PTK derivation during link addition procedures
By introducing new PTK calculation and FILS authentication during seamless roaming, the issues of data loss and security in seamless roaming are resolved, achieving continuity and security of data transmission and ensuring communication stability and security during the link addition phase.
Patent Information
- Application Number
- CN202511173130.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-08-27
- Filing Date
- 2025-08-21
- Publication Date
- 2026-03-06
AI Technical Summary
During seamless roaming, existing technologies suffer from data loss issues, especially when non-access point devices switch from one access point to another. Communication interruptions lead to data loss, and security may be compromised due to PTK sharing as a static context.
By introducing a new PTK calculation during the link addition phase, using a security context container (such as a seamless roaming element SRE) and a fast initial link to establish FILS authentication, non-access point devices and target access points maintain communication with the serving access point while establishing a new connection, ensuring the continuity of data transmission, and deriving a new temporary key PTK through a temporary key and a Diffie-Hellman shared secret.
It achieves continuity of data transmission during seamless roaming, prevents data loss, and enhances security by ensuring secure communication through liveness proof and replay protection.
Smart Images

Figure CN121619632A_ABST
Abstract
Description
Technical Field
[0001] This application relates in general to wireless communication systems, including security for seamless roaming between access points. Background Technology
[0002] Wireless communication technologies use various standards and protocols to transmit data between access points and wireless communication devices. For example, wireless communication system standards and protocols may include, for instance, 3GPP Long Term Evolution (LTE) (e.g., 4G), 3GPP New Radio (NR) (e.g., 5G), and the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard for Wireless Local Area Networks (WLANs) (commonly referred to within the industry organization as...). ).
[0003] In the 802.11 standard for WLAN, an access point (AP) is used to create a wireless local area network (WLAN) or... A network device. An access point (AP) can connect to a wired network (such as Ethernet) and provide wireless access to that network for other devices. A station is a device that can wirelessly connect to an AP to join a WLAN network. A station can be a laptop, smartphone, tablet, or any other device with a WLAN adapter.
[0004] AP and station usage The protocols communicate with each other. Various protocols have been established to improve security on wireless communication networks. For example, simultaneous authentication by peer entities is the core authentication protocol of WPA3-Personal, and all... All Alliance Certified devices (including both access points (APs) and non-AP stations (STAs)) must support this protocol. Attached Figure Description
[0005] To facilitate the identification of any particular element or action in the discussion, one or more of the most significant digits in the figure reference numerals refer to the figure number in which the element was first introduced.
[0006] Figure 1 Example signal flow diagrams of the Distribution System (DS) FT protocol according to some implementation schemes are illustrated.
[0007] Figure 2 Example signaling flow diagrams illustrating the link addition process prior to route switching according to some implementation schemes are shown.
[0008] Figure 3 An example signaling flowchart illustrating PTK calculation during the link addition process prior to route switching, according to some implementation schemes, is shown.
[0009] Figure 4An example signaling flowchart illustrating PTK calculation using FILS authentication during the link addition process prior to route switching, according to some implementation schemes, is shown.
[0010] Figure 5 An example signaling flowchart is shown, illustrating how PTK calculation is performed during the link addition process prior to route switching, according to some implementation schemes, using the SRE carried in the link addition request and response frames.
[0011] Figure 6 Example signal flow diagrams illustrating the link addition process and PTK calculation during PTK verification according to some implementation schemes are shown.
[0012] Figure 7 Example signal flow diagrams for PTK verification after PTK derivation according to some implementation schemes are shown.
[0013] Figure 8 A flowchart illustrating an example method performed by an STA (e.g., a non-AP MLD) according to some implementation schemes is shown.
[0014] Figure 9 A flowchart illustrating an example method performed by a service AP according to some implementation schemes is shown.
[0015] Figure 10 A flowchart illustrating an example method performed by a target AP according to some implementation schemes is shown.
[0016] Figure 11 An example system for performing signaling between a wireless device and a network device according to an embodiment disclosed herein is illustrated. Detailed Implementation
[0017] Wireless communication technologies use various standards and protocols to send data between access points and wireless communication devices. One standard used for wireless communication is the Institute of Electrical and Electronics Engineers (IEEE) 802.11 standard for Wireless Local Area Networks (WLANs) (commonly referred to within the industry organization as...). ). This provides a convenient way to establish a network between devices. Devices (e.g., stations) can connect to... The access point joins the network and connects wirelessly to the Internet. Security is crucial for protecting data and devices from unauthorized access.
[0018] Various implementations are described with respect to non-access points (non-APs) (e.g., stations (STAs)) and access points (APs). However, references to STAs and APs are provided for illustrative purposes only. The example implementations can be used with any electronic components capable of establishing a connection to a network and configured with hardware, software, and / or firmware for exchanging information and data with the network. Therefore, STAs and APs as described herein are used to represent any suitable electronic components.
[0019] Seamless roaming refers to the ability of a device to move between different access points (APs) within the same network without experiencing noticeable interruptions in connectivity. This technology is particularly useful in environments with multiple APs where users frequently move around, such as large offices, campuses, or homes with mesh networks.
[0020] As part of seamless roaming, a pair of transient keys (PTKs) are established and used to protect frames. Some implementations described in this paper use link-addition signaling to provide enhancements to PTK export between a non-AP multilink device (MLD) and the roaming target AP MLD.
[0021] To achieve seamless roaming, The system can use Fast Basic Service Set (BSS) Transformation (FT) to perform fast and secure switching between APs. Figure 1 Example signaling flow diagram 116 illustrates a distribution system (DS) FT protocol according to some implementations. FT is a specific method defined within the IEEE 802.11 standard for facilitating fast and secure roaming between Wi-Fi APs. In the illustrated implementation, the FT originator (FTO) 102 uses FT to switch from the current AP 104 to the target AP 106.
[0022] FTO 102 can be a non-AP device, such as a cellular phone, tablet, laptop, or other STA device. FTO 102 can establish a successful (secure) session with the current AP 104. FTO 102 and the current AP 104 can use this session to transmit data. If FTO 102 moves, the signal strength of the current AP 104 may decrease, and the signal strength of the target AP 106 may become stronger.
[0023] When FTO 102 moves from the coverage area of one AP to the coverage area of another AP, FTO 102 can determine 110 that it needs to switch to the target AP 106. FTO 102 can send an authentication request (e.g., FT request 118) to the current AP MLD (e.g., current AP 104). The authentication request may include the identifier of the target AP 106 (e.g., TargetAP); a robust secure network element (RSNE) including security parameters (e.g., pair master key R0 name (PMKR0Name)); a mobile domain element (MDE); and an FT element (FTE) having a requester random number (SNonce) and an R0 key holder identifier (R0KH-ID). In addition, for the authentication request, the source address (SA) field is set to the media access control (MAC) address of FTO 102, and the destination address (DA) is set to the basic service set identifier (BSSID) of the BSS of the target AP MLD.
[0024] The current AP 104 can forward the authentication request to the target AP 106 via a backhaul. The target AP 106 can share security content with the current AP 104 using a remote request, which may include an MDE and an FTE containing the authenticator random number (ANonce), SNonce, R1KH-ID, and R0KH-ID. The current AP 104 can send an FT response 120 to the FTO 102, which includes an RSNE, MDE, and FTE, where the RSNE includes PMKR0Name and the FTE includes ANonce, SNonce, R1KH-ID, and R0KH-ID.
[0025] FTO 102 and target AP 106 use PMK-R1, PMKR1Name, ANOnce, and SNonce to calculate PTK and PTKName. PTK is used to protect the reassociation transaction, including reassociation request 122 and reassociation response 124. Successful reassociation occurs only if the time between FT request 118 and reassociation request 122 does not exceed the reassociation deadline.
