Secure handover in Li-Fi networks
By establishing neighbor relationships between access points in the Li-Fi network and pre-selecting candidate access points and pre-establishing keys, the latency problem in the handover process of the Li-Fi system is solved, realizing secure and fast network device handover and improving the system's flexibility and efficiency.
Patent Information
- Application Number
- CN202180015700.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2020-02-20
- Filing Date
- 2021-02-15
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2041-02-15
AI Technical Summary
In Li-Fi systems, network devices experience latency issues during handover from one access point to another, especially under line-of-sight communication characteristics and limited field of view, where the overlap area between adjacent cells is small, making it difficult for mobile endpoints to achieve fast and secure handover.
By establishing neighbor relationships among multiple access points in the network, pre-selecting candidate access points, and pre-establishing paired instantaneous keys before potential handover, the information exchange between access points can be coordinated using centralized or distributed subsystems to optimize the handover process.
It enables smooth endpoint switching in Li-Fi networks, reduces latency caused by key export, ensures communication security and data rate, and improves system flexibility and efficiency.
Smart Images

Figure CN115104341B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of roaming of network devices in optical wireless networks such as Li-Fi networks. More particularly, this document discloses various methods, apparatuses, systems, and computer-readable media related to helping network devices securely and quickly switch from one access point to another. Background Technology
[0002] To enable a growing number of electronic devices, such as laptops, tablets, and smartphones, to wirelessly connect to the internet, wireless communication faces unprecedented demands for data rates and link quality, and these demands continue to grow year after year, given the emerging digital revolution associated with the Internet of Things (IoT). Radio frequency (RF) technologies, such as Wi-Fi, have limited spectrum capacity and cannot meet this demand. Meanwhile, Light Fidelity (Li-Fi) is attracting increasing attention due to its inherent enhanced security and ability to support higher data rates across the available bandwidth of the visible, ultraviolet (UV), and infrared (IR) spectra. Furthermore, compared to Wi-Fi, Li-Fi is directional and shielded by light-blocking materials, making it possible to deploy a larger number of access points in densely populated areas by spatially reusing the same bandwidth. These key advantages compared to wireless RF communication make Li-Fi a promising solution for alleviating the congested radio spectrum pressures of IoT applications. Other benefits of Li-Fi include guaranteed bandwidth for specific users and the ability to operate safely in areas susceptible to electromagnetic interference. Therefore, Li-Fi is a very promising technology for enabling next-generation immersive connectivity.
[0003] Several related terms exist in the field of lighting-based communications. Visible light communication (VLC) transmits data via intensity-modulated light sources such as light-emitting diodes (LEDs) and laser diodes (LDs), faster than the persistence of the human eye. VLC is typically used to embed signals into light emitted by a lighting source, such as everyday lamps, for example, indoor or outdoor lighting, thus allowing the lighting from the lamp to serve as a carrier of information. Therefore, the light can include a visible lighting component used to illuminate a target environment such as a room (often the primary purpose of light), and an embedded signal used to provide information to the environment (often considered a secondary function of light). In this case, modulation can typically be performed at a sufficiently high frequency to exceed human perception, or at least make any visible transient light artifacts (such as flicker and / or stroboscopic artifacts) sufficiently weak and not noticeable or at least tolerable to humans at a sufficiently high frequency. Therefore, the embedded signal does not affect the primary lighting function; that is, the user only perceives the overall lighting, not the effect of the data modulated into that lighting.
[0004] The IEEE 802.15.7 Visible Light Communication Personal Area Network (VPAN) standard maps anticipated applications to four topologies: peer-to-peer, star, broadcast, and coordinated. Optical Wireless PAN (OWPAN) is a more general term than VPAN, as it also allows communication over invisible light, such as UV and IR. Therefore, Li-Fi is often considered a derivative of Optical Wireless Communication (OWC) technology, which utilizes a wide range of spectra to support bidirectional data communication.
[0005] In Li-Fi systems, signals are embedded by modulating the properties (typically intensity) of light, using any of a variety of suitable modulation techniques. For high-speed communication, infrared (IR) is often used instead of visible light. Although ultraviolet and infrared radiation are invisible to the human eye, the techniques for utilizing these spectral regions are the same, although variations can occur as a result of wavelength dependence (such as in the case of refractive index). In many instances, using ultraviolet and / or infrared is advantageous because these frequency ranges are invisible to the human eye and can introduce more flexibility into the system. Of course, ultraviolet quanta have higher energy levels than infrared and / or visible light, which in turn may make the use of ultraviolet light undesirable in certain situations.
[0006] Based on modulation, any suitable light sensor can be used to detect information in light. For example, a light sensor can be a photodiode. A light sensor can be a dedicated photocell (point detector), a photocell array possibly with lenses, reflectors, diffusers, or phosphor converters (for lower speeds), or a photocell (pixel) array and lenses for forming an image on the array. For example, a light sensor can be a dedicated photocell included in a dongle inserted into a user device such as a smartphone, tablet, or laptop, or the sensor can be integrated and / or dual-purpose, such as an infrared detector array originally designed for 3D facial recognition. Either way, this allows applications running on the user device to receive data via light.
[0007] In the following text, the term "access point" in Li-Fi systems is used to refer to a logical access device that can be connected to one or more physical access devices (such as optical transceivers). Such physical access devices are typically located at lighting fixtures, and a logical access point can be connected to one or more physical access devices, each located at one or more lighting fixtures. The access point serves one or more network devices or associated terminal devices to form an optical cell.
[0008] Compared to radio frequency (RF) based communication systems, Li-Fi inherently offers the advantage of reduced eavesdropping opportunities due to the physical nature of optical links, which require line-of-sight communication. In addition to this inherent advantage, security aspects of Li-Fi systems can be further enhanced by introducing dedicated security measures such as authentication and encryption.
[0009] Extensible Authentication Protocol (EAP) is an authentication framework commonly used for wireless network and internet connections. The IEEE 802.1X standard defines how to provide authentication for devices attempting to connect to other devices on a LAN or wireless LAN (WLAN), specifying the EAP encapsulation over the IEEE 802 standard. Therefore, IEEE 802.1X is also known as "EAP over LAN or WLAN". IEEE 802.1X authentication involves three parties: the requester, the authenticator, and the authentication server. The requester is a client or terminal device that wants to access the LAN / WLAN. The authenticator is a network device that provides a data link between the client and the network and can allow or block network traffic between them, such as an Ethernet switch or wireless access point. The authentication server is typically a trusted server that receives and responds to network access requests from clients and can inform the authenticator whether to allow the connection, as well as various settings that should be applied to the client's connection or settings. The authentication server typically runs software that supports Remote Authentication Dial-In User Service (RADIUS) and the EAP protocol.
[0010] To generate encryption keys to encrypt actual data, a four-way handshake is typically required to exchange four messages between the authenticator and the client device or requester. Different keys may be used depending on the type of communication. The Master Session Key (MSK) is the first key generated from IEEE 802.1X / EAP, or the first key derived from the Pre-Shared Key (PSK) authentication. The Group Temporary Key (GTK) is used to encrypt all broadcast and multicast traffic between the access point and multiple client devices; it is shared among multiple client devices and one access point. The Paired Transient Key (PTK) is used to encrypt all unicast traffic between the client station and the access point. Therefore, the PTK is unique between the client station and the access point. The Paired Master Key (PMK) is a key generated from the Master Session Key (MSK), and the PTK depends on the PMK. Similarly, the Group Master Key (GMK) is also generated from the Master Session Key (MSK), and the GTK depends on the GMK.
[0011] However, the authentication and security key establishment processes introduce additional latency not only when a network device first establishes a link in the network, but also when it roams from one cell to another. Furthermore, this additional latency can be even more problematic if the network device is in the middle of a communication session during a handover from one cell to another. Summary of the Invention
[0012] Due to the line-of-sight characteristics of optical wireless communication and the limited field of view (FoV) of optical transceivers, the coverage area of access points (APs) and the overlapping coverage area of adjacent APs in optical systems are smaller compared to RF-based systems. Because of the small coverage area of each optical access point or each optical cell, and because of the need to reduce mutual interference between adjacent access points, the overlapping coverage area of adjacent cells in such optical systems is also typically small. Therefore, mobile endpoints in optical wireless networks will require faster transitions (e.g., handovers) between access points compared to RF-based networks or other types of cellular networks with large coverage areas and large overlap areas per access point. Consequently, supporting endpoints to perform secure and smooth handovers from one optical access point to another becomes more challenging.
[0013] Based on the above, this disclosure relates to methods, apparatus, systems, computer programs, and computer-readable media for providing a mechanism to support a fast and secure handover of an endpoint (EP) from an access point (AP) currently associated with the EP to another AP among a plurality of APs.
[0014] Therefore, a subsystem included in or connected to the EP's currently associated AP can select a candidate AP for the EP by considering one or more adjacency relationships obtained from multiple APs, and notify the EP to trigger the process of pre-establishing a new pair of transient keys between the EP and the candidate AP before the actual security handover occurs.
[0015] According to a first aspect of the invention, a subsystem is provided. The subsystem supports an endpoint in performing a secure handover from an access point currently associated with the endpoint to another access point among a plurality of access points in an optical multi-cell wireless communication network. The subsystem is configured to: obtain one or more neighbor relationships among the plurality of access points; select candidate access points for the endpoint from the plurality of access points, other than the currently associated access point, based on the obtained one or more neighbor relationships, for the secure handover of the endpoint; and notify the endpoint about the candidate access points via the currently associated access point to trigger the endpoint to initiate a process of pre-establishing new pairwise transient keys between the endpoint and the candidate access points for secure handover.
