Multi-link security protection method, device, equipment and medium
By adopting the combination methods of multi-link data acquisition, collaborative detection, dynamic link switching and encryption management frame authentication modules in the multi-link operating environment of WiFi 7, the problem of malicious access point attack detection and mitigation is solved, and efficient and accurate multi-link security protection is achieved.
Patent Information
- Application Number
- CN202510424923.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-07
- Publication Date
- 2025-06-10
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the multi-link operating environment of WiFi 7, existing security protection technologies are difficult to quickly and accurately detect and mitigate attacks from malicious access points, especially in terms of encryption management frame resolution and cross-link collaborative protection.
The multi-link data acquisition module is used for data acquisition, the collaborative detection module performs malicious access point AP detection on the collected data, the dynamic link switching module performs dynamic link switching or triggers mitigation strategies, and the encryption management frame authentication module decrypts and completeness verification of the encrypted MLO-MFP management frame. If the verification fails, the exception response mechanism will be triggered.
It effectively breaks through the limitations of single-link detection, can jointly identify malicious AP forgery behavior in multiple frequency bands, improve detection efficiency and accuracy, and dynamically adjust terminal link resources in real time when an attack is detected, ensuring communication security.
Smart Images

Figure CN120128929A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of wireless local area network security, and provides a multi-link security protection method, device, equipment and medium. Background Art
[0002] With the continuous development of WiFi technology, in order to improve the performance of wireless networks, WiFi 7 (802.11be) inherits the advantages of WiFi 6E and introduces multi-link operation (MLO) technology, enabling terminal devices to communicate simultaneously on multiple frequency bands such as 2.4 GHz, 5 GHz, and 6 GHz, thereby achieving higher throughput and lower latency.
[0003] However, the multi-link operation environment also brings the following several new security challenges: (1) malicious access point (AP) attacks. Attackers may use the MLO feature to forge beacon frames, management frames, or control frames in coordination on different frequency bands, launching denial-of-service, connection hijacking, or man-in-the-middle attacks; (2) increased difficulty in parsing encrypted management frames. WiFi 7 requires encrypting and authenticating all management frames using MLO MFP. Traditional detection methods are difficult to effectively parse encrypted management frames, resulting in malicious APs possibly using encrypted frames for forgery attacks; (3) insufficient cross-link collaborative protection. Existing security solutions mainly detect and mitigate single-link issues and cannot make full use of multi-link data for collaborative judgment, making it difficult to respond promptly to cross-frequency band attack behaviors.
[0004] Therefore, there is an urgent need for a multi-link security protection technology that can quickly and accurately detect and mitigate malicious attacks. Summary of the Invention
[0005] The present application provides a multi-link security protection method, device, equipment and medium, which is used to solve the problem that existing security protection technologies cannot quickly and accurately detect and mitigate malicious attacks.
[0006] On the one hand, a multi-link security protection method is provided, and the method includes:
[0007] Use a multi-link data acquisition module to collect data and obtain the collected data corresponding to each link; wherein, the collected data includes management frames, beacon frames, and control frames;
[0008] Use a collaborative detection module to detect malicious access points AP for the collected data corresponding to each link, and determine whether there are abnormalities in each link; wherein, the abnormalities include cross-link forgery and abnormal management frames;
[0009] For any link, if it is determined that there is an abnormality in the any link, a dynamic link switching module is used for dynamic link switching, or a mitigation strategy module is used to trigger a mitigation strategy;
[0010] An encrypted management frame authentication module is used to receive the encrypted MLO-MFP management frame and decrypt the encrypted MLO-MFP management frame to obtain the decrypted MLO-MFP management frame;
[0011] The encrypted management frame authentication module is used to perform integrity verification on the decrypted MLO-MFP management frame to determine whether the verification passes; wherein, the verification includes MLO-MFP field verification, cross-link data comparison, and timestamp verification;
[0012] If it is determined that the verification fails, an exception response mechanism is triggered.
[0013] Optionally, the step of using a multi-link data acquisition module to perform data acquisition to obtain the acquisition data corresponding to each link includes:
[0014] Configure a multi-link data acquisition module in the terminal device;
[0015] The multi-link data acquisition module is used to perform data acquisition from the 2.4 GHz, 5 GHz, and 6 GHz band links respectively to obtain the management frames, beacon frames, and control frames corresponding to each link; wherein each frame is attached with a timestamp, signal strength, link status, and multi-link operation - management frame protection MLO-MFP field.
[0016] Optionally, the step of using a collaborative detection module to perform malicious access point AP detection on the acquisition data corresponding to each link to determine whether there is an abnormality in each link includes:
[0017] Use a preset data fusion algorithm to perform data fusion on the management frames, beacon frames, and control frames corresponding to each link to obtain the fused multi-link data;
[0018] According to a preset threshold and a preset anomaly detection model, perform collaborative analysis on the fused multi-link data to determine whether there is an abnormality in each link; wherein the preset anomaly detection model is composed of a random forest model and an anomaly scoring model.
[0019] Optionally, the step of performing collaborative analysis on the fused multi-link data according to a preset threshold and a preset anomaly detection model to determine whether there is an abnormality in each link includes:
[0020] Use the random forest model in the preset anomaly detection model to process the fused multi-link data to obtain an anomaly probability;
[0021] Process the abnormal probability using the abnormal scoring model in the preset abnormal detection model to obtain an abnormal score;
[0022] Determine whether there is an abnormality in each link according to the preset threshold and the abnormal score.
[0023] Optionally, the step of, if it is determined that there is an abnormality in any one of the links, then using the dynamic link switching module to perform dynamic link switching, or using the mitigation strategy module to trigger a mitigation strategy, includes:
[0024] If it is determined that there is an abnormality in any one of the links, then use the dynamic link switching module to automatically switch the terminal device to a secure link, or use the mitigation strategy module to suspend connecting to the abnormal link, or use the mitigation strategy module to jointly broadcast forged beacon frames with the AP.