[0026] Some benefits of the FT procedure include: SNonce and ANonce enable recovery protection and PTK separation from the serving AP MLD. However, a disadvantage of the FT procedure is that disconnecting communication with the current AP 104 when FTO 102 transmits a reassociation request 122 frame to the target AP 106 can lead to data loss. For example, when FTO 102 transmits reassociation request 122, it may disconnect from the current AP 104. When the connection is broken, the current AP 104 does not see FTO 102 in its network, and therefore the current AP 104 can refresh the packets buffered for FTO 102. Those refreshed packets correspond to the lost downlink data of FTO 102. This type of handover procedure can be called break-before-make (e.g., the old connection is broken before a new connection is established).
[0027] To prevent data loss, some systems can use a make-before-break process (e.g., establishing a new connection before disconnecting the old one). For example, Figure 2 Example signaling flow diagram 202 illustrates a link addition process prior to route switching according to some implementation schemes. The link addition process allows a non-AP MLD 204 to establish a connection with the roaming target AP MLD 208 before disconnecting from the serving AP MLD 206.
[0028] In the illustrated implementation, the non-AP MLD 204 and the serving AP MLD 206 may have an established session and exchange data 210. The non-AP MLD 204 may query / scan 212 to discover the roaming target AP MLD 208. The roaming target AP MLD 208 may indicate that the non-AP MLD 204 is identified as an AP with better signal strength compared to the serving AP MLD 206.
[0029] Non-AP MLD 204 can initiate roaming through serving AP MLD 206. Non-AP MLD 204 sends a link add request 214 with a roaming target AP MLD identifier to serving AP MLD 206. This link add request 214 informs serving AP MLD 206 of the non-AP MLD 204's expectation to roam to the roaming target AP MLD 208 indicated by the identifier in the link add request 214. The link add request 214 can be transmitted over the air.
[0030] Upon receiving a link addition request 214, the serving AP MLD 206 may transmit a link establishment request frame 216 to the indicated roaming target AP MLD 208. The link establishment request frame 216 may include non-AP MLD requirements, capabilities, and PTK. The link establishment request frame 216 can be transmitted via DS.
[0031] The roaming target AP MLD 208 can transmit a link establishment response 218 to the serving AP MLD 206. The link establishment response 218 may include a decision regarding a link add request 214 from a non-AP MLD 204. This decision may instruct the roaming target AP MLD 208 whether to accept the request. The link establishment response 218 from the roaming target AP MLD 208 to the serving AP MLD 206 can be transmitted via DS.
[0032] The serving AP MLD 206 can transmit a link addition response frame 220 over the air to the non-AP MLD 204. After receiving the link addition response frame 220 from the serving AP MLD 206, the link establishment with the roaming target AP MLD 208 is completed (222). The non-AP MLD and the roaming target AP MLD are in state 4. As shown in the figure, the non-AP MLD 204 and the roaming target AP MLD 208 establish a logical connection. Since the serving AP MLD 206 and the non-AP MLD 204 are still connected, they can continue to exchange data. The non-AP MLD 204 can initiate a route switch (224) to the roaming target AP MLD 208 via the established link.
[0033] This process can be beneficial because it maintains communication with the serving AP MLD 206 while adding a link to the roaming target AP MLD 208. This can prevent data loss. However, a potential drawback is that security may be compromised due to PTK sharing being a static context.
[0034] Implementations described herein may include sharing a security context to enhance the link addition process. Some implementations may perform new PTK calculations during the link addition phase (e.g., link addition request and link addition response). For example, a non-AP MLD may derive a new temporary key (PTK) with the roaming target AP MLD during the link addition phase. This can be advantageous because it allows communication with the serving AP MLD to be maintained while adding a link with the roaming target AP MLD. Such enhancements may also enable proof-of-activity, replay protection, and PTK separation. In some implementations, the STA shares its key holder identifier (e.g., R0KH-ID) with the serving AP MLD (which forwards R0KH-ID to the target AP MLD), the target AP MLD shares its key holder identifier R1KH-ID with the serving AP MLD (which forwards R0KH-ID to the STA), and R0KH-ID and R1KH-ID are used by the non-AP MLD and the target AP MLD to derive the PTK.
[0035] Figure 3 Example signaling flow diagram 302 illustrates PTK calculation during a link addition process prior to route switching, according to some implementation schemes. The link addition process allows a non-AP MLD 304 to establish a connection with a roaming target AP MLD 308 before disconnecting from the serving AP MLD 306. Furthermore, the illustrated process introduces a container (e.g., a Seamless Roaming Element (SRE)) including security context carried in management frames (e.g., link addition request and response action frames).
[0036] In the illustrated implementation, the non-AP MLD 304 and the serving AP MLD 306 may have an established session and exchange data 310. The non-AP MLD 304 may query / scan 312 to discover the roaming target AP MLD 308. The roaming target AP MLD 308 may indicate that the non-AP MLD 304 is identified as an AP with better signal strength compared to the serving AP MLD 306.
[0037] Non-AP MLD 304 can initiate roaming through serving AP MLD 306 (e.g., a change of roaming target AP MLD 308 from serving AP MLD 306). Non-AP MLD 304 can transmit a management frame, such as a link-add request frame 314, with a roaming target AP MLD identifier to serving AP MLD 306. This link-add request frame 314 informs serving AP MLD 306 of the non-AP MLD 304's expectation to roam to the roaming target AP MLD 308 as indicated by the identifier in the link-add request frame 314. The link-add request frame 314 can be transmitted over the air.
[0038] Furthermore, the link addition request frame 314 may include an SRE. The SRE may include a security context. The security context included in the SRE of the link addition request frame 314 may include an SNonce and a ROKH-ID. The serving AP MLD 306 may receive the link addition request frame 314 and tunnel the information via the DS. For example, as shown, the serving AP MLD 306 may transmit a link establishment request 316 to the roaming target AP MLD 308, which includes an SRE with an SNonce and a ROKH-ID.
[0039] The roaming target AP MLD 308 can transmit a link establishment response 318 to the serving AP MLD 306 via DS. The link establishment response 318 may include a decision regarding a link add request frame 314 from a non-AP MLD 304. This decision may indicate whether the roaming target AP MLD 308 accepts the request. If the decision is to accept the link add request frame 314 and establish a link with the non-AP MLD 304, the link establishment response 318 may include a container with the security context of the roaming target AP MLD 308. For example, the link establishment response 318 may include an SRE that includes ANonce, R1KH-ID, SNonce, and R0KH-ID.
[0040] The serving AP MLD 306 can transmit a link addition response frame 320 with SRE over the air to the non-AP MLD 304. The link addition response frame 320 transmitted from the serving AP MLD 306 may include all security contexts (e.g., ANonce, R1KH-ID, SNonce, and R0KH-ID) included in the roaming target AP MLD 308's DS link establishment response 318.
[0041] The security context shared by the non-AP MLD 304 and the roaming target AP MLD 308 provides parameters for calculating the PTK. Therefore, upon receiving the security context, both the non-AP MLD 304 and the roaming target AP MLD 308 can calculate the PTK. The PTK can then be used for data encryption and decryption during communication between the roaming target AP MLD 308 and the non-AP MLD 304.
[0042] In some implementations, the non-AP MLD 304 can determine whether its calculated PTK is correct. For example, the non-AP MLD 304 can send a Link Add Acknowledgment Frame 326 to the serving AP MLD 306. The non-AP MLD 304 can forward the information from the Link Add Acknowledgment Frame 326 to the roaming target AP MLD 308 via DS (e.g., Link Add Acknowledgment 328). The Link Add Acknowledgment Frame 326 may include PTK verification information. For example, the Link Add Acknowledgment Frame 326 may include a container (e.g., SRE) containing PTK verification information. If the PTK calculated by the non-AP MLD 304 is incorrect, the roaming target AP MLD 308 can indicate that the PTK is incorrect. If the PTK calculated by the non-AP MLD 304 is correct, the roaming target AP MLD 308 can respond using an Acknowledgment (ACK) message, or the roaming target AP MLD 308 may not provide feedback. In some implementations, the roaming target APMLD 308 only transmits a response frame adding an acknowledgment 328 to the link if the PTK verification information is incorrect.