[0016] By anticipating potential handovers of candidate access points, endpoints can prepare for a potential handover before it actually occurs. This anticipation can be made by the endpoint itself, for example, upon detecting downlink communication from a neighboring access point. However, due to the small overlap between adjacent cells, it may be too late for an endpoint to begin the process of pre-establishing pairwise security keys or pairwise transient keys with a neighboring access point after it enters the overlap area. Therefore, it is advantageous to utilize a subsystem that obtains an overview of the neighbor relationships between multiple access points to pre-select at least one candidate access point for a potential handover for the endpoint. Upon receiving information related to a candidate access point, the endpoint may then begin the process of pre-establishing a new pairwise transient key with the candidate access point for a potential handover before entering the overlap area between two adjacent access points. In this sense, the additional process for establishing pairwise security keys or pairwise transient keys will not introduce additional delays to the endpoint's handover.
[0017] The subsystem can also provide further instructions to the endpoint via the currently associated access point to trigger an actual handover to the candidate access point, either immediately after such further instructions or at a specific interval from the receipt of such further instructions. Alternatively, the endpoint can make its own decision regarding the handover timing based on a comparison of the signal strength of the optical wireless communication links with both the currently associated access point and the candidate access point.
[0018] In one embodiment, the subsystem is a centralized subsystem contained in a central controller, wherein the central controller is configured to communicate with multiple access points via a backbone connection.
[0019] The subsystem can be implemented in a centralized manner, such as by being contained within a central controller. The central controller is connected to multiple access points via a backbone connection, which is a stable and high-speed link, and in some scenarios, even an always-connected link. The backbone connection can be a wired connection such as Ethernet, or a radio frequency (RF) or millimeter-wave based wireless connection. The backbone connection can also be another type of optical wireless link, different from the link performed by the endpoints in an optical multi-cell wireless network. Such an example could be free-space optical communication. Information about selected candidate access points is sent from the subsystem to the endpoints via an associated access point, which is also connected to the backbone network via the backbone connection. A centralized subsystem is the preferred setup for large optical multi-cell networks with a large number of access points, but it can also be beneficial even in smaller systems. Assuming all access points can reach the centralized subsystem via the backbone connection, it can be more efficient in terms of gathering neighbor relationships and making intelligent selections of candidate access points for potential handovers.
[0020] In another embodiment, the subsystem is a distributed subsystem comprising one or more access points among a plurality of access points, wherein the plurality of access points are configured to communicate with each other via a backbone connection.
[0021] Another possibility is to implement the subsystem in a distributed manner, where the distributed subsystem is contained within one or more access points interconnected via a backbone connection. Thus, the related one or more access points coordinate with each other to collectively perform the functions of the subsystem. The advantage of this distributed subsystem is that it eliminates the need for a dedicated central device and its implementation is more flexible and convenient. Therefore, it is the preferred option for small-scale networks, saving the additional cost of deploying a dedicated central device. However, as the network grows, the complexity of the proximity relationships increases, and it may become less efficient compared to a centralized approach due to the information exchange and coordination between the one or more access points involved in the distributed system. Initially, gradual network growth can be supported via a distributed subsystem by providing subsystem coordination functionality within one or more access points. When the network reaches a certain size, local subsystem coordination functionality can be disabled in one or more access points, and correspondingly, a Li-Fi controller with a centralized subsystem can be added to the network to reduce the coordination overhead of one or more access points.
[0022] Advantageously, one of the neighbor relationships is obtained by detecting downlink advertisements from neighbor access points other than the associated access point by the endpoint and / or another endpoint located in the overlapping area of the respective adjacent access point and the respective associated access point, and wherein the detection is reported to the subsystem via the respective associated access point.
[0023] Due to the lack of direct line of sight between adjacent access points, these access points are typically (but not necessarily) located on the same plane, so information related to neighbor relationships between multiple access points is often not directly available. However, endpoints located in the overlapping area of two adjacent access points or two adjacent optical cells can detect signals from both. In a preferred configuration, access points periodically issue downlink advertisements to announce their presence, which may include the access point's unique identifier. By detecting such downlink advertisements from neighboring access points rather than the currently associated access point, endpoints can report the presence of neighboring access points to the subsystem via the currently associated access point. As endpoints and / or other endpoints roam through the area, the subsystem can build a good profile of neighbor relationships between multiple access points over time. The profile obtained by the subsystem is also updated from time to time if endpoints and / or other endpoints continue to provide this information when they detect downlink advertisements from different access points rather than those associated with them.
[0024] In another preferred embodiment, one of the neighbor relationships is obtained by detecting uplink advertisements from an endpoint and / or another endpoint by another access point among a plurality of access points, wherein the endpoint and / or the other endpoint is not associated with the other access point, and wherein the detection by the other access point is reported to the subsystem.
[0025] In another setup, the endpoint is configured to issue an uplink advertisement to announce its presence, which may include the endpoint's unique identifier. This uplink advertisement will be detected by one or more access points within the optical link coverage area of the endpoint. Therefore, when an endpoint enters an area where both its currently associated access point and neighboring access points are within its coverage field of view, the neighboring access point will recognize from the received uplink advertisement that the endpoint is not associated with itself and will report this detection to the subsystem. Using the report from the neighboring access point and knowledge of the association between the endpoint and its currently associated access point, the subsystem can derive the neighbor relationship between the neighboring access point and the endpoint's currently associated access point. Similar to the previous approach of establishing neighbor relationships based on downlink advertisements, the subsystem can also establish a good profile of neighbor relationships between one or more endpoints over time based on their uplink advertisements as one or more endpoints roam through the area.
[0026] In one embodiment, candidate access points are selected by considering a floor plan of the area where multiple access points are located and the spatial location of the multiple access points in that area.
[0027] Using available information about neighbor relationships around the currently associated access point, the subsystem can effectively select candidate access points for potential endpoint handovers. However, this selection can be further improved by considering additional information—such as a map of the area and the access point's location within that area.
[0028] A floor plan can provide information about the layout of an area, including room partitions, room layouts, furniture within rooms, room entrances, corridors, and so on. This knowledge of the floor plan helps the subsystem filter out some adjacent access points as potential candidates for handover when adjacent access points are located in different rooms than the room where the currently associated access point is located. In another example, if the currently associated access point is located on one side of a large table, then adjacent access points on the opposite side of the table are also unlikely to be candidates for immediate handover because the direct path for roaming devices between the two access points is actually blocked by the table.
[0029] In another embodiment, candidate access points are selected by considering statistics regarding the handover between the currently associated access point and other access points among a plurality of access points.
[0030] Preferably, the selection of one or more candidate access points can be further improved by considering statistics regarding the handover history of currently associated access points. These statistics can take the form of a probability distribution of previous handovers from the access point of interest to any adjacent access point. Higher probabilities in the past can indicate a greater chance of future handover events. Therefore, among other things, such statistics can also be considered by the subsystem, enabling it to learn and adapt to any changes in the system, such as changes in area layout or multi-cell optical networks.
[0031] Information associated with one or more candidate access points may also include the estimated handover probability of switching from the currently associated access point to each of the one or more candidate access points. By obtaining more detailed information, based on the estimated handover probabilities, the endpoint can decide for itself to pre-establish a sequence of individual pairwise transient keys or pairwise secure keys with one or more candidate access points. The endpoint can even select a subset of one or more candidate access points suggested by the subsystem to pre-establish keys.
[0032] Advantageously, more than one candidate access point is selected, which includes at least the direct neighbor and non-adjacent other neighbors of the currently associated access point, wherein the non-adjacent other neighbors are adjacent to the direct neighbor.
[0033] Given the relatively small coverage area of a single optical cell, it may be even more beneficial to anticipate several subsequent handovers, including potential handovers from the current associated access point to a direct neighbor, and one or more subsequent potential handovers from the direct neighbor to a non-adjacent neighbor and / or from the non-adjacent neighbor to an even more distant access point. In a preferred configuration, a non-adjacent neighbor is selected when the predicted handover probability of a subsequent handover from a direct neighbor to a non-adjacent neighbor is above a certain threshold. Therefore, by knowing several potential candidate access points for subsequent handovers, the endpoint can pre-establish several pairs of security keys or pairs of transient keys, each dedicated to a different potential access point. This prediction of several related subsequent handovers can be made based on a floor plan of the relevant access points and / or statistics regarding the handover history of the current associated access point, its direct neighbors, and even non-adjacent neighbors. Pre-establishing pairs of security keys or pairs of transient keys for several subsequent handovers can be crucial for high-quality sessions for rapidly moving endpoints.
[0034] According to a second aspect of the invention, an endpoint is provided. An endpoint for performing a secure handover from an access point currently associated with the endpoint to another access point among a plurality of access points in an optical multi-cell wireless communication network, the endpoint comprising: an optical transceiver configured to perform optical wireless communication; a controller configured to protect the link by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point using a pair of instantaneous keys; and, upon the optical transceiver receiving information related to a candidate access point, triggering a process for pre-establishing a new pair of instantaneous keys between the endpoint and the candidate access point for secure handover; and wherein the process is triggered before the handover to the candidate access point actually occurs.
