1 and the terminals WL1 and WL2 acquire the security information about the access point AP1 and the terminals WL1 and WL2 and write them in their respective security tables, and then BSS1 is established by the access point AP1 and the terminals WL1 and WL2, and BSS1 The lowest security level within is sufficient.
【0052】
In the BSS1 shown in FIG. 1, communication is executed between the base station AP1 and the terminals WL11 to WL12 at a security level equal to or higher than the minimum security level "enc.1" set in advance for the BSS1.
【0053】
Next, a case where the terminal WL13 not subscribed to the BSS1 is connected to the base station AP1 of the BSS1 shown in FIG. 1 will be described with reference to the flowchart shown in FIG.
【0054】
The terminal WL13 receives the Beacon frame specified in IEEE 802.11, which is transmitted from the base station AP1. According to the provisions of IEEE 802.11, the reception of a beacon frame is followed by the authentication and association protocols, but during the frame for this authentication or association, the base. The security level of the terminal WL13 is written as the information to be notified to the station AP1.
【0055】
Figure 7 shows the procedure for notifying the base station AP1 of the security level of the terminal WL13 in the authentication frame as an example. In this procedure, it is assumed that the security levels of the terminal WL13 are "enc.0" and "enc.1".
【0056】
FIG. 8 (a) shows the format of the frame body in the frame of the authentication as the MAC frame shown in FIG. 4 defined in IEEE 802.11. In the authentication frame, an authentication algorithm that distinguishes between an open system that does not use a common encryption key and a common encryption key system that uses a common encryption key is described. For the authentication algorithm number, for example, "0" is described in the open system, and "1" is described in the common encryption key system. In the open system specified by the authentication algorithm number 0, ATSN (Authentication Transaction Sequence Number) = 1 and = 2 frames are prepared as the authentication request frames as shown in FIG. 8 (b). The authentication frame with ATSN = 1 is sent from the terminal WL to the base station AP1 and its Status Code field (Status Code). field) is considered to be a reserve. The authentication frame of ATSN = 2 is sent from the base station AP1 to the terminal WL, and the status code (Status Code) describes the connection refusal or connection permission code as the status. In the open system identified by the authentication algorithm number 0, the authentication frame does not have a challenge text to be encrypted. In a common encryption key system, ATSN (Authentication Transaction Sequence) is used as an authentication request frame (authentication request). Number) = 1 ~ 4 frames are prepared. The authentication frame of ATSN = 1 and ATSN = 3 is sent from the terminal WL to the base station AP1, and its status code is reserved. The authentication frame of ATSN = 2 and ATSN = 4 is sent from the base station AP1 to the terminal WL, and the status code describes the connection refusal or connection permission code as the status. In the common encryption system, the challenge text for encryption is prepared for the authentication frame of ATSN = 2 and 3, and the authentication frame of ATSN = 3 is encrypted. On the other hand, the challenge text for encryption is not prepared in the authentication frame of ATSN = 1 and 4.
【0057】
The authentication frame specified by ATSN = 1 is transmitted from the side that issues the connection request. In this request frame, the status code field is reserved and is currently unused. Therefore, the security level "enc.1" or "enc.2" of the side issuing the connection request can be written in this status code field. In the following description of the embodiment, it is assumed that the security level "enc.1" or "enc.2" of the side issuing the connection request is written in the Status code field. In this ATSN = 1 authentication frame, the status code section contains data indicating the security level (for example, "enc. 1") that the transmitter 107 of the terminal WL13 wants to use for communication with the base station AP1. It is written and this ATSN = 1 authentication frame is transmitted to base station AP1 as shown in step S2 of FIG. Note that this security level may be written in any reserve field in the MAC frame shown in FIG.
【0058】
The processing operation of the base station AP1 that has received the authentication frame of ATSN = 1 will be described. As already described, the beacon frame constantly emitted from the base station AP1 is detected by the terminal WL13 as shown in step S1. After this detection, the transmission control unit 106 of the terminal WL13 prepares an authentication frame with ATSN = 1, and refers to the security table 110 to set the security level at a predetermined position of the frame, for example, the status code in the frame body. Write "enc.1" or "enc.2". For the authentication frame in which the security level is written, specify the base station AP1 corresponding to the beacon frame detected by the transmission control unit 106 of the terminal WL13 as the destination to the address 2 and send it to the base station AP1 as shown in step S2. Will be sent. The base station AP1 receives the authentication frame, and the reception control unit 13 of the base station AP1 is written to a predetermined position of the received authentication frame of ATSN = 1, for example, a status code in the frame body. Take out the security level "enc.1" or "enc.2" of the terminal WL13 and compare it with the lowest level security level "enc_low" of BSS1 registered in the security table 21 of the base station AP1. As shown in step S3, the security level "enc.1" or "enc.2" of this terminal WL13 notified from the terminal WL13 is the security level "enc.1" or "enc.2" supported by the base station AP1.
【0059】
In step S3, if the base station AP1 rejects the connection of the terminal WL13, an authentication frame with ATSN = 2 is prepared by the transmission control unit 12 according to the provisions of IEEE802.11, and the connection fails with the status code. A code to that effect is written, and an authentication frame with ATSN = 2 is returned to the terminal WL13 as shown in step S4. The terminal WL13 determines whether the ATSN = 2 authentication frame, which is described as rejecting the connection as shown in step S5, is received for the Nth time. This N times corresponds to the number of security levels (= N) written in the security table 110 on the terminal side. Initially, the terminal WL13 notifies the base station of this low level of security as the security level supported by the base station AP1 is low, and if rejected, raises the security level and raises it as shown in step S2. You will be notified of the security level. When the terminal WL13 receives the authentication frame of ATSN = 2 N times as shown in step S5 by notifying the N security levels supported by the security table 110 on the terminal side. It is determined that the connection is rejected by the base station AP1, and the connection procedure is interrupted at this stage as shown in step S15.
【0060】
On the other hand, when permitting the connection of the terminal WL13, the base station AP1 complies with IEEE 802.11 as shown in step S6 in order to share the cryptographic parameters corresponding to the security level notified from the terminal WL13 with the terminal WL13. , Prepare an authentication frame with ATSN = 2 to send the challenge text, write the code indicating that the authentication frame with ATSN = 1 was successfully received in the status code of this authentication frame, and step. Reply to terminal WL13 as shown in S6.
【0061】
When the terminal WL13 receives an authentication frame with ATSN = 2, the security level between the base station AP1 and the terminal WL13, for example, the security level "enc.1" is determined. In addition, the terminal WL13 uses the IV and private key acquired in advance by the user as the encryption parameters corresponding to the security level, and the frame body including the challenge text etc. is shown in step S7 in accordance with the provisions of IEEE 802.11. Encrypt using the WEP function of the terminal WL13. Further, the terminal WL13 prepares an authentication frame with ATSN = 3, and copies the challenge text from the authentication frame with ATSN = 2 into the frame body. The terminal WL13 encrypts the frame and transmits it to the base station AP1 as shown in step S8.
【0062】
In the base station AP1 that received the authentication frame of ATSN = 3, the secret key of the base station AP1 shared with the terminal WL13 is also in accordance with the provisions of IEEE802.11, and the ATSN received as shown in step S9. The authentication challenge frame of = 3 is decrypted and the stored encryption challenge text is retrieved. This decrypted challenge text is compared with the transmitted challenge text, and encryption / decryption is verified based on the comparison result as shown in step S10.
【0063】
If the verification result is "failure", an authentication frame with ATSN = 4 is prepared to notify that fact in accordance with the provisions of IEEE802.11, and the status code indicates that the verification result is "failure". The code is written and an authentication frame with ATSN = 4 is returned to terminal WL13 as shown in step S11. "Failure" in the verification result means that the encryption method is different between the base station AP1 and the terminal WL13. Therefore, as shown in step S14, it is confirmed that the authentication frame of ATSN = 4 is within M times, the encryption method in the terminal WL13 is changed and returned to step S2, and steps S2 to S10 are repeated. Is done. Here, M times corresponds to the number of encryption methods prepared by the terminal WL13, and the terminal WL13 can receive the authentication frame of M times ATSN = 4. If the encryption method does not match even if the terminal WL13 receives the authentication frame of ATSN = 4 M times in this way, it is determined that the terminal WL13 is denied the connection with the base station AP1. Therefore, it is assumed that the terminal side does not prepare the encryption method provided by the base station AP1, and the connection procedure is completed as shown in step S15.
