Communication methods, communication devices and communication system

By initiating key negotiation during Wi-Fi device roaming and utilizing information such as PMKID and ANounce values, the problem of unclear key negotiation during Wi-Fi device roaming is solved, resulting in a more reliable and lower-latency network connection, and improving network performance and security.

WO2026156498A1PCT designated stage Publication Date: 2026-07-30BEIJING XIAOMI MOBILE SOFTWARE CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
BEIJING XIAOMI MOBILE SOFTWARE CO LTD
Filing Date
2025-01-21
Publication Date
2026-07-30

AI Technical Summary

Technical Problem

Existing Wi-Fi technologies do not clearly define the key negotiation process during device roaming, leading to potential security risks and network instability, and failing to meet the high reliability and low latency requirements of Ultra-High Reliability (UHR).

Method used

After the non-AP MLD roams to the first AP MLD, key negotiation is initiated by sending the first message frame in a multi-link environment, including information such as the key identifier PMKID and ANounce value, to ensure the accuracy and security of key negotiation.

Benefits of technology

It improves the reliability of WLAN connections, reduces the risk of connection interruptions, lowers latency, and enhances overall network performance and security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025073753_30072026_PF_FP_ABST
    Figure CN2025073753_30072026_PF_FP_ABST
Patent Text Reader

Abstract

The embodiments of the present disclosure relate to communication methods, communication devices and a communication system. A communication method comprises: after a non-AP MLD roams from a second AP MLD to a first AP MLD and establishes multiple links with the first AP MLD, the first AP MLD sending a first message frame under a first link among the multiple links. The first message frame is used to initiate key negotiation to the non-AP MLD, so as to improve a key negotiation mechanism of multi-link devices during roaming processes, thus improving key negotiation efficiency of the multi-link devices during roaming processes, and meeting UHR transmission requirements.
Need to check novelty before this filing date? Find Prior Art

Description

Communication methods, communication equipment and communication systems Technical Field

[0001] This disclosure relates to the field of communication technology, and in particular to a communication method, communication device and communication system. Background Technology

[0002] Currently, research on Wi-Fi technology includes topics such as Ultra High Reliability (UHR), with the vision of improving the reliability of Wireless Local Area Networks (WLAN) connections, reducing latency, improving manageability, increasing throughput at different signal-to-noise ratio (SNR) levels, and reducing device-level power consumption. Summary of the Invention

[0003] This disclosure provides a communication method, communication device, and communication system to further improve the key negotiation mechanism of the device during roaming.

[0004] On one hand, embodiments of this disclosure provide a communication method applied to a first AP MLD, the method comprising:

[0005] After a non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD.

[0006] On the other hand, embodiments of this disclosure also provide a communication method applied to non-AP MLD, the method comprising:

[0007] After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, it receives a first message frame sent by the first AP MLD on the first link of the multi-link; wherein, the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

[0008] On the other hand, this disclosure also provides a communication device, which is a first AP MLD, the first AP MLD comprising:

[0009] The sending module is configured to, after a non-AP MLD roams from a second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, send a first message frame on the first link of the multi-link; wherein the first message frame is used to initiate key negotiation with the non-AP MLD.

[0010] On the other hand, this disclosure also provides a communication device, which is a non-AP MLD, the non-AP MLD comprising:

[0011] The receiving module is configured to receive a first message frame sent by the first AP MLD on the first link of the multi-link after the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD; wherein the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

[0012] On the other hand, this disclosure also provides a communication device, which is a first AP MLD, comprising:

[0013] One or more processors;

[0014] The first AP MLD is used to execute the communication method described in the embodiments of this disclosure.

[0015] On the other hand, this disclosure also provides a communication device, which is a non-AP MLD, comprising:

[0016] One or more processors;

[0017] The non-AP MLD is used to execute the communication method described in the embodiments of this disclosure.

[0018] This disclosure also provides a communication system, including a first AP MLD and a non-AP MLD;

[0019] Wherein, after a non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD;

[0020] After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, it receives a first message frame sent by the first AP MLD in the multi-link; wherein, the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

[0021] This disclosure also provides a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the communication method as described in this disclosure.

[0022] In this embodiment of the disclosure, after a non-AP MLD roams from a second AP MLD to a first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link. The first message frame is used to initiate key negotiation with the non-AP MLD, which improves the key negotiation process of the non-AP MLD after roaming to the target AP MLD, enhances the reliability of WLAN connection, reduces the risk of connection interruption, and reduces latency, thereby improving overall network performance.

[0023] Additional aspects and advantages of embodiments of this disclosure will be set forth in part in the description which follows, and will become apparent from the description or may be learned by practice of this disclosure. Attached Figure Description

[0024] To more clearly illustrate the technical solutions in the embodiments of this disclosure, the accompanying drawings required for the description of the embodiments are introduced below. The following drawings are only some embodiments of this disclosure and do not impose specific limitations on the protection scope of this disclosure.

[0025] Figure 1 is an exemplary schematic diagram of the architecture of a communication system provided according to an embodiment of the present disclosure;

[0026] Figure 2 is one of the exemplary interaction diagrams of the method provided according to the embodiments of this disclosure;

[0027] Figure 3 is a second exemplary interactive schematic diagram of the method provided according to the embodiments of this disclosure;

[0028] Figure 4 is a third exemplary interactive schematic diagram of the method provided according to the embodiments of this disclosure;

[0029] Figure 5 is a fourth exemplary interactive schematic diagram of the method provided according to the embodiments of this disclosure;

[0030] Figure 6 is a fifth exemplary interactive schematic diagram of the method provided according to the embodiments of this disclosure;

[0031] Figure 7 is a flowchart illustrating one of the communication methods provided in this embodiment of the present disclosure;

[0032] Figure 8 is a second schematic flowchart of the communication method provided in this embodiment of the present disclosure;

[0033] Figure 9 is a schematic diagram of the structure of the first AP MLD proposed in the embodiment of this disclosure;

[0034] Figure 10 is a schematic diagram of the structure of the non-AP MLD proposed in the embodiment of this disclosure;

[0035] Figure 11 is a schematic diagram of the structure of the terminal proposed in the embodiment of this disclosure;

[0036] Figure 12 is a schematic diagram of the chip structure proposed in the embodiments of this disclosure. Detailed Implementation

[0037] This disclosure presents a communication method, communication device, and communication system.

[0038] In a first aspect, embodiments of this disclosure provide a communication method applied to a first AP MLD, the method comprising:

[0039] After a non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD.

[0040] In the above embodiments, by establishing multiple links between the non-AP MLD and the first AP MLD and initiating key negotiation through the first link, the key negotiation process of the non-AP MLD after roaming to the target AP MLD is improved, the reliability of WLAN connection is enhanced, the risk of connection interruption is reduced, and latency is reduced, thereby improving the overall network performance.

[0041] In conjunction with some embodiments of the first aspect, in some embodiments, the first message frame includes at least one of the following:

[0042] Key identifier PMKID;

[0043] ANounce value.

[0044] In the above embodiments, the first message frame further enhances the security of communication and the accuracy of key negotiation by carrying information such as the key identifier PMKID and ANounce value.

[0045] In conjunction with some embodiments of the first aspect, in some embodiments, the ANounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

[0046] In the above embodiments, the MAC address-based generation method can ensure the uniqueness and unpredictability of communication between different devices, thereby improving the security and anti-interference capability of data transmission in the network.

[0047] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0048] Receive a first radio frame sent by the second AP MLD; wherein the first radio frame includes at least one of the following:

[0049] The MLD MAC address of the non-AP MLD;

[0050] The non-AP MLD requests link information for the multi-link established with the first AP MLD.

[0051] In the above embodiments, the first wireless frame carries the MLD MAC address of the non-AP MLD and the link information of the non-AP MLD requesting to establish a multi-link with the first AP MLD, providing necessary information for subsequent link establishment and key negotiation.

[0052] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0053] The second message frame sent by the non-AP MLD is received under the first link; wherein the second message frame is used to respond to the key negotiation initiated by the first AP MLD.

[0054] In the above embodiment, the second message frame is used to respond to the key negotiation initiated by the first AP MLD. Its content includes the necessary information required for key negotiation to ensure the correct exchange of the security key. Through this design, the non-AP MLD can respond promptly to the AP MLD's key negotiation request, ensuring that both communicating parties can successfully complete key derivation and security verification after establishing a multi-link connection, thereby improving the confidentiality and integrity of data transmission.

[0055] In conjunction with some embodiments of the first aspect, in some embodiments, the second message frame includes at least one of the following:

[0056] SNounce value;

[0057] The non-AP MLD requests the link information of the multi-link established with the first AP MLD;

[0058] The BSSID of the first AP MLD;

[0059] The non-AP MLD requests TSF offset information under at least one link established with the first AP MLD;

[0060] RSNE information element.

[0061] In the above embodiments, by integrating the above information into the second message frame, the key negotiation process can not only be carried out more accurately and efficiently, but also improve the security and stability of the entire multi-link establishment process.

[0062] In conjunction with some embodiments of the first aspect, in some embodiments, the SNounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

[0063] In the above embodiments, the method of generating SNounce values ​​based on MAC addresses helps ensure that each step of key exchange during the negotiation process between different devices is independent and tamper-proof, thereby improving the security and reliability of the overall network communication.

