Method and apparatus for preventing illegal users from accessing a wireless network, router, and medium
By monitoring and analyzing messages sent by the user terminal, blocking the forwarding of messages containing preset identifiers, solving the problem of illegal users accessing wireless networks through password sharing software, and realizing the security of wireless network passwords.
Patent Information
- Application Number
- CN201910570868.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-06-28
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2039-06-28
AI Technical Summary
The prior art is difficult to effectively prevent illegal users from accessing wireless networks through password sharing software, resulting in theft of internal resources.
By monitoring and analyzing the messages sent by the user terminal, extracting their characteristic identifiers and comparing the preset identifiers. If it is found that the preset identifier is contained, the message forwarding is blocked to prevent the wireless network password from being shared.
It effectively prevents wireless network passwords from being shared, reduces the risk of illegal users accessing wireless networks, and protects the security of internal resources.
Smart Images

Figure CN112153637B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of network traffic monitoring and identification, and particularly to a method and a control device for controlling network usage behavior. Background Art
[0002] There are already password sharing software on the market that can share the password of a wireless network (such as a WIFI network). After a user enters the wireless network password in the interface of the password sharing software and accesses the wireless network, the wireless network password will also be sent to the server side of the application software. When other users enter the coverage area of the aforementioned wireless network, they can determine the name of the wireless network through a probe and request the wireless network password through the password sharing software to access the wireless network. However, after the wireless network password is shared, problems such as illegal users waiting to access the network to steal internal resources may occur. Summary of the Invention
[0003] This application provides a method and a device for preventing illegal users from accessing a wireless network. By monitoring and blocking the packets sent by the user terminal, the function of preventing password sharing or the function of changing the password before the password is shared can be realized.
[0004] On the one hand, this application provides a method for preventing illegal users from accessing a wireless network, including:
[0005] Receiving and temporarily storing the current packet sent by the user terminal;
[0006] Extracting the characteristic identifier of the current packet;
[0007] Judging whether the characteristic identifier includes a preset identifier; if so, blocking the forwarding of the current packet;
[0008] Wherein: the preset identifier includes one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; the preset program is a program for sharing the current password of the wireless network; the preset destination address is the destination server address, and the destination server is used to store the password of the shared wireless network; the preset field identifier is a field containing the wireless network password.
[0009] Optionally, the method further includes:
[0010] Generating a management and control prompt packet and sending the management and control prompt packet to the control terminal;
[0011] Wherein: the management and control prompt packet includes a prompt message, and the prompt message is used to prompt that the characteristic identifier includes the preset identifier.
[0012] Optionally, the method further includes:
[0013] Receive the return message sent by the control terminal;
[0014] Extract the reset password from the return message;
[0015] Monitor whether the user terminal leaves the wireless network;
[0016] If so, invalidate the current password of the wireless network and set the reset password as the password of the wireless network.
[0017] Optionally, the method further includes:
[0018] Before generating the management and control prompt message, generate a reset password;
[0019] Monitor whether the user terminal leaves the wireless network;
[0020] If so, invalidate the current password of the wireless network and set the reset password as the password of the wireless network;
[0021] Wherein: the management and control prompt message includes the reset password.
[0022] Optionally, the method further includes:
[0023] Before setting the reset password as the password of the wireless network, send a password reset message to other terminals except the user terminal;
[0024] Wherein; the password reset message includes the reset password.
[0025] Optionally, after determining that the feature identifier includes the preset identifier, the method further includes:
[0026] Monitor whether the user terminal leaves the wireless network;
[0027] If so, generate a reset password, invalidate the current password of the wireless network, and set the reset password as the password of the wireless network.
[0028] Optionally, before setting the reset password as the password of the wireless network, the method further includes:
[0029] Send a password reset message to other terminals except the user terminal, and / or generate a management and control prompt message and send the management and control prompt message to the control terminal;
[0030] Wherein: the password reset message includes the reset password; the management and control prompt message includes prompt information and / or the reset password; the prompt information is used to prompt that the feature identifier includes the preset identifier.
[0031] On the other hand, the present application provides a device for preventing illegal users from accessing a wireless network, including:
[0032] A storage unit for receiving and temporarily storing the current message sent by the user terminal;
[0033] An extraction unit for extracting the characteristic identifier of the current message;
[0034] A judgment unit for judging whether the characteristic identifier includes a preset identifier;
[0035] A blocking unit for blocking the forwarding of the current message when the judgment unit determines that the characteristic identifier includes a preset identifier;
[0036] Wherein, the preset identifier includes one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; the preset program is a program for sharing the current password of the wireless network; the preset destination address is the destination server address, and the destination server is used to store the password of the shared wireless network; the preset field identifier is a field containing the wireless network password.
[0037] Optionally, the device further includes: a management and control prompt unit for generating a management and control prompt message and sending the management and control prompt message to the control terminal;
[0038] Wherein: the management and control prompt message includes prompt information for prompting that the characteristic identifier includes the preset identifier.
[0039] Optionally, the management and control prompt unit is further configured to receive a return message sent by the control terminal and extract the reset password in the return message;
[0040] The device further includes:
[0041] A network monitoring unit for monitoring whether the user terminal leaves the wireless network;
[0042] A password reset unit for invalidating the current password of the wireless network and setting the reset password as the password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network.