[0043] In some implementations, a link handshake timeout 330 may be used. The link handshake timeout 330 may define the values for the PTK and context used for link establishment that expire thereafter. The link handshake timeout 330 may refer to the maximum duration between the link add response frame 320 and the link add acknowledgment frame 326. In some implementations, the serving AP MLD 306 may include a timeout value to the non-AP MLD 304 in the link add response frame 320. The roaming target AP MLD 308 and non-AP MLD 304 may set a timer equal to the link handshake timeout 330. If the roaming target AP MLD 308 does not receive a link add acknowledgment frame within the indicated link handshake timeout 330, the newly derived PTK and context used for link establishment may be considered to have expired.
[0044] After PTK is established and verified, the link between AP 322 and the roaming target AP MLD 308 can be established. As shown in the figure, a logical connection is established between non-AP MLD 304 and the roaming target AP MLD 308. Since the serving AP MLD 306 and non-AP MLD 304 are still connected, they can continue to exchange data. Non-AP MLD 304 can initiate a route handover to the roaming target AP MLD 308 via the established link.
[0045] An illustrative implementation could be PTK export during the link addition process for seamless roaming. As shown in the figure, during the link addition process, security contexts can be exchanged between the non-AP MLD 304 and the serving AP MLD 306. Furthermore, in some implementations, timeout values can be used for activity proof and PTK separation.
[0046] In signaling flow diagram 302, the serving AP MLD 306 receives keys from both the non-AP MLD 304 and the roaming target AP MLD 308, and is able to use these keys to generate a PTK. This allows the serving AP MLD 306 to decrypt the communication between signaling flow diagram 302 and the serving AP MLD 306.
[0047] Additional procedures can be implemented to prevent the serving AP MLD from generating a PTK. In some implementations, the non-AP MLD can use Fast Initial Link Setup (FILS) authentication during the link addition phase (e.g., link addition request and link addition response) to derive a new temporary key (e.g., PTK) with the roaming target AP MLD. Such implementations can maintain communication with the serving AP MLD while adding a link with the roaming target AP MLD; and the serving AP MLD may not be able to derive the PTK without knowing the private keys of the non-AP MLD and the roaming target AP MLD. To implement FILS authentication during the link addition phase, the temporary private keys of the non-AP MLD and the roaming target AP MLD may not be shared with the serving AP MLD. Instead, the non-AP MLD and the roaming target AP MLD can share their temporary public key (EPK) with the serving AP MLD. The roaming target AP MLD can use the non-AP MLD's EPK and its own temporary private key to derive a temporary Diffie-Hellman shared secret (DHss). In addition, a non-AP MLD can use the target AP MLD's EPK and its own temporary private key to derive a temporary Diffie-Hellman shared secret (DHss).
[0048] Figure 4 Example signaling flow diagram 402 illustrates PTK calculation using FILS authentication during a link addition process prior to route switching, according to some implementation schemes. The link addition process allows a non-AP MLD 404 to establish a connection with the roaming target AP MLD 408 before disconnecting from the serving AP MLD 406. Furthermore, the illustrated process introduces a container (e.g., a Seamless Roaming Element (SRE)) using FILS authentication, including a security context carried in management frames (e.g., link addition request and response action frames).
[0049] In the illustrated implementation, the non-AP MLD 404 and the serving AP MLD 406 may have an established session and exchange data 410. The non-AP MLD 404 may query / scan 412 to discover the roaming target AP MLD 408. The roaming target AP MLD 408 may indicate that the non-AP MLD 404 is identified as an AP with better signal strength compared to the serving AP MLD 406.
[0050] Non-AP MLD 404 can initiate roaming through serving AP MLD 406 (e.g., a change of roaming target AP MLD 408 from serving AP MLD 406). Non-AP MLD 404 can transmit a management frame, such as a link-add request frame 414, with a roaming target AP MLD identifier to serving AP MLD 406. This link-add request frame 414 informs serving AP MLD 406 of the non-AP MLD 404's expectation to roam to the roaming target AP MLD 408 as indicated by the identifier in the link-add request frame 414. The link-add request frame 414 can be transmitted over the air.
[0051] Furthermore, the link addition request frame 414 may include a container, such as an SRE. The SRE may include a security context. The security context included in the SRE of the link addition request frame 414 may include an EPK (EPK-1) and SNonce of a non-AP MLD. The serving AP MLD 406 may receive the link addition request frame 414 and send information to the roaming target AP MLD 408 tunnel via DS. For example, as shown, the serving AP MLD 406 may transmit a link establishment request 416 to the roaming target AP MLD 408, which includes an SRE with EPK-1 and SNonce.
[0052] The roaming target AP MLD 408 can transmit a link establishment response 418 to the serving AP MLD 406 via the DS. The link establishment response 418 may include a decision regarding a link add request frame 414 from a non-AP MLD 404. This decision may indicate whether the roaming target AP MLD 408 accepts the request. If the decision is to accept the link add request frame 414 and establish a link with the non-AP MLD 404, the link establishment response 418 may include a container with the security context of the roaming target AP MLD 408. For example, the link establishment response 418 may include an SRE containing the roaming target AP MLD's EPK (EPK-2), ANonce, and Message Integrity Code (MIC). The roaming target AP MLD 408 may derive the MIC from EPK-1, EPK2, and ANonce.
[0053] The serving AP MLD 406 can transmit a link addition response frame 420 with SRE over the air to the non-AP MLD 404. The link addition response frame 420 transmitted from the serving AP MLD 406 may include all security contexts (e.g., EPK-2, ANONCE, and MIC) included in the roaming target AP MLD 408's DS link establishment response 418.
[0054] The security context shared between the non-AP MLD 404 and the roaming target AP MLD 408, combined with the temporary private keys of both, can be used to derive a temporary DHss that can be used to derive the PTK. For example, upon receiving the security context, the non-AP MLD 404 can calculate the DHss based on EPK-2 and its own temporary private key. The non-AP MLD 404 can then use the DHss, ANonce, and SNonce to derive the PTK. Similarly, the roaming target AP MLD 408 can calculate the DHss based on EPK-1 and its own temporary private key. The roaming target AP MLD 408 can then use the DHss, ANonce, and SNonce to derive the PTK. The PTK can then be used for data encryption and decryption in communications between the roaming target AP MLD 408 and the non-AP MLD 404.
[0055] In some implementations, the non-AP MLD 404 may check the correctness of its calculated PTK. For example, the non-AP MLD 404 may transmit a link addition acknowledgment frame 426 to the serving AP MLD 406. The non-AP MLD 404 can then forward the information from the link addition acknowledgment frame 426 to the roaming target AP MLD 408 via DS (e.g., link addition acknowledgment 428). The link addition acknowledgment frame 426 may include PTK verification information. For example, the link addition acknowledgment frame 426 may include a container (e.g., SRE) containing a second MIC (e.g., MIC-1). The MIC can be generated using the PTK derived by the non-AP MLD 404.
[0056] If the PTK calculated by the non-AP MLD 404 is incorrect, the roaming target AP MLD 408 may indicate that the PTK is incorrect. If the PTK calculated by the non-AP MLD 404 is correct, the roaming target AP MLD 408 may respond using an acknowledgment (ACK) message, or the roaming target AP MLD 308 may not provide feedback. In some implementations, the roaming target AP MLD 308 only transmits a response frame adding an acknowledgment 328 to the link if the PTK verification information is incorrect.
