Concurrent access point pre-authentication

By introducing concurrent AP pre-authentication IE in the FT action frame, the signaling overhead and delay problems caused by failure of single AP pre-authentication in the existing FT process are solved, and the seamless transformation of multi-AP pre-authentication is achieved, improving mobility and connection stability.

CN120266515APending Publication Date: 2025-07-04QUALCOMM INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380082116.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-12-06
Filing Date
2023-11-07
Publication Date
2025-07-04

AI Technical Summary

Technical Problem

The existing IEEE 802.11r fast basic service set (BSS) transition (FT) process only supports pre-authentication of a single target AP, resulting in the need to restart the FToDS process when the transition fails, increasing signaling overhead and delay.

Method used

The introduction of concurrent AP pre-authentication information element (IE) into the FT action frame allows pre-authentication of multiple candidate APs at one time, reducing signaling overhead, and directly selecting the pre-authenticated APs for reassociation in the event of failure.

Benefits of technology

By pre-authenticating multiple APs at one time, the signaling overhead and delay of the transition process are reduced, and the stability and efficiency of seamless connection are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120266515A_ABST
    Figure CN120266515A_ABST
Patent Text Reader

Abstract

Techniques related to fast basic service set (BSS) transitions (FT) in IEEE 802.11 Wi-Fi are disclosed. Some aspects of the present disclosure relate to apparatuses and methods for pre-authenticating a plurality of access points (APs) using a modified FT procedure. An AP may obtain an FT action request frame from a station (STA), the FT action request frame including a list of a plurality of candidate APs. The AP may communicate with each of the plurality of candidate APs (e.g., over a distributed system (DS)) to pre-authenticate the STA, and may output an FT action response frame including pre-authentication information for each of the plurality of candidate APs. Other aspects, embodiments, and features are also claimed and described.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to U.S. Patent Application No. 18 / 062,426, filed on December 06, 2022, the entire content of which is hereby incorporated by reference. Technical Field

[0002] The techniques discussed below generally relate to wireless communication systems and, more particularly, to handovers or transitions between access points. Background Art

[0003] The IEEE specifications for Wi-Fi (e.g., IEEE document 802.11-2020) include an amendment named IEEE 802.11r or Fast Basic Service Set (BSS) Transition (FT). This FT amendment provides procedures and protocols for a station (STA) to move from its current associated access point (AP) to a target AP, with substantially seamless connectivity during the transition. For example, FT can provide encryption keys to be stored on all APs in the network, thus providing the flexibility to pre-authenticate with the new target AP without pausing ongoing data delivery through the connected AP.

[0004] As the demand for mobile broadband access continues to increase, research and development continue to improve wireless communication technologies, not only to meet the growing demand for mobile broadband access but also to improve and enhance the user experience of mobile communication. Summary of the Invention

[0005] To provide a basic understanding of one or more aspects of the present disclosure, an overview of such aspects is given below. This overview is not an extensive review of all the expected features of the present disclosure and is neither intended to identify the key or important elements of all aspects of the present disclosure nor to delineate the scope of any or all aspects of the present disclosure. Its sole purpose is to present some concepts of one or more aspects of the present disclosure in a simplified form as a prelude to the more detailed description that follows. While some examples may be discussed as including certain aspects or features, all the examples discussed may include any of the features discussed. And no aspect or feature is necessary for achieving the technical effects or solutions discussed herein unless explicitly described.

[0006] Fast BSS Transition (FT) on Distributed Systems (FToDS) is a collection of processes and procedures for a wireless station (STA) operating under 802.11 Wi-Fi to obtain substantially seamless connectivity during a transition from its current associated access point (AP) to a new target AP by performing pre-authentication of the target AP. The current specification of FToDS provides such pre-authentication only for a single target AP. Thus, if the transition to a given target AP fails (pre-authentication failure or re-association failure), the STA is forced to restart the FToDS process for the security information of a different target AP. In accordance with various aspects of the present disclosure, the FToDS process is modified to provide FToDS pre-authentication for multiple candidate APs for a later transition. That is, a new information element (IE), referred to herein as the concurrent AP pre-authentication IE, is introduced into the FT action frame. The concurrent AP pre-authentication IE includes a list of target APs and their authentication information such that multiple candidate APs can be pre-authenticated in one FT action frame exchange. Thus, if the transition to a given target AP fails (pre-authentication failure or re-association failure), the STA does not need to restart the FToDS process and can re-associate with any selected target AP from the list of candidate APs that have already been pre-authenticated.

[0007] In some aspects, a method, apparatus, and non-transitory computer-readable medium for wireless communication at a station (STA) are disclosed. The STA outputs a request frame including a list of multiple candidate access points (APs). The STA further obtains, in response to the request frame, a response frame including pre-authentication information for each of the multiple candidate APs. The STA further transitions a connection from the current associated AP to a first one of the multiple candidate APs based on the pre-authentication information.

[0008] In additional aspects, a method, apparatus, and non-transitory computer-readable medium for wireless communication at an access point (AP) are disclosed. The AP obtains a request frame from a station (STA), the request frame including a list of multiple candidate APs. The AP communicates with each of the multiple candidate APs to pre-authenticate the STA. The AP outputs, in response to the request frame, a response frame including pre-authentication information for each of the multiple candidate APs.

[0009] After reading the following detailed description, these and other aspects of the techniques discussed herein will be more fully appreciated. Other aspects and features will become apparent to those of ordinary skill in the art after reading the description of the specific examples below in conjunction with the accompanying drawings. Although the following description may discuss various advantages and features with respect to certain examples, specific implementations, and drawings, all examples may include one or more of the advantageous features discussed herein. In other words, although this description may discuss one or more examples as having certain advantageous features, one or more such features may also be used in accordance with various other examples discussed herein. In a similar manner, although this description may discuss certain examples as devices, systems, or methods, it should be understood that such examples of the teachings of the present disclosure may be implemented in a variety of devices, systems, and methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Figure 1 is a schematic diagram of a Fast Transition on Distributed System Processes (FToDS) according to some aspects of the present disclosure.

[0011] Figure 2 is a call flow diagram illustrating signaling in the FToDS process according to some aspects of the present disclosure.

[0012] Figure 3 is a schematic diagram of an FT Action Request Frame and an FT Action Response Frame according to some aspects of the present disclosure.

[0013] Figure 4 is a schematic diagram of a concurrent AP pre-authentication Information Element (IE) according to some aspects of the present disclosure.

