Wireless local area network system, communication method and device
By using the same group temporary key in the wireless LAN system, collaborative multicast or broadcast between multiple access points is achieved, solving the problem of low communication efficiency, improving communication efficiency and reliability, and enhancing the system's compatibility and ease of management.
Patent Information
- Application Number
- CN202510916666.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-24
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2042-02-24
AI Technical Summary
In a wireless local area network system consisting of multiple access points, each station can only receive multicast or broadcast messages from the access point associated with itself, resulting in low communication efficiency.
By using the same group transient key (GTK), the first access point and the second access point multicast or broadcast messages to the first station and the second station, thereby improving communication efficiency.
It improves the efficiency and reliability of multicast or broadcast communications, enhances compatibility with different types of sites, and provides improvements in signal quality and management complexity.
Smart Images

Figure CN120676323A_ABST
Abstract
Description
[0001] This application is a divisional application. The application number of the original application is 202210175153.4, and the original application date is February 24, 2022. The entire content of the original application is incorporated into this application by reference. Technical Field
[0002] The present application relates to the field of wireless communications, and in particular to wireless local area network systems, communication methods, and devices. Background Art
[0003] In wireless local area networks (WLANs), access points (APs) can transmit messages to stations (STAs) via unicast, multicast, or broadcast. To improve communication security, APs use a group transient key (GTK) to encrypt multicast or broadcast messages. When a STA associates with an AP, it obtains the GTK from the AP. The STA uses the GTK to decrypt multicast or broadcast messages. In practical applications, to improve wireless signal coverage, multiple APs can be used to form a WLAN system.
[0004] In a WLAN system consisting of multiple APs, each STA can only receive multicast or broadcast messages from the AP associated with it, resulting in low multicast or broadcast communication efficiency of the AP. Summary of the Invention
[0005] The present application provides a wireless local area network system, a communication method, and an apparatus. By using the same GTK, a first AP can multicast or broadcast a first message to a first STA and a second STA, thereby improving the multicast or broadcast communication efficiency of the first AP.
[0006] In a first aspect, the present application provides a WLAN system. The WLAN system includes an access controller (AC), a first AP, and a second AP. The first AP is associated with a first STA. The second AP is associated with the second STA. The AC is used to generate a first GTK and send the first GTK to the first AP and the second AP. The first AP is used to encrypt data using the first GTK, obtain a first message, and multicast or broadcast the first message. The first AP is used to send the first GTK to the first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The second AP is used to send the first GTK to the second STA. The first GTK is used by the second STA to decrypt the first message based on the first GTK.
[0007] In an optional manner of the first aspect, the AC is configured to generate a first GTK according to a group master key (GMK), a group random number, and a medium access control (MAC) address of the AC.
[0008] In an optional manner of the first aspect, the AC is configured to send a first message to a first AP and a second AP. The first message includes a first GTK. The first message also includes at least one of the following: identifiers of the first AP and the second AP, an identifier of a virtual access point (VAP) in the first AP, an identifier of the VAP in the second AP, a key replay counter, a receive sequence counter, a group random number, and an integrity group temporary key. By adding one or more of the aforementioned contents, the reliability of multicast or broadcast can be improved. For example, the first AP uses the first GTK based on the identifier of the first AP in the first message. The second AP uses the first GTK based on the identifier of the second AP in the first message. The WLAN system also includes a third AP. The first message does not carry the identifier of the third AP. After receiving the first message, the third AP does not use the first GTK. The AC may also generate a second message. The second message carries the second GTK and the identifier of the third AP. The third AP uses the second GTK based on the identifier of the third AP. Therefore, by adding the identifier of the AP, the reliability of the multicast or broadcast can be improved.
[0009] In an optional embodiment of the first aspect, the AC is further configured to send a first instruction to the first AP and the second AP. The first AP is further configured to disable automatic GTK updates according to the first instruction. The second AP is further configured to disable automatic GTK updates according to the first instruction. When the AC is the first AP, the first AP does not need to send the first instruction to the first AP. The first AP sends the first instruction to the second AP. In the present application, the first instruction can prevent the first AP and the second AP from automatically updating the first GTK, resulting in different GTKs for the first AP and the second AP. Therefore, the present application can improve the reliability of multicast or broadcast.
[0010] In an optional embodiment of the first aspect, when a new AP connects to the AC, the AC is further configured to send a first message to the new AP. When the AC is the first AP, the first AP is further configured to send the first message to the new AP. If the new AP uses the first GTK, the first AP may multicast or broadcast the first message to STAs associated with the new AP. Therefore, this application can further improve the communication efficiency of multicast or broadcast.
[0011] In an optional manner of the first aspect, when any of the following conditions is met, the AC is further configured to send an updated first GTK to the first AP and the second AP. The conditions include: AC restart, AC key timer expiration, AC encryption mode changed from public to encrypted, or a STA using the first GTK goes offline. Updating the first GTK can improve multicast or broadcast security.
[0012] In an optional manner of the first aspect, the AC is further configured to update the first GTK according to the updated GMK, the updated group random number, and the MAC address of the AC to obtain an updated first GTK.
[0013] In an optional manner of the first aspect, the WLAN system also includes a third AP. The AC is also used to obtain group reference information of the three APs. The three APs include a first AP, a second AP, and a third AP. The AC is also used to determine that the first AP and the second AP use a first GTK based on the group reference information. The AC is also used to determine that the third AP uses a second GTK based on the group reference information. The second GTK is different from the first GTK. The distances between multiple APs in the WLAN system may be far. At this time, the AC can group multiple APs based on the group reference information. APs within a group use the same GTK, and APs in different groups use different GTKs. Therefore, the present application can improve the security of multicast or broadcast on the basis of improving the communication efficiency of multicast or broadcast.
[0014] In an optional manner of the first aspect, the AC is further used to send a second GTK to a third AP. Or, the AC is further used to send a control instruction to the third AP. The third AP is used to generate a second GTK according to the control instruction. According to the previous description, the AC can group multiple APs. For example, the first AP and the second AP belong to the first group. The third AP belongs to the second group. Different control centers may exist for different groups. For example, the control center of the first group may be the AC. The AC may be the first AP or the second AP. The control center of the second group may be the third AP. The control center is used to generate and update the GTK within the group. Therefore, by assigning different control centers to different groups, the complexity of management can be reduced.
[0015] In an optional manner of the first aspect, the grouping reference information includes channel quality information between APs, location information of STAs associated with the three APs, or on-demand information of STAs associated with the three APs. The channel quality information between APs includes channel quality information between any two of the three APs. The channel quality information between two APs, to a certain extent, represents the distance between the two APs. The distance between the two APs, to a certain extent, represents the channel quality information between a STA associated with one AP and another AP. Therefore, by grouping based on the channel quality information between APs or the location information of STAs associated with the three APs, the communication quality of multicast or broadcast can be improved. When the on-demand information of multiple STAs is the same, the on-demand information can be multicast or broadcast to multiple STAs through a single AP. Therefore, by grouping on-demand information, the communication efficiency of the AP can be improved.
[0016] In an optional embodiment of the first aspect, the second STA is further configured to roam from the second AP to the first AP. The first AP is further configured to encrypt data using the first GTK to obtain a second message, and multicast or broadcast the second message. The second STA is further configured to decrypt the second message based on the first GTK. Specifically, when the first AP and the second AP use different GTKs, after the second STA roams from the second AP to the first AP, the first AP may not be able to send the first AP's GTK to the second STA in a timely manner. Therefore, the second STA may not be able to normally decrypt the message multicast or broadcast by the first AP. At this point, the second STA may exhibit abnormal behavior. For example, the second STA disconnects from the first AP and re-associates with the first AP. In the present application, the first AP and the second AP use the same GTK. Therefore, even if the first AP does not send the first AP's GTK to the second STA in a timely manner, the second STA can use the GTK sent by the second AP to decrypt the message multicast or broadcast by the first AP. Therefore, the present application can improve the reliability of multicast or broadcast.
[0017] In an optional manner of the first aspect, the first AP and the second AP use the same basic service set identifier (BSSID). Among them, certain types of STAs may only receive messages multicast or broadcast by the associated AP based on the BSSID. If the BSSIDs of the first AP and the second AP are different, the second STA may discard the first message. By using the same BSSID, the second STA can normally receive the message multicast or broadcast by the first AP. At this time, the BSSID carried in the first message is the same as the BSSID of the second AP. Therefore, the present application can improve the compatibility with different types of STAs.
[0018] In an optional manner of the first aspect, the first message is a multicast message. The destination IP address of the first message is the IP address of the first multicast group. When the first STA belongs to the first multicast group, the first STA is used to process the decrypted first message. When the first STA does not belong to the first multicast group, the first STA is used to discard the decrypted first message. Different STAs associated with an AP can belong to different multicast groups. Dividing different multicast groups by IP addresses can improve the flexibility of multicast. Similarly, when the second STA belongs to the first multicast group, the second STA is used to process the decrypted first message. When the second STA does not belong to the first multicast group, the second STA is used to discard the decrypted first message.
[0019] In an optional manner of the first aspect, the signal quality information between the second STA and the first AP is greater than a first threshold. As can be seen from the previous description, the present application can group APs in a WLAN system. In practical applications, the AC can also group STAs. For example, when the signal quality information between the second STA and the first AP is greater than the first threshold, the AC determines that the second STA belongs to the first multicast group. When the signal quality information between the second STA and the first AP is less than the first threshold, the AC determines that the second STA does not belong to the first multicast group. At this time, the second STA can receive multicast or broadcast messages from other APs. The other APs can be the second AP or the third AP, etc. In the present application, by grouping STAs, the communication quality of multicast or broadcast can be improved while improving the efficiency of multicast or broadcast communication.
