Method for wirelessly identifying wireless access point based on event log and electronic equipment

By obtaining the signal strength and event logs between the test terminal and the wireless access point, and combining the device status file to match and trustworthiness determination, the automation and non-invasive problems of wireless access point recognition are solved, and efficient and accurate AP device recognition is achieved.

CN120529352AActive Publication Date: 2025-08-22ARTIFICIAL INTELLIGENCE RES INST OF HEFEI COMPREHENSIVE NAT SCI CENT (ANHUI ARTIFICIAL INTELLIGENCE LAB)
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202511014573.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-23
Publication Date
2025-08-22
Estimated Expiration
2045-07-23

AI Technical Summary

Technical Problem

In the prior art, wireless access point (AP) equipment identification lacks automated verification methods, and requires modification of equipment or invasive operations, resulting in low recognition efficiency and high cost, making it difficult to implement in scenarios without control permission.

Method used

By obtaining the test received signal strength indicator value and event log of the test terminal and the wireless access point to be identified, matching and credibility determination are performed in combination with the device status file, and the identification results are supplemented by geographical location information to achieve non-invasive recognition.

Benefits of technology

It improves the efficiency and accuracy of AP device identification, adapts to different network density and coverage conditions, takes into account accuracy and convenience, and reduces deployment costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120529352A_ABST
    Figure CN120529352A_ABST
Patent Text Reader

Abstract

The invention provides a method for wirelessly identifying a wireless access point based on an event log and electronic equipment, which can be applied to the technical field of wireless network management and equipment identification. The method comprises the following steps: in response to an identification request for identifying a wireless access point, acquiring a test received signal strength indication value between a test terminal in a moving state and a to-be-identified wireless access point and a test event log related to the test terminal and the to-be-identified wireless access point; matching the test event log with an equipment state file to obtain an initial equipment identification result of the wireless access point to be identified; according to a wireless communication mode between the test terminal and the to-be-identified wireless access point, determining the credibility of the initial equipment identification result based on the test received signal strength indication value, and obtaining a target equipment identification result; and supplementing the identification result of the target equipment according to the geographical location information of the wireless access point to obtain an identification result of the wireless access point.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of wireless network management and device identification, and in particular to a method for wirelessly identifying wireless access points based on event logs and electronic equipment. Background Art

[0002] With the widespread adoption of wireless networks, wireless access points (APs) are being deployed on a large scale across campuses. Network administrators need to verify the identity, location, and compliance of APs to ensure stable network operation and security. However, current AP identification methods lack automated verification methods and may require AP device modification or intrusive methods like serial port reading, reducing AP identification efficiency. Summary of the Invention

[0003] In view of the above problems, the present invention provides a method and electronic device for wirelessly identifying wireless access points based on event logs, which improve the efficiency of identifying AP devices.

[0004] One aspect of the present invention provides a method for wirelessly identifying a wireless access point based on an event log, comprising: obtaining, in response to an identification request for identifying a wireless access point, a test received signal strength indicator (RSSI) value between a test terminal and a wireless access point to be identified in a mobile state and a test event log related to the test terminal and the wireless access point to be identified; matching the test event log with a device status file to obtain an initial device identification result for the wireless access point to be identified, the device status file including access status information of the wireless access point to be identified; determining, based on a wireless communication mode between the test terminal and the wireless access point to be identified, a credibility of the initial device identification result based on the RSSI value, and obtaining a target device identification result; wherein, if the wireless communication mode indicates wireless access and the credibility of the initial device identification result meets a predetermined value, the initial device identification result is used as the target device identification result; or if the wireless communication mode indicates no wireless access, the initial device identification results are sorted based on the credibility of the initial device identification results, and a target device identification result that meets a predetermined credibility condition is selected from the sorted initial device identification results; and supplementing the target device identification result based on geographic location information of the wireless access point to obtain an identification result for the wireless access point.

[0005] According to an embodiment of the present invention, a device status file includes a real-time status file of a user terminal and a real-time status file of a wireless access point cluster. The user terminal includes a test terminal, and the wireless access point cluster includes wireless access points to be identified. The device status file is obtained by: standardizing an initial event log of the user terminal accessing the wireless access point cluster forwarded by a wireless controller to obtain a standardized event log, wherein the initial event log includes a test event log; modifying the standardized event log to obtain an access relationship between the user terminal and the wireless access point cluster; and constructing the real-time status file of the user terminal and the real-time status file of the wireless access point cluster based on the access relationship, using the hardware address of the user terminal and the hardware address of the wireless access point in the wireless access point cluster as primary keys, respectively.

[0006] According to an embodiment of the present invention, a standardized event log is modified to obtain an access relationship between a user terminal and a wireless access point cluster. The method includes: constructing a sliding time window using the hardware address of the user terminal as a unit, and generating a behavior chain based on the event log within the sliding time window; repairing the behavior chain to obtain a repaired behavior chain; performing a rationality test on the repaired behavior chain to obtain a test result; and processing the repaired behavior chain based on the test result to obtain the access relationship between the user terminal and the wireless access point cluster.

[0007] According to an embodiment of the present invention, a behavior chain is repaired to obtain a repaired behavior chain, including: identifying the behavior chain that has undergone fault tolerance processing to obtain a target behavior chain; in the case where a predetermined number of event logs are missing in the target behavior chain, logical completion is performed based on the semantics of the target behavior chain to obtain a repaired behavior chain.

[0008] According to an embodiment of the present invention, based on a detection result, a repair behavior chain is processed to obtain an access relationship between a user terminal and a wireless access point cluster, including: if the detection result indicates that the user terminal connected to m1 different wireless access points within a predetermined time period, marking the user terminal with a predefined semantic label to obtain processed user terminal information, where m1 is greater than or equal to 0; if the detection result indicates that the user terminal simultaneously accessed m2 wireless access points at different physical locations, selecting a wireless access point with a maximum received signal strength indicator value with the user terminal from among the m2 wireless access points to obtain processed wireless access point information, where m2 is an integer greater than 1; and establishing an access relationship between the user terminal and the wireless access point cluster based on the processed user terminal information and the processed wireless access point information.

[0009] According to an embodiment of the present invention, a test event log includes a hardware address of a test terminal; matching the test event log with a device status file to obtain an initial device identification result of a wireless access point to be identified includes: matching the hardware address of the test terminal with a real-time status file of a user terminal to obtain the hardware address of the wireless access point to be identified; matching the hardware address of the wireless access point to be identified with a real-time status file of a wireless access point cluster to obtain a device name of the wireless access point to be identified; and obtaining an initial device result based on the hardware address and device name of the wireless access point to be identified.

[0010] According to an embodiment of the present invention, the reliability of an initial device identification result is determined based on a test received signal strength indicator value according to a wireless communication mode between a test terminal and a wireless access point to be identified. The method includes: determining the reliability of the initial device identification result based on a test received signal strength indicator value between the test terminal and the wireless access point to be identified, a changing trend of the test received signal strength indicator value, interaction between the test terminal and the wireless access point to be identified, and a behavior pattern of the test terminal when the wireless communication mode indicates wireless access has been established; and determining the reliability of the initial device identification result based on a test received signal strength indicator value between the test terminal and the wireless access point to be identified, and a changing trend of the test received signal strength indicator value when the wireless communication mode indicates no wireless access has been established.

[0011] According to an embodiment of the present invention, when the wireless communication mode indicates no wireless access, the method further includes: using an application installed on the test terminal to scan a surrounding wireless access point cluster in a surrounding area to obtain hardware addresses of the surrounding wireless access point cluster and test received signal strength indicator values ​​of the test terminal and wireless access points in the surrounding wireless access point cluster, wherein the surrounding area includes a spherical area with the test terminal as the center and a predetermined radius.

