Wireless router access management method, system and wireless router

By building a multi-device access management system, collecting and analyzing the behavioral characteristic data of the access device, using a convolutional neural network to generate security indexes, and performing multi-level authentication and security judgment, the problem that traditional methods are difficult to identify and respond to abnormal behaviors of the equipment is solved, and efficient management and security protection of wireless network access is achieved.

CN119450470BActive Publication Date: 2025-05-13深圳市微浦技术有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510031474.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-09
Publication Date
2025-05-13
Estimated Expiration
2045-01-09

AI Technical Summary

Technical Problem

Traditional wireless network access management methods are difficult to effectively identify and respond to abnormal behavior of devices, especially in terms of protocol stack features. Attackers can circumvent network security mechanisms by tampering with or forging the length of the packet header field.

Method used

By building a multi-device access management system, the behavioral characteristic data of the access device is collected and the behavior fingerprint library is generated, the real-time behavior data and fingerprint library data are compared in real time, the behavior recognition model is constructed using a convolutional neural network, the security index of the access device is generated, and multi-level authentication and security judgment are carried out.

Benefits of technology

It realizes accurate identification and management of access equipment behavior, effectively prevents potential threats, ensures the reasonable allocation of network resources and the normal operation of network services, and improves the network's defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119450470B_ABST
    Figure CN119450470B_ABST
Patent Text Reader

Abstract

The present invention discloses a wireless router access management method, system and wireless router, and relates to the technical field of wireless routers. The invention significantly improves network security and resource utilization efficiency through multiple authentication and dynamic management mechanisms. The system first collects the first behavior feature data and network status data of the device, combines the convolutional neural network (CNN) model for intelligent analysis, and judges the security of the access device in real time. For devices that meet safety standards, the system automatically allocates bandwidth and provides continuous network services. For abnormal devices, the system will block their access in time through multiple rounds of authentication and load evaluation to ensure the security and stability of the network environment. In terms of bandwidth management, the system intelligently sorts and dynamically allocates bandwidth resources based on the second access security index and bandwidth requirements of the access device, avoiding the inefficiency and waste of resources of the traditional static allocation method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of wireless routers, and in particular to a wireless router access management method, system and wireless router. Background Art

[0002] With the widespread use of wireless networks, especially in homes, offices and public areas, more and more wireless devices are connected to the same network environment, resulting in a rapid increase in the types and number of network access devices. Especially in scenarios such as the Internet of Things (IoT) and smart homes, various terminal devices frequently access wireless networks, which brings huge challenges to network access management.

[0003] There are many types of access devices in modern wireless networks, and the device behavior patterns vary greatly. Traditional authentication methods based on device identity or static configuration cannot effectively distinguish between normal device behavior and potential threats. For example, some devices may exhibit abnormal channel switching frequency, packet transmission interval or protocol stack characteristics, which are difficult for traditional methods to detect and respond to. In particular, in terms of protocol stack characteristics, the length of the packet header field is an important feature, involving the header part of each layer of the protocol (such as the transport layer, network layer and application layer) during network transmission. Usually, the length of the header field is fixed and complies with specific protocol specifications. However, attackers can circumvent network security mechanisms and conduct various types of attacks by tampering with or forging the length of the header field. For example, attackers may adjust the header length to trigger buffer overflow vulnerabilities or other vulnerabilities, thereby bypassing the protection measures of the network layer and application layer, and then injecting illegal data or disrupting normal network communication. This phenomenon makes traditional network security protection mechanisms, especially detection methods based on static rules or device identities, unable to effectively identify potential security threats. Summary of the invention

[0004] In view of the deficiencies of the prior art, the present invention provides a wireless router access management method, system and wireless router to solve the problems mentioned in the background technology.

[0005] To achieve the above objectives, the present invention is implemented through the following technical solutions: A wireless router access management method, comprising the following steps:

[0006] S1. Pre-build a multi-device access management system, which includes multiple access devices and a wireless router. The wireless router is electrically connected to the multiple access devices after communicating and configuring through multiple frequency channels. The multiple frequency channels include 2.4 GHz, 5 GHz and 6 GHz.

[0007] The access device is connected through a plurality of channel networks; upon initial access, first behavior characteristic data of the access device is collected, the first behavior characteristic data including channel switching frequency, packet transmission interval and protocol stack characteristic data, the first behavior characteristic data is standardized to generate behavior characteristic data, and the behavior characteristic data is encrypted to generate a first behavior fingerprint library;

[0008] S2. Real-time collection of real-time behavior data of the access device, and by comparing the real-time behavior data of the access device with the data in the first behavior fingerprint library, a first behavior matching index M is formed; a behavior matching threshold T is preset, and if the first behavior matching index M exceeds the behavior matching threshold T, it indicates that the behavior of the access device is normal, otherwise, it indicates that the behavior of the access device is abnormal, and a first authentication instruction is generated and executed;

[0009] S3. Collect network status data of access devices, build and train a behavior recognition model using a convolutional neural network (CNN), and generate the first access security index for each access device by combining the network status data and the first behavior matching index M. , and preset the first risk threshold , when the first access security index ≥First risk threshold , the current access device is determined to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed;

[0010] S4. After the second authentication instruction is executed, further collect the communication load data of the access device, and combine it with the first access security index Generate a second access security index , and preset the second risk threshold A second determination is made on the second access security index; if the second access security index ≥ Second risk threshold , the access device is determined to be an abnormal device and its access is terminated; if the second access security index <Second risk threshold , generate qualified tags, continue to allocate network resources and network services; at the same time, count the access devices that generate qualified tags, establish a qualified tag group; and calculate the second access security index in the qualified tag group Priority is sorted from small to large and bandwidth is allocated dynamically.

[0011] Preferably, S1 comprises:

[0012] S11, constructing multiple channels in the wireless router in advance to perform network configuration, dividing and numbering each channel, and configuring basic communication parameters, wherein the basic communication parameters include bandwidth, power, and signal range;

[0013] S12, when the access device is connected to the wireless router for the first time, automatically starting the first behavior feature data collection action to analyze the initial connection behavior of the terminal device;

[0014] The first behavior characteristic data includes: channel switching frequency; the number of times the detection device switches channels in a short period of time;

[0015] Packet sending interval: measures the time interval between terminal devices sending data packets;

[0016] Protocol stack characteristic data: Protocol stack characteristic data includes communication protocol stack layer and packet header field information;

[0017] The communication protocol stack layers include transport layer protocol type, network layer protocol type and application layer protocol type;

[0018] Transport layer protocol types include TCP and UDP protocols;

[0019] Network layer protocol types include IPv4 and IPv6 protocols;

[0020] Application layer protocol types include HTTP, HTTPS, MQTT and CoAP protocols;

[0021] The packet header field information includes the transport layer packet header field length, the network layer packet header field length and the application layer packet header field length.

