Method and apparatus for wps procedure

By reducing the transmission power of management frames and performing ranging in the WPS program, a security vulnerability in the WPS program is resolved, ensuring that connections can only be made to devices that are close to them, thus improving the security of the wireless network.

CN115714977BActive Publication Date: 2026-05-19MEDIATEK SINGAPORE PTE LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
MEDIATEK SINGAPORE PTE LTD
Filing Date
2022-08-05
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

The existing Wi-Fi Protected Settings (WPS) program contains a security vulnerability that allows attackers to obtain network credentials by listening to beacon frames and probe request frames, resulting in insufficient security for wireless networks.

Method used

During the WPS procedure, the Tx power of the transmitted WPS management frames is changed, and credentials are configured when the ranging results meet the threshold. This includes reducing the transmission power of beacon frames, authentication frames, and association frames, as well as performing passive or active ranging to determine the proximity of the device.

Benefits of technology

It improves the security of the WPS program, reduces the possibility of attackers accessing the wireless network, ensures that a successful connection can only be made when the attacker is close to the device, and enhances the network's protection capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115714977B_ABST
    Figure CN115714977B_ABST
Patent Text Reader

Abstract

The present disclosure presents solutions related to improving the security of a Wi-Fi Protected Setup (WPS) procedure. An access point (AP) determines that a WPS procedure is activated. In response, the AP changes a transmit (Tx) power at which one or more WPS management frames are transmitted during the WPS procedure. Further, the AP configures one or more credentials to a station (STA) in response to receiving one or more management frames from the STA.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application generally relates to Wi-Fi communication, and more specifically, to improvements in the security of Wi-Fi Protected Setup (WPS) procedures (which may also be described interchangeably as "processes"). Background Technology

[0002] Unless otherwise stated herein, the methods described in this section are not prior art to the listed claims and cannot be recognized as prior art by being included in this section.

[0003] Generally, WPS (Wi-Fi Protected Access) refers to a network security standard for creating secure wireless home networks. In other words, WPS is a wireless router feature designed to simplify the process of creating a secure wireless network. Users don't need to manually configure security settings; they can create a secure wireless network simply by pressing the WPS button. Therefore, it's a common feature offered on many routers. When the WPS button is pressed, the router scans for nearby wireless devices. Next, the user can open the settings on the corresponding wireless device to select the wireless network. The device will then automatically connect to the wireless network. Using WPS, users don't need to enter a password when connecting to the wireless network, thus simplifying the process of creating a secure wireless network. It's important to note that WPS only supports Wi-Fi Protected Access (WPA) Personal protocol or WPA Personal encryption protocol. That is, users cannot use this feature with Wired Equivalent Privacy (WEP) encryption protocol.

[0004] However, existing WPS processes or programs contain vulnerabilities. For example, in cases where the WPS button on an access point (AP) or registrar is pressed to activate or otherwise launch the WPS program, an attacker might be able to eavesdrop on beacon frames from the AP. Once a beacon(s) containing a WPS information element (IE) is detected, the attacker can perform a WPS exchange immediately after the AP indicates that it has enabled the WPS registrar for push button configuration (PBC). PBC allows users to connect wireless devices to a wireless network by pressing the WPS settings menu on the device's control panel and the WPS (PBC) button on the WPS-enabled AP (or wireless router). As long as the attacker completes the WPS process before the legitimate enrollee has the opportunity to press their WPS button and send a probe request frame on the AP's operational channel, the attacker succeeds and can thus obtain the network credentials that allow the attacker to connect to the network (and, in the case of WPA2-Personall, also allow the attacker to decrypt all past traffic on the network).

[0005] Furthermore, in cases where the user presses the WPS button first, the attacker will need to bypass PBC session overlap detection. Specifically, the attacker will monitor beacon frames from the AP and probe request frames on the AP's operational channel. Once the attacker detects a probe request frame indicating readiness for PBC, the attacker can clone the medium access control (MAC) address and universally unique identifier (UUID) from the frame corresponding to the AP performing the WPS procedure (the AP's WPS button being pressed).

[0006] Therefore, a solution is needed to improve the security of WPS applications. Summary of the Invention

[0007] The following overview is illustrative only and is not intended to be limiting in any way. That is, it is provided to introduce the concepts, highlights, benefits, and advantages of the novel and non-obvious techniques described herein. The chosen implementation methods are further described in the detailed description below. Therefore, the following overview is not intended to identify the essential characteristics of the claimed subject matter, nor is it intended to determine the scope of the claimed subject matter.

[0008] One of the objectives of this invention is to provide a solution, concept, design, technology, method, and apparatus related to improving the security of the WPS program.

[0009] In a first aspect, the present invention provides a method for a WPS program, the method comprising: determining that a Wi-Fi Protected Settings WPS program is activated; changing the transmission Tx power of transmitting one or more WPS management frames during the WPS program; and configuring one or more credentials to the first communication entity in response to receiving one or more management frames from a first communication entity.

