Wireless local area network bidirectional identity authentication method based on access interaction time delay characteristics
By extracting the access interaction delay characteristics and inputting a pre-trained authentication model for identity authentication in the early stages of the connection between the wireless LAN device and the access point, the problem of difficulty in time identifying illegal devices and high computing resource consumption in the prior art is solved, and efficient and secure wireless LAN authentication is achieved.
Patent Information
- Application Number
- CN202510064074.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-15
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
Smart Images

Figure CN119997013A_ABST
Abstract
Description
Technical Field
[0001] The invention relates to the technical field of wireless local area network security, and in particular to a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics. Background Art
[0002] In a wireless LAN environment, the connection process between a wireless terminal device (STA) and an access point (AP) involves multiple key stages such as scanning, authentication, and association. The security of these stages is crucial to ensuring the overall security of the network. However, with the continuous evolution of network attack methods, the existing authentication mechanism faces many challenges. Especially in the authentication and association stages, how to quickly and accurately identify and prevent the access of illegal network entities has become a major technical problem in the current wireless LAN security field. Traditional authentication methods often rely on static authentication materials, such as pre-shared keys (PSK) or digital certificates. Once these materials are leaked or obtained by attackers, they may be used for illegal access, thereby threatening the overall security of the network. Therefore, how to implement an efficient and real-time authentication mechanism without increasing system resource consumption has become a technical problem that needs to be solved urgently.
[0003] In response to the above technical problems, existing technical solutions mainly identify and classify wireless devices by analyzing the timing characteristics of network traffic. Specifically, these solutions include using the arrival interval as a feature to distinguish the types of different wireless access points (APs), and building a unique signature of the device by analyzing the network behavior of the wireless device. For example, the solution proposed by Gao et al. passively monitors wireless network traffic, uses wavelet transform technology to extract energy characteristics, generates feature vectors reflecting AP behavior, and then builds an AP fingerprint library for identifying and classifying unknown AP devices. Neumann et al. capture different network parameters of wireless devices, such as transmission time, arrival interval, etc., to generate fingerprint information of the device, and measure the similarity between the candidate device signature and the reference device signature through cosine similarity to achieve device identification and identity confirmation. These solutions have improved the security of wireless LANs and the accuracy of device identification to a certain extent.
[0004] Although the above-mentioned existing technical solutions have made certain progress in wireless LAN authentication and device identification, there are still some significant problems. First, the existing authentication methods often lag behind the device connection process, making it difficult to detect and block illegal network entities in time at the beginning of the connection, thus bringing potential security risks to the network. Secondly, the technical solution based on network traffic timing requires real-time or offline collection, storage and analysis of a large amount of network traffic, which leads to high computing resource consumption, especially in high-traffic network environments, the performance of the system may be seriously affected. In addition, the existing security authentication mechanism relies too much on static authentication materials. Once these materials are obtained by attackers, they may be forged or reused, thereby reducing the security and reliability of the authentication mechanism. Therefore, how to overcome the limitations of the existing technology and realize an efficient, real-time and secure wireless LAN authentication mechanism is still a key issue that needs to be solved in the current wireless LAN security field. Summary of the invention
[0005] In order to solve the above technical problems, the present invention provides a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics. The technical problem to be solved by the present invention is achieved through the following technical solutions:
[0006] In a first aspect, the present invention provides a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics, comprising:
[0007] Obtaining the original communication data packets between the terminal device and the access point during the access phase;
[0008] Filter the original communication data packets to obtain a set of effective filtered data packets;
[0009] Extracting the timing characteristics of access interaction from the effective filtering data packet set;
[0010] Input the time series features into the pre-trained authentication model, and output the authentication result based on the pre-trained authentication model;
[0011] Perform access response actions based on the authentication result.
[0012] Optionally, the timing characteristics include: request sending time, response time, and response processing delay.
[0013] Optionally, the request sending time includes: an authentication request sending time, an association request sending time, a handshake request sending time, a broadcast request sending time, and a probe request sending time;
[0014] Response time includes: authentication request response time, association request response time, handshake request response time, broadcast request response time, and probe request response time;
[0015] The response processing delay includes: the authentication request response processing delay, the association request response processing delay, the handshake request response processing delay, the broadcast request response processing delay, and the probe request response processing delay.