[0022] Preferably, S1 further comprises:

[0023] S13, standardizing the first behavior feature data collected in S12, and removing abnormal data to generate behavior characteristic data for identifying the behavior pattern of the terminal device;

[0024] S14, using the symmetric encryption algorithm RSA or ECC to encrypt the generated behavior characteristic data;

[0025] S15, storing the encrypted behavior characteristic data in the local storage of the wireless router to form a first behavior fingerprint library;

[0026] S16: Establish an index table of the first behavior fingerprint library in the wireless router for matching and retrieval.

[0027] Preferably, S2 comprises:

[0028] S21, collecting real-time behavior data of the access device in real time, and comparing the real-time behavior data of the access device with the data in the first behavior fingerprint library, the real-time behavior data including: the real-time collected transport layer header field length, network layer header field length, application layer header field length, real-time channel switching frequency and real-time packet sending interval;

[0029] S21 specifically includes:

[0030] S211, compare the real-time collected transport layer header field length, network layer header field length and application layer header field length, compare with the first behavior fingerprint library, and calculate the transport layer protocol similarity by the following formula , Network layer protocol similarity Similarity with application layer protocols :

[0031] ;

[0032] ;

[0033] ;

[0034] In the formula, Indicates the total length of the transport layer header field. Indicates the transport layer header field matching result of the i-th field. If the field values ​​are consistent, ,otherwise ; Indicates the total length of the network layer header field. Indicates the network layer header field matching result of the i-th field. If the field values ​​are consistent, then ,otherwise ; Indicates the total length of the application layer header field. Indicates the application layer header field matching result of the i-th field. If the field values ​​are consistent, then ,otherwise ;

[0035] S212, extracting transport layer protocol similarity , Network layer protocol similarity Similarity with application layer protocols After dimensionless processing, the protocol stack similarity is calculated by the following associated formula :

[0036] ;

[0037] In the formula, , and Represents the transport layer protocol similarity , network layer protocol similarity Similarity with application layer protocols The weight of .

[0038] Preferably, S21 further includes:

[0039] S213, extracting the real-time channel switching frequency and the real-time packet transmission interval in the real-time behavior data; and calculating the frequency similarity by the following formula Similarity with packet sending interval :

[0040] ;

[0041] ;

[0042] In the formula, Indicates the real-time channel switching frequency, represents the channel switching frequency in the first fingerprint library, is a small constant to avoid the denominator being zero; Indicates the real-time packet sending interval. Indicates the packet sending interval in the first fingerprint database, represents the interval tolerance, exp represents the Euler number, which is set to 2.718;

[0043] S214: Extract the protocol stack similarity calculated in S212 Combined with the frequency similarity calculated in S213 Similarity with packet sending interval , after dimensionless processing, the first line matching index M is calculated by the following formula;

[0044] ;

[0045] In the formula, , and Represents the similarity of protocol stacks , frequency similarity Similarity with packet sending interval The weight of ;

[0046] S215. Preset a behavior matching threshold T. If the first behavior matching index M> the behavior matching threshold T, it indicates that the behavior of the access device is normal; if the first behavior matching index M≤ the behavior matching threshold T, it indicates that the behavior of the access device is abnormal, and a first authentication instruction is generated, including: guiding the access device to update its communication protocol stack version and requiring the access device to use a password + dynamic verification code for authentication, starting the network service and allocating network resources. If the authentication fails, terminating its access.

[0047] Preferably, S3 includes:

[0048] S31. Through network performance analysis tools, including NetFlow and SNMP;

[0049] Real-time collection of network status data of access devices, including: network speed , communication delay , Packet loss rate , disconnection times and reconnection frequency ;

[0050] S32, normalizing the network status data, converting the network status data into time-series CNN format data, and dividing the time-series CNN format data into segments of fixed sizes through a sliding window;

[0051] S33. Use the convolutional neural network CNN to build a behavior recognition model, and after training the behavior recognition model with the time-series CNN format data, combine the first behavior matching index M, and calculate the first access security index of each access device through the following formula :

[0052] ;

[0053] In the formula, Indicates the standard network rate threshold. Indicates the maximum tolerated network delay threshold. Indicates the maximum tolerable packet loss rate threshold. Indicates the maximum disconnection threshold. Indicates the standard reconnection frequency threshold. represents the behavior matching threshold; , , , , and represents the weight value, and .

[0054] Preferably, S3 further includes:

[0055] S34. Preset the first risk threshold , the first access security index of each access device With the first risk threshold Performing a comparison to obtain a first determination result includes:

[0056] When the first access security index <First risk threshold , the current access device is determined to be safe, and the current allocation of network resources and network services is continued;

[0057] When the first access security index ≥First risk threshold , the current access device is determined to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed, including: after triggering the access device to restart, after combining the access device password, fingerprint recognition and facial authentication, the network service is started and network resources are allocated. If the authentication fails, the access is terminated.

[0058] Preferably, S4, after the second authentication instruction is executed, use a network traffic analysis tool, including Wireshark or ntopng, to further collect communication load data of the access device, the communication load data including: uplink traffic and downstream traffic ;

[0059] And extract the upstream traffic and downstream traffic , associated with the first access security index , the second access security index is generated by the following associated formula :

[0060] ;

[0061] In the formula, Indicates the sum of the maximum upstream and downstream traffic thresholds. and is the weight value, and ;

[0062] Preset second risk threshold , and the second access security index With the second risk threshold Performing a comparison to obtain a second determination result includes:

[0063] If the second access security index ≥ Second risk threshold , the access device is determined to be an abnormal device and its access is terminated;

[0064] If the second access security index <Second risk threshold , the access device is determined to be a secure device, a qualified tag is generated, and the current allocation of network resources and network services is continued;

[0065] At the same time, the access devices that generate qualified tags are counted to establish a qualified tag group, and the second access security index in the qualified tag group is calculated. Priority is sorted from small to large and bandwidth is allocated dynamically.

