Method for establishing wireless connection and access point and client device for performing method

By ensuring that the AP obtains and ensures that the client device and the AP use the same private PSK during the SAE authentication process of the WPA3 protocol, the problem of private PSKs being incompatible with the WPA3 protocol is solved, thus enabling successful connection of client devices and improving network security.

CN121334657APending Publication Date: 2026-01-13TP-LINK INT SHENZHEN CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511504283.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-10-21
Filing Date
2025-10-20
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Existing proprietary PSK technology is not applicable to wireless networks using the WPA3 protocol, causing the SAE authentication process to fail and preventing client devices from successfully accessing the target network.

Method used

Before performing the SAE authentication process, the AP obtains the target private PSK of the client device through a downgraded security protocol, so that the client device and the AP use the same private PSK for authentication, thus ensuring the success of the SAE authentication process.

Benefits of technology

This ensures that client devices can successfully connect to the target network using the WPA3 protocol, avoiding the negative impact on user experience caused by network qualification revocation due to private PSK leakage or cracking, and improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121334657A_ABST
    Figure CN121334657A_ABST
Patent Text Reader

Abstract

A method of establishing a wireless connection, and an access point and a client device performing the method are provided. The method includes receiving an access request indicating that a client device is requesting access to a target network created by an AP using a Wi-Fi protected access 3 (WPA3) protocol; obtaining a target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a secure protocol different from the WPA3 protocol; and in response to the target private PSK being correct, controlling the client device to connect to the target network using the target private PSK according to the WPA3 protocol.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross-references to related applications

[0002] This application claims priority to U.S. Patent Application No. 18 / 921,604, filed October 21, 2024, entitled “METHOD OF ESTABLISHING WIRELESS CONNECTION AND ACCESS POINT AND CLIENT DEVICE PERFORMING THE METHOD”, the disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0003] This disclosure relates to wireless communication, and more specifically, to a method for establishing a wireless connection between an access point (AP) and a client device, as well as the AP and the client device performing the method. Background Technology

[0004] Compared to Wi-Fi Protected Access 2 (WPA2), Wi-Fi Protected Access 3 (WPA3) introduces a simultaneous authentication process (SAE), significantly enhancing authentication and encryption, improving protection against eavesdropping and spoofing, and providing mitigation measures against wireless attacks such as key reinstallation attacks (KRACK) and deauthentication flood attacks (DEAUTH). Current proprietary PSK (Pre-Shared Key) technology works for WPA2 wireless networks but not for WPA3. An improved mechanism is needed for accessing WPA3 wireless networks using proprietary PSKs. Summary of the Invention

[0005] In view of the above problems, this application provides a technology for establishing a wireless connection between a client device and an access point (AP), ensuring that the client device can use a private PSK to access a wireless network using the WPA3 protocol provided by the AP.

[0006] According to one aspect of this disclosure, a method for establishing a wireless connection by an access point (AP) is provided. The method includes: receiving an access request indicating that a client device is requesting access to a target network using the Wi-Fi Protected Access 3 (WPA3) protocol established by the AP; obtaining a target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol; and, in response to the correctness of the target private PSK, controlling the client device to use the target private PSK to connect to the target network according to the WPA3 protocol.

[0007] According to one aspect of this disclosure, a method for establishing a wireless connection by a client device is provided. The method includes: sending an access request to an access point (AP), the access request indicating that the client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; providing the AP with a target private pre-shared key (PSK), the target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol; and, in response to receiving a connection instruction instructing the client device to establish a connection with the AP according to the WPA3 protocol, performing a peer-to-peer (SAE) authentication process as defined by the WPA3 protocol using the target private PSK.

[0008] According to one aspect of this disclosure, an access point (AP) is provided. The AP includes a memory storing instructions thereon; and a processor coupled to the memory, the processor being configured to execute the instructions to cause the AP to: receive an access request indicating that a client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; obtain a target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol; and, in response to the correctness of the target private PSK, control the client device to connect to the target network using the target private PSK according to the WPA3 protocol.

[0009] According to one aspect of this disclosure, a client device is provided. The client device includes: a memory storing instructions thereon; and a processor coupled to the memory, the processor being configured to execute the instructions to cause the client device to: send an access request to an access point (AP), the access request indicating that the client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; provide the AP with a target private pre-shared key (PSK), the target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol; and, in response to receiving a connection instruction instructing the client device to establish a connection with the AP according to the WPA3 protocol, perform a peer-to-peer (SAE) authentication process as defined by the WPA3 protocol using the target private PSK.

[0010] A computer program product includes a computer-readable medium having instructions stored thereon, the instructions causing the processor, when executed by a processor of an access point (AP), to perform the following operations: receiving an access request indicating that a client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; obtaining a target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol; and, in response to the correctness of the target private PSK, controlling the client device to connect to the target network using the target private PSK according to the WPA3 protocol.

[0011] A computer program product includes a computer-readable medium having instructions stored thereon, the instructions causing the processor, when executed by a processor of a client device, to perform the following operations: sending an access request to an access point (AP), the access request indicating that the client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; providing the AP with a target private pre-shared key (PSK), the target private pre-shared key (PSK) to be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol; and, in response to receiving a connection instruction instructing the client device to establish a connection with the AP according to the WPA3 protocol, performing a peer-to-peer (SAE) authentication process as defined by the WPA3 protocol using the target private PSK.

[0012] Using the technology of this application, the AP can obtain the target private PSK that the client device will use to access the target network using the WPA3 protocol before performing the SAE authentication process as specified by the WPA3 protocol. This allows the AP and the client device to use the same private PSK to perform the SAE authentication process. This ensures that even if the client device is configured with multiple private PSKs, the SAE authentication process will succeed if the client device uses any one of the configured private PSKs, thereby enabling the client device to successfully connect to the target network. Attached Figure Description

[0013] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to offer a further understanding of the embodiments of this disclosure and form part of the specification. The drawings, together with the embodiments of this disclosure, are used to explain this disclosure but do not constitute a limitation thereof. In the drawings, unless explicitly stated otherwise, the same reference numerals denote the same parts, steps, or elements.

[0014] Figure 1 A first exemplary system for establishing a wireless connection between a client device and an access point (AP) according to a first embodiment of the present disclosure is shown;

[0015] Figure 2 An exemplary schematic diagram illustrating example interactions between entities in a first exemplary system according to a first embodiment of the present disclosure is shown;

[0016] Figure 3a and Figure 3b An exemplary schematic diagram illustrating a sample interaction between an AP and a data management server for verifying a target private PSK, according to an embodiment of this disclosure, is shown.

