Information processing method, network equipment and computer readable storage medium
By using the key configuration information in the beacon frame to encrypt sensitive information, the problem that sensitive information in the TWT target wake-up time beacon frame is solved, and the protection of sensitive information and user privacy is achieved is achieved, and the transmission stability and throughput of low-latency services are improved.
Patent Information
- Application Number
- CN202311535924.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-16
- Publication Date
- 2025-05-16
AI Technical Summary
In the prior art, beacon frames that support the TWT target wake-up time function carry TWT packets and service time window information by default, resulting in third-party devices that may occupy channels within the r-TWT service time window, resulting in the risk of low-latency service devices waiting, increasing power consumption and user privacy leakage.
By encrypting the sensitive information domain in the beacon frame using the key configuration information in the transmission side network device, an encrypted beacon frame is generated, and the encrypted beacon frame is sent on the network. The receiving network device uses the corresponding key configuration information to decrypt the sensitive information domain.
It effectively prevents other network equipment or third-party equipment from obtaining sensitive information in beacon frames, reduces the risk of user sensitive information leakage, and improves the timely intervention ability of low-latency service equipment in the TWT window, reducing delay and power consumption.
Smart Images

Figure CN120017293A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to but are not limited to the field of communication technology, and in particular, to an information processing method, a network device, and a computer-readable storage medium. Background Art
[0002] At present, the beacon frame that supports the strict target wake-up time (Restricted Target Wake Up Time, r-TWT) and group wake-up time (broadcast Target Wakeup Time, b-TWT) (hereinafter referred to as: TWT target wake-up time) functions will carry TWT grouping and service time window information by default. If a third-party device detects the TWT information in the beacon frame, it can occupy the channel within each r-TWT service time window, causing devices containing low-latency services to wait for channel intervention because they cannot intervene in the channel in time in the corresponding TWT window, causing delay problems and power consumption problems at the application layer, which may in turn cause the risk of user privacy leakage. Summary of the invention
[0003] The following is a summary of the subject matter described in detail herein. This summary is not intended to limit the scope of the claims.
[0004] The embodiments of the present application provide an information processing method, a network device, and a computer-readable storage medium, which can not only prevent other network devices or third-party devices from obtaining sensitive information in the beacon frame to a certain extent, but also effectively avoid the risk of leakage of user sensitive information.
[0005] In a first aspect, an embodiment of the present application provides an information processing method, which is applied to a sending-side network device, including: using key configuration information to encrypt a sensitive information field in a beacon frame to obtain an encrypted beacon frame; and sending the encrypted beacon frame.
[0006] In the second aspect, an embodiment of the present application also provides an information processing method, applied to a receiving-side network device, comprising: receiving a first beacon frame sent by a sending-side network device, wherein the first beacon frame includes a sensitive information field encrypted using key configuration information; decrypting the sensitive information field in the first beacon frame using the key configuration information to obtain decrypted sensitive information; and performing corresponding information processing based on the decrypted sensitive information.
[0007] In a third aspect, an embodiment of the present application further provides a network device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the information processing method of the first aspect described above is implemented or the information processing method of the second aspect described above is implemented.
[0008] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the information processing method as described above.
[0009] In an embodiment of the present application, the sending side network device uses the secret key configuration information to encrypt the sensitive information field in the beacon frame to obtain an encrypted beacon frame, and then sends the encrypted beacon frame. According to the scheme provided in the embodiment of the present application, the sending side network device encrypts the sensitive information field in the beacon frame by using the corresponding secret key configuration information, and after obtaining the corresponding encrypted beacon frame, the sending side network device sends the encrypted beacon frame in the network. That is, when protecting the sensitive information of the beacon frame during network transmission, the sending side network device only needs to use the corresponding secret key information to encrypt the sensitive information field in the beacon frame, thereby preventing other network devices or third-party devices from obtaining the sensitive information in the beacon frame, and effectively avoiding the risk of leakage of user sensitive information. BRIEF DESCRIPTION OF THE DRAWINGS
[0010] Figure 1 is a structural diagram of the NR provided in the embodiment of the present application;
[0011] Figure 2 It is a structural diagram of the MBSSID element provided in the embodiment of the present application;
[0012] Figure 3 It is a diagram of the RSNE field structure provided in an embodiment of the present application;
[0013] Figure 4 It is a management frame format with BIP protection added provided in an embodiment of the present application;
[0014] Figure 5 is a flow chart of an information processing method provided by an embodiment of the present application;
[0015] Figure 6 It is a schematic diagram of a sending-side network device using the same secret key to generate an information integrity code and encrypt sensitive information provided by an embodiment of the present application;
[0016] Figure 7 It is a structural diagram of a sending-side network device using a first secret key to encrypt sensitive information elements located in different IEs provided by an embodiment of the present application;
[0017] Figure 8 It is a structural diagram of the RSNE field extension provided in an embodiment of the present application;
[0018] Fig. 9 is a flow chart of an information processing method provided by another embodiment of the present application;
[0019] Fig.10It is a structural diagram of the key configuration information provided in the embodiment of the present application;
[0020] Fig.11 is a flowchart of another information processing method provided by an embodiment of the present application;
[0021] Fig.12 It is an information processing flow chart when the receiving side network device is an AP or an AP MLD provided by an embodiment of the present application;
[0022] Fig.13 It is a structural diagram of a receiving-side network device using a second secret key to encrypt sensitive information elements located in different IEs provided by an embodiment of the present application;
[0023] Fig.14 It is a schematic diagram of a process in which a sending-side network device and a receiving-side network device use beacon frames to interact and encrypt sensitive information, provided by an embodiment of the present application;
[0024] Fig.15 This is another process diagram of an embodiment of the present application, in which a sending-side network device and a receiving-side network device use beacon frames to interact and encrypt sensitive information. DETAILED DESCRIPTION
[0025] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0026] It should be noted that, although the functional modules are divided in the device schematic diagram and the logical order is shown in the flowchart, in some cases, the steps shown or described may be performed in a different order than the module division in the device or the order in the flowchart. The terms "first", "second", etc. in the specification, claims and the above drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0027] It is worth noting that in the current wireless communication technology, fiber-to-the-room (FTTR) technology connects wireless router APs in different rooms or locations in scenarios such as homes or small and medium-sized enterprises through optical fibers, thereby providing high-bandwidth, high-reliability connections between multiple APs. On this basis, a point-to-multipoint optical distribution network can be used to achieve the connection between the master control AP and the slave AP.