[0016] Optionally, the pre-trained authentication model is a pre-trained Bayesian probability model.
[0017] Optionally, the authentication result includes: the terminal device is illegal or the access point is illegal, and the access response action is performed based on the authentication result, including:
[0018] When the authentication result is that the terminal device is illegal, the access point rejects the access request of the terminal device;
[0019] When the authentication result is that the access point is illegal, the terminal device rejects the access request of the access point.
[0020] Optionally, the training process of the pre-trained certification model includes:
[0021] Obtaining raw communication data packet samples;
[0022] Filtering the original communication data packet samples to obtain a set of effective filtered data packet samples;
[0023] Obtaining a time series sample feature from a valid filtered data packet sample set; wherein the time series sample feature is sample data stored according to the MAC address of the terminal device and the access point;
[0024] Input the time series sample features into the initial certification model for training;
[0025] When the preset iteration threshold is met, the corresponding initial authentication model is used as the pre-trained authentication model.
[0026] Optionally, the wireless local area network bidirectional identity authentication method based on access interaction delay characteristics further includes:
[0027] Incremental learning is used to update the pre-trained certification model.
[0028] Optionally, filtering is performed on the original communication data packet to obtain a valid filtered data packet set, including:
[0029] Decode the original communication data packet to obtain valid information; the valid information includes: protocol header information and data content;
[0030] Perform data filtering on valid information to obtain a set of valid filtered data packets.
[0031] In a second aspect, the present invention provides a wireless local area network bidirectional identity authentication device based on access interaction delay characteristics, and the wireless local area network bidirectional identity authentication device based on access interaction delay characteristics includes: an acquisition unit, a filtering unit, an authentication unit, and an execution unit;
[0032] The acquisition unit is used to: acquire the original communication data packet between the terminal device and the access point during the access phase;
[0033] The filtering unit is used to: filter the original communication data packet to obtain a valid filtered data packet set;
[0034] The acquisition unit is also used to: extract the timing characteristics of access interaction from the effective filtering data packet set;
[0035] The authentication unit is used to: input the time series feature into the pre-trained authentication model, and output the authentication result based on the pre-trained authentication model;
[0036] The execution unit is used to: execute an access response action based on the authentication result.
[0037] In a third aspect, the present invention provides a wireless local area network two-way identity authentication device based on access interaction delay characteristics, comprising: a processor, a storage medium and a bus, the storage medium storing machine-readable instructions executable by the processor, when the wireless local area network two-way identity authentication device based on access interaction delay characteristics is running, the processor and the storage medium communicate through the bus, and the processor executes the machine-readable instructions to perform the steps of the wireless local area network two-way identity authentication method based on access interaction delay characteristics as described in the first aspect above.
[0038] The present invention provides a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics, comprising: obtaining original communication data packets between a terminal device and an access point in an access phase; filtering the original communication data packets to obtain a valid filtered data packet set; extracting timing characteristics during access interaction from the valid filtered data packet set; inputting the timing characteristics into a pre-trained authentication model, and outputting an authentication result based on the pre-trained authentication model; and executing an access response action based on the authentication result. In the present invention, by extracting the timing features in the authentication association process before the device is formally connected to the access point, and based on the timing features and the pre-trained authentication model, potential illegal devices can be quickly identified, and malicious devices or malicious access points can be discovered in time at the initial stage of connection, effectively reducing the risk of wireless LAN device systems being attacked, and improving the security and defense capabilities of the wireless LAN device system; in addition, by extracting lightweight timing features, the process of analyzing and processing a large amount of network traffic data is reduced. Compared with the traditional traffic timing analysis method, the requirements for storage, computing and hardware performance are greatly reduced, thereby improving the response speed of the wireless LAN device system to the identity authentication process; finally, since the method of the present invention dynamically generates timing features associated with the authentication association process, it avoids dependence on static pre-shared keys or fixed authentication materials. Therefore, even if an attacker steals the timing features used for authentication, since these timing features are dynamically generated based on specific devices, they cannot be directly reused, which significantly improves the security of the authentication process and enhances the resistance of the wireless LAN device system to forged authentication behaviors, thereby effectively reducing the potential security threats to the wireless LAN device system.
