Communication method and system between access controller and access point based on two-layer protocol

The IEEE1905 protocol realizes layer 2 communication between AC and AP, solving the performance bottlenecks, security risks and compatibility problems brought by the CAPWAP protocol, and providing easy-to-use and efficient network management and secure connections.

CN120282167AActive Publication Date: 2025-07-08GUANGZHOU XINDE COMMUNICATION TECHNOLOGY CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510305021.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-14
Publication Date
2025-07-08
Estimated Expiration
2045-03-14

AI Technical Summary

Technical Problem

In the prior art, the use of the CAPWAP protocol for communication between AC and AP leads to performance bottlenecks, security risks, overload controller load and incompatibility problems.

Method used

The layer two protocol based on the IEEE1905 protocol is adopted to realize communication between AC and AP through custom encrypted configuration information and control instructions, including access control, configuration management and task control.

Benefits of technology

Simplifies network setup and device introduction, supports a variety of home network technologies, ensures network security and quality, is compatible with existing devices, and achieves seamless integration and efficient management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120282167A_ABST
    Figure CN120282167A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method and system between an access controller and an access point based on a two-layer protocol. The method comprises the following steps: the access controller receives a first message sent by the access point; the access controller judges whether the access of the access point is allowed or not, and if the access of the access point is allowed, a second message is sent to the access point; the access controller receives a third message and a configuration request sent by the access point after receiving the second message; the access controller sends configuration information to the access point; the access controller sends a fourth message to the access point; and the access controller receives a fifth message after the access point receives the fourth message, wherein the fifth message comprises a processing result after the access point receives the fourth message. According to the invention, the network setting and use are simplified, so that the operations of adding equipment to the network, establishing a secure link, realizing QoS and the like are relatively simple for consumers.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of wireless local area network communication, and more specifically, to a communication method and system between an access controller and an access point based on a layer 2 protocol. Background Art

[0002] The network devices of the AC and AP system in a wireless local area network are divided into two main parts: one is an access controller (referred to as AC for short), and the other is an access point (referred to as AP for short). The AC is responsible for managing the access points (referred to as APs for short) in the wireless network within the area. Its main functions include: issuing configurations to the APs, upgrade management, user access control, roaming control, etc. The AP is a bridge connecting the wireless network and the wired network, connecting wireless network stations (referred to as STAs for short) together and accessing the wired network.

[0003] Currently, in the application of a wireless network environment, the AC and the AP interact through the CAPWAP (Control And Provisioning of Wireless Access Points Protocol) protocol. The AC completes the management and service configuration of the AP through the CAPWAP protocol, and the STA accesses the network by selecting a suitable AP.

[0004] CAPWAP is a general tunnel protocol. CAPWAP packets are formed by encapsulating a CAPWAP tunnel header on the basis of traditional TCP / IP packets and using the UDP protocol as the basis. Therefore, there are the following disadvantages:

[0005] 1) CAPWAP itself may become a bottleneck of network performance because it requires additional processing power to handle additional encapsulation overhead;

[0006] 2) If configured improperly, it may increase security risks because CAPWAP communication may be intercepted and parsed;

[0007] 3) Since CAPWAP needs to establish continuous communication between the access point and the controller, this may cause the controller to be overloaded;

[0008] 4) In some cases, CAPWAP may be incompatible with certain specific access point hardware or software, such as the existence of NAT devices or firewalls; Summary of the Invention

[0009] One of the objectives of the present invention is to provide a communication method between an access controller and an access point based on a layer - two protocol, so as to solve the technical problems such as performance bottleneck, security risk, over - heavy controller load and incompatibility brought by using the CAPWAP protocol in the prior art; the second objective of the present invention is to provide a communication system between an access controller and an access point based on a layer - two protocol.

[0010] To solve the above - mentioned technical problems, the technical solution of the present invention is as follows:

[0011] The first aspect of the present invention provides a communication method between an access controller and an access point based on a layer - two protocol, including the following steps:

[0012] The access controller receives a first message sent by the access point;

[0013] The access controller determines whether to allow the access of the access point. If allowed, it sends a second message to the access point;

[0014] The access controller receives a third message and a configuration request sent by the access point after the access point receives the second message;

[0015] The access controller sends configuration information to the access point;

[0016] The access controller sends a fourth message to the access point;

[0017] The access controller receives a fifth message from the access point after the access point receives the fourth message. The fifth message includes the processing result of the access point after receiving the fourth message.

