Roaming between generations of access points with different security protocols
By enabling rapid switching between different security protocols in Wi-Fi networks, the roaming failure problem between new-generation APs and traditional APs is solved, achieving seamless and efficient STA re-association, reducing network latency, and improving connection efficiency.
Patent Information
- Application Number
- CN202480031751.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-07-21
- Filing Date
- 2024-04-25
- Publication Date
- 2025-12-09
AI Technical Summary
In Wi-Fi networks, during roaming between next-generation access points (APs) and traditional APs, differences in security protocols can lead to rapid switching failures, requiring the STA to re-establish the MAC/802.1X state, resulting in longer network latency.
By enabling rapid switching between different security protocols during STA roaming, STAs can efficiently re-associate with Wi-Fi APs using different security protocols, such as from WPA-2 to WPA-3 or vice versa, without initiating a key exchange protocol, thus achieving seamless roaming.
It enables seamless roaming between Wi-Fi 7/8 APs and traditional APs, reducing network latency and improving network connection efficiency and stability.
Smart Images

Figure CN121100512A_ABST
Abstract
Description
Background Technology
[0001] Since its inception, Wi-Fi technology has been continuously evolving and innovating, with each generation achieving significant progress. Following Wi-Fi 5 (802.11ac), Wi-Fi 6 (802.11ax) and Wi-Fi 7 (802.11be) emerged, and Wi-Fi 8 and Wi-Fi 9 (802.11ce) will soon follow. Each iteration brings significant improvements in speed, capacity, efficiency, and overall performance.
[0002] Wi-Fi 5 represents a significant upgrade to its predecessor, Wi-Fi 4 (802.11n). It introduces wider channel bandwidth, multi-user MIMO (Multiple-Input Multiple-Output), and beamforming technology. These advancements significantly improve data transfer rates and network capacity, allowing multiple devices to connect simultaneously and communicate more efficiently. Wi-Fi 6 includes enhanced Orthogonal Frequency Division Multiple Access (OFDMA) and Target Wake-Up Time (TWT) mechanisms, along with higher frequencies, improved overall spectral efficiency and power management, and better performance in congested areas. Wi-Fi 7 (802.11be) leverages multi-band operation, advanced MIMO technology, and improved modulation schemes to deliver speeds up to 30 Gbps. Wi-Fi 7 also focuses on reducing latency and enhancing security features.
[0003] Wi-Fi 8 (802.11ce) aims to revolutionize wireless connectivity by pushing data rates to new heights (up to 100 Gbps). It is expected to introduce advancements such as terahertz frequencies, enhanced spatial multiplexing, and advanced beamforming technology, paving the way for future applications and seamless connectivity experiences.
[0004] As Wi-Fi technology continues to evolve, each new generation brings improvements to meet the growing demands of modern networks, including increased device density, higher data rates, lower latency, and better overall network performance. These advancements play a crucial role in driving emerging technologies, supporting the proliferation of smart devices, and transforming the way we connect and communicate in an increasingly interconnected world. Attached Figure Description
[0005] To illustrate how the above and other advantages and features of this disclosure can be obtained, a more specific description of the principles briefly described above will be presented with reference to specific embodiments illustrated in the accompanying drawings. It is to be understood that these drawings depict only exemplary embodiments of this disclosure and should not be construed as limiting its scope. The principles herein are described and explained with additional specificity and detail using the drawings, in which: Figure 1The diagram illustrates a block diagram of an example wireless communication network according to some aspects of the present technology; Figure 2A This is a network diagram illustrating an example network environment for multi-link operation according to some aspects of this technology; Figure 2B An illustrative diagram depicts a multi-link operation between two logical entities according to one or more exemplary embodiments of the present technology; Figure 2C An illustrative diagram depicts multi-link operation between an AP with logical entities and a non-AP with logical entities, according to some aspects of this technology. Figure 3 The illustration shows example routines for facilitating a STA's rapid transition from roaming to a second Wi-Fi AP, based on some aspects of this technology, where the Wi-Fi APs utilize different security protocols.
[0006] Figure 4A and Figure 4B The illustration shows a STA roaming from a Wi-Fi AP using WPA-2 to a Wi-Fi AP using WPA-3, according to some aspects of this technology.
[0007] Figure 5A and Figure 5B The illustration shows a STA roaming from a Wi-Fi AP using WPA-3 to a Wi-Fi AP using WPA-2, according to some aspects of this technology.
[0008] Figure 6 An example of a system used to implement some aspects of this technology is shown. Detailed Implementation
[0009] Various embodiments of this disclosure are discussed in detail below. While specific implementations are discussed, it should be understood that this is merely for illustrative purposes. Those skilled in the art will recognize that other components and configurations can be used without departing from the spirit and scope of this disclosure.
[0010] Overview Abbreviations - Extremely High Throughput (EHT) Station (STA) Robust and secure network element (RSNE) Association and Key Management (AKM) Paired Master Key (PMK) Paired Transient Key (PTK) Basic Services Set (BSS) Access Point (AP) Wireless LAN Controller (WLC) Wi-Fi Protected Access (WPA) MLD: Multi-link device MLO: Multilink Operation Extended Service Set (ESS) Service Set Identifier (SSID) Wireless Local Area Network (WLAN) Advanced Encryption Standard (AES) Fast Transition (FT) In some aspects, this technology includes: a STA communicating with a first Wi-Fi AP using a message protected by a first security protocol. While roaming, the STA can request a candidate Wi-Fi AP to connect to. The STA can receive an identifier of a second Wi-Fi AP utilizing a second security protocol, which differs from the first security protocol, and can use aspects of the second security protocol to re-associate with the second Wi-Fi AP using a fast switching mechanism.
[0011] This technology may also include: notifying entities within the Wi-Fi network in an association request message that the STA requires roaming support, which includes support for WPA-2 and WPA-3 security protocols.
[0012] This technology may also include: sharing information related to the security protocols supported by the STA within the Wi-Fi network before handshaking with the first Wi-Fi AP, and establishing a connection with the first Wi-Fi AP.
[0013] The technology may further include: wherein the first security protocol includes a first AKM version and a first cipher suite, and the second security protocol utilizes a second AKM version and a second cipher suite.
[0014] This technology may also include: exporting a key for association with the second Wi-Fi AP using a second AKM version before re-associating with the second Wi-Fi AP.
[0015] This technology may also include: determining to switch to a second Wi-Fi AP, and communicating with a first Wi-Fi AP in a BSS switch response to notify the first Wi-Fi AP that the STA will switch to the second Wi-Fi AP.
[0016] This technology may also include: receiving an action frame specifying a second Wi-Fi AP as the target to be switched to.
[0017] The technology may further include: wherein receiving the identifier of the second Wi-Fi AP utilizing the second security protocol includes receiving a plurality of Wi-Fi APs including the second Wi-Fi AP.