[0057] In some implementations, a link handshake timeout 430 may be used. The link handshake timeout 430 may define the values for the PTK and context used for link establishment that expire thereafter. The link handshake timeout 430 may refer to the maximum duration between the link add response frame 420 and the link add acknowledgment frame 426. In some implementations, the serving AP MLD 406 may include a timeout value to the non-AP MLD 404 in the link add response frame 420. The roaming target AP MLD 408 and non-AP MLD 404 may set a timer equal to the link handshake timeout 430. If the roaming target AP MLD 408 does not receive a link add acknowledgment frame within the indicated link handshake timeout 430, the newly derived PTK and context used for link establishment may be considered to have expired.
[0058] After establishing and verifying the PTK, the link between AP 422 and the roaming target AP MLD 408 can be established. As shown in the figure, a logical connection is established between non-AP MLD 404 and the roaming target AP MLD 408. Since the serving AP MLD 406 and non-AP MLD 404 remain connected, they can continue to exchange data. Non-AP MLD 404 can initiate a route handover to the roaming target AP MLD 408 via the established link.
[0059] Figures 5 to 7 A flowchart illustrating PTK calculation during the link addition phase of a seamless roaming process is provided. During the link addition phase, the non-AP MLD can use Protected Authentication Service Negotiation (PASN) authentication to export and verify a new temporary key (PTK) with the roaming target AP MLD. This allows the non-AP MLD to maintain communication with the serving AP MLD while adding a link with the roaming target AP MLD. Furthermore, by using PASN authentication, the serving AP MLD may be unable to export the PTK without knowing the private keys of both the non-AP MLD and the roaming target AP MLD.
[0060] In the implementation scheme, using PASN authentication, the temporary private keys of the non-AP MLD and the roaming target AP MLD may not be shared with the serving AP MLD. The non-AP MLD and the roaming target AP MLD can share their temporary public keys (EPKs) with the serving AP MLD. The roaming target AP MLD can use the non-AP MLD's EPK and its own temporary private key to derive a temporary DHss. The non-AP MLD can use the AP MLD's EPK and its own temporary private key to derive a temporary DHss.
[0061] Figure 5Example signaling flow diagram 502 illustrates PTK calculation using SRE carried in link add request and response frames during a link add process prior to route switching, according to some implementation schemes. The link add process allows a non-AP MLD 504 to establish a connection with the roaming target AP MLD 508 before disconnecting from the serving AP MLD 506. Furthermore, the illustrated process introduces a container (e.g., a Seamless Roaming Element (SRE)) including the security context carried in management frames (e.g., link add request and response action frames).
[0062] In the illustrated implementation, the non-AP MLD 504 and the serving AP MLD 506 may have an established session and exchange data 510. The non-AP MLD 504 may query / scan 512 to discover the roaming target AP MLD 508. The roaming target AP MLD 508 may indicate that the non-AP MLD 504 is identified as an AP with better signal strength compared to the serving AP MLD 506.
[0063] Non-AP MLD 504 can initiate roaming through serving AP MLD 506 (e.g., a change of roaming target AP MLD 508 from serving AP MLD 506). Non-AP MLD 504 can transmit a management frame, such as a link-add request frame 514, with a roaming target AP MLD identifier to serving AP MLD 506. This link-add request frame 514 informs serving AP MLD 506 of the non-AP MLD 504's expectation to roam to the roaming target AP MLD 508 as indicated by the identifier in the link-add request frame 514. The link-add request frame 514 can be transmitted over the air.
[0064] Furthermore, the link addition request frame 514 may include a container, such as an SRE. The SRE may include a security context. The security context included in the SRE of the link addition request frame 514 may include an EPK (EPK-1) of a non-AP MLD. The serving AP MLD 506 may receive the link addition request frame 514 and send information to the roaming target AP MLD 508 tunnel via DS. For example, as shown, the serving AP MLD 506 may transmit a link establishment request 516 to the roaming target AP MLD 508, which includes an SRE with EPK-1.
[0065] The roaming target AP MLD 508 can transmit a link establishment response 518 to the serving AP MLD 506 via DS. The link establishment response 518 may include a decision regarding a link add request frame 514 from a non-AP MLD 504. This decision may indicate whether the roaming target AP MLD 508 accepts the request. If the decision is to accept the link add request frame 514 and establish a link with the non-AP MLD 504, the link establishment response 518 may include a container with the security context of the roaming target AP MLD 508. For example, the link establishment response 518 may include an SRE containing the roaming target AP MLD's EPK (EPK-2) and Message Integrity Code (MIC).
[0066] The serving AP MLD 506 can transmit a link add response frame 520 with SRE over the air to the non-AP MLD 504. The link add response frame 520 transmitted from the serving AP MLD 506 may include all security contexts (e.g., EPK-2 and MIC) included in the roaming target AP MLD 508's DS link establishment response 518. Furthermore, in some implementations, the link add response frame 520 from the serving AP MLD 506 may include a link handshake timeout. The link handshake timeout may define the interval between subsequent PTK and context expiration for link establishment.
[0067] The security context shared between the non-AP MLD 504 and the roaming target AP MLD 508, combined with the temporary private keys of both, can be used to derive a temporary DHss that can be used to derive the PTK. For example, upon receiving the security context, the non-AP MLD 504 can compute the DHss based on EPK-2 and its own temporary private key. The non-AP MLD 504 can then use the DHss to derive the PTK. Similarly, the roaming target AP MLD 508 can compute the DHss based on EPK-1 and its own temporary private key. The roaming target AP MLD 508 can then use the DHss to derive the PTK. The PTK can then be used for data encryption and decryption during communication between the roaming target AP MLD 508 and the non-AP MLD 504.
[0068] After establishing the PTK, the link between AP 522 and the roaming target AP MLD 508 can be established. As shown in the figure, a logical connection is established between the non-AP MLD 504 and the roaming target AP MLD 508. Since the serving AP MLD 506 and the non-AP MLD 504 remain connected, they can continue to exchange data. The non-AP MLD 504 can initiate a route handover to the roaming target AP MLD 508 via the established link.
[0069] Figure 6 Example signaling flow diagram 602 illustrates a link addition process and PTK calculation during PTK verification according to some implementation schemes. The link addition process allows a non-AP MLD 604 to establish a connection with a roaming target AP MLD 608 before disconnecting from the serving AP MLD 606. Furthermore, the illustrated process introduces a container (e.g., a Seamless Roaming Element (SRE)) that includes a security context carried in management frames (e.g., link addition request and response action frames).
[0070] In the illustrated implementation, the non-AP MLD 604 and the serving AP MLD 606 may have an established session and exchange data 610. The non-AP MLD 604 may query / scan 612 to discover the roaming target AP MLD 608. The roaming target AP MLD 608 may indicate that the non-AP MLD 604 is identified as an AP with better signal strength compared to the serving AP MLD 606.
[0071] Non-AP MLD 604 can initiate roaming through serving AP MLD 606 (e.g., a change of roaming target AP MLD 608 from serving AP MLD 606). Non-AP MLD 604 can transmit a management frame, such as Link Add Request Frame 614, with a roaming target AP MLD identifier to serving AP MLD 606. This Link Add Request Frame 614 informs serving AP MLD 606 of the non-AP MLD 604's expectation to roam to the roaming target AP MLD 608 as indicated by the identifier in Link Add Request Frame 614. Link Add Request Frame 614 can be transmitted over the air. Link Add Request Frame 614 can be the first message used for PASN authentication.
[0072] Furthermore, the Link Add Request Frame 614 may include a container, such as an SRE. The SRE may include a security context. The security context included in the SRE of the Link Add Request Frame 614 may include an EPK (EPK-1) of a non-AP MLD. The serving AP MLD 606 may receive the Link Add Request Frame 614 and send information to the roaming target AP MLD 608 tunnel via DS. For example, as shown, the serving AP MLD 606 may transmit a Link Establishment Request 616 to the roaming target AP MLD 608, which includes an SRE with EPK-1.
