Wireless network access control method and device, electronic equipment and storage medium
By creating multi-link device association and multi-network interface IP forwarding rules on the AP side, STA can realize access to multi-band wireless networks without adding hardware, solving the problem of high hardware costs.
Patent Information
- Application Number
- CN202311495386.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-10
- Publication Date
- 2025-05-13
AI Technical Summary
When accessing a multi-band wireless network, the access method of wireless networks incurs additional hardware costs.
Through the wireless network access control method on the AP side, the association request frame sent by the STA is received. If it is determined that the STA supports multi-network interface capability information, a multi-link device association with the STA and a multi-network interface IP forwarding rule is created, and the STA creates a corresponding virtual network interface based on the identification of the newly added virtual network interface.
It realizes the establishment of multiple links to access different VLANs through multiple network interfaces, saving hardware costs and avoiding the need to install multiple wireless network cards on the STA.
Smart Images

Figure CN119997152A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a wireless network access control method, device, electronic device and storage medium. Background Art
[0002] The 802.11be protocol is the seventh generation Wifi wireless network (abbreviated as Wifi7) protocol. Wifi7 is also called Extremely High Throughput (EHT) network, which achieves extremely high throughput through a series of system features and multiple mechanism enhancements. The 802.11be protocol defines a multi-link device (MLD) device. A physical radio chip of an MLD device can support two or more frequency bands at the same time: 2GHz, 5GHz and 6GHz.
[0003] like Figure 1 As shown, this is a basic block diagram of an MLD device. Figure 1 The MLD devices in the 802.11be protocol include AP (Access Point) 100 and STA (Station) 101, where STA 101 is a terminal station device in a wireless network and can be regarded as a client. Generally speaking, a device in STA mode (i.e., a terminal station device) does not accept wireless access by itself and needs to be connected to AP 100 for network access. Data communication between devices in STA mode can be forwarded by AP 100. The 802.11be protocol proposes a multi-link operation (MLO) function for MLD devices. One frequency band of an MLD device corresponds to one physical communication link. Multiple links can be established between AP 100 and STA 101. MLO can manage multiple links to achieve network access. Figure 1 Take Link1 (link 1) and Link2 (link 2) in as an example, these two links correspond to 2GHz and 5GHz frequency bands respectively, and STA1, STA2 and STA3 are three wireless network cards on STA101.
[0004] However, in some enterprises, for reasons of network security and construction, internal and external networks are used. One way is to install two STAs at the same time to access the internal and external networks respectively. After each STA establishes a link with the AP, it corresponds to a network interface for multi-link data transmission with the AP. Another way is to install two wireless network cards on one STA (for example, Figure 1STA1 and STA2 in the figure access the internal network and the external network respectively through the two wireless network cards. After the STA establishes a link with the AP through the two wireless network cards, a network interface is corresponding to each wireless network card to realize multi-link data transmission with the AP. When wireless networks with different frequency bands need to be accessed at the same time, the above two wireless network access methods will incur additional hardware costs. Summary of the invention
[0005] In order to solve the problem that the wireless network access method generates additional hardware costs when accessing a multi-band wireless network, the embodiments of the present application provide a wireless network access control method, device, electronic device and storage medium.
[0006] In a first aspect, an embodiment of the present application provides a wireless network access control method implemented by an AP side, including:
[0007] Receive the association request frame sent by the station STA;
[0008] If it is determined that the association request frame includes the STA's ability to support multiple network interfaces, a multi-link device association and a multi-network interface IP forwarding rule are created with the STA, wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, and the identifier of each network interface includes an identifier of the STA's physical network interface and an identifier of a newly added virtual network interface;
[0009] An association response frame is returned to the STA, where the association response frame includes the multi-network interface IP forwarding rule, so that the STA can create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0010] In one implementation, before receiving the association request sent by the STA, the method further includes:
[0011] A beacon frame is sent to a station STA, wherein the beacon frame includes information on the access point AP's ability to support multiple network interfaces.
[0012] In one implementation, before receiving the association request sent by the STA, the method further includes:
[0013] Receiving a probe request frame sent by the STA;
[0014] A probe response frame is returned to the STA, wherein the probe response frame includes information about the access point AP's ability to support multiple network interfaces.
[0015] In one implementation, the network segment supported by the link established with each network interface of the STA is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0016] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0017] In one embodiment, the method further comprises:
[0018] receiving a data message sent by the STA, wherein the data message carries a destination IP address;
[0019] If it is determined that the data packet is an IP packet, when converting the IP packet into a physical layer packet, according to the mapping relationship between the DSCP priority and the MAC priority, the DSCP priority of the IP packet is converted into a corresponding MAC priority;
[0020] Determine the VLAN to which the destination IP address belongs;
[0021] The converted physical layer message is sent to the destination IP address through the network interface corresponding to the VLAN to which the destination IP address belongs.