[0018] Other technical features can be readily understood by those skilled in the art through the following figures, description and claims.
[0019] Example Implementation Additional features and advantages of this disclosure will be set forth in the description which follows, and some features and advantages will be apparent from the description or may be learned by practicing the principles disclosed herein. The features and advantages of this disclosure can be realized and obtained by the instruments and combinations particularly pointed out in the appended claims. These and other features of this disclosure will become more apparent from the description which follows and the appended claims, or may be learned by practicing the principles set forth herein.
[0020] The disclosed technology addresses the need in the art for efficient reassociation of a STA from an AP using Wi-Fi 7 / 8 technology and associated MKA versions and cipher suites to an AP using Wi-Fi 5 / 6 technology and associated MKA versions and cipher suites. It facilitates efficient reassociation of a STA with a new AP using different keys and key exchange mechanisms without requiring the initiation of a key exchange protocol from the outset when roaming between APs. Conversely, the disclosed technology is also applicable, for example, when roaming from an AP using Wi-Fi 5 / 6 technology and associated MKA versions and cipher suites to an AP using Wi-Fi 7 / 8 technology and associated MKA versions and cipher suites.
[0021] Most customers choose to integrate next-generation access points (APs) into their existing infrastructure rather than replace them entirely. This trend is likely to continue with the introduction of Wi-Fi 7 and 8, which will coexist with older APs. However, a significant difference between EHT APs / EHT+APs (Wi-Fi 7 / 8) and legacy APs (Wi-Fi 5 / 6) is that WPA-3 support is mandatory in Wi-Fi 7 / 8 APs. The WPA3 specification states that STAs prefer the “new” AKM over the legacy AKM (when both are advertised on the Wi-Fi 7 / 8 AP). When two Wi-Fi 7 devices are associated, the legacy AKM should not be negotiated. In other words, when a Wi-Fi 7 / 8 AP is advertised, the AKM suite list and pair cipher suite list fields will carry the legacy AKM / cipher (in addition to the “new” AKM / cipher) to support association with legacy (pre-Wi-Fi 7) STAs. Because the traditional AKM is ineffective for Wi-Fi 7 / 8 pairings, Wi-Fi 7 / 8 STAs will use the new AKM when pairing with Wi-Fi 7 / 8 APs, but will use the traditional AKM / password when pairing with legacy (pre-Wi-Fi 7) APs. This will disrupt roaming between Wi-Fi 7 / 8 APs and legacy APs, as their advertised AKM and password suites will differ. Therefore, Wi-Fi 7 / 8 STAs will need to establish new pairings with Wi-Fi 7 / 8 APs, and seamless roaming will not be possible.
[0022] In enterprise environments, this issue is particularly pronounced because the selection of the AKM suite is not performed on a per-SSID / WLAN-AP basis (e.g., to handle boundary conditions). Instead, the selection is based on an Extended Service Set (ESS), a group of APs managed collectively. A significant problem arising from the aforementioned AKM issue is that fast transitions fail when a STA roams between APs because the STA will unassociate, invalidating the MAC state (including 802.1X states such as AKM / password). The STA then needs to (re)associate with the new AP, establishing a new MAC / 802.1X state, which can potentially lead to significant network latency (e.g., key re-keying, AAA / RADIUS interaction). This technology addresses these issues by facilitating seamless roaming between non-EHT APs (Wi-Fi 5 / 6) and EHT / EHT++ APs (Wi-Fi 7 / 8).
[0023] As used herein, the term “configured” should be considered interchangeable with “configurable” unless the term “configurable” is explicitly used to distinguish it from “configured.” The correct understanding of the term will be apparent to those skilled in the art within the context of its use.
[0024] Various aspects of this disclosure can be implemented in any device, system, or network capable of transmitting and receiving radio frequency (RF) signals according to one or more of the following standards: Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard, IEEE 802.15 standard, Bluetooth Special Interest Group (SIG) standard. The described implementation can be implemented in any device, system, or network capable of transmitting and receiving RF signals according to one or more of the following methods or technologies: Code Division Multiple Access (CDMA), Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Orthogonal FDMA (OFDMA), Single Carrier FDMA (SC-FDMA), Single User (SU) Multiple Input Multiple Output (MIMO), and Multi User (MU) MIMO. The described implementation can also be implemented using other wireless communication protocols or RF signals suitable for use in one or more of the following networks: Wireless Personal Area Network (WPAN), Wireless Local Area Network (WLAN), Wireless Wide Area Network (WWAN), or Internet of Things (IoT) networks.
[0025] IEEE 802.11, commonly known as Wi-Fi, has been around for three decades and has become one of the most popular wireless communication standards, with billions of devices supporting more than half of the world's wireless services. Users' demands for throughput, capacity, latency, spectrum, and power efficiency are constantly increasing, necessitating updates or modifications to the standard to keep pace. Therefore, Wi-Fi typically undergoes new revisions every few years, each with its own set of characteristics. In earlier generations, the focus was primarily on higher data rates, but as device density increased, area efficiency became a major issue for Wi-Fi networks. Due to this problem, the last revision (802.11be (Wi-Fi 7)) focused more on efficiency, although it also included higher data rates. The next anticipated update to IEEE 802.11 is called Wi-Fi 8. Wi-Fi 8 will attempt to further increase throughput and minimize latency to meet the growing demands of the Internet of Things (IoT), high-resolution video streaming, low-latency wireless services, and more.
[0026] In Wi-Fi, multi-access point (AP) coordination and transmission refers to the management of multiple access points in a wireless network to avoid interference and ensure efficient communication between client devices and the network. When multiple access points are deployed in a network (e.g., in buildings and office buildings), they use the same radio frequency, which can cause interference and degrade network performance. To mitigate this problem, access points can be configured to coordinate their transmissions and avoid overlapping channels.
[0027] Wi-Fi 7 introduces the concept of Multi-Link Operation (MLO), which enables devices (Access Points (APs) and Stations (STAs)) to operate simultaneously on multiple links (or even frequency bands). MLO introduces a new paradigm for multi-AP coordination, which was not part of earlier coordination methods. MLO is considered in Wi-Fi 7 to improve network throughput and address latency issues by allowing devices to use multiple links.
