Method and apparatus for secure access to a wireless network

By employing a two-way verification method involving beacon frames, probe frames, authentication frames, and association frames in WLAN access authentication, and utilizing product identification and random number encryption/decryption technology, the problem of weak security in WLAN access authentication is solved, thus achieving security protection for wireless communication systems.

CN119584109BActive Publication Date: 2025-11-18WUHAN INTELLIGENCE METRO TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411667500.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-21
Publication Date
2025-11-18
Estimated Expiration
2044-11-21

AI Technical Summary

Technical Problem

WLAN access authentication is weak and vulnerable to unauthorized access by attackers, posing a security threat to rail transit wireless communication systems.

Method used

Two-way verification is performed using management frames such as beacon frames, probe frames, authentication frames, and association frames. The legitimacy is verified by encrypting and decrypting product identifiers, random numbers, and dynamic key data, thus preventing phishing attacks, replay attacks, and man-in-the-middle attacks.

Benefits of technology

Effectively prevents unauthorized access, reduces access risks, and ensures the security and stability of wireless communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119584109B_ABST
    Figure CN119584109B_ABST
Patent Text Reader

Abstract

The application discloses a wireless network security access method and device, and belongs to the field of wireless communication. The method comprises the following steps: receiving a beacon frame sent by a second device, wherein the beacon frame comprises a first data field generated and encrypted by the second device, the first data field comprises product identification, a first random number obtained based on a random number generation algorithm and dynamic key data; the first device parses the first data field from the beacon frame and decrypts the first data field to obtain plaintext, and determines the legality of the beacon frame according to the product identification in the plaintext; when the beacon frame is legal, the dynamic key data is stored in a security module, a second random number is obtained by using a random number processing algorithm on the first random number, a second data field is generated by using the product identification, the second random number and a key installation result state code and is encrypted, and the beacon response frame is packaged and sent. In the method, the random number carried by the beacon response frame simulated and sent by an intruder cannot pass the verification of the second device, so that the legality of the first device can be effectively determined.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wireless communication, and more particularly to a method and apparatus for secure access to a wireless network. Background Technology

[0002] With the development of wireless communication technology, WLAN technology is being used more and more widely in various industries. A typical application scenario is wireless communication between rail transit trains and the ground. As people's living standards improve, their demand for safe travel is also increasing, and the services carried by rail transit wireless communication are constantly expanding.

[0003] However, WLAN's access authentication security is relatively weak. Attackers can use specialized tools to eavesdrop and sniff the wireless network, executing various attack methods including phishing, brute-force attacks, man-in-the-middle attacks, and password resets. These attacks can crack or reset WLAN access authentication passwords, allowing attackers to access the rail transit wireless communication system without hindrance, thereby carrying out illegal attacks and damage. Such illegal access poses a serious threat to the safe operation of rail transit services. Summary of the Invention

[0004] The main objective of this invention is to propose a secure access authentication method and device for rail transit wireless networks, based on traditional WLAN access authentication, to solve the problem of WLAN being easily accessed illegally under current technological conditions.

[0005] This invention provides a secure access method for a wireless network, comprising: receiving a beacon frame sent by a second device, the beacon frame including a first data field generated and encrypted by the second device, the first data field including a product identifier, a first random number obtained based on a random number generation algorithm, and dynamic key data; parsing the first data field from the beacon frame and decrypting it to obtain plaintext, and determining the legitimacy of the beacon frame based on the product identifier in the plaintext; if the beacon frame is legitimate, storing the dynamic key data in a security module, and using a random number processing algorithm on the first random number to obtain a second random number, generating a second data field from the product identifier, the second random number, and a key installation result status code, encrypting it, and adding it to a beacon response frame for packaging and sending; wherein, the beacon response frame is used by the second device to decrypt the second data field after receiving it, and to determine the legitimacy of the beacon response frame based on the key installation result status code, the consistency of the product identifier, and the verification result of the consistency between the processing result of the second random number based on the inverse random number processing algorithm and the first random number; wherein, both the first device and the second device pre-store the product identifier and an initial encryption / decryption key, the initial key being used for encryption and decryption of the data field.

[0006] In the wireless network security access method of the present invention, after being packaged and sent in a beacon response frame, the method further includes: generating a third data field based on the product identifier, a third random number obtained by a random number generation algorithm, and an authorization code, encrypting it, and then packaging and sending it in a probe frame; if a probe response frame sent by the second device is received, the fourth data field is decrypted to obtain the product identifier, the fourth random number, and the authorization code verification result identifier; product identifier verification, authorization code verification result identifier verification, and consistency verification of the processing result of the fourth random number based on the random number inverse processing algorithm with the third random number are performed, and the legality of the probe response frame is determined based on the verification results; wherein, the second device pre-stores an authorization code table for multiple devices, each authorization code corresponding one-to-one with a MAC address; after receiving the probe frame, the second device decrypts the third data field and verifies the legality of the probe frame based on the product identifier, authorization code, and the MAC address of the first device; if the probe frame is legal, the third random number is processed by a random number processing algorithm to obtain a fourth random number, and the fourth data field is generated based on the product identifier, the fourth random number, and the authorization code verification result, encrypted, and then packaged and sent in a probe response frame.

[0007] In the wireless network secure access method of the present invention, the dynamic key data is a key group including multiple keys, each key having a one-to-one corresponding key ID. Accordingly, after determining the legality of the probe response frame based on the verification result, the method further includes: selecting a configuration key from the key group, generating a fifth data field based on the product identifier, a fifth random number obtained by a random number generation algorithm, and the key ID of the configuration key, encrypting it, adding it to the authentication frame, and sending it; if an authentication response frame sent by the second device is received, decrypting the sixth data field therein to obtain the product identifier, the sixth random number, and the key ID; performing product identifier verification, key ID verification, and the sixth random number based on the random number... The consistency of the processing result of the inverse processing algorithm with the fifth random number is checked, and the legality of the authentication response frame is determined based on the verification result. If the authentication response frame is confirmed to be legal, the configuration key is used for encryption and decryption of subsequent data fields. Specifically, after receiving the authentication frame, the second device decrypts the fifth data field and verifies the legality of the probe frame based on the product identifier and key ID. If the authentication frame is legal, a random number processing algorithm is applied to the fifth random number to obtain a sixth random number. A sixth data field is generated based on the product identifier, the sixth random number, and the key ID. After encryption, the data field is added to the authentication response frame, packaged, and sent. The configuration key is then used for encryption and decryption of subsequent data fields.

