Wi-Fi switching method and device and storage medium
By saving keys between access points, the problem of the STA need to renegotiate the key when switching back to the original access point is solved, reducing the switching time and improving the user experience.
Patent Information
- Application Number
- CN202311493543.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-09
- Publication Date
- 2025-05-09
AI Technical Summary
When the STA switches back to the original access point, it needs to renegotiate the key, which results in a long time switching and affects the user experience.
By sending request information to the access point, the negotiated key is saved so that there is no need to renegotiate the key during subsequent switching, saving time-consuming of the handshake process.
It reduces the time-consuming switching of terminal devices between access points, improves the smoothness of the switching process, and improves the user experience.
Smart Images

Figure CN119967499A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a Wi-Fi switching method, device, and storage medium. Background Art
[0002] Wireless fidelity (Wi-Fi) technology is a widely used wireless network transmission technology. A station (STA) can connect to an access point (AP) to achieve network transmission through Wi-Fi. STA access to an AP usually requires scanning, authentication, association, handshake and other processes. Among them, after the handshake, the STA and the AP can negotiate the key for encryption and decryption. When the STA successfully accesses the AP, they can communicate interactively through the negotiated key. The STA can switch back and forth between different APs through switching or roaming. When the STA switches to access the target AP, or switches back to the original AP, it is also necessary to complete the above process again and negotiate the key for communicating with the target AP.
[0003] It can be seen that when the STA switches back to the original AP, it needs to renegotiate the key to facilitate data transmission after successful access, which will cause the STA to take a long time to switch back and forth between APs, resulting in STA network interruption.
[0004] Therefore, how to reduce the time consumed by STAs switching APs back and forth, thereby avoiding the impact of AP switching on user experience, is a problem that needs to be solved urgently. Summary of the invention
[0005] The present application provides a Wi-Fi switching method, device and storage medium. The method can reduce the time consumed by a terminal device switching back and forth between access points, and avoid the switching of access points affecting the user experience.
[0006] In a first aspect, a Wi-Fi switching method is provided, the method being applied to a terminal device, the terminal device being connected to a first access point, the method comprising: the terminal device sending a first request message to the first access point, the first request message being used to request the first access point to save a first key; the terminal device saving the first key according to first response message received from the first access point, the first key being used for the terminal device to transmit data with the first access point, the first response message being used to indicate that the first access point supports key storage.
[0007] It should be noted that the terminal device and the first access point are end-pipe collaborative, where "end" refers to the terminal device and "pipe" refers to the first access point. The end-pipe collaborative terminal device and the first access point can collaboratively process information, for example, save the first key.
[0008] Exemplarily, the terminal device is a station (STA), the first request information is an Action request frame, and the first response information is an Action response frame. The first key may be key 1, which is used for the terminal device to transmit data with the first access point. The first key may include PTK1 and / or GTK1.
[0009] In one implementation, the terminal device may set the time for the first access point to store the first key through the first request information.
[0010] It should be understood that if the first access point supports key preservation, the first access point will feedback the first response information to the terminal device. If the first access point does not support key preservation, the terminal device needs to re-access the negotiation key during the subsequent re-access to the first access point.
[0011] In one implementation, the terminal device may save the basic service set identifier (BSSID) of the first access point while saving the first key. Based on this, the terminal device saves the first key, the BSSID of the first access point, and the media access control (MAC) address of the terminal device.
[0012] Based on the above solution, after the terminal device accesses the first access point, the negotiated first key can be saved. This allows the terminal device to re-access the first access point during subsequent switching without having to re-negotiate the key with the first access point through the handshake process. This saves the time spent in the handshake process, makes the terminal device switching process smoother, and improves the user experience.
[0013] In combination with the first aspect, in some implementations of the first aspect, the method further includes: the terminal device disconnects from the first access point and accesses the second access point; the terminal device disconnects from the second access point and accesses the first access point again through the first key.
[0014] It should be noted that the switching may include active switching and roaming.
[0015] Based on the above solution, when the terminal device switches from the first access point to the second access point and then switches from the second access point back to the first access point, the first key saved previously can be used to access the first access point, thus avoiding time-consuming key renegotiation.
[0016] In combination with the first aspect, in certain implementations of the first aspect, the terminal device disconnects from the second access point and accesses the first access point again through the first key, including: the terminal device sends a second request message to the first access point, the second request message includes first encrypted information, and the first encrypted information is information obtained after encrypting the first information using the first key.
[0017] Exemplarily, the second request information may be an association request frame.
[0018] It should be understood that before the terminal device sends the second request information to the first access point, the terminal device encrypts the first information using the first key.
[0019] Exemplarily, the association request frame carries a Vendor IE, and the Vendor IE includes the first encryption information.
[0020] Based on the above solution, when the terminal device accesses the first access point again, information encrypted by the first key can be sent to the first access point via an association request frame to verify whether the first access point stores a valid first key.
[0021] In combination with the first aspect, in certain implementations of the first aspect, the method further includes: the terminal device receives a second response message from the first access point, the second response message being used to indicate that the first key is valid; and the terminal device uses the first key to transmit data with the first access point based on the second response message.
[0022] Based on the above solution, when the first key is valid, the terminal device and the first access point implement data transmission through the first key, which saves the time of switching the terminal device and further verifies the validity of the first key, making subsequent data transmission more reliable.
[0023] In combination with the first aspect, in some implementations of the first aspect, before the terminal device sends the second request information to the first access point, the method further includes: the terminal device scans the first access point and determines that the first access point is a historical access point.
[0024] It should be noted that the terminal device will send the second request information to the first access point only when it determines that the first access point is an access point that has been accessed before. If the first access point is not a historical access point of the terminal device, the terminal device will not send the second request information to the first access point, and the terminal device will access the access point through authentication, association, and handshake processes. In other words, if the first access point is not a historical access point of the terminal device, the terminal device needs to renegotiate the key with the access point.
[0025] Based on the above solution, the terminal device can first verify that the target access point (e.g., the first access point) is a historical access point, and then send an association request to the historical access point to perform the subsequent access process, so as to avoid the terminal device sending an association request to a non-historical access point, resulting in access failure.
[0026] In combination with the first aspect, in certain implementations of the first aspect, the method also includes: the terminal device receives a third response message from the first access point, the third response message is used to indicate that the first key is invalid; the terminal device obtains a second key through a handshake, and the second key is used for the terminal device to transmit data with the first access point.
[0027] It should be noted that when the first key is invalid, the terminal device needs to renegotiate the key with the first access point through a handshake process. It is understandable that the first access point may have lost the previously saved first key, causing the first key to become invalid.
[0028] Based on the above solution, the terminal device can determine whether the previously saved first key is valid according to the specific feedback of the first access point to the second request information. If the first key is invalid, the terminal device will re-access the first access point through association, authentication handshake and other processes. The terminal device re-negotiates with the first access point through the handshake process to obtain the second key, and the second key will be used between the terminal device and the first access point.
[0029] In combination with the first aspect, in some implementations of the first aspect, the first information includes a media access control MAC address of the terminal device and / or a basic service set identifier BSSID of the first access point.
[0030] In combination with the first aspect, in some implementations of the first aspect, the second request information is an association request frame.
[0031] In combination with the first aspect, in some implementations of the first aspect, the second response information is an association response frame.
[0032] In combination with the first aspect, in some implementations of the first aspect, the first encrypted information is carried in a first field, and the second request information includes the first field.
[0033] Exemplarily, the first field is the Vendor IE field.