[0039] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] Figure 1 The schematic diagram of the architecture of the wireless local area network two-way identity authentication scenario is exemplarily shown;
[0041] Figure 2 A schematic flow chart of a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics provided by an embodiment of the present invention;
[0042] Figure 3 The schematic diagram of the data packet of the terminal device and the access point in the authentication association stage is exemplarily shown;
[0043] Figure 4 The complete execution process block diagram of a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics is exemplarily shown;
[0044] Figure 5An exemplary illustration of an association authentication time sequence line chart and a comparison chart of the same device connecting to different APs corresponding to the method of the present invention is shown;
[0045] Figure 6 An exemplary illustration of an association authentication time sequence line chart and a comparison chart of different devices connected to the same AP using the method of the present invention is shown;
[0046] Figure 7 A schematic diagram of the structure of a wireless local area network bidirectional identity authentication device based on access interaction delay characteristics provided by an embodiment of the present invention;
[0047] Figure 8 A schematic structural diagram of a wireless local area network bidirectional identity authentication device based on access interaction delay characteristics provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0048] Before introducing the present invention, a brief introduction to the technical contents involved in the present invention is first given.
[0049] The process of connecting a wireless terminal device (STA) to an access point (AP) includes three key stages: scanning, authentication, and association. In the scanning stage, the device searches for available access points in the surrounding area through active scanning or passive scanning. In active scanning, the device sends a probe request and the access point responds to the probe response; in passive scanning, the device obtains information by listening to the beacon frames broadcast by the access point. Through scanning, the device can obtain basic information about the access point, such as SSID, encryption method, etc., and select a suitable access point for connection. After entering the authentication stage, the device sends an authentication request (AuthenticationRequest) to the access point for identity authentication. According to the authentication method (such as open system authentication or shared key authentication), the access point will verify the identity of the device and return the authentication result through the authentication response (Authentication Response). If the authentication is successful, the device will then send an association request (Association Request) to the access point to request to establish a connection with the access point. After receiving the request, the access point will verify the device's connection authority and confirm that the device has been successfully connected through the association response (Association Response).
[0050] After the device and the access point are successfully authenticated and associated, a four-way handshake key negotiation process will be performed to ensure that both the device and the access point can generate the same session key and confirm that the authentication between the device and the access point is valid. The specific process is as follows: First, the device and the access point exchange two random numbers (ANonce and SNonce). In the first handshake, the access point generates a random number (ANonce) and sends it to the device, and the device generates its own random number (SNonce) and sends it back to the access point. Next, the device uses its own SNonce, the access point's ANonce, and the shared key (such as PSK) to calculate a session key, and sends this key to the access point in the second handshake. After receiving the device's session key in the third handshake, the access point verifies its correctness, uses the same key for calculation, and sends a confirmation message to the device to inform the device that the session key has been successfully generated. Finally, after the device receives the access point's confirmation message, the fourth handshake is completed, indicating that both parties have successfully shared the same session key, and subsequent communications can be encrypted using this key to ensure the confidentiality and integrity of data transmission.
[0051] Due to the differences in hardware architecture, processing power and protocol implementation between different devices and access points, there are differences in their timing characteristics during authentication, association and four-way handshake. These differences are reflected in the time interval of data exchange, response delay, etc., forming unique and stable timing characteristics between devices and access points. By analyzing these timing characteristics, the behavior patterns of specific devices and access points during authentication association and four-way handshake can be identified, and then used for device identity authentication. This authentication method based on timing characteristics can provide a new device identification method, which not only improves security, but also reduces dependence on traditional authentication methods, and has strong anti-counterfeiting capabilities.
[0052] The present invention is further described in detail below with reference to specific embodiments, but the embodiments of the present invention are not limited thereto.
