Devices and methods for multi-link operation in a WLAN

The solution for non-colocated MLDs in IEEE 802.11 WLANs involves deriving and distributing cryptographic keys using nonces and a key derivation function to address roaming challenges, ensuring efficient and secure communication across multiple links.

WO2026032501A1PCT designated stage Publication Date: 2026-02-12HUAWEI TECH CO LTD +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/EP2024/072384
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-08-07
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

Existing IEEE 802.11 WLAN standards face limitations in non-colocated Multi-Link Operation (MLO) due to tight operational timing requirements and the need for dynamic key management during roaming between affiliated access points and stations.

Method used

Implementing a mechanism for non-colocated Multi-Link Devices (MLDs) to derive and distribute new cryptographic keys using nonces and a key derivation function, allowing seamless roaming and association maintenance across multiple links.

Benefits of technology

Enables efficient and secure communication by dynamically generating link-specific keys, facilitating smooth roaming and maintaining association without communication delays or bandwidth limitations in non-colocated MLO scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure EP2024072384_12022026_PF_FP_ABST
    Figure EP2024072384_12022026_PF_FP_ABST
Patent Text Reader

Abstract

An access point, AP, Multi-Link Device, MLD, with a plurality of affiliated APs for communication via a plurality of links with a non-AP MLD with a plurality of affiliated non-AP stations. The AP MLD comprises processing circuitry configured to receive an ML Reconfiguration Request frame from the non-AP MLD, wherein the ML Reconfiguration Request frame comprises an indication of a first and a second affiliated AP and a first nonce. Moreover, the processing circuitry is configured to send an ML Reconfiguration Response frame to the non-AP MLD, wherein the ML Reconfiguration Response frame comprises a second nonce, and to provide one or more local link keys based on the first and second nonce to the second affiliated AP.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DEVICES AND METHODS FOR MULTI-LINK OPERATION IN A WLAN

[0002] TECHNICAL FIELD

[0003] The present invention relates to wireless communications. More specifically, the present invention relates to devices and methods for Multi-Link Operation, MLO, in a wireless local area network, WLAN, in particular a WLAN (also referred to as a Wi-Fi network) according to the IEEE 802.11 framework of standards.

[0004] BACKGROUND

[0005] Wireless Local Area Network (WLAN) technology as defined by the IEEE 802.11 framework of standards is being enhanced with an objective of improving both throughput and reliability. IEEE 802.1 Ibe has introduced multi-link operation (MLO) that allows a multi-link device (MED), for instance, an access point, AP, MLD, to communicate with a peer MLD, for instance, a non-AP MLD, through affiliated stations using one or multiple setup links simultaneously. An AP MLD has one or more affiliated APs, where each affiliated AP is operating on a different link. Similarly, a non-AP MLD has one or more affiliated non-AP STAs, where each affiliated non-AP STA is operating on a different link. Functionality-wise, an MLD can be also viewed as composed of an Upper MAC sublayer and a Lower MAC sublayer, where the affiliated STAs are implemented in the Lower MAC sublayer.

[0006] An MLD as defined in IEEE 802.1 Ibe is assumed to operate as a co-located MLD, where the Upper MAC sublayer and the Lower MAC sublayer reside in the same device. Thus, for a co-located MLD there are no communication delays between layers, no limitations on the information that can be exchanged, and static (i.e. non-dynamic) fragmentation is not permitted. A further standards amendment is looking to define Non-Colocated, NC, MLO, where the MLD Upper MAC sublayer and the MLD Lower MAC sublayer are considered as different entities / components that can be at different physical locations (i.e. non-colocated entities). However, NC MLO is limited, for instance, by tight operational timing requirements defined for colocated MLO.

[0007] SUMMARY

[0008] It is an objective of the present disclosure to provide improved devices and methods for Multi-Link Operation; MLO, in a wireless local area network, WLAN, in particular a WLAN according to the IEEE 802.11 framework of standards.

[0009] The foregoing and other objectives are achieved by the subject matter of the independent claims. Further implementation forms are apparent from the dependent claims, the description and the figures.

[0010] According to a first aspect an access point, AP, Multi-Link Device, MLD, is provided with a plurality of affiliated APs for communication via a plurality of links with a non-AP MLD with a plurality of affiliated non-AP stations. The AP MLD according to the first aspect comprises processing circuitry, which in an implementation form may implement an upper MAC layer, configured to receive an ML Reconfiguration Request frame from the non-AP MLD, wherein the ML Reconfiguration Request frame comprises an indication of a first current and a second target affiliated AP of the plurality of affiliated APs and a first nonce. Moreover, the processing circuitry, e.g. the upper MAC layer of the AP MLD according to the first aspect is configured to send an ML Reconfiguration Response frame to the non-AP MLD, wherein the ML Reconfiguration Response frame comprises a second nonce. The processing circuitry, e.g. the upper MAC layer of the AP MLD according to the first aspect, is further configured to provide one or more local link keys, i.e. link specific keys based on, i.e. derived from the first and second nonce to the second target affiliated AP. The second target affiliated AP of the AP MLD according to the first aspect is configured to establish, i.e. setup a new link with the non-AP MLD using the one or more local link keys received from the processing circuitry, i.e. the upper MAC layer and the first current affiliated AP of the AP MLD according to the first aspect is configured to disconnect, i.e. remove a current link with the non-AP MLD. The AP MLD according to the first aspect, allows the non-AP MLD to roam between affiliated APs of the AP MLD according to the first aspect, maintaining their association, deriving new keys each time a new link is established between the non-AP MLD and one of the affiliated APs of the AP MLD according to the first aspect.

[0011] In a further possible implementation form, the processing circuitry, e.g. the upper MAC layer of the AP MLD according to the first aspect is configured to receive an ML Reconfiguration Confirm frame via the new link from the non-AP MLD.

[0012] In a further possible implementation form, the ML Reconfiguration Confirm frame comprises a status code indicative of whether the setup of the new link was either successful or otherwise (e.g. a warning code).

[0013] In a further possible implementation form, the processing circuitry, e.g. the upper MAC layer of the AP MLD according to the first aspect is configured to generate the one or more local link keys (i.e. link specific) keys based on the first and second nonce.

[0014] In a further possible implementation form, the first nonce (herein also referred to as Snonce) comprises a first random number and the second nonce (herein also referred to as Anonce) comprises a second random number.