[0020] A second aspect of the present application provides a wireless communication method. The wireless communication method includes the following steps: an AC generates a first GTK. The AC sends the first GTK to a first access point (AP) and a second access point (AP). The first GTK is used by a first STA and a second STA to decrypt a first message multicast or broadcast by the first AP. The first AP associates with the first STA. The second AP associates with the second STA.
[0021] In an optional manner of the second aspect, the AC generates a first GTK according to the GMK, a group random number, and a MAC address of the AC.
[0022] In an optional manner of the second aspect, the AC sends a first message to a first AP and a second AP. The first message includes a first GTK. The first message also includes at least one of the following: identifiers of the first AP and the second AP, an identifier of a VAP in the first AP, an identifier of a VAP in the second AP, a key replay counter, a reception sequence counter, a group random number, or an integrity group temporary key.
[0023] In an optional manner of the second aspect, the wireless communication method further includes the following steps: the AC sends a first instruction to the first AP and the second AP, wherein the first instruction is used for the first AP and the second AP to disable automatic update of the GTK according to the first instruction.
[0024] In an optional manner of the second aspect, when any of the following conditions is met, the wireless communication method further includes: the AC sending an updated first GTK to the first AP and the second AP. The conditions include: the AC restarting, the key timer in the AC expiring, the encryption mode of the AC changing from public to encrypted, or the STA using the first GTK going offline.
[0025] In an optional manner of the second aspect, the wireless communication method further includes the following steps: the AC updates the first GTK according to the updated GMK, the updated group random number and the MAC address of the AC to obtain an updated first GTK.
[0026] In an optional manner of the second aspect, before the AC sends the first message to the first AP and the second AP, the wireless communication method further includes the following steps: the AC obtains group reference information of three APs. The three APs include the first AP, the second AP, and the third AP. The AC determines, based on the group reference information, that the first AP and the second AP use a first GTK. The AC determines, based on the group reference information, that the third AP uses a second GTK. The second GTK is different from the first GTK.
[0027] In an optional manner of the second aspect, after the AC determines, based on the group reference information, that the third AP uses the second GTK, the wireless communication method further includes the following steps: the AC sends the second GTK to the third AP. Alternatively, the AC sends a control instruction to the third AP. The control instruction is used by the third AP to generate the second GTK based on the control instruction.
[0028] In an optional manner of the second aspect, the group reference information includes channel quality information between APs, location information of STAs associated with the three APs, or on-demand information of STAs associated with the three APs. The channel quality information between APs includes channel quality information between any two APs among the three APs.
[0029] In an optional manner of the second aspect, after the second STA roams from the second AP to the first AP, the first GTK is also used by the second STA to decrypt the second message multicast or broadcast by the first AP according to the first GTK. The first GTK is received by the second STA from the second AP.
[0030] In an optional manner of the second aspect, the first AP and the second AP use the same BSSID.
[0031] In an optional manner of the second aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0032] In an optional manner of the second aspect, when there is a new AP connected to the AC, the wireless communication method further includes the following steps: the AC sends a first message to the new AP.
[0033] A third aspect of the present application provides a wireless communication method. The wireless communication method includes the following steps: a first AP receives a first message from an AC. The first message includes a first GTK. The first AP encrypts data using the first GTK to obtain a first message. The first AP multicasts or broadcasts the first message. The first AP sends the first GTK to a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The first AP is associated with the first STA. The first AP and the second AP use the same first GTK. The first GTK is used by the second STA to decrypt the first message based on the first GTK.
[0034] The second STA is associated with the second AP.
[0035] In an optional manner of the third aspect, the first message also includes at least one of the following: an identifier of the first AP and the second AP, an identifier of the VAP in the first AP, an identifier of the VAP in the second AP, a key replay counter, a receive sequence counter, a group random number for generating the first GTK, or an integrity group temporary key.
[0036] In an optional manner of the third aspect, the wireless communication method further includes the following steps: the first AP receives a first instruction sent by the AC, and the first AP disables automatic update of the GTK according to the first instruction.
[0037] In an optional embodiment of the third aspect, after the second STA roams from the second AP to the first AP, the wireless communication method further includes the following steps: the first AP encrypts data using the first GTK to obtain a second message. The first AP multicasts or broadcasts the second message. The first GTK is also used by the second STA to decrypt the second message based on the first GTK. The first GTK is received by the second STA from the second AP.
[0038] In an optional manner of the third aspect, the first AP and the second AP use the same BSSID.
[0039] In an optional manner of the third aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0040] A fourth aspect of the present application provides a wireless communication method. The wireless communication method includes the following steps: a first AP generates a first GTK. The first AP encrypts data using the first GTK to obtain a first message. The first AP multicasts or broadcasts the first message. The first AP sends the first GTK to a second AP and a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The first AP and the first STA are associated. The first GTK is used by the second STA to decrypt the first message based on the first GTK. The second STA is associated with the second AP.
[0041] In an optional manner of the fourth aspect, the first AP generating the first GTK includes: the first AP generating the first GTK according to the GMK, a group random number, and a MAC address of the first AP.
[0042] In an optional manner of the fourth aspect, a first AP sends a first message to a second AP and a first STA. The first message includes a first GTK. The first message also includes at least one of the following: an identifier of the second AP, an identifier of a VAP in the second AP, a key replay counter, a receive sequence counter, a group random number used to generate the first GTK, or an integrity group transient key.
[0043] In an optional manner of the fourth aspect, the wireless communication method further includes the following steps: the first AP sends a first instruction to the second AP, wherein the first instruction is used for the second AP to disable automatic update of GTK according to the first instruction.
[0044] In an optional embodiment of the fourth aspect, after the second STA roams from the second AP to the first AP, the wireless communication method further includes the following steps: the first AP encrypts data using the first GTK to obtain a second message. The first AP multicasts or broadcasts the second message. The first GTK is also used by the second STA to decrypt the second message based on the first GTK. The first GTK is received by the second STA from the second AP.
[0045] In an optional manner of the fourth aspect, the first AP and the second AP use the same BSSID.
[0046] In an optional manner of the fourth aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0047] A fifth aspect of the present application provides a wireless communication method. The wireless communication method includes the following steps: a second AP generates a first GTK. The second AP sends the first GTK to the first AP. The first GTK is used by the first AP to encrypt data using the first GTK to obtain a first message. The second AP sends the first GTK to a second STA. The first GTK is used by the second STA to decrypt a first message multicast or broadcast by the first AP based on the first GTK. The second STA associates with the second AP. The first GTK is used by the first STA to decrypt the first message multicast or broadcast by the first AP. The first STA associates with the first AP.
[0048] In an optional manner of the fifth aspect, the second AP generating the first GTK includes: the second AP generating the first GTK according to the GMK, a group random number, and a MAC address of the second AP.
[0049] In an optional manner of the fifth aspect, the second AP sends a first message to the first AP. The first message includes a first GTK. The first message also includes at least one of the following: an identifier of the first AP, an identifier of a VAP within the first AP, a key replay counter, a receive sequence counter, a group random number used to generate the first GTK, or an integrity group transient key.
[0050] In an optional manner of the fifth aspect, the wireless communication method further includes the following steps: the second AP sends a first instruction to the first AP, wherein the first AP disables automatic update of the GTK according to the first instruction.
[0051] In an optional manner of the fifth aspect, the first AP and the second AP use the same BSSID.
[0052] A sixth aspect of the present application provides a wireless communication device. The wireless communication device may be an AC. The wireless communication device includes a generation module and a transmission module. The generation module is configured to generate a first GTK. The transmission module is configured to send a first message to a first AP and a second AP. The first message includes the first GTK. The first GTK is used by a first STA and a second STA to decrypt a first message multicast or broadcast by the first AP. The first AP is associated with the first STA. The second AP is associated with the second STA.
[0053] In an optional manner of the sixth aspect, the generation module is configured to generate a first GTK according to the GMK, a group random number, and a MAC address of the wireless communication device.
[0054] In an optional manner of the sixth aspect, the first message also includes at least one of the following: an identifier of the first AP and the second AP, an identifier of the virtual access point VAP in the first AP, an identifier of the VAP in the second AP, a key replay counter, a reception sequence counter, a group random number or an integrity group temporary key.
[0055] In an optional manner of the sixth aspect, the sending module is further configured to send a first instruction to the first AP and the second AP, wherein the first instruction is configured to cause the first AP and the second AP to disable automatic update of the GTK according to the first instruction.
[0056] In an optional method of the sixth aspect, when any one of the following conditions is met, the sending module is also used to send the updated first GTK to the first AP and the second AP; the conditions include: the wireless communication device is restarted, the key timer in the wireless communication device times out, the encryption mode of the wireless communication device is changed from public to encrypted, and the STA using the first GTK is offline.
[0057] In an optional manner of the sixth aspect, the generation module is further used to update the first GTK according to the updated GMK, the updated group random number and the MAC address of the wireless communication device to obtain an updated first GTK.
[0058] In an optional embodiment of the sixth aspect, the wireless communication device further includes an acquisition module and a determination module. The acquisition module is configured to acquire group reference information of three APs. The three APs include a first AP, a second AP, and a third AP. The determination module is configured to determine, based on the group reference information, that the first AP and the second AP use a first GTK. The determination module is further configured to determine, based on the group reference information, that the third AP uses a second GTK. The second GTK is different from the first GTK.
