System, method and apparatus for association and authentication of multiple access point coordination

By generating and using the PMK between STA and the coordinated AP group, the seamless data exchange and frequent association authentication problems when STA coordinates with multiple APs are solved, and stable and efficient connections between STA and multiple APs are achieved.

CN112512041BActive Publication Date: 2025-05-16SAMSUNG ELECTRONICS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202010951760.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-07-30
Filing Date
2020-09-11
Publication Date
2025-05-16
Estimated Expiration
2040-09-11

AI Technical Summary

Technical Problem

The prior art is difficult to achieve seamless data exchange when workstations (STAs) coordinate with multiple access points (APs), and require frequent reassociation and authentication, resulting in large negotiation overhead.

Method used

By generating paired master keys (PMKs) between workstations (STAs) and coordination access point (APs) groups, and maintaining the association and authentication state between STAs and coordination AP groups based on PMKs, the STAs and multiple APs are enabled to simultaneously connect STAs and multiple APs.

Benefits of technology

It realizes seamless data exchange between STA and multiple APs, reducing the frequency of reassociation and authentication, reducing negotiation overhead, and improving the stability and efficiency of network connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112512041B_ABST
    Figure CN112512041B_ABST
Patent Text Reader

Abstract

A method for associating and authenticating a station (STA) with a coordinated access point (AP) group may include generating a pairwise master key (PMK) between the STA and a coordinator of the coordinated AP group, and maintaining the association and authentication status between the STA and the coordinated AP group based on the PMK.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to U.S. Provisional Patent Application Serial No. 62 / 900,206, filed on September 13, 2019, entitled “Virtual Basic Service Set (BSS) For Multi-Access Point (AP) Coordination,” and Serial No. 16 / 944,135, filed on July 30, 2020, entitled “System, Method, and Device for Association and Authentication for Multi Access Point Coordination,” which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates generally to multiple access point (AP) coordination, and more particularly to systems, methods, and devices for associating and authenticating multiple AP coordination. Background Art

[0004] A connection between a station (STA) and an AP may involve association and authentication of the STA and the AP. Coordination of multiple APs may involve association and authentication of the STA with multiple APs.

[0005] The above information disclosed in this Background section is only for enhancement of understanding of the background of the invention and therefore it may contain information that does not constitute prior art. Summary of the invention

[0006] A method for associating and authenticating a station (STA) with a coordinated access point (AP) group may include: generating a pairwise master key (PMK) between the STA and a coordinator of the coordinated AP group; and maintaining the association and authentication status between the STA and the coordinated AP group based on the PMK.

[0007] The method may also include generating one or more temporary keys between the STA and the coordinator based on the PMK. The method may also include performing a handshake between the STA and the coordinator through the member APs of the coordination AP group. The member APs of the coordination AP group may forward data frames between the STA and the coordinator. The method may also include performing a joint transmission between the STA and a first member AP and a second member AP of the coordination AP group. The method may also include performing a joint transmission between the STA and any number of member APs of the coordination AP group.

[0008] The method may also include distributing the PMK from the coordinator to a first member AP and a second member AP of the coordinated AP group. The method may also include: generating a first temporary key between the STA and the first member AP; and generating a second temporary key between the STA and the second member AP. Generating the first temporary key between the STA and the first member AP may include performing a first handshake between the STA and the first member AP; and generating the second temporary key between the STA and the second member AP may include performing a second handshake between the STA and the second member AP.

[0009] The coordinated AP group may be announced in one or more of a beacon, a probe response, or an association response. The method may also include: sending an association request from a STA to the coordinated AP group through a member AP of the coordinated AP group; and sending an association response from the coordinated AP group to the STA through the same member AP, wherein the association response may indicate a mode for authenticating the STA to the coordinated AP group. The association may include a coordinator key holder identifier (ID). The method may also include dynamically selecting at least one anchor AP for the STA from one or more member APs in the coordinated AP group. The STA and the coordinated access point (AP) group may form a virtual basic service set (V-BSS). The V-BSS may be announced using a V-BSS information element (VBIE) in a beacon frame.

[0010] A wireless station (STA) may include: a wireless transceiver; and a device controller configured to communicate with a coordinated access point (AP) group through the wireless transceiver, generate a pairwise master key (PMK) between the STA and the coordinator of the coordinated AP group, and maintain the association and authentication state between the STA and the coordinated AP based on the PMK. The device controller may also be configured to generate a temporary key between the STA and the coordinator of the coordinated AP group. The device controller may also be configured to generate a temporary key between the STA and the member AP of the coordinated AP group.