[0015] In a further possible implementation form, the processing circuitry, e.g. the upper MAC layer of the AP MLD according to the first aspect is configured to establish, i.e. generate the one or more local link keys, i.e. link specific keys based on the first and second nonce using a key derivation function, KDF, and a key derivation key, KDK, established between the AP MLD according to the first aspect and the non-AP MLD.

[0016] In a further possible implementation form, the indication of the first current and the second target affiliated AP comprises a first address, in particular a MAC address, of the first current affiliated AP and a second address, in particular a MAC address, of the second target affiliated AP.

[0017] In a further possible implementation form, the AP MLD is a non-colocated AP MLD and / or the non-AP MLD is a noncolocated non-AP MLD.

[0018] According to a second aspect a method is provided for operating an access point, AP, Multi-Link Device, MLD, with a plurality of affiliated APs for communication via a plurality of links with a non-AP MLD with a plurality of affiliated non- AP stations. The method according to the second aspect comprises the following steps implemented by a processing circuitry, e.g. the upper MAC layer of the AP MLD: receiving an ML Reconfiguration Request frame from the non-AP MLD, wherein the ML Reconfiguration Request frame comprises an indication of a first current and a second target affiliated AP of the plurality of affiliated APs and a first nonce; sending an ML Reconfiguration Response frame to the non-AP MLD, wherein the ML Reconfiguration Response frame comprises a second nonce; and providing one or more local link keys, i.e. link specific keys based on, i.e. derived from the first and second nonce to the second target affiliated AP; wherein the method according to the second aspect further comprises a step of establishing a new link with the non-AP MLD using the one or more local link keys received from the processing circuitry, i.e. the upper MAC layer implemented by the second target affiliated AP of the AP MLD and a step of disconnecting, i.e. removing a current link with the non-AP MLD implemented by the first current affiliated AP.

[0019] The method according to the second aspect can be performed by the AP MLD according to the first aspect. Thus, further features of the method according to the second aspect result directly from the functionality of the AP MLD according to the first aspect as well as its different implementation forms described above and below.

[0020] According to a third aspect a non-access point, non-AP, Multi-Link Device, MLD, is provided with a plurality of affiliated non-AP stations for communication via a plurality of links with an AP MLD with a plurality of affiliated APs. The non-AP MLD according to the third aspect comprises processing circuitry, in particular an upper MAC layer, configured to send an ML Reconfiguration Request frame to the AP MLD, wherein the ML Reconfiguration Request frame comprises an indication of a first current and a second target affiliated AP of the plurality of affiliated APs of the AP MLD and a first nonce.

[0021] Moreover, the processing circuitry, in particular an upper MAC layer, of the non-AP MLD according to the third aspect is configured to receive an ML Reconfiguration Response frame from the AP MLD, wherein the ML Reconfiguration Response frame comprises a second nonce, and to provide one or more local link keys, i.e. link specific keys based on, i.e. derived from the first and second nonce to the affiliated non-AP station having a current link with the first current affiliated AP of the AP MLD. The affiliated non-AP station having the current link with the first current affiliated AP of the AP MLD is configured to establish, i.e. setup a new link with the second target affiliated AP of the AP MLD using the one or more local link keys received from the processing circuitry, in particular an upper MAC layer of the non-AP MLD according to the third aspect for transitioning to the second target affiliated AP of the AP MLD. Thus, the non-AP MLD according to the third aspect can roam between affiliated APs of the AP MLD, maintaining their association, deriving new keys each time a new link is established between the non-AP MLD according to the third aspect and one of the affiliated APs of the AP MLD.

[0022] In a further possible implementation form, the processing circuitry, in particular an upper MAC layer, of the non-AP MLD according to the third aspect, is configured to send an ML Reconfiguration Confirm frame via the new link to the AP MLD.

[0023] In a further possible implementation form, the ML Reconfiguration Confirm frame comprises a status code indicative of whether the setup of the new link was either successful or otherwise (e.g. a warning code).

[0024] In a further possible implementation form, the processing circuitry, in particular an upper MAC layer, of the non-AP MLD according to the third aspect, is configured to generate the one or more local link keys, i.e. link specific keys based on the first and second nonce.

[0025] In a further possible implementation form, the first nonce (herein also referred to as Snonce) comprises a first random number and the second nonce (herein also referred to as Anonce) comprises a second random number.

[0026] In a further possible implementation form, the processing circuitry, in particular an upper MAC layer, of the non-AP MLD according to the third aspect is configured to generate the one or more local link keys, i.e. link specific keys based on the first and second nonce using a key derivation function, KDF, and a key derivation key, KDK, established between the AP MLD and the non-AP MLD according to the third aspect.

[0027] In a further possible implementation form, the indication of the first current and of the second target affiliated AP comprises a first address, in particular a MAC address, of the first current affiliated AP and a second address, in particular a MAC address, of the second target affiliated AP. In a further possible implementation form, the processing circuitry, in particular an upper MAC layer, of the non-AP MLD according to the third aspect is configured to send the ML Reconfiguration Request frame to the AP MLD, in response to being triggered to transition, i.e. roam from the first current affiliated AP to the second target affiliated AP.

[0028] In a further possible implementation form, the non-AP MLD according to the third aspect is a non-colocated non-AP MLD and / or the AP MLD is a non-colocated AP MLD.

[0029] According to a fourth aspect a method is provided for operating a non-access point, non-AP, Multi-Link Device, MLD, with a plurality of affiliated non-AP stations for communication via a plurality of links with an AP MLD with a plurality of affiliated APs. The method according to the fourth comprises the following steps implemented by processing circuitry, in particular an upper MAC layer, of the non-AP MLD: sending an ML Reconfiguration Request frame to the AP MLD, wherein the ML Reconfiguration Request frame comprises an indication of a first current and a second target affiliated AP of the plurality of affiliated APs of the AP MLD and a first nonce; receiving an ML reconfiguration Response frame from the AP MLD, wherein the ML Reconfiguration Response frame comprises a second nonce; and providing one or more local link keys, i.e. link specific keys based on, i.e. derived from the first and second nonce to the affiliated non-AP station having a link with the first current affiliated AP of the AP MLD; wherein the method according to the fourth aspect further comprises a step, implemented by the affiliated non-AP station having the link with the first current affiliated AP of the AP MLD, of establishing a new link with the second target affiliated AP of the AP MLD based on the one or more local link keys received from the processing circuitry, in particular an upper MAC layer, for transitioning to the second target affiliated AP of the AP MLD.

