Access point and method for establishing wireless connection executed by access point and client

By providing multiple wireless networks that support different protocols at the AP and recording the STA's private PSK mapping relationship, the problem of PPSK being unable to access the WPA3 protocol was solved, thus improving compatibility and security.

CN121968363APending Publication Date: 2026-05-01TP-LINK INT SHENZHEN CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TP-LINK INT SHENZHEN CO LTD
Filing Date
2026-03-10
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing technologies cannot use a private pre-shared key (PPSK) to access a WPA3 protocol wireless network because the WPA3 protocol introduces SAE authentication, and the STA and AP cannot determine the private PSK used.

Method used

It provides multiple wireless networks, each supporting WPA, WPA2, and WPA3 protocols. By recording the unique mapping relationship between the STA and the private PSK, it gradually establishes wireless connections to ensure successful SAE certification.

Benefits of technology

It enables STAs to access WPA3 protocol wireless networks using a private PSK method, ensuring compatibility with older devices and avoiding connection rejection issues caused by protocol conversion.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121968363A_ABST
    Figure CN121968363A_ABST
Patent Text Reader

Abstract

An access point (AP), a method performed by the AP and a client (STA) for establishing a wireless connection are provided. Wherein the method executed by the AP comprises: providing a plurality of wireless networks having the same SSID and different BSSIDs, the plurality of wireless networks including a first wireless network supporting only a Wi-Fi protected access (WPA) protocol, a second wireless network supporting WPA and WPA2 protocols, and a third wireless network supporting WPA2 and WPA3 protocols; and in response to receiving an access request from the STA, establishing a wireless connection with the STA using the first wireless network, the second wireless network and the third wireless network in sequence, in which the first wireless network records a unique mapping relationship between the STA and a private pre-shared key (PSK) used by the STA during establishment of the wireless connection with the STA using the first wireless network, and the second wireless network records a unique mapping relationship between the STA and the private pre-shared key (PSK) used by the STA during establishment of the wireless connection with the STA using the third wireless network. To use the private PSK in the unique mapping relationship during establishment of a wireless connection with the STA using the second wireless network and the third wireless network.
Need to check novelty before this filing date? Find Prior Art

Description

The methods for establishing a wireless connection executed by the access point and the client. Technical Field

[0001] This disclosure relates to wireless communication, and more specifically, to an access point (AP) and methods for establishing a wireless connection performed by the AP, methods for establishing a wireless connection performed by a station (STA), a computer-readable storage medium, and a computer program product. Background Technology

[0002] Traditional wireless networks use a shared public pre-shared key (PSK) for all users or devices to access the network. When the public PSK is leaked, it needs to be modified, but this will interrupt network access for all users or devices. Therefore, a technology using a private pre-shared key (PPSK) to access wireless networks emerged. With PPSK, if a user's or device's private PSK is leaked, only that private PSK needs to be deleted, without interrupting network access for other users or devices. The Wi-Fi Protected Access 3 (WPA3) protocol, due to the introduction of SAE authentication, improves security compared to WPA and Wi-Fi Protected Access 2 (WPA2) protocols. However, currently, private PSK technology cannot be used to access WPA3 wireless networks. Summary of the Invention

[0003] One aspect of this disclosure provides a method for establishing a wireless connection performed by a first access point (AP), the method comprising: providing a plurality of wireless networks having the same Service Set Identifier (SSID) but different Basic Service Set Identifiers (BSSID), wherein the plurality of wireless networks includes a first wireless network supporting only the Wi-Fi Protected Access (WPA) protocol, a second wireless network supporting both WPA and Wi-Fi Protected Access 2 (WPA2) protocols, and a third wireless network supporting both WPA2 and Wi-Fi Protected Access 3 (WPA3) protocols; and, in response to receiving an access request from a client, sequentially establishing a wireless connection with the client using the first wireless network, the second wireless network, and the third wireless network, wherein during the establishment of a wireless connection with the client using the first wireless network, the first wireless network records a unique mapping relationship between the client and a private PSK used by the client, so as to use the private PSK in the unique mapping relationship during the establishment of a wireless connection with the client using the second wireless network and the third wireless network.