[0011] A wireless access point (AP) may include a wireless transceiver; and a device controller configured to communicate with a wireless station (STA) through the wireless transceiver, and maintain an association and authentication state between the STA and the coordinated AP group based on a PMK generated between the STA and the coordinated AP group. The device controller may also be configured to forward data frames between the STA and the coordinator of the coordinated AP group based on the authentication between the STA and the coordinator. The PMK may be a first PMK, and the device controller may also be configured to receive a second PMK from the coordinator of the coordinated AP group based on the first PMK, and generate a temporary key with the STA based on the second PMK. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] The drawings are not necessarily drawn to scale, and for illustrative purposes throughout the drawings, elements of similar structure or function are generally represented by the same reference numerals. The drawings are intended only to help describe the various embodiments disclosed herein. The drawings do not describe every aspect of the teachings disclosed herein and do not limit the scope of the claims. The drawings, together with the specification, illustrate example embodiments of the present disclosure and, together with the description, serve to explain the principles of the present disclosure.

[0013] Figure 1 An example embodiment of a virtual basic service set according to the present disclosure is shown.

[0014] Figure 2 An example embodiment of a virtual basic service set with more than one anchor access point according to the present disclosure is shown.

[0015] Figure 3 Another example embodiment of a virtual basic service set with more than one anchor access point according to the present disclosure is shown.

[0016] Figure 4 An example embodiment of a mobile domain infrastructure is shown.

[0017] Figure 5 is a sequence diagram illustrating an example embodiment of an association process for establishing a common association and authentication state according to the present disclosure.

[0018] Figure 6 Example embodiments of a coordinator and possible sources of master keys according to the present disclosure are shown.

[0019] Figure 7 is a sequence diagram illustrating an example embodiment of a coordinator-level authentication process for establishing a common association and authentication state according to the present disclosure.

[0020] Figure 8 is a sequence diagram illustrating an example embodiment of an AP-level authentication process for establishing a common association and authentication state according to the present disclosure.

[0021] Fig. 9 is a sequence diagram illustrating an example embodiment of coordinated data connectivity of a group of APs that have established a common association and authentication state in accordance with the present disclosure.

[0022] Fig.10 An example embodiment of a wireless workstation according to the present disclosure is shown.

[0023] Fig.11 An example embodiment of a wireless access point according to the present disclosure is shown.

[0024] Fig.12 An example embodiment of a method for associating and authenticating a STA with a coordinated AP group according to the present disclosure is shown. DETAILED DESCRIPTION

[0025] Overview

[0026] According to some embodiments of the present disclosure, association and / or authentication techniques may be implemented that enable a station (STA) to maintain simultaneous connections with multiple access points (APs) in a coordinated AP group. This may enable a STA to seamlessly exchange data frames with multiple APs without re-association and / or re-authentication. For example, simultaneous connections may be achieved by establishing and / or maintaining a common association and authentication state between a STA and the coordinated AP group. The coordinated AP group may be implemented, for example, as a virtual basic service set (V-BSS).

[0027] In some embodiments according to the present disclosure, establishing a common association and authentication state may involve first establishing a security association between the STA and the coordinated AP group, and then performing authentication between the STA and the coordinated AP group.

[0028] In one authentication mode according to the present disclosure, a STA may be authenticated at the coordinator level by generating a temporary key with the coordinator based on a pairwise master key (PMK). In such an embodiment, the coordinator may perform partial or full data encryption and decryption, and the member AP may act as a relay to forward data frames between the STA and the coordinator.

[0029] In another authentication mode according to the present disclosure, the STA may be authenticated at the AP level. In such an embodiment, the coordinator may derive one or more AP-level pairwise master keys (PMK-AP) based on the coordinator-level PMK (PMK-coordinator), and distribute the PMK-AP to one or more member APs in the coordination AP group. The STA may then be authenticated by generating a temporary key based on the PMK-AP with one or more of the member APs. In such an embodiment, encryption and decryption may be performed, for example, by the member AP using a temporary key generated between the member AP and the STA.

[0030] In some embodiments, once a common association and authentication state is established between a STA and the coordinated AP group, the STA can maintain connections with multiple APs in the group. This can enable the STA to roam freely and select different APs to exchange data frames with, while reducing or eliminating the overhead associated with re-association and / or re-authentication for switching between different APs.

[0031] Multi-AP coordination

[0032] Multi-AP coordination may enable some embodiments to provide seamless exchange of data frames between a STA and multiple coordinated APs. Multi-AP coordination may be implemented using one or more coordination techniques, such as joint processing and / or transmission, coordinated orthogonal frequency division multiple access (OFDMA), null steering beamforming, coordinated beamforming, AP selection, and / or the like. In some embodiments, one or more APs used for uplink (UL) and / or downlink (DL) transmissions may vary on a per-frame basis based on, for example, link quality, load balancing, and the like.

[0033] In some embodiments, multi-AP coordination may involve seamless exchange of frames between STAs and coordinating APs without negotiation overhead. This may be achieved, for example, by providing simultaneous connections between STAs and multiple APs.