[0030] The method according to the fourth aspect can be performed by the non-AP MLD according to the third aspect. Thus, further features of the method according to the fourth aspect result directly from the functionality of the non-AP MLD according to the third aspect as well as its different implementation forms described above and below.

[0031] According to a fifth aspect a computer program product is provided, comprising program code which causes a computer or a processor to perform the method according to the second aspect or the method according to the fourth aspect, when the program code is executed by the computer or the processor.

[0032] Details of one or more embodiments are set forth in the accompanying drawings and the description below. Other features, objects, and advantages will be apparent from the description, drawings, and claims.

[0033] BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In the following, embodiments of the present disclosure are described in more detail with reference to the attached figures and drawings, in which:

[0035] Fig. 1 shows a schematic diagram illustrating an AP MLD according to an embodiment with a plurality of affiliated APs in communication via a plurality of links with a non-AP MLD according to an embodiment with a plurality of affiliated non-AP stations; Fig. 2 shows a schematic diagram illustrating a colocated AP MLD according to an embodiment with a plurality of affiliated APs in communication via a plurality of links with a colocated non-AP MLD according to an embodiment with a plurality of affiliated non-AP stations;

[0036] Fig. 3a shows a schematic diagram illustrating a non-colocated AP MLD according to an embodiment with a plurality of affiliated APs;

[0037] Fig. 3b shows a schematic diagram illustrating non-colocated AP MLD according to an embodiment with a plurality of affiliated APs in communication via a plurality of links with a non-colocated non-AP MLD according to an embodiment with a plurality of affiliated non-AP stations;

[0038] Fig. 4 shows a schematic diagram illustrating a mode 1 MLO of a non-colocated AP MLD according to an embodiment with a plurality of affiliated APs in communication via a plurality of links with a non-AP MLD according to an embodiment;

[0039] Fig. 5 shows a schematic diagram illustrating a mode 2 MLO with local bridging of a non-colocated AP MLD according to an embodiment with a plurality of affiliated APs in communication via a plurality of links with a non-AP MLD according to an embodiment;

[0040] Fig. 6 shows a table summarizing differences between mode 1 and mode 2 MLO implemented by an AP MLD according to an embodiment;

[0041] Fig. 7 shows a signaling diagram illustrating a local data path message flow between an AP MLD according to an embodiment with its affiliated APs and a non-AP MLD according to an embodiment with its affiliated non-AP stations for implementing a roaming procedure;

[0042] Fig. 8 shows a signaling diagram illustrating in more detail a local data path message flow, including the exchange of an ML Reconfiguration Confirm frame, between an AP MLD according to an embodiment with its affiliated APs and a non-AP MLD according to an embodiment with its affiliated non-AP stations for implementing a roaming procedure;

[0043] Fig. 9 shows a schematic diagram illustrating the architecture of an ML Reconfiguration Confirm frame exchanged between an AP MLD and a non-AP MLD according to an embodiment;

[0044] Fig. 10 shows a diagram illustrating a key hierarchy implemented by an AP MLD and a non-AP MLD according to an embodiment;

[0045] Fig. 11 shows a flow diagram illustrating steps of a method of operating an AP MLD according to an embodiment; and

[0046] Fig. 12 shows a flow diagram illustrating steps of a method of operating a non-AP MLD according to an embodiment.

[0047] In the following, identical reference signs refer to identical or at least functionally equivalent features.

[0048] DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] In the following description, reference is made to the accompanying figures, which form part of the disclosure, and which show, by way of illustration, specific aspects of embodiments of the present disclosure or specific aspects in which embodiments of the present disclosure may be used. It is understood that embodiments of the present disclosure may be used in other aspects and comprise structural or logical changes not depicted in the figures. The following detailed description, therefore, is not to be taken in a limiting sense, and the scope of the present disclosure is defined by the appended claims.

[0050] For instance, it is to be understood that a disclosure in connection with a described method may also hold true for a corresponding device or system configured to perform the method and vice versa. For example, if one or a plurality of specific method steps are described, a corresponding device may include one or a plurality of units, e.g. functional units, to perform the described one or plurality of method steps (e.g. one unit performing the one or plurality of steps, or a plurality of units each performing one or more of the plurality of steps), even if such one or more units are not explicitly described or illustrated in the figures. On the other hand, for example, if a specific apparatus is described based on one or a plurality of units, e.g. functional units, a corresponding method may include one step to perform the functionality of the one or plurality of units (e.g. one step performing the functionality of the one or plurality of units, or a plurality of steps each performing the functionality of one or more of the plurality of units), even if such one or plurality of steps are not explicitly described or illustrated in the figures. Further, it is understood that the features of the various exemplary embodiments and / or aspects described herein may be combined with each other, unless specifically noted otherwise.

[0051] Figure 1 shows an access point Multi-Link Device, AP MLD, 110 with a plurality of affiliated access points, APs, 113a-c communicating via a plurality of setup links 130a,b (for instance a 2.4 GHz link 130a and a 5 GHz link 130b) with a plurality of the corresponding non-AP stations 123a, b affiliated with a further associated non-AP MLD 120 in a wireless local area network, WLAN, 100 in particular an IEEE 802.11 based WLAN (also referred to as a Wi-Fi network 100), using a MultiLink Operation, MLO, mode. The MLD 110 with the affiliated APs 113a-c is herein also referred to as AP MLD 110, while the further or peer MLD 120 with the affiliated non-AP stations 123a, b is referred to as non-AP MLD 120. For the most part, data and most management traffic may be exchanged directly between the MLDs 110, 120 through one or more of the affiliated APs 113a, b. Control traffic, however, is usually exchanged between the affiliated non-AP STAs 123a, b and the affiliated APs 113a,b on a given link 130a or 130b. In the MLO mode communications between the two MLDs 110, 120 may use either one of the independently operating radio links 130a,b.