[0008] In the wireless network secure access method of the present invention, after determining the legality of the authentication response frame based on the verification result, the method further includes: if the authentication response frame is legal, generating a seventh data field based on the product identifier, a seventh random number obtained by a random number generation algorithm, an authorization code, and a key ID, encrypting it, and adding it to the associated frame for packaging and sending; if an associated response frame sent by the second device is received, decrypting the eighth data field therein based on a new encryption / decryption key to obtain the product identifier, the eighth random number, and the associated status identifier; verifying the consistency between the product identifier, the associated status identifier, and the processing result of the eighth random number based on the inverse random number processing algorithm and the seventh random number, and determining the legality of the associated response frame based on the verification result; if the associated response frame is confirmed to be legal, determining whether the access is successful based on the associated status identifier; wherein, after receiving the associated frame, the second device decrypts the seventh data field and verifies the legality of the probe frame based on the product identifier, the authorization code, and the key ID; if the associated frame is legal, using a random number processing algorithm on the seventh random number to obtain an eighth random number, generating an eighth data field based on the product identifier, the eighth random number, and the associated status identifier, encrypting it, adding it to the associated response frame for packaging and sending.

[0009] In the wireless network secure access method of the present invention, the encryption and decryption process of each data field adopts a symmetric encryption and decryption algorithm.

[0010] In the wireless network security access method of the present invention, the method further includes sending feedback information to the sender of the management frame after the management frame validity verification fails, so that the sender can resend the management frame. After the management frame validity verification fails a preset number of times, communication with the device that sent the corresponding frame will cease. The management frame includes beacon frames, probe frames, authentication frames, association frames and their corresponding response frames, and the preset number of times includes 3 times.

[0011] In the wireless network security access method of the present invention, the random number generation algorithm includes: S n =(S n-1 +IV)mod0xffff; where S0 is the first random number generated after the system is powered on, IV is a constant, n is an integer greater than 0, and mod is the modulo operation.

[0012] In the wireless network security access method of the present invention, the random number processing algorithm includes XORing the random number to be processed with a preset number of bits of the product identifier; correspondingly, the random number inverse processing algorithm includes XORing the random number to be processed with a preset number of bits of the product identifier again.

[0013] The present invention also provides a secure access device for a wireless network, comprising: a data transceiver module for receiving a beacon frame sent by a second device, the beacon frame including a first data field generated and encrypted by the second device, the first data field including a product identifier, a first random number obtained based on a random number generation algorithm, and dynamic key data; an encryption / decryption module for parsing the first data field from the beacon frame and decrypting it to obtain plaintext; a data processing module for determining the legitimacy of the beacon frame based on the product identifier in the plaintext; a data security module for storing the dynamic key data if the beacon frame is legitimate; and a data field generation module for using a random number processing algorithm to obtain a second random number from the first random number, and generating a second data field from the product identifier, the second random number, and the key installation result status code, for encryption by the encryption / decryption module and then adding it to a beacon response frame for packaging and transmission by the data transceiver module.

[0014] The present invention also provides a computer storage medium storing a computer program executable by a processor, the computer program executing any of the above-described wireless network security access methods.

[0015] The beneficial effects of this invention are as follows: the first random number carried in each beacon frame corresponds one-to-one with the second random number in the beacon response frame, and each frame is different. The random number carried in the beacon response frame simulated by an intruder cannot pass the verification of the second device, while the random number carried in the legitimate beacon response frame can be restored to a random number consistent with the first random number through the inverse random number processing algorithm. This effectively verifies the legitimacy of the access device and allows for dynamic key updates through legitimate management frames. Furthermore, the verification is bidirectional; neither simulated access terminals nor simulated access point devices can successfully connect to our device. This method effectively prevents phishing attacks, replay attacks, man-in-the-middle attacks, and password reinstallation attacks, reducing access risks. Attached Figure Description

[0016] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0017] Figure 1 This is a flowchart illustrating the secure wireless network access method according to an embodiment of the present invention;

[0018] Figure 2 This is a schematic diagram of the beacon frame verification process according to an embodiment of the present invention;

[0019] Figure 3 This is a diagram of the dynamic key data format according to an embodiment of the present invention;

[0020] Figure 4 This is a schematic diagram of the key group to be configured according to an embodiment of the present invention;

[0021] Figure 5 This is a schematic diagram of the beacon frame structure according to an embodiment of the present invention;

[0022] Figure 6 This is a schematic diagram of the management frame legality verification process according to an embodiment of the present invention;

[0023] Figure 7 This is a schematic diagram of the key installation result status code according to an embodiment of the present invention;

[0024] Figure 8 This is a schematic diagram of the beacon response frame structure according to an embodiment of the present invention;

[0025] Figure 9 This is a schematic diagram of the detection frame verification process according to an embodiment of the present invention;

[0026] Figure 10 This is a schematic diagram of the basic data of an embodiment of the present invention;

[0027] Figure 11 This is a schematic diagram of the detection frame structure according to an embodiment of the present invention;

[0028] Figure 12 This is a schematic diagram illustrating the authorization verification result code of an embodiment of the present invention;

[0029] Figure 13 This is a schematic diagram of the probe response frame structure according to an embodiment of the present invention.

[0030] Figure 14 This is a schematic diagram of the authentication frame verification process according to an embodiment of the present invention.

[0031] Figure 15 This is a schematic diagram of the authentication frame structure according to an embodiment of the present invention;

[0032] Figure 16 This is a diagram of the authentication response frame structure according to an embodiment of the present invention;

[0033] Figure 17 This is a schematic diagram of the associated frame verification process according to an embodiment of the present invention.

[0034] Figure 18 This is a schematic diagram of the associated frame structure according to an embodiment of the present invention;

[0035] Figure 19 This is a relational state identifier definition diagram according to an embodiment of the present invention;

[0036] Figure 20 This is a diagram of the associated response frame structure according to an embodiment of the present invention;

[0037] Figure 21 This is a schematic diagram of the structure of a wireless network security access device according to an embodiment of the present invention. Detailed Implementation

[0038] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. The following description, in conjunction with... Figures 1 to 21 The wireless network security access method and apparatus of the present invention will be described.