[0028] At present, the neighbor report (NR) field contains information about other surrounding access points (APs) or multi-link access points (AP MLD, hereinafter referred to as AP). It is generally used for a terminal (STA) or a multi-link terminal (non-AP MLD, hereinafter referred to as STA) to send a query frame to the target AP to query the information of other surrounding APs. The target AP sends a response frame to the STA to feedback the information of other surrounding APs queried by the STA. For example, the STA sends an Access Network Query Protocol (ANQP) query frame to the AP, and the AP feeds back an ANQP response frame to the STA. Alternatively, the beacon frame sent by the AP carries the NR field in the detection response frame to actively broadcast the information of other surrounding APs; or, in the case of roaming or multi-AP load balancing, the AP actively recommends the information of other surrounding APs to the STA, and the STA confirms the information and then sends a (re)association request to a recommended AP. For example, the AP sends a BSS transition management (BTM) request frame to the STA, and carries the recommended AP information in the NR field. The STA sends a BTM response frame, which contains the information of the desired AP in the NR field, and then sends an authentication frame and a (re)association frame to establish a connection with the target AP. Figure 1 As shown, Figure 1 This is a diagram of the NR field structure provided in an embodiment of the present application. In this NR structure, the explanations of the main fields are as follows:
[0029] Element ID: used to represent the element identifier;
[0030] Length: used to indicate the length of the element;
[0031] BSSID: used to represent the basic service set identifier (MAC address);
[0032] BSSID Information: used to indicate the basic service set identifier information field;
[0033] Operating Class: used to indicate the operating channel category;
[0034] Channel Number: used to indicate the channel number;
[0035] PHY Type: used to indicate the physical layer type;
[0036] Optional Subelements: used to represent optional subelements;
[0037] AP Reachability: used to indicate whether the neighbor AP can be detected;
[0038] Security: used to indicate whether the security parameters are the same as the current link;
[0039] Key Scope: used to indicate whether the authenticator information corresponding to the current link is the same;
[0040] Capabilities: used to indicate the capability set information of neighboring APs;
[0041] Mobility Domain: Used to indicate whether the beacon frame sent by the neighboring AP carries the Mobility Domain Element (MDE) field;
[0042] High Throughput: used to indicate whether the neighbor AP is an HT AP, that is, whether it supports the HT capability set;
[0043] Very High Throughput: Used to indicate whether the neighbor AP is a VHT AP, that is, whether it supports the VHT capability set;
[0044] FTM: used to indicate whether the neighbor AP supports the FTM (Fine Timing measurement) function;
[0045] High Efficiency: used to indicate whether the neighbor AP is a HE AP, that is, whether it supports the HE capability set;
[0046] ER BSS: used to indicate whether the neighbor AP is an AP that supports the extended range (ER) function;
[0047] Colocated AP: indicates that the neighbor AP and the AP corresponding to the current link are located on the same physical device;
[0048] Unsolicited Probe Responses Active: used to indicate that neighboring APs can send an unsolicited probe response frame every 20ms on the 6GHz band;
[0049] Members of ESS with 2.4 / 5GHz Colocated AP: indicates that the neighbor AP works in the 2.4GHz or 5GHz frequency band and coexists with the current AP on the same physical device.
[0050] OCT Supported With Reporting AP: Used to indicate that the AP on the current link supports exchanging MMPDUs with neighboring APs using on-channel Tunneling (OCT) technology;
[0051] Colocated With 6GHz AP: indicates that the neighbor AP works in the 6GHz frequency band and coexists with the current AP on the same physical device.
[0052] Extremely High Throughput: Used to indicate whether the neighbor AP is an EHT AP, that is, whether it supports the EHT capability set;
[0053] Reserved: used to indicate a reserved field.
[0054] Furthermore, in order to reduce the channel resource overhead caused by the field length, the RNR (reduced neighbor report) field is correspondingly trimmed and modified based on the NR field, and only includes key information of surrounding APs, such as working channels, SSID, BSSID information, etc. When a STA receives a management frame such as a beacon frame and a probe response frame carrying the RNR field sent by an AP, the STA can quickly discover other surrounding APs, and then further detect on the channel where the target AP is located, so as to obtain the complete information of the AP, thus reducing the time overhead of the STA blindly scanning the channel and detecting surrounding APs.
[0055] Since multiple APs can be created on a Wi-Fi radio link, each AP corresponds to a different BSSID. In order to reduce the channel resource overhead of each AP sending beacon frames and probe response frames, the 802.11 protocol introduces multiple basic service set identifiers (MBSSID) technology, that is, beacon frames and probe response frames sent by multiple APs on the same radio frequency are merged into one AP's beacon frame and probe response frame for transmission. That is, the beacon frame and probe response frame of an AP carry information about other APs on the same radio frequency, and this information is placed in the multi-BSSID element field. Its structure is as follows: Figure 2 As shown in the figure, in this structure, the explanations of the main fields are as follows:
[0056] Element ID: used to represent the element identifier;
[0057] Length: used to indicate the length of the element;
[0058] MaxBSSID Indicator: used to indicate the maximum number of basic service set identifiers (BSSIDs);
[0059] Optional Subelements: Used to represent optional subelements.
[0060] Among them, detailed information of other APs is stored in Optional Subelements.
[0061] In order to enhance the data encryption and authentication performance of WLAN, IEEE has defined the concept of Robust Security Network (RSN) through a new generation of security standards, and has made many improvements to the various defects of the WEP encryption mechanism, such as encryption technology and security authentication functions. The Robust Security Network Element (RSN element, RSNE) is used to indicate the elements related to the key suite and RSN capabilities carried in the RSN. Figure 3 As shown, Figure 3 : This is a diagram of the RSNE field structure provided by an embodiment of the present application. In the RSNE structure, the explanations of the main fields are as follows:
[0062] Element ID: used to uniquely identify the element;
[0063] Length: used to indicate the field length information;
[0064] Version: used to indicate RSN version information;
[0065] Group Data Cipher Suite: used to indicate the multicast data frame key suite information;
[0066] Pairwise Cipher Suite Count: used to indicate the number of unicast key suites;
[0067] Pairwise Cipher Suite List: used to represent the unicast key suite list;
[0068] AKM (authentication and key management) Suite Count: used to indicate the number of authentication and key suites;
[0069] AKM Suite List: used to indicate the certification and key suite list;
[0070] RSN Capabilities: used to represent the RSN capability set;
[0071] PMKID Count: used to indicate the number of PMKIDs
[0072] PMKID List: used to indicate the PMKID list
[0073] Group Management Cipher Suite: Used to indicate the multicast management frame key suite information.