[0052] As will be appreciated, MLO at the MAC layer together with a multi-link device (MLD), such as the AP MLD 110 and the non-AP MLD 120, has been introduced in IEEE 802.1 Ibe. MLO provides requirements for MLDs to maintain multiple WLAN connections across multiple links. A multiple link may also include a single radio STA that is able to multiplex between different frequency bands providing multiple logical WLAN connections. It allows traffic to flow on multiple links and provides a performance gain of using multiple channels. As already described above, each link, such as the links 130a, b shown in figure 1, is established during an ML setup procedure between STAs affiliated with the MLDs.

[0053] In an embodiment, the MLDs 110, 120 may each comprise processing circuitry 111, 121, for instance, one or more processors or CPUs for processing data as well as implementing a respective Upper MAC Layer 111, 121. The processing circuitry 111, 121 may be implemented in hardware and / or software and may comprise digital circuitry, or both analog and digital circuitry. Digital circuitry may comprise components such as application-specific integrated circuits (ASICs), field- programmable gate arrays (FPGAs), digital signal processors (DSPs), or general-purpose processors. The MLDs 110, 120 may further each comprise a memory configured to store executable program code which, when executed by the processing circuitry 111, 121, causes the respective MLD 110, 120 to perform the functions and methods described herein.

[0054] Before describing detailed embodiments of the AP MLD 110 and the non-AP MLD 120, in the following some technical background as well as terminology will be introduced making use of one or more of the following abbreviations and / or acronyms: AP Access Point

[0055] BA Block Acknowledgement

[0056] BSS Basic Service Set

[0057] DS Distribution System

[0058] FT Fast Transition

[0059] KDK Key Derivation Key

[0060] MAC Medium Access Control

[0061] MLD Multi-Link Device

[0062] MLO Multi-Link Operation

[0063] MPDU MAC Protocol Data Unit

[0064] MSDU MAC Service Data Unit

[0065] MMPDU MAC Management Protocol Data Unit

[0066] NC Non-Colocated

[0067] PTK Pairwise Transient Key

[0068] STA Station

[0069] TID Traffic Identifier

[0070] WLAN Wireless Local Area Network

[0071] As used herein, an access point (AP) is a special type of wireless station (STA) that provides access to other networks. An AP can support many connected non-AP STAs. APs use control information to control traffic flow over the wireless medium among all associated non-AP STAs within a BSS.

[0072] As used herein, there are three main types of frames communicated between WLAN STAs, namely data, management, and control frames. Data traffic is exchanged between the AP and one or more stations (STAs) in a WLAN to facilitate communication. The data frames are either generated by the one or more non-AP MLDs or by an external network. This traffic is delivered in a secured manner over the WLAN when the AP and the corresponding non-AP STAs negotiate a cryptographic encapsulation method and keys to encrypt the data traffic. Management traffic is exchanged between the AP and one or more non-AP STAs in a BSS to establish and maintain state of data communications. Security can be negotiated to encrypt or sign management traffic. Control traffic is exchanged between the AP and the non-AP STAs in a BSS to control the flow of the data frame exchange.

[0073] As defined in the IEEE 802.11 framework of standards and as used herein, a MAC Service Data Unit, MSDU, refers to data information that is exchanged with the logical link control (LLC) to higher protocol layers, or to a bridge port.

[0074] An MAC Protocol Data Unit, MPDU, takes the MSDU and maps the information to an 802.11 Data frame by including header information such as address information, a sequence number (SN), QoS information, and CRC checksum, as well as the data payload itself. If secure communication is negotiated between peer MACs, the MPDU is cryptographically encapsulated. A cryptographically encapsulated MPDU also includes a packet number (PN) that is used to perform replay detection for the received data and during the operation of data encryption / decryption.

[0075] Another form of payload of the MPDU is an MMPDU (MAC Management Protocol Data Unit) which is transported in one or more management frames. The MMPDU occupies a position in the management plane similar to that of the MSDU in the data plane. In WLAN network communications, data can be aggregated using either MSDUs or MPDUs.

[0076] When MSDU aggregation is negotiated, several MSDUs are grouped into a single A-MSDU (aggregate-MSDU). The A- MSDU is used to form the pay load of an MPDU. When, MAC peers establish a block ack (acknowledgement) agreement per TID, transmission of A-MPDUs (aggregated MPDUs) that contain MPDUs of that TID can be applied. An A-MPDU consist of several MPDUs that are transmitted for a specific STA within a single PHY protocol data unit (PPDU). A Block acknowledgement (BA) is used to efficiently communicate the status of the reception of the transmitted A-MPDUs.

[0077] IEEE 802.1 Ibe has introduced a multi- link device (MED), such as the AP MLD 110 and the non-AP MED 120 illustrated in figure 1. The MLDs 110, 120 communicate over multiple WLAN radio links 130a,b that have been setup between the AP MLD 110 and its associated non-AP MLD 120. The ML setup allows traffic to flow on multiple setup links and provides a performance gain of using multiple channels. The AP MLD 110 has one or more affiliated APs 113a-c, where each affiliated AP 113a-c is operating on a different channel 130a-c. Similarly, the non-AP MLD 120 has one or more affiliated non-AP STAs 123a, b, where each affiliated non-AP STA 123a, b is operating on a different setup link 130a,b.

[0078] In Figure 1, the AP MLD 110 has 3 different links. The non-AP MLD 120 has been associated with the AP MLD 110 by setting up 2 links 130a,b with the AP MLD 110, on which the frames exchanged between the AP MLD 110 and the non-AP MLD 130 can be transmitted.

[0079] An MLD as defined in IEEE 802.1 Ibe, is assumed to operate as a colocated MLD, as will be detailed hereinafter. Figure 2 illustrates a colocated AP MLD 110 according to an embodiment in communication with a colocated non-AP MLD 120 according to an embodiment via three different links. The LLCs 105, 125 provide a respective interface to an external network or a part of a protocol stack of the respective colocated MLD 110, 120.

[0080] As will be appreciated, for the colocated MLDs 110, 120 illustrated in figure 2 the affiliated APs 113a-c and STAs 123a-c as part of a respective Lower MAC sublayer 112, 122 are colocated with the respective processing circuitry 111, 121 implementing the respective Upper MAC sublayer 111, 121, i.e. are integrated within the same device. Consequently, there is no communication delay between layers, there is no limitation on the information that can be exchanged, and static (i.e. nondynamic) fragmentation is not permitted.

