Network access method and device, electronic equipment and medium

By using dynamic MAC address mode interactive packets in wireless LANs, the problem that dynamic MAC address terminal devices cannot perform strict access control is solved, and the effect of automatic access and simplified operation and maintenance is achieved.

CN120151835APending Publication Date: 2025-06-13NEW H3C TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510397521.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

In wireless LANs that require strict access control, terminal devices using dynamic MAC addresses cannot obtain their corresponding MAC addresses in advance, resulting in MAC address authentication or whitelist control, which is cumbersome and has high maintenance costs.

Method used

By sending and receiving access interactive messages between the access point and the terminal device, the terminal device determines the target MAC address according to the dynamic MAC address pattern advertised by the access point and returns it to the access point for verification, allowing access to the network if it matches.

Benefits of technology

It realizes that the terminal equipment automatically adapts to the network side requirements, simplifies the access control process, reduces operation and maintenance costs, and avoids the tedious operation of manually turning off the dynamic MAC address function.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120151835A_ABST
    Figure CN120151835A_ABST
Patent Text Reader

Abstract

The invention provides a network access method and device, electronic equipment and a medium. The method comprises the following steps: sending a first access interaction message to terminal equipment, wherein the first access interaction message comprises a dynamic MAC address mode; receiving a second access interaction message sent by the terminal equipment, wherein the second access interaction message comprises the target MAC address; checking whether the target MAC address is matched with the dynamic MAC address mode or not; and if the target MAC address is matched with the dynamic MAC address mode, allowing the terminal device to access the network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This specification relates to the field of communication technologies, and in particular, to methods, devices, electronic devices, and media for accessing a network. Background Art

[0002] With the wide use of WLAN (Wireless LAN), users have higher requirements for the privacy of sensitive data such as their Internet usage behavior and activity trajectories in the network, and do not want such data to be easily tracked and recorded. Since the MAC address of a device is generally unique, it is easy to be recorded and used as an identifier to identify the user and reflect the user's behavior. In response to this scenario, wireless terminal manufacturers or operating systems will use dynamic MAC (Medium Access Control) addresses to access the network for data communication to enhance their privacy.

[0003] When there are scenarios in the network that require strict access control, for terminal devices using dynamic MAC addresses, AP or AC network-side devices cannot obtain their corresponding MAC addresses in advance to perform access control through MAC address authentication or whitelist. It is necessary to manually turn off the dynamic MAC address function of each terminal device one by one, which is cumbersome to operate and has a high network maintenance cost. Summary of the Invention

[0004] To overcome the problems existing in the related art, this specification provides methods, devices, electronic devices, and media for accessing a network.

[0005] According to the first aspect of the embodiments of this specification, a method for accessing a network is provided, which is applied to an access point. The method includes: sending a first access interaction message to a terminal device, where the first access interaction message includes a dynamic MAC address mode; receiving a second access interaction message sent by the terminal device, where the second access interaction message includes a target MAC address; verifying whether the target MAC address matches the dynamic MAC address mode; if the target MAC address matches the dynamic MAC address mode, then allow the terminal device to access the network.

[0006] According to the second aspect of the embodiments of this specification, a method for accessing a network is provided, which is applied to a terminal device. The method includes: receiving a first access interaction message sent by an access point, where the first access interaction message includes a dynamic MAC address mode; determining a target MAC address according to the dynamic MAC address mode; sending a second access interaction message to the access point, where the second access interaction message includes the target MAC address.

[0007] According to the third aspect of the embodiments of this specification, an apparatus for accessing a network is provided, including:

[0008] A first sending module, configured to send a first access interaction message to a terminal device, where the first access interaction message includes a dynamic MAC address mode;

[0009] A first receiving module, configured to receive a second access interaction message sent by the terminal device, where the second access interaction message includes a target MAC address;

[0010] A verification module, configured to verify whether the target MAC address matches the dynamic MAC address mode;

[0011] An access module, configured to allow the terminal device to access the network if the target MAC address matches the dynamic MAC address mode.

[0012] According to a fourth aspect of the embodiments of the present specification, there is provided a device for accessing a network, including:

[0013] A second receiving module, configured to receive a first access interaction message sent by an access point, where the first access interaction message includes a dynamic MAC address mode;

[0014] A determination module, configured to determine a target MAC address according to the dynamic MAC address mode;

[0015] A second sending module, configured to send a second access interaction message to the access point, where the second access interaction message includes the target MAC address.