[0035] As disclosed above, the subsystem provides an overview of the neighbor relationships among multiple access points in the network and offers endpoints input related to one or more candidate access points for potential handover. On the other hand, the endpoint maintains an active communication link with its currently associated access point and can trigger a pre-establishment of security keys based on available information about one or more candidate access points, regardless of the actual distance to the candidate access points. This early notification from the subsystem allows for proactive preparation of the security aspects of potential handover without the effort required to predict candidate access points, which is advantageous for the endpoint. Therefore, the endpoint can enjoy a smooth handover without experiencing data rate degradation due to delays caused by key derivation or the extra caution required to predict candidate access points. Simultaneously, ongoing sessions after a potential handover can be protected at the same level of security via paired security keys or paired instantaneous keys.
[0036] The process for pre-establishing new pairwise transient keys between an endpoint and a candidate access point can further include a resource allocation request from the endpoint to the candidate access point. In this sense, the endpoint will also reserve resources in the candidate access point.
[0037] The controller can also be configured to trigger a handover to a selected candidate access point based on further instructions received from or via the current associated access point from the subsystem. In this way, when performing a handover in a multi-cell network with overlapping cells, the mechanism can, for example, consider the traffic load conditions of both the current associated access point and the candidate access point. Alternatively, the optical transceiver can be further configured to monitor the link quality with both the current associated access point and the candidate access point. The optical transceiver can provide the controller with information related to the comparison of link quality, and the controller can then determine when to initiate the handover, which can be a hard handover or a soft handover. A soft handover indicative endpoint can receive and combine data from both the earlier associated access point and the candidate access point.
[0038] In a preferred configuration, the optical transceiver is also configured to send a report to the current associated access point when a downlink advertisement from a neighboring access point other than the current associated access point is detected.
[0039] In one option, multiple access points periodically issue announcements including their respective identifiers to announce their presence to surrounding terminal devices. Therefore, it is beneficial to utilize such downlink announcements to establish an overview of neighbor relationships. When an endpoint enters the overlapping area of its current associated access point and a neighboring access point, the endpoint reports to its current associated access point that a downlink announcement from the neighboring access point has been detected. The current associated access point can then forward this information to the subsystem to help the subsystem deduce the neighbor relationship between the two associated access points.
[0040] In another preferred configuration, the optical transceiver is also configured to send an uplink announcement about the presence of the endpoint.
[0041] In another option, the endpoint is configured to issue an uplink advertisement including its identifier to announce its own presence. Therefore, it is beneficial for access points to report to the subsystem the detection of such uplink advertisements from endpoints unrelated to themselves. By combining reports received from neighboring access points with information about the endpoint's currently associated access points, the subsystem can easily identify the neighbor relationship between two related access points.
[0042] In a particularly advantageous system for supporting an endpoint to perform a secure handover from an access point currently associated with that endpoint to another access point among multiple access points in an optical multi-cell wireless communication network, the system includes:
[0043] - A subsystem is configured to obtain one or more neighbor relationships among multiple access points; based on the obtained one or more neighbor relationships, select candidate access points for the endpoint from the multiple access points, excluding the currently associated access point, for secure endpoint handover; and
[0044] The endpoint is notified about the candidate access point via the current associated access point, triggering the endpoint to begin the process of pre-establishing a new pair of transient keys between the endpoint and the candidate access point for secure handover;
[0045] - An endpoint, comprising: an optical transceiver configured to perform optical wireless communication; a controller configured to protect the link by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point using a pair of instantaneous keys; and, upon the optical transceiver receiving information related to a candidate access point, triggering a process for pre-establishing a new pair of instantaneous keys between the endpoint and the candidate access point for secure handover; wherein the process is triggered before the handover to the candidate access point actually occurs; and
[0046] - Multiple access points, including currently associated access points and candidate access points, are configured to perform optical wireless communication with the endpoints and are interconnected via a backbone connection;
[0047] Furthermore, the subsystem is either contained in one or more of the multiple access points, or connected to multiple access points via a backbone connection.
[0048] According to a third aspect of the invention, a method for a subsystem is provided. A method for supporting an endpoint to perform a secure handover from an access point currently associated with the endpoint to another access point among a plurality of access points in an optical multi-cell wireless communication network, the method comprising the steps of the subsystem: obtaining neighbor relationships among the plurality of access points; selecting, based on the obtained neighbor relationships, a candidate access point for the endpoint from the plurality of access points, other than the currently associated access point, for the secure handover of the endpoint; and notifying the endpoint about the candidate access point via the currently associated access point to trigger the endpoint to begin a process of pre-establishing a new pairwise instantaneous key between the endpoint and the candidate access point for secure handover.
[0049] According to a fourth aspect of the invention, a method for an endpoint is provided. A method for performing a secure handover of an endpoint from an access point currently associated with the endpoint to another access point among a plurality of access points in an optical multi-cell wireless communication network, the method comprising the endpoint the steps of: performing optical wireless communication with the currently associated access point; securing the link by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point using a pairwise instantaneous key; and, upon detection of information related to a candidate access point, triggering a process for pre-establishing a new pairwise instantaneous key between the endpoint and the candidate access point for secure handover, wherein the process is triggered before the secure handover to the candidate access point actually occurs.
[0050] The invention can also be embodied in a computer program that includes code means, which, when executed by a subsystem or endpoint including a processing means, causes the processing means to perform a method of the subsystem or endpoint. Attached Figure Description
[0051] In the accompanying drawings, similar reference numerals are used throughout. Figure 1 Generally, the same parts are referred to. Furthermore, the accompanying drawings are not necessarily to scale; instead, the focus is usually on illustrating the principles of the invention.
[0052] Figure 1 An overview of the OWC network and the backbone network connected to it is presented;
[0053] Figure 2 The basic components of a Li-Fi access point are schematically depicted.
[0054] Figure 3 The basic components of a Li-Fi access point with multiple optical front ends are schematically depicted.
[0055] Figure 4 The basic components of a Li-Fi endpoint are schematically depicted.
[0056] Figure 5 The basic components of the optical front end contained in a Li-Fi access point or Li-Fi endpoint are schematically depicted.
[0057] Figure 6 The diagram shows the endpoint roaming in an optical multi-cell wireless communication network, as well as the corresponding coverage areas of the endpoint, associated access point, and neighboring access points.
[0058] Figure 7 An overlay top view of an endpoint roaming in an optical multi-cell wireless communication network is shown, having a first planar surface and a second planar surface.
[0059] Figure 8 The message exchange used to establish neighbor relationships in a centralized subsystem via downlink announcements from multiple access points is illustrated.
[0060] Figure 9 The message exchange used to establish neighbor relationships in a centralized subsystem via uplink announcements from endpoints is illustrated.
[0061] Figure 10 The message exchange used to establish neighbor relationships in a distributed subsystem via downlink announcements from multiple access points is illustrated.
[0062] Figure 11 The message exchange used to establish neighbor relationships in a distributed subsystem via uplink announcements from endpoints is illustrated.
[0063] Figure 12 The floor plan shows the rooms where multiple access points are deployed in the area, as well as the potential movement trajectories of the roaming endpoints;
[0064] Figure 13 The basic components of the endpoints of the present invention are schematically depicted;
[0065] Figure 14 A flowchart of the method executed by the subsystem is shown;
[0066] Figure 15 A flowchart of the method executed by the endpoint is shown. Detailed Implementation
[0067] Now, it will be based on an optical wireless communication (OWC) network system 100, or more specifically, on such Figure 1 The Li-Fi network system shown is used to illustrate various embodiments of the invention. For illustrative purposes, Li-Fi network 100 is connected to backbone network 20 via IP router 15 and Ethernet switch 14. In a real system, more routers and switches may be connected between the Li-Fi network and the backbone network. In this example, the Li-Fi network is connected to the backbone network via backbone connection 21. The backbone connection is a stable and high-speed link, which can be a wired connection (such as Ethernet) or a radio frequency (RF) or millimeter wave-based wireless connection. The backbone connection can also be another type of optical wireless link, which differs from the link performed by the endpoints in an optical multi-cell wireless network. An example of another type of optical wireless link could be a free-space point-to-point optical link.
[0068] Li-Fi System Overview and Network Architecture
[0069] As a wireless communication technology for local area networks, Li-Fi plays a similar role to Wi-Fi in providing connectivity for the last few tens of meters. A Li-Fi network 100 may include multiple optical access points (APs) 120 and network devices or endpoints (EPs) 110. Each endpoint 110 is selectively associated with and synchronized with a corresponding access point 120. Li-Fi APs 120 may connect to one or more optical front-ends or Li-Fi transceivers (TRXs) 121 to provide access to Li-Fi devices or Li-Fi endpoints (EPs) 110. The trapezoidal shape shown by the dashed line illustrates the field of view (FOV) or coverage area of each Li-Fi transceiver 121. An EP 110 will only be able to receive downlink communication from a Li-Fi AP 120 when it is within the coverage area of that AP 120. By assuming symmetrical uplink and downlink in optical communication, bidirectional optical links can be established under the same conditions. Due to the line-of-sight characteristics of optical communication links, there is no direct optical link between adjacent access points 120, but the endpoint 110 located in the overlapping area of the coverage of adjacent access points 120 can detect optical signals from both access points.