[0043] Optionally, the device includes a password generation unit for generating a reset password when the judgment unit determines that the characteristic identifier includes a preset identifier;
[0044] A network monitoring unit for monitoring whether the user terminal leaves the wireless network;
[0045] A password reset unit, configured to invalidate the current password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network, and set the reset password as the password of the wireless network;
[0046] Wherein: the management and control prompt message includes the reset password.
[0047] Optionally, the device further includes:
[0048] A password distribution unit, configured to distribute a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network;
[0049] Wherein; the password reset message includes the reset password.
[0050] Optionally, the device further includes:
[0051] A network monitoring unit, configured to monitor whether the user terminal leaves the wireless network;
[0052] A password generation unit, configured to invalidate the current password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network, and set the reset password as the password of the wireless network.
[0053] Optionally, the device further includes:
[0054] A password distribution unit, configured to distribute a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network; and / or,
[0055] A management and control prompt unit, configured to generate a management and control prompt message and send the management and control prompt message to a control terminal;
[0056] Wherein: the password reset message includes the reset password; the management and control prompt message includes prompt information and / or the reset password; the prompt information is used to prompt that the feature identifier includes the preset identifier.
[0057] On the other hand, the present application provides a router, including a memory and a processor;
[0058] The memory is used to store multiple instructions;
[0059] The processor is used to implement each of the instructions;
[0060] The instructions are adapted to be loaded and executed by the processor to perform the method for preventing illegal users from accessing a wireless network as described above.
[0061] On the other hand, the present application provides a medium, which is a storage medium; the storage medium stores multiple instructions, and the instructions are suitable for being loaded and executed by a processor to perform the method for preventing illegal users from accessing a wireless network as described above.
[0062] In the method for preventing illegal users from accessing a wireless network provided by the present application, by comparing the feature identifier representing the characteristics of the current message with a preset identifier, it is determined whether the current message is a message generated by a password sharing software and sent to the corresponding server; if so, the forwarding of the current message is blocked, thereby avoiding the sharing of the wireless network password.
[0063] Such a method can at least avoid the sharing of the wireless network password before the user terminal leaves the wireless network, and thereby at least avoid illegal users from accessing the wireless network through the shared password during the period when the user terminal accesses the wireless network. Description of the Drawings
[0064] Figure 1 is a flowchart of the method for preventing illegal users from accessing a wireless network provided by an embodiment;
[0065] Figure 2 is a flowchart of the method for preventing illegal users from accessing a wireless network provided by another embodiment;
[0066] Figure 3 is a flowchart of the method for preventing illegal users from accessing a wireless network provided by another embodiment;
[0067] Figure 4 is a flowchart of the method for preventing illegal users from accessing a wireless network provided by another embodiment;
[0068] Figure 5 is a structural diagram of the device for preventing illegal users from accessing a wireless network provided by an embodiment;
[0069] Wherein: 11 - storage unit, 12 - extraction unit, 13 - judgment unit, 14 - blocking unit. Detailed Embodiments
[0070] The present application will be further described in detail below with reference to the drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention and are not intended to limit the invention. Additionally, it should be noted that for the sake of description, only parts related to the relevant invention are shown in the drawings.
[0071] An embodiment of the present application provides a method for preventing illegal users from accessing a wireless network. Here, an illegal user is a user who accesses the wireless network without the consent of an internal member who can normally use the wireless network or without the consent of the wireless network administrator. In the current situation, most illegal users obtain the password of the wireless network through password sharing software; and how to discover or block some legitimate users from sharing the password using password sharing software after accessing the wireless network is the key to solving the aforementioned problem.
[0072] Embodiment 1
[0073] Figure 1 is a flowchart of a method for preventing illegal users from accessing a wireless network provided by an embodiment. As Figure 1 shown, the method includes steps S101 - S105.
[0074] S101: Receive and temporarily store the current message sent by the user terminal.
[0075] After the user terminal connects to the wireless network, when an application installed on the user terminal and in the usage state needs to obtain wireless network resources or upload data, it calls the underlying communication module of the user terminal, and uses the underlying communication module to send the current message to the gateway device of the wireless network.
[0076] The gateway device of the wireless network is mostly the router of the wireless network. Among them, the communication protocol adopted by the wireless network can be any one of the WIFI protocol, Bluetooth protocol, and Zigbee protocol, and the present application does not make a special limitation on this.
[0077] S102: Extract the characteristic identifier of the current message.
[0078] After the gateway device of the wireless network receives and temporarily stores the current message, the corresponding identification device parses and processes the current message. In specific applications, it can be the gateway device that parses and processes the current message, or other devices connected to the gateway device that parse the message. The embodiments of the present application do not make a special limitation on this.
[0079] The methods for extracting the characteristic identifier of the current message include one or more of the following: (1) Parse the IP frame header data of the current message to determine the source IP address and destination IP address; (2) Parse the transport layer header protocol of the current message to determine the source port number and destination port number. (3) Parse the transport layer data body part of the current message to determine other identifying information that can represent the characteristics of the current message.