[0059] In an optional manner of the sixth aspect, the sending module is further configured to send the second GTK to the third AP. Alternatively, the sending module is further configured to send a control instruction to the third AP. The control instruction is used by the third AP to generate the second GTK according to the control instruction.
[0060] In an optional manner of the sixth aspect, the group reference information includes channel quality information between APs, location information of STAs associated with the three APs, or on-demand information of STAs associated with the three APs. The channel quality information between APs includes channel quality information between any two APs among the three APs.
[0061] In an optional manner of the sixth aspect, after the second STA roams from the second AP to the first AP, the first GTK is further used by the second STA to decrypt a second message multicast or broadcast by the first AP according to the first GTK. The first GTK is received by the second STA from the second AP.
[0062] In an optional manner of the sixth aspect, the first AP and the second AP use the same BSSID.
[0063] In an optional manner of the sixth aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0064] In an optional manner of the sixth aspect, when there is a new AP connected to the wireless communication device, the sending module is further used to send a first message to the new AP.
[0065] In a seventh aspect, the present application provides a wireless communication device. The wireless communication device may be a first AP. The wireless communication device includes a receiving module, an encryption module, and a sending module. The receiving module is used to receive a first message from an AC. The first message includes a first GTK. The encryption module is used to encrypt data using the first GTK to obtain a first message. The sending module is used to multicast or broadcast the first message. The sending module is also used to send the first GTK to a second AP and a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The wireless communication device is associated with the first STA. The first GTK is used by the second STA to decrypt the first message based on the first GTK. The second STA is associated with a second AP.
[0066] In an optional manner of the seventh aspect, the first message also includes at least one of the following: an identifier of the first AP and the second AP, an identifier of the VAP in the first AP, an identifier of the VAP in the second AP, a key replay counter, a receive sequence counter, a group random number for generating the first GTK, or an integrity group temporary key.
[0067] In an optional manner of the seventh aspect, the wireless communication device further includes a shut-down module. The receiving module is further configured to receive a first instruction sent by the AC. The shut-down module is configured to shut down automatic updates of the GTK according to the first instruction.
[0068] In an optional embodiment of the seventh aspect, after the second STA roams from the second AP to the first AP, the encryption module is further configured to encrypt data using the first GTK to obtain a second message. The sending module is further configured to multicast or broadcast the second message. The first GTK is further used by the second STA to decrypt the second message based on the first GTK. The first GTK is received by the second STA from the second AP.
[0069] In an optional manner of the seventh aspect, the wireless communication device and the second AP use the same BSSID.
[0070] In an optional manner of the seventh aspect, signal quality information between the second STA and the wireless communication device is greater than a first threshold.
[0071] In an eighth aspect, the present application provides a wireless communication device. The wireless communication device may be a first AP. The wireless communication device includes a generation module, an encryption module, and a sending module. The generation module is used to generate a first GTK. The encryption module is used to encrypt data using the first GTK to obtain a first message. The sending module is used to multicast or broadcast the first message. The sending module is also used to send the first GTK to a second AP and a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The first AP is associated with the first STA. The first GTK is used by the second STA to decrypt the first message based on the first GTK. The second STA is associated with the second AP.
[0072] In an optional manner of the eighth aspect, the generation module is configured to generate a first GTK according to the GMK, a group random number, and a MAC address of the first AP.
[0073] In an optional manner of the eighth aspect, the sending module is configured to send a first message to the second AP and the first STA. The first message includes a first GTK. The first message also includes at least one of the following: an identifier of the second AP, an identifier of a VAP in the second AP, a key replay counter, a reception sequence counter, a group random number used to generate the first GTK, or an integrity group transient key.
[0074] In an optional manner of the eighth aspect, the sending module is further configured to send a first instruction to the second AP, wherein the first instruction is used for the second AP to disable automatic update of GTK according to the first instruction.
[0075] In an optional manner of the eighth aspect, after the second STA roams from the second AP to the first AP, the encryption module is further configured to encrypt data using the first GTK to obtain a second message. The sending module is further configured to multicast or broadcast the second message. The first GTK is further used by the second STA to decrypt the second message based on the first GTK. The first GTK is received by the second STA from the second AP.
[0076] In an optional manner of the eighth aspect, the first AP and the second AP use the same BSSID.
[0077] In an optional manner of the eighth aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0078] In a ninth aspect of the present application, a wireless communication device is provided. The wireless communication device may be a second AP. The wireless communication device includes a generation module and a sending module. The generation module is used to generate a first GTK. The sending module is used to send the first GTK to the first AP. The first GTK is used by the first AP to encrypt data using the first GTK to obtain a first message. The sending module is also used to send the first GTK to a second STA. The first GTK is used by the second STA to decrypt the first message multicast or broadcast by the first AP based on the first GTK. The second STA is associated with the second AP. The first GTK is used by the first STA to decrypt the first message multicast or broadcast by the first AP. The first STA is associated with the first AP.
[0079] In an optional manner of the ninth aspect, the generation module is configured to generate a first GTK according to the GMK, a group random number, and a MAC address of the second AP.
[0080] In an optional manner of the ninth aspect, the sending module is configured to send a first message to a first AP. The first message includes a first GTK. The first message also includes at least one of the following: an identifier of the first AP, an identifier of a VAP within the first AP, a key replay counter, a reception sequence counter, a group random number used to generate the first GTK, or an integrity group transient key.
[0081] In an optional manner of the ninth aspect, the sending module is further configured to send a first instruction to the first AP, wherein the first AP is configured to disable automatic update of the GTK according to the first instruction.
[0082] In an optional manner of the ninth aspect, the first AP and the second AP use the same BSSID.
[0083] In a tenth aspect, the present application provides an AC. The AC includes a processor and a transceiver. The processor is configured to generate a first GTK. The transceiver is configured to send a first message to a first AP and a second AP. The first message includes the first GTK. The first GTK is used by a first STA and a second STA to decrypt a first message multicast or broadcast by the first AP. The first AP and the first STA are associated.
[0084] The second AP is associated with the second STA.
[0085] In an optional manner of the tenth aspect, the processor is configured to generate a first GTK according to the GMK, a group random number, and a MAC address of the wireless communication device.
[0086] In an optional manner of the tenth aspect, the first message also includes at least one of the following: an identifier of the first AP and the second AP, an identifier of the virtual access point VAP in the first AP, an identifier of the VAP in the second AP, a key replay counter, a reception sequence counter, a group random number or an integrity group temporary key.
[0087] In an optional manner of the tenth aspect, the transceiver is further configured to send a first instruction to the first AP and the second AP, wherein the first instruction is configured to cause the first AP and the second AP to disable automatic update of the GTK according to the first instruction.
[0088] In an optional manner of the tenth aspect, when any one of the following conditions is met, the transceiver is also used to send an updated first GTK to the first AP and the second AP; the conditions include: the wireless communication device is restarted, the key timer in the wireless communication device times out, the encryption mode of the wireless communication device is changed from public to encrypted, and the STA using the first GTK is offline.
[0089] In an optional manner of the tenth aspect, the processor is further configured to update the first GTK according to the updated GMK, the updated group random number, and the MAC address of the wireless communication device to obtain an updated first GTK.
[0090] In an optional manner of the tenth aspect, the processor is further configured to obtain group reference information for three APs. The three APs include a first AP, a second AP, and a third AP. The processor is further configured to determine, based on the group reference information, that the first AP and the second AP use a first GTK. The processor is further configured to determine, based on the group reference information, that the third AP uses a second GTK. The second GTK is different from the first GTK.
[0091] In an optional manner of the tenth aspect, the transceiver is further configured to send the second GTK to the third AP. Alternatively, the transceiver is further configured to send a control instruction to the third AP. The control instruction is used by the third AP to generate the second GTK according to the control instruction.
[0092] In an optional manner of the tenth aspect, the group reference information includes channel quality information between APs, location information of STAs associated with the three APs, or on-demand information of STAs associated with the three APs. The channel quality information between APs includes channel quality information between any two APs among the three APs.
[0093] In an optional manner of the tenth aspect, after the second STA roams from the second AP to the first AP, the first GTK is further used by the second STA to decrypt a second message multicast or broadcast by the first AP according to the first GTK. The first GTK is received by the second STA from the second AP.
[0094] In an optional manner of the tenth aspect, the first AP and the second AP use the same BSSID.
[0095] In an optional manner of the tenth aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0096] In an optional manner of the tenth aspect, when there is a new AP connected to the wireless communication device, the sending module is further used to send a first message to the new AP.
[0097] In an eleventh aspect of the present application, a first AP is provided. The first AP includes a processor and a transceiver. The transceiver is used to receive a first message from an AC. The first message includes a first GTK. The processor is used to encrypt data using the first GTK to obtain a first message. The transceiver is used to multicast or broadcast the first message. The transceiver is also used to send the first GTK to a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The first AP is associated with the first STA; wherein the first AP and the second AP use the same first GTK. The first GTK is used by the second STA to decrypt the first message based on the first GTK. The second STA is associated with the second AP.
[0098] In an optional embodiment of the eleventh aspect, the first message also includes at least one of the following: an identifier of the first AP and the second AP, an identifier of the VAP in the first AP, an identifier of the VAP in the second AP, a key replay counter, a reception sequence counter, a group random number for generating the first GTK, or an integrity group temporary key.
[0099] In an optional manner of the eleventh aspect, the transceiver is further configured to receive a first instruction sent by the AC. The processor is further configured to disable automatic update of the GTK according to the first instruction.