[0025] Optionally, the step of using the encrypted management frame authentication module to receive the encrypted MLO-MFP management frame and decrypt the encrypted MLO-MFP management frame to obtain the decrypted MLO-MFP management frame includes:
[0026] Use the encrypted management frame authentication module to receive the encrypted MLO-MFP management frame;
[0027] Perform dynamic key negotiation on the encrypted MLO-MFP management frame according to the dynamic key to obtain the decrypted MLO-MFP management frame; or,
[0028] Decrypt the encrypted MLO-MFP management frame according to the public key infrastructure PKI mechanism to obtain the decrypted MLO-MFP management frame.
[0029] Optionally, after triggering the abnormal response mechanism, the method further includes:
[0030] Use the cross-link record module to record the detection data and abnormal events of each link in a unified secure log system and form a cross-link secure situation map.
[0031] On the one hand, provide a multi-link security protection device, the device includes:
[0032] A data acquisition unit, configured to use a multi-link data acquisition module to perform data acquisition to obtain acquisition data corresponding to each link; wherein, the acquisition data includes management frames, beacon frames, and control frames;
[0033] An abnormal detection unit, configured to use a collaborative detection module to detect malicious access points AP for the acquisition data corresponding to each link to determine whether there is an abnormality in each link; wherein, the abnormality includes cross-link forgery and abnormal management frames;
[0034] A link switching and mitigation unit, for any link, if it is determined that the any link has an abnormality, then a dynamic link switching module is used for dynamic link switching, or a mitigation strategy module is used to trigger a mitigation strategy;
[0035] An encrypted management frame authentication unit, which uses an encrypted management frame authentication module to receive the encrypted MLO-MFP management frame and decrypt the encrypted MLO-MFP management frame to obtain the decrypted MLO-MFP management frame;
[0036] The encrypted management frame authentication unit is further configured to use the encrypted management frame authentication module to perform integrity verification on the decrypted MLO-MFP management frame to determine whether the verification passes; wherein, the verification includes MLO-MFP field verification, cross-link data comparison, and timestamp verification;
[0037] The encrypted management frame authentication unit is further configured to trigger an exception response mechanism if it is determined that the verification fails.
[0038] On the one hand, an electronic device is provided, which includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the above-mentioned any method is implemented.
[0039] On the one hand, a storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the above-mentioned any method is implemented.
[0040] Compared with the prior art, the beneficial effects of the present application are:
[0041] In the present application, when performing network communication security protection, first, a multi-link data acquisition module can be used to acquire data to obtain the acquisition data corresponding to each link; wherein, the acquisition data includes management frames, beacon frames, and control frames; then, a collaborative detection module can be used to detect malicious access points (APs) in the acquisition data to determine whether there are abnormalities in each link; wherein, the abnormalities include cross-link forgery and abnormal management frames; next, for any link, if it is determined that any link has an abnormality, then a dynamic link switching module can be used for dynamic link switching, or a mitigation strategy module can be used to trigger a mitigation strategy; then, an encrypted management frame authentication module can be used to receive the encrypted MLO-MFP management frame and decrypt the encrypted MLO-MFP management frame to obtain the decrypted MLO-MFP management frame; next, the encrypted management frame authentication module can be used to perform integrity verification on the decrypted MLO-MFP management frame to determine whether the verification passes; wherein, the verification includes MLO-MFP field verification, cross-link data comparison, and timestamp verification; finally, if it is determined that the verification fails, then an exception response mechanism can be triggered.
[0042] Therefore, in this application, since the collaborative detection module is used to detect malicious APs for the collected data corresponding to each link, compared with the prior art, this application effectively breaks through the limitation of single-link detection, can collaboratively identify the forgery behavior of malicious APs in multiple frequency bands, thereby significantly improving the detection efficiency and accuracy. Moreover, for any link, if it is determined that there is an abnormality in the any link, since the dynamic link switching module is also used for dynamic link switching, or the mitigation strategy module is used to trigger the mitigation strategy, compared with the prior art, when an attack is detected, this application can also dynamically adjust the terminal link resources in real time to ensure that the communication is not interrupted and the security is guaranteed. In addition, since the encrypted MLO-MFP management frame is also decrypted and verified in real time, compared with the prior art, this application can also realize the real-time parsing and anomaly detection of the encrypted management frame to prevent malicious APs from using the encryption mechanism to evade detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only the embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0044] Figure 1 An electronic device provided by an embodiment of this application;
[0045] Figure 2 A schematic diagram of the overall architecture of a multi-link security protection system provided by an embodiment of this application;
[0046] Figure 3 A schematic diagram of a multi-link security protection method provided by an embodiment of this application;
[0047] Figure 4 A schematic diagram of multi-link data collection and collaborative detection provided by an embodiment of this application;
[0048] Figure 5 A schematic diagram of link state conversion provided by an embodiment of this application;
[0049] Figure 6 A schematic diagram of encrypted management frame parsing and dynamic authentication provided by an embodiment of this application;
[0050] Figure 7 A schematic diagram of a multi-link security protection device provided by an embodiment of this application.
[0051] Markings in the figure: 10 - Multi-link security protection device, 101 - Processor, 102 - Memory, 103 - I / O interface, 104 - Database, 70 - Multi-link security protection device, 701 - Data acquisition unit, 702 - Anomaly detection unit, 703 - Link switching and mitigation unit, 704 - Encryption management frame authentication unit, 705 - Cross-link recording unit. Detailed implementation manners
[0052] To make the objectives, technical solutions and advantages of the present application clearer and more understandable, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without making creative efforts belong to the scope of protection of the present application. Without conflict, the embodiments in the present application and the features in the embodiments can be arbitrarily combined with each other. And although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0053] With the continuous development of WiFi technology, in order to improve the performance of wireless networks, WiFi 7 (802.11be) introduces the Multi-Link Operation (MLO) technology on the basis of inheriting the advantages of WiFi 6E, enabling terminal devices to communicate simultaneously in multiple frequency bands such as 2.4 GHz, 5 GHz, and 6 GHz, thereby achieving higher throughput and lower latency.