[0014] Figure 5 is a block diagram conceptually illustrating an example of a hardware implementation for a Station (STA) according to some aspects of the present disclosure.

[0015] Figure 6 is a block diagram conceptually illustrating an example of a hardware implementation for an Access Point (AP) according to some aspects of the present disclosure.

[0016] Figure 7 is a call flow diagram illustrating signaling in the FToDS process for pre-authenticating multiple candidate APs according to some aspects of the present disclosure.

[0017] Figure 8 is a call flow diagram illustrating signaling in another FToDS process for pre-authenticating multiple candidate APs according to some aspects of the present disclosure.

[0018] Figure 9FIG. is a flowchart illustrating an example of a process for a concurrent associated AP to pre - authenticate multiple candidate APs using FToDS according to some aspects of the present disclosure.

[0019] Figure 10 FIG. is a flowchart illustrating an example of a process for a STA to pre - authenticate multiple candidate APs using FToDS according to some aspects of the present disclosure. DETAILED DESCRIPTION

[0020] The IEEE specification for Wi - Fi (i.e., IEEE document 802.11 - 2020) includes an amendment named IEEE 802.11r or Fast BSS Transition (FT). This FT amendment provides processes and protocols for a STA to move from its current associated AP to a target AP with substantially seamless connectivity during the transition. That is, FT provides encryption keys to be stored on all APs in the network and can provide the flexibility to pre - authenticate with a new target AP without pausing ongoing data transfer through the connected AP.

[0021] There are two versions of FT: the Over - the - Air version (FToAir) and the Through the Distributed System version (FToDS). In the case of FToAir, a wireless station (STA) communicates directly with its target access point (AP) using IEEE 802.11 authentication. However, in the case of FToDS, the STA communicates with the target AP via its current associated AP. Figure 1 FIG. is a schematic diagram of a STA (also referred to as an FT originator, FTO) 102 undergoing an FToDS process from a current associated AP 104 to a target AP 106. As Figure 1 seen, the STA 102 uses FT action frames (FT request and FT response) to communicate with its current AP 104, and the current associated AP 104 conveys this information to the target AP 106 via a distributed system or controller 108. Once the target AP 106 has been pre - authenticated, the STA 102 can then use reassociation request and reassociation response messages to transition to the target AP 106, as further described below. A given AP can use a Mobility Domain Element (MDE) to advertise its ability to employ this FToDS process.

[0022] Figure 2is a call flow diagram illustrating an FToDS process according to an example. The FT authentication sequence includes four messages: an FT request 202, an FT response 204, a re-association request 206, and a re-association response 208. The first two messages in the sequence allow the STA 102 and the target AP 106 to provide association instance identifiers: SNonce and ANonce, respectively. The SNonce and ANonce can be randomly or pseudo-randomly selected and used to generate a refreshed pairwise transient key (PTK). The first two messages also enable the target AP 106 to provide a pairwise master key (PMK)-R1 key holder ID (R1KH-ID), and enable the STA 102 and the target AP 106 to compute the PTK. The third message (re-association request 206) and the fourth message (re-association response 208) verify the liveness of the peer, authenticate these elements, and enable the authenticated resource request.

[0023] Figure 2 The call flow diagram of includes an STA 102 communicating with a current associated AP 104 and a target AP 106, and starts with the assumption that a successful (secure) session and data transmission have been established between the STA 102 and the current associated AP 104. From time to time, the STA 102 may determine to transition from its current associated AP 104 to the target AP 106. To initiate this process, the STA 102 may send a first message (e.g., an FT action request frame 202) to its current associated AP 104. The content of the FT action request frame 202 is as Figure 3 illustrated. The FT action request frame 202 serves as a transmission mechanism for data destined for the target AP 106. The FT action request frame 202 may include a header and an FT frame body 302 (note that the FT frame body also appears in the FT action response frame 204, described below). The header may include information such as a category field, an FT action field, an STA address field for identifying the FTO 102, and a target AP address field for identifying the target AP 106. The category and FT action fields are defined in the IEEE specification for 802.11 and are known to those of ordinary skill in the art. The STA address field may be set to the media access control (MAC) address of the FTO. The target AP address field may be set to the basic service set identifier (BSSID) value of the target AP 106. The FT frame body 302 is illustrated as being in Figure 3at the bottom and has a variable bit length and a content set. In the illustrated example, the FT frame body 302 includes a Robust Secure Network Element (RSNE), which includes a Pairwise Master Key (PMK) R0 Name (RSNE[PMKR0Name]), a Mobility Domain Element (MDE), and a Fast BSS Transition Element (FTE), which may include, among other things, a Supplicant Nonce (SNonce) and an R0 Key Holder (FTE[SNonce,R0KH-ID]). The use of these information elements is defined in the IEEE specification for 802.11 and is known to those of ordinary skill in the art, and thus they are not described in detail herein.

[0024] The currently associated AP 104 can communicate with the target AP 106 via one or more controllers or a Distribution System (DS) 108. For example, the currently associated AP 104 can encapsulate the information elements included in the FT Action Request Frame 202 and transmit the information to the target AP 106 via the DS 108. The target AP 106 can correspondingly convey pre-authentication information to the currently associated AP 104 via the DS 108.

[0025] In response to the FT Action Request Frame 202, the currently associated AP 104 can send a second message (e.g., an FT Action Response Frame 204) to the STA 102. The FT Action Response Frame 204 is also illustrated in Figure 3 and serves as a transmission mechanism for data originating from the target AP 106. The FT Response Frame 204 can include a header and an FT frame body 302. The header can include information in a Category field, an FT Action field, a STA Address field set to the MAC address of the FTO 102, a Target AP Address field set to the BSSID value of the target AP 106, and a Status Code. The Status Code field indicates whether the pre-authentication with the target AP was successful.

[0026] If the pre-authentication between the STA 102 and the target AP 106 is successful, the STA 102 may then send a third message (e.g., re-association request 206) to the target AP 106 and may receive a fourth message (e.g., re-association response 208) from the target AP 106. The re-association request 206 may include: an RSNE including a pairwise master key (PMK) R1 name (RSNE[PMKR1Name]), an MDE, an FTE including a message integrity code (MIC), an ANonce, an SNonce, an R1KH-ID, and an R0KH-ID, and a resource information container (RIC-request). The re-association response 208 may include RSNE[PMKR1Name], an MDE, an FTE including a MIC, an ANonce, an SNonce, an R1KH-ID, an R0KH-ID, and a group temporal key (GTK[N]). The re-association response 208 may also include an integrity group temporal key (IGTK[M]) and a resource information container (RIC-response). The use of these information elements is defined in the IEEE specification for 802.11 and is known to those of ordinary skill in the art, and thus they will not be described in detail herein. When the re-association is complete, the STA 102 may enter a secure session and data transmission with the target AP 106. That is, the STA 102 may obtain at least one packet from the target AP 106 and may decode the at least one packet based on the PTK. In addition, the STA 102 may encode at least one other packet based on the PTK and output the encoded other packet for transmission to the target AP 106.

