Network access method and device
By identifying the characteristic information of terminal devices through access points (APs) and controlling network permissions according to device categories, the complexity and security issues of the MAC whitelist mechanism are resolved, achieving simplified configuration and improved security for network access control.
Patent Information
- Application Number
- CN202110349726.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-31
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2041-03-31
AI Technical Summary
Existing MAC whitelist mechanisms are complex to configure and require a lot of maintenance to prevent unauthorized network access. Furthermore, terminal devices cannot automatically reconnect to the network after changing their MAC addresses, resulting in poor security and user experience.
By identifying the characteristic information of terminal devices through access points (APs), network permissions are controlled according to preset device categories and access policies, including trusted devices, partially trusted devices, and untrusted devices, simplifying configuration and improving security.
It simplifies network access control, improves user experience and network security, and reduces the operational complexity and maintenance costs for administrators.
Smart Images

Figure CN115150832B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a network access method and device. Background Art
[0002] With the increasing number of wireless fidelity (WiFi) password cracking tools, some password cracking tools directly share WiFi passwords with others, rendering the verification of WiFi passwords to improve security ineffective. Freeloaders are everywhere. As long as others know the WiFi password, they can access the local area network, which poses a great threat to the security of devices in the local area network.
[0003] Currently, a common solution to prevent freeloading is to use a MAC whitelist mechanism, that is, to configure the MAC address of the terminal device to the gateway's whitelist. When the terminal device accesses the gateway, the gateway will check whether the MAC address of the terminal device exists in the whitelist. If the MAC address of the terminal device exists in the whitelist, the terminal device is allowed to access the network. If the MAC address of the terminal device is not in the whitelist, the terminal device is not allowed to access the network. This solution has many drawbacks. For example, the process of configuring the whitelist is relatively complicated, and the workload of maintaining the whitelist is large. Moreover, current terminals basically support random MAC addresses to access the network. This will cause the terminal device that has been configured with a MAC address in the whitelist to be unable to access the network the next time it accesses the network with a new MAC address, and the new MAC address needs to be added to the whitelist again. Summary of the Invention
[0004] The embodiments of the present application provide a network access method and apparatus, in order to provide a network access control method that is simple for users to operate and highly secure.
[0005] In a first aspect, the present application provides a network access method, which is applied to an access point AP, and the method includes: when a first terminal device is detected to be connected to the AP, the AP identifies the characteristic information of the first terminal device, the AP determines the device category to which the first terminal device belongs based on the characteristic information of the first terminal device, and the AP controls the first terminal device's access rights to a target network based on a preset access policy according to the device category to which the first terminal device belongs, and the target network includes a local area network and / or the Internet.
[0006] Based on this solution, the AP can identify the category of the terminal device connected to the AP based on its characteristic information, and control its access to the target network based on the preset access policy. It can provide users with a network access control method that is simple to operate and highly secure, and can be used without complex configuration, thereby improving the user experience.
[0007] In one possible design, the AP determines the device category to which the first terminal device belongs based on the characteristic information of the first terminal device, including: the AP determines the device category to which the first terminal device belongs based on the characteristic information of the first terminal device and a first correspondence; the first correspondence indicates a correspondence between preset characteristic information and preset device categories. In this way, the AP can quickly determine the device category to which the first terminal device belongs based on the characteristic information of the first terminal device and the first correspondence.
[0008] In one possible design, the preset device categories include trusted device categories and untrusted device categories. The AP controls the permission of the first terminal device to access the target network based on the preset access policy according to the device category to which the first terminal device belongs, including: if the first terminal device belongs to the trusted device category, the AP allows the first terminal device to access the target network; or, if the first terminal device belongs to the untrusted device category, the AP sends a first request message to the second terminal device, and controls the permission of the first terminal device to access the target network based on the first response message fed back by the second terminal device in response to the first request message; wherein the first request message is used to request authorization for the first terminal device to access the target network. In this way, the preset device categories are divided into two categories. After accessing the network through the WiFi password, the first terminal device belonging to the trusted device category can directly access the Internet and any device in the local area network without the need for administrator authorization. After accessing the network through the WiFi password, the first terminal device belonging to the untrusted device category requires administrator authorization to access the Internet and devices in the local area network.
[0009] In one possible design, the first response message includes information indicating that the first terminal device is authorized to access the target network, or information indicating that the first terminal device is denied access to the target network; based on the first response message fed back by the second terminal device in response to the first request message, the first terminal device's access to the target network is controlled, including: if the first response message includes information indicating that the first terminal device is authorized to access the target network, the AP allows the first terminal device to access the target network; or, if the first response message includes information indicating that the first terminal device is denied access to the target network, the AP denies the first terminal device access to the target network. In this way, after being authorized, the first terminal device in the untrusted device category becomes a trusted device and belongs to the trusted device category. It can then freely access the Internet and devices within the local area network. This allows the untrusted device to freely access the target network with one authorization, without having to authorize each time it accesses the target network. This can simplify user operations and improve user experience. After the first terminal device in the untrusted device category is denied authorization, it cannot access the Internet or devices within the local area network, thus ensuring security.
[0010] In one possible design, the preset device categories include fully trusted device categories, partially trusted device categories, and untrusted device categories; the AP controls the first terminal device's access to the target network based on the preset access policy according to the device category to which the first terminal device belongs, including: if the first terminal device belongs to the fully trusted device category, the AP allows the first terminal device to access the target network; or, if the first terminal device belongs to the partially trusted device category, the AP allows the first terminal device to access the Internet and devices with public attributes in the local area network, and prohibits the first terminal device from accessing devices with privacy attributes in the local area network; or, if the first terminal device belongs to the untrusted device category, the AP denies the first terminal device access to the target network. In this way, after the first terminal device belongs to the fully trusted device category and accesses the network through the WiFi password, it can directly access the Internet and any device in the local area network without the need for administrator authorization. After the first terminal device belongs to the partially trusted device category and accesses the network through the WiFi password, it can directly access the Internet and no authorization is required for trusted network behavior, which is access to devices with public attributes in the local area network.
[0011] In one possible design, the first terminal device belongs to the partially trusted device category, and the method further includes: the AP detects that the first terminal device accesses a device with privacy attributes within the local area network; the AP sends a second request message to the second terminal device, the second request message being used to request authorization for the first terminal device to access the device with privacy attributes within the local area network; and the AP controls access rights to the local area network for the first terminal device based on a second response message fed back by the second terminal device. In other words, if the first terminal device, which belongs to the partially trusted device category, engages in untrusted network behavior, i.e., accesses a device with privacy attributes within the local area network, it will require authorization from the administrator to become a fully trusted device before it can continue the network behavior, thereby ensuring the security of devices with public attributes within the local area network.