[0064] In conjunction with some embodiments of the first aspect, in some embodiments, the MLD MAC address of the first AP MLD is obtained during the process of establishing a multi-link between the non-AP MLD and the second AP MLD, or is obtained through a response frame sent by the second AP MLD; wherein the response frame is used to respond to a roaming request frame sent by the non-AP MLD.

[0065] In the above embodiments, during roaming, the non-AP MLD is allowed to dynamically obtain relevant information of the first AP MLD, ensuring that the target AP MLD can perform accurate authentication and key negotiation during the multi-link establishment process.

[0066] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0067] The first AP MLD sends a third message frame; wherein the third message frame is used to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD.

[0068] In the above embodiment, the first AP MLD sends a third message frame under the first link, which is mainly used to distribute keys for encrypting multicast data and / or broadcast data to the non-AP MLD. These keys will be used for subsequent data encryption to ensure the confidentiality and integrity of multicast and broadcast data when transmitted in the network.

[0069] In conjunction with some embodiments of the first aspect, in some embodiments, the third message frame includes at least one of the following:

[0070] The ANounce value;

[0071] The link information of at least one link determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation is completed;

[0072] The first AP MLD determines the multicast temporary key GTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0073] The first AP MLD determines the multicast integrity key IGTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0074] The BSSID of the first AP MLD.

[0075] In the above embodiments, by passing these keys and link information to the non-AP MLD, the encryption protection of multicast and broadcast data can be guaranteed, while avoiding potential middleware attacks or data tampering, thus improving the overall security of wireless communication.

[0076] In conjunction with some embodiments of the first aspect, in some embodiments, the method further includes:

[0077] A first trigger frame is determined; wherein the first trigger frame instructs the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or the first trigger frame is used to instruct that after the first duration ends, the sending of buffered downlink data to the non-AP MLD or the first AP MLD should be stopped;

[0078] The first trigger frame is sent to the second AP MLD.

[0079] In the above embodiments, after the key negotiation process is completed, in order to ensure communication security and data consistency, the first trigger frame is used to notify the second AP MLD to stop sending the cached downlink data to the non-AP MLD or the first AP MLD. This helps to avoid data inconsistency or duplicate transmission.

[0080] Secondly, embodiments of this disclosure propose a communication method applied to non-AP MLD, the method comprising:

[0081] After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, it receives a first message frame sent by the first AP MLD on the first link of the multi-link; wherein, the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

[0082] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0083] Determine the second message frame; wherein the second message frame is used to respond to the key negotiation initiated by the first AP MLD;

[0084] Under the first link, the second message frame is sent.

[0085] In conjunction with some embodiments of the second aspect, in some embodiments, the second message frame includes at least one of the following:

[0086] SNounce value;

[0087] The non-AP MLD requests the link information of the multi-link established with the first AP MLD;

[0088] The BSSID of the first AP MLD;

[0089] The non-AP MLD requests TSF offset information under at least one link established with the first AP MLD;

[0090] RSNE information element.

[0091] In conjunction with some embodiments of the second aspect, in some embodiments,

[0092] The SNounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

[0093] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0094] The non-AP MLD receives a third message frame; wherein the third message frame is used by the first AP MLD to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD.

[0095] In conjunction with some embodiments of the second aspect, in some embodiments, the third message frame includes at least one of the following:

[0096] The ANounce value;

[0097] The link information of at least one link determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation is completed;

[0098] The first AP MLD determines the multicast temporary key GTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0099] The first AP MLD determines the multicast integrity key IGTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0100] The BSSID of the first AP MLD.

[0101] In conjunction with some embodiments of the second aspect, in some embodiments, the method further includes:

[0102] A second trigger frame is determined; wherein the second trigger frame instructs the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or the second trigger frame is used to instruct that after the first duration ends, the sending of buffered downlink data to the non-AP MLD or the first AP MLD should be stopped;

[0103] Send the second trigger frame to the second AP MLD.

[0104] In the above embodiments, after the key negotiation process is completed, in order to ensure communication security and data consistency, the second trigger frame is used to notify the second AP MLD to stop sending the cached downlink data to the non-AP MLD or the first AP MLD. This helps to avoid data inconsistency or duplicate transmission.

[0105] Thirdly, embodiments of this disclosure also provide a communication device, which is a first AP MLD, the first AP MLD including a transmitting module; wherein the first AP MLD is used to execute the optional implementation of the first aspect.

[0106] Fourthly, embodiments of this disclosure also provide a communication device, which is a non-AP MLD, comprising: a receiving module; wherein the non-AP MLD is used to execute an optional implementation of the second aspect.

[0107] Fifthly, embodiments of this disclosure also provide a communication device, which is a first AP MLD, comprising:

[0108] One or more processors;

[0109] The first AP MLD is used to execute the optional implementation of the first aspect.

[0110] Sixthly, embodiments of this disclosure also provide a communication device, which is a non-AP MLD, comprising:

[0111] One or more processors;

[0112] The non-AP MLD is used to implement the optional implementation of the second aspect.

[0113] In a seventh aspect, embodiments of this disclosure also provide a communication system, including a first AP MLD and a non-AP MLD;

[0114] Wherein, after a non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD;

[0115] After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, it receives a first message frame sent by the first AP MLD on the first link of the multi-link; wherein, the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

[0116] Eighthly, embodiments of this disclosure also provide a storage medium storing instructions that, when executed on a communication device, cause the communication device to perform the optional implementations described in the first and second aspects.

[0117] Ninthly, embodiments of this disclosure provide a program product that, when executed by a communication device, causes the communication device to perform the method as described in the optional implementations of the first and second aspects.

[0118] In a tenth aspect, embodiments of this disclosure provide a computer program that, when run on a computer, causes the computer to perform the methods described in the optional implementations of the first and second aspects.

[0119] Eleventhly, embodiments of this disclosure provide a chip or chip system. The chip or chip system includes processing circuitry configured to perform the methods described according to optional implementations of the first and second aspects above.

[0120] It is understood that the aforementioned first AP MLD, non-AP MLD, communication system, storage medium, program product, computer program, chip, or chip system are all used to perform the methods proposed in the embodiments of this disclosure. Therefore, the beneficial effects that can be achieved can be referred to the beneficial effects in the corresponding methods, and will not be repeated here.

[0121] This disclosure provides communication methods, communication devices, and communication systems. In some embodiments, the terms "communication method" and "signal transmission method," "wireless frame transmission method," etc., can be used interchangeably, as can the terms "information processing system" and "communication system."

[0122] This disclosure is not exhaustive, but merely illustrative of some embodiments, and is not intended to limit the scope of protection of this disclosure. Unless otherwise specified, each step in a particular embodiment can be implemented as an independent embodiment, and the steps can be arbitrarily combined. For example, a solution after removing some steps in a particular embodiment can also be implemented as an independent embodiment, and the order of the steps in a particular embodiment can be arbitrarily interchanged. Furthermore, the optional implementation methods in a particular embodiment can be arbitrarily combined; moreover, the embodiments can be arbitrarily combined, for example, some or all steps of different embodiments can be arbitrarily combined, and a particular embodiment can be arbitrarily combined with the optional implementation methods of other embodiments.

[0123] In each of the disclosed embodiments, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of the embodiments are consistent and can be referenced by each other. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0124] The terminology used in the embodiments of this disclosure is for the purpose of describing particular embodiments only and is not intended to limit the scope of this disclosure.

[0125] In the embodiments disclosed herein, "multiple" refers to two or more.

[0126] In some embodiments, the terms “at least one of A or B, at least one of A and B”, “one or more”, “a plurality of”, “multiple”, etc., may be used interchangeably.

[0127] In some embodiments, the notation "at least one of A and B", "A and / or B", "A in one case, B in another", "in response to one case A, in response to another case B", etc., may include the following technical solutions depending on the situation: in some embodiments, A (execute A regardless of whether there is a branch B); in some embodiments, B (execute B regardless of whether there is a branch A); in some embodiments, execution is selected from A and B (A and B are selectively executed); in some embodiments, both A and B are executed. The same applies when there are more branches such as A, B, C, etc.

[0128] In some embodiments, the notation "A or B" may include the following technical solutions, depending on the situation: in some embodiments, A (execute A regardless of whether a branch B exists); in some embodiments, B (execute B regardless of whether a branch A exists); in some embodiments, execution is selected from A and B (A and B are selectively executed). The same applies when there are more branches such as A, B, and C.

[0129] The prefixes "first," "second," etc., used in the embodiments of this disclosure are merely for distinguishing different descriptive objects and do not impose restrictions on the position, order, priority, quantity, or content of the descriptive objects. The description of the descriptive objects is found in the claims or the context of the embodiments, and the use of prefixes should not constitute unnecessary restrictions. For example, if the descriptive object is a "field," the ordinal numbers preceding "field" in "first field" and "second field" do not restrict the position or order of the "fields." "First" and "second" do not restrict whether the "fields" they modify are in the same message, nor do they restrict the order of "first field" and "second field." Similarly, if the descriptive object is a "level," the ordinal numbers preceding "level" in "first level" and "second level" do not restrict the priority between "levels." Furthermore, the number of descriptive objects is not limited by ordinal numbers and can be one or more. For example, in "first device," the number of "devices" can be one or more. Furthermore, the objects modified by different prefixes can be the same or different. For example, if the object being described is "device", then "first device" and "second device" can be the same device or different devices, and their types can be the same or different. Similarly, if the object being described is "information", then "first information" and "second information" can be the same information or different information, and their content can be the same or different.