[0039] The application process of this invention includes two devices, a first device and a second device, both of which can be used to send and receive wireless data. The secure access method for wireless networks is achieved by using these two devices to send and receive management frames and perform bidirectional authentication. The first and second devices mainly include the following functional modules: a data domain generation module, an encryption / decryption module, a data transmission / reception module, a data processing module, and a data security module.

[0040] Generally, devices installed on the train are access terminal equipment, while those installed beside the track are access point equipment. If the first device is installed on the train, then the second transceiver is installed beside the track at intervals. The first and second devices can be interchanged. If the first device is installed on the train, it is equivalent to an access terminal equipment, and the corresponding second device must be installed beside the track, equivalent to an access point equipment. Alternatively, the first device can be installed beside the track at intervals, in which case it is equivalent to an access point equipment, and the corresponding second device must be installed on the train, equivalent to an access terminal.

[0041] Here, the first and second devices can both send and receive management frames and management response frames. They have a corresponding data transmission and reception relationship: when the first device sends a management frame, the second device receives it, and vice versa. Similarly, when the first device sends a management response frame, the second device receives it, and vice versa. To more clearly describe the specific secure access authentication process, we assume the first device is installed on the train, representing the access terminal equipment, and the corresponding second device is installed beside the track, representing the access point equipment. Figure 1 This is a flowchart illustrating the secure wireless network access method according to an embodiment of the present invention, as shown below. Figure 1 As shown, the method is applied to a first device, and the method includes:

[0042] S1. Receive a beacon frame sent by the second device. The beacon frame includes a first data field generated and encrypted by the second device. The first data field includes a product identifier, a first random number obtained based on a random number generation algorithm, and dynamic key data.

[0043] Both the first and second devices pre-store product identifiers and initial encryption / decryption keys. The initial keys are used for encryption and decryption of the data field. The dynamic key group data is initially stored in the second device, and the dynamic key group data is not the same as the initial key.

[0044] Before S1, the second device generates and sends a beacon frame, and then in S1 the first device receives and processes the beacon frame.

[0045] In the specific implementation process, the flowchart of the interaction steps with the second device is as follows: Figure 2 As shown, the second device first generates a custom data field (referred to as the first data field here for clarity, and similar descriptions will follow) based on the product's unique identification data, a first random number generated by a random number generation algorithm, dynamic key data, and other data. The dynamic key data may include 16 sets of key data, each set consisting of a one-byte ID number and a 32-byte key, such as... Figure 3 As shown. The 16 sets of key data can be organized in order of ID number, as detailed below. Figure 4 As shown.

[0046] In one embodiment, the encryption and decryption process of each data field adopts a symmetric encryption and decryption algorithm, which will be used as an example below.

[0047] The custom data field is encrypted using a symmetric encryption algorithm (the encryption uses the initial key mentioned above, which is different from the dynamic key data). The generated ciphertext is added to the original IEEE 802.11 protocol beacon frame to form a new beacon frame. The new beacon frame conforms to the IEEE 802.11 standard. The well-organized beacon frame is as follows: Figure 5 As shown. Then, the second device sends new beacon frame data to the first device, the new beacon frame carrying an encrypted custom data field.

[0048] S2. Parse the first data field from the beacon frame and decrypt it to obtain plaintext. Determine the legitimacy of the beacon frame based on the product identifier in the plaintext.

[0049] Upon receiving a new beacon frame, the first device first parses out the custom data field, then decrypts it using a symmetric encryption / decryption algorithm to obtain the plaintext product-specific identification data, random number, and dynamic key data. In step S2, the beacon frame is verified. If verification fails, the process returns to step XB001 (e.g., by sending a beacon frame error feedback message to the second device, causing the second device to resend the beacon frame, thus re-executing XB001).

[0050] In one embodiment, the method further includes sending feedback information to the sender of the management frame after the management frame validity verification fails, so that the sender can resend the management frame; after the management frame validity verification fails a preset number of times, communication with the device that sent the corresponding frame is stopped; wherein, the management frame includes beacon frames, probe frames, authentication frames, association frames and their corresponding response frames, and the preset number of times includes 3 times.

[0051] Beacon frames, probe frames, authentication frames, association frames, and their corresponding response frames all fall under the category of management frames. However, for descriptive purposes, this paper defines their response frames as beacon response frames, probe response frames, authentication response frames, and association response frames, respectively. For example... Figure 6 As shown, the beacon frame process is executed first. Beacon frame verification is primarily used to load the dynamic key group data into the access terminal's security module. If the beacon frame verification fails, the current verification continues. After three consecutive verification failures, the system displays an error message. If the beacon frame verification is successful, the subsequent process proceeds. By retransmitting management frames multiple times, data frame errors caused by communication links can be avoided.

[0052] If the beacon frame received by the first device does not contain a custom data field, it indicates that the first device is a fake device. If the beacon frame received by the first device contains a custom data field, the last four bits of the product-specific identification data obtained after decryption are compared with the last four bits of the product-specific identification stored in the device. If they are the same, the subsequent operations continue; otherwise, return to step XB001. If verification errors occur more than three times consecutively, the first device can be determined to be a fake device. The second device will no longer communicate with it.

[0053] S3. If the beacon frame is valid, store the dynamic key data in the security module, and use a random number processing algorithm to obtain a second random number from the first random number. Generate a second data field by combining the product identifier, the second random number, and the key installation result status code, encrypt it, and add it to the beacon response frame for packaging and sending.

[0054] The beacon response frame is used by the second device to decrypt the second data field after receiving it, and to determine the legality of the beacon response frame based on the password installation result status code, product identification consistency, and the verification result of the consistency between the processing result of the second random number based on the random number inverse processing algorithm and the first random number.

[0055] In one embodiment, the random number processing algorithm includes XORing the random number to be processed with a preset number of digits of the product identifier; correspondingly, the inverse random number processing algorithm includes XORing the random number to be processed with a preset number of digits of the product identifier again. The random number can be four digits, and the preset number of digits can be the last four digits of the product identifier; this will be used as an example in the following description.