[0012] According to an embodiment of the present invention, the method further includes: filling the information in the identification result of the wireless access point into an information display template according to the type of information in the identification result of the wireless access point to obtain an information display label; and displaying the information display label in a predetermined image file.

[0013] Another aspect of the present invention provides an electronic device, comprising: one or more processors; a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.

[0014] An embodiment of the present invention provides a method for wirelessly identifying wireless access points based on event logs. In response to an identification request, the method obtains a test received signal strength indicator (RSSI) value and a test event log between a test terminal and a wireless access point to be identified while in motion. The test event log is matched with a device status file to obtain an initial device identification result. The credibility of the initial device identification result is determined based on the RSSI value according to the wireless communication method between the test terminal and the wireless access point to obtain a target device identification result. The target device identification result is then populated based on the geographic location of the wireless access point to obtain an identification result. Since the wireless access point to be identified can be identified regardless of whether the test terminal is wirelessly connected to the wireless access point, these two identification methods balance accuracy and convenience, adapting to varying network densities and coverage conditions. Furthermore, the reliability of the initial device identification result is automatically verified based on the RSSI value, and when multiple initial device identification results are available, the target device identification result is determined based on credibility ranking, effectively improving the efficiency of AP device identification. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] The above contents and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings, in which:

[0016] Figure 1 The diagram shows an application scenario of a method for wirelessly identifying wireless access points based on event logs according to an embodiment of the present invention.

[0017] Figure 2 A flow chart of a method for wirelessly identifying a wireless access point based on an event log according to an embodiment of the present invention is shown.

[0018] Figure 3 The figure shows the installation location of the AP device.

[0019] Figure 4 The information obtained in the scenario where the test terminal has been connected to or can be connected to the AP device to be identified is shown.

[0020] Figure 5 The information obtained in the scenario where the test terminal is not connected to or cannot be connected to the AP device to be identified is shown.

[0021] Figure 6A The image file shows the distribution of the original AP devices.

[0022] Figure 6B A schematic diagram showing information display labels on an interface of a visual management system according to an embodiment of the present invention is shown.

[0023] Figure 7The diagram shows an architecture of a method for wirelessly identifying wireless access points based on event logs according to an embodiment of the present invention.

[0024] Figure 8 FIG. 2 shows a structural block diagram of a device for wirelessly identifying a wireless access point based on an event log according to an embodiment of the present invention.

[0025] Figure 9 FIG2 is a block diagram of an electronic device suitable for implementing a method for wirelessly identifying a wireless access point based on an event log according to an embodiment of the present invention. DETAILED DESCRIPTION

[0026] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present invention. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of embodiments of the present invention. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concept of the present invention.

[0027] The terms used herein are only for describing specific embodiments and are not intended to limit the present invention. The terms "comprise", "include", etc. used herein indicate the presence of the features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components.

[0028] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.

[0029] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).

[0030] With the large-scale deployment of AP devices, network administrators need to identify and conduct compliance audits to ensure stable network operation and security. However, current methods for identifying AP devices have the following limitations: First, they rely on physical tags and manual registration, lacking automated verification methods; second, they require high hardware and software compatibility, requiring specialized collection tools or customized firmware, resulting in high deployment costs; and third, accessing device information through methods such as modifying the AP serial port and using the Simple Network Management Protocol (SNMP) is somewhat invasive and difficult to implement in scenarios where control permissions are not available.

[0031] Currently, mainstream wireless access controllers (ACs) have the ability to output terminal access logs, recording terminal login, roaming, authentication, and other behaviors. These logs are forwarded to logging platforms via methods such as the system log protocol (syslog), forming a low-cost, widely available behavioral data source. In existing networks, these system logs are primarily used for auditing purposes and are underutilized for identifying AP devices themselves. Furthermore, due to the coarse log granularity (typically at the second level) and the limitations of the User Datagram Protocol (UDP) transmission, log transmission can suffer from out-of-order events, packet loss, and latency, posing challenges to log-based behavior reconstruction and device identification. Therefore, building a stable and reliable AP identification mechanism, while addressing the challenges of coarse log granularity, uncontrollable networks, and heterogeneous devices, and integrating it with mobile terminals to implement on-site AP identification and tag matching, remains a key challenge in wireless network operations and maintenance, as well as intelligent identification.

[0032] In light of this, embodiments of the present invention provide a method for wirelessly identifying wireless access points based on event logs. Leveraging terminal (STA) access event logs generated by an AC, this method enables non-intrusive wireless identification of APs without requiring AP modification or hardware data collection, thereby improving the efficiency and accuracy of AP identification. This method integrates log analysis, behavioral modeling, and mobile-end collaboration mechanisms, making it applicable to AP management, operation and maintenance, and security auditing scenarios across a variety of heterogeneous networks.

[0033] Figure 1 The diagram shows an application scenario of a method for wirelessly identifying wireless access points based on event logs according to an embodiment of the present invention.

[0034] like Figure 1As shown, the application scenario 100 according to this embodiment may include a user terminal 101, an AP device cluster 102, and a server 103. The user terminal 101 may interact with the server 103 by wirelessly communicating with any AP device in the AP device cluster 102.

[0035] User terminal 101 can be any electronic device with a display and web browsing support, including but not limited to smartphones, tablet computers, laptops, and desktop computers. User terminal 101 can be installed with various communication client applications, such as applications for identifying AP devices, shopping applications, web browser applications, search applications, instant messaging tools, email clients, social networking platform software, etc. (These are just examples). The terminal device in user terminal 101 can also serve as a test terminal to identify AP devices in AP device cluster 102 and transmit the information obtained during the identification process to server 103. Server 103 processes the information to obtain wireless access point identification results and returns the identification results to the user terminal.

[0036] It should be noted that the method for wirelessly identifying wireless access points based on event logs provided in the embodiments of the present invention can generally be executed by the server 103. Accordingly, the apparatus for wirelessly identifying wireless access points based on event logs provided in the embodiments of the present invention can generally be located in the server 103. The method for wirelessly identifying wireless access points based on event logs provided in the embodiments of the present invention can also be executed by a server or server cluster that is different from the server 103 and that is capable of communicating with the user terminal 101, the AP device cluster 102, and / or the server 103. Accordingly, the apparatus for wirelessly identifying wireless access points based on event logs provided in the embodiments of the present invention can also be located in a server or server cluster that is different from the server 103 and that is capable of communicating with the user terminal 101, the AP device cluster 102, and / or the server 103.

[0037] It should be understood that Figure 1 The numbers of the user terminals, AP device clusters, AP devices, and servers in the embodiment are merely illustrative. Any number of user terminals, AP device clusters, AP devices, and servers may be provided as required.

[0038] The following will be based on Figure 1 The scene described by Figures 2 to 6B A method for wirelessly identifying a wireless access point based on an event log according to an embodiment of the present invention is described in detail.

[0039] Figure 2 A flow chart of a method for wirelessly identifying a wireless access point based on an event log according to an embodiment of the present invention is shown.

[0040] like Figure 2As shown, the method for wirelessly identifying a wireless access point based on an event log in this embodiment includes operations S210 to S240.

[0041] In operation S210, in response to an identification request for identifying a wireless access point, a test received signal strength indicator value between the test terminal in a moving state and the wireless access point to be identified and a test event log related to the test terminal and the wireless access point to be identified are obtained.