[0130] In some embodiments, “including A,” “containing A,” “for indicating A,” and “carrying A” can be interpreted as directly carrying A or indirectly indicating A.

[0131] In some embodiments, terms such as "time / frequency" and "time-frequency domain" refer to the time domain and / or frequency domain.

[0132] In some embodiments, terms such as “in response to…”, “in response to determining…”, “in the case of…”, “when…”, “when…”, “if…”, etc. can be used interchangeably. These descriptions all refer to the device making a corresponding action under certain objective circumstances. They do not necessarily limit the time, nor do they require the device to make a judgment action when implementing it, nor do they mean that there must be other limitations.

[0133] In some embodiments, the terms “greater than,” “greater than or equal to,” “not less than,” “more than,” “more than or equal to,” “not less than,” “higher than,” “higher than or equal to,” “not lower than,” and “above” can be used interchangeably, as can the terms “less than,” “less than or equal to,” “not greater than,” “less than,” “less than or equal to,” “not more than,” “lower than,” “lower than or equal to,” “not higher than,” and “below”.

[0134] In some embodiments, devices, etc., may be interpreted as physical or virtual, and their names are not limited to those described in the embodiments. Terms such as “device,” “equipment,” “circuit,” “network element,” “network function,” “network device,” “function,” “node,” “unit,” “section,” “system,” “network,” “chip,” “chip system,” “entity,” and “subject” are interchangeable.

[0135] In some embodiments, "network" can be interpreted as devices included in a network (e.g., access network devices, core network devices, etc.).

[0136] In addition, terms such as "uplink" and "downlink" can be replaced with terms corresponding to inter-terminal communication (e.g., "side"). For example, uplink channel and downlink channel can be replaced with side channel, and uplink link and downlink link can be replaced with side link.

[0137] In some embodiments, the acquisition of data, information, etc., may comply with the laws and regulations of the country where the location is situated.

[0138] In some embodiments, data, information, etc., may be obtained with the user's consent.

[0139] Furthermore, each element, each row, or each column in the table of this disclosure can be implemented as an independent embodiment, and any combination of any element, any row, or any column can also be implemented as an independent embodiment.

[0140] Figure 1 is a schematic diagram of the architecture of a communication system according to an embodiment of the present disclosure.

[0141] As shown in Figure 1, the communication system 100 includes a first multi-link access point device (AP MLD) 101, a multi-link site device (non-access point multi-link device, non-AP MLD) 102, and a second AP MLD 103.

[0142] In some embodiments, the non-AP MLD 102 includes, for example, a wireless communication chip, a wireless sensor, or a wireless communication terminal that supports Wi-Fi communication. Optionally, the wireless communication terminal may be at least one of, but is not limited to, a mobile phone, a wearable device, an IoT device that supports Wi-Fi communication, a car with Wi-Fi communication capabilities, a smart car, a tablet computer, a computer with wireless transceiver capabilities, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, a wireless terminal device in industrial control, a wireless terminal device in self-driving, a wireless terminal device in remote medical surgery, a wireless terminal device in a smart grid, a wireless terminal device in transportation safety, a wireless terminal device in a smart city, and a wireless terminal device in a smart home.

[0143] Specifically, the non-AP MLD 102 can be a terminal device or network device with a Wi-Fi chip. Optionally, the non-AP MLD 102 can support various WLAN standards such as 802.11ax, 802.11be, 802.11ac, 802.11n, 802.11g, 802.11b, 802.11a, 802.11bf, and 802.11bn, as well as the next-generation 802.11 protocol, but is not limited to these.

[0144] In some embodiments, the first AP MLD 101 and the second AP MLD 103 can be access points for mobile terminals to access a wired network. An AP acts as a bridge connecting wired and wireless networks, its main function being to connect various wireless network clients together and then connect the wireless network to the Ethernet. Specifically, an AP can be a terminal device or network device with a wireless fidelity chip. Optionally, the AP can support various WLAN standards such as 802.11ax, 802.11be, 802.11ac, 802.11n, 802.11g, 802.11b, 802.11a, 802.11bf, and 802.11bn, as well as the next-generation 802.11 protocol, but is not limited to these.

[0145] Optionally, in this embodiment of the disclosure, AP MLD can represent an access point that supports multi-link communication, and non-AP MLD can represent a site that supports multi-link communication. For example, in this embodiment of the disclosure, link can represent connection or link; in various embodiments, connection and link can be interchanged.

[0146] It is understood that the communication system described in this disclosure is for the purpose of more clearly illustrating the technical solutions of this disclosure, and does not constitute a limitation on the technical solutions proposed in this disclosure. As those skilled in the art will know, with the evolution of system architecture and the emergence of new business scenarios, the technical solutions proposed in this disclosure are also applicable to similar technical problems.

[0147] The following embodiments of this disclosure can be applied to the communication system 100 shown in FIG1, or to some of the main bodies, but are not limited thereto. The main bodies shown in FIG1 are illustrative. The communication system may include all or some of the main bodies in FIG1, or may include other main bodies outside of FIG1. ​​The number and form of each main body are arbitrary. Each main body may be physical or virtual. The connection relationship between the main bodies is illustrative. The main bodies may not be connected or may be connected. The connection can be in any way, it can be a direct connection or an indirect connection, it can be a wired connection or a wireless connection.

[0148] The embodiments disclosed herein can be applied to Wireless Local Area Networks (WLANs), such as LANs using the 802.11 series of protocols. In a WLAN, a Basic Service Set (BSS) is a fundamental component. An BSS network consists of site devices with some association within a specific coverage area. One type of association is where sites communicate directly with each other in a self-organizing network; this is called an Independent Basic Service Set (IBSS). Another more common scenario is that in a BSS network, there is only one central site dedicated to managing the BSS, called the Access Point (AP) device, and all other STAs in the network are associated with it. Other sites in the BSS network that are not the central site are called terminals, also known as non-AP STAs; terminals and non-AP STAs are collectively referred to as STAs. When describing STAs, it is not necessary to distinguish between terminals and non-AP STAs. Within the same BSS network, due to distance, transmission power, etc., a STA cannot detect other STAs that are far away; they are each other's hidden nodes.

[0149] Figure 2 is one of the interactive schematic diagrams of a communication method according to an embodiment of the present disclosure. As shown in Figure 2, the method includes:

[0150] Step 201: The first AP MLD 101 determines the first message frame; wherein, the first message frame is sent by the first AP MLD 101 after the non-AP MLD 102 roams from the second AP MLD 103 to the first AP MLD 101 and establishes a multi-link with the first AP MLD 101; the first message frame is used to initiate key negotiation with the non-AP MLD 102.

[0151] In WLANs, to achieve higher throughput and lower network latency, the Multi-Link Operation (MLO) mechanism has been introduced. MLO enables devices that support this function to establish multiple links between multiple frequency bands, thereby increasing the number of data transmission paths and improving network bandwidth utilization efficiency.

[0152] In the MLO mechanism, devices supporting MLO are called multi-link devices (MLDs). Under this mechanism, devices can flexibly select the best link for data transmission, improving network reliability and flexibility. Especially when a non-AP MLD roams from one AP MLD to another, MLO allows the device to smoothly switch to the target AP MLD and establish a new link for data transmission. Specifically, the non-AP MLD sends a request frame to the current AP MLD to initiate the roaming process. The AP MLD receiving the request frame sends a response frame, confirming that the non-AP MLD can roam to the target AP MLD. Optionally, the non-AP MLD remains in state 4 during and after the roaming process. For example, in state 4, the non-AP MLD sends a request frame to the current AP MLD and receives a response frame from the current AP MLD.

[0153] The next-generation Wi-Fi technology, Ultra High Reliability (UHR) 802.11bn, aims to improve the reliability of wireless LAN connections, reduce latency, and lower device power consumption. In particular, it achieves more efficient network communication by supporting Multi-Link Operation (MLO), and most devices supporting this technology are designed as Multi-Link Devices (MLDs) to flexibly switch between multiple Access Points (APs), enhancing network transmission stability and capacity. However, existing technologies do not explicitly define the key negotiation process during roaming, leading to potential security vulnerabilities. Specifically, although a non-AP MLD can complete Request / response interactions with an existing AP MLD during roaming, after completing these interactions, the non-AP MLD still needs to complete a full key negotiation (including unicast and multicast keys) with the target AP MLD before secure data communication can occur. If a device fails to complete the necessary key negotiation after roaming to the target device, communication between devices may lack sufficient security, leading to data leakage, communication interruptions, and even affecting the stability and throughput of the entire network. This problem not only affects the normal operation of the equipment, but also fails to meet the requirements of UHR technology for low latency and high reliability.