[0018] Furthermore, if the access controller determines not to allow the access of the access point, it discards the first message.

[0019] Furthermore, the configuration information is custom - encrypted configuration information.

[0020] Furthermore, the fourth message includes an encrypted control instruction, and the control instruction is used to control the access point to complete a preset task.

[0021] The second aspect of the present invention provides a communication method between an access controller and an access point based on a layer - two protocol, including the following steps:

[0022] The access point sends a first message to the access controller;

[0023] The access point receives a second message sent by the access controller after the access controller receives the first message;

[0024] The access point sends a third message and a configuration request to the access controller;

[0025] The access point receives the configuration information sent by the access controller after receiving the configuration request;

[0026] The access point obtains configuration parameters according to the configuration information, and completes configuration management according to the configuration parameters;

[0027] The access point receives the fourth message;

[0028] After the access point completes a preset task according to the fourth message, it sends a fifth message to the access controller, and the fifth message includes the processing result of the access point after receiving the fourth message.

[0029] Further, the access point obtaining configuration parameters according to the configuration information includes:

[0030] The configuration information is custom-encrypted configuration information;

[0031] The access point decrypts the configuration information to obtain configuration parameters.

[0032] Further, the fourth message includes an encrypted control instruction for controlling the access point to complete a preset task.

[0033] Further, after the access point completes a preset task according to the fourth message, it includes:

[0034] The access point decrypts the fourth message to obtain a control instruction, and the access point completes a preset task according to the control instruction.

[0035] The third aspect of the present invention provides a communication method between an access controller and an access point based on a layer 2 protocol, including:

[0036] The access point sends a first message to the access controller;

[0037] The access controller receives the first message sent by the access point;

[0038] The access controller determines whether to allow the access of the access point. If allowed, it sends a second message to the access point;

[0039] The access point receives the second message;

[0040] The access point sends a third message and a configuration request to the access controller;

[0041] The access controller receives the third message and the configuration request;

[0042] The access controller sends configuration information to the access point;

[0043] The access point receives the configuration information;

[0044] The access point obtains configuration parameters according to the configuration information and completes configuration management according to the configuration parameters;

[0045] The access controller sends a fourth message to the access point;

[0046] The access point receives the fourth message;

[0047] After the access point completes a preset task according to the fourth message, it sends a fifth message to the access controller, and the fifth message includes the processing result of the access point after receiving the fourth message;

[0048] The access controller receives the fifth message of the access point after receiving the fourth message.

[0049] The fourth aspect of the present invention provides a communication system between an access controller and an access point based on a layer - two protocol, which is characterized by including an access controller and an access point, wherein the access controller and the access point adopt the communication method between the access controller and the access point based on the layer - two protocol.

[0050] Compared with the prior art, the beneficial effects of the technical solution of the present invention are:

[0051] The present invention provides a communication method for realizing communication between an access controller and an access point based on a layer - two protocol, which simplifies network setup and usage, making operations such as adding devices to the network, establishing secure links, and implementing QoS relatively simple for consumers; supports multiple home network technologies, including Wi - Fi, Ethernet, and MoCA, without modifying the underlying network technology, and thus can be compatible with already deployed home network devices; at the same time, the communication method provided by the present invention includes discovery and interface selection, which simplifies the introduction of new devices and network management. In addition, by encrypting user data, information security is guaranteed. Brief Description of the Drawings

[0052] Figure 1 A flow diagram of the access controller in a communication method between an access controller and an access point based on a layer - two protocol provided for Embodiment 1;

[0053] Figure 2 A flow diagram of the access point in a communication method between an access controller and an access point based on a layer - two protocol provided for Embodiment 2;

[0054] Figure 3 A flow diagram of the interaction between the access controller and the access point in a communication method between an access controller and an access point based on a layer - two protocol provided for Embodiment 3;

[0055] Figure 4Schematic diagram of the connection between the access controller, access point, and terminal device provided by the embodiments of the present invention. Detailed implementation manners

[0056] The accompanying drawings are only for illustrative purposes and should not be construed as limiting the present patent;

[0057] To better illustrate the present embodiment, some components in the accompanying drawings are omitted, enlarged, or reduced, and do not represent the dimensions of the actual product;

[0058] For those skilled in the art, it is understandable that some well-known structures and their descriptions in the accompanying drawings may be omitted.