【0064】
On the other hand, if the verification result in step S10 is "success", the base station AP1 also complies with IEEE802.11 as shown in step S12, and sends an authentication frame of ATSN = 4 to notify the fact to the terminal WL13. Send to. When the terminal WL13 receives this frame, it starts the association specified in IEEE 802.11, which is the next procedure, as shown in step S12. That is, the terminal WL13 sends an association request frame as shown in step S13 to the base station AP1, and in response to this request, the base station AP1 returns the association response terminal WL13 to the IEEE 802.11-compliant process. The action is performed. After the association is completed normally, data frames are sent and received between the terminal WL13 and the base station AP1. The transmitted / received data frame is encrypted by the encryption predetermined by the above procedure, for example, the 64-bit WEP function corresponding to the security level of "enc.1 = enc.low".
【0065】
In the terminal WL13 and the base station AP1, when the security level and the encryption parameter of the communication between the terminal WL13 and the base station AP1 are determined, the mutual security information is registered in the security tables 21, 110. That is, in the terminal WL13, the security information of the base station AP1 is registered in the security table 110 after the encryption parameters are acquired in step S7 shown in FIG. Further, in the base station AP1, the security information of the terminal WL13 is registered in the security table 21 after the verification is successful in step S10 of FIG. That is, by selecting an appropriate address field indicating the address of the terminal WL13 in the MAC frame shown in FIG. 4, security information is registered in the security table 21 of the access point AP1 in relation to this address. As shown in FIG. 10, security information whose "connection destination" is the terminal WL13 is newly registered in the security table of the base station AP1. Similarly, the security information whose "connection destination" is the base station AP1 is newly registered in the security table of the terminal WL13. That is, by selecting an appropriate address field indicating the address 1 of the base station AP1 in the MAC frame shown in FIG. 4, security information is registered in the security table 110 of the terminal WL13 in relation to this address. The security level of the security information in the newly added terminal WL13 corresponds to the security level requested by the terminal WL13 in step S2 of FIG.
【0066】
Further, if the security information of the base station is registered in the security table on the terminal side, the terminal can select the security level equal to or higher than the minimum level of the base station in advance, and as a result, in step S3, the relevant The connection will not be rejected by the base station. Here, the security information of the base station has at least a security level of at least a minimum level predetermined for the BSS to which the base station belongs. In other words, when the terminal reconnects to the base station, the security level specified by the base station is selected from the security levels supported by the terminal itself to the base station, and the step in FIG. 7 is performed. Notify the base station of this security level as shown in S2.
【0067】
Further, it is preferable that at least the security information of the security level equal to or higher than the minimum level enc_low predetermined in the BSS to which the base station belongs is registered as the security information regarding the terminal WL in the security table of the base station AP. In this registration, regarding the BSS to which the base station belongs, the BSS is specified by the address described in the appropriate address field in the MAC frame shown in FIG. 4, and this address and the security level are described in the security table. If there is such a registration regarding BSS, the security level used for unicast communication from the base station to the terminal can be selected in advance at the minimum level or higher and the security level that the terminal can support. .. In addition, the security level for multicast communication and broadcast communication to the terminal WL in the BSS to which the base station AP belongs is also the minimum level enc_low or higher, and the security level supported by all terminals that should receive it. You can preselect things. That is, as shown in step S5 of FIG. 7, when the connection is rejected by the base station AP1, a security level different from the previously notified security level, preferably a higher level is notified, and the connection is reconnected. Can be requested. While notifying the security level of the terminal WL13 one by one, connection requests can be made up to a predetermined number of times M.
【0068】
Base station AP1 should notify the connection requesting terminal WL13 of all security levels equal to or higher than the lowest security level enc_low preset in BSS1 or the lowest level enc_low supported by base station AP1. You can do it. This notification may be notified using a currently unused frame among the management frame and control frame of the MAC frame specified in IEEE 802.11. For example, the management frame corresponds to a frame having a subtype of "0110" to "0111", and the control frame corresponds to a frame having a subtype such as "0000" to "1001". In step S4 shown in FIG. 7, when the base station AP1 refuses to connect to the terminal, after transmitting an authentication frame with ATSN = 2, this unused frame is transmitted to provide security of the minimum level enc_low or higher. You may want to notify the terminal WL13 of all the levels. Further, in step S4 or step S6, an unused frame may be transmitted before the authentication frame with ATSN = 2 is transmitted to notify the terminal WL13 of all the security levels equal to or higher than the minimum level enc_low. In addition, the access point AP1 sends unused frames at an appropriate time, such as during authentication or association processing, or before the start of data frame transmission / reception, and the security level is at least the lowest level enc_low or higher. You may notify the terminal WL13 of everything.
【0069】
As shown in Fig. 9 (a), Fig. 9 (b) and Fig. 9 (c), the frame of the MAC frame association specified in IEEE 802.11 is the "Capability information (Capability) of the frame body. A reserve field is provided as an unused area in "information)". Utilizing this unused area, the base station AP1 sends the connection requesting terminal WL13 to the lowest security level enc_low of BSS1 or all the security levels higher than the lowest level enc_low supported by the base station AP1. May be notified to the terminal WL13.
【0070】
As described above, in the first embodiment, when a terminal WL11 belonging to BSS1 and a terminal WL13 not belonging to BSS1 other than Wl12 try to connect to the base station AP1, first (1) this terminal WL13 , Notify the base station AP1 of the security level of the terminal WL13 itself. In the flow shown in Figure 7, this notification utilizes an authentication frame.
【0071】
(2) In the base station AP1, when the security level notified from this terminal WL13 is the security level supported by the base station AP1 and is equal to or higher than the security level of the minimum level enc_low predetermined in BSS1. Allow the connection of terminal WL13 and continue the processing operation for connection. However, when the security level notified from the terminal WL13 is less than the minimum security level predetermined in BSS1, the connection of the terminal WL13 is rejected.
【0072】
(3) When the connection from the terminal WL13 is permitted, the recognition process for sharing the information for encryption / decryption, that is, the encryption parameter is executed as necessary.
【0073】
As described above, according to the first embodiment described above, wireless communication that secures the minimum security level by encryption predetermined by each group is realized for each basic group of wireless LAN such as BSS. ..
【0074】
Preferably, in the case of (1) above, if the terminal WL13 notifies the base station AP1 of the security level of the highest level enc_high among the security levels supported by the terminal WL13 itself, the base station AP1 connects to the terminal WL13. There are fewer opportunities to refuse. Further, if the security level of the highest level enc_high is notified to the base station AP1, it is possible to determine whether or not the connection with the base station AP1 is possible with one connection request, and as a result, unnecessary traffic can be reduced.
【0075】
In addition, each base station or terminal in BSS1 should register security information with a security level equal to or higher than the minimum level enc_low predetermined in BSS1 used when communicating with the base station or terminal in BSS1 in the security table. Is preferable. The base station or each terminal refers to this security table and selects in advance the minimum security level at which the connection is not denied as the security level to be notified when the connection request is made to the desired terminal or base station specified by the address. be able to.
【0076】
In the first embodiment described above, in step S2, the terminal WL13 notifies the base station AP1 of only one security level that the terminal WL13 wants to use in communication with the base station AP1, but this is limited to this case. It is clear that this is not the case. The terminal WL13 may notify the base station AP1 of all, or if not all, security levels of the terminal WL13 itself. Further, among the security levels supported by the terminal WL13, only the highest security level enc_high may be notified from the terminal WL13 to the base station AP1.
【0077】
In step S2, the processing operation of the base station AP1 in the case of notifying all, if not all, of the security levels of the terminal WL13 itself will be described.
【0078】
In step S2 shown in FIG. 7, a plurality of security levels possessed by the terminal WL13 itself are transmitted to the base station. In base station AP1, in step S3, whether this security level includes the security level enc_low or higher, which is equivalent to the lowest level in BSS1, and the security level supported by the own device. to decide. The base station AP1 determines that the connection of the terminal WL13 is permitted when the supported security level is included. In addition, the base station AP1 determines that the connection of the terminal WL13 is rejected when the supported security level is not included. If the connection of the terminal WL13 is rejected, the process proceeds to step S4. When permitting the connection of the terminal WL13, the base station AP1 then selects a security level equal to or higher than the lowest level enc_low in BSS1 among the security levels supported by both the terminal WL13 and the base station AP1. When there are multiple security levels equal to or higher than the minimum level enc_low in BSS1, the base station AP1 selects one of them. Regarding this selection, there are the lowest, the highest, and various other selection criteria, but any one of them may be selected. The base station AP1 uses one selected security level as the security level used for communication with the terminal WL13. For example, if the security levels notified from the terminal WL13 are "enc. 0" and "enc. 1", the connection of the terminal WL13 to the base station AP1 is permitted, and the connection between the terminal WL13 and the base station AP1 is permitted. The communication security level is selected as "enc. 1".