[0154] In this embodiment of the disclosure, after a non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD determines and sends a first message frame; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD. Specifically: before the first AP MLD determines the first message frame, the non-AP MLD initiates a roaming request to the second AP MLD via a roaming request frame. After receiving the request frame, the second AP MLD forwards information containing non-AP MLD related information (e.g., the non-AP MLD's MLD MAC address, the links to be established, and the MAC addresses of each link, etc.) to the first AP MLD. This information enables the first AP MLD to understand the non-AP MLD's roaming needs and prepare for access (e.g., the first AP MLD allocates Link IDs and related resources). The second AP MLD then packages the information prepared by the first AP MLD into a response frame and returns it to the non-AP MLD; the non-AP MLD can determine from the received response frame that the first AP MLD has completed the multi-link establishment. In other words, once the request / response interaction between the non-AP MLD and the second AP MLD is completed, it indicates that the non-AP MLD and the first AP MLD have successfully established a multi-link. At this time, the first AP MLD initiates key negotiation with the non-AP MLD through the first message frame. Therefore, this disclosure specifies the timing and triggering conditions for key negotiation during roaming, further improving the key negotiation mechanism for multi-link devices during roaming, enabling it to meet the high reliability and low latency requirements of UHR. It should be noted that in wireless communication, a message frame is actually a special type of wireless frame. A wireless frame refers to the basic data unit transmitted in a wireless network, typically including control information, data payload, and possibly management information. A message frame is one such unit, carrying specific control or management information and used for initiating requests, responses, status notifications, etc., during communication. Message frames are not limited to transmitting user data; they are also frequently used for system-level operations such as signal transmission, connection management, and key negotiation. Therefore, all message frames can be considered part of a wireless frame, possessing a standardized format and function, and conforming to the requirements of wireless communication protocols.

[0155] Step 202: Under the first link in the multi-link system, the first AP MLD 101 sends the first message frame; correspondingly, the non-AP MLD 102 receives the first message frame.

[0156] In this embodiment of the disclosure, the first link refers to any one of the multiple links already established between the first AP MLD and the non-AP MLD in a multi-link environment. By selecting the first link to send the first message frame, it is ensured that the key negotiation process can be carried out quickly and effectively in a multi-link environment, thereby laying a secure foundation for subsequent data transmission.

[0157] Optionally, the non-AP MLD receives the first message frame in state 3.

[0158] In some embodiments, the first message frame includes at least one of the following:

[0159] Key identifier PMKID;

[0160] ANounce value;

[0161] The ANounce value is determined based on the Multi-Link Device Media Access Control (MLD) MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

[0162] In this embodiment, after successfully re-establishing the multi-link connection between the non-AP MLD and the first AP MLD, two security mechanisms are established between the two devices: Pairwise Master Key Security Association (PMKSA) and Pairwise Transient Key Security Association (PTKSA). PTKSA is used to encrypt and decrypt MAC Protocol Data Units (MPDUs) with individual addresses on all configured links. Furthermore, PTKSA can also be used to store and manage the security association information of the Pair Transient Key (PTK), ensuring that a different PTK is used in each session or link. The PTK is a specific key derived from the PMK, and PMKSA is a set of security information associated with the Pair Master Key (PMK), managing the generation and use of the PMK. The Pair Master Key Identifier (PMKID) indicates which master key (PMK) the non-AP MLD device should use to generate the subsequent encryption key (PTK). The PTK generation process relies not only on the PMK but also on unique information from both communicating parties (such as the device's MAC address and random numbers) to ensure that the encryption key is different for each session, thus avoiding security risks. The PMK can be the same as that used by the non-AP MLD and the source AP MLD (second AP MLD).

[0163] The ANounce value is a random number calculated from the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD, and is used to calculate the PTK. By including the device's MAC address in the calculation, the ANounce value ensures the uniqueness and security of each key negotiation process. Because the MAC address is a unique identifier for the device, the ANounce value generated using these addresses increases security. Once the unicast key is generated, the device can use this key to encrypt and decrypt data, thereby ensuring the confidentiality and integrity of data transmission.

[0164] In this embodiment of the disclosure, by carrying PMKID and ANounce values ​​in the first message frame, the correctness and uniqueness of the unicast key are ensured, which helps to achieve a fast, reliable and secure subsequent encryption process.

[0165] In some embodiments, after the non-AP MLD sends a roaming request frame to the second AP MLD, a first radio frame sent by the second AP MLD is received; wherein the first radio frame includes at least one of the following:

[0166] The MLD MAC address of the non-AP MLD;

[0167] The non-AP MLD requests link information for the multi-link established with the first AP MLD.

[0168] In this embodiment, the first AP MLD receives a first radio frame sent by the second AP MLD; wherein the first radio frame carries the MLD MAC address of the non-AP MLD. The MLD MAC address is an address used to uniquely identify a multi-link device (MLD). In a multi-link device, the MLD MAC address is typically considered a global identifier for the device. This address is used to identify the non-AP MLD in the network and serves as the device's identity in subsequent signaling interactions. The first AP MLD can calculate the ANounce value using this address. Furthermore, the first radio frame may also carry link information for the non-AP MLD to establish multiple links with the first AP MLD; wherein the multi-link information includes, but is not limited to, the link ID that the non-AP MLD needs to establish with the first AP MLD and the link MAC address corresponding to each link. The link MAC address is an independent MAC address corresponding to each link, used for the source and destination addresses of link-layer data frames. In a multi-link device, each link has an independent MAC address, enabling the device to transmit data simultaneously on multiple links without conflict. With this link information, the second AP MLD can understand the link type and link configuration requested by the non-AP MLD, and then make corresponding configuration adjustments to ensure smooth connection between devices.

[0169] In some embodiments, the names of information, etc., are not limited to the names described in the embodiments. Terms such as "information", "message", "signal", "signaling", "report", "configuration", "indication", "instruction", "command", "channel", "parameter", "domain", "field", "symbol", "symbol", "codebook", "codeword", "codepoint", "bit", "data", "program", and "chip" can be used interchangeably.

[0170] In some embodiments, terms such as “moment,” “point in time,” “time,” and “time location” can be used interchangeably, as can terms such as “duration,” “segment,” “time window,” “window,” and “time.”

[0171] In some embodiments, terms such as wireless access scheme and waveform can be used interchangeably.

[0172] In some embodiments, terms such as "certain," "preset," "default," "set," "indicated," "a certain," "any," and "first" can be used interchangeably. "Certain A," "preset A," "default A," "set A," "indicated A," "a certain A," "any A," and "first A" can be interpreted as A pre-defined in a protocol or the like, or as A obtained through setting, configuration, or instruction, or as specific A, a certain A, any A, or first A, but are not limited thereto.

[0173] In some embodiments, the determination or judgment can be made by a value represented by 1 bit (0 or 1), or by a true or false value (boolean), or by a comparison of numerical values ​​(e.g., a comparison with a predetermined value), but is not limited thereto.

[0174] In some embodiments, "not expecting to receive" can be interpreted as not receiving on time domain resources and / or frequency domain resources, or as not performing subsequent processing on the data after receiving it; "not expecting to send" can be interpreted as not sending, or as sending but not expecting the receiver to respond to the sent content.

[0175] The communication method involved in the embodiments of this disclosure may include step 201 or step 202. For example, step 201 may be implemented as a standalone embodiment, step 202 may be implemented as a standalone embodiment, and step 201+202 may be implemented as a standalone embodiment.

[0176] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0177] Figure 3 is a second interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 3, the embodiments of the present disclosure relate to a communication method, which includes:

[0178] Step 301, non-AP MLD 102 determines a second message frame; wherein, the second message frame is used to respond to the first AP

[0179] Key negotiation initiated by MLD101.

[0180] In this embodiment, the non-AP MLD determines a second message frame in response to the first message frame sent by the first AP MLD to initiate key negotiation. Specifically, after receiving the first message frame (message1) sent by the first AP MLD on the first link (i.e., any one of the multiple links established with the first AP MLD), the non-AP MLD generates a second message frame (message2) based on the message content. This message frame is used to respond to the key negotiation process initiated by the first AP MLD, so that both parties can use the same encryption key in subsequent data transmission, ensuring the security of communication.

[0181] In some embodiments, the second message frame includes at least one of the following information 1 to information 5:

[0182] Information 1: SNounce value; wherein the SNounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD, and is used to generate a unicast key during the key negotiation process.

[0183] The SNounce value is a random number calculated from the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the target AP MLD, and is used in the PTK calculation. By including the device's MAC address in the calculation, the SNounce value ensures the uniqueness and security of each key negotiation process. Because the MAC address is a unique identifier for the device, the SNounce value generated using these addresses increases security. Once the unicast key (PTK) is generated, the device can use this key to encrypt and decrypt data, thereby ensuring the confidentiality and integrity of data transmission.

[0184] Information 2: The non-AP MLD requests the link information of the multi-link established with the first AP MLD.

[0185] In some embodiments, after receiving the first message frame, the non-AP MLD is ready to communicate with the first AP MLD. Therefore, it needs to reconfirm and provide its link information (including but not limited to link ID, link MAC address, etc.) to ensure that the first AP MLD understands the specific link it is communicating with. It is important to note that the Link ID carried in the second message frame may be the same as or different from the Link ID carried in the first radio frame. That is, the Link ID carried by the non-AP MLD in the Request frame sent to the second AP MLD may be the same as or different from the Link ID carried by the non-AP MLD in the second message frame sent to the first AP MLD. In some cases, after receiving the first radio frame, the first AP MLD may reject the non-AP MLD's request to establish certain links based on the current network environment or resource conditions. Therefore, in the second message frame responding to the first message frame, the non-AP MLD can identify the link ID and the corresponding MAC address of the link that it needs (requests / desires) to establish at least one link with the first AP MLD.