[0100] In an optional embodiment of the eleventh aspect, after the second STA roams from the second AP to the first AP, the processor is further configured to encrypt data using the first GTK to obtain a second message. The transceiver is further configured to multicast or broadcast the second message. The first GTK is further used by the second STA to decrypt the second message based on the first GTK. The first GTK is received by the second STA from the second AP.
[0101] In an optional manner of the eleventh aspect, the first AP and the second AP use the same BSSID.
[0102] In an optional manner of the eleventh aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0103] A twelfth aspect of the present application provides a first AP. The first AP includes a processor and a transceiver. The processor is used to generate a first GTK. The processor is used to encrypt data using the first GTK to obtain a first message. The transceiver is used to multicast or broadcast the first message. The transceiver is also used to send the first GTK to a second AP and a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The first AP is associated with the first STA. The first GTK is used by the second STA to decrypt the first message based on the first GTK. The second STA is associated with the second AP.
[0104] In an optional manner of the twelfth aspect, the processor is configured to generate a first GTK according to the GMK, a group random number, and a MAC address of the first AP.
[0105] In an optional manner of the twelfth aspect, the transceiver is configured to send a first message to a second AP and a first STA. The first message includes a first GTK. The first message also includes at least one of the following: an identifier of the second AP, an identifier of a VAP within the second AP, a key replay counter, a receive sequence counter, a group random number used to generate the first GTK, or an integrity group transient key.
[0106] In an optional manner of the twelfth aspect, the transceiver is further configured to send a first instruction to the second AP, wherein the first instruction is used for the second AP to disable automatic update of the GTK according to the first instruction.
[0107] In an optional manner of the twelfth aspect, after the second STA roams from the second AP to the first AP, the processor is further configured to encrypt data using the first GTK to obtain a second message. The transceiver is further configured to multicast or broadcast the second message. The first GTK is further used by the second STA to decrypt the second message based on the first GTK. The first GTK is received by the second STA from the second AP.
[0108] In an optional manner of the twelfth aspect, the first AP and the second AP use the same BSSID.
[0109] In an optional manner of the twelfth aspect, signal quality information between the second STA and the first AP is greater than a first threshold.
[0110] A thirteenth aspect of the present application provides a second AP. The second AP includes a processor and a transceiver. The processor is used to generate a first GTK. The transceiver is used to send the first GTK to the first AP. The first GTK is used by the first AP to encrypt data using the first GTK to obtain a first message. The transceiver is also used to send the first GTK to a second STA. The first GTK is used by the second STA to decrypt the first message multicast or broadcast by the first AP based on the first GTK. The second STA is associated with the second AP. The first GTK is used by the first STA to decrypt the first message multicast or broadcast by the first AP. The first STA is associated with the first AP.
[0111] In an optional manner of the thirteenth aspect, the processor is configured to generate a first GTK according to the GMK, a group random number, and a MAC address of the second AP.
[0112] In an optional manner of the thirteenth aspect, the transceiver is configured to send a first message to a first AP. The first message includes a first GTK. The first message also includes at least one of the following: an identifier of the first AP, an identifier of a VAP within the first AP, a key replay counter, a reception sequence counter, a group random number used to generate the first GTK, or an integrity group transient key.
[0113] In an optional manner of the thirteenth aspect, the transceiver is further configured to send a first instruction to the first AP, wherein the first AP is configured to disable automatic update of the GTK according to the first instruction.
[0114] In an optional manner of the thirteenth aspect, the first AP and the second AP use the same BSSID.
[0115] In the fourteenth aspect of the present application, a computer storage medium is provided, in which instructions are stored. When the instructions are executed on a computer, the computer is caused to execute the method as described in the second aspect or any one of the embodiments of the second aspect; or the computer is caused to execute the method as described in the third aspect or any one of the embodiments of the third aspect; or the computer is caused to execute the method as described in the fourth aspect or any one of the embodiments of the fourth aspect; or the computer is caused to execute the method as described in the fifth aspect or any one of the embodiments of the fifth aspect.
[0116] In aspect 15 of the present application, a computer program product is provided. When the computer program product is executed on a computer, the computer is caused to execute the method as described in aspect 2 or any one of the embodiments of aspect 2; or the computer is caused to execute the method as described in aspect 3 or any one of the embodiments of aspect 3; or the computer is caused to execute the method as described in aspect 4 or any one of the embodiments of aspect 4; or the computer is caused to execute the method as described in aspect 5 or any one of the embodiments of aspect 5. BRIEF DESCRIPTION OF THE DRAWINGS
[0117] Figure 1 This is a first structural diagram of the WLAN system provided in an embodiment of the present application;
[0118] Figure 2 This is a first flow chart of the wireless communication method provided in an embodiment of the present application;
[0119] Figure 3 This is a second flow chart of the wireless communication method provided in an embodiment of the present application;
[0120] Figure 4 This is a schematic diagram of the structure of the first message provided in an embodiment of the present application;
[0121] Figure 5 This is a first flow chart of the STA grouping method provided in an embodiment of the present application;
[0122] Figure 6 This is a second flow chart of the STA grouping method provided in an embodiment of the present application;
[0123] Figure 7 This is a third flow chart of the wireless communication method provided in an embodiment of the present application;
[0124] Figure 8 This is a fourth flow chart of the wireless communication method provided in an embodiment of the present application;
[0125] Figure 9 This is a second structural diagram of the WLAN system provided in an embodiment of the present application;
[0126] Figure 10 This is a first structural diagram of a wireless communication device provided in an embodiment of the present application;
[0127] Figure 11 This is a second structural diagram of the wireless communication device provided in an embodiment of the present application;
[0128] Figure 12 This is a schematic diagram of the structure of the wireless communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0129] The present application provides a WLAN system, a wireless communication method, and an apparatus. By using the same GTK, a first AP can multicast or broadcast a first message to a first STA and a second STA, thereby improving the multicast or broadcast communication efficiency of the first AP.
[0130] It should be understood that the terms "first," "second," etc. used in this application are used solely for descriptive purposes and should not be construed as indicating or implying relative importance or order. Furthermore, for the sake of brevity and clarity, reference numbers and / or letters are repeated in multiple figures of this application. Repetition does not imply a strict definition between various embodiments and / or configurations. For example, features or content identified by dashed lines in the figures of this application may be understood as optional operations or optional structures of the embodiments.
[0131] The WLAN system described in this application is applied to the field of wireless communications. In this field, to improve the coverage of wireless signals, a WLAN system can be formed by multiple access points (APs). In a WLAN system composed of multiple APs, each STA can only receive multicast or broadcast messages from the AP with which it is associated, resulting in low AP multicast or broadcast communication efficiency.
[0132] To this end, the present application provides a WLAN system and a wireless communication method. Figure 1 This is a first structural diagram of the WLAN system provided in the embodiment of the present application. Figure 1 As shown, the WLAN system includes a first AP 101 and a second AP 102. The first AP 101 is associated with a first STA 103. The second AP 102 is associated with a second STA 104. In practical applications, the WLAN system may further include an AC 105. The AC 105 is connected to the first AP 101 and the second AP 102 via wireless or wired means. Figure 1 On the basis of Figure 2 This is a first flow chart of the wireless communication method provided in the embodiment of the present application. Figure 2 As shown, the wireless communication method includes the following steps.
[0133] In step 201, the first AP sends a first GTK to the first STA. The first AP 101 can generate the first GTK using the following formula: GTK = PRF(GMK + GNonce + MAC(AA)). PRF is a pseudorandom function. Gnonce is a group random number generated by the first AP 101. MAC(AA) is the BSSID of the first AP 101. GMK is generated by the first AP 101 based on the multicast session key (MSK). The first AP 101 can generate the MSK during the pre-shared key (PSK) authentication process. Alternatively, the first AP 101 can receive the first GTK from the second AP 102. When the WLAN system also includes an AC 105, the first AP 101 can receive the first GTK from the AC 105. Alternatively, the first AP 101 can receive information for generating the GTK from the AC 105. The first AP 101 generates the first GTK based on the information for generating the GTK. The information for generating the GTK may include a group random number, a GMK, and a MAC address of the AC 105. The first AP 101 associates with the first STA 103. After obtaining the first GTK, the first AP 101 sends the first GTK to the first STA 103.
[0134] In step 202, the second AP transmits a first GTK to the second STA. When the first AP 101 generates the first GTK, the second AP 102 may receive the first GTK from the first AP 101. Alternatively, the second AP 102 may receive information from the first AP 101 indicating that the first AP 101 has generated the first GTK. The second AP 102 generates the first GTK based on the information. Similarly, when the WLAN system further includes an AC 105, the second AP 102 may receive the first GTK or the information about generating the GTK from the AC 105. The second AP obtains the same first GTK as the first AP. The first AP 101 associates with the first STA 103. After obtaining the first GTK, the second AP 102 sends the first GTK to the second STA 104. It should be understood that there is no strictly defined timing relationship between steps 201 and 202.
[0135] In step 203, the first AP encrypts data according to the first GTK to obtain a first message. The first message is a multicast message or a broadcast message. When the first message is a multicast message, the destination MAC address of the first message may be a multicast MAC address. The multicast MAC address includes six bytes. The least significant bit of the first byte of the six bytes is 1. The destination IP address of the first message may be a multicast Internet Protocol (IP) address. When the first message is a broadcast message, the destination MAC address of the first message may be a broadcast MAC address. The broadcast MAC address includes six bytes. Each bit of the six bytes is 1. The broadcast IP address of the first message may be a broadcast IP address.
[0136] In step 204, the first AP multicasts or broadcasts the first message.
