Wireless communication method, station device and access point device

CN120303968APending Publication Date: 2025-07-11GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280102151.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-12-02
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In wireless LANs, 'spoofing AP' attacks lead to the risk of user privacy leakage. The attacker simulates the AP and sends the SSID that the user has connected to. The STA may automatically send association request frames, thereby leaking the user's location.

Method used

Add certification information (such as Verify_ID) to the frame sent by the access point device. Based on the secret information and time information, the STA verifies whether the access point device is disguised by other devices before receiving the frame containing the saved SSID to prevent deceiving the AP. attack.

Benefits of technology

It effectively solves the risk of privacy leakage caused by 'spoofing AP' attacks, enhances the security of the association process between STA and AP, and adds little signaling overhead and has little impact on system throughput.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120303968A_ABST
    Figure CN120303968A_ABST
Patent Text Reader

Abstract

Provided in an embodiment of the present application are a wireless communication method, a station device and an access point device, in a case where an SSID in a first frame sent by an AP is an SSID connected by an STA, the STA determines whether the AP is disguised by other devices based on certification information, thereby solving the risk of privacy disclosure brought to a user by a spoofing AP attack, increasing a small signaling overhead, and improving user experience. And the influence on system throughput is very small, and implementation is convenient. The wireless communication method comprises: a station device receiving a first frame, the first frame comprising attestation information, the attestation information being determined based on first secret information and time information of an access point device; and under the condition that the SSID in the first frame is the SSID connected with the site equipment, the site equipment determines whether the access point equipment is disguised by other equipment according to the time information of the site equipment, the first secret information and the proof information.
Need to check novelty before this filing date? Find Prior Art

Description

Wireless communication method, station device, and access point device Technical Field

[0001] The embodiments of the present application relate to the field of communications, and more specifically, to a wireless communication method, a station device, and an access point device. Background Art

[0002] In wireless local area networks (WLANs), when a station (STA) receives a beacon frame or probe response frame from an access point (AP), if the service set identifier (SSID) contained in the beacon frame or probe response frame is an SSID to which it has previously connected, the STA may automatically send an association request frame to the AP. An attacker can exploit this mechanism by establishing an AP, calling it a "spoof AP." The "spoof AP" carries an SSID to which a user has previously connected (for example, the SSID of the user's home WLAN) in its beacon or probe response frames. If the "spoof AP" receives an association request frame from a STA, regardless of the STA's Media Access Control (MAC) address, it can infer that the user is likely within the "spoof AP's" coverage area, thereby enabling the identification and tracking of specific users.

[0003] When the SSID contained in the beacon frame or probe response frame belongs to an SSID that the user has connected to before, how to resolve the privacy leakage risk brought to users by the "spoofed AP" attack, or how to associate the STA with the AP, are issues that need to be addressed.

[0004] Summary of the Invention

[0005] An embodiment of the present application provides a wireless communication method, a site device, and an access point device. When the SSID in the first frame sent by the access point device is an SSID to which the site device has been connected, the site device can determine whether the access point device is disguised by another device based on the certification information carried in the first frame, thereby resolving the privacy leakage risk brought to users by the "spoofed AP" attack; alternatively, when the SSID in the first frame sent by the access point device is an SSID to which the site device has been connected, the site device can associate with the access point device based on the certification information carried in the first frame, thereby enhancing the security of the process of the site device associating with the access point device.

[0006] In a first aspect, a wireless communication method is provided, the method comprising:

[0007] The station device receives a first frame, wherein the first frame includes certification information, and the certification information is determined based on the first secret information and time information of the access point device;

[0008] In the case where the SSID in the first frame is an SSID to which the site device has been connected, the site device determines whether the access point device is disguised by another device based on the time information of the site device, the first secret information, and the certification information, or the site device associates the access point device based on the time information of the site device, the first secret information, and the certification information.

[0009] In a second aspect, a wireless communication method is provided, the method comprising:

[0010] The access point device sends a first frame, where the first frame includes authentication information, where the authentication information is determined based on the first secret information and time information of the access point device;

[0011] Wherein, when the SSID in the first frame is an SSID to which the station device has been connected, the certification information is used by the station device to determine whether the access point device is disguised by another device, or the certification information is used by the station device to associate with the access point device.

[0012] In a third aspect, a site device is provided, configured to execute the method in the first aspect.

[0013] Specifically, the site equipment includes a functional module for executing the method in the first aspect above.

[0014] In a fourth aspect, an access point device is provided, configured to execute the method in the second aspect.

[0015] Specifically, the access point device includes a functional module for executing the method in the second aspect.

[0016] In a fifth aspect, a site device is provided, comprising a processor and a memory; the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the site device executes the method in the above-mentioned first aspect.

[0017] In a sixth aspect, an access point device is provided, comprising a processor and a memory; the memory is used to store a computer program, and the processor is used to call and run the computer program stored in the memory, so that the access point device executes the method in the second aspect above.

[0018] In a seventh aspect, a device is provided for implementing the method in any one of the first to second aspects above.

[0019] Specifically, the apparatus includes: a processor, configured to call and run a computer program from a memory, so that a device equipped with the apparatus executes the method in any one of the first to second aspects described above.

[0020] In an eighth aspect, a computer-readable storage medium is provided for storing a computer program, wherein the computer program enables a computer to execute the method in any one of the first to second aspects above.

[0021] In a ninth aspect, a computer program product is provided, comprising computer program instructions, wherein the computer program instructions enable a computer to execute the method in any one of the first to second aspects above.

[0022] In a tenth aspect, a computer program is provided, which, when executed on a computer, enables the computer to execute the method in any one of the first to second aspects above.

[0023] With the above technical solution, if the SSID in the first frame sent by the access point device is an SSID to which the station device has previously connected, the station device can determine whether the access point device is impersonated by another device based on the certification information carried in the first frame. This can mitigate the privacy leakage risks posed by "spoofed AP" attacks, while also minimizing the added signaling overhead and the impact on system throughput, making it easy to implement. Alternatively, if the SSID in the first frame sent by the access point device is an SSID to which the station device has previously connected, the station device can associate the access point device based on the station device's time information, the first secret information, and the certification information, thereby enhancing the security of the process by which the station device associates with the access point device. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] FIG1 is a schematic diagram of a communication system architecture applied in an embodiment of the present application.

[0025] FIG2 is a schematic interactive flowchart of a wireless communication method provided according to an embodiment of the present application.

[0026] FIG3 is a schematic diagram of a certification information element provided according to an embodiment of the present application.

[0027] FIG4 is a schematic diagram of a beacon frame carrying certification information provided according to an embodiment of the present application.

[0028] FIG5 is a schematic diagram of a probe response frame carrying certification information provided according to an embodiment of the present application.

[0029] FIG6 is a schematic diagram of a management frame provided according to an embodiment of the present application.

[0030] FIG7 is a schematic block diagram of a site device provided according to an embodiment of the present application.

[0031] FIG8 is a schematic block diagram of an access point device provided according to an embodiment of the present application.

[0032] FIG9 is a schematic block diagram of a communication device provided according to an embodiment of the present application.

[0033] FIG10 is a schematic block diagram of a device provided according to an embodiment of the present application.

[0034] FIG11 is a schematic block diagram of a communication system provided according to an embodiment of the present application. DETAILED DESCRIPTION

[0035] The following will describe the technical solutions in the embodiments of this application in conjunction with the drawings in the embodiments of this application. Obviously, the embodiments described are part of the embodiments of this application, not all of the embodiments. With respect to the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0036] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as Wireless Local Area Networks (WLAN), Wireless Fidelity (WiFi), or other communication systems.

[0037] Please refer to Figure 1, which shows a schematic diagram of a wireless communication system provided by an embodiment of the present application. As shown in Figure 1, the wireless communication system may include: an access point (AP) and a station (STA).

[0038] In some scenarios, an AP can be referred to as an AP STA, meaning that in a sense, an AP is also a type of STA. In some scenarios, a STA can be referred to as a non-AP STA.

[0039] In some embodiments, STAs may include AP STAs and non-AP STAs. Communication in a communication system may be between an AP and a non-AP STA, between a non-AP STA and a non-AP STA, or between a STA and a peer STA. A peer STA may refer to a device that communicates with a STA. For example, a peer STA may be an AP or a non-AP STA.

[0040] An AP acts as a bridge between wired and wireless networks, connecting wireless network clients together and then connecting the wireless network to the Ethernet. An AP can be a terminal device (such as a mobile phone) or a network device (such as a router) equipped with a Wireless Fidelity (Wi-Fi) chip.

[0041] It should be understood that the role of STA in the communication system is not absolute. For example, in some scenarios, when a mobile phone is connected to a router, the mobile phone is a non-AP STA. When the mobile phone serves as a hotspot for other mobile phones, the mobile phone plays the role of AP.