[0073] The roaming target AP MLD 608 can transmit a link establishment response 618 to the serving AP MLD 606 via DS. The link establishment response 618 may include a decision regarding a link add request frame 614 from a non-AP MLD 604. This decision may indicate whether the roaming target AP MLD 608 accepts the request. If the decision is to accept the link add request frame 614 and establish a link with the non-AP MLD 604, the link establishment response 618 may include a container with the security context of the roaming target AP MLD 608. For example, the link establishment response 618 may include an SRE containing the roaming target AP MLD's EPK (EPK-2) and Message Integrity Code (MIC).
[0074] The serving AP MLD 606 may transmit a link add response frame 620 with SRE over the air to the non-AP MLD 604. The link add response frame 620 transmitted from the serving AP MLD 606 may include all security contexts (e.g., EPK-2 and MIC) included in the roaming target AP MLD 608's DS link establishment response 618. Furthermore, in some implementations, the link add response frame 620 from the serving AP MLD 606 may include a link handshake timeout. The link handshake timeout may define the interval at which the PTK and context used for link establishment expire. The link handshake timeout may refer to the interval between the link add response frame 620 and the route switching request frame 624. If the route switching request frame 624 is not received within the indicated link handshake timeout interval, the newly derived PTK and context used for link establishment may expire. The link add response frame 620 may be a second message for PASN authentication.
[0075] The security context shared between the non-AP MLD 604 and the roaming target AP MLD 608, combined with the temporary private keys of both, can be used to derive a temporary DHss that can be used to derive the PTK. For example, upon receiving the security context, the non-AP MLD 604 can compute the DHss based on EPK-2 and its own temporary private key. The non-AP MLD 604 can then use the DHss to derive the PTK. Similarly, the roaming target AP MLD 608 can compute the DHss based on EPK-1 and its own temporary private key. The roaming target AP MLD 608 can then use the DHss to derive the PTK. The PTK can then be used for data encryption and decryption in communications between the roaming target AP MLD 608 and the non-AP MLD 604.
[0076] After establishing the PTK, the link between AP 622 and the roaming target AP MLD 608 can be set up. As shown in the figure, a logical connection is established between the non-AP MLD 604 and the roaming target AP MLD 608. Since the serving AP MLD 606 and the non-AP MLD 604 remain connected, they can continue to exchange data.
[0077] Non-AP MLD 604 can initiate a route handover to the roaming target AP MLD 608 via an established link. For example, non-AP MLD 604 can transmit a route handover request frame 624. The route handover request frame 624 can be used as a third message to share the MIC generated by the non-AP MLD with the roaming target AP MLD after exporting a new PTK. The route handover response frame 626 from the roaming target AP MLD 608 can be used as a fourth message indicating that the MIC shared by the non-AP MLD 604 has been verified.
[0078] The benefits of the process in signal flow diagram 602 may include: for PTK verification, additional frames are not required. Instead, PASN verification can be piggybacked on frames already used for link establishment and route switching. However, this can also lead to a dependency on PTK derivation and verification between the link addition and route switching phases.
[0079] Figure 7 Example signaling flow diagram 702 illustrates PTK verification after PTK export according to some implementation schemes. The link addition process allows a non-AP MLD 704 to establish a connection with the roaming target AP MLD 708 before disconnecting from the serving AP MLD 706. Furthermore, the illustrated process introduces a container (e.g., a Seamless Roaming Element (SRE)) including the security context carried in management frames (e.g., link addition request and response action frames).
[0080] In the illustrated implementation, the non-AP MLD 704 and the serving AP MLD 706 may have an established session and exchange data 710. The non-AP MLD 704 may query / scan 712 to discover the roaming target AP MLD 708. The roaming target AP MLD 708 may indicate that the non-AP MLD 704 is identified as an AP with better signal strength compared to the serving AP MLD 706.
[0081] Non-AP MLD 704 can initiate roaming via serving AP MLD 706 (e.g., a change of roaming target AP MLD 708 from serving AP MLD 706). Non-AP MLD 704 can transmit a management frame, such as a link-add request frame 714, with a roaming target AP MLD identifier to serving AP MLD 706. This link-add request frame 714 informs serving AP MLD 706 of the non-AP MLD 704's expectation to roam to the roaming target AP MLD 708 as indicated by the identifier in the link-add request frame 714. The link-add request frame 714 can be transmitted over the air. The link-add request frame 714 can be the first message used for PASN authentication.
[0082] Furthermore, the Link Add Request Frame 714 may include a container, such as an SRE. The SRE may include a security context. The security context included in the SRE of the Link Add Request Frame 714 may include an EPK (EPK-1) of a non-AP MLD. The serving AP MLD 706 may receive the Link Add Request Frame 714 and send information to the roaming target AP MLD 708 tunnel via DS. For example, as shown, the serving AP MLD 706 may transmit a Link Establishment Request 716 to the roaming target AP MLD 708, which includes an SRE with EPK-1.
[0083] The roaming target AP MLD 708 can transmit a link establishment response 718 to the serving AP MLD 706 via DS. The link establishment response 718 may include a decision regarding a link add request frame 714 from a non-AP MLD 704. This decision may indicate whether the roaming target AP MLD 708 accepts the request. If the decision is to accept the link add request frame 714 and establish a link with the non-AP MLD 704, the link establishment response 718 may include a container with the security context of the roaming target AP MLD 708. For example, the link establishment response 718 may include an SRE containing the roaming target AP MLD's EPK (EPK-2) and Message Integrity Code (MIC).
[0084] The serving AP MLD 706 can transmit a link add response frame 720 with SRE over the air to the non-AP MLD 704. The link add response frame 720 transmitted from the serving AP MLD 706 may include all security contexts (e.g., EPK-2 and MIC) included in the roaming target AP MLD 708's DS link establishment response 718. Furthermore, in some implementations, the link add response frame 720 from the serving AP MLD 706 may include a link handshake timeout. The link handshake timeout may define the interval at which the PTK and context used for link establishment expire. The link handshake timeout may refer to the interval between the link add response frame 720 and the route link add acknowledgment frame 724. If the route link add acknowledgment frame 724 is not received within the indicated link handshake timeout interval, the newly derived PTK and context used for link establishment may expire. The link add response frame 720 may be a second message for PASN authentication.
[0085] The security context shared between the non-AP MLD 704 and the roaming target AP MLD 708, combined with the temporary private keys of both, can be used to derive a temporary DHss that can be used to derive the PTK. For example, upon receiving the security context, the non-AP MLD 704 can calculate the DHss based on EPK-2 and its own temporary private key. The non-AP MLD 704 can then use the DHss to derive the PTK. Similarly, the roaming target AP MLD 708 can calculate the DHss based on EPK-1 and its own temporary private key. The roaming target AP MLD 708 can then use the DHss to derive the PTK. The PTK can then be used for data encryption and decryption during communication between the roaming target AP MLD 708 and the non-AP MLD 704.
[0086] In some implementations, non-AP MLD 704 may send a Link Addition Acknowledgment Frame 724 to the serving AP MLD 706 as a third message carrying PTK authentication information, and the serving AP MLD 706 may forward it to the roaming target AP MLD 708. A Link Addition Acknowledgment ACK Frame 726 may be used as a fourth message. The Link Addition Acknowledgment ACK Frame 726 may be transmitted from the roaming target AP MLD 708 to acknowledge the MIC shared in the third message.
[0087] After PTK is established and verified, the link between AP 722 and the roaming target AP MLD 708 can be established. As shown in the figure, a logical connection is established between the non-AP MLD 704 and the roaming target AP MLD 708. Since the serving AP MLD 706 and the non-AP MLD 704 remain connected, they can continue to exchange data.
[0088] The benefits of the process in signal flow diagram 702 may include: verification is completed within the standalone link establishment phase. However, this may require additional frames (e.g., six messages for link establishment and route switching) compared to FT-based roaming.