[0016] According to a fifth aspect of the embodiments of the present specification, there is provided an electronic device, including:

[0017] A processor;

[0018] A memory for storing executable instructions of the processor;

[0019] Wherein, the processor is configured to execute the method for accessing a network according to the first aspect, the second aspect or any corresponding embodiment thereof.

[0020] According to a sixth aspect of the embodiments of the present specification, there is provided a computer-readable storage medium, on which computer instructions are stored, and the computer instructions are used to cause a computer to execute the method for accessing a network according to the first aspect, the second aspect or any corresponding embodiment thereof.

[0021] The technical solutions provided by the embodiments of the present specification may include the following beneficial effects:

[0022] In the embodiments of this specification, when the AP announces the MAC address mode that can be used to access the network through the first access interaction message, the terminal device can use the corresponding MAC address to access the network according to the dynamic MAC address mode announced by the AP. Thus, the terminal device can automatically meet the requirements of the network side and jointly perform access control with the network side, without manually turning off the dynamic MAC address function of the terminal device one by one, simplifying the operation difficulty and reducing the operation and maintenance cost.

[0023] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit this specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with this specification, and are used together with the specification to explain the principles of this specification.

[0025] Figure 1 It is a schematic diagram of the system architecture shown according to an exemplary embodiment of this specification.

[0026] Figure 2 It is a flowchart of a method for accessing a network shown according to an exemplary embodiment of this specification.

[0027] Figure 3 It is a schematic diagram of the format of a dynamic MAC address capability element shown according to an exemplary embodiment.

[0028] Figure 4 It is a hardware structure diagram of the computer device where the device for accessing the network in the embodiments of this specification is located.

[0029] Figure 5 It is a block diagram of a device for accessing a network shown according to an exemplary embodiment of this specification.

[0030] Figure 6 It is a block diagram of another device for accessing a network shown according to an exemplary embodiment of this specification. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0031] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this specification. On the contrary, they are only examples of devices and methods consistent with some aspects of this specification as detailed in the appended claims.

[0032] The terms used in this specification are for the purpose of describing particular embodiments only and are not intended to limit this specification. The singular forms "a", "the", and "said" used in this specification and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0033] It should be understood that although the terms first, second, third, etc. may be used in this specification to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from each other. For example, without departing from the scope of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining".

[0034] Next, the embodiments of this specification will be described in detail.

[0035] The following Figure 1 describes the system architecture of the method and apparatus for accessing the network that can be applied to the embodiments of this specification. It should be noted that Figure 1 The illustration is only an example of the system architecture to which the embodiments of this specification can be applied to help those skilled in the art understand the technical content of this specification, but it does not mean that the embodiments of this specification cannot be used in other devices, systems, environments or scenarios.

[0036] Figure 1 is a schematic diagram of the system architecture shown according to an exemplary embodiment of this specification.

[0037] As Figure 1 shown, the system architecture may include, for example, a terminal device and an access point (AP).

[0038] The terminal device may be various electronic devices with wireless communication functions, including but not limited to smart phones, tablet computers, laptop portable computers, desktop computers, and the like.

[0039] The AP can be used to provide the bridging function of wireless users to the local area network and perform wireless-to-wired and wired-to-wireless frame conversion between the terminal device and the WLAN.

[0040] Next, the method for accessing the network provided by the embodiments of this specification will be described in detail. As Figure 2 shown, Figure 2The figure is a flowchart of a method for accessing a network according to an exemplary embodiment of this specification. The method for accessing a network provided by the embodiments of this specification may include the following steps.

[0041] In step 210, the AP sends a first access interaction message to the terminal device. The first access interaction message includes a dynamic MAC address mode.

[0042] According to an embodiment of this specification, the first access interaction message may include, for example, a Beacon frame or a Probe Response frame.

[0043] According to an embodiment of this specification, the dynamic MAC address mode can be used to indicate what MAC address mode the terminal device can use to access the network.

[0044] In step 220, the terminal device receives the first access interaction message sent by the access point.

[0045] In step 230, the terminal device determines a target MAC address according to the dynamic MAC address mode.

[0046] According to an embodiment of this specification, the terminal device can determine the MAC address used to access the network, that is, the target MAC address, according to the indication of the dynamic MAC address mode.

[0047] In step 240, the terminal device sends a second access interaction message to the access point. The second access interaction message includes the target MAC address.

