Method and system for WLAN multi-link TDLS key derivation
The method for WLAN multi-link TDLS key derivation simplifies the establishment of communication links between legacy STAs and non-AP MLDs by using enhanced link identifiers and AKM suites, addressing the complexity of managing multiple authenticators in MLDs.
Patent Information
- Application Number
- JP2025092262
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-02-25
- Filing Date
- 2025-06-03
- Publication Date
- 2025-09-17
AI Technical Summary
The complexity of managing security associations in WLAN multi-link devices (MLDs) with multiple authenticators complicates the establishment of communication links, particularly when legacy STAs and non-AP MLDs need to communicate, requiring additional network resources and protocols to ensure protection and proper service.
A method and system for WLAN multi-link TDLS key derivation that includes transmitting discovery and setup requests with enhanced link identifiers and authentication and key management (AKM) suites to accommodate multiple authenticators, allowing legacy STAs to establish TDLS links with non-AP MLDs.
Facilitates efficient TDLS link establishment between legacy STAs and non-AP MLDs by accommodating multiple authenticators, reducing complexity and resource requirements in WLAN multi-link communication systems.
Smart Images

Figure 2025134731000001_ABST
Abstract
Description
[Technical Field]
[0001]
[0002] The present invention relates to the field of communication networks, and more particularly to a system and method for WLAN multi-link communication. Aspects of the present disclosure provide a method and system for TDLS key derivation WLAN multi-link communication. [Background technology]
[0002]
[0003] IEEE 802.11 security is established between a station (STA) and an access point (AP) to protect traffic passing between the two entities. AP multi-link devices (MLDs) are also additional affiliated APs, each with a different authenticator for establishing security associations. Therefore, an AP multi-link device (MLD) may have multiple authenticators for establishing security associations with multiple devices, including legacy STAs and non-AP MLDs. Having multiple authenticators adds a layer of complexity to managing security associations for establishing communication links.
[0003]
[0004] Furthermore, due to the nature of the security association and the involvement of the authenticator, the communication link may be required to pass through more than one AP, thereby requiring additional network resources to ensure protection and proper service. This may occur, for example, when two STAs (a legacy non-AP STA (e.g., a WLAN-enabled screen) and a non-AP MLD (e.g., a smartphone)) wish to communicate with each other, and each STA has established a security association with a different AP authenticator.
[0004]
[0005] Therefore, what is needed is a system and method for WLAN multi-link TDLS key derivation that obviates or mitigates one or more limitations of the prior art.
[0005]
[0006] This background information is provided to identify information believed by applicant to be of possible relevance to the present invention. No admission is necessarily intended, nor should it be construed, that any of the preceding information constitutes prior art against the present invention. Summary of the Invention
[0006]
[0007] According to a first aspect of the disclosure, a method for WLAN multi-link communication is provided. Such a method includes a step of a first station transmitting a discovery request to a second station, the discovery request including a link identifier indicating a non-access point (AP) multi-link device (MLD), where the first station is associated with the AP and the second station is associated with the AP MLD. Such a method further includes a step of the first station receiving a discovery response from the second station. The method can result in establishing a TDLS link between the legacy STA and the non-AP MLD.
[0007]
[0008] In some embodiments of the first aspect, the method further includes receiving, by the first station, a message from an AP affiliated with the AP MLD indicating a MAC address of a second station. The method may allow for discovering potential TDLS peers.
[0008]
[0009] According to a further aspect of the first aspect in addition to any preceding, the discovery request is transmitted via an AP affiliated with the AP MLD and a non-AP station affiliated with the second station. In some embodiments of the first aspect, one of the discovery request or the discovery response further includes a multi-link element (MLE) indicating one or more addresses of the AP entity. The method can further allow a legacy STA to determine that the AP (and affiliated AP) is multi-link capable.
[0009]
[0010] According to a further aspect of the first aspect in addition to any preceding, the method may further include the first station sending a setup request to the second station and the first station receiving a setup response from the second station. The method may allow for establishing a TDLS link between the peer STAs.
[0010]
[0011] According to a further aspect of the first aspect in addition to any preceding, the setup request indicates an authentication and key management (AKM) suite for establishing a link between the first station and the second station. In some embodiments of the first aspect, the method further includes the first station deriving a key based on the AKM suite; and the first station sending a setup confirmation message to the second station. The method can further allow for negotiating peer keys bound to multiple authenticators. The method can further allow for a legacy STA to use a legacy TDLS handshake or an enhanced ML TDLS handshake.
[0011]
[0012] According to a further aspect of the first aspect in addition to any preceding, a first station is preconfigured to transmit a discovery request including a link identifier. In some embodiments of the first aspect, the first station has a security association via a first authenticator associated with an AP affiliated with the AP MLD, and the second station has a second association via a second authenticator associated with the AP MLD, wherein the first authenticator and the second authenticator have different MAC addresses. The method can further allow for TDLS key derivation that can accommodate multiple authenticator identifiers.
[0012]
[0013] According to a second aspect of the disclosure, another method for WLAN multi-link communication is provided. Such method includes a step of a first station receiving a discovery request from a second station, the discovery request including a link identifier indicating a non-access point (AP) multi-link device (MLD), where the first station is associated with the AP and the second station is associated with the AP MLD. The method further includes a step of the first station transmitting a discovery response to the second station. The method can result in establishing a TDLS link between the legacy STA and the non-AP MLD.
[0013]
[0014] In some embodiments of the second aspect, such a method further includes the first station receiving a message from an AP affiliated with the AP MLD indicating a MAC address of the second station. The method may allow for discovering potential TDLS peers.
[0014]
[0015] According to a further aspect of the second aspect, in addition to any preceding, the discovery response is transmitted via an AP affiliated with the AP MLD and a non-AP station affiliated with the first station. In some embodiments of the second aspect, one of the discovery request or the discovery response further includes a multi-link element (MLE) indicating one or more addresses of the AP entity. The method can further allow legacy STAs to determine that the AP (and affiliated APs) are multi-link capable.
[0015]
[0016] According to a further aspect of the second aspect in addition to any preceding, the method further includes the first station receiving a setup request from the second station indicating an authentication and key management (AKM) suite. The method can further allow for negotiating peer keys bound to multiple authenticators. The method can further allow for a legacy STA to use a legacy TDLS handshake or an enhanced ML TDLS handshake.
[0016]
[0017] According to a further aspect of the second aspect in addition to any preceding, the method further includes the first station deriving a key based on the AKM suite; and the first station sending a setup response to the second station indicating the AKM suite. In some embodiments of the second aspect, the method further includes the first station receiving a setup confirmation message from the second station indicating establishment of a link between the first station and the second station. The method can further allow for TDLS key derivation to accommodate multiple authenticator identifiers.
[0017]
[0018] According to a third aspect of the disclosure, there is provided a WLAN multi-link communication system including a first station and a second station. The first station is configured to transmit a discovery request to the second station, the discovery request including a link identifier indicating a non-access point (AP) multi-link device (MLD), where the first station is associated with the AP and the second station is associated with the AP MLD. The first station is further configured to receive a discovery response from the second station. The second station is configured to receive the discovery request from the second station. The second station is further configured to transmit the discovery response to the second station. The method can result in establishing a TDLS link between the legacy STA and the non-AP MLD.
[0018]
[0019] In some embodiments of the third aspect, the first station is further configured to receive a message from the AP affiliated with the AP MLD indicating a MAC address of the second station. In some embodiments of the third aspect, the second station is further configured to receive a message from the AP indicating a MAC address of the first station. The method may allow for discovering potential TDLS peers.
[0019]
[0020] According to a further aspect of the third aspect in addition to any preceding, the first station is further configured to send a setup request to the second station indicating an authentication and key management (AKM) suite. In some embodiments of the third aspect, the first station is further configured to receive a setup response from the second station. In some embodiments of the third aspect, the second station is further configured to receive the setup request from the first station. The method can allow for establishing a TDLS link between peer STAs.
[0020]
[0021] According to a further aspect of the third aspect in addition to any preceding, the second station is further configured to derive a first key based on the AKM suite. In some embodiments of the third aspect, the second station is further configured to transmit a setup response to the second station. In some embodiments of the third aspect, the first station is further configured to derive a second key based on the AKM suite and the setup response. In some embodiments of the third aspect, the first station is further configured to transmit a setup confirmation message to the second station indicating establishment of a link between the first station and the second station. The method can further allow for negotiating peer keys bound to multiple authenticators. The method can further allow for legacy STAs to use a legacy TDLS handshake or an enhanced ML TDLS handshake.