[0080] Among them, (1) and (2) can be obtained according to the IP protocol rules and TCP / UDP protocol rules, and (3) can be obtained according to the possible application layer protocols adopted, or obtained by possible identification algorithms such as deep learning algorithms.
[0081] S103: Determine whether the feature identifier includes a preset identifier; if not, execute S104; if so, execute S105.
[0082] S104: Forward the current message.
[0083] S105: Block the forwarding of the current message.
[0084] To more clearly illustrate the principle and function of this embodiment, the method of sharing passwords by a password sharing software (or password sharing network) is analyzed here first.
[0085] In practical applications, if a legitimate user obtains the current password of a wireless network through a non-password sharing software channel, this legitimate user inputs the current password of the wireless network into his own user terminal; at this time, the password sharing software obtains the current password of the wireless network; in order to quickly share the current password of the wireless network, the password sharing software will send the current password of the wireless network to the corresponding server as soon as possible.
[0086] To send the current password, the password sharing software causes the user terminal to generate a data message; to send the current password to the server, the data message at least includes the IP address of the server, the port number of the server's corresponding data, and the password field of the wireless network; in addition, some data messages triggered by the password sharing software to the user terminal can also display their program identifiers through the source port number or application layer data.
[0087] By identifying the various possible identifiers representing the server, the identifier representing the password field, or the identifier representing the password sharing program, it can be determined whether the data message is a message triggered by the password sharing software.
[0088] Combined with the foregoing upload message to the server by the secret sharing software for password sharing, after identifying the feature identifier of the current message, by determining whether the current message includes the foregoing feature identifier that may reflect the current password sharing behavior, it can be determined whether the current message is an identifier generated by the password sharing software triggering the user terminal.
[0089] To implement the foregoing judgment process, the embodiment of the present application provides a preset database, in which preset identifiers representing password sharing features corresponding to various sealed sharing software are stored. By comparing the foregoing feature identifier with the feature identifier, it can be determined whether the feature identifier contains the foregoing preset identifier.
[0090] If the feature identifier contains a preset identifier, it proves that the current message is triggered by a password sharing software; in order to prevent the current password of the wireless network from being shared, it is necessary to block the forwarding of the current message to prevent illegal users from accessing the wireless network through the current password obtained by sharing; if the feature identifier does not contain the foregoing preset identifier, it is determined that the current message is not generated by the user terminal triggered by the password sharing software, so the current message can be forwarded.
[0091] As mentioned above, the features of the password sharing software, the address of the server, the password field, etc. may all represent password sharing behaviors. Therefore, the preset identifier may include one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; among them, the preset program is the program for sharing the current password of the wireless network, and the preset destination address is the server address corresponding to the password sharing software and used to store the password of the shared wireless network.
[0092] Combined with the foregoing description, it can be seen that by using the method for preventing illegal users from accessing the wireless network provided in the embodiments of the present application, by comparing the feature identifier representing the characteristics of the current message with the preset identifier, it is determined whether the current message is an identifier generated by the password sharing software trigger and sent to the corresponding server; if so, the forwarding of the current message is blocked, thereby avoiding the sharing of the wireless network password.
[0093] It can be imagined that by using the foregoing method, at least before the user terminal leaves the wireless network, the current password of the wireless network can be prevented from being shared, and thus at least illegal users can be prevented from accessing the wireless network through the current password obtained by sharing during the period when the user terminal accesses the wireless network.
[0094] Embodiment 2
[0095] Figure 2 It is a flowchart of a method for preventing illegal users from accessing the wireless network provided by another embodiment. As Figure 2 shown, in another embodiment, the foregoing method includes steps S201-S206.
[0096] S201: Receive and temporarily store the current message sent by the user terminal.
[0097] After the user terminal connects to the wireless network, when the application program installed on the user terminal and in the use state needs to obtain wireless network resources or upload data, it calls the underlying communication module of the user terminal and uses the underlying communication module to send the current message to the gateway device of the wireless network.
[0098] S202: Extract the feature identifier of the current message.
[0099] The methods for extracting the feature identifier of the current message include one or more of the following: (1) Parse the IP frame header data of the current message to determine the source IP address and the destination IP address; (2) Parse the transport layer header protocol of the current message to determine the source port number and the destination port number. (3) Parse the transport layer data body part of the current message to determine other identifying information that can represent the characteristics of the current message.
[0100] Among them, (1) and (2) can be obtained according to the IP protocol rules and the TCP / UDP protocol rules, and (3) can be obtained according to the possible application layer protocols adopted, or obtained by possible identification algorithms such as deep learning algorithms.
[0101] S203: Determine whether the feature identifier includes a preset identifier; if not, execute S204; if so, execute S205 and S206.
[0102] S204: Forward the current message.
[0103] S205: Block the forwarding of the current message.
[0104] In practical applications, if a legitimate user obtains the password of a wireless network, this legitimate user inputs the current password of the wireless network into his own user terminal; after the password sharing software obtains the current password of the wireless network, in order to quickly share the current password of the wireless network, it will send the current password of the wireless network to the corresponding server as soon as possible.
