Hotspot control method, system, program product, device and storage medium

By enabling the protected management frame function and upgrading the encryption protocol when an attack is detected, the security vulnerability of the WPA2 protocol is solved, and the security of Wi-Fi network and the encryption protection of managed frames is improved.

CN119255231BActive Publication Date: 2025-08-29HONOR DEVICE CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202410494363.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-04-23
Publication Date
2025-08-29
Estimated Expiration
2044-04-23

AI Technical Summary

Technical Problem

The existing WPA2 protocol has security vulnerabilities, and attackers can easily implement unauthentication attacks, resulting in security issues on Wi-Fi networks.

Method used

When an attack is detected, the electronic device enables the protected management frame function (PMF) and notifies the terminal device to use the encrypted management frame through the broadcast beacon frame, or upgrades the Wi-Fi encryption protocol to WPA2/WPA3 and restarts the hotspot to improve network security.

Benefits of technology

On the premise of ensuring network compatibility, the security of Wi-Fi network is improved, the deauthentication attacks are prevented, and the encryption protection of management frames is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119255231B_ABST
    Figure CN119255231B_ABST
Patent Text Reader

Abstract

The embodiments of the present application provide a hotspot control method, system, program product, device and storage medium. In the embodiments of the present application, the method is applied to an electronic device, including: receiving a disassociation frame; when the electronic device receives the disassociation frame, the protected management frame function of the electronic device is not turned on, and a wireless connection is established between the Wi‑Fi hotspot and the terminal device; the disassociation frame is a management frame used to disconnect the wireless connection; after receiving the disassociation frame, determining whether the electronic device is under attack; when it is determined that the electronic device is under attack, turning on the protected management frame function and notifying the terminal device that the electronic device has turned on the protected management frame function; after the electronic device turns on the protected management frame function, the Wi‑Fi hotspot establishes a target wireless connection with the terminal device; the management frame transmitted on the target wireless connection is in an encrypted state. The technical solution provided by the embodiments of the present application can improve the security of the Wi‑Fi network while ensuring network compatibility.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of terminal technology, and in particular to a hotspot control method, system, program product, device and storage medium. Background Art

[0002] WPA (Wi-Fi Protected Access) is a Wi-Fi network security protocol. WPA2 is the second-generation Wi-Fi encryption protocol (or encryption mode), which can prevent hackers from invading wireless access points and terminal devices. It is a widely used security protection mechanism during network transmission.

[0003] Currently, most Wi-Fi devices support or use the WPA2 security protocol. However, WPA2 has multiple vulnerabilities. These vulnerabilities allow attackers to easily perform deauthentication attacks and other attacks, effectively limiting WPA2's security. Summary of the Invention

[0004] Various aspects of the present application provide a hotspot control method, system, program product, device, and storage medium for improving the security of Wi-Fi networks while ensuring network compatibility.

[0005] In a first aspect, a hotspot control method is provided, which is applied to an electronic device for providing a Wi-Fi hotspot. The method includes:

[0006] receiving a disassociation frame; when the electronic device receives the disassociation frame, the protected management frame function of the electronic device is not enabled, and a wireless connection is established between the Wi-Fi hotspot and the terminal device; the disassociation frame is a management frame used to disconnect the wireless connection;

[0007] After receiving the disassociation frame, determining whether the electronic device is under attack;

[0008] When it is determined that the electronic device is under attack, enabling a protected management frame function of the electronic device and notifying the terminal device that the protected management frame function of the electronic device has been enabled;

[0009] After the electronic device enables the protected management frame function, the Wi-Fi hotspot establishes a target wireless connection with the terminal device;

[0010] The management frame transmitted on the target wireless connection is in an encrypted state.

[0011] In the embodiments of the present application, when the electronic device is not subject to a management frame attack (e.g., a deauthentication attack), the protected management frame function of the electronic device is disabled. This improves compatibility and ensures that devices that are not compatible with the protected management frame function can also connect to the Wi-Fi hotspot provided by the electronic device. Only when the electronic device detects a management frame attack will the protected management frame function be enabled to improve the security of the Wi-Fi network. It can be seen that the technical solution provided by the embodiments of the present application can improve the security of the Wi-Fi network while ensuring network compatibility.

[0012] In an implementation manner provided by the first aspect, when determining that the electronic device is under attack, enabling a protected management frame function of the electronic device and notifying the terminal device that the protected management frame function of the electronic device has been enabled includes:

[0013] When it is determined that the electronic device is under attack, enabling a protected management frame function of the electronic device;

[0014] After the protected management frame function of the electronic device is enabled, the beacon frame is broadcasted;

[0015] The beacon frame carries field information of a first field; the field information of the first field is used to indicate that the electronic device has enabled a protected management frame function.

[0016] For example, the protected management frame PMF field of the electronic device can be directly set to 1, so that the protected management frame function can be dynamically enabled without restarting the hotspot.

[0017] In other words, when an electronic device identifies an attack, it activates the protected management frame feature and broadcasts a beacon frame to prompt the terminal device to use the protected management frame feature. This way, after the terminal device re-establishes a connection to the Wi-Fi hotspot provided by the electronic device, the security of the Wi-Fi network is improved by encrypting the management frames required for transmission.

[0018] In an implementation manner provided by the first aspect, when it is determined that the electronic device is under attack, enabling a protected management frame function includes:

[0019] When it is determined that the electronic device is under attack, the Wi-Fi encryption protocol currently used by the electronic device is set to the Wi-Fi encryption protocol WPA2 / WPA3 or the Wi-Fi encryption protocol WPA3 and the Wi-Fi hotspot is restarted to enable the protected management frame function of the electronic device.

[0020] In an embodiment of the present application, the protected management frame function can be enabled by setting the Wi-Fi encryption protocol currently used by the electronic device to WPA2 / WPA3 or WPA3 that supports the protected management frame function and restarting the Wi-Fi hotspot.

[0021] Optionally, when the Wi-Fi encryption protocol currently used by the electronic device is set to the Wi-Fi encryption protocol WPA3, the beacon frame also carries field information of the second field; the field information of the second field is used to indicate that the other end is required to use the protected management frame function.

[0022] In an implementation manner provided by the first aspect, after receiving the disassociation frame, determining whether the electronic device is under attack includes:

[0023] After receiving the disassociation frame, it is determined whether the electronic device is under attack based on whether the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold.