[0056] The first device, upon successful verification, first stores the dynamic key data in the security module. Based on the aforementioned random number processing algorithm, it XORs the received first random number with the last 4 bytes of the product-specific identifier to generate a new random number (the second random number). This new random number, the product-specific identifier data, and the key installation result status code data are then combined to generate a custom data field (the second data field), where the specific information of the key installation result status code is as follows: Figure 7 As shown, 01 indicates that the key was successfully installed, 02 indicates that the key verification was incorrect, and 03 indicates that the key installation process was incorrect.

[0057] The custom data field generated by the first device is encrypted using a symmetric encryption algorithm. The resulting ciphertext is added to the response frame of the original IEEE 802.11 protocol beacon frame, forming a new beacon response frame. The new beacon response frame conforms to the IEEE 802.11 standard, and its specific format is as follows: Figure 8 Then, the first device sends a new beacon response frame carrying an encrypted custom data field to the second device.

[0058] Upon receiving a new beacon response frame, the second device decrypts it using a symmetric decryption algorithm to obtain product-specific identification data, a random number, and a key installation result status code. It then verifies the key installation result status code; if an error occurs, it returns to XB001. Next, it verifies the product-specific identification data; if this also fails, it returns to XB001. If both verifications are successful, it compares the received random number with the original random number (generated by XB001). If they differ, it returns to XB001; otherwise, it continues with subsequent verification procedures.

[0059] The second device verification process: If the beacon response frame received by the second device does not contain a custom data field, it indicates that the first device is a fake device. If the beacon response frame received by the second device contains a custom data field, traditionally, the beacon frame is sent every 40ms by default. To improve and speed up data communication efficiency, if the key installation result status code obtained after decryption is not 0x01, it indicates that the dynamic key data installation of the first device has failed. The second device immediately sends a beacon frame to the first device and repeats the above steps. If three verification errors are sent, a key installation error is indicated, and communication with the first device is stopped. If the verification is correct, the product-specific identification data is verified. The last four bits of the product-specific identification data are compared with the last four bits of the product-specific identification data stored in the device. If they are different, the process returns to step XB001. If they are the same, the process continues. The received random number is XORed with the last four bytes of the product-specific identification data. The value obtained by XORing is compared with the original random number (the random number generated by XB001). If they are the same, the process continues. If more than three consecutive random number verification errors occur, the first device can be determined to be a fake device, and the second device will no longer communicate with it.

[0060] Suppose an intruder obtains all beacon frames and beacon response frames exchanged between the first and second devices via a wireless eavesdropping device. Having acquired this data, the intruder has two possibilities for attack: either impersonating our first device (the access terminal) or impersonating our second device (the access point device). For ease of description, T1 will be used to denote the fake device used by the intruder. If an intruder impersonates our first device and attempts to access our wireless system (access the second device) in this way, beacon frame verification must first be performed. That is, the second device sends an encrypted beacon frame with a custom data field to T1. T1 then simulates sending the beacon response frame heard in the previous frame to the second device. The beacon response frame will definitely contain the encrypted custom data field, but the random number verification obtained by the second device after decrypting the data will definitely fail. This is because the random number carried by each beacon response frame received by our device is temporarily generated based on the random number of the sending device. The random number carried by each beacon frame corresponds one-to-one with the random number of its corresponding beacon response frame, and each frame is different. Therefore, the random number carried by the beacon response frame simulated by the intruder sent by T1 cannot pass the verification of the second device. If the verification error occurs more than three times in a row, it can be determined that T1 is a fake device, and the second device will no longer communicate with it.

[0061] As can be seen, in the wireless network security access method of the present invention, the first random number is randomly generated by the second device, so the second random number that the beacon response frame should return should also be different at every moment. In addition, the returned second random number needs to be obtained based on the first random number using a random number processing algorithm. That is to say, even if a timely and valid first random number is obtained, a legitimate second random number cannot be obtained. It can be seen that the first random number carried by each beacon frame corresponds one-to-one with the second random number of the beacon response frame, and each frame is different. The random number carried by the beacon response frame simulated by the intruder cannot pass the verification of the second device, while the random number carried by the legitimate beacon response frame can be restored to a random number consistent with the first random number through the inverse random number processing algorithm. Thus, the legitimacy of the access device can be effectively verified, and the dynamic key data can be updated through a legitimate management frame.

[0062] In one embodiment, after adding the data to the beacon response frame and sending it, the method further includes: generating a third data field based on the product identifier, a third random number obtained by a random number generation algorithm, and an authorization code; encrypting the third data field and adding it to the probe frame for sending; if a probe response frame sent by the second device is received, decrypting the fourth data field to obtain the product identifier, the fourth random number, and the authorization code verification result identifier; performing product identifier verification, authorization code verification result identifier verification, and consistency verification of the processing result of the fourth random number based on the random number inverse processing algorithm with the third random number; and determining the legality of the probe response frame based on the verification results.

[0063] The second device pre-stores an authorization code table for multiple devices, with each authorization code corresponding to a MAC address. After receiving a probe frame, the second device decrypts the third data field and verifies the legitimacy of the probe frame based on the product identifier, authorization code, and the MAC address of the first device. If the probe frame is legitimate, the second device uses a random number processing algorithm to obtain a fourth random number from the third random number. Based on the product identifier, the fourth random number, and the verification result of the authorization code, the second device generates a fourth data field, encrypts it, and adds it to the probe response frame for packaging and transmission.

[0064] After the beacon frame verification is successful, the probe frame verification begins, primarily to confirm that the access terminal is an authorized device. This can be done using the three-step verification method described above. If the probe frame verification fails, the current verification continues. After three consecutive failed verifications, the system will display an error message. Once the probe frame verification is successful, the following process will proceed.