[0021]
[0022] According to a further aspect of the third aspect in addition to any preceding, the second station is further configured to receive a setup confirmation message from the first station. In some embodiments of the third aspect, the first station has a security association via a first authenticator associated with an AP affiliated with the AP MLD. In some embodiments of the third aspect, the second station has a second association via a second authenticator associated with the AP MLD, the first authenticator and the second authenticator having different MAC addresses. The method can further allow for TDLS key derivation that accommodates multiple authenticator identifiers. The method can result in establishing a TDLS link between a legacy STA and a non-AP MLD.
[0022]
[0023] According to a fourth aspect of the present disclosure, an apparatus is provided, the apparatus including modules configured to perform a method according to one or more aspects described herein.
[0023]
[0024] According to a fifth aspect, there is provided an apparatus, the apparatus including: a memory configured to store a program; and a processor configured to execute the program stored in the memory, wherein when the program stored in the memory is executed, the processor is configured to perform a method in one or more aspects described herein.
[0024]
[0025] According to a sixth aspect, a computer-readable medium is provided, the computer-readable medium storing program code for execution by a device, the program code being used to perform the methods in one or more aspects described herein.
[0025]
[0026] According to a seventh aspect, a chip is provided, the chip including a processor and a data interface, the processor reading instructions stored in a memory by using the data interface and performing the method in one or more aspects described herein.
[0026]
[0027] Another aspect of the present disclosure provides apparatuses and systems configured to implement the method according to the first aspect disclosed herein. For example, wireless stations and access points can be configured with machine-readable memories containing instructions that, when executed by a processor of such devices, configure the devices to perform the method according to one or more aspects disclosed herein.
[0027]
[0028] The embodiments are described above in relation to aspects of the invention in which they may be implemented. Those skilled in the art will understand that while an embodiment may be implemented in relation to the aspect being described, it may also be implemented with other embodiments of that aspect. Where embodiments are mutually exclusive or otherwise incompatible with one another, such will be apparent to those skilled in the art. While some embodiments may be described in relation to one aspect, they may also be applicable to other aspects, as apparent to those skilled in the art. [Brief explanation of the drawings]
[0028]
[0029] Further features and advantages of the present invention will become apparent from the following detailed description taken in conjunction with the accompanying drawings. [Figure 1]
[0030] FIG. 1 illustrates an MLD architecture according to an embodiment of the present disclosure. [Figure 2]
[0031] FIG. 2 illustrates an MLD security association according to an embodiment of the present disclosure. [Figure 3]
[0032] FIG. 3 illustrates a Tunneled Direct Link Setup (TDLS) security operation according to an embodiment of the present disclosure. [Figure 4]
[0033] FIG. 4 illustrates a legacy STA connected to an affiliated AP in an AP MLD according to an embodiment of the present disclosure. [Figure 5]
[0034] FIG. 5 illustrates TDLS security operations between a legacy STA and a non-AP STA according to an embodiment of the present disclosure. [Figure 6A]
[0035] FIG. 6A illustrates a message flow diagram of a TDLS setup between a legacy STA and a non-AP MLD according to an embodiment of the present disclosure. [Figure 6B]
[0035] Figure 6B shows a message flow diagram of TDLS setup between a legacy STA and a non-AP MLD according to an embodiment of the present disclosure. [Figure 6C] FIG. 6C illustrates a message flow diagram of a TDLS setup between a legacy STA and a non-AP MLD according to an embodiment of the present disclosure. [Figure 7]
[0036] FIG. 7 illustrates a combined authentication and key management (AKM) according to an embodiment of the present disclosure. [Figure 8A]
[0037] FIG. 8A illustrates a message flow diagram of a TDLS setup between a legacy STA and a non-AP MLD according to another embodiment of the present disclosure. [Figure 8B]
[0037] FIG. 8B shows a message flow diagram of a TDLS setup between a legacy STA and a non-AP MLD according to another embodiment of the present disclosure. [Figure 8C]
[0037] FIG. 8C shows a message flow diagram of a TDLS setup between a legacy STA and a non-AP MLD according to another embodiment of the present disclosure. [Figure 9]
[0038] FIG. 9 shows a flowchart of a TDLS setup procedure according to an embodiment of the present disclosure. [Figure 10]
[0039] FIG. 10 is a schematic diagram of a user equipment (UE) capable of performing any or all of the operations and features of the above methods explicitly or implicitly described herein in accordance with various embodiments of the present invention.
[0040] It should be noted that throughout the accompanying drawings, like features are identified by like reference numerals. DETAILED DESCRIPTION OF THE INVENTION
[0029]
[0041] A wireless communication system to which embodiments of the present disclosure are applicable may be a wireless local area network (WLAN). A communication device may be a wireless communication device that supports parallel transmission on multiple links. Such a communication device may be referred to as a multi-link device (MLD) or a multi-band device. An MLD may have higher transmission efficiency and higher throughput than a device that supports only single-link transmission.
[0030]
[0042] An MLD can be described as a wireless local area network (WLAN) entity with multiple wireless links to other MLD entities, as further described with reference to Figure 1. An AP MLD may be referred to as an MLD, in which case each station (STA) belonging to the MLD is an AP. A non-AP MLD may be referred to as an MLD, in which case each STA belonging to the MLD is a non-AP STA.
[0031]
[0043] 1 illustrates an MLD architecture according to an embodiment of the present disclosure. As can be understood by one skilled in the art, an MLD device is a logical entity that may have two or more affiliated STAs and a single Medium Access Control (MAC) Service Access Point (SAP) to a Logical Link Control (LLC), which may include one MAC data service.
[0032]
[0044] A typical use case for MLD might be an access point (AP) MLD 102 connected to a non-AP MLD (WLAN station) 112 using two wireless links in the 2.4 GHz (link 140) and 5 GHz (link 150) WLAN bands. The individual wireless links 140 and 150 are sometimes referred to as links. The wireless units 104 and 105 in the AP MLD 102 are called affiliated APs (e.g., 2.4 GHz AP-1, or otherwise, 104, and 5 GHz AP-2, or otherwise, 105). The wireless units 114 and 115 in the non-AP MLD 112 are called affiliated STAs (e.g., 2.4 GHz STA-1, or otherwise, 114, and 5 GHz STA-2, or otherwise, 115).
[0033]
[0045] Each of the affiliated APs 104 and 105 may also serve legacy non-AP STAs. For example, the AP MLD 102 with the 2.4 GHz wireless link 140 may behave as a legacy AP serving legacy 802.11ax non-AP STAs. In this case, the source of the 2.4 GHz wireless link is the affiliated AP 104 within the AP MLD 102, as shown.
[0034]
[0046] As can be appreciated by those skilled in the art, the operation of MLD can differ from that of two logical stations (STAs) (multi-band clients) within the same physical entity (e.g., the operation of two non-AP STAs in the same handset). In MLD, traffic can be matched between two links, and security associations are maintained across those links. This provides several benefits over the concept of multiple logical STAs.
[0035]
[0047] As mentioned, an MLD may include one or more affiliated STAs, as shown in FIG. 1. AP MLD 102 may be connected to a local area network (LAN), such as LAN 1, which may be connected to a wired gateway as shown. AP MLD 102 may have an MLD basic service set (BSS) identifier (ID). FIG. 1 shows Service Set Identifier A (SSID A) as the network identifier. In this case, AP MLD 102 provides access to the LAN for non-AP MLDs through affiliated APs (AP-1 and AP-2). AP-1 and AP-2 may also provide access to the LAN for legacy devices. STAs (e.g., 104, 105, 114, and 115) are logical stations each capable of operating on a link. The logical stations 104 and 105 belonging to the AP MLD may be access points (APs), and the logical stations 114 and 115 belonging to the non-AP MLD may be non-access point stations (non-AP STAs).
[0036]
[0048] A multi-link device 102 belonging to an AP may be referred to as a multi-link AP, a multi-link AP device, or an AP multi-link device (AP MLD). Similarly, a multi-link device 112 belonging to a non-AP STA may be referred to as a multi-link STA, a multi-link STA device, or an STA multi-link device (STA MLD). Furthermore, a "member STA" may be referred to as an "STA," and thus a "multi-link device including member STAs" may be described as a "multi-link device including STAs."
[0037]
[0049] The MLD 102 or 112 may be a single-antenna device or a multi-antenna device. For example, a device with more than two antennas may be used. The number of antennas included in the multi-link device is not limited in the embodiments of the present disclosure. The multi-link device 102 or 112 may allow services of the same access type to be transmitted over different links, or may even allow the same data packet to be transmitted over different links. Alternatively, services of the same access type may not be transmitted over different links, but services of different access types may be transmitted over different links.