[0028] A multilink device (MLD) can have multiple “auxiliary” devices, each with a separate PHY interface, and the MLD has a single link to the Logical Link Control (LLC) layer. In IEEE 802.11be, a multilink device (MLD) is defined as: “a device that is a logical entity and has more than one auxiliary station (STA) and a single Media Access Control (MAC) Service Access Point (SAP) to the Logical Link Control (LLC), which includes a MAC data service” (see: IEEE Computer Society LAN / MAN Standards Committee, Amendment 8: Enhanced Extremely High Throughput (EHT), IEEE P802.11be™ / D0.1, September 2020, Section 3.2). Connections to the MLD(s) on the auxiliary devices can occur individually or jointly. The initial definition and scope of the multilink element are described in Section 9.4.2.247b of the aforementioned IEEE 802.11be draft. The idea behind this information element / container is to provide a way for multi-link devices (MLDs) to share the ability to share different links with each other and to facilitate discovery and association processes. However, this information element may still change, or new mechanisms may be introduced to share MLO information (e.g., related to backhaul usage).
[0029] In multi-link operation (MLO), both the STA and AP can have multiple links, which can be active simultaneously. These links may or may not use the same frequency band / channel.
[0030] MLO allows the transmission of PHY Protocol Data Units (PPDUs) on more than one link between the STA and AP. These links can be carried on different channels in different frequency bands. Depending on the frequency band and / or channel separation and filter performance, the transmission method of PPDUs on each link may be limited.
[0031] MLO can include basic transfer mode, asynchronous transfer mode, and synchronous transfer mode.
[0032] In basic transmission mode, multiple primary links can exist, but a device can send PPDUs on only one link at a time. The link used for transmission can be selected as follows: The device (e.g., AP or STA) can count down the random backoff (RBO) on two links and select the link that wins the transmission medium. The other link may be blocked due to interference within the device. In basic transmission mode, aggregation gain may not be achievable.
[0033] In asynchronous transmission mode, the device can count down the RBO on both links and perform PPDU transmission independently on each link. Asynchronous transmission mode can be used when the device can support simultaneous transmission and reception using frequency bands with sufficient frequency spacing (e.g., the spacing between the 2.4 GHz band and the 5 GHz band). Asynchronous transmission mode can provide both delay gain and aggregation gain.
[0034] In synchronous PPDU transmission mode, the device can count down the RBO on both links. If the first link wins the medium, both links can transmit PPDUs simultaneously. Simultaneous transmission minimizes interference within the device and can provide both delay gain and aggregation gain.
[0035] In the upcoming IEEE 802.11 be amendment, multi-AP coordination and MLO are two features proposed to improve the performance of Wi-Fi networks. Multi-AP coordination aims to reduce interference between basic service sets (BSS) by leveraging (distributed) coordination among different APs to improve spectrum utilization in dense deployments. On the other hand, MLO supports high data rates and low latency by utilizing the flexible resource utilization provided by using multiple links on the same device.
[0036] Figure 1The diagram illustrates a block diagram of an example wireless communication network according to some aspects of the present technology. The wireless communication network 100 may be an example of a wireless local area network (WLAN), such as a Wi-Fi network (hereinafter referred to as WLAN 100). For example, WLAN 100 may be a Wi-Fi network operating based on any currently available or to be developed IEEE 802.11 protocol and standard (e.g., 802.11ay, 802.11ax, 802.11az, 802.11ba, 802.11be, and 802.11ce, etc.). WLAN 100 may include wireless communication devices such as AP 102 and multiple STAs 104. The number of APs and STAs is not limited to this. Figure 1 The number shown is not fixed; it can be more or less. Any one or more of AP 102 and STA 104 are capable of MLO (Multi-Link Receive and / or Transmit).
[0037] Each STA 104 can be one or more of the following: mobile phone, personal digital assistant (PDA), other handheld device, netbook, laptop, tablet, laptop computer, display device (e.g., television, computer monitor, navigation system, etc.), music or other audio or stereo device, remote control device (“remote control”), printer, kitchen or other household appliance, key fob (e.g., for passive keyless entry and start (PKES) system), IoT device, etc.
[0038] A single AP 102 and a set of associated STAs 104 can be referred to as the Basic Service Set (BSS) managed by AP 102.
[0039] Figure 1 An example coverage area 108 of AP 102 is shown, which can represent the Basic Service Area (BSA) of WLAN 100. The BSA can be identified to users via a Service Set Identifier (SSID) and to other devices via a Basic Service Set Identifier (BSSID), which can be the Media Access Control (MAC) address of AP 102. AP 102 can periodically broadcast a beacon including the BSSID to enable any STA 104 within the wireless range of AP 102 to "associate" or reassociate with AP 102, thereby establishing a communication link 106 with AP 102. For example, the beacon may include an identifier of the primary channel used by the corresponding AP 102, and a timing synchronization function for establishing or maintaining timing synchronization with AP 102.
[0040] To establish a communication link 106 with AP 102, each STA 104 is configured to perform passive or active scanning on frequency channels in one or more frequency bands (e.g., 2.4 GHz, 5 GHz, 6 GHz, or 60 GHz bands). Passive scanning requires STA 104 to listen for beacons transmitted by AP 102 at regular intervals (measured in units of time (TU), where one TU can be equal to 1024 microseconds (μs)) called Target Beacon Transmission Time (TBTT). Active scanning requires STA 104 to generate and sequentially send probe requests on each channel to be scanned and listen for probe responses from AP 102. Each STA 104 can be configured to identify or select an AP 102 to associate with based on scanning information obtained through passive or active scanning, and perform authentication and association operations to establish a communication link 106 with the selected AP 102. AP 102 assigns an association identifier to STA 104 at the end of the association operation, which AP 102 can then use to track STA 104.
[0041] Due to the increasing prevalence of wireless networks, STA 104 has the opportunity to select one of many AP 102 within its range, or to choose from multiple AP 102 that collectively form an Extended Service Set (ESS) comprising multiple connected AP 102. The extended network station associated with WLAN 100 can connect to a wired or wireless distribution system that allows multiple AP 102 to be connected within such an ESS. Therefore, STA 104 can be covered by more than one AP 102 and can be associated with different AP 102 at different times for different transmissions. Furthermore, after being associated with an AP 102, STA 104 can also be configured to periodically scan its surroundings to find a more suitable AP 102 to associate with. For example, a STA 104 moving relative to its associated AP 102 can perform a roaming scan to find another AP 102 with more desirable network characteristics, such as a larger Received Signal Strength Indicator (RSSI), reduced traffic load, etc.
[0042] In some cases, STA 104 can form an ad hoc network without AP 102. In some examples, an ad hoc network can be implemented within a larger wireless network (e.g., WLAN 100). In such implementations, while STA 104 can communicate with each other via AP 102 using communication link 106, STA 104 can also communicate directly with each other via direct wireless link 110. Furthermore, two STA 104 can communicate via direct communication direct wireless link 110, regardless of whether the two STA 104 are associated with and served by the same AP 102. In such ad hoc systems, one or more STA 104 can assume the role played by AP 102 in the BSS. Such STA 104 can coordinate transmissions within the ad hoc network. Examples of direct wireless link 110 include Wi-Fi Direct connections, connections established using Wi-Fi Tunneled Direct Link Setup (TDLS) links, and / or any other known or to be developed direct wireless communication schemes.