[0042] APs and non-AP STAs can be devices used in the Internet of Vehicles, IoT nodes and sensors in the Internet of Things (IoT), smart cameras, smart remote controls, smart water and electricity meters in smart homes, and sensors in smart cities.

[0043] In some embodiments, a non-AP STA may support 802.11be. A non-AP STA may also support various current and future 802.11 family wireless LAN standards, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.

[0044] In some embodiments, the AP may be a device supporting the 802.11be standard. The AP may also be a device supporting various current and future 802.11 family WLAN standards, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.

[0045] In the embodiment of the present application, the STA may be a mobile phone, tablet computer, computer, virtual reality (VR) device, augmented reality (AR) device, wireless device in industrial control, set-top box, wireless device in self-driving, in-vehicle communication equipment, wireless device in remote medical, wireless device in smart grid, wireless device in transportation safety, wireless device in smart city, wireless device in smart home, wireless communication chip, ASIC (Application Specific Integrated Circuit), SOC (System on Chip), etc. that supports WLAN / WIFI technology.

[0046] The frequency bands supported by WLAN technology may include but are not limited to: low frequency bands (2.4 GHz, 5 GHz, 6 GHz) and high frequency bands (45 GHz, 60 GHz).

[0047] There are one or more links between the station and the access point. In some embodiments, the station and the access point support multi-band communication. For example, communication is performed simultaneously on the 2.4 GHz, 5 GHz, 6 GHz, 45 GHz, and 60 GHz frequency bands, or communication is performed simultaneously on different channels in the same frequency band (or different frequency bands), thereby improving the communication throughput and / or reliability between devices. Such a device is generally referred to as a multi-band device, or a multi-link device (MLD), sometimes also referred to as a multi-link entity or a multi-band entity. A multi-link device can be an access point device or a station device. If the multi-link device is an access point device, the multi-link device includes one or more APs; if the multi-link device is a station device, the multi-link device includes one or more non-AP STAs.

[0048] A multi-link device including one or more APs may be referred to as an AP MLD, and a multi-link device including one or more non-AP STAs may be referred to as a Non-AP MLD.

[0049] In an embodiment of the present application, the AP may include multiple APs, the Non-AP may include multiple STAs, multiple links may be formed between the APs in the AP and the STAs in the Non-AP, and data communication may be performed between the APs in the AP and the corresponding STAs in the Non-AP through the corresponding links.

[0050] An AP is a device deployed in a wireless local area network to provide wireless communication capabilities for STAs. A station may include: User Equipment (UE), an access terminal, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, a remote terminal, a mobile device, a wireless communication device, a user agent, or a user device. Optionally, a station may also be a cellular phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, a vehicle-mounted device, or a wearable device, but the embodiments of the present application are not limited thereto.

[0051] Optionally, both the station and the access point support the IEEE 802.11 standard.

[0052] It should be understood that the terms "system" and "network" are often used interchangeably herein. The term "and / or" is simply a description of an association between related objects, indicating that three possible relationships exist. For example, "A and / or B" can represent: A exists alone, A and B exist simultaneously, or B exists alone. Furthermore, the character " / " generally indicates that the related objects are in an "or" relationship.

[0053] It should be understood that the "indication" mentioned in the embodiments of this application can be a direct indication, an indirect indication, or an indication of an association. For example, "A indicates B" can mean that A directly indicates B, for example, B can be obtained through A; it can also mean that A indirectly indicates B, for example, A indicates C, and B can be obtained through C; it can also mean that there is an association between A and B.

[0054] The terms used in the embodiments of this application are intended only to explain the specific embodiments of this application and are not intended to limit this application. The terms "first," "second," "third," and "fourth," etc. in the specification and claims of this application and the accompanying drawings are used to distinguish different objects, not to describe a specific order. In addition, the terms "including" and "having," and any variations thereof, are intended to cover non-exclusive inclusions.

[0055] In the description of the embodiments of the present application, the term "corresponding" may indicate a direct or indirect correspondence between the two, or an association relationship between the two, or a relationship between indication and being indicated, configuration and being configured, etc.

[0056] In the embodiments of the present application, "pre-defined" or "pre-configured" may be implemented by pre-storing corresponding codes, tables, or other methods that can be used to indicate relevant information in a device (e.g., including STAs and network devices). The present application does not limit the specific implementation method. For example, pre-defined may refer to what is defined in the protocol.

[0057] In the embodiments of the present application, the “protocol” may refer to a standard protocol in the communication field, for example, it may include a WiFi protocol and related protocols used in future WiFi communication systems, and the present application does not limit this.

[0058] To facilitate understanding of the technical solutions of the embodiments of the present application, the problems solved by the present application are described below.

[0059] STAs discover APs in two ways: passive scanning, where the AP broadcasts beacon frames to announce its presence; and active scanning, where the STA sends a probe request frame with an empty SSID or a specific SSID. Upon receiving the probe request frame, the AP sends a probe response frame to the STA to announce its presence. Both beacon frames and probe response frames sent by the AP contain an SSID element, which identifies a Basic Service Set (BSS).

[0060] When a STA associates with an AP for the first time, it saves the AP's SSID. These saved SSIDs are referred to as saved SSIDs or preferred SSIDs. When a STA receives a beacon frame or probe response frame, if the SSID contained in the beacon frame or probe response frame is one of its saved SSIDs and the user has set the network to "automatically connect when this network is in range," the upper-layer application will control the device's WiFi driver to perform the relevant connection actions (including authentication and association, etc.). For example, the WLAN management program wpa_supplicant allows users to configure network parameters through a graphical user interface or terminal commands. wpa_supplicant can automatically control the device's WiFi driver to connect to the network based on the parameters in its configuration file.

[0061] Attackers can exploit the security vulnerabilities of the current AP discovery and association mechanism to identify and track specific users. Assuming an attacker knows one or more SSIDs a user has connected to, such as the SSID of the user's home network, the attacker can establish an AP and use it to broadcast the SSID of the user's home network. When a STA receives a beacon frame or probe response frame from the attacker's AP, if the STA finds that the SSID in the frame is a saved SSID, it may automatically send an association request frame to the AP. Regardless of whether the STA is associated with the attacker's AP or its MAC address, the fact that the STA has sent an association request frame to the AP indicates that the user is within the coverage area of ​​the attacker's AP.

[0062] Based on the above problems, the present application proposes a wireless communication solution. When the SSID in the first frame sent by the access point device is the SSID to which the site device has connected, the site device can determine whether the access point device is disguised by other devices based on the proof information carried in the first frame, thereby solving the privacy leakage risk brought to users by the "spoofed AP" attack; or, when the SSID in the first frame sent by the access point device is the SSID to which the site device has connected, the site device can associate the access point device based on the proof information carried in the first frame, thereby enhancing the security of the process of the site device associating with the access point device.

[0063] To facilitate understanding of the technical solutions of the embodiments of the present application, the technical solutions of the present application are described in detail below through specific embodiments. The following related technologies can be combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the scope of protection of the embodiments of the present application. The embodiments of the present application include at least part of the following contents.

[0064] FIG2 is a schematic flowchart of a wireless communication method 200 according to an embodiment of the present application. As shown in FIG2 , the wireless communication method 200 may include at least part of the following contents:

[0065] S210: The access point device sends a first frame, where the first frame includes certification information, where the certification information is determined based on first secret information and time information of the access point device.

[0066] S220, the site device receives the first frame;

[0067] S230, when the SSID in the first frame is an SSID to which the site device has been connected, the site device determines whether the access point device is disguised by another device based on the time information of the site device, the first secret information, and the certification information, or the site device associates the access point device based on the time information of the site device, the first secret information, and the certification information.

[0068] That is, in an embodiment of the present application, when the SSID in the first frame is the SSID to which the site device has been connected, the proof information carried in the first frame is used by the site device to determine whether the access point device is disguised by other devices, or the proof information carried in the first frame is used by the site device to associate with the access point device.

[0069] The certification information in the embodiment of the present application may also be referred to as a certification identifier, a certification parameter, or similar names, which are not limited in the embodiment of the present application. For example, the certification information may be Verify_ID.

[0070] In the embodiments of the present application, a “field” may also be referred to as a “field” or a “subfield.” A field may occupy one or more bytes (byte / octet), or a field may occupy one or more bits (bit).

[0071] In some embodiments, the first frame includes a certification information element;

[0072] The certification information element includes a certification field, and the certification field is used to indicate the certification information (such as Verify_ID).

[0073] In some embodiments, the first frame is a beacon frame, or the first frame is a probe response frame. Of course, the first frame can also be other frames, which is not limited in the embodiments of the present application.