[0038]
[0050] IEEE 802.11 security is established between a STA and an AP to protect traffic exchanged by the two entities. The security framework is an authentication and key management framework built on the IEEE 802.1X standard. IEEE 802.1X defines a protocol that allows a supplicant (corresponding to a non-AP STA in an IEEE 802.11 infrastructure network) and an authenticator (corresponding to an AP in an IEEE 802.11 infrastructure network) to mutually authenticate and establish a security association. In an IEEE 802.11 infrastructure network, the supplicant's identity may be the MAC address of the STA, and the authenticator's identity may be the MAC address of the AP.
[0039]
[0051] FIG. 2 illustrates an MLD security association according to an embodiment of the present disclosure. FIG. 2 shows that the non-AP MLD 112 can associate with the AP MLD 102 using its non-AP MLD MAC address. The non-AP MLD 112 and the AP MLD 102 can authenticate each other, establish communication, and exchange data. The MLDs 102 and 112 can communicate via links 140 and 150 between their affiliated STAs (link 140 between AP-1 104 and STA-1 114, and link 150 between AP-2 105 and STA-2 115). Upon successful completion of the authentication and association protocol, the affiliated STAs 114 and 115 of the non-AP MLD 112 can then associate with the AP MLD 102's respective affiliated APs 104 and 105. From an MLD security perspective, a security association 202 exists between the non-AP MLD 112 and the AP MLD 102, but no security association exists between the affiliated non-AP STAs (STA-1 114 and STA-2 115) and their respective affiliated APs (2.4 GHz AP-1 104 and 5 GHz AP-2 105). The affiliated STAs (114 and 115) can be used to facilitate communication between the non-AP MLD 112 and the AP MLD 102.
[0040]
[0052] FIG. 3 illustrates tunneled direct link setup (TDLS) security operations according to an embodiment of the present disclosure. TDLS can enable two peer non-AP STAs, e.g., legacy STA-1 302 and legacy STA-2 304 in FIG. 3, to establish direct communication with each other. Once the TDLS link 310 is established, traffic can flow directly between the peer STAs 302 and 304 and is not bridged through the AP 306. As can be appreciated by those skilled in the art, a TDLS, e.g., TDLS 310, can be established between two STAs associated with an AP (e.g., AP 306) in the same BSS.
[0041]
[0053] Discovery and setup frames can be encapsulated within data frames so that they are exchanged between peer STAs 302 and 304 through AP 306 (e.g., over links 312 and 314). This has the advantage that AP 306 does not need to be "TDLS capable." Once setup is complete, the two non-AP STAs 302 and 304 can communicate directly with each other over the established TDLS link 310.
[0042]
[0054] TDLS communication can be used, for example, in Chromecast (screen sharing and streaming to display devices).
[0043]
[0055] The goal of TDLS security is to establish a direct link, e.g., link 310, between legacy STA-1 302 and legacy STA-2 304 using the 2.4 GHz AP 306 to facilitate communication for discovery and setup. STAs 302 and 304 must be associated with the same AP 306 in the same basic service set (BSS). Once the security connection (322 and 324) is established, data can flow directly between the two STAs 302 and 304 (via TDLS link 310) without going through the AP 306.
[0044]
[0056] As can be appreciated by those skilled in the art, establishing a TDLS may involve two stages: TDLS discovery and TDLS setup.
[0045]
[0057] During the TDLS discovery phase, a STA, e.g., legacy STA-1 302, may determine that it is communicating with a peer STA, e.g., legacy STA-2 304, on a local LAN. This may occur at the application layer or the network layer. The STA, e.g., legacy STA-1 302, may then determine that it may be able to communicate directly with the peer STA, e.g., legacy STA-2 304, over TDLS. To discover whether a TDLS link is possible, the STA (e.g., legacy STA-1 302) may transmit a TDLS discovery request message to the peer STA (e.g., legacy STA-2 304). The TDLS discovery request frame may be transmitted to the peer STA (e.g., legacy STA-2 304) via an AP (e.g., 2.4 GHz AP 306) over links 312 and 314. The peer STA (e.g., legacy STA-2 304) then responds to the originating STA (e.g., legacy STA-1 302) with a TDLS discovery response message via the 2.4 GHz AP 306. At this point, the STA (e.g., legacy STA-1 302) and the peer STA (legacy STA-2 304) can determine whether they are connected to the same BSS (i.e., the same AP).
[0046]
[0058] During the TDLS setup phase, a STA (e.g., legacy STA-1 302) may transmit a TDLS setup request frame to a peer STA (e.g., legacy STA-2 304) via the 2.4 GHz AP 306. The peer STA (e.g., legacy STA-2 304) may process the TDLS setup request and derive a TDLS Peer Key. The peer STA (e.g., legacy STA-2 304) may then respond with a TDLS setup response to the STA (e.g., legacy STA-1 302) via the AP 306. The STA (e.g., legacy STA-1 302) may derive the TDLS key and verify the TDLS setup response. A STA (e.g., legacy STA-1 302) may send a TDLS setup confirm to a peer STA (e.g., legacy STA-2 304) via the 2.4 GHz AP 306. The peer STA (e.g., legacy STA-2 304) may validate the TDLS setup confirm frame and complete the TDLS handshake.
[0047]
[0059] Following the handshake, the STA (e.g., legacy STA-1 302) and the peer STA (e.g., legacy STA-2 304) can communicate encapsulated traffic directly using the TDLS keying information. The STA (e.g., legacy STA-1 302) and the peer STA (e.g., legacy STA-2 304) may be able to communicate directly over the secure connection 310 while maintaining a connection to the AP 306.
[0048]
[0060] 4 illustrates a legacy STA connected to affiliated AP-1 in an AP MLD according to an embodiment of the present disclosure. For example, a legacy STA (legacy STA-L 402 in FIG. 4), which may be a WLAN-enabled screen, may desire to establish a TDLS link with a non-AP MLD 112 (e.g., a smartphone).
[0049]
[0061] Under the condition that the non-AP MLD 112 is capable of communicating with the legacy STA-L 402 via any affiliated link (e.g., link 140 or link 150), the non-AP MLD 112 may need to determine which link it needs to use to establish TDLS communication with the legacy STA-L 402. To do this, the BSSID of the legacy STA-L 402, which in FIG. 4 is the MAC address of AP-1 104, is required by the non-AP MLD 112 to determine which affiliated STA it can use to establish a TDLS connection.
[0050]
[0062] When the non-AP MLD 112 is associated with the AP MLD 102, the non-AP MLD 112 can establish a security association 202 through the authenticator associated with the AP MLD 102. Therefore, no security association exists between STA-1 114 and affiliated AP-1 104, as communications over link 140 can use the AP MLD security association 202.
[0051]
[0063] When a legacy STA-L 402 associates with affiliated AP-1 104, the legacy STA-L 402 can establish a security association 404 through an authenticator associated with affiliated AP-1 104. As a result, two authenticators may be involved (one in the AP MLD 102 and one in the affiliated AP-1 104), which poses a problem in establishing TDLS between the legacy STA-L 402 and the non-AP MLD 112.
[0052]
[0064] For an associated non-AP MLD 112, the authenticator identity may be associated with the MAC address of the AP MLD 102. Meanwhile, for an associated legacy STA-L 402, the authenticator identity for the legacy STA-L 402 may be associated with the MAC address of affiliated AP-1 104 (the AP affiliated with the AP MLD 102).
[0053]
[0065] As can be appreciated by those skilled in the art, AP-1 104, AP-2 105, and AP MLD 102 may each have their own distinct MAC address to which an authenticator identity may be associated. Thus, each authenticator identifier may be associated with a different MAC address.
[0054]
[0066] Therefore, since security associations may be established with different entities, the protocol and key bindings for TDLS may need to be modified to accommodate different authenticator identities.
[0055]
[0067] Embodiments may provide for modifying the TDLS discovery frame to allow a non-AP MLD, e.g., non-AP MLD 112, to advertise MLD information (by including an ML element) during the discovery phase.
[0056]
[0068] This can allow a legacy STA, e.g., legacy STA-L 402, to discover that a potential TDLS peer is a non-AP MLD that uses the AP as an affiliated AP, e.g., non-AP MLD 112. Thus, the non-AP MLD, e.g., non-AP MLD 112, can use the BSSID field in the link identifier element (which can be set to 2.4 GHz AP-1 104, for example) to determine which link to use to discover and establish a TDLS link with the legacy peer STA.