[0105] In order to send the password, the password sharing software causes the user terminal to generate a data message; in order to send the current password to the server, the data message at least includes the IP address of the server, the port number of the server's corresponding data, and the password field of the wireless network; in addition, there are also some data messages triggered by the password sharing software to cause the user terminal to generate, which can also display their own program identifiers through the source port number or the application layer data.
[0106] By identifying the various possible identifiers representing the server, the identifiers representing the password field, or the identifiers representing the password sharing program mentioned above, it can be determined whether the data message is a message triggered by the password sharing software.
[0107] Combined with the foregoing for the secret sharing software to upload the current password to the server, after identifying the feature identifier of the current message, by determining whether the current message includes the foregoing feature identifiers that may reflect the password sharing behavior, it can be determined whether the current message is an identifier triggered by the password sharing software to cause the user terminal to generate.
[0108] To implement the foregoing judgment process, an embodiment of the present application provides a preset database, which stores preset identifiers representing password sharing features corresponding to various sealed sharing software. By comparing the foregoing feature identifiers with the feature identifiers, it can be determined whether the feature identifiers contain the foregoing preset identifiers.
[0109] If the feature identifier contains the preset identifier, it proves that the current message is triggered by the password sharing software; to prevent the current password of the wireless network from being shared, it is necessary to block the forwarding of the current message to prevent illegal users from accessing the wireless network through the shared password; if the feature identifier does not contain the foregoing preset identifier, it is determined that the current message is not generated by the user terminal triggered by the password sharing software, so the current message can be forwarded.
[0110] As described above, features of the password sharing software, server addresses, password fields, etc. may all represent password sharing behaviors. Therefore, the preset identifier may include one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; among them, the preset program is the program for sharing the current password of the wireless network, and the preset destination address is the server address corresponding to the password sharing software and used to store the shared wireless network and its password.
[0111] Combined with the foregoing description, it can be seen that by using the method for preventing illegal users from accessing the wireless network provided by the embodiment of the present application, by comparing the feature identifier representing the characteristics of the current message with the preset identifier, it is determined whether the current message is an identifier triggered by the password sharing software and sent to the corresponding server; if so, the forwarding of the current message is blocked, thereby preventing the wireless network password from being shared.
[0112] It can be imagined that by using the foregoing method, at least before the user terminal leaves the wireless network, the password of the wireless network can be prevented from being shared, and at least illegal users can be prevented from accessing the wireless network through the shared password during the period when the user terminal accesses the wireless network.
[0113] In addition, this embodiment further includes S206: generating a control prompt message and sending the control prompt message to the control terminal.
[0114] In addition to blocking the forwarding of the current message; when it is determined that the feature identifier corresponding to the current message contains the preset identifier, a control prompt message will also be generated and sent to the control terminal. The control prompt message includes prompt information for prompting that the feature identifier includes the preset identifier.
[0115] In this way, if a user terminal accessing the wireless network uses the password sharing software and performs the behavior of sharing the password using the wireless network, the control terminal can learn that the current password of the wireless network has been learned by the password sharing software.
[0116] In some cases, the password sharing software stores the current password of the wireless network and uploads the current password of the wireless network to the server when leaving this wireless network and reconnecting to the server again, so that the current password of the wireless network is shared. At this time, the wireless network cannot block the password sharing action of the user terminal. Therefore, it is necessary to prompt the control terminal that the single-sign password of the current wireless network may be made public in the future, and then prompt the person with control authority to change the password of the wireless network.
[0117] Embodiment III
[0118] Figure 3 is a flowchart of a method for preventing illegal users from accessing a wireless network provided by another embodiment. As Figure 3 shown, another embodiment is an improvement based on Embodiment II, which includes steps S301 - S311.
[0119] S301: Receive and temporarily store the current message sent by the user terminal.
[0120] S302: Extract the feature identifier of the current message.
[0121] S303: Determine whether the feature identifier includes a preset identifier; if not, execute S304; if so, execute S305 and S306.
[0122] S304: Forward the current message.
[0123] S305: Block the forwarding of the current message.
[0124] S306: Generate a management prompt message and send the management prompt message to the control terminal.
[0125] The possible implementation processes of the foregoing steps may be the same as those in Embodiment II and will not be repeated here. For details, please refer to Embodiment II.
[0126] In addition to the foregoing steps, in this embodiment, after S306, steps S307 - S310 are further included.
[0127] S307: Receive the return message sent by the control terminal.
[0128] In some application scenarios, when a person holding a control terminal and having management authority over the wireless network learns that the current password of the wireless network has been learned by the password sharing software, the first consideration is to set a reset password for the wireless network.
[0129] After the person with management authority inputs the reset password through the control terminal, the control terminal generates a return message including the reset password and sends the return message to the device capable of implementing the reset of the wireless network password.
[0130] S308: Extract the password reset in the returned message.
[0131] After receiving the returned message sent by the control terminal, extract the password reset in the returned message for resetting the password of the wireless network. It should be noted that at this time, since the current device installed with the password sharing software may not have left the wireless network yet, if the password of the wireless network is immediately set to the password reset, then after learning that the wireless network cannot be logged in, the person using the user terminal may obtain the password reset by asking, and use the password sharing software to share the password reset again.