[0034] Multi-AP coordination may also involve one or more secure connections between a STA and a coordinated AP. In some embodiments, this may be achieved, for example, using common authentication and association status. In some embodiments, one or more secure connections may be achieved using different encryption for different multi-AP coordination techniques.

[0035] Virtual Basic Service Set

[0036] In some embodiments, multi-AP coordination can be implemented using a virtual basic service set (V-BSS), which can include, for example, an infrastructure BSS with a coordinated AP group.

[0037] Figure 1 An example embodiment of a V-BSS according to the present disclosure is shown. Figure 1 In the illustrated V-BSS 100, the coordination AP group may include a coordinator 108, a first member AP 104, and a second member AP 106. In some embodiments, the member APs 104 and 106 may share the same service set identifier (SSID) and / or the same basic service set identifier (BSSID). The member APs 104 and 106 may also share association and / or authentication with the STA 102, so that when the STA 102 roams within the virtual BSS 100, re-association and / or re-authentication may not be involved. In some embodiments, the coordinator 108 may be implemented as a separate component, while in other embodiments, it may be integrated with one or more of the member APs 104 and 106.

[0038] In some embodiments, STA 102 may use the same association identifier (AID) in V-BSS 100. For example, after being assigned an AID by coordinator 108, it may be assigned to all APs in the coordinated AP group (e.g., Figure 1The AID is shared between the first member AP 104 and the second member AP 106 shown in FIG.

[0039] In some embodiments, STA 102 may select an anchor AP from the member APs based on link quality metrics, such as received signal strength indication (RSSI). STA 102 may retain a local copy of the capabilities of the anchor AP and / or neighboring member APs of the coordinated AP group. STA 102 may obtain link quality metrics for each link between STA 102 and a member AP, which may be obtained, for example, by measurements at STA 102 (e.g., RSSI) or from information received from a member AP, such as the channel capacity of the member AP to the coordinator, the capabilities of the member AP, and the number of STAs attached to the member AP. The member AP may send AP side link quality metric information (AP side link metric information) measured at the member AP to STA 102.

[0040] In some embodiments, anchor APs may be used to relay transmissions between STA 102 and coordinator 108. STA 102's association and / or authentication with at least one anchor AP may be shared with some or all APs in the coordinated AP group, which may allow STA 108 to utilize any subsequently selected anchor AP to relay transmissions without reauthentication.

[0041] Alternatively or additionally, in some embodiments, the coordinator 108 may select an anchor AP for the STA 102 based on, for example, a link quality metric. In other embodiments, a combination of STA driven AP selection and coordinator controlled AP selection may be implemented. For example, the STA 102 may select a first anchor AP for uplink (UL) transmissions, and the coordinator 108 may determine a second anchor AP for downlink (DL) transmissions.

[0042] Figure 2 An example embodiment of a V-BSS with more than one anchor AP according to the present disclosure is shown. Within V-BSS 200, UL traffic may flow from STA 202 to coordinator 208 via first member anchor AP 204. DL traffic may flow from coordinator 208 to STA 202 via second member anchor AP 206.

[0043] Figure 3Another example embodiment of a V-BSS with more than one anchor AP according to the present disclosure is shown. Within the V-BSS 300, DL traffic may flow from the coordinator 302 to the STA 308 via both the first member anchor AP 304 and the second member anchor AP 306. In some embodiments, joint transmission may be performed using the same time and / or frequency resources or using different time and frequency resources (e.g., time division multiplexing (TDM) and / or frequency division multiplexing (FDM)).

[0044] In some embodiments, the STA-driven AP selection scheme is used with multiple anchor APs, and the STA can use, for example, a new management frame to inform the coordinator of the list of anchor APs. In other embodiments, the coordinator-controlled AP selection scheme is used with multiple anchor APs, and the coordinator can select an anchor AP for DL ​​traffic for the STA, and the STA can select an anchor AP for UL transmission.

[0045] In some implementations, there may be more than one hop from the coordinator to the STA. In a coordinator-controlled AP selection scheme with a multi-hop path, the coordinator may select a path based on, for example, link quality metrics. In a STA-driven AP selection scheme, the coordinator may no longer be able to find the STA's anchor AP based on UL data packets. Therefore, after the STA selects or switches to a new anchor AP, the STA may use a management frame to inform the coordinator of its selected / updated anchor AP so that the coordinator can update the routing of DL traffic to the STA.

[0046] Mobile domains and quick conversions

[0047] In some embodiments, multi-AP coordination may be achieved using a mobility domain, which may involve a fast switching mechanism between APs, also known as fast BSS transition (FT).