[0074] Furthermore, in order to provide data integrity and replay protection for multicast management frames and beacon frames, the Broadcast / Multicast Integrity Protocol (BIP) is defined. The basic principle is that when the AP sends the GTK (group temporary key) to the STA, it also sends the integrity group temporary key (integrity group temporal key, IGTK) and a multicast frame integrity protection frame number (IGTK PacketNumber, IPN) for BIP protocol protection to the STA, and then the AP adds the message integrity code (message integrity code, MIC) value of the management frame calculated using the IGTK to the end of the sent multicast frame and sends it to the STA. The STA uses the same IGTK to verify the MIC. If the verification is successful, it proves that the multicast frame has not been tampered with. Similarly, for beacon frame protection, the AP sends the beacon frame integrity group temporary key (Beacon integrity group temporal key, BIGTK) and a frame sequence number (BIPN, BIGTK PN) for beacon frame integrity protection to the STA at the same time as the GTK is sent to the STA. Then the AP adds the MIC value of the management frame calculated using the BIGTK to the end of the multicast frame and sends it to the STA. The STA uses the same BIGTK to verify the MIC. If the verification is successful, it proves that the beacon frame has not been tampered with. Figure 4 As shown, Figure 4 It is the frame format of the management frame with BIP protection added, that is, on the basis of the original management frame, a management frame information integrity code element (Management MIC Element, MME) field containing MIC information, key suite index information (Key ID) and integrity protection frame sequence number frame number information (IPN) is added.
[0075] On the basis of the above, in the group wake-up time (broadcast Target WakeupTime, b-TWT) technology introduced by Wi-Fi 6, the AP slices a period of service time, such as a beacon period, into smaller service time slices corresponding to different b-TWT groups, and uses different b-TWT group IDs to indicate the service time slice information, and then broadcasts the information through the beacon frame. STA can join a b-TWT group through negotiation and non-negotiation. When the STA needs to interact with the AP for data, the STA wakes up during the corresponding b-TWT group service time and interacts with the AP for uplink and downlink cache data. During the non-corresponding b-TWT group service time, the STA does not need to wake up periodically to detect beacon information, nor does it need to compete for channel resources and receive cached data through CSMA / CA. Therefore, the power consumption caused by the STA periodically waking up to detect beacon frames and preempting channels is reduced, achieving the goal of ultra-low power consumption. Furthermore, based on the b-TWT technology, Wi-Fi 7 defines the strict target wake-up time (Restricted Target Wake Up Time, r-TWT) technology to meet the low-latency and low-power business needs. The basic principle is to use the b-TWT technology to slice the channel resources according to the service time, and then periodically allocate these time slices to STAs with low-latency services, and schedule the business data to be transmitted in the channel to meet the latency requirements of the business. In addition, the r-TWT technology adds protection measures at the starting boundary of the time slice to prevent other devices from occupying the r-TWT service time period.
[0076] In the current wireless communication technology, the research direction of the Ultra High Reliability (UHR) study group (SG) established by IEEE is mainly focused on improving transmission stability, including reducing latency, increasing throughput and reducing packet loss rate. One of the methods is non-Wi-Fi signal (such as Bluetooth signal) interference avoidance technology. Specifically, since non-Wi-Fi signals and Wi-Fi signals work on the same Industrial Scientific Medical Band (ISM) frequency band, when the two signals overlap, they are bound to interfere with each other, making it very difficult for the receiver to receive the overlapping signals, which in turn leads to an increase in packet loss rate. In order to solve the above problems, the UHR research team is studying a way to avoid non-Wi-Fi signal interference. Specifically, the STA connected to the AP informs the AP of the characteristics of its non-Wi-Fi service (including start and end time, period, etc.), and the AP broadcasts the characteristics through beacon frames. After receiving the information, other STAs automatically avoid transmitting Wi-Fi signals during the period of non-Wi-Fi services, thereby reducing the problem of packet loss rate caused by mutual interference and improving the stability of the system.
[0077] However, since different non-Wi-Fi signals have their typical business characteristics, such as Bluetooth calls (based on Bluetooth connection-oriented technology, i.e., BT SCO profile), which have a typical period of 3.75ms or 7.5ms, if a third-party device obtains this information, it can infer that an STA around the BSS has used a Bluetooth phone based on the characteristics of the Bluetooth service. Obviously, the use of Bluetooth phones is user privacy information, and directly broadcasting this information creates the risk of user privacy leakage.
[0078] In addition, since the beacon frames that support r-TWT and b-TWT (hereinafter referred to as: TWT target wake-up time) functions carry TWT grouping and service time window information by default, if a third-party device detects the TWT information in the beacon frame, it can occupy the channel within each r-TWT service time window, causing devices containing low-latency services to wait for channel intervention because they cannot intervene in the channel in time in the corresponding TWT window, causing delay problems and power consumption problems at the application layer, which may in turn cause the risk of user privacy leakage.
[0079] In order to prevent other network devices or third-party devices from obtaining sensitive information in beacon frames to a certain extent, and effectively avoid the risk of leakage of user sensitive information, the embodiments of the present application provide an information processing method, a network device and a computer-readable storage medium, wherein the sending side network device can encrypt the sensitive information field in the beacon frame by using the corresponding key configuration information to obtain the corresponding encrypted beacon frame, and then the sending side network device sends the encrypted beacon frame in the network, so that the receiving side network device uses the corresponding key configuration information to decrypt the sensitive information field of the encrypted beacon frame during the process of decrypting the sensitive information of the encrypted beacon frame, that is, when protecting the transmission of sensitive information of the beacon frame in the network, it is only necessary to use the corresponding key configuration information to encrypt the sensitive information of the beacon frame, thereby preventing other network devices or third-party devices from obtaining the sensitive information in the beacon frame to a certain extent, and effectively avoiding the risk of leakage of user sensitive information.
[0080] Based on the above analysis, the embodiments of the present application are further described below in conjunction with the accompanying drawings.
[0081] like Figure 5 As shown, Figure 5 It is a flowchart of an information processing method provided in an embodiment of the present application. The information processing method can be applied to a sending-side network device. The information processing method may include but is not limited to step S100 and step S200.
[0082] Step S100: Use the key configuration information to encrypt the sensitive information field in the beacon frame to obtain an encrypted beacon frame.