[0053] In order to ensure the security and defense capability of the wireless local area network device system while improving the response speed of the identity authentication process, the embodiment of the present invention provides a wireless local area network bidirectional identity authentication method based on the access interaction delay feature. In order to clearly describe the application process of the wireless local area network bidirectional identity authentication method provided by the embodiment of the present invention, Figure 1 The schematic diagram of the architecture of the wireless local area network two-way identity authentication scenario is shown as an example. Figure 1As shown, the terminal device and the legal access point establish a secure communication connection through a two-way authentication mechanism. That is, the wireless local area network two-way identity authentication method provided by the present invention can be set not only on the access point side, but also on the terminal device side, and the two-way authentication is completed through mutual detection at both ends. Specifically, when the terminal device attempts to connect to the access point, the terminal and the access point will perform authentication, association, access and handshake processes, and a series of data packets will be generated during this process. These data packets will be captured at both ends of the access point and the terminal device through a network traffic collection tool and saved as log files. Subsequently, the log file will be passed to the data classification processing module to extract the fingerprint information of the access point or the terminal device. These fingerprint information will be compared with the records in the local or third-party database (AP authentication database and terminal authentication database). If the fingerprint information matches successfully, the terminal device is allowed to access the AP; if the match fails, the AP actively disconnects.
[0054] Further, Figure 2 A flow chart of a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics provided by an embodiment of the present invention. Figure 2 As shown, including:
[0055] S101. Acquire original communication data packets between a terminal device and an access point during an access phase.
[0056] It should be noted that the original communication data packets are all the data packets generated between the terminal device and the access point during the access phase, which contain rich communication information, such as source address, destination address, port number, protocol type, data content, etc. However, in the authentication process, not all data packets are necessary or relevant, so filtering can also be used to screen out valid data packets.
[0057] In addition, you can use network traffic analysis tools such as OmniPeek or Wireshark, combined with the monitor mode of the wireless network card, to capture and analyze the original communication data packets. In monitor mode, the wireless network card no longer relies on the traditional network connection method, but is set to a monitoring state, which can monitor and capture all data frames transmitted through the specified wireless channel.
[0058] Furthermore, the wireless local area network bidirectional identity authentication method provided by the present invention can be specifically applied to a wireless local area network device system, which can include: an access point and a terminal device. Correspondingly, the wireless local area network bidirectional identity authentication method can be embedded in both the access point and the terminal device to complete bidirectional authentication at both ends.
[0059] S102: Filter the original communication data packets to obtain a set of valid filtered data packets.
[0060] Optionally, S102 may specifically include:
[0061] Decode the original communication data packet to obtain valid information; the valid information includes: protocol header information and data content;
[0062] Perform data filtering on valid information to obtain a set of valid filtered data packets.
[0063] It should be noted that, in the embodiment of the present invention, data filtering processing is performed on valid information to further filter out data packets that are directly related to identity authentication and are important. This filtering process can be based on a variety of factors, such as a specific protocol type, content characteristics of the data packet, source address and destination address, etc. By applying these filtering rules, data packets that are irrelevant to identity authentication or redundant can be excluded, thereby obtaining a set of valid filtered data packets that have practical value and significance for the identity authentication process.
[0064] S103: extracting the timing characteristics of access interaction from the effective filtering data packet set.
[0065] Optionally, the timing characteristics include: request sending time, response time, and response processing delay.
[0066] Furthermore, in some other possible implementations, the timing characteristics may also include: round trip time of a data packet, transmission delay, and response time of an intermediate routing node.
[0067] Optionally, the request sending time includes: an authentication request sending time, an association request sending time, a handshake request sending time, a broadcast request sending time, and a probe request sending time;
[0068] Response time includes: authentication request response time, association request response time, handshake request response time, broadcast request response time, and probe request response time;
[0069] The response processing delay includes: the authentication request response processing delay, the association request response processing delay, the handshake request response processing delay, the broadcast request response processing delay, and the probe request response processing delay.
[0070] Figure 3 The schematic diagram of the data packet of the terminal device and the access point in the authentication association stage is shown as an example. Figure 3As shown, in the terminal device (device) authentication phase, the captured Authentication Request (authentication request packet) and Authentication Response (authentication response packet) data can reflect the device's identity authentication process; in the device association phase, the captured Association Request (association request packet) and Association Response (association response packet) data record the process of establishing an association between the device and the access point; in the handshake phase, the captured EAPOL handshake packet can reflect the key exchange process between the device and the access point. By parsing the 802.1X Authentication field and Key Descriptor Type in the EAPOL handshake packet, it can be determined whether the data packet belongs to the handshake process. Further, by analyzing the MessageNumber field, the position of the handshake packet can be accurately located, thereby distinguishing the specific data packets of the first handshake, the second handshake, and the final handshake, so as to finally realize the extraction of timing features during access interaction.