[0017] Figure 4 A second exemplary system for establishing a wireless connection between a client device and an access point (AP) according to a second embodiment of the present disclosure is shown;

[0018] Figure 5 An exemplary schematic diagram illustrating example interactions between entities in a second exemplary system according to a second embodiment of the present disclosure is shown;

[0019] Figure 6 A third exemplary system for establishing a wireless connection between a client device and an access point (AP) according to a third embodiment of the present disclosure is shown;

[0020] Figure 7 An exemplary schematic diagram illustrating example interactions between entities in a third exemplary system according to a third embodiment of the present disclosure is shown;

[0021] Figure 8 An exemplary schematic diagram illustrating a method for establishing a wireless connection by an AP according to an embodiment of the present disclosure is shown;

[0022] Figure 9 An exemplary schematic diagram illustrating a method for establishing a wireless connection by a client device according to an embodiment of the present disclosure is shown;

[0023] Figure 10 This is an exemplary block diagram illustrating an example AP according to an embodiment of the present disclosure; and

[0024] Figure 11 This is an exemplary block diagram illustrating an example client device according to an embodiment of the present disclosure. Detailed Implementation

[0025] The technical solutions of this disclosure will now be clearly and completely described with reference to the accompanying drawings. The described embodiments are part of, but not all, of the embodiments of this disclosure. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without any creative effort fall within the protection scope of this disclosure.

[0026] In the description of this disclosure, it should be noted that the orientations or positional relationships indicated by terms such as “center,” “upper,” “lower,” “left,” “right,” “vertical,” “horizontal,” “inner,” and “outer” are based on the orientations or positional relationships shown in the accompanying drawings and are used solely for the convenience of describing this disclosure and for simplification, and do not indicate or imply that the indicated device or element must have a particular orientation. Furthermore, terms such as “first,” “second,” and “third” are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Similarly, words such as “a,” “an,” or “the” do not represent a limitation of quantity, but rather indicate the presence of at least one. Words such as “comprising” or “including” mean that the element or object preceding the word encompasses those elements or objects listed following the word and their equivalents, without excluding other elements or objects. Words such as “connection” or “link” are not limited to physical or mechanical connections but can include electrical connections, whether direct or indirect.

[0027] In the description of this disclosure, it should be noted that, unless otherwise expressly stated and limited, terms such as “install,” “link,” and “connect” should be interpreted broadly. For example, such terms may refer to a fixed connection, a detachable connection, or an integral connection; they may refer to a mechanical connection or an electrical connection; they may refer to a direct connection, an indirect connection via an intermediate medium, or an internal connection within two elements. Those skilled in the art will be able to understand the specific meaning of the above terms in this disclosure according to the specific circumstances.

[0028] Furthermore, technical features involved in different embodiments of this disclosure described below can be combined, as long as they do not conflict with each other.

[0029] Some accompanying drawings may not depict all components of a given method, device, or system. Throughout the specification and drawings, the same reference numerals may be used to denote the same features.

[0030] Traditional wireless networks use a shared public PSK (Power-Only Key) for all client devices to access the network. If a client device's access to the wireless network needs to be revoked due to an incident (such as a leaked or compromised public PSK), the network administrator must change the public PSK. This disrupts the network access of all client devices, negatively impacting the user experience. To solve this problem, each client device can be configured with its own one or more private PSKs to access the wireless network. Disabling one client device's private PSK will not invalidate the private PSKs of other client devices.

[0031] As mentioned earlier, compared to the WPA2 protocol, the WPA3 protocol introduces the SAE authentication process, making it more effective at preventing wireless attacks such as KRACK and DEAUTH. To ensure the success of the SAE authentication process, peer entities (such as client devices and access points) must use the same proprietary PSK to perform the SAE authentication process. This is because the SAE authentication process involves peer entities independently generating authentication information, rather than one peer entity requesting authentication from the other. If the AP uses a different proprietary PSK than the one used by the client device to perform SAE authentication, the SAE authentication process may fail. This could result in the client device being unable to access the target network even if it uses the correct proprietary PSK. For example, the AP and client device can each independently calculate an acknowledgment field based on their proprietary PSK using, for example, a hash algorithm. The acknowledgment field calculated by the AP is closely related to the proprietary PSK used by the AP, and the acknowledgment field calculated by the client device is closely related to the proprietary PSK used by the client device. The AP can include its calculated acknowledgment field in the SAE authentication frame and send the frame to the client device. The client device can also include its calculated acknowledgment field in the SAE authentication frame and send the frame to the AP. Upon receiving the SAE authentication frame from the client device, the AP can compare the received acknowledgment field with its own calculated acknowledgment field. If the received acknowledgment field is the same as its calculated acknowledgment field, it indicates that the private PSK used by both the client device and the AP is the same, and the AP can determine that SAE authentication was successful. If the received acknowledgment field is different from its own calculated acknowledgment field, the AP can determine that SAE authentication failed. Similarly, the client device can also compare the acknowledgment field included in the SAE authentication frame received from the AP with its own calculated acknowledgment field, and determine that SAE authentication was successful based on the consistency between the received acknowledgment field and its own calculated acknowledgment field.

[0032] The first to third embodiments of this disclosure enable the AP to obtain a target private PSK (Property Safety Sense) that the client device will use to establish a wireless connection with the target network according to a security protocol different from WPA3 before controlling the client device to connect to the target network according to the WPA3 protocol. In this way, the client device and the AP can use the same private PSK to perform the SAE (Safety Assurance) process, thereby ensuring the success of the SAE authentication process and enabling the client device to access the target network using the WPA3 protocol.

[0033] The following will refer to Figures 1 to 3b The first embodiment according to this disclosure is described.

[0034] Figure 1 A first exemplary system for establishing a wireless connection between a client device and an access point (AP) according to a first embodiment of the present disclosure is shown.

[0035] refer to Figure 1 The first exemplary system 10 may include an access point (AP) 110, a client device 120, and a data management server 140. The AP 110 may create a Wi-Fi network 130 (hereinafter referred to as the target network 130) using the WPA3 protocol. The client device 120 may be configured with multiple private PSKs that can be used to connect to the AP 110. The data management server 140 may control and coordinate (including but not limited to) the collection, storage, protection, encryption, decryption, archiving, and destruction of data generated during interactions between the various entities of the first exemplary system 10. When a user of the client device 120 wishes to access the target network 130, the user may use one of the multiple private PSKs to request access to the target network 130. As previously stated, the SAE authentication process will only succeed if the client device 120 and the AP 110 use the same private PSK to perform the SAE authentication process; if the client device 120 and the AP 110 use different private PSKs, the SAE authentication process will fail.