[0132] S309: Monitor whether the user terminal leaves the wireless network; if so, execute S310; if not, continue to execute S309.
[0133] S310: Invalidate the current password of the wireless network and set the password reset as the password of the wireless network.
[0134] To avoid the problem of the password reset being leaked again caused by immediately setting the current password of the wireless network to the password reset, in the method provided by the embodiments of the present application, after obtaining the password reset, the current password of the wireless network is not directly invalidated, and the password of the wireless network is not set to the password reset. Instead, it monitors whether the user terminal installed with the password sharing software leaves the wireless network; if the user terminal leaves the wireless network, the current password of the wireless network is invalidated, and the password reset is set as the password of the wireless network.
[0135] Furthermore, in some other embodiments formed on the basis of Embodiment 3, in addition to the foregoing steps S301 - S310, it may further include step S311. Step S311 is located after S308 and before S310.
[0136] S311: Send a password reset message to other terminals except the user terminal.
[0137] Among them, the password reset message includes the password reset. It can be imagined that the password reset is sent to other terminals except the user terminal installed with the password sharing software through the password reset message, so that other terminals can learn the password reset. After the password of the wireless network is modified to the password reset, other terminals quickly use the password reset to connect to the wireless network again.
[0138] It should be noted that during the process of sending the password reset message, the user terminal installed with the password sharing software may still be connected to the wireless network or may have left the wireless network, and the present application does not limit this.
[0139] In the embodiments of the present application, the reset password is directly sent to other terminals except the user terminal installed with the password sharing software through a password reset message. Of course, in other embodiments, the person controlling the terminal or the control terminal may also inform other users of the devices connected to the wireless network of the reset password.
[0140] Of course, in some other embodiments, while keeping the current password, the reset password can be set as the password of the wireless network, and sent to other terminals except the user terminal through a password reset message, and the current password becomes invalid after the user terminal leaves the wireless network.
[0141] Embodiment 4
[0142] Figure 4 is a flowchart of a method for preventing illegal users from accessing a wireless network provided by another embodiment. As Figure 4 shown, in another embodiment, the method includes steps S401 - S408.
[0143] S401: Receive and temporarily store the current message sent by the user terminal.
[0144] S402: Extract the feature identifier of the current message.
[0145] S403: Determine whether the feature identifier includes a preset identifier; if not, execute S404; if so, execute S405 and S406.
[0146] S404: Forward the current message.
[0147] S405: Block the forwarding of the current message.
[0148] The possible implementation processes of the foregoing steps may be the same as those in Embodiment 2, and will not be repeated here. For details, refer to Embodiment 2.
[0149] In addition to the foregoing steps, in this embodiment, after S405, steps S406 - S407 are further included.
[0150] S406: Monitor whether the user terminal leaves the wireless network; if so, execute S407; if not, continue to execute S406.
[0151] S407: Generate a reset password, make the current password of the wireless network invalid, and set the reset password as the password of the wireless network.
[0152] In the embodiment of the present application, after determining that the current password of the wireless network has been learned by the password sharing software, it is monitored whether the user terminal leaves the wireless network; if so, the gateway device automatically generates a reset password, sets the reset password as the password of the wireless network, and invalidates the current password. In this way, illegal users are prevented from accessing the wireless network subsequently by another method.
[0153] Furthermore, before generating the reset password in S407, step S408 or S409 may also be executed.
[0154] S408: Send a password reset message to other terminals except the user terminal.
[0155] S409: Generate a management and control prompt message and send the management and control prompt message to the control terminal.
[0156] Among them, the password reset message includes the reset password. The management and control prompt message includes a prompt message, and the prompt message is used to prompt that the feature identifier includes the preset identifier and the reset password.
[0157] It can be imagined that through steps S408 and S409, before changing the password of the wireless network to the reset password, the devices still in the wireless network can obtain the reset password and access the wireless network.
[0158] Embodiment Five
[0159] Figure 5 It is a structural diagram of a device for preventing illegal users from accessing a wireless network provided by an embodiment. As Figure 5 shown, the foregoing device includes a storage unit 11, an extraction unit 12, a judgment unit 13, and a blocking unit 14.
[0160] The storage unit 11 is configured to receive and temporarily store the current message sent by the user terminal;
[0161] The extraction unit 12 is configured to extract the feature identifier of the current message;
[0162] The judgment unit 13 is configured to judge whether the feature identifier includes a preset identifier;
[0163] The blocking unit 14 is configured to block the forwarding of the current message when the judgment unit 13 determines that the feature identifier includes the preset identifier;
[0164] Among them, the preset identifier includes one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; the preset program is a program for sharing the current password of the wireless network; the preset destination address is the destination server address, and the destination server is used to store the password of the wireless network that has been shared; the preset field identifier is a field containing the wireless network password.
[0165] Further, in some embodiments, the foregoing device further includes a management and control prompt unit, which is configured to generate a management and control prompt message and send the management and control prompt message to the control terminal;
[0166] Wherein: the management and control prompt message includes a prompt message, and the prompt message is used to prompt that the feature identifier includes a preset identifier.