[0186] Information 3: BSSID of the first AP MLD:

[0187] The second message frame may also include the Basic Service Set Identifier (BSSID) of the target AP MLD, used to identify the specific AP network communicating with the non-AP MLD. This facilitates more precise link and network management in multi-link environments.

[0188] Information 4: TSF offset information of the non-AP MLD under the corresponding link.

[0189] The second message frame may also include the time synchronization function (TSF) offset information of the non-AP MLD under the corresponding link. The TSF offset information provides the difference information of time synchronization between different links. Especially when the non-AP MLD needs to maintain a connection with multiple AP MLDs at the same time, the TSF offset enables the non-AP MLD to accurately control the communication timing between each link, ensuring smooth and synchronized data transmission. This helps the non-AP MLD to seamlessly switch between different APs and avoids data loss or transmission interruption.

[0190] Information 5: RSNE information element.

[0191] The second message frame may also include a Robust Security Network Element (RSNE) information element, which provides detailed information on encryption negotiation and security protocols, further ensuring the confidentiality and integrity of data throughout the communication process.

[0192] In this embodiment of the disclosure, by carrying one or more of the above-mentioned information in the second message frame, the key negotiation process can be effectively supported, ensuring the security, stability, and synchronization between links, which helps to achieve efficient and reliable data transmission in a multi-link environment. The introduction of these elements enables the entire system to manage key negotiation, link selection, and time synchronization more accurately and intelligently when handling multi-link communication, thereby improving network security and performance.

[0193] In some embodiments, the MLD MAC address of the first AP MLD is obtained during the establishment of a multi-link with the second AP MLD, or is obtained through a response frame sent by the second AP MLD; wherein the response frame is used to respond to a roaming request frame sent by the non-AP MLD.

[0194] In this embodiment, the MLD MAC address of the first AP MLD can be obtained through the process of establishing a multi-link with the second AP MLD, or through a response frame sent by the second AP MLD. Specifically, the non-AP MLD can obtain the MAC address of the target AP MLD in two ways: first, during the process of establishing a multi-link with the existing AP MLD, the non-AP MLD obtains the MAC address of the target AP MLD by exchanging information; second, the existing AP MLD responds to a roaming request frame sent by a non-AP device, in which the second AP MLD will contain the MAC address of the target AP MLD. In this way, the non-AP MLD can accurately obtain the MAC address of the target AP MLD, and then perform subsequent multi-link establishment and key negotiation operations. This process can improve the accuracy and security in multi-link communication, ensure the correct identification and communication of the target AP MLD in multi-link communication, and thus achieve more efficient device roaming and connection stability.

[0195] In step 302, the non-AP MLD 102 sends the second message frame under the first link; correspondingly, the first AP MLD 101 receives the second message frame.

[0196] In this embodiment, the non-AP MLD sends a second message frame on the first link, and the first AP MLD receives the message frame. This process is the second step of key negotiation. The non-AP MLD transmits necessary information, such as the SNounce value and link information, to the first AP MLD through this message frame to complete the corresponding operations in key negotiation. This operation ensures that the non-AP MLD and the first AP MLD can successfully complete key negotiation in a multi-link environment, laying the foundation for subsequent secure data transmission. In this way, key negotiation can guarantee the security of data transmission, while supporting the stability and efficiency of multi-link communication, avoiding potential security risks and communication interruptions, and ensuring seamless and secure connections between devices.

[0197] The communication method involved in the embodiments of this disclosure may include step 301 or step 302. For example, step 301 may be implemented as a separate embodiment, step 302 may be implemented as a separate embodiment, and steps 301+302 may be implemented as a separate embodiment.

[0198] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0199] Figure 4 is a third interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 4, the embodiments of the present disclosure relate to a communication method, which includes:

[0200] Step 401, the first AP MLD 101 determines a third message frame; wherein, the third message frame is sent by the first AP MLD 101 after receiving the second message frame; the third message frame is used to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD 101.

[0201] In some embodiments, after receiving the second message frame, the first AP MLD determines a third message frame. The purpose of the third message frame is to distribute keys for encrypting multicast and / or broadcast data to the non-AP MLD. Optionally, the first AP MLD can generate a unicast key (PTK) locally using the information carried in the first and second message frames. Then, it uses the established unicast key (PTK) to encrypt the multicast key (Group Temporal Key, GTK) and / or the multicast integrity key (Integrity Group Temporal Key, IGTK) used for encrypting multicast and / or broadcast data, and sends it to the non-AP MLD. Since multicast and broadcast are managed uniformly by the AP, the first AP MLD needs to actively and securely distribute these keys to all relevant devices to ensure the encryption and integrity protection of multicast and broadcast data. By carrying the keys for encrypting multicast and / or broadcast data in the third message frame, this embodiment of the disclosure can guarantee the security of multicast and broadcast data transmission between the non-AP MLD and the first AP MLD in a multi-link environment. This not only ensures the confidentiality and integrity of the data, but also improves network security, prevents potential man-in-the-middle attacks or data leaks, and ensures that multicast and broadcast data can be reliably and seamlessly transmitted between devices.

[0202] In some embodiments, the third message frame includes at least one of the following information 1 to information 5:

[0203] Information 1: The ANounce value.

[0204] In the third radio frame, the first AP MLD carries the ANounce value again, mainly to reconfirm the random number used by the first AP MLD, thus increasing security.

[0205] Information 2: The multicast temporary key GTK determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation.

[0206] In this embodiment of the disclosure, after successfully re-establishing the multi-link between the non-AP MLD and the first AP MLD, if management frame protection is enabled, a Group Temporal Key Security Association (GTKSA) and an Integrity Group Temporal Key Security Association (IGTKSA) are established between the non-AP MLD and the first AP MLD for each configured link. The GTKSA manages and protects the encryption process of multicast data for each link, including managing the use of GTK; the IGTKSA manages the integrity protection of multicast data, ensuring that data is not tampered with during transmission, including managing the use of IGTK. GTK is a temporary key used to protect multicast data. It ensures the confidentiality and integrity of multicast data during transmission, preventing data leakage and tampering. By sharing this key among multiple devices, the security of data transmission can be ensured.

[0207] Information 3: The multicast integrity key IGTK determined by the first AP MLD for each link to exchange frames with the non-AP MLD after key negotiation.

[0208] IGTK is used to ensure the integrity of broadcast and multicast data during transmission and to prevent data tampering.

[0209] Information 4: Link information of at least one link determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation.

[0210] In the third message frame, the first AP MLD identifies the link information of at least one link that the first AP MLD determines is communicating with the non-AP MLD, including but not limited to the Link ID and the MAC address under the corresponding link, to ensure correct link establishment and management.

[0211] In some embodiments, each pair of GTKs or IGTKs carried in the third message frame of the first AP MLD corresponds to a specific link ID. That is, the first AP MLD manages and assigns a GTK or IGTK separately for each link, and these keys are distinguished according to the link ID, thereby ensuring that the data transmission of each link is independently encrypted and protected, preventing data interference or leakage between different links, and improving the overall communication security.

[0212] Information 5: The Basic Service Set Identifier (BSSID) of the first AP MLD.

[0213] Among them, BSSID is used to identify the basic service set where the first AP MLD is located, providing network identification for the device.

[0214] In this embodiment of the disclosure, by distributing a multicast key (GTK) and a multicast integrity key (IGTK), the non-AP MLD can securely receive and send multicast and broadcast traffic. This ensures the encryption and integrity protection of multicast and broadcast data in a multi-link environment, improving the security of the wireless network. Simultaneously, the carried management information such as the ANounce value, link information, and BSSID provides necessary configuration and management support for communication between the non-AP MLD and the first AP MLD, ensuring smooth multi-link operation.

[0215] Step 402, the first AP MLD 101 sends the third message frame; correspondingly, the non-AP MLD 102 receives the third message frame.

[0216] In this embodiment, the first AP MLD sends a third message frame, which is received by the non-AP MLD. This process marks the completion of a crucial step in key negotiation, whereby the AP distributes the multicast key (GTK) and multicast integrity key (IGTK) to the non-AP MLD, thereby ensuring that the non-AP MLD can securely encrypt and verify the integrity of multicast / broadcast data in a multi-link environment. Through this step, the non-AP MLD has obtained the necessary keys and can conduct secure data transmission in multi-link communication, thus enhancing the security and data protection capabilities of the wireless network.

[0217] Optionally, the first AP MLD sends the third message frame on a first link established with the non-AP MLD, or the first AP MLD sends the third message frame on one or more links established with the non-AP MLD other than the first link. This disclosure does not impose specific limitations.

[0218] The communication method involved in the embodiments of this disclosure may include step 401 or step 402. For example, step 401 may be implemented as a standalone embodiment, step 402 may be implemented as a standalone embodiment, and steps 401+402 may be implemented as standalone embodiments.

[0219] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0220] Figure 5 is a fourth interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 5, the embodiments of the present disclosure relate to a communication method, which includes:

[0221] Step 501: The first AP MLD 101 or non-AP MLD 102 determines a trigger frame; wherein the trigger frame instructs the second AP MLD 103 to stop sending buffered downlink data to the non-AP MLD 102 or the first AP MLD 101, or to stop sending buffered downlink data to the non-AP MLD 102 or the first AP MLD 101 after the first duration ends.