【0079】
When it is necessary to notify the terminal WL13 of this selected security level, for example, in step S6 of FIG. 7, before transmitting the authentication frame of ATSN = 2, the above-mentioned IEEE 802.11 is notified. Of the specified MAC frame management frames and control frames, currently unused frames may be used.
【0080】
The terminal WL13 is notified of the selected security level and can prepare for the subsequent processing.
【0081】
Within BSS1, if the security level is equal to or higher than the minimum level enc_low predetermined for BSS1, it is not always necessary to communicate at the same security level.
【0082】
Further, in BSS1, communication may be performed at different security levels depending on the connection partner. That is, here, as long as the base station AP1 has a security level equal to or higher than the minimum level enc_low predetermined in BSS1, there is no particular limitation on communicating with which terminal at which security level. By communicating with the base station AP1 at a different security level for each terminal, the confidentiality of wireless communication can be improved.
【0083】
Figure 7 has been described as the operation when connecting between terminals WL13 that are not subscribed to BSS1 and base station AP1, but the terminals WL13 described above are replaced with terminals WL11 to WL12 that are subscribed to BSS1 respectively. You may. When each of the terminals WL11 to WL12 tries to connect to the base station AP1, if the procedure shown in FIG. 7 is followed, in step S2 of FIG. 7, a different security level is notified each time, and each connection is made. , The security level can be changed according to the purpose. In this case, the security level of BSS1 is registered in the security table of each terminal, so the security level of this minimum level or higher is selected from the security levels supported by each terminal, and that is the step. Notified by S2. It is also possible to change the cryptographic parameters (in the case of WEP, such as private key and IV) during subsequent authentication without changing the security level.
【0084】
Similarly, the procedure for requesting a connection from a terminal to a base station described in FIG. 7 can also be applied as a procedure for requesting a connection from a base station to a base station belonging to different BSSs. That is, the terminal WL13 described in FIG. 7 can be replaced with the base station AP1, and the base station AP2 can be replaced with a base station belonging to another BSS different from BSS1, for example, here, the base station AP2 of BSS2. As described above, according to the first embodiment, even in the communication between base stations, that is, the DS communication, the communication is realized at the minimum security level or higher of each.
【0085】
When a terminal in BSS1, for example, terminal WL11 communicates with another terminal in the same BSS1, for example, terminal WL12, it may always connect to and communicate with base station AP1 via base station AP1. , Direct communication may be performed between terminals without going through the base station AP1.
【0086】
When the terminals WL11 to WL12 and the base station AP1 try to connect to the other party registered in their respective security tables, the authentication for sending and receiving the security level and the encryption parameter may be omitted. On the side receiving the connection request, if the source of the frame is registered in its own security table, the security table is referred to and the security level is higher than the predetermined minimum level in BSS1. You just have to communicate with the requester.
【0087】
Only the security level security information used in the communication between them in the past may be registered for each connection partner in the security tables of the base station AP1 and the terminals WL11 to WL12. This registered security information corresponds to the security level equal to or higher than the lowest level enc_low in BSS1.
【0088】
At the time of initial setting, the security tables of the base station AP1 and terminals WL11 to WL12 in BSS1 all have the same contents, and each device that constitutes BSS1 is supported as shown in Fig. 5. The security information of all the security levels to be used and the security level set as the minimum level in BSS1 may be registered.
【0089】
In BSS1, the base station AP1 and terminals WL11 to 12 also support "enc. 1", which is the lowest security level allowed by BSS1. Therefore, when any of the terminals WL11 to WL12 multicasts or broadcasts a data frame or the like within BSS1, the frame body of that frame shall be encrypted with the lowest security level allowed. As a result, the lowest security level that BSS1 allows can be ensured.
【0090】
Further, in the first embodiment described above, IEEE 802.11 defines a check of the security level supported by the connection request source and a recognition process for sharing the encryption parameter between the connection request source and the connection request destination. It is done collectively at the time of authentication. However, these two processes can be separated and the former can be executed at the time of association specified in IEEE 802.11. It is also conceivable that the association is performed first, and then the authentication is performed. In this case, the above two processes may be performed together at the time of authentication, or may be performed separately at the time of association and at the time of authentication. However, when the above two processes are separated, it is preferable to perform the security level check prior to the recognition process for sharing the cryptographic parameters in order to ensure security.
【0091】
(Second Embodiment) Communication relating to the second embodiment in which the base station of BSS1 as shown in FIG. 1 in which the minimum security level is predetermined broadcasts the minimum security level defined in the BSS1. The system will be described. In this description, in the communication system according to the second embodiment, the same description as that of the first embodiment will be omitted, and the differences thereof will be described with reference to FIG.
【0092】
In the communication system according to the second embodiment, the minimum security level of the BSS is written in the beacon frame specified in IEEE 802.11, and FIG. 11 in which this beacon frame is transmitted is specified in IEEE 802.11. The format of the frame body of the beacon frame having the structure of the MAC frame is shown. A reserve field is provided as an unused area in the "Capability information" of this beacon frame. Base station AP1 writes to this reserve field the lowest security level of BSS1 or all, or if not all, security levels above the lowest level supported by base station AP1, and that security level. Is notified to the terminal WL.
【0093】
The transmission control unit 14 of the base station AP1 applies the lowest security level of BSS1 or all, or if not all, of the security levels above the lowest level supported by the base station AP1 to the beacon frame. Write and broadcast. As shown in step S21 of FIG. 12, the terminal receives this beacon frame. The beacon frame can also receive a terminal that does not subscribe to BSS1, for example, the terminal WL13 shown in FIG.
【0094】
The receiver 101 of the terminal WL13 extracts the lowest security level of BSS1 written in the received beacon frame as shown in step S22, and sets the security level supported by the terminal WL13 to the security level BSS1 as shown in step S23. Check if there is anything above the minimum level of. Here, all the security levels supported by the terminal WL13 may be registered in the security table of the terminal WL13 in advance. If the security level of the terminal WL13 is not higher than the minimum level of BSS1, the connection with the base station AP1 is stopped and the connection process is terminated.
【0095】
Here, the lowest security level of BSS1 is "enc.1", and the terminal WL13 supports "enc.0" and "enc.1", so the terminal WL13 connects to the base station AP1. It is possible. Since the security level of the terminal WL13 is higher than the minimum level of BSS1, the terminal WL13 selects this security level of "enc.1" and starts a connection request to the base station AP1. That is, the process proceeds to step S2 of FIG. 7, the selected security level is notified, and the same operation as the description of the first embodiment is performed below.
【0096】
However, in this case, since it can be expected that the security level equal to or higher than the minimum level is always notified from the terminal WL side, step S3 in FIG. 7 may be omitted in the base station AP1. Further, in step S2, the terminal WL13 selects a security level equal to or higher than the minimum level of BSS1 notified by the beacon frame from the security levels of the terminal WL13 itself (when there are a plurality of such security levels). , All of them, or some of them, or one of them may be selected, for example, the one with the highest security level, the one with the lowest security level, or the desired one.) Notify the base station AP1.
【0097】
In this way, the base station AP1 of BSS1 whose minimum security level is predetermined broadcasts the minimum security level of the BSS, so that the terminal WL13 can connect to the other party at the security level supported by itself. Since the connection is started after selecting in advance, unnecessary traffic can be reduced.
【0098】
Further, the terminal WL13 can send a probe request frame (probe request) to the base station AP1, and the base station AP1 can notify the security level by the probe response frame (probe response).
【0099】
(Third Embodiment) In the first embodiment described above, the case where the authentication and the association specified in IEEE802.11 are carried out in this order has been described, but the association is first performed and then the authenticity is performed. It is also expected that the application will be implemented. In the third embodiment, this case will be described by taking the case of BSS1 shown in FIG. 1 as an example and referring to the flowchart shown in FIG.
【0100】
Here, as in the first embodiment, the case where the terminal WL13 which is not subscribed to the BSS1 requests the connection to the base station AP1 of the BSS1 will be described, and only the part different from the first embodiment will be described.