[0024] That is, attack behavior is identified based on the frequency of receiving disassociation frames.

[0025] In an implementation provided by the first aspect, the duration of the first preset time period is a set duration; and the starting time of the first preset time period is the time when the association release frame is received.

[0026] The set duration can be set according to actual needs, and the embodiment of the present application does not make any specific restrictions on this.

[0027] Exemplarily, the first preset time period includes the starting time.

[0028] In an embodiment provided by the first aspect, after receiving the disassociation frame, determining whether the electronic device is under attack based on whether a number of disassociation frames received by the electronic device within a preset time period is greater than or equal to a preset number threshold includes:

[0029] After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, it is determined that the electronic device is under attack.

[0030] That is, when the electronic device frequently receives disassociation frames, it is determined that the electronic device is under attack.

[0031] In an embodiment provided by the first aspect, after receiving the disassociation frame, determining whether the electronic device is under attack based on whether a number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold includes:

[0032] After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, and a difference between a received signal strength indicator of an association establishment frame and a received signal strength indicator of the disassociation frame is not within a first preset range, determining that the electronic device is under attack;

[0033] The association establishment frame is received by the electronic device before or after receiving the association release frame; the association establishment frame is a management frame used to establish a wireless connection between the terminal device and the Wi-Fi hotspot.

[0034] That is, when the electronic device frequently receives disassociation frames and the difference between the received signal strength indicators of the association establishment frames and the received signal strength indicators of the disassociation frames is large, it is determined that the electronic device is under attack.

[0035] In an embodiment provided by the first aspect, after receiving the disassociation frame, determining whether the electronic device is under attack based on whether a number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold includes:

[0036] After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, and the frame sequence number of a management frame received later among the multiple management frames received by the electronic device is less than or equal to the frame sequence number of a management frame received earlier, it is determined that the electronic device is under attack.

[0037] That is, when the electronic device frequently receives disassociation frames and the frame sequence number of the management frame received later is less than or equal to the frame sequence number of the management frame received earlier, it is determined that the electronic device is under attack.

[0038] In an embodiment provided by the first aspect, after receiving the disassociation frame, determining whether the electronic device is under attack based on whether a number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold includes:

[0039] After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, and the difference between the frame sequence numbers of two adjacent management frames received by the electronic device is not within a second preset range, it is determined that the electronic device is under attack.

[0040] That is, when the electronic device frequently receives disassociation frames and there is a large difference between the frame sequence numbers of two consecutively received management frames, it is determined that the electronic device is under attack.

[0041] In an implementation manner provided by the first aspect, after receiving the disassociation frame, determining whether the electronic device is under attack includes:

[0042] After receiving the disassociation frame, obtaining source device information carried in the disassociation frame;

[0043] Determining whether the source device information matches the device information of the terminal device; the device information of the terminal device is obtained by the electronic device during the process of establishing the wireless connection with the terminal device;

[0044] When the source device information does not match the device information of the terminal device, it is determined that the electronic device is attacked.

[0045] The source device information refers to the device information of the source device, such as an organization unique identifier.

[0046] That is, when the source device information carried in the disassociation frame is different from the source device information previously acquired during the interaction process of establishing the wireless connection, it is determined that the electronic device is under attack.

[0047] In an implementation manner provided by the first aspect, after receiving the disassociation frame, determining whether the electronic device is under attack includes:

[0048] After receiving the disassociation frame, obtaining the source address carried in the disassociation frame;

[0049] When the source address is the network address of the electronic device, it is determined that the electronic device is attacked.

[0050] In an embodiment of the present application, the electronic device can receive a disassociation frame whose source address is its own network address, indicating that a third-party device has forged itself to send a disassociation frame to the terminal device. Therefore, it can be directly determined that the terminal device connected to itself has been attacked. After receiving the disassociation frame, the terminal device will disconnect from the electronic device, which is equivalent to the electronic device being attacked.

[0051] In one embodiment provided by the first aspect, the method further includes:

[0052] After the Wi-Fi hotspot establishes a target wireless connection with the terminal device, when an unencrypted association release frame is received, the unencrypted association release frame is ignored.

[0053] Because the Wi-Fi hotspot and the terminal device have established the target wireless connection based on protected management frames, any management frames sent by the terminal device are necessarily encrypted. Therefore, when an electronic device receives an unencrypted disassociation frame, it can determine that the disassociation frame is from an attacker and ignore it, meaning it will not disconnect the device, thereby improving the security of the Wi-Fi network.

[0054] In a second aspect, a hotspot control system is provided, comprising: an electronic device for providing a Wi-Fi hotspot and a terminal device to be connected to the Wi-Fi hotspot; wherein,

[0055] The electronic device is used to implement any of the above methods.

[0056] In a second aspect, a computer program product is provided, including a computer program. When the computer program is executed by an electronic device that provides a Wi-Fi hotspot, the computer program implements any of the above methods.

[0057] In a second aspect, an electronic device is provided, comprising: a memory, a processor, and a display screen, wherein:

[0058] The memory is used to store programs;

[0059] The processor is coupled to the memory and the display screen, and is configured to execute the program stored in the memory to implement any of the above methods.

[0060] In a second aspect, a computer-readable storage medium storing a computer program is provided, wherein the computer program can implement any of the above-mentioned methods when executed by a computer. BRIEF DESCRIPTION OF THE DRAWINGS

[0061] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0062] Figure 1 A schematic diagram of the internal framework of an electronic device provided by an exemplary embodiment of the present application;

[0063] Figure 2 A schematic diagram of a hardware and software layered architecture provided for an exemplary embodiment of the present application;

[0064] Figure 3 An interactive signaling diagram for connecting a terminal station device to a wireless access point provided by an exemplary embodiment of the present application;

[0065] Figure 4An interactive signaling diagram of a deauthentication attack provided by an exemplary embodiment of the present application;

[0066] Figure 5 Interactive signaling of a hotspot control method provided by an exemplary embodiment of the present application Figure 1 ;

[0067] Figure 6 Interactive signaling of a hotspot control method provided by another exemplary embodiment of the present application Figure 2 . DETAILED DESCRIPTION

[0068] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.