[0034] In combination with the first aspect, in some implementations of the first aspect, the first request information is an Action request frame.
[0035] In combination with the first aspect, in some implementations of the first aspect, the first response information is an Aciton response frame.
[0036] In combination with the second aspect, a Wi-Fi switching method is provided, the method being applied to a first access point, the first access point being connected to a terminal device, the method comprising: the first access point receiving first request information from the terminal device; the first access point sending first response information to the terminal device, the first response information being used to indicate that the first access point supports key storage; the first access point storing a first key according to the first request information, the first key being used for data transmission between the first access point and the terminal device.
[0037] Exemplarily, the terminal device is a STA, the first request information is an Action request frame, and the first key may be key 1, which is used for the terminal device to transmit data with the first access point. The first key may include PTK1 and / or GTK1.
[0038] It should be understood that after the first access point receives the first request information, if the first access point supports key storage, the first access point will feedback first response information to the terminal device. If the first access point does not support key storage, the first access point can feedback response information to the terminal device indicating that the first access point does not support key storage.
[0039] In one implementation, if the first access point does not support key preservation, the terminal device needs to renegotiate the key during a subsequent re-access to the first access point.
[0040] In one implementation, the first access point may save the MAC address of the terminal device while saving the first key. Based on this, the first access point saves the first key, the BSSID of the first access point, and the MAC address of the terminal device.
[0041] Based on the above solution, for the first access point that supports key preservation, after the terminal device accesses the first access point, the negotiated first key can be saved. When the terminal device subsequently switches and re-accesses the first access point, the first access point does not need to re-negotiate the key with the terminal device through the handshake process. This saves the time of the handshake process, makes the terminal device switching process smoother, and improves the user experience.
[0042] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the first access point disconnecting from the terminal device; and the first access point reconnecting with the terminal device through the first key.
[0043] Based on the above solution, the terminal device can disconnect from the first access point and reconnect to the first access point. When the first access point and the terminal device are connected again, the previously saved first key can be used to avoid time-consuming key renegotiation.
[0044] In combination with the second aspect, in certain implementations of the second aspect, the first access point is connected to the terminal device again through the first key, including: the first access point receives a second request message from the terminal device, the second request message includes first encrypted information, and the first encrypted information is information obtained after the terminal device encrypts the first information using the first key.
[0045] Exemplarily, the second request information may be an association request frame. The association request frame carries a Vendor IE, and the Vendor IE includes the first encrypted information.
[0046] Based on the above solution, when the first access point is connected to the terminal device again, the first access point can receive the second request information from the terminal device, so that the first access point can subsequently verify whether a valid first key is saved.
[0047] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the first access point encrypts the second information using the first key to obtain second encrypted information.
[0048] It should be understood that the first access point can use the previously saved first key to encrypt the MAC address of the terminal device and the BSSID of the first access point. When the first access point previously saved the first key, it also saved the MAC address of the terminal device. Based on this, the first access point saves the second information, so that the first access point can use the first key to encrypt the second information to obtain the second encrypted information.
[0049] Exemplarily, if the terminal device uses PTK1 to encrypt the first encrypted information, the first access point also uses PTK1 to encrypt the second encrypted information. If the terminal device uses GTK1 to encrypt the first information, the first access point also uses GTK1 to encrypt the second encrypted information.
[0050] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the first access point uses the first key to decrypt the first encrypted information to obtain the first information.
[0051] It should be understood that the first access point can decrypt the first encrypted information using the previously stored first key.
[0052] Exemplarily, if the terminal device uses PTK1 to encrypt and obtain the first encrypted information, the first access point uses PTK1 to decrypt and obtain the first information; if the terminal device uses GTK1 to encrypt and obtain the second encrypted information, the first access point uses GTK1 to decrypt and obtain the first information.
[0053] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the first access point sends second response information to the terminal device based on the consistency between the first encryption information and the second encryption information, and the second response information is used to indicate that the first key is valid.
[0054] Based on the above solution, the first access point encrypts to obtain the second encrypted information, and the terminal device encrypts to obtain the first encrypted information. The first access point can compare the first encrypted information received from the terminal device with the second encrypted information. If the information is consistent, the first key is verified to be valid, and the first access point and the terminal device can use the previously saved first key to transmit data.
[0055] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the first access point sends second response information to the terminal device based on the consistency between the first information and the second information, and the second response information is used to indicate that the first key is valid.
[0056] Based on the above scheme, the first access point can decrypt the first encrypted information received from the terminal device to obtain the first information, and compare the second information with the first information. If the information is consistent, the first key is verified to be valid, and the first access point and the terminal device can use the previously saved first key to transmit data.
[0057] In combination with the second aspect, in some implementations of the second aspect, the method further includes: the first access point sends second response information to the terminal device based on successfully decrypting the first encrypted information using the first key, and the second response information is used to indicate that the first key is valid.
[0058] Based on the above solution, when the first access point successfully decrypts the first encrypted information using the previously saved first key, it can be verified that the first key is valid, and the first access point user terminal can use the previously saved first key to transmit data.
[0059] In combination with the second aspect, in some implementations of the second aspect, when the first access point verifies that the first encrypted information is inconsistent with the second encrypted information, or the first access point verifies that the first information is inconsistent with the second information, or the first access point fails to decrypt the first encrypted information using the first key, the first access point sends a third response information to the terminal device, and the third response information is used to indicate that the first key is invalid.
[0060] Based on the above solution, when the first access point verifies that the first key is invalid, response information indicating that the first key is invalid may be fed back to the terminal device, so that the first access point and the terminal device can renegotiate the key later.
[0061] In combination with the second aspect, in some implementations of the second aspect, the first information includes a media access control MAC address of the terminal device and / or a basic service set identifier BSSID of the first access point.
[0062] In combination with the second aspect, in some implementations of the second aspect, the second information includes a MAC address of the terminal device and / or a BSSID of the first access point.
[0063] In combination with the second aspect, in some implementations of the second aspect, the second request information is an association request frame.
[0064] In combination with the second aspect, in some implementations of the second aspect, the second response information is an association response frame.
[0065] In combination with the second aspect, in certain implementations of the second aspect, the first encrypted information is carried in a first field, and the second request information includes the first field.
[0066] Exemplarily, the first field is the Vendor IE field.
[0067] In combination with the second aspect, in some implementations of the second aspect, the first request information is an Action request frame.
[0068] In combination with the second aspect, in some implementations of the second aspect, the first response information is an Action response frame.
[0069] According to a third aspect, a Wi-Fi switching device is provided, the device being connected to a first access point, the device comprising: a transceiver unit, configured to send a first request message to the first access point, the first request message being used to request the first access point to save a first key; a processing unit, configured to save the first key according to first response message received from the first access point, the first key being used for the device to transmit data with the first access point, the first response message being used to indicate that the first access point supports key storage.
[0070] In combination with the third aspect, in some implementations of the third aspect, the transceiver unit is used to disconnect from the first access point and access the second access point; and is also used to disconnect from the second access point and access the first access point again through the first key.
[0071] In combination with the third aspect, in certain implementations of the third aspect, the transceiver unit is specifically used to send a second request message to the first access point, where the second request message includes first encrypted information, and the first encrypted information is information obtained by encrypting the first information using the first key.
[0072] In combination with the third aspect, in certain implementations of the third aspect, the transceiver unit is further used to receive a second response message from the first access point, where the second response message is used to indicate that the first key is valid; the processing unit is further used to transmit data with the first access point using the first key based on the second response message.