【0101】
The terminal WL13 receives the beacon frame transmitted from the base station AP1 as shown in step S31, and then transmits the association request frame to the base station AP1 as shown in step S32 in order to connect to the base station AP1. ..
【0102】
As described above, the frame of the MAC frame association specified in IEEE 802.11 is the "capacity" of the frame body as shown in FIGS. 9 (a), 9 (b) and 9 (c). An unused area, that is, a reserve field, is prepared in "Capability information". The transmitter 107 of the terminal WL13 writes at least one desired security level supported by the terminal WL13 to this reserve field and transmits it to the base station AP1 as shown in step S32. For example, here, the transmitter 107 of the terminal WL13 writes data indicating "enc.1" of one of all the security levels ("enc.0" "enc.1") of the terminal WL13 to the reserve field. , Shall be transmitted to the base station AP1.
【0103】
The processing operation of the base station AP1 that has received this is the same as that of the first embodiment. That is, the reception control unit 13 of the base station AP1 takes out the security level of the terminal WL13 written in the request frame (Association Request) of the received association, and registers this security level in the security table 21 of the base station AP1. Compare with the lowest security level of BSS1. When the security level of this terminal WL13 notified from the terminal WL13 is the security level supported by the base station AP1 and is higher than the lowest security level in BSS1, the connection of the terminal WL13 is performed as shown in step S33. Judge to allow. If the security level is lower than the minimum security level of BSS1, it is determined that the connection of the terminal WL13 is rejected as shown in step S33. That is, when rejecting the connection of the terminal WL13, for example, according to the provisions of IEEE802.11, as shown in step S34, the response frame of the association (Status of Association Response) Write a code to the effect that the connection has failed in code) and reply to the terminal WL13. Upon receiving this frame, the terminal WL13 determines that the connection has been rejected by the base station AP1 and interrupts the connection procedure at this stage.
【0104】
On the other hand, when the connection of the terminal WL13 is permitted, the association responds in accordance with the provisions of IEEE 802.11 for communication using "enc. 1", which is the lowest security level of BSS1 notified from the terminal WL13. Write a code indicating that the connection is successful in the frame (Status code of Association Respose), and reply to the terminal WL13 as shown in step S36.
【0105】
In response to this, the terminal WL13 transmits an authentication frame as shown in step S37 for the authentication process for sharing the cryptographic parameters between the terminal WL13 and the base station AP1 in accordance with the provisions of IEEE 802.11. To do. The processing of the authentication after the transmission of the authentication frame is executed in accordance with the provisions of IEEE 802.11. Since this process complies with the provisions of IEEE 802.11, its description will be omitted.
【0106】
It should be noted that, in the case of this third embodiment, the same effect as in the case of the first embodiment can be expected, and it goes without saying that a number of variations as described in the first embodiment can be applied. Nor.
【0107】
(Fourth Embodiment) Next, when a terminal communicates while moving between the areas of a plurality of base stations, FIG. 1 shows a method for ensuring the security level for each area, that is, for each BSS. A wireless LAN system will be described as an example. This fourth implementation is a method for ensuring a predetermined minimum security level for each BSS to which each base station belongs, even in a situation where the terminal WL is moved, that is, in a so-called mobile environment. It will be described in the form. Basically, as described in the first embodiment above, each BSS base station receives a connection request from a terminal and is notified of the security level by the terminal, which is then sent to its own BSS. It is the same in that the connection of the terminal is permitted and the authentication process for sharing the encryption parameter is executed between the base station and the terminal only when the security level is equal to or higher than the predetermined minimum security level.
【0108】
For example, in the wireless LAN system specified in IEEE 802.11, if the terminal WL13 in Fig. 1 was connected to the base station AP2 and moved into the area of the base station AP1, the terminal WL13 and the base station Reassociation is executed with AP1. Then, when this reassociation procedure is completed normally, data frames are transmitted and received.
【0109】
In this fourth embodiment, the security level of the terminal WL13 is notified from the terminal WL13 to the base station AP1 by using the unused area in the reassociation request frame (Reassociation Request).
【0110】
Hereinafter, in the wireless LAN system shown in FIG. 1, the flowchart shown in FIG. 15 is shown for the case where the terminal WL13 moves from the area of the base station AP2 to the area of the base station AP1 and the reassociation is performed for the base station AP1. It will be explained with reference to. In FIG. 15, the same parts as those in FIG. 13 are designated by the same reference numerals, the description thereof will be omitted, and different procedures will be described.
【0111】
After receiving the beacon frame transmitted from the base station AP1 as shown in step S31, the terminal WL13 transmits a reassociation request frame to the base station AP1 as shown in step S51 in order to connect to the base station AP1. ..
【0112】
As shown in FIGS. 14 (a) to 14 (c), an unused area, that is, a reserve field, is included in the "Capability information" of the frame body of the MAC frame association frame specified in IEEE 802.11. Is prepared.
【0113】
As shown in step S51, the transmission unit 107 of the terminal WL13 writes at least one desired security level supported by the terminal WL13 to this reserve field and transmits it to the base station AP1. For example, here, the transmitter 107 of the terminal WL13 writes the data indicating enc.1 among all the security levels (enc. 0 and enc.1) that it has, and writes the data indicating enc.1 to the base station AP1. Send.
【0114】
The processing operation of the base station AP1 that has received the frame of this association is the same as the description of FIG. 13, so refer to the description of step S33 of FIG. However, if the connection of the terminal WL13 is rejected in step S33, a code indicating that the connection has failed is written in the status code of the reassociation response frame in accordance with the provisions of IEEE802.11, and as shown in step S52. It is returned to the terminal WL13. If the connection of the terminal WL13 is permitted, a code indicating that the connection is successful is written in the status code of the reassociation response frame in accordance with the provisions of IEEE802.11, and the code is returned to the terminal WL13 as shown in step S53. Will be done.
【0115】
When the base station AP1 allows the connection of the terminal WL13, it is required that the encryption parameters are shared between the base station AP1 and the terminal WL13. Therefore, as shown in steps S37 to S44 of FIG. 15, the authentication process for sharing the encryption parameters between the terminal WL13 and the base station AP1 in accordance with the provisions of IEEE802.11, as in FIG. That is, the procedure for authentication may be taken.
【0116】
Further, in the request frame for the association from the terminal WL13, the address of the base station to which the terminal WL13 is currently connected, that is, the base station AP2 is described. This address corresponds to the "Current AP address" shown in FIGS. 14 (a) to 14 (c). Therefore, as shown in Fig. 15, the authentication procedure was not taken and the "current AP address (Current AP)" was not taken. Based on "address)", the base station AP1 connects to the base station AP2. Then, the base station AP1 requests the transfer of the security information about the terminal WL13 registered in the security table of the base station AP2, and after the transfer of the security information, the security information is registered in the security table. good. As a result, the encryption parameters are shared between the base station AP1 and the terminal WL13. Therefore, after the terminal WL13 is allowed to connect from the base station AP1 shown in step S53, the terminal WL13 is encrypted at the same security level, similar to the communication between this terminal WL13 and the base station AP2. Data frames can be sent and received to and from the base station AP1.
【0117】
In the communication system according to the fourth embodiment, the same effect as in the first embodiment can be expected, and many variations as described in the first embodiment can be applied. Needless to say.
【0118】
(Fifth Embodiment) As described above, in the communication system according to the first to fourth embodiments, the terminal WL13 is equal to or higher than the minimum level predetermined for the BSS1 to which the base station AP1 belongs with the base station AP1. Communication can be realized at the security level. However, when the terminal WL13 communicates with the base station AP1 and at the same time the terminal WL13 communicates with a terminal other than the base station AP1 that is not subscribed to BSS1 or another radio station, the security level of communication between them is set in advance in BSS1. If it is lower than the minimum level set, it cannot be said that the minimum level of security of BSS1 is secured as a result. Therefore, in the communication system according to the fifth embodiment, as shown in FIG. 16, when the terminal WL13 is already wirelessly connected to a certain terminal WL14, even if the terminal WL13 requests the base station AP1 to connect. , The minimum level of security set in advance for BSS1 can be ensured by following the procedure described below.
【0119】
When the terminal WL13 is wirelessly connected to another terminal or base station at a security level less than the minimum security level predetermined in BSS1, the terminal WL13 is connected to the base station or terminal in BSS1. Is basically disabled. Therefore, in order to connect to a terminal or base station in BSS1, such a low security level wireless connection must be disconnected in advance, or the security level of the wireless connection must be raised to the minimum level of BSS1 or higher. Is required.