[0066] A wireless router access management system, comprising:

[0067] The device access management module is used to pre-build a multi-device access management system, which includes multiple access devices and wireless routers. The wireless router is electrically connected to multiple access devices after communicating and configuring through multiple channels, and processes the configuration and authentication of the access devices when they are connected for the first time;

[0068] A behavior characteristic collection module, used for collecting first behavior characteristic data of an access device when accessing for the first time, wherein the first behavior characteristic data includes a channel switching frequency, a packet transmission interval, and a protocol stack characteristic data, and after standardizing the first behavior characteristic data, generating behavior characteristic data, and encrypting the behavior characteristic data to generate a first behavior fingerprint library;

[0069] A real-time behavior matching module is used to collect the real-time behavior data of the access device in real time, and to form a first behavior matching index M by comparing the real-time behavior data of the access device with the data in the first behavior fingerprint library; a behavior matching threshold T is preset, and if the first behavior matching index M exceeds the behavior matching threshold T, it indicates that the behavior of the access device is normal, otherwise, it indicates that the behavior of the access device is abnormal, and a first authentication instruction is generated and executed;

[0070] A network status data collection module is used to collect network status data of access devices;

[0071] The dynamic authentication module uses the convolutional neural network (CNN) to build and train a behavior recognition model, combining network status data and the first behavior matching index M to generate the first access security index for each access device. , and preset the first risk threshold , when the first access security index ≥First risk threshold , the current access device is determined to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed;

[0072] The communication load collection module is used to further collect the communication load data of the access device after the second authentication instruction is executed, and combine the first access security index Generate a second access security index ;

[0073] Secondary determination module, used to preset the second risk threshold A second determination is made on the second access security index; if the second access security index ≥ Second risk threshold , the access device is determined to be an abnormal device and its access is terminated; if the second access security index <Second risk threshold , generate qualified tags, and continue the current allocation of network resources and network services;

[0074] The bandwidth allocation and priority scheduling module is used to count the access devices that generate qualified tags, establish qualified tag groups, and calculate the second access security index in the qualified tag group. Priority is sorted from small to large and bandwidth is allocated dynamically.

[0075] A wireless router includes one or more radio devices, a controller and an authentication server, wherein the controller is used to execute the above method steps, and the authentication server is used to execute a first authentication instruction and a second authentication instruction.

[0076] The present invention provides a wireless router access management method, system and wireless router, which have the following beneficial effects:

[0077] (1) A wireless router access management method, system and wireless router can accurately model the normal behavior pattern of the device by collecting the behavioral feature data of the access device (such as channel switching frequency, packet transmission interval, protocol stack characteristic data) and building a first behavioral fingerprint library. By matching the behavioral feature library with real-time behavioral data, it is possible to effectively determine whether the device is a normal device or a potential threat device, avoiding the traditional method of relying solely on static device identity or configuration, and overcoming its drawback of insufficient recognition of dynamic attack behavior.

[0078] (2) A wireless router access management method, system and wireless router, the present invention uses a convolutional neural network (CNN) to model and train the network status data of the access device to generate a first access security index of the access device The introduction of this safety index makes the safety evaluation of equipment more dynamic and intelligent. By setting the first risk threshold , based on real-time judgment of device behavior, the ability to identify potential threats is further enhanced.

[0079] (3) A wireless router access management method, system and wireless router, the present invention adopts a phased authentication mechanism, from the first behavior matching index M at the initial access to the subsequent network status analysis to generate the first access security index , and then collect and analyze the communication load data to generate the second access security index , and conduct a secondary security assessment. This phased security protection mechanism can gradually refine the monitoring and response of devices, conduct accurate security verification and management at different levels, and effectively respond to complex network attacks.

[0080] (4) This wireless router access management method, system and wireless router can effectively prevent malicious devices from occupying network resources by identifying abnormal devices in real time and disconnecting their access, thereby ensuring the reasonable allocation of network resources and the normal operation of network services. In addition, by establishing a qualified tag group, it is possible to perform statistics and classification management on devices that have normal access, further improving the efficiency of network access management. In the case where attackers circumvent network security mechanisms by forging packet header field length or other protocol stack features, the present invention effectively identifies and prevents such attacks through behavior matching and multi-layer security detection, thereby improving the overall network's defense capabilities and ensuring the authenticity and security of access devices. BRIEF DESCRIPTION OF THE DRAWINGS

[0081] Figure 1 A schematic diagram of the steps of a wireless router access management method of the present invention;

[0082] Figure 2 The present invention is a schematic diagram of a wireless router access management system block diagram. DETAILED DESCRIPTION

[0083] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0084] Example 1

[0085] See also Figure 1 The present invention provides a wireless router access management method, comprising the following steps:

[0086] S1. Pre-build a multi-device access management system, which includes multiple access devices and wireless routers. The wireless routers are electrically connected to the multiple access devices after communicating and configuring through multiple channels. The multiple channels include 2.4 GHz, 5 GHz and 6 GHz.

[0087] The access device is connected through several channel networks; when accessing for the first time, first behavior characteristic data of the access device is collected, the first behavior characteristic data includes channel switching frequency, packet transmission interval and protocol stack characteristic data, the first behavior characteristic data is standardized to generate behavior characteristic data, and the behavior characteristic data is encrypted to generate a first behavior fingerprint library;

[0088] S2. Real-time collection of real-time behavior data of the access device, and by comparing the real-time behavior data of the access device with the data in the first behavior fingerprint library, a first behavior matching index M is formed; a behavior matching threshold T is preset, and if the first behavior matching index M exceeds the behavior matching threshold T, it indicates that the behavior of the access device is normal, otherwise, it indicates that the behavior of the access device is abnormal, and a first authentication instruction is generated and executed;

[0089] S3. Collect network status data of access devices, build and train a behavior recognition model using a convolutional neural network (CNN), and generate the first access security index for each access device by combining the network status data and the first behavior matching index M. , and preset the first risk threshold , when the first access security index ≥First risk threshold , the current access device is determined to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed;

[0090] S4. After the second authentication instruction is executed, further collect the communication load data of the access device, and combine it with the first access security index Generate a second access security index , and preset the second risk threshold A second determination is made on the second access security index; if the second access security index ≥ Second risk threshold , the access device is determined to be an abnormal device and its access is terminated; if the second access security index <Second risk threshold , generate qualified tags, continue to allocate network resources and network services; at the same time, count the access devices that generate qualified tags, establish a qualified tag group; and calculate the second access security index in the qualified tag group Priority is sorted from small to large and bandwidth is allocated dynamically.