[0065] The specific implementation steps are as follows: Figure 9 As shown, the first device generates a custom data field (third data field) based on the product's unique identifier, a random number generated by a random number algorithm (third random number), and an authorization code, among other data. The authorization code is system-generated and indicates a legitimate authorized product; this authorization code is unique for each product. The second device pre-stores the basic data from the first device, such as... Figure 10 As shown (n represents the maximum number of records, which can be set to a default maximum of 1000 basic data entries, and the specific number can be configured), the basic data includes the MAC address and authorization code of the first device (the basic data can be imported via network or other means). The custom data field is encrypted using a symmetric encryption algorithm, and the generated ciphertext is added to the original IEEE 802.11 protocol probe frame to form a new probe frame. The new probe frame conforms to the IEEE 802.11 standard, and the specific format is as follows: Figure 11 It should be noted that, similar to the beacon frame, the encryption key used here is the initial key.

[0066] The first device sends a new probe frame to the second device, carrying an encrypted custom data field (third data field). Upon receiving the new probe frame, the second device first parses the custom data field (third data field), then decrypts it using a symmetric encryption / decryption algorithm to obtain product-specific identification data, a third random number, and the authorization code from the first device. The product-specific identification data is verified; if verification fails, the process returns to step TC001; if verification succeeds, the authorization code is verified. If authorization code verification fails, the process returns to step TC001. Upon successful verification, the received random number is XORed with the last 4 bytes of the product-specific identification data to generate a new random number (fourth random number). This new random number, the product-specific identification data, and the authorization code verification result identifier are then combined to generate the custom data field (fourth data field). The specific information of the authorization code verification result identifier can be set as follows: Figure 12 As shown, 0x01 indicates successful authorization code verification, 0x02 indicates the authorization code does not exist, 0x03 indicates the MAC address does not exist, and 0x04 indicates an error in the authorization code verification process. The probe response frame format is as follows: Figure 13 As shown.

[0067] During the verification process, if the probe frame received by the second device does not contain a custom data field, it indicates that the first device is a fake device. If the probe frame received by the second device contains a custom data field, the last four bits of the product-specific identification data obtained after decryption are compared with the last four bits of the product-specific identification data stored in the device. If they are the same, the subsequent operations continue; otherwise, the process returns to step TC001. After the product-specific identification data verification is successful, the second device searches for the corresponding authorization code from the pre-stored basic data based on the MAC address of the first device in the IEEE 802.11 protocol header. The obtained authorization code is compared with the received authorization code. If they are the same, the authorization code verification is successful; otherwise, the first device can be determined to be a fake device, and the second device will no longer communicate with it.

[0068] If an intruder uses T1 to simulate our second device and attempts to gain access by deceiving our first device, then according to Figure 6 The process involves two steps: After beacon frame verification, the first device performs probe frame verification. The first device sends a probe frame to T1, and T1 sends back a previously detected probe response frame. However, the random number carried in this response frame does not correspond to the random number generated by the first device, causing the verification to fail. Similarly, if three or more verification errors occur consecutively, T1 is determined to be a fake device, and the first device will cease communication with it. As described above, T1 cannot successfully connect to our device, whether simulating an access terminal or an access point device. Therefore, this two-way authentication effectively prevents phishing attacks, replay attacks, man-in-the-middle attacks, and password reinstallation attacks, reducing access risks.

[0069] In one embodiment, the dynamic key data is a key group comprising multiple keys, each key having a one-to-one corresponding key ID. Accordingly, after determining the legality of the probe response frame based on the verification result, the method further includes: selecting a configuration key from the key group, generating a fifth data field based on the product identifier, a fifth random number obtained by a random number generation algorithm, and the key ID of the configuration key, encrypting it, adding it to the authentication frame, and sending it; if an authentication response frame sent by the second device is received, decrypting the sixth data field therein to obtain the product identifier, the sixth random number, and the key ID; performing product identifier verification, key ID verification, and consistency verification between the processing result of the sixth random number based on the random number inverse processing algorithm and the fifth random number, and determining the legality of the authentication response frame based on the verification result; if the authentication response frame is confirmed to be legal, using the configuration key for subsequent encryption and decryption of each data field.

[0070] Upon receiving the authentication frame, the second device decrypts the fifth data field and verifies the legitimacy of the probe frame based on the product identifier and key ID. If the authentication frame is valid, it uses a random number processing algorithm to obtain a sixth random number from the fifth random number, and generates a sixth data field based on the product identifier, the sixth random number, and the key ID. After encryption, the data field is added to the authentication response frame and sent. The configuration key is then used for encryption and decryption of subsequent data fields.

[0071] After the probe frame verification is successful, the authentication frame verification will proceed. The authentication frame verification is mainly used to change the key for wireless communication of the management frame. If the authentication frame verification fails, the current verification will continue. If the verification fails three times in a row, the system will prompt an error. After the authentication frame verification is successful, the following process will proceed.

[0072] The specific verification process is as follows: Figure 14 As shown, the first device generates a custom data field (the fifth data field) based on the product's unique identification data, a random number generated by a random number algorithm (the fifth random number), and the key ID, etc., where the key ID is the ID in the dynamic key group, such as... Figure 5 As shown, the ID here is generated based on the key selection algorithm. The time period for each key change can be configured. This can be freely configured within the maximum and minimum timing periods, depending on the system's security needs. The maximum timing period is 1 year, and the minimum is 40ms. Generally, the smaller the configured timing period, the higher the system security level. The custom data field is encrypted using a symmetric encryption algorithm, and the generated ciphertext is added to the original IEEE 802.11 protocol authentication frame to form a new authentication frame. The new authentication conforms to the IEEE 802.11 standard, with the specific format as follows: Figure 15 .

[0073] It should be noted that, similar to beacon frames, the key used for symmetric encryption and decryption is the initial key. The first device sends new authentication frame data to the second device, which carries an encrypted custom data field (the fifth data field). Upon receiving the authentication frame data, the second device first parses the fifth data field, then decrypts it using a symmetric encryption / decryption algorithm to obtain product-specific identification data, a random number, and a key ID. The product-specific identification data is verified; if verification fails, the process returns to step RZ001; if verification succeeds, the key ID is verified. If key ID verification fails, the process returns to step RZ001. Upon successful verification, the received random number is XORed with the last 4 bytes of the product-specific identification data to generate a new random number. This new random number (the sixth random number), the product-specific identification data, and the received key ID are used to generate the custom data field (the sixth data field).