[0059] The technical solution of the present invention will be further described below in conjunction with the accompanying drawings and embodiments.

[0060] Embodiment 1

[0061] The embodiments of the present invention provide a communication method between an access controller and an access point based on a layer 2 protocol. As Figure 1 shown in the processing flow of the access controller, it includes the following steps:

[0062] The access controller receives a first message sent by the access point;

[0063] The access controller determines whether to allow the access of the access point. If allowed, it sends a second message to the access point;

[0064] The access controller receives a third message and a configuration request sent by the access point after receiving the second message;

[0065] The access controller sends configuration information to the access point;

[0066] The access controller sends a fourth message to the access point;

[0067] The access controller receives a fifth message from the access point after receiving the fourth message. The fifth message includes the processing result of the access point after receiving the fourth message.

[0068] In a specific embodiment, the embodiments of the present invention use the IEEE1905 protocol as the layer 2 protocol used. The advantages of the IEEE1905 protocol include:

[0069] 1) Ease of use: The 1905 protocol provides an adaptation layer, which simplifies network setup and use, making operations such as adding devices to the network, establishing secure links, and implementing QoS relatively simple for consumers.

[0070] 2) Compatibility: The 1905 protocol supports a variety of home network technologies, including Wi-Fi, Ethernet, and MoCA, without modifying the underlying network technology, so it is compatible with already deployed home network devices.

[0071] 3) Seamless integration: The 1905 protocol introduces an intermediate sublayer between the logical link control (LLC) layer and the underlying network technology MAC sublayer, abstracting the details of each interface, aggregating available bandwidth, and promoting seamless integration.

[0072] 4) End-to-end QoS: The protocol supports end-to-end QoS, ensuring the quality of network services.

[0073] 5) Secure connection: The 1905 protocol supports the establishment of secure connections, ensuring the security of the network.

[0074] 6) Advanced network management capabilities: including discovery and interface selection, simplifying the introduction of new devices and network management.

[0075] 7) User data encryption processing: to ensure information security.

[0076] This embodiment processes the IEEE1905 protocol message to realize the communication between the AC and the AP, so as to achieve the purpose of the AC managing and controlling the AP. The specific implementation steps are as follows:

[0077] S1.AP initiates a broadcast packet to search for AC through AP autoconfiguration search message;

[0078] S2. The AC receives the AP autoconfiguration search message to determine whether the AP is authorized. If authorized, it notifies the AP that it can access through the Topology query message.

[0079] S3. After receiving the Topology query message, AP replies with a Topology response message and sends WSCM1 to request configuration information;

[0080] After receiving M1, S4.AC sends the custom encryption configuration through WSC M2;

[0081] S5. After receiving M2, AP decrypts and takes effect the corresponding parameters, thus completing the configuration management; M2 message carries the AP configuration information

[0082] S6. If the AC needs to control the AP, it sends the vendor-specific encrypted content in the Higher layer query message to the AP; the management information of the AP is carried in the Higher layer query message.

[0083] S7. After receiving the HL query, the AP decrypts it and performs corresponding processing, and then replies with a Higher layer response message.

[0084] In a further embodiment, if the access controller determines that the access of the access point is not allowed, the first message is discarded.

[0085] In a further embodiment, the configuration information is custom-encrypted configuration information to avoid information leakage.

[0086] In a further embodiment, the fourth message includes an encrypted control instruction, and the control instruction is used to control the access point to complete a preset task.