[0081] A further amendment is looking to define non-colocated, NC, MLO, where the MLD Upper MAC sublayer and the MLD Lower MAC sublayer are considered as different components that can be at different physical locations (i.e. NC components or entities) of an MLD.

[0082] Figures 3a and 3b show schematic diagrams illustrating a NC AP MLD 110 according to an embodiment with a plurality of affiliated APs 113a-c in communication via a plurality of links 130a-c with a NC non-AP MLD 120 according to an embodiment with a plurality of affiliated non-AP stations 123a-c. As illustrated in figures 3a and 3b, for the NC AP MLD 110 and / or the NC non-AP MLD 120 according to an embodiment the MLD components are distributed across multiple network elements. The MLD Upper MAC sublayer 111 and the MLD Lower MAC sublayer 115a-c are considered as separate entities / components of the NC AP MLD 110 that can be at different physical locations (i.e. non-colocated entities). The affiliated APs 113a-c and the Upper MAC sublayer 111 of the NC AP MLD 110 may communicate through one or more interfaces 112, 114a-c. As will be appreciated, however, the NC architecture may result in delays and may limit the bandwidth of these internal MLD communications. In an embodiment, the non-AP MLD 120 may be implemented as a UHR colocated non-AP MLD 120 that can support an operation with both a colocated AP MLD 110 and a NC AP MLD 110 according to an embodiment.

[0083] The data path for any IEEE 802.11 device to and / or from an external network 101 (e.g. an Ethernet network 101) is through an interface called the MAC-SAP. As illustrated in figures 4 and 5, for the NC AP MLD 110, the data path can be defined to be centralized through the processing circuitry 111 of the NC MLD AP 110 (referred to as Mode 1 , which is shown in figure 4) or local to each affiliated AP 113a-g (referred to as Mode 2, which is shown in figure 5). Differently put, in Mode 1 the MAC SAP interface is implemented by the processing circuitry 111 of the NC AP MLD 110, while in Mode 2 the MAC SAP resides at each affiliated AP 113a-g.

[0084] Although in figure 5 the affiliated APs 113a-g are indicated as single APs, in further embodiments one or more of the affiliated APs 113a-g may represent a number of colocated affiliated APs. For example, in an embodiment, the affiliated AP 113a, i.e. API may be operating as a set of APs affiliated with the NC AP MLD 110. That same group of colocated AP stations may also operate as an AP MLD. Thus, as used herein, the term affiliated AP, except when used as part of a key derivation, may represent multiple colocated, affiliated APs.

[0085] Further details of the Mode 1 operation of the NC MLD AP 110 illustrated in figure 4 are disclosed in PCT / EP2024 / 060009 and WO 2024 / 032577 Al), which are fully incorporated herein by reference. As already mentioned above, in Mode 1 all traffic as well as upper MAC and MAC management functions reside internally in the processing circuitry 111 of the NC AP MLD 110, while the lower MAC functions reside in the affiliated APs 113a-g. Contrary thereto, in Mode 2 the MAC management functions reside in the processing circuitry 111 of the NC AP MLD 110, while the MAC SAP and DS connectivity reside in each of the affiliated APs 113a-g. In other words, in Mode 1, all data passes internally through the central processing circuitry 111 of the NC AP MLD 110, while in Mode 2 data is bridged to a network at the respective affiliated AP 113a-g. Figure 6 shows a table summarizing the differences between Mode 1 and Mode 2 MLO implemented by a NC AP MLD 110 according to an embodiment.

[0086] As illustrated by the scenario shown in figure 5, in Mode 2 operation, when the non-AP MLD 120 roams from one affiliated AP to another affiliated AP that resides in a different physical location, the MAC SAP needs to change each time the non-AP MLD 120 changes the link, i.e. affiliated AP through which it is connected to the NC AP MLD 110, even though the association is maintained between the non-AP MLD 120 and the NC AP MLD 110. Thus, in Mode 2 operation the data path on the AP infrastructure switches from one affiliated AP to another. Although the association state is maintained between the non-AP MLD 120 and the NC AP MLD 110, any cryptographic encapsulation needs to be done locally at the non-AP MLD 120, requiring new keying material each time that the non-AP MLD 120 negotiates a new link. To prevent sharing of the same keys among different pairs of entities (the affiliated STA and the new affiliated AP), a new set of keys needs to be derived between the affiliated STA and the new affiliated AP. To this end, embodiments disclosed here provide a secure mechanism for deriving and distributing new keys at the link level.

[0087] As will be described in detail in the following, embodiments of the AP MLD 110 and the non-AP MLD 120 disclosed herein address the derivation and distribution of cryptographic keys, in particular for a roaming scenario, where the AP MLD 110 is implemented as a NC AP MLD 110 and / or the non-AP MLD 120 is implemented as a NC non-AP MLD 120, of the non-AP MLD 120 between the AP stations 113a-g affiliated with the NC AP MLD 110 operating in mode 2. The non-AP MLD 120, which may be a UHR non-AP MLD 120, associates and authenticates with the AP MLD 110, in particular the NC AP MLD 110, to establish a security association. The MAC SAP resides at the one or more affiliated APs 113a-g operating on the setup links established between the UHR non-AP MLD 120 and the AP MLD 110 and is managed on a per-link basis. When the non-AP MLD 120 physically moves through the WLAN 100, ML Reconfiguration Request / Response frames allow the non-AP MLD 120 and the NC AP MLD 110 to mutually derive keys for cryptographic encapsulation for a new link (which is located in a different physical location) to be established (affiliated AP - affiliated STA pair), before transitioning to the new link.

[0088] As illustrated in figures 7 and 8, the central processing circuitry 111, i.e. an upper MAC layer 111 of the AP MLD 110 is configured to receive an ML Reconfiguration Request frame from the non-AP MLD 120, wherein the ML Reconfiguration Request frame comprises an indication of a first current AP 113a and a second affiliated AP 113b and a first nonce (referred to as Snonce in figure 8). Moreover, the central processing circuitry 111 , i.e. an upper MAC layer 111 of the AP MLD 110 is configured to send an ML Reconfiguration Response frame to the non-AP MLD 120, wherein the ML Reconfiguration Response frame comprises a second nonce (referred to as Anonce in figure 8), and provide one or more local link keys based on the first and second nonce to the second affiliated AP 113b. The second affiliated AP 113b of the AP MLD 110 is configured to establish a new link 130b with the non-AP MLD 120 using the one or more local link keys and the first affiliated AP 113a is configured to disconnect a current link 130a with the non-AP MLD 120.