[0022] In a second aspect, an embodiment of the present application provides a wireless network access control device implemented on an AP side, including:
[0023] A first receiving unit, configured to receive an association request frame sent by a station STA;
[0024] a creating unit, configured to, if it is determined that the association request frame includes information that the STA supports multiple network interface capabilities, create a multi-link device association and a multi-network interface IP forwarding rule with the STA, wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, and the identifier of each network interface includes an identifier of the physical network interface of the STA and an identifier of a newly added virtual network interface;
[0025] The first returning unit is used to return an association response frame to the STA, where the association response frame includes the multi-network interface IP forwarding rule, so that the STA can create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0026] In one embodiment, the device further comprises:
[0027] The first sending unit is used to send a beacon frame to the station STA before receiving the association request sent by the STA, wherein the beacon frame includes the access point AP supporting multiple network interface capability information.
[0028] In one embodiment, it further includes:
[0029] A second receiving unit, configured to receive a probe request frame sent by the STA before receiving an association request sent by the STA;
[0030] The second returning unit is configured to return a probe response frame to the STA, wherein the probe response frame includes information about the access point AP's ability to support multiple network interfaces.
[0031] In one implementation, the network segment supported by the link established with each network interface of the STA is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0032] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0033] In one embodiment, the device further comprises:
[0034] A third receiving unit, configured to receive a data message sent by the STA, wherein the data message carries a destination IP address;
[0035] a conversion unit, configured to, if it is determined that the data packet is an IP packet, convert the DSCP priority of the IP packet into a corresponding MAC priority according to the mapping relationship between the DSCP priority and the MAC priority when converting the IP packet into a physical layer packet;
[0036] A determination unit, configured to determine the VLAN to which the destination IP address belongs;
[0037] The second sending unit is used to send the converted physical layer message to the destination IP address through the network interface corresponding to the VLAN to which the destination IP address belongs.
[0038] In a third aspect, an embodiment of the present application provides a wireless network access control method implemented by a STA side, including:
[0039] Sending an association request frame to an access point AP, wherein the association request frame includes information about the station STA's ability to support multiple network interfaces;
[0040] receiving an association response frame sent by the AP, the association response frame including a multi-network interface IP forwarding rule, the multi-network interface IP forwarding rule being created when the AP creates a multi-link device association with the STA, the multi-network interface IP forwarding rule including a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, the identifier of each network interface including an identifier of a physical network interface of the STA and an identifier of a newly added virtual network interface;
[0041] Create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0042] In one implementation, before sending an association request frame to an access point AP, the method further includes:
[0043] A beacon frame sent by the AP is received, wherein the beacon frame includes information about the AP's ability to support multiple network interfaces.
[0044] In one implementation, before sending an association request frame to an access point AP, the method further includes:
[0045] Sending a probe request frame to the AP;
[0046] A probe response frame returned by the AP is received, wherein the probe response frame includes information about the AP's ability to support multiple network interfaces.
[0047] In one implementation, the network segment supported by the link established with each network interface of the AP is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0048] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0049] In a fourth aspect, an embodiment of the present application provides a wireless network access control device implemented by a STA side, including:
[0050] A first sending unit, configured to send an association request frame to an access point AP, wherein the association request frame includes information about a station STA's ability to support multiple network interfaces;
[0051] a first receiving unit, configured to receive an association response frame sent by the AP, wherein the association response frame includes a multi-network interface IP forwarding rule, wherein the multi-network interface IP forwarding rule is created when the AP creates a multi-link device association with the STA, and wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, wherein the identifier of each network interface includes an identifier of a physical network interface of the STA and an identifier of a newly added virtual network interface;
[0052] A creating unit is used to create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0053] In one embodiment, the device further comprises:
[0054] The second receiving unit is configured to receive a beacon frame sent by an access point AP before sending an association request frame to the AP, wherein the beacon frame includes information indicating that the AP supports multiple network interfaces.
[0055] In one embodiment, the device further comprises:
[0056] A second sending unit, configured to send a detection request frame to an access point AP before sending an association request frame to the AP;
[0057] The third receiving unit is configured to receive a probe response frame returned by the AP, wherein the probe response frame includes information about the AP's ability to support multiple network interfaces.
[0058] In one implementation, the network segment supported by the link established with each network interface of the AP is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0059] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0060] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the wireless network access control method described in the present application when executing the program.
[0061] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps in the wireless network access control method described in the present application.
[0062] The beneficial effects of this application are as follows:
[0063] The wireless network access control method, device, electronic device and storage medium provided by the embodiment of the present application, the AP receives an association request frame sent by a STA, and if it is determined that the association request frame includes information about the STA's ability to support multiple network interfaces, creates a multi-link device association and a multi-network interface IP forwarding rule between the AP and the STA, wherein the multi-network interface IP forwarding rule includes an identifier of each network interface and a virtual local area network (English: Virtual Local Area In the embodiment of the present application, the AP and the STA are provided with a corresponding relationship between the identifiers of the physical network interface and the VLAN identifier, wherein the identifiers of the network interfaces include the identifiers of the physical network interface of the STA and the identifiers of the newly added virtual network interface. The AP returns an association response frame to the STA, and the association response frame includes a multi-network interface IP forwarding rule, so that the STA creates a corresponding virtual network interface according to the identifier of the newly added virtual network interface. In the embodiment of the present application, the capability of supporting multiple network interfaces is pre-set in the AP and the STA. When the STA sends an association request frame to the AP, if both support the multi-network interface capability, the AP creates an MLD association with the STA and creates a multi-network interface IP forwarding rule. The corresponding relationship between the identifiers of each network interface and the VLAN identifier is set in the multi-network interface IP forwarding rule, so that the STA creates a corresponding virtual network interface according to the identifiers. Thus, multiple links for accessing different VLANs are established through the multiple network interfaces. Thus, when data is transmitted with different VLANs, data can be transmitted simultaneously through the corresponding links and network interfaces, without interfering with each other. Moreover, there is no need to add a terminal station device STA or a wireless network card to the terminal station device. Only one STA needs to access different VLANs at the same time, and the STA can create a virtual network interface to achieve the establishment of multiple physical links, thereby saving hardware costs.