[0048] According to an embodiment of this specification, the second access interaction message may include, for example, an Authentication Request frame, an Association Request frame, or a Re - association Request frame.

[0049] In step 250, the AP receives the second access interaction message sent by the terminal device.

[0050] In step 260, the AP verifies whether the target MAC address matches the dynamic MAC address mode.

[0051] In step 270, if the target MAC address matches the dynamic MAC address mode, the AP allows the terminal device to access the network.

[0052] According to the embodiments of this specification, when the AP announces the MAC address mode that can be used when accessing the network through the first access interaction message, the terminal device can use the corresponding MAC address to access the network according to the dynamic MAC address mode announced by the AP. Thus, the terminal device can automatically meet the requirements of the network side and jointly perform access control with the network side, without manually closing the dynamic MAC address function of the terminal device one by one, simplifying the operation difficulty and reducing the operation and maintenance cost.

[0053] According to the embodiments of this specification, the dynamic MAC address mode can be, for example, a closed mode, an optional mode, or a forced mode. Among them, the closed mode means that the terminal device is not allowed to access the network using the dynamic MAC address. The optional mode means that the terminal device is allowed to freely choose whether to use the dynamic MAC address. The forced mode means that only the terminal device is allowed to use the dynamic MAC address.

[0054] In the case where the dynamic MAC address mode is the closed mode, the AP can notify the terminal device through the first access interaction message that the current dynamic MAC address mode is the closed mode.

[0055] Optionally, the first access interaction message can carry a dynamic MAC address capability element. The dynamic MAC address mode and the dynamic MAC address survival duration can be located in the dynamic MAC address capability element.

[0056] Figure 3 It is a schematic diagram of the format of a dynamic MAC address capability element shown according to an exemplary embodiment.

[0057] As Figure 3As shown, the Dynamic MAC Address Capabilities Element may include fields such as Element ID (element identifier), Length, Element ID Extension, DMAC Mode (dynamic MAC address mode), and DMAC Life Time. Exemplarily, in this embodiment, Element ID may represent the element identifier, and the value of Element ID may be 255, for example. Element ID Extension may represent the element identifier extension, and the value of Element ID Extension may be 57, for example. Length may represent the length of the element content. DMAC Mode may represent the dynamic MAC address mode, and the values of DMAC Mode may include 1, 2, and 3, representing the off mode, optional mode, and forced mode, respectively. DMAC Life Time represents the dynamic MAC address lifetime, and when DMAC Mode is 2 or 3, the value of DMAC Life Time is valid. When the wireless terminal uses the local MAC address, DMAC Life Time can be used to change the MAC address regularly. The value range of DMAC Life Time may be 1 - 4294967295, for example.

[0058] Corresponding to the embodiments of the foregoing method, this specification also provides embodiments of a device for accessing a network and a terminal to which it is applied.

[0059] The embodiments of the device for accessing a network in this specification can be applied to computer devices, such as servers or terminal devices. The device embodiments can be implemented by software, or by hardware, or by a combination of software and hardware. Taking software implementation as an example, as a logically meaningful device, it is formed by the processor where it is located reading the corresponding computer program instructions in the non-volatile memory into the memory for operation. From the hardware level, as Figure 4 shown, it is a hardware structure diagram of a computer device where the device for accessing a network in the embodiments of this specification is located. In addition to Figure 4 the processor 410, memory 430, network interface 420, and non-volatile memory 440 shown, for the server or electronic device where the device 431 is located in the embodiments, usually according to the actual functions of this computer device, it may also include other hardware, which will not be elaborated here.

[0060] As Figure 5 shown, Figure 5 is a block diagram of a device for accessing a network shown in this specification according to an exemplary embodiment. The device includes:

[0061] A first sending module 510, configured to send a first access interaction message to a terminal device, where the first access interaction message includes a dynamic MAC address mode;

[0062] A first receiving module 520, configured to receive a second access interaction message sent by the terminal device, where the second access interaction message includes a target MAC address;

[0063] A verification module 530, configured to verify whether the target MAC address matches the dynamic MAC address mode;

[0064] An access module 540, configured to allow the terminal device to access the network if the target MAC address matches the dynamic MAC address mode.

[0065] Optionally, the first access interaction message may include a beacon frame or a probe response frame.

[0066] Optionally, the second access interaction message may include an authentication request frame, an association request frame, or a re-association request frame.