[0087] Embodiment 2

[0088] This embodiment provides a communication method between an access controller and an access point based on a layer-2 protocol. As Figure 2 shown in the processing flow of the access point, it includes the following steps:

[0089] The access point sends a first message to the access controller;

[0090] The access point receives the second message sent by the access controller after receiving the first message;

[0091] The access point sends a third message and a configuration request to the access controller;

[0092] The access point receives the configuration information sent by the access controller after receiving the configuration request;

[0093] The access point obtains configuration parameters according to the configuration information, and completes configuration management according to the configuration parameters;

[0094] The access point receives the fourth message;

[0095] After the access point completes the preset task according to the fourth message, it sends a fifth message to the access controller, and the fifth message includes the processing result of the access point after receiving the fourth message.

[0096] In a specific embodiment, the embodiment of the present invention uses the IEEE1905 protocol as the layer-2 protocol used. The advantages of the IEEE1905 protocol include:

[0097] 1) Ease of use: The 1905 protocol provides an adaptation layer that simplifies network setup and use, making operations such as adding devices to the network, establishing secure links, and implementing QoS relatively simple for consumers.

[0098] 2) Compatibility: The 1905 protocol supports a variety of home network technologies, including Wi-Fi, Ethernet, and MoCA, without modifying the underlying network technology, so it is compatible with already deployed home network devices.

[0099] 3) Seamless integration: The 1905 protocol introduces an intermediate sublayer between the logical link control (LLC) layer and the underlying network technology MAC sublayer, abstracting the details of each interface, aggregating available bandwidth, and promoting seamless integration.

[0100] 4) End-to-end QoS: The protocol supports end-to-end QoS, ensuring the quality of network services.

[0101] 5) Secure connection: The 1905 protocol supports the establishment of secure connections, ensuring the security of the network.

[0102] 6) Advanced network management capabilities: including discovery and interface selection, simplifying the introduction of new devices and network management.

[0103] 7) User data encryption processing: to ensure information security.

[0104] This embodiment processes the IEEE1905 protocol message to realize the communication between the AC and the AP, so as to achieve the purpose of the AC managing and controlling the AP. The specific implementation steps are as follows:

[0105] S1.AP initiates a broadcast packet to search for AC through AP autoconfiguration search message;

[0106] S2. The AC receives the AP autoconfiguration search message to determine whether the AP is authorized. If authorized, it notifies the AP that it can access through the Topology query message.

[0107] S3. After receiving the Topology query message, AP replies with a Topology response message and sends WSCM1 to request configuration information;

[0108] After receiving M1, S4.AC sends the custom encryption configuration through WSC M2;

[0109] S5. After receiving M2, AP decrypts and takes effect the corresponding parameters, thus completing the configuration management; M2 message carries the AP configuration information

[0110] S6. If the AC needs to control the AP, it sends the vendor specific encrypted content in the Higher layer query message to the AP; the management information of the AP is carried in the Higher layer query message.

[0111] S7. After receiving the HL query, the AP decrypts it and performs corresponding processing, and then replies with a Higher layer response message.

[0112] In a further embodiment, the access point obtains configuration parameters according to the configuration information, including:

[0113] The configuration information is custom encrypted configuration information to avoid information leakage.

[0114] The access point decrypts the configuration information to obtain configuration parameters.

[0115] In a further embodiment, the fourth message includes an encrypted control instruction, and the control instruction is used to control the access point to complete a preset task.

[0116] In a further embodiment, after the access point completes the preset task according to the fourth message, it includes:

[0117] The access point decrypts the fourth message to obtain a control instruction, and the access point completes the preset task according to the control instruction.

[0118] Embodiment 3

[0119] The embodiment of the present invention provides a communication method between an access controller and an access point based on a layer 2 protocol, as Figure 3 shown in the processing flow of the interaction between the access controller and the access point, including:

[0120] The access point sends a first message to the access controller;

[0121] The access controller receives the first message sent by the access point;

[0122] The access controller determines whether to allow the access of the access point. If allowed, it sends a second message to the access point;

[0123] The access point receives the second message;

[0124] The access point sends a third message and a configuration request to the access controller;

[0125] The access controller receives the third message and the configuration request;

[0126] The access controller sends configuration information to the access point;

[0127] The access point receives the configuration information;

[0128] The access point obtains configuration parameters according to the configuration information, and completes configuration management according to the configuration parameters;

[0129] The access controller sends a fourth message to the access point;

[0130] The access point receives the fourth message;

[0131] After the access point completes a preset task according to the fourth message, it sends a fifth message to the access controller, and the fifth message includes the processing result of the access point after receiving the fourth message;

[0132] The access controller receives the fifth message of the access point after receiving the fourth message.

