Fast and safe handover

By introducing an endpoint subsystem into the Li-Fi network and utilizing the collaborative work of the host processor and controller, the latency problem in access point handover of network devices is solved, enabling fast and secure access point handover and improving the handover efficiency of network devices in multi-cell wireless communication networks.

CN115211154BActive Publication Date: 2026-04-17SIGNIFY HOLDING BV
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SIGNIFY HOLDING BV
Filing Date
2021-03-01
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

In Li-Fi networks, existing technologies suffer from latency issues during the handover process from one access point to another, especially in IoT applications. This is particularly true due to the small coverage area of ​​optical access points and the small overlap between adjacent cells, which necessitates faster handover for mobile endpoints.

Method used

An endpoint subsystem is introduced, including a host processor and a controller. The host processor acts as the first requester to establish an initial pairwise transient key, and the controller acts as the second requester to communicate with the authenticator. New pairwise transient keys are derived by using the activated pairwise transient key, reducing latency.

Benefits of technology

It enables faster and more secure access point handover in Li-Fi networks, reduces latency in the key export process, and improves the handover efficiency of network devices in multi-cell wireless communication networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115211154B_ABST
    Figure CN115211154B_ABST
Patent Text Reader

Abstract

Due to the line-of-sight nature of optical wireless communication and the limited field of view of optical receivers, the coverage of an access point and the overlapping coverage area of neighboring access points in an optical multi-cell wireless communication network is smaller compared to RF systems. Supporting secure roaming of an endpoint (110) in an optical multi-cell wireless communication network becomes more challenging. To speed up the derivation of a new pairwise transient key with a new access point during a handover procedure, the endpoint of the present invention comprises a controller (118) configured to act as a second requestor (1181) on behalf of a first requestor (1186) comprised in a host processor (1185) to communicate with an authentication party to establish a new pairwise transient key for the endpoint (110) and a candidate access point, and the active pairwise transient key with the currently associated access point is used to protect the communication of the new key derivation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of roaming of network devices in optical wireless networks such as Li-Fi networks. More particularly, this document discloses various methods, apparatuses, systems, and computer-readable media related to helping network devices securely and quickly switch from one access point to another. Background Technology

[0002] To enable a growing number of electronic devices, such as laptops, tablets, and smartphones, to wirelessly connect to the internet, wireless communication faces unprecedented demands for data rates and link quality, and these demands continue to grow year after year, given the emerging digital revolution associated with the Internet of Things (IoT). Radio frequency (RF) technologies, such as Wi-Fi, have limited spectrum capacity and cannot meet this demand. Meanwhile, Light Fidelity (Li-Fi) is attracting increasing attention due to its inherent enhanced security and ability to support higher data rates across the available bandwidth of the visible, ultraviolet (UV), and infrared (IR) spectra. Furthermore, compared to Wi-Fi, Li-Fi is directional and shielded by light-blocking materials, making it possible to deploy a larger number of access points in densely populated areas by spatially reusing the same bandwidth. These key advantages compared to wireless RF communication make Li-Fi a promising solution for alleviating the congested radio spectrum pressures of IoT applications. Other benefits of Li-Fi include guaranteed bandwidth for specific users and the ability to operate safely in areas susceptible to electromagnetic interference. Therefore, Li-Fi is a very promising technology for enabling next-generation immersive connectivity.

[0003] Several related terms exist in the field of lighting-based communications. Visible light communication (VLC) transmits data via intensity-modulated light sources such as light-emitting diodes (LEDs) and laser diodes (LDs), faster than the persistence of the human eye. VLC is typically used to embed signals into light emitted by a lighting source, such as an everyday lamp, for example, indoor or outdoor lighting, thus allowing the lighting from the lamp to serve as a carrier of information. Therefore, the light can include a visible lighting component used to illuminate a target environment such as a room (often the primary purpose of light), and an embedded signal used to provide information to the environment (often considered a secondary function of light). In this case, modulation can typically be performed at a sufficiently high frequency to exceed human perception, or at least make any visible transient light artifacts (such as flicker and / or stroboscopic artifacts) sufficiently weak and not noticeable or at least tolerable to humans at a sufficiently high frequency. Therefore, the embedded signal does not affect the primary lighting function; that is, the user only perceives the overall lighting, not the effect of the data modulated into that lighting.

[0004] The IEEE 802.15.7 Visible Light Communication Personal Area Network (VPAN) standard maps anticipated applications to four topologies: peer-to-peer, star, broadcast, and coordinated. Optical Wireless PAN (OWPAN) is a more general term than VPAN, as it also allows communication over invisible light, such as UV and IR. Therefore, Li-Fi is often considered a derivative of Optical Wireless Communication (OWC) technology, which utilizes a wide range of spectra to support bidirectional data communication.

[0005] In Li-Fi systems, signals are embedded by modulating the properties (typically intensity) of light, using any of a variety of suitable modulation techniques. For high-speed communication, infrared (IR) is often used instead of visible light. Although ultraviolet and infrared radiation are invisible to the human eye, the techniques for utilizing these spectral regions are the same, although variations can occur as a result of wavelength dependence (such as in the case of refractive index). In many instances, using ultraviolet and / or infrared is advantageous because these frequency ranges are invisible to the human eye and can introduce more flexibility into the system. Of course, ultraviolet quanta have higher energy levels than infrared and / or visible light, which in turn may make the use of ultraviolet light undesirable in certain situations.

[0006] Based on modulation, any suitable light sensor can be used to detect information in light. For example, a light sensor can be a photodiode. A light sensor can be a dedicated photocell (point detector), a photocell array possibly with lenses, reflectors, diffusers, or phosphor converters (for lower speeds), or a photocell (pixel) array and lenses for forming an image on the array. For example, a light sensor can be a dedicated photocell included in a dongle inserted into a user device such as a smartphone, tablet, or laptop, or the sensor can be integrated and / or dual-purpose, such as an infrared detector array originally designed for 3D facial recognition. Either way, this allows applications running on the user device to receive data via light.

[0007] In the following text, the term "access point" in Li-Fi systems is used to refer to a logical access device that can be connected to one or more physical access devices (such as optical transceivers). Such physical access devices are typically (but not necessarily) located at lighting fixtures, and a logical access point can be connected to one or more physical access devices, each located at one or more lighting fixtures. The access point serves one or more network devices or associated terminal devices to form an optical cell.

[0008] Compared to radio frequency (RF) based communication systems, Li-Fi inherently offers the advantage of reduced eavesdropping opportunities due to the physical nature of optical links, which require line-of-sight communication. In addition to this inherent advantage, security aspects of Li-Fi systems can be further enhanced by introducing dedicated security measures such as authentication and encryption.

[0009] Extensible Authentication Protocol (EAP) is an authentication framework commonly used for wireless network and internet connections. The IEEE 802.1X standard defines how to provide authentication for devices attempting to connect to other devices on a LAN or wireless LAN (WLAN), specifying the EAP encapsulation over the IEEE 802 standard. Therefore, IEEE 802.1X is also known as "EAP over LAN or WLAN". IEEE 802.1X authentication involves three parties: the requester, the authenticator, and the authentication server. The requester is the client or terminal device wishing to access the LAN / WLAN. The authenticator is a network device that provides a data link between the client and the network and can allow or block network traffic between them, such as an Ethernet switch or wireless access point. The authentication server is typically a trusted server that receives and responds to network access requests from clients and can inform the authenticator whether to allow the connection, as well as various settings that should be applied to the client's connection or settings. The authentication server typically runs software that supports Remote Authentication Dial-In User Service (RADIUS) and the EAP protocol.

[0010] To generate encryption keys to encrypt actual data, a four-way handshake is typically required to exchange four messages between the authenticator and the client device or requester. Different keys may be used depending on the type of communication. The Master Session Key (MSK) is the first key generated from IEEE 802.1X / EAP, or the first key derived from the Pre-Shared Key (PSK) authentication. The Group Transient Key (GTK) is used to encrypt all broadcast and multicast traffic between the access point and multiple client devices; it is shared among multiple client devices and one access point. The Paired Transient Key (PTK) is used to encrypt all unicast traffic between the client station and the access point. Therefore, the PTK is unique between the client station and the access point. The Paired Master Key (PMK) is a key generated from the Master Session Key (MSK), and the PTK depends on the PMK. Similarly, the Group Master Key (GMK) is also generated from the Master Session Key (MSK), and the GTK depends on the GMK.

[0011] However, the authentication and security key establishment processes introduce additional latency when a network device first establishes a link in the network, or when it roams from one cell to another. Furthermore, this additional latency can be even more problematic if the network device is in the middle of a communication session during a handover from one cell to another.

[0012] The performance study of fast BSS transition using IEEE 802.11r by Sangeetha Bangolae et al. involved the evaluation of WLAN roaming capabilities affected by the IEEE 802.11r standard. Summary of the Invention

[0013] Due to the line-of-sight characteristics of optical wireless communication and the limited field of view (FoV) of optical receivers, the coverage area of ​​access points (APs) and the overlapping coverage area of ​​adjacent APs in optical systems are smaller compared to RF-based systems. Because of the small coverage area of ​​each optical access point or each optical cell, and because of the need to reduce mutual interference between adjacent access points, the overlapping coverage area of ​​adjacent cells in such optical systems is also typically small. Therefore, mobile endpoints in optical wireless networks will require faster transitions (e.g., handovers) between access points compared to RF-based networks or other types of cellular networks with large coverage areas and large overlap areas per access point. Consequently, supporting endpoints to perform secure and smooth handovers from one optical access point to another becomes more challenging.

[0014] Based on the above, this disclosure relates to methods, apparatus, systems, computer programs, and computer-readable media for providing a mechanism to support a fast and secure handover of an endpoint (EP) from an access point (AP) currently associated with that EP to another AP among a plurality of APs. More particularly, the object of the invention is achieved by the aforementioned endpoint subsystem, the aforementioned system, the aforementioned method for the endpoint subsystem, and the aforementioned computer program.

[0015] Therefore, in order to accelerate the derivation of a new pairwise transient key or a new pairwise security key with a new access point during the handover process, the endpoint subsystem of the present invention includes: a host processor configured to act as a first requester to establish an initial pairwise transient key or an initial pairwise security key for the endpoint subsystem; and a controller configured to act as a second requester to communicate with an authenticator to establish a new pairwise transient key for the endpoint subsystem and the candidate access point, and to derive the new key using the active pairwise transient key of the currently associated access point in the communication.

[0016] According to a first aspect of the invention, an endpoint subsystem is provided. The endpoint subsystem is used to perform a secure handover from an access point currently associated with the endpoint subsystem to another access point among a plurality of access points in an optical multi-cell wireless communication network. The endpoint subsystem includes: an optical transceiver configured to perform optical wireless communication; a controller configured to secure the link by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point using a pairwise transient key; and a host processor configured to act as a first requester to perform a first process for establishing an initial pairwise transient key with an authenticator for the endpoint subsystem in the optical multi-cell wireless communication network. The controller is also configured to act as a second requester to prepare for a secure handover to candidate access points among the plurality of access points by performing a second process for establishing a new pairwise transient key for the endpoint subsystem and the candidate access point using the authenticator. The host processor is further configured to provide the controller with the initial pairwise transient key for use as a pairwise transient key when the endpoint subsystem does not have a secure connection.

