Communication method and device

By implementing PTK full-network synchronization in the FTTR system, the problem of cumbersome and time-consuming access process between FTTR devices and terminal devices is solved, and communication performance and security are improved.

CN122002277APending Publication Date: 2026-05-08HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
HUAWEI TECH CO LTD
Filing Date
2025-01-09
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

The access process between FTTR devices and terminal devices is cumbersome and time-consuming, especially when the terminal device is roaming, it needs to re-execute scanning, authentication, association and four-way handshake, which affects communication performance.

Method used

With network-wide uplink and downlink encryption enabled, the primary access device synchronizes the PTK of the terminal devices to the associated FTTR device, achieving network-wide PTK synchronization and avoiding the need for terminal devices to rescan, authenticate, and perform four-way handshakes while roaming.

Benefits of technology

It reduces the complexity of the access process, shortens the access time, improves communication performance, and enhances communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122002277A_ABST
    Figure CN122002277A_ABST
Patent Text Reader

Abstract

The invention discloses a communication method and device, relates to the technical field of communication, and can reduce the tedious degree of an access process, shorten the access duration and improve the communication performance when terminal equipment roams from first equipment to second equipment. The method comprises the following steps: a first device sends first information to a main access device under the condition that a whole network and downlink encryption function is opened; the first information comprises an encrypted pairwise temporary key PTK, and the PTK is the PTK obtained by interaction between the first equipment and the terminal equipment; the main access device sends second information to one or more second devices associated with the main access device according to the first information; wherein the second information comprises the encrypted PTK; the second equipment is other FTTR equipment except the first equipment in the FTTR equipment associated with the main access equipment.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to Chinese Patent Application No. 202411569887.6, filed with the State Intellectual Property Office of China on November 4, 2024, entitled "Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of communication technology, and in particular to a communication method and apparatus. Background Technology

[0003] In communication systems, fiber-to-the-room (FTTR) devices and terminal devices require three stages—scanning, authentication, and association—before data transmission. When the network is in encrypted mode, an additional four-way handshake using the Extended Authentication Protocol over LAN (EAPoL) is required for access authentication. Through this four-way handshake process, FTTR devices and terminal devices can securely negotiate and exchange pairwise transient keys (PTKs). After the four-way handshake is complete, subsequent frame propagation can be performed in an encrypted manner.

[0004] As shown above, the access process between FTTR devices and terminal devices involves many steps and is time-consuming. This extended access time is noticeable in cases of packet loss and retransmission. When a terminal device roams from one FTTR device to another on the same network, the above access process needs to be re-executed, making the access process cumbersome, time-consuming, and impacting communication performance. Summary of the Invention

[0005] This application provides a communication method and apparatus that can reduce the complexity of the access process, shorten the access time, and improve communication performance when a terminal device roams from a first device to a second device or a main access device on the same network.

[0006] Firstly, this application provides a communication method that can be executed by a primary access device. Unless otherwise specified, the term "primary access device" in this application can refer to the primary access device itself, a component within the primary access device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the primary access device. The method includes: receiving first information from a first device when the network uplink and downlink encryption functions are enabled; wherein the first information includes an encrypted pairwise temporary key PTK, the PTK being obtained through interaction between the first device and a terminal device; and sending second information to one or more second devices associated with the primary access device based on the first information; wherein the second information includes the encrypted PTK; the second devices are other FTTR devices (excluding the first device) among the fiber-to-the-room FTTR devices associated with the primary access device.

[0007] Based on the first aspect, the primary access device can obtain the PTK (Platform Target Key) exchanged between the first device and the terminal device, and synchronize it with other FTTR devices (i.e., the second device) associated with the primary access device, excluding the first device. This achieves network-wide PTK synchronization. When a terminal device roams from the first device to the second device, since the second device has already obtained the PTK corresponding to the terminal device during the synchronization process, there is no need to re-scan, authenticate, associate, or perform a four-way handshake. This reduces the complexity of the access process, shortens the access time, and improves communication performance. Furthermore, the aforementioned PTK synchronization process is performed with network-wide uplink and downlink encryption enabled, which enhances communication security.

[0008] In one possible design, the first information may also include one or more of the following: the virtual access point (AP) identifier in the first device, the media access control (MAC) address of the terminal device, the frame type, the frame content, the frame length, or the key length.

[0009] Based on this possible design, one or more of the above parameters can also be carried in the first message to improve communication performance.

[0010] In one possible design, the first information is decrypted to obtain PTK; PTK is then encrypted using an encryption mechanism to obtain the second information.

[0011] The encryption mechanism can be a link-layer encryption mechanism, that is, encrypting PTK based on the link-layer encryption mechanism to obtain the second information.

[0012] In one possible design, the first information is decrypted based on the key between the main access device and the first device to obtain the PTK.

[0013] In one possible design, a key request message is sent to the first device, and a key is received from the first device, which is the key between the main access device and the first device.

[0014] In one possible design, the PTK is encrypted using the key between the primary access device and the second device to obtain the encrypted PTK.

[0015] In one possible design, a key request message is sent to the second device, and a key is received from the second device, which is the key between the main access device and the second device.

[0016] In one possible design, the second information may also include one or more of the following: the virtual AP identifier in the second device, the MAC address of the terminal device, the frame type, the identification information of the terminal device, the frame content, the frame length, or the key length.

[0017] Based on this possible design, one or more of the above parameters can also be carried in the second information to improve communication performance.

[0018] In one possible design, the method further includes receiving third information from one or more second devices; wherein the third information is used to indicate that a PTK has been received.

[0019] Based on this possible design, the second device can also send third information to the primary access point device, so that the primary access point device can determine whether to complete PTK network-wide synchronization based on the received third information.

[0020] In one possible design, if no third information is received from one or more second devices, the second information is retransmitted; wherein the third information is used to indicate that PTK has been received.

[0021] Based on this possible design, when one or more second devices fail to receive the second information, the primary access point device can resend the second information to achieve PTK network-wide synchronization.

[0022] In one possible design, before receiving the first information from the first device, the method further includes: determining a first state of the entire network uplink and downlink encryption function; wherein the first state is either an enabled state or an disabled state; and enabling the entire network uplink and downlink encryption function if the first state is disabled.

[0023] Based on this possible design, the first information can be transmitted using the aforementioned encryption mechanism when the uplink and downlink encryption functions of the entire network are enabled, thereby improving communication security.

[0024] In one possible design, when the first state is the disabled state, the method further includes: disabling the entire network uplink and downlink encryption function upon receiving third information from one or more second devices.

[0025] Based on this possible design, the main access point device can also restore the state of the entire network's uplink and downlink encryption functions according to the first state after achieving PTK full network synchronization.

[0026] In one possible design, the method further includes sending a fourth message to the first device; wherein the fourth message is used to indicate that the first message has been received.

[0027] Based on this possible design, the primary access point device can also send a fourth message to the first device to inform the first device that it has received the first message.

[0028] Secondly, this application provides a communication method, which can be executed by a first device. Unless otherwise specified, the "first device" in this application can refer to the first device itself, a component within the first device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the first device. The method includes: obtaining a pairwise temporary key PTK; wherein the PTK is obtained through interaction between the first device and a terminal device; and sending first information to a main access device; wherein the first information includes the encrypted PTK.

[0029] Based on the second aspect, the first device can report the PTK (Platform Target Key) exchanged between itself and the terminal device to the primary access point device. The primary access point device can then synchronize the PTK with other FTTR devices (i.e., the second device) associated with the primary access point device, excluding the first device, achieving network-wide PTK synchronization. When a terminal device roams from the first device to the second device, since the second device has already obtained the corresponding PTK during the synchronization process, there is no need to re-scan, authenticate, associate, or perform a four-way handshake. This reduces the complexity of the access process, shortens access time, and improves communication performance. Furthermore, the above PTK synchronization process is performed with network-wide uplink and downlink encryption enabled, which enhances communication security.

[0030] In one possible design, sending the first information to the main access device includes: encrypting the PTK based on an encryption mechanism to obtain the first information; and sending the first information to the main access device.

[0031] Based on this possible design, the encryption mechanism could be a link-layer encryption mechanism, that is, encrypting the PTK using a link-layer encryption mechanism to obtain the first information. Transmitting the PTK using an encryption mechanism can improve communication security.

[0032] In one possible design, the PTK is encrypted using the key between the main access device and the first device to obtain the first information.

[0033] In one possible design, a key request message is received from the main access device, and a key is sent to the main access device. This key is the key between the main access device and the first device.

[0034] In one possible design, the method further includes: receiving fourth information from the main access device; wherein the fourth information is used to indicate that the first information has been received.

[0035] Based on this possible design, the primary access point device can also send a fourth message to the first device to inform the first device that it has received the first message.

