Network connection method, electronic equipment and computer readable storage medium
By guiding the site device to use WPA2 encrypted connections in the access point device, the compatibility problem that the site device cannot connect because it does not have WPA3 encryption capabilities is solved, ensuring that users can use these devices normally.
Patent Information
- Application Number
- CN202311503284.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-09
- Publication Date
- 2025-05-16
AI Technical Summary
Currently, many site devices do not have the ability to use WPA3 and access point devices to complete encryption authentication, which results in some site devices being unable to successfully establish connections with access point devices when access point devices adopt WPA2/WPA3 hybrid encryption mode, which affects users' use.
When the access point device determines that the site device to be accessed does not have WPA3 encryption capabilities but claims to support WPA3, it guides the site device to use WPA2 to establish a connection with it to ensure that the site device can successfully access the local area network.
Through this method, the problem that the site device cannot connect to access point devices using WPA2/WPA3 hybrid encryption mode is solved, ensuring that users can use these site devices normally, and improving the user experience.
Smart Images

Figure CN120018115A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of terminals and communication technologies, and in particular to a network connection method, an electronic device, and a computer-readable storage medium. Background Art
[0002] Wireless fidelity (WiFi) technology is a technology that connects electronic devices to a local area network in a wireless connection. Among them, the electronic device that provides the local area network can be called an access point device, and the electronic device connected to the local area network through the access point device can be called a station device. Early WiFi usually uses the WPA2 (Wi-Fi protected access 2) wireless encryption standard for encryption. The station device needs to complete the encryption and authentication method process specified in WPA2 with the access point device before it can connect to the local area network. Because the security vulnerabilities of WPA2 have seriously affected the security of WiFi encrypted with WPA2, a more secure wireless security standard has emerged: WPA3 (Wi-Fi protected access 3).
[0003] Currently, many site devices do not have the ability to use WPA3 to complete encryption authentication with access point devices. Some access point devices use the WPA2 / WPA3 mixed encryption mode when encrypting WiFi: when the site device supports WPA3, the access point device can establish a connection with the site device using the encryption and authentication methods specified in WPA3; when the site device only supports WPA2, the access point device can establish a connection with the site device using the encryption and authentication methods specified in WPA2. However, some site devices that only support WPA2 will have compatibility issues when connecting to access point devices that use the WPA2 / WPA3 mixed encryption mode, resulting in the inability of such site devices to successfully establish a connection with the access point device. Summary of the invention
[0004] The present application provides a network connection method, an electronic device, and a computer-readable storage medium. In the case where the access point device uses the WPA2 / WPA3 mixed encryption mode, when the access point device determines that the site device to be accessed does not have the WPA3 encryption capability but declares that it supports WPA3, the access point device can guide the site device to use WPA2 to establish a connection with it. In this way, some site devices with compatibility issues can successfully access the local area network, thereby ensuring that users can use these site devices normally.
[0005] In a first aspect, the present application provides a network connection method, which is applied to a first electronic device, which is used to provide a network access service, and the first electronic device uses a mixed encryption mode of WPA2 and WPA3. The method includes: the first electronic device receives a first message, and the first message indicates that the second electronic device requests to access the network; the first electronic device receives a second message, and the second message indicates that the second electronic device adopts open system authentication; the first electronic device receives a third message, and the second electronic device declares that it supports WPA3 encryption in the third message; the first electronic device determines that the second electronic device does not have the ability of WPA3 encryption based on the second message and the third message; the first electronic device establishes a connection with the second electronic device through WPA2 encryption.
[0006] Here, the first electronic device can be an access point device, and the second electronic device can be a site device. That is to say, when the first electronic device uses the WPA2 / WPA3 hybrid encryption mode, when the second electronic device uses open system authentication and declares support for WPA3 encryption, it will enter the WPA3 quick connection process. The first electronic device can guide the second electronic device to use WPA2 to establish a connection with it when it is determined that the second electronic device does not have the parameters required for WPA3 quick connection. In this way, some problematic devices can be guided to the WPA2 connection process and successfully connect to the local area network, ensuring that users can use it normally.
[0007] In combination with the first aspect, in some embodiments, the first electronic device determines that the second electronic device does not have the capability of WPA3 encryption based on the second message and the third message, including: when it is determined according to the second message that the second electronic device uses open system authentication, the first electronic device determines that the third message does not carry a quick connection key and / or supports a management frame protection field.
[0008] That is to say, the first electronic device determines whether the second electronic device supports WPA3 encryption by verifying the quick connection key and the management frame protection field in the third message. This is because when open system authentication is selected and the second electronic device supports WPA3, the WPA3 quick connection process will be entered. The third message needs to include the quick connection key and the management frame protection field. When the first electronic device determines that the third message does not contain the parameters required for WPA3's quick connection, the second electronic device may be an electronic device that only supports WPA2 but mistakenly claims to support WPA3. At this time, the first electronic device can try to use WPA2 to establish a connection with the second electronic device to improve its compatibility in the WPA2 / WPA3 mixed mode.
[0009] In combination with the first aspect, in some embodiments, before the first electronic device receives the second message, the method further includes: the first electronic device sends a fourth message to the second electronic device, and the fourth message indicates that the first electronic device supports WPA2 encryption and WPA3 encryption. That is to say, when the first electronic device adopts the WPA2 / WPA3 mixed encryption mode, the first electronic device will declare that it supports both WPA2 encryption and WPA3 encryption. The first electronic device can indicate that it supports both WPA2 encryption and WPA3 encryption by declaring that it supports PSK encryption and SAE encryption.
[0010] In combination with the first aspect, in some embodiments, the second electronic device also declares in the third message that it supports WPA2 encryption. Some problematic second electronic devices will declare that they support both WPA2 encryption and WPA3 encryption. In this case, the first electronic device can determine whether the second electronic device declares that it supports WPA2 when the second electronic device cannot use WPA3 encryption. In the case where the first electronic device determines that the second electronic device also supports WPA2 encryption, the first electronic device can establish a connection with the second electronic device using the WPA2 encryption process instead of using WPA3's quick connection.
[0011] In combination with the first aspect, in some embodiments, the second electronic device does not declare support for WPA2 encryption in the third message, and before the first electronic device establishes a connection with the second electronic device through WPA2 encryption, the method also includes: the first electronic device sends a fifth message to the second electronic device, the fifth message indicating that the second electronic device failed to connect to the network; the first electronic device receives a sixth message, the sixth message indicating that the second electronic device requests to access the network; the first electronic device sends a seventh message to the second electronic device, the seventh message indicating that the first electronic device only supports WPA2 encryption; the first electronic device receives an eighth message, in which the second electronic device declares support for WPA2 encryption.
[0012] That is to say, some problematic second electronic devices only declare that they support WPA3 encryption, but do not declare that they support WPA2 encryption. Then the connection will fail because the second electronic device does not carry the parameters required for WPA3. When the first electronic device receives the access request from the second electronic device again, it can declare that it is an access point device that only supports WPA2, and try to guide the problematic device to use WPA2 to establish a connection with it. In this way, some problematic devices that only have WPA2 encryption capabilities but mistakenly claim that they support WPA3 can access the local area network, thereby ensuring normal use by users.
[0013] In combination with the first aspect, in some embodiments, after the first electronic device sends the fifth message to the second electronic device, the method also includes: the first electronic device stores the MAC address of the second electronic device in a first list, the first list being used to store the MAC addresses of electronic devices that declare to support WPA3 encryption but cannot use WPA3 encryption to connect to the network; after the first electronic device receives the sixth message, the method also includes: the first electronic device determines that the MAC address of the second electronic device is in the first list.
[0014] In combination with the first aspect, in some embodiments, the method also includes: the first electronic device determines that the time length for which the MAC address of the second electronic device is stored in the first list exceeds a first time length; and the first electronic device deletes the MAC address of the second electronic device from the first list.