[0070] In one example, the Li-Fi AP 120 can also operate as a domain host with additional functions according to G. hn, ITU G.9960, and G.9961 to manage several Li-Fi EPs 110. In one implementation, a handover occurs when an EP roams from one domain to another. In another implementation, each Li-Fi AP 120 operates as a domain host managing a separate domain hosting multiple Li-Fi EPs, up to 255 in total. Such Li-Fi APs 120 are typically located on the ceiling. They may, but not necessarily, be juxtaposed with lighting fixtures, especially when communication is not based on visible light. The main functions of the Li-Fi AP 120 may include announcing the presence of the AP 120 to surrounding Li-Fi EPs 110, registering and deregistering Li-Fi EPs 110, providing Media Access Control (MAC) scheduling between associated Li-Fi EPs 110, collecting interference reports from EPs 110, adjusting local scheduling in response to interference reports, and / or reporting adjacency relationships to the Li-Fi controller 13. Some features of the Li-Fi AP 120—such as MAC scheduling for interference avoidance—can be implemented in a centralized manner by the Li-Fi controller 13.
[0071] Li-Fi EP or Li-Fi device 110 is an end-user modem that facilitates connection of terminal devices to Li-Fi network 100. Currently, Li-Fi EP 110 is typically a dedicated entity for connecting to laptops or other terminal devices. In the future, Li-Fi EP 110 may be partially or fully integrated into smartphones, tablets, computers, remote controls, smart TVs, display devices, storage devices, home appliances, or other smart electronic devices.
[0072] There may be multiple Li-Fi controllers or central controllers 13 connected to access points 120 in the Li-Fi network 100. The Li-Fi controllers or central controllers 13 are responsible for centrally controlling the Li-Fi system when necessary, such as deriving information about topology and adjacency relationships, and determining scheduling between different Li-Fi access points (APs) to suppress interference. Furthermore, the Li-Fi controllers 13 can also provide a user interface that allows users or administrators (such as IT administrators) to configure scheduling tables among multiple Li-Fi APs, monitor reports from these Li-Fi APs, and / or derive further statistics about system performance. Typically, it is ensured that only one Li-Fi controller 13 is visible to a single AP; this is achieved through network configuration such that traffic to and from the Li-Fi controller 13 is isolated within its own network segment via a virtual LAN (VLAN) or similar. Additionally, protocols such as the Control and Configuration of Wireless Access Points (CAPWAP) protocol can be used to discover multiple controllers and select one with available resources to host / manage access points joining the infrastructure.
[0073] In one exemplary implementation, the Li-Fi system can utilize G.vlc-based technology, with a Li-Fi synchronization server 16 connected to the system. This server is responsible for synchronizing (or aligning) the G.vlc Media Access Control (MAC) cycles of different G.vlc domains. This requires aligning some common time slots for detecting adjacent APs 120 and avoiding interference to EP 110 located in the overlapping area of adjacent APs 120. Due to the line-of-sight nature of optical links, adjacent APs 120 typically cannot directly detect each other's signals. However, if adjacent APs 120 are transmitting simultaneously, EP 110 located in the overlapping area of two adjacent APs 120 may experience interference. To avoid this, it may be necessary to keep adjacent APs 120 synchronized with a common time base and prevent them from transmitting at the same time. A preferred option for network synchronization is to use the Precision Time Protocol (PTP), IEEE 1588v2. PTP provides sub-microsecond accuracy, which is sufficiently fair for MAC alignment in G.vlc domains. To maintain PTP accuracy, support from Ethernet switches is necessary, and this should also be a capability of PTP. To maintain the accuracy of PTP, every element in the Ethernet network must handle PTP, therefore the switches chosen for any deployment must support and be configured accordingly to operate in PTP mode.
[0074] It is also possible that the Li-Fi system will be deployed on legacy systems where PTP is not supported by the existing infrastructure. Therefore, additional measures should be taken to synchronize neighboring APs 120 in a different and potentially suboptimal manner, and thus a solution should be found for EP 110 to handle the non-ideal synchronization between neighboring APs 120.
[0075] Detailed system description
[0076] Li-Fi AP
[0077] The Li-Fi AP 120 is a key unit for establishing the Li-Fi network 100. In some scenarios, the Li-Fi AP 120 also forms the interface between the existing IT infrastructure and the Li-Fi network 100. Figure 2 A high-level block diagram of the Li-Fi AP 120 is shown. On one hand, the Li-Fi AP 120 has an interface 124 to a backbone network, which can be a wired connection (Ethernet) or a wireless connection (RF, millimeter wave, or another type of optical wireless than the optical wireless being performed by the Li-Fi AP). On the other hand, the Li-Fi AP 120 has an optical front-end 121 to establish an optical link with one or more Li-Fi APs 110. Furthermore, the Li-Fi AP 120 also performs bidirectional conversion or transformation between data on the backbone network 20 and data on the optical link, in terms of conversion between different modulation schemes and modulation of analog signals. Therefore, the Li-Fi AP 120 also includes at least a digital modulator and demodulator assembly 123 and an analog front-end 122. In the transmission path, the analog front-end (AFE) 122 may include programmable amplifiers, filters, and drivers to modulate and amplify the baseband signal to drive the optical front-end. For the receiving path, the AFE 122 may include attenuators, low-noise amplifiers, filters, and programmable gain amplifiers to accommodate the received signal for further digital processing.
[0078] An optical front end 121, comprising at least a light source and a light sensor, performs the conversion between electrical and optical signals. In the transmitter chain, the optical front end 121 converts the electrical transmission signal into an output optical signal via the light source. In the receiver chain, the optical front end 121 converts the received optical signal into an output electrical signal via the light sensor for further signal processing. The optical front end 121, also referred to as a Li-Fi transceiver (TRX), enables:
[0079] Li-Fi transmitters (Tx): convert electrical signals obtained from the AFE into optical signals (e.g., to be emitted by an LED), and
[0080] Li-Fi receiver (Rx): Converts received optical signals (e.g., from photodiodes) into electrical signals for AFE.
[0081] The Li-Fi AP 120 can connect to a single Li-Fi TRX 121 or multiple Li-Fi TRX 121s, allowing optical signals to be transmitted on different optical paths. When the Li-Fi AP 120 is connected to multiple Li-Fi TRX 121s, the Li-Fi AP can treat them as a coherent signal or as (partially) independent incoherent signals used to establish a communication link. Figure 3 An example of a Li-Fi AP 120 with multiple Li-Fi TRX 121s is shown. A Li-Fi interface component 125 is used to separate or combine data sent to or received from the multiple Li-Fi TRX 121s.
[0082] Li-Fi EP
[0083] Figure 4 A high-level overview of the Li-Fi EP or Li-Fi device 110 is shown. Similar to the Li-Fi AP 120, the Li-Fi EP 110 includes at least an optical front end 111, an analog front end 112, a digital modulator / demodulator 113, and an interface 114 to an end device or processor.
[0084] The Li-Fi EP 110 can be connected to a terminal device as a separate entity via cable, or partially or fully integrated into the terminal device. For many terminal devices (such as laptops, smartphones, and remote controls), Ethernet is a mature interface in the terminal device's operating system. Alternatively, Li-Fi can also be used to provide a communication interface to the terminal device. To simplify system integration of the Li-Fi EP or Li-Fi device into the terminal device's operating system, Ethernet over USB is advantageous. Therefore, in one option, the Li-Fi EP or Li-Fi device 110 can be connected to the terminal device via a standard USB cable. Using Ethernet over USB as an example, the Li-Fi EP 110 may include an Ethernet over USB interface 114 and connect to the terminal device via a USB cable 115. Similar to the Li-Fi AP 120, the Li-Fi EP 110 can also be connected to one or more client optical TRX 111s. Alternatively, a single optical front end with segmented transmitters / receivers, where each transceiver / receiver points in a different direction, is also conceivable.
[0085] In another example, a different interface 114 can be used to connect the Li-Fi EP to the operating system of the terminal device, and the corresponding interface 114 (Ethernet over USB) and / or cable 115 should be replaced accordingly.
[0086] Figure 5 Exemplary components are provided for optical front-ends or optical TRX 111, 121 included in or connected to Li-Fi AP 120 and Li-Fi EP 110. Optical TRX 111, 121 include at least a light source 1211, a photosensor 1212, a driver 1213, and an amplifier 1214. The light source 1211 is used to convert an electrically transmitted signal into an output optical signal; it may be a light-emitting diode (LED), a laser diode (LD), or a vertical-cavity surface-emitting laser (VCSEL). The photosensor 1212 is used to convert the received optical signal into an output electrical signal; it may be a photodiode, an avalanche diode, or another type of photosensor. The driver 1213 is primarily used to regulate the power required by the light source 1211. The amplifier 1214 is primarily used to regulate the signal received by the photosensor 1212 to make the signal suitable for further processing in the circuit. In one example, the amplifier 1214 may be a transimpedance amplifier (TIA), which is a current-to-voltage converter implemented using one or more operational amplifiers. The TIA can be located near the receiving optical sensor or photodiode 1212 to amplify the signal with minimal noise.
[0087] Interconnection in Li-Fi systems
[0088] Typically, the Li-Fi AP 120 is deployed on the ceiling. This AP 120 requires power to perform communication activities. Therefore, the connection to the AP 120 involves both power and data. On one side, the AP 120 establishes a bidirectional link with the cloud or backbone network 20, and on the other side, the AP 120 communicates with one or more associated EPs 110 via an optical link. The EPs 110 typically draw power from an end device, which is coupled to or integrated into the end device; and communicate with the associated AP 120 via an optical link.