[0133] In a specific embodiment, the embodiment of the present invention uses the IEEE1905 protocol as the used layer 2 protocol. The advantages of the IEEE1905 protocol include:

[0134] 1) Ease of use: The 1905 protocol provides an adaptation layer, simplifies network setup and use, and makes operations such as adding devices to the network, establishing secure links, and implementing QoS relatively simple for consumers.

[0135] 2) Compatibility: The 1905 protocol supports multiple home network technologies, including Wi-Fi, Ethernet, and MoCA, without modifying the underlying network technology, and thus can be compatible with already deployed home network devices.

[0136] 3) Seamless integration: The 1905 protocol introduces an intermediate sublayer between the logical link control (LLC) layer and the underlying network technology MAC sublayer, abstracts the details of each interface, aggregates the available bandwidth, and promotes seamless integration.

[0137] 4) End-to-end QoS: The protocol supports end-to-end QoS, ensuring the quality of network services.

[0138] 5) Secure connection: The 1905 protocol supports the establishment of secure connections, ensuring the security of the network.

[0139] 6) Advanced network management functions: including discovery and interface selection, which simplifies the introduction of new devices and network management.

[0140] 7) User data encryption processing: Ensure information security.

[0141] This embodiment processes the IEEE1905 protocol message to realize the communication between the AC and the AP, so as to achieve the purpose of the AC managing and controlling the AP. The specific implementation steps are as follows:

[0142] S1.AP initiates a broadcast packet to search for AC through AP autoconfiguration search message;

[0143] S2. The AC receives the AP autoconfiguration search message to determine whether the AP is authorized. If authorized, it notifies the AP that it can access through the Topology query message.

[0144] S3. After receiving the Topology query message, AP replies with a Topology response message and sends WSCM1 to request configuration information;

[0145] After receiving M1, S4.AC sends the custom encryption configuration through WSC M2;

[0146] S5. After receiving M2, AP decrypts and takes effect the corresponding parameters, thus completing the configuration management; M2 message carries the AP configuration information

[0147] S6. If the AC needs to control the AP, it sends the vendor specific encrypted content in the Higher layer query message to the AP; the Higher layer query message carries the management information of the AP;

[0148] S7. After receiving the HL query, the AP decrypts it, processes it accordingly, and replies with a Higher layer response message.

[0149] like Figure 4 As shown, there is 1 AC controller (device A), 1 AP access terminal (device B), and 1 STA terminal device (device C).

[0150] The process of establishing communication between device A and device B is as follows:

[0151] Step 1: Device B sends an AP autoconfiguration search message;

[0152] Step 2: Device A receives the AP autoconfiguration search, determines whether access is allowed, and then sends a Topology query message;

[0153] Step 3: After receiving the Topology query message, Device B replies with a Topology response message and simultaneously sends a WSC M1 request for configuration information;

[0154] Step 4: After receiving M1, Device A distributes the custom-encrypted configuration through WSC M2;

[0155] Step 5: After receiving M2, Device B decrypts it and enables the corresponding parameters, thus completing the configuration management;

[0156] Step 6: When Device A needs to control Device B, it sends the vendor-specific encrypted content in the Higher layer query message to Device B;

[0157] Step 7: After receiving the HL query, Device B decrypts it and performs corresponding processing, and replies with a Higher layer response message;

[0158] After the above steps, Device A and Device B establish a communication mechanism, so that Device A and Device B form a wireless local area network through the IEEE1905 protocol, and then the STA device C accesses the Internet through Device B and Device A.

[0159] Embodiment 4

[0160] The embodiment of the present invention provides a communication system between an access controller and an access point based on a layer-2 protocol, including an access controller and an access point. Among them, the access controller and the access point adopt the communication method between the access controller and the access point based on the layer-2 protocol as described in any one of Embodiments 1 to 3.