[0017] For IoT applications, optical wireless communication or Li-Fi has been proposed as a supplement or even replacement technology for wired connections or radio-based wireless communication to enable electronic devices or terminal devices to support higher data rate communications. Endpoint subsystems can be connected or communicated to such terminal devices as separate entities, or partially or fully integrated into the terminal devices. Terminal devices can be smartphones, tablets, computers, remote controls, smart TVs, display devices, storage devices, home appliances, or other smart electronic devices, which may already have one or more mature communication interfaces based on short-range wireless communication protocols (Wi-Fi / BLE / Zigbee), cellular communication protocols (3G / 4G / 5G), or wired communication protocols (Ethernet). Sharing the same security infrastructure between Li-Fi networks and existing, more traditional communication networks is convenient. Therefore, it is also preferable that Li-Fi systems follow authentication and key establishment protocols similar to those in existing communication networks.

[0018] Wi-Fi is one of the most widely used wireless communication technologies for local area networks (LANs). Wi-Fi networks are deployed almost everywhere: homes, offices, buses, trains, stations, airports, stadiums, and the like. Therefore, it is advantageous to integrate Li-Fi security infrastructure into existing IT infrastructure, such as Wi-Fi compliant IT infrastructure.

[0019] For the traditional four-way handshake in a Wi-Fi system, deriving a Paired Transient Key (PTK) involves two parties: an authenticator and a requester. The authenticator can be located in one of the access points or in the central controller. The requester typically runs on the host processor of the terminal or client device. Each time a new PTK is derived, the requester needs knowledge of the PMK generated from the master session key. The host processor is the central processing unit or main processor of an electronic device that processes and executes instructions from the user and assigns certain tasks derived from those instructions to other dedicated processors or controllers within the electronic device. Assuming the host processor can perform many tasks (such as similar functions of an operating system) and can also support one or more other communication interfaces besides Li-Fi, the information associated with the PMK included in the host processor may not always be available to the endpoint or in a timely manner. On the other hand, latency requirements involved in handover processes in optical multi-cell networks are critical. Therefore, it is advantageous to introduce a second requester in the dedicated controller of the endpoint to accelerate the key derivation process.

[0020] The endpoint subsystem includes a host processor configured to act as a first requester to perform a first procedure for establishing an initial PTK. The host processor may be dedicated to the endpoint subsystem, or it may be the same host processor shared with an end device to which the endpoint subsystem is connected, communicatively coupled, or partially or wholly integrated. The first procedure may be a conventional method for deriving a security key, such as a Wi-Fi four-way handshake in another communication system. Similar to the second procedure disclosed in this invention, the first procedure may also be a modified variant compared to conventional methods, and one difference may be that the host processor utilizes a PMK to derive the initial PTK.

[0021] The communication or signaling exchange in the first process can be performed via the same optical multi-cell wireless communication network. Alternatively, the first process can be performed via another communication system (short-range wireless communication, cellular communication, or Ethernet), provided it is supported by the terminal device, to which the endpoint subsystem is connected, or partially or wholly integrated. In the first process, the host processor obtains the initial PTK. When the endpoint subsystem does not have a secure connection, the host processor is also configured to provide the initial PTK to the controller as an activation PTK for use in protecting data communication on the optical link.

[0022] The controller of the endpoint can be a processor, one or more microprocessors, or special-purpose hardware such as application-specific integrated circuits (ASICs) and field-programmable gate arrays (FPGAs). Alternatively, the controller can also be a modem included in the optical transceiver.

[0023] The endpoint's controller is configured to use a PTK (Presentation Point Kernel) to encrypt or decrypt data transmitted over the optical wireless link. When the endpoint enters an area of ​​an optical multi-cell wireless network, the controller can use an initial PTK established by the host processor as the active PTK for the initial establishment of a secure optical link. However, in the case of establishing an initial PTK between the host processor and another access point besides the currently associated access point, the endpoint can use a second process to establish a new PTK with the currently associated access point based on the knowledge of the initial PTK to protect the optical link. Therefore, the endpoint can first establish an optical link with the associated access point without additional security measures, and then it can use the initial PTK provided by the host processor to derive a new PTK to protect the ongoing optical link with the associated access point, which may be derived via another communication network and possibly with another access point in that other communication network.

[0024] To prepare for a potential switch from the currently associated access point to a candidate access point, the controller is configured to act as a second requester to expedite the process of deriving a new PTK or security key. Unlike the host processor, the controller is more dedicated to the endpoint or optical communication, and can primarily handle key establishment and digital processing of the optical link, such as digital signal conditioning, modulation, and demodulation. Therefore, the endpoint controller can respond more quickly to operations related to new key establishment (such as in the second process) compared to the host processor.

[0025] Another advantage of using a controller as a second requester to prepare a new PTK for a candidate access point is that, given that the host processor can be shared with the terminal device—whether the endpoint is connected to that terminal device or is partially or fully integrated into it—it is often necessary to maintain the first process in accordance with the conventional or standard methods used by another communication interface supported by the terminal device. More flexible is the ability to define or customize the second process performed by a controller dedicated to optical communications, thereby establishing a new PTK in a rapid and efficient manner.

[0026] In one embodiment, the optical transceiver is further configured to receive information related to a candidate access point from the currently associated access point or a candidate access point; and when information related to a candidate access point is received, to trigger the controller to initiate a second process.

[0027] Because a new PTK is established between the endpoint and the candidate access point, information related to the candidate access point (such as the candidate access point's unique identifier) ​​can be received by the endpoint from the currently associated access point, or it can be obtained directly from the candidate access point.

[0028] When a central controller or Li-Fi controller is present in an optical wireless communication network, this handover can be controlled centrally. The central controller or Li-Fi controller has a good understanding of the deployment of multiple access points and the associations between endpoints and their currently associated access points. Based on this, the central controller can also provide recommendations regarding potential handovers of endpoints to candidate access points. Multiple access points are typically connected to the central controller or Li-Fi controller via a high-speed and reliable backbone connection, which can be wired or wireless. The endpoint can then receive these recommendations regarding candidate access points from the central controller or Li-Fi controller via its currently associated access point.

[0029] An endpoint may also enter the overlapping area between the associated access point and the candidate access point. Then, the endpoint can initiate a second process upon detecting downlink communication from the candidate access point.

[0030] In a further embodiment, the information associated with the candidate access point is the downlink advertisement received from the candidate access point.

[0031] In this example, multiple access points issue downlink advertisements to announce their existence, which may include their identification information. When an endpoint roams into an overlapping area of ​​the currently associated access point and candidate access points, the endpoint can calculate the existence of the candidate access point upon receiving such an advertisement and begin a second process to prepare a new security key or PTK for the candidate access point.

[0032] Advantageously, the optical transceiver is also configured to compare the link quality of the optical wireless communication links with the currently associated access point and the candidate access point, respectively; based on the comparison of the link quality, the controller is triggered to begin switching to the candidate access point.

[0033] The actual handover timing can be determined by the endpoint itself based on its assessment of the link quality with the currently associated access point and the candidate access point, respectively. The handover can be either hard or soft. A hard handover means that at any given time, the endpoint may be associated with only one access point. A soft handover indicates that the endpoint can be associated with both access points simultaneously, and data communicated with the earlier associated access point and the candidate access point can even be combined.

[0034] Link quality is an indication of the quality of packets received on a link, which can be derived from the received signal strength. To estimate the link quality with a candidate access point before an actual handover, an endpoint can measure the received signal strength of downlink advertisements from the candidate access point, or the received signal strength of another downlink communication heard by the endpoint from the candidate access point. One criterion for comparing link quality could be that the endpoint chooses to establish an optical link with the access point that has the better link quality. Another criterion could be that the endpoint will not handover to the candidate access point as long as the link quality of the connection to the currently associated access point is not lower than a certain threshold. Yet another criterion could be that the endpoint hands over to the candidate access point when the link quality of the signal received from the candidate access point is higher than a certain threshold. Yet yet another criterion could be that the endpoint maintains the existing link and simultaneously establishes a new link, where soft handover can occur, as long as the link quality of both the existing link and the new link is higher than a certain threshold.

[0035] In another embodiment, a pairwise transient key between the endpoint subsystem and the currently associated access point is used in a second process to establish a new pairwise transient key.

[0036] As disclosed above, in a conventional system, the requesting party needs to use knowledge of the PMK to derive a new PTK. However, information related to the PMK is typically contained within the host processor and may not always be or timely available to the endpoint subsystem. Because the controller always has an available or active PTK when a secure optical connection to the endpoint subsystem is present, it is advantageous in the second process to use an active PTK directly available to the controller to derive a new PTK or new security key for the candidate access point. This reduces the chance of any additional delays due to obtaining the PMK.

[0037] In a preferred configuration, the optical transceiver and controller are included in a single housing attached to a device including a host processor.

[0038] When the endpoint subsystem is connected to, communicates with, or is partially integrated into a device / terminal device / mobile device, it is advantageous that the optical transceiver and controller are contained in a single housing, such as a pluggable small device like a dongle, while the host processor is a shared processor included within the device / terminal device / mobile device. Therefore, the initial PTK establishment can be handled by the device / terminal device / mobile device using conventional methods—such as via a Wi-Fi link, Ethernet connection, or cellular connection. Once the Li-Fi dongle obtains the initial PTK used when the optical link was first established, it can independently establish a new PTK using a customized second process without further interaction with the device / terminal device / mobile device's host processor. This is because in the second process, only the active PTK currently used by the controller is used to derive the new PTK. This setup provides significant system flexibility.

[0039] Alternatively, the optical transceiver, controller, and host processor are housed in the same enclosure, thus making the endpoint subsystem an endpoint device. The host processor will be more dedicated to application-layer processing for the endpoint device, while the controller will be dedicated to optical communication-related processing.

[0040] According to a second aspect of the invention, a system is provided. A system for supporting the aforementioned endpoint subsystem to perform a secure handover from an access point currently associated with the endpoint subsystem to another access point among a plurality of access points in an optical multi-cell wireless communication network, the system comprising: an endpoint subsystem; a plurality of access points including the currently associated access point and candidate access points, configured to perform optical wireless communication with the endpoint subsystem and connected to each other via a backbone connection and / or connected to a central controller; and an authenticator configured to perform a first process with a first requester and a second process with a second requester, wherein the first and second requesters are included in the endpoint subsystem.

[0041] Advantageously, the endpoint subsystem discloses two requesters. The first requester is included in a host processor configured to establish an initial PTK or initial security key via an optical wireless link, such as in an optical multi-cell network, or via an alternative mode such as an RF-based wireless link or a wired connection. The second requester is included in a controller that can be dedicated to optical wireless communication and can respond more quickly to the need to initiate a second process. Therefore, splitting the single requester for each client or terminal device in a traditional system into a first and a second requester accelerates the process of establishing a new PTK or new security key, which helps to achieve a more seamless handover experience in optical multi-cell wireless networks by reducing latency caused by security key provisioning.

[0042] Note that the connections between multiple access points and between access points and the central controller constitute the backbone connection. This backbone connection is a stable and high-speed link, and in some scenarios, it can even be an always-connected link. The backbone connection can be a wired connection such as Ethernet, or a radio frequency (RF) or millimeter-wave based wireless connection. The backbone connection can also be another type of optical wireless link, distinct from the link performed by the endpoints in an optical multi-cell wireless network. An example of this is free-space optical communication.