[0036] Thirdly, this application provides a communication method that can be executed by a second device. Unless otherwise specified, the "second device" in this application can refer to the second device itself, a component within the second device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the functions of the second device. The method includes: receiving second information from a primary access device; wherein the second information includes an encrypted pairwise temporary key PTK, the PTK being obtained through interaction between a first device and a terminal device; and decrypting the second information to obtain the PTK.

[0037] Based on the third aspect, the primary access point device can synchronize the PTK (Platform Target Key) exchanged between the first device and the terminal device to other FTTR devices (i.e., the second device) associated with the primary access point device, excluding the first device. This achieves network-wide PTK synchronization. When a terminal device roams from the first device to the second device, since the second device has already obtained the corresponding PTK during the synchronization process, there is no need to re-scan, authenticate, associate, or perform a four-way handshake. This reduces the complexity of the access process, shortens access time, and improves communication performance. Furthermore, the aforementioned PTK synchronization process is performed with network-wide uplink and downlink encryption enabled, which enhances communication security.

[0038] In one possible design, the method further includes sending third information to the primary access device; wherein the third information is used to indicate that PTK has been received.

[0039] Based on this possible design, the second device can also send third information to the primary access point device, so that the primary access point device can determine whether to complete PTK network-wide synchronization based on the received third information.

[0040] In one possible design, the second information is decrypted to obtain PTK, including: decrypting the second information based on an encryption mechanism to obtain PTK.

[0041] The encryption mechanism can be a link-layer encryption mechanism, that is, encrypting PTK based on the link-layer encryption mechanism to obtain the second information.

[0042] In one possible design, the second information is decrypted based on the key between the primary access device and the second device to obtain the PTK.

[0043] In one possible design, a key request message is received from the primary access device, and a key is sent to the primary access device. This key is the key between the primary access device and the second device.

[0044] In one possible design, the method further includes: receiving first association request information from a terminal device; wherein the first association request information is used to request access to a second device; if it is determined that the terminal device has already accessed the network corresponding to the second device, sending first association response information to the terminal device; wherein the first association response information is used to instruct the terminal device to access the second device; and communicating with the terminal device according to PTK.

[0045] Based on this possible design, when a terminal device roams from the first device to the second device, it can communicate with the second device using the above method based on a single handshake, without having to re-scan, authenticate, associate, and perform a four-way handshake. This can reduce the complexity of the access process, shorten the access time, and improve communication performance.

[0046] Fourthly, this application provides a communication method that can be executed by a main access device. Unless otherwise specified, the term "main access device" in this application can refer to the main access device itself, a component within the main access device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the main access device's functions. The method includes: receiving first information from a first device when the network uplink and downlink encryption functions are enabled; wherein the first information includes an encrypted pairwise temporary key PTK, the PTK being obtained through interaction between the first device and a terminal device; and communicating with the terminal device based on the first information.

[0047] Based on the fourth aspect, the first device can report the PTK (Platform Target Key) exchanged between the first device and the terminal device to the primary access point device. When the terminal device roams from the first device to the primary access point device, since the primary access point device has already obtained the PTK corresponding to the terminal device based on the first information, there is no need to re-scan, authenticate, associate, or perform a four-way handshake. This reduces the complexity of the access process, shortens the access time, and improves communication performance. Furthermore, the aforementioned PTK synchronization process is performed with the entire network's uplink and downlink encryption functions enabled, and the encryption mechanism enhances communication security.

[0048] In one possible design, communicating with a terminal device based on the first information includes: receiving second association request information from the terminal device; wherein the second association request information is used to request access to a primary access device; if it is determined that the terminal device has already accessed the network corresponding to the primary access device, sending second association response information to the terminal device; wherein the second association response information is used to instruct the terminal device to access the primary access device; and communicating with the terminal device according to PTK.

[0049] Based on this possible design, when a terminal device roams from the first device to the main access device, it can communicate with the main access device in a single handshake using the above method. This eliminates the need for re-scanning, authentication, association, and four-way handshake, reducing the complexity of the access process, shortening access time, and improving communication performance.

[0050] In one possible design, the first information is decrypted based on the key between the main access device and the first device to obtain the PTK.

[0051] In one possible design, a key request message is sent to the first device, and a key is received from the first device, which is the key between the main access device and the first device.

[0052] Fifthly, this application provides a communication method that can be executed by a terminal device. Unless otherwise specified, "terminal device" in this application can refer to the terminal device itself, a component within the terminal device (e.g., a processor, chip, or chip system), or a logic module or software capable of implementing all or part of the terminal device's functions. The method includes: when the terminal device roams from an associated first device to a target device, sending association request information to the target device; wherein the association request information is used to request access to the target device; receiving association response information from the target device; wherein the association response information is used to instruct the terminal device to access the target device; and communicating with the target device based on a pairwise temporary key PTK; wherein the PTK is a PTK obtained through interaction between the first device and the terminal device.

[0053] Based on the fifth aspect, when a terminal device roams from the first device to the target device, it can use the above method to achieve communication with the target device based on a single handshake, without having to re-scan, authenticate, associate, and perform a four-way handshake. This can reduce the complexity of the access process, shorten the access time, and improve communication performance.

[0054] In one possible design, the target device is the primary access device; or, the target device is the second device, which is another FTTR device in the fiber-to-room FTTR equipment associated with the primary access device, excluding the first device.

[0055] Sixthly, this application provides a communication device that can be applied to the main access device described in the first or fourth aspect to realize the functions performed by the main access device. The communication device can be the main access device, or it can be a chip, chip system, or system-on-a-chip of the main access device, etc. The communication device can execute the functions performed by the main access device through hardware, or it can execute corresponding software through hardware. The hardware or software includes one or more modules corresponding to the above functions. For example, a transceiver module and a processing module. The transceiver module can independently complete the following transceiver operations, or it can cooperate with the processing module to complete the following transceiver operations; correspondingly, the processing module can independently complete the following processing operations, or it can cooperate with the transceiver module to complete the following processing operations, without limitation.

[0056] For example, the transceiver module is configured to receive first information from a first device when the network uplink and downlink encryption functions are enabled; wherein the first information includes an encrypted pairwise temporary key PTK, the PTK being obtained by the interaction between the first device and the terminal device; the transceiver module is further configured to send second information to one or more second devices associated with the main access device according to the first information; wherein the second information includes the encrypted PTK; the second devices are other FTTR devices in the fiber-to-the-room FTTR devices associated with the main access device besides the first device.

[0057] In another example, the transceiver module is used to receive first information from the first device when the uplink and downlink encryption functions of the entire network are enabled; wherein, the first information includes an encrypted pairwise temporary key PTK, the PTK being obtained by the interaction between the first device and the terminal device; the transceiver module and the processing module are used to communicate with the terminal device based on the first information.

[0058] Optionally, the transceiver module and processing module of the communication device in the sixth aspect may also perform the corresponding functions in the first aspect or any possible design of the first aspect, or perform the corresponding functions in the fourth aspect or any possible design of the fourth aspect, as detailed in the above method examples, and the beneficial effects that can be achieved can also be found in the foregoing related content.

[0059] Seventhly, this application provides a communication device that can be applied to the first device described in the second aspect above to realize the functions performed by the first device. The communication device can be the first device, or it can be a chip, chip system, or system-on-a-chip of the first device, etc. The communication device can execute the functions performed by the first device through hardware, or it can execute corresponding software through hardware. The hardware or software includes one or more modules corresponding to the above functions. For example, a transceiver module and a processing module. The transceiver module can independently complete the following transceiver operations, or it can cooperate with the processing module to complete the following transceiver operations; correspondingly, the processing module can independently complete the following processing operations, or it can cooperate with the transceiver module to complete the following processing operations, without limitation.

[0060] For example, the processing module is used to obtain a pair of temporary keys PTK; wherein the PTK is obtained by the interaction between the first device and the terminal device; the transceiver module is used to send first information to the main access device; wherein the first information includes the encrypted PTK.

[0061] Optionally, the transceiver module and processing module of the communication device in the seventh aspect may also perform the corresponding functions in the second aspect or any possible design of the second aspect, as detailed in the above method examples, and the beneficial effects that can be achieved can also be found in the foregoing related content.

[0062] Eighthly, this application provides a communication device that can be applied to the second device described in the third aspect to realize the functions performed by the second device. The communication device can be the second device, or it can be a chip, chip system, or system-on-a-chip of the second device, etc. The communication device can execute the functions performed by the second device through hardware, or it can execute corresponding software through hardware. The hardware or software includes one or more modules corresponding to the above functions. For example, a transceiver module and a processing module. The transceiver module can independently complete the following transceiver operations, or it can cooperate with the processing module to complete the following transceiver operations; correspondingly, the processing module can independently complete the following processing operations, or it can cooperate with the transceiver module to complete the following processing operations, without limitation.