[0091] In this embodiment, by collecting the behavioral feature data of the access device (such as channel switching frequency, packet transmission interval, protocol stack characteristic data) and building a first behavioral fingerprint library, the normal behavior mode of the device can be accurately modeled. By matching the behavioral feature library with the real-time behavioral data, it is possible to effectively determine whether the device is a normal device or a potential threat device, avoiding the traditional method of relying solely on static device identity or configuration, and overcoming its drawback of insufficient recognition of dynamic attack behaviors.

[0092] The present invention uses a convolutional neural network (CNN) to model and train the network status data of the access device to generate a first access security index of the access device. The introduction of this safety index makes the safety evaluation of equipment more dynamic and intelligent. By setting the first risk threshold , based on real-time judgment of device behavior, the ability to identify potential threats is further enhanced.

[0093] The present invention adopts a phased authentication mechanism, from the first behavior matching index M at the initial access to the subsequent network status analysis to generate the first access security index , and then collect and analyze the communication load data to generate the second access security index , and conduct a secondary security assessment. This phased security protection mechanism can gradually refine the monitoring and response of devices, conduct accurate security verification and management at different levels, and effectively respond to complex network attacks.

[0094] By identifying abnormal devices in real time and disconnecting their access, it is possible to effectively avoid the occupation of network resources by malicious devices, thereby ensuring the reasonable allocation of network resources and the normal operation of network services. In addition, by establishing a qualified tag group, it is possible to perform statistics and classification management on devices with normal access, further improving the efficiency of network access management. In response to the situation where attackers circumvent network security mechanisms by forging the length of packet header fields or other protocol stack features, the present invention effectively identifies and prevents such attacks through behavior matching and multi-layer security detection, thereby improving the overall network's defense capabilities and ensuring the authenticity and security of access devices.

[0095] Example 2

[0096] This embodiment is an explanation of the embodiment 1. Specifically, S1 includes:

[0097] S11. Build multiple channels in the wireless router in advance for network configuration, divide and number each channel, and configure basic communication parameters, including bandwidth, power, and signal range. Reasonable configuration of bandwidth, power, and signal range will help optimize network coverage and device connection quality, especially in environments with dense devices and high traffic, which can reduce network congestion and improve user experience.

[0098] S12. When the access device is connected to the wireless router for the first time, the first behavior feature data collection action is automatically started to analyze the initial connection behavior of the terminal device; this not only simplifies the network management process, but also enables the rapid identification of the initial behavior features of the access device. By analyzing the initial connection behavior in real time, it is possible to promptly identify whether the device is a normal device or a potential attacker, thereby strengthening the security protection of the network.

[0099] The first behavioral feature data includes: channel switching frequency; the number of times the detection device switches channels in a short period of time; and the ability to identify abnormal device behavior, such as frequent channel hopping, which may mean malicious scanning or denial of service attacks (DoS).

[0100] Packet interval: measures the time interval between terminal devices sending data packets; it can determine the regularity of device behavior. Abnormal packet intervals may indicate attack activities (such as packet injection, network sniffing, etc.).

[0101] Protocol stack characteristic data: Protocol stack characteristic data includes communication protocol stack layer and packet header field information; it can accurately identify the type of protocol used by the device, including the specific configuration of the transport layer protocol, network layer protocol and application layer protocol. This data is important for distinguishing the communication behavior of the device and identifying abnormal protocol stacks or forged communication traffic.

[0102] The communication protocol stack layers include transport layer protocol types, network layer protocol types, and application layer protocol types;

[0103] Transport layer protocol types include TCP and UDP protocols;

[0104] Network layer protocol types include IPv4 and IPv6 protocols;

[0105] Application layer protocol types include HTTP, HTTPS, MQTT and CoAP protocols;

[0106] The packet header field information includes the transport layer packet header field length, the network layer packet header field length, and the application layer packet header field length.

[0107] S13, standardizing the first behavior feature data collected in S12, and removing abnormal data to generate behavior characteristic data for identifying the behavior pattern of the terminal device;

[0108] S14. Use the symmetric encryption algorithm RSA or ECC to encrypt the generated behavior characteristic data. Encrypting the behavior characteristic data effectively ensures the security of the device's behavior data and prevents the data from being tampered with or stolen during transmission. This measure can protect user privacy and avoid the leakage of sensitive data.

[0109] S15. The encrypted behavior characteristic data is stored in the local storage of the wireless router to form the first behavior fingerprint library; ensuring that the behavior characteristics of each device are securely stored and convenient for subsequent matching and retrieval. Through local storage, efficient offline and real-time query can be achieved, avoiding the delay and privacy leakage risks caused by frequent cloud data exchange.

[0110] S16. Establish an index table of the first behavior fingerprint library in the wireless router for matching and retrieval. When a new device is connected, the behavior characteristics of the device can be quickly compared with the stored behavior fingerprints for matching, thereby identifying the normality or abnormality of the device in real time. This method significantly improves the management efficiency of the wireless network, and can quickly respond to abnormal devices and take security measures in a timely manner.

[0111] Example 3

[0112] This embodiment is an explanation of the embodiment 1. Specifically, S2 includes:

[0113] S21. Collect real-time behavior data of the access device in real time, and compare the real-time behavior data of the access device with the data in the first behavior fingerprint library, the real-time behavior data includes: real-time collected transport layer header field length, network layer header field length, application layer header field length, real-time channel switching frequency and real-time packet sending interval; this step provides dynamic monitoring capabilities, improves network security and response speed to abnormal behavior.