[0057]
[0069] Embodiments may further provide for modifying the TDLS handshake to negotiate a TDLS Peer Key that is bound to both the affiliated AP and the AP MLD authenticator identifier during the TDLS setup phase, as shown in FIG. 5.
[0058]
[0070] 5 illustrates TDLS security operations between a legacy STA and a non-AP STA according to an embodiment of the present disclosure. As shown, a legacy STA-L 402 can establish a security association 404 with AP-1 104. The legacy STA-L can communicate with AP-1 104 over a link 406.
[0059]
[0071] Referring to Figure 5, the legacy STA-L 402 can determine whether it has established a TDLS link with an MLD or another legacy STA. If the legacy STA-L 402 receives a TDLS discovery response frame containing a link identifier element with the peer MAC address set to the non-AP MLD 112 and an ML element containing the MLD AP address, the legacy STA-L 402 can use the new "ML-TDLS" AKM during the TDLS setup frame exchange, as described further herein. Following the discovery and TDLS setup phases, the STA-L 402 can establish a TDLS link 502 with the non-AP MLD 112, as described further with reference to Figures 6 through 8.
[0060]
[0072] If the legacy STA-L 402 receives a TDLS response frame that contains a link identifier element that matches the peer STA address and does not contain an ML element, the legacy STA-L 402 is able to use the legacy TDLS AKM during the TDLS setup frame exchange.
[0061]
[0073] 6A, 6B, and 6C illustrate message flowcharts for TDLS setup between a legacy STA and a non-AP MLD according to an embodiment of the present disclosure. The message flowcharts of Figures 6A, 6B, and 6C may be based on the architecture shown in Figure 5. Those skilled in the art may recognize that non-AP STA-1 114 may connect to affiliated AP-1 104 as shown without an existing security association between the two, as described elsewhere herein.
[0062]
[0074] Referring to Figures 6A, 6B, and 6C, message flow 600 can enhance the TDLS discovery and setup (handshake) stages based on the content of the messages and how the content can be used in these stages, as described further herein.
[0063]
[0075] 6A, at 602, the legacy STA-L 402, or its software, can be updated or otherwise configured to perform the operations contemplated in method 600. As will be explained, these operations include, among other things, sending a TDLS discovery request message and a TDLS setup request, as described further herein. The TDLS discovery request message can include, for example, a link identifier that identifies one or more of AP-1, the STA-L, and a non-AP MLD, as described further herein.
[0064]
[0076] At 604, the affiliated AP-1 104 may transmit a beacon to the legacy STA-L 402 and the non-AP STA-1 114 that includes one or more of the following information: BSSID and Multi-Link Element (MLE). The BSSID may be the affiliated AP-1 MAC address. The Multi-Link Element (MLE) may include one or more of the AP MLD MAC address and the affiliated AP MAC address.
[0065]
[0077] Legacy STA-L 402 and non-AP STA-1 114 receive the beacons and thus know each other's addresses and AP MLDs. Legacy STA-L 402 can then discover that AP-1 104 is affiliated with AP MLD 102.
[0066]
[0078] At 606, the legacy STA-L 402 can transmit a TDLS discovery request to the non-AP MLD 112 via affiliated AP-1 104, bridging process 610, and non-AP STA-1 114, as shown.
[0067]
[0079] The legacy STA-L 402 may transmit 608 an encrypted TDLS discovery request to the AP-1 104 affiliated with the AP MLD 102. The encrypted TDLS discovery request may include one or more of a destination address (DA) configured for the non-AP MLD and a link identifier. The link identifier may identify one or more of AP-1, the STA-L, and the non-AP MLD, as shown. The designation of non-AP MLD in the link identifier may indicate that one end of the link is a non-AP MLD.
[0068]
[0080] As can be appreciated by one skilled in the art, the bridging process 610 may include routing the TDLS discovery request to the non-AP MLD 102 through one or more of the affiliated APs (e.g., AP-1 and AP-2) and the AP MLD 102.
[0069]
[0081] In an embodiment, the bridging process 610 may include affiliated AP-1 104 receiving and decrypting the encrypted TDLS discovery request. Affiliated AP-1 104 may determine that the TDLS discovery request is addressed to the non-AP MLD 112 and may relay 612 the decrypted TDLS discovery request to the AP MLD 102. The AP MLD 102 may re-encrypt the TDLS discovery request and relay 614 the re-encrypted TDLS discovery request back to AP-1 104 for transmission to the non-AP MLD 112.
[0070]
[0082] AP-1 104 can then transmit the re-encrypted TDLS discovery request at 616 to non-AP STA-1 114, as shown. Non-AP STA-1 114 can forward the re-encrypted TDLS discovery request to non-AP MLD 112 at 618.
[0071]
[0083] As can be appreciated by those skilled in the art, the bridging process 610 may occur for all message transmissions between the legacy STA-L 402 and the associated STAs (e.g., non-AP STA-1 114) of the non-AP MLD 112 for the TDLS discovery and setup (handshake) procedures.
[0072]
[0084] As can be appreciated by those skilled in the art, because legacy STA-L 402 has a security association, e.g., 404, with AP-1 104, as described elsewhere herein, messaging sent between the two over a communication link, e.g., 406, can be encrypted based on a first set of keys associated with the established security association 404. Similarly, because the communication link, e.g., 140, between STA-1 114 and AP-1 104 is based on a security association 202 between the AP MLD 102 and the non-AP MLD 112, a second set of keys can be used to encrypt messaging between STA-1 114 and AP-1 104, or between the otherwise non-AP MLD 112 and the AP MLD 102.
[0073]
[0085] At 620, the non-AP MLD 112 may perform decryption and process the decrypted TDLS discovery request. The non-AP MLD 112 may then create a TDLS discovery response frame. The TDLS discovery response frame may include one or more of a link identifier element and an ML element. The link identifier element may have a BSSID field set to AP-1, an initiator field set to legacy STA-L, and a responder field set to the non-AP MLD MAC address. The ML element may include one or more AP entity addresses.
[0074]
[0086] From the BSSID field in the link identifier element, the non-AP MLD 112 can discover that a TDLS link with the legacy STA-L may need to be established through the non-AP STA-1.
[0075]
[0087] At 622, the non-AP MLD 112 can transmit the TDLS discovery response to the legacy STA-L 402 via the non-AP STA-1 114, the bridging process 628, and the affiliated AP-1 104, as shown.
[0076]
[0088] At 624, the non-AP MLD 112 may encrypt the TDLS discovery response and transmit the encrypted TDLS discovery response to the non-AP STA-1 114. The TDLS discovery response may include one or more of the DA, link identifier, and ML elements configured for the STA-L. The link identifier may identify one or more of the AP-1, the STA-L, or the non-AP MLD.
[0077]
[0089] At 626, the non-AP STA-1 114 may send the encrypted TDLS discovery response to the affiliated AP-1 104. In an embodiment, the bridging process 628 may include, at 630, the affiliated AP-1 104 relaying the encrypted TDLS discovery response to the AP MLD 102. At 632, the AP MLD 102 may decrypt the encrypted TDLS discovery response and relay the decrypted TDLS discovery response to the affiliated AP-1 104 for transmission to the legacy STA-L 402.
[0078]
[0090] At 634 , the affiliated AP- 1 104 can re-encrypt the TDLS discovery response and transmit the re-encrypted TDLS discovery response to the legacy STA-L 402 .
[0079]
[0091] After receiving and decrypting the re-encrypted TDLS discovery response, legacy STA-L 402 may become aware that non-AP STA-1 114 is affiliated with non-AP MLD 112.
[0080]
[0092] As can be appreciated by one skilled in the art, the operations performed at 606 through 634 can be referred to as a TDLS discovery phase or procedure.
[0081]
[0093] Referring to FIG. 6B, as shown, at 636, the legacy STA-L 402 can transmit a TDLS setup request to the non-AP MLD 112 via the affiliated AP-1 104, the bridging process 640, and the non-AP STA-1 114.
[0082]
[0094] The legacy STA-L 402 may transmit 638 an encrypted TDLS setup request to the AP MLD 102's affiliated AP-1 104. The TDLS setup request may include one or more of the DA configured for the non-AP MLD, a Robust Security Network Element (RSNE) (e.g., RSNE(AKM=00-0F-AC:21)), a Link Identifier (Link ID), and an ML element (MLE), as shown. The Link Identifier may identify one or more of the AP-1, the STA-L, and the non-AP MLD. The MLE may include one or more of the AP entity addresses.