[0054] However, the multi-link operation environment also brings the following several new security challenges: (1) Malicious Access Point (AP) attacks. Attackers may use the MLO feature to collaboratively forge beacon frames, management frames, or control frames in different frequency bands to initiate denial-of-service, connection hijacking, or man-in-the-middle attacks; (2) Increased difficulty in parsing encrypted management frames. WiFi 7 requires encrypting and authenticating all management frames using MLO MFP. Traditional detection methods are difficult to effectively parse encrypted management frames, resulting in malicious APs possibly using encrypted frames for forgery attacks; (3) Insufficient cross-link collaborative protection. Existing security solutions mainly detect and mitigate single links and cannot make full use of multi-link data for collaborative judgment, making it difficult to respond in a timely manner to cross-frequency band attack behaviors.
[0055] Based on this, an embodiment of the present application provides a multi-link security protection method. In this method, first, a multi-link data acquisition module can be used to perform data acquisition to obtain the acquired data corresponding to each link; wherein, the acquired data includes management frames, beacon frames, and control frames. Then, a collaborative detection module can be used to detect malicious access points (APs) in the acquired data to determine whether there are abnormalities in each link; wherein, the abnormalities include cross-link forgery and abnormal management frames. Next, for any one link, if it is determined that there is an abnormality in the any one link, a dynamic link switching module can be used to perform dynamic link switching, or a mitigation strategy module can be used to trigger a mitigation strategy. Then, an encrypted management frame authentication module can be used to receive the encrypted MLO-MFP management frame and decrypt the encrypted MLO-MFP management frame to obtain the decrypted MLO-MFP management frame. Next, the encrypted management frame authentication module can be used to perform integrity verification on the decrypted MLO-MFP management frame to determine whether the verification passes; wherein, the verification includes MLO-MFP field verification, cross-link data comparison, and timestamp verification. Finally, if it is determined that the verification fails, an exception response mechanism can be triggered. Therefore, in the present application, since the collaborative detection module is used to detect malicious APs in the acquired data corresponding to each link, compared with the prior art, the present application effectively breaks through the limitation of single-link detection and can collaboratively identify the forgery behavior of malicious APs in multiple frequency bands, thereby greatly improving the detection efficiency and accuracy. Moreover, for any one link, if it is determined that there is an abnormality in the any one link, since a dynamic link switching module is also used to perform dynamic link switching, or a mitigation strategy module is used to trigger a mitigation strategy, compared with the prior art, when an attack is detected, the present application can also dynamically adjust the terminal link resources in real time to ensure that the communication is not interrupted and the security is guaranteed. In addition, since the encrypted MLO-MFP management frame is also decrypted and verified in real time, compared with the prior art, the present application can also implement real-time parsing and anomaly detection of encrypted management frames to prevent malicious APs from using the encryption mechanism to evade detection.
[0056] After introducing the design concept of the embodiment of the present application, the following briefly introduces the application scenarios applicable to the technical solution of the embodiment of the present application. It should be noted that the following introduced application scenarios are only used to illustrate the embodiment of the present application rather than to limit it. In the specific implementation process, the technical solution provided by the embodiment of the present application can be flexibly applied according to actual needs.
[0057] As Figure 1 shown, an electronic device provided by an embodiment of the present application, and this electronic device can specifically be a multi-link security protection device 10.
[0058] Among them, the multi-link security protection device 10 can be used for multi-link security protection. For example, it can be a personal computer (PC), a server, a laptop, etc. The multi-link security protection device 10 may include one or more processors 101, a memory 102, an I / O interface 103, and a database 104. Specifically, the processor 101 can be a central processing unit (CPU), or a digital processing unit, etc. The memory 102 can be a volatile memory, such as a random-access memory (RAM); the memory 102 can also be a non-volatile memory, such as a read-only memory, a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); or the memory 102 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 102 can be a combination of the above memories. Part of the program instructions of the multi-link security protection method provided by the embodiments of the present application can be stored in the memory 102. When these program instructions are executed by the processor 101, they can be used to implement the steps of the multi-link security protection method provided by the embodiments of the present application, so as to solve the problem that the existing security protection technology cannot quickly and accurately detect and mitigate malicious attacks. The database 104 can be used to store data such as the collected data, mitigation strategies, preset anomaly detection models, and key features corresponding to each link involved in the solution provided by the embodiments of the present application.
[0059] In the embodiments of the present application, the multi-link security protection device 10 can obtain multi-link security protection instructions through the I / O interface 103. Then, the processor 101 of the multi-link security protection device 10 will quickly and accurately detect and mitigate malicious attacks according to the program instructions of the multi-link security protection method provided by the embodiments of the present application in the memory 102. In addition, data such as the collected data, mitigation strategies, preset anomaly detection models, and key features corresponding to each link can be stored in the database 104.
[0060] As Figure 2 shown, it is a schematic diagram of the overall architecture of the multi-link security protection system provided by the embodiments of the present application. Among them, the multi-link security protection system is composed of a terminal device, an AP cluster, and a central management platform.
[0061] Specifically, a multi-link data collection module, a collaborative detection module, a dynamic link switching module, a mitigation strategy module, an encrypted management frame authentication module, and a cross-link recording module are provided in the terminal device.
[0062] There are multiple access points (APs) in the AP cluster. Each AP is a basic device in the WiFi network and is used to provide wireless network connections. During use, the AP allows multiple terminal devices to access the WiFi network through itself to achieve communication between devices and access to the network.
[0063] The central management platform can be used for cross-link security situation analysis and security protection strategy management.
[0064] Furthermore, in the actual application process, the terminal device will communicate on multiple frequency bands such as 2.4 GHz, 5 GHz, and 6 GHz simultaneously through the AP cluster. Therefore, when performing multi-link security protection, first, the terminal device can collect multi-link data and detect malicious APs for the AP cluster through the multi-link data collection module and the collaborative detection module.