[0043] In one embodiment, the authenticator is included in a central controller connected to multiple access points via a backbone connection.

[0044] It is possible to deploy the authenticator in a central controller or Li-Fi controller, similar to a centralized approach. Multiple access points are connected to the central controller or Li-Fi controller via a backbone connection. This centralized setup is preferred for large optical multi-cell networks with a large number of access points, but can also be beneficial even in smaller systems. As disclosed above, the backbone connection is a stable and high-speed link, and in some scenarios, it can even be an always-connected link. Therefore, all access points can reach the authenticator included in the central controller quickly and efficiently via the backbone connection.

[0045] Leveraging the centralized deployment of the authenticator, and considering the optical link established between the endpoint and the currently associated access point, as well as the backbone connection between the currently associated access point and the central controller, the second requester included in the endpoint can communicate with the authenticator via the currently associated access point. Therefore, the logical connection between the endpoint and the authenticator is ready for use.

[0046] In another embodiment, the authenticator is included in one of a plurality of access points, and the access point is configured to communicate with other access points in the plurality of access points via a backbone connection.

[0047] Alternatively, similar to a distributed approach, the authenticator can be deployed across one or more access points, interconnected via a reliable and high-speed backbone. The associated access points then coordinate to perform the authenticator's functions collectively. The advantage of this distributed approach is that it eliminates the need for a dedicated central device or controller and is more flexible and convenient to implement. Therefore, it is the preferred choice for small-scale systems, saving the additional cost of deploying a dedicated central device or controller.

[0048] However, as the network scales, the complexity of coordinating one or more related access points and the resources required for a single access point to handle authenticator functionality can also increase considerably. Therefore, it may become less efficient compared to a centralized approach. Initially, a distributed approach can support gradual network growth by providing authenticator functionality within one or more access points. As the network scales, the local authenticator functionality of the related one or more access points can be disabled, and correspondingly, a central controller or Li-Fi controller, including a centralized authenticator, can be added to the network to reduce the overhead of the related one or more access points.

[0049] Similar to a centralized approach, a second requester included in the endpoint can communicate with the authenticator via the currently associated access point. The logical link between the endpoint and the authenticator can primarily include an optical link between the endpoint and the currently associated access point, and secondarily include a backbone connection between the currently associated access point and another access point where the authenticator resides. If the currently associated access point also includes authenticator functionality, the second requester can communicate directly with the authenticator via the optical link.

[0050] Advantageously, the certifier is also configured to provide new pairwise transient keys to candidate access points.

[0051] Regardless of whether the authenticator is implemented using a centralized or distributed approach, it is advantageous that the authenticator can proactively provide new pairwise transient keys (PTKs) to candidate access points, such as when generating a new PTK and before the actual handover occurs. It is also possible that the authenticator will send the new PTK at a later stage upon receiving notification from a previously associated or candidate access point, either just before the handover is about to occur or even shortly after it has occurred.

[0052] In another example, the second process for establishing a new PTK also triggers or even includes a resource request to the candidate access point to allocate resources (such as time slots, frequency channels, or wavelengths) to the endpoint for post-handover communication. It is likely preferable to provide the new PTK to the candidate access point only if the candidate access point allows resource allocation. It is also possible for the new PTK to be provided to the candidate access point in any way during its generation. Often, this PTK may have a certain lifetime or validity period, and the new PTK will only be effectively used if a handover occurs within its lifetime or validity period. Otherwise, the pre-established new PTK will simply expire and be deleted by the controller.

[0053] According to a third aspect of the present invention, a method for an endpoint subsystem is provided. A method for an endpoint subsystem to perform a secure handover from an access point currently associated with the endpoint subsystem to another access point among a plurality of access points in an optical multi-cell wireless communication network, the method comprising the following steps of the endpoint subsystem:

[0054] - Perform optical wireless communication;

[0055] - Protect the optical wireless communication link with the currently associated access point by using paired instantaneous keys to encrypt or decrypt data transmitted on the link;

[0056] - Act as the first requester to perform the first process, which is used to establish an initial pair of transient keys between the endpoint subsystem and the authenticator;

[0057] - Act as a second requester to prepare for a secure handover to candidate access points among multiple access points by performing a second process, which is used to establish new pairwise transient keys for the endpoint subsystem and candidate access points using the authenticator;

[0058] - When the endpoint subsystem has no secure connection, provide the controller with an initial pair of transient keys to be used as a pair of transient keys.

[0059] As an example of one way to practice the invention, the first process can be a conventional or standard process executed by the host processor, acting as the first requester, to establish an initial PTK. This process can, but does not necessarily, be performed via an optical link in an optical multi-cell network. It is assumed that the host processor can be shared with terminal devices / mobile devices and is not dedicated to the endpoint subsystem for optical communication, or that the host processor has already established a secure link via another communication technology (wired or wireless). To assist the endpoint subsystem in establishing a secure optical link, the host processor provides the initial PTK to the endpoint's controller. When establishing an initial PTK between the endpoint subsystem and the same associated L1-Fi access point, the controller will directly use the initial PTK to encrypt and decrypt data on the optical link with the associated access point. Otherwise, the controller will use the initial PTK via a second process to generate a new PTK for the associated access point. Therefore, whenever the endpoint has a secure optical link, the endpoint's controller, which can be dedicated to signal processing and digital control for optical communication, always uses the active PTK. To prepare for a potential handover, it is advantageous for the controller, acting as the second requester, to perform a second process on behalf of the endpoint to establish a new PTK for the endpoint and the candidate access point by using the activated PTK in this second process. Therefore, unlike conventional methods, the controller no longer interacts with the host processor to obtain the PMK in order to derive the new PTK in this second process. Furthermore, assuming the controller is more dedicated to optical communication and is ready in a timely manner for operations related to optical communication, using the controller, rather than the host processor, as the requester on behalf of the endpoint helps to further reduce the additional latency introduced by the security key supply. Preferably, the second process is performed before the handover actually occurs. With the new PTK in use, the optical link between the terminal and the candidate access point can be protected in secure mode from the outset.

[0060] Preferably, the second process includes the following steps by the second requester:

[0061] - Send a request to the authenticator, which includes at least a first random number, a first frame count, and a first message integrity code derived based on a pair of transient keys;

[0062] - Receive confirmation from the authenticator, which includes at least a second random number, a second frame count, and a second message integrity code derived from the new pairwise transient key;

[0063] - Extract a second random number from the received confirmation;

[0064] - Derive a new local pairwise instantaneous key based on the extracted second random number;

[0065] - Generate local message integrity code based on a new pairwise transient key exported locally;

[0066] - Verify the second frame count and the second message integrity code by comparing the first frame count with the local message integrity code;

[0067] - After successfully verifying the second frame count and the second message integrity code, a new pairwise transient key derived locally is used as the new pairwise transient key.

[0068] Compared to the traditional four-way handshake in Wi-Fi systems, the second process performed by the second requester is a customized handshake to derive a new PTK for potential handover in optical multi-cell wireless networks. As disclosed above, the second process can be triggered by the front end of the endpoint itself upon detecting downlink communication from the candidate access point, or by messages about the candidate access point received from the central controller via the currently associated access point. If information related to the candidate access point is available, the second requester can trigger a handshake to establish a new session key or a new transient key.

[0069] Communication between the second requester and the authenticator occurs via a logical link between the endpoint subsystem and the authenticator. This logical link may be located in the central controller or Li-Fi controller, or in one or more access points. Therefore, the logical link between the endpoint subsystem and the authenticator may include more than one physical link, such as, firstly, an optical link between the endpoint subsystem and the currently associated access point, and secondly, a backbone connection between the currently associated access point and another access point where the central controller or authenticator functionality resides.

[0070] To protect the request message sent to the authenticator, the handshake utilizes the endpoint's active PTK, which can also be the initial PTK when the endpoint first attempts to switch in the optical network. The request includes at least a first random number, a first frame count, and a first message integrity code (MIC) derived from the active PTK. The first random number is a cryptographically generated random number by the second requester. The first frame count is a count bit (bit / bits) or number used to indicate a sequence of messages sent by a sender, which is used by the receiver to detect frame / message loss or duplication. The first MIC is calculated for the request message using the active PTK currently held by the second requester. Optionally, the request may also include a unique identifier for a candidate access point, depending on whether the candidate access point is detected by the endpoint itself. The request is then sent by the second requester to the authenticator via the currently associated access point. Upon successful delivery of the request from the second requester, the second requester can receive an acknowledgment from the authenticator via the currently associated access point. The acknowledgment from the authenticator is constructed in a similar format to the request message, including at least a second random number, a second frame count, and a second message integrity code derived from the new pairwise transient key. Upon receiving confirmation, the second requesting party can then retrieve a second random number from the authenticator. Using the first random number, the second random number, and the endpoint's activation session key, the second requesting party can export a new local PTK. To verify the second random number included in the confirmation message, the second requesting party generates a local message integrity code and compares it with the second message integrity code included in the confirmation message. Using the locally exported new PTK and plaintext in the confirmation message—such as the second random number and the second frame count—a local message integrity code is generated. If the second frame count has not expired, and the locally generated message integrity code also matches the second message integrity code included in the confirmation message, then the second requesting party can ensure that the locally exported new PTK is correct and ready for use.

[0071] According to another aspect of the present invention, a method for an authenticator is provided to support an endpoint subsystem in performing a secure handover from an access point currently associated with the endpoint subsystem to another access point among a plurality of access points in an optical multi-cell wireless communication network, the method comprising the following steps by the authenticator:

[0072] - When the endpoint subsystem does not have an established secure connection, a first procedure is performed using the first requester included in the endpoint subsystem to establish an initial pairwise transient key for the endpoint subsystem, and

[0073] - A second process is performed using a second requester included in the endpoint subsystem to establish new pairwise transient keys for the endpoint subsystem and candidate access points among multiple access points in preparation for a secure handover from the endpoint subsystem to the candidate access points.

[0074] The first procedure is triggered when no secure connection is established at the endpoint subsystem. An established secure connection may not be the active link, but it does indicate that a pair of transient keys are available to the two relevant parties to the connection to protect data exchange between them if necessary.

[0075] The authenticator functionality can be implemented in a centralized manner, such as within a central controller, or in a distributed manner, such as across one or more access points. The authenticator functionality can also include a hybrid of a first process for deriving the PTK in a conventional manner and a second process for deriving the PTK as disclosed in this invention. It is also possible that the first and second processes are identical.

[0076] In the preferred configuration, the second process includes the following steps by the certifying party:

[0077] - Receive a request from the second requester that includes at least a first random number, a first frame count, and a first message integrity code;

[0078] - Verify the first frame count and the integrity code of the first message based on the pairwise instantaneous key;

[0079] - Extract the first random number upon successful verification of the first frame count and the first message integrity code;

[0080] - Derive a new pairwise instantaneous key based on the extracted first random number;

[0081] - Send an acknowledgment to the second requester, the acknowledgment including at least a second random number, a second frame count, and a second message integrity code derived based on the new pairwise transient key;

[0082] - Notify candidate access points about the new pairwise instantaneous key.