[0043] AP 102 and STA 104 can operate and communicate according to the IEEE 802.11 wireless communication protocol family (via the corresponding communication link 106). AP 102 and STA 104 in WLAN 100 can transmit PPDUs on unlicensed spectrum, which may include frequency bands used by Wi-Fi technology, such as the 2.4 GHz band, 5 GHz band, 60 GHz band, 3.6 GHz band, and 900 MHz band. Some implementations of AP 102 and STA 104 described herein can also communicate in other frequency bands (e.g., the 6 GHz band), which can support both licensed and unlicensed communication. AP 102 and STA 104 can also be configured to communicate on other frequency bands (e.g., shared licensed frequency bands), where multiple operators may have licenses to operate in one or more of the same or overlapping frequency bands.
[0044] Each frequency band can include multiple sub-bands or frequency channels. For example, PPDUs conforming to the IEEE 802.11n, 802.11ac, 802.11ax, and 802.11be standard amendments can be transmitted in 2.4 GHz, 5 GHz, or 6 GHz bands, each of which can be divided into multiple 20 MHz channels. PPDUs can be transmitted on physical channels with a minimum bandwidth of 20 MHz, or on larger channels with bandwidths of 40 MHz, 80 MHz, 160 MHz, or 320 MHz, which can be formed by bundling multiple 20 MHz channels together.
[0045] Each PPDU is a composite structure comprising a PHY preamble and a payload in the form of a PHY Service Data Unit (PSDU). The receiving device can use the information provided in the preamble to decode subsequent data in the PSDU. When the PPDU is transmitted over bonded channels, the preamble field can be copied and transmitted in each of the multiple component channels. The PHY preamble can include a traditional portion (or "traditional preamble") and a non-traditional portion (or "non-traditional preamble"). The traditional preamble can be used for purposes such as packet detection, automatic gain control, and channel estimation. The traditional preamble is also typically used to maintain compatibility with legacy equipment. The format, encoding, and information provided in the non-traditional portion of the preamble are based on the specific IEEE 802.11 protocol used for transmitting the payload.
[0046] Figure 2A This is a network diagram illustrating an example network environment for multi-link operation according to some aspects of the present technology. The wireless network 200 may include one or more STAs 204 (including example devices 208, 210, and 212) and one or more APs 202, which can communicate according to the IEEE 802.11 communication standard. The STAs 204 and APs 202 can respectively communicate with… Figure 1 The STA104 and AP 102 are the same.
[0047] One or more STA 204 and / or AP 202 can be operated by one or more users 206.
[0048] STA 204 and / or AP 202 may also include, for example, mesh stations in a mesh network according to one or more IEEE 802.11 and / or 3GPP standards.
[0049] Either STA 204 and AP 202 can be configured to communicate with each other via one or more communication networks 214 and / or network 216, which may be the same as WLAN 100. STA 204 can also communicate peer-to-peer or directly with or without AP 202. Either communication network 214 and / or network 216 may include, but is not limited to, any or a combination of suitable communication networks of different types, such as broadcast networks, wired networks, public networks (e.g., the Internet), private networks, wireless networks, cellular networks, or any other suitable private and / or public networks. Furthermore, either communication network 214 and / or network 216 may have any suitable communication range associated with it and may include, for example, a global network (e.g., the Internet), a metropolitan area network (MAN), a wide area network (WAN), a local area network (LAN), or a personal area network (PAN). Furthermore, either communication network 214 and / or network 216 may include any type of medium capable of carrying network services, including but not limited to coaxial cable, twisted pair, optical fiber, hybrid fiber-coaxial (HFC) medium, microwave terrestrial transceiver, radio frequency communication medium, space communication medium, ultra-high frequency communication medium, satellite communication medium, or any combination thereof.
[0050] Either STA 204 or AP 202 can be configured to perform directional transmission and / or directional reception in conjunction with wireless communication in a wireless network. Either STA 204 or AP 202 can be configured to use a collection of multiple antenna arrays (e.g., a DMG antenna array, etc.) to perform such directional transmission and / or reception. Each of the multiple antenna arrays can be used to transmit and / or receive in a specific corresponding direction or directional range. Either STA 204 or AP 202 can be configured to perform any given directional transmission to one or more defined transmit sectors. Either STA 204 or AP 202 can be configured to perform any given directional reception from one or more defined receive sectors.
[0051] Multiple-input multiple-output (MIMO) beamforming in a wireless network can be implemented using RF beamforming and / or digital beamforming. In some embodiments, when performing a given MIMO transmission, STA 204 and / or AP 202 can be configured to perform MIMO beamforming using all or a subset of their one or more communication antennas.
[0052] Either STA 204 and AP 202 may include any suitable radio device and / or transceiver for transmitting and / or receiving radio frequency (RF) signals in a bandwidth and / or channel corresponding to the communication protocol used by either STA 204 or AP 202 for communicating with each other. The radio components may include hardware and / or software to modulate and / or demodulate the communication signals according to a pre-established transmission protocol. The radio components may also have hardware and / or software instructions for communicating via one or more Wi-Fi and / or Wi-Fi Direct protocols, such as the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard. In an example embodiment, the radio component, in conjunction with a communication antenna, can be configured to communicate via a 2.4 GHz channel (e.g., 802.11b, 802.11g, 802.11n, 802.11ax), a 5 GHz channel (e.g., 802.11n, 802.11ac, 802.11ax), a 60 GHz channel (e.g., 802.11ad, 802.11ay), or an 800 MHz channel (e.g., 802.11ah). The communication antenna can operate at frequencies of 28 GHz and 40 GHz. It should be understood that this list of communication channels according to certain 802.11 standards is only a partial list, and other 802.11 standards (e.g., next-generation Wi-Fi or other standards) may also be used. In some embodiments, non-Wi-Fi protocols may be used for communication between devices, such as Bluetooth, Dedicated Short Range Communication (DSRC), Ultra High Frequency (UHF) (e.g., IEEE 802.11af, IEEE 802.22), unused frequency bands (e.g., unused space), or other packet radio communications. Radio components may include any known receiver and baseband suitable for communication via a communication protocol. Radio components may also include low-noise amplifiers (LNAs), additional signal amplifiers, analog-to-digital (A / D) converters, one or more buffers, and a digital baseband.
[0053] In some examples, reference Figure 2A AP 102 can facilitate multi-link operation 218 with one or more STAs 204.