[0063] For example, the transceiver module is used to receive second information from the main access device; wherein, the second information includes an encrypted pairwise temporary key PTK, the PTK being obtained by the interaction between the first device and the terminal device; the processing module is used to decrypt the second information to obtain the PTK.

[0064] Optionally, the transceiver module and processing module of the communication device in the eighth aspect may also perform the corresponding functions in the third aspect or any possible design of the third aspect, as detailed in the above method examples, and the beneficial effects that can be achieved can also be found in the foregoing related content.

[0065] Ninthly, this application provides a communication device that can be applied to the terminal device described in the fifth aspect to realize the functions performed by the terminal device. The communication device can be the terminal device itself, or it can be a chip, chip system, or system-on-a-chip (SoC) of the terminal device. The communication device can execute the functions performed by the terminal device through hardware or through corresponding software. The hardware or software includes one or more modules corresponding to the functions described above. For example, a transceiver module and a processing module. The transceiver module can independently complete the following transceiver operations or cooperate with the processing module to complete the following transceiver operations; correspondingly, the processing module can independently complete the following processing operations or cooperate with the transceiver module to complete the following processing operations, without limitation.

[0066] For example, the transceiver module is used to send association request information to the target device when the terminal device roams from the associated first device to the target device; wherein the association request information is used to request access to the target device; the transceiver module is also used to receive association response information from the target device; wherein the association response information is used to instruct the terminal device to access the target device; the processing module and the transceiver module are used to communicate with the target device according to a pairwise temporary key PTK; wherein the PTK is the PTK obtained by the interaction between the first device and the terminal device.

[0067] Optionally, the transceiver module and processing module of the communication device in the ninth aspect may also perform the corresponding functions in the fifth aspect or any possible design of the fifth aspect, as detailed in the above method examples, and the beneficial effects that can be achieved can also be found in the foregoing related content.

[0068] In a tenth aspect, this application provides a communication device comprising one or more processors; the one or more processors being configured to run computer programs or instructions, such that when the one or more processors execute the computer instructions or instructions, the communication method described in any one of the first to fifth aspects is performed.

[0069] In one possible design, the communication device further includes one or more memories coupled to one or more processors, the memories used to store the aforementioned computer programs or instructions. In one possible implementation, the memories are located outside the communication device. In another possible implementation, the memories are located inside the communication device. In embodiments of this application, the processor and memory may also be integrated into a single device, i.e., the processor and memory may be integrated together. In one possible implementation, the communication device further includes a transceiver for receiving and / or transmitting information.

[0070] In one possible design, the communication device further includes one or more communication interfaces coupled to one or more processors, and the communication interfaces are used to communicate with other modules outside the communication device.

[0071] In one aspect, this application provides a communication device, which includes an interface circuit and a logic circuit; the interface circuit is used to input and / or output information; the logic circuit is used to perform the communication method as described in any one of the first to fifth aspects, and to process and / or generate information based on the information.

[0072] In a twelfth aspect, this application provides a computer-readable storage medium storing computer instructions or programs that, when executed on a computer, cause the communication method described in any one of the first to fifth aspects to be performed.

[0073] In a thirteenth aspect, this application provides a computer program product containing computer instructions that, when run on a computer, causes the communication method described in any one of the first to fifth aspects to be executed.

[0074] In a fourteenth aspect, this application provides a computer program that, when run on a computer, causes the communication method described in any one of the first to fifth aspects to be executed.

[0075] In a fifteenth aspect, this application provides a chip comprising: a processor coupled to a memory for storing programs or instructions, wherein when the programs or instructions are executed by the processor, a communication method as described in any one of the first to fifth aspects is executed.

[0076] The technical effects of any of the design methods in aspects 10 to 15 can be found in the technical effects of any of the aspects 1 to 5 mentioned above, and will not be elaborated upon further.

[0077] In a sixteenth aspect, this application provides a communication system that may include communication means for performing the communication described in the first aspect or any possible design of the first aspect, communication means for performing the communication described in the second aspect or any possible design of the second aspect, and communication means for performing the communication described in the third aspect or any possible design of the third aspect. Alternatively, it may include communication means for performing the communication described in the second aspect or any possible design of the second aspect, communication means for performing the communication described in the fourth aspect or any possible design of the fourth aspect, and communication means for performing the communication described in the fifth aspect or any possible design of the fifth aspect. Attached Figure Description

[0078] Figure 1 A schematic diagram of a communication system provided in an embodiment of this application;

[0079] Figure 2 A schematic diagram illustrating a roaming method provided in an embodiment of this application;

[0080] Figure 3 A flowchart illustrating a communication method provided in an embodiment of this application;

[0081] Figure 4 A flowchart illustrating another communication method provided in an embodiment of this application;

[0082] Figure 5 A flowchart illustrating yet another communication method provided in an embodiment of this application;

[0083] Figure 6 A schematic diagram of a communication device provided in an embodiment of this application;

[0084] Figure 7 A schematic diagram of a communication device provided in an embodiment of this application;

[0085] Figure 8 This is a structural diagram of a communication device provided in an embodiment of this application. Detailed Implementation

[0086] The technical solutions provided in this application can be applied to fiber-to-the-room (FTTR) system networking scenarios. Furthermore, this application can also be applied to FTTR-based evolution networking scenarios, or networking scenarios similar to FTTR networking scenarios, without limitation.

[0087] like Figure 1As shown in (a), an FTTR system may include a main FTTR unit (MFU) and at least one sub FTTR unit (SFU). The MFU can be connected to one or more SFUs via an optical link (such as optical fiber), and the SFUs can communicate with terminal equipment (STAs) via wireless local area network (WLAN) technology. Optionally, the MFU can also communicate with the STA via WLAN technology, and the MFU can also be connected to an optical line terminal (OLT) via an optical link.

[0088] As one possible implementation, in this embodiment, the SFU and MFU communicate via the WLAN management and control interface (WMCI) / WMCI management channel. The WMCI management channel is a low-latency channel in the FTTR network that enables WLAN control and other functions between the MFU and SFU. It is used to carry WMCI messages and is carried through an independent FEM port-ID.

[0089] As one possible implementation, in the embodiments of this application, the basic service set identifier (BSSID) of the MFU and the SFU are the same, and / or the service set identifier (SSID) is the same.

[0090] As one possible implementation, MFU can also be called the main gateway, and SFU can also be called the sub-gateway.

[0091] As one possible implementation, in large areas or areas with high network quality requirements, multiple FTTR systems can be centrally deployed, providing a unified wireless network access service. In a centralized FTTR deployment scenario, multiple FTTR systems may be deployed within the same subnet. When these multiple FTTR systems are deployed and put into operation, they are logically configured in the OLT to belong to the same subnet, and the configuration can be manual or automatic. For example, ... Figure 1As shown in (b), FTTR system 1 and FTTR system 2 are deployed in the same subnet and are managed by OLT1. FTTR system 1 includes MFU1, SFU1.1 and SFU1.2. MFU1 is connected to SFU1.1 and SFU1.2 via optical fibers and is connected to OLT1. FTTR system 2 includes MFU2, SFU2.1 and SFU2.2. MFU2 is connected to SFU2.1 and SFU2.2 via optical fibers and is connected to OLT1.

[0092] As one possible implementation, the embodiments of this application can be applied to roaming scenarios in FTTR-related networks.

[0093] When a terminal device moves within an FTTR network, the channel quality with its currently associated SFU deteriorates, necessitating roaming to an SFU with better channel quality to ensure service continuity. However, during roaming, the terminal needs to re-establish a connection on the new SFU, leading to service interruption. To ensure timely and continuous roaming, a cooperative roaming control scheme using WMCI is employed.

[0094] The WMCI-based collaborative roaming solution mainly includes three aspects: roaming configuration information synchronization, network information synchronization, terminal online processing, and terminal roaming processing.

[0095] Roaming network configuration is triggered when SFU goes online, WMCI roaming is enabled or disabled, and network parameters are configured.

[0096] When an SFU is launched and initialized, the MFU will check whether the network's cooperative roaming function is enabled. If the network's cooperative roaming function is enabled, the MFU will check whether the SFU meets the enabling conditions based on the SFU's roaming capability information. If it does, the roaming configuration of the newly launched SFU will be enabled. If the SFU does not meet the enabling conditions, the roaming configuration will not be enabled. If the network's cooperative roaming function is not enabled, no cooperative roaming configuration will be performed.

[0097] After network deployment is complete, the cooperative roaming function can be enabled or disabled. When enabling cooperative roaming, the MFU should first determine if the enabling conditions are met. If they are met, a roaming configuration command should be issued to all SFUs. If the conditions are not met, no roaming configuration should be performed. When disabling cooperative roaming, the MFU should restore the network's normal configuration and disable the roaming feature.