[0048] Figure 4 An example embodiment of a mobile domain infrastructure is shown. The infrastructure 400 may include a wireless local area network (WLAN) controller 402, a first wireless AP 404, and a second wireless AP 406. The infrastructure 400 may implement a three-level FT key hierarchy, which may include: a level 1 pairwise master key (PMK-R0), which may be derived by the WLAN controller 402 from a master session key (MSK) generated by an IEEE 802.1X authentication mechanism, for example, with a STA being authenticated to the WLAN. Alternatively, PMK-R0 may be derived from other master key sources, such as a master PMK (MPMK) from simultaneous authentication of equals (SAE), or FILS-FT from fast initial link establishment (FILS) authentication. In some embodiments, PMK-R0 may be obtained directly from a pre-shared key (PSK).

[0049] The Level 2 pairwise master key (PMK-R1) may be derived from PMK-R0 by the WLAN controller 402 and distributed to the APs 404 and 406 in the mobility domain. For security authentication, the wireless APs 404 and 406 may then generate Level 3 pairwise transient keys by performing a four-way handshake with various STAs that may provide a valid PMK-R0 in an FT authentication request and / or FT action frame. This may enable the IEEE 802.1X authentication mechanism and / or the four-way handshake to be omitted when the STA transitions to a different AP. The mobility domain FT mechanism may implement a make-before-break approach, where the STA may complete authentication with the new (target) AP before disconnecting from the current AP.

[0050] However, because the mobile domain FT mechanism may not enable simultaneous connections between a STA and multiple APs, the STA may need to disassociate from the existing AP connection, associate with the new AP, and reestablish the protocol before a data frame exchange can be initiated with the new AP. The FT mechanism for this may involve four frame exchanges for the transition, which may result in significant negotiation overhead for AP transitions.

[0051] Co-association and certification status

[0052] In some embodiments according to the present disclosure, a STA may maintain simultaneous connections with more than one AP in a coordinated AP group by achieving a common or shared association and authentication state with the coordinated AP group.

[0053] A common association and authentication state in accordance with the present disclosure may take many different forms and may be established and / or maintained using many different association and / or authentication techniques.

[0054] For example, in some embodiments, the STA may perform an association with each AP in the coordinated AP group. In other embodiments, the association may initially be performed between the STA and a specific AP of the coordinated AP group, and the association may then be shared with other APs in the coordinated AP group, for example, by allocating an association identifier (AID) by the coordinator of the V-BSS and distributing it to all APs in the coordinated AP group of the V-BSS.

[0055] As another example, the STA may perform authentication with each AP in the coordinated AP group. However, in other embodiments, the STA may only perform authentication with the coordinator of the V-BSS, and the AP may then act as a relay to forward data packets between the STA and the coordinator.

[0056] Therefore, the common association and authentication state may not necessarily require association and authentication between the STA and each AP in the coordinated AP group, while still enabling the STA to maintain connectivity with each AP in the coordinated AP group. In addition, in some embodiments, maintaining the common association and authentication state can enable the STA to maintain connectivity with multiple APs in the coordinated AP group in a manner that can reduce or eliminate sources of delay (such as negotiation overhead) when the STA begins to exchange data with different APs.

[0057] The embodiments of the association and authentication techniques described above are only a few of the infinite number of different techniques that can be used to implement the common association and authentication states according to the present invention. For example, any of the association and / or authentication techniques described above and below can be implemented in a mixed combination thereof. As another example, the association and / or authentication techniques used for uplink transmissions between a STA and a coordinated AP group may be different from the association and / or authentication techniques used for downlink transmissions. In some implementations, a STA may establish and / or maintain uplink and downlink connections between different subsets of APs in a coordinated group. The association and / or authentication techniques used between a first STA and a coordinated AP group may be different from the association and / or authentication techniques used between a second STA and a coordinated AP group. In addition, different common association and authentication states may be established for different STAs, and the different STAs may form overlapping V-BSSs with one or more coordinated AP groups.

[0058] Some example embodiments of systems, processes, methods, features, techniques, and / or the like are described below that illustrate some possible implementation details of the present invention. These examples are provided to illustrate the principles of the present disclosure, but the principles are not limited to these implementation details. For example, some embodiments may be described in the context of a V-BSS, which may include a coordinated AP group with two member APs. However, the principles of the present invention are not limited to a V-BSS or any particular number of access points, and may be applied to multi-AP coordination of any type and / or arrangement.

[0059] Relationship

[0060] Figure 5 is a sequence diagram illustrating an example embodiment of an association process for establishing a common association and authentication state according to the present disclosure. Figure 6 An example embodiment of a coordinator and possible sources of master keys according to the present disclosure is shown. The V-BSS may be described in the context of a V-BSS including a STA 502 and a coordinating AP group. Figure 5 In the process shown in , the coordinating AP group includes V-BSS coordinator 508, first member AP 504 and second member AP 506.