[0015] That is to say, the first electronic device can store the MAC address of the problematic device in the first list for a certain period of time. When the problematic device connects again, the first electronic device can query whether the MAC address of the device is stored in the first list. In this way, the first electronic device can guide the problematic device to establish a connection using WPA2.
[0016] In combination with the first aspect, in some embodiments, the method further includes: the first electronic device receives a ninth message, the ninth message indicates that the third electronic device requests to access the network; the first electronic device receives a tenth message, the tenth message indicates that the third electronic device adopts open system authentication; the first electronic device receives an eleventh message, in which the third electronic device declares to support WPA3 encryption; the first electronic device determines that the third electronic device has the capability of WPA3 encryption based on the tenth message and the eleventh message; the first electronic device establishes a connection with the third electronic device through WPA3 encryption. Here, the third electronic device can be a site device. That is to say, for a site device with WPA3 encryption capability, when open system authentication is adopted and the site device declares support for WPA3, the first electronic device can still use WPA3's quick connection to establish a connection with the site device.
[0017] In a second aspect, the present application provides an electronic device, comprising a memory and a processor coupled to the memory; the memory stores a computer program, and when the processor executes the above computer program, the electronic device implements any one of the methods described in the above first aspect.
[0018] In a third aspect, the present application provides a computer-readable storage medium, which stores a computer program or computer instructions, and the aforementioned computer program or computer instructions are executed by a processor to implement any method described in the first aspect above.
[0019] In a fourth aspect, an embodiment of the present application provides a computer program product. When the computer program product is executed by a processor, the method described in any one of the above-mentioned first aspects will be implemented.
[0020] In a fifth aspect, an embodiment of the present application provides a chip, comprising a processor and a memory, wherein the memory is used to store computer programs or computer instructions, and the processor is used to execute the computer programs or computer instructions stored in the memory, so that the chip executes any method described in the first aspect above.
[0021] The solutions provided in the second to fifth aspects are used to implement or cooperate with the corresponding methods provided in the first aspect, and therefore can achieve the same or corresponding beneficial effects as the corresponding methods in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 is a schematic diagram of the architecture of a communication system 10 provided in an embodiment of the present application;
[0023] Figure 2 This is a schematic diagram of a process for normally establishing a connection between a site device and an access point device provided in an embodiment of the present application;
[0024] Figure 3 It is a field diagram of Gu'an network information provided by an embodiment of the present application;
[0025] Figure 4 This is a schematic diagram of a process for quickly connecting a site device and an access point device provided in an embodiment of the present application;
[0026] Figure 5 This is a flow chart provided by an embodiment of the present application when a station device fails to connect to an access point device;
[0027] Figure 6 This is a flow chart of an access point device guiding a station device to establish a connection using WPA2, provided in an embodiment of the present application;
[0028] Figure 7 This is another flow chart provided in an embodiment of the present application when a station device fails to connect to an access point device;
[0029] Figure 8 This is a flowchart of another access point device guiding a station device to establish a connection using WPA2 provided in an embodiment of the present application;
[0030] Fig. 9 is a flow chart of a network connection method provided by an embodiment of the present application;
[0031] Fig.10It is a schematic diagram of the structure of the electronic device 100 provided in an embodiment of the present application. DETAILED DESCRIPTION
[0032] The terms used in the following embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to be used as limitations to the present application. As used in the specification and appended claims of the present application, the singular expressions "one", "a kind of", "said", "above", "the" and "this" are intended to also include plural expressions, unless there is a clear indication to the contrary in the context. It should also be understood that the term "and / or" used in the present application refers to and includes any or all possible combinations of one or more listed items.
[0033] In the following, the terms "first" and "second" are used for descriptive purposes only and are not to be understood as suggesting or implying relative importance or implicitly indicating the number of the indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features, and in the description of the embodiments of the present application, unless otherwise specified, "plurality" means two or more.
[0034] WiFi technology is a technology that connects electronic devices to a local area network in a wireless way. Among them, WiFi can be established based on the IEEE 802.11 standard. The IEEE 802.11 standard defines access points (AP) and stations (STA) in a WiFi network. Among them, an access point (or access point device) can connect a station (or station device) connected to the access point to a local area network through a wireless medium (wireless medium, WM). Data transmission and resource sharing can be carried out between electronic devices in a local area network.
[0035] In order to enhance the security of WiFi network connection, the WiFi Alliance has developed the WPA2 wireless encryption standard (hereinafter referred to as WPA2 or WPA2 encryption). WPA2 may include link authentication methods, access authentication methods, data encryption methods, etc. A station device can only access the local area network after completing the link authentication, access authentication, and data encryption processes specified in WPA2 with the access point device. However, with the discovery of WPA2 security vulnerabilities, if the WiFi network continues to use WPA2 encryption, the security will be low. Based on this, the WiFi Alliance proposed another wireless security standard, namely the WPA3 wireless encryption standard (hereinafter referred to as WPA3 or WPA3 encryption), to replace WPA2 encryption for security authentication. WPA3 encryption has higher security than WPA2 encryption. Since many station devices do not have the ability to establish a connection with the access point device through WPA3, if the access point device only supports WPA3 encryption, some station devices will not be able to connect to the access point device normally. In order to enable site devices that do not support WPA3 encryption to access access point devices that use WPA3, some access point devices will use the WPA2 / WPA3 hybrid encryption mode (or called WPA2 / WPA3 hybrid authentication, WPA2 / WPA3 mode) encryption method. The site device does not support WPA3 encryption means that the site device does not have or does not fully have the link authentication method, access authentication method or data encryption method specified in the WPA3 wireless encryption standard.
[0036] When the station device and the access point device are connected, the wireless encryption methods supported by both parties will be determined. The station device can declare the wireless encryption methods it supports to the access point device, so that the access point device can select the corresponding wireless encryption method based on the wireless encryption methods supported by the station device to perform identity authentication and encryption with the station device. The wireless encryption capabilities here may include but are not limited to WPA2 and WPA3. In the case where the access point device adopts the WPA2 / WPA3 mixed encryption mode as the access authentication method, when the station device declares in the message that it supports WPA3 encryption, the access point device can use WPA3 encryption to establish a connection with the station device; when the station device declares in the message that it only supports WPA2 encryption, the access point device can use WPA2 encryption to establish a connection with the station device. When the station device declares in the message that it supports both WPA2 encryption and WPA3 encryption, the access point device can preferentially use WPA3 encryption to establish a connection with the station device.
[0037] However, when the access point device uses the WPA2 / WPA3 mixed encryption mode, some station devices do not support WPA3 encryption, but claim in the message that they support WPA3 encryption. Such station devices can normally connect to the access point device using the WPA2-only encryption mode but cannot connect to the access point device using the WPA2 / WPA3 mixed encryption mode, which may prevent users from using the station device normally. The above-mentioned WPA2-only encryption mode means that the access point device only allows station devices to establish a connection with it using WPA2 encryption.
[0038] Figure 1 It is a schematic diagram of the architecture of a communication system 10 provided in an embodiment of the present application.
[0039] like Figure 1 As shown, the communication system 10 may include a router 101, a smart camera 102, a smart speaker 103, a smart air conditioner 104 and a mobile phone 105.
[0040] The router 101 can be called an access point device in the communication system 10, and the smart camera 102, the smart speaker 103, the smart air conditioner 104 and the mobile phone 105 can be called site devices in the communication system 10. Among them, the router 101, the smart camera 102, the smart speaker 103, the smart air conditioner 104 and the mobile phone 105 can all be called electronic devices. The smart camera 102, the smart speaker 103 and the smart air conditioner 104 can be called smart homes. Among them, smart homes are home appliances that can connect to a local area network and exchange data through the local area network.