【0120】
Hereinafter, the procedure for that purpose will be described by omitting the description of the common procedure described in the first to fourth embodiments and explaining different procedures.
【0121】
In FIG. 16, the same parts as those in FIG. 1 are designated by the same reference numerals, and the description thereof will be omitted. It is assumed that the security level supported by the terminal WL14 shown in FIG. 16 is only "enc. 0". When the terminal WL13 initiates a connection request to the base station AP1, it is assumed that the terminal WL13 is already wirelessly connected to the terminal WL14 and the communication security level during that time is "enc.0".
【0122】
In such a state, a case where the terminal WL13 starts a connection request to the base station AP1 of BSS1 will be described.
【0123】
First, as described in the second embodiment, the case where the BSS1 is notified of the minimum security level predetermined by the beacon frame will be described with reference to the flowchart shown in FIG. In this case, the terminal WL13 knows that the lowest security level that can wirelessly connect to the base station AP1 from the received beacon frame is "enc.1". Therefore, the terminal WL13 executes the processing operation shown in FIG. 17 before proceeding to step S32 in FIG.
【0124】
In step S61 of FIG. 17, it is confirmed whether the security level of the terminal WL13 has a security level equal to or higher than the minimum level enc.1 allowed by BSS1. If the terminal WL13 has a security level of "enc.1" or higher, the process proceeds to step S62. In this step S62, whether or not the security level of communication between the terminal WL13 is currently wirelessly connected, that is, the terminal WL14 and the terminal WL13 is equal to or higher than the minimum level "enc.1" allowed by BSS1. Is checked. If the security level of communication between the terminal WL13 and the terminal WL14 is equal to or higher than the minimum level "enc.1" allowed by BSS1, the process proceeds to step S64 and the connection procedure between the terminal WL13 and the base station AP1 is started. Will be done. That is, in the terminal WL13, the processes after step S32 in FIG. 13 are executed. On the other hand, if the security level between terminal WL13 and terminal WL14 is less than the minimum level allowed by BSS1 (enc.1), proceed to step S63 and wirelessly connect between terminal WL13 and terminal WL14. Is disconnected, and the process proceeds to step S64.
【0125】
As described above, since the security level of the communication between the terminal WL13 and the terminal WL14 is "enc.0", the process proceeds from step S62 to step S63, and the wireless connection between the terminal WL13 and the terminal WL14 is disconnected. To. After that, the terminal WL13 ends the deauthentication specified in IEEE 802.11 and proceeds to step S64.
【0126】
In this way, when the security level between the terminal WL13 and the currently connected terminal WL14 is lower than the security level broadcast from the base station AP1 that is required to be connected, the terminal WL13 and the terminal WL14 are connected in advance by wireless connection. It is disconnected and a connection request is made from the terminal WL13 to the base station AP1. Therefore, the wireless connection between the terminal WL13 and the base station AP1 is surely executed while maintaining the minimum security level of BSS1.
【0127】
In step S63, after the wireless connection between the terminal WL13 and the terminal WL14 is temporarily disconnected, the terminal WL13 and the terminal WL14 may be wirelessly connected again at a security level equal to or higher than the minimum level of BSS1.
【0128】
In the above description, the case where the terminal WL13 is wirelessly connected to only one of the terminals WL14 has been described, but when the terminal WL13 is wirelessly connected to a plurality of terminals or a plurality of base stations, the same procedure as described above is performed. The security level of each one is checked. If the security level is not higher than the minimum level of BSS1, the connection between the terminal WL13 and other terminals is temporarily disconnected, the terminal WL13 is set to the minimum level of BSS1 or higher, and the connection to the base station AP1 is started. You may.
【0129】
In the above explanation, the case of the terminal WL13 wirelessly connected to the terminal WL14 has been described as an example, but the above series of procedures may be applied to the processing operation of the base station AP2 of another BSS2 different from the BSS1. it can. In this way, when both the side that issued the connection request and the side that received the connection request are base stations instead of terminals, DS communication in which the minimum security level is ensured in each of a plurality of BSSs becomes possible. When the side that issued the connection request is a base station, the base station may be wirelessly connected to multiple terminals or base stations. In such a case, the security level of each of them may be the same as above. If the level is not higher than the minimum level of BSS to be connected, the access point may temporarily disconnect from the terminal WL and other access points. After that, if necessary, the security level of the access point may be set to the minimum level or higher of the BSS to be connected, and then the connection to the desired base station may be started.
【0130】
Next, as described in the first, third, and fourth embodiments, the flowchart shown in FIG. 18 is shown for the case of checking the security level of the terminal WL13 at the time of authentication, association, and reassociation. It will be explained with reference to. The processing operation shown in FIG. 18 corresponds to step S3 in FIG. 7, step S33 in FIGS. 13 and 15, and the like.
【0131】
When checking the security level of the terminal WL13, as described above, the terminal WL13 writes the security level of the terminal WL13 in the unused area on the request frame of the authentication or the request frame of the association or the association. , At least one of the following items (1) to (2) is written to the unused area or the other unused area.
【0132】
1 Whether or not there is a terminal or base station to which the terminal WL13 is currently wirelessly connected.
【0133】
2 Security level between terminal WL13 and the terminal or base station currently wirelessly connected Here, if terminal WL13 is wirelessly connected to multiple terminals or base stations, the security level for all of them. Is written to the unused area.
【0134】
The base station AP1 receives the frame as shown in step S71, and first checks the security level of the terminal WL13 as shown in step S72. If the security level of terminal WL13 does not meet the minimum security level specified in BSS1, the process proceeds to step S73 and the connection is refused. That is, as described in the first, third, and fourth embodiments, the connection refusal is notified to the terminal WL13 in the frames of authentication, association, and reassociation.
【0135】
On the other hand, if the security level of the terminal WL13 is the security level supported by the base station AP1 and is higher than the minimum security level defined in BSS1, the next step is to proceed to step S74. If it is determined from the above information (1) or (2) that there is no terminal or base station currently wirelessly connected to the terminal WL13, the process proceeds to step S75, and the wireless connection of the terminal WL13 is permitted. That is, as described in the first, third, and fourth embodiments, the permission of the wireless connection is notified to the terminal WL13 in the frame of authentication, association, and reassociation, and the subsequent processing is described above. Is executed in the same way as. This process corresponds to step S6 in FIG. 7, step S36 in FIG. 13, step S53 in FIG. 15, and the like. If it is determined from the information of (1) or (2) above that there is a terminal or base station currently wirelessly connected to the terminal WL13, the process proceeds to step S76.
【0136】
In step S76, if the information received in step S71 includes the "security level between the terminal WL13 and the terminal WL14 currently wirelessly connected" shown in 2 , the security level is Checked. If the security level with the terminal WL14 is higher than the minimum security level specified in BSS1, the process proceeds to step S75, and the wireless connection of the terminal WL13 is permitted. On the other hand, when the security level with the terminal WL14 is less than the minimum security level defined in BSS1, or when the information received in step S71 does not include the information shown in 2 above. That is, when the security level with the terminal WL14 is unknown, the process proceeds to step S77, and the connection request from the terminal WL13 is rejected. As described in the first, third, and fourth embodiments, the rejection of this connection request is notified to the terminal WL13 in the frames of authentication, association, and reassociation.
【0137】
In step S77, instead of notifying that the connection request is rejected, the request for instructing the disconnection of the wireless connection with the terminal WL14 is made in the same manner in the authentication, association, and reassociation frames. You may notify by. In this case, the terminal WL13 can immediately determine that it can connect to the base station AP1 by disconnecting the wireless connection with the terminal WL14. Therefore, the terminal WL13 can request the connection to the base station AP1 again after disconnecting the wireless connection with the terminal WL14, for example, after terminating the deauthentication specified in IEEE 802.11. ..
【0138】
In addition, after rejecting the connection request in step S77, the subtype is the management frame of the MAC frame specified in IEEE802.11 and the currently unused frame among the control frames, for example, the management frame. For frames such as "0110" to "0111" and control frames, use frames with subtypes such as "0000" to "1001" to notify the lowest security level allowed by BSS1. Is also good. If there is a notification of the lowest security level allowed by BSS1, if terminal WL14 can support the lowest security level, terminal WL13 reconnects to that security level and then makes a connection request to base station AP1 again. It can be carried out.
