IP Library Granted Patent US 12696084
Granted Patent B2
US 12696084 · App. 18/128,302 · Granted Jul 28, 2026

Optimization of fast connection, roaming and steering in DPP networks

Inventors: Prakhar Vig (Noida, IN); Amit Shakya (Noida, IN)
Assignee: MediaTek Singapore Pte. Ltd.
H04W12/06H04W12/041H04W76/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12696084
App. No.
18/128,302
Granted
Jul 28, 2026
Kind
B2
Abstract

Various schemes pertaining to optimization of fast connection, roaming and steering in Device Provisioning Protocol (DPP) networks are described. A secure connection is formed between a first network device and a second network device in a DPP network by performing an optimized network introduction procedure. Relative to a convention network introduction procedure, an overhead in network introduction frame exchanges is reduced with the optimized network introduction procedure.

Claims (55)

1 . A method, comprising:

forming a secure connection between a first network device and a second network device in a Device Provisioning Protocol (DPP) network by performing an optimized network introduction procedure,

wherein, relative to a convention network introduction procedure comprising sending a peer discovery request and sending a peer discovery response, an overhead in network introduction frame exchanges is reduced with the optimized network introduction procedure, and

wherein the optimized network introduction procedure involves no frame exchange of the peer discovery request and the peer discovery response between the first network device and the second network device, and involves:

the first network device generating a first pairwise master key (PMK) identifier (PMKID) using a second connector configured for the second network device during a DPP configuration stage, wherein the second connector is included in an authentication response transmitted by the second network device; and

the second network device generating a second PMKID using a first connector configured for the first network device during the DPP configuration stage, wherein the first connector is included in an authentication request transmitted by the first network device.

2 . The method of claim 1 , wherein the forming of the secure connection by performing the optimized network introduction procedure comprises the first network device and the second network device performing an authentication frame exchange, an association frame exchange, and a four-way handshake with one another.

3 . The method of claim 1 , wherein the forming of the secure connection by performing the optimized network introduction procedure comprises:

the first network device transmitting the authentication request to the second network device, the authentication request comprising at least the first connector configured for the first network device during the DPP configuration stage;

the first network device receiving the authentication response from the second network device responsive to transmitting the authentication request, the authentication response comprising at least the second connector configured for the second network device during the DPP configuration stage;

the first network device generating a PMK based least in part on information in the authentication response;

the first network device generating the first PMKID;

the first network device transmitting an association request to the second network device, the association request comprising at least the first PMKID;

the first network device receiving an association response from the second network device responsive to transmitting the association request; and

the first network device performing a four-way handshake procedure with the second network device.

4 . The method of claim 1 , wherein the forming of the secure connection by performing the optimized network introduction procedure comprises:

the second network device receiving the authentication request from the first network device, the authentication request comprising at least the first connector configured for the first network device during the DPP configuration stage;

the second network device transmitting the authentication response to the first network device responsive to receiving the authentication request, the authentication response comprising at least the second connector configured for the second network device during the DPP configuration stage;

the second network device generating a PMK based least in part on information in the authentication request;

the second network device receiving an association request from the first network device, the association request comprising at least the first PMKID generated by the first network device;

the second network device transmitting an association response to the first network device responsive to receiving the association request; and

the second network device performing a four-way handshake procedure with the first network device.

5 . The method of claim 1 , wherein the forming of the secure connection comprises forming a first connection between the first network device and the second network device.

6 . The method of claim 1 , wherein the forming of the secure connection comprises forming the secure connection between the first network device and the second network device during roaming or steering by the first network device or the second network device.

7 . The method of claim 1 , wherein the DPP network comprises a multiple-access point (MAP) DPP network.

8 . The method of claim 1 , wherein the DPP network comprises a non-multiple-access point (non-MAP) DPP network.

9 . The method of claim 1 , wherein the second network device comprises a controller, an access point (AP) or a first agent, and wherein the first network device comprises a second agent or a station (STA).

10 . An apparatus, comprising:

a transceiver configured to communicate wirelessly; and

a processor coupled to the transceiver and configured to, via the transceiver, form a secure connection between a first network device and a second network device in a HAR Device Provisioning Protocol (DPP) network by performing an optimized network introduction procedure,

wherein, relative to a convention network introduction procedure comprising sending a peer discovery request and sending a peer discovery response, an overhead in network introduction frame exchanges is reduced with the optimized network introduction procedure, and

wherein the optimized network introduction procedure involves no frame exchange of the peer discovery request and the peer discovery response between the first network device and the second network device, and involves:

the first network device generating a first pairwise master key (PMK) identifier (PMKID) using a second connector configured for the second network device during a DPP configuration stage, wherein the second connector is included in an authentication response transmitted by the second network device; and

the second network device generating a second PMKID using a first connector configured for the first network device during the DPP configuration stage, wherein the first connector is included in an authentication request transmitted by the first network device.

11 . The apparatus of claim 10 , wherein, in forming the secure connection by performing the optimized network introduction procedure, the processor is configured to perform an authentication frame exchange, an association frame exchange, and a four-way handshake.

12 . The apparatus of claim 10 , wherein the apparatus is implemented in or as the first network device, and wherein, in forming the secure connection by performing the optimized network introduction procedure, the processor is configured to perform operations comprising:

transmitting the authentication request to the second network device, the authentication request comprising at least the first connector configured for the first network device during the DPP configuration stage;

receiving the authentication response from the second network device responsive to transmitting the authentication request, the authentication response comprising at least the second connector configured for the second network device during the DPP configuration stage;

generating a PMK based least in part on information in the authentication response;

generating the first PMKID;

transmitting an association request to the second network device, the association request comprising at least the first PMKID;

receiving an association response from the second network device responsive to transmitting the association request; and

performing a four-way handshake procedure with the second network device.

13 . The apparatus of claim 10 , wherein the apparatus is implemented in or as the second network device, and wherein, in forming the secure connection by performing the optimized network introduction procedure, the processor is configured to perform operations comprising:

receiving the authentication request from the first network device, the authentication request comprising at least the first connector configured for the first network device during the DPP configuration stage;

transmitting the authentication response to the first network device responsive to receiving the authentication request, the authentication response comprising at least the second connector configured for the second network device during the DPP configuration stage;

generating a PMK based least in part on information in the authentication request;

receiving an association request from the first network device, the association request comprising at least the first PMKID generated by the first network device;

transmitting an association response to the first network device responsive to receiving the association request; and

performing a four-way handshake procedure with the first network device.

14 . The apparatus of claim 10 , wherein, in forming the secure connection, the processor is configured to form a first connection between the first network device and the second network device.

15 . The apparatus of claim 10 , wherein, in forming the secure connection, the processor is configured to form the secure connection between the first network device and the second network device during roaming or steering by the first network device or the second network device.

16 . The apparatus of claim 10 , wherein the DPP network comprises a multiple-access point (MAP) DPP network.

17 . The apparatus of claim 10 , wherein the DPP network comprises a non-multiple-access point (non-MAP) DPP network.

18 . The apparatus of claim 10 , wherein the first second network device comprises a controller, an access point (AP) or a first agent, and wherein the first network device comprises a second agent or a station (STA).