Title of Invention

"A WIRELESS LOCAL AREA NETWORK FOR REALIZING VIRTUAL LOCAL AREA NETWORK ON ACCESS POINT AND EQUIPMENTS AND METHODS THEREOF"

Abstract The present invention belongs to a wireless local area network for realizing virtual local area network on access point equipments and methods thereof. The method of implementing VLAN(virtual local area network) on the device of wireless LAN access point, divide the access device of distributed system to management domain; allocate the unique management domain identifier for each radio terminal; divide the accessed radio terminals to subscriber domain , allocate the unique subscriber domain identifier for each radio terminal; the access point device package the data frame as the data frame having VLAN label, transferring to distributed system; the access point device check the received data frame whether it has VLAN label; discard the data frame which have not VLAN label; with the data frame having VLAN label, check the matching related to VLAN identifier; if no matching then discarding the data frame; if matching , after taking off VLAN identifier of the data frame then forwarding it. adopting the method of the invention, capable of implementing the free switching of radio terminals when establishing networks about the different domain, decrease the dependability for the external exchange when establishing networks, saving the cost of establishing networks, improving the security of network.
Full Text Technical Field
The present invention relates to a method for networking of wireless local area network in communication field, in particular, to a method for realizing virtual local area network (VLAN) on access point (AP) equipments in a wireless local area network (WLAN) according to IEEE 802.11 standard.
Technical Background
Security is always the focus of networking in a wireless local area network. At present, there have been various kinds of schemes for resolving the security of wireless local area network, in which the application of virtual local area network technology relating to IEEE 802.1Q standard on a wireless local area network provides an effective scheme for ensuring the security of wireless local area network. Currently, a common used networking method with application of virtual local area network on a wireless local area network is such a method that when networking wireless local area network, multiple access point AP equipments are connected to a switch in a virtual local area network, and multiple VLAN domains are divided on the VLAN switch with each VLAN domain including one or more APs to form aggregation of multiple virtual subnets within the distribution system, in which, when all APs are finally connected access controller AC or other equipment with equivalent function, AC controls whether wireless terminals corresponding to respective APs in different VLAN domains can access one another or not, and otherwise the wireless terminals of different VLAN domains can not access one another. When a wireless terminal handovers from one AP in one VLAN domain to another AP in another VLAN domain, the connection between the wireless terminal and the wireless terminal in original domain may be interrupted once the VLAN domain where the wireless terminal belongs to has changed, since the handover information can not be delivered directly between APs in different VLAN domains, so that the method for realizing VLAN in the above prior art has the following disadvantages obviously:
(1) the division for VLAN is realized by a switch, that is, the realization of VLAN depends on a switch outside of AP;
(2) when wireless terminal handovers between different VLAN domains, the


handover information can not be delivered between APs, and the wireless terminal can not remain the property of original VLAN domain, which will cause interrupting on the connection between wireless terminal and original VLAN domain.
China patent application, entitled " the access technology of virtual local area network with Ethernet", provided a method for realizing VLAN on Ethernet equipment, in which the Ethernet equipment obtained division on VLAN domain by automatically studying, but this method can not resolve the problem for realizing VLAN on AP equipment in a wireless local area network.
Summary of the Invention
The technical problem to be solved in the present invention is to provide a method for realizing virtual local area network on access point equipments in a wireless local area network, to resolve the problems existing in the prior art and realize security of wireless local area network.
The core idea of the present invention is dividing all access point equipments added to an distribution system into managing domains, dividing wireless terminals accessed to each access point equipment to user domains, and managing and controlling all access point equipments by setting labels.
The method of the present invention for realizing virtual local area network on access point equipments in a wireless local area network, comprises:
dividing access point equipments (202) in a distribution system to a managing domain and assigning a unique managing domain identifier to each access point equipment, by manager (204) or access controller (301);
dividing wireless terminals (203) accessed to a user domain and assigning a unique user domain identifier to each wireless terminal by manager (204) or access controller (301);
encapsulating a data frame to be transmitted by an access point equipment (202) into a data frame with a virtual local area network tag, and transmitting to the distribution system;