[0041] The router 101 can connect the smart camera 102, smart speaker 103, smart air conditioner 104 and mobile phone 105 connected to the router 101 to the local area network. In this way, the mobile phone 105 can receive and send control instructions to the smart camera 102, smart speaker 103 or smart air conditioner 104 in response to user operations, instructing the smart camera 102, smart speaker 103 or smart air conditioner 104 to perform corresponding actions. For example, the mobile phone 105 can receive and send control instruction A to the smart air conditioner 104 in response to user operations, and the control instruction A is used to instruct the smart air conditioner 104 to start. The smart air conditioner 104 can receive and respond to the control instruction A and then switch from the off state to the start state. Alternatively, the mobile phone 105 can also receive and send control instruction B to the smart camera 102 in response to user operations, and the control instruction B is used to instruct the smart camera 102 to send the data of the captured video to the mobile phone 105. In this way, the mobile phone 105 can receive the data of the video sent by the smart camera 102 and then view the real-time video captured by the smart camera 102.
[0042] Because some smart home manufacturers do not write codes in a standardized manner, these smart homes will mistakenly declare in the message that they do not support wireless encryption methods when establishing a connection with the router, which in turn causes the smart home to be unable to connect to the router normally, affecting user use. For example, when the router 101 adopts the WPA2 / WPA3 mixed encryption mode, if the smart air conditioner 104 claims that it supports WPA3 without having WPA3 capabilities, the smart air conditioner may not be able to connect to the local area network through the router 101. In this way, the user cannot control the smart air conditioner 104 through the mobile phone 105, affecting the user's experience when using the smart air conditioner.
[0043] In order to solve the above problems, the embodiments of the present application provide a network connection method, an electronic device and a computer-readable storage medium. In this method, when the access point device determines that the site device to be accessed claims in the message that it supports WPA3, but the site device does not actually have the link authentication, access authentication and data encryption methods required in WPA3 to establish a connection with the access point device, the access point device can use WPA2 to establish a connection with the site device to ensure that the site device can be normally connected to the local area network. In this way, the problem of being unable to connect normally to an access point device in a WPA2 / WPA3 mixed encryption mode due to the site device erroneously claiming that it does not support a wireless encryption method, thereby causing the user to be unable to use the site device normally. The user does not need to modify the configuration of the above-mentioned type of access point device or site device, and the above-mentioned access point device and site device can successfully complete the connection, thereby improving the user experience when using the site device and access point device. In the embodiment of the present application, the site device and the access point device use WPA2 to establish a connection, which actually means that the site device and the access point device use the link authentication method, access authentication method, and data encryption method specified in WPA2 to connect; the site device and the access point device use WPA3 to establish a connection, which actually means that the site device and the access point device use the link authentication method, access authentication method, and data encryption method specified in WPA3 to connect.
[0044] Here we first introduce the process of establishing a normal connection between a station device and an access point device in combination with the IEEE 802.11 standard.
[0045] Figure 2 1 is a flow chart of establishing a connection between a station device and an access point device for the first time provided by an embodiment of the present application. Figure 2 As shown in the figure, the first connection between the station device and the access point device needs to go through the following stages:
[0046] 1. Scanning stage.
[0047] The scanning phase is used to detect and discover the peer device. The scanning phase may include but is not limited to the following steps:
[0048] S201: A station device sends a probe request frame to an access point device.
[0049] S202: The access point device returns a probe response frame to the site device, where the probe response frame states that the access point device supports WPA2 encryption and WPA3 encryption.
[0050] Scanning can be divided into active scanning and passive scanning. S201-S202 is the active detection process of the site device. In active scanning, the site device will actively send a probe request frame on each channel to request the access point device to respond. The probe request frame will carry the media access control address (MAC) of the site device. When the access point device receives the probe request frame sent by the site device, it will return a probe response frame to the site device in reply.
[0051] In passive scanning ( Figure 2 (not shown in the figure), the station device switches between the channels in the channel list and waits for the beacon frame sent by the access point device.
[0052] Beacon frames and Probe Response frames can carry Robust Security Network (RSN) information, which is used to identify network security-related information. Figure 3 As shown, the RSN information may include an element ID field, a length field, a version field, a group cipher suite field, a pairwise cipher suite count field, a pairwise cipher suite field, an authentication and key management count (authentication and key management count, AKM count) field, an authentication and key management suite (authentication and key management suites, AKM suites) field, an RSN capability field, a pairwise master key (pairwise master key count, PMK count) field, and a PMK list (pairwise master key list, PMK list) field.
[0053] Among them, the AKM count field can indicate that the network supports several access authentication methods, and the AKM suites field can include the OUIs of the corresponding number of access authentication methods, where the OUI is used to identify the access authentication method. The site device and the access point device can determine the access authentication method of the network through the OUI field and the type number. The access authentication methods here may include pre-shared key (PSK) encryption and simultaneous authentication of equals (SAE) encryption. Among them, PSK encryption is the access authentication method included in WPA2, and SAE encryption is the access authentication method included in WPA3. Optionally, the OUI of PSK encryption can be 00-0F-AC-02, and the OUI of SAE encryption can be 00-0F-AC-08.
[0054] When the access point device adopts the WPA2 / WPA3 mixed encryption mode, the access point device can declare in the probe response frame that it supports both WPA2 encryption and WPA3 encryption. The access point device can declare that it supports both WPA2 encryption and WPA3 encryption through the AKM count field and the AKM suites field. For example, the access point device can set the AKM count field to 2 in the probe response frame, which indicates that the access point device supports two access authentication methods. The access point device can fill in the OUI of the two access authentication methods it supports in the AKM suites field. The AKMsuites field can include the OUI of PSK encryption and the OUI of SAE encryption.
[0055] 2. Link authentication (Authentication) stage.
[0056] The link authentication phase is used to verify whether the identity of the access point device is secure. The link authentication phase may include but is not limited to the following steps:
[0057] S203: The site device sends a link authentication request frame to the access point device, where the link authentication request frame declares a used link authentication method.
[0058] S204: The access point device returns an authentication pass frame to the site device, where the authentication pass frame indicates that the site device has passed the authentication.
[0059] After receiving the probe response frame sent by the access point device, the station device needs to be authenticated by the access point device. The station device can send a link authentication request frame to the access point device, and the link authentication request frame can include the link authentication method selected by the station device.
[0060] The link authentication method may include open system authentication and SAE authentication. In addition to open system authentication and SAE authentication, the link authentication request frame may also include shared key authentication. For an introduction to shared key authentication, please refer to the definition of the IEEE 802.11 standard, which will not be described in detail in the embodiments of the present application.
[0061] When the station device selects WPA2 to connect to the access point device, the station device can select open system authentication as the link authentication method when establishing a connection with the access point device. When the station device selects open system authentication, the access point device returns an authentication pass frame to the station device, indicating to the station device that it has passed the link authentication in the authentication pass frame.
[0062] When the site device selects WPA3 to connect to the access point device, the site device can declare that SAE authentication is adopted. When the site device selects SAE authentication, the site device and the access point device will negotiate based on the password of the network connection (i.e., PSK), and each will generate a pairwise master key (PMK). Then the two can verify whether the PMK calculated by the other device is consistent with the PMK calculated by themselves. Only when the PMK calculated by the two are consistent can the site device pass the authentication. Then the access point device can return an authentication pass frame to the site device to indicate that it has passed the authentication. When the PMKs calculated by the two are inconsistent, the access point device will inform the site device that the authentication has failed. The purpose of verifying PMK here is actually to verify PSK. The PMKs of the access point device and the site device are generated based on their respective PSKs. When the PMKs generated by the two are consistent, it can be shown that the PSKs of the two are consistent, which also indicates that the PSK used by the site device is correct. The PSK obtained by the site device can be input by the user. When the site device and the access point device calculate the PMK, they will also obtain a pairwise master key identifier (PMKID). PMKID can be used to quickly establish a connection between a station device and an access point device when it is not the first connection. In the embodiment of the present application, PMKID can also be called a quick connection key.