[0061] At the beginning of the process, one or more APs, such as first member AP 504 and / or second member AP 506, may periodically broadcast beacon frames that may announce the V-BSS capabilities of the coordinated AP group. The capabilities may be indicated, for example, by including a virtual BSS information element (VBIE) in the beacon frame. At event E501, STA 502 may receive a beacon including a VBIE from first member AP 504. Additionally or alternatively, at event E502, STA 502 may receive a beacon including a VBIE from second member AP 506.

[0062] After the V-BSS capabilities of the coordinating AP group have been learned from either or both of the member APs 504 and 506, STA 502 may initiate a series of events to perform an association for establishing a common association and authentication state. At event E503, STA 502 may perform an IEEE 802.11 open system authentication with the first member AP 504. At event E504, STA 502 may send an association request to the first member AP 504, which may relay the association request to the coordinator 508 at event E505. The association request may include an indication in the VBIE that STA 502 is requesting to establish a common association and authentication state.

[0063] At event E506, coordinator 508 may respond by sending an association response to first member AP 504, which may be relayed to STA 502 at event E507. The association response may include information that may be used by STA 502 in subsequent authentication and / or key generation operations. The information may be provided in the form of a virtual BSS coordinator information element (VCIE), which may include, for example, a V-BSS coordinator identifier (V-BSS coordinator ID) and / or a mode indicator. In some embodiments, the V-BSS coordinator ID may be used as a key holder ID for the purpose of generating a pairwise master key (PMK). In some embodiments, the mode indicator may inform STA 502 of the authentication mode to be used during a subsequent authentication process, for example, for generating a temporary key.

[0064] At event E508, STA 502 may perform authentication, wherein a PMK between STA 502 and coordinator 508 may be generated. The PMK may be referred to as a PMK coordinator. In some embodiments, the PMK coordinator may be derived from a master session key MSK that may be generated through an IEEE 802.1X authentication process. In other embodiments, the PMK coordinator may be generated through a master session key MSK such as Figure 6The PMK coordinator may be generated by other processes shown. For example, the PMK may be derived from the Master PMK (MPMK) from Simultaneous Authentication of Equals (SAE) or from FILS-FT from Fast Initial Link Establishment (FILS). In some embodiments, the PMK may be obtained directly from the Pre-Shared Key (PSK), in which case the PMK generation at event E508 may be omitted.

[0065] exist Figure 5 In the illustrated embodiment, STA 502 and coordinator 508 may perform authentication through AP 504, but in other embodiments, STA 502 and coordinator 508 may perform authentication through different APs or through any other path. Figure 5 In the illustrated embodiment, the V-BSS capabilities of the coordinated AP group may be announced via a beacon frame. However, in other embodiments, the V-BSS capabilities of the coordinated AP group may be announced in other ways, such as via a probe response frame sent in response to a probe request frame broadcast by a STA, or via an association response frame sent in response to an association request frame.

[0066] Certification

[0067] In some embodiments, after a security association has been established between the STA and the coordinator (e.g., the association portion in the jointly associated and authenticated state), the STA may perform authentication, for example, to generate a temporary key for exchanging data with the coordinated AP group (e.g., the authentication portion in the jointly associated and authenticated state). The type of authentication performed may depend on a wide range of considerations, such as the capabilities of the coordinator in the V-BSS, the capabilities of the STA, the type and / or amount of data expected to be exchanged, the number and / or capabilities of the APs in the coordinated AP group, and / or other considerations that may be relevant to maintaining connectivity between the STA and the coordinated AP group in a manner that may reduce or eliminate sources of delay (e.g., negotiation overhead) when the STA begins to exchange data with different APs.

[0068] In some embodiments, authentication may be established and / or maintained in two modes: (1) a coordinator-level mode, in which authentication may be performed between a STA and a coordinator; and (2) an AP-level mode, in which authentication may be performed between a STA and one or more APs in a coordinated AP group. In other embodiments, only one mode may be implemented, other or additional modes may be implemented, and / or a hybrid combination of modes may be implemented.

[0069] Figure 7 is a sequence diagram illustrating an example embodiment of a coordinator-level authentication process for establishing a common association and authentication state according to the present disclosure. Figure 5 The association process shown in FIG. 1 may be described in the context of a V-BSS including STA 702 and a coordinated AP group. Figure 7 In the illustrated authentication process 700 , the coordination AP group includes a V-BSS coordinator 708 , a first member AP 704 , and a second member AP 706 .

[0070] The authentication process may begin at event E701, where STA 702 may send an association request including a VBIE to first member AP 704, which may be forwarded to coordinator 708 at event E702. The VBIE may include an indication that STA 702 is requesting to establish a common association and authentication state with the coordinating AP group. The process may then proceed in a manner similar to Figure 5 Events E703 to E705 continue in the manner of events E506 to E508 in order to generate a PMK coordinator between STA 702 and coordinator 708 .