[0036] In the first embodiment, AP 110 can obtain the target private PSK to be used by client device 120 to connect to target network 130 according to the WPA2 protocol before performing the SAE authentication process specified by the WPA3 protocol. That is, in the first embodiment, the aforementioned security protocol, different from the WPA3 protocol, can be the WPA2 protocol. Reference will be made below. Figure 2 Describe the details.

[0037] Figure 2 An exemplary schematic diagram is shown illustrating example interactions between entities of a first exemplary system according to a first embodiment of the present disclosure.

[0038] refer to Figure 2In step S201, client device 120 may send an access request to AP 110, indicating that client device 120 is requesting access to target network 130 using the WPA3 protocol created by AP 110. In one example, the access request may be a probe request frame or may be included in a probe request frame, and may include information elements associated with client device 120, such as the MAC address of client device 120.

[0039] In step S202, in response to receiving the access request, AP 110 may send an access request response to client device 120, instructing client device 120 to establish a connection with AP 110 according to the WPA2 protocol. In one example, the access request response may be a probe response frame or may be included in a probe response frame, and may include information elements indicating that the security protocol supported by AP 110 is the WPA2 protocol. Simultaneously, AP 110 may downgrade the security protocol of the target network 130 from the WPA3 protocol to the WPA2 protocol.

[0040] In step 203, in response to receiving the access request response, client device 120 can establish a pre-connection with AP 110 according to the WPA2 protocol, allowing AP 110 to obtain the target private PSK during the pre-connection establishment period. In one example, client device 120 can establish a pre-connection with AP 110 through the four-way handshake process specified by the WPA2 protocol. As is known, according to the WPA2 protocol, client device 120 can send an SNonce (i.e., a random number generated by client device 120) and a Message Integrity Check (MIC) to AP 110 in the second step of the four-way handshake process. The MIC is associated with the target private PSK. Specifically, the MIC is generated based on the first 16 bytes of a pair of temporary keys (PTK). The PTK is generated based on the pair of master keys (PMK), ANonce (i.e., a random number generated by AP 110), the MAC address of client device 120, and the MAC address of AP 110. The PMK is calculated based on the target private PSK and the SSID (Service Set Identifier) ​​of the target network 130.

[0041] In step 204, AP 110 can obtain the target private PSK from the information acquired during step S203 and verify the target private PSK. In one example, AP 110 can extract the MIC from the information acquired during the four-way handshake process, and then derive the target private PSK from the MIC in the reverse manner as used by client device 120 to generate the MIC, or retrieve the target private PSK from a mapping between the MIC and target private PSKs pre-stored by the network administrator. AP 110 can then verify the target private PSK.

[0042] In this way, by downgrading the security protocol of the target network 130 from WPA3 to WPA2, the client device 120 is allowed to establish a pre-connection with the AP 110, so that the AP 110 can obtain the target private PSK according to the WPA2 protocol.

[0043] Figure 3a and Figure 3b An exemplary schematic diagram illustrates a sample interaction between an illustrative AP and a data management server for verifying a target private PSK, according to an embodiment of this disclosure.

[0044] refer to Figure 3a In one example, step S204 may include substeps S204-1 to S204-3. In substep S204-1, a set of private PSKs configured for client device 120 may be set up and stored at data management server 140 by the network administrator. In one example, this set of private PSKs may be set not to bind to any MAC address. In another example, this set of private PSKs may be set to bind to a MAC address (such as the MAC address of client device 120). After the set of private PSKs associated with client device 120 is set up in data management server 140, in substep S204-2, data management server 140 may distribute the set of private PSKs to AP 110. If the set of private PSKs is set to bind to a MAC address, data management server 140 may also notify AP 110 of the binding relationship between the set of private PSKs and the MAC address. In substep S204-3, AP 110 may determine whether the target private PSK is correct. Specifically, if the set of private PSKs is not bound to a MAC address, AP 110 can compare the target private PSK with each private PSK in the set associated with client device 120, and determine that the target private PSK is correct based on a match between the target private PSK and one of the private PSKs in the set associated with client device 120. If the set of private PSKs is bound to a MAC address, AP 110 can compare the target private PSK with each private PSK in the set, and determine that the target private PSK is correct based on a match between the target private PSK and one of the private PSKs in the set, and that the MAC address of client device 120 matches the MAC address to which the matching private PSK is bound.

[0045] refer to Figure 3bIn another example, step S204 may include substeps S204-1' to S204-4'. It should be noted that the operation at substep S204-1' is the same as the operation at substep S204-1, therefore, for brevity, the details of the operation at substep S204-1' are omitted here. At substep S204-2', the client device 120 may send the acquired target private PSK to the data management server 140. At substep S204-3', the data management server 140 may determine whether the target private PSK is correct. Specifically, if the set of private PSKs is not bound to a MAC address, the data management server 140 may compare the target private PSK with each private PSK in the set of private PSKs associated with the client device 120, and determine that the target private PSK is correct based on its match with one of the private PSKs in the set of private PSKs associated with the client device 120. When the group of private PSKs is bound to a MAC address, the data management server 140 can compare the target private PSK with each private PSK in the group associated with the client device 120, and determine that the target private PSK is correct based on the fact that the target private PSK matches one of the private PSKs in the group and the MAC address of the client device 120 matches the MAC address bound to the matching private PSK. In sub-steps S204-4', the data management server 140 can return a comparison result message indicating whether the target private PSK is correct to the AP 110.

[0046] In this way, AP 110 can easily verify the acquired target private PSK by comparing it with a set of private PSKs pre-configured at data management server 140. If one or more private PSKs in the set are leaked due to attacks and / or vulnerabilities (such as side-channel attacks and / or dragonfly handshake vulnerabilities), only one or more leaked private PSKs need to be deleted at data management server 140 without resetting the entire set of private PSKs, thus avoiding negative impacts on client device 120.