[0074] The specific verification process is as follows: If the authentication frame received by the second device does not contain a custom data field, it indicates that the first device is a fake device. If the authentication frame received by the second device contains a custom data field, the last four bits of the product-specific identification data obtained after decryption are compared with the last four bits of the product-specific identification data stored in the device. If they are the same, the subsequent operations continue; otherwise, the process returns to step RZ001. After the product-specific identification data verification is successful, the key ID is verified. Specifically, the received key ID must be within the range of 1 to 16; otherwise, the process returns to step RZ001. If the verification fails more than three times consecutively, the first device can be determined to be a fake device, and the second device will no longer communicate with it.

[0075] The custom data field generated by the second device is encrypted using a symmetric encryption algorithm. The resulting ciphertext is added to the original IEEE 802.11 protocol authentication response frame to form a new authentication response frame. The new authentication response frame conforms to the IEEE 802.11 standard, and its specific format is as follows: Figure 16 .

[0076] The second device sends a new authentication response frame containing an encrypted custom data field (sixth data field) to the first device. Upon receiving the new authentication response frame, the first device decrypts it using a symmetric decryption algorithm to obtain the product-specific identification data, a random number, and a key ID. It verifies the product-specific identification data; if the verification fails, it returns to RZ001; if the verification is successful, it performs key ID verification. If the verification fails, it returns to RZ001; if the key ID verification is successful, it XORs the received random number (sixth random number) with the last four bits of the product identifier and then compares it with the original random number (the fifth random number generated by RZ001). If they are different, it returns to RZ001; if they are the same, it continues with the following verification.

[0077] It should be noted that all custom data fields in subsequent management frames are encrypted and decrypted using the key corresponding to the key ID here. That is, the configuration key selected in the dynamic key data is used for encryption and decryption of subsequent data fields.

[0078] If the authentication response frame received by the first device does not contain a custom data field, it indicates that the second device is a fake device. If the authentication response frame received by the first device contains a custom data field, the last four bits of the product-specific identification data are compared with the last four bits of the product-specific identification data stored in the device. If they are different, the process returns to step RZ001. If they are the same, the key ID is verified. Specifically, the received key ID is compared with the key ID generated by RZ001. If they are different, the process returns to step RZ001. After verifying that the key ID is correct, the received random number is XORed with the last four bytes of the product-specific identification data. The result of the XOR is compared with the original random number (generated by RZ001). If they are the same, the following association authentication process is performed. If the above verification fails three times consecutively, the first device can be determined to be a fake device, and the second device will no longer communicate with it.

[0079] In one embodiment, after determining the legality of the authentication response frame based on the verification result, the method further includes: if the authentication response frame is legal, generating a seventh data field based on the product identifier, a seventh random number obtained by a random number generation algorithm, an authorization code, and a key ID, encrypting it, adding it to the associated frame, and sending it; if an associated response frame sent by the second device is received, decrypting the eighth data field based on a new encryption / decryption key to obtain the product identifier, the eighth random number, and the associated status identifier; verifying the consistency between the product identifier, the associated status identifier, and the processing result of the eighth random number based on the inverse random number processing algorithm and the seventh random number, and determining the legality of the associated response frame based on the verification result; if the associated response frame is confirmed to be legal, determining whether the access was successful based on the associated status identifier.

[0080] In this process, after receiving the association frame, the second device decrypts the seventh data field and verifies the legality of the probe frame based on the product identifier, authorization code, and key ID. If the association frame is legal, the device uses a random number processing algorithm to obtain an eighth random number from the seventh random number, and generates an eighth data field based on the product identifier, the eighth random number, and the association status identifier. The data field is then encrypted and added to the association response frame for packaging and transmission.

[0081] After the authentication frame verification is successful, the associated frame verification begins. This is used for final confirmation of the wireless communication session and also to prevent DoS attacks. If the associated frame verification fails, the current verification will continue. After three consecutive failed verifications, the system will display an error message. Once the associated frame verification is successful, the access is successful, and normal data transmission and reception can begin.

[0082] like Figure 17As shown, the first device generates a custom data field (the seventh data field) based on the product's unique identification data, a random number generated by a random number algorithm (the seventh random number), an authorization code (the authorization code mentioned in the probe frame process), and a key ID (the key ID mentioned in the authentication frame). The generated ciphertext is added to the original IEEE 802.11 protocol association frame to form a new association frame. The new association frame conforms to the IEEE 802.11 standard, and its specific format is as follows: Figure 18 .

[0083] It should be noted that the encryption key used at GL003 is the key configured during the authentication frame. The first device sends new association frame data to the second device, which carries an encrypted custom data field. Upon receiving the new association frame data, the second device first parses out the custom field, then decrypts it using a symmetric encryption / decryption algorithm to obtain the product-specific identification data, a random number, an authorization code, and a key ID. The product-specific identification data is verified. If verification fails, the process returns to step GL001; if verification succeeds, the authorization code is verified. If verification fails, it indicates that the first device is simulating our device to launch a DoS attack, and we will no longer communicate with the first device. If verification succeeds, the key ID is verified. If key ID verification fails, it indicates that the first device is simulating our device to launch a DoS attack, and we will no longer communicate with it. After successful verification, the received random number is XORed with the last 4 bytes of the product-specific identification data to generate a new random number (the eighth random number). This new random number, the product-specific identification data, the association status identifier, and other data are used to generate the custom data field (the eighth data field). The specific information of the association status identifier is as follows... Figure 19 As shown, 0x01 indicates a successful association, and 0x02 indicates a failed association.

[0084] The specific verification method is as follows: if the associated frame received by the second device does not contain a custom data field, it indicates that the first device is a fake device. If the associated frame received by the second device contains a custom data field, the last four bits of the product-specific identification data obtained after decryption are compared with the last four bits of the product-specific identification data stored in the device. If they are the same, the subsequent operations continue; otherwise, return to step GL001. After successful verification of the product-specific identification data, the authorization code is verified. The verification method is the same as the probe frame process. After successful verification, the key ID is verified. The specific method is the same as the authentication frame process. If the verification fails, return to step GL001. If the verification fails more than three times consecutively, the first device can be determined to be a fake device, and the second device will no longer communicate with it.

[0085] The custom data field generated by the second device is encrypted using a symmetric encryption algorithm. The resulting ciphertext is added to the original IEEE 802.11 protocol associated response frame, forming a new associated response frame. The new associated response frame conforms to the IEEE 802.11 standard, and its specific format is as follows: Figure 20 .