[0063] That is to say, when the site device selects open system authentication, the site device and the access point device do not need to verify the PSK during the link authentication phase, and the access point device will return an authentication pass frame to the site device to indicate that the site device has passed the authentication. When the site device selects SAE authentication, the two will verify the PSK during the link authentication phase. Only after the access point device successfully verifies the PSK of the site device will the access point device return an authentication pass frame to the site device to indicate that it has passed the authentication.
[0064] 3. Association stage.
[0065] The association phase is used to establish an association between the station device and the access point device. The station device can only establish an association with one access point device at a time. Establishing an association between the station device and the access point device means that the station device joins the network where the access point device is located.
[0066] The association phase can also be called the connection phase. The association phase may include but is not limited to the following steps:
[0067] S205: The station device sends a connection request frame to the access point device, in which the encryption method supported by the station device is declared.
[0068] S206: The access point device returns a connection response frame to the site device, where the connection response frame indicates that the site device is successfully connected.
[0069] During the association phase, the station device and the access point device negotiate some parameters of the network service. For example, the station device and the access point device can negotiate the listen interval to determine how often the station device listens to the Beacon frame, or the station device and the access point device can also determine whether the encryption capabilities of the two devices match.
[0070] The site device will send an Association Request frame to the access point device, which will carry the Gu'an network information. The AKM count field and AKM suites field in the Gu'an network information can indicate the access authentication methods that the site device can support. The site device can fill in the OUI of the PSK in the AKM suites field, which can indicate that the site device supports the use of WPA2 encryption.
[0071] After receiving the connection request frame, the access point device can determine whether the capabilities of the station device match its own. For example, the access point device can determine from the AKM suites field in the connection request frame that the station device supports WPA2 encryption, and the access point device itself can also support WPA2 encryption, which indicates that the encryption capabilities of the two match.
[0072] When a station device selects WPA2 to connect to an access point device, it declares in the connection request frame that it supports PSK encryption.
[0073] When a site device selects WPA3 to connect to an access point device, it will declare in the connection request frame that it supports SAE encryption. Since WPA3 requires site devices and access point devices to encrypt management frames, when a site device uses WPA3 encryption to connect to an access point device, the site device needs to configure a field in the connection request frame that supports management frame protection to indicate that it has the ability to protect management frames. In the connection request frame, the RSN Capabilities field may include a management frame protection capability (MFPC) field and a management frame protection required (MFPR) field. When the MFPC field is 1, it indicates that the device supports management frame protection (PMF), and when the MFPR field is 1, it indicates that the peer device must support PMF. The above-mentioned field that supports management frame protection may refer to the MFPC field being 1.
[0074] The access point device can send an AssociationResponse frame to the site device, and indicate in the frame that the two are successfully associated (i.e. connected). The site device and the access point device also need to complete the key negotiation in the access authentication phase, so that the site device can join the LAN where the access point device is located and communicate with other site devices in the LAN.
[0075] 4. Access authentication phase.
[0076] The access authentication phase is used to negotiate keys, so that when the access point device and the site device communicate subsequently, the two can use the negotiated keys to encrypt messages, thereby ensuring the security of data transmission.
[0077] The access authentication phase may include:
[0078] S207: The station device negotiates a key with the access point device.
[0079] In the access authentication phase, the station device may negotiate a key with the access point device to generate one or more keys, and the one or more keys are used to encrypt subsequent messages.
[0080] When a site device selects WPA2 to connect to an access point device, the two can negotiate based on the password of the network connection (i.e., PSK) and each generate a pairwise transient key (PTK). Then, the two can verify whether the PTK calculated by the other device is consistent with the PTK calculated by themselves.
[0081] When a station device selects WPA3 to connect to an access point device, the two can negotiate to generate their own PTKs through the PMK generated during the link authentication phase. Then, the station device and the access point device can determine whether the PTK generated by themselves is consistent with the PTK generated by the peer device. When the PTKs generated by the two are consistent, it indicates that the PMKs of the two are consistent.
[0082] Not limited to PTK, the station device and the access point device can also negotiate a group temporary key (GTK). PTK is used to encrypt unicast messages, and GTK is used to encrypt multicast and broadcast messages.
[0083] The station device and the access point device may generate PTK and GTK after four-way handshake of the extensible authentication protocol over LAN (EAPOL). When the station device and the access point device use WPA2 to establish a connection, the two use PSK to perform the EAPOL four-way handshake to generate keys, and when the station device and the access point device use WPA3 to establish a connection, the two use PMK to perform the EAPOL four-way handshake to generate keys.
[0084] After the site device and the access point device are authenticated for the first time through WPA3 encryption, the site device and the access point device can save the PMKID and its corresponding PMK generated by negotiation with the site device within a preset time. When the site device connects to the access point device again, the site device can send the PMKID to the access point device for verification. If the site device successfully verifies the PMKID, the two do not need to negotiate to generate PMK again, but directly use the existing PMK to perform EAPOL four-way handshake to generate PTK and GTK during the access authentication phase. The above process can be called WPA3 encrypted fast connection.
[0085] Figure 4 It is a flow chart of a quick connection between a site device and an access point device provided in an embodiment of the present application.
[0086] like Figure 4 As shown in the figure, the station device and access point device need to go through the following stages for a quick connection:
[0087] 1. Scanning stage.
[0088] The scanning phase may include but is not limited to the following steps:
[0089] S401: A station device sends a probe request frame to an access point device.
[0090] S402: The access point device returns a probe response frame to the site device, where the probe response frame states that the access point device supports WPA2 encryption and WPA3 encryption.
[0091] 2. Link authentication (Authentication) stage.
[0092] The link authentication phase may include but is not limited to the following steps:
[0093] S403: The site device sends a link authentication request frame to the access point device, where the link authentication request frame states that open system authentication is adopted.
[0094] S404: The access point device returns an authentication pass frame to the site device, where the authentication pass frame indicates that the site device has passed the authentication.
[0095] 3. Association stage.
[0096] The association phase may include but is not limited to the following steps:
[0097] S405: The site device sends a connection request frame to the access point device. The connection request frame declares that it supports WPA3 encryption and carries a quick connection key and supports management frame protection fields.
[0098] S406: The access point device determines that the fast connection key carried by the site device is correct and that the site device supports management frame protection.
[0099] S407: The access point device returns a connection response frame to the site device, where the connection response frame indicates that the site device is successfully connected.
[0100] In the case where the site device and the access point device use open system authentication, when the site device declares that it supports SAE encryption, the access point device will use WPA3's quick connection to authenticate the identity of the site device. The access point device will verify whether the site device carries the quick connection key (i.e. PMKID) and whether it has stored the PMK corresponding to the PMKID. The above PMKID and PMK can be determined when the site device and the access point device establish a connection for the first time.
[0101] At the same time, the access point device also determines whether the station device supports management frame protection. When the access point device and the station device use WPA3 fast connection, the connection request frame needs to carry the management frame protection support field. The above-mentioned management frame protection support field can refer to the MFPC field being 1.
[0102] When the access point device determines that the fast connection key carried by the station device is correct and the station device supports management frame protection, the two do not need to renegotiate to generate the PMK. The access point device can send a connection response frame to the station device, indicating in the connection response frame that the station device is successfully connected.
[0103] When the station device does not carry the fast connection key, or the fast connection key is incorrect, the access point device may indicate in a connection response frame that the station device connection fails, and the two are disconnected.
[0104] 4. Access authentication phase.
[0105] The access authentication phase may include:
[0106] S408: The station device negotiates a key with the access point device.
[0107] The station device and the access point device can use the PMK found in step S406 to perform an EAPOL four-way handshake to generate a PTK and a GTK. The two can use the above keys to encrypt messages during subsequent communication.
[0108] Currently, the implementation codes of some site devices (such as smart homes) are not standardized. They do not have the ability to encrypt WPA3, but they declare in the message that they support WPA3 encryption. When the access point device uses the WPA2-only encryption mode (in the WPA2-only encryption mode, the access point device declares that it only supports WPA2 encryption), this type of site device can successfully establish a connection with the access point device. When the access point device uses the WPA2 / WPA3 mixed encryption mode (in the WPA2 / WPA3 mixed encryption mode, the access point device declares that it supports both WPA2 encryption and WPA3 encryption), the problem of the non-standard implementation code of this type of site device will be exposed, making it impossible for this type of site device to establish a normal connection with the access point device.