[0073] In combination with the third aspect, in certain implementations of the third aspect, before the transceiver unit is specifically used to send the second request information to the first access point, the processing unit is also used to scan the first access point and determine that the first access point is a historical access point.
[0074] In combination with the third aspect, in certain implementations of the third aspect, the transceiver unit is further used to receive a third response message from the first access point, and the third response message is used to indicate that the first key is invalid; the processing unit is further used to obtain a second key through a handshake, and the second key is used for the device to transmit data with the first access point.
[0075] In combination with the third aspect, in some implementations of the third aspect, the first information includes a media access control MAC address of the terminal device and / or a basic service set identifier BSSID of the first access point.
[0076] In combination with the third aspect, in some implementations of the third aspect, the second request information is an association request frame.
[0077] In combination with the third aspect, in some implementations of the third aspect, the second response information is an association response frame.
[0078] In combination with the third aspect, in certain implementations of the third aspect, the first encrypted information is carried in a first field, and the second request information includes the first field.
[0079] In combination with the third aspect, in some implementations of the third aspect, the first request information is an Action request frame.
[0080] In combination with the third aspect, in certain implementations of the third aspect, the first response information is an Aciton response frame.
[0081] In a fourth aspect, a Wi-Fi switching device is provided, which is connected to a terminal device and includes: a transceiver unit, used to receive a first request message from the terminal device; the transceiver unit is also used to send a first response message to the terminal device, the first response message is used to indicate that the device supports key storage; a processing unit, used to save a first key according to the first request information, and the first key is used for the device to transmit data with the terminal device.
[0082] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is further used to disconnect with the terminal device; and the processing unit is further used to reconnect with the terminal device through the first key.
[0083] In combination with the fourth aspect, in certain implementations of the fourth aspect, the transceiver unit is specifically used to receive a second request message from the terminal device, the second request message includes first encrypted information, and the first encrypted information is information obtained after the terminal device encrypts the first information using the first key.
[0084] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to encrypt the second information using the first key to obtain second encrypted information.
[0085] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to decrypt the first encrypted information using the first key to obtain the first information.
[0086] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to send a second response message to the terminal device based on the consistency between the first encryption information and the second encryption information, and the second response message is used to indicate that the first key is valid.
[0087] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to send second response information to the terminal device based on the consistency between the first information and the second information, and the second response information is used to indicate that the first key is valid.
[0088] In combination with the fourth aspect, in certain implementations of the fourth aspect, the processing unit is further used to send a second response message to the terminal device based on successfully decrypting the first encrypted information using the first key, and the second response message is used to indicate that the first key is valid.
[0089] In combination with the fourth aspect, in certain implementations of the fourth aspect, when the device verifies that the first encrypted information is inconsistent with the second encrypted information, or the device verifies that the first information is inconsistent with the second information, or the device fails to decrypt the first encrypted information using the first key, the transceiver unit is also used to send a third response message to the terminal device, and the third response message is used to indicate that the first key is invalid.
[0090] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first information includes a media access control MAC address of the terminal device and / or a basic service set identifier BSSID of the first access point.
[0091] In combination with the fourth aspect, in certain implementations of the fourth aspect, the second information includes a MAC address of the terminal device and / or a BSSID of the first access point.
[0092] In combination with the fourth aspect, in some implementations of the fourth aspect, the second request information is an association request frame.
[0093] In combination with the fourth aspect, in some implementations of the fourth aspect, the second response information is an association response frame.
[0094] In combination with the fourth aspect, in certain implementations of the fourth aspect, the first encrypted information is carried in a first field, and the second request information includes the first field.
[0095] In combination with the fourth aspect, in some implementations of the fourth aspect, the first request information is an Action request frame.
[0096] In combination with the fourth aspect, in some implementations of the fourth aspect, the first response information is an Action response frame.
[0097] In a fifth aspect, a terminal device is provided, comprising: a transceiver for receiving and sending messages; a memory for storing programs; and a processor for executing the programs stored in the memory, so that the terminal device performs the method in the first aspect and any possible implementation thereof.
[0098] In a sixth aspect, a first access point is provided, comprising: a transceiver for receiving and sending messages; a memory for storing programs; and a processor for causing the terminal to execute the method in the second aspect and any possible implementation manner thereof.
[0099] In combination with the sixth aspect, in some implementations of the sixth aspect, the first access point is a routing device, or an access point on the routing device.
[0100] In the seventh aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a computer, the computer implements the method as in the first aspect and any possible implementation thereof, or the method as in the second aspect and any possible implementation thereof.
[0101] In an eighth aspect, a computer program product comprising instructions is provided, which, when executed on a computer, enables the computer to execute a method as described in the first aspect and any possible implementation thereof, or a method as described in the second aspect and any possible implementation thereof.
[0102] In a ninth aspect, a chip is provided, comprising a processor and a data interface, wherein the processor reads instructions stored in a memory through the data interface to execute a method as in the first aspect and any possible implementation thereof, or a method as in the second aspect and any possible implementation thereof.
[0103] In combination with the ninth aspect, in one possible implementation, the processor is coupled to the memory via an interface.
[0104] In combination with the ninth aspect, in a possible implementation, the chip system also includes a memory, in which a computer program or computer instructions are stored. BRIEF DESCRIPTION OF THE DRAWINGS
[0105] Figure 1 The present invention is a schematic flowchart of a method for a STA to access an AP.
[0106] Figure 2 It is a scene graph provided in an embodiment of the present application.
[0107] Figure 3 It is a schematic flowchart of a method for STA switching AP provided in an embodiment of the present application.
[0108] Figure 4 It is a system architecture diagram provided in an embodiment of the present application.
[0109] Figure 5 It is a schematic flow chart of a Wi-Fi switching method provided in an embodiment of the present application.
[0110] Figure 6 It is a schematic diagram of a frame structure provided in an embodiment of the present application.
[0111] Figure 7 It is a schematic flow chart of a Wi-Fi switching method provided in an embodiment of the present application.
[0112] Figure 8 A schematic block diagram of a device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0113] The technical solution in this application will be described below in conjunction with the accompanying drawings.
[0114] The terms used in the following embodiments are only for the purpose of describing specific embodiments, and are not intended to be used as limitations on the present application. As used in the specification and the appended claims of the present application, the singular expressions "one", "a kind of", "said", "above", "the" and "this" are intended to also include expressions such as "one or more", unless there is a clear contrary indication in the context. It should also be understood that in the following embodiments of the present application, "at least one", "one or more" refer to one, two or more. The term "and / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist; for example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the objects associated before and after are in an "or" relationship.
[0115] References to "one embodiment" or "some embodiments" etc. described in this specification mean that a particular feature, structure or characteristic described in conjunction with the embodiment is included in one or more embodiments of the present application. Thus, the phrases "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear at different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.
[0116] A wireless access point (AP) can be a node at the center of a network. Generally speaking, a wireless router can be regarded as an AP. Of course, a router can also include multiple APs. For example, a multi-band router includes a 2.4GHz band and a 5GHz band, and one band can correspond to one AP. A station (STA) can be understood as a terminal device connected to a wireless network, such as a personal computer, a mobile terminal, a tablet computer, etc. STA can generally be understood as a client in a wireless local area network (WLAN), which can be mobile or fixed. Wireless fidelity (Wi-Fi) technology is a widely used wireless network transmission technology. STA can communicate with AP through Wi-Fi. For ease of understanding, the following is combined with Figure 1 Taking STA accessing AP1 as an example, a method for STA accessing AP is introduced. The method mainly includes the following steps:
[0117] S101, scanning.