[0114] S21 specifically includes:

[0115] S211, compare the real-time collected transport layer header field length, network layer header field length and application layer header field length, compare with the first behavior fingerprint library, and calculate the transport layer protocol similarity by the following formula , network layer protocol similarity Similarity with application layer protocols :

[0116] ;

[0117] ;

[0118] ;

[0119] In the formula, Indicates the total number of words in the transport layer header field length. Indicates the transport layer header field matching result of the i-th field. If the field values ​​are consistent, ,otherwise ; Indicates the total number of words in the network layer header field length. Indicates the network layer header field matching result of the i-th field. If the field values ​​are consistent, then ,otherwise ; Indicates the total length of the application layer header field. Indicates the application layer header field matching result of the i-th field. If the field values ​​are consistent, ,otherwise ; Use the formula to calculate the transport layer protocol similarity , network layer protocol similarity Similarity with application layer protocols , improving the accuracy and precision of behavior recognition.

[0120] S212, extracting transport layer protocol similarity , network layer protocol similarity Similarity with application layer protocols After dimensionless processing, the protocol stack similarity is calculated by the following associated formula :

[0121] ;

[0122] In the formula, , and Represents the transport layer protocol similarity , network layer protocol similarity Similarity with application layer protocols The weight of Combining the similarities of the three protocol layers, the behavior patterns of the devices can be evaluated more comprehensively, ensuring comprehensive and accurate identification of the access device protocol stack. This method also avoids deviations in protocol stack similarities, making behavior identification more consistent and reliable.

[0123] S213, extracting the real-time channel switching frequency and the real-time packet transmission interval in the real-time behavior data; and calculating the frequency similarity by the following formula Similarity with packet sending interval :

[0124] ;

[0125] ;

[0126] In the formula, Indicates the real-time channel switching frequency, represents the channel switching frequency in the first fingerprint library, is a small constant to avoid the denominator being zero; Indicates the real-time packet sending interval. Indicates the packet sending interval in the first fingerprint database, represents the interval tolerance, exp represents the Euler number, which is set to 2.718; frequent channel switching or irregular packet transmission intervals may indicate abnormal behavior of the device, such as attackers forging traffic or interfering with the network. By calculating the frequency similarity Similarity with packet sending interval , can quantify this anomaly and further enhance the system's intelligent monitoring capabilities.

[0127] S214: Extract the protocol stack similarity calculated in S212 Combined with the frequency similarity calculated in S213 Similarity with packet sending interval , after dimensionless processing, the first line matching index M is calculated by the following formula;

[0128] ;

[0129] In the formula, , and Represents the similarity of protocol stacks , frequency similarity Similarity with packet sending interval The weight of ; Combining the protocol stack similarity, frequency similarity and packet interval similarity, a comprehensive first behavior matching index M is calculated, which can comprehensively evaluate whether the behavior of the access device conforms to the expected pattern. This matching index can dynamically reflect the normality of the device and ensure comprehensive and accurate behavior analysis of all access devices.

[0130] S215. Preset a behavior matching threshold T. If the first behavior matching index M> the behavior matching threshold T, it indicates that the access device behaves normally and the access device obtains normal access authority.

[0131] If the first behavior matching index M≤behavior matching threshold T, it indicates that the access device behavior is abnormal, and a first authentication instruction is generated, including: guiding the access device to update its communication protocol stack version and requiring the access device to use a password + dynamic verification code for authentication, starting the network service and allocating network resources; if the authentication fails, terminating its access.

[0132] In this embodiment, when the behavior of the access device is highly matched with the normal behavior pattern in the fingerprint library, the access device obtains normal access rights; when the access device behaves abnormally, it can issue authentication instructions in time to perform additional identity authentication or security detection to prevent potential network attacks or device intrusions. This mechanism effectively reduces the occupation of network resources by unsafe devices and improves network security. By forcing terminal devices to update the communication protocol stack version and adopt a stronger authentication mechanism (such as password + dynamic verification code authentication), the security of device access can be enhanced. Even if the behavioral characteristics of the device are abnormal, the legitimacy of the device can be further verified through multi-factor authentication to prevent unauthorized devices or attackers from invading the network through vulnerabilities. If the device authentication fails, the system can immediately terminate the access of the device to prevent it from further affecting network security. This step strengthens the network's active protection capabilities and effectively prevents potential threats.

[0133] Example 4

[0134] This embodiment is an explanation of the embodiment 1. Specifically, S3 includes:

[0135] S31. Through network performance analysis tools, including NetFlow and SNMP;

[0136] Real-time collection of network status data of access devices, including: network speed , communication delay , Packet loss rate , disconnection times and reconnection frequency ;

[0137] S32, normalizing the network status data, converting the network status data into time-series CNN format data, and dividing the time-series CNN format data into segments of fixed sizes through a sliding window;

[0138] S33. Use the convolutional neural network CNN to build a behavior recognition model, and after training the behavior recognition model with the time-series CNN format data, combine the first behavior matching index M, and calculate the first access security index of each access device through the following formula :

[0139] ;

[0140] In the formula, Indicates the standard network rate threshold. Indicates the maximum tolerated network delay threshold. Indicates the maximum tolerable packet loss rate threshold. Indicates the maximum disconnection threshold. Indicates the standard reconnection frequency threshold. represents the behavior matching threshold; , , , , and represents the weight value, and .

[0141] S34. Preset the first risk threshold , the first access security index of each access device With the first risk threshold Performing a comparison to obtain a first determination result includes:

[0142] When the first access security index <First risk threshold , the current access device is determined to be safe, and the current allocation of network resources and network services is continued;

[0143] When the first access security index ≥First risk threshold , the current access device is determined to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed, including: after triggering the access device to restart, after combining the access device password, fingerprint recognition and facial authentication, the network service is started and network resources are allocated. If the authentication fails, the access is terminated.

[0144] In this embodiment, according to the first access security index of the access device With the first risk threshold The comparison results can be used to manage network access in a timely manner. When the access device is judged to be safe, the system can continue to allocate network resources to it to ensure its normal access. When the access device is judged to be abnormal, the system will automatically interrupt its network service, generate and execute the second authentication instruction. This dynamic and real-time security management mechanism can effectively prevent abnormal access devices from entering the network, thereby improving the security of the overall network. Especially in the IoT environment, a large number of access devices are connected to the network. Through automated management and instant response, the burden of manual management and security risks can be greatly reduced. Through multi-factor authentication (including passwords, fingerprint recognition and facial authentication), the security of device access can be further enhanced. When the access behavior of the device is abnormal, by forcing the device to restart and perform multiple authentications, malicious devices can be effectively prevented from bypassing simple authentication mechanisms to enter the network. If the device authentication fails, the system will immediately terminate the device's access to prevent it from posing any security threats to the network. This multi-level authentication mechanism effectively improves the rigor of network protection and ensures that only legitimate devices can access and enjoy network services.