[0098] The process of enabling / disabling the collaborative roaming feature includes the following steps:

[0099] (1) The MFU sends roaming configuration information to the SFU via roaming configuration messages;

[0100] (2) After receiving the configuration message, the SFU completes the relevant parameter configuration and sends back a roaming configuration confirmation message;

[0101] (3) After receiving the roaming configuration confirmation message from the SFU, the MFU sends a roaming enable or disable message to the SFU.

[0102] (4) After the SFU is turned on or off, a confirmation message is sent to the MFU to confirm whether the roaming is turned on or off.

[0103] After cooperative roaming is enabled, periodic synchronization of network information is required. This includes the synchronized transmission of beacon frames. There are two main synchronization methods: one is that the MFU controls the synchronization time and sends network synchronization information to the SFUs within the network at the specified synchronization time; the other is that all SFUs report synchronization information, and then the MFU summarizes the information and sends out the network information for synchronization.

[0104] When a terminal device goes online, its association information and key information need to be synchronized across the entire network to enable roaming functionality. When a terminal device goes offline, the associated SFU sends an offline event to the MFU. Upon receiving the offline event, the MFU sends instructions to all SFUs and MFUs across the network to delete the terminal information. After receiving the deletion instructions from the MFU, the SFU deletes the terminal information and reports a successful deletion to the MFU, which then deletes the terminal-related information.

[0105] As one possible implementation, the terminal device in this application embodiment can be a device that supports relevant standards of the Institute of Electrical and Electronics Engineers (IEEE), and can achieve communication connection with the SFU based on WLAN technology, such as sending physical frames to the SFU based on radio frequency analog signals (or wireless signals, wireless radio frequency analog signals, wireless analog signals, etc.).

[0106] The relevant IEEE standards can include: 802.11a / b / g, 802.11n, 802.11ac, 802.11ax, 802.11be, 802.11bn (Ultra High Reliability, UHR) / Wi-Fi 8, 802.11ad, 802.11ay, 802.11bf (sensing), Ultra Wide Bandwidth (UWB), and 802.15, etc., without restriction. Regarding bandwidth configuration, channel bundling was introduced starting with 802.11n, allowing multiple 20MHz channels to be bundled together to achieve greater bandwidth and higher transmission rates. Starting with 802.11ac, a maximum bandwidth of 160MHz can be provided. The 802.11ax standard supports the following bandwidth configurations: 20MHz, 40MHz, 80MHz, 160MHz, and 80+80MHz. The 802.11be standard also supports a 320MHz bandwidth configuration.

[0107] For example, the terminal device can be a wireless communication chip, a wireless sensor (such as a temperature and humidity sensor), a wireless communication terminal, a communication server, a router, a switch, a bridge, a computer, etc. For instance, the terminal device can be a mobile phone supporting Wi-Fi communication, a tablet computer supporting Wi-Fi communication, a set-top box supporting Wi-Fi communication, a smart home appliance supporting Wi-Fi communication, a smart wearable device supporting Wi-Fi communication, an in-vehicle communication device supporting Wi-Fi communication, a computer supporting Wi-Fi communication, a camera supporting Wi-Fi communication, a robot supporting Wi-Fi communication, office equipment supporting Wi-Fi communication, etc., without limitation.

[0108] As one possible implementation, the SFU in this embodiment can be a device supporting relevant IEEE standards, capable of communicating with terminal devices based on WLAN technology, and also communicating with the MFU via an optical link. That is, when the SFU and MFU communicate, digital signals can be converted into optical signals for transmission. This optical signal can be understood as a form of signal transmission between the SFU and MFU, and the transmission of the optical signal converted from the digital signal between the SFU and MFU can also be understood as the transmission of digital signals via optical signals between the SFU and MFU. For example, the SFU can send an optical signal converted from the uplink digital signal to the MFU through the uplink transmission channel of the optical link, and receive an optical signal converted from the downlink digital signal sent by the MFU through the downlink transmission channel of the optical link.

[0109] The SFU (Streaming Unit) may include one or more antennas. The SFU can convert the digital signals from the antennas into optical signals and transmit them to the MFU (Medium-Level Unit) via the uplink transmission channel of the optical link. Alternatively, the SFU can receive optical signals converted from downlink digital signals transmitted by the MFU via the downlink transmission channel of the optical link, using one or more antennas. Taking uplink transmission as an example, the SFU can collect the wireless signals transmitted by the terminal device according to the uplink bandwidth indicated by the MFU, obtain digital signals, and transmit the optical signals converted from the uplink digital signals to the MFU via the uplink transmission channel of the optical link, according to the uplink bandwidth indicated by the MFU.

[0110] As one possible implementation, the MFU in this embodiment can be a device supporting relevant IEEE standards, and can establish a communication connection with the SFU via an optical link. For example, the MFU can receive optical signals converted from uplink digital signals sent by the SFU through the uplink transmission channel of the optical link, and send optical signals converted from downlink digital signals to the SFU through the downlink transmission channel of the optical link. The MFU can also indicate the uplink bandwidth to the SFU, instructing the SFU to perform uplink transmission according to the uplink bandwidth. The MFU can also determine the baseband signal based on the acquired uplink digital signal, perform physical layer demodulation on the baseband signal, and obtain the physical frame sent by the terminal device.

[0111] For example, an MFU can be a terminal device with a Wi-Fi chip, network device, communication server, router, switch, bridge, computer, etc. An MFU can also serve as an access point for mobile users to access a wired network, primarily deployed in homes, buildings, and campuses, with a typical coverage radius of tens to hundreds of meters. Of course, it can also be deployed outdoors. An MFU acts as a bridge connecting wired and wireless networks, its main function being to connect various wireless network clients together and then connect the wireless network to the Ethernet.

[0112] In the FTTR networking scenario described above, when the SFU communicates with the terminal device, it needs to go through three stages: scan, authentication, and association before data transmission can take place.

[0113] The scanning phase can include both active and passive scanning methods. In active scanning, the terminal device sequentially sends probe request frames on each channel to search for Service Functions (SFUs). In passive scanning, the terminal device passively waits for beacon frames periodically sent by the SFUs. These beacon frames provide information about the SFU and its associated basic service set (BSS). The scanning phase completes the scanning of the SFU list, and then selects one SFU from this list to proceed to the authentication phase.

[0114] During the authentication phase, the terminal device can send an authentication request to the SFU, and the SFU responds with an authentication response, completing the link authentication. Only terminal devices that pass authentication can access the wireless network. Common authentication methods include Open System Authentication (OSA), Shared-Key Authentication (SCAS), Wi-Fi Protected Access (WPA) PSK (Pre-Shared Key) authentication, and 802.1X (Extensible Authentication Protocol, EAP) authentication. Once the SFU returns authentication response information to the terminal device, and authentication is successful, the distribution system can record the location of each terminal device.

[0115] During the association phase, the terminal device sends an association request to the SFU, and the SFU returns an association response to the terminal device. At this point, the access process is complete, the terminal device is initialized, and it can begin transmitting data frames to the SFU.

[0116] When the network is in encrypted mode, the SFU and the terminal device also need to perform a four-way handshake using the Extended Authentication Protocol over LAN (EAPoL) for access authentication. The four-way handshake process between the SFU and the terminal device allows for the secure negotiation and exchange of pairwise transient keys (PTKs). After the four-way handshake is complete, subsequent frame propagation can be performed in an encrypted manner.

[0117] As shown above, the access process between the SFU and the terminal device involves many steps and is time-consuming. In cases of packet loss and retransmission, the extended access time is noticeably apparent. Figure 2 As shown, when a terminal device roams from one SFU to another SFU in the same network, it needs to re-execute the above access process (including scanning, authentication, association, and four-way handshake), which makes the access process cumbersome, time-consuming, and affects communication performance.

[0118] To address the aforementioned technical problems, this application provides a communication method. In this method, when the network uplink and downlink encryption functions are enabled, a first device sends first information to a main access device. The first information includes an encrypted PTK, which is obtained through interaction between the first device and a terminal device. Based on the first information, the main access device sends second information to one or more second devices associated with the main access device. The second information includes the encrypted PTK. The second devices are other FTTR devices associated with the main access device besides the first device.

[0119] In this embodiment, the primary access device can obtain the PTK (Platform Target Key) exchanged between the first device and the terminal device, and synchronize it with other FTTR devices (i.e., the second device) associated with the primary access device, excluding the first device. This achieves network-wide PTK synchronization. When the terminal device roams from the first device to the second device, since the second device has already obtained the PTK corresponding to the terminal device during the synchronization process, there is no need to re-scan, authenticate, associate, or perform a four-way handshake. This reduces the complexity of the access process, shortens the access time, and improves communication performance. Furthermore, the aforementioned PTK synchronization process is performed with network-wide uplink and downlink encryption enabled, which enhances communication security.

[0120] The following is combined Figure 1 The communication system shown refers to the following Figure 3 The communication method provided in the embodiments of this application is described below, wherein the first device can be Figure 1 In any SFU of the communication system shown, the main access device can be Figure 1 In any MFU of the communication system shown, the second device can be Figure 1 In the communication system shown, for any SFU other than the first device, the terminal device can be... Figure 1 Any terminal device in the communication system shown.