[0109] The following introduces several scenarios in which the connection between a site device and an access point device fails, and a network connection method for each scenario provided in an embodiment of the present application.
[0110] Figure 5 This is a flow chart of a case where a station device fails to connect to an access point device, as provided in an embodiment of the present application. Figure 5 As shown in the figure, the process of connecting the station device to the access point device includes the following steps:
[0111] 1. Scanning phase.
[0112] The scanning phase may include:
[0113] S501: A station device sends a probe request frame to an access point device.
[0114] S502: The access point device returns a probe response frame to the site device. The probe response frame states that the access point device supports WPA2 encryption and WPA3 encryption.
[0115] For the introduction of the scanning phase, please refer to the above description, which will not be repeated here.
[0116] 2. Link authentication phase.
[0117] The link authentication phase may include:
[0118] S503: The site device sends a link authentication request frame to the access point device, where the link authentication request frame declares that open system authentication is adopted.
[0119] S504: The access point device returns an authentication pass frame to the site device, where the authentication pass frame indicates that the site device has passed the authentication.
[0120] For an introduction to the link authentication phase, please refer to the previous description and will not be repeated here.
[0121] 3. Association stage.
[0122] The association phase may include:
[0123] S505: The station device sends a connection request frame to the access point device. The connection request frame declares that it supports WPA2 encryption and WPA3 encryption, but does not carry a quick connection key and / or support a management frame protection field.
[0124] S506: The access point device returns a connection response frame to the site device, where the connection response frame indicates that the site device connection fails.
[0125] The access point device is in WPA2 / WPA3 mixed encryption mode, and the site device indicates that it supports both WPA2 and WPA3 encryption by filling the OUI of PSK encryption and SAE encryption in the AKM suites field.
[0126] Since the station device declares in the connection request frame that it supports both WPA2 encryption and WPA3 encryption, the access point device will preferentially select WPA3 encryption as the encryption method for this connection. In step S503, the station device declares in the link authentication request frame sent to the access point device that open system authentication is used, and the access point device will select WPA3's fast connection as the encryption method for this connection.
[0127] The access point device verifies whether the station device has a fast connection key (PMKID). If the station device does not carry the fast connection key, a fast connection cannot be made, and the access point device returns a connection response frame to the station device, indicating in the connection response frame that the station device connection failed.
[0128] Since the WPA3 network must support management frame protection, the access point device will also verify whether the station device supports management frame protection. The access point device can determine whether the station device supports management frame protection based on the MFPC field and MFPR field in the RSN capabilities field. If the station device does not support management frame protection, the connection will also fail.
[0129] Figure 5 The station device shown will enter the WPA3 quick connection process when using WPA3 encryption, resulting in access failure, but the station device can use WPA2 encryption to establish a connection with the access point device normally. In some embodiments, the access point device can guide the station device to use WPA2 encryption to establish a connection when the WPA3 quick connection process with the station device fails.
[0130] Figure 6 This is a flow chart of an access point device guiding a station device to establish a connection using WPA2 encryption provided by an embodiment of the present application. Figure 6 As shown in the figure, the process when the access point device guides the station device to use WPA2 to establish a connection may include but is not limited to the following steps:
[0131] 1. Scanning phase.
[0132] The scanning phase may include the following steps:
[0133] S601: A station device sends a probe request frame to an access point device.
[0134] S602: The access point device returns a probe response frame to the site device. The probe response frame states that the access point device supports WPA2 encryption and WPA3 encryption.
[0135] 2. Link authentication phase.
[0136] The link authentication phase may include the following steps:
[0137] S603: The site device sends a link authentication request frame to the access point device, where the link authentication request frame declares that open system authentication is adopted.
[0138] S604: The access point device returns an authentication pass frame to the site device, where the authentication pass frame indicates that the site has passed the authentication.
[0139] 3. Association stage.
[0140] The association phase may include the following steps:
[0141] S605: The station device sends a connection request frame to the access point device. The connection request frame declares that it supports WPA2 encryption and WPA3 encryption, but does not carry a quick connection key and / or support a management frame protection field.
[0142] S606: The access point device determines that the site device does not have the parameters necessary to implement WPA3 fast connection.
[0143] S607: The access point device determines that the site device supports WPA2 encryption, and uses the WPA2 encryption method to connect to the site device.
[0144] S608: The access point device returns a connection response frame to the site device, where the connection response frame indicates that the site connection is successful.
[0145] When the station device selects open system authentication, after receiving the connection request frame, the access point device determines that the station device does not carry the parameters required for WPA3 fast connection, and can determine whether the station device also supports WPA2 encryption. When the access point device determines that the station device supports WPA2 encryption, it can use the WPA2 encryption process to establish a connection with the station device.
[0146] The parameters required for the WPA3 fast connection include the field supporting management frame protection and the PMKID generated by the station device and the access point device in the past. The field supporting management frame protection can refer to the MFPC field and the MFPR field taking 1. In addition, the access point device can determine whether the station device supports WPA2 encryption by whether there is an OUI of PSK in the AKM suites in the RSN information.
[0147] In some embodiments, after the access point device determines that the site device selects WPA3 encrypted quick connection to establish a connection with the access point device, but does not have the parameters required for WPA3 quick connection, the MAC address of the site device can also be added to the encryption degradation list. In this way, when the access point device obtains the MAC address of the site device through active scanning or passive scanning during the scanning phase, it can first determine whether the MAC address exists in the encryption degradation list. If the MAC address of the site device is in the encryption degradation list, the access point device can use the WPA2 encryption process to establish a connection with the site device. Optionally, when the MAC address of the site device is stored in the encryption degradation list for a period of time exceeding a preset period of time, the access point device can remove the MAC address of the site device from the encryption degradation list.
[0148] 4. Access authentication phase.
[0149] The access authentication phase may include:
[0150] S609: The access point device and the station device negotiate a key.
[0151] The access point device can perform an EAPOL four-way handshake with the station device to verify the PSK of the station device, and then generate PTK and GTK. It should be noted that the access point device and the station device can negotiate and generate keys according to the EAPOL four-way handshake process during WPA2 encryption, and the two will generate PTK and GTK based on PSK. When the access point device and the station device encrypt according to WPA3, the two will verify PSK and then generate PMK during the link authentication phase, and then generate PTK and GTK based on PMK during the access authentication phase for use in subsequent data transmission.
[0152] That is to say, if the station device intends to use WPA2 to negotiate the key and chooses open system authentication, if the station device declares that it supports both WPA2 and WPA3 encryption, the access point device will authenticate the station device according to WPA3's quick connection. The access point device can use WPA2 to establish a connection with the station device when it determines that the station device does not have the parameters required for WPA3's quick connection. This ensures that the station device that wants to use WPA2 encryption but mistakenly enters the WPA3 quick connection process can successfully establish a connection with the access point device, thereby improving the user experience.
[0153] Figure 7 This is another flow chart provided in an embodiment of the present application when a station device fails to connect to an access point device.
[0154] like Figure 7 As shown in the figure, the process of connecting the station device to the access point device includes the following steps:
[0155] 1. Scanning phase.
[0156] The scanning phase may include:
[0157] S701: A station device sends a probe request frame to an access point device.
[0158] S702: The access point device returns a probe response frame to the site device. The probe response frame states that the access point device supports WPA2 encryption and WPA3 encryption.
[0159] 2. Link authentication phase.
[0160] The link authentication phase may include:
[0161] S703: The site device sends a link authentication request frame to the access point device, where the link authentication request frame states that open system authentication is adopted.
[0162] S704: The access point device returns an authentication pass frame to the site device, where the authentication pass frame indicates that the site device has passed the authentication.