[0074] For example, the format of the certification information element can be as shown in Figure 3. When the value of the element identifier (Element ID) is 255, the values ​​114-255 of the element identifier extension (Element ID Extension) are reserved and unused. For example, the certification information element can be represented by Element ID=255 and Element ID Extension=114. The certification information element is present in beacon frames and probe response frames. The access point device uses the certification information (such as Verify_ID) to prove its identity to the station device. When the station device receives a beacon frame or a probe response frame, if the SSID contained in the beacon frame or the probe response frame is an SSID to which it has previously connected, before the station device sends an association request frame to the access point device, the station device verifies whether the access point device is impersonated by another device based on the certification information (such as Verify_ID) in the beacon frame or the probe response frame. If not, the station device sends an association request frame. Otherwise, the station device does not send an association request frame.

[0075] In some embodiments, the first frame is a beacon frame, and the frame interaction process containing the proof information (such as Verify_ID) can be as shown in Figure 4. The AP sends a beacon frame, which contains the SSID and proof information (such as Verify_ID) of the AP. The sending address (Transmitter Address, TA) of the beacon frame is the MAC address of the AP, and the receiving address (Receiver Address, RA) of the beacon frame is the broadcast address.

[0076] In some embodiments, the first frame is a probe response frame, and the frame interaction process including the proof information (such as Verify_ID) can be as shown in Figure 5, where the STA sends a probe request frame and the AP sends a probe response frame, which includes the SSID and proof information (such as Verify_ID) of the AP. The TA of the probe response frame is the medium access control (MAC) address of the AP, and the RA of the probe response frame is the MAC address of the STA.

[0077] In some embodiments, in the above S230, the site device determines whether the access point device is disguised by another device based on the time information of the site device, the first secret information, and the certification information, including:

[0078] The site device determines verification information according to the first secret information and time information of the site device;

[0079] When the verification information is identical to the certification information, the site device determines that the access point device is not disguised by another device; and / or when the verification information is different from the certification information, the site device determines that the access point device is disguised by another device.

[0080] For example, the comparison between the verification information and the certification information may occur at the Media Access Control (MAC) layer of the site device, as the MAC layer is more efficient. Of course, the comparison between the verification information and the certification information may also occur at other layers of the site device, such as the application layer, which is not limited in this embodiment of the present application.

[0081] In some embodiments, when the station device determines that the access point device is not disguised by another device, the station device sends an association request frame to the access point device.

[0082] In some embodiments, when the station device determines that the access point device is disguised by another device, the station device does not send an association request frame to the access point device, or the station device ignores the first frame.

[0083] In a wireless LAN, when a STA receives a beacon frame or probe response frame from an AP, if the SSID contained in the frame is one to which it has previously connected, the STA may automatically send an association request frame to the AP. An attacker can exploit this mechanism by establishing an AP, calling it a "spoof AP." This "spoof AP" carries an SSID to which a user has previously connected (for example, the SSID of a user's home WLAN) in its beacon or probe response frames. If the "spoof AP" receives an association request frame from a STA, regardless of the MAC address used by the STA, it can infer that the user is likely within the "spoof AP's" coverage area, thereby enabling identification and tracking of specific users.

[0084] In this embodiment, the access point device adds identification information (such as Verify_ID) in the first frame to prove its identity to the site device. The identification information (such as Verify_ID) is determined based on the first secret information and the time information of the access point device. When the SSID in the first frame is an SSID to which the site device has been connected, the site device will verify whether the access point device is disguised by another device based on the identification information (such as Verify_ID) before sending the association request frame. That is, it verifies whether the access point device is a "spoofed AP", thereby solving the privacy leakage risk brought to users by the "spoofed AP" attack. In addition, the increased signaling overhead is relatively small, and the impact on system throughput is extremely small, which is easy to implement.

[0085] In some embodiments, in the above S230, the site device associating the access point device according to the time information of the site device, the first secret information, and the certification information includes:

[0086] The site device determines verification information according to the first secret information and time information of the site device;

[0087] When the verification information is the same as the certification information, the site device directly associates with the access point device by sending an association request frame; and / or, when the verification information is different from the certification information, the site device associates with the access point device through initial access.

[0088] Specifically, for example, the comparison between the verification information and the certification information may occur at the MAC layer of the site device, as the MAC layer is more efficient. Of course, the comparison between the verification information and the certification information may also occur at other layers of the site device, such as the application layer, which is not limited in this embodiment of the present application.

[0089] In some embodiments, when the access point device performs a system reset, the verification information is different from the certification information. That is, the difference between the verification information and the certification information may be caused by the access point device performing a system reset.

[0090] Optionally, the difference between the verification information and the certification information may also be caused by time asynchrony between the station device and the access point device.

[0091] Specifically, if an AP undergoes a system reset or other operations, which may cause the AP and STA time to become out of sync, the STA will mistake a previously connected real AP for an unconnected AP and will not automatically connect to it. If the user needs to connect to the AP again, they can manually click the network name to reconnect after confirming that it is safe (the same workflow as for connecting to the AP for the first time).

[0092] In this embodiment, if the SSID in the first frame sent by the access point device is an SSID to which the station device has previously connected, the station device can associate with the access point device based on the authentication information carried in the first frame, thereby enhancing the security of the station device's association process with the access point device. For example, if the access point device performs a system reset or the time between the station device and the access point device is out of sync, and the authentication information differs from the authentication information, the station device can associate with the access point device through initial access. For another example, if the authentication information and authentication information are identical, the station device can directly associate with the access point device by sending an association request frame.

[0093] In some embodiments, the time information of the access point device is determined based on the system time of the access point device and the time interval for the access point device to update the certification information.

[0094] It should be noted that the system time of the access point device is the system time when the access point device determines the certification information.

[0095] For example, the current system time of the access point device is T ap_now =[D:H:M:S] AP , where D represents the date, H represents the hour, M represents the minute, and S represents the second.

[0096] Optionally, the access point device sets its own system time based on the current time obtained from the world time server.

[0097] In some embodiments, the time interval for the access point device to update the certification information may be determined by the access point device, or the time interval for the access point device to update the certification information may be agreed upon by a protocol, or the time interval for the access point device to update the certification information may be determined by negotiation between the station device and the access point device. Optionally, to prevent the access point device from updating the certification information at an excessively long time interval, thereby allowing an attacker ample time to directly copy the certification information and apply it to a "spoofed AP", the time interval for the access point device to update the certification information should be relatively short, for example, within the following time range (in seconds): [1,2047].

[0098] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the access point device is determined based on Formula 1:

[0099] Time AP =[D:H:M:(S mod T)] AP Formula 1

[0100] Among them, Time AP Indicates the time information of the access point device, [D:H:M:S] AP Indicates the system time of the access point device. D indicates the date, H indicates the hour, M indicates the minute, S indicates the second, T indicates the interval for the access point device to update the certification information, and mod indicates the modulo operation.

[0101] In some embodiments, when the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the access point device is determined based on Formula 2:

[0102] Time AP =[D:H:(M mod T')]AP Formula 2

[0103] Among them, Time AP Indicates the time information of the access point device, [D:H:M:S] AP Indicates the system time of the access point device, D indicates date, H indicates hour, M indicates minute, S indicates second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0104] In some embodiments, the access point device determines the certification information according to the following formula 3:

[0105] Verify_ID=HASH(IV||Time AP ) m Formula 3

[0106] Among them, Verify_ID represents the proof information, IV represents the first secret information, Time AP Indicates the time information of the access point device, || indicates string concatenation, HASH(X) indicates hashing the parameter X, HASH(X) m Indicates that m bits are truncated from the result of HASH(X), where m is a positive integer. For example, m=16.

[0107] For example, the algorithm corresponding to the hash operation in the above formula 3 may be Secure Hash Algorithm 2 (SHA-2) or Secure Hash Algorithm 3 (SHA-3).

[0108] In some embodiments, the m bits are m bits intercepted from the result of HASH(X) in the first order.

[0109] In some embodiments, the first order is from front to back, or the first order is from back to front.

[0110] For example, HASH(X) 16 Indicates that 16 bits are intercepted from the result of HASH(X). For example, 16 bits may be intercepted from the 0th bit and forward, or 16 bits may be intercepted from the last bit and forward, or 16 bits may be intercepted from the xth bit and forward or backward, where x may be determined by the protocol or by negotiation between the site device and the access point device.

[0111] In some embodiments, the time information of the site device is determined based on the system time of the site device and the time interval for the access point device to update the certification information.

[0112] For example, the current system time of the site device is T STA_now =[D:H:M:S] STA , where D represents the date, H represents the hour, M represents the minute, and S represents the second.

[0113] Optionally, the site device sets its own system time based on the current time obtained from the world time server.

[0114] In some embodiments, the STA may maintain a list locally, as shown in Table 1, wherein the first row of the list is the SSID of the AP to which the STA has associated, and the second row of the list is the time interval for the AP to which the STA has associated to update the certification information (such as Verify_ID).