【0139】
Further, in the above description, the case where the terminal WL13 is wirelessly connected to only one of the terminals WL14 is described as an example. However, even when wirelessly connected to a plurality of terminals and base stations, the terminal WL13 has the presence or absence of already connected terminals and base stations, preferably one by one, in the same manner as described above. You may notify the security level. When a plurality of security levels of wireless communication already connected are notified from the terminal WL13, the base station AP1 may check the security level for each of them in step S76.
【0140】
As described above, even if the side that issued the connection request is already wirelessly connected to another terminal or base station, when the security level of this wireless connection is unknown, or the side that received the connection request. When the minimum security level of is not met, the minimum security level of the side receiving the connection request can be ensured by rejecting the connection request. Although the above description has been given by taking the case of the terminal WL13 wirelessly connected to the terminal WL14 as an example, it can also be applied to the processing operation of the base station AP2 of another BSS2 different from the BSS1. In this way, when both the side that issued the connection request and the side that received the connection request are base stations instead of terminals, DS communication in which the minimum security level of each is ensured is possible in a plurality of BSSs. When the side issuing the connection request is a base station, the base station may be wirelessly connected to a plurality of terminals or base stations. In such a case as well, it is preferable that the side issuing the connection request notifies the presence / absence of the terminal or base station already connected, preferably the security level of each of them, in the same manner as described above. When the side that received the connection request notifies the side that issued the connection request of multiple security levels of the wireless communication that is already connected, in step S76, the security level for each of them may be checked. ..
【0141】
(Sixth Embodiment) In the wireless system according to the first embodiment, the case where the connection request is made to the base station has been described, but the same method is applied to the case where the connection request is made from the terminal to the terminal. Can be done. Here, as shown in FIG. 19, a case where a terminal WL12 belonging to BSS1 is requested to be connected by a terminal WL15 not subscribed to BSS1 will be described as an example. The only security level that the terminal WL15 can support is "enc. 0". Since the terminal WL12 is subscribed to BSS1, it is necessary to ensure the minimum security level predetermined for BSS1 when the terminal WL12 communicates. Therefore, the same processing operation as that shown in FIG. 7 between the terminal and the base station is performed between the terminal WL12 and the terminal WL15.
【0142】
FIG. 20 shows a processing procedure between the terminal WL12 and the terminal WL15 when a connection request is made from the terminal WL15 to the terminal WL12. In FIG. 20, the same parts as those in FIG. 7 are designated by the same reference numerals, the description thereof will be omitted, and the differences will be described below.
【0143】
In FIG. 20, the processing operation at the base station shown in FIG. 7 corresponds to the processing operation at the terminal WL12. Therefore, step S1 of transmitting the beacon frame is unnecessary. The other steps S2 to S12 are the same as those in FIG. 7. The association procedure is not required.
【0144】
As shown in FIG. 20, when setting the connection between the terminal WL12 and the terminal WL15, the terminal WL12 on the side receiving the connection request checks the security level of the terminal WL15 on the side issuing the connection request. .. Here, the security level of the terminal that issued the connection request is the security level supported by the device that received the connection request, and moreover, it is equal to or higher than the lowest security level of BSS1 to which the terminal that received the connection request belongs. If so, the connection of the terminal WL15 is permitted. If the security level of the terminal that issued the connection request is not the security level supported by the device that received the connection request, or if it is below the lowest security level of BSS1 to which the terminal that received the connection request belongs. , The connection of terminal WL15 is rejected. If the connection is allowed, a manual operation is performed to share the cryptographic parameters corresponding to the security level.
【0145】
When the terminal WL12 receives a connection request from the terminal WL13, the terminal WL12 executes the processing operation as shown in FIG. 20 regardless of whether the terminal WL12 is wirelessly connected to the base station AP1. ..
【0146】
In FIG. 19, the terminal WL15 may be subject to a mode of directly transmitting a data frame to the terminal WL12. This mode is called ad hoc mode. This ad hoc mode can be executed without going through authentication. The ad hoc mode and the processing operation on the terminal WL12 will be described with reference to the flowchart shown in FIG.
【0147】
The terminal WL12 receives a data frame directly addressed to the terminal WL12 from the terminal WL15 without going through the base station as shown in step S81). For such a data frame, for example, according to the specification of IEEE802.11, "To DS" and "From DS" in the frame control of the MAC frame shown in FIG. 4 are both "0", so that it is easy. I can judge.
【0148】
When this data frame is received, the receiving unit 101 of the terminal WL12 checks whether the security information corresponding to the source address is registered in the security table 110 of the terminal WL12 as shown in step S82. Will be done.
【0149】
The fact that the security information of the terminal WL15 is registered in the security table means that the terminal WL15 has communicated with the terminal WL12 in the past at a security level equal to or higher than the minimum level predetermined in BSS1 registered in the security table. It means that there is something or that it is predetermined to communicate at such a security level. Therefore, the process proceeds to step S83, and the terminal WL12 transmits, for example, an ACK frame for the received data frame specified in EEE802.11 to the terminal WL15, and starts transmitting / receiving data to / from the terminal WL15.
【0150】
On the other hand, in step S82, when the security information of the terminal WL15 is not registered in the security table, the security level of the terminal WL15 is unknown as it is, so that the terminal WL12 cannot communicate with the terminal WL15. Therefore, the process proceeds to step S84, and the terminal WL15 is notified that the authentication is requested without transmitting the ACK frame. This notification is for the management frame of the MAC frame specified in IEEE 802.11, and the currently unused frame among the control frames, for example, in the case of the management frame, the subtype is "0110" to "0111". In the case of a frame or a control frame, the notification may be made using a frame whose subtype is "0000" to "1001".
【0151】
Upon receiving this notification, the terminal WL15 may start the processing operation after step S2 shown in FIG. In step 84 described above, the terminal WL12 may transmit an ACK frame, the terminal WL15 may start the process of step S2, and then the step shown in FIG. 20 may be executed.
【0152】
In the communication procedure according to the fifth embodiment, as shown in FIG. 16, when the terminal WL13 is already wirelessly connected to a certain terminal WL14 and requests the base station AP1 to connect, the base station AP1 Explained the method for ensuring the minimum level of security predetermined in BSS1 of. Correspondingly, next, as shown in FIG. 22, when the terminal WL15 is wirelessly connected to the existing terminal WL16, the case where the terminal WL15 requests the connection to the terminal WL12 will be described.
【0153】
Here, the security level that can be supported by the terminal WL16 is only "enc. 0". Since the terminal WL12 is subscribed to BSS1, it is necessary to ensure the minimum security level predetermined for BSS1 when the terminal WL12 starts communication. For that purpose, the same processing operation as that shown in FIG. 18 may be performed on the terminal WL12.
【0154】
FIG. 23 shows a processing procedure between the terminal WL12 and the terminal WL15 when a connection request is made from the terminal WL15 to the terminal WL12. In FIG. 23, the same parts as those in FIG. 18 are designated by the same reference numerals, the description thereof will be omitted, and different parts will be described. That is, in FIG. 23, the processing operations of the base station and the terminal WL13 of FIG. 18 correspond to the processing operations of the terminal WL12 and the terminal WL15, respectively, and substantially the same processing as the processing procedure shown in FIG. 18 is performed. .. Therefore, the explanation with reference to FIG. 23 can be understood without any particular explanation if the base station and the terminal WL13 in the above explanation in FIG. 18 are replaced with the terminal WL12 and the terminal WL15, respectively.
【0155】
Further, in FIG. 22, when the terminal WL15 tries to directly transmit the data frame to the terminal WL12 without going through the authentication, the terminal WL12 performs the processing operation of the flowchart of FIG. The processing operation as shown may be performed. Preferably, when the terminal WL12 receives a data frame directly addressed to the terminal WL12 from the terminal WL15 in step S81 of FIG. 21 without going through the base station, the terminal WL12 immediately proceeds to step S84 and proceeds to the terminal WL15. In order to ensure security, it is desirable to notify the user that an authentication is requested and always perform the processing operation shown in FIG. 23. Since the security information of the terminal WL15 is registered in the security table of the terminal WL12, the terminal WL15 does not always communicate with a terminal other than the terminal WL12 at the minimum security level of BSS1 to which the terminal WL12 belongs. Because there isn't.