[0121] It is understood that the processing performed by a single execution entity (first device, main access device, second device, or terminal device) shown in the embodiments of this application can also be divided into multiple execution entities, which can be logically and / or physically separated, without limitation. Furthermore, the message names or parameter names in the messages exchanged between devices in the embodiments of this application are merely examples; other names can be used in specific implementations without limitation. Actions, terms, etc., involved in the various embodiments of this application can be referenced mutually without limitation.

[0122] Figure 3 A flowchart of a communication method provided in an embodiment of this application is shown below. Figure 3 As shown, the method may include:

[0123] Step 301: The first device acquires PTK.

[0124] The PTK can be the PTK obtained through the interaction between the first device and the terminal device.

[0125] In this process, the first device and the terminal device can obtain the PTK (Personal Technology Key) exchanged between them after scanning, authentication, association, and a four-way handshake. A detailed description of the scanning, authentication, association, and four-way handshake processes can be found below. Figure 5 The relevant descriptions are not elaborated here.

[0126] Step 302: With the network uplink and downlink encryption functions enabled, the first device sends the first information to the main access device; correspondingly, the main access device receives the first information from the first device.

[0127] The first information includes the encrypted PTK. For example, the first device can encrypt the PTK based on an encryption mechanism to obtain the first information.

[0128] For example, the encryption mechanism could be a link-layer encryption mechanism.

[0129] For example, the encryption mechanism can also be any of the following: encryption algorithms supported by the FTTR system (such as SM4), AES algorithm, etc., or any other mechanism that can be used for encryption, without limitation.

[0130] Optionally, the first information may also include one or more of the following: the virtual AP identifier in the first device, the media access control (MAC) address of the terminal device, the frame type, the frame content, the frame length, or the key length.

[0131] For example, as shown in Table 1 below, the parameters included in the second information are described in detail:

[0132] Table 1

[0133]

[0134]

[0135] Optionally, the aforementioned first information can also be referred to as a terminal connection information reporting message.

[0136] Optionally, the primary access device can determine the first state of the network-wide uplink and downlink encryption function. This first state can be either enabled or disabled. If the first state is disabled, the network-wide uplink and downlink encryption function is enabled.

[0137] Among them, the main access device can enable the entire network uplink and downlink encryption function according to the link layer specifications.

[0138] Optionally, the primary access device may also send a fourth message to the first device upon successfully receiving the first message, the fourth message being used to indicate that the first message has been received.

[0139] For example, the fourth message may be an acknowledgment (ACK) frame, or it may be described as a received acknowledgment frame.

[0140] Step 303: The primary access device sends second information to one or more secondary devices associated with the primary access device according to the first information; correspondingly, one or more secondary devices receive the second information from the primary access device.

[0141] The second information may include the encrypted PTK. The second device is any FTTR device other than the first device among the FTTR devices associated with the primary access device.

[0142] The main access device can decrypt the first information to obtain PTK, and encrypt PTK based on the encryption mechanism to obtain the second information.

[0143] Optionally, the second information may also include one or more of the following: the virtual AP identifier in the second device, the MAC address of the terminal device, the frame type, the identification information of the terminal device, the frame content, the frame length, or the key length.

[0144] For example, as shown in Table 2 below, the parameters included in the second information are described in detail:

[0145] Table 2

[0146]

[0147] Optionally, the second piece of information mentioned above can also be referred to as the virtual user creation message.

[0148] Optionally, the primary access device can send second information to all its associated secondary devices to achieve PTK network-wide synchronization and improve communication performance.

[0149] When the second device receives the second information, it can decrypt the second information (e.g., decrypt it based on an encryption mechanism) to obtain PTK.

[0150] Based on the above Figure 3The method shown allows the primary access device to obtain the PTK (Personal Key) exchanged between the first device and the terminal device, and synchronize it with all other FTTR devices (i.e., the second device) associated with the primary access device, excluding the first device. This achieves network-wide PTK synchronization. When a terminal device roams from the first device to the second device, since the second device has already obtained the corresponding PTK during the synchronization process, there is no need to re-scan, authenticate, associate, or perform a four-way handshake. This reduces the complexity of the access process, shortens access time, and improves communication performance. Furthermore, the aforementioned PTK synchronization process is performed with network-wide uplink and downlink encryption enabled, which enhances communication security.

[0151] Based on the above Figure 3 Optionally, in the method shown, each second device may send a third message to the main access device upon successfully decrypting the PTK (or, as described, successfully receiving the second information), indicating that the PTK has been received.

[0152] If the primary access device does not receive the third information from one or more secondary devices, the primary access device can resend the second information, for example, it can resend the second information to the secondary devices that have not received the third information.

[0153] Optionally, if the first state is not enabled, the main access device may disable the entire network uplink and downlink encryption function if the main access device receives the third information sent by all the second devices.

[0154] Based on the above description, for example, taking the main access device as MFU, the first device as SFU1, the second device as SFU2, and the terminal device as STA, the interaction between MFU, SFU1, SFU2, and STA can be as follows. Figure 4 The steps are shown in the image:

[0155] Step 401: MFU can determine whether the entire network uplink and downlink encryption function is enabled to determine the first state. If the first state is disabled, then the entire network uplink and downlink encryption function is enabled.

[0156] Step 402: After scanning, authentication, association, and four-way handshake, SFU1 and STA can obtain the PTK exchanged between SFU1 and STA, encrypt the PTK based on the encryption mechanism, obtain the first information, and report it to MFU.

[0157] Step 403: After receiving the first message, the MFU can send an ACK to the SFU1.

[0158] Step 404: MFU can also send second information to SFU2 based on the received first information to perform PTK synchronization.

[0159] Step 405: SFU2 can send an ACK to MFU after receiving the second information.

[0160] Step 406: After receiving the ACK from SFU2, MFU can determine whether to disable the entire network uplink and downlink encryption function based on the first state. If the first state is disabled, the entire network uplink and downlink encryption function is disabled; if the first state is enabled, no action is taken.

[0161] Furthermore, based on the PTK network-wide synchronization process described above, when a terminal device roams from the first device to the second device, the terminal device can send a first association request message to the second device to request access to the second device. Since the terminal device has already established a connection with the first device, the second device can determine that the terminal device has already accessed the network corresponding to the second device, and can then send a first association response message to the terminal device; the first association response message is used to instruct the terminal device to access the second device. Subsequently, the second device can communicate with the terminal device based on the PTK obtained during the PTK synchronization process.

[0162] Based on the above description, taking the main access device as MFU, the first device as SFU1, the second device as SFU2, and the terminal device as STA as an example, refer to the following... Figure 5 The document provides a detailed description of the scanning, authentication, association, four-way handshake, and PTK network-wide synchronization process between SFU and STA.

[0163] Step a: When the SFU receives the probe request frame sent by the STA, it sends the received probe request frame and the received signal strength indication (RSSI) to the MFU through the terminal probe authentication reporting message.

[0164] Step b: After receiving terminal probe authentication reporting messages from all SFUs, the MFU can decide whether the SFUs need to reply with a probe response frame, and select one SFU to reply to the STA. The MFU then instructs the SFU to reply or not to reply with a probe response via a terminal probe authentication response indication message. The selected SFU can be the one with the strongest RSSI.

[0165] Step c: When the SFU receives the authentication request frame sent by the STA, it sends the authentication request frame and the RSSI strength of the received message to the MFU through the terminal detection authentication reporting message.

[0166] Step d: After receiving the authentication request frames from all SFUs, the MFU can select one SFU to reply with an authentication response to continue associating with the STA. This SFU can be the one with the strongest signal or the one with the best signal and the fewest connected STAs. The MFU selects an idle AID in the network and assigns it to this STA. At the same time, it sends a terminal online indication message to instruct the other SFUs to close their communication channels with the STA and not respond to the STA.

[0167] In addition, with generational evolution, the MFU can also determine the capability information of the STA and select the AID based on the STA's capability information. For example, when the AID range specified by the communication standard increases, a suitable AID value can be selected based on the capabilities of the access STA.

[0168] Step e: The MFU distributes the AID and Auth to other SFUs to create virtual users.

[0169] For example, an MFU can send the AID and Auth request to other SFUs via an endpoint online instruction message.

[0170] Step f: After the selected SFU (e.g., SFU1) is successfully associated with the STA, it obtains the STA association / reassoc request (assoc / reassoc req) frame and key information, and then sends them to the MFU in an encrypted manner.

[0171] The key is the aforementioned PTK, and the key information encrypted using the encryption mechanism is the aforementioned first information. When the selected SFU reports the key information and the association / reassociation request frame to the MFU, it can report the association / reassociation request frame to the MFU by including it in the frame content of the first information.