[0115] Table 1

[0116] SSID of the AP to which the STA has associated. Time interval for updating the certification information of the AP to which the STA has associated. SSID1T1SSID2T2SSID3T3...SSID n T n

[0117] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the station device is determined based on the following formula 4:

[0118] Time STA =[D:H:M:(S mod T)] STA Formula 4

[0119] Among them, Time STA Indicates the time information of the site device, [D:H:M:S] STA Indicates the system time of the site device, D indicates the date, H indicates the hour, M indicates the minute, S indicates the second, T indicates the time interval for the access point device to update the certification information, and mod indicates the modulo operation.

[0120] In some embodiments, when the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the station device is determined based on the following formula 5:

[0121] Time STA =[D:H:(M mod T')] STA Formula 5

[0122] Among them, Time STA Indicates the time information of the site device, [D:H:M:S] STA Indicates the system time of the site device, D indicates date, H indicates hour, M indicates minute, S indicates second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0123] In some embodiments, if the error between the system time of the site device and the system time of the access point device has a significant impact on the time information used to calculate the certification information (for example, the time interval for the access point device to update the certification information is 10 seconds, and the error is 5 seconds), the time information of the site device is determined based on the system time of the site device, the time interval for the access point device to update the certification information, and the error value between the system time of the site device and the system time of the access point device.

[0124] Optionally, the error value is determined based on the system time of the site device and the system time of the access point device. That is, after obtaining the system time of the access point device, the site device may determine the error value based on the system time of the site device and the system time of the access point device.

[0125] For example, the error value (unit: second) between the system time of the station device and the system time of the access point device is +1, that is, the system time of the station device is 1 second earlier than the system time of the access point device.

[0126] For example, the error value (unit: seconds) between the system time of the station device and the system time of the access point device is -5, that is, the system time of the station device is 5 seconds later than the system time of the access point device.

[0127] In some embodiments, the STA may locally maintain a list, as shown in Table 2, where the first row of the list is the SSID of the AP to which the STA has associated, the second row of the list is the error value between the system time of the STA and the system time of the AP to which the STA has associated, and the third row of the list is the time interval for the AP to which the STA has associated to update verification information (such as Verify_ID).

[0128] Table 2

[0129]

[0130] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the station device is determined based on the following formula 6:

[0131] TimeSTA =[D':H':M':(S'mod T)] Formula 6

[0132] Among them, Time STA Indicates the time information of the site device. [D':H':M':S'] indicates the time obtained by subtracting the error value from the system time of the site device. D' indicates the date, H' indicates the hour, M' indicates the minute, S' indicates the second, T indicates the time interval for the access point device to update the certification information, and mod indicates the modulo operation.

[0133] In some embodiments, when the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the station device is determined based on the following formula 7:

[0134] Time STA =[D':H':(M'mod T')] Formula 7

[0135] Among them, Time STA Indicates the time information of the site device. [D':H':M':S'] indicates the time obtained by subtracting the error value from the system time of the site device. D' indicates the date, H' indicates the hour, M' indicates the minute, S' indicates the second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0136] In some embodiments, the site device determines the verification information according to the following formula 8:

[0137] Verify_ID'=HASH(IV||Time STA ) m Formula 8

[0138] Among them, Verify_ID' represents the verification information, IV represents the first secret information, Time STA Indicates the time information of the site device, || indicates string concatenation, HASH(X) indicates hashing the parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

[0139] In some embodiments, the m bits are m bits intercepted from the result of HASH(X) in the first order.

[0140] In some embodiments, the first order is from front to back, or the first order is from back to front.

[0141] For example, HASH(X) 16 Indicates that 16 bits are intercepted from the result of HASH(X). For example, 16 bits may be intercepted from the 0th bit and forward, or 16 bits may be intercepted from the last bit and forward, or 16 bits may be intercepted from the xth bit and forward or backward, where x may be determined by the protocol or by negotiation between the site device and the access point device.

[0142] In some embodiments, before the site device receives the first frame, the site device receives a second frame sent by the access point device after initially accessing the access point device; wherein the second frame includes at least one of the following: the time interval for the access point device to update the certification information, and the system time of the access point device.

[0143] In some embodiments, the second frame is a management frame, or the second frame is a control frame. Of course, the second frame can also be other frames, which is not limited in the embodiments of the present application.

[0144] In some embodiments, the second frame includes a first time presence field and a second time presence field;

[0145] The first time existence field is used to indicate whether the first time field exists in the second frame, and the second time existence field is used to indicate whether the second time field exists in the second frame;

[0146] The first time field is used to indicate the time interval for the access point device to update the certification information, and the second time field is used to indicate the system time of the access point device.

[0147] Optionally, the first time existence field occupies 1 bit. For example, a value of 1 in the first time existence field indicates that the first time field exists in the second frame, and a value of 0 in the first time existence field indicates that the first time field does not exist in the second frame. For another example, a value of 0 in the first time existence field indicates that the first time field exists in the second frame, and a value of 1 in the first time existence field indicates that the first time field does not exist in the second frame.

[0148] Optionally, the second time existence field occupies 1 bit. For example, a value of 1 in the second time existence field indicates that the second time field exists in the second frame, and a value of 0 in the second time existence field indicates that the second time field does not exist in the second frame. For another example, a value of 0 in the second time existence field indicates that the second time field exists in the second frame, and a value of 1 in the second time existence field indicates that the second time field does not exist in the second frame.

[0149] In some embodiments, the time interval for the access point device to update the certification information and / or the system time of the access point device included in the second frame are encrypted by the access point device, specifically, encrypted by a secret value determined by negotiation between the station device and the access point device.

[0150] In some embodiments, the first secret information is a secret value shared between the access point device and an associated station device.

[0151] For example, the second frame is a management frame, the frame format of which can be as shown in FIG6 . This management frame is an Action frame. Since the values ​​of "30 to 125" in the Action Category field of the Action frame are reserved, this embodiment selects any value (e.g., "32") to indicate the presence of the following First Time (Time1Present) field. If the First Time Present (Time1Present) field is set to "1," it indicates that the following First Time (Time1) field exists; otherwise, it indicates that the following First Time (Time1) field does not exist. The value of the First Time (Time1) field is the time interval for the access point device to change the verification information (Verify_ID). The first 11 bits of the First Time (Time1) field are valid, and the last 5 bits are reserved and unused. The value of the First Time (Time1) value ranges from 1 to 2047, and the unit of the First Time (Time1) is seconds. If the second time presence (Time2Present) field is set to "1", it indicates that there is a second time (Time2) field behind it; otherwise, it indicates that there is no second time (Time2) field behind it. The value of the second time (Time2) field is the system time of the access point device. The first byte represents the value of hours, the second byte represents the value of minutes, and the third byte represents the value of seconds.

[0152] In some embodiments, the first secret information is agreed upon by a protocol, or the first secret information is determined by negotiation between the station device and the access point device, or the first secret information is configured by the access point device.

[0153] In some embodiments, the first secret information is a preshared key (PSK) or a simultaneous authentication of equals (SAE) key.

[0154] In some embodiments, the first secret information is a key derived from a PSK or SAE key.

[0155] Specifically, when a STA first accesses an AP, it negotiates a secret value (IV) with the AP. This secret value (IV) can be a network key (such as a PSK or SAE key) or a key derived from the network key (such as a PSK or SAE key). All STAs that have associated with the AP have the same IV value. After the STA completes the security association with the AP, the AP can encrypt the time interval for changing the verification information (Verify_ID) and the AP's current system time in a management frame as shown in Figure 6 and send it to the STA. After receiving the management frame, the STA decrypts it to obtain the time interval for the AP to change the verification information (Verify_ID), and the STA directly obtains the AP's current system time from the second time (Time2) field of the management frame. Optionally, the STA can determine an error value based on its own current system time and the AP's current system time, and maintain this error value in Table 2 above.

[0156] The following describes the technical solution of the present application in detail through a specific embodiment. Specifically, when a STA receives a beacon frame or a probe response frame, if the SSID contained in the frame belongs to an SSID that the STA has connected to before, the STA needs to verify the legitimacy of the beacon frame and the probe response frame based on the verification information (Verify_ID) in the beacon frame or the probe response frame before sending an association request frame to the AP. In other words, it needs to verify whether the AP is disguised by another device. The steps for the STA to verify the legitimacy of the beacon frame and the probe response frame are as follows:

[0157] Step 1: STA obtains the current system time and records this time as T STA_now =[D:H:M:S] STA , D, H, M and S represent date, hour, minute and second respectively;

[0158] Step 2: The STA uses the SSID contained in the beacon frame or probe response frame to find the corresponding error value and the time interval T for the AP to update the verification information (such as Verify_ID) in Table 2 above;

[0159] Step 3: STA will T STA_now Subtract the error value obtained in step 2 from the time of synchronization with the AP, and get the time T now’ =[D':H':M':S'];

[0160] Step 4: If the value of time interval T is within the range (0,60), Time STA =[D':H':M':(S'mod T)]; If the value of the time interval T is within the range [60,2047], let The symbol indicates rounding up, Time STA =[D':H':(M'mod T')];

[0161] Step 5: STA calculates verification information Verify_ID'=HASH(IV||Time STA ) 16 , IV is a secret value between STA and AP. If the calculated Verify_ID' value is equal to the Verify_ID value in the beacon frame or probe response frame, an association request frame is sent, otherwise no association request frame is sent.