[0004] Another aspect of this disclosure provides a method for establishing a wireless connection performed by a STA, the method comprising: sending an access request to an access point (AP), wherein the AP provides a plurality of wireless networks having the same Service Set Identifier (SSID) but different Basic Service Set Identifiers (BSSIDs), wherein the plurality of wireless networks includes a first wireless network supporting only the WPA protocol, a second wireless network supporting both WPA and WPA2 protocols, and a third wireless network supporting both WPA2 and WPA3 protocols; and sequentially responding to receiving an access request from the first wireless network by using a private PSK to establish a wireless connection with the first wireless network, responding to receiving an access request from the second wireless network by using the private PSK to establish a wireless connection with the second wireless network, and responding to receiving a request from the third wireless network by using the private PSK to establish a wireless connection with the third wireless network.

[0005] Another aspect of this disclosure provides an access point (AP) that can serve as the aforementioned first AP, comprising: a memory having instructions stored thereon; and a processor coupled to the memory, the processor being configured to execute the instructions to cause the AP to perform the method for wireless connectivity as described above, performed by the first AP.

[0006] Another aspect of this disclosure provides a computer program product having instructions stored thereon that, when executed by the processor of an AP, cause the AP to perform the wireless connection method as previously described by the first AP.

[0007] The AP and the method for establishing a wireless connection performed by the AP according to this disclosure can ensure that clients can access WPA3 protocol wireless networks using proprietary PSK technology. Attached Figure Description

[0008] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to offer a further understanding of the embodiments of this disclosure and form part of the specification. The drawings, together with the embodiments of this disclosure, are used to explain this disclosure but do not constitute a limitation thereof. In the drawings, unless explicitly stated otherwise, the same reference numerals denote the same parts, steps, or elements.

[0009] Figure 1 illustrates a schematic system for implementing access to a WPA3 protocol wireless network via a private PSK according to a first embodiment of the present disclosure;

[0010] Figure 2 shows a schematic flowchart of a method for wireless connectivity performed by an AP according to a first embodiment of the present disclosure;

[0011] Figure 3 shows a schematic flowchart of step S230 in Figure 2;

[0012] Figure 4 illustrates a schematic interaction between the AP and STA according to a first embodiment of the present disclosure;

[0013] Figure 5 illustrates a schematic system for implementing a private PSK to access a WPA3 protocol wireless network according to a second embodiment of the present disclosure;

[0014] Figure 6 shows a schematic flowchart of a method for wireless connectivity performed by an AP according to a second embodiment of the present disclosure;

[0015] Figure 7 shows a schematic flowchart of steps S630 and S640 in Figure 6;

[0016] Figure 8 illustrates a schematic interaction between the AP and STA according to a second embodiment of the present disclosure;

[0017] Figure 9 illustrates a schematic diagram of synchronizing client association status information among multiple APs according to at least one embodiment of the present disclosure; and

[0018] Figure 10 shows a schematic structural block diagram of an access point according to at least one embodiment of the present disclosure. Detailed Implementation

[0019] The technical solutions of this disclosure will now be clearly and completely described with reference to the accompanying drawings. The described embodiments are part of the embodiments of this disclosure, but not all embodiments. All other embodiments obtained by those skilled in the art based on the embodiments of this disclosure without any creative effort are within the scope of protection of this disclosure.

[0020] In the description of this disclosure, words such as "exemplary" and "for example" are used to illustrate, exemplify, or explain. Unless otherwise stated, any embodiment or design referred to as "exemplary" in this disclosure should not be construed as being more preferred or advantageous than other embodiments or designs. Rather, the term "exemplary" is intended to present concepts in a specific form.