[0089] Connect the Li-Fi AP to the backbone network
[0090] The L1-Fi AP 120 can use different options to connect to the backbone network 20.
[0091] In one aspect, data and power can be delivered together to the Li-Fi AP, which can be achieved via a single power cable with power line communication (PLC) or a single Ethernet cable with power over Ethernet (PoE).
[0092] PLCs utilize existing power cables, both for providing mains power to the equipment and for data communication. Popular PLC communication standards (such as HomePlug) ® Or G.hn) utilizes Orthogonal Frequency Division Multiplexing (OFDM) technology, which is also widely used in Li-Fi systems. Therefore, the physical layer (PHY) of PLC and Li-Fi systems can be very similar, such as the modulation and synchronization methods used in both systems. However, transmission in the optical domain is unipolar, while OFDM typically uses bipolar signals. As a result, some adaptation may be required for transmission in optical networks. A simple solution is to use DC offset, which eliminates the need for demodulation and subsequent remodulation of the OFDM-based PLC signal before optical transmission, or alternatively, to use unipolar OFDM modulation techniques (such as ACO-OFDM, DCO-OFDM, ADO-OFDM, and / or inverted OFDM) for demodulation and subsequent remodulation. Therefore, for a Li-Fi AP 120 typically juxtaposed with ceiling lights, it may be very convenient to utilize existing power cables to obtain data connectivity to the backbone network 20.
[0093] However, it is also recognized that the channels of PLC systems are quite noisy, considering that the trunk power lines may act as antennas, picking up all sorts of unwanted signals that may interfere with the communication signals also present on the trunk power lines. Therefore, it is important to handle this external interference for devices enabling Li-Fi on PLCs. Furthermore, the amount of attenuation experienced by the communication signals on the trunk power lines is unpredictable during manufacturing and may vary throughout the day. Influencing factors include cable lengths varying from building to building, electrical loads that more or less create short circuits at high frequencies, and being switched on or off, etc.
[0094] One known solution to address signal integrity issues introduced by PLC systems is to equip Li-Fi-enabled devices with a PLC with a PLC decoder to decode PLC communication signals received over the mains power line. Impairments to the communication signal are handled digitally. For example, narrowband interference causes errors only on a single subcarrier of the OFDM modulated signal. Error correction algorithms can be used to correct the reconstructed data. The reconstructed data is then converted back to the analog domain to modulate the LED current flowing to at least one LED. In this way, more robust operating devices can be provided, with reduced data loss, although one drawback of this solution is that the devices become larger, more complex, and more expensive.
[0095] On the other hand, if power can be delivered via Ethernet cables, Li-Fi APs may also be convenient in utilizing existing IT infrastructure to obtain both power and connectivity to the backbone network. Power over Ethernet (PoE) is described in the IEEE 802.3af / at standard and is currently being extended to 4-pair power delivery in the IEEE task group P802.3bt. PoE is designed to supply 40V to 48V of power supply voltage from a power supply equipment (PSE) to a power consumption device (PD), along with data lines for control and communication purposes. PSE devices are also known as PoE switches. In a PoE lighting system, the PD can be a light source, a user interface device, or a sensor. The PSE is typically powered by a trunk power supply, such as according to the IEC / TR 60083 standard. Traditional PoE systems transport data and power through the network and its endpoints, thus between the PSE and the PD.
[0096] Therefore, data can be received by control devices, for example, via an Ethernet connection using the Ethernet protocol. Data is communicated between devices in a Power over Ethernet (PoE) system via the Ethernet protocol. Thus, microchips in the form of Ethernet controllers can be used to establish communication links between devices, supporting the Media Access Control (MAC) and Physical Layer (PHY) of the Open Systems Interconnection (OSI) model.
[0097] Ethernet connections can be, for example, fiber optic cables, electrical wires, or twisted-pair cables, such as Category 3, Category 4, Category 5, Category 5e, Category 6, Category 6A, Category 7, Category 7A, Category 8, Category 8.1, or Category 8.2 cables. An Ethernet connection can have several pairs of cables, such as 2, 3, 4, or more. The cables can be unshielded or shielded, particularly individually or collectively shielded. Power and data can be transmitted via the same fiber optic cable, electrical wire, or cable connected to the Ethernet connection, or via different fiber optic cables, electrical wires, or cables connected to the Ethernet connection. In the case of power transmission via fiber optics, the power can be transmitted in the form of photons, which can be received by the solar cell unit of the data receiving device.
[0098] Data receiving devices in a PoE system may include one or more ports. Each port may include one or more pins. Pins may be configured to receive power, data, or both. Alternatively or additionally, the port may also include one or more solar cell units for receiving power in the form of photons. Because the port can receive power and data via an Ethernet connection, some pins can be powered while other pins are supplied with data via the Ethernet connection. Alternatively or additionally, power and data may also be supplied to pins via an Ethernet connection.
[0099] In another aspect, data and power can be delivered to the Li-Fi AP separately, and the option can be either via a power cable and an Ethernet cable (a wired connection to the backbone network), or a combination of a power cable and a wireless link (optical wireless link or free-space optical link) to the backbone network 20.
[0100] Preferably, the Li-Fi system can be integrated into existing wireless communication systems, such as Wi-Fi or cellular systems. Therefore, the Li-Fi AP 120 can be integrated into or directly connected to a Wi-Fi access point or cellular base station. By performing signal conversion or transformation between the Li-Fi AP 120 and the Wi-Fi access point or cellular base station, the existing infrastructure of the Wi-Fi or cellular system can be used to provide the Li-Fi AP 120 with connectivity to the backbone network 20.
[0101] Connect the Li-Fi EP to the Li-Fi AP
[0102] The Li-Fi EP 110 connects to the Li-Fi system via the Li-Fi AP 120, which is typically referred to as the local AP. Several aspects need to be considered regarding the connection between the Li-Fi EP 120 and the Li-Fi AP 110:
[0103] Coverage: Li-Fi EPs may not always be able to see Li-Fi APs, depending on their location, orientation, the location of the Li-Fi AP, and the size of the Li-Fi EP's transducer / sensor coverage area.
[0104] Downlink interference: If these Li-Fi APs transmit simultaneously, the Li-Fi EPs in the overlapping coverage areas of multiple optical downlinks will be subject to interference.
[0105] Uplink interference: When one Li-Fi EP transmits a signal to its associated Li-Fi AP, while another Li-Fi EP is transmitting to the same Li-Fi AP, this causes uplink interference at the Li-Fi AP.
[0106] Handover: Due to the mobility of Li-Fi EPs, handover is required when a Li-Fi EP moves from the coverage area of one Li-Fi AP to an adjacent Li-Fi AP. That is, when a Li-Fi EP (such as one connected to or contained in a user equipment, client device, mobile phone, etc.) moves from its current cell to an adjacent cell, any active communication must be switched to the node or access point of that adjacent cell. To minimize interference with any ongoing communication or data transmission, handover is designed to be performed as quickly as possible and may include a preparation period to facilitate this. When there is insufficient time to prepare and establish a link to the new Li-Fi AP before the link with the existing Li-Fi AP is broken, the Li-Fi EP may experience a period of no connection. Considering the relatively small size of Li-Fi cells due to the line-of-sight characteristics of optical links, seamless handover is important for ensuring link quality and user experience.
[0107] Essentially, the Li-Fi EP 110 can connect to the Li-Fi AP 120 via a bidirectional optical link or a hybrid downlink and uplink. Note that here, the downlink represents the communication link from the Li-Fi AP 120 to the Li-Fi EP 110, and the uplink represents the communication link from the Li-Fi EP 110 to the Li-Fi AP 120. The bidirectional optical link achieves a relatively symmetrical connection between the Li-Fi EP 110 and the Li-Fi AP 120. Therefore, both the downlink and uplink enjoy the same advantages of Li-Fi communication as described above. However, in some applications (such as web surfing or video streaming), the link between the Li-Fi AP and the Li-Fi EP can also be a hybrid link, combining an optical downlink from the Li-Fi AP 120 to the Li-Fi EP 110 and a radio frequency (RF) uplink from the Li-Fi EP 120 to the Li-Fi AP 110. RF links can be based on popular short-range wireless communication protocols, such as Wi-Fi, BLE, or Zigbee; or on cellular communication protocols, such as 4G or 5G cellular.
[0108] Referring back to the option of building the Li-Fi AP 120 via a combination of devices supporting Li-Fi AP functionality and Wi-Fi access point or cellular base station functionality, this hybrid link can be seamlessly handled by the controller on the Li-Fi AP side. Since the Li-Fi EP 110 is typically connected to or integrated into an end device—which could be a smartphone, tablet, computer, or other smart device—this end device may already have hardware support for the short-range wireless communication protocols or cellular protocols used in the hybrid link. Therefore, this hybrid link also utilizes the existing resources of the end device and provides a simplified solution for the Li-Fi EP, which only requires a receive path and not a transmit path. The cost, power consumption, and form factor of the EP 110 can be further reduced in this way. Correspondingly, the Li-Fi AP 120 is also simplified by primarily including an optical transmitter to send data to the Li-Fi EP 110 via an optical downlink, while the RF-based uplink from the Li-Fi EP 110 to the AP 120 can be received by utilizing an RF receiver in a combined device or a cooperatively positioned Wi-Fi access point / cellular base station, or via a dedicated RF receiver included in the Li-Fi AP 120 itself.