[0083] In this step, it can be understood that the beacon frame can be a management frame periodically sent in the wireless local area network. The beacon frame contains information about the network and is usually sent by an access point device to announce the existence of the network.
[0084] In one embodiment, the sending side network device may be an access point (AP) or an AP multi-link device (AP MLD), such as a wireless router, etc., which is not specifically limited in this embodiment.
[0085] In one embodiment, the information in the sensitive information domain may include: information closely related to the user's non-Wi-Fi services, such as the time and period of the non-Wi-Fi services using the channel; and information related to the user's Wi-Fi services, such as the time information of the target wake-up time TWT of the network device.
[0086] In this embodiment, it can be understood that the channel is the transmission medium connecting the sending side network device and the receiving side network device, that is, the channel for signal transmission. In addition, in TWT, a schedule is established between STA and AP, which is an agreement between STA and AP and consists of TWT time periods. Usually, the TWT time period negotiated by STA and AP includes one or more beacon periods. When the time period negotiated by STA and AP arrives, STA will wake up, wait for the trigger frame sent by AP, and exchange data. When this transmission is completed, it returns to sleep state. Each STA and AP will conduct independent negotiations, and each STA has a separate TWT time period. AP can also group according to the TWT time periods set by multiple STAs, and transmit data with multiple STAs at a time, thereby improving energy saving efficiency.
[0087] In one embodiment, if a terminal wants to establish a TWT connection, the terminal can inform the AP of its energy-saving scheduling information, and then the AP will allocate a TWT period and feed the period back to the terminal. Then the terminal will wake up at the specified TWT period and exchange data frames with the AP. In this round of exchange, the TWT period information may be obtained by a third-party device during the transmission process. When the third-party device obtains the TWT period information, it can occupy the channel in each r-TWT service time window, causing the device containing low-latency services to wait for channel intervention because it cannot intervene in the channel in time in the corresponding TWT window, thereby causing delay problems and power consumption problems at the application layer. Therefore, the TWT period information is encrypted as sensitive information of the beacon frame and then transmitted. Other network devices or third-party devices cannot decrypt the encrypted sensitive information field because they cannot obtain the key information of the sensitive information field, so that the network devices containing low-latency services can intervene in the channel in time in the corresponding TWT window, thereby improving transmission stability and throughput, while reducing latency and packet loss rate.
[0088] In one embodiment, the sensitive information domain may include only the sensitive information domain of the present device, or may include the first sensitive information domain of the sending side network device and the second sensitive information domain of the neighboring network device. For the second case, when the sending side network device uses the secret key configuration information to encrypt the sensitive information domain in the beacon frame, the secret key configuration information may be used to encrypt the first sensitive information and the second sensitive information domain in the beacon frame to obtain an encrypted beacon frame.
[0089] In one embodiment, when protecting the transmission of sensitive information of a beacon frame, the sending side network device can use corresponding key configuration information to encrypt the sensitive information field of the beacon frame, and then send the encrypted beacon frame and the key configuration information. After the receiving side network device receives the encrypted beacon frame and the key configuration information, it can directly use the corresponding key configuration information to decrypt the sensitive information field of the beacon frame, thereby preventing other network devices or third-party devices from obtaining sensitive information of the beacon frame to a certain extent, thereby effectively avoiding the risk of leakage of user sensitive information.
[0090] In one embodiment, the key configuration information may use the same frame number information, key suite information and / or key information as the BIP technology, that is, the sending side network device uses the key information, such as the beacon frame integrity group temporal key (Beacon integrity group temporal key, BIGTK), to simultaneously generate a message integrity code (Message Integrity Code, MIC) and encrypt sensitive information.
[0091] See also Figure 6 , Figure 6 It is a schematic diagram of the sending side network device using the same secret key to generate an information integrity code and encrypt sensitive information. The basic principle is: when the AP sends a group temporary key (GTK) to the STA, it sends a beacon frame integrity group temporary key and a frame sequence number (BIPN, BIGTKPN) used for beacon frame integrity protection to the STA. Then the AP adds the MIC value of the management frame calculated using BIGTK to the end of the sent multicast frame and sends it to the STA. The STA uses the same BIGTK to verify the MIC value. If the verification is successful, it proves that the beacon frame has not been tampered with. If the verification fails, it proves that the beacon frame has been tampered with.
[0092] In one embodiment, when the beacon frame sent by the sending side network device carries sensitive information of a neighbor AP in a neighbor report (NR), a reduced neighbor report (RNR), or a multiple basic service set identifier (MBSSID), the first sensitive information field of the current AP and the second sensitive information field of the neighbor AP can be encrypted using the first secret key information.
[0093] Among them, MBSSID technology can reduce the channel resource overhead of each AP sending beacon frames and detection response frames.
[0094] In this embodiment, see Figure 7 , Figure 7An exemplary structural diagram is given of a sending side network device using the same secret key to encrypt sensitive information elements located in different IEs. Among them, the MBSSID field in the beacon frame sent by the sending side network device carries sensitive information of the neighbor AP, and when the sensitive information field in the beacon frame and the sensitive information field of the neighbor AP are encrypted using the first secret key information in the secret key configuration information, the sending side network device can use the first secret key information to encrypt the sensitive information field in the beacon frame and the sensitive information field of the neighbor AP respectively.
[0095] In one embodiment, the beacon frame sent by the sending side network device carries key suite indication information, and the key suite indication information can be used to indicate the key suite information selected when encrypting the sensitive information domain, so that after the receiving side network device receives the beacon frame sent by the sending side network device, it can use the key suite indication information carried in the beacon frame to indicate the decryption of the sensitive information domain.
[0096] Step S200: Send an encrypted beacon frame.
[0097] In one embodiment, by adopting the information processing method of step S100 above, the encrypted beacon frame includes at least the encrypted sensitive information field and the key suite indication information for indicating the key suite information selected when encrypting the sensitive information field. Thus, during the network transmission process, other network devices or third-party devices can be prevented from obtaining the sensitive information of the encrypted beacon frame, thereby avoiding the risk of leakage of user sensitive information.
[0098] In one embodiment, the encrypted beacon frame may be sent in a network including but not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0099] In one embodiment, a STA connected to an AP may inform the AP of the characteristics of its non-Wi-Fi service (including start and end time, period, etc.), and the AP encrypts the characteristics through a beacon frame and broadcasts them. After other STAs receive the information, they automatically avoid transmitting Wi-Fi signals during the period of the non-Wi-Fi service, thereby reducing the problem of packet loss rate caused by mutual interference and improving the stability of the system.