[0222] In this scenario, after the non-AP MLD and the second AP MLD complete their request / response interaction, the second AP MLD may continue to send cached downlink data to the non-AP MLD or forward data to the target AP MLD until certain conditions for stopping transmission are met. This practice can lead to redundancy or delays in data transmission during roaming, affecting network efficiency and stability. This is especially true when the first AP MLD is ready to take over data transmission, as unnecessary downlink data may still be transmitted or forwarded, wasting bandwidth and resources.

[0223] To avoid such redundant transmission and data delays, embodiments of this disclosure propose that, after key negotiation is completed, a trigger frame is sent to the current AP MLD via a non-AP MLD or the target AP MLD, explicitly indicating that buffered downlink data or forwarded data no longer needs to be sent to the target AP MLD. Simultaneously, a timeout value can be set, after which the existing AP MLD will no longer perform these operations. This mechanism effectively avoids redundant data transmission, reduces latency, improves network efficiency, and ensures the security and accuracy of data transmission.

[0224] Step 502, the first AP MLD 101 or non-AP MLD 102 sends the trigger frame; correspondingly, the second AP MLD 103 receives the trigger frame.

[0225] Optionally, after sending the third message frame, the first AP MLD sends a first trigger frame to the second AP MLD; wherein the first trigger frame instructs the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or to stop sending buffered downlink data to the non-AP MLD or the first AP MLD after the first duration has ended.

[0226] Optionally, after receiving the third message frame, the non-AP MLD sends a second trigger frame to the second AP MLD; wherein the second trigger frame is used to instruct the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or to stop sending buffered downlink data to the non-AP MLD or the first AP MLD after the first duration ends.

[0227] The communication method involved in the embodiments of this disclosure may include step 501 or step 502. For example, step 501 may be implemented as a standalone embodiment, step 502 may be implemented as a standalone embodiment, and steps 501+502 may be implemented as standalone embodiments.

[0228] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0229] Figure 6 is a fifth interactive schematic diagram of a communication method according to an embodiment of the present disclosure. As shown in Figure 6, the embodiments of the present disclosure relate to a communication method, which includes:

[0230] Step 601, the first AP MLD 101 determines the first message frame; wherein, the first message frame is sent by the first AP MLD 101 after the non-AP MLD 102 roams from the second AP MLD 103 to the first AP MLD 101 and establishes a multi-link with the first AP MLD 101; the first message frame is used to initiate key negotiation with the non-AP MLD 102.

[0231] After the non-AP MLD completes the request / response interaction with the second AP MLD (indicating that the non-AP MLD and the target AP MLD have completed the multi-link establishment), the first AP MLD sends a first message frame (message1) to the non-AP MLD on one of the established multi-links. Message1 includes one or more of PMKID and ANounce values. The ANounce value is calculated from the MLD MAC address of the non-AP MLD and the MLD MAC address of the first AP MLD. The first AP MLD obtains the MLD MAC address of the non-AP MLD and sends it to the target AP MLD after the second AP MLD receives the request frame sent by the non-AP MLD. This message also contains information about the multi-links that the non-AP MLD needs to establish with the target AP MLD, such as the Link ID and the corresponding MAC address under this link.

[0232] Step 602: Under the first link in the multi-link system, the first AP MLD 101 sends the first message frame; correspondingly, the non-AP MLD 102 receives the first message frame.

[0233] In this embodiment of the disclosure, the first link refers to any one of the multiple links already established between the first AP MLD and the non-AP MLD in a multi-link environment. By selecting the first link to send the first message frame, it is ensured that the key negotiation process can be carried out quickly and effectively in a multi-link environment, thereby laying a secure foundation for subsequent data transmission.

[0234] Step 603, non-AP MLD 102 determines the second message frame; wherein the second message frame is used to respond to the key negotiation initiated by the first AP MLD 101.

[0235] In this scenario, the non-AP MLD replies with a second message frame on the first link after receiving the first message frame, wherein the second message frame includes at least one of the following:

[0236] The SNounce value is calculated from the MLD MAC address of the non-AP MLD and the MLD MAC address of the target AP MLD. The non-AP MLD can obtain the MAC address of the first AP MLD by: 1. during the establishment of a multi-link with the second AP MLD; 2. or through the response frame replied by the second AP MLD.

[0237] The Link ID and the corresponding MAC address for this link; the Link ID may be exactly the same as or different from the Link ID in the Request frame. For example, the Link ID in the second message frame may be a subset of the Link ID in the Request frame (indicating that the first AP MLD rejected part of the link).

[0238] The BSSID of the BSS where the first AP MLD is located.

[0239] TSF offset refers to the TSF offset information between the target AP MLD and the existing AP MLD on this link.

[0240] RSNE information elements, etc.

[0241] In step 604, non-AP MLD 102 sends the second message frame under the first link; correspondingly, the first AP MLD 101 receives the second message frame.

[0242] In this embodiment, the non-AP MLD sends a second message frame on the first link, and the first AP MLD receives the message frame. This process is the second step of key negotiation. The non-AP MLD transmits necessary information, such as the SNounce value and link information, to the first AP MLD through the message frame to complete the corresponding operations in key negotiation.

[0243] Step 605, the first AP MLD 101 determines a third message frame; wherein, the third message frame is sent by the first AP MLD 101 after receiving the second message frame; the third message frame is used to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD 101.

[0244] The first AP MLD replies with a third message frame to the non-AP MLD, wherein the third message frame includes at least one of the following:

[0245] The ANounce value is consistent with the ANounce value in step 601;

[0246] GTK;

[0247] IGTK;

[0248] Link information of at least one link through which the first AP MLD communicates with the non-AP MLD, including but not limited to Link ID and MAC address under the corresponding link;

[0249] The BSSID of the first AP MLD.

[0250] Step 606: The first AP MLD 101 sends the third message frame; correspondingly, the non-AP MLD 102 receives the third message frame.

[0251] The first AP MLD sends the third message frame, which is received by the non-AP MLD. This process marks a crucial step in key negotiation: the AP distributes the multicast key (GTK) and multicast integrity key (IGTK) to the non-AP MLD, ensuring that the non-AP MLD can securely encrypt and verify the integrity of multicast / broadcast data in a multi-link environment. Through this step, the non-AP MLD obtains the necessary keys, enabling secure data transmission in multi-link communication, thereby enhancing the security and data protection capabilities of the wireless network.

[0252] In some embodiments, the method further includes:

[0253] After sending the third message frame, the first AP MLD sends a first trigger frame to the second AP MLD; wherein, the first trigger frame is used to instruct the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or to stop sending buffered downlink data to the non-AP MLD or the first AP MLD after the first duration ends;

[0254] Or,

[0255] After receiving the third message frame, the non-AP MLD sends a second trigger frame to the second AP MLD; wherein the second trigger frame is used to instruct the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or to stop sending buffered downlink data to the non-AP MLD or the first AP MLD after the first duration ends.

[0256] The communication method involved in the embodiments of this disclosure may include at least one of steps 601 to 606. For example, step 601 may be implemented as an independent embodiment, step 602 may be implemented as an independent embodiment, step 603 may be implemented as an independent embodiment, step 604 may be implemented as an independent embodiment, step 605 may be implemented as an independent embodiment, step 606 may be implemented as an independent embodiment, steps 601+602 may be implemented as independent embodiments, steps 603+604 may be implemented as independent embodiments, and steps 605+606 may be implemented as independent embodiments, but are not limited thereto.

[0257] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0258] Figure 7 is a flowchart illustrating one of the communication methods according to an embodiment of the present disclosure.

[0259] As shown in Figure 7, the above method can be applied to the first AP MLD101, and the above method includes:

[0260] Step 701: After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD.

[0261] Optionally, in this embodiment of the disclosure, the first message frame includes at least one of the following:

[0262] Key identifier PMKID;

[0263] ANounce value.

[0264] Optionally, in this embodiment of the disclosure, the ANounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

[0265] Optionally, in this embodiment of the disclosure, the method further includes:

[0266] Receive a first radio frame sent by the second AP MLD; wherein the first radio frame includes at least one of the following:

[0267] The MLD MAC address of the non-AP MLD;

[0268] The non-AP MLD requests link information for the multi-link established with the first AP MLD.

[0269] Step 702: Receive a second message frame sent by the non-AP MLD under the first link; wherein the second message frame is used to respond to the key negotiation initiated by the first AP MLD.

[0270] Optionally, in this embodiment of the disclosure, the second message frame includes at least one of the following:

[0271] SNounce value;

[0272] The non-AP MLD requests the link information of the multi-link established with the first AP MLD;

[0273] The BSSID of the first AP MLD;

[0274] The non-AP MLD requests TSF offset information under at least one link established with the first AP MLD;

[0275] RSNE information element.

[0276] Optionally, in this embodiment of the disclosure, the SNounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

[0277] Optionally, in this embodiment of the disclosure, the MLD MAC address of the first AP MLD is obtained during the process of establishing a multi-link between the non-AP MLD and the second AP MLD, or is obtained through a response frame sent by the second AP MLD; wherein, the response frame is used to respond to the roaming request frame sent by the non-AP MLD.