[0012] In one possible design, the second response message includes information indicating that the first terminal device is authorized to access devices with privacy attributes in the local area network, or information indicating that the first terminal device is denied access to devices with privacy attributes in the local area network; the AP controls access rights of the first terminal device to the local area network based on the second response message fed back by the second terminal device, including: if the second response message includes information indicating that the first terminal device is authorized to access devices with privacy attributes in the local area network, the AP allows the first terminal device to access devices with privacy attributes in the local area network; or, if the second response message includes information indicating that the first terminal device is denied access to devices with privacy attributes in the local area network, the AP denies the first terminal device access to devices with privacy attributes in the local area network. If the first terminal device belonging to the partially trusted device category obtains authorization once, it becomes a fully trusted device and can continue to access devices with privacy attributes in the local area network. It does not need administrator authorization every time it accesses a device with privacy attributes, which is convenient for users to operate. If the first terminal device belonging to the partially trusted device category does not obtain authorization, it can still only access devices with public attributes in the Internet and the local area network, and cannot access devices with privacy attributes in the local area network, thereby ensuring the security of devices with public attributes in the local area network.
[0013] In a second aspect, the present application provides a network access method, which is applied to a terminal device, such as the second terminal device described above, and includes: the second terminal device receiving a first request message sent by an AP, the first request message being used to request authorization for the first terminal device to access a target network; and the second terminal device sending a first response message to the AP, the first response message including information indicating authorization for the first terminal device to access the target network, or information indicating denial of access to the target network for the first terminal device. In this way, an administrator can operate on the second terminal device and selectively decide to authorize or deny authorization for the first terminal device to access the target network, the target network including a local area network and / or the Internet.
[0014] In one possible design, the second terminal device also receives a second request message sent by the AP, the second request message being used to request authorization for the first terminal device to access devices with privacy attributes within the local area network. The second terminal device sends a second response message to the AP, the second response message including information indicating authorization for the first terminal device to access devices with privacy attributes within the local area network, or information indicating denial of access for the first terminal device to devices with privacy attributes within the local area network. In this way, the administrator can operate on the second terminal device and selectively decide to authorize or deny authorization for the first terminal device to access devices with privacy attributes within the local area network.
[0015] In a third aspect, the present application provides a network access device, which may be a device for a communication system or a chip or chipset within a device in a communication system, wherein the device for a communication system may be a terminal or an access point. The device may include a processing unit and a transceiver unit. When the device is a device for a communication system, the processing unit may be a processor and the transceiver unit may be a transceiver. The device may also include a storage unit, which may be a memory. The storage unit is configured to store instructions, and the processing unit executes the instructions stored in the storage unit to cause the terminal to perform the corresponding functions of the first or second aspect described above. When the device is a chip or chipset within a communication system, the processing unit may be a processor and the transceiver unit may be an input / output interface, pin, or circuit, etc. The processing unit executes the instructions stored in the storage unit to cause the device to perform the corresponding functions of the first aspect and any possible design of the first aspect, or to perform the corresponding functions of the second aspect and any possible design of the second aspect. The storage unit may be a storage unit within the chip or chipset (eg, a register, a cache, etc.), or a storage unit within a device for a communication system that is external to the chip or chipset (eg, a read-only memory, a random access memory, etc.).
[0016] In a fourth aspect, the present application also provides a computer-readable storage medium, which stores instructions. When the computer-readable storage medium is executed, the method described in the first aspect and any possible design in the first aspect is executed, or the method described in the second aspect and any possible design in the second aspect is executed.
[0017] In a fifth aspect, the present application also provides a computer program product comprising instructions, which, when executed, enables the method described in the first aspect and any possible design of the first aspect to be executed, or enables the method described in the second aspect and any possible design of the second aspect to be executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] Figure 1A A schematic diagram of the architecture of a communication system applicable to this application;
[0019] Figure 1B A schematic diagram of the architecture of a communication system applicable to this application;
[0020] Figure 2 A flowchart of a network access method provided by this application;
[0021] Figure 3 A flowchart of a network access method provided by this application;
[0022] Figure 4A flowchart of a network access method provided by this application;
[0023] Figure 5 A schematic diagram of the structure of an access point provided for this application;
[0024] Figure 6 A schematic diagram of the structure of an access point provided for this application;
[0025] Figure 7 A schematic diagram of the structure of a terminal device applicable to this application. DETAILED DESCRIPTION
[0026] In order to make the purpose, technical solutions and advantages of this application clearer, this application will be further described in detail below with reference to the accompanying drawings.
[0027] Figure 1A A schematic diagram of the architecture of a communication system applicable to an embodiment of the present application.
[0028] like Figure 1A As shown, the communication system may include an access point (AP) 101, at least one terminal device ( Figure 1A Taking the terminal device 102 and the terminal device 103 as an example) and the Internet. The Internet is, for example, a mobile network, such as a fifth-generation (5G) network, a long term evolution (LTE) network, and the like. Both AP101 and the terminal device 102 and AP101 and the terminal device 103 can perform local area network (WLAN) communication based on a WiFi connection. The terminal device 103 can be fixed or movable. The present application does not limit the number of APs and terminal devices included in the communication system. The AP can perform WLAN communication with a single terminal device or with multiple terminal devices.
[0029] An AP (such as AP101), also known as a wireless access point or hotspot, bridges the gap between wireless and wired networks and is the core device for establishing a wireless local area network (WLAN). It primarily provides access between terminal devices and the wired LAN. Terminal devices within the AP's signal coverage area can communicate with each other through the AP. In other words, an AP is the access point for terminal devices to access the wired network. APs can be deployed in homes, buildings, and campuses, with a typical coverage radius of tens to hundreds of meters. They can also be deployed outdoors. An AP can be a base station, an evolved NodeB (eNodeB), a transmission reception point (TRP), the next-generation NodeB (gNB) in 5G communication systems, a base station in future communication systems, or an access point in a Wi-Fi system. It can also be a module or unit that performs some of the functions of a base station, such as a centralized unit (CU) or a distributed unit (DU). It can also be a router, a switch, a bridge, a wireless gateway, or a terminal device. This application does not limit the specific technology and specific device form adopted by the AP.
[0030] Terminal devices (such as terminal device 102 and terminal device 103) are communication devices connected to a wireless network, such as wireless communication chips, terminal devices, etc.; wherein, terminal devices can also be referred to as terminals, user equipment (UE), mobile stations, mobile terminals, etc. Terminal devices can be mobile phones, tablet computers, computers with wireless transceiver functions, virtual reality terminal devices, augmented reality terminal devices, wireless terminals in industrial control, wireless terminals in unmanned driving, wireless terminals in remote surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, etc. This application does not limit the specific technology and specific device form used by the terminal devices.
[0031] The AP and the terminal device can communicate via a 2.4 gigahertz (GHz) spectrum, a 5 GHz spectrum, or a 60 GHz spectrum. This application does not limit the spectrum resources used between the AP and the terminal device.
