Method for implementing fast roaming of terminal in wireless local area network and wireless local area network
Patent Information
- Application Number
- CN202510295748.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2026-09-15
Smart Images

Figure CN122765488A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of communication technology, and in particular to a method for enabling fast roaming of terminals in a wireless local area network (WLAN) and a WLAN itself. Background Technology
[0002] With the development of smart terminals, users have increasingly higher requirements for high transmission bandwidth and low data transmission latency. Hotspot wireless networks have gained high usage rates due to their high bandwidth and low latency characteristics, especially in places such as large office buildings and smart parks.
[0003] When the required wireless network coverage area is small, and the space covered by a single access point (AP) meets the user's needs, the AP and its wireless terminals (Stations, STAs) within its signal coverage area access each other based on the wireless network communication protocol. When the wireless coverage area is very large, and a single AP cannot cover the entire space, it is necessary to expand the hotspot coverage area by increasing the number of APs to build a multi-AP hotspot wireless LAN. Each AP in the wireless LAN establishes communication with the STA in the same way as a single AP. When a STA roams within the wireless LAN (i.e., the STA moves from one AP to the signal coverage area of another AP), re-establishing the connection increases access time, and users will experience noticeable service lag in actual use. To improve the user experience, communication manufacturers have proposed a fast roaming solution, which involves setting up a wired network between APs, connecting the APs to the same AC (Access Controller) through the wired network, unifying the wireless network name of all APs under the same AC, and forming a communication loop together with the STA, the original AP, the destination AP, and the AC to enable user roaming.
[0004] However, existing roaming solutions based on AC+multiple APs only consider efficiency and do not take any measures to protect user data security. Data security is increasingly important in the information age. Although wireless LANs have already ensured security in wireless transmission through the 802.11 protocol and WAP / WAP2 security protocols, there are no effective means to securely protect the mutual authentication between APs and the transmission of link-layer keys between AP terminals when building LANs and in fast roaming scenarios. Summary of the Invention
[0005] Based on the above analysis, the embodiments of the present invention aim to provide a method and a wireless local area network for enabling fast roaming of terminals in a wireless local area network, in order to solve the problem that the existing technology lacks security protection for user data in fast roaming scenarios.
[0006] In a first aspect, embodiments of the present invention provide a method for enabling fast roaming of a terminal in a wireless local area network, comprising the following steps:
[0007] The first wireless access point and the second wireless access point perform identity authentication and key negotiation through the AP-AC-AP data transmission channel, wherein the first wireless access point and the second wireless access point are adjacent wireless access points among the multiple wireless access points of the wireless local area network.
[0008] In response to a terminal in the wireless local area network moving from the wireless coverage of the first wireless access point to the wireless coverage of the second wireless access point, the first wireless access point encrypts and transmits the link layer key between itself and the terminal to the second wireless access point through the AP-AC-AP data transmission channel, wherein the key used for the encrypted transmission is a key negotiated between the first wireless access point and the second wireless access point.
[0009] The second wireless access point uses the key negotiated between itself and the first wireless access point to decrypt the link layer key, and uses the decrypted link layer key as the link layer key between itself and the terminal.
[0010] Based on a further improvement of the above method, a security unit is embedded within the wireless access point, and the security unit is pre-configured with authentication resources for authenticating with other wireless access points.
[0011] Based on a further improvement to the above method, the first wireless access point and the second wireless access point perform authentication and key negotiation through the AP-AC-AP data transmission channel, including:
[0012] The first and second wireless access points exchange authentication and negotiation resources through the AP-AC-AP data transmission channel.
[0013] The first wireless access point and the second wireless access point calculate the negotiated key using a key negotiation algorithm based on each other's authentication resources and negotiation resources.
[0014] Further improvements to the above method include the following: The authentication and key negotiation between the first and second wireless access points via the AP-AC-AP data transmission channel also includes:
[0015] The first wireless access point and the second wireless access point verify the negotiated key using verification data.