[0047] Return to reference Figure 2In step 205, AP 110 can disconnect client device 120 from the established pre-connection. In step 206, client device 120 can send another access request indicating that client device 120 is requesting access to target network 130. This other access request is similar to the access request in step S201. For example, AP 110 can send a deauthentication frame to client device 120 to disconnect client device 120. The other access request can be in the form of a probe request frame, or can be included in a probe request frame and include information elements associated with client device 120, such as the MAC address of client device 120.

[0048] In step 207, in response to receiving another access request, if the target private PSK was verified as correct in step S204, AP 110 can send a connection indication to client device 120 instructing client device 120 to establish a connection with AP 110 according to the WPA3 protocol; or if the target private PSK was not verified as correct in step S204, AP 110 can send a denial indication to client device 120 instructing client device 120 to refuse connection to AP 110. The connection indication may be in the form of a probe response frame, or may be included in a probe response frame. The denial indication may be in the form of a deauthentication frame, or may be included in a deauthentication frame. Simultaneously, AP 110 can upgrade the security protocol of the target network 130 from WPA2 to WPA3.

[0049] In step 208, client device 120 and AP 110 can perform the SAE authentication process specified by the WPA3 protocol using the target private PSK. In this step, both client device 120 and AP 110 calculate their own confirmation fields based on the same target private PSK, ensuring that the confirmation fields calculated by client device 120 and AP 110 are identical, thereby guaranteeing that SAE authentication will be successful.

[0050] In this way, AP 110 can obtain the target private PSK that client device 120 will use to connect to the target network 130 according to the WPA3 protocol by downgrading the security protocol to the WPA2 protocol before performing the SAE authentication process specified by the WPA3 protocol. This ensures that client device 120 and AP 110 use the same target private PSK to perform the SAE authentication process. This ensures that the SAE authentication process will succeed as long as the target private PSK is correct, and enables client device 120 to connect to the target network according to the WPA3 protocol.

[0051] The following will refer to Figures 4 to 5 A second embodiment according to this disclosure is described.

[0052] Figure 4 A second exemplary system for establishing a wireless connection between a client device and an access point (AP) according to a second embodiment of the present disclosure is shown.

[0053] refer to Figure 4 The second exemplary system 20 may include an access point (AP) 110, a client device 120, a data management server 140, and an intermediate server 210. The intermediate server 210 may communicate with the AP 110 and the client device 120 via a first auxiliary network 220 using the Hypertext Transfer Protocol Security (HTTPS) protocol. For example, the first auxiliary network 220 may be a cellular network, a mobile network, or any other network different from the target network 130. When a user of the client device 120 wishes to access the target network 130, the user can establish a pre-connection with the intermediate server 210 via the first auxiliary network 220, allowing the intermediate server 210 to relay the target private PSK of the client device 120 to the AP 110 according to the HTTPS protocol. That is, in the second embodiment, the aforementioned security protocol, different from the WPA3 protocol, may be the HTTPS protocol. Reference will be made below. Figure 5 Describe the details.

[0054] refer to Figure 5 In step S501, upon detecting that the client device 120 is connected to the first auxiliary network 220, the intermediate server 210 can send a network list including the target network 130 to the client device 120 via the first auxiliary network 220. For ease of explanation, let's assume the first auxiliary network 220 is a cellular network, and the intermediate server 210 is associated with an application installed on the client device 120. After the client device 120 connects to the cellular network, the intermediate server 210 can detect the connection as long as the client device 120 activates the application (e.g., the client device 120 can be a mobile phone and the user can activate the application by touching the screen of the mobile phone). The intermediate server 210 can then send the network list including the target network 130 to the client device 120. The client device 120 can present the network list to the user via the application. The user can input a gesture command via the application to select the target network 130 from the network list. In step S502, the client device 120 can select the target network 130 from the network list in response to the gesture command.

[0055] In step S503, the intermediate server 210 may, in response to the selection of the target network 130 in step S502, send a private PSK request to the client device 120 to request the target private PSK of the client device 120.

[0056] In step S504, the client device 120 may send the target private PSK via the first auxiliary network 220 in response to receiving a private PSK request. For example, the private PSK request may be presented to the user via an application, and the user may input the target private PSK via the application. The client device 120 may send the target private PSK in response to the user's input.

[0057] In step S505, the intermediate server 210 may include the target private PSK in the access request and send the access request to the AP 110 to indicate that the client device 120 is requesting access to the target network 130 using the WPA3 protocol.

[0058] In step S506, AP 110 can extract the target private PSK from the access request received in step S505 and verify the target private PSK. It should be noted that the operation for verifying the target private PSK in step S506 is the same as the operation for verifying the target private PSK in step 204. For the sake of brevity, the details of the operation for verifying the target private PSK in step S506 are omitted here.

[0059] In this way, by enabling client device 120 to establish a pre-connection with AP 110 via intermediate server 210 and a first auxiliary network 220 using the HTTPS protocol, AP 110 is able to obtain the target private PSK before performing the SAE authentication process.

[0060] It should be noted that, in addition to the HTTPS protocol, the first auxiliary network 220 can also use one or more security protocols different from WPA3, such as TLS / SSL (Transport Layer Security / Secure Sockets Layer), IPSec (Internet Protocol Security), SSH (Secure Shell), Kerberos, RADIUS (Remote Authentication Dial-In User Service), OAuth (Open Authorization), SAML (Secure Assertion Markup Language), DTLS (Datagram Transport Layer Security), PEAP (Protected Extensible Authentication Protocol), HTTP (Hypertext Transfer Protocol), WebSocket, XMPP (Extensible Messaging and Presence Protocol), etc.

[0061] In step S507, AP 110 can return a verification result message to intermediate server 210 indicating whether the target private PSK is correct.

[0062] In step S508, if the received verification result message indicates that the target private PSK is correct, the intermediate server 210 can send a connection indication to the client device 120, which instructs the client device 120 to establish a connection with the AP 110 according to the WPA3 protocol; or if the received verification result message indicates that the target private PSK is incorrect, the intermediate server 210 can send a rejection indication to the client device 120, which instructs the client device 120 to refuse connection to the AP 110.

[0063] In step S509, client device 120 and AP 110 can perform the SAE authentication process specified by the WPA3 protocol using the target private PSK. In this step, both client device 120 and AP 110 calculate their own confirmation fields based on the same target private PSK, ensuring that the confirmation fields calculated by client device 120 and AP 110 are identical, thereby guaranteeing that SAE authentication will be successful.