[0067] Optionally, the dynamic MAC address mode may be, for example, a closed mode, an optional mode, or a forced mode; the verification module may include:

[0068] A first verification sub-module, configured to, when the dynamic MAC address mode is the closed mode, verify whether the target MAC address conforms to the global MAC address format, and if the MAC address conforms to the global MAC address format, determine that the target MAC address matches the dynamic MAC address mode;

[0069] A second verification sub-module, configured to, when the dynamic MAC address mode is the optional mode, verify whether the target MAC address conforms to the global MAC address format or the local MAC address format, and if the target MAC address conforms to the global MAC address format or the local MAC address format, determine that the target MAC address matches the dynamic MAC address mode;

[0070] A third verification sub-module, configured to, when the dynamic MAC address mode is the forced mode, verify whether the target MAC address conforms to the local MAC address format, and if the target MAC address conforms to the local MAC address format, determine that the target MAC address matches the dynamic MAC address mode.

[0071] Optionally, the first access interaction message may further include: a dynamic MAC address lifetime.

[0072] Correspondingly, this specification also provides an electronic device, which includes a processor; a memory for storing instructions executable by the processor; wherein, the processor is configured to: send a first access interaction message to a terminal device, the first access interaction message including a dynamic MAC address mode; receive a second access interaction message sent by the terminal device, the second access interaction message including a target MAC address; verify whether the target MAC address matches the dynamic MAC address mode; if the target MAC address matches the dynamic MAC address mode, then allow the terminal device to access the network.

[0073] As Figure 6 shown, Figure 6 FIG. is a block diagram of another device for accessing a network according to an exemplary embodiment of this specification. The device includes:

[0074] A second receiving module 610, configured to receive a first access interaction message sent by an access point, the first access interaction message including a dynamic MAC address mode;

[0075] A determining module 620, configured to determine a target MAC address according to the dynamic MAC address mode;

[0076] A second sending module 630, configured to send a second access interaction message to the access point, the second access interaction message including the target MAC address.

[0077] Optionally, the first access interaction message may include a beacon frame or a probe response frame.

[0078] Optionally, the second access interaction message may include an authentication request frame, an association request frame, or a re-association request frame.

[0079] Optionally, the dynamic MAC address mode may be, for example, a closed mode, an optional mode, or a forced mode; the determining module may include:

[0080] A first determining sub-module, configured to determine the global MAC address of the terminal device as the target MAC address when the dynamic MAC address mode is the closed mode;

[0081] A second determining sub-module, configured to determine the global MAC address or the local MAC address of the terminal device as the target MAC address when the dynamic MAC address mode is the optional mode;

[0082] A third determining sub-module, configured to determine the local MAC address of the terminal device as the target MAC address when the dynamic MAC address mode is the forced mode.

[0083] Optionally, the first access interaction message may further include: a dynamic MAC address survival duration; the device further includes:

[0084] An update module, configured to, when determining that the local MAC address of the terminal device is used as the target MAC address, update the target MAC address regularly according to the dynamic MAC address survival duration.

[0085] Correspondingly, this specification also provides an electronic device, which includes a processor; a memory for storing instructions executable by the processor; wherein, the processor is configured to: receive a first access interaction message sent by an access point, the first access interaction message including a dynamic MAC address mode; determine a target MAC address according to the dynamic MAC address mode; and send a second access interaction message to the access point, the second access interaction message including the target MAC address.

[0086] According to the embodiments of this specification, when the AP announces the MAC address mode that can be used when accessing the network through the first access interaction message, the terminal device can use the corresponding MAC address to access the network according to the dynamic MAC address mode announced by the AP. Thus, the terminal device can automatically meet the requirements of the network side and jointly perform access control with the network side, without the need to manually turn off the dynamic MAC address function of the terminal device one by one, simplifying the operation difficulty and reducing the operation and maintenance cost.

[0087] The implementation processes of the functions and effects of each module in the above device are specifically described in detail in the implementation processes of the corresponding steps in the above method, and will not be elaborated here.

[0088] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can refer to the partial descriptions of the method embodiments. The device embodiments described above are only illustrative. The modules described as separate components may or may not be physically separated, and the components shown as modules may or may not be physical modules, that is, they may be located in one place, or may be distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this specification. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0089] The specific embodiments of this specification are described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired results. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0090] Those skilled in the art will readily conceive of other embodiments of the present specification after considering the specification and practicing the invention claimed herein. This specification is intended to cover any variations, uses, or adaptations of the specification that follow the general principles of the specification and include known common general knowledge or conventional technical means in the technical field not claimed in this specification. The specification and examples are only to be considered as exemplary, and the true scope and spirit of this specification are pointed out by the following claims.