[0109] Scheduling and interference suppression in optical multi-cell wireless networks
[0110] Media Access Control (MAC) becomes necessary for interference-free optical communication when multiple Li-Fi AP 120s are deployed adjacent to each other, or when multiple EP 110s are associated with the same local AP 120 or neighboring AP 120s. Different MAC mechanisms can be employed in optical multi-cell wireless networks, such as Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Carrier Sense Multiple Access (CSMA), Code Division Multiple Access (CDMA), Space Division Multiple Access, or a combination of one or more of these mechanisms. TDMA is based on a time division multiplexing scheme, where radio resources are scheduled in the time domain, and different time slots are allocated to different transmitters in a typical cyclic repeating frame structure or MAC cycle. FDMA is based on frequency division multiplexing, where different frequency bands are allocated to different devices for simultaneous transmission. Furthermore, in optical communication, FDMA can evolve into wavelength division multiple access (WDMA) based on wavelength division multiplexing. Another advanced variant of FDMA is Orthogonal Frequency Division Multiple Access (OFDMA), where each device can use one or more subcarriers outside the entire frequency band. OFDMA offers greater flexibility in providing different data rates or qualities of service to different users, while maintaining high resource efficiency despite this diversity. CSMA typically employs a "listen-before-talk" approach, where devices verify the presence of any other traffic before transmitting over a shared medium. CSMA is widely used in sparse networks, and further collision avoidance techniques emerge as node density increases. CDMA is typically built on spread spectrum, and a common form is direct sequence CDMA based on direct sequence spread spectrum, where different devices simultaneously transmit messages using different orthogonal spreading codes. Given that the FoV of optical links is generally smaller compared to radio links, spatial division multiple access can also be a very attractive solution here.
[0111] In a TDMA-based multi-cell network with multiple AP 120s, adjacent AP 120s may sometimes lack synchronized MAC cycles due to the lack of direct communication. While the duration of a MAC cycle or superframe is typically the same for all AP 120s in the network, the start time of the MAC cycle can differ for each individual AP 120. Note that the start time of the MAC cycle is used by the AP as its local time base to divide the wireless media into consecutive time slots. Even when a time slot is specifically allocated to an AP 120 for communication with an EP 110 in an overlapping area, this MAC cycle offset between two adjacent AP 120s can still cause interference to the EP 110 located in the overlapping coverage area of these two adjacent AP 120s. Therefore, it is necessary for the AP 120s to synchronize to a common time base. The common time base can be obtained via a synchronization handshake, via a reference clock distributed across the network (such as a synchronized Ethernet clock), or via a dedicated synchronization server in the network, or derived from a common signal (such as the zero-crossing of trunk power). However, due to unpredictable delays or interference in the network, timing synchronization uncertainties between APs and a timing base may still exist. An EP 110 located in the overlapping area of at least two adjacent APs 120 may still need to derive timing information related to the MAC cycles of at least two APs 120 based on downlink communications from these APs, which can be normal data communication links or out-of-band signaling messages. Then, based on the derived timing information related to the MAC cycles of at least two APs 120, the EP 110 can further assist at least one of the two adjacent APs 120 in adjusting its MAC cycle to align with the other.
[0112] Quick and safe switching
[0113] For Wi-Fi systems, IEEE 802.11 defines that communication for handover or transition can be performed directly with adjacent access points, for example, on a direct path (i.e., "over-the-air") or via a local access point in a distributed system (DS) (i.e., "over-the-DS"). Furthermore, the EP may want adjacent access points to reserve resources before the transition, for example, based on the Fast Transition (FT) resource request protocol (Fast BSS transition) according to Section 13 of the IEEE 802.11 (2016) specification. Two FT protocols are defined for this purpose. These are the FT protocols executed when a transition to the target access point is performed and no resource request is required before the transition, and the FT resource request protocol executed when a resource request is required before the transition. For an EP to perform a fast transition / handover from its current associated access point to the target access point using the FT protocols, message exchange can be performed using either the over-the-air method (where the EP communicates directly with the target AP using IEEE 802.11 authentication with an FT authentication algorithm) or the over-the-DS method (where the EP communicates with the target AP via its current local AP). Communication between the EP and the target AP can take place within FT action frames between the EP and its current local AP. Communication between the current AP and the target AP can be achieved via encapsulation methods, such as those described in section 13.10.3 of the IEEE 802.11 (2016) specification. The current local AP can switch between two encapsulation methods.
[0114] Fast Secure Roaming (FSR), based on the 802.11r amendment (officially called Fast BSS Transition), is the first IEEE-approved method for performing fast secure transitions between Wi-Fi access points. It works by having the client complete an initial successful 802.1X Extensible Authentication Protocol (EAP) authentication with the authentication server. The resulting Master Session Key (MSK) is then passed to the Wireless LAN Controller (WLC), as in other methods. However, this method differs in that it derives a slightly different key hierarchy. The Paired Master Key (PMK)-R0 is derived from the MSK, which is known only to the client and the WLC. PMK-R1 is derived from PMK-R0 and is known to the client and AP managed by the WLC that holds PMK-R0. The final layer is the Paired Transient Key (PTK), which is derived from the PMK-R1 protocol and is known to the client and AP managed by the WLC. Typically, APs managed by the WLC form a group called the FT Mobility Domain, which is essentially all APs with the same SSID. The IEEE 802.11r amendment does not define how PMK-R1 becomes known to other APs.
[0115] During initial authentication, the client performs full 802.1X authentication, completes a four-way handshake to derive a Paired Transient Key Security Association (PTKSA) with the AP (using PMK-R1 key material), and is then granted network access. When the client begins roaming, the client and the target AP derive a new key based on PMK-R1. This method is even more efficient because the four-way handshake occurs within the Open Systems Authentication (OSA) from the client, OSA from the AP, the re-association request, and the re-association response. This replaces the four-way handshake that occurs after these frames in other methods.
[0116] There is also a less-deployed variant of this technology called Fast BSS Transition over Distributed Systems (DS). Using this technique, once a client decides it might roam to another AP, it sends an FT Action Request frame to the original AP. The client indicates the MAC address of the target AP it wants to roam to. The original AP forwards the FT Action Request frame to the target AP via DS, and the target AP responds to the client with an FT Action Response frame (also via DS). Once this FT Action frame exchange is successful, the client has completed FT roaming. The client sends a reassociation request to the target AP in the air and receives a reassociation response from the new AP to confirm roaming and final key export. These last two messages are exchanged when the client finally roams to the target AP. Therefore, Fast Transition allows for faster roaming than static PMK caching.
[0117] Clearly, rapid handover is crucial for ensuring quality of service when endpoints are roaming in multi-cell networks. The design challenges in Li-Fi systems are even greater than in RF systems such as Wi-Fi, given the smaller optical cells and less overlapping areas in optical communication systems.
[0118] Figure 6 An endpoint 110 roaming in an optical multi-cell wireless communication network 100 is shown, along with the corresponding coverage areas of endpoint 110, associated access point 120, and neighboring access point 120. Multiple access points, including at least associated and candidate access points, are located on a first planar surface 410. In a typical application scenario, the first planar surface 410 is a ceiling. On the first planar surface 410, the coverage area 412 of the endpoint is shown by a dashed circle, covering the associated and neighboring access points. The endpoint is located on a second planar surface 420, which can be a floor, a table, a planar surface of another horizontal surface where the endpoint is located, or any arbitrary planar area where the endpoint roams with the user. On the second surface 420, the coverage area 422 of the associated and neighboring access points is shown by a shaded circle, and endpoint 110 is located in the overlapping area of these two coverage areas. Arrows indicate the direction of movement of the endpoint toward the neighboring access point and suggest a potential handover. Figure 6In this example, the identical coverage areas of the endpoints and access points are merely for illustrative purposes. Depending on the optical components used by the various access points and endpoints, the coverage area 422 of access point 120 and the coverage area 412 of endpoint 110 may differ. Furthermore, even if the optical components remain the same, the actual coverage area will vary with the distance between the first and second planar surfaces.
[0119] For ease of explanation, it is assumed here that each access point 120 includes a single optical front end, and each point on the first planar surface 410 represents a different access point 120. Therefore, a fast handover is always necessary when an endpoint roams into the coverage area of an adjacent access point 120. In another example, if an access point includes more than one optical front end, handover may be unnecessary when an endpoint roams within the coverage area of multiple optical front ends belonging to the same access point 120, which transmits the same information via multiple optical front ends.
[0120] Figure 7 A top-view view of the coverage of the first planar surface 410 and the second planar surface 420 is provided when the L1-Fi endpoint 110 is roaming in the optical multi-cell wireless communication network 100. It can be seen that, depending on the endpoint's movement trajectory, different neighboring access points can be potential candidate access points for handover. To derive information about the candidate access points, subsystems 500, 510, 510' need to first obtain one or more neighbor relationships among the multiple access points 120 in the optical multi-cell wireless communication network 100.