[0089] Figure 8 A flowchart illustrating an example method 800 performed by a STA (e.g., a non-AP MLD) according to some implementation schemes is shown. The illustrated method 800 includes establishing 802 a first link with a first AP. Method 800 also includes transmitting 804 a first management frame to the first AP, the first management frame including an identifier of a second AP and a first container having the STA's security context. Method 800 further includes receiving 806 a second management frame from the first AP, the second management frame including a second container having the second AP's security context. Method 800 also includes deriving 808 a temporary key for communicating with the second AP based on the second AP's security context. Method 800 further includes establishing 810 a second link with the second AP before disconnecting the first link with the first AP.
[0090] In some implementations of method 800, the first management frame includes a link-add request, and the second management frame includes a link-add response.
[0091] In some embodiments of method 800, the first container includes a first seamless roaming element (SRE) of the STA, and the second container includes a second SRE of the second AP.
[0092] In some implementations of method 800, the first SRE includes a requester random number (SNonce) and a first key holder identifier (R0KH-ID) for the STA, and the second SRE includes a certifier random number (ANonce) and a second key holder identifier (R1KH-ID) for the second AP. In some implementations, the temporary key is further based on a pair of master keys, ANonce, and SNonce.
[0093] In some implementations of method 800, the first SRE includes the STA's first temporary public key (EPK) (EPK-1) and SNonce, the second SRE includes the second AP's second EPK (EPK-2), ANonce and Message Integrity Code (MIC), and the derived temporary key is further based on SNonce, ANonce and a temporary Diffie-Hellman shared secret (DHss) derived from the STA's temporary private key and EPK-2.
[0094] In some implementations of method 800, the temporary key includes a pairwise transient key (PTK).
[0095] In some implementations, method 800 also includes transmitting a link-added acknowledgment that includes temporary key verification information.
[0096] In some implementations of method 800, temporary key verification includes a MIC based on the temporary key.
[0097] In some implementations, method 800 further includes performing a route switch to disconnect the first link with the first AP and begin data exchange with the second AP on the second link.
[0098] In some implementations of method 800, protected authentication service negotiation (PASN) authentication is used to verify the temporary key.
[0099] The embodiments contemplated herein include an apparatus comprising components for performing one or more elements of method 800. This apparatus may be, for example, an STA (such as STA 1102, as described herein).
[0100] The embodiments contemplated herein include one or more non-transitory computer-readable media comprising instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements of method 800. The non-transitory computer-readable medium may be, for example, memory of an STA (such as memory 1106 of STA 1102, as described herein).
[0101] The embodiments contemplated herein include an apparatus comprising logic components, modules, or circuitry for performing one or more elements of method 800. This apparatus may be, for example, an STA (such as STA 1102, as described herein).
[0102] The embodiments contemplated herein include an apparatus comprising: one or more processors and one or more computer-readable media, the one or more computer-readable media including instructions that, when executed by the one or more processors, cause the one or more processors to perform one or more elements of method 800. The apparatus may be, for example, an STA (such as STA 1102, as described herein).
[0103] The implementation scheme envisioned herein includes a signal as described in or associated with one or more elements of method 800.
[0104] The embodiments contemplated herein include a computer program or computer program product comprising instructions, wherein execution of the program by a processor will cause the processor to perform one or more elements of method 800. The processor may be a processor of an STA (such as processor 1104 of STA 1102, as described herein). These instructions may, for example, reside in the processor and / or in the memory of the STA (such as memory 1106 of STA 1102, as described herein).
[0105] Figure 9 A flowchart illustrating an example method 900 performed by a serving AP according to some implementation schemes is provided. The illustrated method 900 includes establishing a first link with a STA (Station) 902. Method 900 also includes receiving a first management frame 904 from the STA, the first management frame including an identifier of the target AP and a first container having the STA's security context. Method 900 further includes transmitting the first management frame 906 to the target AP. Method 900 also includes receiving a second management frame 908 from the target AP, the second management frame including a second container having the target AP's security context. Method 900 further includes transmitting the second management frame 910 to the STA.
[0106] In some implementations of method 900, the first management frame includes a link-add request, and the second management frame includes a link-add response.
[0107] In some embodiments of method 900, the first container includes a first SRE of the STA, and the second container includes a second SRE of the target AP.
[0108] In some implementations of method 900, the first SRE includes the first key holder identifier (R0KH-ID) of SNonce and STA, and the second SRE includes the second key holder identifier (R1KH-ID) of ANonce and target AP.
[0109] In some implementations of method 900, the first SRE includes the first temporary public key (EPK) (EPK-1) of the STA and SNonce, wherein the second SRE includes the second EPK (EPK-2), ANonce and MIC of the target AP.
[0110] In some implementations, method 900 also includes receiving a link-addition confirmation that includes temporary key verification information.
[0111] In some implementations of method 900, temporary key verification includes a MIC based on the temporary key.
[0112] In some implementations of method 900, protected authentication service negotiation (PASN) authentication is used to verify the temporary key.
[0113] The embodiments contemplated herein include an apparatus comprising components for performing one or more elements of method 900. This apparatus may be, for example, an AP (such as AP 1118, as described herein).
[0114] The embodiments contemplated herein include one or more non-transitory computer-readable media comprising instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements of method 900. The non-transitory computer-readable medium may be, for example, the memory of an access point (such as memory 1122 of AP 1118, as described herein).
[0115] The embodiments contemplated herein include an apparatus comprising logic components, modules, or circuitry for performing one or more elements of method 900. This apparatus may be, for example, an AP (such as AP 1118, as described herein).
[0116] The embodiments contemplated herein include an apparatus comprising: one or more processors and one or more computer-readable media, the one or more computer-readable media including instructions that, when executed by the one or more processors, cause the one or more processors to perform one or more elements of method 900. The apparatus may be, for example, an AP (such as AP 1118, as described herein).
[0117] The implementation scheme envisioned herein includes a signal as described in or associated with one or more elements of method 900.
[0118] The embodiments contemplated herein include a computer program or computer program product comprising instructions, wherein execution of the program by a processing element will cause the processing element to perform one or more elements of method 900. The processor may be the processor of an AP (such as processor 1120 of AP 1118, as described herein). These instructions may, for example, reside in the processor and / or in the memory of the AP (such as memory 1122 of AP 1118, as described herein).
[0119] Figure 10 A flowchart illustrating an example method 1000 performed by a target AP according to some implementation schemes is provided. The illustrated method 1000 includes receiving 1002 a first management frame from a STA via a serving AP, the first management frame including a first container having the STA's security context. Method 1000 also includes transmitting 1004 a second management frame to the serving AP, the second management frame including a second container having the target AP's security context. Method 1000 further includes deriving 1006 a temporary key for communicating with the STA based on the STA's security context. Method 1000 also includes establishing 1008 a link with the STA before the STA disconnects from the serving AP.
[0120] In some implementations of method 1000, the first management frame includes a link add request, and the second management frame includes a link add response.
[0121] In some embodiments of method 1000, the first container includes a first seamless roaming element (SRE) of the STA, and the second container includes a second SRE of the target AP.
[0122] In some embodiments of method 1000, the first SRE includes the first key holder identifier (R0KH-ID) of SNonce and STA, and the second SRE includes the second key holder identifier (R1KH-ID) of ANonce and target AP.
[0123] In some implementations of method 1000, the first SRE includes the first EPK (EPK-1) and SNonce of the STA, the second SRE includes the second EPK (EPK-2), ANonce and MIC of the target AP, and wherein the derived temporary key is further based on a temporary DHss derived from the temporary private key of the target AP.
[0124] In some implementations of method 1000, the temporary key includes PTK.
[0125] In some implementations, method 1000 also includes receiving a link-addition confirmation that includes temporary key verification information.
[0126] In some implementations of method 1000, temporary key verification includes a MIC based on the temporary key.
[0127] In some implementations of method 1000, protected authentication service negotiation (PASN) authentication is used to verify the temporary key.