[0083] In the second process, the authenticator acts as the counterpart to the second requester during the handshake. Upon receiving the request from the second requester, the authenticator can first check if the request has expired based on the first frame count. Since the authenticator possesses information about the endpoint's active PTK, it can derive a local message integrity code based on the received request and the endpoint's active PTK. Upon successful authentication, the authenticator extracts a first random number from the request. Based on the endpoint's first random number, a second random number generated by the authenticator itself, and the endpoint's active PTK information, the authenticator can derive a new PTK. The authenticator then compiles an acknowledgment message for the second requester, which includes at least the second random number, the second frame count, and a second message integrity code generated with the new PTK.

[0084] The authenticator can learn about candidate access points via a central controller, Li-Fi controller, or another access point. The authenticator can also obtain information related to candidate access points from requests sent by a second requester. Therefore, the authenticator can notify candidate access points of the new PTK when it is generated.

[0085] It is also possible for the authenticator to be included in the candidate access point. In this case, the associated access point or L1-Fi controller forwards the request from the second requester to the candidate access point. The authenticator included in the candidate access point then generates a new PTK. As a result, the candidate access point obtains the new PTK directly from the local authenticator.

[0086] The invention can also be embodied in a computer program that includes code means, which, when executed by an endpoint subsystem or authenticator including a processing means, causes the processing means to perform the methods of the endpoint subsystem and the authenticator. Attached Figure Description

[0087] In the accompanying drawings, similar reference numerals are used throughout. Figure 1 Generally, the same parts are referred to. Furthermore, the accompanying drawings are not necessarily to scale; instead, the focus is usually on illustrating the principles of the invention.

[0088] Figure 1 An overview of the OWC network and the backbone network connected to it is presented;

[0089] Figure 2 The basic components of a Li-Fi access point are schematically depicted.

[0090] Figure 3 The basic components of a Li-Fi access point with multiple optical front ends are schematically depicted.

[0091] Figure 4 The basic components of a Li-Fi endpoint are schematically depicted.

[0092] Figure 5 The basic components of the optical front end included in a Li-Fi access point or Li-Fi endpoint are schematically depicted.

[0093] Figure 6 The diagram illustrates the roaming of an endpoint in an optical multi-cell wireless communication network and the corresponding coverage areas of the endpoint, associated access points, and neighboring access points.

[0094] Figure 7 A top view showing an endpoint roaming in an optical multi-cell wireless communication network, having coverage of a first planar surface and a second planar surface;

[0095] Figure 8The basic components of the endpoint subsystem of the present invention are schematically depicted;

[0096] Figure 9 The basic components of the endpoint subsystem of the present invention are schematically depicted when the host processor is shared with the terminal device / mobile device, wherein the endpoint is connected to the terminal device / mobile device, communicatively coupled to the terminal device / mobile device, or partially integrated into the terminal device / mobile device;

[0097] Figure 10 The basic components of the endpoint subsystem of the present invention are schematically depicted when the host processor is shared with a terminal device / mobile device in which the endpoint is fully integrated;

[0098] Figure 11 It demonstrates the signaling handshake between the requester, which is included in the endpoint subsystem, and the authenticator, which is included in the access point;

[0099] Figure 12 The signaling handshake between the requester, which is included in the endpoint subsystem, and the authenticator, which is included in the central controller, is demonstrated.

[0100] Figure 13 The signaling handshake between the second requester and the authenticator in the endpoint subsystem is demonstrated using a triggering event from the central controller.

[0101] Figure 14 The signaling handshake between the second requester in the endpoint subsystem and the authenticator of the triggering event from the endpoint is demonstrated.

[0102] Figure 15 The signaling handshake of the second process performed between the second requester and the authenticator included in the endpoint is shown;

[0103] Figure 16 A flowchart of the method executed by the endpoint subsystem is shown;

[0104] Figure 17 A flowchart of the second process executed by the endpoint subsystem is shown;

[0105] Figure 18 A flowchart illustrating the method performed by the certifying party is shown;

[0106] Figure 19 A flowchart of the second process performed by the certifying party is shown. Detailed Implementation

[0107] Now, it will be based on an optical wireless communication (OWC) network system 100, or more specifically, on such Figure 1The Li-Fi network system shown is used to illustrate various embodiments of the invention. For illustrative purposes, Li-Fi network 100 is connected to backbone network 20 via IP router 15 and Ethernet switch 14. In a real system, more routers and switches can be deployed to connect the backbone network to the Li-Fi network. Note that Ethernet switch 14 and IP router 15 are also part of the backbone network. Figure 1 The symbol 20 for the backbone network is for illustrative purposes; it should be considered as the remainder of the backbone network excluding the Ethernet switch 14 and IP router 15 shown in the diagram. In this example, the connection between the Li-Fi network and the backbone network is referred to as backbone connection 21. A backbone connection is a stable and high-speed link, which can be a wired connection (such as Ethernet) or a radio frequency (RF) or millimeter wave-based wireless connection. A backbone connection can also be another type of optical wireless link, distinct from the link performed by the endpoints in an optical multi-cell wireless network. An example of another type of optical wireless link could be a free-space point-to-point optical link.

[0108] Li-Fi System Overview and Network Architecture

[0109] As a wireless communication technology for local area networks, Li-Fi plays a similar role to Wi-Fi in providing connectivity for the last few tens of meters. A Li-Fi network 100 may include multiple optical access points (APs) 120 and network devices or endpoints (EPs) 110. Each endpoint 110 is selectively associated with and synchronized with a corresponding access point 120. Li-Fi APs 120 may connect to one or more optical front-ends or Li-Fi transceivers (TRXs) 121 to provide access to Li-Fi devices or Li-Fi endpoints (EPs) 110. The trapezoidal shape shown by the dashed line illustrates the field of view (FOV) or coverage area of ​​each Li-Fi transceiver 121. An EP 110 will only be able to receive downlink communication from a Li-Fi AP 120 when it is within the coverage area of ​​that AP 120. By assuming symmetrical uplink and downlink in optical communication, bidirectional optical links can be established under the same conditions. Due to the line-of-sight characteristics of optical communication links, there is no direct optical link between adjacent access points 120, but the endpoint 110 located in the overlapping area of ​​the coverage of adjacent access points 120 can detect optical signals from both access points.

[0110] In one example, the Li-Fi AP 120 can also operate as a domain host with additional functions according to G. hn, ITU G.9960, and G.9961 to manage several Li-Fi EPs 110. In one implementation, a handover occurs when an EP roams from one domain to another. In another implementation, each Li-Fi AP 120 operates as a domain host managing a separate domain hosting multiple Li-Fi EPs, up to 255 in total. Such Li-Fi APs 120 are typically located on the ceiling. They may, but not necessarily, be juxtaposed with lighting fixtures, especially when communication is not based on visible light. The main functions of the Li-Fi AP 120 may include announcing the presence of the AP 120 to surrounding Li-Fi EPs 110, registering and deregistering Li-Fi EPs 110, providing Media Access Control (MAC) scheduling between associated Li-Fi EPs 110, collecting interference reports from EPs 110, adjusting local scheduling in response to interference reports, and / or reporting adjacency relationships to the Li-Fi controller 13. Some features of the Li-Fi AP 120—such as MAC scheduling for interference avoidance—can be implemented in a centralized manner by the Li-Fi controller 13.

[0111] Li-Fi EP or Li-Fi device 110 is an end-user modem that facilitates connection of terminal devices to Li-Fi network 100. Currently, Li-Fi EP 110 is typically a dedicated entity for connecting to laptops or other terminal devices. In the future, Li-Fi EP 110 may be partially or fully integrated into smartphones, tablets, computers, remote controls, smart TVs, display devices, storage devices, home appliances, or other smart electronic devices.

[0112] There may be multiple Li-Fi controllers or central controllers 13 connected to access points 120 in the Li-Fi network 100. The Li-Fi controllers or central controllers 13 are responsible for centrally controlling the Li-Fi system when necessary, such as deriving information about topology and adjacency relationships, and determining scheduling between different Li-Fi access points (APs) to suppress interference. Furthermore, the Li-Fi controllers 13 can also provide a user interface that allows users or administrators (such as IT administrators) to configure scheduling tables among multiple Li-Fi APs, monitor reports from these Li-Fi APs, and / or derive further statistics about system performance. Typically, it is ensured that only one Li-Fi controller 13 is visible to a single AP; this is achieved through network configuration such that traffic to and from the Li-Fi controller 13 is isolated within its own network segment via a virtual LAN (VLAN) or similar. Additionally, protocols such as the Control and Configuration of Wireless Access Points (CAPWAP) protocol can be used to discover multiple controllers and select one with available resources to host / manage access points joining the infrastructure.

[0113] In one exemplary implementation of the Li-Fi system, a Li-Fi synchronization server 16 is connected to the system, which is responsible for synchronizing (or aligning) the G.vlc Media Access Control (MAC) cycles of different G.vlc domains. This requires aligning some common time slots for detecting adjacent APs 120 and avoiding interference to EP 110 located in the overlapping area of ​​adjacent APs 120. Due to the line-of-sight nature of optical links, adjacent APs 120 typically cannot directly detect each other's signals. However, if adjacent APs 120 are transmitting simultaneously, EP 110 located in the overlapping area of ​​two adjacent APs 120 may experience interference. To avoid this, it may be necessary to keep adjacent APs 120 synchronized with a common time base and prevent them from transmitting at the same time. A preferred option for network synchronization is to use the Precision Time Protocol (PTP), IEEE 1588v2. PTP provides sub-microsecond accuracy, which is sufficiently fair for MAC alignment in G.vlc domains. To maintain the accuracy of PTP, support from Ethernet switches is necessary, and this should also be a capability of PTP. To maintain the accuracy of PTP, every element in the Ethernet network must handle PTP, therefore the switches chosen for any deployment must support and be configured accordingly to operate in PTP mode.

[0114] It is also possible that the Li-Fi system will be deployed on legacy systems where PTP is not supported by the existing infrastructure. Therefore, additional measures should be taken to synchronize neighboring APs 120 in a different and potentially suboptimal manner, and thus a solution should be found for EP 110 to handle the non-ideal synchronization between neighboring APs 120.

[0115] Detailed system description

[0116] Li-Fi AP

[0117] The Li-Fi AP 120 is a key unit for establishing the Li-Fi network 100. In some scenarios, the Li-Fi AP 120 also forms the interface between the existing IT infrastructure and the Li-Fi network 100. Figure 2 A high-level block diagram of the Li-Fi AP 120 is shown. On one hand, the Li-Fi AP 120 has an interface 124 to a backbone network, which can be a wired connection (Ethernet) or a wireless connection (RF, millimeter wave, or another type of optical wireless than the optical wireless being performed by the Li-Fi AP). On the other hand, the Li-Fi AP 120 has an optical front-end 121 to establish an optical link with one or more Li-Fi APs 110. Furthermore, the Li-Fi AP 120 also performs bidirectional conversion or transformation between data on the backbone network 20 and data on the optical link, in terms of conversion between different modulation schemes and modulation of analog signals. Therefore, the Li-Fi AP 120 also includes at least a digital modulator and demodulator assembly 123 and an analog front-end 122. In the transmission path, the analog front-end (AFE) 122 may include programmable amplifiers, filters, and drivers to modulate and amplify the baseband signal to drive the optical front-end. For the receiving path, the AFE 122 may include attenuators, low-noise amplifiers, filters, and programmable gain amplifiers to accommodate the received signal for further digital processing.