[0071] At event E706, STA 702 may perform a four-way (e.g., four-frame) handshake, where a PMK coordinator may be used to generate a pairwise transient key (PTK) and a group transient key (GTK) between STA 702 and coordinator 708. In an embodiment based on IEEE 802.1X authentication, the four-way handshake may result in unlocking of one or more IEEE 802.1X controlled ports. The PTK and GTK may then be used for encrypted data transmission starting at event E707.

[0072] In some embodiments with coordinator-level authentication according to the present disclosure, the coordinator 708 may be responsible for coordinating all or a relatively large portion of the data processing and / or security management of the AP group. For example, in some embodiments, the coordinator 708 may perform substantially all encryption and / or decryption. Thus, the member APs 704 and 706 may act as relays that may forward frames between the STA 702 and the coordinator 708. In some embodiments, joint transmissions from APs in the coordinated AP group may be achieved using coordinator-level authentication.

[0073] Some embodiments implementing coordinator-level authentication according to the present disclosure may be used with a variety of multi-AP coordination techniques, such as coordinated OFDMA, coordinated beamforming, nulling, joint AP transmission, and / or the like.

[0074] Figure 8 is a sequence diagram illustrating an example embodiment of an AP-level authentication process for establishing a common association and authentication state according to the present disclosure. Figure 5 and Figure 7 The association / authentication process shown in FIG. 1 may be described in the context of a V-BSS including STA 802 and a coordinated AP group. Figure 8In the authentication process 800 shown in FIG. 8 , the coordination AP group includes a V-BSS coordinator 808 , a first member AP 804 , and a second member AP 806 .

[0075] The process may begin at event E801, STA 802 may send an association request including VBIE to first member AP 804, and the association request may be forwarded to coordinator 808 at event E802. The process may then proceed in a manner similar to Figure 7 Events E803 to E805 are performed in the manner of events E703 to E705 in STA 802 to generate a PMK coordinator between STA 802 and coordinator 808.

[0076] At events E806 and E807, coordinator 808 may derive an AP-level pairwise master key (PMK-AP) from the PMK coordinator and distribute them to AP 804 and AP 806. At event E808, STA 802 may perform a first four-way handshake with first AP 804. During the performance of the first handshake, a first pairwise transient key (PTK1) and a first group transient key (GTK1) between STA 802 and first member AP 804 may be generated using PMK-AP distributed to first member AP 804. At event E809, STA 802 may perform a second four-way handshake with second member AP 806. During the performance of the second handshake, a second pairwise transient key (PTK2) and a second group transient key (GTK2) between STA 802 and second member AP 806 may be generated using PMK-AP distributed to second member AP 806. The PTKs, ie, PTK1 and PTK2, and the GTKs, ie, GTK1 and GTK2, may then be used to encrypt data transmissions.Thus, in some embodiments, separate keys maintained for each member AP and corresponding keys may be used for communications between a STA and the corresponding member AP.

[0077] In some embodiments with AP-level authentication according to the present disclosure, a temporary key may be generated, for example, using a mechanism similar to that described above with respect to a mobile domain for fast transition. In addition, if a STA is authenticated only with a single AP, a mechanism similar to that described above with respect to a mobile domain for fast transition may be used to implement transition.

[0078] In some embodiments with AP-level authentication according to the present disclosure, a STA may select only those APs with which it has successfully completed authentication to exchange data frames.

[0079] Some embodiments implementing AP-level authentication according to the present disclosure may be used with a variety of multi-AP coordination techniques, such as coordinated OFDMA, coordinated beamforming, null-forming, and / or the like.

[0080] In some embodiments, and depending on the implementation details, the common association and authentication state according to the present disclosure can reduce or eliminate one or more problems associated with STA switching between APs. For example, if the STA is located at the boundary of two APs that can provide approximately the same quality of service (QoS), and the AP that can provide the best QoS always flips back and forth between the two APs, the STA may frequently switch between APs while evaluating the best QoS. However, the negotiation overhead (ping-pong overhead) associated with each transition may consume a large percentage of the total transmission time, resulting in low performance. To overcome this problem, some systems may implement a threshold time or QoS difference that can cause the STA to maintain (stick to) one AP to prevent flipping back and forth, but this may cause the STA to abandon a connection that can provide better performance. However, by reducing or eliminating the negotiation overhead, some embodiments of the present disclosure may enable the STA to always or more frequently select an AP that can provide better performance.

[0081] Data connectivity

[0082] Fig. 9 902 and the coordinated AP group. Fig. 9 In the illustrated embodiment 900 , the coordinated AP group includes a V-BSS coordinator 908 , a first member AP 904 , and a second member AP 906 .

[0083] exist Fig. 9 In the illustrated embodiment, a common association and authentication state may have been established between STA902 and the coordinated AP group using any of the above techniques. At event E901, a block acknowledgement agreement may be established between STA902 and coordinator 908 (communicating through first AP904). This may enable the block acknowledgement agreement to be shared at the V-BSS coordinator level. In some embodiments, for example, for QoS purposes, the block acknowledgement agreement may be implemented.