[0054] In one example, multilink operation 218 can enable a single radio device non-access point MLD (non-AP MLD, such as STA 204) to simultaneously listen to two or more channels by: (1) configuring a 2×2 Tx / Rx (or M×M Tx / Rx) to allocate 1×1 resources on each channel / band (e.g., 5 GHz and 6 GHz); (2) adding an additional Rx module; or (3) adding a wake-up receiver. The AP MLD then transmits a control frame (e.g., Request to Send (RTS) or Multi-User (MU) RTS) on any idle channel before a set of data frames within a single data frame or a single transmission opportunity (TXOP) to indicate that a frame will be transmitted on that channel. The non-AP MLD responds with a control frame (e.g., Allow to Send (CTS)). The single radio device non-AP MLD configures its radio device back to the 2×2 Tx / Rx module on the channel on which it receives the control frame from the AP MLD and receives data. When using a wake-up receiver (802.11ba), the AP MLD sends a wake-up packet. This can also be extended to other architectures with different antenna configurations. As an example, consider a 3×3 device, in which one channel has 2×2 resources and the other channel has 1×1 resources.
[0055] In one example, multi-link operation 218 enables a single radio-device non-AP MLD to achieve increased throughput and reduced latency in a busy network without the need for concurrent dual radio devices, thus significantly reducing equipment costs.
[0056] Figure 2B An illustrative diagram depicts a multi-link operation between two logical entities according to one or more exemplary embodiments of the present technology.
[0057] refer to Figure 2B The diagram illustrates two multi-link logical entities, 220 and 222, which can establish communication links 224, 226, and 228 with each other. Multi-link logical entities 220 or 222 can be logical entities containing one or more STAs (e.g., STA 204). Each logical entity has a MAC data service interface and a primitive to the logical link control (LLC), as well as a single address associated with that interface, which can be used for communication on the distribution system medium (DSM). It should be noted that multi-link logical entities allow STAs within a multi-link logical entity to have the same MAC address. It should also be noted that the exact names can be changed.
[0058] exist Figure 2BIn the example, multi-link logical entities 220 and 222 can be two separate physical devices, each comprising multiple virtual or logical devices. For example, multi-link logical entity 220 may include three STAs, such as STAs 208, 210, and 212. Multi-link logical entity 222 may include three additional STAs (e.g., STAs 230, 232, and 234). In one example, STA 208 can communicate with STA 230 via link 224, STA 210 can communicate with STA 232 via link 226, and STA 212 can communicate with STA 234 via link 228.
[0059] Figure 2C An illustrative diagram depicts multi-link operation between an AP with logical entities and a non-AP with logical entities, according to some aspects of this technology.
[0060] refer to Figure 2C The diagram illustrates two multi-link logical entities, 236 and 238. AP logical entity 236 may include physical and / or logical APs 240, 242, and 244 operating in different frequency bands (e.g., 2.4 GHz, 5 GHz, and 6 GHz). APs 240, 242, and 244 may be identical to AP 102 and / or any of AP 202 described above. Non-AP logical entity 238 may include STAs 246, STA 248, and STA 250, which may be identical or similar to STAs 208, 210, 212, 230, 232, and / or 234.
[0061] AP 240 can communicate with STA 246 via link 252. AP 242 can communicate with STA 248 via link 254. AP 244 can communicate with STA 250 via link 256.
[0062] Figure 2C The diagram shows that a multi-link AP logical entity 236 can access a distribution system (DS) 258, which is a system for interconnecting a group of BSSs to create an extended service set (ESS). Figure 2C The diagram also shows that the multi-link AP logical entity 236 can access the distribution system medium (DSM) 260, which is the medium used by the DS for BSS interconnection. In short, the DS and DSM allow the AP to communicate with different BSSs.
[0063] It should be understood that although this example shows three logical entities within a multi-link AP logical entity and three logical entities within a multi-link non-AP logical entity, this is for illustrative purposes only, and it is conceivable that each multi-link AP and non-AP logical entity includes other numbers of logical entities.
[0064] Figure 3 The illustrations depict example routines for facilitating rapid transitions of a STA from roaming to a second Wi-Fi AP, based on aspects of the present technology, where the Wi-Fi APs utilize different security protocols. While the example routines depict a specific sequence of operations, this sequence can be changed without departing from the scope of this disclosure. For example, some of the depicted operations may be performed in parallel or in a different order without materially affecting the functionality of the routines. In other examples, different components of the example device or system implementing the routines may perform functions substantially simultaneously or in a specific order.
[0065] The disclosed technology addresses the need in the art for efficient reassociation of a STA from a first Wi-Fi AP to a second Wi-Fi AP, where each Wi-Fi AP utilizes a different security protocol. For example, Wi-Fi APs using Wi-Fi 5 / 6 technology use WPA-2, while newer generation Wi-Fi APs using Wi-Fi 7 / 8 technology use the WPA-3 security protocol. WPA-2 and WPA-3 use different MKA versions and cipher suites. This technology allows for efficient reassociation of a STA to a second Wi-Fi AP that uses a different key and key exchange mechanism than the first Wi-Fi AP, without requiring the initiation of a key exchange protocol. The disclosed technology is applicable whether the STA is roaming from a WPA-2 Wi-Fi AP to a WPA-3 Wi-Fi AP, or vice versa.
[0066] In Figure 4A and Figure 4B as well as Figure 5A and Figure 5B Discuss in the context Figure 3 , Figure 4A and Figure 4B The diagram illustrates a STA roaming from a WPA-2 Wi-Fi access point to a WPA-3 Wi-Fi access point. Figure 5A and Figure 5B The illustration shows a STA roaming from a Wi-Fi AP using WPA-3 to a Wi-Fi AP using WPA-2. Figure 3 The actions that occurred in Figure 4A and Figure 4B as well as Figure 5A and Figure 5B The embodiments shown are general; however, some details differ between the embodiments, which will be the focus of this document.
[0067] Throughout this disclosure, the term "Extremely High Throughput (EHT) STA" is mentioned. This means that the STA is capable of communicating with Wi-Fi 7 / 8 access points that can achieve throughput speeds of 30 Gbps (and potentially higher in future technologies). It is not strictly required that the STA possess extremely high throughput (EHT) capabilities to utilize this technology, although most commonly, if the STA can connect to a Wi-Fi 7 / 8 access point, it will be capable of extremely high throughput (EHT). Therefore, the reference to STAs with extremely high throughput (EHT) capabilities is illustrative rather than demanding.
[0068] Figure 4B Start by connecting STA 406 to the first Wi-Fi AP 402. Figure 4A and Figure 4B The first Wi-Fi AP402 is a Wi-Fi 5 / 6 AP that utilizes the WPA-2 security protocol. For example... Figure 4B As shown, in Wi-Fi 5 / 6, the STA 406 executes a probe request, announcing the key management methods and cipher suites it supports. When the STA 406 wants to join a Wi-Fi network, it sends a probe request frame to discover nearby available access points (APs). These probe request frames contain information about the client device and its capabilities. For security, the client device can include an RSNE element in the probe request frame to indicate its support for specific security protocols. The RSNE element carries information related to security capabilities, such as the security protocols, encryption algorithms, key management methods, and other security-related parameters supported by the STA 406. These steps are... Figure 5B It did not happen in China.