[0118] The STA can scan the AP on each available channel. The specific scanning method may include the following two methods.
[0119] First, passive scanning
[0120] STA discovers the network by listening to the Beacon frames periodically sent by the AP. The Beacon frames can provide relevant information about the AP, such as the AP's (service set identifier, SSID).
[0121] It should be noted that each AP has an identifier for user identification, and the SSID may be the identifier for user identification.
[0122] Second, Active Scanning
[0123] STA can send Probe Request frames on multiple channels to scan APs with the same SSID as the STA. If the STA cannot find an AP with the same SSID, it will continue scanning.
[0124] S102, authentication.
[0125] When STA finds an AP with the same SSID as it, STA can further select the AP with the strongest signal from the APs with matching SSIDs to enter the authentication phase based on the strength of the received AP signal. The authentication process can be understood as an identity verification process. Authentication methods include open authentication and non-open authentication. For open authentication, STA can initiate an authentication request, and AP can respond to the authentication request. For non-open authentication, STA can initiate an authentication request, and AP replies to the query text after receiving the authentication request. STA encrypts the plaintext with the preset key and sends it to AP. AP decrypts the encrypted plaintext based on the preset key and compares it with the previous plaintext. If the comparison is consistent, it means that the authentication is successful.
[0126] S103, association.
[0127] When the AP returns an authentication response message to the STA, the association phase can begin after the identity authentication is successful. The STA sends an association request to the AP, and the AP can return an association request response to the STA, completing the association process.
[0128] S104, handshake.
[0129] It should be noted that the handshake also occurs in the process of STA accessing the AP. Generally speaking, the four-way handshake between the STA and the AP involves four information exchanges to generate keys for encrypting wireless data. The keys include pairwise transient key (PTK) and group temporal key (GTK). Among them, PTK is used for encryption and decryption of unicast data frames, and the PTK used for communication between the AP and each STA is unique; GTK is used for encryption and decryption of multicast data frames and broadcast data frames, and all STAs connected to a certain AP can share a GTK. Management frames, control frames, and empty data frames do not need to be encrypted. After the STA successfully accesses the AP, the PTK / GTK generated after the handshake can be used for data transmission.
[0130] It is understandable that the process of STA accessing AP can generally include the above-mentioned scanning, authentication, association and handshake. In actual applications, STA will not always access one AP. STA can actively switch between multiple APs, or roam between different APs according to AP information (including whether the AP is fully connected and the strength of the AP signal). It should be noted that the active switching of STA and the roaming of STA can be understood as the switching of STA between different APs. Among them, the active switching of STA can be understood as the active switching of the terminal device between different routers. The roaming of STA can be understood as the AP guiding the STA to switch between different APs. The different APs here can refer to APs of different frequency bands of the same router. For example, when the 5GHz frequency band of a router is fully connected, the STA can be guided to roam to the AP of the 2.4GHz frequency band. When STA switches between different APs, it is necessary to disconnect the currently connected AP and re-access the new AP. The re-access process usually also requires the completion of scanning, authentication, association and handshake processes to negotiate a new key so that data can be transmitted with the new AP. This process usually takes about 1 second, which will cause STA service interruption. For video and live broadcast services, service interruption will cause service freezes, thus affecting user experience.
[0131] like Figure 2 As shown in the figure, a scenario diagram of STA switching back and forth between APs is shown. The STA originally accessing AP1 can switch to access AP2, and the STA can also switch from AP2 back to the original AP1. In this switching process, the STA needs to complete at least three access processes. Figure 3 Taking the STA switching back and forth between AP1 and AP2 as an example, the access process of the STA is introduced.
[0132] S301, STA accesses AP1.
[0133] It should be noted that the process of STA accessing AP1 includes the scanning, authentication, association and handshake in the above method 100.
[0134] For example, STA discovers AP1 by listening to the Beacon frame sent by AP1. STA sends an authentication request to AP1, and determines that the authentication is successful based on the authentication response received from AP1. Subsequently, STA sends an association request to AP1, and receives an association request response from AP1 to determine that the association is complete. Finally, after the four-way handshake process, STA and AP1 negotiate to obtain the key (PTK / GTK), thereby completing STA access to AP1.
[0135] S302, STA accesses AP2.
[0136] For example, before STA accesses AP2, STA has already accessed AP1. When STA initiates switching, the process of STA switching from AP1 to AP2 can be triggered. Among them, STA initiating switching can include STA's active switching and roaming. Generally speaking, STA can roam between different frequency bands of the same Wi-Fi, and STA can actively switch between different Wi-Fi. In comparison, the time required for STA's roaming is shorter than the time required for active switching.
[0137] It should be noted that the process of STA accessing AP2 may also include the scanning, authentication, association and handshake in the above method 100.
[0138] For example, STA detects AP2 by listening to the Beacon frame sent by AP2, sends an authentication request to AP2, and determines that the authentication is successful based on the authentication response received from AP2. Subsequently, STA sends an association request to AP2, and receives an association request from AP2 to determine that the association is complete. Finally, after the four-way handshake process, STA and AP2 negotiate to obtain the key (PTK / GTK), thereby completing STA access to AP2.
[0139] S303, the STA re-accesses AP1.
[0140] It is understandable that when the STA switches from accessing AP2 back to AP1, it will go through the scanning, authentication, association and handshake processes again.
[0141] In step S303, the STA re-accesses AP1, which means that the STA scans AP1 and completes the authentication process with AP1.
[0142] S304, STA associates with AP1.
[0143] It should be noted that after the STA completes the authentication with AP1, the association process in step S103 of method 100 is performed. After the STA completes the association process with AP1, it will perform a four-way handshake with AP1 again to negotiate a new key.
[0144] Specifically, the handshake process may include the following steps:
[0145] S305, STA and AP1 shake hands 1.
[0146] It should be noted that the AP can initiate a four-way handshake.
[0147] Specifically, AP1 sends a message containing a random number (authenticator nonce, ANonce) to STA, and STA can generate its own PTK according to the message. ANonce is generated by AP.
[0148] S306, STA shakes hands with AP1 2.
[0149] Specifically, after the STA determines the PTK, it can respond to the AP1 with a message based on the Extensible Authentication Protocol over LAN (EAPOL). The message includes a supplicant nonce (SNonce) and a message integrity check (MIC). AP1 generates its own PTK based on the SNonce and verifies the integrity of the message from the STA based on the MIC.
[0150] It should be noted that, except for the message (message) transmitted during the first handshake in step S305, the message (message) transmitted in each handshake after the second handshake in step S306 will include MIC. After receiving SNonce in step S306, AP1 can generate its own PTK for the keys of the subsequent two handshakes.
[0151] S307, STA shakes hands with AP1 3.
[0152] It should be noted that, in the third handshake, AP1 can send GTK to STA and instruct STA to install PTK and GTK. Since AP1 determines its own PTK in step S306, AP1 can encrypt GTK and then send it to STA in step S307.
[0153] S308, STA shakes hands with AP1 4.
[0154] It should be noted that, in the fourth handshake, STA can send a confirmation message to AP1 to notify AP1 that the installation of PTK has been completed, and AP1 can also install PTK after receiving the confirmation message sent by STA. Among them, STA or AP1 installing PTK means that PTK can be used to encrypt data.
[0155] S309, STA and AP1 communicate using the key.
[0156] It should be noted that, after the four-way handshake process from step S305 to step S308, the STA and the AP1 renegotiate to obtain a key, and then the STA and the AP1 can communicate using the negotiated key.