[0069] In the following, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the technical features indicated. Therefore, a feature specified as "first," "second," or "third" may explicitly or implicitly include one or more of the features.

[0070] The words "if" or "when" as used herein may be interpreted as "at the time" or "when" or "in response to" depending on the context.

[0071] In addition, the step sequence in the following method embodiments is only an example and not a strict limitation.

[0072] First, the terms used in the embodiments of the present application are explained. It should be understood that this explanation is for a clearer understanding of the embodiments of the present application and does not necessarily constitute a limitation on the embodiments of the present application.

[0073] AP: Short for Access Point, it's a wireless access point. It's the central node of a wireless network and can be thought of as a server. As a central node in a network, it provides wireless access services, allowing other wireless devices to connect to it. All wireless signal data from devices connected to it must pass through it for exchange and mutual access. Typical wireless routers, gateways, and hotspots operate in AP mode, allowing AP nodes to connect to each other.

[0074] Soft AP: Soft-AP, its hardware part is a standard wireless network card, but it provides the same signal switching, routing and other functions as an AP through a driver. For example, the AP in the following embodiments of this application can be a soft AP.

[0075] STA: It is the abbreviation of Station. It is a terminal station device in a wireless network and can be regarded as a client. Generally speaking, a device in STA mode does not accept wireless access itself. The device connects to the AP node for network access. Communication between devices in STA mode can be forwarded through the AP.

[0076] PMF stands for Protected Management Frames. PMF is a technology used to improve Wi-Fi network security, specifically protecting management frames. By introducing encryption and integrity protection into management frames, PMF prevents potential attacks, such as replay and tampering attacks.

[0077] WPA3 (Wi-Fi Protected Access 3) is the third-generation Wi-Fi encryption protocol or encryption mode, and is the successor to WPA2 technology. It should be noted that WPA3 requires the use of PMF.

[0078] WPA2 / WPA3 is a hybrid encryption mode of WPA2 and WPA3, which means it can support both WPA2 and WPA3 encryption methods at the same time.

[0079] An embodiment of the present application provides a method for controlling a hotspot, which is applied to an electronic device capable of providing a Wi-Fi hotspot (hereinafter referred to as a hotspot). Exemplarily, the electronic device provides a hotspot by converting a wired signal into a wireless signal (e.g., a Wi-Fi signal). Exemplarily, the electronic device provides a hotspot by converting a received mobile network signal (e.g., 3G, 4G, 5G, etc.) into a wireless signal (e.g., a Wi-Fi signal). It should be noted that an electronic device capable of providing a hotspot may be referred to as an AP, and an electronic device that accesses the network by connecting to an AP (or a device that accesses the network by connecting to a hotspot provided by an AP) is referred to as a STA.

[0080] The electronic device that can provide a hotspot can be a wireless router, a mobile phone, a tablet computer, an augmented reality (AR) device, a virtual reality (VR) device, an in-vehicle computer, a wearable device, a smart home device, or any other device that can provide a Wi-Fi hotspot. The embodiments of the present application do not specifically limit the specific form of the electronic device.

[0081] Figure 1 A schematic structural diagram of the electronic device 100 is shown.

[0082] The electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0083] It should be understood that the structure illustrated in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0084] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor, a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.

[0085] The controller can generate operation control signals according to the instruction operation code and timing signal to complete the control of instruction fetching and execution.

[0086] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.

[0087] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.

[0088] The wireless communication function of the electronic device 100 can be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor and the baseband processor.

[0089] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.

[0090] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied to the electronic device 100. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify, and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.

[0091] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.) or displays an image or video through the display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.

[0092] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to the electronic device 100. The wireless communication module 160 can be one or more devices that integrate at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.

[0093] In some embodiments, the antenna 1 of the electronic device 100 is coupled to the mobile communication module 150, and the antenna 2 is coupled to the wireless communication module 160, so that the electronic device 100 can communicate with the network and the terminal device through wireless communication technology. The wireless communication technology may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include a global positioning system (GPS), a global navigation satellite system (GLONASS), a Beidou navigation satellite system (BDS), a quasi-zenith satellite system (QZSS) and / or a satellite based augmentation system (SBAS).

[0094] Electronic device 100 implements display functionality through a GPU, display screen 194, and an application processor. A GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.

[0095] Display screen 194 is used to display images, videos, and the like. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, or a quantum dot light-emitting diode (QLED). In some embodiments, electronic device 100 may include one or N display screens 194, where N is a positive integer greater than one.

[0096] The electronic device 100 can implement a shooting function through an ISP, a camera 193, a video codec, a GPU, a display screen 194, and an application processor.

[0097] The electronic device 100 can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.

[0098] The SIM card interface 195 is used to connect a SIM card. The SIM card can be connected to or disconnected from the electronic device 100 by inserting it into or removing it from the SIM card interface 195. The electronic device 100 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The electronic device 100 interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the electronic device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.

[0099] The software and hardware system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a micro-kernel architecture, a micro-service architecture, or a cloud architecture. In the embodiment of the present invention, the Android system with a layered architecture is used as an example to illustrate the software structure of the electronic device 100.

[0100] Figure 2 FIG. 1 is a block diagram of the software and hardware structure of the electronic device 100 according to an embodiment of the present invention.

[0101] A layered architecture divides software and hardware into several layers, each with a clear role and division of labor. Layers communicate with each other via software interfaces. In some embodiments, the system is divided into four layers: the application layer, the application framework layer, the kernel layer, and the hardware layer, from top to bottom. It should be noted that the software and hardware system may include more or fewer layers, and this is not specifically limited in the present embodiments.

[0102] The application layer can include a series of application packages.

[0103] like Figure 2 As shown, the application package may include: an application package for setting applications. In addition, the application package may also include applications such as camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, music, video, and short message.

[0104] The application framework layer provides an application programming interface (API) and programming framework for the applications in the application layer. The application framework layer includes some predefined functions.

[0105] like Figure 2 As shown, the application framework layer may include a hotspot framework (or hotspot management service). In addition, the application framework layer may include a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, etc.

[0106] The application layer and application framework layer run in a virtual machine. The virtual machine executes Java files in the application layer and application framework layer as binary files. The virtual machine manages object lifecycles, stack management, thread management, security and exception management, and garbage collection.