[0042] In operation S220, the test event log is matched with the device status file to obtain an initial device identification result of the wireless access point to be identified. The device status file includes access status information of the wireless access point to be identified.

[0043] In operation S230 , the reliability of the initial device identification result is determined based on the test received signal strength indicator value according to the wireless communication mode between the test terminal and the wireless access point to be identified, and the target device identification result is obtained.

[0044] When the wireless communication mode indicates wireless access, there is one wireless access point to be identified. When the credibility of the initial device identification result meets a predetermined value, the initial device identification result is used as the target device identification result.

[0045] When the wireless communication mode indicates no wireless access, there are at least two wireless access points to be identified, the initial device identification results are sorted according to their credibility, and a target device identification result that meets a predetermined credibility condition is selected from the sorted results of the initial device identification results.

[0046] In operation S240 , the target device identification result is supplemented according to the geographical location information of the wireless access point to obtain an identification result of the wireless access point.

[0047] In some embodiments, an AP device is a hardware device that implements Wireless Fidelity (Wi-Fi). Wi-Fi technology requires an AP (or a router with integrated AP functionality) to provide wireless network services. A Wi-Fi network can consist of a single AP device (such as in a home scenario) or multiple AP devices (such as in an enterprise deployment), covering different areas. An AP device is a physical device responsible for providing wireless access; Wi-Fi is a technical standard that specifies the implementation of wireless communication. AP devices use the Wi-Fi protocol to connect devices to the Internet wirelessly, and the widespread use of Wi-Fi relies on the deployment of AP devices. Wi-Fi and AP devices together form the foundation of wireless networks.

[0048] Figure 3 The figure shows the installation location of the AP device.

[0049] In some embodiments, the installation location of the AP device can be as follows: Figure 3 As shown, it is installed on the ceiling. Lights for lighting and signal lights for indicating wireless signals can also be deployed around the AP device. Using the method provided by the embodiment of the present invention, it is possible to realize the non-sensing collection of AP device data on the ground, improving the convenience of identifying AP devices.

[0050] In some embodiments, an identification request can be an event or instruction initiated by a test STA or management system to identify an AP device. For example, a target object (e.g., a user or intelligent robot) needs to identify the AP device information at location D. They can move to location D based on a map showing that location and click a button to connect or scan for nearby Wi-Fi or AP devices to trigger the identification request. In another embodiment, the identification request can be triggered by periodic inspections of network devices based on a scheduled task of the management system. In yet another embodiment, the identification request can be triggered by detecting a signal from a newly added AP device.

[0051] In some embodiments, the test STA may be a movable STA device used to collect information of the wireless access point to be identified, such as a mobile phone and a laptop computer.

[0052] In some embodiments, the AP to be identified may be an AP device that needs to be identified. For example, if information about the AP device at position D is desired, the AP to be identified may be any AP device in the AP device cluster at position D.

[0053] In some embodiments, the Received Signal Strength Indicator (RSSI) value can indicate the signal strength between the test STA and the AP to be identified. A larger RSSI value indicates a greater signal strength and a closer distance between the test STA and the AP to be identified. By moving the test STA, multiple test RSSI values ​​can be obtained.

[0054] In some embodiments, the test event log may be an event log related to the test STA and the AP device to be identified. For example, when the test STA accesses the AP device to be identified, the test event log may be an event log between the test STA and the AP device to be identified. The test event log may record online events, Internet Protocol (IP) allocation for interconnection between networks, and roaming events triggered by the test STA. The test log may include the test STA name, the test STA's hardware address (Media Access Control Address, MAC), online or offline events and timestamps, the device name of the AP device to be identified, and the MAC of the AP device to be identified. If the test STA is not connected to the AP device to be identified, the test event log may be an event log between the AP device to be identified and other STAs, including the MAC of the AP device to be identified and the MAC of other STAs that access the AP device to be identified.

[0055] In some embodiments, the device status file may include a real-time status file for a wireless access point cluster (e.g., an AP device status table) that describes the access status of an AP device. For example, this file, keyed by the AP MAC address, contains information about STAs connected to the AP (e.g., multiple STA MAC addresses, RSSIs, etc.), as well as the device name of the AP device. The device status file may also include a real-time status file for a user terminal (e.g., a STA status table). The STA status table, keyed by the STA MAC address, contains the MAC address of the connected AP and connection information such as the AP's RSSI.

[0056] In some embodiments, an initial device identification result may be obtained by matching the test event log with the device status file. The initial device identification result may include the device name and MAC of the AP device.

[0057] When the test STA accesses the AP device to be identified, you can directly go to the AP device status table to check the device name of the AP device to be identified based on the MAC of the AP device to be identified in the test event log; you can also go to the AP device status table to check the device name and MAC of the AP device to be identified based on the STAMAC in the test event log; you can also go to the STA status table to check the MAC of the AP device to be identified based on the STA MAC in the test event log, and go to the AP device status table to check the device name of the AP device to be identified based on the found MAC of the AP device to be identified.

[0058] When the test STA is not connected to the AP device to be identified, the application loaded on the test STA can scan the AP devices around the test STA and look up the device name of the AP device to be identified in the AP device status table based on the MAC address of the scanned AP device.

[0059] In some embodiments, a test STA and the AP to be identified can have two wireless connection modes: one in which the test STA and the AP to be identified are wirelessly connected or accessible. In the case of wireless access between the test STA and the AP to be identified, the relationship between the STA and the AP can be one-to-one. Alternatively, the test STA and the AP to be identified can be wirelessly disconnected or physically unavailable. In the case of wireless access between the test STA and the AP to be identified, the relationship between the STA and the AP can be one-to-many. Different connection modes can employ different identification methods to obtain AP identification results. In other words, embodiments of the present invention can identify AP device information and obtain identification results in both modes.

[0060] In some embodiments, the credibility of the initial device identification result may be determined based on the RSSI value to improve the accuracy of the initial device identification result.

[0061] For example, if the target object accesses AP1 through a test STA, but this AP1 may be the AP1 at location D, the target object has moved to location E, which is different from location D, but the AP1 accessed by the test STA has not yet switched to the AP2 closest to location E. If the credibility of the AP device's initial device identification result is uncertain, even though the target object is at location E, continued identification using this AP1 may result in the AP1 at location D being mistaken for the AP2 at location E, leading to misjudgment. Therefore, the credibility of the initial device identification result must be determined.

[0062] The credibility of the initial device identification result can be determined based on the RSSI value. If the RSSI value between the test STA and AP2, which is closest to location E, is weaker than the RSSI value between the test STA and AP1, which is at location D, or if the RSSI value between the test STA and AP2 does not meet the predetermined value, this indicates that the AP the STA is currently connected to is not at location E, and the initial device identification result obtained using AP1 is unreliable. If the RSSI value between the test STA and AP2 meets the predetermined value, the initial device identification result obtained using AP1 is reliable. The predetermined value can be adjusted adaptively based on actual needs. By determining AP devices based on the credibility of RSSI values, identification accuracy can be improved.

[0063] In some embodiments, if the test STA is not connected to an AP, the test STA may scan multiple APs. By identifying these APs, multiple initial device identification results can be obtained. The credibility of the multiple initial device identification results can be determined based on the RSSI values ​​between the test STA and the multiple APs, and the initial device identification results can be ranked based on the credibility. The target device identification result can be the initial device identification result selected from the ranked initial device identification results that meets a predetermined credibility condition (e.g., the one with the highest credibility).

[0064] In some embodiments, the geographical location information of the AP device can be obtained from a map file. The identification result of the AP device can be obtained by supplementing the target device identification result obtained by the above operation with the geographical location information of the AP device.