[0032] Figure 1A The communication system shown can be applied to the WiFi network of a smart home. Figure 1AWhen the communication system shown is applied to a smart home WiFi network, AP 101 can be a router, and terminal devices 102 and 103 can be wireless terminals in the smart home, such as mobile phones, tablet computers, laptops, smart refrigerators, smart air conditioners, etc. In one possible scenario, a new wireless terminal needs to access the smart home WiFi network. For example, a guest's mobile phone may need to access the smart home WiFi network.
[0033] based on Figure 1A , Figure 1B This is a schematic diagram of the architecture of another communication system applicable to the embodiments of the present application.
[0034] like Figure 1B As shown, the terminal devices connected to the router in the communication system may include: an administrator device, a device that has been authorized by the administrator, and a device that has not been authorized by the administrator, wherein the administrator device is, for example, Figure 1B Mobile phone A in the figure can set the access permission for the terminal device that is connected to the router for the first time. For devices that have been authorized by the administrator, such as Figure 1B The file servers, printers, projectors, and cameras in the system can access the Internet and devices in the LAN through the router. Devices that are not authorized by the administrator, such as mobile phone B, are not allowed to access the Internet and devices in the LAN through the router.
[0035] It should be noted that the system architecture and application scenarios described in this application are intended to more clearly illustrate the technical solutions of this application and do not constitute a limitation on the technical solutions provided by this application. Ordinary technicians in this field can know that with the evolution of the system architecture and the emergence of new business scenarios, the technical solutions provided by this application are also applicable to similar technical problems.
[0036] The following describes in detail the network access method provided by this application for solving the technical problems in the background technology. In the following introduction, the AP can be the above Figure 1A The AP101 in the example above can be the terminal device. Figure 1A Terminal device 102 or terminal device 103 in Figure 1A The communication system shown is applied to the WiFi network of a smart home. The first terminal device can be a terminal device to be connected to the WiFi network of the smart home, for example, a visiting guest's mobile phone; the second terminal device can be any terminal device in the WiFi network of the smart home that has been authorized to access the AP, for example, the owner's mobile phone.
[0037] Reference below Figure 2 , is a flow chart of the network access method provided by this application. Figure 2 As shown, the method flow includes the following steps:
[0038] Step 201: When it is detected that a first terminal device is connected to an access point AP, the AP identifies feature information of the first terminal device.
[0039] The characteristic information is the behavioral characteristics of the first terminal device when using the network, including but not limited to the identity information of the accessed IP address, the characteristics of the accessed network, etc. For example, the characteristic information is the IP address accessed by the first terminal device, and the characteristics of the first terminal device accessing the network through HUAWEI HiLink.
[0040] Step 202: The AP determines the device category to which the first terminal device belongs based on the feature information of the first terminal device.
[0041] In one possible implementation, the AP stores a first correspondence relationship, the first correspondence relationship including a correspondence relationship between preset feature information and preset device categories. The AP can determine the device category to which the first terminal device belongs based on the feature information of the first terminal device and the first correspondence relationship.
[0042] In an embodiment of the present application, the preset device categories may include two categories: trusted device categories and untrusted device categories. For example, IOT devices, mobile phones and computers that have been authorized by the administrator belong to the trusted device category and can freely access the network. Mobile phones and computers that have not been authorized by the administrator belong to the untrusted device category and require the administrator's authorization to use the network. The preset device categories may also include three categories: fully trusted device categories, partially trusted device categories and untrusted device categories. For example, IOT devices, mobile phones and computers that have been authorized by the administrator to access devices with privacy attributes in the local area network belong to the fully trusted device category and can freely access the network. Mobile phones and computers that have not been authorized by the administrator to access devices with privacy attributes in the local area network belong to the partially trusted device category and require the administrator's authorization to access devices with privacy attributes in the local area network. Mobile phones and computers that are using the Internet for free belong to the untrusted device category and cannot access any network. They need the administrator's authorization to use the network.
[0043] For example, if the AP detects the IP address accessed by the first terminal device, it can identify the first terminal device as a mobile phone. The first terminal device is not authorized to access the network through the AP and can be determined as an untrusted device. For another example, if the AP detects that the first terminal device accesses the network through HUAWEI HiLink, it can identify the first terminal device as an IoT device and determine it as a trusted device.
[0044] The following is an example of an administrator. Taking a Huawei router as an example, when a user uses the router for the first time after purchasing it (or the first time they power it on), they are required to register a Huawei account and bind it to the router through the "Smart Life" app before they can continue to configure and use it. This user is defined as an administrator, and all authorizations require the administrator to operate. When the administrator does not turn on the "WiFi access authorization" function, all terminal devices can use the local area network and the Internet normally as long as they enter the WiFi password. When the administrator turns on the "WiFi access authorization" function, the router will turn on the identity recognition function and classify the connected terminal devices into: trusted devices, partially trusted devices, and untrusted devices. It should be understood that the "WiFi access authorization" function can also be called by other names, such as the "WiFi authorization" function, the "authorized WiFi" function, the "authorization" function, etc., and of course it can also be called by other names, which are not limited here.
[0045] In step 203 , the AP controls the access permission of the first terminal device to the target network based on a preset access policy according to the device category to which the first terminal device belongs. The target network includes a local area network and / or the Internet.
[0046] The embodiment of the present application is described by taking the target network including a local area network and the Internet as an example.
[0047] In the embodiment of the present application, the local area network includes a wired local area network and a wireless local area network, which will not be described in detail below.
[0048] Here, if the preset device categories include trusted device categories and untrusted device categories, the preset access policy may include: terminal devices belonging to the trusted device category are allowed to access any device in the local area network and the Internet, and terminal devices belonging to the untrusted device category are prohibited from accessing any device in the local area network and the Internet. If the preset device categories include fully trusted device categories, partially trusted device categories, and untrusted device categories, the preset access policy may include: terminal devices belonging to the fully trusted device category are allowed to access any device in the local area network and the Internet, terminal devices belonging to the partially trusted device category are allowed to access devices with public attributes in the local area network and the Internet, and are prohibited from accessing devices with public or private attributes in the local area network, and terminal devices belonging to the untrusted device category are prohibited from accessing any device in the local area network and the Internet.
[0049] There are multiple possible implementations of step 203. The following exemplifies two implementations of controlling the access permission of the first terminal device to the target network based on a preset access policy according to the device category to which the first terminal device belongs.
[0050] In the first embodiment, the preset device categories include trusted device categories and untrusted device categories. The above step 203 can be implemented in the following manner a1 or a2:
[0051] Mode a1: If the first terminal device belongs to the trusted device category, the AP allows the first terminal device to access the target network, that is, the AP allows the first terminal device to access the Internet and any device in the local area network through the AP.