[0107] The kernel layer is the layer between the hardware layer and the application framework layer. Figure 2 As shown, the kernel layer includes hotspot drivers. In addition, the kernel layer can also include display drivers, camera drivers, audio drivers, sensor drivers, etc.

[0108] like Figure 2 As shown, the hardware layer can include hotspot firmware, which is located in the Wi-Fi chip. In addition, the hardware layer can also include cellular network cards, cameras, displays, sensors, etc.

[0109] The following will be combined Figure 3This section describes the interaction process between a STA and an AP under the WAP2 security protocol. The AP is the electronic device mentioned above, and the STA is the terminal device mentioned above.

[0110] 301. The AP periodically broadcasts beacon frames.

[0111] Beacon frames are periodically sent by an AP to announce the existence of its Wi-Fi (802.11) network. Beacon frames contain basic AP information, such as the AP's SSID (Service Set Identifier), the Management Frame Protection Capable (MFPC) field, the Management Frame Protection Required (MFPR) field, the channel, frequency, signal strength, and country code.

[0112] Among them, SSID is the name used to uniquely identify the wireless LAN, which allows users to find and connect to the required network in the wireless LAN.

[0113] The Supported Management Frame Protection field indicates whether the AP supports PMF (i.e., whether PMF is enabled on the AP). A value of true or 1 indicates that the AP supports PMF, while a value of false or 0 indicates that the AP does not support PMF. The Required Management Frame Protection field indicates whether the peer must use PMF. A value of true or 1 indicates that the peer must use PMF to connect, while a value of false or 0 indicates that the peer is not forced to use PMF.

[0114] For example, when the Wi-Fi encryption protocol currently used by the AP is WPA2, the Supported Management Frame Protection field is 0, and the Required Management Frame Protection field is 0. When the Wi-Fi encryption protocol currently used by the AP is WPA2 / WPA3, the Supported Management Frame Protection field is 1, and the Required Management Frame Protection field is 0. When the Wi-Fi encryption protocol currently used by the AP is WPA3, the Supported Management Frame Protection field is 1, and the Required Management Frame Protection field is 1.

[0115] In this embodiment, the Wi-Fi encryption protocol adopted by the AP is WPA2. Therefore, the Management Frame Protection Supported field and the Management Frame Protection Required field carried in the beacon frame are 0.

[0116] After the STA passively receives the beacon frame, it does not need to perform the following steps 302 and 303 and can directly perform step 304.

[0117] 302. The STA broadcasts a probe request frame.

[0118] STA broadcasts a probe request frame to detect surrounding wireless networks.

[0119] After receiving the probe request frame, the AP executes step 303 .

[0120] 303. The AP sends a probe response frame to the STA.

[0121] The probe response frame may include basic information of the AP.

[0122] After receiving the probe response frame, the STA may execute the following step 304 .

[0123] 304. The STA sends an authentication request frame to the AP.

[0124] After receiving the authentication request frame, the AP authenticates the STA. If the authentication succeeds, the process proceeds to step 305. Otherwise, the process ends. The purpose of sending the authentication request is to allow the STA and AP to verify that the other party is an 802.11 device and for the AP to perform link authentication on the STA to confirm its legitimacy.

[0125] 305. The AP sends an authentication response frame to the STA.

[0126] After receiving the authentication response message, the STA executes step 303 .

[0127] 306. The STA sends an Association Request frame to the AP.

[0128] It should be noted that association is always initiated by the STA. In fact, the association process is the negotiation process for establishing a wireless connection between the STA and the AP. After the AP receives the association request message from the STA, it executes step 304.

[0129] 307. The AP sends an Association Response frame to the STA.

[0130] When the STA receives the association response frame, it indicates that a wireless connection has been established between the STA and the AP (ie, the connection is successful).

[0131] 308. The AP and the STA generate a key for encrypting wireless data (ie, data to be transmitted, or data frames) through a four-way handshake (ie, four information exchanges).

[0132] The specific implementation process of the four-way handshake can be found in the prior art and will not be described in detail here.

[0133] In the Wi-Fi protocol, there are three types of frames: management frames, control frames, and data frames. A frame type consists of a Type field and a Subtype field. The Type field indicates which of the three types a frame belongs to. For example, management frames include, but are not limited to, the following subtypes: Authentication Request frame, Authentication Response frame, Association Request frame, Association Response frame, Deauthentication frame, and Deassociation frame. Management frames primarily facilitate STA access and exit from a wireless network.

[0134] Management frames may include, but are not limited to, the frame type, source address, destination address, sequence number (Seq), and OUI (Organizationally Unique Identifier). When an AP or STA receives any management frame, they also detect or measure the received signal strength indicator (RSSI) of the frame.

[0135] For example, in a management frame sent from a STA to an AP, the source address is the STA's network address, and the destination address is the AP's network address. In a management frame sent from an AP to a STA, the source address is the AP's network address, and the destination address is the STA's network address. Specifically, the network address may be a MAC (Media Access Control) address.

[0136] The frame sequence number indicates the number of transmitted frames and is used to filter duplicate frames. If the frame is retransmitted, the frame's Seq remains unchanged; that is, the retransmitted frame's Seq is the same as the original frame's Seq. For example, if frame A needs to be retransmitted, the retransmitted frame's Seq will still be the same as frame A's sequence number. Each time a STA transmits a frame, the frame's Seq increments by 1. It should be noted that management frames and data frames are counted separately. That is, the management frame's Seq indicates the number of transmitted management frames, while the data frame's Seq indicates the number of transmitted data frames.

[0137] It should be noted that the wireless connection between the AP and the STA in each embodiment of the present application is also the wireless connection between the Wi-Fi hotspot provided by the AP and the STA.

[0138] In actual applications, after the AP and STA complete the above-mentioned authentication or establish a wireless connection, the AP or STA may face a deauthentication attack, also known as a Deauth attack. A deauthentication attack is a denial-of-service attack against a wireless local area network. This attack disconnects the target device from the wireless network by sending forged deauthentication frames (De-authentication, abbreviated as De-auth) and disassociation frames (Disassociation, abbreviated as Disassoc) to the target device (AP or STA). Among them, deauthentication frames and disassociation frames are both called disassociation frames. Optionally, the disassociation frame mentioned in the embodiment of the present application is a unicast management frame. By exploiting the vulnerability that the WiFi management frame is not encrypted, the attacker can forge a management frame and thus send a deauthentication frame to forcibly cut off the connection between the AP and the STA. This attack does not require cracking the network password, but only requires obtaining the network addresses of the AP and the STA to implement.