checking by the access point equipment (202) whether the data frame received has the virtual local area network tag or not;
if the data frame has no the virtual local area network tag, the access point equipment (202) discarding the data frame;
if the data frame has the virtual local area network tag, the access point equipment (202) checking match of the virtual local area network identifier for the data frame;
if the virtual local area network identifier does not match, the access point equipment (202) discarding the data frame;
if the virtual local area network identifier matches, the access point equipment (202) removing the virtual local area network tag from the data frame, and forwarding the data frame to the access point equipment or wireless terminal (203).
Compared to the prior art, the method of the present invention for realizing virtual local area network on access point equipments in a wireless local area network can realize the purpose for wireless terminal handing over between APs freely when applying in the networking of different domains, thus reducing the dependence on outside VLAN switch when networking, and saving the cost of networking, and improving the flexibility of networking; meanwhile, all APs can be divided into a special managing domain, and only the manager of the domain can manage and control the APs, thereby further improving the security of network.
Brief Description of the Drawings
Fig. 1 is the flow chart of the method for realizing virtual local area network on access point equipments in a wireless local area network according to the present invention;
Fig. 2 is the networking schematic view of one embodiment employing the method of the present invention for realizing virtual local area network; and
Fig. 3 is the networking schematic view of another embodiment employing the method of present invention for realizing virtual local area network.


Detailed description of embodiment
The technical solutions of present invention will be described in details in combination with the appended drawings and embodiments in the following.
As shown in Fig.l, the method provided by the present invention for realizing virtual local area network on access point equipments in a wireless local area network, comprises the following steps of: firstly, all access point AP equipments within a distribution system are divided to a managing domain; wireless terminals accessed to APs are divided to a user domain; a manager or access controller AC assigns a unique VLAN identifier (referred as VID) in managing domain to each AP, and meanwhile also assigns a unique VID of user domain to each wireless terminal (Step 101). Then AP encapsulates its own or a received data frame transmitted to the distribution system by a wireless terminal into a data frame with a VLAN Tag, and transmit it to the distribution system (step 102). After received a data frame transmitted from the distribution system, AP checks whether the received frame has a VLAN Tag or not (step 103, 104), if the data frame does not have a VLAN Tag, then discards the data frame (step 105). If the data frame is with a VLAN Tag, check the match of its VID (step 106), if the VID of the data frame does not match, discard the data frame (step 105), if the VID matches, remove the VLAN Tag of the data frame (step 107), and forward the data frame to the corresponding AP or wireless terminal (step 108).
In step 106, checking the match of VID of the data frame with a VLAN Tag is checking whether the VID with the received data frame matches the VID of the AP in the managing domain or the VID of the wireless terminal in the user domain.
In the present invention, when a wireless terminal occurs handover between the respective access point equipments, the AP currently accessed by this wireless terminal is responsible for obtaining and maintaining the original user domain property of the wireless terminal, and broadcasts the handover information of the wireless terminal to the distribution system; however, after the AP originally accessed by the wireless terminal receives the information of the terminal handover, it releases the user domain property of the wireless terminal. Exchanging messages on the user domain properties between


different APs is accomplished by privately exchanging messages, that is, by privately exchanging messages, the AP delivers information on VID of user domain, etc., of the wireless terminal originally accessed to the AP to which the current wireless terminal accessed.
Next, the method of the present invention for realizing virtual local area network on access equipments in a wireless local area network will be described according to two different networking examples respectively.
When networking a wireless local area network, a distribution system is divided into two VLAN domains: one, referred as a managing domain, is a VLAN domain comprising all access point equipments AP 202, manager 204 or access controller AC 301, in which manager 204 or access controller 301 can access and control all access point equipments AP 202, and all access point equipments AP 202 can also access freely each other; the other, referred as user domain, is multiple VLAN domains comprising wireless terminals MT 203, that is a virtual subset aggregation of multiple wireless terminals, in which the wireless terminals in the same user domain can access each other freely, but the wireless terminals in different user domains can not access each other.
Fig. 2 shows the application of the present invention in a wireless local area network that is without access controller AC or other equipments with equivalent function, which is suitable to be applied in enterprise level application. Manager 204 and access point equipments 202 are connected to the switch 201 respectively, thus forming a managing domain; the wireless terminals MT 203 to which each AP accesses form multiple user domains. Manager 204 adds the AP 202 entering the distribution system to the managing domain, and configures a VID of user domain for a wireless terminal on the AP 202. When a certain wireless terminal MT 203 accesses AP 202, AP 202 adds the terminal to the corresponding user domain according to the VID of the wireless terminal, and thus, the whole network forms the managing domain and user domains 1, 2, and 3. Then, only the wireless terminals located in the same user domain can communicate each other; if a certain wireless terminal occurs handover between APs, the AP currently accessed by the wireless terminal is used to obtain and maintain original user domain property of the wireless terminal, and notifies the distribution system of message for handovering