[0027] From Figure 3 It can be observed that the existing FToDS protocol allows pre-authentication with only one target AP at a time. That is, the first message (FT request 202) includes only a single target AP address. However, there may be multiple candidate APs to which the STA 102 may roam or multiple APs to which the STA 102 may transition. If the pre-authentication with a given target AP fails, the STA 102 currently re-initiates the FT pre-authentication with another candidate AP. Thus, after the pre-authentication fails, another set of FT action frames 202, 204 may be exchanged with the currently associated AP 104. This may result in additional overhead signaling and potential latency during the handover process.

[0028] According to various aspects of the present disclosure, an AP and an STA may be configured to communicate using an FT action frame including an additional information element (IE) as part of the FT frame body 302. Figure 4 An example of such an IE is illustrated, and this IE may be referred to as a concurrent AP pre-authentication IE 402. Thus, according to the techniques disclosed herein, Figure 4The IE 402 illustrated herein may appear in the FT frame body 302. The concurrent AP pre-authentication IE 402 includes an element ID field, a length field, and an information field. The element ID field indicates the information element type. The length field indicates the length of the concurrent AP pre-authentication IE 402.

[0029] Rather than including only the BSSID of a single target AP, this new IE provides an FT action request frame to include a list of target APs, and the STA uses this list of target APs to seek pre-authentication. Using this information, the currently associated AP can perform pre-authentication with all the listed target APs via the DS.

[0030] Thus, if the FT pre-authentication and / or re-association with the first target AP fails, the STA 102 can re-associate with any other pre-authenticated target AP without performing another FT request / FT response message exchange with its currently associated AP. That is, compared to a conventional system where FToDS uses a separate FT request / FT response message for each candidate target AP, the signaling overhead can be reduced. In addition, in the case of FT pre-authentication failure or re-association failure, the handover process can be accelerated and the latency can be reduced because the STA 102 does not have to restart the FT pre-authentication process for each candidate target AP. That is, instead of restarting the FT pre-authentication process whenever the FT pre-authentication or re-association fails, the STA 102 can immediately initiate re-association signaling with any of the multiple APs that have already performed pre-authentication.

[0031] As described above, Figure 4 is a diagram illustrating a concurrent AP pre-authentication IE 402 according to an example. The IE 402 can be carried in the FT frame body 302. That is, referring to Figure 3 , the FT frame body 302 is illustrated as including three information elements, sorted as numbers 1 to 3. According to an example, the concurrent AP pre-authentication IE 402 can be item number 4 sorted after any fast BSS transition IE in the FT frame body 302.

[0032] The concurrent AP pre-authentication IE 402 includes an element ID field, a length field, and an information field 404. In Figure 4In the description, each line of information field 404 corresponds to the target AP that the STA desires to authenticate. For each target AP that the STA desires to authenticate, the information field 404 includes a target AP information length field, a target AP address field, a status code field, an ANonce field, an SNonce field, and an R1KH-ID. The target AP information length field indicates the length of the information content for each specific target AP. The status code, ANonce, and R1KH-ID fields are only applicable to FT response frames and can be omitted or can take on any value in the FT request frame. The status code field indicates whether the pre-authentication with the candidate AP was successful. The STA can use the ANonce and R1KH-ID to generate the PMK-R1 / PTK key, and the target AP can use the SNonce to derive the key.

[0033] Figure 5 is a block diagram illustrating an example of a hardware implementation of STA 102 that employs a processing system 514. For example, STA 102 can be a STA as illustrated in any one or more of Figure 1 and / or Figure 2 as exemplified therein.

[0034] STA 102 may include a processing system 514 having one or more processors 504. Examples of processors 504 include microprocessors, microcontrollers, digital signal processors (DSPs), field programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gated logic components, discrete hardware circuits, and other suitable hardware configured to perform the various functions described throughout this disclosure. In various examples, STA 102 can be configured to perform any one or more of the functions described herein. For example, the processor 504 as utilized in STA 102 can be configured to (e.g., in coordination with the memory 505) implement the processes and any one or more of the processes described below and Figure 10 as exemplified therein.

[0035] The processing system 514 can be implemented using a bus architecture commonly represented by bus 502. Bus 502 can include any number of interconnected buses and bridges, depending on the specific application of the processing system 514 and overall design constraints. Bus 502 communicatively couples various circuits including one or more processors (commonly represented by processor 504), memory 505, and a computer-readable medium (commonly represented by computer-readable medium 506). Bus 502 can also link various other circuits such as a timing source, peripherals, voltage regulators, and power management circuits, which are well known in the art and will not be described further herein. Bus interface 508 provides an interface between bus 502 and transceiver 510. Transceiver 510 provides a communication interface or component for communicating with various other devices via a transmission medium. Depending on the nature of the device, a user interface 512 (e.g., keypad, display, speaker, microphone, joystick) may also be provided. Of course, such a user interface 512 is optional and may be omitted in some examples such as a base station.

[0036] In some aspects of the present disclosure, processor 504 can include a transition determination circuit 540 that is configured (e.g., in coordination with memory 505) for various functions including, for example, monitoring candidate APs, monitoring associated APs, and determining a transition from an associated AP to a target AP. Processor 504 can also include an FToDS circuit 542 that is configured (e.g., in coordination with memory 505) for various functions including, for example, outputting an FT request frame, obtaining an FT response frame, transitioning the connection from the current associated AP (e.g., using a reassociation procedure), generating a PMK-R1 and a PTK for a candidate AP, and storing the PMK-1 and PTK for each candidate AP in memory 505. For example, FToDS circuit 542 can be configured to implement one or more of the functions described below with respect to Figure 10 the functions described.

[0037] Processor 504 is responsible for managing bus 502 and general processing, including executing software stored on computer-readable medium 506. The software, when executed by processor 504, causes processing system 514 to perform the various functions described below for any particular device. Processor 504 can also use computer-readable medium 506 and memory 505 to store data that processor 504 manipulates when executing the software.