[0010] In some embodiments, changing the Tx power for transmitting the one or more WPS management frames during the WPS procedure includes: transmitting one or more regular beacon frames at a first power level; and transmitting one or more beacon frames with WPS information elements at a second power level lower than the first power level.

[0011] In some embodiments, changing the Tx power for transmitting the one or more WPS management frames during the WPS program further includes: transmitting one or more authentication frames and one or more associated frames at the second power level or a third power level lower than the first power level.

[0012] In some embodiments, changing the Tx power for transmitting the one or more WPS management frames during the WPS program includes: receiving one or more probe request frames at a first reduced power level; and, in response to receiving the one or more probe request frames, sending one or more probe response frames at a second reduced power level, wherein each of the first reduced power level and the second reduced power level is lower than the normal power level used when the WPS program is not activated.

[0013] In some embodiments, changing the Tx power for transmitting the one or more WPS management frames during the WPS program further includes: sending one or more authentication frames and one or more associated frames at the second reduced power level or the third reduced power level, wherein the third reduced power level is lower than the normal power level.

[0014] In a second aspect, the present invention provides a method for a WPS program, the method comprising: performing ranging before or during setting up a WPS program with Wi-Fi protection; determining a distance between a first communication entity and a second communication entity based on the result of the ranging; and configuring one or more credentials to the first communication entity in response to the determined distance being less than a threshold.

[0015] In some embodiments, the ranging operation includes performing passive ranging.

[0016] In some embodiments, the passive ranging includes performing Received Signal Strength Indication (RSSI) monitoring.

[0017] In some embodiments, the ranging operation includes performing active ranging.

[0018] In some embodiments, the execution of active ranging includes performing FTM-based ranging by exchanging fine time measurement (FTM) frames before or after association in a manner that measures distance.

[0019] In some embodiments, performing FTM-based ranging includes exchanging FTM frames between the first communication entity and the second communication entity before or after association to measure the distance.

[0020] In some embodiments, performing the ranging includes alternating between passive ranging and active ranging in response to relative movement between the first communication entity and the second communication entity.

[0021] Thirdly, the present invention provides an apparatus for a WPS program, comprising: a transceiver configured to perform wireless communication; and a processor coupled to the transceiver and configured to: perform one or both of a first defense process and a second defense process during the Wi-Fi protection setting of the WPS program to improve the security of the WPS program; wherein the first defense process involves reducing transmission Tx power and the second defense process involves ranging.

[0022] In some embodiments, when performing the first defense process, the processor is configured to perform the following operations: determine that the WPS program is activated; and change the Tx power of transmitting one or more WPS management frames during the WPS program.

[0023] In some embodiments, during the process of changing the Tx power of transmitting one or more WPS management frames during the WPS program, the processor is configured to perform the following operations: transmit one or more regular beacon frames via the transceiver at a first power level; transmit one or more beacon frames with WPS information elements via the transceiver at a second power level lower than the first power level; and transmit one or more authentication frames and one or more associated frames via the transceiver at the second power level or a third power level lower than the first power level.

[0024] In some embodiments, during the process of changing the Tx power of transmitting one or more WPS management frames during the WPS program, the processor is configured to perform the following operations: receive one or more probe request frames at a first reduced power level via the transceiver; in response to receiving the one or more probe request frames, transmit one or more probe response frames via the transceiver at a second reduced power level; and transmit one or more authentication frames and one or more association frames at the second reduced power level or a third reduced power level, wherein each of the first reduced power level, the second reduced power level, and the third reduced power level is lower than the normal power level used when the WPS program is not activated.

[0025] In some embodiments, when performing the second defense process, the processor is configured to perform the following operations: perform ranging before or during the WPS program; determine the distance between the first communication entity and the second communication entity based on the result of the ranging; and, in response to the determined distance being less than a threshold, assign one or more credentials to the first communication entity.

[0026] In some embodiments, when performing the ranging, the processor is configured to perform passive ranging by performing Received Signal Strength Indication (RSSI) monitoring.

[0027] In some embodiments, when performing the ranging, the processor is configured to perform active ranging, the execution of which includes performing FTM-based ranging by exchanging fine time measurement FTM frames before or after association to measure the distance.

[0028] In some embodiments, when performing the ranging, the processor is configured to alternate between passive ranging and active ranging in response to relative movement between the first communication entity and the second communication entity.

[0029] It is worth noting that while the description provided herein is set in the context of certain radio access technologies, networks, and network topologies (e.g., Wi-Fi), the proposed concepts, schemes, and any variations / derivatives thereof can be implemented, used for, or implemented by other types of radio access technologies, networks, and network topologies, such as, but not limited to, Bluetooth, ZigBee, infrared, 5G / New Radio (NR), Long-Term Evolution (LTE), LTE-Advanced, LTE-Advanced Pro, Internet of Things (IoT), Industrial IoT (IIoT), and Narrowband IoT (NB-IoT). Therefore, the scope of the invention is not limited to the examples described herein.