[0071] S104: Input the time series features into the pre-trained authentication model, and output the authentication result based on the pre-trained authentication model.
[0072] Optionally, the pre-trained authentication model is a pre-trained Bayesian probability model.
[0073] Optionally, the training process of the pre-trained certification model includes:
[0074] Obtaining raw communication data packet samples;
[0075] Filtering the original communication data packet samples to obtain a set of effective filtered data packet samples;
[0076] Obtaining a time series sample feature from a valid filtered data packet sample set; wherein the time series sample feature is sample data stored according to the MAC address of the terminal device and the access point;
[0077] Input the time series sample features into the initial certification model for training;
[0078] When the preset iteration threshold is met, the corresponding initial authentication model is used as the pre-trained authentication model.
[0079] S105. Execute access response action based on the authentication result.
[0080] Optionally, the authentication result includes: the terminal device is illegal or the access point is illegal, and the access response action is performed based on the authentication result, including:
[0081] When the authentication result is that the terminal device is illegal, the access point rejects the access request of the terminal device;
[0082] When the authentication result is that the access point is illegal, the terminal device rejects the access request of the access point.
[0083] Optionally, the wireless local area network bidirectional identity authentication method based on access interaction delay characteristics further includes:
[0084] Incremental learning is used to update the pre-trained certification model.
[0085] Optionally, in order to ensure that the wireless LAN device system can adapt to the changes in the terminal device state and the dynamic characteristics of the access environment, in an embodiment of the present invention, incremental learning is used to perform model update processing on the pre-trained authentication model. Specifically, during the device access process, the wireless LAN device system will continuously monitor the timing features used for authentication association, and use the new timing features for authentication judgment based on the existing model. If there is a certain deviation in the new timing features, but it is still within the reasonable range of changes in the device behavior, the wireless LAN device system will use the new timing features as a supplement, optimize the existing authentication model by incremental training, and gradually improve the adaptability of the authentication model to the device behavior. For significant behavioral changes in the terminal device, such as hardware replacement, network environment changes, or long-term inactivity, the original fingerprint may become invalid. To this end, the wireless LAN device system can allow the deletion of the old fingerprint data of the terminal device, re-register and generate a new model to ensure the accuracy and reliability of identity authentication.
[0086] An embodiment of the present invention provides a wireless local area network bidirectional identity authentication method, comprising: obtaining original communication data packets between a terminal device and an access point during an access phase; filtering the original communication data packets to obtain a set of valid filtered data packets; extracting timing features during access interaction from the set of valid filtered data packets; inputting the timing features into a pre-trained authentication model, and outputting an authentication result based on the pre-trained authentication model; and executing an access response action based on the authentication result. In the present invention, by extracting the timing features in the authentication association process before the device is formally connected to the access point, and based on the timing features and the pre-trained authentication model, potential illegal devices can be quickly identified, and malicious devices or malicious access points can be discovered in time at the initial stage of connection, effectively reducing the risk of wireless LAN device systems being attacked, and improving the security and defense capabilities of the wireless LAN device system; in addition, by extracting lightweight timing features, the process of analyzing and processing a large amount of network traffic data is reduced. Compared with the traditional traffic timing analysis method, the requirements for storage, computing and hardware performance are greatly reduced, thereby improving the response speed of the wireless LAN device system to the identity authentication process; finally, since the method of the present invention dynamically generates timing features associated with the authentication association process, it avoids dependence on static pre-shared keys or fixed authentication materials. Therefore, even if an attacker steals the timing features used for authentication, since these timing features are dynamically generated based on specific devices, they cannot be directly reused, which significantly improves the security of the authentication process and enhances the resistance of the wireless LAN device system to forged authentication behaviors, thereby effectively reducing the potential security threats to the wireless LAN device system.
[0087] In order to generally illustrate the execution process of a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics provided by an embodiment of the present invention, Figure 4 The following is a flowchart showing the complete execution process of a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics. Figure 4 As shown, first deploy the environment, then start monitoring, when the terminal requests a connection, capture the key handshake packet in the access phase, classify the data packets according to the handshake packet, and determine whether to perform a registration operation. If no registration operation is performed, directly perform fingerprint comparison. If a registration operation is performed, send registration information to the server and then perform corresponding fingerprint matching. If the match is successful, the access point agrees to the device access, and if the match fails, the access point actively disconnects the device. If the device verifies the access point, just replace the execution subject, and the steps are the same as the above execution process, which will not be repeated in this embodiment.