[0038] One or more processors 504 in the processing system may execute software. Software should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subprograms, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc., whether referred to as software, firmware, middleware, microcode, hardware description language, or otherwise. The software may reside on a computer-readable medium 506. The computer-readable medium 506 may be a non-transitory computer-readable medium. Non-transitory computer-readable media include, for example, magnetic storage devices (e.g., hard disks, floppy disks, magnetic strips), optical discs (e.g., compact disc (CD) or digital versatile disc (DVD)), smart cards, flash memory devices (e.g., cards, sticks, or key drives), random access memory (RAM), read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), registers, removable disks, and any other suitable medium for storing software and / or instructions that can be accessed and read by a computer. The computer-readable medium 506 may reside within the processing system 514, be located external to the processing system 514, or be distributed across multiple entities including the processing system 514. The computer-readable medium 506 may be embodied as a computer program product. For example, the computer program product may include the computer-readable medium in a packaging material. Those skilled in the art will recognize how best to implement the described functionality presented throughout this disclosure, depending on the particular application and the overall design constraints imposed on the overall system.

[0039] In one or more examples, the computer-readable storage medium 506 may store computer-executable code including transition determination software 560 that configures the STA 102 for various functions, including, for example, monitoring candidate APs, monitoring associated APs, and determining a transition from an associated AP to a target AP. The computer-readable storage medium 506 may further store computer-executable code including FToDS software 562 that configures the STA 102 for various functions, including, for example, outputting an FT request frame, obtaining an FT response frame, transitioning the connection from the current associated AP (e.g., using a reassociation procedure), and generating a PMK-R1 and PTK for a candidate AP and storing the PMK-1 and PTK for each candidate AP in the memory 505. For example, the FToDS instructions 562 may be configured to cause the STA 102 to implement one or more of the functions described below with respect to Figure 10 one or more of the functions described.

[0040] In one configuration, a device 102 for wireless communication includes components for outputting an FT request frame that includes a list of multiple candidate APs; components for obtaining an FT response frame that includes pre-authentication information for each candidate AP; components for transitioning a connection from a current associated AP; components for generating a PMK-R1 and a PTK; components for storing the pMK-R1 and the PTK for each candidate AP; components for obtaining at least one packet from an AP and decoding the at least one packet based on the PTK; and components for encoding at least one other packet based on the PTK. In one aspect, the foregoing components may be the processor 504 shown in Figure 5 and the processor is configured to perform the functions recited by the foregoing components. In another aspect, the foregoing components may be a circuit or any device configured to perform the functions recited by the foregoing components.

[0041] Of course, in the above example, the circuits included in the processor 504 are provided only as an example, and other components for performing the described functions may be included in various aspects of the present disclosure, including but not limited to those stored in a computer-readable storage medium 506 or Figure 1 , Figure 2 , Figure 7 and / or Figure 8 and any other suitable device or component described in any one of them and utilize instructions for processes and / or algorithms such as those described herein with respect to Figure 10 .

[0042] Figure 6 is a conceptual diagram illustrating an example of a hardware implementation of an exemplary AP 104 that employs a processing system 614. According to various aspects of the present disclosure, the processing system 614 may include elements having one or more processors 604, or any portion of an element, or any combination of elements. For example, the AP 104 may be an AP as illustrated in any one or more of Figure 1 and / or Figure 2 .

[0043] The processing system 614 may be substantially the same as the processing system 514 illustrated in Figure 5 , including a bus interface 608, a bus 602, a memory 605, a processor 604, and a computer-readable medium 606. Additionally, the AP 104 may include a user interface 612 and a transceiver 610 that are substantially similar to those described above in Figure 5 . The AP 104 may also include a DS interface 611 for communicating with one or more target APs via a distributed system (DS). That is, the processor 604 utilized in the AP 104 may be configured to (e.g., in coordination with the memory 605) implement the functions described below and in Figure 9Any one or more of the processes illustrated therein.

[0044] In some aspects of the present disclosure, the processor 604 may include an FToDS circuit 640 that is configured (e.g., in coordination with the memory 605) for various functions, including, for example, obtaining an FT request frame from a STA, communicating with multiple candidate APs to pre - authenticate the STA, and outputting an FT response frame including pre - authentication information for the multiple candidate APs. For example, the FToDS circuit 640 may be configured to implement one or more of the functions described below with respect to Figure 9 The processor 604 may also include a communication circuit 642 that is configured (e.g., in coordination with the memory 605) for various functions, including, for example, establishing, maintaining, and using a communication interface between the STA and the AP 104.

[0045] Furthermore, the computer - readable storage medium 606 may store computer - executable code including FToDS software 660 that configures the AP 104 for various functions, including, for example, obtaining an FT request frame from a STA, communicating with multiple candidate APs to pre - authenticate the STA, and outputting an FT response frame including pre - authentication information for the multiple candidate APs. For example, the FToDS software 660 may be configured to cause the AP 104 to implement one or more of the functions described below with respect to Figure 9 The computer - readable storage medium 606 may further store computer - executable code including communication software 662 that configures the AP 104 for various functions, including, for example, establishing, maintaining, and using a communication interface between the STA and the AP 104.

[0046] In one configuration, a device 104 for wireless communication includes: means for obtaining an FT request frame from a STA; means for communicating with multiple candidate APs to pre - authenticate the STA (e.g., via the DS); and means for outputting an FT response frame including pre - authentication information for the multiple candidate APs for transmission. In one aspect, the foregoing means may be Figure 6 The processor 604 and / or the transceiver 610 shown in which are configured to perform the functions recited by the foregoing means. In another aspect, the foregoing means may be a circuit or any device configured to perform the functions recited by the foregoing means.

[0047] Of course, in the above example, the circuits included in the processor 604 are provided only as examples, and other components for performing the described functions may be included in various aspects of the present disclosure, including but not limited to those stored in the computer - readable storage medium 606 or Figure 1 , Figure 2 , Figure 7 and / or Figure 8in any other suitable apparatus or component described by any of them and using, for example, the procedures and / or algorithms described herein with respect to Figure 9 instructions.