[0021] In the description of this disclosure, unless otherwise stated, terms such as “first,” “second,” and “third” are used for descriptive purposes only and should not be construed as indicating or implying relative importance. Similarly, words such as “a,” “an,” or “the” do not indicate a quantity limitation but rather indicate the presence of at least one. Words such as “comprising” or “including” mean that the element or object preceding the word encompasses those elements or objects listed following the word and their equivalents, without excluding other elements or objects. Words such as “connection” or “link” are not limited to physical or mechanical connections but can include electrical connections, whether direct or indirect.

[0022] In the description of this disclosure, unless otherwise stated, "B corresponding to A" means that B is associated with A and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.

[0023] In the description of this disclosure, unless otherwise stated, "at least one" means one or more, and "more than" means two or more. "And / or" describes the relationship between related objects, implying the existence of three relationships. For example, A and / or B can represent: the existence of A alone, the existence of both A and B simultaneously, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, covering any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or multiple.

[0024] In the description of this disclosure, an AP may also be referred to as a wireless access point or hotspot. An AP is an access point for mobile users to access a wired network, mainly deployed in homes, buildings, and campuses, with a typical coverage radius of tens to hundreds of meters, but it can also be deployed outdoors. An AP acts as a bridge connecting wired and wireless networks, its main function being to connect various wireless network clients together, thereby connecting the wireless network to the Ethernet.

[0025] In the description of this disclosure, the STA can be a wireless communication chip, a wireless sensor, or a wireless communication terminal. Examples include mobile phones with Wi-Fi communication capabilities, tablet computers with Wi-Fi communication capabilities, set-top boxes, smart TVs, smartphones, smart wearable devices, in-vehicle communication devices, and computers.

[0026] In the description of this disclosure, an STA or AP may include a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also called main memory). The operating system can be any one or more computer operating systems that implement business processing through processes, such as Linux, Unix, Android, iOS, or Windows. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software. The above examples do not limit the specific structure of the execution entity of the method provided in the embodiments of this disclosure to a unique implementation form. As long as communication can be carried out according to the method provided in the embodiments of this disclosure by running a program that records the code of the method provided in the embodiments of this disclosure, for example, the execution entity of the method provided in the embodiments of this disclosure can be an STA or AP, or a module in the STA or AP that can call and execute a program function.

[0027] Furthermore, various aspects or features of this disclosure can be implemented as methods, apparatus, or products employing standard programming and / or engineering techniques. As used herein, the term "product" encompasses a computer program accessible from any computer-readable device, carrier, or medium. For example, computer-readable media may include, but are not limited to: magnetic storage devices (e.g., hard disks, floppy disks, or magnetic tapes), optical discs (e.g., compact discs (CDs), digital versatile discs (DVDs), etc.), smart cards, and flash memory devices (e.g., erasable programmable read-only memory (EPROM), etc.). Additionally, the various storage media described herein may represent one or more devices and / or other machine-readable media for storing information. The term "computer-readable medium" may include, but is not limited to, wireless channels and various other media capable of storing, containing, and / or carrying instructions and / or data.

[0028] Some of the accompanying drawings in this disclosure may not depict all components of a given method, apparatus, and system. Throughout the specification and drawings, the same reference numerals may be used to denote the same features.

[0029] As mentioned earlier, current PPSK technology is only applicable to WPA and WPA2 protocol wireless networks and cannot yet access WPA3 protocol wireless networks via a private PSK. This is because the WPA3 protocol introduces SAE authentication to improve security, and the success of SAE authentication depends on the STA and AP using the same private PSK to perform the SAE authentication process. When the STA may use any of several legitimate and correct private PSKs, the AP cannot determine which private PSK the STA is using during SAE authentication, thus SAE authentication cannot be performed, preventing the STA from accessing the WPA3 protocol wireless network. Therefore, this disclosure provides a WPA-compatible method for accessing a WPA3 protocol wireless network using a private PSK through multi-wireless network convergence bootstrapping.

[0030] Figure 1 illustrates a schematic system for implementing a WPA3 protocol wireless network with a private PSK according to a first embodiment of the present disclosure.