[0016] Based on a further improvement to the above method, the link layer key between the first wireless access point and the terminal is obtained in the following manner:
[0017] The terminal and the first wireless access point negotiate and generate a link layer key through the 802.11 protocol.
[0018] Based on a further improvement of the above method, the security unit is a MINI-PCIE cryptographic card.
[0019] Based on a further improvement of the above method, the data transmission channel of the AP-AC-AP is a data transmission channel based on the TCP-IP protocol.
[0020] Based on a further improvement to the above method, the adjacency relationship between the various wireless access points is obtained in the following way:
[0021] Receive broadcast probe frames sent by the other party's wireless access point and identify whether the other party's wireless access point is an adjacent wireless access point based on the probe frames.
[0022] In a second aspect, embodiments of the present invention provide a wireless local area network, including:
[0023] Multiple wireless access points (APs) and an access controller (AC) for centralized control of the multiple wireless access points; a terminal, which accesses any of the wireless access points according to the wireless Internet Protocol and completes link layer key negotiation;
[0024] The wireless local area network is configured as follows:
[0025] The first wireless access point and the second wireless access point perform identity authentication and key negotiation through the AP-AC-AP data transmission channel, wherein the first wireless access point and the second wireless access point are adjacent wireless access points among the plurality of wireless access points.
[0026] In response to a terminal in the wireless local area network moving from the wireless coverage of the first wireless access point to the wireless coverage of the second wireless access point, the first wireless access point encrypts and transmits the link layer key between itself and the terminal to the second wireless access point through the AP-AC-AP data transmission channel, wherein the key used for the encrypted transmission is a key negotiated between the first wireless access point and the second wireless access point.
[0027] The second wireless access point uses the key negotiated between itself and the first wireless access point to decrypt the link layer key, and uses the decrypted link layer key as the link layer key between itself and the terminal.
[0028] Based on the further improvements to the wireless local area network described above, a security unit is embedded within the wireless access point, and the security unit is pre-configured with authentication resources for authenticating with other wireless access points.
[0029] Compared with the prior art, the present invention can achieve at least one of the following beneficial effects:
[0030] 1. This invention establishes a secure terminal key transmission channel through bidirectional authentication between adjacent APs. When STAs roam, they can quickly synchronize the STA link layer keys between APs, preventing data theft during key synchronization, improving the security of fast roaming, enhancing user experience, and enabling the construction of a secure and user-friendly hotspot wireless LAN.
[0031] 2. This invention adds a security unit to the AP. When multiple APs form a hotspot network, the security unit completes the two-way authentication design between APs. Unauthorized APs cannot complete the customized two-way authentication between APs. This strategy effectively and efficiently identifies unauthorized APs and strictly prevents unauthorized APs from accessing the hotspot network.
[0032] 3. This invention adds a security unit to the AP. When multiple APs form a network, the security unit completes key negotiation between APs, and each pair of APs establishes a secure transmission channel to protect all data transmitted in this channel.
[0033] 4. By adding a security unit to the AP, when the STA roams, the original AP and the destination AP use the negotiated key to build a secure transmission channel, quickly synchronize the link layer key, cut off the renegotiation process for the STA to access the AP, shorten the STA network access time, and realize secure and fast STA roaming.
[0034] In this invention, the above-described technical solutions can be combined with each other to achieve more preferred combinations. Other features and advantages of this invention will be set forth in the following description, and some advantages may become apparent from the description or be learned by practicing the invention. The objects and other advantages of this invention can be realized and obtained from what is particularly pointed out in the description and drawings. Attached Figure Description
[0035] The accompanying drawings are for illustrative purposes only and are not intended to limit the invention. Throughout the drawings, the same reference numerals denote the same parts.
[0036] Figure 1 A flowchart illustrating a method for enabling fast roaming of a terminal in a wireless local area network according to an embodiment of the present invention is shown.
[0037] Figure 2 An example of a wireless LAN built using an AC and an AP is shown.
[0038] Figure 3 The process of establishing a secure passage between neighboring APs is shown.