[0172] The SFU can encrypt the PTK using the key between the MFU and the SFU, and then send the association / reassociation request frame and the encrypted unicast key information to the MFU. This encrypted unicast key signal is the encrypted PTK.

[0173] Step g: After receiving the assoc / reassoc req frame and key information reported by the real associated SFU, the MFU encrypts the key and synchronizes it along with the assoc / reassoc req frame to other SFUs (such as SFU2) in the network.

[0174] Among them, the key information reported by the SFU that the MFU receives from the real associated SFU can be encrypted key information, that is, encrypted PTK.

[0175] For example, the MFU can receive assoc / reassoc req frames and encrypted key information (i.e., encrypted PTK) reported by the real associated SFU through the terminal connection information reporting message.

[0176] When the MFU receives the assoc / reassoc req frame and encrypted key information reported by the real associated SFU, it can first use the key between the MFU and the SFU to decrypt the encrypted PTK, and then use the key between the MFU and each SFU to encrypt the PTK, and then synchronize it with other SFUs (such as SFU2) in the network along with the assoc / reassoc req frame.

[0177] Specifically, the MFU can synchronize the assoc / reassoc req frame, which includes the encrypted key information, to other SFUs across the network within the frame content of the second information mentioned above. Alternatively, it can be described as follows: the MFU synchronizes the encrypted PTK along with the assoc / reassoc req frame to other SFUs across the network by creating a virtual user message.

[0178] In step h, after receiving the sent assoc / reassoc and encrypted key information, other SFUs obtain the key information and create a virtual user for the terminal. Upon successful virtual user creation, the creation result is reported back to the MFU; if SFU2 fails to create the user, a creation failure message is reported to the MFU.

[0179] The encrypted key information is the encrypted PTK.

[0180] Once other SFUs receive the sent assoc / reassoc and encrypted key information, they can use the key between this SFU and the MFU to decrypt the encrypted PTK, and create a terminal virtual user using the association / reassociation request frame and the decrypted PTK. When the STA subsequently roams to other SFUs, the other SFUs can send encrypted unicast messages of the PTK synchronized by the MFU to the STA.

[0181] In addition, SFU1 and SFU2 can also send a terminal online reporting message to MFU after the STA is successfully online, informing the STA of its online status.

[0182] Step i: After receiving the creation failure message, the MFU recreates the user information. If creation continues to fail, the user is kicked out (e.g., a user kick message is sent to the terminal device).

[0183] Specifically, the operation of recreating user information after receiving a creation failure message can be: MFU executes step g.

[0184] The MFU and SFU can transmit the aforementioned unicast key via data link layer encryption. In this case, the SFU can encrypt the PTK using data link layer encryption and then send the encrypted PTK to the MFU.

[0185] Specifically, the process of synchronizing the data link layer (DLL) keys between the MFU and SFU can be described in the following description:

[0186] The key exchange is initiated by the MFU. The MFU sends a key request message in the Physical Layer Operation, Administration, and Maintenance (PLOAM) channel, and the SFU responds by generating, storing, and sending a key. The SFU stores the new key in the shadow key register. The key generated by the SFU should be difficult to guess. Due to the finite length of PLOAM messages, the key is sent in two fragments, using a fragmentation field to indicate which part of the key is being sent. To ensure redundancy, each part of the key is sent three times. All SFUs use the same key index (Key_Index) value when sending a specific key, so the MFU can confirm that all transmissions use the same key. The Key_Index is incremented when the SFU generates a key based on the MFU's request.

[0187] If the MFU fails to receive any part of the key three times, it will send a new key_request message to the SFU to generate another key. If the key transmission fails three times, the MFU will declare LOKi (key synchronization lost) and deactivate the SFU.

[0188] Once the MFU successfully receives the key, the valid key will be stored in its shadow_key_register, and the system will prepare for key switching. The MFU selects a future frame number as the first frame using the new key and transmits the multiframe number of that frame to the SFU via a key switching time message. The key switching time message will be sent three times, and the SFU only needs to receive one correct copy to know the key switching time.

[0189] In addition, similar to the roaming of a terminal device from a first device to a second device described above, a terminal device may also roam from a first device to a main access device. In this case, the main access device can communicate with the terminal device based on the PTK in the first information.

[0190] When a terminal device roams from an associated first device to a primary access device, it can send a second association request to the primary access device to request access. Since the terminal device has already established a connection with the first device, the primary access device can determine that the terminal device has already accessed its network and can then send a second association response to the terminal device. This second association response instructs the terminal device to access the primary access device. The primary access device can then communicate with the terminal device based on the PTK determined by the first information.

[0191] In one possible implementation, in this embodiment of the application, the information exchanged between the first device or the second device and the main access device (i.e., MFU and SFU) can be transmitted through the WLAN management and control interface (WMCI). For example, the format of the WMCI message is shown in Table 3.

[0192] Table 3

[0193]

[0194] As one possible implementation, the Message Type ID is an 8-bit field used to indicate the type of message and define the semantics of the message content. When the MFU receives an uplink message with an unsupported message type ID, it should ignore the message. Similarly, when the SFU receives a message with a reserved or unsupported message type ID, it should ignore the message.

[0195] As one possible implementation, SeqNo is an 8-bit field containing a sequence number counter to ensure the robustness of the WMCI message channel. In the downlink direction, the SeqNo field is filled with the corresponding MFU sequence number counter value. The MFU maintains a separate sequence number counter for each SFU unicast and broadcast WMCI message stream. Each sequence number counter rolls from 255 to 1. A value of 0 is not used in the downlink direction. In the uplink direction, when an uplink WMCI message is a response to a downlink message, the value of the SeqNo field is equal to the value of the SeqNo field in the downlink message. If the WMCI message is initiated by the SFU, then SeqNo = 0 is used.

[0196] As one possible implementation, the message length and processing requirements are a 2-byte field consisting of three fields: message priority, operation type, and message content length.

[0197] X (the most significant bit of the third byte): Indicates the priority of processing this message. When X=1, it indicates that the message has a high priority; when X=0, it indicates that the message has a low priority.

[0198] C: Used to indicate the operation type of the current message.

[0199] In the downlink direction, when C=1, it indicates that the operation type of the message is a parameter request type, requesting the SFU to send the output indicated by the Message type ID field; when C=0, it indicates that the message is a parameter configuration type message, and the parameter type configured in the message is indicated by the Messagetype ID field.

[0200] In the uplink direction, when C=1, the message indicates that the operation type is a scheduling request, requesting the MFU to send the scheduling configuration indicated by the Message type ID field; when C=0, the message indicates that it is a parameter reporting message or an alarm message, with the Message type ID field indicating the type of parameters or alarms reported. (Response)

[0201] LL LLLL LLLL: This field indicates the length of the message content. The value range is 0 to 1023.

[0202] As one possible implementation, the format of the message content field is related to the specific message, and the message content includes two parts: the message mask and the parameter content.

[0203] The message content field may include the fields from Tables 1 and 2 above. Each field from Table 1 or Table 2 can be added to the message content field as needed.

[0204] The message mask consists of a 16-bit mask, as shown in Table 4. For example, when a bit in the message mask is set to a specific value (such as 1 or 0), it indicates that the content parameters carry (or contain) the parameter corresponding to that mask; when set to a non-specific value, it indicates that the content parameters do not carry (or do not contain) the parameter corresponding to that mask.

[0205] Table 4

[0206]

[0207]

[0208] Each message type can carry a maximum of 16 parameters. The message content should be filled in the order indicated by the parameter mask. For downlink request messages, the parameter mask represents the parameters the MFU wants to obtain. For uplink messages, the parameter mask represents the parameters being reported and replied to.

[0209] As one possible implementation, the integrity check field can also be replaced with a message check field to verify whether the message has been corrupted during transmission. For example, the value of this field is generated by a cyclic redundancy check (CRC) algorithm.

[0210] As one possible implementation, WMCI messages are encapsulated in FEM frames for managing and controlling the WLAN functions of the SFU. The FTTR transceiver can identify the destination of the WMCI message using the FEM port ID in the FEM frame.

[0211] It should be noted that the various embodiments of this application can be implemented independently or in combination, without limitation. Unless otherwise specified or in conflict, the terminology and / or descriptions between the different embodiments provided in this application are consistent and can be referenced mutually. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0212] It is understood that in the embodiments of this application, the executing entity may perform some or all of the steps in the embodiments of this application. These steps or operations are merely examples, and the embodiments of this application may also perform other operations or variations thereof. Furthermore, the various steps may be executed in different orders as presented in the embodiments of this application, and it is not necessarily necessary to execute all the operations in the embodiments of this application.