[0139] The following will be combined Figure 3 This section describes the process of an AP being attacked by a third-party device (also known as an attacker) after a wireless connection is established between the AP and STA.

[0140] 309. The AP receives a disassociation frame sent by the third-party device.

[0141] When a third-party device pretends to be a STA and sends a disassociation frame to the AP, the source address in the disassociation frame is forged as the network address of the STA, and the destination address is forged as the network address of the AP.

[0142] When a third-party device pretends to be an AP and sends a disassociation frame to a STA, the source address in the disassociation frame is forged as the network address of the AP, and the destination address is forged as the network address of the STA.

[0143] The sequence number and OUI of the frame in the disassociation frame are forged.

[0144] It should be noted that the disassociation frames in the above two cases will be received by the AP and the STA.

[0145] 310. After receiving the disassociation frame, the AP disassociates with the STA.

[0146] When the AP receives a disassociation frame with the source address being the STA's network address and the destination address being the AP's network address, the AP disassociates with the STA, that is, disconnects the wireless connection between the AP and the STA.

[0147] Disassociating the AP from the STA may specifically include: the AP deleting the STA from the locally maintained association list and / or clearing (or resetting) the locally maintained state machine of the STA. The association list records at least one STA to which the AP is currently associated. The STA's state machine is used to record the STA's current state (e.g., authenticated state, associated state, etc.). It should be noted that when the AP receives the above-mentioned disassociation frame after establishing a wireless connection with the STA, the STA is deleted from the locally maintained association list and the locally maintained state machine of the STA needs to be cleared. When the AP receives the above-mentioned disassociation frame after completing authentication with the STA and before establishing a wireless connection, it only needs to clear the locally maintained state machine of the STA.

[0148] It should be noted that when an AP receives a Disassociation Frame with the AP's network address as the source and the STA's network address as the destination, it will ignore it and will not proactively disassociate with the STA. Furthermore, if an AP can receive a Disassociation Frame with the AP's network address as the source and the STA's network address as the destination, this means that the STA will also receive a Disassociation Frame with the AP's network address as the source and the STA's network address as the destination. Upon receiving this Disassociation Frame, the STA will disassociate with the AP, effectively terminating its wireless connection to the AP.

[0149] 311. The STA receives a disassociation frame sent by a third-party device.

[0150] 312. After receiving the disassociation frame, the STA disassociates with the AP.

[0151] Disassociating from an AP means disconnecting the wireless connection to the AP.

[0152] When a STA receives a disassociation frame with the AP's network address as the source address and the STA's network address as the destination address, it disconnects from the AP. The specific steps for disassociating a STA from an AP are described in the previous section on disassociating an AP from a STA and are not detailed here.

[0153] Generally speaking, third-party devices frequently send disassociation frames to APs and STAs, such as Figure 4 shown.

[0154] The following will be combined Figure 5 Introduce the control method of hot spots. Figure 5 As shown, the AP includes: a hotspot framework, a hotspot driver, and hotspot firmware. Exemplarily, the hotspot firmware is located in the Wi-Fi chip of the AP.

[0155] 501. The hotspot firmware establishes a wireless connection with the STA.

[0156] The process of establishing a wireless connection between the hotspot firmware and the STA is also the process of establishing a wireless connection between the AP and the STA. For details, please refer to the corresponding content in the above embodiments and will not be repeated here. It should be noted that the hotspot driver will also participate in the process of establishing a wireless connection.

[0157] 502. The hotspot firmware receives a disassociation frame sent by a third-party device.

[0158] 503. Abnormal behavior detection.

[0159] When the hotspot firmware determines that the source address in the received disassociation frame is the network address of the AP, it can be determined that abnormal behavior (ie, attack behavior) currently exists.

[0160] The hotspot firmware receives disassociation frames with its own network address as the source because a third-party device impersonating an AP sends disassociation frames to a STA. When a third-party device impersonating an AP sends a disassociation frame to a STA, the frame is received not only by the STA but also by the AP. When an AP receives a disassociation frame with its own network address as the source, it indicates that the STA connected to the AP is under attack by a third-party device, thus confirming abnormal behavior.

[0161] It should be noted that after receiving a Disassociation frame with its own network address as the source address, the hotspot firmware will not actively disassociate with the STA. However, after receiving the Disassociation frame, the STA will actively disassociate with the STA.

[0162] When the hotspot firmware determines that the source address in the received disassociation frame is the network address of the STA, the following steps S11 and S12 may be executed simultaneously or successively.

[0163] S11. The hotspot firmware disassociates from the STA.

[0164] When the hotspot firmware terminates its association with the STA, it can also notify the hotspot driver to terminate its association with the STA. For the specific operations of the hotspot driver terminating its association with the STA and the hotspot firmware terminating its association with the STA, please refer to the relevant content of the AP terminating its association with the STA in the above embodiments. It should be noted that the hotspot firmware and hotspot driver respectively maintain the above-mentioned association list and STA state machine.

[0165] S12. The hotspot firmware determines whether the OUI in the disassociation frame matches the OUI of the STA.

[0166] If the hotspot firmware determines that the OUI in the disassociation frame does not match the STA's OUI, it indicates that the disassociation frame was sent by a third-party device rather than the STA, and abnormal behavior is detected. The STA's OUI is obtained by the AP during the wireless connection establishment process.

[0167] If the hotspot firmware determines that the OUI in the disassociation frame matches the OUI of the STA, the hotspot firmware may proceed to step S13 below.

[0168] S13: Determine whether the number of disassociation frames received by the AP within a set time (ie, a first preset time period) is greater than or equal to a preset number threshold.

[0169] The duration of the first preset time period is a set duration; and the starting time of the first preset time period is the time when the association release frame is received.

[0170] If the number does not exceed the preset threshold, it is determined that there is no abnormal behavior at present.

[0171] If the number exceeds the preset threshold, the following steps S14, S15 and S16 are continued to be executed.

[0172] S14: Determine whether a difference between the received signal strength indicator of the association establishment frame and the received signal strength indicator of the association release frame is within a first preset range.