[0039] Figure 4 The process of key synchronization between neighboring APs is shown. Detailed Implementation
[0040] Preferred embodiments of the present invention will now be described in detail with reference to the accompanying drawings, which form part of this application and are used together with the embodiments of the present invention to illustrate the principles of the present invention, but are not intended to limit the scope of the present invention.
[0041] Figure 1 A flowchart illustrating a method for enabling fast terminal roaming in a wireless local area network according to an embodiment of the present invention is shown. Figure 1 As shown, the method for enabling fast terminal roaming in a wireless local area network includes the following steps:
[0042] Step S100: The first wireless access point and the second wireless access point perform identity authentication and key negotiation through the AP-AC-AP data transmission channel.
[0043] In this embodiment, the first wireless access point and the second wireless access point are adjacent wireless access points among multiple wireless access points in a wireless local area network.
[0044] Figure 2 An example of a wireless LAN built using an AC and an AP is shown. Figure 2 As shown, the wireless local area network contains at least AP1 and AP2. Each AP has an embedded security unit, which contains pre-configured resources (e.g., device certificates and root certificates) that can authenticate with other AP units.
[0045] In this embodiment, the AP can identify neighboring APs through the combined action of wireless frames and the AC, and the AC enables data transmission channels between APs and ACs. In this embodiment, the AC is the central hub connecting all APs, and each AP registers an ID with the AC. During the neighbor identification process, after an AP detects a broadcast frame from another AP, it needs to report the other AP's ID to the AC. The AC confirms that the other AP's ID has been registered, thus achieving neighbor identification. Figure 3 The process for establishing a secure passage between neighboring APs is illustrated. Figure 3 The first piece of data in the sequence indicates that the AP can identify the other AP as a neighboring AP by receiving a broadcast Probe frame from the other AP. The broadcast Probe frame data format is as follows:
[0046]
[0047] In this embodiment, the "SSID" in the broadcast Probe frame is the ID of the AP.
[0048] In this embodiment, the APs can perform authentication negotiation and resource exchange through the bidirectional transmission channel of AP-AC-AP. Figure 3 It illustrates the process of the two parties exchanging resources. Figure 3The data "Authentication Negotiation Request (Certificate, Negotiation Parameters)" in the document sends AP1's identity information data and negotiation data to AP2. Figure 3 The data "Authentication Negotiation Response (Certificate, Negotiation Parameters)" sends AP2's identity information and negotiation data to AP1, and its data format is as follows:
[0049] Diagram of AP1 authentication negotiation request frame format:
[0050]
[0051] AP2 authentication negotiation response frame format diagram:
[0052]
[0053] In this embodiment, after exchanging authentication negotiation resources, both parties can parse each other's authentication negotiation data, extract the certificate, and then use the certificate to verify each other's identity. After successful identity verification, the public key in the certificate and the negotiation data can be used to calculate the channel key EncKey through a key negotiation algorithm. In this embodiment, the key negotiation algorithm can be SM2, RSA, etc.
[0054] In this embodiment, after AP1 successfully authenticates and negotiates the key EncKey, it can generate verification data and encrypt it using the key EncKey, and generate an authentication negotiation response frame as shown in the figure below, which is then sent to AP2. AP2 uses the key EncKey to decrypt the data and verify whether the verification data is correct.
[0055] Authentication negotiation response frame format diagram:
[0056]
[0057] In this embodiment, after AP2 verifies the data is correct, both parties confirm the negotiated key EncKey. At this point, a secure channel between AP1 and AP2 has been established.
[0058] Step S200: In response to a terminal in the wireless local area network moving from the wireless coverage of the first wireless access point to the wireless coverage of the second wireless access point, the first wireless access point transmits the link layer key between itself and the terminal to the second wireless access point via the AP-AC-AP data transmission channel in encrypted form.
[0059] Step S300: The second wireless access point decrypts the link layer key using the key negotiated between it and the first wireless access point, and uses the decrypted link layer key as the link layer key between it and the terminal.