[0157] Based on the steps described in the above method 300, when the STA switches between multiple APs, each access to an AP needs to go through the processes of scanning, authentication, association, and handshake. When the STA returns to access a certain AP, the time-consuming access process may cause service interruption, thereby affecting the user experience.
[0158] In view of this, the embodiments of the present application provide a method, device and storage medium for Wi-Fi switching. Figure 2 In the scenario shown, in this scenario, the STA originally connected to AP1 switches from AP1 to AP2 and from AP2 to AP1, which simplifies the process of STA re-accessing the original AP1, reduces the time consumed by the need to renegotiate keys, makes the service smoother, and improves the user experience.
[0159] For ease of understanding, Figure 4 A system architecture diagram provided by an embodiment of the present application is shown. The system architecture includes an end side and a pipe side. The end side can be understood as the STA side, and the pipe side can be understood as the AP side. The kernel layer of the STA side and the AP side includes a Wi-Fi driver, and a proprietary path is constructed in the Wi-Fi driver, and key negotiation and other processes are performed through the constructed proprietary path to implement the Wi-Fi switching method provided by the embodiment of the present application.
[0160] like Figure 5 As shown, a Wi-Fi switching method provided by an embodiment of the present application is shown. The method can be applied to Figure 2 In the scenario shown, the method 500 is specifically introduced below by taking STA, AP1 and AP2 as examples.
[0161] S501, STA accesses AP1.
[0162] It should be noted that the process of STA accessing AP1 may include scanning, authentication, association and handshake.
[0163] For example, STA discovers AP1 by listening to the Beacon frame sent by AP1. STA sends an authentication request to AP1, and determines that the authentication is successful based on the authentication response received from AP1. Subsequently, STA sends an association request to AP1, and receives an association request response from AP1 to determine that the association is complete. Finally, after the four-way handshake process, STA and AP1 negotiate to obtain key 1 (including PTK / GTK), thereby completing STA access to AP1.
[0164] S502, STA sends an Action request frame, and accordingly, AP1 receives the Action request frame.
[0165] It should be noted that after the STA accesses AP1, the STA can send a request through an Action frame. The Action request frame can be used to request AP1 to save the key 1, and the time for AP1 to save the key 1 can also be set through the Action request frame.
[0166] S503, AP1 sends an Action response frame, and correspondingly, the STA receives the Action response frame.
[0167] It should be noted that AP1 may support the function of saving the key or may not support the function of saving the key.
[0168] For AP1 that does not support the key saving function, after receiving the Action request frame, it can feed back an Action response frame to the STA to indicate that AP1 does not support the key saving function, so that AP1 and STA will not save the key. For AP1 that cannot save the key, in the scenario where the STA switches from AP1 to AP2 and then switches back to AP1 from AP2, the steps in the above method 300 will be executed later, that is, the key needs to be renegotiated each time the AP is switched.
[0169] For AP1 that supports the key saving function, after receiving the Action request frame, an Action response frame can be fed back to the STA to indicate that the AP1 supports the key saving function. For AP1 that supports key saving, in the scenario where the STA switches from AP1 to AP2 and then switches from AP2 back to AP1, the subsequent steps in method 500 can be performed so that when the STA switches back and forth between AP1 and AP2, it does not need to renegotiate the key, saving time in the access process.
[0170] For example, Figure 6As shown, a format of an Action frame is shown. This format is applicable to Action request frames and Action response frames. The Action frame includes a Category field, an organizationally unique identifier (OUI) field, and an Operation field. Among them, the Operation field can have different definitions depending on the value.
[0171] For example, when the Operation field value is 5, the Operation field is defined as Announcement. For the Action request frame, when the STA accesses AP1, it can notify AP1 through Announcement that it supports the key preservation function. Similarly, for the Aciton response frame, AP1 can also notify STA through Announcement that it supports the key preservation function.
[0172] When AP1 receives an Action request frame, it can learn from the Action request frame that STA supports the key preservation function; when STA receives an Action response frame, it can learn from the Action response frame that AP1 supports the key preservation function. When STA and AP1 reach an agreement (both support the key preservation function), the subsequent steps can be executed. It can be seen that STA can request AP1 to save the key by notifying AP1 that it supports the key preservation function.
[0173] It should be noted that the format of the above-mentioned Action frame is only used as an example, and the embodiment of the present application does not limit the specific format of the Action frame. In addition, the above-mentioned STA and AP1 mutually notify each other of the function of supporting key preservation through the Action frame is also used as an example. The embodiment of the present application does not limit the specific information of the function of supporting key preservation by the STA and AP1, and it can be other frames except the Action frame.
[0174] S504: STA saves the key.
[0175] S505, AP1 saves the key.
[0176] It should be noted that when AP1 supports the key saving function, AP1 can save the key 1 negotiated with STA in step S501. When the Action response frame received by STA in step S503 indicates that AP1 supports the key saving function, STA can save the key 1 negotiated with STA in step S501.
[0177] In one implementation, when the STA and the AP1 save the key, the basic service set identifier (BSSID) of the AP1 and the media access control (MAC) address of the STA may be saved accordingly.
[0178] Specifically, the STA stores the BSSID of the AP1, and the AP1 stores the MAC address of the STA.
[0179] S506: STA accesses AP2.
[0180] It should be noted that, through automatic switching, roaming or manual connection, the STA can disconnect from AP1 and connect to AP2.
[0181] It should be noted that the process of STA accessing AP2 may also include scanning, authentication, association and handshake.
[0182] For example, STA discovers AP2 by listening to the Beacon frame sent by AP2. STA sends an authentication request to AP2, and determines that the authentication is successful based on the authentication response received from AP2. Subsequently, STA sends an association request to AP2, and receives an association request response from AP2 to determine that the association is complete. Finally, after the four-way handshake process, STA and AP2 negotiate to obtain key 2 (including PTK / GTK), thereby completing STA access to AP2.
[0183] S507, the STA re-accesses AP1.
[0184] It should be noted that, through automatic switching, roaming or manual connection, the STA first disconnects from AP2 and connects to AP1.
[0185] It should be noted that the process of STA re-accessing AP1 in step S507 may include scanning and authentication. That is, in the process of STA re-accessing AP1, scanning and authentication processes need to be completed first, and the scanning and authentication processes are similar to those in the above steps S501 and S506.
[0186] S508, STA encrypts information.
[0187] In one implementation, before encrypting information, the STA needs to determine whether the AP1 is an AP that the STA has accessed before.
[0188] Exemplarily, the STA obtains the BSSID of AP1 through the scanning or authentication process in step S507, and determines that AP1 is an AP that the STA has accessed before according to the BSSID of AP1. The STA determines that the AP1 has the key 1 cached.
[0189] It should be noted that the STA uses key 1 to encrypt the MAC address of the STA and / or the BSSID of AP1, and adds the encrypted information to the Vendor IE.
[0190] In one implementation, STA uses key 1 to encrypt only the MAC address of STA; or, STA uses key 1 to encrypt only the BSSID of AP1; or, STA uses key 1 to encrypt the MAC address of STA and the BSSID of AP1. The embodiments of the present application do not limit the specific information to be encrypted, and the above implementation is only for exemplary description.
[0191] S509, STA sends an association request frame, and accordingly, AP1 receives the association request frame.
[0192] It should be noted that the STA will carry the Vendor IE in the association request frame. Since the Vendor IE includes encrypted information, based on this, the STA can send the encrypted information to AP1 through the association request frame.