【0156】
In the above description, the case where the terminal WL15 is wirelessly connected to only one of the terminals WL16 has been described as an example, but when the terminal is wirelessly connected to a plurality of terminals or base stations, the terminals are similarly connected in the same manner as described above. The WL15 notifies the presence or absence of terminals and base stations that are already connected, preferably the security level of each one. When a plurality of security levels of wireless communication already connected are notified from the terminal WL15, the terminal WL12 may check the security level for each of them in step S76.
【0157】
As described above, according to the sixth embodiment, even in communication between a plurality of terminals, when one of them is a terminal in the BSS in which the minimum security level to be protected is predetermined. The security level can be ensured.
【0158】
(7th Embodiment) In the 1st to 6th embodiments described above, the case of ensuring the security level of BSS has been described. A similar method can be applied to ensure the security level in IBSS.
【0159】
In this seventh embodiment, IBSS1 having a configuration as shown in FIG. 24 will be described as an example.
【0160】
In FIG. 24, IBSS1 is composed of a plurality of terminals, for example, three terminals WL31 to WL33. Terminal WL31 supports security levels "enc.0", "enc.1", terminal WL32 supports security levels "enc.0", "enc.1", "enc.2", terminal WL33 Shall support security levels "enc.0" and "enc.1".
【0161】
According to the provisions of IEEE 802.11, IBSS can directly send and receive data frames between multiple terminals in IBSS without going through a base station and without going through the authentication authentication process. If each terminal in IBSS1 has a security table and the security information of each terminal that composes IBSS1 is registered in this security table, communication can be performed at a predetermined minimum security level or higher in IBSS1. , The minimum security level can be ensured between the terminals in IBSS1.
【0162】
Therefore, regarding the processing operation when a connection request is received from one of the plurality of terminals constituting IBSS1, for example, terminal WL31, from terminal WL34 which is not subscribed to IBSS1, that is, is not registered in the security table. explain.
【0163】
In this processing operation as well, similarly to the sixth embodiment, the terminal WL31 preferably performs the processing operation as shown in FIG. 21, and the security information of the source of the received data frame is its own security table. When it is not registered in, a notification to the effect that authentication is requested is transmitted to the source of the data frame, that is, the terminal WL34. After that, when the authentication frame is transmitted from the terminal WL34, the processing operation as shown in FIG. 23 is preferably performed. However, the terminal WL15 shown in FIG. 23 may be replaced with the terminal WL34. That is, the terminal WL34 writes the security level of the terminal WL34 in the frame of the authentication, writes at least one of the above 1 to 2 , and transmits it to the terminal WL31. The terminal WL31 may receive such an authentication frame from the terminal WL34 and perform the same processing operation as the terminal WL12 shown in FIG. 23.
【0164】
In this way, even in the IBSS, the minimum security level predetermined for the IBSS can be ensured.
【0165】
Also, in communication between a plurality of terminals, if one of them is a terminal in IBSS in which the minimum security level to be protected is predetermined, the security level can be ensured.
【0166】
As described in the first to seventh embodiments above, each of the wireless communication devices constituting the wireless LAN, such as a base station and a terminal, has at least one (preferably a plurality) security levels, and has the following (preferably a plurality of) security levels. By providing the features shown in x1) to (x8), for example, wireless communication that secures the minimum security level by the basic group of wireless LAN such as BSS and IBSS, that is, the encryption predetermined for each communication group. Can be realized. Further, in communication between a plurality of wireless communication devices, at least one of the plurality of wireless communication devices is a communication group having a predetermined minimum security level, in other words, a minimum security level, for example. When it is a wireless communication device in BSS or IBSS, the security level above the above minimum level can always be ensured. Of the following (x1) to (x8), the features that are not specified as being a base station are preferably functions that both the base station and the terminal should have in common.
【0167】
(x1) When a connection request is made from the own device to the first wireless communication device which is another wireless communication device, the first radio among the security levels of the own device is sent to the first wireless communication device. Notify at least one first security level, which is the security level used for communication with the communication device.
【0168】
(x2) When requesting a connection to the first wireless communication device, the own device is already connected to a second wireless communication device which is another wireless communication device different from the first wireless communication device. Occasionally, the second security level, which is the security level used for communication with the second wireless communication device, is notified.
【0169】
(x3) When the first wireless communication device is a base station and the lowest security level that can be connected to the first wireless communication device is broadcast, the lowest security level of the own device is broadcast. A security level equal to or higher than the level is selected, and the first wireless communication device is notified when a connection request is made.
【0170】
(x4) When the first wireless communication device is a base station and a plurality of security levels connectable to the first wireless communication device are broadcast, the broadcast among the security levels of the own device is broadcast. A security level that matches any of the plurality of security levels that have been set is selected, and the selected security level is notified when a connection request is made to the first wireless communication device.
【0171】
(x5) When the own device receives a connection request from a fourth wireless communication device which is another wireless communication device, A at least the fourth wireless communication device notified from the fourth wireless communication device. The third security level, which is the security level used for communication with the own device, is the security level of the own device, and the minimum predetermined for the communication group to which the own device belongs (that is, for example, BSS or IBSS). When it is above the level, the connection of the fourth wireless communication device is permitted, and (b) at least when the third security level is less than the minimum level, the connection with the fourth wireless communication device is permitted. Provide a third means of refusal.
【0172】
(x5 ́) In the third means, A, the third security level is equal to or higher than the minimum level predetermined for the communication group to which the own device belongs, and the fourth wireless communication device is the fourth. This is the security level used for communication with the fifth wireless communication device when it is already connected to the fifth wireless communication device, which is another wireless communication device different from the wireless communication device. When the security level of 4 is at least the minimum level, connection with the fourth wireless communication device is permitted, and (b) when the third security level is less than the minimum level, or at the first level. When the security level of 4 is less than the minimum level, or when the fourth wireless communication device is already connected to the fifth wireless communication device and the fourth security level is unknown. Reject the connection with the fourth wireless communication device.
【0173】
(x7) When the own device is a base station, the communication group to which the own device belongs is provided with a predetermined lowest security level or a fourth means for broadcasting a plurality of security levels above the lowest level.
【0174】
(x8) When a plurality of security levels are notified from the fourth wireless communication device, if the plurality of security levels are equal to or higher than the predetermined minimum level in the communication group to which the own device belongs, among them. It comprises a fifth means of selecting one of the above and notifying the fourth wireless communication device of it.
【0175】
The method of the present invention described in the embodiment of the present invention records magnetic disks (floppy disks, hard disks, etc.), optical disks (CD-ROM, DVD, etc.), semiconductor memories, etc. as programs that can be executed by a computer. It can also be stored on a medium and distributed.
【0176】
[Effect of the invention]
As described above, according to the present invention, for each basic wireless LAN group (communication group) such as BSS and IBSS, wireless communication that secures the minimum security level by encryption predetermined in each group. Can be done. Further, in communication between a plurality of wireless communication devices, at least one of the plurality of wireless communication devices has a communication group (for example, BSS) in which a minimum security level (minimum security level) is predetermined. And IBSS), the security level above the minimum level can always be ensured.
[Simple explanation of drawings]
FIG. 1 is a schematic diagram schematically showing a communication system according to an embodiment of the present invention.
FIG. 2 is a block diagram showing an example of a circuit configuration of the base station shown in FIG.
FIG. 3 is a block diagram showing an example of a circuit configuration of the wireless terminal shown in FIG.
FIG. 4 is a schematic diagram showing a structure of a MAC frame defined in IEEE 802.11, which is transferred between a base station and a terminal in the communication system shown in FIG. 1.
FIG. 5 is a table showing a specific example of a security table provided in a base station or terminal in the communication system shown in FIG.
FIG. 6 is a table in which a base station or terminal in the communication system shown in FIG. 1 shows another specific example of a security table.
FIG. 7 is a flowchart for explaining an example of processing operations of a base station and a terminal in the communication system shown in FIG.
FIG. 8 (a) is a schematic diagram showing a frame structure of authentication defined in IEEE 802.11, which is transferred between a base station and a terminal in the communication system shown in FIG. 1 and (b). Is a table showing the contents described in the item of the frame shown in (a).
9 (a) to 9 (c) show the structures of an association request frame and an association response frame specified in IEEE 802.11, which are transferred between a base station and a terminal in the communication system shown in FIG. It is a schematic diagram.
FIG. 10 is a table showing a specific example of an updated security table provided in a base station or terminal in the communication system shown in FIG.