[0065] An embodiment of the present invention provides a method for wirelessly identifying wireless access points based on event logs. In response to an identification request, the method obtains a test received signal strength indicator (RSSI) value and a test event log between a test terminal and a wireless access point to be identified while in motion. The test event log is matched with a device status file to obtain an initial device identification result. The credibility of the initial device identification result is determined based on the RSSI value according to the wireless communication method between the test terminal and the wireless access point to obtain a target device identification result. The target device identification result is then populated based on the geographic location of the wireless access point to obtain an identification result. Since the wireless access point to be identified can be identified regardless of whether the test terminal is wirelessly connected to the wireless access point, these two identification methods balance accuracy and convenience, adapting to varying network densities and coverage conditions. Furthermore, the reliability of the initial device identification result is automatically verified based on the RSSI value, and when multiple initial device identification results are available, the target device identification result is determined based on credibility ranking, effectively improving the efficiency of AP device identification.

[0066] In some embodiments, the device status file mentioned in the above operation can be updated in real time. The device status file includes the real-time status file of the user terminal (STA status table) and the real-time status file of the AP device cluster (AP device status table). The user terminal can be a terminal device connected to the AP device cluster. These terminal devices include not only test terminals for identifying AP devices, but also terminal devices that use AP devices. The AP device cluster includes not only AP devices to be identified by the test terminal, but also AP devices used by the user terminal. In some embodiments, the AP device to be identified can also be used by the user terminal, and the user terminal can also serve as an AP device. The user terminal can activate the hotspot signal.

[0067] In some embodiments, the device status file can be obtained in the following manner: standardize the initial event log of the user terminal accessing the AP device cluster forwarded by the wireless controller to obtain a standardized event log, the initial event log including the test event log; modify the standardized event log to obtain the access relationship between the user terminal and the wireless access point cluster; use the hardware address of the user terminal and the hardware address of the AP device in the AP device cluster as the primary keys, and construct a real-time status file of the user terminal and a real-time status file of the AP device cluster according to the access relationship.

[0068] In some embodiments, the initial event log may be an unprocessed STA access event log forwarded by an AC device, and may include an event log of a test terminal accessing an AP device to be identified. The server may support receiving STA access event logs forwarded by AC devices from various vendors. To account for differences in output formats between different AC devices, the server may parse multiple received initial event logs into a standardized field structure, extracting key fields such as the STA MAC address, AP MAC address, Service Set Identifier (SSID), event type (online, roaming, disconnection), timestamp, and interface information, and record them as a standard event entity to generate a standard event log.

[0069] In some embodiments, because AC devices only support the UDP protocol to retrieve STA event logs from a server, the actual process of obtaining the initial event logs may present the following issues: logs have second-level time accuracy (typically the local clock of the AP device or the AC's local time, with second granularity); STA events from multiple APs may have different timestamps and different transmission sources; UDP transmission is uncontrollable and subject to packet loss, out-of-order transmission, and delayed transmission; and the actual STA roaming process is very short (e.g., approximately 100ms on some ACs), while the log granularity is much coarser. Therefore, the present invention can avoid these issues by processing standardized event logs.

[0070] In some embodiments, the process of correcting the standardized event log to obtain the access relationship between the user terminal and the wireless access point cluster may include the following operations: constructing a sliding time window based on the hardware address of the user terminal, and generating a behavior chain based on the event log within the sliding time window; repairing the behavior chain to obtain a repaired behavior chain; performing a rationality test on the repaired behavior chain to obtain a test result; and processing the repaired behavior chain based on the test result to obtain the access relationship between the user terminal and the wireless access point cluster.

[0071] In some embodiments, the processing of standardized event logs can be divided into two processes: sliding window aggregation and fault-tolerant sorting, and behavioral semantic reasoning and confidence determination. Sliding window aggregation and fault-tolerant sorting can include constructing a sliding time window based on the hardware address of the user terminal, generating a behavior chain based on the event log within the sliding time window, and repairing the behavior chain to obtain a repaired behavior chain. Behavioral semantic reasoning and confidence determination can include performing a rationality test on the repaired behavior chain to obtain a test result; based on the test result, processing the repaired behavior chain to obtain an access relationship between the user terminal and the wireless access point cluster.

[0072] In some embodiments, for sliding window aggregation and fault-tolerant sorting, the server can construct a sliding time window (e.g., 3 to 5 seconds) based on STA MAC, collect all relevant log events within this time period (such as online, offline, roaming, IP switching, etc.), and form a local behavior chain.

[0073] In some embodiments, the process of repairing a behavior chain to obtain a repaired behavior chain may include the following operations: identifying the behavior chain that has undergone fault tolerance processing to obtain a target behavior chain; in the case where a predetermined number of event logs are missing in the target behavior chain, performing logical completion based on the semantics of the target behavior chain to obtain a repaired behavior chain.

[0074] In some embodiments, in order to deal with log disorder and time accuracy limitations, the server can re-arrange the event logs within the window according to time and semantic priority, and at the same time have a fault-tolerant mechanism. Specifically, fault-tolerant processing, for example, can tolerate event order dislocation, such as "the old AP device goes offline before the new AP device goes online." Typical behavior chains can be identified to obtain target behavior chains (such as a roaming process: "new AP device goes online → roaming → old AP device goes offline"); for target behavior chains that are missing a predetermined number of logs (for example, 1 to 2), "logical completion" is allowed based on the context of the target behavior chain to obtain a repair behavior chain. All state changes during these operations are "rollbackable" and support state repair driven by subsequent events.

[0075] In some embodiments, after the event chain is repaired, the server can determine the rationality of the behavior sequence based on predefined semantic tags (such as "roaming," "online," "handover," and "offline") and a finite state machine model, and obtain a test result. For example, the server can test whether the STA is connected to two different AP devices at the same time.

[0076] In some embodiments, the repair behavior chain is processed according to the detection result to obtain the access relationship between the user terminal and the wireless access point cluster, including: when the detection result indicates that the user terminal is connected to m1 different AP devices within a predetermined time period, the user terminal is marked as a predefined semantic label to obtain processed user terminal information, where m1 is greater than or equal to 0; when the detection result indicates that the user terminal simultaneously accesses m2 AP devices in different physical locations, among the m2 AP devices, the AP device with the largest received signal strength indication value with the user terminal is selected to obtain processed AP device information, where m2 is an integer greater than 1; based on the processed user terminal information and the processed AP device information, the access relationship between the user terminal and the wireless access point cluster is constructed.

[0077] In some embodiments, when m1 is equal to 0, that is, when the user terminal is not connected to the AP device within a predetermined time (for example, 2 seconds), the user terminal can be marked as a predefined semantic label (for example, offline) to obtain processed user terminal information.

[0078] In some embodiments, when m1 is equal to 1, that is, when the terminal is connected to a different AP device within a predetermined time (e.g., 2s), the terminal is marked as a predefined semantic tag (e.g., online) to obtain processed terminal information.

[0079] In some embodiments, when m1 is equal to 2, that is, when the terminal is connected to two different AP devices within a predetermined time (e.g., 2s), the terminal is marked as a predefined semantic tag (e.g., roaming) to obtain processed terminal information.

[0080] In some embodiments, when m2 equals 2, that is, when a user terminal simultaneously accesses two APs in different physical locations (e.g., two buildings), the AP with the highest RSSI value relative to the user terminal is selected and retained to obtain processed AP information. For example, multiple APs can be ranked by confidence based on behavior (e.g., duration of stay and association switching order) and RSSI signal strength, and the AP with the highest RSSI value can be selected to improve AP identification accuracy.