[0193] It should be noted that the STA may send the encrypted information to the AP1 through other signaling during the process of associating with the AP1, and does not necessarily send the encrypted information to the AP1 through the association request frame.
[0194] As an example, the association request frame may adopt the following code format:
[0195] Management-Association Request
[0196] Vendor Specific ID=221Vendor Specific Len=5Value=0×AC853D5008
[0197] Vendor Specific ID=221Vendor Specific Len=8OUI=00-E0-FC Value=(5byte)
[0198] Vendor Specific ID=221Vendor Specific Len=16OUI=00-E0-FC Value=(13byte)
[0199] Vendor Specific ID=221Vendor Specific Len=5Value=0×AC853D2004
[0200] It should be noted that the vendor specific IE included in the association request frame (Asscociation Request) may carry the MAC address of the STA and / or the BSSID of AP1 encrypted by using key 1.
[0201] Among them, Vendor Specific IE can be understood as the above-mentioned Vendor IE.
[0202] S510, AP1 encryption information.
[0203] It should be noted that, in the above step S505, AP1 saves the MAC address of the STA while saving the key 1. Based on this, AP1 can encrypt the MAC address of the STA and / or the BSSID of AP1.
[0204] Exemplarily, if in step S508, STA uses PTK1 to encrypt the MAC address of STA and / or BSSID of AP1, then in step S510, AP1 also uses PTK1 to encrypt the MAC address of STA and / or BSSID of AP1. If in step S508, STA uses GTK1 to encrypt the MAC address of STA and / or BSSID of AP1, then in step S510, AP1 also uses GTK1 to encrypt the MAC address of STA and / or BSSID of AP1.
[0205] It should be noted that step S510 is optional. After receiving the association request frame from the STA, AP1 can also decrypt the information.
[0206] That is, the association request frame received by AP1 includes the STA's encrypted MAC address and / or AP1's BSSID. After receiving the association request frame, AP1 decrypts the encrypted STA's MAC address and / or AP1's BSSID.
[0207] For example, if in step S508, STA uses PTK1 to encrypt the MAC address of STA and / or BSSID of AP1, then in step S510, AP1 also uses PTK1 to decrypt the encrypted information. If in step S508, STA uses GTK1 to encrypt the MAC address of STA and / or BSSID of AP1, then in step S510, AP1 also uses GTK1 to decrypt the encrypted information.
[0208] S511, AP1 information comparison is consistent.
[0209] It should be noted that if the API also uses a key to encrypt the MAC address of the STA and / or the BSSID of AP1, AP1 will compare the encrypted information included in the association request frame with the encrypted information of AP1. When the encrypted information is consistent, it means that the key 1 saved by AP1 in step S505 is valid.
[0210] Exemplarily, when STA uses PTK1 to encrypt STA's MAC address and AP1's BSSID in step S508, AP1 also uses PTK1 to encrypt STA's MAC address and / or AP1's BSSID in step S510. AP1 compares the information encrypted in step S510 with the STA encrypted information carried in the association request frame. When the encrypted information is consistent, it indicates that the PTK1 saved by AP1 in step S505 is valid.
[0211] Exemplarily, when STA uses GTK1 to encrypt STA's MAC address and / or AP1's BSSID in step S508, AP1 also uses GTK1 to encrypt STA's MAC address and / or AP1's BSSID in step S510. AP1 compares the information encrypted in step S510 with the STA encrypted information carried in the association request frame. When the encrypted information is consistent, it indicates that GTK1 saved by AP1 in step S505 is valid.
[0212] It should be noted that if AP1 decrypts the encrypted information in the association request frame and compares it with the MAC address of the STA and / or the BSSID of AP1 saved by AP1 in step S505, when the decrypted information is consistent, it means that the key 1 saved by AP1 in step S505 is valid.
[0213] Exemplarily, when the STA uses PTK1 to encrypt the MAC address of the STA and / or the BSSID of AP1 in step S508, AP1 uses PTK1 to decrypt the encrypted information carried in the association request frame in step S510. AP1 compares the decrypted information with the MAC address of the STA and / or the BSSID of AP1 saved in step S505. When the decrypted information is consistent, it indicates that the PTK1 saved by AP1 in step S505 is valid.
[0214] Exemplarily, when the STA uses GTK1 to encrypt the MAC address of the STA and / or the BSSID of AP1 in step S508, AP1 uses GTK1 to decrypt the encrypted information carried in the association request frame in step S510. AP1 compares the decrypted information with the MAC address of the STA and / or the BSSID of AP1 saved in step S505. When the decrypted information is consistent, it indicates that the GTK1 saved by AP1 in step S505 is valid.
[0215] In one implementation, when the information comparison is consistent, AP1 may reply to the STA with an association response frame, where the association response frame is used to feedback that the information comparison is consistent.
[0216] Obviously, there may be inconsistencies in the information comparison.
[0217] In one implementation, when the information comparison is inconsistent (including, the encrypted information comparison is inconsistent, or the decrypted information comparison is inconsistent), AP1 may feed back a message of the information comparison inconsistency to the STA.
[0218] S512, STA and AP1 communicate using a key.
[0219] It should be noted that AP1 determines whether the key saved in step S505 is valid by comparing the information. If the key is valid, STA can communicate with AP1 using the previously saved key. This ensures that AP1 has saved a valid key before STA and AP1 use the key to communicate, avoiding the subsequent communication process being blocked due to the loss of AP1's key.
[0220] In one implementation, when the information comparison is inconsistent, the handshake process between the STA and AP1 will not be simplified. That is, the process of the STA re-accessing AP1 will be similar to the process of accessing AP1 for the first time, which may include scanning, authentication, association, and handshake. In particular, it is necessary to renegotiate the key with AP1 through the handshake process and use the new key to communicate with AP1.
[0221] It can be understood that the above method 500 introduces the process of STA switching from AP1 to AP2 and then switching from AP2 to AP1. When STA re-accesses AP1, the handshake process can be reduced to reduce power consumption. Obviously, STA can also switch from AP1 to AP2 again, that is, when STA re-accesses AP2, the handshake process can also be reduced to reduce power consumption. It should be noted that in order to ensure that the handshake process can be reduced when STA re-accesses AP2, after STA accesses AP2 in step S506, similar steps S502 to S505 are also required, that is, STA can send an Action request frame to AP2, and receive an Action response frame from AP2 to indicate that AP2 supports the key saving function. STA and AP2 can respectively save the key 2 negotiated in step S506.
[0222] Generally speaking, it takes 40ms for STA and AP to negotiate a key through a handshake process. If the Wi-Fi switching method provided in the embodiment of the present application is adopted, when the STA reconnects to the AP it has connected to before, it does not need to shake hands again and renegotiate the key, which can reduce the time consumption of 40ms. Compared with STAs in strong field conditions, STAs in weak field conditions can further reduce the time consumption by reducing the handshake process using the Wi-Fi switching method provided in the embodiment of the present application.
[0223] like Figure 7 As shown, a Wi-Fi switching method provided by an embodiment of the present application is shown, and the method can be applied to a system architecture including a terminal device and a first access point, wherein the terminal device can be understood as the STA described above, and the access point can be understood as the AP1 described above. The method can specifically include the following contents:
[0224] S701, a terminal device sends a first request message, and correspondingly, a first access point receives the first request message.
[0225] It should be noted that the terminal device and the first access point are end-pipe collaborative, where "end" refers to the terminal device and "pipe" refers to the first access point. The end-pipe collaborative terminal device and the first access point can collaboratively process information, for example, save the first key.