[0065] Then, for any link, if it is determined that there is an abnormality in the any link, the terminal device can use the dynamic link switching module to perform dynamic link switching, or trigger a mitigation strategy using the mitigation strategy module, and at the same time report a warning message to the central management platform to achieve joint protection within the region.
[0066] Next, in order to prevent malicious APs from bypassing authentication using encrypted management frames, in this application, for the encrypted management frames after MLO-MFP encryption, the terminal device can also use the encrypted management frame authentication module to perform real-time decryption of the encrypted management frames using dynamic key negotiation or the Public Key Infrastructure (PKI) mechanism. Based on this, the terminal device can also perform cross-link collaborative authentication through this encrypted management frame authentication module. That is, it is possible to use the authentication data and dynamic feature comparison between devices to detect and respond to abnormal management frames (such as forged and tampered frames), thereby preventing malicious APs from bypassing authentication using encrypted management frames.
[0067] Finally, in order to assist in optimizing subsequent detection algorithms and improving dynamic defense strategies, in this application, the terminal device can record the detection data and abnormal events of each link in the unified security log system of the central management platform through the cross-link recording module to form a cross-link security situation map. Of course, the AP cluster can also send some of its own data to the central management platform for recording. To use historical data to track and model malicious APs to assist in optimizing subsequent detection algorithms and improving dynamic defense strategies.
[0068] Of course, the method provided in the embodiments of this application is not limited to Figure 1In the application scenarios shown, it can also be used in other possible application scenarios, which are not limited in the embodiments of this application. For Figure 1 The functions that can be achieved by each device in the application scenarios shown will be described together in the subsequent method embodiments, and will not be elaborated here for the time being. Next, the method of the embodiments of this application will be introduced with reference to the accompanying drawings.
[0069] As Figure 3 shown, it is a schematic diagram of a multi-link security protection method provided by an embodiment of this application. This method can be executed by the multi-link security protection device 10 in Figure 1 . Specifically, the process of this method is introduced as follows.
[0070] Step 301: Use a multi-link data acquisition module to acquire data and obtain the acquired data corresponding to each link.
[0071] In the embodiments of this application, the acquired data includes management frames, beacon frames, and control frames.
[0072] Specifically, a multi-link data acquisition module can be configured in the terminal device; then, as Figure 4 shown, it is a schematic diagram of multi-link data acquisition and collaborative detection provided by an embodiment of this application. A multi-link data acquisition module can be used to synchronously acquire data from the 2.4 GHz, 5 GHz, and 6 GHz band links respectively to obtain the management frames, beacon frames, and control frames corresponding to the 2.4 GHz, 5 GHz, and 6 GHz band links; among them, each frame is attached with a timestamp T i , signal strength S i , link status L i and the multi-link operation - management frame protection MLO - MFP field M i .
[0073] In the embodiments of this application, a smart spectrum sensing module can also be used to introduce cognitive radio technology for dynamic spectrum allocation. Among them, the spectrum occupancy detection formula is as follows:
[0074]
[0075] Among them, I occupied (f,t) is the spectrum occupancy indication function (take 1 when the signal strength exceeds -80 dBm, otherwise 0).
[0076] In addition, in the embodiments of this application, an adaptive sampling mechanism can also be used to dynamically adjust the sampling period:
[0077]
[0078] In the case of burst traffic, doubling of the sampling frequency is supported.
[0079] In the embodiments of the present application, when performing multi-link data acquisition, cross-link timestamp synchronization can also be performed. Specifically, the cross-link time deviation Δt ij can be compensated based on the following two methods:
[0080] ① Compensate using the improved two-way delay of IEEE 1588. The compensation formula is as follows:
[0081]
[0082] where T 1 and T 4 are the local transmission and reception timestamps, T 2 and T 3 are the peer timestamps, and δ ij is the propagation delay compensation value between links, which can be averaged by a sliding window.
[0083] ② Compensate using the quantum clock synchronization mechanism:
[0084] That is, a hybrid NTP-PTP architecture can be used to introduce quantum key distribution. The compensation formula is as follows:
[0085] Δt corr = 2τ master - τ slave + cδ prop × Q factor
[0086] where Q factor is the quantum calibration coefficient to further improve the time synchronization accuracy (target range 10 ns to 100 ns).
[0087] Step 302: Use a collaborative detection module to detect malicious access points (APs) for the collected data corresponding to each link, and determine whether there are any abnormalities in each link.
[0088] In the embodiments of the present application, abnormalities include cross-link forgery (for example, in beacon frames of the same AP on different links, the SSID field, BSSID field, or MLo-MFP field is inconsistent, etc.) and abnormal management frames.
[0089] Specifically, as Figure 4 shown, after obtaining the data of each link, data fusion and feature extraction can be performed. That is, first, a preset data fusion algorithm can be used to fuse the management frames, beacon frames, and control frames corresponding to each link to obtain the fused multi-link data. The data fusion process is as follows:
[0090] (1) First, perform feature extraction to convert the data of each link into feature vectors:
[0091]
[0092] Among them, T i is the timestamp of the i-th link, S i is the signal strength of the i-th link, L i is the link state of the i-th link, M i is the MLO-MFP field of the i-th link.
[0093] (2) The following three methods can be used for weighted fusion.
[0094] ① Use weighted average for weighted fusion:
[0095]
[0096] ② Use weighted Kalman filter for weighted fusion:
[0097] State equation:
[0098] x k = Ax k-1 + w k-1
[0099] Observation equation:
[0100]
[0101] The weights are based on the signal-to-noise ratio (SNR i ) of each link:
[0102]
[0103] Fusion output:
[0104]
[0105] ③ Use the federated learning mechanism for weighted fusion:
[0106] Each link updates the model parameters locally:
[0107]
[0108] Global model aggregation:
[0109]
[0110] Among them, D i is the data volume of the i-th link, ensuring that the multi-modal data fusion model is updated consistently among different links.