[0030] These and other objects of the invention will be readily understood by those skilled in the art upon reading the following detailed description of the preferred embodiments illustrated in the accompanying drawings. A detailed description will be given in the following embodiments with reference to the accompanying drawings. Attached Figure Description

[0031] The invention will be more fully understood by reading the following detailed description and embodiments, which are given with reference to the accompanying drawings. The drawings are included to provide a further understanding of the invention and are incorporated in and constitute a part of this invention. The drawings illustrate embodiments of the invention and, together with the specific embodiments, serve to explain the principles of the invention. It will be understood that, for the sake of clarity in illustrating the concept of the invention, the drawings are not necessarily drawn to scale, as some components may be shown out of proportion to their actual dimensions in practice.

[0032] Figure 1 This is a schematic diagram of an example network environment in which various proposed schemes can be implemented according to embodiments of the present invention.

[0033] Figure 2 This is a block diagram of an example communication system according to an embodiment of the present invention.

[0034] Figure 3 This is a flowchart illustrating an example process according to an embodiment of the present invention.

[0035] Figure 4 This is a flowchart illustrating an example process according to an embodiment of the present invention.

[0036] In the following detailed description, numerous specific details are set forth for illustrative purposes so that those skilled in the art can more thoroughly understand the embodiments of the invention. However, it will be apparent that one or more embodiments may be practiced without these specific details, and different embodiments may be combined as needed, and should not be limited to the embodiments illustrated in the accompanying drawings. Detailed Implementation

[0037] The following description illustrates preferred embodiments of the present invention and is intended only to exemplify the technical features of the invention, not to limit the scope of the invention. Throughout this specification and claims, certain terms are used to refer to specific elements. Those skilled in the art should understand that manufacturers may use different names for the same element. Therefore, this specification and claims do not distinguish elements by differences in name, but rather by differences in function. The terms "element," "system," and "device" used in this invention can refer to computer-related entities, where the computer can be hardware, software, or a combination of hardware and software. The terms "comprising" and "including" as used in the following description and claims are open-ended terms and should be interpreted as "comprising, but not limited to...". Furthermore, the term "coupled" refers to an indirect or direct electrical connection. Therefore, if a device is described as coupled to another device, it means that the device can be directly electrically connected to the other device, or indirectly electrically connected to the other device through other devices or connection means.

[0038] The terms "basically" or "roughly" as used in this document mean that, within an acceptable range, a person skilled in the art can solve the technical problem to be solved and basically achieve the desired technical effect. For example, "roughly equal to" means a method that a person skilled in the art can accept with a certain margin of error from "exactly equal to" without affecting the correctness of the result.

[0039] Overview

[0040] Embodiments of the present invention relate to various techniques, methods, schemes, and / or solutions related to improving the security of WPS procedures (or alternatively, "processes"). According to the present invention, multiple possible solutions can be implemented individually or in combination. That is, although these possible solutions may be described separately below, two or more of these possible solutions may be implemented in one combination or another.

[0041] As mentioned above, while WPS is convenient and easy to use, it is often plagued by security vulnerabilities. The biggest problem is that the existing WPS program exposes all connected wireless devices. If a hacker gains access to a wireless device connected to the network, the hacker can have unrestricted access to all wireless devices on that network.

[0042] refer to Figure 1 Network environment 100 involves communication entities 110 (interchangeably referred to as "first communication entity") and 120 (interchangeably referred to as "second communication entity") conducting wireless communication (e.g., in a WLAN (wireless local area network) according to one or more IEEE (Institute of Electrical and Electronics Engineers) 802.11 standards). For example, communication entity 110 may be a first station (STA), and communication entity 120 may be a second STA, wherein each of the first STA and the second STA acts as an access point (AP) STA or a non-AP STA. Under various embodiments proposed according to the invention, communication entities 110 and 120 are configured to improve the security of the WPS program (enhance the security of the WPS program). More specifically, communication entities 110 and 120 may be configured to implement one or more defense mechanisms (also interchangeably described as defense processes or defense procedures) to reduce or otherwise minimize the possibility of an attacker exploiting WPS, as described below.

[0043] Under a first proposal according to the invention, the first defense mechanism may include: reducing the transmission (Tx, also described as "emitting" or "sending") power of the WPS management frame (reducing the transmission power of the WPS management frame). In a first method according to the first proposal, the Tx power of the device is varied once the WPS button is pressed (e.g., by a user to activate the WPS program or otherwise initiate the WPS program). For example, the user places the device to be onboarded (or to be connected) next to the AP as instructed in the user manual and then powers on the device. Alternatively or additionally, the user may first press the WPS button on the AP and then press the WPS button on the device to be onboarded, thereby causing the AP to begin transmitting beacon frames with WPS IE. Under the proposed solution, certain modifications can be made to existing implementations. For example, in addition to transmitting regular beacon frames, the AP may also transmit or send beacon frames with WPS IE. Beacon frames with WPS IE are transmitted at a much lower Tx power level to ensure that only devices(s) very close to the AP can hear these beacons. For example, one or more regular beacon frames are transmitted at a first power level, and one or more beacon frames with WPS IE are transmitted at a second power level lower than the first power level. Understandably, a regular beacon frame refers to a beacon frame without WPS IE, for example, it could be a beacon frame transmitted when the AP is in its default operating mode. During the Monitor Time (e.g., 2 minutes after the WPS button is pressed), authentication frames (also interchangeably described as "authentication frames") and association frames transmitted by the AP are also transmitted at a lower Tx power. For example, one or more authentication frames and one or more association frames are transmitted at a second power level or a third power level lower than the first power level. In embodiments of the invention, the second and third power levels may be the same or different, and the invention is not limited thereto.