[0100] In one embodiment, before executing step S100, the information processing method may include but is not limited to the following step S110.
[0101] S110: Interacting with the receiving-side network device through management frames to support the protection of sensitive information.
[0102] In this step, it can be understood that the management frame includes at least one of the following: a beacon frame, a probe request frame, a probe response frame, a multi-link probe request frame (ML proberequest), a multi-link probe response frame (ML probe response), an association request frame, a reassociation request frame, an association response frame, a reassociation response frame, an authentication frame, and an action frame.
[0103] In one embodiment, a supported capability set for sensitive information protection may be carried in an RSNE field, wherein RSNE may be used to indicate elements related to a key suite and RSN capabilities carried in a robust security network (RSN), which is beneficial for enhancing data encryption and authentication performance of a WLAN.
[0104] In one embodiment, the management frame may include a robust security network element field, such as Figure 8 As shown, Figure 8 The structure of RSNE field extension is given as an example. In the RSN Capabilities capability set field of RSNE, there may be multiple Reserved bit indicators, such as Figure 8 The B10 flag bit, B11 flag bit, B12 flag bit, and B15 flag bit shown in the figure can all be used as sensitive information protection capability indication flag bits to indicate whether sensitive information protection in beacon frames is supported. When indicating that sensitive information protection in beacon frames is supported, you can select any one of the reserved flag bits and then set the bit of the flag bit to 1. In addition, if it is indicated that sensitive information protection in beacon frames is not supported, the bit of the flag bit can be set to 0. For example Figure 8 The B10 flag in the frame sets the original Reserved bit indicator to the sensitive information protection capability indicator flag (Sensitive Info Protection). When the sensitive information protection capability indicator flag is set to 1, it indicates that sensitive information protection in the beacon frame can be supported; when the sensitive information protection capability indicator flag is set to 0, it indicates that sensitive information protection in the beacon frame is not supported.
[0105] like Fig. 9 As shown, Fig. 9This is a flow chart of an information processing method provided by another embodiment of the present application. Before the encrypted beacon frame in step S100, the information processing method may include but is not limited to steps S300 to S400.
[0106] S300: Generate key configuration information.
[0107] In one embodiment, the sending side network device can locally generate key configuration information for encrypting and decrypting sensitive information in the beacon frame. The key configuration information includes key information, beacon frame number information, and key suite information. Fig.10 As shown, Fig.10 The structure of the key configuration information is given as an example. In this structure, the explanations of the main fields are as follows:
[0108] Key ID: used to indicate key suite indication information;
[0109] PN: used to indicate the frame number;
[0110] Key: used to represent key information.
[0111] Among them, the secret key information can be used to generate a message integrity code and to encrypt sensitive information fields in the beacon frame.
[0112] In one embodiment, the key suite information may include at least one of the following: AES-128-CMAC, AES-128-GMAC, AES-256-CMAC, AES-256-GMAC, and SM4.
[0113] S400: Send the key configuration information to the receiving-side network device via an information frame.
[0114] In this step, the type of information frame may include any of the following: authentication frame; EAPOL frame; action frame. In addition, the receiving side network device may be an access point (AP), a multi-link access point (AP multi-link device, AP MLD), a terminal (STA) and a multi-link terminal (non-AP MLD).
[0115] In one embodiment, the sending side network device can interact with the receiving side network device through information frames to exchange key configuration information, so that the receiving side network device obtains the corresponding key configuration information, and uses the key information in the key configuration information to decrypt the sensitive information field of the received beacon frame to obtain decrypted information.
[0116] In one embodiment, the information processing method of the sending side network device may further include: not initiating competition and using channel resources within the time window of the service access channel corresponding to the sensitive information carried by the sensitive information domain.
[0117] In addition, if Fig.11 As shown, Fig.11 It is a flowchart of another information processing method provided in an embodiment of the present application. The information processing method is applied to a receiving-side network device. The information processing method may include but is not limited to steps A100 to A300.
[0118] Step A100: Receive a first beacon frame sent by a sending-side network device, wherein the first beacon frame includes a sensitive information field encrypted using key configuration information.
[0119] In one embodiment, the first beacon frame sent by the sending network device and received by the receiving network device may carry key suite indication information, wherein the key suite indication information is used to indicate the key suite information selected when decrypting the sensitive information field of the first beacon frame.
[0120] It is worth noting that the relevant introduction and explanation of the first beacon frame and the sensitive information field in this embodiment are consistent with the relevant introduction and explanation of the beacon frame and sensitive information in the embodiment shown in the aforementioned step S100. For the relevant introduction and explanation of the first beacon frame and the sensitive information field in this embodiment, reference can be made to the relevant introduction and explanation of the beacon frame and sensitive information in the embodiment shown in the aforementioned step S100, and no further details will be given here.
[0121] Step A200: Use the key configuration information to decrypt the sensitive information field in the first beacon frame to obtain decrypted sensitive information.
[0122] In this step, it should be noted that the key configuration information may include key information, beacon frame numbering information and key suite information, wherein the key information may be used to verify the information integrity code and to decrypt the sensitive information field in the first beacon frame.
[0123] In one embodiment, the key configuration information may include key information used to encrypt the sensitive information field in the first beacon frame and generate the information integrity code in the first beacon frame, number information of the first beacon frame, and key suite information.
[0124] In one embodiment, when the receiving side network device receives the encrypted beacon frame sent by the sending side network device, the receiving side network device can use the key information of the key configuration information previously received from the sending side network device to decrypt the sensitive information field in the encrypted beacon frame and verify its MIC information. If the verification is successful, it proves that the beacon frame has not been tampered with; if the verification fails, it proves that the beacon frame has been tampered with.
[0125] In one embodiment, when the sensitive information field in the first beacon frame includes the first sensitive information field of the sending side network device and the second sensitive information field of the neighboring network device of the sending side network device, the receiving side network device can use the key information of the received key configuration information to decrypt the first sensitive information field and the second sensitive information field to obtain corresponding decrypted sensitive information, so that corresponding operations can be performed subsequently based on the decrypted sensitive information.
[0126] Step A300: Perform corresponding information processing according to the decrypted sensitive information.
[0127] In one embodiment, when the receiving side network device is a terminal or a multi-link terminal, the receiving side network device performing corresponding information processing may include: not initiating competition and using channel resources within a time window of a service access channel corresponding to decryption of sensitive information.