[0064] Other features and advantages of the present application will be described in the subsequent description, and partly become apparent from the description, or be understood by practicing the present application. The purpose and other advantages of the present application can be realized and obtained by the structures specifically pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0066] Figure 1 A basic block diagram of an MLD device;
[0067] Figure 2 A schematic diagram of an application scenario of the wireless network access control method provided in an embodiment of the present application;
[0068] Figure 3 A schematic diagram of an implementation flow of a wireless network access control method provided in an embodiment of the present application;
[0069] Figure 4 A schematic diagram of an implementation flow of a wireless network access control method implemented on an AP side provided in an embodiment of the present application;
[0070] Figure 5 A schematic diagram of the structure of a wireless network access control device implemented on the AP side provided in an embodiment of the present application;
[0071] Figure 6 A schematic diagram of an implementation flow of a wireless network access control method implemented by a STA side provided in an embodiment of the present application;
[0072] Figure 7 A schematic diagram of the structure of a wireless network access control device implemented on the STA side provided in an embodiment of the present application;
[0073] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0074] In order to solve the problems in the background technology, the embodiments of the present application provide a wireless network access control method, device, electronic device and storage medium.
[0075] The preferred embodiments of the present application are described below in conjunction with the drawings in the specification. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application. In addition, the embodiments and features in the embodiments of the present application may be combined with each other if there is no conflict.
[0076] First reference Figure 2 , which is a schematic diagram of an application scenario of the wireless network access control method provided by an embodiment of the present application, and may include AP 200 and STA 201. In this application scenario, only two physical links are directly established between AP 200 and STA 201 as an example for explanation. It is assumed that one physical link corresponds to one VLAN. For example, one VLAN is the enterprise's external network, and one VLAN is the enterprise's internal network. The two VLANs work in different frequency bands, for example, VLAN1 works in the 2.4G frequency band, and VLAN2 works in the 4G frequency band. Then, when AP 200 and STA 201 establish an MLD association, two links can be created, such as Figure 2Link 1: Link1 and Link 2: Link2, Link1 corresponds to the physical network interface of STA 201, that is, network interface 1, STA201 creates a new virtual network interface, that is, network interface 2, Link1 and network interface 1 correspond to VLAN1, Link2 and network interface 2 correspond to VLAN2, so that when accessing intranet data and extranet data through STA, data can be transmitted simultaneously through their corresponding links and network interfaces without interfering with each other, and there is no need to add a terminal site device STA or a new wireless network card to the terminal site device. Only one STA needs to access the intranet and the extranet at the same time, and the STA can create a virtual network interface to achieve the establishment of multiple physical links, thereby saving hardware costs.
[0077] In the embodiment of the present application, only one AP and one STA are used as an example for description. In actual applications, one AP can establish connections with multiple STAs.
[0078] It should be noted that the wireless network access control method provided in the embodiment of the present application can be applied to different VLAN scenarios in the same WLAN (Wireless Local Area Network), and can also be applied to VLAN scenarios in different WLANs. The embodiment of the present application is not limited to this. The embodiment of the present application is only described by applying to the VLAN scenario as an example.
[0079] Based on the above application scenarios, the following will refer to the attached Figures 3 to 7 The exemplary embodiments of the present application are described in more detail. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principle of the present application, and the implementation of the present application is not limited in any way. On the contrary, the implementation of the present application can be applied to any applicable scenario.
[0080] like Figure 3 As shown, it is a schematic diagram of the implementation process of the wireless network access control method provided in the embodiment of the present application, which may specifically include the following steps:
[0081] S31. The AP sends a beacon frame to the STA. The beacon frame includes information about the AP's ability to support multiple network interfaces.
[0082] During specific implementation, the AP sends a beacon frame (i.e., a Beacon frame) to the STA at a preset time period to inform the STA of the existence of the wireless network. The Beacon frame includes the performance information of the AP, which is used to inform the STA what performance the wireless network has, so that the STA can verify whether it meets its requirements before associating with the AP. In an embodiment of the present application, the Beacon frame also includes manufacturer-defined information for characterizing the AP's ability to support multiple network interfaces. The AP's ability to support multiple network interfaces is carried in the Beacon frame as private IE information.