[0173] Association establishment frames include authentication request frames and association request frames. Association establishment frames are received by the AP before or after receiving an association release frame. It's important to note that after the AP disconnects from a STA, the STA will continue to send association establishment frames to the AP to request a wireless connection, as the STA is forced to disconnect.

[0174] In actual applications, the distance between the AP and STAs is relatively stable. Therefore, the RSSI of each frame sent by the STA and received by the AP is stable within a certain range. If the difference between the RSSI of the disassociation frame and the RSSI of the association establishment frame is not within a first preset range, it can be determined that the disassociation frame was sent by a third-party device, indicating abnormal behavior.

[0175] S15. Determine whether, among the multiple management frames received by the AP, there is a management frame whose frame sequence number is less than or equal to the frame sequence number of the management frame received earlier.

[0176] Exemplarily, the multiple management frames may be received by the AP within a second preset time period. The second preset time period may include: the first preset time period. Exemplarily, the second preset time period includes: the first preset time period and a third preset time period located before the first preset time period.

[0177] If the frame sequence number of the management frame received later is less than or equal to the frame sequence number of the management frame received earlier, it can be determined that the disassociation frame is sent by a third-party device, that is, abnormal behavior occurs.

[0178] S16. Determine whether, among the multiple management frames received by the AP, there are two adjacent management frames whose frame sequence numbers are different from each other and are not within a second preset range.

[0179] When the difference between the frame sequence numbers of two consecutively received management frames is not within the second preset range, it can be determined that the disassociation frame is sent by a third-party device, ie, abnormal behavior occurs.

[0180] In actual applications, if multiple management frames are sent by STAs, then the Seq sequence of multiple management frames should follow the following rule: the latter Seq of any two adjacent Seqs in the Seq sequence is greater than the former Seq, and the difference between any two adjacent Seqs is within the second preset range. When the latter Seq of two adjacent Seqs in the Seq sequence is less than or equal to the former Seq, or the difference between two adjacent Seqs in the Seq sequence is not within the second preset range, it can be determined that the disassociation frame is sent by a third-party device, that is, there is abnormal behavior. The Seq sequence is obtained by sorting the Seqs of multiple management frames according to the order of frame reception. In the Seq sequence, the Seq of the frame received first is before the Seq of the frame received later.

[0181] The first preset range may be less than or equal to the first preset value. The size of the first preset value can be set according to actual needs and is not specifically limited in the embodiments of the present application. The second preset range may be greater than or equal to the first negative number and less than or equal to the second positive number.

[0182] Exemplarily, when the difference between the received signal strength indication of the association establishment frame and the received signal strength indication of the association release frame in the multiple management frames received by the AP is within a first preset range, the frame sequence number of the management frame received later does not exist in the multiple management frames received by the AP is less than or equal to the frame sequence number of the management frame received earlier, and the difference between the frame sequence numbers of two adjacent management frames received in the multiple management frames received by the AP does not exist within a second preset range, it is determined that there is no abnormal behavior at present.

[0183] After the hotspot firmware detects abnormal behavior, step 504 is executed.

[0184] 504. The hotspot firmware notifies the hotspot driver of an exception.

[0185] 505. The hotspot driver enables PMF.

[0186] That is, the hotspot driver turns on the PMF function.

[0187] Exemplarily, the hotspot driver sets the PMF field to 1.

[0188] 506. The hotspot driver notifies the hotspot firmware to set MFPC to 1.

[0189] 507. The hotspot firmware broadcasts a beacon frame.

[0190] It should be noted that in step 507 , the MFPC (ie, the first field mentioned above) in the beacon frame broadcast by the hotspot firmware is 1, and the MFPR (ie, the second field mentioned above) is 0.

[0191] In addition, after the above step 506, when the hotspot firmware receives a probe request frame sent by the STA, the hotspot firmware returns a probe response frame to the STA in which MFPC is 1 and MFPR is 0.

[0192] 508. The hotspot firmware establishes a wireless connection with the STA.

[0193] That is, the hotspot firmware and the STA re-establish a wireless connection. The process of re-establishing a wireless connection can refer to the process of establishing a connection between an AP and a STA under the WPA2 / WPA3 hybrid encryption protocol in the prior art.

[0194] It should be noted that after the STA receives the beacon frame broadcast by the hotspot firmware or the probe response frame returned by the hotspot firmware, it can determine that the AP supports / has enabled PMF based on the MFPC being 1 and the MFPR being 0 in the beacon frame or probe response frame. However, the use of PMF is not mandatory. When the STA has the PMF function, the STA and the AP establish a wireless connection based on the WPA3 protocol and perform key negotiation. Subsequently, the STA and AP will encrypt the management frames and data frames to be sent to the other end based on the negotiated key.

[0195] 509. The third-party device sends a disassociation frame to the hotspot firmware.

[0196] 510. The hotspot firmware determines whether the disassociation frame is encrypted.

[0197] If the judgment result is no, then execute step 511; if the judgment result is yes, then execute step 512.

[0198] The specific method for determining whether the disassociation frame is encrypted can be selected based on actual needs. In an optional embodiment, whether the disassociation frame is encrypted can be determined based on the protected flag field in the disassociation frame. If the protected flag is 1, the disassociation frame is determined to be encrypted; otherwise, it is determined to be unencrypted.

[0199] 511. Ignore.

[0200] That is, the disconnection operation is not performed.

[0201] 512. The hotspot firmware determines whether the decryption is successful.

[0202] The hotspot firmware uses the negotiated key to decrypt the association release frame; if the decryption fails, it means that the key release frame is sent by a third-party device, and step 511 is executed, that is, it is ignored.

[0203] It should be noted that if the decryption is successful, it means that the association release frame is sent by the STA, and the operation of releasing the association with the STA is performed.

[0204] It should be added that, in actual applications, it is possible to determine whether there is abnormal behavior at present by judging whether the source address in the disassociation frame is the network address of the AP, whether the OUI in the disassociation frame matches the OUI of the STA, whether the number of disassociation frames received by the AP within a set time exceeds a set number threshold, whether the difference between the received signal strength indication of the association establishment frame and the received signal strength indication of the association disassociation frame is within a first preset range, whether the frame sequence number of the management frame received later is less than or equal to the frame sequence number of the management frame received earlier among the multiple management frames received by the AP, and whether the difference between the frame sequence numbers of two adjacent management frames received by the AP is not within a second preset range. The multiple items listed here can be used individually for abnormal behavior detection, or two or more items can be combined for abnormal behavior detection. The embodiments of the present application do not impose any specific restrictions on this. When two or more items are combined for abnormal behavior detection, the judgment order of the two or more items can be designed according to actual needs. The embodiments of the present application do not impose any specific restrictions on this.