[0048] Figure 7 is a call flow diagram illustrating concurrent AP pre - authentication using FToDS according to one aspect of the present disclosure. In Figure 7 , the STA / FTO 102 communicates with the current associated AP 104 and seeks pre - authentication with the target AP 1106 - A and the target AP 2106 - B. The STA 102 and the APs 104, 106 can be, respectively, Figure 5 the STA 102 illustrated in Figure 6 and the example of the AP 104 illustrated in

[0049] Figure 7 The call flow diagram of starts by assuming that a successful (secure) session and data transmission have been established between the STA 102 and the current associated AP 104. From time to time, the STA 102 can determine to transition from its current associated AP to one of the multiple target APs 106 - A and 106 - B. To initiate this process, the STA 102 can send a first message (e.g., FT action request frame 702) including the concurrent AP pre - authentication IE 402 described above and illustrated in Figure 4 . That is, the FT action request frame 702 can include a list of multiple candidate APs and an SNonce for each respective candidate AP.

[0050] Based on the FT action request message 702, the current associated AP 104 can contact each listed candidate AP via the DS (e.g., Figure 1 's DS 108), including the information provided by the STA 102 for that AP. Thus, at 704, the target AP 1 106 - A can process the request, and at 706, the target AP 2 106 - B can process the request. Both the target AP 1 106 - A and the target AP 2 106 - B can respond to the current associated AP 104 via the DS with FT pre - authentication information.

[0051] Based on the responses received by the current associated AP 104 via the DS, the current associated AP 104 transmits a second message (e.g., FT action response frame 708) to the STA 102. According to one aspect of the present disclosure, the FT action response frame 708 includes the above - mentioned and in Figure 4The concurrent AP pre-authentication IE 402 illustrated in. That is, the FT action response frame 708 may include a list of multiple candidate APs and the ANonce, SNonce, and R1KH-ID for each respective candidate AP. The FT action response frame 708 may also include a status code field for each respective candidate AP to indicate whether the pre-authentication with the candidate AP was successful.

[0052] In some cases, the FT pre-authentication with a specific target AP may fail. For example, at 710, the STA 102 determines that the FT pre-authentication with the target AP 1 106-A has failed. Thus, the STA 102 may skip the target AP 1 106-A and may send a reassociation request 712 to the target AP 2 106-B. The reassociation request 712 and the reassociation response 714 may be the same as those described above and illustrated in Figure 2 Once the reassociation is complete, the STA 102 may enter into a secure session and data transmission with the target AP 2 106-B. Thus, in accordance with aspects of the present disclosure, when the FT pre-authentication fails, the STA 102 does not need to restart the FToDS process and does not need to send another FT action request frame indicating a different target AP. Instead, the STA 102 may select any suitable target AP from the list of target APs for which the FT pre-authentication was successful.

[0053] Figure 8 is a call flow diagram illustrating concurrent AP pre-authentication using FToDS in accordance with additional aspects of the present disclosure. In Figure 8 the STA / FTO 102 communicates with the current associated AP 104 and seeks pre-authentication with the target AP 1 106-A and with the target AP2 106-B. The STA 102 and the APs 104, 106 may be, respectively, Figure 5 the STA 102 illustrated in Figure 6 and the example of the AP 104 illustrated in

[0054] Figure 8 The call flow diagram of begins by assuming that a successful (secure) session and data transmission have been established between the STA 102 and the current associated AP 104. From time to time, the STA 102 may determine to transition from its current associated AP to one of the multiple target APs 106-A and 106-B. To initiate the process, the STA 102 may send a first message (e.g., the FT action request frame 802) including the concurrent AP pre-authentication IE 402 described above and illustrated in Figure 4 That is, the FT action request frame 802 may include a list of multiple candidate APs and the SNonce for each respective candidate AP.

[0055] Based on the FT action request message 802, the current associated AP 104 can contact each listed candidate AP via the DS, including the information provided by the STA 102 for that AP. Thus, at 804, the target AP 1 106-A can process the request, and at 806, the target AP 2 106-B can process the request. Both the target AP 1 106-A and the target AP 2 106-B can respond to the current associated AP 104 via the DS with FT pre-authentication information.

[0056] Based on the responses received by the current associated AP 104 via the DS, the current associated AP 104 transmits a second message (e.g., FT action response frame 808) to the STA 102. According to one aspect of the present disclosure, the FT action response frame 808 includes the concurrent AP pre-authentication IE 402 described above and illustrated in Figure 4 That is, the FT action response frame 808 can include a list of multiple candidate APs and the ANonce, SNonce, and R1KH-ID for each respective candidate AP. The FT action response frame 808 can also include a status code field for each respective candidate AP to indicate whether the pre-authentication with the candidate AP was successful.

[0057] Assuming pre-authentication is successful, as indicated by the FT action response frame 808, the STA 102 can send a reassociation request 810 to the selected target AP. The STA 102 can send the reassociation request 810 to any suitable target AP from the list of target APs for which FT pre-authentication was successful. For example, the STA 102 can send the reassociation request 810 to the target AP 1 106-A and can receive a reassociation response 812 as a response.

[0058] In some cases, although the FT pre-authentication with a particular target AP is successful, the reassociation with that target AP may fail. For example, at 814, the STA 102 determines that the reassociation with the target AP 1 106-A has failed. Thus, the STA 102 can attempt to reassociate with any other suitable target AP from the list of candidate APs for which pre-authentication was successful. For example, the STA 102 can send a second reassociation request 816 to the target AP 2 106-B and can receive a second reassociation response 818 as a response. Once the reassociation is complete, the STA 102 can enter a secure session and data transmission with the target AP 2 106-B. Thus, according to aspects of the present disclosure, when the reassociation fails, the STA 102 does not need to restart the FToDS process and does not need to send another FT action request frame indicating a different target AP. Instead, the STA 102 can select any suitable target AP from the list of target APs for which FT pre-authentication was successful.

[0059] Figure 9 is a flowchart illustrating an exemplary process for a currently associated AP in accordance with some aspects of the present disclosure. As described below, certain specific implementations may omit some or all of the illustrated features, and some of the illustrated features may not be required to implement all embodiments. In some examples, Figure 6 the AP 104 illustrated in Figure 9 may be configured to perform the process of Figure 9 . In some examples, any suitable device or component for performing the functions or algorithms described below may execute the process of

[0060] At block 902, the associated AP 104 may receive an FT action request frame that includes the concurrent AP pre-authentication IE 402 as described above and illustrated in Figure 4 . In some cases, the associated AP may lack the ability to perform concurrent AP pre-authentication as described in the present disclosure. In such cases, the associated AP may not expect or understand the concurrent AP pre-authentication IE 402. However, according to one aspect of the present disclosure, the concurrent AP pre-authentication IE 402 is included in the FT frame body 302 (see Figure 3 ). Thus, a legacy AP lacking the ability to perform concurrent AP pre-authentication (the "no" branch of 904) may proceed to block 906, where the legacy AP may perform pre-authentication with one AP (the target AP identified in the FT action request frame 202) according to a legacy process (e.g., see Figure 2 ). That is, the legacy AP may send the information from the FT action request frame 202 to the target AP via the DS and may receive a response from the target AP via the DS. At block 908, the legacy AP may transmit an FT action response frame 204. In this example, the FT action response frame 204 may lack the concurrent AP pre-authentication IE 402.