[0086] The second device sends a new associated response frame carrying an encrypted custom data field to the first device. Upon receiving the new authentication response frame, the first device decrypts it using a symmetric decryption algorithm to obtain the product-specific identification data, a random number, and an associated status identifier. It verifies the product-specific identification data; if the verification fails, it returns to GL001; if the verification is successful, it verifies the associated status identifier. If the verification fails, it returns to GL001; if the associated status identifier is successful, it then verifies the received random number with the original random number (generated by GL001). If they are different, it returns to GL001; if they are the same, the connection is successful.

[0087] During the specific verification process, if the associated response frame received by the first device does not contain a custom data field, it indicates that the second device is a fake device. If the authentication response frame received by the first device contains a custom data field, the last four bits of the product-specific identification data are compared with the last four bits of the product-specific identification data stored in the device. If they are different, the process returns to step GL001. If the verification is correct, the associated status identifier is checked to determine if this identifier is 0x01. Otherwise, the process returns to step GL001. If the associated status identifier is correct, the received random number is XORed with the last four bytes of the product-specific identification data. The XOR result is compared with the original random number (the random number generated by GL001). If they are the same, the connection is successful. If the above verification fails three times consecutively, the first device can be determined to be a fake device, and the second device will no longer communicate with it.

[0088] It is important to note that from the completion of the authentication frame verification process, subsequent management frame processes will use the configuration key specified in the authentication process for communication.

[0089] In one embodiment, the random number generation algorithm includes: S n =(S n-1 +IV)mod 0xffff. Where, when n=1, S0 is the first random number generated after the system is powered on, IV is a constant, and n is an integer greater than 0.

[0090] This is the random number generation algorithm at the sending end. The random number generated in each subsequent transmission is obtained by summing the random number sent last time with the IV constant and then taking the modulo 0xffff of the sum.

[0091] Furthermore, the random number generation algorithm at the response end is as follows: Sr = St ⊕ A4, where St is the random number received from the sender. A4 is the last four bits of the product-specific identifier, and the response end's random number Sr is the XOR value of the sender's random number and the last four bits of the product-specific identifier data. During verification, Sr is XORed again with the last four bits of the product identifier to obtain Sr'. The consistency between Sr' and Sr is verified, and combined with other parameters, such as the product identifier, the legitimacy of the management frame can be determined.

[0092] like Figure 21 As shown, the present invention also provides a secure wireless network access device, comprising: a data transceiver module for receiving a beacon frame sent by a second device, the beacon frame including a first data field generated and encrypted by the second device, the first data field including a product identifier, a first random number obtained based on a random number generation algorithm, and dynamic key data; an encryption / decryption module for parsing the first data field from the beacon frame and decrypting it to obtain plaintext; a data processing module for determining the legitimacy of the beacon frame based on the product identifier in the plaintext; a data security module for storing the dynamic key data if the beacon frame is legitimate; and a data field generation module for using a random number processing algorithm to obtain a second random number from the first random number, and generating a second data field from the product identifier, the second random number, and the key installation result status code, for encryption by the encryption / decryption module and then adding it to a beacon response frame for packaging and transmission by the data transceiver module.

[0093] The beacon response frame is received by the second device, which decrypts the second data field and determines its legitimacy based on the password installation result status code, product identifier consistency, and the verification result of the second random number processed by the inverse random number processing algorithm and the consistency with the first random number. Both the wireless network security access device and the second device pre-store the product identifier and an initial encryption / decryption key, which is used for data field encryption / decryption. The data transceiver module is used for transmitting and receiving wired and wireless data, specifically receiving the beacon frame sent by the second device.

[0094] The encryption / decryption module is mainly used to encrypt and decrypt communication data, specifically, parsing the first data field from the beacon frame and decrypting it to obtain plaintext.

[0095] The data processing module is mainly used to package the data to be sent, analyze and process the received data, and verify it. Specifically, it determines the legality of the beacon frame based on the product identifier in the plaintext.

[0096] The data security module is mainly used to store important system initialization data and key data. The storage method is in encrypted form and can only be accessed by dedicated interface functions. Specifically, if the beacon frame is valid, the key data is stored.

[0097] The data field generation module is mainly used to generate custom data fields using product-specific identification data and random numbers.

[0098] The wireless network security access device provided in this embodiment of the invention has the same implementation principle and technical effects as the aforementioned wireless network security access method embodiment. For the sake of brevity, any parts not mentioned in the wireless network security access device embodiment can be referred to the corresponding content in the aforementioned wireless network security access method embodiment.

[0099] This application also provides a computer-readable storage medium, such as flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, disk, optical disk, server, App application store, etc., which stores a computer program, and the program implements corresponding functions when executed by a processor. This embodiment implements a wireless network secure access method when the computer-readable storage medium is executed by a processor.

[0100] It should be noted that, depending on the implementation needs, the various steps / components described in this application can be broken down into more steps / components, or two or more steps / components or parts of the operation of steps / components can be combined into new steps / components to achieve the purpose of this invention.

[0101] The order of the steps in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0102] It should be understood that those skilled in the art can make improvements or modifications based on the above description, and all such improvements and modifications should fall within the protection scope of the appended claims.

Claims

1. A method for secure access to a wireless network, characterized in that, Applied to a first device, the method includes: The device receives a beacon frame sent by a second device. The beacon frame includes a first data field generated and encrypted by the second device. The first data field includes a product identifier, a first random number obtained based on a random number generation algorithm, and dynamic key data. The first data field is parsed from the beacon frame and decrypted to obtain the plaintext. The legitimacy of the beacon frame is determined based on the product identifier in the plaintext. If the beacon frame is valid, the dynamic key data is stored in the security module, and a second random number is obtained by using a random number processing algorithm on the first random number. The product identifier, the second random number, and the key installation result status code are used to generate a second data field, which is then encrypted and added to the beacon response frame for packaging and transmission. The beacon response frame is used by the second device to decrypt the second data field after receiving it, and to determine the legality of the beacon response frame based on the password installation result status code, product identification consistency, and the verification result of the consistency between the processing result of the second random number based on the random number inverse processing algorithm and the first random number. Both the first and second devices pre-store product identifiers and initial encryption / decryption keys, which are used for encryption and decryption of the data field.