[0089] The central processing circuitry 121, i.e. an upper MAC layer 121 of the non-AP MLD 120 is configured to send an ML Reconfiguration Request frame to the AP MLD 110, wherein, as already described above, the ML Reconfiguration Request frame comprises the indication of the first current AP 113a and the second target affiliated AP 113b of the plurality of affiliated APs 113a-c of the AP MLD 110 as well as the first nonce, i.e. Snonce. Moreover, the central processing circuitry 121, i.e. an upper MAC layer 121 of the non-AP MLD 120 is configured to receive an ML Reconfiguration Response frame from the AP MLD 110, wherein, as already described above, the ML Reconfiguration Response frame comprises the second nonce, i.e. Anonce, and to provide one or more local link keys based on the first and second nonce, to its affiliated non-AP station 123a having the link 130a with the first affiliated AP 113a ofthe AP MLD 110. The affiliated non-AP station 123a having the link 130a with the first current affiliated AP 113a of the AP MLD 110 is configured to establish the new link 130b with the second target affiliated AP 113b of the AP MLD 110 using the one or more local link keys, for transitioning to the second affiliated AP 113b of the AP MLD 110.

[0090] Thus, when the non-AP MLD 120 according to an embodiment, moves through the network, it is configured to negotiate new links with different affiliated APs of the AP MLD 110 that may be located in different physical locations. In an embodiment, the ML Reconfiguration Request frame generated by the non-AP MLD 120 and / or the ML Reconfiguration Response frame generated by the AP MLD 110 may be based on the conventional ML Reconfiguration Request and ML Reconfiguration Response frames with the extension and / or modification that these frames may be transmitted on any setup link between the non-AP MLD 120 and the AP MLD 110, in particular NC AP MLD 110 to negotiate a new link or set of links (i.e. not only on the link to be modified).

[0091] As illustrated in figure 8, in an embodiment, the non-AP MLD 120 is configured to send an ML Reconfiguration Confirm frame 900 via the new link 130b to the AP MLD 110. An embodiment of the ML Reconfiguration Confirm frame 900 is shown in figure 9. As illustrated in figure 9, in an embodiment, the ML Reconfiguration Confirm frame 900 comprises a status code (field) 940 indicative of whether the setup of the new link 130b was either successful or otherwise (e.g. a warning code). Moreover, the ML Reconfiguration Confirm frame 900 may comprise a Category field 910, a Protected EHT Action field 920, and a Dialog Token field 930.

[0092] Thus, according to embodiments disclosed herein, the completion of a successful ML Reconfiguration Request / Response frame exchange may be done using the ML Reconfiguration Confirm frame 900, which can be considered to move the MAC SAP from the current affiliated AP 130a to the new target affiliated AP 130b. As already described above, the non-AP MLD 120 negotiates a new cryptographic key for use on the new link 130b and transfers any context corresponding to the affiliated non-AP STA (e.g. BlockAck, TWT state) between the affiliated APs (i.e. current AP and target AP), as illustrated in figure 7.

[0093] As already described above, while a non-AP MLD 120 according to an embodiment moves through the WLAN, it may negotiate new links with different affiliated APs 130a-g of the AP MLD 110. ML Reconfiguration Request and ML Reconfiguration Response frames may be used on the current link between the Non-AP MLD 120 and the NC AP MLD 110 to replace an operating link 130a with another link 130b (which may be affiliated with a different AP MLD). using a new reconfiguration operation type in the ML Reconfiguration Request / Response frames, using these request / response frame exchanges. Figure 8 shows an exemplary reconfiguration message exchange between the AP MLD 110 according to an embodiment in the form of a NC AP MLD 110 and the non-AP MLD 120 according to an embodiment. The non-AP MLD 120 is triggered to roam from the current affiliated AP 113a, i.e. AP2 to the target affiliated AP 113b and discovers that the target affiliated AP 113b is affiliated with the same NC AP MLD 110. The non-AP MLD 120 and the NC AP MLD 110 exchange ML Reconfiguration Request and Response frames, including the Snonce and Anonce to allow the precomputation of new keys. This exchange can occur over any setup link (i.e. it does not have to be sent to the current affiliated AP 113a, i.e. AP2). When the time comes to complete the roam / transition, the non-AP MLD 120 sends an ML Reconfiguration Confirm frame on the newly negotiated setup link with the target affiliated AP 113b.

[0094] As alreadv described above, the ML Reconfiguration Confirm frame 900 illustrated in figure 9 is used by the non-AP MLD 120 according to an embodiment to verify the status of the link local keys (e.g. Success). This ML Reconfiguration Confirm frame 900 is transmitted on the link on which the target affiliated AP 130b is currently operating on. The status code 940 is created for the cryptographic encapsulation keys derivation. In an embodiment, the status code 940 may be used to indicate that Mode 2 re-keying is not supported (or has failed) and therefore the non-AP MLD 120 has to re-associate with the NC AP MLD 110. An exemplary status code could be: ML-RECONFIGURATION-DENIED, while an exemplary reason is: “MultiLink Reconfiguration Denied”.

[0095] As already described above and as illustrated in figure 10, the AP MLD 110 and the non-AP MLD 120 are configured to derive the one or more local link keys for establishing the new link based on the first and second nonce using a key derivation function, KDF, and a key derivation key, KDK, established between the AP MLD 110 and the non-AP MLD 120. More specifically, in an embodiment, the AP MLD 110 and the non-AP MLD 120 may use the KDF-hash-length function and the KDK to derive a new link key. The new key is bound to the Authenticator, Supplicant, the new affiliated AP and affiliated STA MAC addresses, and the respective Nonces.

[0096] PTK-LINK = KDF-hash-length(PTK-KDK, “MLO link key” || min(AA, SPA) || max(AA, SPA) || min(A-AP-MAC, A-STA- MAC) || max(A-AP-MAC, A-STA-MAC) || min( Anonce, Snonce) || max(Anonce, Snonce) )

[0097] Where:

[0098] KDF-hash-length - KDF function as specified in 12.7.1.6.2 of IEEE 802.11-2020 (e.g. KDF-HMAC-SHA-256)

[0099] PTK-KDK - Derived in the (re)-association between the Non-AP MLD and NC AP MLD

[0100] AA, SPA - Authenticator and Supplicant addresses which are the MAC addresses of the NC AP MLD and Non-AP MLD

[0101] A-AP-MAC, A-STA-MAC - affiliated AP and affiliated STA MAC addresses

[0102] Anonce, Snonce - AP and STA nonces exchanged during link configuration.