[0083]
[0095] In the TDLS Setup Request message, the legacy STA-L 402 can use the enhanced Multi-Link TPK (TDLS Peer Key) authentication and key management (AKM) combination exchanged within the RSNE. Because the legacy STA-L 402 knows that it will be establishing a TDLS connection with a non-AP MLD, the legacy STA-L 402 can use the new AKM. An exemplary embodiment of the definition of the new AKM combination is shown in FIG. 7 and will be further described herein.
[0084]
[0096] In some embodiments, enhanced AKM combinations may be required because the derivation of the TPK may involve multiple MAC addresses in the link identifier subfield. For example, the BSSID field may be set to AP-1, the initiator field may be set to legacy STA-L, and the responder field may be set to non-AP MLD.
[0085]
[0097] As can be appreciated by one skilled in the art, the bridging process 640 may be similar to the bridging process 610. The bridging process 640 may include routing the TDLS setup request through the AP MLD 102 and one or more of the affiliated APs (e.g., AP-1 and AP-2) to the non-AP MLD.
[0086]
[0098] In some embodiments, the bridging process 640 may include affiliated AP-1 104 receiving and decrypting the encrypted TDLS setup request. The affiliated AP-1 104 may relay 642 the decrypted TDLS setup request to the AP MLD 102. The AP MLD 102 may re-encrypt the decrypted TDLS setup request and relay 644 the re-encrypted TDLS setup request to AP-1 104 for transmission to the non-AP MLD 112 via non-AP STA-1 114.
[0087]
[0099] At 646, AP-1 104 may then transmit the re-encrypted TDLS setup request to non-AP STA-1 114, as shown. Non-AP STA-1 114 may forward the re-encrypted TDLS setup request to non-AP MLD 112, at 648.
[0088]
[0100] At 650, the non-AP MLD 112 can receive and decrypt the re-encrypted TDLS setup request message that includes the link identifier, and can derive the TPK (TDL key material) using equation (1) shown below.
[0089]
[0101]
[0090]
number
[0102] Referring to equation (1), MAC_I and MAC_R may be set to the legacy STA-L MAC address and the non-AP MLD MAC address. TPK-Key-Input may be defined according to equation (2) below.
[0091]
[0103]
[0092]
number
[0104] As can be appreciated by one skilled in the art, Equation 1 is an extension or update to existing TPK derivation functions that can be used by new AKMs.
[0093]
[0105] At 652, the non-AP MLD 112 can transmit the TDLS setup response to the legacy STA-L 402 via the non-AP STA-1 114, the bridging process 658, and the affiliated AP-1 104, as shown.
[0094]
[0106] At 654, the non-AP MLD 112 may encrypt the TDLS setup response and transmit the encrypted TDLS setup response to the non-AP STA-1 114. The TDLS setup response may include a link identifier and a new AKM suite identifier (e.g., as indicated by RSNE(AKM=00-0F-AC:21)) as shown. The TDLS setup response may further indicate one or more of: a DA indicating the STA-L; a link ID indicating one or more of AP-1, the STA-L, and the non-AP MLD; and an ML indicating one or more of the AP entity addresses (e.g., AP MLD addresses).
[0095]
[0107] At 656, non-AP STA-1 114 may transmit the encrypted TDLS setup response to affiliated AP-1 104. Affiliated AP-1 104 and AP MLD 102 may perform a bridging process 658, which may be similar to bridging process 628.
[0096]
[0108] In an embodiment, the bridging process 658 may include, at 660, the affiliated AP-1 104 relaying the encrypted TDLS setup response to the AP MLD 102. At 662, the AP MLD 102 may decrypt the encrypted TDLS setup response and relay the decrypted TDLS setup response to the affiliated AP-1 104 for transmission to the legacy STA-L 402.
[0097]
[0109] At 664 , the affiliated AP- 1 104 can re-encrypt the TDLS setup response and transmit the re-encrypted TDLS setup response to the legacy STA-L 402 .
[0098]
[0110] 6C, the legacy STA-L 402 can receive and decrypt the re-encrypted TDLS setup response at 666. The legacy STA-L 402 can then derive the TPK (TDLS key material) using equation (1) shown elsewhere in this application.
[0099]
[0111] At 668, the legacy STA-L 402 may transmit an encrypted TDLS setup confirm message to the non-AP MLD 112 via affiliated AP-1 104, bridging process 672, and non-AP STA-1 114, as shown. The TDLS setup confirm message may include one or more of a new link identifier and an AKM suite identifier (e.g., as indicated by RSNE(AKM=00-0F-AC:21)), as shown. The TDLS setup confirm message may further indicate one or more of: a DA indicating the non-AP MLD; a link ID indicating one or more of AP-1, the STA-L, and the non-AP MLD; and an ML indicating one or more AP entity addresses (e.g., AP MLD addresses).
[0100]
[0112] At 670, the legacy STA-L 402 may transmit the encrypted TDLS setup confirmation message to the affiliated AP-1 104. At 672, the affiliated AP-1 104 and the AP MLD 102 may perform a bridging process similar to the bridging processes 610 and 640.
[0101]
[0113] In an embodiment, the bridging process 672 may include the affiliated AP-1 104 receiving and decrypting the encrypted TDLS setup confirm message. The affiliated AP-1 104 may relay 674 the decrypted TDLS setup confirm message to the AP MLD 102. The AP MLD 102 may re-encrypt the TDLS setup confirm message and relay 676 the re-encrypted TDLS setup confirm message to the AP-1 104 for transmission to the non-AP MLD 112.
[0102]
[0114] AP-1 104 may then transmit the re-encrypted TDLS setup confirm message to non-AP STA-1 114 at 678, as shown. Non-AP STA-1 114 may forward the re-encrypted TDLS setup confirm message to non-AP MLD 112 at 680.
[0103]
[0115] The non-AP MLD 112 can then receive and decrypt the re-encrypted TDLS confirmation message. The TDLS setup confirmation message can complete the TDLS Peer Key (TPK) handshake. The operations performed in 636 through 680 may be referred to as the TDLS setup (handshake) phase or procedure.
[0104]
[0116] After the TPK handshake is complete, a Tunneled Direct Link (TDL) is assumed to be established, and the legacy STA-L 402 can communicate directly with the non-AP MLD 112 through the non-AP STA-1 114, at 682. Once the Tunneled Direct Link (TDL) is established, frames transmitted by the legacy STA-L can be received by the affiliated non-AP STA-1 114. Thus, the legacy STA-L 402 and the non-AP MLD 112 can then use the established TDL for traffic between their peers (the legacy STA-L 402 and the non-AP MLD 112) rather than using the links (e.g., 406 and 140) associated with the affiliated AP-1 104.
[0105]
[0117] As can be appreciated by those skilled in the art, to support compatibility with legacy devices, it is useful for communication between the legacy STA-L and affiliated STA-1 to resemble communication in a LAN. Thus, in some embodiments, the non-AP MLD may use a non-AP MLD address instead of the affiliated AP MAC address. Thus, frames transmitted by the non-AP MLD 112 to the legacy STA-L 402 may be set as follows: the RA (receiver address) may be set to the legacy STA-L, the TA (transmitter address) may be set to the non-AP MLD, and the DA (destination address) may be set to the legacy STA-L.
[0106]
[0118] Similarly, in some embodiments, frames transmitted by legacy STA-L 402 destined for non-AP MLD 112 may be set as follows: RA may be set to non-AP MLD, TA may be set to legacy STA-L, and DA may be set to non-AP MLD.
[0107]
[0119] In some embodiments, beacon 604 may be replaced by IP discovery. As a non-limiting example, a user may launch an app (e.g., YouTube®) on their phone and decide to post to their TV using, for example, a Chromecast device. Through discovery in the IP network, the phone will learn the IP address and MAC address of the Chromecast device. The phone will then send the TDLS discovery request described above with link identifier information using the MAC address of the Chromecast device. The Chromecast device will then receive the TDLS discovery request and respond with the TDLS discovery response described above.
[0108]
[0120] 7 illustrates an authentication and key management (AKM) combination according to an embodiment of the present disclosure. The AKM combination 700 may include assigned values, indicators, or definitions for one or more of the following: Organizationally Unique Identifier (OUI) (e.g., 00-0F-AC), Suite Type, Authentication, Key Management, Key Derivation, and Authentication Number, as shown, as well as other parameters defined in, for example, IEEE 802.11-2020.
[0109]
[0121] As an example, a suite type value of 21 may be assigned. The authentication indicator or definition may refer to "ML-TDLS." The key management indicator or definition may refer to "ML-TPK handshake." Those skilled in the art will recognize that other values may be assigned to the suite type and that other names may be used to indicate or define authentication and key management.