[0205] The following will be combined Figure 6 Introduce the control method of hot spots. Figure 6 As shown, the method includes:

[0206] 601. The hotspot firmware establishes a wireless connection with the STA.

[0207] 602. The hotspot firmware receives a disassociation frame sent by a third-party device.

[0208] 603. Abnormal behavior detection.

[0209] After the hotspot firmware detects abnormal behavior, step 604 is executed.

[0210] 604. The hotspot firmware notifies the hotspot driver of an exception.

[0211] 605. The hotspot driver notifies the hotspot framework to set the Wi-Fi encryption protocol to WPA3.

[0212] 606. The hotspot framework sets the Wi-Fi encryption protocol to WPA3.

[0213] 607. Restart the hotspot.

[0214] Specifically, the hotspot framework may first turn off the hotspot and then turn on the hotspot.

[0215] 608. The hotspot framework notifies the hotspot driver that the current Wi-Fi encryption protocol is WPA3.

[0216] 609 . The hotspot driver notifies the hotspot firmware to set MFPR to 1 and MFPC to 1.

[0217] It should be noted that the hotspot driver may also set the PMF field to 1 after step 608 .

[0218] 610. The hotspot firmware broadcasts a beacon frame.

[0219] After step 609 , the hotspot firmware broadcasts a beacon frame with MFPR set to 1 and MFPC set to 1.

[0220] After step 609 , the AP receives the probe request frame sent by the STA and returns a probe response frame to the STA in response to the probe request frame, in which the MFPR and the MFPC are both 1.

[0221] 611. The hotspot firmware establishes a wireless connection with the STA.

[0222] That is, the hotspot firmware and the STA re-establish the wireless connection.

[0223] The process of re-establishing a wireless connection may refer to the process of establishing a connection between an AP and a STA under the WPA 3 encryption protocol in the prior art.

[0224] It should be noted that after the STA receives the beacon frame broadcast by the hotspot firmware or the probe response frame returned by the hotspot firmware, it can determine that the AP supports / has enabled PMF and forces the use of PMF based on the MFPC and MFPR values ​​in the beacon frame or probe response frame. If the STA supports PMF, the STA and the AP establish a wireless connection based on the WPA3 protocol and perform key negotiation. Subsequently, the STA and AP encrypt the management frames and data frames to be sent to the other end based on the negotiated key. If the STA does not support PMF, the STA cannot establish a wireless connection with the AP.

[0225] 612. The third-party device sends a disassociation frame to the hotspot firmware.

[0226] 613. The hotspot firmware determines whether the disassociation frame is encrypted.

[0227] If the judgment result is no, then execute step 614; if the judgment result is yes, then execute step 615.

[0228] 614. Ignore.

[0229] That is, the disconnection operation is not performed.

[0230] 615. The hotspot firmware determines whether the decryption is successful.

[0231] The hotspot firmware decrypts the association release frame using the negotiated key; if the decryption fails, it means that the key release frame is sent by a third-party device, and step 614 is executed, that is, it is ignored.

[0232] It should be noted that if the decryption is successful, it means that the association release frame is sent by the STA, and the operation of releasing the association with the STA is performed.

[0233] Optionally, in Figure 6In the illustrated embodiment, the hotspot driver may notify the hotspot framework to set the Wi-Fi encryption protocol to WPA2 / WPA3; after the hotspot framework sets the Wi-Fi encryption protocol to WPA2 / WPA3 and restarts the hotspot, it notifies the hotspot driver that the current Wi-Fi encryption protocol is WPA2 / WPA3. In this way, the hotspot driver notifies the hotspot firmware to set MFPR to 0 and MFPC to 1. Subsequently, after the STA receives the beacon frame or probe response frame sent by the hotspot firmware, it can determine that the Wi-Fi encryption protocol currently adopted by the AP is WPA2 / WPA3 based on the MFPR being 0 and the MFPC being 1 in the beacon frame or probe response frame, and then decide the access method according to its own situation. For example: when the STA supports WPA3, the STA and the AP establish a wireless connection based on the WPA3 protocol and perform key negotiation; subsequently, the STA and the AP will encrypt the management frames and data frames to be sent to the other end based on the negotiated key. When the STA does not support WPA3, the STA and the AP establish a wireless connection based on the WPA2 protocol. It should be noted that after a STA establishes a wireless connection with an AP based on the WPA2 protocol, management frames are not protected and can still be attacked by a third party.

[0234] For steps not described in detail in the embodiments of this application, please refer to the corresponding contents in the above embodiments and will not be repeated here.

[0235] In the above Figure 5 and Figure 6 In the embodiments, abnormal behavior detection is performed by the hotspot firmware. Optionally, abnormal behavior detection can also be performed by the hotspot driver. Exemplarily, after receiving the association release frame, the hotspot firmware sends the association release frame to the hotspot driver, and the hotspot driver performs the above-mentioned abnormal behavior detection process.

[0236] In each embodiment of the present application, the AP disables PMF by default, which can maximize compatibility (some devices are currently incompatible with PMF, which will cause connection problems). The AP will only enable the PMF function when abnormal behavior is detected to avoid third-party attacks.

[0237] It should be noted that the execution entity of each step executed by the hotspot framework, hotspot driver, and hotspot firmware in this article is essentially the AP.

[0238] In addition, some of the processes described in the above embodiments and the accompanying drawings include multiple operations that appear in a specific order. However, it should be clearly understood that these operations may not be executed in the order in which they appear in this document or may be executed in parallel. The sequence numbers of the operations, such as 401 and 402, are merely used to distinguish between different operations and do not represent any execution order. In addition, these processes may include more or fewer operations, and these operations may be executed sequentially or in parallel.

[0239] An embodiment of the present application also provides an electronic device, comprising: a memory and a processor, wherein the memory is used to store a program; the processor is coupled to the memory and is used to execute the program stored in the memory to implement the methods in the above embodiments.