[0162] Therefore, in an embodiment of the present application, the access point device adds verification information (such as Verify_ID) in the first frame to prove its identity to the site device. The verification information (such as Verify_ID) is determined based on the first secret information and the time information of the access point device. If the SSID in the first frame is an SSID that the site device has connected to, the site device will verify whether the access point device is disguised by another device based on the verification information (such as Verify_ID) before sending the association request frame. In other words, it verifies whether the access point device is a "spoofed AP", thereby resolving the privacy leakage risk brought to users by "spoofed AP" attacks. In addition, the "spoofed AP" problem can be resolved by simply adding the Verify_ID field to the first frame (such as a beacon frame or a probe response frame), and the value of Verify_ID is obtained through hash calculation, which has the advantages of simple implementation and low communication overhead. The increased signaling overhead is relatively small, and the impact on system throughput is extremely small, making it easy to implement.

[0163] Alternatively, in an embodiment of the present application, if the SSID in the first frame sent by the access point device is an SSID to which the station device has previously connected, the station device can associate with the access point device based on the certification information carried in the first frame, thereby enhancing the security of the site device's association process with the access point device. For example, if the access point device performs a system reset or the time between the station device and the access point device is out of sync, and the verification information differs from the certification information, the station device can associate with the access point device through initial access. For another example, if the verification information and certification information are identical, the station device can directly associate with the access point device by sending an association request frame.

[0164] The above text, in combination with Figures 2 to 6, describes in detail the method embodiment of the present application. The following text, in combination with Figures 7 to 11, describes in detail the device embodiment of the present application. It should be understood that the device embodiment and the method embodiment correspond to each other, and similar descriptions can refer to the method embodiment.

[0165] Figure 7 shows a schematic block diagram of a station device 300 according to an embodiment of the present application. As shown in Figure 7, the station device 300 includes: a communication unit 310 and a processing unit 320;

[0166] The communication unit 310 is configured to receive a first frame, wherein the first frame includes certification information, and the certification information is determined based on first secret information and time information of the access point device;

[0167] When the service set identifier SSID in the first frame is the SSID to which the site device has been connected, the processing unit 320 is configured to determine whether the access point device is disguised by another device based on the time information of the site device, the first secret information, and the certification information, or to associate the access point device based on the time information of the site device, the first secret information, and the certification information.

[0168] In some embodiments, the processing unit 320 is specifically configured to:

[0169] determining verification information according to the first secret information and time information of the site device;

[0170] If the verification information is identical to the certification information, it is determined that the access point device is not disguised by another device; and / or if the verification information is different from the certification information, it is determined that the access point device is disguised by another device.

[0171] In some embodiments, when the station device determines that the access point device is not disguised by another device, the communication unit 310 is further configured to send an association request frame to the access point device.

[0172] In some embodiments, when the station device determines that the access point device is disguised by another device, the station device does not send an association request frame to the access point device, or the station device ignores the first frame.

[0173] In some embodiments, the processing unit 320 is specifically configured to:

[0174] determining verification information according to the first secret information and time information of the site device;

[0175] When the verification information is the same as the certification information, the access point device is directly associated by sending an association request frame; and / or when the verification information is different from the certification information, the access point device is associated through initial access.

[0176] In some embodiments, the verification information is different from the certification information when the access point device performs a system reset.

[0177] In some embodiments, the processing unit 320 is specifically configured to:

[0178] The verification information is determined according to the following formula:

[0179] Verify_ID'=HASH(IV||Time STA ) m ;

[0180] Among them, Verify_ID' represents the verification information, IV represents the first secret information, Time STA Indicates the time information of the site device, || indicates string concatenation, HASH(X) indicates hashing the parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

[0181] In some embodiments, the certification information is determined based on the following formula:

[0182] Verify_ID=HASH(IV||Time AP ) m ;

[0183] Among them, Verify_ID represents the proof information, IV represents the first secret information, Time AP Indicates the time information of the access point device, || indicates string concatenation, HASH(X) indicates hashing the parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

[0184] In some embodiments, the m bits are m bits intercepted from the result of HASH(X) in the first order.

[0185] In some embodiments, the first order is from front to back, or the first order is from back to front.

[0186] In some embodiments, the time information of the site device is determined based on the system time of the site device and the time interval for the access point device to update the certification information.

[0187] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the site device is determined based on the following formula: Time STA =[D:H:M:(S mod T)] STA ;

[0188] When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the site device is determined based on the following formula: Time STA =[D:H:(M mod T')] STA ;

[0189] Among them, Time STA Indicates the time information of the site device, [D:H:M:S] STA Indicates the system time of the site device, D indicates date, H indicates hour, M indicates minute, S indicates second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0190] In some embodiments, the time information of the site device is determined based on the system time of the site device, the time interval for the access point device to update the certification information, and the error value between the system time of the site device and the system time of the access point device.

[0191] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the site device is determined based on the following formula: Time STA =[D':H':M':(S'mod T)];

[0192] When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the site device is determined based on the following formula: Time STA =[D':H':(M'mod T')];

[0193] Among them, Time STA Indicates the time information of the site device. [D':H':M':S'] indicates the time obtained by subtracting the error value from the system time of the site device. D' indicates the date, H' indicates the hour, M' indicates the minute, S' indicates the second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0194] In some embodiments, the error value is determined based on a system time of the station device and a system time of the access point device.

[0195] In some embodiments, before the station device receives the first frame, the communication unit 310 is further configured to receive a second frame sent by the access point device after initially accessing the access point device;

[0196] The second frame includes at least one of the following: a time interval for the access point device to update the certification information, and a system time of the access point device.

[0197] In some embodiments, the second frame includes a first time presence field and a second time presence field;

[0198] The first time existence field is used to indicate whether the first time field exists in the second frame, and the second time existence field is used to indicate whether the second time field exists in the second frame;

[0199] The first time field is used to indicate the time interval for the access point device to update the certification information, and the second time field is used to indicate the system time of the access point device.

[0200] In some embodiments, the time interval for the access point device to update the certification information and / or the system time of the access point device included in the second frame are encrypted by the access point device.

[0201] In some embodiments, the second frame is a management frame, or the second frame is a control frame.

[0202] In some embodiments, the time information of the access point device is determined based on the system time of the access point device and the time interval for the access point device to update the certification information.

[0203] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the access point device is determined based on the following formula: AP =[D:H:M:(S mod T)] AP ;

[0204] When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the access point device is determined based on the following formula: Time AP =[D:H:(M mod T')] AP ;

[0205] Among them, Time AP Indicates the time information of the access point device, [D:H:M:S] AP Indicates the system time of the access point device, D indicates the date, H indicates the hour, M indicates the minute, S indicates the second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0206] In some embodiments, the first secret information is a secret value shared between the access point device and an associated station device.

[0207] In some embodiments, the first secret information is a pre-shared key PSK or a simultaneous authentication of peers SAE key; or,

[0208] The first secret information is a key derived from the PSK or SAE key.

[0209] In some embodiments, the first secret information is agreed upon by a protocol, or the first secret information is determined by negotiation between the station device and the access point device, or the first secret information is configured by the access point device.

[0210] In some embodiments, the first frame includes a certification information element;

[0211] The certification information element includes a certification field, and the certification field is used to indicate the certification information.

[0212] In some embodiments, the first frame is a beacon frame, or the first frame is a probe response frame.

[0213] In some embodiments, the communication unit may be a communication interface or a transceiver, or an input / output interface of a communication chip or a system on chip. The processing unit may be one or more processors.

[0214] It should be understood that the site device 300 according to the embodiment of the present application may correspond to the site device in the embodiment of the method of the present application, and the above-mentioned and other operations and / or functions of each unit in the site device 300 are respectively for implementing the corresponding processes of the site device in the method 200 shown in Figure 2. For the sake of brevity, they are not repeated here.

[0215] FIG8 shows a schematic block diagram of an access point device 400 according to an embodiment of the present application. As shown in FIG8 , the access point device 400 includes:

[0216] The communication unit 410 is configured to send a first frame, the first frame including certification information, the certification information being determined based on the first secret information and time information of the access point device;

[0217] In which case, when the service set identifier SSID in the first frame is an SSID to which the site device has been connected, the certification information is used by the site device to determine whether the access point device is disguised by other devices, or the certification information is used by the site device to associate with the access point device.

[0218] In some embodiments, the certification information is used by the station device to determine whether the access point device is disguised by another device, including:

[0219] If the verification information is identical to the certification information, the site device determines that the access point device is not disguised by another device; and / or if the verification information is different from the certification information, the site device determines that the access point device is disguised by another device;

[0220] The verification information is determined based on the first secret information and time information of the site device.