[0145] Example 5

[0146] This embodiment is an explanation of the embodiment 1. Specifically, S4, after the second authentication instruction is executed, a network traffic analysis tool, including Wireshark or ntopng, is used to further collect communication load data of the access device. The communication load data includes: uplink traffic and downstream traffic ;

[0147] And extract the upstream traffic and downstream traffic , associated with the first access security index , the second access security index is generated by the following associated formula :

[0148] ;

[0149] In the formula, Indicates the sum of the maximum upstream and downstream traffic thresholds. and is the weight value, and ; Upstream traffic and downstream traffic With First Access Security Index Combined to generate the second access security index , making the security assessment of access devices more comprehensive. This step further refines the security assessment by comprehensively considering the network traffic characteristics and preliminary behavioral characteristics of the device, especially in the identification of high-traffic devices, potential attacks or abnormal devices. This multi-dimensional security assessment method helps to avoid the shortcomings of relying on a single indicator and improve the accuracy of security judgment.

[0150] Preset second risk threshold , and the second access security index With the second risk threshold Performing a comparison to obtain a second determination result includes:

[0151] If the second access security index ≥ Second risk threshold , the access device is determined to be an abnormal device and its access is terminated;

[0152] If the second access security index <Second risk threshold , the access device is determined to be a secure device, a qualified tag is generated, and the current allocation of network resources and network services is continued;

[0153] At the same time, the access devices that generate qualified tags are counted to establish a qualified tag group, and the second access security index in the qualified tag group is calculated. Sort by priority from small to large and dynamically allocate bandwidth. The specific method of dynamically allocating bandwidth is as follows:

[0154] Collect the available bandwidth pool of the current wireless router , and according to the second access security index According to the priority order from small to large, the bandwidth requirement of the jth access device in the qualified tag group is collected as follows: , then the bandwidth allocation value of the jth access device is Generated by the following formula:

[0155] ;

[0156] In the formula, Indicates the available bandwidth pool, It is the sum of the bandwidth requirements of access devices in all qualified tag groups, and m represents the total number of access devices in the qualified tag group.

[0157] At the same time, for devices that meet security standards, the system will generate qualified tags and continue to provide network services. Automatic tagging and priority sorting of qualified devices can effectively improve network management efficiency, ensure that qualified devices receive continuous services, and avoid manual operation omissions. As devices are connected to the network or their status changes (such as security changes, bandwidth demand changes, etc.), bandwidth allocation will also be dynamically adjusted to ensure the rational use of network resources.

[0158] Example 6

[0159] See also Figure 2 , a wireless router access management system, comprising:

[0160] The device access management module is used to pre-build a multi-device access management system, which includes multiple access devices and wireless routers. The wireless routers are electrically connected to multiple access devices after communicating and configuring through multiple channels, and handle the configuration and authentication of the access devices when they are connected for the first time.

[0161] The behavior characteristic collection module is used to collect the first behavior characteristic data of the access device when accessing for the first time, the first behavior characteristic data includes the channel switching frequency, the packet sending interval and the protocol stack characteristic data, and after the first behavior characteristic data is standardized, the behavior characteristic data is generated, and the behavior characteristic data is encrypted to generate a first behavior fingerprint library;

[0162] A real-time behavior matching module is used to collect the real-time behavior data of the access device in real time, and to form a first behavior matching index M by comparing the real-time behavior data of the access device with the data in the first behavior fingerprint library; a behavior matching threshold T is preset, and if the first behavior matching index M exceeds the behavior matching threshold T, it indicates that the behavior of the access device is normal, otherwise, it indicates that the behavior of the access device is abnormal, and a first authentication instruction is generated and executed;

[0163] A network status data collection module is used to collect network status data of access devices;

[0164] The dynamic authentication module uses the convolutional neural network (CNN) to build and train a behavior recognition model, combining network status data and the first behavior matching index M to generate the first access security index for each access device. , and preset the first risk threshold , when the first access security index ≥First risk threshold , the current access device is determined to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed;

[0165] The communication load collection module is used to further collect the communication load data of the access device after the second authentication instruction is executed, and combine the first access security index Generate a second access security index ;

[0166] Secondary determination module, used to preset the second risk threshold Security index for the second access Perform a secondary determination; if the second access security index ≥ Second risk threshold , the access device is determined to be an abnormal device and its access is terminated; if the second access security index <Second risk threshold , generate qualified tags, and continue the current allocation of network resources and network services;

[0167] The bandwidth allocation and priority scheduling module is used to count the access devices that generate qualified tags, establish qualified tag groups, and evaluate the second access security index in the qualified tag group. Priority is sorted from small to large and bandwidth is allocated dynamically.

[0168] In this embodiment, the wireless router access management system significantly improves network security and resource utilization efficiency through multiple authentication and dynamic management mechanisms. The system first collects the first behavior feature data and network status data of the device, combines the convolutional neural network (CNN) model for intelligent analysis, and judges the security of the access device in real time. For devices that meet security standards, the system automatically allocates bandwidth and provides continuous network services. For abnormal devices, the system will block their access in time through multiple rounds of authentication and load evaluation to ensure the security and stability of the network environment.

[0169] In terms of bandwidth management, the system uses the second access security index of the access device It intelligently sorts and dynamically allocates bandwidth resources based on the needs of different devices and bandwidth requirements, avoiding the inefficiency and resource waste of traditional static allocation methods. This priority scheduling method based on real-time data and behavioral characteristics not only improves the utilization of network resources, but also optimizes the quality of network services and ensures the bandwidth needs of priority devices.

[0170] A wireless router includes one or more radio devices, a controller and an authentication server, wherein the controller is used to execute the above method steps, and the authentication server is used to execute a first authentication instruction and a second authentication instruction. The authentication server also processes and stores behavior characteristic data and a first access security index. and the second access security index , supports dynamic bandwidth allocation. When a device is connected, the system adjusts bandwidth resources according to the security priority of the device to ensure fair distribution of network resources while guaranteeing the network needs of high-quality devices.