[0064] In this way, AP 110 can obtain the target private PSK that client device 120 will use to connect to target network 130 via a first auxiliary network 220, which is different from target network 130. This ensures that client device 120 and AP 110 use the same target private PSK to perform the SAE authentication process. This ensures that the SAE authentication process will succeed as long as the target private PSK is correct, and enables client device 120 to connect to the target network according to the WPA3 protocol.

[0065] The following will refer to Figures 6 to 7 The third embodiment according to this disclosure is described.

[0066] Figure 6 A third exemplary system for establishing a wireless connection between a client device and an access point (AP) according to a third embodiment of the present disclosure is shown.

[0067] refer to Figure 6The third exemplary system 30 may further include an AP 110, a client device 120, and a portal server 310 using a portal authentication protocol. AP 110 can create a target network 130 using the WPA3 protocol and an unencrypted Wi-Fi network as a second auxiliary network 320. When a user of client device 120 wishes to access the target network 130, the user can establish a pre-connection with AP 110 via the second auxiliary network 320, allowing AP 110 to redirect client device 120 to portal server 310 and have portal server 310 verify client device 120's credentials. After verifying that client device 120's credentials are correct, client device 120 can configure a target private PSK to be used to connect to the target network 130, and then use the configured target private PSK to perform the SAE authentication process defined by the WPA3 protocol. In one example, the configured target private PSK may be stored in AP 110's memory. In another example, the third exemplary system 30 may further include a data management server 140, and the configured target private PSK may be stored in the data management server 140. A network administrator can manage the configured target private PSK, such as deleting it from the data management server 140. That is, in the third embodiment, the aforementioned security protocol, different from the WPA3 protocol, may be a portal authentication protocol. Reference will be made below. Figure 7 Describe the details.

[0068] Figure 7 An exemplary schematic diagram illustrating example interactions between entities of a third exemplary system according to a third embodiment of the present disclosure is shown.

[0069] refer to Figure 7 In step S701, AP 110 can create an unencrypted Wi-Fi network as a second auxiliary network 320, so that client device 120 can establish a pre-connection with AP 110 via the second auxiliary network 320.

[0070] In step S702, client device 120 may send an access request to AP 110, indicating that the client device is requesting access to target network 130 via second auxiliary network 320. In this embodiment, the access request may be in the form of an HTTP request. In step S703, AP 110 may redirect client device 120 to portal server 310. For example, after receiving the access request, AP 110 returns a redirection response to client device 120 including the URL of portal server 310. After receiving the redirection response, client device 120 may send a new HTTP request to the URL of portal server 310.

[0071] In step S704, portal server 170 may send a portal authentication request to client device 120 to request the identity credentials of client device 120. In step S705, client device 120 may send its identity credentials to portal server 170. In step S706, portal server 170 may forward the identity credentials of client device 120 to AP 110. In step S707, AP 110 may determine whether the identity credentials of client device 120 are correct, and then send an authentication result message to portal server indicating whether the authentication of the identity credentials of client device 120 was successful. The methods that AP 110 may use to verify identity credentials include, but are not limited to: authentication-free, account password authentication, RADIUS (Remote Authentication Dial-Up Subscriber Service) server authentication, mobile phone verification code authentication, email authentication, and combinations thereof.

[0072] In step S708, if the authentication result message received in step S707 indicates successful authentication of the client device 120's identity credentials, the portal server 310 can send a Private PSK Setting Instruction to the client device 120, instructing it to set a target Private PSK. Alternatively, if authentication of the client device 120's identity credentials fails, the portal server 310 can send a Reject Instruction to the client device 120, rejecting its connection to the AP 110. The Private PSK Setting Instruction allows the user of the client device 120 to set their own Private PSK, or select a Private PSK automatically generated by the AP 110 or data management server 140 with a specific length and / or format (e.g., whether it includes letters and / or special characters). In step S709, the client device 120 can send the target Private PSK to the portal server 170. In step S710, the portal server 310 can forward the set target Private PSK to the AP 110.

[0073] In this way, by enabling client device 120 to establish a pre-connection with AP 110 via an unencrypted second auxiliary network 220 and by utilizing portal server 310 to verify client device 120 according to the portal authentication protocol, AP 110 is able to obtain the target private PSK before performing the SAE authentication process.

[0074] In step S711, AP 110 can return the target private PSK acknowledgment message to portal server 310. In step S712, portal server 310 can forward the target private PSK acknowledgment message to client device 120. During these steps, AP 110 does not verify the target private PSK set by client device 120, but assumes it is correct, provided that client device 120's identity credentials have been successfully verified. That is, the target private PSK is correctly verified based on successful identity credential verification.

[0075] In this way, by allowing the client device 120 to set the target private PSK instead of pre-configuring a set of private PSKs for the client device 120, the flexibility of setting the private PSK can be increased and the user experience can be improved.

[0076] In step S713, AP 110 can disconnect client device 120 from the second auxiliary network 320, allowing client device 120 to send another access request to AP 110 in step S714. This other access request may be in the form of a probe response request frame, or may be included in a probe request frame. It should be noted that step S713 can be executed in parallel with steps S711 or S712.

[0077] At step S715, AP 110 may return a connection indication to client device 120, instructing client device 120 to establish a connection with AP 110 according to the WPA3 protocol. This connection indication may be in the form of a probe response frame, or it may be included in a probe response frame.

[0078] At step S716, client device 120 and AP 110 can use the target private PSK to perform the SAE authentication process specified by the WPA3 protocol. For example, client device 120 and AP 110 can both calculate their own acknowledgment fields based on the same target private PSK, so that the acknowledgment fields calculated by client device 120 and AP 110 are the same, thereby enabling the execution of the four-way handshake process specified by WPA3.

[0079] Therefore, AP 110 can obtain the target private PSK that client device 120 will use to connect to the target network 130 via the unencrypted second auxiliary network 320 and the portal server 310 using the portal authentication protocol, thereby ensuring that client device 120 and AP 110 use the same target private PSK to perform the SAE authentication process. This ensures that the SAE authentication process will succeed as long as the target private PSK is correct, and enables client device 120 to connect to the target network according to the WPA3 protocol.

[0080] The above has been referenced Figures 1 to 7 The first to third embodiments have been described. It should be noted that... Figure 4 The intermediate server 210 and Figure 6 The portal servers in the diagram are shown as being outside AP 110, but in some instances, they may also be inside AP 110.