[0111] Then, anomaly detection (e.g., abnormal behavior recognition and malicious AP detection) can be performed. That is, based on a preset threshold and a preset anomaly detection model, collaborative analysis can be carried out on the fused multi-link data to determine whether there are anomalies in each link. Among them, the preset anomaly detection model consists of a random forest model and an anomaly scoring model. As Figure 5 shown, it is a schematic diagram of link state conversion provided by an embodiment of the present application. That is, in the embodiment of the present application, based on the preset anomaly detection model, the following random forest model can be first used to classify the fused multi-link data (fused feature vector F) to obtain an anomaly probability:
[0112]
[0113] Among them, in order to ensure the correctness of the anomaly probability, a support vector machine (SVM) model can be used here for secondary verification. Specifically, when P abnormal is in the fuzzy interval (e.g., 0.4 - 0.6), the SVM model can be used for verification, and its decision function is as follows:
[0114] f(F) = sign(w T F + b)
[0115] Then, the following anomaly scoring model can be used to obtain an anomaly score in combination with the cross-link time deviation Δt ij .
[0116] Score = α·P abnormal + β·Δt ij , (α + β = 1)
[0117] Furthermore, when Score exceeds the preset threshold (e.g., 0.8), it is determined as a cross-link forgery attack; or when the cross-link MLO-MFP hash check finds that at least two links are inconsistent (calculating the Hamming distance D H > 0), it is determined as a cross-link forgery attack.
[0118] Step 303: For any link, if it is determined that there is an anomaly in any link, the dynamic link switching module is used for dynamic link switching, or the mitigation strategy module is used to trigger a mitigation strategy.
[0119] Specifically, as Figure 4As shown in the figure, for any link, if it is determined that any link is abnormal, the dynamic link switching module can be used to automatically switch the terminal device from the abnormal link to the secure link according to the preset policy, or the mitigation policy module can be used to pause the connection to the abnormal link, or the mitigation policy module can be used to jointly broadcast forged beacon frames with adjacent APs, or send a dynamic key update instruction to force the malicious AP to lose control. At the same time, warning information can also be reported to the central management platform to achieve joint protection within the area. On the contrary, if it is determined that each link is normal, communication continues. That is to say, in this application, dynamic link switching and other measures can be automatically triggered according to the detection results to ensure high security while the terminal device seamlessly switches between different frequency bands.
[0120] In the embodiment of this application, the switching priority formula is as follows:
[0121]
[0122] where BER i is the bit error rate of the i-th link, and D H is the Hamming distance of the cross-link MLO-MFP field, and D max is the maximum theoretical value. The link with a higher priority is the secure link, and the system automatically switches or executes the mitigation policy.
[0123] Step 304: Use the encrypted management frame authentication module to receive the encrypted MLO-MFP management frame and decrypt the encrypted MLO-MFP management frame to obtain the decrypted MLO-MFP management frame.
[0124] To prevent malicious APs from bypassing authentication using encrypted management frames, in the embodiment of this application, after anomaly detection and response, encrypted management frame parsing and dynamic authentication can also be performed, as Figure 6 shown, which is a schematic diagram of encrypted management frame parsing and dynamic authentication provided by the embodiment of this application.
[0125] Specifically, first, the encrypted management frame authentication module can be used to receive the encrypted MLO-MFP management frame.
[0126] Then, dynamic key negotiation can be performed on the encrypted MLO-MFP management frame according to the dynamic key to obtain the decrypted MLO-MFP management frame; among them, when it is detected that the cross-link MLO-MFP fields are inconsistent (D H >0), dynamic key update is triggered. In the embodiment of this application, the process of performing dynamic key negotiation on the encrypted MLO-MFP management frame according to the dynamic key is as follows:
[0127] (1) The key parameters (such as random numbers, device unique identifiers, etc.) can be configured according to the request initiated by the terminal device.
[0128] (2) The following Diffie-Hellman algorithm can be adopted to negotiate and generate the dynamic key K:
[0129] K = g ab mod p
[0130] (3) The dynamic key K is distributed to both communication parties (such as the terminal device and the AP) through a secure channel, so as to use the dynamic key K to decrypt the encrypted MLO-MFP management frame and verify the integrity.
[0131] Alternatively, the encrypted MLO-MFP management frame can be decrypted according to the public key infrastructure PKI mechanism to obtain the decrypted MLO-MFP management frame. In the embodiments of the present application, the process of decrypting the encrypted MLO-MFP management frame based on the PKI mechanism is as follows:
[0132] (1) Obtain certificate and private key secure storage: The receiving party obtains the certificate issued by the trusted CA, where the certificate contains the public key and identity information; store the private key required for decryption in a secure module (such as a hardware security module HSM or a trusted execution environment TEE) to ensure that unauthorized access cannot obtain it.
[0133] (2) Verify the sender's certificate and extract the public key: Check whether the certificate chain is issued by the trusted CA, and confirm that the certificate has not been revoked through the CRL (Certificate Revocation List) or OCSP (Online Certificate Status Protocol); extract the public key from the sender's certificate for subsequent key negotiation or data decryption.
[0134] (3) Perform key negotiation and data decryption: If the hybrid encryption mode is adopted (encryption process: the sender encrypts the symmetric key (such as the AES key) using the receiver's public key and attaches the encrypted symmetric key to the MLO-MFP management frame), then during decryption, the receiver can decrypt the symmetric key using the private key and then use the symmetric key to decrypt the encrypted MLO-MFP management frame; if direct asymmetric decryption is adopted, then during decryption, the receiver can directly decrypt the encrypted MLO-MFP management frame using the private key.
[0135] (4) Data integrity verification: HMAC or SHA series algorithms can be used to verify the integrity of the decrypted MLO-MFP management frame.
[0136] Step 305: Use the encrypted management frame authentication module to perform integrity verification on the decrypted MLO-MFP management frame to determine whether the verification passes.
[0137] In an embodiment of the present application, as Figure 6 shown, the verification may include MLO-MFP field verification, cross-link data comparison, and timestamp verification.
[0138] Step 306: If it is determined that the verification fails, trigger an exception response mechanism.
