Extending secondary authentication for fast roaming between service provider and enterprise network
US-2021218744-A1 · Jul 15, 2021 · US
US11452008B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-11452008-B2 |
| Application number | US-201916320943-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jan 22, 2019 |
| Priority date | Jan 16, 2019 |
| Publication date | Sep 20, 2022 |
| Grant date | Sep 20, 2022 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A wireless roaming method, an access point apparatus and a mobile station are disclosed. The wireless roaming method comprises: determining whether or not a key for a target access point corresponding to a mobile station is stored; if the key is not stored, performing key exchange on behalf of the mobile station with the target access point so as to obtain a key corresponding to the mobile station; and sending the key to the mobile station. In the technical solution of the present disclosure, before the mobile station connects to a target access point, a current access point, on behalf of the mobile station, obtains a key corresponding to the mobile from the target access point. Therefore, the mobile station does not need to perform key exchange with the target access point after accessing to the target access point, which may reduce roaming delays caused by key exchange and improve the efficiency of wireless roaming, and thereby improve user experience.
Opening claim text (preview).
What is claimed is: 1. A wireless roaming method comprising: determining, by a current access point, whether a mobile station is in a boundary state, wherein the boundary state includes that a difference between a first signal strength information value and a second signal strength information value of the mobile station is less than a boundary threshold value, the first signal strength information value representing a signal strength between the mobile station and the current access point, and the second signal strength information value representing a signal strength between the mobile station and a target access point; in response to the mobile station being in the boundary state, determining, by the current access point, whether a key for the target access point corresponding to the mobile station is stored; in response to the key not being stored, performing, by the current access point, a key exchange on behalf of the mobile station with the target access point to obtain a key corresponding to the mobile station, wherein the key exchange includes: sending, by the current access point, key request information to the target access point, the key request information including a MAC address of the mobile station that is represented, obtaining, by the current access point, key request feedback information from the target access point, calculating, by the current access point, based on the key request feedback information and obtaining a key, and confirming, by the current access point, the key with the target access point; and sending, by the current access point, the key to the mobile station. 2. The wireless roaming method according to claim 1 , wherein the boundary threshold value is a fixed value. 3. The wireless roaming method according to claim 1 , wherein the boundary threshold value is related to a larger one of the first signal strength information value and the second signal strength information value, or related to an average value of the first signal strength information value and the second signal strength information value. 4. The wireless roaming method according to claim 1 , further comprising: receiving, by the target access point, a key update request sent by the current access point; performing, by the target access point, a key exchange with the current access point; performing, by the target access point, key confirmation with the current access point; determining, by the target access point, an access of the mobile station; and based on the determined access of the mobile station, communicating, by the target access point, with the mobile station using the key. 5. The wireless roaming method according to claim 4 , wherein performing key exchange with the current access point includes: receiving, by the target access point, key request information sent by the current access point, the key request information including a MAC address of a mobile station represented by the current access point; sending, by the target access point, the key request information to an access point controller; receiving, by the target access point, a Base Transient Key (BTK) and a Refresh Number (RN) sent by the access point controller; and generating, by the target access point, a Pairwise Transient Key (PTK) based on the BTK and the RN and sending key feedback information to the current access point, the key feedback information including the BTK and the RN. 6. The wireless roaming method according to claim 4 , wherein subsequent to the access of the mobile station, the wireless roaming method further comprises: sending a broadcast key to the mobile station. 7. The wireless roaming method according to claim 1 , further comprising: receiving, by the mobile station and from the current access point, a key corresponding to a target access point; determining, by the mobile station, whether roaming is to be performed; and in response to a determination that roaming is to be performed, communicating, by the mobile station, with the target access point using the received key, wherein the current access point has the same Service Set Identifier as the target access point. 8. The wireless roaming method according to claim 7 , wherein in response to a key sent by the current access point not being received when roaming is performed, performing, by the mobile station, key exchange with the target access point so as to obtain a key. 9. The wireless roaming method according to claim 7 , wherein after roaming is proceeded, the roaming method further comprises: receiving, by the mobile station, a broadcast key sent by the target access point. 10. The wireless roaming method according to claim 1 , wherein: the first signal strength information value includes the signal strength of the current access point detected by the mobile station or the signal strength of the mobile station detected by the current access point, and the second signal strength information value includes the signal strength of the target access point detected by the mobile station or the signal strength of the mobile station detected by the target access point. 11. An access point apparatus, comprising: a first access point apparatus functioning as a current access point, the first access point comprising: a non-transitory memory which stores a computer program executable on a processor; and the processor, wherein the processor carries out operations comprising: determining whether a mobile station is in a boundary state, wherein the boundary state includes that a difference between a first signal strength information value and a second signal strength information value of the mobile station is less than a boundary threshold value, the first signal strength information value representing a signal strength between the mobile station and the current access point, and the second signal strength information value representing a signal strength between the mobile station and a target access point; in response to the mobile station being in the boundary state, determining whether a key for the target access point corresponding to the mobile station is stored; in response to the key being not stored, performing a key exchange on behalf of the mobile station with the target access point to obtain a key corresponding to the mobile station, wherein the key exchange includes: sending, by the current access point, key request information to the target access point, the key request information including a MAC address of the mobile station that is represented, obtaining, by the current access point, key request feedback information from the target access point, calculating, by the current access point, based on the key request feedback information and obtaining a key, and confirming, by the current access point, the key with the target access point; and sending the key to the mobile station. 12. The access point apparatus according to claim 11 , wherein: the first signal strength information value includes the signal strength of the current access point detected by the mobile station or the signal strength of the mobile station detected by the current access point, and the second signal strength information value includes the signal strength of the target access point detected by the mobile station or the signal strength of the mobile station detected by the target access point. 13. A system, comprising: a first access point apparatus functioning as a current access point, the first access point apparatus comprising: a first non-transitory memory which stores a computer program executable on a first processor; and the first processor, wherein the first proces
of security context information · CPC title
using a trusted network node as an anchor · CPC title
Hardware identity · CPC title
Key exchange · CPC title
between terminal device and access point, i.e. wireless air interface · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.