[0121] Figure 8The diagram illustrates message exchange for establishing one or more neighbor relationships in a centralized subsystem 500 via downlink advertisements from multiple access points 120. It is assumed that adjacent access points AP1 and AP2 are typically located on the same plane surface (first plane surface 410 shown in the figure), and the fields of view of AP1 and AP2 are projected onto the same second plane surface 420 where endpoint 110 is located. Therefore, there is no direct line-of-sight optical link between adjacent access points 120. Consequently, information related to neighbor relationships between multiple access points is not directly available. However, endpoint EP1, located in the overlapping area of two adjacent access points or two adjacent optical cells, is able to detect signals from both. In a preferred configuration, the access points periodically issue downlink advertisements DL-A, which may include a unique identifier of the access point to announce its presence. By detecting such a downlink advertisement DL-A from neighboring access point AP2 instead of the currently associated access point AP1, endpoint EP1 can send a report REP regarding the presence of neighboring access point AP2 to the currently associated access point AP1. The associated access point AP1 forwards the report REP to subsystem 500. As the endpoint and / or other endpoints roam through the area, subsystem 500 can establish a good profile of neighbor relationships among multiple access points over time. Subsystem 500 can be contained in a separate controller, such as a Li-Fi controller or central controller 13 within the system. The connection between the subsystem and the multiple access points is a backbone connection 21, which is a stable and high-speed link and, in some scenarios, can even be an always-connected link. The backbone connection can be a wired connection such as Ethernet, or a radio frequency (RF) or millimeter-wave-based wireless connection. The backbone connection can also be another type of optical wireless link, different from the link performed by the endpoints in an optical multi-cell wireless network. Such an example could be free-space optical communication.
[0122] Figure 9The diagram illustrates message exchange for establishing one or more neighbor relationships in a centralized subsystem 500 via uplink advertisements from endpoints. In this setup, endpoint EP1 is configured to issue an uplink advertisement UL-A, which may include the endpoint's unique identifier to announce its presence. This uplink advertisement UL-A is detected by the currently associated access point AP1 and the neighboring access point AP2, which is also located within the coverage area of the optical uplink from endpoint EP1. Therefore, neighboring access point AP2 will recognize from the received uplink advertisement UL-A that the endpoint is not associated with itself and will send a report REP to subsystem 500 directly related to this detection. Using the report REP from neighboring access point AP2 and knowledge of the association between endpoint EP1 and its currently associated access point AP1, subsystem 500 can derive the neighbor relationship between neighboring access point AP2 and the currently associated access point AP1 of endpoint EP1. With one or more endpoints roaming through the area, subsystem 500 can establish a good profile of neighbor relationships over time based on the uplink advertisements of one or more endpoints.
[0123] In another setup, distributed subsystems 510 and 510' are used for a relatively small-scale optical multi-cell wireless network 100. Figure 10 and Figure 11 The diagram illustrates message exchanges used to establish neighbor relationships in distributed subsystems 510 and 510' via downlink advertisements (DL-A) from multiple access points or uplink advertisements (UL-A) from endpoints. Distributed subsystems 510 and 510' may be contained within more than one access point 120. For ease of explanation, Figure 10 and Figure 11 An example is shown where portions of distributed subsystems 510 and 510' are respectively contained within the currently associated access point AP1 and the neighboring access point AP2. Alternatively, the distributed subsystem may be included in more than one of several access points besides AP1 and AP2. The multiple access points can be interconnected via a backbone connection 21, which can be wired (Ethernet) or wireless.
[0124] exist Figure 10 In this example, the currently associated access point AP1 receives a report REP from its associated endpoint EP1 regarding the presence of its neighboring access point AP2, and then forwards the report REP to distributed subsystems 510 and 510'. In this example, a portion of distributed subsystem 510 co-located with AP1, and another portion of distributed subsystem 510' is reachable via, for example, backbone connection 21. Neighboring APs can also be connected via free-space optical communication.
[0125] Similarly, in Figure 11In this process, neighboring access point AP2 receives an uplink advertisement UL-A from an endpoint EP1 that is not associated with it. AP2 will send a report REP to distributed subsystems 510 and 510'. Here, a part of distributed subsystem 510' is co-located with AP2, and another part of distributed subsystem 510 is reachable via backbone connection 21.
[0126] Having an overview of one or more neighbor relationships among multiple access points 120 in the network, subsystems 510, 510, 510' can select one or more neighboring access points as candidate access points for endpoints. However, the selection can be further improved by considering additional information, such as a map of the area and the location of access points in that area, statistics on the handover history of currently associated access points, or a combination of both.
[0127] Figure 12 A floor plan of a room with multiple access points deployed in the area is shown, along with potential movement paths 650 for roaming endpoints. Pattern-filled stripes indicate room boundaries, with openings indicating room entrances. Rectangular blocks 651 represent several pieces of furniture in the room, making certain movement paths less likely to occur. Sometimes, two access points may be positioned close to each other on the ceiling, and separation from a wall or a piece of furniture (such as a table or cabinet) may prevent potential switching from one access point to another, thus blocking downward movement paths on the second planar surface 420. Figure 12 In the example, we can see that the potential movement trajectory 650, represented by the dashed line, is rooted at the room entrance. Extending from the entrance is a corridor within the room, which is also the most frequently visited part of the room. Access points located on the corridor ceiling can also indicate several potential switches. Therefore, using additional information from the floor plan can help to more intelligently select one or more candidate access points.
[0128] Preferably, the selection of one or more candidate access points can be further improved by considering statistics regarding the handover history of currently associated access points, which can represent the probability distribution of previous handovers from the access point of interest to any adjacent access point. Due to room layout, user movement behavior, or other factors, handovers between some of two adjacent access points may occur more frequently than those between others. Higher probabilities in the past can indicate a greater chance of future handover events. Therefore, such statistics derived from the handover history can be used to improve the accuracy of the subsystem's selection of one or more candidate access points. Furthermore, since the statistics can be updated over time, this enables the subsystem to have self-learning capabilities and adapt to changes in user behavior within the system, environment, or network.
[0129] Given the relatively small coverage area of a single optical cell, several subsequent handovers are anticipated to be even more beneficial. These subsequent handovers include potential handovers from the currently associated access point to a direct neighbor, and one or more subsequent (potential) handovers from a direct neighbor to another non-adjacent neighbor and / or from another non-adjacent neighbor to an access point even further away. Therefore, by knowing several potential candidate access points for subsequent handovers, endpoints can pre-establish several pairs of security keys or pairs of instantaneous keys (far in advance), each dedicated to a different potential access point, resulting in a more seamless handover experience without the latency caused by security key provisioning.
[0130] Return to reference Figure 12 When an endpoint has just entered a room and is associated with the middle left access point closest to the entrance, three direct neighbors of the associated access point can be selected as candidate access points by assuming the endpoint will move left or right, and that the user moving the endpoint might subsequently sit at a table or move forward in the corridor area. Typically, an endpoint moves faster in the corridor than when it is resting on furniture. Therefore, it may also be beneficial to prepare for subsequent handovers to two other access points in the corridor area that are not direct neighbors of the associated access point, but rather other non-adjacent neighbors. This information can be derived from the floor plan and also from statistics of the handover history. For example, if the subsystem has a probability distribution of previous handovers from each of multiple access points to any of its adjacent access points, then each time a new subsequent access point is added, the probability of a handover from the new subsequent access point to its adjacent access points should be considered to make a decision about another further handover.
[0131] The statistical data model can be maintained in the form of a directed adjacency graph, where edge weights represent the transition probabilities between access points (APs) over time. Considering that the terminal devices connected to or contained within endpoints can be personal devices (such as mobile phones), a preferred solution is to determine this statistical data model aggregated across all endpoints and for each individual endpoint. The aggregated data can then be used for new or unknown devices in the system, as it captures the limitations of the physical world; and when sufficient data has been collected, individual terminal device data can capture the routing / behavior of a specific end-user.
[0132] Figure 13The basic components of the endpoint of the present invention are schematically depicted. Endpoint 110 includes at least an optical transceiver 117 and a controller 118. The optical transceiver 117 should be understood as a complete Li-Fi transceiver, which includes at least an optical front end 111, an analog front end 112, a digital modulator / demodulator 113, and an interface 114 to a terminal device connected to or included in the Li-Fi transceiver. The controller 118 may be a dedicated controller or a controller shared with the terminal device. The terminal device may optionally include a user interface 119, which may provide users with additional convenience for status inquiries or operation.
[0133] Figure 14 A flowchart of method 700, performed by subsystems 500, 510, 510', is shown to support endpoint 110 in performing a secure handover from the access point currently associated with endpoint 110 to another access point among a plurality of access points 120 in the optical multi-cell wireless communication network 100. Method 700 includes the following steps for subsystems 500, 510, and 510': In step S701, subsystems 500, 510, and 510' obtain neighbor relationships among multiple access points 120; based on the obtained neighbor relationships, in step S702, subsystems 500, 510, and 510' select candidate access points from the multiple access points 120 for endpoint 110's secure handover, in order to select such candidate access points for endpoint 110; and then in step S703, subsystems 500, 510, and 510' notify endpoint 110 about the candidate access points via the current associated access point to trigger endpoint 110 to begin the process of pre-establishing new pairwise transient keys between endpoint 110 and the candidate access points for secure handover.
[0134] Figure 15 A flowchart of method 800, performed by endpoint 110, is shown for performing a secure handover from an access point 120 currently associated with endpoint 110 to another access point among a plurality of access points 120 in an optical multi-cell wireless communication network 100. Method 800 includes the following steps for endpoint 110: in step S801, endpoint 110 performs optical wireless communication with the currently associated access point; in step S802, the endpoint secures the link by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point using a pairwise transient key; and then, when information related to a candidate access point is detected in step S803, in step S804, endpoint 110 triggers a process for pre-establishing a new pairwise transient key between endpoint 110 and the candidate access point for a secure handover, wherein this process is triggered before the actual secure handover to the candidate access point occurs.