[0226] It should be noted that the first request information is used to request the first access point to save the first key.
[0227] Exemplarily, the first request information is an Action request frame, and the first key may be key 1, which is used for the terminal device to transmit data with the first access point. The first key may include PTK1 and / or GTK1.
[0228] In one implementation, the terminal device may set the time for the first access point to store the first key through the first request information.
[0229] S702: The first access point sends first response information, and correspondingly, the terminal device receives the first response information.
[0230] Exemplarily, the first response information is an Aciton response frame.
[0231] It should be noted that the first response information is used to indicate that the first access point supports key storage.
[0232] It should be understood that after the first access point receives the first request information, if the first access point supports key storage, the first access point will feed back first response information to the terminal device.
[0233] In an implementation manner, if the first access point does not support key preservation, the first access point may feed back to the terminal device response information indicating that the first access point does not support key preservation.
[0234] It should be understood that if the first access point does not support key preservation, the terminal device needs to renegotiate the key during a subsequent re-access to the first access point.
[0235] S703: The terminal device saves the first key according to the first response information received from the first access point.
[0236] In one implementation, the terminal device may save the BSSID of the first access point while saving the first key. Based on this, the terminal device saves the first key, the BSSID of the first access point, and the MAC address of the terminal device.
[0237] S704: The first access point saves the first key according to the first request information.
[0238] Exemplarily, the first key is PTK1 or GTK1.
[0239] It should be noted that, if the first access point supports key storage, the first key may be stored after receiving the first request information.
[0240] In one implementation, the first access point may save the MAC address of the terminal device while saving the first key. Based on this, the first access point saves the first key, the BSSID of the first access point, and the MAC address of the terminal device.
[0241] Further, the terminal device disconnects from the first access point and accesses the second access point; and the terminal device disconnects from the second access point and accesses the first access point again through the first key.
[0242] That is to say, the terminal device can access the first access point again by using the key saved by previously accessing the first access point, thereby saving the process of accessing the first access point again to renegotiate the key and saving time.
[0243] Specifically, the terminal device sends a second request message to the first access point, the second request message includes first encrypted information, the first encrypted information is information obtained by encrypting the first information using the first key, and the first information includes the MAC address of the terminal device and / or the BSSID of the first access point.
[0244] In one implementation, the first encrypted information is carried in a first field, and the second request information includes the first field.
[0245] Exemplarily, the second request information is an association request frame. The association request frame carries a Vendor IE, and the Vendor IE includes the first encrypted information. Among them, the first field is the Vendor IE.
[0246] It should be understood that before the terminal device sends the second request information to the first access point, the terminal device encrypts the first information using the first key.
[0247] For the first access point, the first key may be used to encrypt the second information to obtain the second encrypted information, where the second information includes the MAC address of the terminal device and / or the BSSID of the first access point.
[0248] It should be noted that the embodiment of the present application does not limit the specific information included in the first information and the second information, and the first information and the second information including the MAC address of the terminal device and / or the BSSID of the first access point are only for exemplary purposes.
[0249] That is, the first access point may use the previously stored first key to encrypt the MAC address of the terminal device and / or the BSSID of the first access point.
[0250] It should be noted that, when the first access point previously saved the first key, it also saved the MAC address of the terminal device. Based on this, the first access point saves the second information, so that the first access point can use the first key to encrypt the second information.
[0251] Exemplarily, if the terminal device uses PTK1 to encrypt the first encrypted information, the first access point also uses PTK1 to encrypt the second encrypted information. If the terminal device uses GTK1 to encrypt the first encrypted information, the first access point also uses GTK1 to encrypt the second encrypted information.
[0252] In one implementation, the first access point sends second response information to the terminal device according to the consistency between the first encryption information and the second encryption information, where the second response information is used to indicate that the first key is valid.
[0253] Exemplarily, the second response information is an association response frame.
[0254] That is, the first access point encrypts to obtain the second encrypted information, and the terminal device encrypts to obtain the first encrypted information. The first access point can compare the first encrypted information received from the terminal device with the second encrypted information. If the information is consistent, the first key is verified to be valid, and the first access point and the terminal device can use the previously saved first key to transmit data.
[0255] For the first access point, the first encrypted information may be decrypted using the first key to obtain the first information, where the first information includes the MAC address of the terminal device and / or the BSSID of the first access point.
[0256] That is, the first access point can decrypt the first encrypted information using the previously stored first key.
[0257] Exemplarily, if the terminal device uses PTK1 to encrypt and obtain the first encrypted information, the first access point uses PTK1 to decrypt and obtain the first information; if the terminal device uses GTK1 to encrypt and obtain the second encrypted information, the first access point uses GTK1 to decrypt and obtain the first information.
[0258] In one implementation, the first access point sends second response information to the terminal device according to the consistency between the first information and the second information, where the second response information is used to indicate that the first key is valid.
[0259] That is to say, the first access point can decrypt the first encrypted information received from the terminal device to obtain the first information, and compare the second information with the first information. If the information is consistent, the first key is verified to be valid, and the first access point and the terminal device can use the previously saved first key to transmit data.
[0260] In one implementation, the first access point sends second response information to the terminal device based on successfully decrypting the first encrypted information using the first key, where the second response information is used to indicate that the first key is valid.
[0261] That is, when the first access point successfully decrypts the first encryption using the previously saved first key, it can be verified that the first key is valid.
[0262] It should be noted that, before the terminal device sends the second request information to the first access point, the terminal device scans the first access point and determines that the first access point is a historical access point.
[0263] That is, when the terminal device determines that the first access point is an access point that has been accessed before, the second request information will be sent to the first access point. If the first access point is not a historical access point of the terminal device, the terminal device will not send the second request information to the first access point, and the terminal device will access the access point through authentication, association, and handshake processes. In other words, if the first access point is not a historical access point of the terminal device, the terminal device needs to renegotiate the key with the access point.
[0264] In one implementation, after the terminal device sends the second request information to the first access point, it may also receive a third response information from the first access point, and the third response information is used to indicate that the first key is invalid. If the first key is invalid, the terminal device needs to obtain the second key through handshake, and the second key is used to transmit data between the terminal device and the first access point.
[0265] That is, when the first key is invalid, the terminal device needs to renegotiate the key with the first access point through a handshake process.
[0266] Exemplarily, the first key may be invalid in the following situations:
[0267] In case 1, when the first access point verifies that the first encryption information is inconsistent with the second encryption information, the first access point may feed back third response information to the terminal device to indicate that the first key is invalid.
[0268] In case 2, when the first access point verifies that the first information is inconsistent with the second information, the first access point may feed back third response information to the terminal device to indicate that the first key is invalid.
[0269] In case three, when the first access point fails to decrypt the first encrypted information using the first key, the first access point may feed back third response information to the terminal device to indicate that the first key is invalid.
[0270] Based on the above solution, when the terminal device re-accesses the access point it has accessed before, it can use the previously negotiated key to transmit data without the need to handshake again and renegotiate the key, thus saving time in the access process, making the terminal service smoother and improving the user experience.
[0271] Figure 8 Schematic block diagram of a device according to an embodiment of the present application. The device may be a terminal device or an access point as described above. Figure 8The device 800 shown may include: a processor 810, a transceiver 820, and a memory 830. The processor 810, the transceiver 820, and the memory 830 are connected via an internal connection path, the memory 830 is used to store programs, the processor 810 is used to execute the programs stored in the memory 830, and the transceiver 820 receives / sends messages. Optionally, the memory 830 may be coupled to the processor 810 via an interface, or may be integrated with the processor 810.