[0139] In an embodiment of the present application, the exception response mechanism may be the following three-level defense trigger mechanism (dynamic defense method):
[0140] Level 1: When Score ∈ [0.6, 0.8), perform link speed reduction;
[0141] Level 2: When Score ∈ [0.8, 0.9), trigger forced re-authentication;
[0142] Level 3: When Score ≥ 0.9, perform physical layer isolation (directly disconnect the connection).
[0143] Conversely, if it is determined that the verification passes, continue the communication.
[0144] In an embodiment of the present application, a dynamic defense decision module may be adopted to perform dynamic defense, and the decision tree node conditions satisfy the following formula:
[0145]
[0146] In a possible implementation manner, in order to further improve the overall network security, in an embodiment of the present application, after the exception response mechanism is triggered, a cross-link recording module may also be adopted to record the detection data and exception events of each link in a unified security log system, and form a cross-link security situation map. Therefore, in the present application, a multi-link security log recording and tracking mechanism can be designed to converge the detection data from each frequency band, so as to realize the tracking and modeling of the historical behavior of malicious APs, and assist in the optimization of subsequent detection algorithms and the improvement of dynamic defense strategies.
[0147] In a possible implementation manner, the defense strategy may include physical layer fingerprint authentication and dynamic confusion defense.
[0148] ① Physical layer fingerprint authentication: The radio frequency fingerprint features can be extracted through the following formula.
[0149]
[0150] Among them, W taper is the Kaiser window function. Furthermore, the device identity can be identified by extracting radio frequency features.
[0151] ② Dynamic deception defense: The virtual link features can be generated through the following formula.
[0152]
[0153] In a possible implementation, blockchain auditing can also be performed. Specifically, the tamper-proof security log can be constructed through the following formula.
[0154]
[0155] In a possible implementation, the RF front-end of the multi-link security protection system can include a reconfigurable filter bank, and its transfer function is as follows:
[0156]
[0157] where f n is the center frequency, B n is the instantaneous bandwidth, and τ n is the delay compensation. Specific Example 1:
[0159] Implement this technical solution on the terminal device side. The specific process is as follows:
[0160] Step 1: Use the multi-link data acquisition module built in the terminal device to collect multi-link data.
[0161] That is, the management frames, beacon frames, and control frames can be collected on the 2.4 GHz, 5 GHz, and 6 GHz band links through the multi-link data acquisition module built in the terminal device. Each frame collected comes with a timestamp, signal strength, link status, and MLO-MFP field.
[0162] Step 2: Use the collaborative detection module built in the terminal device to perform collaborative detection on the collected management frames, beacon frames, and control frames.
[0163] That is, through the collaborative detection module built in the terminal device, the collected data such as management frames, beacon frames, and control frames from each link can be compared in real time, and collaborative detection can be performed through a preset threshold and a preset anomaly detection model to determine whether there are cross-link forgeries or abnormal management frames.
[0164] Step 3: For any link, if it is determined that there is an anomaly in the any link, use the dynamic link switching module built in the terminal device to perform dynamic link switching, or use the mitigation strategy module built in the terminal device to trigger a mitigation strategy.
[0165] That is, if abnormal behavior is detected in a certain link, the data of other links can be verified to determine whether there are abnormalities (malicious AP behavior) in other links. If an abnormality is detected, the built-in dynamic link switching module in the terminal device can be used to select a secure link for communication. And when necessary, a request can be sent, and the built-in mitigation strategy module in the terminal device can be used to suspend the connection to the abnormal link, or the mitigation strategy module can be used to jointly broadcast forged beacon frames with adjacent APs, or send dynamic key update instructions to force the malicious AP to lose control. At the same time, warning information can also be reported to the central management platform to achieve joint protection within the region.
[0166] Step 4: Use the built-in encryption management frame authentication module in the terminal device to decrypt and parse the encrypted management frame.
[0167] That is, for the encrypted MLO-MFP management frame, the built-in encryption management frame authentication module in the terminal device can use the dynamic key negotiation or public key infrastructure (PKI) mechanism to decrypt the encrypted management frame in real time and perform cross-link collaborative authentication. That is, integrity verification (MLO-MFP field verification, cross-link data comparison, and timestamp verification) can be performed on the decrypted MLO-MFP management frame. If an abnormality is found, a three-level defense trigger mechanism is triggered. Specific Embodiment 2:
[0169] The AP cluster and the central management platform carry out a collaborative protection plan.
[0170] Step 1: Share data across APs.
[0171] That is, each AP can upload the collected management frame and security event data to the central management platform through the internal private network to form a global security situation.
[0172] Step 2: The central management platform conducts joint detection and policy update.
[0173] The central management platform can comprehensively analyze the data from each AP, use big data analysis and historical models to track malicious APs, and issue global policy updates according to the analysis results, and adjust the channel configuration, authentication parameters, and key update frequency of each AP.
[0174] Step 3: The central management platform conducts collaborative defense response.
[0175] When malicious AP behavior across links is detected, the central management platform can coordinate nearby APs to synchronously implement measures such as dynamic link switching, broadcasting collaborative pseudo beacon frames, and temporarily blocking suspicious channels to form a regional joint defense. Specific Embodiment 3:
[0177] If the terminal device detects an anomaly on the 5GHz link (the random forest outputs P abnormal = 0.85 and the SVM verifies it as an anomaly), then the system can automatically switch to the 6GHz link according to the priority formula, and at the same time trigger dynamic key negotiation to generate a new key K = g ab mod p, and complete the verification of the MLO-MFP field (the Hamming distance D H = 3). Specific Embodiment 4:
[0179] In the case of burst traffic, through the adaptive sampling mechanism, the sampling period is dynamically adjusted to (not exceeding T max ) to ensure data timeliness and accuracy.
[0180] Table 1 Comparison Table of Experimental Data
[0181]
[0182]
[0183] According to Table 1 above, for attacks such as cross-link MLO-MFP forgery, quantum computing brute force cracking, and AI generative attacks, compared with the traditional scheme, this scheme obviously has a higher detection rate.