[0091] It should be understood that this specification is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of this specification is only limited by the appended claims.

[0092] The above are only the preferred embodiments of this specification and are not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of this specification shall be included within the scope of protection of this specification.

Claims

1. A method for accessing a network, applied to an access point, characterized in that: The method comprises: Sending a first access interaction message to a terminal device, wherein the first access interaction message includes a dynamic MAC address mode; Receiving a second access interaction message sent by the terminal device, where the second access interaction message includes a target MAC address; Verify whether the target MAC address matches the dynamic MAC address pattern; If the target MAC address matches the dynamic MAC address pattern, the terminal device is allowed to access the network.

2. The method according to claim 1, characterized in that The first access interaction message includes a beacon frame or a probe response frame.

3. The method according to claim 1, characterized in that The second access interaction message includes an authentication request frame, an association request frame, or a reassociation request frame.

4. The method according to claim 1, characterized in that: The dynamic MAC address mode is a closed mode, an optional mode, or a mandatory mode; and the checking whether the target MAC address matches the dynamic MAC address mode includes: When the dynamic MAC address mode is the off mode, checking whether the target MAC address conforms to the global MAC address format, and if the MAC address conforms to the global MAC address format, determining that the target MAC address matches the dynamic MAC address mode; In the case where the dynamic MAC address mode is an optional mode, checking whether the target MAC address conforms to a global MAC address format or a local MAC address format, and if the target MAC address conforms to a global MAC address format or a local MAC address format, determining that the target MAC address matches the dynamic MAC address mode; When the dynamic MAC address mode is the forced mode, it is checked whether the target MAC address conforms to the local MAC address format. If the target MAC address conforms to the local MAC address format, it is determined that the target MAC address matches the dynamic MAC address mode.

5. The method according to claim 4, characterized in that The first access interaction message also includes: the dynamic MAC address lifetime.

6. A method for accessing a network, applied to a terminal device, characterized in that: The method comprises: A first access interaction message sent by a receiving access point includes a dynamic MAC address mode; Determine a target MAC address according to the dynamic MAC address mode; Sending a second access interaction message to the access point, where the second access interaction message includes the target MAC address.

7. The method according to claim 6, characterized in that The first access interaction message includes a beacon frame or a probe response frame.

8. The method according to claim 6, characterized in that The second access interaction message includes an authentication request frame, an association request frame, or a reassociation request frame.

9. The method according to claim 6, characterized in that The dynamic MAC address mode is a closed mode, an optional mode, or a mandatory mode; and determining the target MAC address according to the dynamic MAC address mode includes: When the dynamic MAC address mode is the off mode, determining the global MAC address of the terminal device as the target MAC address; In a case where the dynamic MAC address mode is an optional mode, determining a global MAC address or a local MAC address of the terminal device as the target MAC address; When the dynamic MAC address mode is a forced mode, the local MAC address of the terminal device is determined as the target MAC address.

10. The method according to claim 9, characterized in that The first access interaction message further includes: a dynamic MAC address lifetime; and the method further includes: When the local MAC address of the terminal device is determined as the target MAC address, the target MAC address is periodically updated according to the lifetime of the dynamic MAC address.

11. A device for accessing a network, characterized in that: The device comprises: A first sending module, configured to send a first access interaction message to a terminal device, wherein the first access interaction message includes a dynamic MAC address mode; A first receiving module, configured to receive a second access interaction message sent by the terminal device, where the second access interaction message includes a target MAC address; A verification module, used to verify whether the target MAC address matches the dynamic MAC address mode; An access module is used to allow the terminal device to access the network if the target MAC address matches the dynamic MAC address pattern.

12. A device for accessing a network, characterized in that: The device comprises: A second receiving module, configured to receive a first access interaction message sent by an access point, wherein the first access interaction message includes a dynamic MAC address mode; A determination module, used to determine a target MAC address according to the dynamic MAC address mode; The second sending module is used to send a second access interaction message to the access point, where the second access interaction message includes the target MAC address.

13. An electronic device comprising: processor; a memory for storing processor-executable instructions; The processor is configured to execute the method for accessing a network according to any one of claims 1 to 10.

14. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the method for accessing a network according to any one of claims 1 to 10.