[0135] The method according to the invention can be implemented on a computer as a computer-implemented method, or in dedicated hardware, or in a combination of both.
[0136] The executable code of the method according to the invention can be stored on a computer / machine-readable storage device. Examples of computer / machine-readable storage devices include non-volatile storage devices, optical storage media / devices, solid-state media, integrated circuits, servers, etc. Preferably, the computer program product includes non-transitory program code means stored on a computer-readable medium for executing the method according to the invention when the program product is executed on a computer.
[0137] Methods, systems, and computer-readable media (transitory and non-transitory) may also be provided to implement selected aspects of the above embodiments.
[0138] The term "controller" is used generally herein to describe various means relating to the operation of one or more network devices or coordinators—among other functions. A controller can be implemented in a variety of ways (e.g., such as with dedicated hardware) to perform the various functions discussed herein. A "processor" is an example of a controller employing one or more microprocessors, which can be programmed using software (e.g., microcode) to perform the various functions discussed herein. A controller can be implemented with or without a processor, and can also be implemented as a combination of dedicated hardware performing some functions and a processor (e.g., one or more programmed microprocessors and associated circuitry) performing other functions. Examples of controller components that can be employed in various embodiments of this disclosure include, but are not limited to, conventional microprocessors, application-specific integrated circuits (ASICs), and field-programmable gate arrays (FPGAs).
[0139] In various embodiments, the processor or controller may be associated with one or more storage media (collectively referred to herein as "memory," such as volatile and non-volatile computer memories, such as RAM, PROM, EPROM, and EEPROM, compact disks, optical disks, etc.). In some embodiments, the storage media may be encoded with one or more programs that, when executed on one or more processors and / or controllers, perform at least some of the functions discussed herein. Various storage media may be fixed within the processor or controller, or may be transportable, such that one or more programs stored thereon may be loaded into the processor or controller to implement various aspects of the invention discussed herein. The terms "program" or "computer program" are used herein in a general sense to refer to any type of computer code (e.g., software or microcode) that can be used to program one or more processors or controllers.
[0140] As used herein, the term “network” refers to any interconnection of two or more devices (including controllers or processors) that facilitates the transport of information (e.g., for device control, data storage, data exchange, etc.) between any two or more devices and / or between multiple devices coupled to the network.
Claims
1. A system for supporting an endpoint (110) to perform a secure handover from an access point (120) currently associated with the endpoint (110) to another access point (120) among a plurality of access points (120) in an optical multi-cell wireless communication network (100), the system comprising: Subsystems (500, 510, 510') are configured as follows: Obtain one or more neighbor relationships among the plurality of access points (120). Based on one or more neighbor relationships obtained, candidate access points (120) other than the currently associated access point (120) are selected from the plurality of access points (120) for the endpoint (110) for secure handover of the endpoint (110), and The endpoint (110) is notified about the candidate access point (120) via the current associated access point (120) to trigger the endpoint (110) to begin the process of pre-establishing a new pair of transient keys between the endpoint (110) and the candidate access point (120) for secure handover; The endpoint (110) includes: The optical transceiver (117) is configured to perform optical wireless communication. The controller (118) is configured as follows: - The link is protected by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point (120) using a pair of instantaneous keys; when the optical transceiver (117) receives information related to the candidate access point (120), a process is triggered to pre-establish the new pair of instantaneous keys between the endpoint (110) and the candidate access point (120) for secure handover; and wherein the process is triggered before the handover to the candidate access point (120) actually occurs; and The plurality of access points (120), including the currently associated access point (120) and the candidate access point (120), are configured to perform optical wireless communication with the endpoint (110) and are connected to each other via a backbone connection; And the subsystems (500, 510, 510') are either contained in one or more of the plurality of access points (120) or connected to the plurality of access points (120) via a backbone connection (21).
2. A subsystem (500, 510, 510') for supporting an endpoint (110) to perform a secure handover from an access point (120) currently associated with the endpoint (110) to another access point (120) among a plurality of access points (120) in an optical multi-cell wireless communication network (100), the subsystem (500, 510, 510') being configured to: - Obtain one or more neighbor relationships among the plurality of access points (120); - Based on one or more obtained neighbor relationships, select candidate access points (120) from the plurality of access points (120) for the endpoint (110) other than the currently associated access point (120) for secure handover of the endpoint (110); and - The endpoint (110) is notified about the candidate access point (120) via the current associated access point (120) to trigger the endpoint (110) to begin the process of pre-establishing a new pair of transient keys between the endpoint (110) and the candidate access point (120) for secure switching.
3. The subsystem according to claim 2, wherein the subsystem is a centralized subsystem (500) included in a central controller (13), and wherein the central controller (13) is configured to communicate with the plurality of access points (120) via a backbone connection (21).
4. The subsystem according to claim 2, wherein the subsystem (510, 510') is a distributed subsystem contained in one or more of the plurality of access points (120), and wherein the plurality of access points (120) are configured to communicate with each other via a backbone connection (21).
5. The subsystem (500, 510, 510') according to any one of claims 2-4, wherein one of the one or more neighbor relationships is obtained by detecting downlink advertisements from neighbor access points other than the associated access point by the endpoint (110) and / or another endpoint (110) located in the overlapping area of the respective adjacent access point and the respective associated access point, and wherein the detection is reported to the subsystem (500, 510, 510') via the respective associated access point.
6. The subsystem (500, 510, 510') according to any one of claims 2-4, wherein one of the one or more neighbor relationships is obtained by detecting uplink advertisements from the endpoint (110) and / or the other endpoint (110) by another access point among the plurality of access points (120), and wherein the endpoint (110) and / or the other endpoint (110) is not associated with the other access point, and wherein the detection by the other access point is reported to the subsystem (500, 510, 510').
7. The subsystem (500, 510, 510') according to any one of claims 2-4, wherein the candidate access points are selected by taking into account a plan view of the layout of the area where the plurality of access points (120) are located and the spatial location of the plurality of access points (120) in the area.
8. The subsystem (500, 510, 510') according to any one of claims 2-4, wherein the candidate access point is selected by taking into account statistics regarding the switching between the currently associated access point and other access points among the plurality of access points (120).
9. The subsystem (500, 510, 510') according to any one of claims 2-4, wherein more than one candidate access point is selected, which includes at least the direct neighbors and non-adjacent neighbors of the currently associated access point, and The non-adjacent neighbor is adjacent to the direct neighbor.
10. An endpoint (110) for performing a secure handover from an access point currently associated with the endpoint to another access point among a plurality of access points (120) in an optical multi-cell wireless communication network (100), the endpoint (110) comprising: An optical transceiver (117) is configured to perform optical wireless communication; The controller (118) is configured to: - Protect the link by using paired instantaneous keys to encrypt or decrypt data transmitted on the optical wireless communication link with the currently associated access point; as well as When the optical transceiver (117) receives information related to a candidate access point, it triggers a process for pre-establishing a new pair of instantaneous keys between the endpoint (110) and the candidate access point for a secure handover; and wherein the process is triggered before the handover to the candidate access point actually occurs, wherein the candidate access point includes access points selected from the plurality of access points, other than the currently associated access point, for the secure handover based on the neighbor relationships among the plurality of access points.
11. The endpoint (110) of claim 10, wherein the optical transceiver is further configured to send a report to the current associated access point when a downlink advertisement from a neighboring access point other than the current associated access point is detected.
12. The endpoint (110) of claim 10, wherein the optical transceiver is further configured to send an uplink announcement regarding the presence of the endpoint (110).
13. A method (700) for supporting an endpoint to perform a secure handover from an access point currently associated with the endpoint (110) to another access point among a plurality of access points (120) in an optical multi-cell wireless communication network (100). The method (700) includes the following steps in the subsystem (500, 510, 510'): - Obtain (S701) the neighbor relationships among the plurality of access points (120); - Based on the obtained neighbor relationships, select (S702) candidate access points from the plurality of access points (120) for the endpoint (110) other than the currently associated access point, for secure handover of the endpoint (110); and - The endpoint (110) is notified (S703) about the candidate access point via the current associated access point to trigger the endpoint (110) to begin the process of pre-establishing a new pair of transient keys between the endpoint (110) and the candidate access point for secure handover.
14. A method (800) for performing a secure handover of said endpoint (110) from an access point currently associated with said endpoint (110) to another access point among a plurality of access points (120) in an optical multi-cell wireless communication network (100), said method (800) comprising the following steps of said endpoint (110): - Perform optical wireless communication with the currently associated access point (S801); - Protect the link (S802) by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point using a pair of instantaneous keys; - Upon detecting (S803) information related to a candidate access point, a process (S804) is triggered to pre-establish a new pair of transient keys between the endpoint (110) and the candidate access point for a secure handover, wherein the process is triggered before the actual secure handover to the candidate access point occurs. The candidate access points include access points selected from the plurality of access points based on the neighbor relationships among the plurality of access points, other than the currently associated access point, for the secure handover.
15. A computer program product comprising code means that, when the computer program product is executed by a subsystem (500, 510, 510') or an endpoint (110) including a processing means, the code means causes the processing means to perform the method of claim 13 or 14.
Citation Information
Patent Citations
Secure authentication advertisement protocol
US20060130126A1
System and method for providing a wireless communication with a mobile device
US20180254826A1