[0128] The embodiments contemplated herein include an apparatus comprising components for performing one or more elements of method 1000. This apparatus may be, for example, an AP (such as AP 1118, as described herein).
[0129] The embodiments contemplated herein include one or more non-transitory computer-readable media comprising instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform one or more elements of method 1000. The non-transitory computer-readable medium may be, for example, the memory of an access point (such as memory 1122 of AP 1118, as described herein).
[0130] The embodiments contemplated herein include an apparatus comprising logic components, modules, or circuitry for performing one or more elements of method 1000. This apparatus may be, for example, an AP (such as AP 1118, as described herein).
[0131] The embodiments contemplated herein include an apparatus comprising: one or more processors and one or more computer-readable media including instructions that, when executed by the one or more processors, cause the one or more processors to perform one or more elements of method 1000. The apparatus may be, for example, an AP (such as AP 1118, as described herein).
[0132] The implementation scheme envisioned herein includes a signal as described in or associated with one or more elements of method 1000.
[0133] The embodiments contemplated herein include a computer program or computer program product comprising instructions, wherein execution of the program by a processing element will cause the processing element to perform one or more elements of method 1000. The processor may be the processor of an AP (such as processor 1120 of AP 1118, as described herein). These instructions may, for example, reside in the processor and / or in the memory of the AP (such as memory 1122 of AP 1118, as described herein).
[0134] Figure 11A system 1100 for executing signaling 1134 between STA 1102 and AP 1118 according to an embodiment disclosed herein is illustrated. System 1100 may be part of a wireless communication system as described herein. STA 1102 may be, for example, a UE of a wireless communication system. AP 1118 may be, for example, an access point of a wireless communication system.
[0135] STA 1102 may include one or more processors 1104. Processor 1104 may execute instructions that cause various operations of STA 1102 to be performed as described herein. Processor 1104 may include one or more baseband processors, which may be implemented using, for example, a central processing unit (CPU), digital signal processor (DSP), application-specific integrated circuit (ASIC), controller, field-programmable gate array (FPGA) device, another hardware device, firmware device, or any combination thereof configured to perform the operations described herein.
[0136] STA 1102 may include memory 1106. Memory 1106 may be a non-transitory computer-readable storage medium that stores instructions 1108 (which may include, for example, instructions executed by processor 1104). Instructions 1108 may also be referred to as program code or a computer program. Memory 1106 may also store data used by processor 1104 and results calculated by the processor.
[0137] STA 1102 may include one or more transceivers 1110, which may include radio frequency (RF) transmitter circuitry and / or receiver circuitry that uses antenna 1112 of STA 1102 to facilitate signaling (e.g., signaling 1134) to and / or from STA 1102 and other devices (e.g., AP 1118).
[0138] STA 1102 may include one or more antennas 1112 (e.g., one, two, three, four, or more antennas). For implementations with multiple antennas 1112, STA 1102 can fully utilize the spatial diversity of such multiple antennas 1112 to transmit and / or receive multiple different data streams on the same time-frequency resource. This behavior can be referred to as, for example, multiple-input multiple-output (MIMO) behavior (referring to multiple antennas used separately at each of the transmitting and receiving devices to achieve this aspect). MIMO transmission by STA 1102 can be achieved according to pre-decoding (or digital beamforming) applied at STA 1102, whereby the STA multiplexes data streams across antennas 1112 based on known or assumed channel characteristics, such that each data stream is received with appropriate signal strength relative to the others at a desired location in the spatial domain (e.g., the location of the receiver associated with that data stream). Some implementations may use a single-user MIMO (SU-MIMO) approach (where all data streams are directed to a single receiver) and / or a multi-user MIMO (MU-MIMO) approach (where individual data streams may be directed to individual (different) receivers at different locations in the airspace).
[0139] In some implementations with multiple antennas, STA 1102 can implement analog beamforming technology, whereby the phase of the signal transmitted by antenna 1112 is relatively adjusted, enabling (joint) transmission of the directional antenna 1112 (this is sometimes referred to as beam control).
[0140] STA 1102 may include one or more interfaces 1114. Interfaces 1114 can be used to provide input to or from STA 1102. For example, STA 1102 as a UE may include interfaces 1114, such as microphones, speakers, touchscreens, and buttons, to allow users of the UE to input to and / or output to the UE. Other interfaces of such a UE may consist of transmitters, receivers, and other circuitry that allow communication between the UE and other devices (e.g., in addition to the transceiver 1110 / antenna 1112 already described) and may be configured according to known protocols (e.g., (etc.) to perform the operation.
[0141] STA 1102 may include a link addition module 1116. The link addition module 1116 may be implemented via hardware, software, or a combination thereof. For example, the link addition module 1116 may be implemented as a processor, circuitry, and / or instructions 1108 stored in memory 1106 and executed by processor 1104. In some examples, the link addition module 1116 may be integrated within processor 1104 and / or transceiver 1110. For example, the link addition module 1116 may be implemented via a combination of software components and hardware components (e.g., logic gates and circuitry) within processor 1104 or transceiver 1110 (e.g., executed by a DSP or general-purpose processor).
[0142] Link addition module 1116 can be used in various aspects of this disclosure, for example, Figures 3 to 7 All aspects.
[0143] AP 1118 may include one or more processors 1120. Processor 1120 is executable instructions that cause AP 1118 to perform various operations as described herein. Processor 1120 may include one or more baseband processors, which are implemented using, for example, a CPU, DSP, ASIC, controller, FPGA device, another hardware device, firmware device, or any combination thereof configured to perform the operations described herein.
[0144] AP 1118 may include memory 1122. Memory 1122 may be a non-transitory computer-readable storage medium that stores instructions 1124 (which may include, for example, instructions executed by processor 1120). Instructions 1124 may also be referred to as program code or a computer program. Memory 1122 may also store data used by processor 1120 and results calculated by the processor.
[0145] AP 1118 may include one or more transceivers 1126, which may include RF transmitter circuitry and / or receiver circuitry that uses the antenna 1128 of AP 1118 to facilitate signaling (e.g., signaling 1134) to and / or from AP 1118 and other devices (e.g., STA 1102).
[0146] AP 1118 may include one or more antennas 1128 (e.g., one, two, three, four or more antennas). In embodiments with multiple antennas 1128, AP 1118 may perform MIMO, digital beamforming, analog beamforming, beam control, etc., as already described.
[0147] AP 1118 may include one or more interfaces 1130. Interface 1130 can be used to provide input to or from AP 1118. For example, AP 1118 as a base station may include interface 1130 consisting of transmitters, receivers and other circuitry (e.g., in addition to transceiver 1126 / antenna 1128 already described), which enables the base station to communicate with other equipment in the core network and / or enables the base station to communicate with external networks, computers, databases, etc., for the purpose of operating, managing and maintaining the base station or other equipment operable to the base station.
[0148] AP 1118 may include a link addition module 1132. Link addition module 1132 may be implemented via hardware, software, or a combination thereof. For example, link addition module 1132 may be implemented as a processor, circuitry, and / or instructions 1124 stored in memory 1122 and executed by processor 1120. In some examples, link addition module 1132 may be integrated within processor 1120 and / or transceiver 1126. For example, link addition module 1132 may be implemented via a combination of software components and hardware components (e.g., logic gates and circuitry) within processor 1120 or transceiver 1126 (e.g., executed by a DSP or general-purpose processor).
[0149] Link addition module 1132 can be used in various aspects of this disclosure, for example, Figures 3 to 7 All aspects.
[0150] For one or more embodiments, at least one of the components illustrated in one or more of the foregoing figures may be configured to perform one or more operations, techniques, processes, and / or methods as set forth herein. For example, a processor described herein in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples set forth herein. Similarly, circuitry associated with a STA or AP described above in conjunction with one or more of the foregoing figures may be configured to operate according to one or more of the examples set forth herein.