[0031] Referring to Figure 1, system 100 may include AP 110, STA 120, and server 130. Access point 110 can provide multiple wireless networks with the same SSID but different BSSIDs. As shown, three such wireless networks can be provided. The first wireless network 150 only supports the WPA protocol, and its BSSID is BSSID_150. The second wireless network 160 supports both WPA and WPA2 protocols (i.e., supports WPA / WPA2 mixed mode), and its BSSID is BSSID_160, which is different from BSSID1. The third network 170 supports both WPA2 and WPA3 protocols (i.e., supports WPA2 / WPA3 mixed mode), and its BSSID is BSSID_170, which is different from both BSSID_150 and BSSID_160.

[0032] Server 130 may include, but is not limited to, controlling and coordinating the collection, storage, protection, encryption, decryption, archiving, and destruction of data generated during interactions between the various entities of system 100. In one example, server 130 may be an AAA server (i.e., a server responsible for authentication, authorization, and accounting).

[0033] Under PPSK technology, STA120 can be configured to have multiple private PSKs (e.g., assigned by the network administrator or set by the STA). These private PSKs can be pre-stored in server 130 connected to access point 110 to verify the correctness of the private PSK used by STA120 during subsequent wireless connection establishment. If the private PSK used by STA120 is not one of these pre-stored private PSKs, it is considered that STA120 is using an incorrect private PSK, and access to STA120 can be denied.

[0034] Figure 2 shows a schematic flowchart of a method for wireless connectivity performed by an AP according to a first embodiment of the present disclosure.

[0035] Referring to FIG2, the wireless connection method 200 performed by an AP according to the first embodiment of the present disclosure may include steps S210 to S230. The method 200 is performed by the AP110 of FIG1 below.

[0036] In step S210, AP 110 can provide a first wireless network 150 that supports only the WPA protocol but has different BSSIDs, a second wireless network 160 that supports both WPA and WPA2 protocols (i.e., supports WPA / WPA2 mixed mode), and a third wireless network 170 that supports both WPA2 and WPA3 protocols (i.e. supports WPA2 / WPA3 mixed mode), as described in conjunction with FIG1.

[0037] In step S220, AP110 may receive an access request from STA120. This access request may include information elements associated with STA120, such as a unique identifier for STA120 (e.g., a MAC address). In one example, the access request may be a probe request frame or be included within a probe request frame. For example, STA120 may send probe request frames to the first wireless network 150, the second wireless network 160, and the third wireless network 170 respectively after receiving beacon frames from the first wireless network 150, the second wireless network 160, and the third wireless network 170. In another example, the access request may also be an association request frame or be included within an association request frame.

[0038] In step 230, in response to receiving an access request from STA 120, AP 110 can sequentially establish a wireless connection with STA 120 using the first wireless network 150, the second wireless network 160, and the third wireless network 170. Furthermore, during the establishment of a wireless connection with STA 120 using the first wireless network 150, the first wireless network 150 records a unique mapping relationship between STA 120 and the private PSK used by the STA, so that the private PSK recorded in the unique mapping relationship can be used during the establishment of wireless connections with STA 120 using the second wireless network 160 and the third wireless network 170.

[0039] Generally, STA120 can be configured to select the highest protocol among two or more wireless networks (i.e., mixed mode) when establishing a wireless connection, as higher protocols offer greater security. For example, when STA120 establishes a wireless connection with the second wireless network 160, it selects WPA2; when STA120 establishes a wireless connection with the third wireless network 170, it selects WPA3. Therefore, in step 230, AP110 sequentially uses the first wireless network 150, the second wireless network 160, and the third wireless network 170 to establish wireless connections with STA120. This allows STA120 to sequentially use its proprietary PSK to establish connections with AP110 according to WPA, WPA2, and WPA3 protocols, ultimately enabling STA120 to access the WPA3 protocol wireless network using its proprietary PSK.