[0128] In this embodiment, it can be understood that the network device communication can be random channel access, that is, the network device does not occupy fixed resources. In order to arrange the use of resources between different network devices, it is usually necessary to complete it through a "competition" process. The time window of the service access channel corresponding to the decrypted sensitive information means that within a period of time, the channel resources are occupied by the service corresponding to the decrypted sensitive information. The receiving side network device can, according to the indication of the decrypted sensitive information, not initiate competition and use channel resources within the time window of the service access channel corresponding to the decrypted sensitive information, so that the corresponding service can use the channel resources.
[0129] See also Fig.12 , Fig.12 The information processing flow chart when the receiving side network device is an AP or an AP MLD is exemplarily given. In one embodiment, when the receiving side network device is an access point or a multi-link access point, the corresponding information processing may include but is not limited to steps A310 to A320.
[0130] A310: Use the key configuration information generated locally by the receiving side network device to encrypt the decryption sensitive information to obtain encrypted information.
[0131] In one embodiment, the key configuration information generated locally by the receiving side network device may include second key information used to encrypt the sensitive information field in the second beacon frame and generate the information integrity code in the second beacon frame, the numbering information of the second beacon frame, and the key suite information.
[0132] In one embodiment, when the receiving side network device uses the first key information in the received key configuration information to decrypt the sensitive information field in the first beacon frame and obtains the decrypted information, the second key information generated locally by the receiving side network device can be used again to encrypt the obtained decrypted information, and then the re-encrypted decrypted information is copied to the field for storing the sensitive information of the sending side network device in the second beacon frame. Then, the receiving side network device can send the second beacon frame in the network.
[0133] A320: Generate a second beacon frame according to the encrypted information, where the second beacon frame includes a sensitive information field for storing the encrypted information.
[0134] In one embodiment, a field for storing sensitive information of a sending side network device is provided in the second beacon frame, wherein the field for storing may include: an NR field, an RNR field, or an MBSSID field. The NR field, the RNR field, or the MBSSID field may be used to indicate that a neighboring AP contains sensitive information, where the neighboring AP is a sending side network device.
[0135] In one embodiment, see Fig.13 , Fig.13 An exemplary structural diagram of the receiving side network device using the second secret key to encrypt sensitive information elements located in different IEs is given. Among them, the NR field in the second beacon frame is used to store the sensitive information of the sending side network device. When the receiving side network device uses the secret key information in the secret key configuration information to encrypt the sensitive information field in the second beacon frame and the sensitive information field of the sending side network device, the second secret key information can be used to encrypt the sensitive information field in the second beacon frame and the sensitive information field of the sending side network device respectively.
[0136] In one embodiment, when the receiving side network device is an access point or a multi-link access point, the corresponding information processing may further include: not initiating competition and not using channel resources within a time window of a service access channel corresponding to decryption of sensitive information.
[0137] In this embodiment, the beacon frame received by the receiving side network device can support r-TWT and b-TWT functions. At this time, the beacon frame carries TWT grouping and service time window information by default. The receiving side network device can decrypt the sensitive information according to the instructions. Within the time window of the service access channel corresponding to the decrypted sensitive information, if it is not a member of the corresponding r-TWT and b-TWT group, it will not initiate competition and use channel resources, so that the corresponding service can intervene in the channel in time in the corresponding TWT window, thereby reducing transmission delay, improving throughput and reducing packet loss rate.
[0138] In one embodiment, when the receiving side network device is an access point or a multi-link access point, the corresponding information processing may include but is not limited to the following two types: the receiving side network device does not initiate competition and use channel resources within the time window of the service access channel corresponding to the decrypted sensitive information; the receiving side network device uses the locally generated key configuration information to encrypt the decrypted sensitive information to obtain encrypted information, and then generates a second beacon frame based on the encrypted information, wherein the second beacon frame includes a sensitive information field for storing the encrypted information, and then sends the second beacon frame.
[0139] It is worth noting that, in this embodiment, the specific implementation methods and related introductions and explanations of the technical effects of the corresponding information processing are consistent with the specific implementation methods and related introductions and explanations of the technical effects of the information processing method described in any one of the above steps A300, A310 and A320. For the specific implementation methods and related introductions and explanations of the technical effects of the corresponding information processing in this embodiment, reference can be made to the specific implementation methods and related introductions and explanations of the technical effects of the information processing method described in any one of the above steps A300, A310 and A320, which will not be repeated here.
[0140] A330: Send the second beacon frame.
[0141] In one embodiment, by adopting an information processing method including the above-mentioned steps A310 and A320, the second beacon frame can include at least the sensitive information field in the encrypted second beacon frame and the encrypted sensitive information field of the sending side network device, and the key suite indication information for indicating the key suite information selected when encrypting the sensitive information field.
[0142] In one embodiment, the receiving side network device can interact with the third receiving side network device to discuss the support capabilities of both parties for the protection of sensitive information, and the third receiving side network device can also receive and save the second key configuration information sent by the receiving side network device through the second information frame, so that when the third receiving side network device receives the encrypted second beacon frame, it can decrypt and verify the encrypted sensitive information field of the second beacon frame according to the key information in the second key configuration information, and then perform subsequent information processing according to the decrypted sensitive information after obtaining the decrypted sensitive information. In this way, not only can other network devices or third-party devices be prevented from obtaining the sensitive information of the encrypted second beacon frame, but the risk of leakage of user sensitive information can also be effectively avoided.
[0143] In one embodiment, before executing step A100, the step of interacting with the sending-side network device through management frames to determine the support capabilities of both parties for sensitive information protection may be further included.
[0144] In one embodiment, the receiving-side network device exchanges the support capability of sensitive information protection with the sending-side network device by setting the bit of the flag in the robust security network element field of the management frame to 1.
[0145] It is worth noting that the specific implementation methods and technical effects of the information processing involved in this embodiment are consistent with the specific implementation methods and technical effects of the information processing method described in any one of the embodiments in the above step S110. For the specific implementation methods and technical effects involved in this embodiment, refer to the specific implementation methods and technical effects of the information processing method described in any one of the embodiments in the above step S110, and they will not be repeated here.
[0146] In one embodiment, before executing step A100, the step of receiving key configuration information sent by the sending side network device through an information frame may be further included.
[0147] The key configuration information may include: key information used to encrypt the sensitive information field in the beacon frame and generate the information integrity code in the beacon frame, the numbering information of the beacon frame, and key suite information.
[0148] In one embodiment, the key suite information may include at least one of the following: AES-128-CMAC, AES-128-GMAC, AES-256-CMAC, AES-256-GMAC and SM4. In addition, the type of the information frame may include any one of the following: authentication frame, EAPOL frame, action frame.