[0151] Unless otherwise expressly stated, any of the above embodiments may be combined with any other embodiment (or combination of embodiments). The foregoing description of one or more specific embodiments provides illustration and description, but is not intended to be exhaustive or to limit the scope of the embodiments to the precise form disclosed. In view of the teachings above, modifications and variations are possible, or modifications and variations may be derived from the practice of various embodiments.
[0152] Implementations and specific embodiments of the systems and methods described herein may include various operations embodied in machine-executable instructions to be executed by a computer system. The computer system may include one or more general-purpose or special-purpose computers (or other electronic devices). The computer system may include hardware components, including specific logical units for performing the operations; or may include a combination of hardware, software, and / or firmware.
[0153] It should be recognized that the systems described herein include descriptions of specific implementations. These implementations may be combined into a single system, partially integrated into other systems, divided into multiple systems, or otherwise partitioned or combined. Furthermore, it is conceivable to use parameters, attributes, aspects, etc., of one implementation in one implementation. For clarity, these parameters, attributes, aspects, etc., are described only in one or more implementations, and it should be recognized that, unless expressly stated herein, these parameters, attributes, aspects, etc., may be combined with or substituted for parameters, attributes, aspects, etc., of another implementation.
[0154] As is widely recognized, the use of personally identifiable information should comply with privacy policies and practices that are generally accepted to meet or exceed industry or governmental requirements for protecting user privacy. Specifically, personally identifiable information data should be managed and processed to minimize the risk of unintentional or unauthorized access or use, and the nature of authorized use should be clearly explained to users.
[0155] Although the foregoing has been described in considerable detail for clarity, it will be apparent that certain changes and modifications can be made without departing from the principles of the invention. It should be noted that many alternative ways exist to implement both the processes and apparatus described herein. Therefore, embodiments of the invention should be considered illustrative rather than restrictive, and this specification is not limited to the details given herein, but can be modified within the scope and equivalents of the appended claims.
Claims
1. A method performed by a station (STA), the method comprising: establishing a first link with a first access point (AP); transmitting a first management frame to the first AP, the first management frame including an identifier of a second AP and a first container with a STA security context; receiving a second management frame from the first AP including a second container with an AP security context to the second AP; deriving a temporal key for communicating with the second AP based on the security context of the second AP; and establishing a second link with the second AP prior to disconnecting the first link with the first AP.
2. The method of claim 1, wherein the first management frame is received over-the-air and includes a link addition request, and the second management frame is received over-the-air and includes a link addition response.
3. The method of claim 1, wherein the first container includes a first seamless roaming element (SRE) of the STA, and the second container includes a second SRE of the second AP.
4. The method of claim 3, wherein the first SRE includes a supplicant nonce (SNonce) and a first key holder identifier (R0KH-ID) of the STA, and wherein the second SRE includes an authenticator nonce (ANonce) and a second key holder identifier (R1KH-ID) of the second AP, and wherein deriving the temporal key is further based on a pairwise master key, the ANonce, and the SNonce.
5. The method of claim 3, wherein the first SRE includes a first ephemeral public key (EPK) (EPK-1) of the STA and a SNonce, wherein the second SRE includes a second EPK (EPK-2) of the second AP, an ANonce, and a message integrity code (MIC), and wherein deriving the temporal key is further based on the SNonce, the ANonce, and an ephemeral Diffie-Hellman shared secret (DHss) derived from an ephemeral private key of the STA and the EPK-2.
6. The method of claim 1, wherein the temporal key includes a pairwise transient key (PTK).
7. The method of claim 1, further comprising transmitting a link addition confirmation including temporal key verification information.
8. The method of claim 7, wherein the temporal key verification includes a MIC based on the temporal key.
9. The method of claim 1, further comprising performing a route switch with the second AP to disconnect the first link with the first AP and begin data exchange with the second AP over the second link.
10. The method of claim 1, wherein the first SRE includes a first ephemeral public key (EPK) (EPK-1) of the STA, wherein the second SRE includes a second EPK (EPK-2) of the second AP and a message integrity code (MIC), and wherein deriving the temporal key is further based on the EPK-1, the EPK-2, and the MIC. wherein the temporary key is verified using a protected authentication service negotiation (PASN) authentication.
11. A method performed by a serving access point (AP), the method comprising: establishing a first link with a station (STA); receiving a first management frame from the STA over the air, the first management frame including an identifier of a target AP and a first container with a STA security context; transmitting the first management frame to the target AP; receiving a second management frame from the target AP, the second management frame including a second container with a security context of the target AP; and transmitting the second management frame to the STA over the air.
12. The method of claim 11, wherein the first management frame includes a link addition request and the second management frame includes a link addition response.
13. The method of claim 11, wherein the first container includes a first seamless roaming element (SRE) of the STA and the second container includes a second SRE of the target AP.
14. The method of claim 13, wherein the first SRE includes a supplicant nonce (SNonce) and a first key holder identifier (R0KH-ID) of the STA, and wherein the second SRE includes an authenticator nonce (ANonce) and a second key holder identifier (R1KH-ID) of the target AP.
15. The method of claim 13, wherein the first SRE includes a first ephemeral public key (EPK) of the STA (EPK-1) and the SNonce, wherein the second SRE includes a second EPK of the target AP (EPK-2), the ANonce, and a message integrity code (MIC).
16. The method of claim 11, further comprising receiving a link addition confirmation including temporary key verification information.
17. The method of claim 16, wherein the temporary key verification includes a MIC based on a temporary key.
18. The method of claim 16, wherein the first SRE includes a first ephemeral public key (EPK) of the STA (EPK-1), wherein the second SRE includes a second EPK of the second AP (EPK-2) and a message integrity code (MIC), and wherein the temporary key is verified using a protected authentication service negotiation (PASN) authentication.
19. A method performed by a target access point (AP), the method comprising: receiving a first management frame from a station (STA) via a serving AP, the first management frame including a first container with a STA security context; transmitting a second management frame to the serving AP, the second management frame including a second container with a security context to the target AP; deriving a temporary key for communicating with the STA based on the STA security context; and establishing a link with the STA before the STA disconnects from the serving AP.
20. The method of claim 19, wherein the first management frame comprises a link add request and the second management frame comprises a link add response.
21. The method of claim 19, wherein the first container comprises a first seamless roaming element (SRE) of the STA and the second container comprises a second SRE of the target AP.
22. The method of claim 21, wherein the first SRE comprises a supplicant nonce (SNonce) and a first key holder identifier (R0KH-ID) of the STA, and wherein the second SRE comprises an authenticator nonce (ANonce) and a second key holder identifier (R1KH-ID) of the target AP.
23. The method of claim 21, wherein the first SRE comprises a first ephemeral public key (EPK) (EPK-1) of the STA and a SNonce, wherein the second SRE comprises a second EPK (EPK-2) of the target AP, an ANonce, and a message integrity code (MIC), and wherein the derivation of the temporal key is further based on an ephemeral Diffie-Hellman shared secret (DHss) derived from a temporary private key of the target AP and the EPK-1.
24. The method of claim 19, wherein the temporal key comprises a pairwise transient key (PTK).
25. The method of claim 19, further comprising receiving a link add confirmation comprising temporal key verification information.
26. The method of claim 25, wherein the temporal key verification comprises a MIC based on the temporal key.
27. The method of claim 21, wherein the first SRE comprises a first ephemeral public key (EPK) (EPK-1) of the STA, wherein the second SRE comprises a second EPK (EPK-2) of the second AP and a message integrity code (MIC), and wherein the temporal key is verified using a protected authentication service negotiation (PASN) authentication.
28. An apparatus comprising means for performing a method of any of claims 1-26.
29. A computer-readable medium comprising instructions that, when executed by one or more processors of an electronic device, cause the electronic device to perform a method of any of claims 1-26.
30. An apparatus comprising logic, means, or circuitry for performing a method of any of claims 1-26.