[0110]
[0122] 8A, 8B, and 8C show message flowcharts for TDLS setup between a legacy STA and a non-AP MLD according to another embodiment of the present disclosure. Those skilled in the art can understand that, although FIGS. 8A, 8B, and 8C may be similar to FIGS. 6A, 6B, and 6C, the TDLS discovery and setup (handshake) procedures are initiated by the non-AP MLD 112 in FIGS. 8A, 8B, and 8C, rather than by the legacy STA-L 402 (as in FIGS. 6A, 6B, and 6C). In other words, in FIGS. 8A, 8B, and 8C, the TDLS discovery request message and the TDLS setup request message are initiated and transmitted by the non-AP MLD, as shown and further described herein.
[0111]
[0123] Similar to message flow 600, message flow 800 can enhance the TDLS discovery and setup (handshake) stages based on the content of the messages and how that content may be used in these stages, as described further herein.
[0112]
[0124] 8A, at 802, the legacy STA-L 402, or its software, can be updated or otherwise configured to perform the operations contemplated in method 800. As will be explained, these operations include, among other things, sending a TDLS discovery request message and a TDLS setup response, as will be explained further herein.
[0113]
[0125] At 804, the affiliated AP-1 104 may transmit a beacon to the legacy STA-L 402 and the non-AP STA-1 114 that includes one or more of the following information: BSSID and Multi-Link Element (MLE). The BSSID may be the affiliated AP-1 MAC address. The Multi-Link Element (MLE) may include one or more of the AP MLD MAC address and the affiliated AP MAC address.
[0114]
[0126] Legacy STA-L 402 and non-AP STA-1 114 receive the beacon and are therefore able to know each other's address and AP MLD. Note that in some embodiments, IP discovery can be used instead of beacon 804, as described above.
[0115]
[0127] At 805, the non-AP MLD 112 may create a TDLS discovery request. The TDLS discovery request may include one or more of: a destination address (DA) configured for the STA-L, a link identifier, and a multi-link element (MLE). The multi-link element (MLE) may include one or more of an AP MLD MAC address and associated AP MAC addresses. The link identifier may identify one or more of the AP MLD, affiliated AP-1, the non-AP MLD, and the STA-L, as shown.
[0116]
[0128] At 806, the non-AP MLD 112 can transmit the TDLS discovery request to the legacy STA-L 402 via the legacy STA-L 402, the bridging process 812, and the affiliated AP-1 104, as shown.
[0117]
[0129] At 808, the non-AP MLD 112 may encrypt the TDLS discovery request and transmit the encrypted TDLS discovery request to the non-AP STA-1 114. At 810, the non-AP STA-1 114 may transmit the encrypted TDLS discovery request to the affiliated AP-1 104.
[0118]
[0130] At 812, the affiliated AP-1 104 and the AP MLD 102 may perform a bridging process 812. In an embodiment, the bridging process 812 may include routing the TDLS discovery request to the legacy STA-L 402 via one or more of the affiliated APs (e.g., AP-1 and AP-2) and the AP MLD 102.
[0119]
[0131] In an embodiment, the bridging process 812 may include the affiliated AP-1 104 relaying the encrypted TDLS discovery request to the AP MLD 102 at 814. The AP MLD 102 may decrypt the encrypted TDLS discovery request and relay it back to the affiliated AP-1 104 at 816.
[0120]
[0132] At 818, affiliated AP-1 104 can re-encrypt the decrypted TDLS discovery request and transmit the re-encrypted TDLS discovery request to legacy STA-L 402, as shown.
[0121]
[0133] The legacy STA-L 402 may perform the decryption and process the decrypted TDLS discovery request at 820. The legacy STA-L 402 may then become aware that the non-AP STA-1 114 is associated with the non-AP MLD 112 and that the AP-1 104 is an AP associated with the AP MLD 102.
[0122]
[0134] The legacy STA-L 402 may then create a TDLS discovery response frame. The TDLS discovery response frame may include one or more of the following: a modified link identifier element and an ML element. The modified link identifier element may have the BSSID field set to AP-1, the initiator field set to non-AP MLD, and the responder field set to the AP-1 MAC address. The ML element may include one or more AP entity addresses.
[0123]
[0135] At 822, the legacy STA-L 402 can transmit the TDLS discovery response to the non-AP MLD 112 via the affiliated AP-1 104, the bridging process 826, and the non-AP STA-1 114, as shown.
[0124]
[0136] At 824, the legacy STA-L 402 may encrypt the TDLS discovery response and transmit the encrypted TDLS discovery response to the affiliated AP-1 104. The TDLS discovery response may include one or more of the following: a DA configured for the non-AP MLD, a link identifier, and an ML element. The link identifier may identify one or more of the AP-1, the STA-L, or the non-AP MLD.
[0125]
[0137] At 826, affiliated AP-1 104 and AP MLD 102 may perform a bridging process. In an embodiment, the bridging process 826 may include affiliated AP-1 104 decrypting the encrypted TDLS discovery response and relaying it to the AP MLD 102 at 828. At 830, the AP MLD 102 may re-encrypt the decrypted TDLS discovery response and relay it back to affiliated AP-1 104 for transmission to the non-AP MLD 112 via non-AP STA-1 114.
[0126]
[0138] At 832, affiliated AP-1 104 can transmit the re-encrypted TDLS discovery response to non-AP STA-1 114. At 834, non-AP STA-1 114 can forward the re-encrypted TDLS discovery response to the non-AP MLD 112. The non-AP MLD 112 can receive and decrypt the re-encrypted TDLS discovery response.
[0127]
[0139] As can be appreciated by one skilled in the art, the operations performed at 806 through 834 can be referred to as a TDLS discovery phase or procedure.
[0128]
[0140] Referring to FIG. 8B, at 836, the non-AP MLD 112 can transmit a TDLS setup request to the legacy STA-L 402 via the non-AP STA-1 114, the bridging process 842, and the affiliated AP-1 104. The TDLS setup request can include one or more of a DA set configured for the legacy STA-L, a Robust Security Network Element (RSNE) (e.g., RSNE(AKM=00-0F-AC:21)), a link identifier, and an MLE, as shown. The link identifier can identify one or more of AP-1, the STA-L, and the non-AP MLD. The MLE can include one or more AP entity addresses. The non-AP MLD 112 can store the affiliated STA link address based on the BSSID received in the link ID.
[0129]
[0141] As described herein with reference to Figure 7, in the TDLS Setup Request message, the non-AP MLD 112 can use an extended multi-link TPK AKM suite. As described elsewhere herein, a new AKM suite may be required because the derivation of the TPK may involve multiple MAC addresses in the link identifier subfield. In an example where the initiator is a non-AP MLD, the BSSID field can be set to AP-1, the initiator field can be set to non-AP MLD, and the responder field can be set to legacy STA-L.
[0130]
[0142] The non-AP MLD 112 may transmit 838 the encrypted TDLS setup request to the non-AP STA-1 114. The non-AP STA-1 114 may transmit 840 the encrypted TDLS setup request to the affiliated AP-1 104.
[0131]
[0143] At 842, the affiliated AP-1 104 and the AP MLD 102 may perform a bridging process. In some embodiments, the bridging process 842 may include the affiliated AP-1 104 relaying the encrypted TDLS setup request to the AP MLD 102 at 844. The AP MLD 102 may decrypt the TDLS setup request and relay the decrypted TDLS setup request to the AP-1 104 at 846 for transmission to the legacy STA-L 402.
[0132]
[0144] At 848, AP-1 104 can re-encrypt the decrypted TDLS setup request and transmit the re-encrypted TDLS setup request to the legacy STA-L 402, as shown.
[0133]
[0145] At 850, the legacy STA-L 402 can receive and decrypt the re-encrypted TDLS Setup Request message containing the link identifier and can derive the TPK (TDLS key material) using equation (1) described herein.
[0134]
[0146] At 852, the legacy STA-L 402 can transmit the TDLS setup response to the non-AP MLD 112 via the affiliated AP-1 104, the bridging process 856, and the non-AP STA-1 114, as shown.
[0135]
[0147] At 854, the legacy STA-L 402 may encrypt the TDLS setup response and transmit the encrypted TDLS setup response to the affiliated AP-1 104. The TDLS setup response may include a link identifier and one or more of the new AKM suite identifiers (e.g., as indicated by RSNE(AKM=00-0F-AC:21)), as shown. The TDLS setup response may further indicate one or more of: a DA indicating a non-AP MLD; a link ID indicating one or more of AP-1, the non-AP MLD, and the STA-L; and an ML indicating one or more AP entity addresses (e.g., AP MLD addresses).