[0137] In step 205, the first STA decrypts the first message based on the first GTK. After receiving the first message, the first STA 103 can read the destination MAC address in the first message. When the destination MAC address in the first message is a broadcast MAC address, the first STA 103 decrypts the first message based on the first GTK. When the destination MAC address in the first message is a multicast MAC address, the first STA 103 determines whether it belongs to the multicast group corresponding to the multicast MAC address. When the first STA 103 belongs to the multicast group corresponding to the multicast MAC address, the first STA 103 decrypts the first message based on the first GTK. When the first STA 103 does not belong to the multicast group corresponding to the multicast MAC address, the first STA 103 can discard the first message. After decrypting the first message, the first STA 103 can obtain the destination IP address of the first message. If the destination IP address in the first message is a broadcast IP address, the first STA 103 can process the decrypted first message. When the destination IP address in the first message is a multicast IP address, first STA 103 determines whether it belongs to the multicast group corresponding to the multicast IP address. If first STA 103 belongs to the multicast group corresponding to the multicast IP address, first STA 103 may process the decrypted first message. If first STA 103 does not belong to the multicast group corresponding to the multicast IP address, first STA 103 may discard the decrypted first message.
[0138] In step 206, the second STA decrypts the first message according to the first GTK. For the description of step 206, reference may be made to the description of step 205. It should be understood that there is no strictly defined timing relationship between steps 205 and 206.
[0139] In the present application, the first AP 101 and the second AP 102 use the same GTK. Therefore, the first AP can multicast or broadcast the first message to the first STA and the second STA, thereby improving the communication efficiency of the first AP multicast or broadcast.
[0140] In practical applications, STAs may roam between multiple APs in a WLAN system. Figure 2 In the example, second STA 104 can roam from second AP 102 to first AP 101. After second STA 104 roams to first AP 101, first AP 101 encrypts data using the first GTK to obtain a second message. First AP 101 multicasts or broadcasts the second message. Second STA 104 can decrypt the second message using the first GTK received from second AP 102.
[0141] In actual applications, first AP 101 and second AP 102 may use the same BSSID. Second STA 104 may determine to use the first GTK to decrypt the first message based on the same BSSID. It should be understood that when the BSSIDs of first AP 101 and second AP 102 are different, second AP 102 may send an instruction to second STA 104. The instruction includes the BSSID of first AP 101. Second STA 104 may determine to use the first GTK to decrypt the first message based on the instruction. It should be understood that when second AP 102 has multiple VAPs, first AP 101 may use the same BSSID as one of the multiple VAPs.
[0142] According to the above description, the first AP 101 and the second AP 102 can obtain the first GTK in various ways. In the following embodiments, the AC 105 generating the first GTK will be described as an example. It should be understood that in the following examples, the steps performed by the AC 105 can be performed by the first AP 101 or the second AP 102. Moreover, when the first AP 101 or the second AP 102 performs the steps performed by the AC 105, the first AP 101 or the second AP 102 does not need to perform the information exchange steps with itself. For example, in Figure 2 In the embodiment, when the first AP 101 generates the first GTK, the first AP 101 does not need to send the first GTK to the first AP 101.
[0143] First AP 101 and second AP 102 may be configured with a key timer. After the key timer expires, first AP 101 and second AP 102 may each update their first GTK. However, the updated first GTK for first AP 101 and the updated first GTK for second AP 102 may differ, resulting in second STA 104 being unable to properly decrypt messages multicast or broadcast by first AP 101. Therefore, in this embodiment of the present application, AC 105 may uniformly update the first GTK. Figure 3 This is a second flow chart of the wireless communication method provided in the embodiment of the present application. Figure 3 As shown, the wireless communication method includes the following steps.
[0144] In step 301, the AC sends a first indication to the first AP and the second AP. This embodiment of the application does not limit the manner in which the AC 105 sends the first indication or the format of the first indication. The AC 105 may send the first indication via unicast, multicast, or broadcast. The format of the first indication may be agreed upon by the AC 105 and the AP.
[0145] In step 302, the first AP 101 disables automatic GTK updates based on the first instruction. After receiving the first instruction, the first AP 101 may disable the key timer for GTK updates. Alternatively, the first AP 101 may remove the relationship between key timer expiration and GTK updates. That is, after the key timer expires, the first AP 101 does not update the GTK. It should be understood that when the first AP 101 includes multiple VAPs, the first AP 101 may disable automatic GTK updates only in the target VAP. The target VAP uses the first GTK. For example, the first AP 101 includes a first VAP and a second VAP. The first VAP uses the first GTK, and the second VAP uses the third GTK. The first AP 101 may disable automatic GTK updates only in the first VAP. In this case, after the key timer expires, the first AP 101 may still update the GTK in the second VAP.
[0146] In step 303, the second AP disables automatic GTK update according to the first instruction. For the description of step 303, reference may be made to the description of step 302. It should be understood that there is no strict time sequence between steps 302 and 303.
[0147] In step 304, the AC sends a first GTK to the first AP and the second AP. The AC can generate the first GTK based on the GMK, the group random number, and the MAC address of AC 105. After generating the first GTK, AC 105 sends the first GTK to the first AP 101 and the second AP 102. The first GTK can be carried in the first message. The embodiment of the present application does not limit the manner in which AC 105 sends the first message and the format of the first message. For example, Figure 4 This is a schematic diagram of the structure of the first message provided in the embodiment of this application. Figure 4 As shown, the first message 401 includes a protocol version information field, a message type field, a message size field, an AP ID field, a VAP ID field, a GTK field, a key replay counter field, a receive sequence counter (RSC) field, a group nonce (Gnonce) field, an integrity group transient key (IGTK) field, and a reserved field.
[0148] The protocol version information field can be used to indicate that the first message is a GTK synchronization message. The message type field is used to record the type of the first message, for example, if the first message is a control message. The message size field is used to record the data size of the first message. The AP ID field is used to record the identifier of the AP using the first GTK. For example, in this embodiment of the present application, the AP ID field includes the identifiers of the first AP 101 and the second AP 102. The VAP ID field records the identifier of the VAP using the first GTK. For example, the first VAP in the first AP 101 uses the first GTK. In this case, the VAP ID field includes the identifier of the first VAP. The GTK field is used to record the first GTK. The key replay counter field is used to record the serial number of the first GTK. The serial number of the first GTK is used to prevent attackers from attacking the system by intercepting key exchange packets and replaying them. The receive counter field carries the RSC value. The RSC value can be used to synchronize the replay status. The RSC value may indicate the TKIP sequence counter (TSC) value of the frame that failed the message integrity code (MIC) check. The first AP 101 or the second AP 102 may identify the replayed first message based on the RSC value. The group random number field records the group random number used to generate the first GTK. The integrity group temporary key field carries verification information. The first AP 101 or the second AP 102 may verify the integrity of the first message based on the verification information. The reserved field is also referred to as a reserved field.
[0149] In step 305, the AC updates the first GTK. The AC 105 may update the GMK to obtain an updated GMK. The AC 105 may also update the group random number to obtain an updated group random number. The AC 105 generates an updated first GTK based on the updated GMK, the updated group random number, and the MAC address of the AC 105.
[0150] In step 306, the AC sends the updated first GTK to the first AP 101 and the second AP 102. AC 105 sends the updated first GTK to the first AP 101 and the second AP 102 when any one or more of the following conditions are met. These conditions include: AC 105 restarting, a key timer in AC 105 expiring, the encryption mode of AC 105 changing from public to encrypted, or a STA using the first GTK going offline. A key timer may be set in AC 105. After the key timer expires, AC 105 sends the updated first GTK to the first AP 101 and the second AP 102. The STA using the first GTK may be a STA associated with the first AP 101 or the second AP 102. For example, when the first STA 103 goes offline, AC 105 sends the updated first GTK to the first AP 101 and the second AP 102.
[0151] It should be understood that the updated first GTK can be carried in the updated first message. For the description of the first message, please refer to the aforementioned Figure 4 In the subsequent description, the description of the GTK sent by one device to another device can refer to the description of the first message in the embodiment of the present application.
[0152] It should be understood that Figure 3 In the embodiment of the present application, only the first AP 101 and the second AP 102 are used as examples for description. In actual applications, more APs in the WLAN system can use the same first GTK. Furthermore, when a new AP connects to the AC 105, the AC 105 can send the first GTK to the new AP.
[0153] In an embodiment of the present application, the first AP 101 can multicast or broadcast the first message to the second STA 104. Moreover, the second STA 104 is not associated with the first AP 101. Therefore, the channel quality information between the second STA 104 and the first AP 101 will affect the communication quality of the multicast or broadcast. To this end, the AC 105 can group all STAs to obtain N groups. The number of N groups corresponds one to one with the N APs. All STAs include STAs associated with any one of the N APs. The AP only multicasts or broadcasts to the corresponding STA. The following description takes N equal to two as an example, and the two APs include the first AP 101 and the second AP 102. For example, Figure 5 This is a first flow chart of the STA grouping method provided in an embodiment of the present application. The wireless communication method may include the STA grouping method. Figure 5 As shown, the STA grouping method includes the following steps.
[0154] In step 501, the AC obtains STA grouping reference information from the first AP and the second AP. The STA grouping reference information may include channel quality information between all STAs and N APs. For example, Figure 5 In the example, N APs include a first AP 101 and a second AP 102. All STAs include a first STA 103, a second STA 104, and a third STA. The first STA 103 is associated with the first AP 101. The second STA 104 and the third STA are associated with the second AP 102. The STA grouping reference information includes channel quality information between the first STA 103 and the first AP 101 and the second AP 102. The STA grouping reference information also includes channel quality information between the second STA 104 and the first AP 101 and the second AP 102. The STA grouping reference information also includes channel quality information between the third STA and the first AP 101 and the second AP 102. The channel quality information may be a received signal strength indication (RSSI), an interference duty cycle, or noise.