[0221] In some embodiments, when the site device determines that the access point device is not disguised by another device, the communication unit 410 is further configured to receive an association request frame sent by the site device.

[0222] In some embodiments, the certification information is used for the site device to associate with the access point device, including:

[0223] When the verification information is the same as the certification information, the station device directly associates with the access point device by sending an association request frame; and / or when the verification information is different from the certification information, the station device associates with the access point device by initial access;

[0224] The verification information is determined based on the first secret information and time information of the site device.

[0225] In some embodiments, the verification information is different from the certification information when the access point device performs a system reset.

[0226] In some embodiments, the verification information is determined based on the first secret information and time information of the site device, including:

[0227] The verification information is determined based on the following formula:

[0228] Verify_ID'=HASH(IV||Time STA ) m ;

[0229] Among them, Verify_ID' represents the verification information, IV represents the first secret information, Time STA Indicates the time information of the site device, || indicates string concatenation, HASH(X) indicates hashing the parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

[0230] In some embodiments, the time information of the site device is determined based on the system time of the site device and the time interval for the access point device to update the certification information.

[0231] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the site device is determined based on the following formula: Time STA =[D:H:M:(S mod T)] STA ;

[0232] When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the site device is determined based on the following formula: TimeSTA =[D:H:(M mod T')] STA ;

[0233] Among them, Time STA Indicates the time information of the site device, [D:H:M:S] STA Indicates the system time of the site device, D indicates date, H indicates hour, M indicates minute, S indicates second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0234] In some embodiments, the time information of the site device is determined based on the system time of the site device, the time interval for the access point device to update the certification information, and the error value between the system time of the site device and the system time of the access point device.

[0235] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the site device is determined based on the following formula: Time STA =[D':H':M':(S'mod T)];

[0236] When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the site device is determined based on the following formula: Time STA =[D':H':(M'mod T')];

[0237] Among them, Time STA Indicates the time information of the site device. [D':H':M':S'] indicates the time obtained by subtracting the error value from the system time of the site device. D' indicates the date, H' indicates the hour, M' indicates the minute, S' indicates the second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0238] In some embodiments, the error value is determined based on a system time of the station device and a system time of the access point device.

[0239] In some embodiments, before the access point device sends the first frame and after the station device initially accesses the access point device, the communication unit 410 is further configured to send a second frame;

[0240] The second frame includes at least one of the following: a time interval for the access point device to update the certification information, and a system time of the access point device.

[0241] In some embodiments, the second frame includes a first time presence field and a second time presence field;

[0242] The first time existence field is used to indicate whether the first time field exists in the second frame, and the second time existence field is used to indicate whether the second time field exists in the second frame;

[0243] The first time field is used to indicate the time interval for the access point device to update the certification information, and the second time field is used to indicate the system time of the access point device.

[0244] In some embodiments, the time interval for the access point device to update the certification information and / or the system time of the access point device included in the second frame are encrypted by the access point device.

[0245] In some embodiments, the second frame is a management frame, or the second frame is a control frame.

[0246] In some embodiments, the access point device 400 further includes:

[0247] The processing unit 420 is configured to determine the certification information according to the following formula:

[0248] Verify_ID=HASH(IV||Time AP ) m ;

[0249] Among them, Verify_ID represents the proof information, IV represents the first secret information, Time AP Indicates the time information of the access point device, || indicates string concatenation, HASH(X) indicates hashing the parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

[0250] In some embodiments, the m bits are m bits intercepted from the result of HASH(X) in the first order.

[0251] In some embodiments, the first order is from front to back, or the first order is from back to front.

[0252] In some embodiments, the time information of the access point device is determined based on the system time of the access point device and the time interval for the access point device to update the certification information.

[0253] In some embodiments, when the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the access point device is determined based on the following formula: AP=[D:H:M:(S mod T)] AP ;

[0254] When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the access point device is determined based on the following formula: Time AP =[D:H:(M mod T')] AP ;

[0255] Among them, Time AP Indicates the time information of the access point device, [D:H:M:S] AP Indicates the system time of the access point device, D indicates the date, H indicates the hour, M indicates the minute, S indicates the second, and T indicates the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

[0256] In some embodiments, the first secret information is a secret value shared between the access point device and an associated station device.

[0257] In some embodiments, the first secret information is a pre-shared key PSK or a simultaneous authentication of peers SAE key; or,

[0258] The first secret information is a key derived from the PSK or SAE key.

[0259] In some embodiments, the first secret information is agreed upon by a protocol, or the first secret information is determined by negotiation between the station device and the access point device, or the first secret information is configured by the access point device.

[0260] In some embodiments, the first frame includes a certification information element;

[0261] The certification information element includes a certification field, and the certification field is used to indicate the certification information.

[0262] In some embodiments, the first frame is a beacon frame, or the first frame is a probe response frame.

[0263] In some embodiments, the communication unit may be a communication interface or a transceiver, or an input / output interface of a communication chip or a system on chip. The processing unit may be one or more processors.

[0264] It should be understood that the access point device 400 according to the embodiment of the present application may correspond to the access point device in the embodiment of the method of the present application, and the above-mentioned and other operations and / or functions of each unit in the access point device 400 are respectively for implementing the corresponding process of the access point device in the method 200 shown in FIG. 2 , and for the sake of brevity, they are not further described here.

[0265] Figure 9 is a schematic structural diagram of a communication device 500 provided in an embodiment of the present application. The communication device 500 shown in Figure 9 includes a processor 510, which can call and run a computer program from a memory to implement the method in the embodiment of the present application.

[0266] In some embodiments, as shown in FIG9 , the communication device 500 may further include a memory 520. The processor 510 may call and execute a computer program from the memory 520 to implement the method in the embodiment of the present application.

[0267] The memory 520 may be a separate device independent of the processor 510 , or may be integrated into the processor 510 .

[0268] In some embodiments, as shown in FIG9 , the communication device 500 may further include a transceiver 530 , and the processor 510 may control the transceiver 530 to communicate with other devices, specifically, to send information or data to other devices, or to receive information or data sent by other devices.

[0269] The transceiver 530 may include a transmitter and a receiver. The transceiver 530 may further include an antenna, and the number of antennas may be one or more.

[0270] In some embodiments, the processor 510 may implement the functions of a processing unit in a station device, or the processor 510 may implement the functions of a processing unit in an access point device, which will not be described in detail here for the sake of brevity.

[0271] In some embodiments, the transceiver 530 may implement the function of a communication unit in a station device, which will not be described in detail here for the sake of brevity.

[0272] In some embodiments, the transceiver 530 may implement the functionality of a communication unit in an access point device, which will not be described in detail herein for the sake of brevity.

[0273] In some embodiments, the communication device 500 may specifically be an access point device in the embodiments of the present application, and the communication device 500 may implement the corresponding processes implemented by the access point device in the various methods in the embodiments of the present application, which will not be described in detail here for the sake of brevity.

[0274] In some embodiments, the communication device 500 may specifically be a site device in an embodiment of the present application, and the communication device 500 may implement the corresponding processes implemented by the site device in each method in the embodiment of the present application. For the sake of brevity, they will not be repeated here.

[0275] Figure 10 is a schematic structural diagram of an apparatus according to an embodiment of the present application. The apparatus 600 shown in Figure 10 includes a processor 610, which can call and execute a computer program from a memory to implement the method according to the embodiment of the present application.

[0276] In some embodiments, as shown in FIG10 , the apparatus 600 may further include a memory 620. The processor 610 may call and execute a computer program from the memory 620 to implement the method in the embodiment of the present application.

[0277] The memory 620 may be a separate device independent of the processor 610 , or may be integrated into the processor 610 .

[0278] In some embodiments, the processor 610 may implement the functions of a processing unit in a station device, or the processor 610 may implement the functions of a processing unit in an access point device, which will not be described in detail here for the sake of brevity.

[0279] In some embodiments, the apparatus 600 may further include an input interface 630. The processor 610 may control the input interface 630 to communicate with other devices or chips, and specifically, may obtain information or data sent by other devices or chips. Optionally, the processor 610 may be located inside or outside the chip.

[0280] In some embodiments, the input interface 630 may implement the functionality of a communication unit in a station device, or the input interface 630 may implement the functionality of a communication unit in an access point device.

[0281] In some embodiments, the apparatus 600 may further include an output interface 640. The processor 610 may control the output interface 640 to communicate with other devices or chips, and specifically, may output information or data to other devices or chips. Optionally, the processor 610 may be located inside or outside the chip.

[0282] In some embodiments, the output interface 640 may implement the functionality of a communication unit in a station device, or the output interface 640 may implement the functionality of a communication unit in an access point device.

[0283] In some embodiments, the apparatus may be applied to the access point device in the embodiments of the present application, and the apparatus may implement the corresponding processes implemented by the access point device in the various methods in the embodiments of the present application, which will not be described in detail here for the sake of brevity.