[0184] Reliability Verification: The Monte Carlo simulation display system is used for verification. Furthermore, it can be seen from the following formula that the Mean Time between Failures (MTBF) has been significantly improved. Therefore, the stability of the multi-link security protection system has been significantly enhanced.
[0185]
[0186] In summary, compared with the prior art, this application has the following advantages:
[0187] (1) Through multi-link collaborative detection, the limitation of single-link detection can be effectively broken through, and the forgery behavior of malicious APs can be jointly identified in multiple frequency bands, thereby significantly improving the detection efficiency and accuracy.
[0188] (2) Through dynamic link switching and mitigation, when an attack is detected, the terminal link resources can be dynamically adjusted in real time to ensure that the communication is not interrupted and the security is guaranteed.
[0189] (3) Through real-time decryption of encrypted management frames, dynamic key negotiation and cross-link authentication can be carried out, thereby realizing real-time parsing and anomaly detection of encrypted management frames to prevent malicious APs from using the encryption mechanism to evade detection.
[0190] (4) Through data sharing, joint response, collaborative defense, and centralized management of the AP cluster and the central management platform, not only is regional and global malicious AP protection achieved, but also the overall network security is improved.
[0191] (5) The present invention is applicable to enterprises, public places, and scenarios with high security requirements in the WiFi 7 environment. Therefore, it has high applicability, practical value, and promotion prospects.
[0192] Based on the same inventive concept, an embodiment of the present application provides a multi-link security protection device 70, as Figure 7 shown. The multi-link security protection device 70 includes:
[0193] A data acquisition unit 701, configured to acquire data by using a multi-link data acquisition module to obtain acquisition data corresponding to each link; wherein, the acquisition data includes management frames, beacon frames, and control frames;
[0194] An anomaly detection unit 702, configured to detect malicious access points AP for the acquisition data corresponding to each link by using a collaborative detection module to determine whether there is an anomaly in each link; wherein, the anomaly includes cross-link forgery and abnormal management frames;
[0195] A link switching and mitigation unit 703, configured to, for any one link, if it is determined that there is an anomaly in any one link, perform dynamic link switching by using a dynamic link switching module, or trigger a mitigation strategy by using a mitigation strategy module;
[0196] An encrypted management frame authentication unit 704, configured to receive an encrypted MLO-MFP management frame by using an encrypted management frame authentication module and decrypt the encrypted MLO-MFP management frame to obtain a decrypted MLO-MFP management frame;
[0197] The encrypted management frame authentication unit 704 is further configured to perform integrity verification on the decrypted MLO-MFP management frame by using an encrypted management frame authentication module to determine whether the verification passes; wherein, the verification includes MLO-MFP field verification, cross-link data comparison, and timestamp verification;
[0198] The encrypted management frame authentication unit 704 is further configured to trigger an anomaly response mechanism if it is determined that the verification fails.
[0199] Optionally, the data acquisition unit 701 is further configured to:
[0200] Configure a multi-link data acquisition module in the terminal device;
[0201] Adopt a multi-link data acquisition module to collect data from the 2.4GHz, 5GHz, and 6GHz frequency band links respectively, and obtain the management frames, beacon frames, and control frames corresponding to each link; among them, each frame is attached with a timestamp, signal strength, link status, and multi-link operation - management frame protection MLO - MFP field.
[0202] Optionally, the anomaly detection unit 702 is further configured to:
[0203] Adopt a preset data fusion algorithm to perform data fusion on the management frames, beacon frames, and control frames corresponding to each link, and obtain the fused multi-link data;
[0204] According to a preset threshold and a preset anomaly detection model, perform collaborative analysis on the fused multi-link data to determine whether there are anomalies in each link; among them, the preset anomaly detection model consists of a random forest model and an anomaly scoring model.
[0205] Optionally, the anomaly detection unit 702 is further configured to:
[0206] Adopt the random forest model in the preset anomaly detection model to process the fused multi-link data to obtain an anomaly probability;
[0207] Adopt the anomaly scoring model in the preset anomaly detection model to process the anomaly probability to obtain an anomaly score;
[0208] Determine whether there are anomalies in each link according to the preset threshold and the anomaly score.
[0209] Optionally, the link switching and mitigation unit 703 is further configured to:
[0210] If it is determined that any link has an anomaly, then use the dynamic link switching module to automatically switch the terminal device to a secure link, or, use the mitigation strategy module to suspend connecting to the abnormal link, or, use the mitigation strategy module to jointly broadcast forged beacon frames with the AP.
[0211] Optionally, the multi-link security protection device 70 further includes an encrypted management frame authentication unit 704, which is used for:
[0212] Adopt an encrypted management frame authentication module to receive the encrypted MLO - MFP management frame;
[0213] According to the dynamic key, perform dynamic key negotiation on the encrypted MLO - MFP management frame to obtain the decrypted MLO - MFP management frame; or,
[0214] According to the public key infrastructure PKI mechanism, decrypt the encrypted MLO - MFP management frame to obtain the decrypted MLO - MFP management frame.
[0215] Optionally, the multi-link security protection device 70 further includes a cross-link recording unit 705, which is configured to:
[0216] Adopt a cross-link recording module to record the detection data and abnormal events of each link in a unified security log system, and form a cross-link security situation map.
[0217] The multi-link security protection device 70 can be used to execute Figures 3 - 6 the method executed in the embodiments shown, and therefore, for the functions that can be achieved by each functional module of the multi-link security protection device 70, reference can be made to Figures 3 - 6 the description of the embodiments shown, which will not be elaborated here.
[0218] In some possible implementation manners, various aspects of the method provided in this application can also be implemented in the form of a program part, which includes program code. When the program part runs on a computer device, the program code is used to cause the computer device to execute the steps in the method according to various exemplary embodiments of this application described above. For example, the computer device can execute the method executed in the embodiments shown in Figures 3 - 6 the embodiments shown.