[0155] In step 502, the AC groups all STAs according to the STA grouping reference information to obtain STA grouping information. The AC 105 can group all STAs according to different methods. For example, Figure 6 This is a second flow chart of the STA grouping method provided in the embodiment of the present application. Figure 6 As shown, the STA grouping method includes the following steps.
[0156] In step 5020, start.
[0157] In step 5021, the AC sorts the N APs and selects the first AP as the current AP. For example, AC 105 may obtain load information or channel condition information from first AP 101 and second AP 102. AC 105 sorts the APs based on their load or channel condition. The load information may include idle duty cycle. AC 105 may sort the APs in descending order of idle duty cycle. For example, if the idle duty cycle of first AP 101 is greater than that of second AP 102, first AP 101 is sorted first. AC 105 selects first AP 101 as the current AP.
[0158] In step 5022, the AC obtains the channel quality information of all STAs and the current AP. Figure 5 In step 501, AC 105 obtains STA grouping reference information. The STA grouping reference information includes channel quality information between all STAs and the current AP. The channel quality information between all STAs and the current AP includes channel quality information between the first AP 101 and the first STA 103, the second STA 104, and the third STA.
[0159] In step 5023, the AC establishes a mapping relationship between the current STA and the current AP. The channel quality information between the current STA and the current AP is greater than a first threshold. Assume that the channel quality information between first AP 101 and first STA 103 and second STA 104 is greater than the first threshold. The channel quality information between first AP 101 and third STA is less than or equal to the first threshold. In this case, the current STAs include first STA 103 and second STA 104. First AP 101 corresponds to first STA 103 and second STA 104. First STA 103 and second STA 104 can also be referred to as a first multicast group.
[0160] In step 5024, the AC determines whether N APs have been traversed. The N APs also include the second AP 102. Therefore, the AC 105 determines that the N APs have not been traversed. The AC 105 executes step 5025.
[0161] In step 5025, the AC uses the next AP as the current AP. The AC uses the second AP 102 as the current AP.
[0162] In step 5026, the AC obtains the channel quality information between the remaining STAs and the current AP. Figure 5 In step 501, AC 105 obtains STA grouping reference information. The STA grouping reference information includes channel quality information between the remaining STAs and the current AP. The channel quality information between the remaining STAs and the current AP includes channel quality information between the second AP 102 and the third STA.
[0163] In step 5023, the AC establishes a mapping between the current STA and the current AP. The channel quality information between the current STA and the current AP is greater than a first threshold. Assume that the channel quality information between second AP 102 and a third STA is greater than the first threshold. In this case, the current STA includes the third STA. Second AP 103 corresponds to the third STA. The third STA can also be referred to as the second multicast group.
[0164] In step 5024, the AC determines whether to traverse N APs. The AC determines to traverse N APs. The AC 105 executes step 5027.
[0165] In step 5027, end.
[0166] In step 503, the AC sends the STA grouping information of the STA to the second AP. The STA grouping information includes the information of the first multicast group and the information of the second multicast group. Figure 6 As can be seen from the description, the second STA 104 belongs to the first multicast group. The third STA belongs to the second multicast group. The multicast group information may be the IP address or MAC address of the multicast group. For example, the first multicast group information is the IP address of the first multicast group. The second multicast group information is the IP address of the second multicast group.
[0167] In step 504, the second AP sends information of the first multicast group to the second STA.
[0168] In step 505, the second AP sends information about the second multicast group to the third STA. When the information about the first multicast group is the IP address of the first multicast group and the information about the second multicast group is the IP address of the second multicast group, second AP 102 also sends a first GTK to the third STA and second STA 104. The third STA receives a multicast or broadcast message from second AP 102. The third STA decrypts the multicast or broadcast message based on the first GTK. The destination IP address of the multicast or broadcast message is the IP address of the second multicast group. The third STA also processes the decrypted multicast or broadcast message based on the IP address of the second multicast group. Second STA 104 receives a multicast or broadcast message from first AP 101. Second STA 104 decrypts the multicast or broadcast message based on the first GTK. The destination IP address of the multicast or broadcast message is the IP address of the first multicast group. Second STA 104 also processes the decrypted multicast or broadcast message based on the IP address of the first multicast group. After the second STA 104 receives the multicast or broadcast message sent by the second AP 102, the second STA 104 may decrypt the multicast or broadcast message. However, because the destination IP address of the multicast or broadcast message is the IP address of the second multicast group, the second STA 104 may discard the decrypted multicast or broadcast message. Similarly, after the third STA receives the multicast or broadcast message sent by the first AP 101, the second STA 104 may also discard the decrypted multicast or broadcast message.
[0169] When the information about the first multicast group is the MAC address of the first multicast group, and the information about the second multicast group is the MAC address of the second multicast group, the destination MAC address of the multicast or broadcast message sent by second AP 102 is the MAC address of the second multicast group. A third STA receives the multicast or broadcast message from second AP 102. The third STA decrypts the multicast or broadcast message based on the first GTK. The destination MAC address of the multicast or broadcast message sent by first AP 101 is the MAC address of the first multicast group. Second STA 104 receives the multicast or broadcast message from first AP 101. Second STA 104 decrypts the multicast or broadcast message based on the first GTK. The third STA may discard the multicast or broadcast message sent by first AP 101 based on the MAC address of the first multicast group. Similarly, second STA 104 may discard the multicast or broadcast message sent by second AP 102 based on the MAC address of the second multicast group.
[0170] In step 506, the AC sends STA grouping information to the first AP. For the description of step 506, reference may be made to the description of step 503 above.
[0171] In step 507, the first AP sends information of the first multicast group to the first STA.
[0172] When the information about the first multicast group is the IP address of the first multicast group, first AP 101 also sends a first GTK to first STA 103. First STA 103 receives a multicast or broadcast message from first AP 101. First STA 103 decrypts the multicast or broadcast message based on the first GTK. The destination IP address of the multicast or broadcast message is the IP address of the first multicast group. First STA 103 also processes the decrypted multicast or broadcast message based on the IP address of the first multicast group. After first STA 103 receives the multicast or broadcast message sent by second AP 102, first STA 103 may decrypt the multicast or broadcast message based on the first GTK. However, because the destination IP address of the multicast or broadcast message sent by second AP 102 is the IP address of the second multicast group, first STA 103 may discard the decrypted multicast or broadcast message.
[0173] When the information about the first multicast group is the MAC address of the first multicast group, first AP 101 also sends a first GTK to first STA 103. First STA 103 receives a multicast or broadcast message from first AP 101. The destination MAC address of the multicast or broadcast message is the MAC address of the first multicast group. First STA 103 decrypts the multicast or broadcast message based on the first GTK. After first STA 103 receives the multicast or broadcast message from second AP 102, because the destination MAC address of the multicast or broadcast message is the MAC address of the second multicast group, first STA 103 may discard the multicast or broadcast message sent by second AP 102.
[0174] It should be understood that Figure 5 There is no strictly defined timing relationship between any two steps in step 503 to step 507. Figure 6 The grouping of STAs in FIG. 1 is only an example. In practical applications, those skilled in the art can group STAs according to actual conditions.
[0175] For example, N APs include first AP 101 and second AP 102. All STAs include first STA 103, second STA 104, and third STA. In step 502, AC 105 determines, based on the STA grouping information, that first STA 103, second STA 104, and third STA belong to the first multicast group. AC 105 also determines, based on the STA grouping information, that there are no STAs in the second multicast group. In this case, second AP 102 does not need to send multicast or broadcast messages.
[0176] For another example, N APs include a first AP 101, a second AP 102, and a third AP. All STAs include a first STA 103, a second STA 104, a third STA, and a fourth STA. The fourth STA is associated with the third AP. In step 502, AC 105 determines, based on the STA grouping information, that the first STA 103, the second STA 104, and the fourth STA belong to the first multicast group. The first multicast group corresponds to the first AP 101. AC 105 determines, based on the STA grouping information, that the third STA belongs to the second multicast group. The second multicast group corresponds to the second AP 102. AC 105 determines, based on the STA grouping information, that there are no STAs in the third multicast group. The third multicast group corresponds to the third AP. At this point, the first multicast group receives multicast or broadcast messages from the first AP 101. The second multicast group receives multicast or broadcast messages from the second AP 102. The third AP does not need to send multicast or broadcast messages.
[0177] In the above description, the first AP 101 and the second AP 102 use the same first GTK. In actual applications, the distances between multiple APs in the WLAN system may be relatively far. In this case, the AC 105 can group multiple APs according to the AP grouping reference information. The AP grouping reference information is referred to as the grouping reference information. APs in the same group use the same GTK, and APs in different groups use different GTKs. For example, Figure 7 This is a third flow chart of the wireless communication method provided in the embodiment of the present application. Figure 7 As shown, the wireless communication method includes the following steps.
[0178] In step 701, the AC obtains grouping reference information from the first, second, and third APs. The grouping reference information may include channel quality information between APs, location information of STAs associated with the three APs, or on-demand information of STAs associated with the three APs. The channel quality information between APs includes channel quality information between any two of the three APs. The three APs include the first AP 101, the second AP 102, and the third AP. The location information of STAs associated with the three APs may include location information of the first STA 103 and the second STA 104. The on-demand information of STAs associated with the three APs may include on-demand information of the first STA 103 and the second STA 104.