[0044] According to the proposed embodiment of the invention, when a user first presses the WPS button on the device to be logged in (although otherwise indicated in the user manual), the device to be logged in can begin sending probe request frames with WPS readiness. For example, one or more probe request frames are sent at a reduced power level, which is lower than the normal power level used when the WPS program is not activated. In some examples, this normal power level may be equal to a first power level. To avoid being spied on by an attacker, the device to be logged in also sends its probe request frames at a reduced Tx power. After the AP's WPS button is pressed, the AP responds with a probe response frame with reduced Tx power (that is, the AP receives one or more probe request frames at a reduced power level and responds by sending a probe response frame with reduced Tx power). Furthermore, during the monitoring period (e.g., 2 minutes after the WPS button is pressed), the AP sends authentication and association frames at a lower Tx power.

[0045] In the first method under the first proposed scheme, by sending management frames at reduced Tx power, the AP can ensure that only very close devices can receive those management frames and continue the WPS procedure. Examples of management frame types may include, for example, but not limited to, one or more Association Request frames, one or more Reassociation Request frames, one or more Probe Request frames, one or more Timing Advertisement frames, one or more Beacon frames, Disassociation frames, one or more De-authentication frames, one or more Authentication frames, one or more Action frames, one or more Association Response frames, one or more Reassociation Response frames, and one or more Probe Response frames.

[0046] Under a second proposal according to the invention, the second defense mechanism may include ranging. According to this proposal, the AP may perform ranging with the device before or during the WPS process (but before configuring its credentials to the device to be logged in). For example, ranging may be passive, and the AP may only configure credentials for the device to be logged in if the result of the ranging operation indicates that the given device to be logged in is very close to the AP. An example of passive ranging may be Received Signal Strength Indicator (RSSI) monitoring (i.e., monitoring RSSI). For example, the AP may be configured with a policy to provide a password (or credentials) to the device to be logged in only when the result of RSSI monitoring indicates that the distance between the device and the AP is less than a threshold (e.g., the threshold may be 5 meters, which is not limited by the invention, and the actual value may be determined according to design requirements).

[0047] Optionally, when the device to be logged in supports Wi-Fi positioning (e.g., ranging based on Fine Time Measurement (FTM)), active ranging can be used. For example, FTM frames can be exchanged before or after association to measure the distance between the AP and each device to be logged in. Similarly, the AP will only proceed with configuring credentials for the device to be logged in if the FTM frame exchange concludes that the given device to be logged in is very close to the AP. For example, the AP can be configured with a policy to provide a password (or credentials) to the device to be logged in only when the result of active ranging (e.g., FTM-based ranging) indicates that the distance between the device and the AP is less than a threshold (e.g., the threshold can be set to 1 meter, 5 meters, or 10 meters, etc., the specific value of which is not limited in this invention).

[0048] Optionally, the AP can perform active or passive ranging based on one or more variable measurement results indicating that the enrollee is in motion, for example, manually shaking the enrollee to be configured until it is configured. For example, the device to be logged in is moving rather than stationary. Therefore, the AP can alternate between passive and active ranging in implementing the second defense mechanism proposed according to the present invention. For example, ranging can be performed alternately between passive and active ranging in response to relative movement between the AP and the device.

[0049] Illustrative Implementation

[0050] Figure 2 An example system 200 with example apparatus 210 and example apparatus 220 according to an embodiment of the present invention is shown. Each of apparatus 210 and apparatus 220 can perform various functions to implement the schemes, techniques, processes and methods described herein related to improving the security of WPS programs, including the various proposed designs, concepts, schemes, systems and methods described above and the processes described below.

[0051] Each of devices 210 and 220 can be part of an electronic device, which can be user equipment (UE), such as a portable or mobile device, a wearable device, a wireless communication device, or a computing device. For example, each of devices 210 and 220 can be implemented in a smartphone, smartwatch, personal digital assistant, digital camera, or computing device such as a tablet, laptop, or notebook computer. Each of devices 210 and 220 can also be part of a machine-type device (which can be a STA, e.g., an AP STA or a non-AP STA). Each of devices 210 and 220 can be implemented in a smart thermostat, smart refrigerator, smart door lock, wireless speaker, or home control center. Optionally, each of devices 210 and 220 may be implemented in the form of one or more integrated circuit (IC) chips, such as, but not limited to, one or more single-core processors, one or more multi-core processors, one or more reduced-instruction-set computing (RISC) processors, or one or more complex-instruction-set computing (CISC) processors. Each of devices 210 and 220 may respectively include Figure 2 At least some of the components shown, such as processor 212 and processor 222. Each of devices 210 and 220 may also include one or more other components unrelated to the proposed solution of the present invention (e.g., internal power supply, display device, and / or user interface device), therefore, for simplicity, such components of devices 210 and 220 are not listed. Figure 2 It is shown in the image and not described below.