[0061] However, an AP 104 having the ability to perform concurrent AP pre-authentication (the "yes" branch of 904) may proceed to block 910, where the associated AP 104 may perform pre-authentication with all APs listed in the FT action request frame 202 via the DS, including those identified in the concurrent AP pre-authentication IE 402 in the FT frame body 302. Thus, in response to the FT action request frame, at block 912, the associated AP 104 may send an FT action response frame 204 that includes the concurrent AP pre-authentication IE 402. In this way, the associated AP104 may pre-authenticate multiple candidate target APs. Thus, in the case of a failure of FT pre-authentication with or re-association with a target AP, the associated AP 104 may reduce the transition latency.

[0062] Figure 10is a flowchart illustrating an exemplary process for a STA in accordance with some aspects of the present disclosure. As described below, certain embodiments may omit some or all of the illustrated features, and some of the illustrated features may not be required to implement all embodiments. In some examples, Figure 5 the STA 102 illustrated in Figure 10 may be configured to perform the Figure 10 process. In some examples, any suitable device or component for performing the functions or algorithms described below may execute the

[0063] process.

[0063] At block 1002, the STA 102 may send an FT action request frame that includes the concurrent AP pre - authentication IE 402 as described above and illustrated in Figure 4 . In some cases, the associated AP may lack the ability to perform concurrent AP pre - authentication as described in the present disclosure. In such a case, the associated AP may not expect or understand the concurrent AP pre - authentication IE 402. Thus, if the associated AP is not able to perform concurrent AP pre - authentication (the "no" branch of 1004), the process may proceed to block 1006, where the STA 102 may receive an FT action response frame 204. In this example, the FT action response frame 204 may lack the concurrent AP pre - authentication IE 402. That is, the FT action response frame 204 may appear as illustrated in Figure 2 and may include information related to only a single target AP.

[0064] At block 1008, the STA 102 may attempt to perform re - association with the pre - authenticated target AP. However, in some cases, the FT action response frame 204 may indicate that the pre - authentication process has failed; and in some cases, the re - association with the pre - authenticated target AP may fail. In such cases (the "no" branch of 1010), the process may return to block 1002. That is, if the legacy FToDS process lacking the concurrent AP pre - authentication IE 402 fails, the STA 102 has no choice but to restart the FToDS process.

[0065] However, if the associated AP has the ability to perform concurrent AP pre - authentication (the "yes" branch of 1004), the process may proceed to block 1012, and the STA 102 may receive an FT action response frame 204 that includes the concurrent AP pre - authentication IE 402 with pre - authentication information for a set of one or more candidate target APs.

[0066] Using the pre - authentication information corresponding to multiple target APs, at block 1014, the STA 102 can select from multiple pre - authenticated target APs and can perform the re - association process with the selected pre - authenticated target AP as described above. If the re - association with the selected target AP is unsuccessful (the "No" branch of 1016), the process can return to block 1014, where the STA 102 can select a different target AP from the multiple pre - authenticated target APs and can perform the re - association process with the selected pre - authenticated target AP. Thus, the STA 102 can avoid the need to restart the FToDS process upon re - association failure and can move to the next pre - authenticated target AP in its list for a re - association attempt.

[0067] Section 5.01 Additional Embodiments with Multiple Features :

[0068] The following numbered clauses are illustrative only and may be combined with aspects of other embodiments or teachings described herein, but are not limited thereto.

[0069] Clause 1: A method for wireless communication at a station (STA), the method comprising: outputting a request frame including a list of multiple candidate access points (APs); obtaining, in response to the request frame, a response frame including pre - authentication information for each of the multiple candidate APs; and transitioning a connection from a current associated AP to a first one of the multiple candidate APs based on the pre - authentication information.

[0070] Clause 2: The method according to Clause 1, wherein the request frame includes a concurrent AP pre - authentication information element (IE), the concurrent AP pre - authentication information element (IE) including: the list of the multiple candidate APs and a supplicant nonce (SNonce) for each respective candidate AP of the multiple candidate APs.

[0071] Clause 3: The method according to any one of Clauses 1 or 2, wherein the response frame includes a concurrent AP pre - authentication information element (IE), the concurrent AP pre - authentication information element (IE) including the list of the multiple candidate APs, the list of the multiple candidate APs including, for each respective candidate AP of the multiple candidate APs: an authenticator nonce (ANonce), a supplicant nonce (SNonce), and an R1 key holder identifier (R1KH - ID).

[0072] Clause 4: The method according to Clause 3, wherein the concurrent AP pre - authentication IE further includes a status field for indicating whether pre - registration corresponding to each respective candidate AP of the multiple candidate APs is successful.

[0073] Clause 5: The method according to Clause 3, the method further comprising: for each candidate AP among the plurality of candidate APs, generating a pairwise master key (PMK)-R1 and a pairwise transient key (PTK) based on the corresponding ANonce and the R1KH-ID; and storing the PMK-R1 and the PTK for each candidate AP in a memory.

[0074] Clause 6: The method according to Clause 5, the method further comprising at least one of the following: obtaining at least one packet from the first AP and decoding the at least one packet based on the PTK; or encoding at least one other packet based on the PTK and outputting the encoded at least one other packet for transmission.

[0075] Clause 7: A method for wireless communication at an access point (AP), the method comprising: obtaining a request frame from a station (STA), the request frame including a list of a plurality of candidate APs; communicating with each candidate AP among the plurality of candidate APs to pre-authenticate the STA; and outputting, in response to the request frame, a response frame including pre-authentication information for each candidate AP among the plurality of candidate APs.

[0076] Clause 8: The method according to Clause 7, wherein the request frame includes a concurrent AP pre-authentication information element (IE), the concurrent AP pre-authentication information element (IE) including: the list of the plurality of candidate APs and a supplicant nonce (SNonce) for each corresponding candidate AP among the plurality of candidate APs.