[0171] The threshold is set to facilitate comparison. The size of the threshold depends on the amount of sample data and the number of bases set by technicians in this field for each group of sample data; as long as it does not affect the proportional relationship between the parameter and the quantized value.

[0172] The above formulas are obtained by collecting a large amount of data for software simulation and selecting a formula that is close to the actual value. The coefficients in the formula are set by technical personnel in this field according to actual conditions. The above is only a preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited to this. Any technical personnel familiar with the technical field within the technical scope disclosed by the present invention, according to the technical solution and the inventive concept of the present invention, make equivalent replacement or change, which should be covered within the protection scope of the present invention.

Claims

1. A wireless router access management method, characterized in that: The following steps are involved: S1. Pre-build a multi-device access management system, which includes multiple access devices and a wireless router. The wireless router is electrically connected to the multiple access devices after communicating and configuring through multiple frequency channels. The multiple frequency channels include 2.4 GHz, 5 GHz and 6 GHz. The access device is connected through a plurality of channel networks; upon initial access, first behavior characteristic data of the access device is collected, the first behavior characteristic data including channel switching frequency, packet transmission interval and protocol stack characteristic data, the first behavior characteristic data is standardized to generate behavior characteristic data, and the behavior characteristic data is encrypted to generate a first behavior fingerprint library; S2, collecting real-time behavior data of the access device in real time, and summarizing and forming a first behavior matching index M by comparing the real-time behavior data of the access device with the behavior characteristic data in the first behavior fingerprint library; A behavior matching threshold T is preset. If the first behavior matching index M exceeds the behavior matching threshold T, it indicates that the access device behavior is normal. Otherwise, it indicates that the access device behavior is abnormal, and a first authentication instruction is generated and executed. S3, collecting network status data of access devices, using convolutional neural network CNN to build and train behavior recognition model, combining network status data and first behavior matching index M, generating first access security index A1 for each access device, and presetting first risk threshold Q1, when first access security index A1 ≥ first risk threshold Q1, determining that the current access device is abnormal, disconnecting network service, generating and executing second authentication instruction; S3 includes: S31. Through network performance analysis tools, including NetFlow and SNMP; Real-time collection of network status data of access devices, including: network rate V s , communication delay V y , Packet loss rate V d , disconnection times V dk and reconnection frequency V cl ; S32, normalizing the network status data, converting the network status data into time-series CNN format data, and dividing the time-series CNN format data into segments of fixed sizes through a sliding window; S33. Use a convolutional neural network (CNN) to build a behavior recognition model. After training the behavior recognition model using time-series CNN format data, combine the first behavior matching index M and calculate the first access security index A1 of each access device using the following formula: In the formula, Indicates the standard network rate threshold. Indicates the maximum tolerated network delay threshold. Indicates the maximum tolerable packet loss rate threshold. Indicates the maximum tolerated disconnection times threshold. represents the standard reconnection frequency threshold, T represents the behavior matching threshold; a1, a2, a3, a4, a5 and a6 represent weight values, and a1+a2+a3+a4+a5+a6=1; S4. After the second authentication instruction is executed, the communication load data of the access device is further collected, and the second access security index A2 is generated in combination with the first access security index A1, and the second risk threshold Q2 is preset to perform a secondary judgment on the second access security index A2; if the second access security index A2 ≥ the second risk threshold Q2, the access device is judged to be an abnormal device and the access is terminated; if the second access security index A2 < the second risk threshold Q2, a qualified mark is generated, and the current allocation of network resources and network services is continued; at the same time, the access devices that generate qualified marks are counted to establish a qualified mark group; and the second access security index A2 in the qualified mark group is sorted according to priority from small to large, and bandwidth is dynamically allocated.

2. The wireless router access management method according to claim 1, characterized in that: S1 includes: S11, constructing multiple channels in the wireless router in advance to perform network configuration, dividing and numbering each channel, and configuring basic communication parameters, wherein the basic communication parameters include bandwidth, power, and signal range; S12, when the access device is connected to the wireless router for the first time, automatically starting the first behavior feature data collection action to analyze the initial connection behavior of the terminal device; The first behavior characteristic data includes: channel switching frequency; the number of times the detection device switches channels in a short period of time; Packet sending interval: measures the time interval between terminal devices sending data packets; Protocol stack characteristic data: Protocol stack characteristic data includes communication protocol stack layer and packet header field information; The communication protocol stack layers include transport layer protocol type, network layer protocol type and application layer protocol type; Transport layer protocol types include TCP and UDP protocols; Network layer protocol types include IPv4 and IPv6 protocols; Application layer protocol types include HTTP, HTTPS, MQTT and CoAP protocols; The packet header field information includes the transport layer packet header field length, the network layer packet header field length and the application layer packet header field length.

3. The wireless router access management method according to claim 2, characterized in that: S1 also includes: S13, standardizing the first behavior feature data collected in S12, and removing abnormal data to generate behavior characteristic data for identifying the behavior pattern of the terminal device; S14, using the symmetric encryption algorithm RSA or ECC to encrypt the generated behavior characteristic data; S15, storing the encrypted behavior characteristic data in the local storage of the wireless router to form a first behavior fingerprint library; S16: Establish an index table of the first behavior fingerprint library in the wireless router for matching and retrieval.

4. The wireless router access management method according to claim 1, characterized in that: S2 includes: S21, collecting real-time behavior data of the access device in real time, and comparing the real-time behavior data of the access device with the data in the first behavior fingerprint library, the real-time behavior data including: the real-time collected transport layer header field length, network layer header field length, application layer header field length, real-time channel switching frequency and real-time packet sending interval; S21 specifically includes: S211, compare the real-time collected transport layer header field length, network layer header field length and application layer header field length, compare with the first behavior fingerprint library, and calculate the transport layer protocol similarity S by the following formula t , network layer protocol similarity S n Similarity S with application layer protocol α : Where N t Indicates the total number of words in the transport layer header field length, δ t,i Indicates the transport layer header field matching result of the i-th field. If the field values ​​are consistent, then δ t,i =1, otherwise δ t,i =0; N n Indicates the total number of words in the network layer header field length, δ n,i Indicates the network layer header field matching result of the i-th field. If the field values ​​are consistent, then δ n,i =1, otherwise δ n,i =0; N α Indicates the total length of the application layer header field, δ α,i Indicates the application layer header field matching result of the i-th field. If the field values ​​are consistent, then δ α,i =1, otherwise δ α,i =0; S212, extracting transport layer protocol similarity S t , network layer protocol similarity S n Similarity S with application layer protocol α After dimensionless processing, the protocol stack similarity S is calculated by the following associated formula xy : S xy =S t *w1+S n *w2+S α *w3; Where w1, w2 and w3 represent the transport layer protocol similarity S t , network layer protocol similarity S n Similarity S with application layer protocol α ’s weight, and w1+w2+w3=1.