[0213] The following is an exemplary description of the message formats involved in the embodiments of this application. Referring to Table 5, these are terminal online / offline indication and reporting messages. The parameters corresponding to each terminal online / offline indication and reporting message are different, indicated by a mask. Specifically, the terminal detection and authentication reporting messages sent by SFU1 / 2 contain sequence numbers 2-4 and 7-9; the terminal connection information reporting messages sent by SFU1 contain sequence numbers 2-4 and 8-11; the terminal online / offline reporting messages sent by SFU1 / 2 contain sequence numbers 2-3 and 12; the terminal detection and authentication reply indication messages sent by MFU contain sequence numbers 2-3 and 5; the terminal online indication messages sent by MFU contain sequence numbers 2-3, 6, 12, and 8-9; the virtual user creation messages sent by MFU contain sequence numbers 2-4, 6, and 8-11; and the terminal deletion messages sent by MFU contain sequence numbers 2-3. Table 5 is only an example; the message types or message states corresponding to different values ​​can be configured according to requirements, and this embodiment of the application does not limit this.

[0214] Table 5

[0215]

[0216]

[0217] In addition to the unicast key PTK, the Key field can also include an encryption mode, such as wired equivalent privacy (WEP), temporary key integrity protocol (TKIP), advanced encryption standard (AES), or (TKIP and AES) encryption modes.

[0218] In another possible implementation, the above communication method also includes:

[0219] MFU can instruct SFU (SFU1 or SFU2) to disable multicast key updates in a cooperative roaming enable message or other messages;

[0220] During the multicast key update cycle, the MFU updates the multicast key and then encrypts the updated multicast key GTK before distributing it to all SFUs within the network. The MFU uses the key it shares with the SFUs to encrypt the multicast key information to be sent to each SFU. The MFU and SFUs can use multicast key synchronization (update) messages to update the multicast key GTK.

[0221] After receiving the latest encrypted multicast key GTK from the MFU, the SFU decrypts the multicast key using the key it shares with the MFU, and then updates the multicast key information. All STAs associated with the SFU then update the multicast key, and each SFU uses the updated multicast key GTK to send broadcast and multicast messages to its associated STAs.

[0222] In this implementation, the MFU controls the multicast key update in the FTTR network. The multicast keys between the MFU and SFU remain consistent, which avoids the STA being unable to receive or send data due to different multicast keys after roaming to different access points, thus improving the efficiency of STA roaming.

[0223] See Table 6 below. Table 6 shows the structure of the multicast key synchronization message. GTK in serial number 3 is the multicast key GTK mentioned above.

[0224] Table 6

[0225]

[0226] For the first multicast key GTK1, the first multicast key GTK1 may include one or more parameters among GTK, Counter, and / or Gnonce.

[0227] The foregoing primarily describes the solutions provided in this application from the perspective of device-to-device interaction. It is understood that each device, in order to achieve the aforementioned functions, includes corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should readily recognize that, based on the algorithm steps of the examples described in conjunction with the embodiments disclosed herein, this application can be implemented in hardware or a combination of hardware and computer software. Whether a function is executed in hardware or by computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0228] This application embodiment can divide each device into functional modules according to the above method example. For example, each function can be divided into a separate functional module, or two or more functions can be integrated into one processing module. The integrated module can be implemented in hardware or as a software functional module. It should be noted that the module division in this application embodiment is illustrative and only represents one logical functional division. In actual implementation, there may be other division methods.

[0229] When dividing each function into modules according to its corresponding function. Figure 6 A communication device 60 is shown, which can perform the above-described... Figures 3 to 5 The actions performed by the first device, main access device, second device, or terminal device in the method shown, and all related content of each step involved in the above method embodiments can be referenced from the functional description of the corresponding functional module. The technical effects that can be obtained can be referred to the above method embodiments, and will not be repeated here.

[0230] The communication device 60 may include a transceiver module 601 and a processing module 602. Exemplarily, the communication device 60 may be a communication equipment, or a chip or other combination device or component having the aforementioned communication device functions. When the communication device 60 is a communication equipment, the transceiver module 601 may be a transceiver, which may include an antenna and radio frequency circuits; the processing module 602 may be a processor (or processing circuit), such as a baseband processor, which may include one or more CPUs. When the communication device 60 is a component having the aforementioned communication device functions, the transceiver module 601 may be a radio frequency unit; the processing module 602 may be a processor (or processing circuit), such as a baseband processor. When the communication device 60 is a chip system, the transceiver module 601 may be an input / output interface of a chip (e.g., a baseband chip); the processing module 602 may be a processor (or processing circuit) of the chip system, and may include one or more central processing units. It should be understood that the transceiver module 601 in the embodiments of this application can be implemented by a transceiver or transceiver-related circuit components; the processing module 602 can be implemented by a processor or processor-related circuit components (or, referred to as processing circuit).

[0231] For example, the transceiver module 601 can be used to perform... Figures 3 to 5 In the illustrated embodiment, all transmit and receive operations performed by the communication device, and / or other processes used to support the techniques described herein; the processing module 602 can be used to perform Figures 3 to 5 The embodiments shown include all operations performed by the communication device other than the transmit and receive operations, and / or other processes used to support the techniques described herein.

[0232] As another feasible approach Figure 6 The transceiver module 601 can be replaced by a transceiver unit, which can integrate the functions of the transceiver module 601; the processing module 602 can be replaced by a processor, which can integrate the functions of the processing module 602. Furthermore, Figure 6 The communication device 60 shown may also include a memory.

[0233] Alternatively, when the processing module 602 is replaced by a processor and the transceiver module 601 is replaced by a transceiver, the communication device 60 involved in the embodiments of this application can also be... Figure 7 The communication device 70 shown. The processor can be logic circuit 701, and the transceiver can be interface circuit 702. Further, Figure 7 The communication device 70 shown may also include a memory 703.

[0234] This application also provides a communication device 800, such as... Figure 8 As shown, the communication device 800 can be the above-mentioned Figures 3 to 5 The method shown can be the first device or the chip or system-on-a-chip in the first device; or it can be the above. Figures 3 to 5 The method shown may refer to the main access device or the chip or system-on-a-chip in the main access device; or it may be the above-mentioned Figures 3 to 5 The second device or the chip or system-on-a-chip in the second device in the method shown can also be the one described above. Figures 3 to 5 The terminal device or the chip or system-on-a-chip in the terminal device shown in the method. For example... Figure 8 As shown, the communication device 800 includes a processor 801, a transceiver 802, and a communication line 803.

[0235] Furthermore, the communication device 800 may also include a memory 804. The processor 801, memory 804, and transceiver 802 can be connected via a communication line 803.

[0236] The processor 801 can be a central processing unit (CPU), a general-purpose processor, a network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller, a programmable logic device (PLD), or any combination thereof. The processor 801 can also be other devices with processing capabilities, such as circuits, devices, or software modules, without limitation.

[0237] Transceiver 802 is used to communicate with other devices or other communication networks. These other communication networks can be Ethernet, radio access network (RAN), wireless local area networks (WLAN), etc. Transceiver 802 can be a module, circuit, transceiver, or any device capable of enabling communication.

[0238] Communication line 803 is used to transmit information between the components included in communication device 800.

[0239] The memory 804 is used to store instructions. These instructions can be computer programs.

[0240] The memory 804 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions; it can also be a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions; it can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, etc., without limitation.

[0241] It should be noted that the memory 804 can exist independently of the processor 801, or it can be integrated with the processor 801. The memory 804 can be used to store instructions, program code, or some data, etc. The memory 804 can be located inside or outside the communication device 800, without limitation. The processor 801 is used to execute the instructions stored in the memory 804 to implement the communication method provided in the following embodiments of this application.

[0242] In one example, processor 801 may include one or more CPUs, for example Figure 8 CPU0 and CPU1 in the CPU.

[0243] As an optional implementation, the communication device 800 includes multiple processors, for example, besides Figure 8 In addition to processor 801, it may also include processor 807.

[0244] As an optional implementation, the communication device 800 also includes an output device 805 and an input device 806. For example, the input device 806 is a device such as a keyboard, mouse, microphone, or joystick, and the output device 805 is a device such as a display screen or speaker.

[0245] It should be noted that the communication device 800 can be a desktop computer, laptop computer, network server, mobile phone, tablet computer, wireless terminal, embedded device, chip system, or something else. Figure 8 Equipment with a similar structure. Furthermore... Figure 8 The structural composition shown does not constitute a limitation on the communication device, except... Figure 8 In addition to the components shown, the communication device may include more or fewer components than illustrated, or combine certain components, or have different component arrangements.

[0246] In this embodiment of the application, the chip system may be composed of chips or may include chips and other discrete devices.

[0247] This application also provides a computer program product that, when executed by a computer, can implement the functions of any of the above method embodiments.

[0248] This application also provides a computer program that, when executed by a computer, can implement the functions of any of the above method embodiments.