[0069] According to some examples, the method includes receiving information related to the security protocols supported by the network at block 302. For example, in Figure 4B and Figure 5B Of the two, STA 406 / STA 506 can receive information related to the security protocols supported by the network. In this communication, the first Wi-Fi AP 402 / first Wi-Fi AP 504 learns about the security protocols available to the Wi-Fi APs in the Extended Service Set (ESS). In other words, the STA learns that the network supports multiple Wi-Fi technologies and related security protocols.
[0070] According to some examples, the method includes notifying the Wi-Fi network STA of the need for roaming support in the association request at block 304, which includes Wi-Fi APs supporting WPA-2 and WPA-3 security protocols. For example, in Figure 4B and Figure 5BOf the two, STA 406 / STA 506 can notify the wireless controller 408 / wireless controller 508 through communication with the first Wi-Fi AP 402 / first Wi-Fi AP 504 that the STA requires roaming support, which includes Wi-Fi APs that support WPA-2 and WPA-3 security protocols in the Basic Services Set (BSS) query.
[0071] According to some examples, the method includes establishing a connection with a first Wi-Fi AP at block 306 and communicating with the first Wi-Fi AP using a message protected by a first security protocol. For example, in Figure 4B and Figure 5B Of the two, STA406 / STA 506 can establish a connection with the first Wi-Fi AP to communicate with it using messages protected by a first security protocol. To facilitate connection establishment, [the following occurs]. Figure 4B and Figure 5B Various steps are not shown. These steps may differ in Wi-Fi 5 / 6 and Wi-Fi 7 / 8 standards. For example, in Wi-Fi 5 / 6 utilizing WPA-2, the STA and AP perform a 4-way handshake to exchange and export security keys as part of Association and Key Management (AKM) 8.
[0072] Once the STA determines it is ready to roam to another Wi-Fi AP, it can initiate the roaming process. According to some examples, this method includes requesting a candidate Wi-Fi AP to connect to while the STA roams by performing a BSS translation query at block 308. For example, in Figure 4B and Figure 5B Of the two, STA 406 / STA 506 can request candidate Wi-Fi APs to connect to when the STA is roaming.
[0073] Wireless controller 408 / 508 can determine that STA 406 / 506 supports WPA-2 and WPA-3 security protocols (as conveyed at block 304). Therefore, wireless controller 408 / 508 can identify candidate APs in the Extended Service Set (ESS) that support the technologies that the STA can connect to, and can share the BSS information of each candidate AP as well as the association and key management (AKM) versions and cipher suites supported by the identified candidate APs.
[0074] According to some examples, the method includes receiving the identifier of a second Wi-Fi AP utilizing a second security protocol at block 310. For example, in Figure 4B and Figure 5BOf the two, STA 406 / STA 506 can receive the identifier of a second Wi-Fi AP utilizing a second security protocol.
[0075] The second security protocol differs from the first security protocol. The first security protocol includes a first AKM version and a first cipher suite, while the second security protocol utilizes a second AKM version and a second cipher suite.
[0076] More specifically, in Figure 4A and Figure 4B In the illustrated embodiment, the first security protocol is WPA-2, and the first AKM version and the first cipher suite conform to the WPA-2 security protocol. WPA-2 supports AKM version 8 and AES-128CCMP encryption. The second security protocol is WPA-3, and the second AKM version and the second cipher suite conform to the WPA-3 security protocol. WPA-3 supports AKM versions 8 and 24 and AES-256GCMP encryption.
[0077] exist Figure 5A and Figure 5B In the illustrated embodiment, the first security protocol is WPA-3, and the first AKM version and the first cipher suite conform to the WPA-3 security protocol. The second security protocol is WPA-2, and the second AKM version and the second cipher suite conform to the WPA-2 security protocol.
[0078] In some embodiments, the STA can receive information relating to a plurality of Wi-Fi APs, including a second Wi-Fi AP. In such embodiments, the STA or WLC can determine which of the plurality of Wi-Fi APs will be selected as the second Wi-Fi AP.
[0079] This technology considers at least two embodiments for determining the transition to a second Wi-Fi AP. These embodiments are not mutually exclusive, although they may be redundant in some aspects.
[0080] In some embodiments, the method includes deriving a key for association with a second Wi-Fi AP using a second AKM version at block 312. For example, in Figure 4B and Figure 5B Of the two, STA 406 / STA 506 can use a second AKM version to derive the key used for association with a second Wi-Fi AP. The method also includes determining the transition to the second Wi-Fi AP at block 314. For example, in Figure 4B and Figure 5BOf the two, STA 406 / STA 506 can determine whether to switch to the second Wi-Fi AP. The method also includes communicating with the first Wi-Fi AP in the BSS switch response at block 316, notifying the first Wi-Fi AP that the STA will switch to the second Wi-Fi AP. For example, in Figure 4B and Figure 5B Of the two, STA 406 / STA 506 can communicate with the first Wi-Fi AP in the BSS switching response to notify the first Wi-Fi AP that the STA will switch to the second Wi-Fi AP.
[0081] In some embodiments, the method includes receiving, at block 318, an action frame specifying a second Wi-Fi AP as the target to which the STA will switch. For example, in Figure 4B and Figure 5B In both cases, STA 406 / STA 506 can receive an action frame from the first Wi-Fi AP 402 / 504, specifying the second Wi-Fi AP as the target to which the STA intends to switch. The action frame is then modified to notify the STA to prepare the keys (Paired Master Key (PMK), Paired Transient Key (PTK)) required to establish a secure connection with the second Wi-Fi AP 404 / 502. This exchange may require negotiating the Association and Key Management (AKM) and cipher suites supported by the second Wi-Fi AP 404 / 502.
[0082] According to some examples, the method includes using a second security protocol at block 322 to re-associate with a second Wi-Fi AP using a fast transition. For example, in Figure 4B and Figure 5B Of the two, the STA 406 / STA 506 can use a second security protocol to re-associate with a second Wi-Fi AP using fast switching. Since the STA 406 / STA 506 has exported a new key and is ready to process communications using the correct cipher suite, the STA 406 / STA 506 is able to support fast switching within an Extended Service Set (ESS).
[0083] Fast Switching (FT) is a mechanism in Wi-Fi networks that allows STAs to roam quickly and seamlessly between access points (APs) without needing to re-authenticate.