[0118] An optical front end 121, comprising at least a light source and a light sensor, performs the conversion between electrical and optical signals. In the transmitter chain, the optical front end 121 converts the electrical transmission signal into an output optical signal via the light source. In the receiver chain, the optical front end 121 converts the received optical signal into an output electrical signal via the light sensor for further signal processing. The optical front end 121, also referred to as a Li-Fi transceiver (TRX), enables:

[0119] Li-Fi transmitters (Tx): convert electrical signals obtained from the AFE into optical signals (e.g., to be emitted by an LED), and

[0120] Li-Fi receiver (Rx): Converts received optical signals (e.g., from photodiodes) into electrical signals for AFE.

[0121] The Li-Fi AP 120 can connect to a single Li-Fi TRX 121 or multiple Li-Fi TRX 121s, allowing optical signals to be transmitted on different optical paths. When the Li-Fi AP 120 is connected to multiple Li-Fi TRX 121s, the Li-Fi AP can treat them as a coherent signal or as (partially) independent incoherent signals used to establish a communication link. Figure 3 An example of a Li-Fi AP 120 with multiple Li-Fi TRX 121s is shown. A Li-Fi interface component 125 is used to separate or combine data sent to or received from the multiple Li-Fi TRX 121s.

[0122] Li-Fi EP

[0123] Figure 4 A high-level overview of the Li-Fi EP or Li-Fi device 110 is shown. Similar to the Li-Fi AP 120, the Li-Fi EP 110 includes at least an optical front end 111, an analog front end 112, a digital modulator / demodulator 113, and an interface 114 to an end device or processor.

[0124] The Li-Fi EP 110 can be connected to a terminal device as a separate entity via cable, or partially or fully integrated into the terminal device. For many terminal devices (such as laptops, smartphones, and remote controls), Ethernet is a mature interface in the terminal device's operating system. Alternatively, Li-Fi can also be used to provide a communication interface to the terminal device. To simplify system integration of the Li-Fi EP or Li-Fi device into the terminal device's operating system, Ethernet over USB is advantageous. Therefore, in one option, the Li-Fi EP or Li-Fi device 110 can be connected to the terminal device via a standard USB cable or plug. Using Ethernet over USB as an example, the Li-Fi EP 110 can include an Ethernet over USB interface 114 and connect to the terminal device via a USB cable 115. Similar to the Li-Fi AP 120, the Li-Fi EP 110 can also be connected to one or more client optical TRX 111s. Alternatively, a single optical front end with segmented transmitters / receivers, where each transceiver / receiver points in a different direction, is also conceivable.

[0125] In another example, a different interface 114 can be used to connect the Li-Fi EP to the operating system of the terminal device, and the corresponding interface 114 (Ethernet over USB) and / or cable 115 should be replaced accordingly.

[0126] Figure 5 Exemplary components are provided for optical front-ends or optical TRX 111, 121 included in or connected to Li-Fi AP 120 and Li-Fi EP 110. Optical TRX 111, 121 include at least a light source 1211, a photosensor 1212, a driver 1213, and an amplifier 1214. The light source 1211 is used to convert an electrically transmitted signal into an output optical signal; it may be a light-emitting diode (LED), a laser diode (LD), or a vertical-cavity surface-emitting laser (VCSEL). The photosensor 1212 is used to convert the received optical signal into an output electrical signal; it may be a photodiode, an avalanche diode, or another type of photosensor. The driver 1213 is primarily used to regulate the power required by the light source 1211. The amplifier 1214 is primarily used to regulate the signal received by the photosensor 1212 to make the signal suitable for further processing in the circuit. In one example, the amplifier 1214 may be a transimpedance amplifier (TIA), which is a current-to-voltage converter implemented using one or more operational amplifiers. The TIA can be located near the receiving optical sensor or photodiode 1212 to amplify the signal with minimal noise.

[0127] Interconnection in Li-Fi systems

[0128] Typically, the Li-Fi AP 120 is deployed on the ceiling. This AP 120 requires power to perform communication activities. Therefore, the connection to the AP 120 involves both power and data. The AP 120 establishes a bidirectional link with the cloud or backbone network 20 on one side via backbone connection 21, and on the other side, the AP 120 communicates with one or more associated EPs 110 via an optical link. The EP 110 typically draws power from an end device, which is coupled to or integrated into the end device; and communicates with the associated AP 120 via an optical link.

[0129] Connect the Li-Fi AP to the backbone network

[0130] The L1-Fi AP 120 can use different options to connect to the backbone network 20.

[0131] In one aspect, data and power can be delivered together to the Li-Fi AP, which can be achieved via a single power cable with power line communication (PLC) or a single Ethernet cable with power over Ethernet (PoE).

[0132] PLCs utilize existing power cables, both for providing mains power to the equipment and for data communication. Popular PLC communication standards (such as HomePlug) ® Or G.hn) utilizes Orthogonal Frequency Division Multiplexing (OFDM) technology, which is also widely used in Li-Fi systems. Therefore, the physical layer (PHY) of PLC and Li-Fi systems can be very similar, such as the modulation and synchronization methods used in both systems. However, transmission in the optical domain is unipolar, while OFDM typically uses bipolar signals. As a result, some adaptation may be required for transmission in optical networks. A simple solution is to use DC offset, which eliminates the need for demodulation and subsequent remodulation of the OFDM-based PLC signal before optical transmission, or alternatively, to use unipolar OFDM modulation techniques (such as ACO-OFDM, DCO-OFDM, ADO-OFDM, and / or inverted OFDM) for demodulation and subsequent remodulation. Therefore, for a Li-Fi AP 120 typically juxtaposed with ceiling lights, it may be very convenient to utilize existing power cables to obtain data connectivity to the backbone network 20.

[0133] However, it is also recognized that the channels of PLC systems are quite noisy, considering that the trunk power lines may act as antennas, picking up all sorts of unwanted signals that may interfere with the communication signals also present on the trunk power lines. Therefore, it is important to handle this external interference for devices enabling Li-Fi on PLCs. Furthermore, the amount of attenuation experienced by the communication signals on the trunk power lines is unpredictable during manufacturing and may vary throughout the day. Influencing factors include cable lengths varying from building to building, electrical loads that more or less create short circuits at high frequencies, and being switched on or off, etc.

[0134] One known solution to address signal integrity issues introduced by PLC systems is to equip Li-Fi-enabled devices with a PLC with a PLC decoder to decode PLC communication signals received over the mains power line. Impairments to the communication signal are handled digitally. For example, narrowband interference causes errors only on a single subcarrier of the OFDM modulated signal. Error correction algorithms can be used to correct the reconstructed data. The reconstructed data is then converted back to the analog domain to modulate the LED current flowing to at least one LED. In this way, more robust operating devices can be provided, with reduced data loss, although one drawback of this solution is that the devices become larger, more complex, and more expensive.

[0135] On the other hand, if power can be delivered via Ethernet cables, Li-Fi APs may also be convenient in utilizing existing IT infrastructure to obtain both power and connectivity to the backbone network. Power over Ethernet (PoE) is described in the IEEE 802.3af / at standard and is currently being extended to 4-pair power delivery in the IEEE task group P802.3bt. PoE is designed to supply 40V to 48V of power supply voltage from a power supply equipment (PSE) to a power consumption device (PD), along with data lines for control and communication purposes. PSE devices are also known as PoE switches. In a PoE lighting system, the PD can be a light source, a user interface device, or a sensor. The PSE is typically powered by a trunk power supply, such as according to the IEC / TR 60083 standard. Traditional PoE systems transport data and power through the network and its endpoints, thus between the PSE and the PD.

[0136] Therefore, data can be received by control devices, for example, via an Ethernet connection using the Ethernet protocol. Data is communicated between devices in a Power over Ethernet (PoE) system via the Ethernet protocol. Thus, microchips in the form of Ethernet controllers can be used to establish communication links between devices, supporting the Media Access Control (MAC) and Physical Layer (PHY) of the Open Systems Interconnection (OSI) model.

[0137] Ethernet connections can be, for example, fiber optic cables, electrical wires, or twisted-pair cables, such as Category 3, Category 4, Category 5, Category 5e, Category 6, Category 6A, Category 7, Category 7A, Category 8, Category 8.1, or Category 8.2 cables. An Ethernet connection can have several pairs of cables, such as 2, 3, 4, or more. The cables can be unshielded or shielded, particularly individually or collectively shielded. Power and data can be transmitted via the same fiber optic cable, electrical wire, or cable connected to the Ethernet connection, or via different fiber optic cables, electrical wires, or cables connected to the Ethernet connection. In the case of power transmission via fiber optics, the power can be transmitted in the form of photons, which can be received by the solar cell unit of the data receiving device.

[0138] Data receiving devices in a PoE system may include one or more ports. Each port may include one or more pins. Pins may be configured to receive power, data, or both. Alternatively or additionally, the port may also include one or more solar cell units for receiving power in the form of photons. Because the port can receive power and data via an Ethernet connection, some pins can be powered while other pins are supplied with data via the Ethernet connection. Alternatively or additionally, power and data may also be supplied to pins via an Ethernet connection.

[0139] In another aspect, data and power can be delivered to the Li-Fi AP separately, and the option can be either via a power cable and an Ethernet cable (a wired connection to the backbone network), or a combination of a power cable and a wireless link (optical wireless link or free-space optical link) to the backbone network 20.

[0140] Preferably, the Li-Fi system can be integrated into existing wireless communication systems, such as Wi-Fi or cellular systems. Therefore, the Li-Fi AP 120 can be integrated into or directly connected to a Wi-Fi access point or cellular base station. By performing signal conversion or transformation between the Li-Fi AP 120 and the Wi-Fi access point or cellular base station, the existing infrastructure of the Wi-Fi or cellular system can be used to provide the Li-Fi AP 120 with connectivity to the backbone network 20.

[0141] Connect the Li-Fi EP to the Li-Fi AP

[0142] The Li-Fi EP 110 connects to the Li-Fi system via the Li-Fi AP 120, which is typically referred to as the local AP. Several aspects need to be considered regarding the connection between the Li-Fi EP 120 and the Li-Fi AP 110:

[0143] Coverage: Li-Fi EPs may not always be able to see Li-Fi APs, depending on their location, orientation, the location of the Li-Fi AP, and the size of the Li-Fi EP's transducer / sensor coverage area.

[0144] Downlink interference: If these Li-Fi APs transmit simultaneously, the Li-Fi EPs in the overlapping coverage areas of multiple optical downlinks will be subject to interference.

[0145] Uplink interference: When one Li-Fi EP transmits a signal to its associated Li-Fi AP, while another Li-Fi EP is transmitting to the same Li-Fi AP, this causes uplink interference at the Li-Fi AP.