[0052] In method a1, after the first terminal device belonging to the trusted device category accesses the network through the WiFi password, it can directly access the Internet and any device in the local area network without the need for administrator authorization.
[0053] In method a2, if the first terminal device is classified as untrusted, the AP requests the administrator to authorize the first terminal device to access the target network. The AP can send a first request message to the second terminal device, requesting authorization for the first terminal device to access the target network. The AP then controls the first terminal device's access to the target network based on the first response message sent back by the second terminal device in response to the first request message.
[0054] The second terminal device is a device having authority to manage access to the target network through the AP, that is, a terminal device used by an administrator.
[0055] In one possible implementation, the first response message includes information indicating authorization for the first terminal device to access the target network, or information indicating denial of access to the target network for the first terminal device. Controlling the first terminal device's access to the target network based on the first response message fed back by the second terminal device in response to the first request message can be implemented using the following methods b1 and b2:
[0056] Mode b1, the first response message includes information indicating that the first terminal device is authorized to access the target network, then the AP allows the first terminal device to access the target network, that is, the AP allows the first terminal device to access the Internet and any device in the local area network through the AP.
[0057] Mode b2, the first response message includes information indicating that the first terminal device is denied access to the target network, then the AP denies the first terminal device access to the target network, that is, the AP does not allow the first terminal device to access the Internet and any device in the local area network through the AP.
[0058] In method a2, after the first terminal device belonging to the untrusted device category accesses the network through the WiFi password, it needs administrator authorization to access the Internet and the devices in the local area network. After the first terminal device in the untrusted device category is authorized, it becomes a trusted device and belongs to the trusted device category. It can then freely access the Internet and the devices in the local area network. For example, a family member buys a new mobile phone 1. When mobile phone 1 connects to the AP for the first time, it is identified as an untrusted device. Through method a2, the untrusted device (i.e., mobile phone 1) can be authorized once to freely access the target network. There is no need to authorize it every time it accesses, which can simplify user operations and improve user experience. For another example, someone in the neighboring household uses mobile phone 2 to surf the Internet. Mobile phone 2 cracks the password using a WiFi password cracking tool and connects to the AP. It is identified as an untrusted device by the AP. Method a2 can be used to deny authorization to mobile phone 2 to access the Internet and any device in the local area network through the AP.
[0059] The following provides a specific example of a method for implementing network access, taking the example of preset device categories including trusted device categories and untrusted device categories.
[0060] like Figure 3 As shown, the method includes the following steps:
[0061] Step 301: When it is detected that a first terminal device is connected to an access point AP, the AP identifies feature information of the first terminal device.
[0062] Step 302: The AP determines the device category to which the first terminal device belongs based on the feature information of the first terminal device.
[0063] The specific implementation of steps 301-302 can refer to the relevant content in the above steps 201-202, which will not be repeated here.
[0064] Step 303 : Whether the first terminal device belongs to the trusted device category; if so, execute step 305 ; if not, execute step 304 .
[0065] Here, if the first terminal device does not belong to the trusted device category, that is, the first terminal device belongs to the untrusted device category, then the AP can request the second terminal device to authorize the first terminal device to access the target network through the above method a2, and determine whether it is authorized based on the response message feedback from the second terminal device. The specific implementation can be found in the above method a2, which will not be repeated here.
[0066] Step 304: Is the user authorized to access the target network? If so, proceed to step 305; if not, proceed to step 306.
[0067] Step 305: The AP allows the first terminal device to freely access the target network.
[0068] Step 306: The AP prohibits the first terminal device from accessing the target network.
[0069] In the second embodiment, the preset device categories include fully trusted device categories, partially trusted device categories, and untrusted device categories. The above step 203 can be implemented in the following manner c1 or manner c2:
[0070] Mode c1: the first terminal device belongs to the fully trusted device category, and the AP allows the first terminal device to access the target network, that is, the AP allows the first terminal device to access the Internet and any device in the local area network through the AP.
[0071] In mode c1, after the first terminal device, which belongs to the fully trusted device category, accesses the network through the WiFi password, it can directly access the Internet and any device in the local area network without the need for administrator authorization.
[0072] In method c2, if the first terminal device belongs to the partially trusted device category, the AP allows the first terminal device to access the Internet and public devices within the LAN, but prohibits the first terminal device from accessing private devices within the LAN. That is, the AP allows the first terminal device to access the Internet and public devices within the LAN through the AP, but prohibits the first terminal device from accessing private devices within the LAN through the AP.
[0073] Devices with public attributes are, for example, IoT devices, including but not limited to home cameras, smart refrigerators, smart speakers, and robot vacuums. Devices with private attributes are, for example, devices that store sensitive information (such as photos and important documents) and devices related to property security, including but not limited to file servers, safes, and laptops.
[0074] In one possible implementation, a first terminal device belongs to the partially trusted device category. An AP detects that the first terminal device has accessed a device with privacy attributes within a local area network. The AP sends a second request message to a second terminal device, requesting authorization for the first terminal device to access the device with privacy attributes within the local area network. The AP controls access rights of the first terminal device to the local area network based on a second response message fed back by the second terminal device. The second response message includes information indicating authorization for the first terminal device to access the device with privacy attributes within the local area network, or information indicating denial of access to the device with privacy attributes within the local area network.
[0075] The AP controls the access rights of the first terminal device to the local area network according to the second response message fed back by the second terminal device, which can be achieved through the following methods d1 and d2:
[0076] Mode d1: The second response message includes information indicating that the first terminal device is authorized to access the device with privacy attributes in the local area network, and the AP allows the first terminal device to access the information of the device with privacy attributes in the local area network.
[0077] In mode d2, the second response message includes information indicating that the first terminal device is denied access to the device with privacy attributes in the local area network, and the AP denies the first terminal device access to the device with privacy attributes in the local area network.
[0078] In method c2, after the first terminal device belonging to the partially trusted device category accesses the network through the WiFi password, it can directly access the Internet and does not need authorization for trusted network behavior, which is accessing devices with public attributes in the local area network. Once untrusted network behavior occurs, the administrator's authorization is required to continue the network behavior, which is accessing devices with privacy attributes in the local area network. In a specific implementation, the user can choose to authorize as a fully trusted device, or only authorize access to the requested device with privacy attributes. For example, taking privacy device A as an example, if the first terminal device is only authorized to access the requested privacy device A, then the first terminal device still belongs to the partially trusted device category and can only access the requested privacy device A. If the first terminal device wants to access other privacy devices, such as privacy device B, it needs to initiate a request again to access privacy device B after obtaining authorization.
[0079] If the first terminal device belonging to the partially trusted device category is not authorized, it can still only access the Internet and devices with public attributes in the local area network, and cannot access devices with privacy attributes in the local area network.