[0040] It should be noted that the unique mapping relationship between STA120 and its proprietary PSK described here does not refer to the correspondence between STA120 and its multiple proprietary PSKs mentioned earlier, but rather to the correspondence between STA120 and the proprietary PSK it uses when establishing a wireless connection with the first wireless network 150. Even if STA120 has multiple proprietary PSKs, only one proprietary PSK can be used at a time to perform the authentication process during the establishment of a wireless connection; therefore, this mapping relationship is unique. If STA120 uses another proprietary PSK from among its multiple proprietary PSKs to establish a wireless connection, the proprietary PSK recorded in this unique mapping relationship will also change accordingly.

[0041] In this way, method 200 offers the following benefits: Since the unique mapping between STA120 and its proprietary PSK is recorded by the first wireless network 150 when STA120 establishes a wireless connection with the first wireless network 150 using the proprietary PSK, when AP110 subsequently establishes a wireless connection with STA120 using the second wireless network 160 and the third wireless network 170, this unique mapping can be directly or indirectly queried to determine the proprietary PSK that STA120 will use. This ensures that the proprietary PSK used by AP110 when finally establishing a WPA3 connection with STA120 is consistent with that used by STA, thereby facilitating successful SAE certification.

[0042] In this way, method 200 also offers the following benefits: For some older STAs, which may not recognize encryption methods above WPA, AP110 can still be compatible with these older STAs because it provides not only a primary wireless network 150 supporting the WPA-only protocol, but also a WPA / WPA2 hybrid encrypted wireless network and a hybrid encrypted wireless network using WPA2 and higher encryption methods. For example, if STA120 is an older device that only supports the WPA protocol, and AP110 only provides a wireless network with a usage level higher than WPA, STA120 cannot establish a connection with AP110 at all. However, if AP110 uses method 200, it can ensure that STA120 and AP110 can still establish a connection using WPA.

[0043] It should be understood that, since the current protocol does not specify a mixed WPA and WPA3 mode, if the STA is allowed to directly transition from a WPA protocol wireless network to a mixed WPA2 and WPA3 protocol wireless network, STA120 may experience connection rejection issues (e.g., due to reasons related to Protected Management Frames (PMF)). Therefore, method 200 does not allow the STA to directly transition from a WPA protocol wireless network to a mixed WPA2 and WPA3 protocol wireless network, but instead allows the STA to directly transition from a WPA protocol wireless network to a mixed WPA2 and WPA3 protocol wireless network, and then to a mixed WPA2 and WPA3 protocol wireless network.

[0044] Figure 3 shows a schematic flowchart of step S230 in Figure 2.

[0045] Referring to Figure 3, step S230 may further include sub-steps S301 to S311.

[0046] In sub-step S301, in response to receiving an access request from STA 120, AP 110 can determine whether STA 120 has associated with the first wireless network 150. For example, AP 110 can identify a unique identifier (e.g., MAC address) of STA 120 from the access request and determine whether STA 120 has associated with the first wireless network 150 based on that unique identifier. In one example, AP 110 can use an association record maintained by itself or server 130 representing the MAC addresses of currently connected and recently connected STAs to determine whether STA 120 has associated with the first wireless network 150. In another example, AP 110 can query historical logs related to the association process stored in itself or server 130 to determine whether STA 120 has associated with the first wireless network 150. If it is determined in sub-step S301 that AP 110 has not associated with the first wireless network 150, proceed to sub-step S302. Conversely, if it is determined in sub-step S301 that AP 110 has associated with the first wireless network 150, proceed to sub-step S307.