[0088] In order to further illustrate the effectiveness of a wireless local area network bidirectional identity authentication method based on access interaction delay characteristics provided by an embodiment of the present invention, a simulation experiment was also conducted. Specifically, Figure 5 The associated authentication timing line chart and comparison chart of the same device connected to different APs corresponding to the method of the present invention are exemplarily shown. Figure 5 The figure above shows the delay variation of the authentication phase when the same terminal device initiates connection requests to different APs. The horizontal axis represents the number of connection request experiments, and the vertical axis corresponds to the delay of the authentication request. Figure 5 The following figure shows the latency changes in the association phase under the corresponding scenario. The horizontal axis represents the number of connection request experiments, and the vertical axis represents the latency of the association request. Figure 5 It can be seen that in the process of the same terminal device establishing connections with different APs, the delay data in the authentication and association stages show stability and distinguishability, indicating that the delay information can be used as an effective component of the device fingerprint feature. Figure 6 The associated authentication timing line chart and comparison chart of different devices connected to the same AP corresponding to the method of the present invention are exemplarily shown. Figure 6 The figure above shows the delay variation of the authentication phase when different terminal devices initiate connection requests to the same AP. The horizontal axis represents the number of connection request experiments, and the vertical axis corresponds to the delay of the authentication request. Figure 6 The following figure shows the latency changes in the association phase under the corresponding scenario. Figure 6 The results verify the differences in the delays in the authentication and association stages of different terminal devices when connecting to the same AP, indicating that the solution of the present invention is also applicable to the identification and authentication of wireless terminals by access points.
[0089] The method provided in the embodiment of the present invention can be applied to an electronic device. Specifically, the electronic device can be: a desktop computer, a portable computer, an intelligent mobile terminal, a server, etc., which is not limited in the embodiment of the present invention.
[0090] Based on the same inventive concept, an embodiment of the present invention further provides a wireless local area network bidirectional identity authentication device based on access interaction delay characteristics. Figure 7 A schematic diagram of the structure of a wireless local area network bidirectional identity authentication device based on access interaction delay characteristics provided by an embodiment of the present invention. Figure 7 As shown, it includes: an acquisition unit 701, a filtering unit 702, an authentication unit 703 and an execution unit 704;
[0091] The acquisition unit 701 is used to: acquire the original communication data packet between the terminal device and the access point during the access phase;
[0092] The filtering unit 702 is used to: filter the original communication data packet to obtain a valid filtered data packet set;
[0093] The acquisition unit 701 is further used to: extract the timing characteristics of access interaction from the effective filtering data packet set;
[0094] The authentication unit 703 is used to: input the time series feature into the pre-trained authentication model, and output the authentication result based on the pre-trained authentication model;
[0095] The execution unit 704 is used to: execute an access response action based on the authentication result.
[0096] Figure 8 A schematic diagram of the structure of a wireless local area network bidirectional identity authentication device based on access interaction delay characteristics provided by an embodiment of the present invention includes: a processor 810, a storage medium 820 and a bus 830, the storage medium 820 stores machine-readable instructions executable by the processor 810, when the wireless local area network bidirectional identity authentication device based on access interaction delay characteristics is running, the processor 810 communicates with the storage medium 820 through the bus 830, and the processor 810 executes the machine-readable instructions to execute the steps of the above method embodiment. The specific implementation method and technical effect are similar and will not be repeated here.
[0097] The storage medium may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk storage. Optionally, the storage medium may also be at least one storage device located away from the aforementioned processor.
[0098] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0099] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" etc. means that the specific features or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine the different embodiments or examples described in this specification.
[0100] Although the present invention is described herein in conjunction with various embodiments, in the process of implementing the claimed invention, those skilled in the art can understand and implement other changes of the above disclosed embodiments by viewing the drawings and the disclosed content. In the description of the present invention, the term "comprising" does not exclude other components or steps, "one" or "an" does not exclude multiple situations, and the meaning of "multiple" is two or more, unless otherwise clearly and specifically limited. In addition, certain measures are recorded in different embodiments, but this does not mean that these measures cannot be combined to produce good results.