[0052] On one hand, each of processors 212 and 222 may be implemented as one or more single-core processors, one or more multi-core processors, one or more RISC processors, or one or more CISC processors. That is, even though the singular term "processor" is used herein to refer to processors 212 and 222, each of processors 212 and 222 may include multiple processors in some embodiments and a single processor in other embodiments. On the other hand, each of processors 212 and 222 may be implemented as hardware (and optionally, firmware) having electronic components, including, for example, but not limited to, one or more transistors, one or more diodes, one or more capacitors, one or more resistors, one or more inductors, one or more memristors, and / or one or more varactors configured and arranged according to the invention to perform a particular purpose. In other words, in at least some embodiments, each of processors 212 and 222 is a dedicated machine specifically designed, arranged, and configured to perform specific tasks, including those related to improving the security of the WPS program according to various embodiments of the invention.

[0053] In some embodiments, device 210 may further include a transceiver 216 coupled to processor 212. Transceiver 216 is capable of wirelessly transmitting and receiving data. In some embodiments, device 210 may further include a memory 214 coupled to and accessible by processor 212 and storing data therein. In some embodiments, device 220 may further include a transceiver 226 coupled to processor 222, capable of wirelessly transmitting and receiving data. In some embodiments, device 220 may further include a memory 224 coupled to and accessible by processor 222 and storing data therein. Therefore, devices 210 and 220 communicate wirelessly with each other via transceiver 216 and transceiver 226, respectively. Each of memories 214 and 224 may include a random-access memory (RAM), such as dynamic RAM (DRAM), static RAM (SRAM), thyristor RAM (T-RAM), and / or zero-capacitor RAM (Z-RAM). Alternatively or additionally, each of memories 214 and 224 may include a type of read-only memory (ROM), such as mask ROM, programmable ROM (PROM), erasable programmable ROM (EPROM), and / or electrically erasable programmable ROM (EEPROM). Alternatively or additionally, each of memories 214 and 224 may include a type of non-volatile random-access memory (NVRAM), such as flash memory, solid-state memory, ferroelectric RAM (FeRAM), magnetoresistive RAM (MRAM), and / or phase-change memory.

[0054] Each of devices 210 and 220 may be a communication entity capable of communicating with each other using various proposed schemes according to the present invention. For example, in network environment 100, device 210 may be an example implementation of communication entity 110 (or a first communication entity), and device 220 may be an example implementation of communication entity 120 (or a second communication entity). To aid in better understanding, the following description of the operation, function, and capabilities of each of devices 210 and 220 is provided in the context of device 210 being implemented in or as a communication device or a device to be logged in, and device 220 being implemented in or as an AP or wireless router in a communication network (e.g., a Wi-Fi network). Under various schemes proposed according to the present invention, the processor 222 of device 220 may be configured to execute one or both of a first defense process (also interchangeably described as a "program") and a second defense process during the WPS program to enhance the security of the WPS program, wherein the first defense process involves Tx power reduction, and the second defense process involves ranging. It is also worth noting that although the example implementation described below is provided in the context of mobile communications, it can also be implemented in other types of networks.

[0055] In one aspect of some proposed solutions related to improvements in the security of the WPS program according to the invention, device 210 is implemented as a device to be logged in, while device 220 is implemented as an access point or a wireless router for a wireless network (e.g., a Wi-Fi network or other wireless local area network, WLAN). Processor 222 can determine that the WPS program is activated or otherwise started (e.g., due to a user pressing a WPS button on device 220). Furthermore, during the WPS program, processor 222 changes the Tx power while transmitting one or more WPS management frames to device 210 via transceiver 216. Additionally, processor 222 configures one or more credentials to device 210 in response to receiving one or more management frames from device 210.

[0056] In some implementations, processor 222 may perform certain operations when changing the Tx power for transmitting one or more WPS management frames during a WPS procedure. For example, processor 222 may transmit or broadcast one or more regular beacon frames at a first power level. Furthermore, processor 222 may transmit or broadcast one or more beacon frames with WPS IE at a second power level lower than the first power level. Additionally, processor 222 may transmit one or more authentication frames and one or more associated frames (e.g., to device 210) at a second power level lower than the first power level or a third power level lower than the first power level.

[0057] In some implementations, during the process of changing the Tx power of sending one or more WPS management frames during the WPS program, the processor 222 may perform other operations. For example, the processor 222 may receive from the device 210 one or more probe request frames at a first reduced power level (also described as a "fourth power level," where "reduced power level" in this invention refers to a power level lower than the normal power level used when the WPS program is not activated). Furthermore, the processor 222 may, in response to receiving the one or more probe request frames, send one or more probe response frames to the device 210 at a second reduced power level (also described as a "fifth power level"). In this case, each of the first and second reduced power levels is lower than the normal power level used when the WPS program is not activated. In other words, when the WPS program is not activated, the corresponding frames are transmitted using the normal power level, while when the WPS program is activated, these frames are transmitted using a reduced power level (below the normal power level), such as a first reduced power level or a second reduced power level. Furthermore, the processor 222 can send one or more authentication frames and one or more associated frames to the device 210 at a second reduced power level or a third reduced power level (also described as a "sixth power level"). In this case, the third reduced power level is also below the normal power level.