[0167] In addition, in some embodiments, the management and control prompt unit is further configured to receive a return message sent by the control terminal and extract the reset password in the return message; the device further includes a network monitoring unit and a password reset unit: the network monitoring unit is configured to monitor whether the user terminal leaves the wireless network; the password reset unit is configured to invalidate the current password of the wireless network and set the reset password as the password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network.
[0168] In some other embodiments, the foregoing device also includes a password generation unit, a network monitoring unit and a password reset unit; the password generation unit is configured to generate a reset password when the determination unit 13 determines that the feature identifier includes a preset identifier; the network monitoring unit is configured to monitor whether the user terminal leaves the wireless network; the password reset unit is configured to invalidate the current password of the wireless network and set the reset password as the password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network; wherein: the management and control prompt message includes the reset password.
[0169] In the embodiments mentioned in the foregoing two paragraphs, the device for preventing illegal users from accessing the wireless network may further include a password distribution unit; the password distribution unit is configured to send a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network; wherein; the password reset message includes the reset password.
[0170] In some other embodiments, the device for preventing illegal users from accessing the wireless network further includes a network monitoring unit and a password generation unit. The network monitoring unit is configured to monitor whether the user terminal leaves the wireless network; the password generation unit is configured to invalidate the current password of the wireless network and set the reset password as the password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network.
[0171] Based on the foregoing embodiments, some other devices for preventing illegal users from accessing the wireless network further include a password distribution unit and a management and control prompt unit; the password distribution unit is configured to send a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network; the management and control prompt unit is configured to generate a management and control prompt message and send the management and control prompt message to the control terminal; wherein: the password reset message includes the reset password; the management and control prompt message includes the prompt message and / or the reset password; the prompt message is used to prompt one or more of the feature identifiers including the preset identifier.
[0172] An embodiment of the present invention further provides a storage medium, which stores multiple instructions for a processor to load and execute the foregoing method for an illegal user to access a wireless network.
[0173] In addition, an embodiment of the present application further provides a router, which includes a storage medium and a processor; the processor is used to implement each instruction, and the memory is used to store multiple instructions, and the instructions are suitable for being loaded and executed by the processor for the foregoing device for an illegal user to access a wireless network.
[0174] A1. A method for preventing an illegal user from accessing a wireless network, including:
[0175] Receiving and temporarily storing a current message sent by a user terminal;
[0176] Extracting a feature identifier of the current message;
[0177] Determining whether the feature identifier includes a preset identifier;
[0178] If so, blocking the forwarding of the current message;
[0179] Wherein: the preset identifier includes one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; the preset program is a program for sharing the current password of the wireless network; the preset destination address is a destination server address, and the destination server is used to store the password of the shared wireless network; the preset field identifier is a field containing the wireless network password.
[0180] A2. The method for preventing an illegal user from accessing a wireless network according to A1, the method further includes:
[0181] Generating a control prompt message and sending the control prompt message to a control terminal;
[0182] Wherein: the control prompt message includes prompt information for prompting that the feature identifier includes the preset identifier.
[0183] A3. The method for preventing an illegal user from accessing a wireless network according to A2, the method further includes:
[0184] Receiving a return message sent by the control terminal;
[0185] Extracting a reset password from the return message;
[0186] Monitoring whether the user terminal leaves the wireless network;
[0187] If so, invalidating the current password of the wireless network and setting the reset password as the password of the wireless network.
[0188] A4. The method for preventing illegal users from accessing a wireless network according to claim A2, the method further comprising:
[0189] Before generating the management prompt message, generate a reset password;
[0190] Monitor whether the user terminal leaves the wireless network;
[0191] If so, invalidate the current password of the wireless network, and set the reset password as the password of the wireless network;
[0192] Wherein: the management prompt message includes the reset password.
[0193] A5. The method for preventing illegal users from accessing a wireless network according to A3 or A4, the method further comprising:
[0194] Before setting the reset password as the password of the wireless network, send a password reset message to other terminals except the user terminal;
[0195] Wherein; the password reset message includes the reset password.
[0196] A6. The method for preventing illegal users from accessing a wireless network according to A1,
[0197] After determining that the feature identifier includes the preset identifier, the method further comprises:
[0198] Monitor whether the user terminal leaves the wireless network;
[0199] If so, generate a reset password, invalidate the current password of the wireless network, and set the reset password as the password of the wireless network.
[0200] A7. The method for preventing illegal users from accessing a wireless network according to A6, before setting the reset password as the password of the wireless network, the method further comprises:
[0201] Send a password reset message to other terminals except the user terminal, and / or, generate a management prompt message, and send the management prompt message to a control terminal;
[0202] Wherein: the password reset message includes the reset password; the management prompt message includes prompt information, and / or, includes the reset password; the prompt information is used to prompt that the feature identifier includes the preset identifier.
