Multi-Link TDLS Key Derivation Across Multiple WLAN Authenticators

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of managing security associations in WLAN multi-link communication systems is increased due to the presence of multiple authenticators, particularly when legacy STAs and non-AP MLDs need to communicate, requiring additional network resources and complicating the establishment of secure communication links.

Innovation Solution

A method for WLAN multi-link communication that includes sending and receiving discovery and setup requests with enhanced authentication and key management (AKM) suites to accommodate multiple authenticator identities, allowing for the establishment of a Tunneled Direct Link Setup (TDLS) between legacy STAs and non-AP MLDs, using modified TDLS Discovery and Setup frames to negotiate keys bound to both affiliated and AP MLD authenticators.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authenticators are used in AP MLD to establish security associations, then security coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomplexity of managing security associations
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple authenticator identities into a unified TDLS key derivation process. Instead of treating each authenticator separately, the system combines their identities (BSSID and AP MLD address) into a single key derivation input, allowing one security association to cover multiple authenticators. This reduces the number of separate security associations needed while maintaining comprehensive security coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal key derivation mechanism that works across different authenticator types (legacy STA and non-AP MLD). The enhanced AKM suite enables a single TDLS setup procedure to establish security associations that are valid across multiple authenticators, making the system multi-functional rather than requiring separate procedures for each authenticator type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If legacy STAs and non-AP MLDs communicate through multiple authenticators, then communication compatibility is improved, but network resource requirements increase

Engineering Contradiction:
Improvecommunication compatibilityVSAvoidnetwork resources
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent combines the identity information of multiple authenticators (BSSID and AP MLD address) into a unified key derivation process. This merging allows the system to establish a single security association that covers communication across multiple authenticators, reducing the number of separate security associations and associated network resources required.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent uses the BSSID as a reference copy of the AP MLD identity for key derivation purposes. By copying the BSSID into the TDLS key derivation process along with the AP MLD address, the system creates a unified security context without requiring separate security associations for each authenticator, thereby reducing network resource consumption.

Inventive Principle:
Principle #26Copying

3Reliability

If separate security associations are established for each authenticator, then security precision is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity precisionVSAvoidease of establishing communication links
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple authenticator identities into a single TDLS key derivation process. By combining the BSSID and AP MLD address in the key derivation, the system maintains security precision (each authenticator's identity is still represented) while simplifying operations (only one TDLS setup procedure is needed instead of separate procedures for each authenticator).

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the key derivation process to separately incorporate both the BSSID and AP MLD address. This segmentation ensures that each authenticator's identity is distinctly represented in the security association while the overall process remains unified and easier to operate than establishing separate associations for each authenticator.

Inventive Principle:
Principle #1Segmentation

4Reliability

If communication passes through multiple AP authenticators, then security protection is improved, but communication efficiency deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidcommunication efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges multiple authenticator identities into a unified security association through enhanced key derivation. This allows TDLS packets to be encrypted once with a key that protects communication across multiple authenticators, eliminating the need for separate encryption/decryption operations for each authenticator and thereby improving communication efficiency while maintaining security protection.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20260019807A1WLAN multi-link TDLS key derivation
Publication Date: 2026.01.15 HUAWEI TECH CO LTD
  • US20260019807A1 patent drawing
  • US20260019807A1 patent drawing
  • US20260019807A1 patent drawing

AI summary

Systems and methods for WLAN multi-link TDLS key derivation. An aspect of the disclosure provides a method for WLAN multi-link communication. Such a method includes sending, by a first station to a second station, a discovery request comprising a link identifier indicating a non-access point (AP) multi-link device (MLD), wherein the first station and the second station are associated with an AP MLD. Such a method further includes receiving, by the first station from the second station, a discovery response. In some embodiments, the method further includes receiving, by the first station from an AP affiliated with the AP MLD, a message indicating a MAC address of the second station. In some embodiments, the discovery request is sent via an AP affiliated with the AP MLD and a non-AP station affiliated with the second station.