[0083] In another implementation, the STA can also actively send a probe request frame (i.e., Probe request frame) to actively detect the associated AP information. When the AP receives the probe request frame sent by the STA, it returns a probe response frame (i.e., Probe response frame) to the STA, and the probe response frame carries the AP's ability to support multiple network interfaces.
[0084] S32, STA sends an authentication request to AP. In specific implementation, after receiving the Beacon frame sent by AP, STA sends an authentication request (Auth request) to AP, and AP performs identity authentication on STA.
[0085] S33. The AP returns an authentication response to the STA.
[0086] During specific implementation, the AP receives the authentication request sent by the STA, performs identity authentication on the STA, obtains the authentication result, and returns an authentication response (Auth response) to the STA.
[0087] S34. The STA sends an association request frame to the AP. The association request frame includes information about the STA's ability to support multiple network interfaces.
[0088] During the specific implementation, the STA receives the authentication response returned by the AP. If it is determined that the authentication result is successful, the STA enters the association stage with the AP. The STA sends an association request frame (Association request frame) to the AP. The association request frame includes the STA's performance information and the manufacturer's customized information used to characterize the STA's ability to support multiple network interfaces. The STA's ability to support multiple network interfaces is carried in the association request frame as private IE information.
[0089] S35. The AP creates a multi-link device association and a multi-network interface IP forwarding rule with the STA.
[0090] In specific implementation, the AP receives an association request frame sent by the STA. Through the information carried in the association request frame, the AP can understand the relevant capability information of the STA. The AP checks each 802.11 parameter carried in the association request frame and matches it with the 802.11 parameters supported by itself. If there is a mismatch, the connection is rejected. If there is a match, and the AP determines that the association request frame includes the STA's support for multiple network interface capabilities, the AP creates an MLD association with the STA, creates a multi-network interface IP forwarding rule, and assigns an AID (English: Association Identifier) to the STA. Among them, the multi-network interface IP forwarding rule includes the correspondence between the identifier of each network interface and the VLAN identifier. The identifier of each network interface includes the identifier of the physical network interface of the STA and the identifier of the newly added virtual network interface. The number of newly added virtual network interfaces can be set according to actual needs. For example, if the STA needs to access two VLAN networks with different frequency bands, one virtual network interface can be added. If the STA needs to access three VLAN networks with different frequency bands, two virtual network interfaces can be added. The network segment supported by the link established between each network interface of the AP and the STA is the network segment of the VLAN corresponding to the VLAN identifier corresponding to each network interface. For example, assuming that the VLAN identifier corresponding to the network interface 1 of the STA is VLAN1, and the network segment supported by the VLAN corresponding to VLAN1 is 2GHz, then the network segment supported by the link established between the AP and the network interface 1 of the STA is 2GHz. The maximum number of virtual network interfaces that can be created can be determined according to the number of frequency bands supported by the protocol. The maximum number of virtual network interfaces that can be created is the number of frequency bands supported by the protocol minus 1. The AID parameter is equivalent to an identifier set for the STA. There is an AID table (Association ID table) in the AP, in which each AID is bound to the MAC of its corresponding STA. The value range of AID is from 0 to 2007, which also shows that an AP can be associated with up to 2007 nodes in the protocol. After the AP assigns an AID to the STA, the STA can broadcast its own cached Buffer information. In the 802.11 protocol, since the Buffer information is also fed back periodically, it is placed in the Beacon frame and carried as a field.
[0091] The multi-network interface IP forwarding rules also include a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer (MAC) priority, where the same DSCP priority on different links is mapped to different MAC priorities.
[0092] When MLO manages MLD multi-link communications, the high throughput of the 802.11be protocol mainly relies on the A-MPDU (MAC Protocol Data Unit Aggregation) frame aggregation and sending mechanism of the physical layer. A-MPDU aggregates the MPDU encapsulated by the 802.11 message. Here, MPDU refers to the data frame encapsulated by 802.11. It relies on the priority tid window movement mechanism of 802.11e. However, if multiple network interfaces use the same priority tid shared window sliding, the congestion of one link will affect the latency of multiple network interfaces.
[0093] In the 802.11e protocol, based on EDCA (Enhanced Distributed Channel Access), there are four access categories (AC): AC_BE (Best Effort), AC_BK (Background), AC_VI (Video), and AC_VO (Voice). Each AC category defines a set of channel competition EDCA parameters, which determine the AC category's ability to occupy a channel. By configuring EDCA parameters for different categories of messages, you can prioritize different categories of messages, provide different channel preemption capabilities, and achieve different quality of service. There are eight priority levels tid: tid0 to tid7, called 802.11.e MAC priority levels, where MAC priority levels tid0 and tid3 correspond to AC_BE, MAC priority levels tid1 and tid2 correspond to AC_BK, MAC priority levels tid4 and tid5 correspond to AC_VI, and MAC priority levels tid6 and tid7 correspond to AC_VO.