[0203] A8. An apparatus for preventing illegal users from accessing a wireless network, comprising:
[0204] A storage unit, configured to receive and temporarily store a current message sent by a user terminal;
[0205] An extraction unit, configured to extract a feature identifier of the current message;
[0206] A judgment unit, configured to judge whether the feature identifier includes a preset identifier;
[0207] A blocking unit, configured to block the forwarding of the current message when the judgment unit determines that the feature identifier includes a preset identifier;
[0208] Wherein, the preset identifier includes one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; the preset program is a program for sharing the current password of the wireless network; the preset destination address is a destination server address, and the destination server is used to store the password of the shared wireless network; the preset field identifier is a field containing the wireless network password.
[0209] A9. The device for preventing illegal users from accessing a wireless network according to A8 further includes:
[0210] A management and control prompt unit, configured to generate a management and control prompt message and send the management and control prompt message to a control terminal;
[0211] Wherein: the management and control prompt message includes prompt information, and the prompt information is used to prompt that the feature identifier includes the preset identifier.
[0212] A10. The device for preventing illegal users from accessing a wireless network according to A9
[0213] The management and control prompt unit is further configured to receive a return message sent by the control terminal and extract a reset password from the return message;
[0214] The device further includes:
[0215] A network monitoring unit, configured to monitor whether the user terminal leaves the wireless network;
[0216] A password reset unit, configured to invalidate the current password of the wireless network and set the reset password as the password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network.
[0217] A11. The device for preventing illegal users from accessing a wireless network according to A9 further includes:
[0218] A password generation unit, configured to generate a reset password when the judgment unit determines that the feature identifier includes a preset identifier;
[0219] A network monitoring unit for monitoring whether the user terminal has left the wireless network;
[0220] A password reset unit for invalidating the current password of the wireless network and setting the reset password as the password of the wireless network when the network monitoring unit detects that the user terminal has left the wireless network;
[0221] Wherein: the management prompt message includes the reset password.
[0222] A12. The device for preventing illegal users from accessing a wireless network according to A10 or A11 further includes:
[0223] A password distribution unit for distributing a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network;
[0224] Wherein; the password reset message includes the reset password.
[0225] A13. The device for preventing illegal users from accessing a wireless network according to A8 further includes:
[0226] A network monitoring unit for monitoring whether the user terminal has left the wireless network;
[0227] A password generation unit for invalidating the current password of the wireless network and setting the reset password as the password of the wireless network when the network monitoring unit detects that the user terminal has left the wireless network.
[0228] A14. The device for preventing illegal users from accessing a wireless network according to A13 further includes:
[0229] A password distribution unit for distributing a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network; and / or,
[0230] A management prompt unit for generating a management prompt message and sending the management prompt message to a control terminal;
[0231] Wherein: the password reset message includes the reset password; the management prompt message includes prompt information, and / or, the reset password, and the prompt information is used to prompt that the feature identifier includes the preset identifier.
[0232] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0233] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working process of the device for describing the control network usage behavior can refer to the corresponding process in the foregoing method embodiments, and will not be elaborated herein.
[0234] It should be noted that the algorithms and displays provided in the embodiments are not inherently related to any specific computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The structure required to construct such a system is obvious from the above description. In addition, the present invention is not directed to any specific programming language. It should be understood that the content of the present invention described herein can be implemented using various programming languages, and the description of the specific language above is to disclose the best mode of the present invention.
[0235] In the specification provided herein, a large number of specific details are set forth. However, it can be understood that the embodiments of the present invention can be practiced without these specific details. In some instances, well-known methods, structures, and technologies have not been shown in detail so as not to obscure the understanding of this specification.
[0236] Similarly, it should be understood that in order to streamline this disclosure and assist in understanding one or more of the various inventive aspects, in the foregoing description of the exemplary embodiments of the present invention, the various features of the present invention are sometimes grouped together into a single embodiment, figure, or description thereof. However, the disclosed method should not be construed as reflecting an intention that the claimed invention requires more features than are expressly recited in each claim. Rather, as reflected in the following claims, the inventive aspects lie in less than all the features of the single foregoing disclosed embodiment. Thus, the claims following the detailed description are hereby expressly incorporated into this detailed description, with each claim standing on its own as a separate embodiment of the present invention.
[0237] Those skilled in the art can understand that the modules in the devices in the embodiments can be adaptively changed and disposed in one or more devices different from this embodiment. The modules or units or components in the embodiments can be combined into one module or unit or component, and in addition, they can be divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination can be used to combine all the features disclosed in this specification (including the accompanying claims, abstract, and drawings) and all the processes or units of any method or device so disclosed. Unless otherwise expressly stated, each feature disclosed in this specification (including the accompanying claims, abstract, and drawings) can be replaced by an alternative feature providing the same, equivalent, or similar purpose.
[0238] In addition, those skilled in the art will appreciate that, although some of the embodiments described herein include certain features included in other embodiments and not others, combinations of features of different embodiments are meant to be within the scope of the present invention and form different embodiments. For example, in the following claims, any one of the claimed embodiments can be used in any combination.