[0103] The ML Reconfiguration Confirm frame can be protected using the new link key when transmitted on the new link (to complete link the link reconfiguration process).

[0104] Figure 11 shows a flow diagram illustrating steps of a method 1100 of operating an access point, AP, Multi-Link Device, MLD, 110 with a plurality of affiliated AP 113a-c for communication via a plurality of links 130a-c with a non-AP MLD 120 with a plurality of affiliated non-AP stations 123a-c. The method 1100 comprises the following steps implemented by a processing circuitry 111 of the AP MLD 110: receiving 1101 an ML Reconfiguration Request frame from the non-AP MLD 120, wherein the ML Reconfiguration Request frame comprises an indication of a first and a second affiliated AP and a first nonce; sending 1103 an ML Reconfiguration Response frame to the non-AP MLD 120, wherein the ML Reconfiguration Response frame comprises a second nonce; and providing 1105 one or more local link keys based on the first and second nonce to the second affiliated AP 113b; wherein the method 1100 further comprises a step 1107 of establishing a new link 130b with the non-AP MLD 120 using the one or more local link keys implemented by the second affiliated AP 113b of the AP MLD 110 and a step 1109 of disconnecting a current link 130a with the non-AP MLD 120 implemented by the first affiliated AP 113a.

[0105] As the method 1100 can be implemented by the AP MLD 110, further features of the method 1100 result directly from the functionality of the AP MLD 110 as well as its different embodiments described above and below.

[0106] Figure 12 shows a flow diagram illustrating steps of a method 1200 of operating a non-access point, non-AP, Multi-Link Device, MLD, 120 with a plurality of affiliated non-AP stations 123a-c for communication via a plurality of links 130a-c with an AP MLD 110 with a plurality of affiliated APs 113a-c. The method 1200 comprises the following steps implemented by processing circuitry 121 of the non-AP MLD 120: sending 1201 an ML Reconfiguration Request frame to the AP MLD 110, wherein the ML Reconfiguration Request frame comprises an indication of a first and a second affiliated AP 113a, b of the plurality of affiliated APs 113a-c of the AP MLD 110 and a first nonce; receiving 1203 an ML Reconfiguration Response frame from the AP MLD 110, wherein the ML Reconfiguration Response frame comprises a second nonce; and providing 1205 one or more local link keys based on the first and second nonce to the affiliated non-AP station 123a having a link 130a with the first affiliated AP 113a of the AP MLD 110; wherein the method 1200 further comprises a step 1207, implemented by the affiliated non-AP station 123a having the link 130a with the first affiliated AP 113a of the AP MLD 110, of establishing a new link 130b with the second affiliated AP 113b of the AP MLD 110 based on the one or more local link keys for transitioning to the second affiliated AP 113b of the AP MLD 110.

[0107] As the method 1200 can be implemented by the non-AP MLD 120, further features of the method 1200 result directly from the functionality of the non-AP MLD 120 as well as its different embodiments described above and below.

[0108] The person skilled in the art will understand that the "blocks" ("units") of the various figures (method and apparatus) represent or describe functionalities of embodiments of the present disclosure (rather than necessarily individual "units" in hardware or software) and thus describe equally functions or features of apparatus embodiments as well as method embodiments (unit = step).

[0109] In the several embodiments provided in the present application, it should be understood that the disclosed system, apparatus, and method may be implemented in other manners. For example, the described embodiment of an apparatus is merely exemplary. For example, the unit division is merely logical function division and may be another division in an actual implementation. For example, a plurality of units or components may be combined or integrated into another system, or some features may be ignored or not performed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections may be implemented by using some interfaces. The indirect couplings or communication connections between the apparatuses or units may be implemented in electronic, mechanical, or other forms.

[0110] The units described as separate parts may or may not be physically separate, and parts displayed as units may or may not be physical units, may be located in one position, or may be distributed on a plurality of network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the solutions of the embodiments.

[0111] In addition, functional units in the embodiments of the invention may be integrated into one processing unit, or each of the units may exist alone physically, or two or more units are integrated into one unit.

Claims

CLAIMS1. An access point, AP, Multi-Link Device, MLD, (110) with a plurality of affiliated APs (113a-c) for communication via a plurality of links (130a-c) with a non-AP MLD (120) with a plurality of affiliated non-AP stations (123a-b), wherein the AP MLD (110) comprises processing circuitry (111 ) configured to: receive an ML Reconfiguration Request frame from the non-AP MLD (120), wherein the ML Reconfiguration Request frame comprises an indication of a first and a second affiliated AP (113a, b) and a first nonce; send an ML Reconfiguration Response frame to the non-AP MLD (120), wherein the ML Reconfiguration Response frame comprises a second nonce; and provide one or more local link keys based on the first and second nonce to the second affiliated AP (113b); wherein the second affiliated AP (113b) ofthe AP MLD (110) is configured to establish a new link (130b) with the non-AP MLD (120) using the one or more local link keys and wherein the first affiliated AP (113a) is configured to disconnect a current link (130a) with the non-AP MLD (120).

2. The AP MLD (110) of claim 1, wherein the processing circuitry (111) is configured to receive an ML Reconfiguration Confirm frame (900) via the new link (130b) from the non-AP MLD (120).

3. The AP MLD (110) of claim 2, wherein the ML Reconfiguration Confirm frame (900) comprises a status code (940) indicative of whether the setup of the new link (130b) was either successful or not.

4. The AP MLD (110) of any one of the preceding claims, wherein the processing circuitry (111) is configured to generate the one or more local link keys based on the first and second nonce.

5. The AP MLD (110) of claim 4, wherein the first nonce comprises a first random number and wherein the second nonce comprises a second random number.

6. The AP MLD (110) of any one of the preceding claims, wherein the processing circuitry (111) is configured to establish the one or more local link keys based on the first and second nonce using a key derivation function, KDF, and a key derivation key, KDK, established between the AP MLD (110) and the non-AP MLD (120).