[0249] This application also provides a computer-readable storage medium. All or part of the processes in the above method embodiments can be implemented by a computer program instructing related hardware. This program can be stored in the computer-readable storage medium, and when executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be an internal storage unit of the terminal (including a data sending end and / or a data receiving end) of any of the foregoing embodiments, such as the terminal's hard disk or memory. The computer-readable storage medium can also be an external storage device of the terminal, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the terminal. Further, the computer-readable storage medium can include both the terminal's internal storage unit and external storage devices. The computer-readable storage medium is used to store the computer program and other programs and data required by the terminal. The computer-readable storage medium can also be used to temporarily store data that has been output or will be output.

[0250] It should be noted that the terms "first" and "second," etc., in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific order. "First" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Therefore, a feature defined with "first" and "second" may explicitly or implicitly include one or more of that feature. In the description of this embodiment, unless otherwise stated, "a plurality of" means two or more.

[0251] Furthermore, the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or apparatus that includes a series of steps or units is not limited to the steps or units listed, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to such process, method, product, or apparatus.

[0252] It should be understood that in this application, "at least one (item)" means one or more. "More than one" means two or more. "At least two (items)" means two or three or more. "And / or" is used to describe the relationship between related objects, indicating that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist simultaneously, where A and B can be singular or plural. The character " / " generally indicates that the related objects before and after are in an "or" relationship. "At least one (item) of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple. Both "...when" and "if" indicate that a corresponding action will be taken under certain objective circumstances. They are not time limits, nor do they require a judgment action to be taken when the action is taken, nor do they imply any other limitations.

[0253] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner to facilitate understanding.

[0254] In this application, "sending information to...(terminal device)" can be understood as the destination of the information being the terminal device. This can include sending information directly or indirectly to the terminal device. "Receiving information from...(terminal device)" can be understood as the source of the information being the terminal device, and can include receiving information directly or indirectly from the terminal device. Information may undergo necessary processing between the source and destination, such as format changes, but the destination can understand the valid information from the source.

[0255] Through the above description of the embodiments, those skilled in the art can clearly understand that, for the sake of convenience and brevity, only the division of the above functional modules is used as an example. In actual applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the device can be divided into different functional modules to complete all or part of the functions described above.

[0256] In the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules or units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another device, or some features may be ignored or not executed. Furthermore, the mutual coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0257] The units described as separate components may or may not be physically separate. A component shown as a unit can be one or more physical units; that is, it can be located in one place or distributed in multiple different locations. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0258] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0259] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of this application embodiment, or all or part of the technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions to cause a device (which may be a microcontroller, chip, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, ROM, RAM, magnetic disks, or optical disks.

Claims

1. A communication method, characterized in that, include: When the network uplink and downlink encryption functions are enabled, the system receives first information from the first device; wherein, the first information includes an encrypted pairwise temporary key PTK, and the PTK is obtained by the interaction between the first device and the terminal device; Based on the first information, second information is sent to one or more second devices associated with the main access device; wherein, the second information includes the encrypted PTK; the second device is another FTTR device other than the first device among the fiber-to-room FTTR devices associated with the main access device.

2. The method according to claim 1, characterized in that, The first information also includes one or more of the following: the virtual access point (AP) identifier in the first device, the media access control (MAC) address of the terminal device, the frame type, the frame content, the frame length, or the key length.

3. The method according to claim 1 or 2, characterized in that, The first information is decrypted to obtain the PTK; The PTK is encrypted using an encryption mechanism to obtain the second information.

4. The method according to any one of claims 1-3, characterized in that, The second information may also include one or more of the following: the virtual AP identifier in the second device, the MAC address of the terminal device, the frame type, the identification information of the terminal device, the frame content, the frame length, or the key length.

5. The method according to any one of claims 1-4, characterized in that, The method further includes: Receive third information from the one or more second devices; wherein the third information is used to indicate that the PTK has been received.

6. The method according to any one of claims 1-5, characterized in that, If no third information is received from one or more of the second devices, the second information is retransmitted; wherein the third information is used to indicate that the PTK has been received.

7. The method according to any one of claims 1-6, characterized in that, Before receiving the first information from the first device, the method further includes: Determine the first state of the network uplink and downlink encryption functions; wherein the first state is either enabled or disabled. When the first state is not enabled, the entire network uplink and downlink encryption function is enabled.

8. The method according to claim 7, characterized in that, When the first state is the off state, the method further includes: Upon receiving third information from one or more of the second devices, the entire network uplink and downlink encryption functions are disabled.

9. The method according to any one of claims 1-8, characterized in that, The method further includes: Send a fourth message to the first device; wherein the fourth message is used to indicate that the first message has been received.

10. A communication method, characterized in that, include: Obtain a pair of temporary keys PTK; wherein, the PTK is the PTK obtained by the interaction between the first device and the terminal device; Send first information to the main access device; wherein, the first information includes the encrypted PTK.

11. The method according to claim 10, characterized in that, Sending the first information to the main access device includes: The PTK is encrypted using an encryption mechanism to obtain the first information; The first information is sent to the main access device.

12. The method according to claim 10 or 11, characterized in that, The method further includes: Receive fourth information from the main access device; wherein the fourth information is used to indicate that the first information has been received.

13. A communication method, characterized in that, include: Receive second information from the main access device; wherein, the second information includes an encrypted pairwise temporary key PTK, the PTK being obtained by the interaction between the first device and the terminal device; The second information is decrypted to obtain the PTK.

14. The method according to claim 13, characterized in that, The method further includes: Send third information to the main access device; wherein the third information is used to indicate that the PTK has been received.

15. The method according to claim 13 or 14, characterized in that, The step of decrypting the second information to obtain the PTK includes: The second information is decrypted based on the encryption mechanism to obtain the PTK.

16. The method according to any one of claims 13-15, characterized in that, The method further includes: Receive a first association request information from the terminal device; wherein the first association request information is used to request access to the second device; If it is determined that the terminal device has already accessed the network corresponding to the second device, a first association response information is sent to the terminal device; wherein, the first association response information is used to instruct the terminal device to access the second device; According to the PTK, communication is performed with the terminal device.

17. A communication method, characterized in that, include: When the network uplink and downlink encryption functions are enabled, the system receives first information from the first device; wherein, the first information includes an encrypted pairwise temporary key PTK, and the PTK is obtained by the interaction between the first device and the terminal device; Based on the first information, communication is established with the terminal device.

18. The method according to claim 17, characterized in that, The step of communicating with the terminal device based on the first information includes: Receive a second association request information from the terminal device; wherein the second association request information is used to request access to the main access device; If it is determined that the terminal device has already accessed the network corresponding to the main access device, a second association response information is sent to the terminal device; wherein, the second association response information is used to instruct the terminal device to access the main access device; According to the PTK, communication is performed with the terminal device.

19. A communication method, characterized in that, include: When a terminal device roams from an associated first device to a target device, it sends an association request message to the target device; wherein the association request message is used to request access to the target device; Receive association response information from the target device; wherein the association response information is used to instruct the terminal device to access the target device; The first device communicates with the target device based on a pairwise temporary key (PTK); wherein the PTK is the PTK obtained by the interaction between the first device and the terminal device.

20. The method according to claim 19, characterized in that, The target device is the primary access device; or The target device is the second device, which is another FTTR device other than the first device among the fiber-to-room FTTR devices associated with the main access device.

21. A communication device, characterized in that, The communication device includes a processor; the processor is configured to run a computer program or instructions that cause the communication method as described in any one of claims 1-9 to be executed, or cause the communication method as described in any one of claims 10-12 to be executed, or cause the communication method as described in any one of claims 13-16 to be executed, or cause the communication method as described in any one of claims 17-18 to be executed, or cause the communication method as described in any one of claims 19-20 to be executed.

22. A communication device, characterized in that, The communication device includes an interface circuit and a logic circuit; the interface circuit is used to input and / or output information; the logic circuit is used to execute the communication method as described in any one of claims 1-9, or the communication method as described in any one of claims 10-12, or the communication method as described in any one of claims 13-16, or the communication method as described in any one of claims 17-18, or the communication method as described in any one of claims 19-20, and to process and / or generate the information based on the information.

23. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions or programs that, when executed on a computer, cause the communication method as described in any one of claims 1-9 to be executed, or cause the communication method as described in any one of claims 10-12 to be executed, or cause the communication method as described in any one of claims 13-16 to be executed, or cause the communication method as described in any one of claims 17-18 to be executed, or cause the communication method as described in any one of claims 19-20 to be executed.

24. A computer program product, characterized in that, The computer program product includes computer instructions; when some or all of the computer instructions are executed on a computer, they cause the communication method as described in any one of claims 1-9 to be executed, or the communication method as described in any one of claims 10-12 to be executed, or the communication method as described in any one of claims 13-16 to be executed, or the communication method as described in any one of claims 17-18 to be executed, or the communication method as described in any one of claims 19-20 to be executed.