Claims
1. A method for preventing illegal users from accessing a wireless network, characterized in that, including: Receiving and temporarily storing the current message sent by the user terminal; Extracting the feature identifier of the current message; Judging whether the feature identifier includes a preset identifier; If so, blocking the forwarding of the current message; Wherein: the preset identifier includes one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; the preset program is a program for sharing the current password of the wireless network; the preset destination address is the destination server address, and the destination server is used to store the password of the shared wireless network; the preset field identifier is a field containing the wireless network password; The method further includes: Generating a control prompt message and sending the control prompt message to the control terminal; Wherein: the control prompt message includes a prompt message for prompting that the feature identifier includes the preset identifier; Receiving the return message sent by the control terminal; Extracting the reset password in the return message; Monitoring whether the user terminal leaves the wireless network; If so, invalidating the current password of the wireless network and setting the reset password as the password of the wireless network.
2. The method for preventing illegal users from accessing a wireless network according to claim 1, wherein The method further includes: Before generating the control prompt message, generating a reset password; Monitoring whether the user terminal leaves the wireless network; If so, invalidating the current password of the wireless network and setting the reset password as the password of the wireless network; Wherein: the control prompt message includes the reset password.
3. The method for preventing illegal users from accessing a wireless network according to claim 1 or 2, characterized in that, The method further includes: Before setting the reset password as the password of the wireless network, sending a password reset message to other terminals except the user terminal; Wherein; the password reset message includes the reset password.
4. The method for preventing illegal users from accessing a wireless network according to claim 1, characterized in that After determining that the feature identifier includes the preset identifier, the method further includes: Monitoring whether the user terminal leaves the wireless network; If so, generating a reset password, invalidating the current password of the wireless network, and setting the reset password as the password of the wireless network.
5. The method for preventing illegal users from accessing a wireless network according to claim 4, characterized in that Before setting the reset password as the password of the wireless network, the method further includes: Sending a password reset message to other terminals except the user terminal, and / or, generating a control prompt message and sending the control prompt message to the control terminal; Wherein: the password reset message includes the reset password; the control prompt message includes a prompt message and / or includes the reset password; the prompt message is used to prompt that the feature identifier includes the preset identifier.
6. A device for preventing illegal users from accessing a wireless network, characterized in that, including: A storage unit for receiving and temporarily storing the current message sent by the user terminal; An extraction unit for extracting the feature identifier of the current message; A judgment unit for judging whether the feature identifier includes a preset identifier; A blocking unit for blocking the forwarding of the current message when the judgment unit determines that the feature identifier includes a preset identifier; Wherein, the preset identifier includes one or more of a preset program identifier, a preset destination address identifier, and a preset field identifier; the preset program is a program for sharing the current password of the wireless network; the preset destination address is the destination server address, and the destination server is used to store the password of the shared wireless network; the preset field identifier is a field containing the wireless network password; Further included are: A control prompt unit, configured to generate a control prompt message and send the control prompt message to the control terminal; Wherein: the control prompt message includes a prompt message, and the prompt message is used to prompt that the feature identifier includes the preset identifier; The control prompt unit is further configured to receive a return message sent by the control terminal and extract the reset password in the return message; The device further includes: A network monitoring unit, configured to monitor whether the user terminal leaves the wireless network; A password reset unit, configured to invalidate the current password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network, and set the reset password as the password of the wireless network.
7. The device for preventing illegal users from accessing a wireless network according to claim 6, characterized in that, Further included are: A password generation unit, configured to generate a reset password when the determination unit determines that the feature identifier includes a preset identifier; A network monitoring unit, configured to monitor whether the user terminal leaves the wireless network; A password reset unit, configured to invalidate the current password of the wireless network when the network monitoring unit detects that the user terminal leaves the wireless network, and set the reset password as the password of the wireless network; Wherein: the control prompt message includes the reset password.
8. The device for preventing illegal users from accessing a wireless network according to claim 6 or 7, characterized in that, Further included are: A password distribution unit, configured to send a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network; Wherein; The password reset message includes the reset password.
9. The device for preventing illegal users from accessing a wireless network according to claim 6, wherein Further included are: A network monitoring unit, configured to monitor whether the user terminal leaves the wireless network; A password generation unit, configured to generate a reset password when the network monitoring unit detects that the user terminal leaves the wireless network, invalidate the current password of the wireless network, and set the reset password as the password of the wireless network.
10. The device for preventing illegal users from accessing a wireless network according to claim 9, wherein Further included are: A password distribution unit, configured to send a password reset message to other terminals except the user terminal before setting the reset password as the password of the wireless network; And / or, A control prompt unit, configured to generate a control prompt message and send the control prompt message to the control terminal; Wherein: the password reset message includes the reset password; the control prompt message includes a prompt message, and / or, the reset password, and the prompt message is used to prompt that the feature identifier includes the preset identifier.
11. A router, characterized in that, Including a memory and a processor; The memory is used to store multiple instructions; The processor is used to implement each of the instructions; The instructions are adapted to be loaded and executed by the processor to perform the method for preventing illegal users from accessing a wireless network according to any one of claims 1-5.
12. A medium, characterized in that, The medium is a storage medium; the storage medium stores multiple instructions, and the instructions are adapted to be loaded and executed by a processor to perform the method for preventing illegal users from accessing a wireless network according to any one of claims 1-5.
Citation Information
Patent Citations
Mobile terminal sharing isolation method and system
CN106850701A