[0094] The DSCP priority in the IP message includes 8 priorities: tid0 to tid7. In the embodiment of the present application, when the IP message is transmitted between the AP and the STA, when the IP message is transmitted to the 802.11MAC layer, the IP message needs to be converted into an 802.11 data message for transmission. In order to solve the problem that the congestion of a link will affect the delay of multiple network interfaces, the mapping relationship between the DSCP priority and the MAC priority is pre-established in the embodiment of the present application. When the IP message is converted into an 802.11 data message, the DSCP priority in the IP message is replaced with the corresponding MAC priority. In this way, the same DSCP priority on different links is mapped to different MAC priorities. Therefore, when one link is congested, it will not affect the data transmission on other network interfaces.
[0095] Taking two network interfaces and two established links as an example, in one implementation, the mapping relationship between the DSCP priority and the MAC priority may be set as follows:
[0096] DSCP priorities tid0 and tid3 on link 1 are uniformly mapped to MAC priority tid0; DSCP priorities tid1 and tid2 on link 1 are uniformly mapped to MAC priority tid1; DSCP priorities tid4 and tid5 on link 1 are uniformly mapped to MAC priority tid4; DSCP priorities tid6 and tid7 on link 1 are uniformly mapped to MAC priority tid6; DSCP priorities tid0 and tid3 on link 2 are uniformly mapped to MAC priority tid3; DSCP priorities tid1 and tid2 on link 2 are uniformly mapped to MAC priority tid2; DSCP priorities tid4 and tid5 on link 2 are uniformly mapped to MAC priority tid5; DSCP priorities tid6 and tid7 on link 2 are uniformly mapped to MAC priority tid7.
[0097] During implementation, the mapping relationship between the DSCP priority and the MAC priority may be arbitrarily set, which is not limited in the embodiment of the present application. For example, it may be set as follows:
[0098] DSCP priorities tid0 and tid3 on link 1 are uniformly mapped to MAC priority tid0; DSCP priorities tid1 and tid2 on link 1 are uniformly mapped to MAC priority tid3; DSCP priorities tid4 and tid5 on link 1 are uniformly mapped to MAC priority tid4; DSCP priorities tid6 and tid7 on link 1 are uniformly mapped to MAC priority tid6; DSCP priorities tid0 and tid3 on link 2 are uniformly mapped to MAC priority tid2; DSCP priorities tid1 and tid2 on link 2 are uniformly mapped to MAC priority tid1; DSCP priorities tid4 and tid5 on link 2 are uniformly mapped to MAC priority tid5; DSCP priorities tid6 and tid7 on link 2 are uniformly mapped to MAC priority tid7.
[0099] S36. The AP returns an association response frame to the STA.
[0100] In specific implementation, the AP returns an association response frame to the STA. The association response frame includes the multi-network interface IP forwarding rule, the AID assigned by the AP to the STA, and a status code. A status code of 0 indicates that the association is successful.
[0101] S37. STA creates a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0102] During specific implementation, STA extracts the multi-network interface IP forwarding rules in the association response frame, and creates a corresponding virtual network interface according to the identifier of the newly added virtual network interface. The WIFI7 site device STA can establish multiple links with the AP through one association in one frequency band.
[0103] Furthermore, when the AP receives a data packet sent by the STA, the data packet carries a destination IP address. If the data packet is determined to be an IP packet, when converting the IP packet to a physical layer packet, the DSCP priority of the IP packet is converted into the corresponding MAC priority according to the mapping relationship between the DSCP priority and the MAC priority, the VLAN to which the destination IP address belongs is determined, and the converted physical layer packet is sent to the destination IP address through the network interface corresponding to the VLAN to which the destination IP address belongs.
[0104] In specific implementation, if the AP receives a Layer 3 (i.e., network layer) message such as an IP message sent by a STA, when the IP message is transmitted to the 802.11 MAC layer, the DSCP priority of the IP message will be converted into the corresponding MAC priority according to the mapping relationship between the DSCP priority and the MAC priority, so as to convert the IP message into an 802.11 MAC layer message. The MLO can select any link to send, and the AP judges by the destination IP address and the route, and sends it to the network interface of the VLAN to which it belongs to the device where the destination IP address is located. If the STA sends a Layer 2 (i.e., data link layer) message such as a DHCP (Dynamic Host Configuration Protocol) message or an ARP (Address Resolution Protocol) message to the AP, it cannot be sent and received across links. The MLO selects the link corresponding to the network interface corresponding to the VLAN to which the destination IP address belongs, and sends the converted physical layer message to the destination IP address through the link corresponding to the network interface corresponding to the VLAN to which the destination IP address belongs.