[0179] In step 702, the AC determines that the first AP and the second AP use the first GTK based on the group reference information, and determines that the third AP uses the second GTK based on the group reference information. The following description takes the case where the group reference information is the channel quality information between APs as an example. For example, Table 1 is a channel quality information matrix between APs provided in an embodiment of the present application. As shown in Table 1, the channel quality information measured between the first AP 101 and the second AP 102 is -60. The channel quality information measured between the first AP 101 and the third AP is NA. Similarly, the channel quality information measured between the second AP 102 and the first AP 101 is -59. The channel quality information measured between the second AP 102 and the third AP is NA.
[0180]
[0181]
[0182] Table 1
[0183] In Table 1, a larger value for channel quality information indicates better channel quality. NA indicates that the peer's signal cannot be received. Based on Table 1, AC 105 assigns first AP 101 and second AP 102 to the first group. Based on Table 1, AC 105 assigns the third AP to the second group. APs in the first group use the first GTK. APs in the second group use the second GTK.
[0184] In step 703, the AC sends a first GTK to the first AP and the second AP. For the description of step 703, please refer to the above Figure 2 After the first AP 101 and the second AP 102 receive the first GTK, the first AP 101 and the second AP 102 may decrypt the first message multicast or broadcast by the first AP 101 according to the first GTK.
[0185] In step 704, the AC sends a second GTK to the third AP. For the description of AC 105 generating the second GTK, please refer to the above Figure 2 In the description, AC 105 generates a description of the first GTK. The second GTK is different from the first GTK. After receiving the second GTK, the third AP can send the second GTK to the fourth STA. The fourth STA is associated with the third AP. The third AP can encrypt data based on the second GTK to obtain a multicast or broadcast message. The fourth STA can decrypt the multicast or broadcast message using the second GTK. It should be understood that the description of the third AP and the fourth STA can refer to the description of the first AP and the first STA mentioned above. For example, AC 105 can also send a first indication to the third AP. The third AP turns off automatic update of the GTK according to the first indication.
[0186] In the aforementioned Figure 7 In the example, AC 105 serves as the control center for both the first and second groups. The control center is responsible for maintaining the GTK for this group. In practice, different groups of APs may have different control centers. For example, Figure 8 This is a fourth flow chart of the wireless communication method provided in the embodiment of the present application. Figure 8 As shown, the wireless communication method includes the following steps.
[0187] For the description of steps 701 to 703, please refer to the aforementioned Figure 7 The description of steps 701 to 703 in FIG.
[0188] In step 801, the AC sends a control instruction to the third AP. The embodiment of the present application does not limit the sending method and format of the control instruction. The format of the control instruction can be agreed upon by the third AP and AC 105.
[0189] In step 802, the third AP generates a second GTK based on the control instruction. After receiving the control instruction, the third AP becomes the control center for the second group. The third AP is responsible for maintaining the second GTK for the second group. For example, the third AP generates the second GTK based on the control instruction. The third AP may also send the second GTK to the fourth STA. The third AP may also update the second GTK based on the control instruction, obtaining an updated second GTK. The third AP sends the updated second GTK to the fourth STA.
[0190] It should be understood that Figure 7 and Figure 8 The description is only given by taking three APs as an example. In actual applications, AC 105 can group multiple APs differently according to actual conditions. For example, the WLAN system also includes a fourth AP. AC 105 groups the third AP and the fourth AP as the second group according to the reference grouping information. Figure 8 In the embodiment, the third AP may also send a second GTK to the fourth AP.
[0191] Figure 9 This is a second structural diagram of the WLAN system provided in the embodiment of the present application. Figure 9 As shown, the WLAN system includes a first AP 101, a second AP 102, a third AP 901, and a fourth AP 902. The circular dashed lines outside the APs represent the AP's signal coverage. The dashed lines between the APs and the STAs represent their associations. Specifically, the first AP 101 is associated with STA1 and STA3. The second AP 102 is associated with STA2. The third AP 901 is associated with STA4 and STA6. The fourth AP 902 is associated with STA5.
[0192] The solid arrow lines between the APs and STAs represent the transmission direction of multicast or broadcast messages. AC 105 (not shown) defines the first AP 101 and the second AP 102 as a first group. In the first group, the first AP 101 encrypts data using the first GTK to obtain a first message. The first AP 101 multicasts or broadcasts the first message. STA1, STA2, and STA3 decrypt the first message using the first GTK. AC 105 defines the third AP 901 and the fourth AP 902 as a second group. In the second group, the third AP 901 encrypts data using the second GTK to obtain a multicast or broadcast message. STA4, STA5, and STA6 decrypt the multicast or broadcast message sent by the third AP 901 using the second GTK.
[0193] exist Figure 9 In this example, AC 105 can select an AP in the second group as the control center for the second group. AC 105 can select the control center based on the processing capabilities of the APs in the second group or the relationship between the APs in the second group and AC 105. For example, AC 105 can select an AP with high processing capabilities in the second group as the control center. Alternatively, AC 105 can select an AP with fewer nodes connected to AC 105 as the control center. For example, if third AP 901 is directly connected to AC 105, and fourth AP 902 is connected to AC 105 through first AP 101, AC 105 will select third AP 901 as the control center for the second group.
[0194] The wireless communication method and WLAN system provided in the embodiments of the present application are described above. The wireless communication device provided in the embodiments of the present application is described below. Figure 10 This is a first structural diagram of a wireless communication device provided in an embodiment of the present application. Figure 10 As shown, wireless communication device 1000 includes a generation module 1001 and a sending module 1002. Generation module 1001 is configured to generate a first GTK. Sending module 1002 is configured to send a first message to a first AP and a second AP. The first message includes a first GTK. The first GTK is used by a first STA and a second STA to decrypt a first message multicast or broadcast by the first AP. The first AP is associated with the first STA. The second AP is associated with the second STA.
[0195] It should be understood that the wireless communication device 1000 can be the AC 105 in the aforementioned wireless communication method or WLAN system. Therefore, for the description of the wireless communication device 1000, reference can be made to the relevant description in the aforementioned wireless communication method or WLAN system. For example, the sending module 1002 can also be configured to send the first indication to the first AP. For another example, the sending module 1002 can also be configured to send the updated first GTK to the first AP.
[0196] Figure 11 This is a second structural diagram of the wireless communication device provided in the embodiment of the present application. Figure 11 As shown, wireless communication device 1100 includes a generation module 1101, an encryption module 1102, and a sending module 1103. Generation module 1101 is used to generate a first GTK. Encryption module 1102 is used to encrypt data using the first GTK to obtain a first message. Sending module 1103 is used to multicast or broadcast the first message. Sending module 1103 is also used to send the first GTK to a second AP and a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. Wireless communication device 1100 is associated with the first STA. The first GTK is used by the second STA to decrypt the first message based on the first GTK. The second STA is associated with the second AP.
[0197] It should be understood that the wireless communication device 1100 can be the first AP 101 in the aforementioned wireless communication method or WLAN system. Therefore, for the description of the wireless communication device 1100, reference can be made to the relevant description of the aforementioned wireless communication method or WLAN system. For example, the encryption module 1102 can also be used to encrypt data based on the first GTK to obtain a second message. The sending module 1003 can also be used to multicast or broadcast the second message. For another example, the wireless communication device 1100 can also include a receiving module and a disabling module. The receiving module is used to receive a first instruction from the AC. The disabling module disables automatic GTK updates based on the first instruction.
[0198] Figure 12 This is a schematic diagram of the structure of the wireless communication device provided in the embodiment of the present application. Figure 12 As shown, the wireless communication device 1200 includes a processor 1201 and a transceiver 1202. The wireless communication device 1200 may be an AC or a first AP in a WLAN system or a wireless communication method.
[0199] When wireless communication device 1200 is an AC, processor 1201 is configured to generate a first GTK. Transceiver 1202 is configured to send a first message to a first AP and a second AP. The first message includes the first GTK. The first GTK is used by the first STA and the second STA to decrypt a first message multicast or broadcast by the first AP. The first AP and the first STA are associated. The second AP and the second STA are associated.
[0200] It should be understood that for the description of the wireless communication device 1200, reference can be made to the description of the wireless communication method or WLAN system described above. The processor 1201 can also be used to execute the processing steps performed by the AC 105 in the wireless communication method described above. For example, the processor 1201 can also be used to execute Figure 3Step 305 in step 306. For another example, the processor 1201 can also be used to execute Figure 5 The transceiver 1202 may also be used to perform the sending or receiving steps performed by the AC 105 in the aforementioned wireless communication method. For example, the transceiver 1202 may also be used to Figure 3 Step 301 in the above. For another example, the transceiver 1202 can also be used to Figure 5 Step 501 and step 503 in .
[0201] When wireless communication device 1200 is a first AP, processor 1201 is configured to generate a first GTK. Processor 1201 is configured to encrypt data using the first GTK to obtain a first message. Transceiver 1202 is configured to multicast or broadcast the first message. Transceiver 1202 is further configured to send the first GTK to a second AP and a first STA. The first GTK is used by the first STA to decrypt the first message based on the first GTK. The first AP and the first STA are associated. The first GTK is used by the second STA to decrypt the first message based on the first GTK. The second STA is associated with a second AP.
[0202] It should be understood that for the description of the wireless communication device 1200, reference can be made to the description of the wireless communication method or WLAN system described above. The processor 1201 can also be used to execute the processing steps performed by the first AP 101 in the wireless communication method described above. For example, the processor 1201 can also be used to execute Figure 3 The transceiver 1202 may also be used to perform the sending or receiving steps performed by the first AP 101 in the aforementioned wireless communication method. For example, the transceiver 1202 may also be used to Figure 5 Step 504 in .