[0219] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above method embodiments can be completed by hardware related to program instructions. The foregoing program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps including the above method embodiments; and the foregoing storage medium includes: removable storage devices, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disks or optical disks and other various media that can store program code. Alternatively, if the above integrated unit is implemented in the form of a software functional module and sold or used as an independent part, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software part. This computer software part is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the methods described in various embodiments of the present invention. And the foregoing storage medium includes: removable storage devices, ROM, RAM, magnetic disks or optical disks and other various media that can store program code.
[0220] Although the preferred embodiments of the present application have been described, additional changes and modifications can be made to these embodiments by those skilled in the art once they learn of the basic creative concept. Therefore, the appended claims are intended to be interpreted to include the preferred embodiments as well as all changes and modifications that fall within the scope of the present application.
[0221] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalent technologies, the present application is also intended to include these modifications and variations.
Claims
1. A multi-link security protection method, characterized in that: The method comprises: A multi-link data acquisition module is used to collect data to obtain the collected data corresponding to each link; wherein the collected data includes management frames, beacon frames and control frames; Using a collaborative detection module to detect malicious access points AP on the collected data corresponding to each link to determine whether each link has an abnormality; wherein the abnormality includes cross-link forgery and abnormal management frames; For any link, if it is determined that any link is abnormal, a dynamic link switching module is used to perform dynamic link switching, or a mitigation strategy module is used to trigger a mitigation strategy; Using an encrypted management frame authentication module, receiving the encrypted MLO-MFP management frame, and decrypting the encrypted MLO-MFP management frame to obtain a decrypted MLO-MFP management frame; Using the encrypted management frame authentication module, perform integrity check on the decrypted MLO-MFP management frame to determine whether the check passes; wherein the check includes MLO-MFP field check, cross-link data comparison and timestamp check; If it is determined that the verification fails, the exception response mechanism is triggered.
2. The method according to claim 1, characterized in that The step of using a multi-link data acquisition module to collect data and obtain the collected data corresponding to each link includes: Configure a multi-link data acquisition module in the terminal device; The multi-link data acquisition module is used to collect data from the 2.4GHz, 5GHz and 6GHz frequency band links respectively to obtain the management frames, beacon frames and control frames corresponding to each link; wherein each frame is accompanied by a timestamp, signal strength, link status and multi-link operation-management frame protection MLO-MFP field.
3. The method according to claim 1, characterized in that The step of using the collaborative detection module to detect malicious access points APs on the collected data corresponding to each link to determine whether each link is abnormal includes: Using a preset data fusion algorithm to perform data fusion on the management frames, beacon frames and control frames corresponding to each link to obtain fused multi-link data; According to a preset threshold and a preset anomaly detection model, the fused multi-link data is collaboratively analyzed to determine whether there is an anomaly in each link; wherein the preset anomaly detection model consists of a random forest model and an anomaly scoring model.
4. The method according to claim 3, characterized in that The step of collaboratively analyzing the fused multi-link data according to a preset threshold and a preset anomaly detection model to determine whether each link has an anomaly includes: The fused multi-link data is processed using a random forest model in the preset anomaly detection model to obtain anomaly probability; Using an anomaly scoring model in the preset anomaly detection model to process the anomaly probability to obtain an anomaly score; According to the preset threshold and the abnormality score, it is determined whether each link has an abnormality.
5. The method according to claim 1, characterized in that If it is determined that any of the links is abnormal, the step of using a dynamic link switching module to perform dynamic link switching, or using a mitigation strategy module to trigger a mitigation strategy, includes: If it is determined that any of the links is abnormal, the dynamic link switching module is used to automatically switch the terminal device to a secure link, or the mitigation strategy module is used to suspend the connection to the abnormal link, or the mitigation strategy module is used to jointly broadcast a forged beacon frame with the AP.
6. The method according to claim 1, characterized in that The step of using an encrypted management frame authentication module to receive an encrypted MLO-MFP management frame, and decrypting the encrypted MLO-MFP management frame to obtain a decrypted MLO-MFP management frame includes: Adopt the encrypted management frame authentication module to receive the encrypted MLO-MFP management frame; According to the dynamic key, dynamic key negotiation is performed on the encrypted MLO-MFP management frame to obtain a decrypted MLO-MFP management frame; or, According to a public key infrastructure (PKI) mechanism, the encrypted MLO-MFP management frame is decrypted to obtain a decrypted MLO-MFP management frame.
7. The method according to claim 1, characterized in that After triggering the abnormal response mechanism, the method further includes: A cross-link recording module is used to record the detection data and abnormal events of each link in a unified security log system, and form a cross-link security situation map.
8. A multi-link safety protection device, characterized in that: The device comprises: A data acquisition unit, used to acquire data using a multi-link data acquisition module to obtain acquisition data corresponding to each link; wherein the acquisition data includes management frames, beacon frames and control frames; An abnormality detection unit, used to use the collaborative detection module to perform malicious access point AP detection on the collected data corresponding to each link to determine whether each link has an abnormality; wherein the abnormality includes cross-link forgery and abnormal management frames; A link switching and mitigation unit, configured to, for any link, if it is determined that any link is abnormal, use a dynamic link switching module to perform dynamic link switching, or use a mitigation strategy module to trigger a mitigation strategy; An encrypted management frame authentication unit, configured to receive an encrypted MLO-MFP management frame using an encrypted management frame authentication module, and decrypt the encrypted MLO-MFP management frame to obtain a decrypted MLO-MFP management frame; The encrypted management frame authentication unit is further used to use the encrypted management frame authentication module to perform integrity check on the decrypted MLO-MFP management frame to determine whether the check passes; wherein the check includes MLO-MFP field check, cross-link data comparison and timestamp check; The encryption management frame authentication unit is also used to trigger an abnormal response mechanism if it is determined that the verification fails.
9. An electronic device, characterized in that: The device comprises: A memory for storing program instructions; A processor is used to call the program instructions stored in the memory, and execute any method according to claims 1-7 according to the obtained program instructions.
10. A storage medium, characterized in that: The storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable a computer to execute any one of the methods of claims 1-7.