wireless terminals in the managing domain.
Fig. 3 shows the application of the present invention in a wireless local area network in which all access point equipments AP converge to the access controller AC, which is suitable to the operating level application. The elements consisting of the managing domain are the respective access point equipments AP 202 and access controller AC 301; AP 202 is connected to the access controller AC 301 through switch 201, while one end of the access controller AC 301 is connected to the switch 201, its other end is connected to the INTERNET. AC 301 adds the AP 202 entering the distribution system to the managing domain, after a certain wireless terminal MT 203 accesses the AP 202, AC 301 configures a VID of user domain to the wireless terminal, AP 202 adds it to the corresponding user domain according to the VID of the wireless terminal, and, thus, the whole network forms the managing domain and user domains 1, 2, and 3. In Fig. 3, AC 301 is used to control whether wireless terminals in different user domains can communication each other, when a certain wireless terminal hands over between APs, the AP currently accessed is responsible for obtaining and maintaining the original user domain property of the wireless terminal, and notifies the distribution system of the message for handing over wireless terminal in the managing domain.
At last, it should be noted that the above embodiments are only to illustrate the technical solutions of the present invention, without any limitation. Although the present invention is described in details with reference to the preferred embodiments, the ordinary person skilled in the art should understand that the technical solutions of the present invention can be modified or substituted, without departing from the spirit and scope of the technical solutions of the present invention, all of which should be covered in the following claims.














We claim :
1. A wireless local area network for realizing virtual local area network on access point
equipments, characterizing in that, comprising:
manager ( 204) or access controller (301), capable of dividing access point equipments (202) in the distribution system into managing domain and assigning a unique identifier of managing domain to each access point equipment (202);
manager ( 204) or access controller ( 301) capable of dividing wireless terminal (203) into a user domain and assigning a unique identifier of user domain to each wireless terminal (203);
means for encapsulating by the access point equipment (202) a data frame to be transmitted into a data frame with a virtual local area network tag, and transmitting to the distribution system;
means for checking by an access point equipment (202), a data frame received whether has a virtual local area network tag or not, whereby the access point equipment (202) discards the data frame having no virtual local area network tag; in case the data frame has a virtual local area network tag, the access point equipment (202) checks the match of the virtual local area network identifier for the data frame and discards the data frame, if the virtual local area network identifier does not match; in case the virtual local area network identifier matches and the access point equipment (202) removes the virtual local area network tag from said data frame, the frame and forwards said data frame to a corresponding access point equipment or wireless terminal (203).
2. A method for realizing virtual local area network on access point equipments in a wireless
local area network as claimed in claim 1, comprising:
dividing access point equipments (202) in a distribution system into a managing domain and assigning a unique identifier of managing domain to each access point equipment, by manager (204) or access controller (301);
dividing wireless terminals (203) accessed into a user domain and assigning a unique identifier of user domain to each wireless terminal by manager (204) or access controller (301);

encapsulating by an access point equipment (202) a data frame to be transmitted into a data frame with a virtual local area network tag, and transmitting to the distribution system;
checking by an access point equipment (202) a data frame received whether has a virtual local area network tag or not;
if the data frame has no the virtual local area network tag, the access point equipment (202) discarding the data frame;
if the data frame has a virtual local area network tag, the access point equipment (202) checking the match of the virtual local area network identifier for the data frame;
if the virtual local area network identifier does not match, the access point equipment (202) discarding the data frame;
if the virtual local area network identifier matches, the access point equipment (202) removing the virtual local area network tag from the data frame and forwarding the data frame to a corresponding access point equipment or wireless terminal (203).
3. The method for realizing virtual local area network on access point equipments in a
wireless local area network as claimed in claim 2, wherein the method further comprises:
obtaining and maintaining original user domain property of the wireless terminal by the access point equipment currently accessed, when the wireless terminal occurs handover between the respective access point equipments, and transmitting a message for handing over the wireless terminal to the distribution system in the managing domain, releasing the related resource of the wireless terminal after the access point equipment originally accessed by the wireless terminal receives the handover message.
4. The method for realizing virtual local area network on access point equipments in a
wireless local area network as claimed in claim 2 or 3, wherein the step of checking the
match of the virtual local area network identifier for the data frame with the virtual local area
network identifier comprises checking whether the virtual local area network identifier of the
data frame matches the virtual local area identifier of the access point equipment in the
managing domain.

5. The method for realizing virtual local area network on access point equipments in a wireless local area network as claimed in claim 2 or 3, wherein the step of checking the match of the virtual local area network identifier for the data frame with the virtual local area network identifier comprises checking whether the virtual local area network identifier of the data frame matches the virtual local area identifier of the wireless terminal in the user domain.
6. The method for realizing virtual local area network on access point equipments in a wireless local area network as claimed in claim 2 or 3, wherein the managing domain comprises the manager (204) and each of access point equipments.
7. The method for realizing virtual local area network on access point equipments in a wireless local area network as claimed in claim 2 or 3, wherein the managing domain comprises the access controller (301) and each of access point equipments.
8. The method for realizing virtual local area network on access point equipments in a wireless local area network as claimed in claim 2 or 3, wherein the user domain comprises wireless terminals that connect to respective access point equipments correspondingly.
9. A wireless local area network for realizing virtual local area network on access point equipments, as substantially as herein described with reference to the accompanying specification, examples and drawings.
10. A method for realizing virtual local area network on access point equipments in a wireless
local area network, as substantially as herein described with reference to the accompanying
specification, examples and drawings.