[0081] According to an embodiment of the present invention, the above-mentioned processing of the initial event log can restore the STA access status as much as possible even when the log is out of order or missing, without relying on high-precision timestamps, establish an accurate and reliable access relationship between the STA and the AP device, and improve the robustness and practicality of the wireless identification system.

[0082] In some embodiments, when the access relationship between the STA and the AP device is obtained, the MAC of the STA and the MAC of the AP device in the AP device cluster can be used as primary keys respectively, and the STA status table and the AP device status table can be constructed according to the access relationship.

[0083] In some embodiments, the server may use the AP MAC address and the STA MAC address as primary keys, respectively, to construct an AP device status table and a STA status table, so as to maintain bidirectional status information in the wireless network in real time.

[0084] The AP device status table can record the current access terminal list, active status, latest event time, SSID, deployment location, and tag information of each AP device.

[0085] The STA status table can record each STA's current or most recently associated AP device, state change records, roaming tracks, connection duration, and dynamic behaviors such as IP changes.

[0086] The dual-table structure of the AP device status table and the STA status table supports real-time updates based on event logs, forming the core data source for system identification, confidence calculation, and front-end display. These tables can be persistently stored in a database and provide high-performance external interfaces through caching components such as the Remote Dictionary Server (Redis). This supports application scenarios such as World Wide Web (Web) display, mobile identification linkage, and Application Programming Interface (API) queries.

[0087] According to embodiments of the present invention, by analyzing existing event log data from wireless controllers (ACs), no hardware modifications or firmware upgrades are required for AP devices, and no reliance is placed on underlying serial port control or SNMP access rights. This method enables non-invasive, "unnoticeable" data collection from existing network devices, ensuring zero network impact during deployment and excellent engineering feasibility. Furthermore, this method supports log input from multiple AC models and vendors. By enabling log standardization and dynamic parsing, it can integrate with a variety of log structures, demonstrating strong versatility and scalability, strong compatibility, and broad applicability.

[0088] According to an embodiment of the present invention, this method has out-of-order fault tolerance and high recognition accuracy. In response to the UDP packet loss and out-of-order problems in the log forwarding process, the embodiment of the present invention introduces a sliding window mechanism and a time-series fault-tolerant reasoning model to restore the actual access sequence and state transitions of the terminal as much as possible, ensuring the rigor and repeatability of the recognition logic. On the other hand, by maintaining a real-time device status table, it can dynamically reflect information such as the access terminal, active status, roaming relationship, etc. of the AP device, achieving near-real-time updates and queries, which is suitable for dynamic network monitoring and operation and maintenance scenarios, and realizing real-time identification and status tracking.

[0089] In some embodiments, the above-mentioned test event log may include the MAC of the test STA. The process of matching the test event log with the device status file mentioned in the above operation to obtain the initial device identification result of the wireless access point to be identified may include the following operations: matching the hardware address of the test terminal with the real-time status file of the user terminal to obtain the hardware address of the wireless access point to be identified; matching the hardware address of the wireless access point to be identified with the real-time status file of the wireless access point cluster to obtain the device name of the wireless access point to be identified; and obtaining the initial device result based on the hardware address of the wireless access point to be identified and the device name of the wireless access point to be identified.

[0090] In some embodiments, when a test STA is connected to or can access an AP to be identified, for example, after an application installed on the test STA actively connects to an AP to be identified, the server obtains the AP's MAC address based on the online, IP allocation, or roaming events triggered by the test STA and the STA status table. Based on the AP's MAC address, the server queries the AP's status table for the device name of the currently associated AP. The server then pushes the obtained AP's MAC address and device name to the test STA for identification or registration. This mode allows for more accurate AP identification because triggering and event changes are visible. However, it can be difficult to quickly access or distinguish APs when APs are densely populated or inaccessible locations.

[0091] Figure 4 The information obtained in the scenario where the test terminal has been connected to or can be connected to the AP device to be identified is shown.

[0092] like Figure 4As shown, in an application compatible with the method for wirelessly identifying wireless access points based on event logs according to an embodiment of the present invention, when a test STA is connected to or can connect to the AP device to be identified, the obtained content may include the mobile phone connection information (i.e., the test STA connection information), the STA's latest information in the STA-associated background status table, and the STA's recent offline information. The RSSI information in the mobile phone connection information, the STA's latest information, and the STA's recent offline information includes data from the STA to the AP, and from the AP to the STA, obtained in the background. The RSSI value is measured in dBm. The MAC in the mobile phone connection information, the STA's latest information, and the STA's recent offline information is the STA's MAC. In the mobile phone connection information, the STA's latest information, and the STA's recent offline information, "sta" and "STA" have the same meaning, and "ap" and "AP" have the same meaning.

[0093] In some embodiments, when the wireless communication mode indicates that there is no wireless access, the method may further include the following operations: using an application loaded on the test terminal to scan a surrounding wireless access point cluster in a surrounding area, obtaining a hardware address of the surrounding wireless access point cluster, and a test received signal strength indicator value between the test terminal and the wireless access points in the surrounding wireless access point cluster. The surrounding area may include a spherical area with the test terminal as the center and a predetermined size as the radius. The predetermined size may be adaptively adjusted according to actual needs.

[0094] In some embodiments, if a test STA cannot connect to the network or does not need to actually access the network, an application installed on the test terminal can scan the MAC and RSSI information of APs in the surrounding area and upload it to a server. The server then matches the AP's MAC address with the AP status table it maintains to obtain the AP's device name. Combining signal strength and trend analysis, the server infers the likelihood of the target AP and returns an identification result. This approach is highly efficient and adaptable, particularly suitable for scenarios with dense AP density or limited network connectivity, and serves as an effective complement to the connection mode.

[0095] Figure 5 The information obtained in the scenario where the test terminal is not connected to or cannot be connected to the AP device to be identified is shown.

[0096] An application matching the method for wirelessly identifying wireless access points based on event logs in an embodiment of the present invention can scan the AP MAC information and background AP tag information obtained from surrounding AP devices in the scenario where the test STA is not connected to or cannot access the AP device to be identified. Figure 5 As shown in the figure, because AP devices have multiple radio chains, they will have multiple AP MAC addresses. All MAC addresses can be unified by a unique AP device name. In addition, the RSSI in the AP tag information can be used to determine the confidence level. Figure 5 The MHz in the number represents the channel frequency. For example, 5240.MHz-6 indicates a channel frequency of 5240.MHz, which is Wi-Fi 6 (the sixth generation of wireless network technology). For example, 5280.MHz-5 indicates a channel frequency of 5280.MHz, which is Wi-Fi 5 (the fifth generation of wireless network technology).

[0097] Embodiments of this invention support multi-mode collaborative identification on mobile devices. By offering both connected identification and connectionless scanning, they balance accuracy and convenience, adapting to varying network densities and coverage conditions. They also enable terminal apps to quickly identify surrounding APs on-site, making them suitable for practical scenarios such as equipment acceptance, on-site verification, and maintenance inspections.

[0098] To improve the accuracy of AP device identification, the present invention adopts a relative distance analysis model based on RSSI difference reasoning. The RSSI value changes reported by the STA during multiple movements are tested, and the approach or distance from an AP device is determined according to formula (1).

[0099] (1);

[0100] Where n is the path loss factor, is the reference power, and d is the distance from the test STA to the AP device.

[0101] For the two measured RSSI values ​​RSS1 and RSS2, the distance change trend can be deduced according to formula (2).