[0080] Mode c3: If the first terminal device belongs to the untrusted device category, the AP denies the first terminal device access to the target network, that is, the AP does not allow the first terminal device to access the Internet and any device in the local area network through the AP.
[0081] Furthermore, the AP may send a third request message to the second terminal device, where the third request message is used to request authorization for the first terminal device to become a partially trusted device. If the third response message fed back by the second terminal device to the third request message includes authorization for the first terminal device to become a partially trusted device, the first terminal device may access the Internet and devices with public attributes within the local area network through the AP, but is not allowed to access devices with privacy attributes within the local area network through the AP.
[0082] If the third response message fed back by the second terminal device in response to the third request message includes refusing to authorize the first terminal device to become a partially trusted device, the first terminal device may not be able to access the Internet and any device in the local area network through the AP.
[0083] In method c3, after a first terminal device in the untrusted device category accesses the network using a WiFi password, it needs administrator authorization to access the Internet and public devices within the LAN through the AP. After being authorized, the first terminal device in the untrusted device category becomes a partially trusted device, belonging to the partially trusted device category. It can then access the Internet and public devices within the LAN, but is not allowed to access private devices within the LAN through the AP.
[0084] Of course, the second terminal device can also choose to authorize specific permissions for the first terminal device, for example, authorizing a terminal device belonging to the untrusted device category to become a partially trusted device, belonging to the partially trusted device category; for another example, authorizing a terminal device belonging to the untrusted device category to become a fully trusted device, belonging to the fully trusted device category; for another example, authorizing a terminal device belonging to the partially trusted device category to become a fully trusted device, belonging to the fully trusted device category.
[0085] Based on any of the above embodiments, the second terminal device can also update or revoke the permissions of the authorized terminal device. For example, for a terminal device belonging to the fully trusted device category, its permissions are reduced so that the terminal device belongs to the partially trusted device category, and its permissions are updated to: allowing access to the Internet and devices with public attributes within the local area network; for another example, for a terminal device belonging to the fully trusted device category, its permissions are reduced so that the terminal device belongs to the untrusted device category, and its permissions are updated to: not allowing access to the Internet and any device within the local area network; for another example, for a terminal device belonging to the partially trusted device category, its permissions are reduced so that the terminal device belongs to the untrusted device category, and its permissions are updated to: not allowing access to the Internet and any device within the local area network.
[0086] The following provides a specific example of a method for implementing network access, taking the preset device categories including a fully trusted device category, a partially trusted device category, and an untrusted device category as an example.
[0087] like Figure 4 As shown, the method includes the following steps:
[0088] Step 401: When it is detected that a first terminal device is connected to an access point AP, the AP identifies feature information of the first terminal device.
[0089] Step 402: The AP determines the device category to which the first terminal device belongs based on the feature information of the first terminal device.
[0090] The specific implementation of steps 401-402 can refer to the relevant content in the above steps 201-202, which will not be repeated here.
[0091] Step 403 : Whether the first terminal device belongs to the category of fully trusted devices; if so, execute step 409 ; if not, execute step 404 .
[0092] Here, if the first terminal device belongs to the fully trusted device category, the first terminal device can access all devices in the local area network and can also access the Internet. If the first terminal device does not belong to the fully trusted device category, that is, the first terminal device may be in one of two situations: a partially trusted device category or an untrusted device category, and further determination can be made in step 404.
[0093] Step 404 : Whether the first terminal device belongs to the partially trusted device category; if so, execute step 407 ; if not, execute step 405 .
[0094] Here, if the first terminal device belongs to the partially trusted device category, the first terminal device can access the Internet and public devices within the local area network, but is prohibited from accessing private devices and access points within the local area network. In this case, if the first terminal device accesses a private device and access points within the local area network, it constitutes unauthorized access to the network. Execution continues at step 407 to determine whether unauthorized access to the network has occurred.
[0095] If the first terminal device does not belong to the partially trusted device category, that is, the first terminal device belongs to the untrusted device category.
[0096] Step 405 , whether the first terminal device is authorized to access the target network; if so, execute step 406 ; if not, execute step 413 .
[0097] Here, the first terminal device belongs to the untrusted device category. A request can be made to authorize the first terminal device to access the target network. If the first terminal device is authorized to access the target network, the next step is to determine whether it is authorized as a fully trusted device or a partially trusted device, i.e., step 406. If the first terminal device is not authorized to access the target network, it cannot access the Internet or the local area network.
[0098] Step 406 : Whether the first terminal device is authorized as a fully trusted device; if so, execute step 409 ; if not, execute step 407 .
[0099] Here, if the first terminal device belonging to the untrusted device category in step 405 is authorized as a fully trusted device, step 409 is executed, that is, the AP can allow the first terminal device to access any device in the external network and the wireless local area network.
[0100] If the first terminal device, which belongs to the untrusted device category in step 405, is not authorized as a fully trusted device, then it is authorized as a partially trusted device. The first terminal device can access the Internet and public devices within the local area network, but is prohibited from accessing devices with private attributes within the local area network. In this case, if the first terminal device accesses the private device AP within the local area network, it is considered an unauthorized access to the network. The process then proceeds to step 407 to determine whether there is any unauthorized access to the network.
[0101] Step 407 , whether the first terminal device has unauthorized access to the network; if so, execute step 408 ; if not, execute step 409 .
[0102] Here, if the first terminal device, which belongs to the category of partially trusted devices, accesses the network without authorization, that is, accesses a device with privacy attributes, such as accessing privacy device C, it can request authorization to access privacy device C. The administrator can choose to authorize the first terminal device to access devices with privacy attributes (that is, it can access all privacy devices in the local area network), or choose to authorize the first terminal device to access a single privacy device it requests access, that is, privacy device C, or choose not to authorize the first terminal device to access any privacy device.
[0103] Step 408 , whether access to the device with privacy attributes in the local area network is authorized; if so, execute step 409 ; if not, execute step 410 .
[0104] Step 409: The AP allows the first terminal device to freely access the target network.
[0105] Step 410 : Whether the first terminal device is authorized to access a single privacy device; if so, execute step 411 ; if not, execute step 412 .
[0106] Step 411: The AP allows the first terminal device to access a single privacy device.
[0107] Step 412: The AP allows the first terminal device to access the Internet and devices with public attributes in the local area network.
[0108] Step 413: The AP prohibits the first terminal device from accessing the target network.
[0109] In this embodiment, after a terminal device connects to an AP, its category can be automatically identified. For example, IoT devices at home are automatically identified as trusted devices and can access the network without configuration or authorization. After connecting to Wi-Fi for the first time, computers and mobile phones only need to go through a one-time authorization process: the administrator simply clicks an authorization button, and the phone can access the network. Devices that the administrator has not authorized are denied any network permissions. This solution eliminates the need for complex pre-configuration by administrators, reduces maintenance costs, lowers the barrier to entry, and improves intranet network security.