[0058] In another aspect of some proposed solutions related to improvements in the security of the WPS program according to the invention, device 210 is implemented as a device to be logged in, device 220 is implemented as an access point or a wireless router for a wireless network (e.g., a Wi-Fi network or WLAN), and processor 222 can perform ranging before or during the WPS program. Additionally, processor 222 can determine the distance between device 210 and device 220 based on the ranging results. Furthermore, processor 222 can configure one or more credentials to device 210 in response to the measured distance being determined to be less than a threshold (e.g., 1 meter, 5 meters, 10 meters, or another threshold).

[0059] In some embodiments, processor 222 may perform passive ranging during ranging (i.e., in the process of performing ranging). In some embodiments, processor 222 may perform RSSI monitoring during passive ranging.

[0060] In some embodiments, processor 222 may perform active ranging during ranging. In some embodiments, during active ranging, processor 222 may perform FTM-based ranging by exchanging FTM frames before or after association to measure distance. In some embodiments, during FTM-based ranging, processor 222 exchanges FTM frames with device 210 before or after association to measure distance.

[0061] In some implementations, when performing ranging, processor 222 may alternate between passive ranging and active ranging in response to relative movement / motion between device 210 and device 220.

[0062] Explanatory process

[0063] Figure 3 An example process (or alternatively described as a "method") 300 according to an embodiment of the present invention is illustrated. Process 300 may partially or completely represent an example implementation of the above-described scheme for enhancing the security of a WPS program according to embodiments of the present invention. Process 300 may represent aspects of the feature implementation of apparatus 210 and / or apparatus 220. Process 300 may include one or more operations, actions, or functions as shown in one or more of blocks (or alternatively referred to as "steps") 310, 320, and 330. Although shown as discrete blocks, the individual blocks of process 300 may be divided into additional blocks, combined into fewer blocks, or eliminated, depending on the desired implementation. Furthermore, the blocks of process 300 may be arranged in... Figure 3The process can be executed in the order shown, or in a different order. Process 300 can be implemented by devices 210 and 220. For illustrative purposes only and without limitation, process 300 is described below in the context that device 210 is implemented as a device to be logged in and device 220 is implemented as an access point or wireless router in a wireless network. Process 300 may begin at box 310.

[0064] At 310, process 300 may include: processor 222 of device 220 (as an AP or wireless router) determining that the WPS program is activated or otherwise started (e.g., because the WPS button on device 220 is pressed by a user). Process 300 may proceed from 310 to 320.

[0065] At 320, process 300 may include: processor 222 changing Tx power when transmitting one or more WPS management frames to device 210 (as a device to be logged in) via transceiver 216 during the WPS program. Process 300 may proceed from 320 to 330.

[0066] At 330, process 300 may include: processor 222 configuring one or more credentials to the first communication entity in response to receiving one or more management frames from the first communication entity (e.g., device 210).

[0067] In some implementations, when the Tx power for transmitting one or more WPS management frames is changed during a WPS procedure, process 300 may include: processor 222 performing certain operations. For example, process 300 may include: processor 222 transmitting or broadcasting one or more regular beacon frames at a first power level. Furthermore, process 300 may include: processor 222 transmitting or broadcasting one or more beacon frames with WPS IE at a second power level lower than the first power level. Additionally, process 300 may include: processor 222 transmitting one or more authentication frames and one or more associated frames (e.g., to device 210) at a second power level or a third power level lower than the first power level.

[0068] In some implementations, when the Tx power for sending one or more WPS management frames is changed during the WPS program, process 300 may include: processor 222 performing other operations. For example, process 300 may include: processor 222 receiving one or more probe request frames at a first reduced power level from device 210. Furthermore, process 300 may include: processor 222 sending one or more probe response frames to device 210 at a second reduced power level in response to receiving the one or more probe request frames. In this case, each of the first and second reduced power levels is lower than the normal power level used when the WPS program is not activated. Additionally, process 300 may include: processor 222 sending one or more authentication frames and one or more association frames to device 210 at a second or third reduced power level. In this case, the third reduced power level is also lower than the normal power level.

[0069] Figure 4 An example process 400 according to an embodiment of the present invention is illustrated. Process 400 may be an example implementation, either partially or completely, of the improved security of the WPS program according to the present invention described above. Process 400 may represent implementation aspects of the features of device 210 and / or device 220. Process 400 may include one or more operations, actions, or functions as shown in boxes (or steps) 410, 420, and 430. Although shown as discrete boxes, the individual boxes of process 400 may be divided into additional boxes, combined into fewer boxes, or eliminated, depending on the desired implementation. Furthermore, the boxes of process 400 may be arranged in... Figure 4 The process may be executed in the order shown, or in a different order. Process 400 may be implemented by devices 210 and 220. For illustrative purposes only and without limitation, process 400 is described below in the context of device 210 being implemented as a device to be logged in and device 220 being implemented as an access point or wireless router in a wireless network. Process 400 may begin at box 410.