[0163] 3. Association stage.
[0164] The association phase may include:
[0165] S705: The station device sends a connection request frame to the access point device. The connection request frame declares that it only supports WPA3 encryption, but does not carry a quick connection key and / or support a management frame protection field.
[0166] S706: The access point device returns a connection response frame to the site device, where the connection response frame indicates that the site device connection fails.
[0167] The access point device is in WPA2 / WPA3 mixed encryption mode. The station device only uses the SAE encrypted OUI in the AKM suites field of the RSN information to indicate that it only supports WPA3 encryption.
[0168] and Figure 5 The difference between the situation shown when the station device fails to connect to the access point device is that the station device declares in the connection request frame that it only supports WPA3 encryption and not WPA2 encryption. The access point device cannot successfully establish a connection when authenticating with the station device according to WPA3's quick connection. However, when the access point device is WPA2-only, this type of station device can authenticate with the access point device through WPA2 and establish a network connection. This situation may occur because this type of station device declares the encryption it supports based on the encryption capabilities of the access point device. When the access point device declares that it supports WPA3 encryption, this type of station device will declare that it only supports WPA3 encryption; when the access point device declares that it only supports WPA2 encryption, this type of station device will declare that it supports WPA2 encryption.
[0169] against Figure 7 Regarding the problem of connection failure between the site device and the access point device shown, in some embodiments, the access point device can guide the site device to use WPA2 encryption for identity authentication when the site device claims that it only supports WPA3 encryption but fails to use the WPA3 quick connection process.
[0170] Figure 8 This is another flow chart provided by an embodiment of the present application where an access point device guides a station device to establish a connection using WPA2. Figure 8As shown in the figure, the process when the access point device guides the station device to establish a connection using WPA2 encryption may include but is not limited to the following steps:
[0171] 1. Scanning phase.
[0172] The scanning phase may include the following steps:
[0173] S801. A station device sends a probe request frame to an access point device.
[0174] S802: The access point device returns a probe response frame to the site device. The probe response frame states that the access point device supports WPA2 encryption and WPA3 encryption.
[0175] 2. Link authentication phase.
[0176] The link authentication phase may include the following steps:
[0177] S803: The site device sends a link authentication request frame to the access point device. The link authentication request frame declares that open system authentication is adopted.
[0178] S804: The access point device returns an authentication pass frame to the site device, where the authentication pass frame indicates that the site has passed the authentication.
[0179] 3. Association stage.
[0180] The association phase may include the following steps:
[0181] S805: The station device sends a connection request frame to the access point device. The connection request frame declares that it supports WPA2 encryption and WPA3 encryption, but does not carry a quick connection key and / or support a management frame protection field.
[0182] S806: The access point device returns a connection response frame to the site device, where the connection response frame indicates that the site device connection fails.
[0183] S801-S806 is the process of the site device first accessing the network where the access point device is located. For the introduction of S801-S806, please refer to the introduction of S701-S706, which will not be repeated here.
[0184] S807: The access point device adds the MAC address of the site device to the encryption degradation list.
[0185] In some embodiments, when the station device and the access point device use open system authentication as the link authentication method of both, if the station device declares that it only supports WPA3 encryption but does not carry the parameters required for WPA3's fast connection, the access point device can add the MAC address of the station device to the encryption degradation list. The encryption degradation list may include one or more MAC addresses of station devices that use open system authentication and declare that they support WPA3 encryption but do not carry the parameters required for WPA3's fast connection.
[0186] The process when the station device tries to connect to the network where the access point device is located again may include:
[0187] 4. Scanning phase.
[0188] The scanning phase may include the following steps:
[0189] S808: The station device sends a probe request frame to the access point device.
[0190] S809: The access point device determines that the MAC address of the site device is in the encryption degradation list.
[0191] S810: The access point device returns a probe response frame to the site device, where the probe response frame states that the access point device only supports WPA2 encryption.
[0192] When the access point device receives the probe request frame from the station device, it can first query whether the MAC address of the station device is in the encryption degradation list. When the access point device determines that the MAC address of the station device exists in the encryption degradation list, it can declare in the probe response frame that it only supports WPA2 encryption.
[0193] It should be noted that the access point device declares in the detection response frame that it only supports WPA2 encryption only when it determines that the MAC address of the site device is in the encryption degradation list. For site devices whose MAC addresses are not in the encryption degradation list, the access point device still declares that it supports both WPA2 encryption and WPA3 encryption. In this way, the access point device can use WPA3 encryption first to establish a connection with a site device with WPA3 encryption capability, which is more secure.
[0194] 5. Link authentication phase.
[0195] The link authentication phase may include:
[0196] S811. The site device sends a link authentication request frame to the access point device. The link authentication request frame declares that open system authentication is adopted.
[0197] S812: The access point device returns an authentication pass frame to the site device, where the authentication pass frame indicates that the site device has passed the authentication.
[0198] 6. Association stage.
[0199] The association phase may include:
[0200] S813: The station device sends a connection request frame to the access point device, in which the station device declares that it supports WPA2 encryption.
[0201] S814: The access point device returns a connection response frame to the site device, where the connection response frame indicates that the site device is successfully connected.
[0202] 7. Access authentication phase.
[0203] The access authentication phase may include:
[0204] S815: The station device negotiates a key with the access point device.
[0205] The site device can negotiate the key with the access point device according to the pre-shared key (PSK) encryption method of WPA2 encryption. For example, the two can perform an EAPOL four-way handshake based on PSK to generate PTK and GTK. Among them, the two can adapt the message accordingly when performing the EAPOL four-way handshake based on the encryption method actually used (i.e., WPA2 encryption). For example, the access point device can indicate that it is a device that only supports WPA2 when performing the EAPOL four-way handshake.
[0206] That is to say, when a site device selects open system authentication and declares that it only supports WPA3 encryption, if the access point device determines that the site device does not have the parameters necessary for a fast connection with WPA3 encryption, the access point device can declare that it only supports WPA2 encryption when the site device tries to connect again. In this way, some site devices that only have WPA2 encryption capabilities but declare that they also support WPA3 encryption because the access point device supports WPA3 encryption can be guided by the access point device to use WPA2 encryption for access, thereby ensuring that such site devices can successfully connect to the LAN where the access point device is located.
[0207] Fig. 9 It is a flow chart of a network connection method provided in an embodiment of the present application.
[0208] like Fig. 9 As shown, the network connection method may include but is not limited to the following steps:
[0209] S901. A first electronic device receives a first message, where the first message indicates that a second electronic device requests to access a network.
[0210] The first electronic device may be an access point device (e.g., a router, a mobile phone with a portable hotspot turned on, etc.), and the second electronic device may be a station device with a compatibility problem (e.g., Figure 1 The first electronic device may receive a first message sent by the second electronic device, where the first message may be a probe request (ProbeRequest) frame sent by the site device to the access point device. The first electronic device uses a mixed encryption mode of WPA2 and WPA3 (also referred to as a mixed encryption mode of WPA2 / WPA3). When the first electronic device uses a mixed encryption mode of WPA2 and WPA3, when the second electronic device declares that it only supports WPA2 encryption, the first electronic device will use WPA2 encryption to connect to the second electronic device. When the second electronic device declares that it supports WPA3 encryption, the first electronic device will use WPA3 encryption to connect to the second electronic device.
[0211] S902: The first electronic device receives a second message, where the second message instructs the second electronic device to use open system authentication.
[0212] The first electronic device may receive a second message sent by the second electronic device, wherein the second message may be a link authentication request frame sent by the second electronic device. The second electronic device may declare to use open system authentication in the link authentication request frame.
[0213] S903: The first electronic device receives a third message, in which the second electronic device declares that it supports WPA3 encryption.
[0214] The first electronic device may receive a third message sent by the second electronic device, and the third message may be an Association Request frame sent by the second electronic device. The second electronic device may declare support for SAE encryption in the third message, where SAE encryption is an authentication method included in WPA3 encryption, which means that the second electronic device declares support for WPA3 encryption.