[0110] It is understood that in order to implement the functions in the above embodiments, the communication device and server include hardware structures and / or software modules corresponding to the execution of each function. It should be readily apparent to those skilled in the art that, in combination with the units and method steps of each example described in the embodiments disclosed in this application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in hardware or in a manner driven by computer software depends on the specific application scenario and design constraints of the technical solution.
[0111] Figure 5 and Figure 6 This is a schematic diagram of the structure of the possible AP provided in this application. These APs can be used to implement the method performed by the AP in the above method embodiment, and thus can also achieve the beneficial effects possessed by the above method embodiment. In this application, the AP can be as follows Figure 1A The AP101 shown may also be applied to an AP or a module of an AP (such as a chip).
[0112] like Figure 5 As shown, the AP500 includes an identification module 501, a determination module 502 and a control module 503. The AP500 is used to implement the above Figure 2 、 Figure 3 or Figure 4 The method embodiment shown in FIG.
[0113] When AP500 is used to achieve Figure 2 The functions of the AP in the method embodiment shown are: an identification module 501, which is used to identify the characteristic information of the first terminal device when it is detected that the first terminal device is connected to the access point AP; a determination module 502, which is used to determine the device category to which the first terminal device belongs based on the characteristic information of the first terminal device; a control module 503, which is used to control the access rights of the first terminal device to the target network based on a preset access policy according to the device category to which the first terminal device belongs, and the target network includes a local area network and the Internet.
[0114] In an optional implementation, the determination module 502 is specifically configured to determine the device category to which the first terminal device belongs based on the feature information of the first terminal device and a first correspondence; the first correspondence includes a correspondence between preset feature information and a preset device category.
[0115] In an optional embodiment, AP500 also includes a transceiver module 504, and the preset device categories include a trusted device category and an untrusted device category; a control module 503 is specifically used to allow the first terminal device to access the target network if the first terminal device belongs to the trusted device category; or, the first terminal device belongs to the untrusted device category, the transceiver module 504 is used to send a first request message to the second terminal device and receive a first response message, and the control module 503 is specifically used to control the access permission of the first terminal device to the target network according to the first response message fed back by the second terminal device to the first request message; wherein, the first request message is used to request authorization for the first terminal device to access the target network, and the second terminal device is a device with management permission to access the target network through the AP.
[0116] In an optional embodiment, the first response message includes information indicating that the first terminal device is authorized to access the target network, or information indicating that the first terminal device is denied access to the target network; the control module 503 is specifically used to allow the first terminal device to access the target network if the first response message includes information indicating that the first terminal device is authorized to access the target network; or, if the first response message includes information indicating that the first terminal device is denied access to the target network, deny the first terminal device access to the target network.
[0117] In an optional embodiment, the preset device category includes a fully trusted device category, a partially trusted device category, and an untrusted device category;
[0118] The control module 503 is specifically used to allow the first terminal device to access the target network if the first terminal device belongs to the fully trusted device category; or, if the first terminal device belongs to the partially trusted device category, allow the first terminal device to access the Internet and devices with public attributes in the local area network, and prohibit the first terminal device from accessing devices with privacy attributes in the local area network; or, if the first terminal device belongs to the untrusted device category, deny the first terminal device access to the target network.
[0119] In an optional embodiment, the first terminal device belongs to the partially trusted device category, and the identification module 501 is further used to detect that the first terminal device accesses a device with privacy attributes in the local area network; the transceiver module 504 is further used to send a second request message to the second terminal device, and the second request message is used to request authorization for the first terminal device to access the device with privacy attributes in the local area network; the second terminal device is a device with management authority to access the target network through the AP; the control module 503 is further used to control the access authority of the first terminal device to the local area network according to the second response message fed back by the second terminal device.
[0120] In an optional embodiment, the second response message includes information indicating that the first terminal device is authorized to access devices with privacy attributes in the local area network, or information indicating that the first terminal device is denied access to devices with privacy attributes in the local area network; the control module 503 is specifically used for: if the second response message includes information indicating that the first terminal device is authorized to access devices with privacy attributes in the local area network, then the first terminal device is allowed to access devices with privacy attributes in the local area network; or, if the second response message includes information indicating that the first terminal device is denied access to devices with privacy attributes in the local area network, then the first terminal device is denied access to devices with privacy attributes in the local area network.
[0121] For more detailed description of the identification module 501, the determination module 502, the control module 503 and the transceiver module 504, please refer to Figure 2 The relevant descriptions in the method embodiment shown are directly obtained and will not be repeated here.
[0122] It should be understood that the identification module 501, determination module 502 and control module 503 in the embodiment of the present application can be implemented by a processor or processor-related circuit components, and the transceiver module 504 can be implemented by a transceiver or transceiver-related circuit components.
[0123] Based on the above content and the same concept, Figure 6 As shown, the present application also provides an AP 600. The AP 600 may include a processor 601 and a transceiver 602. The processor 601 and the transceiver 602 are coupled to each other. It is understood that the transceiver 602 may be an interface circuit or an input / output interface. Optionally, the communication device 600 may also include a memory 603 for storing instructions executed by the processor 601, input data required by the processor 601 to execute instructions, or data generated by the processor 601 after executing instructions.
[0124] When the communication device 600 is used to implement Figure 2In the method shown, the processor 601 is used to execute the functions of the above-mentioned identification module 501, determination module 502, and control module 503, and the transceiver 602 is used to execute the functions of the above-mentioned transceiver module 504, which will not be repeated here.
[0125] The following describes the hardware structure of the terminal device provided in the embodiments of the present application.
[0126] Please refer to Figure 7 , which is a structural example diagram of an example of a terminal device 200 provided in an embodiment of the present application. The terminal device 200 may include a processor 210, an external memory interface 220, an internal memory 221, a universal serial bus (USB) interface 230, a charging management module 240, a power management module 241, a battery 242, an antenna, a wireless communication module 250, an audio module 260, a speaker 260A, a speaker interface 260B, a sensor module 270, a button 280, an indicator 281, a display screen 282, etc. The sensor module 270 may include a pressure sensor 270A, a gyroscope sensor 270B, a magnetic sensor 270C, a distance sensor 270D, a proximity light sensor 270E, a touch sensor 270F, an ambient light sensor 270G, etc.
[0127] It should be understood that the structure illustrated in the embodiment of the present invention does not constitute a specific limitation on the terminal device 200. In other embodiments of the present invention, the terminal device 200 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0128] The processor 210 may include one or more processing units. For example, the processor 210 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.
[0129] The controller may be the nerve center and command center of the terminal device 200. The controller may generate an operation control signal according to the instruction operation code and the timing signal to complete the control of fetching and executing instructions.
[0130] Processor 210 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 210 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 210. If processor 210 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 210 latency, and thus improves system efficiency.