[0084] like Figure 4B and Figure 5BAs shown, STA 406 / STA 506 sends a Fast Switching Request (FT Reassociation Request) frame to the second Wi-Fi AP 404 / Second Wi-Fi AP 502, indicating its roaming intention. The FT request includes information such as the client's identity and Pair Master Key (PMK) identifier (PMKID). The second Wi-Fi AP 404 / Second Wi-Fi AP 502, which previously cached the Pair Master Key (PMK), can use the stored Pair Master Key to quickly establish a secure connection with the client. The second Wi-Fi AP 404 / Second Wi-Fi AP 502 responds to the FT request with a Fast Switching Response (FT Reassociation Response) frame. This frame contains the information required by STA 406 / STA 506 and the second Wi-Fi AP 404 / Second Wi-Fi AP 502 to verify the authenticity of the connection and session key (derived at block 312).
[0085] Therefore, this technology allows STAs to efficiently reassociate from a first Wi-Fi AP to a second Wi-Fi AP, where each Wi-Fi AP utilizes a different security protocol. Due to differences in association and key management (AKM) protocols and cipher suites between generations of Wi-Fi technologies, STAs typically cannot utilize the fast conversion process. However, because this technology allows STAs to pre-export security keys, they can perform a fast conversion and efficiently roam to Wi-Fi APs utilizing different versions of association and key management (AKM).
[0086] Figure 6 An example of a computing system 600 is shown. The computing system 600 can be any computing device, such as constituting an AP, STA, or WLC, or any component thereof, wherein the components of the system communicate with each other using connection 602. Connection 602 can be a physical connection via a bus, or a direct connection to processor 604, such as in a chipset architecture. Connection 602 can also be a virtual connection, a network connection, or a logical connection.
[0087] In some embodiments, the computing system 600 is a distributed system, wherein the functions described herein may be distributed across a data center, multiple data centers, a peer-to-peer network, etc. In some embodiments, one or more of the described system components represent a plurality of such components, each performing some or all of the functions described for that component. In some embodiments, a component may be a physical device or a virtual device.
[0088] Example computing system 600 includes at least one processing unit (CPU or processor) 604 and a connection 602 that couples various system components, including system memory 608, such as read-only memory (ROM) 610 and random access memory (RAM) 612, to processor 604. Computing system 600 may include a cache 606 of high-speed memory that is directly connected to, adjacent to, or integrated as part of processor 604.
[0089] Processor 604 may include any general-purpose processor and hardware or software services configured to control processor 604 (e.g., services 616, 618, and 620 stored in storage device 614), as well as dedicated processors that incorporate software instructions into the actual processor design. Processor 604 may essentially be a completely independent computing system, containing multiple cores or processors, buses, memory controllers, caches, etc. Multi-core processors may be symmetric or asymmetric.
[0090] To enable user interaction, the computing system 600 includes an input device 626, which can represent any number of input mechanisms, such as a microphone for voice, a touchscreen for gesture or graphical input, a keyboard, a mouse, motion input, voice, etc. The computing system 600 may also include an output device 622, which can be one or more of many output mechanisms known to those skilled in the art. In some cases, a multimodal system can enable the user to provide multiple types of input / output to communicate with the computing system 600. The computing system 600 may include a communication interface 624, which typically controls and manages user input and system output. There are no limitations on operation on any particular hardware arrangement; therefore, as hardware or firmware arrangements evolve, the basic features described here can be easily replaced by improved hardware or firmware arrangements.
[0091] Storage device 614 may be a non-volatile memory device and may be a hard disk or other type of computer-readable medium that can store computer-accessible data, such as magnetic tape, flash memory card, solid-state memory device, digital multifunction disk, tape cartridge, random access memory (RAM), read-only memory (ROM) and / or some combination of these devices.
[0092] Storage device 614 may include software services, servers, etc., which cause the system to perform a function when the code defining such software is executed by processor 604. In some embodiments, hardware services that perform a particular function may include software components stored in a computer-readable medium in association with the necessary hardware components for performing that function (e.g., processor 604, connection 602, output device 622, etc.).
[0093] For clarity, in some cases, this technology may be presented as comprising individual functional blocks, including functional blocks having the following: devices, device components, steps or routines in methods embodied in software, or combinations of hardware and software.
[0094] Any steps, operations, functions, or processes described herein may be performed or implemented by a combination of one or more hardware and software services (alone or in combination with other devices). In some embodiments, a service may be software residing in the memory of one or more servers of a client device and / or a content management system, and performing one or more functions when a processor executes the software associated with the service. In some embodiments, a service is a program or collection of programs that performs a specific function. In some embodiments, a service may be considered a server. The memory may be a non-transitory computer-readable medium.
[0095] In some embodiments, computer-readable storage devices, media, and memories may include cables or wireless signals containing bit streams, etc. However, when referring to non-transitory computer-readable storage media, media such as energy, carrier signals, electromagnetic waves, and the signals themselves are explicitly excluded.
[0096] The methods described in the examples above can be implemented using computer-executable instructions stored in or otherwise accessible from a computer-readable medium. For example, such instructions may include instructions and data that cause or otherwise configure a general-purpose computer, special-purpose computer, or special-purpose processing device to perform certain functions or a set of functions. Some of the computer resources used may be accessible via a network. The computer-executable instructions may be, for example, binary files, intermediate format instructions (e.g., assembly language), firmware, or source code. Examples of computer-readable media that can be used to store the instructions, information, and / or information created during the methods according to the examples include disks or optical discs, solid-state storage devices, flash memory, USB devices equipped with non-volatile memory, network storage devices, and the like.
[0097] Devices implementing the methods according to these disclosures may include hardware, firmware, and / or software, and may take on any of a variety of form factors. Typical examples of such form factors include servers, laptops, smartphones, minicomputers, personal digital assistants, and so on. The functionality described herein may also be embodied in peripheral devices or add-in cards. By further example, such functionality may also be implemented on a circuit board between different chips or different processes executing in a single device.
[0098] Instructions, the medium for transmitting such instructions, the computing resources for executing the instructions, and other structures for supporting such computing resources are means of providing the functionality described in these disclosures.
[0099] While various examples and other information have been used to interpret aspects of the scope of the appended claims, no limitation on the claims should be implied based on specific features or arrangements in such examples, as those skilled in the art will be able to derive a wide variety of implementations from these examples. Furthermore, while certain topics may have been described using language specific to structural features and / or method steps, it should be understood that the topics defined in the appended claims are not necessarily limited to these described features or actions. For example, such functionality may be distributed in different ways or performed in components other than those identified herein. Rather, the described features and steps are disclosed as examples of components of systems and methods within the scope of the appended claims.