FIG. 11 is a schematic diagram showing a structure of a beacon frame defined in IEEE 802.11 directed from a base station to a terminal in the communication system shown in FIG.
FIG. 12 is a flowchart showing a processing procedure in which a base station in the communication system shown in FIG. 1 notifies the BSS to which the base station belongs to a terminal and requests a connection to the base station.
FIG. 13 is a flowchart showing a processing procedure in which a security level is notified using an association response frame transferred between a base station and a terminal in the communication system shown in FIG. 1 and the security level is checked.
14 (a) to 14 (c) show the structures of the reassociation request frame and the reassociation response frame specified in IEEE 802.11, which are transferred between the base station and the terminal in the communication system shown in FIG. It is a schematic diagram which showed.
FIG. 15 is a flowchart showing a processing procedure in which a security level is notified using a reassociation response frame transferred between a base station and a terminal in the communication system shown in FIG. 1 and the security level is checked. ..
FIG. 16 is a block diagram schematically showing a communication system according to another embodiment of the present invention.
FIG. 17 is an example of a processing procedure on the side that issued a connection request when a wireless communication device connected to another wireless communication device requests a connection to another wireless communication device in the communication system shown in FIG. It is a flowchart for demonstrating.
FIG. 18 is an example of a processing procedure on the side that issued a connection request when a wireless communication device connected to another wireless communication device requests a connection to another wireless communication device in the communication system shown in FIG. It is a flowchart for demonstrating.
FIG. 19 is a block diagram schematically showing a communication system according to still another embodiment of the present invention.
FIG. 20 is a flowchart for explaining a processing procedure for wirelessly connecting terminals in the communication system shown in FIG. 19.
FIG. 21 is a flowchart for explaining an example of a processing operation in a terminal when wirelessly connecting between terminals in the communication system shown in FIG. 19.
FIG. 22 is a block diagram schematically showing a communication system according to still another embodiment of the present invention.
FIG. 23 is a flowchart for explaining another example of processing operation in a terminal for wirelessly connecting terminals in the communication system shown in FIG. 22.
FIG. 24 is a block diagram schematically showing a communication system according to still another embodiment of the present invention.
[Explanation of symbols]
AP1, AP2 ... Base station (wireless base station device) WL11 ~ WL16, WL31 ~ WL34 ... Terminal (wireless terminal device) 11 ... Receiver 12 ... Transmitter 13 ... Reception control unit 14 ... Transmission control unit 20, 100 ... Antenna 21, 110 ... Security table 101 ... Receiver unit 107 ... Transmitter unit 108 ... Information processing unit
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US7269409B2 | Cited by | United States of America | Applicant |
| JP2007074297A | Cited by | Japan | Search report |
| US9544929B2 | Cited by | United States of America | Applicant |
| JP2007535257A | Cited by | Japan | Examiner |
| JP2015192223A | Cited by | Japan | Search report |
| JP2010041666A | Cited by | Japan | Examiner |
| JP2008539660A | Cited by | Japan | Search report |
| WO2006134772A1 | Cited by | World Intellectual Property Organization (WIPO) | International search |
| JP2004274193A | Cited by | Japan | Search report |
| JP2008539660A | Cited by | Japan | Search report |
| JP2006279848A | Cited by | Japan | Search report |
| JP2011512699A | Cited by | Japan | Search report |
| JP2009080847A | Cited by | Japan | Examiner |
| JP4896145B2 | Cited by | Japan | Examiner |
| JP2009534697A | Cited by | Japan | Search report |
| JP2016178412A | Cited by | Japan | Search report |
| JP2006075990A | Cited by | Japan | Examiner |
| JP2007150454A | Cited by | Japan | Search report |
| KR101860515B1 | Cited by | Republic of Korea | Search report |
| US9301328B2 | Cited by | United States of America | Applicant |
| JP2021175069A | Cited by | Japan | Search report |
| US8856523B2 | Cited by | United States of America | Applicant |
| US10015830B2 | Cited by | United States of America | Applicant |
| US7835725B2 | Cited by | United States of America | Applicant |
| JP2008312200A | Cited by | Japan | Examiner |
| JP2010041666A | Cited by | Japan | Search report |
| KR101860515B1 | Cited by | Republic of Korea | Search report |
| US8638689B2 | Cited by | United States of America | Applicant |
| JP2009164971A | Cited by | Japan | Examiner |
| JP2009529273A | Cited by | Japan | Search report |
| JP2011512699A | Cited by | Japan | Examiner |
| US7739491B2 | Cited by | United States of America | Applicant |
| JP2015192223A | Cited by | Japan | Search report |
| US8374339B2 | Cited by | United States of America | Applicant |
| JP2009534697A | Cited by | Japan | Search report |
| JP2005311653A | Cited by | Japan | Examiner |
31 members in 5 offices
Priority claims6
| Document | Office | Kind | Date |
|---|---|---|---|
| 2001395475 | Japan | A | |
| 2001395475 | Japan | – | |
| 2002378650 | Japan | A | |
| 20012001395475 | – | – | – |
| JP20010395475 | – | – | – |
| JP20020378650 | – | – | – |
Members31
| Document | Office | Kind | |
|---|---|---|---|
| US2003119484A1 | United States of America | A1 | |
| EP1324541A2 | European Patent Office (EPO) | A2 | |
| CN1430342A | China | A | |
| JP2004032664AThis record | Japan | A | |
| EP1324541A3 | European Patent Office (EPO) | A3 | |
| CN1251427C | China | C | |
| JP2006333521A | Japan | A | |
| EP1742422A1 | European Patent Office (EPO) | A1 | |
| JP3940670B2 | Japan | B2 | |
| EP1324541B1 | European Patent Office (EPO) | B1 | |
| US7269260B2 | United States of America | B2 | |
| DE60222227D1 | Germany | D1 | |
| US2007286425A1 | United States of America | A1 | |
| DE60222227T2 | Germany | T2 | |
| US7519183B2 | United States of America | B2 | |
| US2009175447A1 | United States of America | A1 | |
| JP2009303238A | Japan | A | |
| JP4405487B2 | Japan | B2 | |
| JP4405586B2 | Japan | B2 | |
| US7813508B2 | United States of America | B2 | |
| US2010329462A1 | United States of America | A1 | |
| US2012189123A1 | United States of America | A1 | |
| US8588419B2 | United States of America | B2 | |
| EP1742422B1 | European Patent Office (EPO) | B1 | |
| US8798271B2 | United States of America | B2 | |
| US2014307874A1 | United States of America | A1 | |
| US9584486B2 | United States of America | B2 | |
| US2017126637A1 | United States of America | A1 | |
| US2017163612A1 | United States of America | A1 | |
| US10250566B2 | United States of America | B2 | |
| US10250567B2 | United States of America | B2 |
15 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Cancellation because of completion of termEXPY | EXPY | |
| Receipt of annual feesJAPANESE INTERMEDIATE CODE: R250R250 | R250 | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Renewal fee payment (event date is renewal date of database)FPAY | FPAY | |
| Written notification of patent or utility model registrationJAPANESE INTERMEDIATE CODE: R151R151 | R151 | |
| First payment of annual fees (during grant procedure)JAPANESE INTERMEDIATE CODE: A61A61 | A61 | |
| Written decision to grant a patent or to grant a registration (utility model)JAPANESE INTERMEDIATE CODE: A01A01 | A01 | |
| Decision of grant or rejection writtenTRDD | TRDD | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Notification of reasons for refusalJAPANESE INTERMEDIATE CODE: A131A131 | A131 | |
| Report on retrievalJAPANESE INTERMEDIATE CODE: A971007A977 | A977 | |
| Request for written amendment filedJAPANESE INTERMEDIATE CODE: A523A521 | A521 | |
| Written request for application examinationJAPANESE INTERMEDIATE CODE: A621A621 | A621 |
Numbers
- Publication
- 2004032664
- Publication, DOCDB
- 2004032664
- Publication, EPODOC
- JP2004032664
- Application
- 378650
- Application, DOCDB
- 2002378650
- Application, EPODOC
- JP20020378650
Titles3
- Japanese
- 無線通信システム及び無線通信装置並びに無線通信方法
- English
- Wireless communication system, wireless communication device and wireless communication method
- English
- RADIO COMMUNICATION SYSTEM, RADIO COMMUNICATION APPARATUS, AND RADIO COMMUNICATION METHOD
Classification
- IPC, 4
- H04L12 28
- H04L9 14
- H04W12 02
- H04W12 08