[0081] Furthermore, the network administrator can configure a unique private PSK for the client device 120 at the data management server 140, and can bind the unique private PSK to the MAC address of the client device 120. After receiving an access request including the MAC address of the client device 120 from the client device 120, in response to determining that the MAC address in the access request matches the MAC address of the client device 120, the AP 110 can allow the client device 120 to connect to the target network 130 using the unique private PSK according to the WPA3 protocol.

[0082] Figure 8 An exemplary schematic diagram illustrating a method for establishing a wireless network by AP 110 according to an embodiment of the present disclosure is shown.

[0083] refer to Figure 8 The method 800 for establishing a wireless network by AP 110 may include steps S810 to S830.

[0084] In step S810, AP 110 may receive an access request indicating that client device 120 is requesting access to a target network 130 using the WPA3 protocol created by AP 110. For example, in a first embodiment of this disclosure, AP 110 may receive an access request from client device 120, as per [the relevant documentation / context]. Figure 2 As described in step S201. In the second embodiment of this disclosure, AP 110 can receive an access request from intermediate server 210, as per the description of... Figure 5 The steps S501 to S505 are described in the previous section. In the third embodiment of this disclosure, AP 110 can receive an access request from client device 120, as per the description of... Figure 7 The steps S701 and S702 described therein.

[0085] In step S820, AP 110 can obtain the target private PSK that the client device 120 will use to connect to the target network 130, based on a security protocol different from WPA3. For example, in the first embodiment of this disclosure, AP 110 can obtain the target private PSK based on the WPA2 protocol, as per [reference to...]. Figure 2 The steps S202 to S204 are described in the second embodiment of this disclosure. In this second embodiment, AP 110 can obtain the target private PSK via a first auxiliary network 220 using the HTTPS protocol, as per [reference to...]. Figure 5 As described in step S506. In the third embodiment of this disclosure, AP 110 can obtain the target private PSK via the second auxiliary network 320 and the portal server 310 using the portal authentication protocol, as per the description. Figure 7 The steps S703 and S710 described in the text.

[0086] In step S830, in response to the target private PSK being correct, AP 110 can control client device 120 to connect to target network 130 according to the WPA3 protocol. For example, in the first embodiment of this disclosure, AP 110 can control client device 120 to connect to target network 130 according to the WPA3 protocol by disconnecting a pre-connection established according to the WPA2 protocol and sending a connection indication to client device 120 after receiving another access request automatically sent by client device 120, as per [reference to...]. Figure 2 The steps S205 to S208 are described in the second embodiment of this disclosure. In this second embodiment, AP 110 can control client device 120 to connect to target network 130 according to the WPA3 protocol by sending an authentication result message indicating that the target private PSK is correct to trigger intermediate server 210 to send a connection indication to client device 120, as per the description of... Figure 5 The steps S507 to S509 are described in the document. In the third embodiment of this disclosure, AP 110 can control client device 120 to connect to target network 130 according to the WPA3 protocol by disconnecting the pre-connection between client device 120 and the unencrypted second auxiliary network and sending a connection indication to client device 120 after client device 120 automatically sends another access request, as per the relevant provisions. Figure 7 The steps S711 to S716 are described in the text.

[0087] In this way, the AP can obtain the target private PSK that the client device 120 will use to connect to the target network 130 according to the WPA3 protocol through a security protocol different from the WPA3 protocol. This allows the client device and the AP to use the same private PSK for the SAE process, thereby ensuring the success of the SAE authentication process and ultimately enabling the client device to access the target network according to the WPA3 protocol.

[0088] Figure 9 An exemplary schematic diagram illustrating a method for establishing a wireless network by a client device 120 according to an embodiment of the present disclosure is shown.

[0089] refer to Figure 9 The method 900 for establishing a wireless network by a client device 120 may include steps S910 to S930.

[0090] In step S910, client device 120 may send an access request to AP 110, indicating that client device 120 is requesting access to target network 130 using the WPA3 protocol provided by AP 110. For example, in the first embodiment of this disclosure, client device 120 may send an access request, such as regarding... Figure 2 As described in step S201. In the second embodiment of this disclosure, the client device 120 may send an access request via the first auxiliary network 220, as per the description. Figure 5 The steps S501 to S505 are described in the third embodiment of this disclosure. In this embodiment, the client device 120 may send an access request via the second auxiliary network 320, as per the description of... Figure 7 The steps S701 and S702 described therein.

[0091] In step S920, the client device 120 may send a target private PSK, used by the client device 120 to connect to the target network 130, to the AP 110 according to a security protocol different from the WPA3 protocol. For example, in the first embodiment of this disclosure, the client device 120 may send the target private PSK to the AP 110 according to the WPA2 protocol, as per [reference to...]. Figure 2 The steps described in step S203 are as follows. In another example, client device 120 may send the target private PSK to AP 110 via intermediate server 210 according to the HTTPS protocol, as per the description. Figure 5 Steps S504 to S505 are described in the third embodiment of this disclosure. In this embodiment, the client device 120 may send a target private PSK to the AP 110 via the portal server 210 according to the portal authentication protocol, as per the relevant provisions. Figure 7 As described in S703 to S710.

[0092] In step S930, the client device 120 may, in response to receiving a connection instruction instructing the client device 120 to establish a connection with the AP 110 according to the WPA3 protocol, perform the SAE authentication process specified by the WPA3 protocol using a private PSK. For example, in the first embodiment of this disclosure, the AP 110 may, in response to receiving a connection instruction from the AP 110, perform the SAE authentication process using a private PSK, as per the relevant provisions. Figure 2 Steps S207 and S208 are described in the previous section. In the second embodiment of this disclosure, the client device 120 may perform an SAE authentication process using a private PSK in response to receiving a connection instruction from the intermediate server 210 via the first auxiliary network 220, as per the description of... Figure 2 Steps S507 and S509 are described in the previous section. In the third embodiment of this disclosure, the client device 120 may perform an SAE authentication process using a private PSK in response to receiving a connection indication from the AP 110, as per the description of... Figure 7 As described in S713 to S716 shown.

[0093] In this way, the client device can send a target private PSK to the AP 110 via a security protocol different from the WPA3 protocol. This target private PSK will be used by the client device 120 to connect to the target network 130 according to the WPA3 protocol. This allows the AP 110 to know this target private PSK before performing the SAE authentication process, enabling the client device and the AP to use the same private PSK to perform the SAE process. This ensures the success of the SAE authentication process and ultimately facilitates the client device's access to the target network according to the WPA3 protocol.

[0094] Figure 10 This is an exemplary block diagram illustrating an example AP according to an embodiment of the present disclosure.