[0215] S904: The first electronic device determines, based on the second message and the third message, that the second electronic device does not have WPA3 encryption capability.
[0216] The first electronic device can determine that the second electronic device uses open system authentication based on the second message. When the first electronic device and the second electronic device use open system authentication, and the second electronic device declares that it supports SAE encryption, the first electronic device will verify whether the connection request frame carries a quick connection key (i.e., PMKID), and will verify whether the connection request frame contains a field that supports management frame protection.
[0217] When open system authentication is adopted and the second electronic device declares to support SAE, when the first electronic device determines that the second electronic device does not carry the quick connection key and / or the field supporting management frame protection, the first electronic device can determine that the second electronic device does not have the ability to complete WPA3 quick connection, that is, it does not have the ability of WPA3 encryption.
[0218] S905: The first electronic device establishes a connection with the second electronic device through WPA2 encryption.
[0219] When the first electronic device determines that the second electronic device claims to support WPA3 encryption but does not have the ability to encrypt WPA3, it can use WPA2 encryption to establish a connection with the second electronic device. In this way, the first electronic device can ensure that the second electronic device can use WPA2 to connect to the local area network normally when it cannot use WPA3 encryption to establish a connection, thereby improving compatibility.
[0220] In some embodiments, before the first electronic device receives the second message, the method further includes: the first electronic device sends a fourth message to the second electronic device, and the fourth message indicates that the first electronic device supports WPA2 encryption and WPA3 encryption. Here, the fourth message can be a probe response frame returned by the first electronic device to the second electronic device after receiving the probe request frame. In the case where the first electronic device uses the WPA2 / WPA3 mixed encryption mode, the first electronic device can indicate in the probe response frame that it supports both PSK encryption and SAE encryption, that is, the first electronic device supports both WPA2 encryption and WPA3 encryption. This makes it easier for the second electronic device to choose the encryption method it wants to use.
[0221] In some embodiments, the second electronic device further declares in the third message that it supports WPA2 encryption. Figure 6In the embodiment shown, the second electronic device declares in the third message (connection request frame) that it supports both WPA2 and WPA3 encryption. In this way, the first electronic device can use WPA2 to negotiate a key with the second electronic device when it is determined that the second electronic device does not have the ability to encrypt WPA3. In this way, a site device that only has WPA2 encryption capability but mistakenly declares that it supports WPA3 can be guided to WPA2 by the access point device, and then the site device uses WPA2 to establish a connection with the access point device, thereby ensuring that the site device with problems can still be normally connected to the local area network to avoid affecting the normal use of users.
[0222] In some embodiments, the second electronic device does not declare support for WPA2 encryption in the third message, and before the first electronic device establishes a connection with the second electronic device through WPA2 encryption, the method further includes: the first electronic device sends a fifth message to the second electronic device, the fifth message indicates that the second electronic device fails to connect to the network; the first electronic device receives a sixth message, the sixth message indicates that the second electronic device requests to access the network; the first electronic device sends a seventh message to the second electronic device, the seventh message indicates that the first electronic device only supports WPA2 encryption; the first electronic device receives an eighth message, in which the second electronic device declares support for WPA2 encryption. Reference Figure 8 In the embodiment shown, the third message here may be a connection request frame sent by the site device when it first attempts to connect to the access point device. The site device may declare in the connection request frame that it only supports WPA3 encryption. Since the site device does not carry the parameters required for using WPA3, the connection will fail. Referring to step S806, the access point device returns a connection response frame to the site device indicating that the site device connection failed. Here, the connection response frame may be referred to as the fifth message. The second electronic device may also try to establish a connection with the access point device again. Referring to step S808, the site device may send a probe request frame to the access point device again. Here, the probe request frame may also be referred to as the sixth message. Furthermore, the access point device may declare in the seventh message that it only supports WPA2 encryption, and guide the site device to use WPA2 to establish a connection with it. Here, the seventh message may be a probe response frame returned by the access point device to the site device when the site device attempts to connect to the access point device again (refer to step S810). Then, the station device will use WPA2 to establish a connection with it, and the station device can send an eighth message to the access point device, declaring in the eighth message that it only supports WPA2 encryption, and the eighth message can be, for example, the connection request frame in step S813. In this way, the station device that only has WPA2 encryption capability but declares that it also supports WPA3 because the access point device declares that it supports WPA3 can also be successfully connected to the local area network.
[0223] In some embodiments, after the first electronic device sends the fifth message to the second electronic device, the method further includes: the first electronic device stores the MAC address of the second electronic device in a first list, and the first list is used to store the MAC addresses of electronic devices that declare to support WPA3 encryption but cannot use WPA3 encryption to connect to the network; after the first electronic device receives the sixth message, the method further includes: the first electronic device determines that the MAC address of the second electronic device is in the first list. In the embodiment of the present application, the first list may also be referred to as an encryption degradation list. It should be noted that the first list here is not a list data structure, and the embodiment of the present application does not limit the data structure for storing the MAC addresses of electronic devices. Reference Figure 8 In the illustrated embodiment, when open system authentication is adopted, when the second electronic device declares that it supports SAE encryption but does not carry a quick connection key and / or supports the management frame protection field, the first electronic device can add the MAC address of the second electronic device to the encryption degradation list (refer to step S807). When the first electronic device receives the probe request frame (sixth message) from the second electronic device again requesting access, the first electronic device can search whether the MAC address of the second electronic device exists in the encryption degradation list. Since the MAC address of the second electronic device is stored in the encryption degradation list, the first electronic device can declare in the probe response frame that it only supports WPA2 encryption, thereby guiding the second electronic device to use WPA2 to establish a connection with it.
[0224] In some embodiments, the method further includes: the first electronic device determines that the length of time the MAC address of the second electronic device is stored in the first list exceeds a first duration; the first electronic device deletes the MAC address of the second electronic device from the first list. In other words, the MAC addresses in the encrypted degradation list are not stored indefinitely. When the length of time the MAC address of the second electronic device is stored in the encrypted degradation list exceeds a preset first duration, the first electronic device can also delete the MAC address of the second electronic device from the encrypted degradation list, so as to ensure that some site devices that only have problems for a short period of time can subsequently use WPA3 to establish a connection with the access point device.
[0225] In some embodiments, the method further includes: the first electronic device receives a ninth message, the ninth message indicates that the third electronic device requests to access the network; the first electronic device receives a tenth message, the tenth message indicates that the third electronic device uses open system authentication; the first electronic device receives an eleventh message, in which the third electronic device declares that it supports WPA3 encryption; the first electronic device determines that the third electronic device has WPA3 encryption capabilities based on the tenth and eleventh messages; the first electronic device establishes a connection with the third electronic device through WPA3 encryption. The third electronic device may be a station device with WPA3 encryption capabilities (for example, a station device that can complete WPA3 encryption). Figure 4 The first electronic device may receive a ninth message sent by the third electronic device, and the ninth message may be, for example, Figure 4 The first electronic device may also receive a tenth message that the third electronic device selects open system authentication, where the tenth message may be, for example, Figure 4 The third electronic device may also send an eleventh message to the first electronic device to declare support for WPA3 encryption. The eleventh message may be, for example, Figure 4 Furthermore, the first electronic device can determine that the connection request frame contains a support management frame protection field and a quick connection key, which means that the third electronic device has the WPA3 encryption capability. In this way, the first electronic device can establish a connection with the third electronic device through the WPA3 quick connection, and the two can generate a key based on the PMK corresponding to the PMKID during the access authentication stage.
[0226] An exemplary electronic device 100 provided in an embodiment of the present application is introduced below.
[0227] Fig.10 It is a schematic diagram of the structure of the electronic device 100 provided in an embodiment of the present application.