[0131] In some embodiments, the processor 210 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.
[0132] The processor 210 may control the execution of application code to implement the functions of the terminal device 200 in this embodiment.
[0133] The USB interface 230 is an interface that complies with USB standards and may be a MiniUSB interface, a MicroUSB interface, a USB Type-C interface, or the like. The USB interface 230 can be used to connect a charger to charge the terminal device 200, or to transfer data between the terminal device 200 and peripheral devices. It can also be used to connect to a speaker to play audio. This interface can also be used to connect to other terminal devices, such as AR devices.
[0134] It is understood that the interface connection relationship between the modules illustrated in the embodiment of the present invention is merely an illustrative illustration and does not constitute a structural limitation on the terminal device 200. In other embodiments of the present invention, the terminal device 200 may also adopt a different interface connection method from the above embodiment, or a combination of multiple interface connection methods.
[0135] The charging management module 240 is configured to receive charging input from a charger. The charger can be either a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 240 can receive charging input from the wired charger via the USB interface 230. In some wireless charging embodiments, the charging management module 240 can receive wireless charging input via the wireless charging coil of the terminal device 200. While charging the battery 242, the charging management module 240 can also provide power to the terminal device 200 via the power management module 241.
[0136] The power management module 241 is used to connect the battery 242, the charging management module 240, and the processor 210. The power management module 241 receives input from the battery 242 and / or the charging management module 240 and provides power to the processor 210, the internal memory 221, the external memory, the display 282, and the wireless communication module 250. The power management module 241 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 241 can also be provided in the processor 210. In other embodiments, the power management module 241 and the charging management module 240 can also be provided in the same device.
[0137] The wireless communication function of the terminal device 200 can be implemented through an antenna, a wireless communication module 250, a modem processor, and a baseband processor.
[0138] Antennas are used to transmit and receive electromagnetic wave signals. Each antenna in terminal device 200 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, one of the multiple antennas can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antenna can be used in conjunction with a tuning switch.
[0139] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through the audio module 260 (not limited to the speaker 260A, the speaker interface 260B, etc.) or displays an image or video through the display screen 282. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 210 and be provided in the same device as the wireless communication module 250 or other functional modules.
[0140] The wireless communication module 250 can provide wireless communication solutions including Bluetooth (BT), wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared technology (IR), etc. applied on the terminal device 200. The wireless communication module 250 can be one or more devices integrating at least one communication processing module. The wireless communication module 250 receives electromagnetic waves via an antenna, frequency modulates and filters the electromagnetic wave signal, and sends the processed signal to the processor 210. The wireless communication module 250 can also receive the signal to be sent from the processor 210, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna.
[0141] Terminal device 200 implements display functionality through a GPU, display screen 282, and an application processor. The GPU is a microprocessor for image processing that connects display screen 282 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 210 may include one or more GPUs that execute program instructions to generate or modify display information.
[0142] The display screen 282 is used to display images, videos, etc. For example, after the terminal device 200 receives a Bluetooth broadcast from the Bluetooth device 100, the display screen 282 displays the pairing information of the Bluetooth device 100 and prompts the user whether to establish a Bluetooth connection with the Bluetooth device 100. If the terminal device 200 receives an operation from the user to instruct to establish a Bluetooth connection with the Bluetooth device 100, the display screen 282 displays an interface for establishing a Bluetooth connection with the Bluetooth device 100 in response to the operation.
[0143] The display screen 282 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the terminal device 200 may include one or more display screens 282, for example, two, four, or N display screens 282, where N is a positive integer greater than 4.
[0144] The external memory interface 220 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the terminal device 200. The external memory card communicates with the processor 210 via the external memory interface 220 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.
[0145] The internal memory 221 can be used to store computer executable program codes, which include instructions. The processor 210 executes various functional applications and data processing of the terminal device 200 by running the instructions stored in the internal memory 221. The internal memory 221 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area can store data created during the use of the terminal device 200 (such as audio data, a phone book, etc.), etc. In addition, the internal memory 221 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0146] The terminal device 200 can implement audio functions through the audio module 260, the speaker 260A, the speaker interface 260B, and the application processor.
[0147] The audio module 260 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 260 can also be used to encode and decode audio signals. In some embodiments, the audio module 260 can be provided in the processor 210, or some functional modules of the audio module 260 can be provided in the processor 210.
[0148] Speaker 260A, also known as a "horn," is used to convert audio electrical signals into sound signals. The terminal device 200 can listen to music or audio through speaker 260A. For example, when the terminal device 200 establishes a Bluetooth connection with the Bluetooth device 100, speaker 260A can play voice prompts.
[0149] The buttons 280 include a power button, a volume button, etc. The buttons 280 may be mechanical buttons or touch buttons. The terminal device 200 may receive key inputs and generate key signal inputs related to user settings and function control of the terminal device 200.
[0150] The indicator 281 may be an indicator light, which may be used to indicate the charging status, power changes, messages, connection status with the Bluetooth device 100, notifications, and the like.
[0151] In the above embodiments, all or part of the embodiments can be implemented by software, hardware, firmware, or any combination thereof. When implemented using software, all or part of the embodiments can be implemented in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instructions are loaded and executed on a computer, the process or function of the embodiment of the present application is performed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, or other programmable device. The computer program or instruction can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instruction can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; it can also be an optical medium, such as a digital video disc (DVD); it can also be a semiconductor medium, such as a solid-state drive (SSD).
[0152] In the various embodiments of the present application, unless otherwise specified or there is a logical conflict, the terms and / or descriptions between different embodiments are consistent and can be referenced by each other. The technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationships.
[0153] In this application, "and / or" describes the relationship between associated objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, and B exists alone. A and B can be singular or plural. In the text description of this application, the character " / " generally indicates that the associated objects are in an "or" relationship.
[0154] It will be appreciated that the various numerals involved in the embodiments of the present application are merely for the purpose of describing the distinctions made, and are not intended to limit the scope of the embodiments of the present application. The size of the sequence numbers of the above-mentioned processes does not mean the order of execution, and the order of execution of each process should be determined by its function and inherent logic. The terms "first", "second", etc. are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. In addition, the terms "comprise" and "have" and any of their variations are intended to cover non-exclusive inclusions, for example, comprising a series of steps or units. Methods, systems, products or devices are not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or that are inherent to these processes, methods, products or devices.
[0155] Obviously, those skilled in the art may make various modifications and variations to this application without departing from the scope of protection of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.