[0077] Clause 9: The method according to any one of Clauses 7 or 8, wherein the response frame includes a concurrent AP pre-authentication information element (IE), the concurrent AP pre-authentication information element (IE) including the list of the plurality of candidate APs, the list of the plurality of candidate APs including, for each corresponding candidate AP among the plurality of candidate APs: an authenticator nonce (ANonce), a supplicant nonce (SNonce), and a pairwise master key (PMK)-R1 key holder identifier (R1KH-ID).

[0078] Clause 10: The method according to Claim 9, wherein the concurrent AP pre-authentication IE further includes a status field for indicating whether pre-registration corresponding to each corresponding candidate AP among the plurality of candidate APs is successful.

[0079] Clause 11: A wireless station (STA), the wireless station (STA) comprising: a transceiver; a memory including instructions; and one or more processors configured to execute the instructions to cause the STA to perform the method according to any one of Clauses 1 to 6, wherein the transceiver is configured to: transmit a request frame; receive a response frame; and communicate with a first AP among a plurality of candidate APs.

[0080] Clause 12: An access point (AP), the access point (AP) comprising: a transceiver; a memory including instructions; and one or more processors configured to execute the instructions to cause the AP to perform the method according to any one of Clauses 7 to 10, wherein the transceiver is configured to: receive a request frame; and transmit a response frame.

[0081] Clause 13: A device for wireless communication, the device comprising components for performing the method according to any one of Examples 1 to 10.

[0082] Clause 14: A non-transitory computer-readable medium, the non-transitory computer-readable medium including instructions that, when executed by a device, cause the device to perform the method according to any one of Examples 1 to 10.

[0083] Clause 15: A device for wireless communication, the device comprising: a memory including instructions; and one or more processors configured to execute the instructions to cause the device to perform the method according to any one of Examples 1 to 10.

[0084] The detailed description set forth above in connection with the accompanying drawings is intended as a description of various configurations and is not intended to represent the only configurations in which the concepts described herein may be practiced. To provide a thorough understanding of the various concepts, the detailed description includes specific details. However, one of ordinary skill in the art will readily recognize that the concepts may be practiced without these specific details. In some instances, well-known structures and components are shown in block diagram form in order to avoid obscuring such concepts.

[0085] While this specification describes certain aspects and examples with reference to some illustrations, those skilled in the art will understand that additional specific implementations and use cases may arise in many different arrangements and scenarios. The innovations described herein can be implemented across many different platform types, devices, systems, shapes, sizes, packaging arrangements. For example, various specific implementations and / or uses can be generated via integrated chip (IC) implementations and other devices based on non-module components (e.g., end-user devices, vehicles, communication devices, computing devices, industrial equipment, retail / shopping devices, medical devices, artificial intelligence (AI)-enabled devices, etc.). Although some examples may or may not specifically point to use cases or applications, a wide variety of applicability of the described innovations may occur. Specific implementations can span the spectrum from chip-level or modular components to non-modular, non-chip-level implementations, and further to the spectrum of aggregated, distributed, or original equipment manufacturer (OEM) devices or systems that incorporate one or more aspects of the disclosed technology. In some practical settings, devices incorporating the described aspects and features will necessarily also include additional components and features for the specific implementation and practice of the implementations protected and described by the claims. For example, the transmission and reception of wireless signals includes several components for analog and digital purposes (e.g., hardware components including antennas, radio frequency (RF) chains, power amplifiers, modulators, buffers, processors, interleavers, adders / summers, etc.). It is intended that the disclosed technology can be practiced in a variety of devices, chip-level components, systems, distributed arrangements, end-user devices, etc. having various sizes, shapes, and configurations.

[0086] By way of example, various aspects of the present disclosure can be implemented within systems defined by 3GPP, such as Fifth Generation New Radio (5G NR), Long Term Evolution (LTE), Evolved Packet System (EPS), Universal Mobile Telecommunications System (UMTS), and / or Global System for Mobile Communications (GSM). The various aspects can also be extended to systems defined by the Third Generation Partnership Project 2 (3GPP2), such as CDMA2000 and / or Evolution-Data Optimized (EV-DO). Other examples can be implemented within systems employing IEEE 802.11 (Wi-Fi), IEEE 802.16 (WiMAX), IEEE 802.20, Ultra-Wideband (UWB), Bluetooth, and / or other suitable systems. The actual telecommunications standards, network architectures, and / or communication standards employed will depend on the specific application and the overall design constraints imposed on the system.

[0087] The present disclosure uses the term "exemplary" to mean "serving as an example, instance, or illustration". Any particular implementation or aspect described herein as "exemplary" is not necessarily to be construed as superior to or better than other aspects of the present disclosure. Similarly, the term "aspect" does not require that all aspects of the present disclosure include the described features, advantages, or modes of operation. The present disclosure uses the terms "coupled" and / or "communicatively coupled" to refer to either a direct or an indirect coupling between two objects. For example, if object A physically contacts object B and object B contacts object C, then objects A and C can still be considered to be coupled to each other even if they do not directly physically contact each other. For example, a first object can be coupled to a second object even if the first object has never directly physically contacted the second object. The present disclosure uses the term "circuit" and "circuitry" broadly to include both hardware implementations of electronic devices and conductors (where these electronic devices and conductors, when connected and configured, perform the functions described in the present disclosure, without limitation as to the type of electronic circuit) and software implementations of information and instructions (where these information and instructions, when executed by a processor, perform the functions described in the present disclosure).

[0088] Figures 1 through 10 One or more of the components, steps, features, and / or functions illustrated therein may be rearranged and / or combined into a single component, step, feature, or function or embodied in several components, steps, or functions. Additional elements, components, steps, and / or functions may also be added without departing from the novel features disclosed herein. Figures 1 through 10 The apparatuses, devices, and / or components illustrated therein may be configured to perform one or more of the methods, features, or steps described herein. The novel algorithms described herein may also be effectively implemented in software and / or embedded in hardware.

[0089] It should be understood that the specific order or hierarchy of the steps in the disclosed methods is an illustration of an exemplary process. It should be understood that based on design preferences, the specific order or hierarchy of these steps in the methods may be rearranged. The appended method claims present the elements of the various steps in an example order, but are not meant to be limited to the specific order or hierarchy presented unless expressly stated herein.