[0146] Handover: Due to the mobility of Li-Fi EPs, handover is required when a Li-Fi EP moves from the coverage area of ​​one Li-Fi AP to an adjacent Li-Fi AP. That is, when a Li-Fi EP (such as one connected to or included in a user equipment, client device, mobile phone, etc.) moves from its current cell to an adjacent cell, any active communication must be switched to the node or access point of that adjacent cell. To minimize interference with any ongoing communication or data transmission, handover is designed to be performed as quickly as possible and may include a preparation period to facilitate this. When there is insufficient time to prepare and establish a link to the new Li-Fi AP before the link with the existing Li-Fi AP is broken, the Li-Fi EP may experience a period of no connection. Considering the relatively small size of Li-Fi cells due to the line-of-sight characteristics of optical links, seamless handover is important for ensuring link quality and user experience.

[0147] Essentially, the Li-Fi EP 110 can connect to the Li-Fi AP 120 via a bidirectional optical link or a hybrid downlink and uplink. Note that here, the downlink represents the communication link from the Li-Fi AP 120 to the Li-Fi EP 110, and the uplink represents the communication link from the Li-Fi EP 110 to the Li-Fi AP 120. The bidirectional optical link achieves a relatively symmetrical connection between the Li-Fi EP 110 and the Li-Fi AP 120. Therefore, both the downlink and uplink enjoy the same advantages of Li-Fi communication as described above. However, in some applications (such as web surfing or video streaming), the link between the Li-Fi AP and the Li-Fi EP can also be a hybrid link, combining an optical downlink from the Li-Fi AP 120 to the Li-Fi EP 110 and a radio frequency (RF) uplink from the Li-Fi EP 120 to the Li-Fi AP 110. RF links can be based on popular short-range wireless communication protocols, such as Wi-Fi, BLE, or Zigbee; or on cellular communication protocols, such as 4G or 5G cellular.

[0148] Referring back to the option of building the Li-Fi AP 120 via a combination of devices supporting Li-Fi AP functionality and Wi-Fi access point or cellular base station functionality, this hybrid link can be seamlessly handled by the controller on the Li-Fi AP side. Since the Li-Fi EP 110 is typically connected to or integrated into an end device—which could be a smartphone, tablet, computer, or other smart device—this end device may already have hardware support for the short-range wireless communication protocols or cellular protocols used in the hybrid link. Therefore, this hybrid link also utilizes the existing resources of the end device and provides a simplified solution for the Li-Fi EP, which only requires a receive path and not a transmit path. The cost, power consumption, and form factor of the EP 110 can be further reduced in this way. Correspondingly, the Li-Fi AP 120 is also simplified by primarily including an optical transmitter to send data to the Li-Fi EP 110 via an optical downlink, while the RF-based uplink from the Li-Fi EP 110 to the AP 120 can be received by utilizing an RF receiver in a combined device or a cooperatively positioned Wi-Fi access point / cellular base station, or via a dedicated RF receiver included in the Li-Fi AP 120 itself.

[0149] Scheduling and interference suppression in optical multi-cell wireless networks

[0150] Media Access Control (MAC) becomes necessary for interference-free optical communication when multiple Li-Fi AP 120s are deployed adjacent to each other, or when multiple EP 110s are associated with the same local AP 120 or neighboring AP 120s. Different MAC mechanisms can be employed in optical multi-cell wireless networks, such as Time Division Multiple Access (TDMA), Frequency Division Multiple Access (FDMA), Carrier Sense Multiple Access (CSMA), Code Division Multiple Access (CDMA), Space Division Multiple Access, or a combination of one or more of these mechanisms. TDMA is based on a time division multiplexing scheme, where radio resources are scheduled in the time domain, and different time slots are allocated to different transmitters in a typical cyclic repeating frame structure or MAC cycle. FDMA is based on frequency division multiplexing, where different frequency bands are allocated to different devices for simultaneous transmission. Furthermore, in optical communication, FDMA can evolve into wavelength division multiple access (WDMA) based on wavelength division multiplexing. Another advanced variant of FDMA is Orthogonal Frequency Division Multiple Access (OFDMA), where each device can use one or more subcarriers outside the entire frequency band. OFDMA offers greater flexibility in providing different data rates or qualities of service to different users, while maintaining high resource efficiency despite this diversity. CSMA typically employs a "listen-before-talk" approach, where devices verify the presence of any other traffic before transmitting over a shared medium. CSMA is widely used in sparse networks, and further collision avoidance techniques emerge as node density increases. CDMA is typically built on spread spectrum, and a common form is direct sequence CDMA based on direct sequence spread spectrum, where different devices simultaneously transmit messages using different orthogonal spreading codes. Given that the FoV of optical links is generally smaller compared to radio links, spatial division multiple access can also be a very attractive solution here.

[0151] In a TDMA-based multi-cell network with multiple AP 120s, adjacent AP 120s may sometimes lack synchronized MAC cycles due to the lack of direct communication. While the duration of a MAC cycle or superframe is typically the same for all AP 120s in the network, the start time of the MAC cycle can differ for each individual AP 120. Note that the start time of the MAC cycle is used by the AP as its local time base to divide the wireless media into consecutive time slots. Even when a time slot is specifically allocated to an AP 120 for communication with an EP 110 in an overlapping area, this MAC cycle offset between two adjacent AP 120s can still cause interference to the EP 110 located in the overlapping coverage area of ​​these two adjacent AP 120s. Therefore, it is necessary for the AP 120s to synchronize to a common time base. The common time base can be obtained via a synchronization handshake, via a reference clock distributed across the network (such as a synchronized Ethernet clock), or via a dedicated synchronization server in the network, or derived from a common signal (such as the zero-crossing of trunk power). However, due to unpredictable delays or interference in the network, timing synchronization uncertainties between APs and a timing base may still exist. An EP 110 located in the overlapping area of ​​at least two adjacent APs 120 may still need to derive timing information related to the MAC cycles of at least two APs 120 based on downlink communications from these APs, which can be normal data communication links or out-of-band signaling messages. Then, based on the derived timing information related to the MAC cycles of at least two APs 120, the EP 110 can further assist at least one of the two adjacent APs 120 in adjusting its MAC cycle to align with the other.

[0152] Quick and safe switching

[0153] For Wi-Fi systems, IEEE 802.11 defines that communication for handover or transition can be performed directly with adjacent access points, for example, on a direct path (i.e., "over-the-air") or via a local access point in a distributed system (DS) (i.e., "over-the-DS"). Furthermore, the EP may want adjacent access points to reserve resources before the transition, for example, based on the Fast Transition (FT) resource request protocol (Fast BSS transition) according to Section 13 of the IEEE 802.11 (2016) specification. Two FT protocols are defined for this purpose. These are the FT protocols executed when a transition to the target access point is performed and no resource request is required before the transition, and the FT resource request protocol executed when a resource request is required before the transition. For an EP to perform a fast transition / handover from its current associated access point to the target access point using the FT protocols, message exchange can be performed using either the over-the-air method (where the EP communicates directly with the target AP using IEEE 802.11 authentication with an FT authentication algorithm) or the over-the-DS method (where the EP communicates with the target AP via its current local AP). Communication between the EP and the target AP can take place within FT action frames between the EP and its current local AP. Communication between the current AP and the target AP can be achieved via encapsulation methods, such as those described in section 13.10.3 of the IEEE 802.11 (2016) specification. The current local AP can switch between two encapsulation methods.

[0154] Fast Secure Roaming (FSR), based on the 802.11r amendment (officially called Fast BSS Transition), is the first IEEE-approved method for performing fast secure transitions between Wi-Fi access points. It works by having the client complete an initial successful 802.1X Extensible Authentication Protocol (EAP) authentication with the authentication server. The resulting Master Session Key (MSK) is then passed to the Wireless LAN Controller (WLC), as in other methods. However, this method differs in that it derives a slightly different key hierarchy. The Paired Master Key (PMK)-R0 is derived from the MSK, which is known only to the client and the WLC. PMK-R1 is derived from PMK-R0 and is known to the client and AP managed by the WLC that holds PMK-R0. The final layer is the Paired Transient Key (PTK), which is derived from the PMK-R1 protocol and is known to the client and AP managed by the WLC. Typically, APs managed by the WLC form a group called the FT Mobility Domain, which is essentially all APs with the same SSID. The IEEE 802.11r amendment does not define how PMK-R1 becomes known to other APs.

[0155] During initial authentication, the client performs full 802.1X authentication, completes a four-way handshake to derive a Paired Transient Key Security Association (PTKSA) with the AP (using PMK-R1 key material), and is then granted network access. When the client begins roaming, the client and the target AP derive a new key based on PMK-R1. This method is even more efficient because the four-way handshake occurs within the Open Systems Authentication (OSA) from the client, OSA from the AP, the re-association request, and the re-association response. This replaces the four-way handshake that occurs after these frames in other methods.

[0156] There is also a less-deployed variant of this technology called Fast BSS Transition over Distributed Systems (DS). Using this technique, once a client decides it might roam to another AP, it sends an FT Action Request frame to the original AP. The client indicates the MAC address of the target AP it wants to roam to. The original AP forwards the FT Action Request frame to the target AP via DS, and the target AP responds to the client with an FT Action Response frame (also via DS). Once this FT Action frame exchange is successful, the client has completed FT roaming. The client sends a reassociation request to the target AP in the air and receives a reassociation response from the new AP to confirm roaming and final key export. These last two messages are exchanged when the client finally roams to the target AP. Therefore, Fast Transition allows for faster roaming than static PMK caching.

[0157] Clearly, rapid handover is crucial for ensuring quality of service when endpoints are roaming in multi-cell networks. The design challenges in Li-Fi systems are even greater than in RF systems such as Wi-Fi, given the smaller optical cells and less overlapping areas in optical communication systems.

[0158] Figure 6 An endpoint 110 roaming in an optical multi-cell wireless communication network 100 is shown, along with the corresponding coverage areas of endpoint 110, associated access point 120, and neighboring access point 120. Multiple access points, including at least associated and candidate access points, are located on a first planar surface 410. In a typical application scenario, the first planar surface 410 is a ceiling. On the first planar surface 410, the coverage area 412 of the endpoint is shown as a dashed circle, covering the associated and neighboring access points. The endpoint is located on a second planar surface 420, which can be a floor, a table, a planar surface of another horizontal surface where the endpoint is located, or any arbitrary planar area where the endpoint roams with the user. On the second surface 420, the coverage area 422 of the associated and neighboring access points is shown as a shaded circle, and endpoint 110 is located in the overlapping area of ​​these two coverage areas. Arrows indicate the direction of movement of the endpoint toward the neighboring access point and suggest a potential handover. Figure 6In this example, the identical coverage areas of the endpoints and access points are merely for illustrative purposes. Depending on the optical components used by the various access points and endpoints, the coverage area 422 of access point 120 and the coverage area 412 of endpoint 110 may differ. Furthermore, even if the optical components remain the same, the actual coverage area will vary with the distance between the first and second planar surfaces.

[0159] For ease of explanation, it is assumed here that each access point 120 includes a single optical front end, and each point on the first planar surface 410 represents a different access point 120. Therefore, a fast handover is always necessary when an endpoint roams into the coverage area of ​​an adjacent access point 120. In another example, if an access point includes more than one optical front end, handover may be unnecessary when an endpoint roams within the coverage area of ​​multiple optical front ends belonging to the same access point 120, which transmits the same information via multiple optical front ends.