[0203] In other embodiments, the wireless communication device 1200 may further include a memory 1203. The memory 1203 may be a non-volatile memory, such as a hard disk drive (HDD), or a volatile memory, such as a random-access memory (RAM). The memory 1203 is any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but is not limited thereto.
[0204] The memory 1203 may be used to store the first GTK or the first message. The memory 1203 may also be used to store instructions so that the processor 1201 can perform the steps mentioned in the aforementioned wireless communication method. Alternatively, the memory 1203 may also be used to store other instructions to configure parameters of the processor 1201 to implement corresponding functions.
[0205] It should be understood that Figure 12 The device can also be used to execute the method steps mentioned in the embodiment variations or optional solutions shown in the aforementioned figures, which will not be described in detail here.
[0206] In the embodiments of the present application, the processor 1201 can be a general-purpose processor, a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor can be a microprocessor or any conventional processor. The steps of the methods disclosed in the embodiments of the present application can be directly implemented as being executed by a hardware processor, or can be executed by a combination of hardware and software units in the processor.
[0207] The program code executed by processor 1201 to implement the above-mentioned wireless communication method may be stored in memory 1203. Memory 1203 and processor 1201 are coupled. Coupling in the embodiments of the present application refers to an indirect coupling or communication connection between devices, units, or modules, which may be electrical, mechanical, or other forms, and is used for information exchange between devices, units, or modules. Processor 1201 may operate in conjunction with memory 1203.
[0208] Based on the above embodiments, embodiments of the present application further provide a computer-readable storage medium. This storage medium stores a software program that, when read and executed by one or more processors, can implement the methods provided in any one or more of the above embodiments. The computer-readable storage medium may include any medium capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory, a random access memory, a magnetic disk, or an optical disk.
[0209] Based on the above embodiments, embodiments of the present application further provide a chip. The chip includes a processor configured to implement the functions described in any one or more of the above embodiments, such as obtaining or processing the first message described in the above method. Optionally, the chip also includes a memory for program instructions and data necessary for execution by the processor. The chip may be comprised of a single chip or may include a chip and other discrete components.
[0210] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems) and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0211] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0212] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0213] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present application without departing from the scope of the embodiments of the present application. Thus, if these modifications and variations of the embodiments of the present application fall within the scope of the claims of the present application and their equivalents, the present application also intends to include these modifications and variations.
Claims
1. A wireless local area network system, characterized in that: The system includes a controller, a first access point, and a second access point, wherein the first access point is associated with a first station, and the second access point is associated with a second station, wherein: The controller is configured to generate a first group of temporary keys GTK, and send the first GTK to the first access point and the second access point; The first access point is used to encrypt data using the first GTK to obtain a first message, and multicast or broadcast the first message; The first access point is used to send the first GTK to the first station, and the second access point is used to send the first GTK to the second station.
2. The wireless local area network system according to claim 1, wherein: The controller is configured to send a first GTK to the first access point and the second access point, including: the controller is configured to send a first message to the first access point and the second access point, where the first message includes the first GTK; The first message further includes at least one of the following: identifiers of the first access point and the second access point, an identifier of a virtual access point in the first access point, an identifier of a virtual access point in the second access point, a key replay counter, a reception sequence counter, a group random number, and an integrity group temporary key.
3. The wireless local area network system according to claim 1, wherein: The controller is further configured to send a first indication to the first access point and the second access point; The first access point is further configured to disable automatic update of GTK according to the first instruction; The second access point is further configured to disable automatic update of GTK according to the first instruction.
4. The wireless local area network system according to claim 1, wherein: When a new access point is connected to the controller, the controller is further configured to send a first message to the new access point.
5. The wireless local area network system according to claim 1, wherein: The controller is configured to generate a first GTK, including: the controller is configured to generate the first GTK according to a group master key GMK, a group random number, and a MAC address of the controller.
6. The wireless local area network system according to any one of claims 1 to 5, characterized in that: When any one of the following conditions is met, the controller is further configured to send an updated first GTK to the first access point and the second access point; The conditions include: the controller is restarted, a key timer in the controller times out, the encryption mode of the controller is changed from public to encrypted, and a site using the first GTK is offline.
7. The wireless local area network system according to claim 5, wherein: The controller is further configured to update the first GTK according to the updated GMK, the updated group random number, and the MAC address of the controller to obtain the updated first GTK.
8. The wireless local area network system according to any one of claims 1 to 5, characterized in that: The wireless local area network system further includes a third access point; The controller is further configured to obtain grouping reference information of three access points, where the three access points include the first access point, the second access point, and the third access point; The controller is further configured to determine, based on the group reference information, that the first access point and the second access point use the first GTK, and the third access point uses a second GTK, where the second GTK is different from the first GTK.
9. The wireless local area network system according to any one of claims 1 to 5, characterized in that: The second station is further configured to roam from the second access point to the first access point; The first access point is further configured to encrypt data using the first GTK to obtain a second message, and multicast or broadcast the second message; The second site is further configured to decrypt the second message according to the first GTK.
10. The wireless local area network system according to any one of claims 1 to 5, characterized in that: The first access point and the second access point use the same basic service set identifier (BSSID).
11. The wireless local area network system according to any one of claims 1 to 5, characterized in that: The first GTK is used by the first site to decrypt the first message according to the first GTK.
12. The wireless local area network system according to claim 11, wherein: The first GTK is used by the second site to decrypt the first message according to the first GTK.
13. The wireless local area network system according to any one of claims 1 to 5, characterized in that: The controller is connected to the first access point and the second access point in a wired manner.
14. A communication method, characterized in that: include: The controller generates the first set of temporary keys GTK, The controller sends a first GTK to a first access point and a second access point, so that the first access point sends the first GTK to a first station and the second access point sends the first GTK to a second station. The first access point is associated with the first station, and the second access point is associated with the second station.
15. The method according to claim 14, characterized in that The controller sending the first GTK to the first access point and the second access point includes: the controller sending a first message to the first access point and the second access point, where the first message includes the first GTK; The first message further includes at least one of the following: identifiers of the first access point and the second access point, an identifier of a virtual access point in the first access point, an identifier of a virtual access point in the second access point, a key replay counter, a reception sequence counter, a group random number, or an integrity group temporary key.
16. The method according to claim 14, characterized in that The method further comprises: The controller sends a first instruction to the first access point and the second access point, where the first instruction is used for the first access point and the second access point to disable automatic update of GTK according to the first instruction.
17. The method according to claim 14, characterized in that When any one of the following conditions is met, the method further includes: The controller sends the updated first GTK to the first access point and the second access point; The conditions include: the controller is restarted, a key timer in the controller times out, the encryption mode of the controller is changed from public to encrypted, and a site using the first GTK is offline.
18. The method according to claim 14, characterized in that The controller generating the first GTK includes: the controller generating the first GTK according to a group master key GMK, a group random number, and a MAC address of the controller.
19. The method according to any one of claims 14 to 18, characterized in that Before the controller sends the first message to the first access point and the second access point, the method further includes: The controller obtains grouping reference information of three access points, where the three access points include the first access point, the second access point, and a third access point; The controller determines, based on the group reference information, that the first access point and the second access point use the first GTK; The controller determines, according to the group reference information, that the third access point uses a second GTK, where the second GTK is different from the first GTK.
20. The method according to any one of claims 14 to 18, characterized in that The first GTK is used by the first station to decrypt the first message sent by the first access point according to the first GTK.
21. The method according to claim 20, characterized in that The first GTK is used by the second station to decrypt the first message sent by the first access point according to the first GTK.
22. A communication device, characterized in that: It includes a generation module and a sending module, wherein: The generating module is used to generate a first group of temporary keys GTK; The sending module is configured to send a first message to a first access point and a second access point, where the first message includes a first GTK, so that the first access point sends the first GTK to a first station and the second access point sends the first GTK to a second station, the first access point being associated with the first station, and the second access point being associated with the second station.
23. The device according to claim 22, characterized in that The first message further includes at least one of the following: identifiers of the first access point and the second access point, identifiers of virtual access points in the first access point, identifiers of virtual access points in the second access point, a key replay counter, a reception sequence counter, a group random number, or an integrity group temporary key.
24. The device according to claim 22, characterized in that The sending module is further configured to send a first instruction to the first access point and the second access point, where the first instruction is used for the first access point and the second access point to disable automatic update of GTK according to the first instruction.
25. The device according to claim 22, characterized in that When any one of the following conditions is met, the sending module is further used to send the updated first GTK to the first access point and the second access point; the conditions include: the communication device is restarted, the key timer in the communication device times out, the encryption mode of the communication device is changed from public to encrypted, and the site using the first GTK is offline.
26. The device according to any one of claims 22 to 25, characterized in that The first GTK is used by the first station to decrypt the first message multicast or broadcast by the first access point.
27. The device according to claim 26, characterized in that The first GTK is used by the second station to decrypt the first message multicast or broadcast by the first access point.
28. The device according to any one of claims 22 to 25, characterized in that The generating module is used to generate a first GTK according to the GMK, a group random number and the MAC address of the communication device.
29. The device according to any one of claims 22 to 25, characterized in that The communication device is a controller.
30. A controller, characterized in that: The controller is configured to execute the method according to any one of claims 14 to 21.
Citation Information
Patent Citations
Method, apparatus and system for updating group transient key
CN102217239A
WLAN roaming method and device
CN108012306A
Synchronized group messaging
US20150124681A1