[0100] Some aspects of this technology include: Aspect 1. A method comprising: a STA communicating with a first Wi-Fi AP using a message protected by a first security protocol; requesting a candidate Wi-Fi AP to connect to while the STA is roaming; receiving an identifier of a second Wi-Fi AP using a second security protocol, wherein the second security protocol is different from the first security protocol; and using some aspects of the second security protocol to re-associate with the second Wi-Fi AP using a fast switching mechanism.
[0101] Aspect 2. The method of aspect 1 further includes: notifying the Wi-Fi network in an association request message that the STA requires roaming support, the roaming support including support for WPA-2 and WPA-3 security protocols.
[0102] Aspect 3. The method of any one of Aspects 1 to 2 further includes: sharing information related to the security protocols supported by the STA within the Wi-Fi network before handshaking with the first Wi-Fi AP; and establishing a connection with the first Wi-Fi AP.
[0103] Aspect 4. The method of any one of Aspects 1 to 3, wherein the first security protocol includes a first AKM version and a first cipher suite, and the second security protocol utilizes a second AKM version and a second cipher suite.
[0104] Aspect 5. The method of any one of Aspects 1 to 4 further includes: exporting a key for association with the second Wi-Fi AP using a second AKM version before re-associating with the second Wi-Fi AP.
[0105] Aspect 6. The method of any one of Aspects 1 to 5 further includes: determining a switch to the second Wi-Fi AP; and communicating with the first Wi-Fi AP in a BSS switch response to notify the first Wi-Fi AP that the STA will switch to the second Wi-Fi AP.
[0106] Aspect 7. The method of any one of Aspects 1 to 6 further includes: receiving an action frame specifying the second Wi-Fi AP as the target to be switched to.
[0107] Aspect 8. The method of any one of Aspects 1 to 7, wherein receiving the identifier of the second Wi-Fi AP utilizing the second security protocol includes receiving a plurality of Wi-Fi APs including the second Wi-Fi AP.
Claims
1. A method comprising: The STA communicates with the first Wi-Fi AP using messages protected by a first security protocol; Request candidate Wi-Fi APs to connect to while STA is roaming; Receive the identifier of a second Wi-Fi AP utilizing a second security protocol, wherein the second security protocol is different from the first security protocol; as well as Using some aspects of the second security protocol, a fast conversion is used to re-associate with the second Wi-Fi AP.
2. The method of claim 1, further comprising: The association request message notifies entities within the Wi-Fi network that the STA requires roaming support, which includes support for WPA-2 and WPA-3 security protocols.
3. The method of claim 1 or 2, further comprising: Before shaking hands with the first Wi-Fi AP, information related to the security protocols supported by the STA is shared within the Wi-Fi network; as well as Establish a connection with the first Wi-Fi AP.
4. The method as claimed in any of the preceding claims, wherein, The first security protocol includes a first AKM version and a first cipher suite, and the second security protocol utilizes a second AKM version and a second cipher suite.
5. The method according to any of the preceding claims, further comprising: Before re-associating with the second Wi-Fi AP, export the key for associating with the second Wi-Fi AP using the second AKM version.
6. The method according to any of the preceding claims, further comprising: Determine to switch to the second Wi-Fi AP; In the BSS transition response, the system communicates with the first Wi-Fi AP to notify the first Wi-Fi AP that the STA will transition to the second Wi-Fi AP.
7. The method according to any of the preceding claims, further comprising: Receive an action frame specifying the second Wi-Fi AP as the target to switch to.
8. The method as claimed in any of the preceding claims, wherein, Receiving the identifier of the second Wi-Fi AP utilizing the second security protocol includes receiving a plurality of Wi-Fi APs including the second Wi-Fi AP.
9. A computing device, comprising: processor; as well as A memory that stores instructions, which, when executed by the processor, configure the device to: The STA communicates with the first Wi-Fi AP using messages protected by a first security protocol; Request candidate Wi-Fi APs to connect to while STA is roaming; Receive the identifier of a second Wi-Fi AP utilizing a second security protocol, wherein the second security protocol is different from the first security protocol; as well as Using some aspects of the second security protocol, a fast conversion is used to re-associate with the second Wi-Fi AP.
10. The computing device of claim 9, wherein, The instructions also configure the device as follows: The association request message notifies entities within the Wi-Fi network that the STA requires roaming support, which includes support for WPA-2 and WPA-3 security protocols.
11. The computing device as claimed in claim 9 or 10, wherein, The instructions also configure the device as follows: Before handshaking with the first Wi-Fi AP, information related to the security protocols supported by the STA is shared within the Wi-Fi network; and Establish a connection with the first Wi-Fi AP.
12. The computing device according to any one of claims 9 to 11, wherein, The first security protocol includes a first AKM version and a first cipher suite, and the second security protocol utilizes a second AKM version and a second cipher suite.
13. The computing device according to any one of claims 9 to 12, wherein, The instructions also configure the device as follows: Before re-associating with the second Wi-Fi AP, export the key for associating with the second Wi-Fi AP using the second AKM version.
14. The computing device according to any one of claims 9 to 13, wherein, The instructions also configure the device as follows: Determine to switch to the second Wi-Fi AP; In the BSS transition response, the system communicates with the first Wi-Fi AP to notify the first Wi-Fi AP that the STA will transition to the second Wi-Fi AP.
15. The computing device according to any one of claims 9 to 14, wherein, The instructions also configure the device as follows: Receive an action frame specifying the second Wi-Fi AP as the target to switch to.
16. A non-transitory computer-readable storage medium, the computer-readable storage medium comprising instructions that, when executed by a computer, cause the computer to perform the following operations: The STA communicates with the first Wi-Fi AP using messages protected by a first security protocol; Request candidate Wi-Fi APs to connect to while STA is roaming; Receive the identifier of a second Wi-Fi AP utilizing a second security protocol, wherein the second security protocol is different from the first security protocol; as well as Using some aspects of the second security protocol, a fast conversion is used to re-associate with the second Wi-Fi AP.
17. The computer-readable storage medium of claim 16, wherein, The instructions also configure the computer to: The association request message notifies entities within the Wi-Fi network that the STA requires roaming support, which includes support for WPA-2 and WPA-3 security protocols.
18. The computer-readable storage medium as claimed in any one of claims 16 or 17, wherein, The instructions also configure the computer to: Before re-associating with the second Wi-Fi AP, export the key for associating with the second Wi-Fi AP using the second AKM version.
19. The computer-readable storage medium as claimed in any one of claims 16 to 18, wherein, The instructions also configure the computer to: Determine to switch to the second Wi-Fi AP; In the BSS transition response, the system communicates with the first Wi-Fi AP to notify the first Wi-Fi AP that the STA will transition to the second Wi-Fi AP.
20. The computer-readable storage medium as claimed in any one of claims 16 to 19, wherein, The instructions also configure the computer to: Receive an action frame specifying the second Wi-Fi AP as the target to switch to.