[0102] (2);

[0103] That is, if the RSSI increases, the test STA is approaching the AP device. This analysis does not depend on the path loss factor n or the reference power. ,judging only by relative changes, it helps to identify the most likely target AP device in a non-connected state and obtain the target device identification result.

[0104] From formula (1), we can see that the distance d is inversely proportional to the signal strength RSSI. It is a proportional relationship, that is, when the distance from STA to AP increases, RSSI decreases. Therefore, in formula (2) , means Proportional to , Indicates the difference in distances between the two locations of a STA and the AP device. For example, the two locations of a STA are location 1 and location 2. The RSSI measured when the STA is at location 1 is RSSI1, and the RSSI measured when the STA is at location 2 is RSSI2. Inputting RSSI1 into formula (1) yields the distance d1 between the STA and the AP device at location 1, and inputting RSSI2 into formula (1) yields the distance d2 between the STA and the AP device at location 2. Indicates the difference in signal strength between the STA at position 2 and position 1 and the AP. =d2-d1 represents the difference in distance between the STA and the AP at location 2 and location 1. The greater the difference in signal strength, the greater the distance difference.

[0105] Based on the aforementioned RSSI values ​​and RSSI value trends, to improve the reliability of the final AP device identification result, an embodiment of the present invention further provides an AP confidence model to determine the credibility of the initial device identification result and to rank the credibility of the initial device identification results of multiple AP devices associated with the same test STA terminal to obtain the target device identification result.

[0106] Specifically, the process of determining the credibility of the initial device identification result based on the test received signal strength indicator value according to the wireless communication mode between the test terminal and the wireless access point to be identified may include the following operations: when the wireless communication mode indicates that wireless access has been established, determining the credibility of the initial device identification result based on the test received signal strength indicator value between the test terminal and the wireless access point to be identified, the changing trend of the test received signal strength indicator value, the interaction between the test terminal and the wireless access point to be identified, and the behavior pattern of the test terminal; when the wireless communication mode indicates that no wireless access has been established, determining the credibility of the initial device identification result based on the test received signal strength indicator value between the test terminal and the wireless access point to be identified, and the changing trend of the test received signal strength indicator value.

[0107] In some embodiments, at least one of the following factors may be used to determine the credibility of the initial device identification result:

[0108] (a) Test the RSSI value between the STA and the AP device (estimate the distance).

[0109] (b) RSSI continuous trend (moving closer or farther away).

[0110] (c) The activity level of events between the AP and the test STAs currently connected to the AP during a predetermined period (e.g., number of connections, roaming frequency). The predetermined period can be adaptively adjusted based on actual needs.

[0111] (d) Test the STA's behavior patterns between multiple AP devices (such as roaming, stay duration, and association switching sequence).

[0112] When the wireless communication method indicates that wireless access has been achieved, the credibility of the initial device identification result can be determined according to formula (3): ; In the case where the wireless communication mode indicates no wireless access, the credibility of the initial device identification result can be determined according to formula (4) .

[0113] (3);

[0114] (4);

[0115] in, is the normalized RSSI value, Whether RSSI shows a continuous upward or downward trend, The frequency of the event triggering between the AP and the test STA recently. Indicates whether the AP device has roamed with the test STA within the predetermined period. This can be obtained from the event log. If roaming has occurred, If it is 1, then no roaming occurs. is 0, - The weight parameters for each dimension can be set based on scenario experience or training data, and can be adaptively adjusted according to actual needs.

[0116] In practical applications, It can make quick judgments directly in open scenes. The actual change trend of the specified value needs to be displayed. and Used to additionally determine the activity and stability between the STA and AP in connection mode.

[0117] The system calculates The credibility of the initial device identification results is ranked, and the initial device identification result with the highest credibility is selected as the target device identification result. At the same time, the credibility is provided for display in the upstream system or user interface to achieve interpretable feedback of the results and multi-strategy fusion control.

[0118] The embodiment of the present invention integrates the confidence mechanism of signals and behaviors, constructs a confidence model based on RSSI estimation, log event frequency and mobility trend, and can comprehensively judge and rank multiple candidate AP devices, effectively improving the accuracy and robustness of recognition and supporting interpretable result output.

[0119] In some embodiments, when the target device identification result is supplemented by the geographic location information of the AP device to obtain the AP device identification result, the following operations can be performed: according to the type of information in the identification result of the wireless access point, the information in the identification result of the wireless access point is filled into the information display template to obtain an information display label; and the information display label is displayed in a predetermined image file.

[0120] In some embodiments, the information type may include a name type, a MAC address type, and a geographic location type. The information display template may include three areas: a first area for populating the AP device's device name, a second area for populating the AP device's MAC address, and a third area for populating the AP device's geographic location. By populating the information display template with information from the recognition result based on the information type, an information display tag may be generated. This information display tag may be displayed in the image file for viewing by the target user.

[0121] Figure 6A The image file shows the distribution of the original AP devices.

[0122] like Figure 6A The figure shows the distribution of AP devices before AP devices are identified. Figure 6A There is an error problem of AP device information duplication in the display. For example, AP004 is displayed in the first display area 601 and AP004 is displayed in the second display area 602. In other words, the AP information displayed in one display area is incorrect and should not be displayed in that display area. Therefore, the method for wireless access point identification based on event logs provided in the embodiments of the present invention is needed to accurately identify AP devices.

[0123] Figure 6B A schematic diagram showing information display labels on an interface of a visual management system according to an embodiment of the present invention is shown.

[0124] The information display tag 603 obtained by identifying the AP device through the method provided by the embodiment of the present invention can be as follows: Figure 6B The information display tag 603 of the AP device is imported into the map 604 of the visual management system interface for display. The display result can be as follows: Figure 6B As shown. Clicking an AP device at any location on the map 604 in the visual management system interface will bring up a pop-up tab 603 displaying information about that AP device. The AP distribution display box 605 in the visual system interface displays the number of AP devices on map 604, such as 21 in area ** (for example only). In the location selection box 606 in the visual system interface, you can select the location for which you want to query the map and AP distribution.

[0125] In some embodiments, the target device identification results can be directly transmitted back to the backend as calibration data to complete or confirm the name, floor, location, and other tag information corresponding to the AP device MAC address. Information display tags can be mapped to building drawings and, combined with STA terminal movement trajectories, used to mark points. This allows for simultaneous data collection and visualization of AP device deployment locations, enabling structured and spatialized management of wireless devices and demonstrating the practicality of the event log-based wireless access point identification method of this embodiment.

[0126] In some embodiments, an embodiment based on the above method may include: browsing a building map, moving to the vicinity of an AP device at a building entrance, measuring information of the AP device at the entrance (e.g., the MAC address and name of the AP device) according to the above method, and marking the AP device information on the building map.

[0127] Figure 7 The diagram shows an architecture of a method for wirelessly identifying wireless access points based on event logs according to an embodiment of the present invention.

[0128] like Figure 7 As shown, AC 701 can manage multiple APs 702, and STA 703 can interact with AP 702, for example, in wireless connection mode and wireless connectionless mode. The interaction between STA 703 and AP 702 can generate event logs, which can be processed by log processing service 704, for example, to perform out-of-order fault tolerance and timing correction. Based on the processing results, a state table is generated, which includes an AP device state table and a STA device state table. Based on the matching results between the event log and at least one of the AP device state table and the STA device state table, a target identification result for the AP device can be obtained. The information obtained from the target identification result is displayed and tagged to an external system 705, such as a digital map or device management system, for viewing by the target user. STA 703 can also query the AP device's geographic location from external system 705 or write the AP device identification result. STA 703 can also query the AP device's name from log processing service 704 or write the AP device identification result.