[0090] The applicant provides this description to enable any person skilled in the art to practice the various aspects described herein. Those skilled in the art will readily recognize various modifications to these aspects, and can apply the general principles defined herein to other aspects. The applicant does not intend for the claims to be limited to the aspects shown herein, but rather should be accorded the full scope consistent with the language of the claims, where a reference to an element in the singular is not intended to mean "one and only one" but rather "one or more" unless specifically stated otherwise. Unless specifically stated otherwise, the present disclosure uses the term "some" to refer to one or more. A phrase referring to "at least one" of a list of items means any combination of those items, including a single member. As an example, "at least one of a, b, or c" is intended to cover: a; b; c; a and b; a and c; b and c; and a, b, and c. All structural and functional equivalents of the elements of the various aspects described throughout this disclosure that are known or later will be known to those of ordinary skill in the art are expressly incorporated herein by reference and are intended to be covered by the claims. Moreover, nothing disclosed herein is intended to be dedicated to the public, whether or not such disclosure is expressly recited in the claims. No claim element shall be construed under the provisions of 35 U.S.C. § 112(f) unless the element is expressly recited using the phrase "means for" or, in the case of a method claim, the phrase "step for".

Claims

1. A method for wireless communication at a station (STA), the method comprising: Outputting a request frame including a list of multiple candidate access points (APs) for transmission; Obtaining, in response to the request frame, a response frame including pre - authentication information for each of the multiple candidate APs; And Based on the pre - authentication information, transitioning a connection from a current associated AP to a first AP among the multiple candidate APs.

2. The method according to claim 1, wherein the request frame includes a concurrent AP pre-authentication information element (IE), and the concurrent AP pre-authentication information element (IE) includes: The list of the multiple candidate APs and a supplicant nonce (SNonce) for each corresponding candidate AP among the multiple candidate APs.

3. The method according to claim 1, wherein the response frame includes a concurrent AP pre - authentication information element (IE), the concurrent AP pre - authentication information element (IE) including the list of the multiple candidate APs, and the list of the multiple candidate APs includes, for each corresponding candidate AP among the multiple candidate APs: An authenticator nonce (ANonce), A supplicant nonce (SNonce), and An R1 key holder identifier (R1KH - ID).

4. The method according to claim 3, wherein the concurrent AP pre - authentication IE further includes a status field for indicating whether pre - registration corresponding to each corresponding candidate AP among the multiple candidate APs is successful.

5. The method according to claim 3, the method further comprising: For each candidate AP among the multiple candidate APs, generating a pairwise master key (PMK) - R1 and a pairwise transient key (PTK) based on the corresponding ANonce and the R1KH - ID; And Storing the PMK - R1 and the PTK for each candidate AP in a memory.

6. The method according to claim 5, the method further comprising at least one of the following: Obtaining at least one packet from the first AP and decoding the at least one packet based on the PTK; or Encoding at least one other packet based on the PTK and outputting the encoded at least one other packet for transmission.

7. An apparatus for wireless communication, the apparatus comprising: A memory for storing instructions; And A processor coupled to the memory and configured to execute the instructions, the instructions including code for causing the apparatus to perform the following operations: Outputting a request frame including a list of multiple candidate access points (APs) for transmission; Obtaining, in response to the request frame, a response frame including pre - authentication information for each of the multiple candidate APs; And Based on the pre - authentication information, transitioning a connection from a current associated AP to a first AP among the multiple candidate APs.

8. The apparatus according to claim 7, wherein the request frame includes a concurrent AP pre-authentication information element (IE), and the concurrent AP pre-authentication information element (IE) includes: The list of the multiple candidate APs and a supplicant nonce (SNonce) for each corresponding candidate AP among the multiple candidate APs.

9. The apparatus according to claim 7, wherein the response frame includes a concurrent AP pre-authentication information element (IE), the concurrent AP pre-authentication information element (IE) includes the list of the plurality of candidate APs, and the list of the plurality of candidate APs includes, for each respective candidate AP of the plurality of candidate APs: Authenticator Nonce (ANonce), Supplicant Nonce (SNonce), and R1 Key Holder Identifier (R1KH-ID).

10. The apparatus according to claim 9, wherein the concurrent AP pre-authentication IE further includes a status field for indicating whether pre-registration corresponding to each respective candidate AP of the plurality of candidate APs is successful.

11. The apparatus according to claim 9, wherein the processor is further configured to execute instructions, the instructions including code for causing the apparatus to perform the following operations: For each candidate AP of the plurality of candidate APs, generate a pairwise master key (PMK)-R1 and a pairwise transient key (PTK) based on the corresponding ANonce and the R1KH-ID; and Store the PMK-R1 and the PTK for each candidate AP in a memory.

12. The apparatus according to claim 11, wherein the processor is further configured to execute instructions, the instructions including code for causing the apparatus to perform at least one of the following operations: Obtain at least one packet from the first AP and decode the at least one packet based on the PTK; or Encode at least one other packet based on the PTK, and output the encoded at least one other packet for transmission.

13. The apparatus according to claim 7, the apparatus further includes a transceiver, the transceiver being configured to: Transmit the request frame; Receive the response frame; and Transition the connection from the current associated AP to the first AP, wherein the apparatus is configured as a STA.

14. An apparatus for wireless communication, the apparatus includes: A memory for storing instructions; And A processor coupled to the memory and configured to execute the instructions, the instructions including code for causing the apparatus to perform the following operations: Obtain a request frame from a station (STA), the request frame including a list of a plurality of candidate access points (APs); Communicate with each candidate AP of the plurality of candidate APs to pre-authenticate the STA; And In response to the request frame, output a response frame including pre-authentication information for each candidate AP of the plurality of candidate APs for transmission.

15. The apparatus according to claim 14, wherein the request frame includes a concurrent AP pre-authentication information element (IE), and the concurrent AP pre-authentication information element (IE) includes: The list of the plurality of candidate APs and the Supplicant Nonce (SNonce) for each respective candidate AP of the plurality of candidate APs.

16. The apparatus according to claim 14, wherein the response frame includes a concurrent AP pre-authentication information element (IE), the concurrent AP pre-authentication information element (IE) includes the list of the plurality of candidate APs, and the list of the plurality of candidate APs includes, for each respective candidate AP of the plurality of candidate APs: Authenticator Nonce (ANonce), Supplicant Nonce (SNonce), and a Pairwise Master Key (PMK)-R1 Key Holder Identifier (R1KH-ID) for each respective candidate AP of the plurality of candidate APs.

17. The apparatus according to claim 16, wherein the concurrent AP pre-authentication IE further includes a status field for indicating whether pre-registration corresponding to each respective candidate AP of the plurality of candidate APs is successful.

18. The apparatus according to claim 14, the apparatus further comprising: a transceiver configured to: receive the request frame from the STA; and transmit the response frame, wherein the apparatus is configured as an AP.