[0284] In some embodiments, the apparatus may be applied to the site equipment in the embodiments of the present application, and the apparatus may implement the corresponding processes implemented by the site equipment in the various methods in the embodiments of the present application. For the sake of brevity, they will not be described in detail here.

[0285] In some embodiments, the device mentioned in the embodiments of the present application may also be a chip, such as a system-on-chip, a system-on-chip, a chip system, or a system-on-chip chip.

[0286] FIG11 is a schematic block diagram of a communication system 700 provided in an embodiment of the present application. As shown in FIG11 , the communication system 700 includes a station device 710 and an access point device 720 .

[0287] The site device 710 may be used to implement the corresponding functions implemented by the site device in the above method, and the access point device 720 may be used to implement the corresponding functions implemented by the access point device in the above method, which will not be described in detail for the sake of brevity.

[0288] It should be understood that the processor of the embodiments of the present application may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method embodiment can be completed by hardware integrated logic circuits in the processor or software instructions. The above processor can be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components. The various methods, steps, and logic block diagrams disclosed in the embodiments of the present application can be implemented or executed. The general-purpose processor can be a microprocessor or any conventional processor. The steps of the method disclosed in the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or can be executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a storage medium mature in the art, such as random access memory, flash memory, read-only memory, programmable read-only memory, electrically erasable programmable memory, registers, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware.

[0289] It is understood that the memory in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM bus random access memory (DR RAM). It should be noted that the memory of the systems and methods described herein is intended to include, but is not limited to, these and any other suitable types of memory.

[0290] It should be understood that the above-mentioned memories are exemplary but not restrictive. For example, the memories in the embodiments of the present application may also be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct RAM RAM (DR RAM), etc. In other words, the memories in the embodiments of the present application are intended to include, but are not limited to, these and any other suitable types of memories.

[0291] An embodiment of the present application also provides a computer-readable storage medium for storing a computer program.

[0292] In some embodiments, the computer-readable storage medium can be applied to the access point device in the embodiments of the present application, and the computer program enables the computer to execute the corresponding processes implemented by the access point device in the various methods of the embodiments of the present application. For the sake of brevity, they are not described here.

[0293] In some embodiments, the computer-readable storage medium can be applied to the site device in the embodiments of the present application, and the computer program enables the computer to execute the corresponding processes implemented by the site device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.

[0294] An embodiment of the present application also provides a computer program product, including computer program instructions.

[0295] In some embodiments, the computer program product can be applied to the access point device in the embodiments of the present application, and the computer program instructions enable the computer to execute the corresponding processes implemented by the access point device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.

[0296] In some embodiments, the computer program product can be applied to the site device in the embodiments of the present application, and the computer program instructions enable the computer to execute the corresponding processes implemented by the site device in the various methods of the embodiments of the present application. For the sake of brevity, they are not repeated here.

[0297] The embodiment of the present application also provides a computer program.

[0298] In some embodiments, the computer program can be applied to the access point device in the embodiments of the present application. When the computer program runs on a computer, the computer executes the corresponding processes implemented by the access point device in the various methods of the embodiments of the present application. For the sake of brevity, they are not further described here.

[0299] In some embodiments, the computer program can be applied to the site device in the embodiments of the present application. When the computer program runs on a computer, the computer executes the corresponding processes implemented by the site device in the various methods of the embodiments of the present application. For the sake of brevity, they will not be repeated here.

[0300] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0301] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0302] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0303] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0304] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0305] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. In view of this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0306] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A wireless communication method, characterized in that: include: The station device receives a first frame, wherein the first frame includes certification information, and the certification information is determined based on the first secret information and time information of the access point device; When the service set identifier SSID in the first frame is an SSID to which the site device has been connected, the site device determines whether the access point device is disguised by another device based on the time information of the site device, the first secret information, and the certification information, or the site device associates the access point device based on the time information of the site device, the first secret information, and the certification information.

2. The method according to claim 1, wherein The station device determines whether the access point device is disguised by another device according to the time information of the station device, the first secret information, and the certification information, including: The site device determines verification information according to the first secret information and time information of the site device; When the verification information is identical to the certification information, the station device determines that the access point device is not disguised by another device; and / or when the verification information is different from the certification information, the station device determines that the access point device is disguised by another device.

3. The method according to claim 2, wherein The method further comprises: If the station device determines that the access point device is not disguised by another device, the station device sends an association request frame to the access point device.

4. The method according to claim 2, wherein The method further comprises: If the station device determines that the access point device is disguised by another device, the station device does not send an association request frame to the access point device, or the station device ignores the first frame.

5. The method according to claim 1, wherein The site device associating the access point device according to the time information of the site device, the first secret information, and the certification information, including: The site device determines verification information according to the first secret information and time information of the site device; When the verification information is the same as the certification information, the site device directly associates with the access point device by sending an association request frame; and / or when the verification information is different from the certification information, the site device associates with the access point device through initial access.

6. The method according to claim 5, wherein In a case where the access point device performs a system reset, the verification information is different from the certification information.

7. The method according to any one of claims 2 to 6, characterized in that The site device determines verification information according to the first secret information and the time information of the site device, including: The site device determines the verification information according to the following formula: Verify_ID'=HASH(IV||Time STA ) m ; Wherein, Verify_ID' represents the verification information, IV represents the first secret information, Time STA Indicates the time information of the site equipment, || indicates string concatenation, HASH(X) indicates performing a hash operation on parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

8. The method according to any one of claims 1 to 7, characterized in that The certification information is determined based on the following formula: Verify_ID=HASH(IV||Time AP ) m ; Among them, Verify_ID represents the certification information, IV represents the first secret information, Time AP Indicates the time information of the access point device, || indicates string concatenation, HASH(X) indicates performing a hash operation on parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

9. The method according to claim 7 or 8, wherein The m bits are m bits intercepted from the result of HASH(X) in the first order.

10. The method according to claim 9, wherein The first order is an order from front to back, or the first order is an order from back to front.

11. The method according to any one of claims 1 to 10, characterized in that The time information of the station device is determined based on the system time of the station device and the time interval for the access point device to update the certification information.

12. The method according to claim 11, wherein When the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the station device is determined based on the following formula: STA =[D:H:M:(S mod T)] STA ; When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the station device is determined based on the following formula: STA =[D:H:(M mod T')] STA ; Among them, Time STA Indicates the time information of the site equipment, [D:H:M:S] STA represents the system time of the site device, D represents date, H represents hour, M represents minute, S represents second, and T represents the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

13. The method according to any one of claims 1 to 10, characterized in that The time information of the station device is determined based on the system time of the station device, the time interval for the access point device to update the certification information, and the error value between the system time of the station device and the system time of the access point device.

14. The method according to claim 13, wherein When the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the station device is determined based on the following formula: STA =[D':H':M':(S'mod T)]; When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the station device is determined based on the following formula: STA =[D':H':(M'mod T')]; Among them, Time STA represents the time information of the site device, [D':H':M':S'] represents the time obtained by subtracting the error value from the system time of the site device, D' represents the date, H' represents the hour, M' represents the minute, S' represents the second, and T represents the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

15. The method according to claim 13 or 14, characterized in that The error value is determined based on the system time of the station device and the system time of the access point device.

16. The method according to any one of claims 11 to 15, characterized in that Before the site device receives the first frame, the method further includes: After initially accessing the access point device, the station device receives a second frame sent by the access point device; The second frame includes at least one of the following: a time interval for the access point device to update the certification information, and a system time of the access point device.

17. The method according to claim 16, wherein The second frame includes a first time presence field and a second time presence field; The first time existence field is used to indicate whether the first time field exists in the second frame, and the second time existence field is used to indicate whether the second time field exists in the second frame; The first time field is used to indicate the time interval for the access point device to update the certification information, and the second time field is used to indicate the system time of the access point device.

18. The method according to claim 16 or 17, wherein: The time interval for the access point device to update the certification information and / or the system time of the access point device included in the second frame are encrypted by the access point device.

19. The method according to any one of claims 16 to 18, characterized in that The second frame is a management frame, or the second frame is a control frame.

20. The method according to any one of claims 1 to 19, characterized in that The time information of the access point device is determined based on the system time of the access point device and a time interval for the access point device to update the certification information.

21. The method according to claim 20, wherein When the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the access point device is determined based on the following formula: AP =[D:H:M:(S mod T)] AP ; When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the access point device is determined based on the following formula: AP =[D:H:(M mod T')] AP ; Among them, Time AP Indicates the time information of the access point device, [D:H:M:S] AP represents the system time of the access point device, D represents the date, H represents the hour, M represents the minute, S represents the second, and T represents the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

22. The method according to any one of claims 1 to 21, characterized in that The first secret information is a secret value shared between the access point device and the associated station device.