[0136]
[0148] Affiliated AP-1 104 and AP MLD 102 may then perform a bridging process 856. In an embodiment, the bridging process 856 may include, at 858, affiliated AP-1 104 decrypting the encrypted TDLS setup response and relaying it to the AP MLD 102. At 860, the AP MLD 102 may re-encrypt the TDLS setup response and relay it back to affiliated AP-1 104 for transmission to non-AP STA-1 114.
[0137]
[0149] At 862, affiliated AP-1 104 can transmit the re-encrypted TDLS setup response to non-AP STA-1 114. At 864, non-AP STA-1 114 can transmit the received re-encrypted TDLS setup response to non-AP MLD 112.
[0138]
[0150] 8C, the non-AP MLD 112 can receive and decrypt the re-encrypted TDLS setup response at 866. The non-AP MLD 112 can then derive the TPK (TDLS key material) using equation (1) shown elsewhere in this application.
[0139]
[0151] At 868, the non-AP MLD 112 may transmit an encrypted TDLS setup confirm message to the legacy STA-L 402 via the non-AP STA-1 114, the bridging process 874, and the affiliated AP-1 104, as shown. The TDLS setup confirm message may include one or more of a link identifier and an AKM suite identifier (e.g., as indicated by RSNE(AKM=00-0F-AC:21)), as shown. The TDLS setup confirm message may further indicate one or more of: a DA indicating the STA-L; a link ID indicating one or more of AP-1, the non-AP MLD, and the STA-L; and an ML indicating one or more of the AP entity addresses (e.g., AP MLD addresses).
[0140]
[0152] At 870, the non-AP MLD 112 may transmit the encrypted TDLS setup confirm message to the non-AP STA-1 114. At 872, the non-AP STA-1 114 may transmit the encrypted TDLS setup confirm message to the affiliated AP-1 104.
[0141]
[0153] At 874, affiliated AP-1 104 and AP MLD 102 may perform a bridging process. In an embodiment, the bridging process 874 may include affiliated AP-1 104 relaying the encrypted TDLS setup confirm message to the AP MLD 102 at 876. The AP MLD 102 may decrypt the TDLS setup confirm message and relay it back to affiliated AP-1 104 at 878.
[0142]
[0154] At 880, affiliated AP-1 104 can re-encrypt the decrypted TDLS setup confirmation message and transmit it to the legacy STA-L 402. The legacy STA-L 402 can then receive and decrypt the re-encrypted TDLS confirmation message.
[0143]
[0155] The TDLS setup confirm message may complete the TPK (TDLS Peer Key) handshake. The operations performed in 836 through 880 may be referred to as the TDLS setup (handshake) phase or procedure.
[0144]
[0156] After the TPK handshake is completed, a Tunneled Direct Link (TDL) is assumed to be established, and the legacy STA-L 402 can communicate directly with the non-AP MLD 112 through the non-AP STA-1 114 at 882.
[0145]
[0157] FIG. 9 shows a flowchart of a TDLS setup procedure according to an embodiment of the present disclosure. Procedure 900 can include, from the perspective of an STA, discovery procedures (e.g., 904 and 906) and TPK handshake procedures (e.g., 908-914), as described further herein. Procedure 900 can be from the perspective of either a legacy STA-L 402 or a non-AP MLD 112. In the case of a legacy STA-L 402, procedure 900 reflects the TDL setup of FIGS. 6A, 6B, and 6C described herein. In the case of a non-AP MLD 112, procedure 900 reflects the TDL setup of FIGS. 8A, 8B, and 8C described herein.
[0146]
[0158] The procedure 900 may begin at 902, where the STA may determine a peer STA MAC address from the LAN as a trigger for the TDL. For a legacy STA-L 402, 902 is reflected at 604 in FIG. 6A. For a non-AP MLD 112, 902 is reflected at 804 in FIG. 8A.
[0147]
[0159] The procedure 900 may further include the STA sending a TDLS discovery request at 904. In the case of a legacy STA-L 402, 904 is reflected at 606 in FIG. 6A. In the case of a non-AP MLD 112, 904 is reflected at 806 in FIG. 8A, in which case the TDLS discovery request includes a multi-link element (MLE).
[0148]
[0160] The procedure 900 may further include the STA receiving a TDLS discovery response at 906. For a legacy STA-L 402, 906 is reflected at 634 in FIG. 6A, in which case the TDLS discovery response includes an MLE. For a non-AP MLD 112, 906 is reflected at 834 in FIG. 8A.
[0149]
[0161] As can be appreciated by one skilled in the art, the operations performed at 904 and 906 may be referred to as a discovery procedure.
[0150]
[0162] The procedure 900 may further include, at 908, the STA using the enhanced AKM and including the MLE in the TDLS setup request. The procedure 900 may further include, at 910, the STA sending the TDLS setup request. For a legacy STA-L 402, 908 and 910 may be reflected at 636 in FIG. 6B. For a non-AP MLD 112, 908 and 910 may also be reflected at 836 in FIG. 8B, in which case the non-AP MLD 112 may store the affiliated STA link address based on the BSSID received in the link ID.
[0151]
[0163] The procedure 900 may further include the STA receiving the TDLS setup response and deriving TDLS key information at 912. For a legacy STA-L 402, 912 may be reflected as 664 and 666 in Figures 6B and 6C, in which case the legacy STA-L 402 may store the affiliated STA link address based on the BSSID received in the link ID. For a non-AP MLD 112, 912 may be reflected as 864 and 866 in Figures 8B and 8C.
[0152]
[0164] The procedure 900 may further include the STA sending a TDLS setup confirm message at 914. In the case of a legacy STA-L 402, 914 may be reflected at 668 in FIG. 6C. In the case of a non-AP MLD 112, 914 may be reflected at 868 in FIG. 8C, in which case the non-AP MLD 112 may set the affiliated link address to the MLD address for frames transmitted over the TDLS link.
[0153]
[0165] Embodiments may enhance the AP MLD's ability to correctly support TDLS security (key derivation) to enable the AP MLD to support features such as screen sharing between legacy screens (e.g., 802.11ax) and 802.11be mobile devices. Supporting TDLS security to enable features such as screen sharing may be essential for services such as Chromecast.
[0154]
[0166] Embodiments, as described herein, can allow for the capability and use of TDLS security in 802.11be multi-link devices and 802.11 legacy devices.
[0155]
[0167] As described herein, embodiments can provide for the derivation of a TDLS peer key between a legacy STA (e.g., 802.11ax) and an ML STA (e.g., 802.11be). The derivation of the TDLS peer key may use two authenticator identities, rather than one as described herein.
[0156]
[0168] Embodiments may further provide an enhanced authentication and key management suite as described herein. Embodiments may further provide for legacy STAs to determine that an AP (and affiliated APs) is MLD TDLS-capable, for example, based on notifications from the AP MLD (and affiliated APs) as described herein.
[0157]
[0169] Embodiments may further provide for establishing a TDL between a legacy STA and a non-AP MLD to allow traffic flow from the legacy STA and the non-AP MLD through an affiliated non-AP STA, as described herein.
[0158]
[0170] 10 is a schematic diagram of a UE 1000 capable of performing any or all of the operations of the above methods and features explicitly or implicitly described herein in accordance with various embodiments of the present invention. For example, a computer with network capabilities may be configured as the UE 1000. As can be recognized by those skilled in the art, the UE 1000 may represent one or more entities described herein, such as an AP, an AP MLD, an affiliated AP, a non-AP MLD, a STA, an affiliated STA, a legacy STA, or the like.
[0159]
[0171] As shown, UE 1000 may include a processor 1010, such as a central processing unit (CPU), a dedicated processor such as a graphics processing unit (GPU), or other such processor unit, memory 1020, non-transitory mass storage 1030, an input / output interface 1040, a network interface 1050, and a transceiver 1060, all of which are communicatively coupled via a bidirectional bus 1070. According to particular embodiments, any or all of the illustrated elements may be utilized, or only a subset of the elements may be utilized. Furthermore, UE 1000 may include multiple instances of a given element, such as multiple processors, memories, or transceivers. Elements of a hardware device may also be directly coupled to other elements without a bidirectional bus. In addition to or instead of the processor and memory, other electronic elements, such as integrated circuits, may be used to perform the necessary logical operations.