[0070] At 410, process 400 may include: processor 222 of device 220 (as an AP or wireless router) performing ranging before or during the WPS program. Process 400 may proceed from 410 to 420.

[0071] At 420, process 400 may include: processor 222 determining the distance between device 210 (as the device to be logged in) and device 220 based on the ranging result. Process 400 may proceed from 420 to 430.

[0072] At 430, process 400 may include: in response to the determined distance being less than a threshold (e.g., 1 meter, 5 meters, 10 meters or another threshold), processor 222 configures one or more credentials to device 210.

[0073] In some embodiments, when performing ranging, process 400 may include: processor 222 performing passive ranging. In some embodiments, when performing passive ranging, process 400 may include: processor 222 performing RSSI monitoring.

[0074] In some embodiments, when performing ranging, process 400 may include: processor 222 performing active ranging. In some embodiments, when performing active ranging, process 400 may include: processor 222 performing FTM-based ranging by exchanging FTM frames before or after association to measure distance. In some embodiments, when performing FTM-based ranging, process 400 may include: processor 222 exchanging FTM frames with device 210 before or after association to measure distance.

[0075] In some implementations, when performing ranging, process 400 may include processor 222 alternating between passive ranging and active ranging in response to relative movement between device 210 and device 220.

[0076] Additional Notes

[0077] The topics described herein sometimes illustrate different components contained within or connected to other different components. It is important to understand that the architectures depicted are merely examples, and many other architectures can actually be implemented to achieve the same functionality. Conceptually, any arrangement of components that achieve the same functionality is effectively “associated” to achieve the desired function. Therefore, any two components combined here to achieve a particular function can be considered “associated” with each other to achieve the desired function, regardless of the architecture or intermediate components. Similarly, any two components so associated can also be considered “operably connected” or “operably coupled” to each other to achieve the desired function, and any two components that can be so associated can also be considered “operably coupled” to each other to achieve the desired function. Specific examples of operational coupling include, but are not limited to, physically pairable and / or physically interacting components and / or wirelessly interactive components and / or logically interacting and / or logically interactive components.

[0078] Furthermore, regarding the use of virtually any plural and / or singular terms in this document, those with ordinary knowledge in the field may convert from plural to singular and / or from singular to plural depending on the context and / or application. For clarity, various singular / plural substitutions may be explicitly described herein.

[0079] Furthermore, it will be understood by those skilled in the art that the terms generally used herein, particularly those used in the appended claims, such as the subject of the appended claims, are generally intended to be “open-ended” terms; for example, the term “comprising” should be interpreted as “including but not limited to,” the term “containing” should be interpreted as “including but not limited to,” the term “having” should be interpreted as “having at least,” and so on. Those skilled in the art will further understand that if a specific number of the introduced claim elements are intended, such intent will be explicitly stated in the claim, and the absence of such a statement will preclude the presence of such intent. For example, to aid understanding, the appended claim may contain the introductory phrases “at least one” and “one or more” to introduce claim elements. However, the use of such phrases should not be construed as implying that the claim element introduced by the indefinite article "a" or "one" limits any particular claim containing such an element to only one such element, even when the same claim contains the introductory phrase "one or more" or "at least one" and the indefinite article such as "a" or "one," for example, "a" or "one" should be interpreted as meaning "at least one" or "one or more," and this also applies to the use of definite articles used to introduce claim elements. Furthermore, even where a specific number of introduced claim elements is explicitly stated, those skilled in the art will recognize that such a statement should be interpreted as meaning at least the listed number; for example, the statement "two elements" without other modifiers means at least two elements or two or more elements. Furthermore, when using phrases like "at least one of A, B, and C," for their intended purpose, such a structure is generally understood by those skilled in the art to be conventional. For example, "the system has at least one of A, B, and C" includes, but is not limited to, the system having a single A, a single B, a single C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. Similarly, when using phrases like "at least one of A, B, or C," for their intended purpose, such a structure is generally understood by those skilled in the art to be conventional. For example, "the system has at least one of A, B, or C" includes, but is not limited to, the system having a single A, a single B, a single C, A and B together, A and C together, B and C together, and / or A, B, and C together, etc. Those skilled in the art to be conventional will further understand that any transitional words and / or phrases that actually indicate two or more options, whether in the specification, request, or drawings, should be understood to consider the possibility of including one of multiple terms, any one of multiple terms, or two terms. For example, the phrase “A or B” would be understood to include the possibility of “A” or “B” or “A and B”.

[0080] As can be seen from the above, it is understood that various embodiments of this application have been described herein for illustrative purposes, and various modifications can be made without departing from the scope and spirit of this application. Therefore, the various embodiments disclosed herein are not intended to be limiting, and the true scope and spirit are determined by the appended claims.