Claims
1. A network access method, characterized in that: The method comprises: When detecting that a first terminal device is connected to an access point AP, the AP identifies characteristic information of the first terminal device, where the characteristic information is a behavioral characteristic of the first terminal device when using a network; The AP determines, based on the feature information of the first terminal device and a first correspondence, a device category to which the first terminal device belongs, where the first correspondence includes a correspondence between preset feature information and preset device categories; The AP controls the access permission of the first terminal device to a target network based on a preset access policy according to the device category to which the first terminal device belongs, and the target network includes a local area network and / or the Internet; The preset device categories include fully trusted device categories, partially trusted device categories, and untrusted device categories; The AP controls the permission of the first terminal device to access a target network based on a preset access policy according to the device category to which the first terminal device belongs, including: If the first terminal device belongs to the category of fully trusted devices, the AP allows the first terminal device to access the target network; or If the first terminal device belongs to the partially trusted device category, the AP allows the first terminal device to access the Internet and devices with public attributes in the local area network, and prohibits the first terminal device from accessing devices with private attributes in the local area network; or If the first terminal device belongs to an untrusted device category, the AP denies the first terminal device access to the target network; When the first terminal device belongs to a partially trusted device category, the method further includes: The AP detects that the first terminal device accesses a device with privacy attributes in the local area network; The AP sends a second request message to a second terminal device, where the second request message is used to request authorization for the first terminal device to access a device with privacy attributes in the local area network; the second terminal device is a device having permission to manage access to a target network through the AP; The AP controls the access rights of the first terminal device to the local area network based on the second response message fed back by the second terminal device; the second response message includes information indicating that the first terminal device is authorized to access devices with privacy attributes in the local area network, or information indicating that the first terminal device is authorized to access a single device with privacy attributes in the local area network, or information indicating that the first terminal device is denied access to devices with privacy attributes in the local area network.
2. The method according to claim 1, wherein The preset device categories include trusted device categories and untrusted device categories; The AP controls the permission of the first terminal device to access a target network based on a preset access policy according to the device category to which the first terminal device belongs, including: If the first terminal device belongs to a trusted device category, the AP allows the first terminal device to access the target network; or If the first terminal device belongs to the category of untrusted devices, the AP sends a first request message to the second terminal device, and controls the permission of the first terminal device to access the target network based on the first response message fed back by the second terminal device to the first request message; wherein, the first request message is used to request authorization for the first terminal device to access the target network, and the second terminal device is a device with management permission to access the target network through the AP.
3. The method according to claim 2, wherein The first response message includes information indicating that the first terminal device is authorized to access the target network, or information indicating that the first terminal device is denied access to the target network; The controlling, according to the first response message fed back by the second terminal device in response to the first request message, permission for the first terminal device to access the target network includes: The first response message includes information indicating that the first terminal device is authorized to access the target network, then the AP allows the first terminal device to access the target network; or, The first response message includes information indicating that the first terminal device is denied access to the target network, and the AP denies the first terminal device access to the target network.
4. The method according to claim 1, wherein The AP performing access control of the local area network for the first terminal device according to the second response message fed back by the second terminal device, including: The second response message includes information indicating that the first terminal device is authorized to access the device with privacy attributes in the local area network, and the AP allows the first terminal device to access the device with privacy attributes in the local area network; or The second response message includes information indicating that the first terminal device is denied access to the device with privacy attributes in the local area network, and the AP denies the first terminal device access to the device with privacy attributes in the local area network.
5. A network access device, characterized in that: Includes processor, memory and transceiver; The memory stores program instructions; The transceiver is used to send and receive data or messages; The processor is coupled to the memory and the transceiver, and is configured to execute the program instructions stored in the memory so as to cause the device to perform: When detecting that a first terminal device is connected to an access point AP, identifying characteristic information of the first terminal device, the characteristic information being a behavioral characteristic of the first terminal device when using a network; determining, based on the feature information of the first terminal device and a first correspondence, a device category to which the first terminal device belongs, wherein the first correspondence includes a correspondence between preset feature information and preset device categories; Controlling, based on a preset access policy and according to the device category to which the first terminal device belongs, the authority of the first terminal device to access a target network, the target network including a local area network and / or the Internet; The preset device categories include fully trusted device categories, partially trusted device categories, and untrusted device categories; The processor is specifically configured to execute the program instructions stored in the memory, so that the device performs: If the first terminal device belongs to the category of fully trusted devices, the first terminal device is allowed to access the target network; or If the first terminal device belongs to the partially trusted device category, the first terminal device is allowed to access the Internet and devices with public attributes in the local area network, and is prohibited from accessing devices with private attributes in the local area network; or, If the first terminal device belongs to an untrusted device category, denying the first terminal device access to the target network; When the first terminal device belongs to the partially trusted device category, the processor is further configured to execute the program instructions stored in the memory so as to cause the apparatus to perform: detecting that the first terminal device accesses a device with privacy attributes in the local area network; Sending a second request message to a second terminal device, where the second request message is used to request authorization for the first terminal device to access devices with privacy attributes in the local area network; the second terminal device is a device having permission to manage access to the target network through the AP; According to the second response message fed back by the second terminal device, access permission of the first terminal device to the local area network is controlled; the second response message includes information indicating that the first terminal device is authorized to access devices with privacy attributes in the local area network, or information indicating that the first terminal device is authorized to access a single device with privacy attributes in the local area network, or information indicating that the first terminal device is denied access to devices with privacy attributes in the local area network.
6. The device according to claim 5, characterized in that The preset device categories include trusted device categories and untrusted device categories; The processor is specifically configured to execute the program instructions stored in the memory, so that the device performs: If the first terminal device belongs to the trusted device category, the first terminal device is allowed to access the target network; or If the first terminal device belongs to the category of untrusted devices, a first request message is sent to the second terminal device, and the permission of the first terminal device to access the target network is controlled based on the first response message fed back by the second terminal device to the first request message; wherein, the first request message is used to request authorization for the first terminal device to access the target network, and the second terminal device is a device with management permission to access the target network through the AP.
7. The device according to claim 6, characterized in that The first response message includes information indicating that the first terminal device is authorized to access the target network, or information indicating that the first terminal device is denied access to the target network; The processor is specifically configured to execute the program instructions stored in the memory, so that the device performs: The first response message includes information indicating that the first terminal device is authorized to access the target network, then the first terminal device is allowed to access the target network; or The first response message includes information indicating that the first terminal device is denied access to the target network, and the first terminal device is denied access to the target network.
8. The device according to claim 5, wherein The processor is specifically configured to execute the program instructions stored in the memory, so that the device performs: The second response message includes information indicating that the first terminal device is authorized to access the device with privacy attributes in the local area network, then the first terminal device is allowed to access the device with privacy attributes in the local area network; or The second response message includes information indicating that the first terminal device is denied access to the device with privacy attributes in the local area network, and the first terminal device is denied access to the device with privacy attributes in the local area network.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program or instruction. When the computer program or instruction is executed by an access point AP, the method according to any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Terminal type identification method and device
CN104683124A
System and method for wireless network management
US20170134171A1