[0160]
[0172] The memory 1020 may include any type of non-transitory memory, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), read-only memory (ROM), any combination thereof, etc. The mass storage element 1030 may include any type of non-transitory storage device, such as a solid state drive, a hard disk drive, a magnetic disk drive, an optical disk drive, a USB drive, or any computer program product configured to store data and machine-executable program code. According to certain embodiments, the memory 1020 or mass storage 1030 may have statements and instructions stored thereon that are executable by the processor 1010 to perform any of the foregoing method operations described above.
[0161]
[0173] Embodiments of the present invention may be implemented using electronic hardware, software, or a combination thereof. In some embodiments, the invention is implemented by one or more computer processors executing program instructions stored in memory. In some embodiments, the invention is implemented partially or fully in hardware, for example, using one or more field programmable gate arrays (FPGAs) or application specific integrated circuits (ASICs) to rapidly perform processing operations.
[0162]
[0174] While specific embodiments of the present technology have been described herein for purposes of illustration, it will be understood that various modifications may be made. Accordingly, the specification and drawings should be considered merely as illustrative of the invention as defined by the appended claims, and are intended to cover any and all modifications, variations, combinations, or equivalents that fall within the scope of the invention. In particular, it is within the scope of the present technology to provide computer program products or program elements, or program storage or memory devices such as magnetic or optical wires, tapes, disks, etc., for storing machine-readable signals, for controlling the operation of a computer in accordance with the methods of the present technology, and / or for implementing some or all of its components in accordance with the systems of the present technology.
[0163]
[0175] The operations associated with the methods described herein may be embodied as coded instructions in a computer program product, which is a computer-readable medium having software code recorded thereon that performs the methods when the computer program product is loaded into memory and executed on a microprocessor of a wireless communication device.
[0164]
[0176] Furthermore, each operation of the method can be performed according to one or more program elements, modules, or objects, or portions thereof, created from any programming language, such as C++, Java, etc., on any computing device, such as a personal computer, a server, a PDA, etc. Furthermore, each operation, or a file or object implementing each operation, etc., may be performed by dedicated hardware or circuit modules designed for that purpose.
[0165]
[0177] Through the description of the foregoing embodiments, it has been understood that the present invention can be implemented by using hardware alone or by using software and a necessary universal hardware platform. Based on this understanding, the technical solutions of the present invention can be embodied in the form of a software product. The software product can be stored in a non-volatile or non-transitory storage medium, such as a compact disc read-only memory (CD-ROM), a USB flash disk, or a removable hard disk. The software product includes instructions that enable a computing device (personal computer, server, or network device) to execute the methods provided in the embodiments of the present invention. For example, such execution may correspond to simulating logic operations as described herein. The software product can additionally or alternatively include instructions that enable a computing device to execute operations for constructing or programming a digital logic device according to the embodiments of the present invention.
[0166]
[0178] While the invention has been described with reference to particular features and embodiments thereof, it will be apparent that various modifications and combinations may be made thereto without departing from the invention. Accordingly, the specification and drawings are to be considered merely as illustrative of the invention as defined by the appended claims, and are intended to cover any and all modifications, variations, combinations, or equivalents.
Claims
1. transmitting a discovery request from a first station to a second station via an access point (AP) connected to each of the first station and the second station to obtain identification information from the second station, wherein only one of the first station and the second station has an affiliation relationship with a non-access point multi-link device (non-AP MLD); and receiving, at the first station, a discovery response from the second station via the AP, the discovery response providing the identification information; the identification information includes a link identifier indicating an affiliation relationship with the non-AP MLD; The AP MLD is in an affiliate relationship with one or more affiliate APs, the one or more affiliate APs including the AP; and At least one of the discovery request and the discovery response includes a multi-link element (MLE) indicating at least one of the MAC addresses of the one or more affiliate APs and each of the AP MLDs.
2. 10. The method of claim 1, further comprising: receiving, at the first station, a message from the AP indicating a MAC address of the second station; The method further comprises:
3. 3. The method of claim 1 or 2, further comprising: sending a setup request from the first station to the second station via the AP; receiving, at the first station, a setup response from the second station via the AP; A method comprising:
4. 4. The method of claim 3, Only one of the first station and the second station having an affiliation relationship with the non-AP MLD is an affiliated station; one of the first station and the second station that lacks an affiliation relationship with the non-AP MLD is a non-affiliated station; The method, wherein the setup request indicates an authentication and key management (AKM) suite for establishing a link between the non-affiliated station and the AP MLD via the affiliated station.
5. 5. The method of claim 4, further comprising: the first station deriving a key based on the AKM suite; and sending a setup confirmation message from the first station to the second station via the AP; A method comprising:
6. The method of claim 5, wherein the key is derived according to each of the AP MLD and the non-AP MLD's respective MAC addresses.
7. 7. The method according to claim 5 or 6, The non-affiliated station has a security association with the AP via a first authenticator associated with the AP; and The non-AP MLD has a security association with the AP MLD via a second authenticator associated with the AP MLD; The method, wherein the key is bound to each of the first authenticator and the second authenticator.
8. receiving, at the first station, a discovery request from a second station regarding identification information from the first station, wherein only one of the first station and the second station has an affiliation relationship with a non-access point (AP) multi-link device (MLD) (non-AP MLD), the discovery request being received via an AP connected to each of the first station and the second station, the AP having an affiliation relationship with the AP MLD, and the AP MLD providing the AP with connectivity to a network; and transmitting a discovery response from the first station to the second station via the AP, the discovery response providing the identification information, the identification information including a link identifier indicating an affiliation relationship with a non-AP MLD; wherein the AP MLD is in an affiliate relationship with one or more affiliate APs, the one or more affiliate APs including the AP; and At least one of the discovery request and the discovery response includes a multi-link element (MLE) indicating at least one of the MAC addresses of the one or more affiliate APs and each of the AP MLDs.
9. 10. The method of claim 8, further comprising: receiving, at the first station, a message indicating a MAC address of the second station from an AP connected to each of the first station and the second station; A method comprising:
10. 10. The method according to claim 8 or 9, Only one of the first station and the second station having an affiliation relationship with the non-AP MLD is an affiliated station; one of the first station and the second station that lacks an affiliation relationship with the non-AP MLD is a non-affiliated station; The method further comprises: receiving, at the first station, a setup request from the second station via the AP indicating an authentication and key management (AKM) suite for establishing a link between the non-affiliated station and the non-AP MLD via the affiliated station; the first station deriving a key based on the AKM suite; and transmitting a setup response from the first station to the second station via the AP indicating the AKM suite; A method comprising:
11. 11. The method of claim 10, further comprising: receiving, at the first station, a setup confirmation message from the second station indicating establishment of the link between the non-affiliated station and the non-AP MLD via the affiliated station; A method comprising:
12. 1. A system including a first station and a second station, wherein only one of the first station and the second station has an affiliation relationship with a non-access point multi-link device (non-AP MLD); the first station is configured to send a discovery request to the second station to obtain identification information from the second station; the second station is configured to transmit a discovery response to the first station providing the identification information; the identification information includes a link identifier indicating an affiliation relationship with the non-access point (AP) multi-link device (MLD); the first station is further configured to send a setup request indicating an authentication and key management (AKM) suite to the second station via an AP connected to each of the first station and the second station; and When the setup request is received, the second station: Deriving a first key based on the AKM suite; and The system is further configured to send a setup response to the first station via the AP.
13. 13. The system of claim 12, wherein: the first station is further configured to receive a message from the AP indicating a MAC address of the second station; and The second station is further configured to receive a message from the AP indicating a MAC address of the first station.
14. 14. The system according to claim 12 or 13, wherein: Only one of the first station and the second station having an affiliation relationship with the non-AP MLD is an affiliated station; one of the first station and the second station that lacks an affiliation relationship with the non-AP MLD is a non-affiliated station; The first station is further configured to derive a second key based on the AKM suite and the setup response; and to send a setup confirmation message to the second station via the AP indicating establishment of a link between the non-affiliated station and the non-AP MLD via the affiliated station; and The second station is further configured to receive the setup confirmation message from the first station via the AP.
15. 15. The system according to any one of claims 12 to 14, a non-affiliated station having a security association with the AP via a first authenticator associated with the AP; The non-AP MLD has a security association with the AP MLD via a second authenticator associated with the AP MLD; and The system, wherein the first key and second key are respectively bound to each of the first authenticator and the second authenticator.
16. A computer-readable storage medium storing instructions that, when executed by a processor, cause an electronic device to perform the method of any one of claims 1 to 11.
Citation Information
Patent Citations
Method and apparatus for establishing security association between nodes of an ad hoc wireless network
US20080065884A1