7. The AP MLD (110) of any one of the preceding claims, wherein the indication of the first and the second affiliated AP (113a,b) comprises a first address ofthe first affiliated AP (113a) and a second address ofthe second affiliated AP (113b).

8. The AP MLD (110) of any one of the preceding claims, wherein the AP MLD (110) is a non-colocated AP MLD (110) and / or the non-AP MLD (120) is a non-colocated non-AP MLD (120).

9. A method (1100) of operating an access point, AP, Multi-Link Device, MLD, (110) with a plurality of affiliated APs (113a-c) for communication via a plurality of links (130a-c) with a non-AP MLD (120) with a plurality of affiliated non- AP stations (123a-c), wherein the method (1100) comprises the following steps implemented by a processing circuitry (111) ofthe AP MLD (110): receiving (1101) an ML Reconfiguration Request frame from the non-AP MLD (120), wherein the ML Reconfiguration Request frame comprises an indication of a first and a second affiliated AP (113a, b) and a first nonce; sending (1103) an ML Reconfiguration Response frame to the non-AP MLD (120), wherein the ML Reconfiguration Response frame comprises a second nonce; andproviding (1105) one or more local link keys based on the first and second nonce to the second affiliated AP (113b); wherein the method (1100) further comprises a step (1107) of establishing a new link (130b) with the non-AP MLD (120) using the one or more local link keys implemented by the second affiliated AP (113b) of the AP MLD (110) and a step (1109) of disconnecting a current link (130a) with the non-AP MLD (120) implemented by the first affiliated AP (113a).

10. A non-access point, non-AP, Multi-Link Device, MLD, (120) with a plurality of affiliated non-AP stations (123a-c) for communication via a plurality of links (130a-c) with an AP MLD (110) with a plurality of affiliated APs (113a-c), wherein the non-AP MLD (120) comprises processing circuitry (121) configured to: send an ML Reconfiguration Request frame to the AP MLD (110), wherein the ML Reconfiguration Request frame comprises an indication of a first and a second affiliated AP (113a, b) of the plurality of affiliated APs (113a-c) of the AP MLD (110) and a first nonce; receive an ML Reconfiguration Response frame from the AP MLD (110), wherein the ML Reconfiguration Response frame comprises a second nonce; and provide one or more local link keys based on the first and second nonce to an affiliated non-AP station (123a) having a link (130a) with the first affiliated AP (113a) of the AP MLD (110); wherein the affiliated non-AP station (123a) having the link (130a) with the first affiliated AP (113a) ofthe AP MLD (110) is configured to establish a new link (130b) with the second affiliated AP (113b) ofthe AP MLD (110) using the one or more local link keys for transitioning to the second affiliated AP (113b) of the AP MLD (110).

11. The non-AP MLD (120) of claim 10, wherein the processing circuitry (121) is configured to send an ML Reconfiguration Confirm frame (900) via the new link (130b) to the AP MLD (110).

12. The non-AP MLD (120) of claim 11, wherein the ML Reconfiguration Confirm frame (900) comprises a status code (940) indicative of whether the setup of the new link (130b) was either successful or not.

13. The non-AP MLD (120) of any one of claims 10 to 12, wherein the processing circuitry (121) is configured to generate the one or more local link keys based on the first and second nonce.

14. The non-AP MLD (120) of claim 13, wherein the first nonce comprises a first random number and the second nonce comprises a second random number.

15. The non-AP MLD (120) of any one of claims 10 to 14, wherein the processing circuitry (121) is configured to generate the one or more local link keys based on the first and second nonce using a key derivation function, KDF, and a key derivation key, KDK, established between the AP MLD (110) and the non-AP MLD (120).

16. The non-AP MLD (120) of any one of claims 10 to 15, wherein the indication of the first and the second affiliated AP (113a, b) comprises a first address of the first affiliated AP (113a) and a second address of the second affiliated AP (113b).

17. The non-AP MLD (120) of any one of claims 10 to 16, wherein the processing circuitry (121) is configured to send the ML Reconfiguration Request frame to the AP MLD (110), in response to being triggered to transition from the first affiliated AP (113a) to the second affiliated AP (113b).

18. The non-AP MLD (120) of any one of claims 10 to 17, wherein the non-AP MLD (120) is a non-colocated non-AP MLD (120) and / or the AP MLD (110) is a non-colocated AP MLD (110).

19. A method (1200) of operating a non-access point, non-AP, Multi-Link Device, MLD, (120) with a plurality of affiliated non- AP stations (123a-c) for communication via a plurality of links (130a-c) with an AP MLD (110) with a plurality of affiliated APs (113a-c), wherein the method (1200) comprises the following steps implemented by processing circuitry (121) ofthe non-AP MLD (120): sending (1201) an ML Reconfiguration Request frame to the AP MLD (110), wherein the ML Reconfiguration Request frame comprises an indication of a first and a second affiliated AP (113a, b) of the plurality of affiliated APs (113a-c) of the AP MLD (110) and a first nonce; receiving (1203) an ML Reconfiguration Response frame from the AP MLD (110), wherein the ML Reconfiguration Response frame comprises a second nonce; and providing (1205) one or more local link keys based on the first and second nonce to the affiliated non-AP station (123a) having a link (130a) with the first affiliated AP (113a) ofthe AP MLD (110); wherein the method (1200) further comprises a step (1207), implemented by the affiliated non-AP station (123a) having the link (130a) with the first affiliated AP (113a) ofthe AP MLD (110), of establishing a new link (130b) with the second affiliated AP (113b) ofthe AP MLD (110) based on the one or more local link keys for transitioning to the second affiliated AP (113b) ofthe AP MLD (110).

20. A computer program product comprising a computer-readable storage medium for storing program code which causes a computer or a processor to perform the method (1100) of claim 9 or the method (1200) of claim 19 when the program code is executed by the computer or the processor.

Citation Information

Patent Citations

  • Methods, modules, and storage media for changing communication links for multi-link devices on mobile wireless local area networks

    WO2024032577A1

  • Devices and methods for reliable BSS transition in a wireless network

    WO2025214611A1

  • Fast basic service set transition for multi-link operation

    WO2022015502A1

  • Device and method for reconfiguring multi link in wireless local area network

    WO2024150979A1