[0278] Step 703: After receiving the second message frame, the first AP MLD sends a third message frame; wherein the third message frame is used to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD.

[0279] Optionally, in this embodiment of the disclosure, the third message frame includes at least one of the following:

[0280] The ANounce value;

[0281] The link information of at least one link determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation is completed;

[0282] The first AP MLD determines the multicast temporary key GTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0283] The first AP MLD determines the multicast integrity key IGTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0284] The BSSID of the first AP MLD.

[0285] Step 704: Determine a first trigger frame; wherein the first trigger frame instructs the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or the first trigger frame is used to instruct that after the first duration ends, the sending of buffered downlink data to the non-AP MLD or the first AP MLD should be stopped.

[0286] Step 705: Send the first trigger frame to the second AP MLD.

[0287] The communication method involved in the embodiments of this disclosure may include at least one of steps 701 to 705. For example, step 701 may be implemented as an independent embodiment, step 702 may be implemented as an independent embodiment, step 703 may be implemented as an independent embodiment, step 704 may be implemented as an independent embodiment, step 705 may be implemented as an independent embodiment, steps 701+702 may be implemented as an independent embodiment, steps 702+703 may be implemented as an independent embodiment, steps 704+705 may be implemented as an independent embodiment, steps 701+702+703+704+705 may be implemented as an independent embodiment, but are not limited thereto.

[0288] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0289] Figure 8 is a second schematic flowchart illustrating a communication method according to an embodiment of the present disclosure.

[0290] As shown in Figure 8, the above method can be applied to non-AP MLD 102, and the method includes:

[0291] Step 801: After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, it receives a first message frame sent by the first AP MLD; wherein, the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

[0292] Step 802: Determine the second message frame; wherein the second message frame is used to respond to the key negotiation initiated by the first AP MLD.

[0293] Step 803: Send the second message frame under the first link.

[0294] Optionally, in this embodiment of the disclosure, the second message frame includes at least one of the following:

[0295] SNounce value;

[0296] The non-AP MLD requests the link information of the multi-link established with the first AP MLD;

[0297] The BSSID of the first AP MLD;

[0298] The non-AP MLD requests TSF offset information under at least one link established with the first AP MLD;

[0299] RSNE information element.

[0300] Optionally, in this embodiment of the disclosure, the SNounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

[0301] Step 804, the non-AP MLD receives a third message frame; wherein the third message frame is used by the first AP MLD to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD.

[0302] Optionally, in this embodiment of the disclosure, the third message frame includes at least one of the following:

[0303] The ANounce value;

[0304] The link information of at least one link determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation is completed;

[0305] The first AP MLD determines the multicast temporary key GTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0306] The first AP MLD determines the multicast integrity key IGTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed;

[0307] The BSSID of the first AP MLD.

[0308] Step 805: Determine a second trigger frame; wherein the second trigger frame instructs the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or the second trigger frame is used to instruct that after the first duration ends, the sending of buffered downlink data to the non-AP MLD or the first AP MLD should be stopped.

[0309] Step 806: Send the second trigger frame to the second AP MLD.

[0310] The communication method involved in the embodiments of this disclosure may include at least one of steps 801 to 806. For example, step 801, step 802, step 803, step 804, step 805, and step 806 may be implemented as independent embodiments.

[0311] Steps 801 and 802 can be implemented as independent embodiments, steps 802 and 803 can be implemented as independent embodiments, steps 804 and 805 can be implemented as independent embodiments, steps 805 and 806 can be implemented as independent embodiments, steps 801, 802, 803, 804, 805, and 806 can be implemented as independent embodiments, but are not limited thereto.

[0312] In some embodiments, the steps and their optional implementations in other embodiments described before or after this embodiment, as well as other related parts in the specification, can be referred to, and will not be repeated here.

[0313] This disclosure also proposes an apparatus (also referred to as a communication device, etc.) for implementing any of the above methods. For example, an apparatus is proposed that includes units or modules for implementing the steps performed by the terminal in any of the above methods. Furthermore, another apparatus is proposed that includes units or modules for implementing the steps performed by a network device (e.g., an access network device, a core network functional node, a core network device, etc.) in any of the above methods.

[0314] It should be understood that the division of units or modules in the above device is only a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, the units or modules in the device can be implemented by a processor calling software: for example, the device includes a processor connected to a memory containing instructions. The processor calls the instructions stored in the memory to implement any of the above methods or to implement the functions of the units or modules in the above device. The processor can be, for example, a general-purpose processor, such as a Central Processing Unit (CPU) or a microprocessor, and the memory can be internal or external to the device. Alternatively, the units or modules in the device can be implemented in the form of hardware circuits. The functionality of some or all of the units or modules can be achieved through the design of these hardware circuits, which can be understood as one or more processors. For example, in one implementation, the hardware circuit is an application-specific integrated circuit (ASIC). The functionality of some or all of the units or modules is achieved through the design of the logical relationships between the components within the circuit. In another implementation, the hardware circuit can be implemented using a programmable logic device (PLD). Taking a field-programmable gate array (FPGA) as an example, it can include a large number of logic gates. The connection relationships between the logic gates are configured through configuration files, thereby achieving the functionality of some or all of the units or modules. All units or modules of the above device can be implemented entirely through processor-called software, entirely through hardware circuits, or partially through processor-called software with the remaining parts implemented through hardware circuits.

[0315] In this embodiment, the processor is a circuit with signal processing capabilities. In one implementation, the processor can be a circuit with instruction read and execute capabilities, such as a Central Processing Unit (CPU), a microprocessor, a graphics processing unit (GPU) (which can be understood as a microprocessor), or a digital signal processor (DSP). In another implementation, the processor can implement certain functions through the logical relationships of hardware circuits. The logical relationships of the aforementioned hardware circuits are fixed or reconfigurable. For example, the processor is a hardware circuit implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), such as an FPGA. In a reconfigurable hardware circuit, the process of the processor loading a configuration document and configuring the hardware circuit can be understood as the process of the processor loading instructions to implement the functions of some or all of the above units or modules. Furthermore, it can also be a hardware circuit designed for artificial intelligence, which can be understood as an ASIC, such as a Neural Network Processing Unit (NPU), a Tensor Processing Unit (TPU), or a Deep Learning Processing Unit (DPU).

[0316] Figure 9 is a schematic diagram of the structure of the first AP MLD proposed in an embodiment of this disclosure. The first AP MLD is used to perform any of the above methods. In some embodiments, as shown in Figure 9, the first AP MLD 900 may include: a transmitting module 902.

[0317] In some embodiments, the sending module 902 is configured to send a first message frame under the first link after the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD; wherein the first message frame is used to initiate key negotiation with the non-AP MLD.

[0318] Optionally, the sending module 901 is used to perform at least one of the communication steps (such as steps 202, 602, and 702, but not limited thereto) performed by the first AP MLD101 in any of the above methods, which will not be described in detail here.

[0319] In some embodiments, the sending module can be interchanged with the transceiver module or transceiver.

[0320] Figure 10 is a schematic diagram of the structure of a non-AP MLD proposed in an embodiment of this disclosure. The non-AP MLD is used to perform any of the above methods. In some embodiments, as shown in Figure 10, the non-AP MLD 1000 may include a receiving module 1001.

[0321] In some embodiments, the receiving module 1001 is used to receive a first message frame sent by the first AP MLD after the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD; wherein the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

[0322] Optionally, the receiving module 1001 is used to perform at least one of the communication steps (such as step 202, step 602, step 801, but not limited thereto) performed by the non-AP MLD 102 in any of the above methods, which will not be described in detail here.

[0323] In some embodiments, the receiving module can be interchanged with the transceiver module or transceiver.

[0324] Figure 11 is a schematic diagram of the structure of a terminal 1100 (e.g., a user equipment) according to an embodiment of this disclosure. The terminal 1100 may be a chip, chip system, or processor that supports network devices in implementing any of the above methods, or it may be a chip, chip system, or processor that supports a terminal in implementing any of the above methods. The terminal 1100 can be used to implement the methods described in the above method embodiments; for details, please refer to the descriptions in the above method embodiments.

[0325] As shown in Figure 11, terminal 1100 includes one or more processors 1101. The processor 1101 can be a general-purpose processor or a dedicated processor, such as a baseband processor or a central processing unit (CPU). The baseband processor can be used to process communication protocols and communication data, while the CPU can be used to control communication devices (e.g., base stations, baseband chips, terminal devices, terminal device chips, DUs or CUs, etc.), execute programs, and process program data. Terminal 1100 is used to execute any of the above methods.

[0326] In some embodiments, terminal 1100 further includes one or more memories 1102 for storing instructions. Optionally, all or part of the memories 1102 may also be located outside of terminal 1100.

[0327] In some embodiments, the terminal 1100 further includes one or more transceivers 1104. When the terminal 1100 includes one or more transceivers 1104, the transceivers 1104 perform at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps 202, 302, 402, 502, 602, 604, 606, 701, 702, 703, 705, 801, 803, 804, 806, but not limited thereto), and the processor 1101 performs at least one of other steps (e.g., steps 201, 301, 404, 501, 601, 603, 605, 704, 802, 805, but not limited thereto).