[0095] like Figure 10 As shown, the AP 1000 according to an embodiment of this disclosure may include a processor 111, a memory 112, a transmitting unit 113, and a receiving unit 114. These components may be coupled together via a communication bus 115. The memory 112 may store instructions thereon that, when executed by the processor 111, cause the AP 110 to perform the method 800 described above.

[0096] Figure 11 This is an exemplary block diagram illustrating an example client device according to an embodiment of the present disclosure.

[0097] like Figure 11As shown, the client device 120 according to an embodiment of this disclosure may include a processor 121, a memory 122, a transmitting unit 123, and a receiving unit 124. These components may be coupled together via a communication bus 125. The memory 122 may store instructions thereon that, when executed by the processor 121, cause the AP 120 to perform the method 900 described above.

[0098] Examples of processors 111 and 121 may include microprocessors, microcontrollers, digital signal processors (DSPs), field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gated logic, discrete hardware circuits, and other suitable hardware configured to perform the various functionalities described throughout this disclosure.

[0099] Each of processors 111 and 121 can execute software. Whether referred to as software, firmware, middleware, microcode, hardware description language, or other terms, the term "software" should be broadly interpreted to mean instructions, instruction sets, code, code segments, program code, programs, subroutines, software modules, applications, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc. The corresponding software can reside on memories 121 and 122, respectively.

[0100] Each of the memories 112 and 122 may be a non-transitory computer-readable medium. For example, non-transitory computer-readable media include magnetic storage devices (e.g., hard disks, floppy disks, magnetic stripes), optical disks (e.g., compact discs (CDs) or digital versatile discs (DVDs)), smart cards, flash memory devices (e.g., card, stick, or key drives), random access memory (RAM), read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), registers, removable disks, and any other suitable medium for storing software and / or instructions that can be accessed and read by a computer.

[0101] Furthermore, according to another embodiment of this disclosure, a computer program product for establishing a wireless network is disclosed. As an example, the computer program product includes a computer-readable medium having program instructions embodied therewith, and these program instructions are executable by a processor. When the program instructions are executed by the processor, one or more of the processes described above are performed. This disclosure can be a system, method, and / or computer program product at any possible level of technical detail integration. The computer program product may include a computer-readable storage medium having computer-readable program instructions thereon for causing a processor to perform aspects of this disclosure.

[0102] This disclosure can be a system, method, and / or computer program product at any possible level of technical detail integration. A computer program product may include a computer-readable storage medium having computer-readable program instructions thereon for causing a processor to perform aspects of this disclosure.

[0103] Unless otherwise expressly stated, expressions such as “according to,” “based on,” “dependent on,” etc., as used in this disclosure do not mean “according to only,” “based on only,” or “dependent on only.” In other words, such expressions in this disclosure generally mean “at least according to,” “at least based on,” or “at least dependent on.”

[0104] As used in this disclosure, the term "determine" can include various operations. For example, "determine" refers to operations, calculations, processing, derivation, investigation, searching (e.g., searching in a table, database, or other data structure), ascertainment, etc. Additionally, "determine" refers to receiving (e.g., receiving information), sending (e.g., sending information), inputting, outputting, accessing (e.g., accessing data in memory), etc. Furthermore, "determine" can also refer to parsing, selecting, picking, building, comparing, etc. That is, several actions can be considered as "determining" in relation to "determining".

[0105] As used in this disclosure, terms such as “connection,” “coupling,” or any variations thereof refer to any direct or indirect connection or combination between two or more units, which may include situations where one or more intermediate units exist between two units that are “connected” or “coupled” to each other. The coupling or connection between units may be physical or logical, or a combination of both. As used in this disclosure, two units may be considered electrically connected by means of one or more wires, cables, and / or printing, and as numerous non-limiting and non-exhaustive examples, they may be “connected” or “coupled” to each other by means of electromagnetic energy having wavelengths in the radio frequency region, microwave region, and / or light (visible and invisible) region, etc.

[0106] When used in this disclosure or claims, the terms “comprising,” “including,” and variations thereof are open-ended, as is the term “having.” Furthermore, the term “or” as used in this disclosure or claims is not an exclusive or.

[0107] The present disclosure has been described in detail above, but it will be apparent to those skilled in the art that the present disclosure is not limited to the embodiments described herein. The present disclosure can be implemented as modifications and variations without departing from the spirit and scope of the present disclosure as defined by the claims. Therefore, the description in this disclosure is illustrative and does not constitute any limitation on the present disclosure.

Claims

1. A method for establishing a wireless connection from an access point (AP), comprising: Receive an access request, the access request indicating that the client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; Obtain a target private pre-shared key (PSK), which the client device will use to connect to the target network according to a security protocol different from the WPA3 protocol; as well as In response to the correctness of the target private PSK, the client device is controlled to connect to the target network using the target private PSK according to the WPA3 protocol.

2. The method according to claim 1, wherein, The security protocol includes: Wi-Fi Protected Access 2 (WPA2) protocol; Hypertext Transfer Protocol Security (HTTPS) protocol; or Portal authentication protocol.

3. The method according to claim 2, wherein, The security protocol is the WPA2 protocol, and obtaining the target private PSK includes: In response to receiving the access request, an access request response is sent to the client device, the access request response instructing the client device to establish a pre-connection with the AP according to the WPA2 protocol; and During the pre-connection with the client device according to the WPA2 protocol, the target private PSK is obtained from the client device.

4. The method according to claim 1, wherein, A set of private PSKs associated with the client device is not bound to a Media Access Control (MAC) address, and the correctness of the target private PSK is determined based on the target private PSK matching one of the private PSKs in the set; or The set of private PSKs is bound to a MAC address, and the correctness of the target private PSK is determined based on the target private PSK matching one of the private PSKs in the set of private PSKs and the MAC address of the client device included in the access request matching the MAC address to which the set of private PSKs is bound.

5. The method according to claim 3, wherein, Controlling the client device to connect to the target network according to the WPA3 protocol includes: Disconnect the client device from the established pre-connection, causing the client device to send another access request to the AP, indicating that the client device is requesting access to the target network; In response to receiving the other access request, a connection indication is sent to the client device, the connection indication instructing the client device to establish a connection with the AP according to the WPA3 protocol; and The target private PSK is used to perform the peer simultaneous authentication (SAE) authentication process as defined by the WPA3 protocol.