[0149] In one embodiment, the sending side network device can send updated key configuration information via an information frame in the network at any time. When the receiving side network device receives the information frame, it can obtain the updated key configuration information and then replace the originally saved key configuration information with the updated key configuration information.
[0150] In the embodiment of the present application, for the STA device connected to the AP, the STA device can obtain the sensitive information by directly using the corresponding key information to decrypt the protected sensitive information domain, and can prevent the use of the same channel during its working time period. For other STA or third-party devices, because they do not obtain the corresponding key, they cannot obtain sensitive information related to the user's business, thereby effectively avoiding the risk of leakage of user sensitive information.
[0151] The information processing method provided in the above embodiment is described in detail below with specific examples:
[0152] Example 1:
[0153] See also Fig.14 , Fig.14 It is a schematic diagram of the process of the sending side network device and the receiving side network device using beacon frames to interact and encrypt sensitive information. Fig.14 The sending side network device shown may be an access point or a multi-link access point, and the receiving side network device may be a terminal or a multi-link terminal. The specific example of the interaction process is as follows:
[0154] Step 1: The sending-side network device exchanges sensitive information protection support capabilities with the receiving-side network device through management frames.
[0155] Step 2: The sending side network device locally generates key configuration information 1 for encrypting and decrypting sensitive information in the beacon frame.
[0156] Step 3: During the frame interaction between the sending side network device and the receiving side network device, the sending side network device sends an information frame to the receiving side network device, and sends the above-mentioned secret key configuration information 1 to the receiving side network device.
[0157] Step 4: The receiving-side network device saves the above-mentioned key configuration information 1 locally.
[0158] Step 5: The sending network device sends a beacon frame whose sensitive information field has been encrypted using the above-mentioned key configuration information 1.
[0159] Step 6: After receiving the beacon frame, the receiving network device uses the key configuration information 1 to decrypt its sensitive information.
[0160] Step 7: The receiving network device performs corresponding information processing according to the decrypted sensitive information indication.
[0161] It should be noted that the sending side network device in the above interaction process may be an AP or an AP MLD, and the receiving side network device may be any one of an AP, an AP MLD, a STA, and a non-AP MLD.
[0162] In one embodiment, when the sensitive information field of the beacon frame in step (5) includes the first sensitive information of the sending side network device and the second sensitive information of the neighboring AP, the sending side network device needs to use the same key information to encrypt the first sensitive information and the second sensitive information, and when the receiving side network device is an AP or an AP MLD, after the receiving side network device decrypts the sensitive information field according to the key configuration information, it needs to encrypt the decrypted information field again using the second key information generated locally.
[0163] It is worth noting that since the relevant introduction and explanation of the specific implementation methods and technical effects involved in this example one include the information processing method described in any of the above embodiments, the relevant introduction and explanation of the specific implementation methods and technical effects involved in this example one can refer to the information processing method described in any of the above embodiments and will not be repeated here.
[0164] Example 2:
[0165] See also Fig.15 , Fig.15 This is another schematic diagram of the process in which the sending side network device and the receiving side network device use beacon frames to interact and encrypt sensitive information. Fig.15 The sending side network device shown may be an access point or a multi-link access point, and the receiving side network device may be an access point or a multi-link access point. Fig.15 The receiving side network device shown can repeat Fig.14 The operation of the sending side network device shown in , correspondingly, Fig.15 The sending side network device shown is repeated Fig.14 The operation of the receiving side network device shown in FIG. Fig.14 Based on the interactive process shown, Fig.15 The interactive process shown specifically includes the following steps:
[0166] Step A: The receiving-side network device exchanges sensitive information protection support capabilities with the sending-side network device through management frames.
[0167] Step B: The receiving-side network device locally generates key configuration information 2 for encrypting and decrypting sensitive information in the beacon frame.
[0168] Step C: During the frame interaction between the receiving side network device and the sending side network device, the receiving side network device sends an information frame to the sending side network device, and sends the above-mentioned secret key configuration information 2 to the sending side network device.
[0169] Step D: The sending side network device stores the above-mentioned secret key configuration information 2 locally.
[0170] Step E: The receiving-side network device sends a beacon frame whose sensitive information field has been encrypted using the above-mentioned key configuration information 2.
[0171] Step F: After receiving the beacon frame, the sending network device uses the key configuration information 2 to decrypt its sensitive information.
[0172] Step G: The sending side network device performs corresponding information processing according to the decrypted sensitive information indication.
[0173] It is worth noting that since the relevant introduction and explanation of the specific implementation methods and technical effects involved in this Example 2 include the information processing method described in any of the above embodiments, the relevant introduction and explanation of the specific implementation methods and technical effects involved in this Example 2 can refer to the information processing method described in any of the above embodiments and will not be repeated here.
[0174] The sending side network device and the receiving side network device in the present application respectively include a memory and a processor, wherein the memory and the processor may be connected via a bus or other means.
[0175] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0176] The application scenario described in the embodiment of the present application in which the sending-side network device and the receiving-side network device use beacon frames to exchange encrypted sensitive information is intended to more clearly illustrate the technical solution of the embodiment of the present application, and does not constitute a limitation on the technical solution provided by the embodiment of the present application. Those skilled in the art will know that with the emergence of new application scenarios, the technical solution provided by the embodiment of the present application is also applicable to similar technical problems.
[0177] Based on the above information processing method, an embodiment of the present application provides a network device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor.
[0178] The processor and the memory may be connected via a bus or other means.
[0179] It should be noted that the network device in this embodiment can be applied to the sending side network device, the receiving side network device and the third receiving side network device in the embodiments of the present application. These embodiments all belong to the same inventive concept, so these embodiments have the same implementation principles and technical effects, and will not be described in detail here.
[0180] The non-transient software program and instructions required to implement the information processing method of the above embodiment are stored in the memory. When executed by the processor, the information processing method of the above embodiment is executed, for example, the above described information processing method is executed. Figure 5 Method steps S100 to S200, Fig. 9 Steps S300 to S400, Fig.11 Method steps A100 to A300, Fig.12 Method steps A310 to A330 in.
[0181] The device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0182] In addition, based on the above information processing method, an embodiment of the present application further provides a computer-readable storage medium, which stores computer-executable instructions. The computer-executable instructions are executed by a processor or a controller, for example, by a processor in the above network device embodiment, so that the above processor can execute the information processing method in the above embodiment, for example, execute the above described Figure 5 Method steps S100 to S200, Fig. 9 Steps S300 to S400, Fig.11 Method steps A100 to A300, Fig.12 Method steps A310 to A330 in.