[0240] An embodiment of the present application further provides a computer-readable storage medium storing a computer program, wherein the computer program, when executed by a computer, can implement one or more steps of the method in any of the above embodiments.

[0241] The computer readable storage medium may be a non-transitory computer readable storage medium, for example, a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, and the like.

[0242] Another embodiment of the present application further provides a computer program product comprising a computer program. When the computer program is executed by a computer, one or more steps in any of the above method embodiments can be implemented.

[0243] Among them, the electronic device, computer-readable storage medium, and computer program product provided in this embodiment are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods provided above, and will not be repeated here.

[0244] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0245] Units described as separate components may or may not be physically separate, and components shown as units may be one physical unit or multiple physical units, that is, they may be located in one place or distributed in multiple places. Some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0246] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0247] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a device (which can be a single-chip microcomputer, chip, etc.) or a processor (processor) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0248] The above content is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A hotspot control method, characterized in that: Applicable to an electronic device for providing a Wi-Fi hotspot; the method includes: receiving a disassociation frame; when the electronic device receives the disassociation frame, the protected management frame function of the electronic device is not enabled, and a wireless connection is established between the Wi-Fi hotspot and the terminal device; the disassociation frame is a management frame used to disconnect the wireless connection; After receiving the disassociation frame, determining whether the electronic device is under attack; the attack is a deauthentication attack; When it is determined that the electronic device is under attack, enabling a protected management frame function of the electronic device and notifying the terminal device that the protected management frame function of the electronic device has been enabled; After the electronic device enables the protected management frame function, the Wi-Fi hotspot establishes a target wireless connection with the terminal device; The management frame transmitted on the target wireless connection is in an encrypted state.

2. The method according to claim 1, characterized in that When it is determined that the electronic device is under attack, enabling a protected management frame function of the electronic device and notifying the terminal device that the protected management frame function of the electronic device has been enabled, including: When it is determined that the electronic device is under attack, enabling a protected management frame function of the electronic device; After the protected management frame function of the electronic device is enabled, the beacon frame is broadcasted; The beacon frame carries field information of a first field; the field information of the first field is used to indicate that the electronic device has enabled a protected management frame function.

3. The method according to claim 2, characterized in that When it is determined that the electronic device is under attack, enabling a protected management frame function of the electronic device includes: When it is determined that the electronic device is under attack, the Wi-Fi encryption protocol currently used by the electronic device is set to the Wi-Fi encryption protocol WPA2 / WPA3 or the Wi-Fi encryption protocol WPA3 and the Wi-Fi hotspot is restarted to enable the protected management frame function of the electronic device.

4. The method according to claim 1, wherein After receiving the disassociation frame, determining whether the electronic device is under attack includes: After receiving the disassociation frame, it is determined whether the electronic device is under attack based on whether the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold.

5. The method according to claim 4, characterized in that The duration of the first preset time period is a set duration; the starting time of the first preset time period is the time when the association release frame is received.

6. The method according to claim 4, characterized in that After receiving the disassociation frame, determining whether the electronic device is under attack based on whether the number of disassociation frames received by the electronic device within a preset time period is greater than or equal to a preset number threshold includes: After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, it is determined that the electronic device is under attack.

7. The method according to claim 4, characterized in that After receiving the disassociation frame, determining whether the electronic device is under attack based on whether a number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold includes: After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, and a difference between a received signal strength indicator of an association establishment frame and a received signal strength indicator of the disassociation frame is not within a first preset range, determining that the electronic device is under attack; The association establishment frame is received by the electronic device before or after receiving the association release frame; the association establishment frame is a management frame used to establish a wireless connection between the terminal device and the Wi-Fi hotspot.

8. The method according to claim 4, characterized in that After receiving the disassociation frame, determining whether the electronic device is under attack based on whether a number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold includes: After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, and the frame sequence number of a management frame received later among the multiple management frames received by the electronic device is less than or equal to the frame sequence number of a management frame received earlier, it is determined that the electronic device is under attack.

9. The method according to claim 4, characterized in that After receiving the disassociation frame, determining whether the electronic device is under attack based on whether a number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold includes: After receiving the disassociation frame, when the number of disassociation frames received by the electronic device within a first preset time period is greater than or equal to a preset number threshold, and the difference between the frame sequence numbers of two adjacent management frames received by the electronic device is not within a second preset range, it is determined that the electronic device is under attack.

10. The method according to claim 1, characterized in that After receiving the disassociation frame, determining whether the electronic device is under attack includes: After receiving the disassociation frame, obtaining source device information carried in the disassociation frame; Determining whether the source device information matches the device information of the terminal device; the device information of the terminal device is obtained by the electronic device during the process of establishing the wireless connection with the terminal device; When the source device information does not match the device information of the terminal device, it is determined that the electronic device is attacked.

11. The method according to claim 1, wherein After receiving the disassociation frame, determining whether the electronic device is under attack includes: After receiving the disassociation frame, obtaining the source address carried in the disassociation frame; When the source address is the network address of the electronic device, it is determined that the electronic device is attacked.

12. The method according to claim 1, characterized in that Also includes: After the Wi-Fi hotspot establishes a target wireless connection with the terminal device, when an unencrypted association release frame is received, the unencrypted association release frame is ignored.

13. A hotspot control system, characterized in that: include: An electronic device for providing a Wi-Fi hotspot and a terminal device that needs to connect to the Wi-Fi hotspot; wherein, The electronic device is used to implement the method according to any one of claims 1 to 12.

14. A computer program product comprising a computer program, characterized in that When the computer program is executed by an electronic device that provides a Wi-Fi hotspot, the method according to any one of claims 1 to 12 is implemented.

15. An electronic device, characterized in that: include: Memory, processor and display screen, wherein, The memory is used to store programs; The processor is coupled to the memory and the display screen, and is configured to execute the program stored in the memory to implement the method according to any one of claims 1 to 12.

16. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a computer, the method according to any one of claims 1 to 12 can be implemented.

Citation Information

Patent Citations

  • Wireless LAN access point device and unauthorized management frame detection method

    CN101895887A

  • Management frame encryption and decryption

    CN110650476A

  • Defense method for wireless management frame flooding attack and wireless access point equipment

    CN115996382A