[0084] After the block ACK agreement has been established and a common association and authentication state has been established, the STA may be free to dynamically select the AP that can provide the best QoS at any level of granularity, such as frame-by-frame, uplink, and / or downlink, etc. For example, at event E902, the STA 902 may send an uplink data block to the second AP 906, which may relay the data block to the coordinator 908 at event E903. The second AP 906 may send a block ACK to the STA 902 at event E904. However, at event E905, a downlink data block may be sent from the coordinator 908 to the first AP 904, which may relay the downlink data block to the STA 902 at event E906. The STA 902 may then send a block ACK to the first AP 904 at event E907, which may then relay the block ACK to the coordinator 908 at event E908.

[0085] like Fig. 9 As shown, in some embodiments, the use of common association and authentication states can enable dynamic AP selection in both the uplink direction and the downlink direction. This can also enable data frames to be seamlessly sent from different APs to STAs, and from STAs to different APs in the coordinated AP group.

[0086] Fig.10 An example embodiment of a wireless workstation according to the present disclosure is shown. Fig.10 The wireless station 1000 shown may include a wireless transceiver 1002 and a device controller 1004, which may control the operation of the wireless transceiver 1002 and / or any other components in the wireless station 1000. The wireless station 1000 may be used, for example, to implement any wireless station (STA) functions described in the present disclosure, such as establishing and / or maintaining a common association and authentication state, generating keys, exchanging data frames, etc. The device controller 1004 may include, for example, one or more processors 1006 and a memory 1008, which may store instructions for execution by the one or more processors 1006 to implement any wireless station functions described in the present disclosure.

[0087] For example, in some embodiments, the device controller 1004 may be configured to communicate with the coordinated AP group through the wireless transceiver 1002, generate a PMK between the STA and the coordinator of the coordinated AP group, and maintain the association and authentication status between the STA and the coordinated AP based on the PMK.

[0088] Fig.11 An example embodiment of a wireless access point according to the present disclosure is shown. Fig.11The illustrated wireless access point 1100 may include a wireless transceiver 1102 and a device controller 1104, which may control the operation of the wireless transceiver 1102 and / or any other components in the wireless access point 1100. The wireless access point 1100 may be used, for example, to implement any wireless access point (AP) functionality described in the present disclosure, such as establishing and / or maintaining a common association and authentication state, generating keys, exchanging data frames, etc. The device controller 1104 may include, for example, one or more processors 1106 and a memory 1108, which may store instructions for execution by the one or more processors 1106 to implement any AP functionality described in the present disclosure.

[0089] For example, in some embodiments, the device controller 1104 may be configured to communicate with the STA through the wireless transceiver 1102 and maintain the association and authentication status between the STA and the coordinated AP group based on the PMK.

[0090] Fig.12 An example embodiment of a method for associating and authenticating a STA with a coordinated AP group according to the present disclosure is shown. The method may start with operation 1200. At operation 1202, the method may generate a pairwise master key (PMK) between the STA and the coordinator of the coordinated AP group. At operation 1204, the method may maintain the association and authentication state between the STA and the coordinated AP group based on the PMK. The method may end at operation 1206.

[0091] about Figures 10 to 12 The operations and / or components described in the illustrated embodiments, as well as any other embodiments described herein, are exemplary operations and / or components. In some embodiments, some operations and / or components may be omitted, and / or other operations and / or components may be included. In addition, in some embodiments, the temporal and / or spatial order of operations and / or components may be changed.

[0092] The present disclosure covers many inventive principles related to association and authentication for multi-access point coordination. These principles may have independent utility and may be embodied separately, and not every embodiment may utilize every principle. In addition, the principles may also be embodied in various combinations, some of which may amplify the benefits of the individual principles in a synergistic manner.

[0093] The embodiments disclosed above have been described in the context of various implementation details, but the principles of the present disclosure are not limited to these or any other specific details. For example, some functions have been described as being implemented by certain components, but in other embodiments, the functions may be distributed between different systems and components in different locations and have various user interfaces. Certain embodiments have been described as having specific processes, steps, etc., but these terms also include embodiments in which a specific process, step, etc. may be implemented with multiple processes, steps, etc., or embodiments in which multiple processes, steps, etc. may be integrated into a single process, step, etc. A reference to a component or element may refer to only a portion of the component or element.

[0094] Terms such as "first" and "second" used in the present disclosure and claims may be used solely for the purpose of distinguishing the things they modify and may not indicate any spatial or temporal order unless otherwise apparent from the context. Reference to a first thing does not imply the existence of a second thing. Various organizational aids such as section headings may be provided for convenience, but the subject matter and principles of the present disclosure, which are arranged according to these aids, are not limited by these organizational aids.