2. The wireless network secure access method according to claim 1, characterized in that, After being added to the beacon response frame and sent, the process also includes: A third data field is generated based on the product identifier, a third random number obtained by the random number generation algorithm, and the authorization code. This data field is then encrypted, added to the probe frame, and sent. If a probe response frame is received from the second device, the fourth data field is decrypted to obtain the product identifier, the fourth random number, and the authorization code verification result identifier. Perform product identification verification, authorization code verification result identification verification, and consistency verification between the processing result of the fourth random number based on the random number inverse processing algorithm and the third random number, and determine the legality of the probe response frame based on the verification results; The second device pre-stores an authorization code table for multiple devices, with each authorization code corresponding to a MAC address. After receiving a probe frame, the second device decrypts the third data field and verifies the legitimacy of the probe frame based on the product identifier, authorization code, and the MAC address of the first device. If the probe frame is legitimate, the second device uses a random number processing algorithm to obtain a fourth random number from the third random number. Based on the product identifier, the fourth random number, and the verification result of the authorization code, the second device generates a fourth data field, encrypts it, and adds it to the probe response frame for packaging and transmission.

3. The wireless network secure access method according to claim 2, characterized in that, The dynamic key data is a key group comprising multiple keys, each key having a one-to-one corresponding key ID. Accordingly, after determining the legality of the probe response frame based on the verification result, the process further includes: Select a configuration key from the key group, and generate a fifth data field based on the product identifier, the fifth random number obtained by the random number generation algorithm, and the key ID of the configuration key. Encrypt the data field, add it to the authentication frame, and send it. If an authentication response frame is received from the second device, the sixth data field is decrypted to obtain the product identifier, the sixth random number, and the key ID. Perform product identification verification, key ID verification, and consistency verification between the processing result of the sixth random number based on the random number inverse processing algorithm and the fifth random number. Determine the legality of the authentication response frame based on the verification results. If the authentication response frame is confirmed to be legal, use the configuration key for encryption and decryption of subsequent data fields. Upon receiving the authentication frame, the second device decrypts the fifth data field and verifies the validity of the authentication frame based on the product identifier and key ID. If the authentication frame is valid, it uses a random number processing algorithm to obtain a sixth random number from the fifth random number, and generates a sixth data field based on the product identifier, the sixth random number, and the key ID. After encryption, the data field is added to the authentication response frame and sent. The configuration key is then used for encryption and decryption of subsequent data fields.

4. The wireless network secure access method according to claim 3, characterized in that, After determining the validity of the authentication response frame based on the verification result, the method further includes: If the authentication response frame is valid, a seventh data field is generated based on the product identifier, the seventh random number obtained by the random number generation algorithm, the authorization code, and the key ID. This data field is then encrypted, added to the associated frame, and sent. If an associated response frame is received from the second device, the eighth data field is decrypted using the new encryption / decryption key to obtain the product identifier, the eighth random number, and the associated status identifier. Perform product identification, associated status identification, and verification of the consistency between the processing result of the eighth random number based on the random number inverse processing algorithm and the seventh random number, and determine the legality of the associated response frame based on the verification result. If the associated response frame confirms that the connection is valid, the connection status identifier will be used to determine whether the connection was successful. In this process, after receiving the association frame, the second device decrypts the seventh data field and verifies the legality of the association frame based on the product identifier, authorization code, and key ID. If the association frame is legal, the device uses a random number processing algorithm to obtain an eighth random number from the seventh random number, and generates an eighth data field based on the product identifier, the eighth random number, and the association status identifier. The data field is then encrypted and added to the association response frame for packaging and transmission.

5. The wireless network secure access method according to any one of claims 1-4, characterized in that, The encryption and decryption process for each data field uses a symmetric encryption and decryption algorithm.

6. The wireless network secure access method according to any one of claims 1-4, characterized in that, The method further includes sending feedback information to the sender of the management frame after the management frame validity verification fails, so that the sender can resend the management frame. After the management frame validity verification fails a preset number of times, communication with the device that sent the corresponding frame will cease. The management frames include beacon frames, probe frames, authentication frames, association frames, and their corresponding response frames, and the preset number of times includes 3 times.

7. The wireless network secure access method according to any one of claims 1-4, characterized in that, The random number generation algorithm includes: S n =(S n-1 +IV)mod 0xffff; Where S0 is the first random number generated after the system is powered on, IV is a constant, n is an integer greater than 0, and mod is the modulo operation.

8. The wireless network secure access method according to any one of claims 1-4, characterized in that, The random number processing algorithm includes XORing the random number to be processed with a preset number of bits in the product identifier; Accordingly, the random number inverse processing algorithm includes XORing the random number to be processed with a preset number of bits of the product identifier again.

9. A secure wireless network access device, characterized in that, include: The data transceiver module is used to receive beacon frames sent by the second device. The beacon frames include a first data field generated and encrypted by the second device. The first data field includes a product identifier, a first random number obtained based on a random number generation algorithm, and dynamic key data. An encryption / decryption module is used to parse the first data field from the beacon frame and decrypt it to obtain the plaintext; The data processing module is used to determine the legitimacy of the beacon frame based on the product identifier in the plaintext; The data security module is used to store the dynamic key data if the beacon frame is valid; The data field generation module is used to obtain a second random number by using a random number processing algorithm on the first random number, and to generate a second data field by combining the product identifier, the second random number, and the key installation result status code. This second data field is then encrypted by the encryption / decryption module and added to the beacon response frame for packaging and transmission by the data transceiver module. The beacon response frame is used by the second device to decrypt the second data field after receiving it, and to determine the legality of the beacon response frame based on the password installation result status code, product identification consistency, and the verification result of the consistency between the processing result of the second random number based on the random number inverse processing algorithm and the first random number. Both the wireless network security access device and the second device pre-store product identifiers and initial encryption / decryption keys, which are used for encryption and decryption in the data domain.

10. A computer storage medium, characterized in that, It contains a computer program that can be executed by a processor, which performs the wireless network secure access method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Wireless network access method and access device, and client

    CN105682093A

  • Method and apparatus for authentication of wireless devices

    CN108293185A