5. The wireless router access management method according to claim 4, characterized in that: The S21 also includes: S213, extracting the real-time channel switching frequency and the real-time packet transmission interval in the real-time behavior data; and calculating the frequency similarity S by the following formula xd Similarity S to the packet sending interval fb : In the formula, F xd Indicates the real-time channel switching frequency, F c represents the channel switching frequency in the first fingerprint library, ∈ is a small constant to avoid the denominator being zero; I ss Indicates the real-time packet sending interval, I c represents the packet sending interval in the first fingerprint database, σ represents the interval tolerance, and exp represents the Euler number, which is set to 2.718; S214, extracting the protocol stack similarity S calculated in S212 xy Combined with the frequency similarity S calculated in S213 xd Similarity S to the packet sending interval fb , after dimensionless processing, the first line matching index M is calculated by the following formula; M=S xy *β1+S xd *β2+S fb *β3; Where β1, β2 and β3 represent the protocol stack similarity S xy , frequency similarity S xd Similarity S to the packet sending interval fb The weight of , and β1+β2+β3=1; S215. Preset a behavior matching threshold T. If the first behavior matching index M> the behavior matching threshold T, it indicates that the behavior of the access device is normal; if the first behavior matching index M≤ the behavior matching threshold T, it indicates that the behavior of the access device is abnormal, and a first authentication instruction is generated, including: guiding the access device to update its communication protocol stack version and requiring the access device to use a password + dynamic verification code for authentication, starting the network service and allocating network resources. If the authentication fails, terminating its access.

6. The wireless router access management method according to claim 1, characterized in that: S3 also includes: S34, presetting a first risk threshold Q1, comparing the first access security index A1 of each access device with the first risk threshold Q1, and obtaining a first determination result, including: When the first access security index A1 is less than the first risk threshold Q1, the current access device is determined to be safe, and the current allocation of network resources and network services is continued; When the first access security index A1 ≥ the first risk threshold Q1, the current access device is determined to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed, including: after triggering the access device to restart, after combining the access device password, fingerprint recognition and facial authentication, the network service is started and network resources are allocated. If the authentication fails, the access is terminated.

7. The wireless router access management method according to claim 1, characterized in that: S4. After the second authentication instruction is executed, use network traffic analysis tools, including Wireshark or ntopng, to further collect communication load data of the access device. The communication load data includes: uplink traffic S sll and downstream traffic S xll ; And extract the upstream traffic S sll and downstream traffic S xll , associate the first access security index A1, and generate the second access security index A2 through the following association formula: In the formula, S llb It represents the sum of the maximum uplink and downlink traffic thresholds, γ and ρ are weight values, and γ+ρ=1; Presetting a second risk threshold Q2, and comparing the second access security index A2 with the second risk threshold Q2 to obtain a second determination result, including: If the second access security index A2 ≥ the second risk threshold Q2, the access device is determined to be an abnormal device and its access is terminated; If the second access security index A2 is less than the second risk threshold Q2, the access device is determined to be a secure device, a qualified mark is generated, and the current allocation of network resources and network services is continued; At the same time, the access devices that generate qualified tags are counted to establish a qualified tag group, and the second access security indexes A2 in the qualified tag group are sorted in order of priority from small to large, and bandwidth is dynamically allocated.

8. A wireless router access management system, used to implement the wireless router access management method according to any one of claims 1 to 7, characterized in that: include: The device access management module is used to pre-build a multi-device access management system, which includes multiple access devices and a wireless router. The wireless router is electrically connected to the multiple access devices after communicating and configuring through multiple channels, and processes the configuration and authentication of the access devices when they are connected for the first time. A behavior characteristic collection module, used for collecting first behavior characteristic data of an access device when accessing for the first time, wherein the first behavior characteristic data includes a channel switching frequency, a packet transmission interval, and a protocol stack characteristic data, and after standardizing the first behavior characteristic data, generating behavior characteristic data, and encrypting the behavior characteristic data to generate a first behavior fingerprint library; A real-time behavior matching module is used to collect real-time behavior data of access devices in real time, and to form a first behavior matching index M by comparing the real-time behavior data of access devices with data in the first behavior fingerprint library; A behavior matching threshold T is preset. If the first behavior matching index M exceeds the behavior matching threshold T, it indicates that the access device behavior is normal. Otherwise, it indicates that the access device behavior is abnormal, and a first authentication instruction is generated and executed. A network status data collection module is used to collect network status data of access devices; The dynamic authentication module uses the convolutional neural network CNN to build and train a behavior recognition model, combines the network status data and the first behavior matching index M, generates a first access security index A1 for each access device, and presets a first risk threshold Q1. When the first access security index A1 ≥ the first risk threshold Q1, the current access device is judged to be abnormal, the network service is disconnected, and a second authentication instruction is generated and executed; A communication load collection module, used to further collect communication load data of the access device after the second authentication instruction is executed, and generate a second access security index A2 in combination with the first access security index A1; A secondary determination module, used for performing a secondary determination on a second access security index A2 by presetting a second risk threshold Q2; If the second access security index A2 ≥ the second risk threshold Q2, the access device is determined to be an abnormal device and its access is terminated; If the second access security index A2 is less than the second risk threshold Q2, a qualified mark is generated, and the current allocation of network resources and network services is continued; The bandwidth allocation and priority scheduling module is used to count the access devices that generate qualified tags, establish a qualified tag group, sort the second access security index A2 in the qualified tag group from small to large, and dynamically allocate bandwidth.

9. A wireless router, characterized in that: It comprises one or more radio devices, a controller and an authentication server; the controller is used to execute the steps of a wireless router access management method described in any one of claims 1-7, and the authentication server is used to execute a first authentication instruction and a second authentication instruction.

Citation Information

Patent Citations

  • Remote management method and system of wireless router

    CN117560701A