[0160] Figure 7 A top-view view of the coverage of the first planar surface 410 and the second planar surface 420 is provided when the L1-Fi endpoint 110 is roaming in the optical multi-cell wireless communication network 100. It can be seen that, depending on the endpoint's movement trajectory, different neighboring access points can be candidate access points for potential handover. When an endpoint enters an overlapping coverage area of ​​the currently associated access point and neighboring access points, endpoint 110 may detect downlink communication from neighboring access points. It is also possible to implement a centralized or distributed function in the network that can be responsible for selecting candidate access points for endpoints undergoing potential handover. Such a centralized or distributed function can select candidate access points based on an overview of one or more adjacency relationships in the optical multi-cell wireless network.

[0161] Figure 8 The basic components of the endpoint subsystem of the present invention are schematically depicted. The endpoint subsystem 110 includes at least an optical transceiver 117, a controller 118, and a host processor 1185. The optical transceiver 117 should be understood as a complete Li-Fi transceiver, which includes at least an optical front end 111, an analog front end 112, a digital modulator / demodulator / modem 113, and an interface 114 to a terminal device connected to or included in the Li-Fi transceiver. The controller 118 may be as follows: Figure 8 The dedicated controller shown. Controller 118 can also be a shared controller that performs some functions of a typical optical transceiver, such as the digital modulator / demodulator / modem 113 section of the optical transceiver. If the controller performs the functions of the digital modulator / demodulator / modem 113 of the optical transceiver 117, in addition to the digital modulator / demodulator / modem 113, Figure 8The optical transceiver 117 may include components such as an optical front-end 111 and an analog front-end 112. Compared to the controller 118, the host processor 1185 is the main processor and has higher performance; besides supporting only optical communication, it can perform many other tasks, such as similar functions of an operating system. To derive a pairwise security key, or PTK, the endpoint is represented by two requesters. A first requester 1186, used to establish the initial PTK, is included in the host processor 1185, while a second requester 1181, used to establish a new PTK for a potential handover, is included in the controller 118. The first requester may derive the initial PTK using conventional or standard methods in the first process. Considering the more critical latency requirements involved in secure handover in optical multi-cell wireless networks compared to conventional communication networks that typically have large cell areas, the second requester performs a second process according to the invention to accelerate key supply. The endpoint may optionally include a user interface 119, which can provide users with additional convenience for status queries or operations.

[0162] As a slightly different setting for the endpoint subsystem Figure 9 The diagram schematically depicts the basic components of the endpoint subsystem 110 of the present invention when the host processor 1185 is shared with the terminal device / mobile device 101—endpoint 110 is connected to, communicatively coupled to, or partially integrated into the terminal device / mobile device 101. A controller 118, an optical transceiver 117, and an optional user interface 119 are included in a single housing 1100. As an exemplary drawing, the host processor 1185 is now included in the terminal device / mobile device 101, but it can also be a separate processor connected to and shared by the terminal device / mobile device 101 and endpoint 110. The terminal device / mobile device 101 may also include another communication interface 1175, via which a first requester 1186 included in the host processor 1185 can establish an initial PTK using conventional methods. Thus, the host processor is configured to perform various tasks, such as the operating system of the terminal device / mobile device 101, and it may also support one or more other communication interfaces besides the optical communication proposed in this invention. Similar to endpoint 110, terminal device / mobile device 101 will likely include user interface 119.

[0163] Figure 10An alternative configuration of endpoint subsystem 110 is shown, in which endpoint subsystem 110 is fully integrated into terminal device / mobile device 101. Host processor 1185 is shared by terminal device / mobile device 101 and endpoint subsystem 110, while controller 118 is more dedicated to tasks related to optical communication. The controller 118, optical transceiver 117, and optional user interface 119 of endpoint subsystem 110 can be included in a single housing 1100 within terminal device / mobile device 101. However, Figure 10 The individual housing 1100 may not be reflected as a physical boundary, but may also indicate the integration of related components on the same PCB. It is also possible that there is no individual housing 1100 in such a fully integrated setup.

[0164] To provide an overview of how optical multi-cell networks can adapt to IEEE 802.1X / EAP type security infrastructures, Figure 11 and Figure 12 Two possible implementations are shown. Hollow bidirectional arrows are used to indicate signaling flow on logical channels, which can include one or more physical channels. The first type of physical channel is an optical link between an endpoint and an access point. The second type of physical channel is a backbone connection, which is a stable and high-speed link, and in some scenarios, may even be an always-connected link.

[0165] exist Figure 11 In this diagram, the requesting party of the endpoint is included in the host processor H, and it performs the authentication and security key derivation steps. The authenticating party is included in the host processor H of the access point. This diagram is for illustrative purposes only; the authenticating party may be included in one or more access points, but not necessarily in the access point associated with the endpoint. The connection between multiple access points is a backbone connection. By entering the area of ​​the optical multi-cell network, the requesting party, representing the endpoint, first runs an authentication handshake with the authentication server to obtain the Master Session Key (MSK). Based on the MSK, the requesting party can perform a four-way handshake with the authenticating party to derive a Paired Transient Key (PTK), thereby securing the point-to-point link between the endpoint and the associated access point. Upon obtaining the PTK, the requesting party of the endpoint provides the PTK to the modem M of its optical transceiver to encrypt or decrypt data on the optical link. Similarly, upon obtaining the PTK, the authenticating party provides the PTK directly (where the authenticating party is included in the associated access point) or via the backbone connection to the modem M of the associated access point.

[0166] The authentication process may only be required once when an event occurs (such as when an endpoint enters the network or upon receiving a user command). The same MSK can be reused by the endpoint to derive a new PTK for a new peer-to-peer link with another access point in the same network. To switch to a new access point, the endpoint can be the initiator to trigger a new key deriving process for the new access point upon detection of the new access point. Although not shown in the diagram, the authenticator can also be the initiator to trigger a new deriving process when it anticipates such a potential switch.

[0167] and Figure 11 compared to, Figure 12 Another example is provided where the authenticator is included in the central controller CL. The authentication process is performed between the requester included in the endpoint and the authentication server, which is necessary when the endpoint first enters the optical multi-cell network. This process can also be performed via existing communication networks other than the optical network, provided the endpoint's host processor obtains the MSK. A key export process is performed between the requester and the authenticator. During PTK export, the endpoint's requester provides the PTK to the endpoint's modem M to encrypt and decrypt data transmitted over the optical link; and the authenticator included in the central controller also provides the key to the access point. The exported PTK is then used to secure the optical link between the endpoint and the access point. Figure 11 Similarly, an endpoint or central controller can trigger the key export process.

[0168] As disclosed in this invention, it is advantageous that the endpoint comprises two requesters, or that the conventional requester functionality is split into two entities: a first requester included in a host processor H, and a second requester included in a controller C, to accelerate the key derivation process for fast and secure handover in optical multi-cell networks. The controller is more dedicated to optical communications and uses the active PTK held by the controller to derive a new PTK in the second process of the second requester. No further interaction with the host processor is required in the second process to derive a new PTK for potential handovers within the optical multi-cell network. Therefore, the proposed method effectively reduces the latency of deriving a new PTK. Figure 13 and Figure 14 An exemplary implementation of the system is provided. In both examples, the authenticator is included in the central controller CL. However, as... Figure 11 As shown, the authenticator function can also be included in one or more access points in the network.

[0169] exist Figure 13The diagram illustrates that the first requester, included in the endpoint subsystem, can be responsible for the traditional authentication process with the authentication server. The first requester is also responsible for establishing the initial PTK for the endpoint. In the diagram, although the authentication process and the initial key derivation process are combined in a single arrow for illustration, these two processes are actually executed sequentially and can be triggered by two separate trigger signals, which are not shown in the diagram. When the endpoint does not have a secure optical link, the host processor only needs to provide the initial PTK once to the endpoint's controller C. Afterward, the key derivation process occurs between the second requester and the authenticator. The central controller CL may include a repository containing information related to the association between the endpoint and the access point, one or more neighbor relationships between access points, or some other location information. The central controller can anticipate potential handovers from the endpoint to the access point, and then it can trigger the authenticator to become the initiator to begin the key derivation process using the second requester included in the endpoint, thereby establishing a new PTK.

[0170] Figure 14 Another example is provided where the triggering of the new key export process is not generated by the central controller (CL), but by the endpoint itself. One possibility is that the endpoint's optical front end detects downlink communication from the access point, and this can trigger a second requester to begin a new key export process.

[0171] from Figure 13 and Figure 14 It can be seen that the disclosed new key derivation between the second requester and the authenticator can be applied before or during handover in the optical network, and when the endpoint first attempts to establish a secure optical link in an optical multi-cell network. In the latter case, the initial PTK can first be established by the first requester via a conventional communication network. Then, the second requester uses the initial PTK to establish a new PTK for optical communication.

[0172] Figure 15 This illustrates a more detailed signaling handshake of the second process performed between the second requester and the authenticator within the endpoint subsystem. In this example, the endpoint's optical front end detects the presence of a potential candidate access point or target AP for a handover, which might occur when the endpoint enters an area where the coverage of the associated access point and the target access point overlaps. The endpoint then triggers the second requester to initiate the second process by first sending a request to the authenticator to establish a new PTK for the target AP. The second process may also include resource allocation steps, such as... Figure 15As shown, after the authenticator successfully verifies the request from the second requester in step S853, the authenticator can proceed to step S854 to derive a new PTK. In parallel, the authenticator can also send a request / command / instruction to the target AP, requesting the target AP to prepare to allocate resources to the relevant endpoint. Furthermore, this request / command / instruction can also include a timer regarding the validity period of the request, or a timer regarding when the resource allocation should be implemented. The target AP can then provide feedback to the authenticator to confirm whether it is possible to allocate such resources to the new endpoint. This feedback regarding resource allocation can be carried over to the confirmation sent to the second requester in step S855.

[0173] As previously disclosed, new PTKs may have a limited lifespan or validity period. If no switchover occurs within this period, the new PTK may simply expire and not be put into use. Similarly, if no switchover occurs within a certain time window, the resources allocated to endpoints in the target AP will be released.

[0174] Figure 16 A flowchart of method 700, executed by endpoint subsystem 110, is shown. This method performs a secure handover from an access point currently associated with endpoint subsystem 110 to another access point among a plurality of access points 120 in an optical multi-cell wireless communication network 100. As one implementation of this method, in step S701, the host processor acts as a first requester 1186 to execute a first process for establishing an initial pairwise transient key with the endpoint's authenticator, and then the endpoint checks in step S702 whether it has a secure connection. If not, in step S703, the host processor provides the initial pairwise transient key to the controller 118 to be used as an activation pairwise transient key, and in step S704, optical wireless communication is performed, and then in step S705, the optical link is secured with the activation pairwise transient key. If the endpoint already has a secure optical connection, the endpoint proceeds to step S705 to perform secure optical communication. In step 706, when triggered internally or externally, the controller acts as a second requester 1181 to prepare for a secure handover to candidate access points among multiple access points by executing a second process 750, which is used to establish new pairwise transient keys for endpoint 110 and candidate access points using an authenticator.