[0161] The same or similar reference numerals correspond to the same or similar components;

[0162] The terms used to describe the positional relationship in the drawings are only for illustrative purposes and cannot be construed as a limitation of this patent;

[0163] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the present invention, rather than limitations on the implementation manners of the present invention. For those of ordinary skill in the art, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to enumerate all the implementation manners here. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention shall be included in the protection scope of the claims of the present invention.

Claims

1. A communication method between an access controller and an access point based on a layer 2 protocol, characterized in that It includes the following steps: The access controller receives the first message sent by the access point; The access controller determines whether to allow the access of the access point. If allowed, it sends a second message to the access point; The access controller receives the third message and the configuration request sent by the access point after receiving the second message; The access controller sends configuration information to the access point; The access controller sends a fourth message to the access point; The access controller receives the fifth message from the access point after the access point receives the fourth message. The fifth message includes the processing result of the access point after receiving the fourth message.

2. The communication method between an access controller and an access point based on a two-layer protocol according to claim 1, characterized in that, If the access controller determines not to allow the access of the access point, it discards the first message.

3. The communication method between an access controller and an access point based on a layer 2 protocol according to claim 1, wherein The configuration information is custom-encrypted configuration information to prevent interception and eavesdropping.

4. The communication method between an access controller based on a layer 2 protocol and an access point according to claim 1, wherein The fourth message includes an encrypted control instruction, and the control instruction is used to control the access point to complete a preset task.

5. A communication method between an access controller and an access point based on a layer 2 protocol, characterized in that It includes the following steps: The access point sends a first message to the access controller; The access point receives the second message sent by the access controller after receiving the first message; The access point sends a third message and a configuration request to the access controller; The access point receives the configuration information sent by the access controller after receiving the configuration request; The access point obtains configuration parameters according to the configuration information and completes configuration management according to the configuration parameters; The access point receives the fourth message; After the access point completes the preset task according to the fourth message, it sends a fifth message to the access controller. The fifth message includes the processing result of the access point after receiving the fourth message.

6. The communication method between an access controller and an access point based on a two-layer protocol according to claim 5, characterized in that, The access point obtains configuration parameters according to the configuration information, including: The configuration information is custom-encrypted configuration information; The access point decrypts the configuration information to obtain configuration parameters.

7. The communication method between an access controller and an access point based on a layer 2 protocol according to claim 5, wherein The fourth message includes an encrypted control instruction, and the control instruction is used to control the access point to complete a preset task.

8. The communication method between the access controller and the access point based on the second-layer protocol according to claim 5, wherein After the access point completes the preset task according to the fourth message, it includes: The access point decrypts the fourth message to obtain the control instruction, and the access point completes the preset task according to the control instruction.

9. A communication method between an access controller and an access point based on a layer 2 protocol, characterized in that, It includes: The access point sends a first message to the access controller; The access controller receives the first message sent by the access point; The access controller determines whether to allow the access of the access point. If allowed, it sends a second message to the access point; The access point receives the second message; The access point sends a third message and a configuration request to the access controller; The access controller receives the third message and the configuration request; The access controller sends configuration information to the access point; The access point receives the configuration information; The access point obtains configuration parameters according to the configuration information and completes configuration management according to the configuration parameters; The access controller sends a fourth message to the access point; The access point receives the fourth message; After the access point completes the preset task according to the fourth message, it sends a fifth message to the access controller. The fifth message includes the processing result of the access point after receiving the fourth message; The access controller receives the fifth message from the access point after the access point receives the fourth message.

10. A communication system between an access controller and an access point based on a layer 2 protocol, characterized in that, It includes an access controller and an access point. Among them, the access controller and the access point adopt the communication method between the access controller and the access point based on the layer 2 protocol as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • An access method and access device of AP to AC in wireless LAN

    CN101217440A

  • Wireless access control method, wireless access point and wireless access controller

    CN103260150A

  • Wireless access point safe authentication method and system

    CN104125568A

  • Lightweight WLAN small-size wireless network networking method

    CN108419305A

  • Method and system for discovering cloud access controller by access point

    WO2017177798A1