[0228] The following is a detailed description of the embodiment using the electronic device 100 as an example. It should be understood that the electronic device 100 may have more than Fig.10 More or fewer components may be shown, two or more components may be combined, or there may be a different configuration of components. Fig.10 The various components shown in the EMBODIMENTS 2000 may be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.
[0229] The electronic device 100 may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna, a wireless communication module 160, a button 190, an indicator 192, etc.
[0230] The processor 110 may include one or more processing units, for example, the processor 110 may include an application processor (AP), a modem processor, a controller, a memory, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Different processing units may be independent devices or integrated into one or more processors.
[0231] The controller may be the nerve center and command center of the electronic device 100. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0232] The processor 110 may also be provided with a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory may store instructions or data that the processor 110 has just used or cyclically used. If the processor 110 needs to use the instruction or data again, it may be directly called from the memory. This avoids repeated access, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0233] The charging management module 140 is used to receive charging input from a charger, where the charger can be a wireless charger or a wired charger.
[0234] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140 to power the processor 110, the internal memory 121, the external memory and the wireless communication module 160.
[0235] The wireless communication function of the electronic device 100 can be implemented through an antenna, a wireless communication module 160, a modem processor, a baseband processor, and the like.
[0236] The antenna is used to transmit and receive electromagnetic wave signals. The antenna in the electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve the utilization of the antenna. For example, the antenna can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.
[0237] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks) applied to the electronic device 100. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via an antenna, modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive signals to be sent from the processor 110, modulate the frequency of the signals, amplify the signals, and convert them into electromagnetic waves for radiation through the antenna. In some embodiments, at least some of the functional modules of the wireless communication module 160 can be set in the processor 110. In some embodiments, at least some of the functional modules of the wireless communication module 160 can be set in the same device as at least some of the modules of the processor 110.
[0238] In some embodiments, the antenna of the electronic device 100 is coupled to the wireless communication module 160 so that the electronic device 100 can communicate with a network and other devices through wireless communication technology.
[0239] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 via the external memory interface 120 to implement a data storage function.
[0240] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area may store an operating system, applications required for at least one function, etc. The data storage area may store data created during the use of the electronic device 100, etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. In some embodiments, an encrypted degradation list may be stored in the internal memory 121.
[0241] The key 190 includes a power button, etc. The key 190 may be a mechanical key or a touch key. The electronic device 100 may receive key input and generate key signal input related to user settings and function control of the electronic device 100.
[0242] The indicator 192 may be an indicator light, which may be used to indicate a charging status or a network connection status, etc.
[0243] It is to be understood that the structure shown in the embodiment of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include: Fig.10 More or fewer components may be shown, or some components may be combined or separated, or the components may be arranged differently. Fig.10 The components shown may be implemented in hardware, software, or a combination of software and hardware. For example, the electronic device 100 may also include a display screen, a touch sensor, and the like.
[0244] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
[0245] Figure 1 The router 101, smart camera 102, smart speaker 103, smart air conditioner 104 and mobile phone 105 shown in the figure can all be referred to as electronic devices. In the embodiment of the present application, the first electronic device can also be referred to as electronic device 100. The first electronic device can be Figure 1 The router 101 shown in FIG. 1 is a schematic diagram of a router 101. The structure of other electronic devices can be referred to the introduction of the electronic device 100, which will not be repeated here. In addition, other electronic devices may also include Fig.10 The electronic device 100 shown may have more or fewer components, and the embodiments of the present application are not limited to this.
[0246] As used in the above embodiments, the term "when..." may be interpreted to mean "if..." or "after..." or "in response to determining..." or "in response to detecting...", depending on the context. Similarly, the phrases "upon determining..." or "if (the stated condition or event) is detected" may be interpreted to mean "if determining..." or "in response to determining..." or "upon detecting (the stated condition or event)" or "in response to detecting (the stated condition or event)", depending on the context.
[0247] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that contains one or more available media integration. The available medium can be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk), etc.
[0248] Those skilled in the art can understand that to implement all or part of the processes in the above-mentioned embodiments, the processes can be completed by computer programs to instruct related hardware, and the programs can be stored in computer-readable storage media. When the programs are executed, they can include the processes of the above-mentioned method embodiments. The aforementioned storage media include: ROM or random access memory RAM, magnetic disk or optical disk and other media that can store program codes.
Claims
1. A network connection method, characterized in that: The method is applied to a first electronic device, the first electronic device is used to provide a network access service, and the first electronic device uses a mixed encryption mode of WPA2 and WPA3, and the method includes: The first electronic device receives a first message, wherein the first message indicates that the second electronic device requests to access a network; The first electronic device receives a second message, wherein the second message indicates that the second electronic device adopts open system authentication; The first electronic device receives a third message, in which the second electronic device declares that it supports WPA3 encryption; The first electronic device determines, based on the second message and the third message, that the second electronic device does not have WPA3 encryption capability; The first electronic device establishes a connection with the second electronic device through WPA2 encryption.
2. The method according to claim 1, characterized in that The first electronic device determines, based on the second message and the third message, that the second electronic device does not have a WPA3 encryption capability, including: When it is determined according to the second message that the second electronic device adopts the open system authentication, the first electronic device determines that the third message does not carry a fast connection key and / or supports a management frame protection field.
3. The method according to claim 1 or 2, characterized in that: Before the first electronic device receives the second message, the method further includes: the first electronic device sends a fourth message to the second electronic device, where the fourth message indicates that the first electronic device supports WPA2 encryption and WPA3 encryption.
4. The method according to any one of claims 1 to 3, characterized in that In the third message, the second electronic device also declares to support WPA2 encryption.
5. The method according to any one of claims 1 to 3, characterized in that: In the third message, the second electronic device does not declare that it supports WPA2 encryption, and before the first electronic device establishes a connection with the second electronic device through WPA2 encryption, the method further includes: The first electronic device sends a fifth message to the second electronic device, where the fifth message indicates that the second electronic device fails to connect to the network; The first electronic device receives a sixth message, wherein the sixth message indicates that the second electronic device requests to access a network; The first electronic device sends a seventh message to the second electronic device, where the seventh message indicates that the first electronic device only supports WPA2 encryption; The first electronic device receives an eighth message, in which the second electronic device declares to support WPA2 encryption.
6. The method according to claim 5, characterized in that After the first electronic device sends the fifth message to the second electronic device, the method further includes: the first electronic device storing the MAC address of the second electronic device in a first list, the first list being used to store the MAC addresses of electronic devices that declare to support WPA3 encryption but cannot use WPA3 encryption to connect to the network; After the first electronic device receives the sixth message, the method further includes: the first electronic device determining that the MAC address of the second electronic device is in the first list.
7. The method according to claim 6, characterized in that The method further comprises: The first electronic device determines that the MAC address of the second electronic device is stored in the first list for a period exceeding a first period; The first electronic device deletes the MAC address of the second electronic device from the first list.
8. The method according to any one of claims 1 to 7, characterized in that The method further includes: the first electronic device receiving a ninth message, the ninth message indicating that the third electronic device requests to access the network; The first electronic device receives a tenth message, wherein the tenth message indicates that the third electronic device adopts open system authentication; The first electronic device receives an eleventh message, in which the third electronic device declares to support WPA3 encryption; The first electronic device determines, based on the tenth message and the eleventh message, that the third electronic device has a WPA3 encryption capability; The first electronic device establishes a connection with the third electronic device through WPA3 encryption.
9. An electronic device, characterized in that: The electronic device comprises: a memory and a processor coupled to the memory; the memory stores a computer program, and when the processor executes the computer program, the electronic device implements the method according to any one of claims 1 to 8.
10. A computer-readable storage medium storing computer instructions, characterized in that: When the computer instructions are executed on an electronic device, the electronic device is caused to execute the method as claimed in any one of claims 1 to 8.
Citation Information
Cited By
Network connection method, electronic device, and computer-readable storage medium
EP4791057A1
Network connection method, electronic device, and computer-readable storage medium
WO2025097840A1