6. The method according to claim 2, wherein, The security protocol is the HTTPS protocol, and obtaining the target private PSK includes: In response to receiving the access request from an intermediate server associated with the AP via a first auxiliary network using the HTTPS protocol, the target private PSK is obtained from the access request, and The intermediate server is configured to send a list of networks including the target network to the client device via the first auxiliary network, and in response to the target network being selected, to send a private PSK request for requesting the target private PSK to the client device via the first auxiliary network.

7. The method according to claim 6, wherein, Controlling the client device to connect to the target network according to the WPA3 protocol includes: The first auxiliary network sends a verification result message indicating that the target private PSK is correct to the intermediate server; and The target private PSK is used to perform the simultaneous peer authentication (SAE) authentication process as defined by the WPA3 protocol. The intermediate server is configured to send a connection indication to the client device in response to receiving the verification result message, the connection indication instructing the client device to establish a connection with the AP according to the WPA3 protocol.

8. The method according to claim 2, wherein, The security protocol is the portal authentication protocol, and obtaining the target private PSK includes: In response to receiving the access request from the client device via an unencrypted second auxiliary network created by the AP, the client device is redirected to the portal server using the portal authentication protocol associated with the AP, such that the portal server sends a portal authentication request to the client device to request the client device's identity credentials. Receive the identity credentials of the client device from the portal server; In response to the correct identity credentials, an authentication result message indicating successful authentication is sent to the portal server, causing the portal server to send a private PSK setting instruction to the client device, instructing the client device to set the target private PSK; and Receive the target private PSK from the portal server.

9. The method according to claim 8, wherein, The target private PSK is correct based on the successful verification of the identity credentials.

10. The method according to claim 8, wherein, Controlling the client device to connect to the target network according to the WPA3 protocol includes: After receiving the target private PSK, the client device is disconnected from the second auxiliary network, causing the client device to send another access request to the AP, indicating that the client device is requesting access to the target network. Send a connection indication to the client device, the connection indication instructing the client device to establish the connection with the AP according to the WPA3 protocol; and The target private PSK is used to perform the peer simultaneous authentication (SAE) authentication process as defined by the WPA3 protocol.

11. The method of claim 10, further comprising: In response to receiving the target private PSK, a private PSK confirmation message is sent to the portal server, causing the portal server to forward the private PSK confirmation message to the client device.

12. A method for establishing a wireless connection by a client device, comprising: Send an access request to an access point (AP), the access request indicating that the client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; The target private pre-shared key (PSK) is provided to the AP, and the target private pre-shared key (PSK) will be used by the client device to connect to the target network according to a security protocol different from the WPA3 protocol; as well as In response to receiving a connection instruction instructing the client device to establish a connection with the AP according to the WPA3 protocol, the target private PSK is used to perform the peer simultaneous authentication (SAE) authentication process as specified by the WPA3 protocol.

13. The method according to claim 12, wherein, The security protocol includes: Wi-Fi Protected Access 2 (WPA2) protocol; Hypertext Transfer Protocol Security (HTTPS) protocol; or Portal authentication protocol.

14. The method according to claim 13, wherein, The security protocol is WPA2, and providing the target private PSK includes: The client device receives an access request response from the AP, the access request response instructing the client device to establish a pre-connection with the AP according to the WPA2 protocol; and A pre-connection is established with the AP according to the WPA2 protocol, so that the AP obtains the target private PSK during the establishment of the pre-connection.

15. The method according to claim 13, wherein, The security protocol is HTTPS, and providing the target private PSK includes: Receive a network list including the target network from an intermediate server associated with the AP via a first auxiliary network using the HTTPS protocol; Select the target network from the network list; In response to receiving a private PSK request for the target private PSK for the client device from the intermediate server, the target private PSK is sent to the intermediate server via the first auxiliary network. The intermediate server is configured to send the access request, which includes the target private PSK, to the AP in response to receiving the target private PSK.

16. The method according to claim 13, wherein, The security protocol is the portal authentication protocol, and providing the target private PSK includes: The access request is sent to the AP via an unencrypted second auxiliary network created by the AP, causing the AP to redirect the client device to a portal server associated with the AP; In response to receiving a portal authentication request from the portal server, the client device's identity credentials are sent to the portal server; and In response to receiving a private PSK setting instruction from the portal server, the target private PSK is sent to the portal server.

17. An access point (AP), comprising: Memory, on which instructions are stored; as well as A processor, coupled to the memory, is configured to execute the instructions to cause the AP to: Receive an access request, the access request indicating that the client device is requesting access to a target network created by the AP using the Wi-Fi Protected Access 3 (WPA3) protocol; Obtain a target private pre-shared key (PSK), which the client device will use to connect to the target network according to a security protocol different from the WPA3 protocol; as well as In response to the correctness of the target private PSK, the client device is controlled to connect to the target network using the target private PSK according to the WPA3 protocol.

18. The AP according to claim 17, wherein, The security protocol is Wi-Fi Protected Access 2 (WPA2) protocol, and wherein, in order to obtain the target private PSK, the processor is configured to execute the instructions to make the AP: In response to receiving the access request, an access request response is sent to the client device, the access request response instructing the client device to establish a pre-connection with the AP according to the WPA2 protocol; and During the pre-connection with the client device according to the WPA2 protocol, the target private PSK is obtained from the client device.

19. The AP according to claim 17, wherein, The security protocol is Hypertext Transfer Protocol Security (HTTPS), and wherein, in order to obtain the target private PSK, the processor is configured to execute the instructions to cause the AP to: In response to receiving the access request from an intermediate server associated with the AP via a first auxiliary network using the HTTPS protocol, the target private PSK is obtained from the access request, and The intermediate server is configured to send a list of networks including the target network to the client device via the first auxiliary network, and in response to the target network being selected, to send a private PSK request for requesting the target private PSK to the client device via the first auxiliary network.

20. The AP according to claim 17, wherein, The security protocol is a portal authentication protocol, and wherein, in order to obtain the target private PSK, the processor is configured to execute the instructions to make the AP: In response to receiving the access request from the client device via an unencrypted second auxiliary network created by the AP, the client device is redirected to the portal server using the portal authentication protocol associated with the AP, such that the portal server sends a portal authentication request to the client device to request the client device's identity credentials. Receive the identity credentials of the client device from the portal server; In response to the correct identity credentials, an authentication result message indicating successful authentication is sent to the portal server, causing the portal server to send a private PSK setting instruction to the client device, instructing the client device to set the target private PSK; and Receive the target private PSK from the portal server.