[0101] The above contents are further detailed descriptions of the present invention in combination with specific preferred embodiments, and it cannot be determined that the specific implementation of the present invention is limited to these descriptions. For ordinary technicians in the technical field to which the present invention belongs, several simple deductions or substitutions can be made without departing from the concept of the present invention, which should be regarded as falling within the scope of protection of the present invention.
Claims
1. A wireless local area network bidirectional identity authentication method based on access interaction delay characteristics, characterized in that: include: Obtaining the original communication data packets between the terminal device and the access point during the access phase; Filtering the original communication data packets to obtain a set of effective filtered data packets; Extracting the timing characteristics of access interaction from the effective filtering data packet set; Inputting the time series feature into a pre-trained authentication model, and outputting an authentication result based on the pre-trained authentication model; An access response action is performed based on the authentication result.
2. The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics according to claim 1 is characterized in that: The timing characteristics include: request sending time, response time and response processing delay.
3. The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics according to claim 2 is characterized in that: The request sending time includes: authentication request sending time, association request sending time, handshake request sending time, broadcast request sending time and probe request sending time; The response time includes: authentication request response time, association request response time, handshake request response time, broadcast request response time and probe request response time; The response processing delay includes: the processing delay of the authentication request response, the processing delay of the association request response, the processing delay of the handshake request response, the processing delay of the broadcast request response and the processing delay of the probe request response.
4. The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics according to claim 1 is characterized in that: The pre-trained authentication model is a pre-trained Bayesian probability model.
5. The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics according to claim 1 is characterized in that: The authentication result includes: the terminal device is illegal or the access point is illegal, and the access response action is performed based on the authentication result, including: When the authentication result indicates that the terminal device is illegal, the access point rejects the access request of the terminal device; When the authentication result is that the access point is illegal, the terminal device rejects the access request of the access point.
6. The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics according to claim 1, characterized in that: The training process of the pre-trained certification model includes: Obtaining raw communication data packet samples; Filtering the original communication data packet samples to obtain a set of effective filtered data packet samples; Acquire a time series sample feature from the effective filtered data packet sample set; wherein the time series sample feature is sample data stored according to the MAC address of the terminal device and the access point; Inputting the time series sample features into an initial authentication model for training; When the preset iteration threshold is met, the corresponding initial authentication model is used as the pre-trained authentication model.
7. The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics according to claim 6 is characterized in that: The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics also includes: Incremental learning is used to perform model update processing on the pre-trained authentication model.
8. The wireless local area network bidirectional identity authentication method based on access interaction delay characteristics according to claim 1, characterized in that: The filtering of the original communication data packet to obtain a valid filtered data packet set includes: Decoding the original communication data packet to obtain valid information; the valid information includes: protocol header information and data content; The valid information is subjected to data filtering processing to obtain the valid filtered data packet set.
9. A wireless local area network bidirectional identity authentication device based on access interaction delay characteristics, characterized in that: The wireless local area network bidirectional identity authentication device based on access interaction delay characteristics comprises: an acquisition unit, a filtering unit, an authentication unit and an execution unit; The acquisition unit is used to: acquire the original communication data packet between the terminal device and the access point during the access phase; The filtering unit is used to: filter the original communication data packet to obtain a valid filtered data packet set; The acquisition unit is also used to: extract the timing characteristics of access interaction from the effective filtering data packet set; The authentication unit is used to: input the time series feature into a pre-trained authentication model, and output an authentication result based on the pre-trained authentication model; The execution unit is used to: execute an access response action based on the authentication result.
10. A wireless local area network bidirectional identity authentication device based on access interaction delay characteristics, characterized in that: include: A processor, a storage medium and a bus, wherein the storage medium stores machine-readable instructions executable by the processor, and when the wireless local area network two-way identity authentication device based on access interaction delay characteristics is running, the processor communicates with the storage medium through the bus, and the processor executes the machine-readable instructions to perform the steps of the wireless local area network two-way identity authentication method based on access interaction delay characteristics as described in any one of claims 1-8.
Citation Information
Patent Citations
Wireless local area network security communication method based on quantum key distribution
CN103338448A
Method and system for generating secret key information, terminal device and access network device
CN103391540A
Block chain node identity authentication method and system based on channel state information
CN112347513A