23. The method according to claim 22, wherein The first secret information is a pre-shared key PSK or a simultaneous authentication of peers SAE key; or The first secret information is a key derived from a PSK or SAE key.

24. The method according to any one of claims 1 to 21, characterized in that The first secret information is agreed upon by a protocol, or the first secret information is determined by negotiation between the station device and the access point device, or the first secret information is configured by the access point device.

25. The method according to any one of claims 1 to 24, characterized in that The first frame includes a certification information element; The certification information element includes a certification field, and the certification field is used to indicate the certification information.

26. The method according to any one of claims 1 to 25, characterized in that The first frame is a beacon frame, or the first frame is a probe response frame.

27. A wireless communication method, characterized in that: include: The access point device sends a first frame, where the first frame includes authentication information, where the authentication information is determined based on first secret information and time information of the access point device; Among them, when the service set identifier SSID in the first frame is the SSID to which the site device has been connected, the certification information is used by the site device to determine whether the access point device is disguised by other devices, or the certification information is used by the site device to associate with the access point device.

28. The method of claim 27, wherein: The certification information is used by the site device to determine whether the access point device is disguised by another device, including: When the verification information is identical to the certification information, the station device determines that the access point device is not disguised by another device; and / or when the verification information is different from the certification information, the station device determines that the access point device is disguised by another device; The verification information is determined based on the first secret information and time information of the site device.

29. The method of claim 28, wherein The method further comprises: If the station device determines that the access point device is not disguised by another device, the access point device receives the association request frame sent by the station device.

30. The method of claim 27, wherein: The certification information is used for the site device to associate with the access point device, including: When the verification information is the same as the certification information, the station device directly associates with the access point device by sending an association request frame; and / or when the verification information is different from the certification information, the station device associates with the access point device by initial access; The verification information is determined based on the first secret information and time information of the site device.

31. The method of claim 30, wherein: In a case where the access point device performs a system reset, the verification information is different from the certification information.

32. The method according to any one of claims 28 to 31, wherein The verification information is determined based on the first secret information and the time information of the site device, including: The verification information is determined based on the following formula: Verify_ID'=HASH(IV||Time STA ) m ; Wherein, Verify_ID' represents the verification information, IV represents the first secret information, Time STA Indicates the time information of the site equipment, || indicates string concatenation, HASH(X) indicates performing a hash operation on parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

33. The method according to any one of claims 28 to 32, wherein The time information of the station device is determined based on the system time of the station device and the time interval for the access point device to update the certification information.

34. The method of claim 33, wherein: When the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the station device is determined based on the following formula: STA =[D:H:M:(S mod T)] STA ; When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the station device is determined based on the following formula: STA =[D:H:(M mod T')] STA ; Among them, Time STA Indicates the time information of the site equipment, [D:H:M:S] STA represents the system time of the site device, D represents date, H represents hour, M represents minute, S represents second, and T represents the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

35. The method according to any one of claims 28 to 32, wherein The time information of the station device is determined based on the system time of the station device, the time interval for the access point device to update the certification information, and the error value between the system time of the station device and the system time of the access point device.

36. The method of claim 35, wherein: When the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the station device is determined based on the following formula: STA =[D':H':M':(S'mod T)]; When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the station device is determined based on the following formula: STA =[D':H':(M'mod T')]; Among them, Time STA represents the time information of the site device, [D':H':M':S'] represents the time obtained by subtracting the error value from the system time of the site device, D' represents the date, H' represents the hour, M' represents the minute, S' represents the second, and T represents the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

37. The method according to claim 35 or 36, wherein The error value is determined based on the system time of the station device and the system time of the access point device.

38. The method according to any one of claims 33 to 37, wherein Before the access point device sends the first frame, the method further includes: After the station device initially accesses the access point device, the access point device sends a second frame; The second frame includes at least one of the following: a time interval for the access point device to update the certification information, and a system time of the access point device.

39. The method of claim 38, wherein The second frame includes a first time presence field and a second time presence field; The first time existence field is used to indicate whether the first time field exists in the second frame, and the second time existence field is used to indicate whether the second time field exists in the second frame; The first time field is used to indicate the time interval for the access point device to update the certification information, and the second time field is used to indicate the system time of the access point device.

40. The method according to claim 38 or 39, wherein The time interval for the access point device to update the certification information and / or the system time of the access point device included in the second frame are encrypted by the access point device.

41. The method according to any one of claims 38 to 40, wherein The second frame is a management frame, or the second frame is a control frame.

42. The method according to any one of claims 27 to 41, wherein The method further comprises: The access point device determines the certification information according to the following formula: Verify_ID=HASH(IV||Time AP ) m ; Among them, Verify_ID represents the certification information, IV represents the first secret information, Time AP Indicates the time information of the access point device, || indicates string concatenation, HASH(X) indicates performing a hash operation on parameter X, HASH(X) m Indicates extracting m bits from the result of HASH(X), where m is a positive integer.

43. The method according to claim 32 or 42, wherein: The m bits are m bits intercepted from the result of HASH(X) in the first order.

44. The method of claim 43, wherein: The first order is an order from front to back, or the first order is an order from back to front.

45. The method according to any one of claims 27 to 44, wherein The time information of the access point device is determined based on the system time of the access point device and a time interval for the access point device to update the certification information.

46. ​​The method of claim 45, wherein When the time interval for the access point device to update the certification information is less than 60 seconds, the time information of the access point device is determined based on the following formula: AP =[D:H:M:(S mod T)] AP ; When the time interval for the access point device to update the certification information is greater than or equal to 60 seconds, the time information of the access point device is determined based on the following formula: AP =[D:H:(M mod T')] AP ; Among them, Time AP Indicates the time information of the access point device, [D:H:M:S] AP represents the system time of the access point device, D represents the date, H represents the hour, M represents the minute, S represents the second, and T represents the time interval for the access point device to update the certification information. Indicates rounding up, and mod indicates modulo operation.

47. The method according to any one of claims 27 to 46, wherein The first secret information is a secret value shared between the access point device and the associated station device.

48. The method of claim 47, wherein The first secret information is a pre-shared key PSK or a simultaneous authentication of peers SAE key; or The first secret information is a key derived from a PSK or SAE key.

49. The method according to any one of claims 27 to 46, wherein The first secret information is agreed upon by a protocol, or the first secret information is determined by negotiation between the station device and the access point device, or the first secret information is configured by the access point device.

50. The method according to any one of claims 27 to 49, wherein The first frame includes a certification information element; The certification information element includes a certification field, and the certification field is used to indicate the certification information.

51. The method according to any one of claims 27 to 50, wherein The first frame is a beacon frame, or the first frame is a probe response frame.

52. A site device, characterized in that: include: a communication unit and a processing unit; The communication unit is configured to receive a first frame, wherein the first frame includes certification information, and the certification information is determined based on first secret information and time information of an access point device; When the service set identifier SSID in the first frame is an SSID to which the site device has been connected, the processing unit is configured to determine whether the access point device is disguised by another device based on the time information of the site device, the first secret information, and the certification information, or to associate the access point device based on the time information of the site device, the first secret information, and the certification information.

53. An access point device, characterized in that: include: a communication unit, configured to send a first frame, wherein the first frame includes certification information, wherein the certification information is determined based on first secret information and time information of the access point device; Among them, when the service set identifier SSID in the first frame is the SSID to which the site device has been connected, the certification information is used by the site device to determine whether the access point device is disguised by other devices, or the certification information is used by the site device to associate with the access point device.

54. A site device, characterized in that: include: A processor and a memory, the memory being used to store a computer program, the processor being used to call and run the computer program stored in the memory, so that the station device executes the method according to any one of claims 1 to 26.

55. An access point device, characterized in that: include: A processor and a memory, the memory being used to store a computer program, the processor being used to call and run the computer program stored in the memory, so that the access point device executes the method according to any one of claims 27 to 51.

56. A chip, characterized in that include: A processor, configured to call and run a computer program from a memory, so that a device equipped with the chip executes the method according to any one of claims 1 to 26.

57. A chip, characterized in that: include: A processor, configured to call and execute a computer program from a memory, so that a device equipped with the chip executes a method as claimed in any one of claims 27 to 51.

58. A computer-readable storage medium, characterized in that For storing a computer program, when the computer program is executed, the method according to any one of claims 1 to 26 is implemented.

59. A computer-readable storage medium, characterized in that For storing a computer program, when the computer program is executed, the method according to any one of claims 27 to 51 is implemented.

60. A computer program product, characterized in that The method comprises computer program instructions, which, when executed, implement the method according to any one of claims 1 to 26.

61. A computer program product, characterized in that The method comprises computer program instructions which, when executed, implement the method according to any one of claims 27 to 51.

62. A computer program, characterized in that When the computer program is executed, the method according to any one of claims 1 to 26 is implemented.

63. A computer program, characterized in that When the computer program is executed, the method according to any one of claims 27 to 51 is implemented.