[0105] In the wireless network access control method provided by the embodiment of the present application, the AP receives an association request frame sent by the STA. If it is determined that the association request frame includes information that the STA supports multiple network interface capabilities, the AP creates a multi-link device association and a multi-network interface IP forwarding rule with the STA. The multi-network interface IP forwarding rule includes a correspondence between the identifier of each network interface and the VLAN identifier. The identifier of each network interface includes the identifier of the physical network interface of the STA and the identifier of the newly added virtual network interface. The AP returns an association response frame to the STA. The association response frame includes the multi-network interface IP forwarding rule, so that the STA creates a corresponding virtual network interface according to the identifier of the newly added virtual network interface. In the embodiment of the present application, the AP and the STA are pre-set to support multiple network interface capabilities. When the STA sends an association request frame to the AP, if both support multiple network interface capabilities, the AP creates an MLD association with the STA and creates a multi-network interface IP forwarding rule. The correspondence between the identifier of each network interface and the VLAN identifier is set in the multi-network interface IP forwarding rule, so that the STA creates a corresponding virtual network interface according to the identifier of the newly added virtual network interface. Thus, multiple links for accessing different VLANs are established through the multiple network interfaces, so that when communicating with different VLANs, During data transmission, data can be transmitted simultaneously through the corresponding links and network interfaces without interfering with each other. There is no need to add a new STA or a new wireless network card on the STA. Only one STA needs to access different VLANs at the same time. The STA can create a virtual network interface to establish multiple physical links, thereby saving hardware costs. For example, the current 802.11be protocol supports three frequency bands: 2GHz, 5GHz and 6GHz, and one frequency band corresponds to one network interface. If it is necessary to transmit data of these three frequency bands at the same time and realize that the data of the three frequency bands each corresponds to a physical link, three physical wireless network cards need to be installed on one STA. One physical wireless network card generates one network interface, and each network interface corresponds to a physical link when connected to the AP, and one physical link transmits data of one frequency band. In this application, only one physical wireless network card is required on one STA, and two virtual network interfaces are created to realize the functions that can be realized by installing three physical wireless network cards, namely: a network interface generated by a physical wireless network card and two virtual network interfaces, and each network interface corresponds to a physical link when connected to the AP, and one physical link transmits data of one frequency band without installing any additional physical wireless network cards, thereby saving hardware costs.
[0106] Based on the same inventive concept, an embodiment of the present application also provides a wireless network access control method implemented on the AP side. Since the principle of solving the problem by the wireless network access control method implemented on the AP side is similar to that of the wireless network access control method, the implementation of the wireless network access control method implemented on the AP side can refer to the implementation of the wireless network access control method, and the repeated parts will not be repeated.
[0107] like Figure 4 As shown, it is a schematic diagram of an implementation flow of a wireless network access control method implemented on the AP side provided in an embodiment of the present application, which may include the following steps:
[0108] S41. The AP receives an association request frame sent by a station STA.
[0109] S42. If it is determined that the association request frame includes information that the STA supports multiple network interface capabilities, a multi-link device association and a multi-network interface IP forwarding rule are created between the STA. The multi-network interface IP forwarding rule includes a correspondence between the identifier of each network interface and the VLAN identifier. The identifier of each network interface includes the identifier of the STA's physical network interface and the identifier of the newly added virtual network interface.
[0110] S43. Return an association response frame to the STA, where the association response frame includes a multi-network interface IP forwarding rule, so that the STA can create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0111] In one implementation, before receiving the association request sent by the STA, the method further includes:
[0112] A beacon frame is sent to a station STA, wherein the beacon frame includes information on the access point AP's ability to support multiple network interfaces.
[0113] In one implementation, before receiving the association request sent by the STA, the method further includes:
[0114] Receiving a probe request frame sent by the STA;
[0115] A probe response frame is returned to the STA, wherein the probe response frame includes information about the access point AP's ability to support multiple network interfaces.
[0116] In one implementation, the network segment supported by the link established with each network interface of the STA is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0117] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0118] In one embodiment, the method further comprises:
[0119] receiving a data message sent by the STA, wherein the data message carries a destination IP address;
[0120] If it is determined that the data packet is an IP packet, when converting the IP packet into a physical layer packet, according to the mapping relationship between the DSCP priority and the MAC priority, the DSCP priority of the IP packet is converted into a corresponding MAC priority;
[0121] Determine the VLAN to which the destination IP address belongs;
[0122] The converted physical layer message is sent to the destination IP address through the network interface corresponding to the VLAN to which the destination IP address belongs.
[0123] Based on the same inventive concept, an embodiment of the present application also provides a wireless network access control device implemented on the AP side. Since the principle of solving the problem by the wireless network access control device implemented on the AP side is similar to the wireless network access control method, the implementation of the wireless network access control device implemented on the AP side can refer to the implementation of the wireless network access control method, and the repeated parts will not be repeated.
[0124] like Figure 5 As shown, it is a structural diagram of a wireless network access control device implemented on the AP side provided in an embodiment of the present application, which may include:
[0125] The first receiving unit 51 is used to receive an association request frame sent by a station STA;
[0126] A creating unit 52 is configured to, if it is determined that the association request frame includes information that the STA supports multiple network interface capabilities, create a multi-link device association and a multi-network interface IP forwarding rule with the STA, wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, and the identifier of each network interface includes an identifier of the physical network interface of the STA and an identifier of a newly added virtual network interface;
[0127] The first returning unit 53 is used to return an association response frame to the STA, where the association response frame includes the multi-network interface IP forwarding rule, so that the STA can create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0128] In one embodiment, the device further comprises:
[0129] The first sending unit is used to send a beacon frame to the station STA before receiving the association request sent by the STA, wherein the beacon frame includes the access point AP supporting multiple network interface capability information.