[0175] Figure 17A flowchart of the second process 750 performed by endpoint 110 is shown. In step S751, the second requester sends a request to the authenticator that includes at least a first random number, a first frame count, and a first message integrity code derived based on a pairwise transient key. In this request, the plaintext includes at least the first random number and the first frame count, and the first message integrity code is generated based on the plaintext using the controller's activation PTK. When the second process is triggered by the endpoint itself, the request may also include a unique identifier of the candidate access point. Then, in step S752, the second requester receives an acknowledgment from the authenticator that includes at least a second random number, a second frame count, and a second message integrity code. Similar to the request message, the second random number and the second frame count constitute the plaintext portion of the acknowledgment message, and the second message integrity code is derived from the new PTK and the plaintext portion of the acknowledgment message. By extracting the second random number from the acknowledgment received in step S753, the second requester can derive a new local pairwise transient key in step S754. Using the locally derived new pairwise transient key, in step S755, the second requesting party can generate a local message integrity code based on the plaintext portion of the received acknowledgment. The second frame count and the second message integrity code are verified by comparing the first frame count and the local message integrity code in step S756. Then, in step S757, the endpoint will use the locally derived new pairwise transient key as the new pairwise transient key.

[0176] Figure 18 A flowchart of method 800 performed by an authenticator is shown, which supports endpoint 110 in performing a secure handover from an access point currently associated with the endpoint to another access point among a plurality of access points 120 in an optical multi-cell wireless communication network 100. In step S801, it is checked whether the endpoint has a secure connection. If not, a first process is performed between a first requester 1186 included in the endpoint and the authenticator to establish an initial pairwise transient key for the endpoint. The first process can be performed via a communication network other than the optical multi-cell network. In step S803, the authenticator is configured to perform a second process 850 with a second requester 1181 included in the endpoint to establish a new pairwise transient key for the endpoint and a candidate access point among the plurality of access points, in preparation for a secure handover from the endpoint to a candidate access point.

[0177] Figure 19A flowchart of the second process 850 performed by the authenticator is shown, which is the corresponding part of the second process 750 performed by the second requester. In step S851, the authenticator receives a request from the second requester 1181 that includes at least a first random number, a first frame count, and a first message integrity code. Then, in step S852, the authenticator verifies the first frame count and verifies the first message integrity code based on the pairwise transient key. Upon successful verification of the first frame count and the first message integrity code, in step S853, the authenticator extracts the first random number from the second requester. Based on the extracted first random number, in step S854, the second requester can derive a new pairwise transient key. Optionally, in parallel with step S854, the authenticator can also send a request / command / instruction to the target AP to request the candidate access point / target AP to prepare to allocate resources to the relevant endpoint. In step S855, the authenticator sends an acknowledgment to the second requester 1181, which includes at least the second random number, the second frame count, and the second message integrity code derived based on the new pairwise transient key. Optionally, the confirmation may also include feedback from the candidate access point / target AP related to a resource allocation request for a potential handover. In step S856, the authenticator will also notify the candidate access point of the new pairwise transient key.

[0178] The method according to the invention can be implemented on a computer as a computer-implemented method, or in dedicated hardware, or in a combination of both.

[0179] The executable code of the method according to the invention can be stored on a computer / machine-readable storage device. Examples of computer / machine-readable storage devices include non-volatile storage devices, optical storage media / devices, solid-state media, integrated circuits, servers, etc. Preferably, the computer program product includes non-transitory program code means stored on a computer-readable medium for executing the method according to the invention when the program product is executed on a computer.

[0180] Methods, systems, and computer-readable media (transitory and non-transitory) may also be provided to implement selected aspects of the above embodiments.

[0181] The term "controller" is used generally herein to describe various means relating to the operation of one or more network devices or coordinators—among other functions. A controller can be implemented in a variety of ways (e.g., such as with dedicated hardware) to perform the various functions discussed herein. A "processor" is an example of a controller employing one or more microprocessors, which can be programmed using software (e.g., microcode) to perform the various functions discussed herein. A controller can be implemented with or without a processor, and can also be implemented as a combination of dedicated hardware performing some functions and a processor (e.g., one or more programmed microprocessors and associated circuitry) performing other functions. Examples of controller components that can be employed in various embodiments of this disclosure include, but are not limited to, conventional microprocessors, application-specific integrated circuits (ASICs), and field-programmable gate arrays (FPGAs).

[0182] In various embodiments, the processor or controller may be associated with one or more storage media (collectively referred to herein as "memory," such as volatile and non-volatile computer memories, such as RAM, PROM, EPROM, and EEPROM, compact disks, optical disks, etc.). In some embodiments, the storage media may be encoded with one or more programs that, when executed on one or more processors and / or controllers, perform at least some of the functions discussed herein. Various storage media may be fixed within the processor or controller, or may be transportable, such that one or more programs stored thereon may be loaded into the processor or controller to implement various aspects of the invention discussed herein. The terms "program" or "computer program" are used herein in a general sense to refer to any type of computer code (e.g., software or microcode) that can be used to program one or more processors or controllers.

[0183] As used herein, the term “network” refers to any interconnection of two or more devices (including controllers or processors) that facilitates the transport of information (e.g., for device control, data storage, data exchange, etc.) between any two or more devices and / or between multiple devices coupled to the network.

Claims

1. An endpoint subsystem (110) for performing a secure handover from an access point (120) currently associated with the endpoint subsystem (110) to another access point (120) among a plurality of access points (120) in an optical multi-cell wireless communication network (100), the endpoint subsystem (110) comprising: - An optical transceiver (117) is configured to perform optical wireless communication; - The controller (118) is configured to protect the link by using a pair of instantaneous keys to encrypt or decrypt data transmitted on the optical wireless communication link with the currently associated access point (120); - A shared host processor (1185) separate from the controller (118) is configured to act as a first requester (1186) to perform a first process for establishing an initial pairwise transient key for the endpoint subsystem (110) in the optical multi-cell wireless communication network (100) using an authenticator, wherein the first process is performed via another communication technology instead of optical wireless communication; The shared host processor (1185) is shared by the endpoint subsystem (110) and the device (101), wherein the endpoint subsystem (110) is connected to the device (101), communicatively coupled to the device (101), or partially or wholly integrated into the device (101); as well as The controller (118) is also configured to act as a second requester (1181) to prepare for a secure handover to a candidate access point (120) among the plurality of access points (120) by performing a second process for establishing new pairwise instantaneous keys for the endpoint subsystem (110) and the candidate access point (120) using the authenticator; wherein the second process is performed via optical wireless communication, and The shared host processor (1185) is also configured to provide the initial pairwise transient key to the controller (118) for use as a pairwise transient key when the endpoint subsystem (110) does not have a secure optical connection.

2. The endpoint subsystem (110) according to claim 1, wherein the optical transceiver (117) is further configured to - Receive information related to the candidate access point from the currently associated access point or the candidate access point; and - Upon receiving information related to the candidate access point (120), the controller (118) is triggered to initiate the second process.

3. The endpoint subsystem (110) according to claim 2, wherein the information associated with the candidate access point (120) is a downlink advertisement received from the candidate access point (120).

4. The endpoint subsystem (110) according to any one of the preceding claims, wherein the optical transceiver (117) is further configured to - Compare the link quality of the optical wireless communication link with the currently associated access point and the candidate access point, respectively; - Based on the comparison of link quality, the controller (118) is triggered to start switching to the candidate access point (120).

5. The endpoint subsystem (110) according to any one of claims 1-3, wherein the pairwise transient key between the endpoint subsystem (110) and the currently associated access point (120) is used in the second process of establishing a new pairwise transient key.

6. The endpoint subsystem (110) according to any one of claims 1-3, wherein the optical transceiver (117) and the controller (118) are included in a single housing (1100) attached to a device (101) including the shared host processor (1185).

7. A system for supporting an endpoint subsystem (110) according to claim 1 to perform a secure handover from an access point currently associated with the endpoint subsystem to another access point among a plurality of access points (120) in an optical multi-cell wireless communication network (100), the system comprising: -The endpoint subsystem (110); - Multiple access points (120), including currently associated access points and candidate access points, are configured to perform optical wireless communication with the endpoint subsystem and are connected to each other and / or to the central controller (13) via a backbone connection (21). - The authenticator is configured to perform a first process with a first requester (1186) and a second process with a second requester (1181), wherein the first requester is a shared host processor (1185) included in the endpoint subsystem (110) and the second requester is a controller (118) included in the endpoint subsystem (110) and separate from the shared host processor (1185).

8. The system of claim 7, wherein the authenticator is included in a central controller (13) connected to the plurality of access points (120) via a backbone connection (21).

9. The system of claim 7, wherein the authenticator is included in one of the plurality of access points (120), and wherein the access point is configured to communicate with the other access points (120) via a backbone connection (21).

10. The system according to any one of claims 7-9, wherein the authenticator is further configured to provide a new pairwise instantaneous key to the candidate access point (120).

11. A method (700) for an endpoint subsystem (110) to perform a secure handover from an access point currently associated with the endpoint subsystem (110) to another access point among a plurality of access points (120) in an optical multi-cell wireless communication network (100), the method (700) comprising the following steps of the endpoint subsystem (110): - Perform (S704) optical wireless communication; - Protect (S705) the link by encrypting or decrypting data transmitted on the optical wireless communication link with the currently associated access point using a pair of instantaneous keys; - When the endpoint subsystem (110) does not have an established secure connection, the shared host processor (1185) included in the endpoint subsystem (110) acts as (S701) the first requester (1186) to perform a first process for establishing an initial pairwise transient key for the endpoint subsystem (110) using the authenticator; The first process is performed via another communication technology instead of optical wireless communication; - A controller (118) separate from the shared host processor (1185) included in the endpoint subsystem (110) acts as (S706) a second requester (1181) to prepare for a secure handover to a candidate access point among the plurality of access points by performing a second process (750), the second process being used to establish new pairwise transient keys for the endpoint subsystem (110) and the candidate access points using the authenticator; The second process is performed via optical wireless communication; - When the endpoint subsystem (110) does not have a secure optical connection (S702), the initial pairwise transient key is provided (S703) from the shared host processor (1185) to the controller (118) for use as a pairwise transient key.

12. The method (700) according to claim 11, wherein the second process (750) includes the following steps of the second requester (1181): - Send a request to the authenticator (S751) including at least a first random number, a first frame count, and a first message integrity code derived based on the pair of transient keys; - Receive confirmation from the authenticator (S752), the confirmation including at least a second random number, a second frame count, and a second message integrity code derived from the new pairwise transient key; - Extract the second random number from the received confirmation (S753); - Derive a new local pairwise instantaneous key based on the extracted second random number (S754); - A new pairwise instantaneous key generation (S755) local message integrity code based on local export; - Verify the second frame count and the second message integrity code by comparing the first frame count with the local message integrity code (S756); - Upon successful verification of both the second frame count and the second message integrity code, a new pairwise transient key derived locally in (S757) is used as the new pairwise transient key.

13. A computing program including a code means, wherein when the program is executed by an endpoint subsystem (110) including a processing means, the code means causes the processing means to perform the method of claim 11 or 12.

Citation Information

Patent Citations

  • 802.11 Using a Compressed Reassociation Exchange to Facilitate Fast Handoff

    EP1887758A2

  • Visible light communication personal area network coordinator (VPANC) and associated method for selecting suitable VPANCs

    US9882640B1