[0060] Figure 4The process of key synchronization between neighboring APs is illustrated below. Figure 4 Steps S200 to S300 will be explained.
[0061] In this embodiment, the terminal STA and AP1 can complete access and link layer key negotiation according to the 802.11 protocol. When the terminal STA moves from the wireless coverage of AP1 to the wireless coverage of AP2, it sends an association request message to AP2. AP2 then detects the association request from a new terminal moving from AP1 to its own network. The 802.11 protocol is a series of wireless local area network (WLAN) communication standards developed by the IEEE (Institute of Electrical and Electronics Engineers) to standardize data transmission and communication methods between wireless devices.
[0062] In this embodiment, the AC can trigger the terminal roaming process and perform key synchronization. For example... Figure 4 As shown, AP1 sends the STA's link layer key to the security unit. The security unit uses the key EncKey to encrypt the STA's link layer key. The key synchronization data frame content is as follows:
[0063] Key synchronization frame format diagram:
[0064]
[0065] In this embodiment, the link layer key of the STA, encrypted with the key EncKey, is sent to AP2 via the AP-AC-AP transmission channel (e.g., a data transmission channel based on the TCP-IP protocol). AP2 then forwards this to the security unit to obtain the link layer key. After obtaining the link layer key, AP2 can send an associated response to notify the STA that roaming has been successful, completing the entire roaming process. At this point, the STA can achieve fast roaming under AP2 without needing to renegotiate the key.
[0066] This invention proposes a method for achieving secure and fast roaming of wireless LAN terminals. Based on the existing hotspot wireless network architecture, this method adds a security unit (e.g., an embedded MINIPCIE cryptographic card, a small cryptographic device supporting Chinese national cryptographic algorithms such as SM1, SM2, SM3, and SM4, as well as internationally recognized algorithms such as AES, RSA, and SHA) to each access point (AP). Based on this security unit, bidirectional authentication between adjacent APs is performed, and a secure transmission channel for terminal keys is established. During roaming, STAs can achieve rapid synchronization of STA link-layer keys between APs, preventing data theft during key synchronization, improving the security of fast roaming, enhancing user experience, and ultimately building a secure and user-friendly hotspot wireless LAN.
[0067] The present invention also proposes a wireless local area network (WLAN), comprising: multiple wireless access points (APs) and an access controller (AC) for centralized control of the multiple wireless access points; a terminal, wherein the terminal accesses any of the wireless access points according to the wireless Internet Protocol (WLAN) and completes link layer key negotiation; the WLAN is configured such that: a first wireless access point and a second wireless access point perform authentication and key negotiation through an AP-AC-AP data transmission channel, wherein the first wireless access point and the second wireless access point are adjacent wireless access points among the multiple wireless access points; in response to a terminal in the WLAN moving from the wireless coverage of the first wireless access point to the wireless coverage of the second wireless access point, the first wireless access point encrypts and transmits its link layer key with the terminal to the second wireless access point through the AP-AC-AP data transmission channel, wherein the key used for encryption is a key negotiated between the first wireless access point and the second wireless access point; the second wireless access point decrypts the link layer key using the key negotiated with the first wireless access point, and uses the decrypted link layer key as its link layer key with the terminal.
[0068] Compared with the prior art, the embodiments of the present invention can achieve at least one of the following beneficial effects:
[0069] 1. This invention establishes a secure terminal key transmission channel through bidirectional authentication between adjacent APs. When STAs roam, they can quickly synchronize the STA link layer keys between APs, preventing data theft during key synchronization, improving the security of fast roaming, enhancing user experience, and enabling the construction of a secure and user-friendly hotspot wireless LAN.
[0070] 2. This invention adds a security unit to the AP. When multiple APs form a hotspot network, the security unit completes the two-way authentication design between APs. Unauthorized APs cannot complete the customized two-way authentication between APs. This strategy effectively and efficiently identifies unauthorized APs and strictly prevents unauthorized APs from accessing the hotspot network.