[0130] In one embodiment, it further includes:
[0131] A second receiving unit, configured to receive a probe request frame sent by the STA before receiving an association request sent by the STA;
[0132] The second returning unit is configured to return a probe response frame to the STA, wherein the probe response frame includes information about the access point AP's ability to support multiple network interfaces.
[0133] In one implementation, the network segment supported by the link established with each network interface of the STA is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0134] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0135] In one embodiment, the device further comprises:
[0136] A third receiving unit, configured to receive a data message sent by the STA, wherein the data message carries a destination IP address;
[0137] a conversion unit, configured to, if it is determined that the data packet is an IP packet, convert the DSCP priority of the IP packet into a corresponding MAC priority according to the mapping relationship between the DSCP priority and the MAC priority when converting the IP packet into a physical layer packet;
[0138] A determination unit, configured to determine the VLAN to which the destination IP address belongs;
[0139] The second sending unit is used to send the converted physical layer message to the destination IP address through the network interface corresponding to the VLAN to which the destination IP address belongs.
[0140] Based on the same inventive concept, an embodiment of the present application also provides a wireless network access control method implemented on the STA side. Since the principle of solving the problem by the wireless network access control method implemented on the STA side is similar to that of the wireless network access control method, the implementation of the wireless network access control method implemented on the STA side can refer to the implementation of the wireless network access control method, and the repeated parts will not be repeated.
[0141] like Figure 6 As shown, it is a schematic diagram of an implementation flow of the wireless network access control method implemented by the STA side provided in an embodiment of the present application, which may include the following steps:
[0142] S61. The STA sends an association request frame to the AP. The association request frame includes information about the STA's ability to support multiple network interfaces.
[0143] S62. Receive an association response frame sent by the AP, where the association response frame includes a multi-network interface IP forwarding rule. The multi-network interface IP forwarding rule is created when the AP creates a multi-link device association with the STA. The multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN. The identifier of each network interface includes an identifier of the physical network interface of the STA and an identifier of a newly added virtual network interface.
[0144] S63: Create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0145] In one implementation, before sending an association request frame to an access point AP, the method further includes:
[0146] A beacon frame sent by the AP is received, wherein the beacon frame includes information about the AP's ability to support multiple network interfaces.
[0147] In one implementation, before sending an association request frame to an access point AP, the method further includes:
[0148] Sending a probe request frame to the AP;
[0149] A probe response frame returned by the AP is received, wherein the probe response frame includes information about the AP's ability to support multiple network interfaces.
[0150] In one implementation, the network segment supported by the link established with each network interface of the AP is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0151] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0152] Based on the same inventive concept, an embodiment of the present application also provides a wireless network access control device implemented on the STA side. Since the principle of solving the problem by the wireless network access control device implemented on the STA side is similar to the wireless network access control method, the implementation of the wireless network access control device implemented on the STA side can refer to the implementation of the wireless network access control method, and the repeated parts will not be repeated.
[0153] like Figure 7 As shown, it is a structural diagram of a wireless network access control device implemented on the STA side provided in an embodiment of the present application, which may include:
[0154] The first sending unit 71 is used to send an association request frame to the access point AP, wherein the association request frame includes the station STA's ability to support multiple network interfaces;
[0155] a first receiving unit 72, configured to receive an association response frame sent by the AP, wherein the association response frame includes a multi-network interface IP forwarding rule, wherein the multi-network interface IP forwarding rule is created when the AP creates a multi-link device association with the STA, and wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, wherein the identifier of each network interface includes an identifier of a physical network interface of the STA and an identifier of a newly added virtual network interface;
[0156] The creating unit 73 is used to create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
[0157] In one embodiment, the device further comprises:
[0158] The second receiving unit is configured to receive a beacon frame sent by an access point AP before sending an association request frame to the AP, wherein the beacon frame includes information indicating that the AP supports multiple network interfaces.
[0159] In one embodiment, the device further comprises:
[0160] A second sending unit, configured to send a detection request frame to an access point AP before sending an association request frame to the AP;
[0161] The third receiving unit is configured to receive a probe response frame returned by the AP, wherein the probe response frame includes information about the AP's ability to support multiple network interfaces.
[0162] In one implementation, the network segment supported by the link established with each network interface of the AP is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
[0163] In one embodiment, the multi-network interface IP forwarding rule further includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
[0164] Based on the same technical concept, the embodiment of the present application also provides an electronic device 800, referring to Figure 8As shown, the electronic device 800 is used to implement the wireless network access control method described in the above method embodiment. The electronic device 800 of this embodiment may include: a memory 801, a processor 802, and a computer program stored in the memory and executable on the processor, such as a wireless network access control program. When the processor executes the computer program, the steps in the above wireless network access control method embodiments are implemented.
[0165] The specific connection medium between the memory 801 and the processor 802 is not limited in the embodiment of the present application. Figure 8 In the embodiment, the memory 801 and the processor 802 are connected via a bus 803. The bus 803 is Figure 8 The connection between other components is shown by bold lines, and is not intended to be limiting. The bus 803 can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.