[0183] It will be appreciated by those skilled in the art that all or some of the steps and systems in the disclosed method above may be implemented as software, firmware, hardware and appropriate combinations thereof. Some physical components or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or a non-transitory medium) and a communication medium (or a temporary medium). As known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technologies, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, disk storage or other magnetic storage devices, or any other medium that may be used to store desired information and may be accessed by a computer. Furthermore, it is well known to those skilled in the art that communication media typically embodies computer readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
[0184] The above is a specific description of the preferred implementation of the present application, but the present application is not limited to the above-mentioned implementation mode. Technical personnel familiar with the field can also make various equivalent deformations or substitutions without violating the spirit of the present application. These equivalent deformations or substitutions are all included in the scope defined by the claims of the present application.
Claims
1. An information processing method, applied to a sending-side network device, the method comprising: The sensitive information field in the beacon frame is encrypted using the secret key configuration information to obtain an encrypted beacon frame; The encrypted beacon frame is sent.
2. The method according to claim 1, characterized in that Before using the key configuration information to encrypt the sensitive information field in the beacon frame, the method further includes: The ability to support the protection of sensitive information by interacting with the receiving network device through management frames.
3. The method according to claim 2, characterized in that The management frame includes a robust security network element field, and the robust security network element field includes a sensitive information protection capability indication flag bit, and the sensitive information protection capability indication flag bit is used to indicate whether protection of the sensitive information field of the beacon frame is supported.
4. The method according to claim 3, characterized in that: The management frame includes one of the following: Beacon frame; Probe request frame; Probe response frame; Multilink detection request frame; Multilink probe response frame; Association request frame; Reassociation request frame; Association response frame; Reassociation response frame; Authentication frame; Action Frame.
5. The method according to claim 1, characterized in that Before using the key configuration information to encrypt the sensitive information field in the beacon frame, the method further includes: Generate the key configuration information; The key configuration information is sent to the receiving side network device via an information frame.
6. The method according to claim 5, characterized in that The key configuration information includes key information, beacon frame number information and key suite information.
7. The method according to claim 6, characterized in that: The secret key information is used to generate a message integrity code and to encrypt the sensitive information field in the beacon frame.
8. The method according to claim 6, characterized in that The beacon frame includes key suite indication information, where the key suite indication information is used to indicate the key suite information selected when encrypting the sensitive information domain.
9. The method according to claim 5, characterized in that The information frame includes one of the following: Authentication frame; EAPOL frames; Action Frames.
10. The method according to claim 1, characterized in that The sensitive information domain includes a first sensitive information domain of the sending side network device and a second sensitive information domain of the neighboring network device; The sensitive information field in the beacon frame is encrypted using the secret key configuration information to obtain an encrypted beacon frame, including: The first sensitive information field in the beacon frame is encrypted using the key configuration information, and the second sensitive information field in the beacon frame is encrypted using the key configuration information to obtain an encrypted beacon frame.
11. The method according to claim 1, characterized in that: The method further comprises: Do not initiate competition and use channel resources within the time window of the service access channel corresponding to the sensitive information carried by the sensitive information domain.
12. An information processing method, applied to a receiving-side network device, the method comprising: Receive a first beacon frame sent by a sending-side network device, wherein the first beacon frame includes a sensitive information field encrypted using key configuration information; Decrypting the sensitive information field in the first beacon frame using the secret key configuration information to obtain decrypted sensitive information; Corresponding information processing is performed according to the decrypted sensitive information.
13. The method according to claim 12, characterized in that Before receiving the first beacon frame sent by the sending side network device, the method further includes: The support capabilities of both parties for sensitive information protection are interacted with the sending side network device through management frames.
14. The method according to claim 13, characterized in that The management frame includes a robust security network element field, and the robust security network element field includes a sensitive information protection capability indication flag bit, and the sensitive information protection capability indication flag bit is used to indicate whether protection of the sensitive information field of the first beacon frame is supported.
15. The method according to claim 14, characterized in that The management frame includes one of the following: Beacon frame; Probe request frame; Probe response frame; Multilink detection request frame; Multilink probe response frame; Association request frame; Reassociation request frame; Association response frame; Reassociation response frame; Authentication frame; Action Frame.
16. The method according to claim 12, characterized in that Before receiving the first beacon frame sent by the sending side network device, the method further includes: Receive the key configuration information sent by the sending side network device through an information frame.
17. The method according to claim 16, characterized in that The key configuration information includes key information, beacon frame number information and key suite information.
18. The method according to claim 17, characterized in that The secret key information is used to verify the information integrity code and to decrypt the sensitive information field in the first beacon frame.
19. The method according to claim 17, characterized in that The first beacon frame includes key suite indication information, where the key suite indication information is used to indicate the key suite information selected when decrypting the sensitive information domain.
20. The method according to claim 16, characterized in that The information frame includes one of the following: Authentication frame; EAPOL frames; Action Frames.
21. The method according to claim 12, characterized in that The sensitive information domain includes a first sensitive information domain of the sending side network device and a second sensitive information domain of the neighboring network device; The using the key configuration information to decrypt the sensitive information field in the first beacon frame to obtain decrypted sensitive information includes: The first sensitive information field in the first beacon frame is decrypted using the key configuration information, and the second sensitive information field in the first beacon frame is decrypted using the key configuration information to obtain decrypted sensitive information.
22. The method according to claim 12, characterized in that The receiving-side network device is a terminal device, and the performing corresponding information processing according to the decrypted sensitive information includes: Do not initiate competition and use channel resources within the time window of the service access channel corresponding to the decrypted sensitive information.
23. The method according to claim 12, characterized in that The receiving-side network device is an access point device, and the performing corresponding information processing according to the decrypted sensitive information includes at least one of the following: Not initiating competition and using channel resources within the time window of the service access channel corresponding to the decrypted sensitive information; Encrypting the decrypted sensitive information using the locally generated key configuration information to obtain encrypted information; generating a second beacon frame according to the encrypted information, wherein the second beacon frame includes a sensitive information field for storing the encrypted information; The second beacon frame is sent.
24. A network device comprising: A memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the information processing method according to any one of claims 1 to 23 when executing the computer program.
25. A computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the information processing method according to any one of claims 1 to 23.
Citation Information
Cited By
Information processing method, network device, and computer-readable storage medium
EP4811719A1