[0272] It should be noted that the transceiver 820 may include but is not limited to a transceiver device such as an input / output interface to achieve communication between devices.
[0273] In the implementation process, each step of the above method can be completed by an integrated logic circuit of hardware in the processor 810 or an instruction in the form of software. The method disclosed in conjunction with the embodiment of the present application can be directly embodied as a hardware processor for execution, or a combination of hardware and software modules in the processor for execution. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory 830, and the processor 810 reads the information in the storage 830 and completes the steps of the above method in conjunction with its hardware. To avoid repetition, it is not described in detail here.
[0274] It should also be understood that in the embodiment of the present application, the memory may include a read-only memory and a random access memory, and provide instructions and data to the processor. A part of the processor may also include a non-volatile random access memory.
[0275] The embodiment of the present application provides a computer program product, which, when executed on a device, enables the device to execute the technical solution in the above embodiment. Its implementation principle and technical effect are similar to those of the above method-related embodiments, and will not be described in detail here.
[0276] The embodiment of the present application provides a readable storage medium, which contains instructions. When the instructions are executed on a device, the device executes the technical solution of the above embodiment. The implementation principle and technical effect are similar and will not be repeated here.
[0277] The embodiment of the present application provides a chip, which is used to execute instructions. When the chip is running, the technical solution in the above embodiment is executed. The implementation principle and technical effect are similar and will not be repeated here.
[0278] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the embodiments of the present application.
[0279] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the above-described devices and units (modules) can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0280] In the several embodiments provided in the present application, it should be understood that the disclosed devices, apparatuses and methods can be implemented in other ways. For example, the device embodiments described above are only schematic. For example, the division of the unit is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.
[0281] The units described above as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0282] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
[0283] If the above functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the prior art or the part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk and other media that can store program code.
[0284] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
Claims
1. A Wi-Fi switching method, characterized in that: The method is applied to a terminal device, the terminal device is connected to a first access point, and the method includes: The terminal device sends first request information to the first access point, where the first request information is used to request the first access point to save a first key; The terminal device saves the first key according to first response information received from the first access point, where the first key is used for transmitting data between the terminal device and the first access point, and the first response information is used to indicate that the first access point supports key storage.
2. The method according to claim 1, characterized in that The method further comprises: The terminal device disconnects from the first access point and accesses the second access point; The terminal device disconnects from the second access point and accesses the first access point again by using the first key.
3. The method according to claim 2, characterized in that The terminal device disconnects from the second access point and accesses the first access point again by using the first key, including: The terminal device sends a second request message to the first access point, where the second request message includes first encrypted information, and the first encrypted information is information obtained by encrypting the first information using the first key.
4. The method according to claim 3, characterized in that The method further comprises: The terminal device receives second response information from the first access point, where the second response information is used to indicate that the first key is valid; The terminal device transmits data with the first access point using the first key according to the second response information.
5. The method according to claim 2 or 3, characterized in that: Before the terminal device sends the second request information to the first access point, the method further includes: The terminal device scans the first access point and determines that the first access point is a historical access point.
6. The method according to claim 3, characterized in that The method further comprises: The terminal device receives third response information from the first access point, where the third response information is used to indicate that the first key is invalid; The terminal device obtains a second key through handshake, and the second key is used for transmitting data between the terminal device and the first access point.
7. The method according to any one of claims 3, 4 and 6, characterized in that: The first information includes a media access control MAC address of the terminal device and / or a basic service set identifier BSSID of the first access point.
8. The method according to any one of claims 3 to 7, characterized in that The second request information is an association request frame.
9. The method according to claim 4, characterized in that The second response information is an association response frame.
10. The method according to any one of claims 3 or 4, 6 to 9, characterized in that: The first encrypted information is carried in a first field, and the second request information includes the first field.
11. The method according to any one of claims 1 to 10, characterized in that The first request information is an Action request frame.
12. The method according to any one of claims 1 to 11, characterized in that The first response information is an Action response frame.
13. A Wi-Fi switching method, characterized in that: The method is applied to a first access point, the first access point is connected to a terminal device, and the method includes: The first access point receives first request information from the terminal device; The first access point sends a first response message to the terminal device, where the first response message indicates that the first access point supports key storage; The first access point saves a first key according to the first request information, where the first key is used for transmitting data between the first access point and the terminal device.
14. The method according to claim 13, characterized in that The method further comprises: The first access point disconnects from the terminal device; The first access point is connected to the terminal device again through the first key.
15. The method according to claim 14, characterized in that The first access point is connected to the terminal device again by using the first key, including: The first access point receives second request information from the terminal device, where the second request information includes first encrypted information, and the first encrypted information is information obtained after the terminal device encrypts the first information using the first key.
16. The method according to claim 15, characterized in that The method further comprises: The first access point encrypts second information using the first key to obtain second encrypted information.
17. The method according to claim 15, characterized in that The method further comprises: The first access point decrypts the first encrypted information using the first key to obtain first information.
18. The method according to claim 16, characterized in that The method further comprises: The first access point sends second response information to the terminal device according to the consistency between the first encryption information and the second encryption information, where the second response information is used to indicate that the first key is valid.
19. The method according to claim 17, characterized in that The method further comprises: The first access point sends second response information to the terminal device according to the consistency between the first information and the second information, where the second response information is used to indicate that the first key is valid.
20. The method according to claim 15, characterized in that The method further comprises: The first access point sends second response information to the terminal device according to successfully decrypting the first encrypted information using the first key, where the second response information is used to indicate that the first key is valid.
21. The method according to any one of claims 15 to 20, characterized in that The first information includes a media access control MAC address of the terminal device and / or a basic service set identifier BSSID of the first access point.
22. The method according to any one of claims 16, 18 and 19, characterized in that: The second information includes the MAC address of the terminal device and / or the BSSID of the first access point.
23. The method according to any one of claims 15 to 22, characterized in that The second request information is an association request frame.
24. The method according to any one of claims 18 to 20, characterized in that The second response information is an association response frame.
25. The method according to any one of claims 15 to 24, characterized in that The first encrypted information is carried in a first field, and the second request information includes the first field.
26. The method according to any one of claims 13 to 25, characterized in that The first request information is an Action request frame.
27. The method according to any one of claims 13 to 26, characterized in that The first response information is an Action response frame.
28. A terminal device, characterized in that: include: a transceiver, for receiving and sending messages; Memory, used to store programs; A processor, configured to execute the program stored in the memory so that the terminal device executes the method as claimed in any one of claims 1 to 12.
29. A first access point, characterized in that: include: a transceiver, for receiving and sending messages; Memory, used to store programs; A processor, configured to execute the program stored in the memory, so that the first access point executes the method according to any one of claims 13 to 27.
30. A computer-readable storage medium, characterized in that: A computer program is stored thereon, and when the computer program is executed by a computer, the computer is caused to implement the method according to any one of claims 1 to 12 and 13 to 27.
31. A computer program product comprising instructions, characterized in that When the computer program product is run on a computer, the computer is caused to perform the method according to any one of claims 1 to 12 and 13 to 27.
32. A chip, characterized in that: The chip includes a processor and a data interface, and the processor reads instructions stored in a memory through the data interface to execute the method as claimed in any one of claims 1 to 12 and 13 to 27.
Citation Information
Cited By
Multi-band wireless local area network security switching method, device and equipment and storage medium
CN121334669A