[0166] The memory 801 may be a volatile memory, such as a random-access memory (RAM); the memory 801 may also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the memory 801 may be any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 801 may be a combination of the above memories.
[0167] The processor 802 is used to implement the wireless network access control method provided in the embodiment of the present application.
[0168] An embodiment of the present application also provides a computer-readable storage medium that stores computer-executable instructions required to execute the above-mentioned processor, which includes a program required to execute the above-mentioned processor.
[0169] In some possible implementations, various aspects of the wireless network access control method provided in the present application may also be implemented in the form of a program product, which includes a program code. When the program product is run on an electronic device, the program code is used to enable the electronic device to execute the steps of the wireless network access control method according to various exemplary implementations of the present application described above in this specification.
[0170] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, devices, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0171] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (apparatus), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0172] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0173] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0174] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0175] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. A wireless network access control method, characterized in that: include: Receive the association request frame sent by the station STA; If it is determined that the association request frame includes the STA's ability to support multiple network interfaces, a multi-link device association and a multi-network interface IP forwarding rule are created with the STA, wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, and the identifier of each network interface includes an identifier of the STA's physical network interface and an identifier of a newly added virtual network interface; An association response frame is returned to the STA, where the association response frame includes the multi-network interface IP forwarding rule, so that the STA can create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
2. The method according to claim 1, characterized in that Before receiving the association request sent by the STA, the following steps are also included: A beacon frame is sent to a station STA, wherein the beacon frame includes information on the access point AP's ability to support multiple network interfaces.
3. The method according to claim 1, characterized in that Before receiving the association request sent by the STA, the following steps are also included: Receiving a probe request frame sent by the STA; A probe response frame is returned to the STA, wherein the probe response frame includes information about the access point AP's ability to support multiple network interfaces.
4. The method according to any one of claims 1 to 3, characterized in that: The network segment supported by the link established with each network interface of the STA is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
5. The method according to claim 4, characterized in that The multi-network interface IP forwarding rule also includes a mapping relationship between a Differentiated Services Code Point (DSCP) priority and a physical layer MAC priority, wherein the same DSCP priority on different links is mapped to different MAC priorities.
6. The method according to claim 5, characterized in that Also includes: receiving a data message sent by the STA, wherein the data message carries a destination IP address; If it is determined that the data packet is an IP packet, when converting the IP packet into a physical layer packet, according to the mapping relationship between the DSCP priority and the MAC priority, the DSCP priority of the IP packet is converted into a corresponding MAC priority; Determine the VLAN to which the destination IP address belongs; The converted physical layer message is sent to the destination IP address through the network interface corresponding to the VLAN to which the destination IP address belongs.
7. A wireless network access control method, characterized in that: include: Sending an association request frame to an access point AP, wherein the association request frame includes information about the station STA's ability to support multiple network interfaces; receiving an association response frame sent by the AP, the association response frame including a multi-network interface IP forwarding rule, the multi-network interface IP forwarding rule being created when the AP creates a multi-link device association with the STA, the multi-network interface IP forwarding rule including a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, the identifier of each network interface including an identifier of a physical network interface of the STA and an identifier of a newly added virtual network interface; Create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
8. The method according to claim 7, characterized in that Before sending an association request frame to the access point AP, it also includes: Sending a probe request frame to the AP; A probe response frame returned by the AP is received, wherein the probe response frame includes information about the AP's ability to support multiple network interfaces.
9. The method according to claim 7 or 8, characterized in that The network segment supported by the link established with each network interface of the AP is the network segment of the VLAN corresponding to the corresponding VLAN identifier.
10. A wireless network access control device, characterized in that: include: A first receiving unit, configured to receive an association request frame sent by a station STA; a creating unit, configured to, if it is determined that the association request frame includes information that the STA supports multiple network interface capabilities, create a multi-link device association and a multi-network interface IP forwarding rule with the STA, wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, and the identifier of each network interface includes an identifier of the physical network interface of the STA and an identifier of a newly added virtual network interface; The first returning unit is used to return an association response frame to the STA, where the association response frame includes the multi-network interface IP forwarding rule, so that the STA can create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
11. A wireless network access control device, characterized in that: include: A first sending unit, configured to send an association request frame to an access point AP, wherein the association request frame includes information about a station STA's ability to support multiple network interfaces; a first receiving unit, configured to receive an association response frame sent by the AP, wherein the association response frame includes a multi-network interface IP forwarding rule, wherein the multi-network interface IP forwarding rule is created when the AP creates a multi-link device association with the STA, and wherein the multi-network interface IP forwarding rule includes a correspondence between an identifier of each network interface and an identifier of a virtual local area network VLAN, wherein the identifier of each network interface includes an identifier of a physical network interface of the STA and an identifier of a newly added virtual network interface; A creating unit is used to create a corresponding virtual network interface according to the identifier of the newly added virtual network interface.
12. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the wireless network access control method according to any one of claims 1 to 9 is implemented.
13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps in the wireless network access control method according to any one of claims 1 to 9 are implemented.