[0129] The embodiment of the present invention can complete the identification and labeling of AP devices without increasing hardware investment. It has the advantages of low deployment cost, wide application range, high identification efficiency, strong integrability, etc., and has significant engineering application value and industrial promotion prospects.

[0130] The following example uses a campus wireless network. Multiple batches of APs and ACs have been deployed within the campus, covering a wide range of brands and generations, including earlier models and newer Wi-Fi 6 devices. The wireless network boasts high coverage, with over 3,000 APs distributed across different areas within the campus, such as Area 1, Area 2, Area 3, and Area 4. However, the lack of tag data for the APs in these areas has limited the campus's intelligent development. This embodiment of the present invention can identify APs and generate tags.

[0131] The management AC device of this server network system can enable STA access event logging, but only supports forwarding logs to an external log server in syslog format via the UDP protocol. The log format varies between device manufacturers and versions, including fields that are not completely consistent, and time accuracy is typically at the second level. While most APs have deployment location records, they lack structured tagging information such as device name, floor number, and functional area, making it difficult to later organize network assets and identify on-site devices.

[0132] In this scenario, the specific implementation of the present invention is as follows:

[0133] System deployment and log access. Deploy a log receiving service node in the core area of ​​the campus network. Receive STA event logs from each AC device through a UDP listening port. Use a customized parser to identify the log format and standardize the log data into a unified structure.

[0134] Event stream processing and state table construction. Because logs can be prone to packet loss and out-of-order events, the system uses a sliding time window mechanism and a finite state machine model to perform sequence correction and conflict resolution on multiple events within a short period of time. Processed events are used to update the AP device state table in real time, recording information such as the most recently connected terminal, active status, and the time of the most recent event for each AP.

[0135] Mobile terminal identification operation. The operation and maintenance personnel go to the site with a mobile phone installed with the application supporting the identification method provided by the embodiment of the present invention, and identify the specific AP in the following two ways:

[0136] Connection method identification: The mobile phone attempts to connect to the AP device with the strongest signal on site. After the connection is successful, the system will immediately receive the STA's online or roaming event, obtain the MAC address of the AP currently associated with the STA through the real-time status table, and then query and return the corresponding tags (such as the teaching building name, floor, device number, etc.).

[0137] Connectionless identification: If connectivity is limited, the application obtains the MAC and RSSI lists of nearby APs through the system interface. The system matches relevant records in the AP device status table and estimates the relative distance between the test STA and each AP device based on the RSSI value. The confidence model selects the most reliable initial identification result to obtain the target device identification result.

[0138] The identification results are displayed. The system returns the results to the application frontend and synchronizes them with the backend management platform. The backend can annotate the AP's location on building drawings for visual identification and confirmation. The platform supports screening and statistics by building, floor, device type, and more.

[0139] The method provided by the embodiment of the present invention is suitable for addressing information asymmetry problems in heterogeneous AP and AC equipment environments, and for remedying problems such as missing label information and difficulty in manual identification. It successfully helped the network center complete label verification and unified coding of multiple batches of AP equipment, providing a reliable foundation for subsequent equipment inspections, security audits, and network optimization.

[0140] It should be noted that, unless it is clearly stated that there is a sequence of execution between different operations shown in the flowchart in the embodiments of the present invention, or there is a sequence of execution between different operations in technical implementation, otherwise, the execution order of multiple operations may not be prioritized, and multiple operations may also be executed simultaneously.

[0141] Based on the above method for wirelessly identifying wireless access points based on event logs, the present invention also provides a device for wirelessly identifying wireless access points based on event logs. Figure 8 The device is described in detail.

[0142] Figure 8 A structural block diagram of a device for wirelessly identifying wireless access points based on event logs according to an embodiment of the present invention is shown.

[0143] like Figure 8 As shown, the apparatus 800 for wirelessly identifying wireless access points based on event logs in this embodiment includes an acquisition module 810 , a matching module 820 , a determination module 830 and a supplementation module 840 .

[0144] The acquisition module 810 is configured to obtain, in response to an identification request for identifying a wireless access point, a test received signal strength indicator between the test terminal in a moving state and the wireless access point to be identified and a test event log related to the test terminal and the wireless access point to be identified.

[0145] The matching module 820 is configured to match the test event log with the device status file to obtain an initial device identification result of the wireless access point to be identified. The device status file includes access status information of the wireless access point to be identified.

[0146] a determination module 830 configured to determine the credibility of the initial device identification result based on the test received signal strength indicator value according to the wireless communication mode between the test terminal and the wireless access point to be identified, and obtain a target device identification result, wherein if the wireless communication mode indicates wireless access and the credibility of the initial device identification result satisfies a predetermined value, the initial device identification result is used as the target device identification result; or if the wireless communication mode indicates no wireless access, the initial device identification results are sorted according to the credibility of the initial device identification results, and the target device identification result that satisfies the predetermined credibility condition is selected from the sorted initial device identification results;

[0147] The supplementing module 840 is configured to supplement the target device identification result according to the geographical location information of the wireless access point to obtain an identification result of the wireless access point.

[0148] It should be noted that the apparatus for wirelessly identifying wireless access points based on event logs in the embodiments of the present invention corresponds to the method for wirelessly identifying wireless access points based on event logs in the embodiments of the present invention. For a detailed description of the apparatus for wirelessly identifying wireless access points based on event logs, reference may be made to the method for wirelessly identifying wireless access points based on event logs, and will not be repeated here.

[0149] According to embodiments of the present invention, any multiple modules among the acquisition module 810, matching module 820, determination module 830, and supplementation module 840 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present invention, at least one of the acquisition module 810, matching module 820, determination module 830, and supplementation module 840 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or may be implemented in any one of software, hardware, and firmware, or any suitable combination of these. Alternatively, at least one of the acquisition module 810, matching module 820, determination module 830, and supplementation module 840 may be at least partially implemented as a computer program module that, when executed, performs the corresponding functionality.

[0150] Figure 9 A block diagram of an electronic device suitable for implementing a method for wirelessly identifying a wireless access point based on an event log according to an embodiment of the present invention is shown.

[0151] like Figure 9 As shown, an electronic device 900 according to an embodiment of the present invention includes a processor 901, which can perform various appropriate actions and processes based on programs stored in a read-only memory (ROM) 902 or programs loaded from a storage unit 908 into a random access memory (RAM) 903. The processor 901 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or related chipsets and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 901 may also include onboard memory for caching purposes. The processor 901 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.

[0152] The RAM 903 stores various programs and data required for the operation of the electronic device 900. The processor 901, ROM 902, and RAM 903 are connected to each other via a bus 904. The processor 901 executes the programs in the ROM 902 and / or RAM 903 to perform various operations according to the method flow of the embodiment of the present invention. It should be noted that the programs may also be stored in one or more memories other than the ROM 902 and RAM 903. The processor 901 may also execute the programs stored in the one or more memories to perform various operations according to the method flow of the embodiment of the present invention.

[0153] According to an embodiment of the present invention, electronic device 900 may further include an input / output (I / O) interface 905, which is also connected to bus 904. Electronic device 900 may also include one or more of the following components connected to I / O interface 905: an input section 906 including a keyboard, mouse, etc.; an output section 907 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 908 including a hard disk; and a communication section 909 including a network interface card such as a LAN card or modem. Communication section 909 performs communication processing via a network such as the Internet. A drive 910 is also connected to I / O interface 905 as needed. Removable media 911, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 910 as needed, so that computer programs read from the removable media can be installed into storage section 908 as needed.

[0154] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present invention.