[0071] 3. This invention adds a security unit to the AP. When multiple APs form a network, the security unit completes key negotiation between APs, and each pair of APs establishes a secure transmission channel to protect all data transmitted in this channel.
[0072] 4. By adding a security unit to the AP, when the STA roams, the original AP and the destination AP use the negotiated key to build a secure transmission channel, quickly synchronize the link layer key, cut off the renegotiation process for the STA to access the AP, shorten the STA network access time, and realize secure and fast STA roaming.
[0073] The above description is only a preferred embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any changes or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in the present invention should be included within the scope of protection of the present invention.
Claims
1. A method for implementing fast terminal roaming in a wireless local area network, characterized in that, Includes the following steps: The first wireless access point and the second wireless access point perform identity authentication and key negotiation through the AP-AC-AP data transmission channel, wherein the first wireless access point and the second wireless access point are adjacent wireless access points in the wireless local area network. In response to a terminal in the wireless local area network moving from the wireless coverage of the first wireless access point to the wireless coverage of the second wireless access point, the first wireless access point encrypts and transmits the link layer key between itself and the terminal to the second wireless access point through the AP-AC-AP data transmission channel, wherein the key used for the encrypted transmission is a key negotiated between the first wireless access point and the second wireless access point. The second wireless access point uses the key negotiated between itself and the first wireless access point to decrypt the link layer key, and uses the decrypted link layer key as the link layer key between itself and the terminal.
2. The method of claim 1, wherein, The wireless access point embeds a security unit, which is pre-configured with authentication resources for authenticating with other wireless access points.
3. The method of claim 2, wherein, The first and second wireless access points perform authentication and key negotiation through the AP-AC-AP data transmission channel, including: The first and second wireless access points exchange authentication and negotiation resources through the AP-AC-AP data transmission channel. The first wireless access point and the second wireless access point calculate the negotiated key using a key negotiation algorithm based on each other's authentication resources and negotiation resources.
4. The method of claim 3, wherein, The authentication and key negotiation between the first and second wireless access points via the AP-AC-AP data transmission channel also includes: The first wireless access point and the second wireless access point verify the negotiated key using verification data.
5. The method of claim 1, wherein, The link layer key between the first wireless access point and the terminal is obtained in the following manner: The terminal and the first wireless access point generate a link layer key using the 802.11 protocol.
6. The method of claim 2, wherein, The security unit is a MINI-PCIE password card.
7. The method of claim 1, wherein, The data transmission channel of the AP-AC-AP is a data transmission channel based on the TCP-IP protocol.
8. The method of claim 1, wherein, The adjacency relationships between the various wireless access points are obtained in the following way: Receive broadcast probe frames sent by the other party's wireless access point and identify whether the other party's wireless access point is an adjacent wireless access point based on the probe frames.
9. A wireless local area network, characterized by include: Multiple wireless access points (APs) and an access controller (AC) for centralized control of the multiple wireless access points; a terminal, which accesses any of the wireless access points according to the wireless Internet Protocol and completes link layer key negotiation; The wireless local area network is configured as follows: The first wireless access point and the second wireless access point perform identity authentication and key negotiation through the AP-AC-AP data transmission channel, wherein the first wireless access point and the second wireless access point are adjacent wireless access points among the plurality of wireless access points. In response to a terminal in the wireless local area network moving from the wireless coverage of the first wireless access point to the wireless coverage of the second wireless access point, the first wireless access point encrypts and transmits the link layer key between itself and the terminal to the second wireless access point through the AP-AC-AP data transmission channel, wherein the key used for the encrypted transmission is a key negotiated between the first wireless access point and the second wireless access point. The second wireless access point uses the key negotiated between itself and the first wireless access point to decrypt the link layer key, and uses the decrypted link layer key as the link layer key between itself and the terminal.
10. The wireless local area network of claim 1, wherein, The wireless access point embeds a security unit, which is pre-configured with authentication resources for authenticating with other wireless access points.