[0328] In some embodiments, a transceiver may include a receiver and / or a transmitter, which may be separate or integrated. Optionally, the terms transceiver, transceiver unit, transceiver, transceiver circuit, etc., may be used interchangeably; the terms transmitter, transmitting unit, transmitter, transmitting circuit, etc., may be used interchangeably; and the terms receiver, receiving unit, receiver, receiving circuit, etc., may be used interchangeably.

[0329] In some embodiments, terminal 1100 may include one or more interface circuits 1103. Optionally, interface circuit 1103 is connected to memory 1102, and interface circuit 1103 can be used to receive signals from memory 1102 or other devices, and can be used to send signals to memory 1102 or other devices. For example, interface circuit 1103 can read instructions stored in memory 1102 and send the instructions to processor 1101.

[0330] The terminal 1100 described in the above embodiments may be a user equipment or other communication device, but the scope of the terminal 1100 described in this disclosure is not limited thereto, and the structure of the terminal 1100 may not be limited by FIG11. The communication device may be an independent device or a part of a larger device. For example, the communication device may be: (1) an independent integrated circuit IC, or chip, or chip system or subsystem; (2) a set of one or more ICs, optionally, the IC set may also include storage components for storing data and programs; (3) an ASIC, such as a modem; (4) a module that can be embedded in other devices; (5) a receiver, terminal device, smart terminal device, cellular phone, wireless device, handheld device, mobile unit, vehicle device, network device, cloud device, artificial intelligence device, etc.; (6) others, etc.

[0331] Figure 12 is a schematic diagram of the structure of the chip 1200 proposed in an embodiment of this disclosure. For cases where the terminal 1100 can be a chip or a chip system, please refer to the schematic diagram of the chip 1200 shown in Figure 12, but it is not limited thereto.

[0332] Chip 1200 includes one or more processors 1201, which are used to perform any of the above methods.

[0333] In some embodiments, chip 1200 further includes one or more 1203s. Optionally, interface circuitry 1203 is connected to memory 1202. Interface circuitry 1203 can be used to receive signals from memory 1202 or other devices, and interface circuitry 1203 can be used to send signals to memory 1202 or other devices. For example, interface circuitry 1203 can read instructions stored in memory 1202 and send the instructions to processor 1201.

[0334] In some embodiments, the interface circuit 1203 performs at least one of the communication steps such as sending and / or receiving in the above method (e.g., steps 202, 302, 402, 502, 602, 604, 606, 701, 702, 703, 705, 801, 803, 804, 806, but not limited thereto), and the processor 1201 performs at least one of other steps (e.g., steps 201, 301, 404, 501, 601, 603, 605, 704, 802, 805, but not limited thereto).

[0335] In some embodiments, the terms interface circuit, interface, transceiver pin, transceiver, etc., can be used interchangeably.

[0336] In some embodiments, chip 1200 further includes one or more memories 1202 for storing instructions. Optionally, all or part of the memories 1202 may be located outside of chip 1200.

[0337] This disclosure also proposes a storage medium storing instructions that, when executed on terminal 1100, cause terminal 1100 to perform any of the above methods. Optionally, the storage medium is an electronic storage medium. Optionally, the storage medium is a computer-readable storage medium, but not limited thereto; it may also be a storage medium readable by other devices. Optionally, the storage medium may be a non-transitory storage medium, but not limited thereto; it may also be a temporary storage medium.

[0338] This disclosure also proposes a program product that, when executed by terminal 1100, causes terminal 1100 to perform any of the above methods. Optionally, the program product is a computer program product.

[0339] This disclosure also proposes a computer program that, when run on a computer, causes the computer to perform any of the above methods.

Claims

1. A communication method applied to a first multi-link access point device (AP MLD), characterized in that, include: After a multi-link site device (non-AP MLD) roams from a second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD.

2. The communication method according to claim 1, characterized in that, The first message frame includes at least one of the following: Key identifier PMKID; Random ANounce value.

3. The communication method according to claim 2, characterized in that, The ANounce value is determined based on the Multi-Link Device Media Access Control (MLD) MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

4. The communication method according to any one of claims 1 to 3, characterized in that, The method further includes: Receive a first radio frame sent by the second AP MLD; wherein the first radio frame includes at least one of the following: The MLD MAC address of the non-AP MLD; The non-AP MLD requests link information for the multi-link established with the first AP MLD.

5. The communication method according to any one of claims 1 to 4, characterized in that, The method further includes: The second message frame sent by the non-AP MLD is received under the first link; wherein the second message frame is used to respond to the key negotiation initiated by the first AP MLD.

6. The communication method according to claim 5, characterized in that, The second message frame includes at least one of the following: Random SNounce value; The non-AP MLD requests the link information of the multi-link established with the first AP MLD; The BSSID of the first AP MLD; The non-AP MLD requests time synchronization TSF offset information under at least one link established by the first AP MLD; Protected Service Set Network Extension RSNE Information Elements.

7. The communication method according to claim 6, characterized in that, The SNounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

8. The communication method according to claim 6, characterized in that, The MLD MAC address of the first AP MLD is obtained during the process of establishing a multi-link between the non-AP MLD and the second AP MLD, or is obtained through a response frame sent by the second AP MLD; wherein, the response frame is used to respond to the roaming request frame sent by the non-AP MLD.

9. The communication method according to any one of claims 1 to 8, characterized in that, The method further includes: The first AP MLD sends a third message frame; wherein the third message frame is used to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD.

10. The communication method according to claim 9, characterized in that, The third message frame includes at least one of the following: The ANounce value; The link information of at least one link determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation is completed; The first AP MLD determines the multicast temporary key GTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed; The first AP MLD determines the multicast integrity key IGTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed; The BSSID of the first AP MLD.

11. The communication method according to any one of claims 1 to 10, characterized in that, The method further includes: A first trigger frame is determined; wherein the first trigger frame instructs the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or the first trigger frame is used to instruct that after the first duration ends, the sending of buffered downlink data to the non-AP MLD or the first AP MLD should be stopped; The first trigger frame is sent to the second AP MLD.

12. A communication method applied to non-AP MLD, characterized in that, include: After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, it receives a first message frame sent by the first AP MLD on the first link of the multi-link; wherein, the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

13. The communication method according to claim 12, characterized in that, The method further includes: Determine the second message frame; wherein the second message frame is used to respond to the key negotiation initiated by the first AP MLD; Under the first link, the second message frame is sent.

14. The communication method according to claim 13, characterized in that, The second message frame includes at least one of the following: SNounce value; The non-AP MLD requests the link identifier and / or the MAC address under the link required to establish a multi-link with the first AP MLD; The BSSID of the first AP MLD; The non-AP MLD requests TSF offset information under at least one link established with the first AP MLD; RSNE information element.

15. The communication method according to claim 14, characterized in that, The SNounce value is determined based on the MLD MAC address of the non-AP MLD and / or the MLD MAC address of the first AP MLD.

16. The communication method according to any one of claims 12 to 15, characterized in that, The method further includes: The non-AP MLD receives a third message frame; wherein the third message frame is used by the first AP MLD to distribute a key for encrypting multicast data and / or broadcast data to the non-AP MLD.

17. The communication method according to claim 16, characterized in that, The third message frame includes at least one of the following: The ANounce value; The link information of at least one link determined by the first AP MLD for frame exchange with the non-AP MLD after key negotiation is completed; The first AP MLD determines the multicast temporary key GTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed; The first AP MLD determines the multicast integrity key IGTK corresponding to each link for frame exchange with the non-AP MLD after key negotiation is completed; The BSSID of the first AP MLD.

18. The communication method according to any one of claims 12 to 17, characterized in that, The method further includes: A second trigger frame is determined; wherein the second trigger frame instructs the second AP MLD to stop sending buffered downlink data to the non-AP MLD or the first AP MLD, or the second trigger frame is used to instruct that after the first duration ends, the sending of buffered downlink data to the non-AP MLD or the first AP MLD should be stopped; Send the second trigger frame to the second AP MLD.

19. A communication device, wherein the communication device is a first AP MLD, characterized in that, include: One or more processors; Wherein, the first AP MLD is used to execute the communication method according to any one of claims 1 to 11.

20. A communication device, wherein the communication device is a non-AP MLD, characterized in that, include: One or more processors; The non-AP MLD is used to perform the communication method according to any one of claims 12 to 18.

21. A communication system, characterized in that, Including first-AP MLD and non-AP MLD; Wherein, after a non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, the first AP MLD sends a first message frame on the first link of the multi-link; wherein, the first message frame is used to initiate key negotiation with the non-AP MLD; After the non-AP MLD roams from the second AP MLD to the first AP MLD and establishes a multi-link with the first AP MLD, it receives a first message frame sent by the first AP MLD on the first link of the multi-link; wherein, the first message frame is used by the first AP MLD to initiate key negotiation with the non-AP MLD.

22. A storage medium storing instructions, characterized in that, When the instructions are executed on the communication device, the communication device performs the communication method as described in any one of claims 1 to 11, or performs the communication method as described in any one of claims 12 to 18.

23. A program product comprising at least one of a program and instructions, characterized in that, When at least one of the programs or instructions is executed by a communication device, it implements the communication method of any one of claims 1 to 11, or the communication method of any one of claims 12 to 18.