[0155] According to an embodiment of the present invention, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present invention, a computer-readable storage medium may include the ROM 902 and / or RAM 903 described above, and / or one or more memories other than ROM 902 and RAM 903.

[0156] The embodiments of the present invention further include a computer program product, which includes a computer program containing program code for executing the method shown in the flowchart. When the computer program product is run in a computer system, the program code is used to cause the computer system to implement the method provided by the embodiments of the present invention.

[0157] The computer program executes the above functions defined in the system / device of the embodiment of the present invention when executed by the processor 901. According to the embodiment of the present invention, the system, device, module, unit, etc. described above can be implemented by a computer program module.

[0158] In one embodiment, the computer program may be stored on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may be transmitted and distributed in the form of a signal on a network medium, downloaded and installed via the communication portion 909, and / or installed from a removable medium 911. The program code contained in the computer program may be transmitted using any appropriate network medium, including but not limited to wireless, wired, or any suitable combination thereof.

[0159] In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 909 and / or installed from a removable medium 911. When the computer program is executed by the processor 901, the above-described functions defined in the system of the embodiment of the present invention are performed. According to the embodiment of the present invention, the systems, devices, means, modules, units, etc. described above can be implemented by computer program modules.

[0160] According to an embodiment of the present invention, the program code for executing the computer program provided by the embodiment of the present invention can be written in any combination of one or more programming languages. Specifically, these computer programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages ​​include, but are not limited to, languages ​​such as Java, C++, Python, "C" or similar programming languages. The program code can be executed entirely on the user computing device, partially on the user device, partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device can be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computing device (for example, using an Internet service provider to connect via the Internet).

[0161] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.

[0162] It will be understood by those skilled in the art that the features described in the various embodiments of the present invention may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in the present invention. In particular, the features described in the various embodiments of the present invention may be combined and / or coupled in various ways without departing from the spirit and teachings of the present invention. All such combinations and / or couplings fall within the scope of the present invention.

[0163] The above describes embodiments of the present invention. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present invention, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present invention.

Claims

1. A method for wirelessly identifying wireless access points based on event logs, characterized in that: The method comprises: In response to the wireless access point identification request, obtaining a test received signal strength indicator value of the test terminal in a mobile state and the wireless access point to be identified and a test event log related to the test terminal and the wireless access point to be identified; Obtaining an initial device identification result of the wireless access point to be identified based on a match between the test event log and a device status file, wherein the device status file includes an access status of the wireless access point to be identified; determining, based on a wireless communication mode between the test terminal and the wireless access point to be identified, the credibility of the initial device identification result and the test received signal strength indicator value, to obtain a target device identification result, wherein the wireless communication mode includes wireless access and no wireless access. If wireless access has been established and the credibility of the initial device identification result meets a predetermined value, using the initial device identification result as the target device identification result; or if no wireless access has been established, sorting the initial device identification results according to the credibility of the initial device identification results, and selecting a target device identification result that meets a predetermined credibility condition from the sorted results; The target device identification result is supplemented according to the geographical location of the wireless access point to obtain an identification result of the wireless access point.

2. The method according to claim 1, characterized in that The device status file includes a real-time status file of a user terminal and a real-time status file of a wireless access point cluster, the user terminal includes the test terminal, and the wireless access point cluster includes the wireless access point to be identified. The device status file is obtained in the following manner: Standardizing an initial event log forwarded by a wireless controller and indicating access to a wireless access point cluster by a terminal to obtain a standardized event log, wherein the initial event log includes the test event log; Modifying the standardized event log to obtain an access relationship between the user terminal and the wireless access point cluster; The hardware address of the user terminal and the hardware address of the wireless access point in the wireless access point cluster are respectively used as primary keys, and according to the access relationship, a real-time status file of the user terminal and a real-time status file of the wireless access point cluster are constructed.

3. The method according to claim 2, characterized in that The modifying the standardized event log to obtain the access relationship between the user terminal and the wireless access point cluster includes: Building a sliding time window using the hardware address of the user terminal as a unit, and generating a behavior chain based on the event log within the sliding time window; Repairing the behavior chain to obtain a repaired behavior chain; Performing a rationality test on the repair behavior chain to obtain a test result; The repair behavior chain is processed according to the detection result to obtain an access relationship between the user terminal and the wireless access point cluster.

4. The method according to claim 3, characterized in that Repairing the behavior chain to obtain a repaired behavior chain includes: Identify the behavior chain that has undergone fault tolerance processing and obtain the target behavior chain; In the case that a predetermined number of event logs are missing in the target behavior chain, logical completion is performed based on the semantics of the target behavior chain to obtain the repair behavior chain.

5. The method according to claim 3, characterized in that The processing of the repair behavior chain according to the detection result to obtain the access relationship between the user terminal and the wireless access point cluster includes: If the detection result indicates that the user terminal is connected to m1 different wireless access points within a predetermined time period, marking the user terminal as a predefined semantic label to obtain processed user terminal information, where m1 is greater than or equal to 0; When the detection result indicates that the user terminal simultaneously accesses m2 wireless access points at different physical locations, selecting wireless access point information having a maximum received signal strength indicator value with the user terminal among the m2 wireless access points to obtain processed wireless access point information, where m2 is an integer greater than 1; An access relationship between the user terminal and the wireless access point cluster is established based on the processed user terminal information and the processed wireless access point information.

6. The method according to claim 2, characterized in that The test event log includes the hardware address of the test terminal; Obtaining an initial device identification result of the wireless access point to be identified based on a match between the test event log and the device status file, including: Matching the hardware address of the test terminal with the real-time status file of the user terminal to obtain the hardware address of the wireless access point to be identified; Matching the hardware address of the wireless access point to be identified with the real-time status file of the wireless access point cluster to obtain the device name of the wireless access point to be identified; The initial device identification result is obtained according to the hardware address of the wireless access point to be identified and the device name of the wireless access point to be identified.

7. The method according to claim 1, characterized in that The determining the credibility of the initial device identification result based on the test received signal strength indicator value according to the wireless communication mode between the test terminal and the wireless access point to be identified includes: When the wireless communication mode indicates wireless access, determining the credibility of the initial device identification result based on a test received signal strength indicator value between the test terminal and the wireless access point to be identified, a change trend of the test received signal strength indicator value, an interaction between the test terminal and the wireless access point to be identified, and a behavior pattern of the test terminal; When the wireless communication mode indicates no wireless access, the credibility of the initial device identification result is determined based on a test received signal strength indicator value between the test terminal and the wireless access point to be identified, and a change trend of the test received signal strength indicator value.

8. The method according to claim 1, characterized in that In the case of no wireless access, the method further includes: Using an application loaded on the test terminal, a surrounding wireless access point cluster in a surrounding area is scanned to obtain a hardware address of the surrounding wireless access point cluster and test received signal strength indicator values ​​of the test terminal and wireless access points in the surrounding wireless access point cluster, wherein the surrounding area includes a spherical area with the test terminal as the center and a predetermined size as the radius.

9. The method according to claim 1, characterized in that The method further comprises: Filling the information in the identification result of the wireless access point into an information display template according to the type of information in the identification result of the wireless access point to obtain an information display label; The information display label is displayed in a predetermined image file.

10. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Method for estimating ap position using log data, and device and terminal for same

    CN103181224A

  • Access points and methods for access point selection using an information data structure

    CN105359602A

  • Link log monitoring method, device, computer equipment and storage medium

    CN110855477A

  • FTTR-based home user hot spot area identification method, system and device, and medium

    CN114641030A

  • Wireless access point batch simulation test method, device and equipment and storage medium

    CN120091344A