Documents:

234-DEL-2009-Correspondence-031114.pdf

853-DELNP-2006-Abstract (19-01-2010).pdf

853-DELNP-2006-Abstract-(18-08-2010).pdf

853-DELNP-2006-Abstract-241114.pdf

853-delnp-2006-abstract.pdf

853-DELNP-2006-Claims (19-01-2010).pdf

853-delnp-2006-Claims-(02-03-2015).pdf

853-DELNP-2006-Claims-(18-08-2010).pdf

853-DELNP-2006-Claims-241114.pdf

853-delnp-2006-claims.pdf

853-delnp-2006-Correspondence Others-(02-03-2015).pdf

853-delnp-2006-Correspondence Others-(15-01-2014).pdf

853-delnp-2006-Correspondence Others-(18-01-2013).pdf

853-delnp-2006-Correspondence Others-(21-04-2014).pdf

853-delnp-2006-Correspondence Others-(23-08-2012).pdf

853-delnp-2006-Correspondence Others-(31-05-2013).pdf

853-DELNP-2006-Correspondence-241114.pdf

853-DELNP-2006-Correspondence-Others (19-01-2010).pdf

853-delnp-2006-correspondence-others 1.pdf

853-DELNP-2006-Correspondence-Others-(18-08-2010).pdf

853-delnp-2006-correspondence-others.pdf

853-DELNP-2006-Description (Complete) (19-01-2010).pdf

853-delnp-2006-description (complete).pdf

853-DELNP-2006-Drawings (19-01-2010).pdf

853-delnp-2006-drawings.pdf

853-DELNP-2006-Form 2(Title Page)-241114.pdf

853-DELNP-2006-Form-1-(18-08-2010).pdf

853-delnp-2006-Form-1-(31-05-2013).pdf

853-delnp-2006-form-1.pdf

853-delnp-2006-form-18.pdf

853-DELNP-2006-Form-2 (19-01-2010).pdf

853-DELNP-2006-Form-2-(18-08-2010).pdf

853-delnp-2006-form-2.pdf

853-DELNP-2006-Form-3 (19-01-2010).pdf

853-delnp-2006-form-3.pdf

853-delnp-2006-form-5.pdf

853-delnp-2006-GPA-(23-08-2012).pdf

853-delnp-2006-GPA-(31-05-2013).pdf

853-delnp-2006-gpa.pdf

853-delnp-2006-Marked Claims-(02-03-2015).pdf

853-delnp-2006-pct-210.pdf


Patent Number 265865
Indian Patent Application Number 853/DELNP/2006
PG Journal Number 13/2015
Publication Date 27-Mar-2015
Grant Date 20-Mar-2015
Date of Filing 20-Feb-2006
Name of Patentee ZTE CORPORATION
Applicant Address ZTE PLAZA, KEJI ROAD SOUTH HI-TECH INDUSTRIAL PARK, NANSHAN DISTRICT, SHENZHEN, GUANGDONG 518057, CHINA
Inventors:
# Inventor's Name Inventor's Address
1 WANG, ZHANLI ZTE PLAZA, KEJI ROAD SOUTH HI-TECH INDUSTRIAL PARK, NANSHAN DISTRICT, SHENZHEN, GUANGDONG 518057, CHINA
2 GUO, ZHONG ZTE PLAZA, KEJI ROAD SOUTH HI-TECH INDUSTRIAL PARK, NANSHAN DISTRICT, SHENZHEN, GUANGDONG 518057, CHINA
3 TANG, JIANGUO ZTE PLAZA, KEJI ROAD SOUTH HI-TECH INDUSTRIAL PARK, NANSHAN DISTRICT, SHENZHEN, GUANGDONG 518057, CHINA
4 WANG, WEI ZTE PLAZA, KEJI ROAD SOUTH HI-TECH INDUSTRIAL PARK, NANSHAN DISTRICT, SHENZHEN, GUANGDONG 518057, CHINA
PCT International Classification Number H04L 12/00
PCT International Application Number PCT/CN2003/001010
PCT International Filing date 2003-11-27
PCT Conventions:
# PCT Application Number Date of Convention Priority Country
1 03139932.0 2003-07-21 China