[0095] The various details and embodiments described above can be combined to produce additional embodiments according to the inventive principles disclosed in this patent. Since the inventive principles disclosed in this patent can be modified in arrangement and detail without departing from the concept of the invention, such changes and modifications are considered to fall within the scope of the appended claims.

Claims

1. A method for associating and authenticating a workstation STA with a coordination access point AP group, the method comprising: Generate a pairwise master key PMK between the station and a coordinator coordinating the access point group; establishing a mutual association and authentication state between the station and one or more member access points based on the generated pairwise master key using a virtual basic service set information element VBIE; as well as A simultaneous connection is maintained between the station and each of the one or more member access points of the coordinating access point group based on the established common association and authentication state.

2. The method according to claim 1, further comprising: One or more temporary keys between the workstation and the coordinator are generated based on the pairwise master key.

3. The method according to claim 2, further comprising: A handshake is performed between the station and the coordinator through a first member access point of the coordinating access point group.

4. The method according to claim 2, wherein: A first member access point of the coordinating access point group forwards data frames between the station and the coordinator.

5. The method according to claim 2, further comprising: Joint transmissions are performed between the station and a first member access point of the coordinated access point group and between the station and a second member access point of the coordinated access point group.

6. The method according to claim 1, further comprising: The pairwise master key is distributed from the coordinator to a first member access point and a second member access point of the coordinating access point group.

7. The method according to claim 6, further comprising: generating a first temporary key between the workstation and the first member access point; as well as A second temporary key is generated between the station and the second member access point.

8. The method according to claim 7, wherein: Generating a first temporary key between the station and the first member access point includes performing a first handshake between the station and the first member access point; and Generating a second temporary key between the station and the second member access point includes performing a second handshake between the station and the second member access point.

9. The method according to claim 1, wherein: The coordinating set of access points is announced in one or more of a beacon, a probe response, or an association response.

10. The method according to claim 1, further comprising: sending an association request from the workstation to the coordinating access point group via a first member access point of the coordinating access point group; as well as An association response is sent from the coordinating access point group to the station via the first member access point, wherein the association response indicates to the station a mode for authenticating the coordinating access point group.

11. The method according to claim 10, wherein: The association includes a coordinator keyholder identifier ID.

12. The method according to claim 1, further comprising: At least one anchor access point for the station is dynamically selected from one or more member access points in the coordinating access point group.

13. The method according to claim 1, wherein: The station and the coordinated access point group include a virtual basic service set (V-BSS) corresponding to a VBIE for establishing a common association and authentication state between the station and one or more member access points.

14. The method according to claim 1, wherein: The virtual basic service set V-BSS is announced using VBIE in the beacon frame.

15. A wireless workstation STA, comprising: Wireless transceiver; as well as The device controller is configured as: Communicate with a coordination access point AP group via the wireless transceiver; Generate a pairwise master key PMK between the wireless workstation and a coordinator coordinating an access point group; Using a virtual basic service set information element VBIE, establishing a common association and authentication state between the wireless station and one or more member access points based on the generated pairwise master key; as well as A simultaneous connection is maintained between the wireless station and each of the one or more member access points of the coordinating access point group based on the established common association and authentication state.

16. The wireless workstation according to claim 15, wherein: The device controller is further configured to generate a temporary key between the wireless station and a coordinator of the coordinated access point group.

17. The wireless workstation according to claim 15, wherein: The device controller is also configured to generate a temporary key between the wireless station and a first member access point of the coordinating access point group.

18. A method for coordinating wireless member access points in a wireless access point AP group, comprising: Wireless transceiver; as well as The device controller is configured as: Communicate with a wireless workstation STA via the wireless transceiver; Using a virtual basic service set information element VBIE, establishing a common association and authentication state between the wireless station and one or more member access points based on a pairwise master key PMK generated between the wireless station and a coordinator of the coordinating access point group; as well as A simultaneous connection between the member access point and the wireless station is maintained based on a common association and authentication state established while the wireless station is simultaneously connected to at least a second member access point in the coordinating access point group.

19. The wireless member access point of claim 18, wherein: The device controller is further configured to forward data frames between the wireless station and the coordinator of the coordinated access point group based on authentication between the wireless station and the coordinator.

20. The wireless member access point of claim 18, wherein: The pairwise master key includes a first pairwise master key, and the device controller is further configured to: receiving a second pairwise master key from a coordinator of the coordinated access point group based on the first pairwise master key; and A temporary key with the wireless station is generated based on the second pairwise master key.

Citation Information

Patent Citations

  • Method for fast roaming in a wireless network

    US20080051060A1

  • Enhancements to enable fast security setup

    US20140050320A1

  • Method and apparatus for associating station (STA) with access point (AP)

    US20150040195A1