[0081] The use of ordinal terms such as “first,” “second,” and “third” in the claims to modify claim elements does not in itself indicate any priority, precedence, or order of one claim element relative to another claim element, or the chronological order of the execution of method actions. Rather, it is merely used as a marker to distinguish one claim element with the same name from another element with the same name.

[0082] While the invention has been described by way of example and according to preferred embodiments, it should be understood that the invention is not limited to the disclosed embodiments. Rather, it is intended to cover various variations and similar structures (as will be apparent to those skilled in the art), such as combinations or substitutions of different features in different embodiments. Therefore, the scope of the appended claims should be given the broadest interpretation to cover all such variations and similar structures.

Claims

1. A method for WPS applications, characterized in that, The method includes: Make sure the Wi-Fi protection settings WPS program is activated; During the period when the WPS program is activated, the transmission Tx power for transmitting one or more WPS management frames is changed; and, In response to receiving one or more management frames from a first communication entity, one or more credentials are configured for the first communication entity; Changing the Tx power for transmitting one or more WPS management frames during the period when the WPS program is activated includes: Transmit one or more conventional beacon frames at a first power level; and, One or more beacon frames with WPS information elements are transmitted at a second power level lower than the first power level.

2. The method as described in claim 1, characterized in that, Changing the Tx power for transmitting one or more WPS management frames during the period when the WPS program is activated also includes: One or more authentication frames and one or more associated frames are transmitted at the second power level or a third power level lower than the first power level.

3. A method for WPS programs, characterized in that, The method includes: Make sure the Wi-Fi protection settings WPS program is activated; During the period when the WPS program is activated, the transmission Tx power for transmitting one or more WPS management frames is changed; and, In response to receiving one or more management frames from a first communication entity, one or more credentials are configured for the first communication entity; Changing the Tx power for transmitting one or more WPS management frames during the period when the WPS program is activated includes: Receive one or more probe request frames at a first reduced power level; and, In response to receiving the one or more probe request frames, one or more probe response frames are transmitted at a second reduced power level. Each of the first reduced power level and the second reduced power level is lower than the normal power level used when the WPS program is not activated.

4. The method as described in claim 3, characterized in that, Changing the Tx power for transmitting one or more WPS management frames during the period when the WPS program is activated also includes: One or more authentication frames and one or more associated frames are transmitted at the second or third reduced power level. The third reduced power level is lower than the normal power level.

5. An apparatus for a WPS application, comprising: A transceiver, configured to perform wireless communication; as well as, The processor, coupled to the transceiver, is configured as follows: Make sure the Wi-Fi protection settings WPS program is activated; During the period when the WPS program is activated, the transmission Tx power of transmitting one or more WPS management frames is changed; as well as, In response to receiving one or more management frames from a first communication entity, one or more credentials are configured for the first communication entity; Changing the Tx power for transmitting one or more WPS management frames during the period when the WPS program is activated includes: Transmit one or more conventional beacon frames at a first power level; and, One or more beacon frames with WPS information elements are transmitted at a second power level lower than the first power level; Alternatively, changing the Tx power for transmitting one or more WPS management frames during the period when the WPS program is activated includes: Receive one or more probe request frames at a first reduced power level; and, In response to receiving the one or more probe request frames, one or more probe response frames are transmitted at a second reduced power level. Each of the first reduced power level and the second reduced power level is lower than the normal power level used when the WPS program is not activated.

6. The apparatus as claimed in claim 5, characterized in that, During the period when the WPS program is activated, while changing the Tx power of transmitting one or more WPS management frames, the processor is also configured to perform the following operations: One or more authentication frames and one or more associated frames are transmitted via the transceiver at the second power level or a third power level lower than the first power level.

7. The apparatus as claimed in claim 5, characterized in that, During the period when the WPS program is activated, while changing the Tx power of transmitting one or more WPS management frames, the processor is also configured to perform the following operations: One or more authentication frames and one or more associated frames are transmitted at the second or third reduced power level. Each of the first reduced power level, the second reduced power level, and the third reduced power level is lower than the normal power level used when the WPS program is not activated.

8. The apparatus as claimed in claim 5, characterized in that, The processor is also configured to perform the following operations: Distance measurement is performed before or during the activation of the WPS program; Based on the ranging result, the distance between the first communication entity and the second communication entity is determined; and, In response to the determined distance being less than a threshold, one or more credentials are configured for the first communication entity.

9. The apparatus as claimed in claim 8, characterized in that, When performing this ranging operation, the processor is configured to perform passive ranging by performing Received Signal Strength Indication (RSSI) monitoring.

10. The apparatus as claimed in claim 8, characterized in that, When performing this ranging, the processor is configured to perform active ranging, which includes performing FTM-based ranging by exchanging fine time measurement FTM frames before or after association to measure the distance.

11. The apparatus as claimed in claim 8, characterized in that, When performing the ranging, the processor is configured to alternate between passive ranging and active ranging in response to relative movement between the first communication entity and the second communication entity.