[0047] In sub-step S302, AP110 establishes a wireless connection with STA120 using the first wireless network 150. Specifically, AP110 sends an access request response to STA120 using the first wireless network 150. When the access request sent by STA120 is a probe request frame, the access request response from AP110 can be a probe response frame. When the access request sent by STA120 is an association request frame, the access request response from AP110 can be an association response frame. For example, when the access request sent by STA120 is a probe request frame, AP110 can send a probe response frame to STA120 whose frame header includes the BSSID (i.e., BSSID_150) indicating the sender of the frame, and whose frame body includes information elements indicating that the first wireless network 150 with the BSSID only supports the WPA protocol. After receiving the probe response frame, STA120 establishes a wireless connection with the first wireless network 150 in accordance with the WPA protocol. During the process of establishing a wireless connection with the first wireless network 150, STA120 can also refuse to access the first wireless network 150 if the encryption method-related information carried in the probe response frame received from the first wireless network 150 is inconsistent with the encryption method-related information carried in the beacon frame received from the first wireless network 150, in order to avoid potential risks including downgrade attacks.

[0048] During the establishment of a wireless connection between STA120 and the first wireless network 150 according to the WPA protocol, AP110 can determine the private PSK used by STA120. In one example, AP110 can send a request for the private PSK to server 130, which includes the MAC address of STA120. Server 130 can match the private PSK used by STA120 in this connection with a plurality of private PSKs pre-stored on it. If the private PSK used by STA120 matches one of the plurality of private PSKs owned by STA120 pre-stored on server 130, server 130 determines that the private PSK used by STA120 is correct and sends a verification result indicating that the private PSK used by STA120 is correct to AP110. This verification result may include the private PSK used by STA120. Conversely, if the private PSK used by STA120 does not match any of the plurality of private PSKs pre-stored on server 130, server 130 sends a verification result indicating that the private PSK used by STA120 is incorrect to AP110. It should be understood that the method described herein for AP110 to learn about the proprietary PSK used by STA120 is merely an example, and AP110 may also use other methods (such as those specified in the relevant protocols) to learn about the proprietary PSK used by STA120.

[0049] In sub-step S303, AP110 can determine whether the private PSK used by STA120 is correct. For example, in the previous example, AP110 can determine this based on the verification result received from server 130. If it is determined that the private PSK used by STA120 is incorrect, proceed to sub-step S304 and deny STA120 access. If it is determined that the private PSK used by STA120 is correct, proceed to sub-step S305 to record the unique mapping relationship between STA120 and the private PSK. For example, this unique mapping relationship records that the MAC address of STA120 uniquely corresponds to the private PSK. This unique mapping relationship can be recorded in AP110 itself or in server 130.

[0050] After STA 120 successfully establishes a wireless connection with the first wireless network 150, AP 110 can execute sub-step S306 to disconnect the network connection with STA 120. The "disconnection" can be done in various ways. For example, in this step, AP 110 can send a Deauth frame to STA 120 to actively kick out STA 120 or wait for STA 120 to actively reconnect. It can also send a BTM (BSS Transition Management) message to STA 120 to suggest that STA 120 migrate to another BSSID, etc. Once STA 120 disconnects from the first wireless network 150, STA 120 will resend the access request to AP 110, and method 300 returns to step S301.

[0051] Executing sub-step S301 again, AP110 will find that STA120 has already associated with the first wireless network 150, and then proceed to sub-step S307. In sub-step S307, AP110 can determine whether STA120 has associated with the second wireless network 160. For example, in a similar manner as described above, AP110 can determine whether STA120 has associated with the second wireless network 160 by querying association records or historical logs that contain the MAC addresses of currently connected and recently connected STAs. If it is determined in this step that STA120 has not associated with the second wireless network 160, then proceed to sub-step S308. Conversely, if it is determined in this step that STA120 has associated with the second wireless network 160, then proceed to sub-step S310.

[0052] In substep S308, AP110 can query the private PSK in the unique mapping relationship recorded by the first wireless network 150. Then, proceeding to substep S309, AP110 establishes a wireless connection with STA120 using the second wireless network 160 and the queried private PSK. In substep S309, AP110 can send an access request response to STA120 using the second wireless network 160. When the access request sent by STA120 is a probe request frame, AP110 replies with an access request response frame. When the access request is an association request frame, the access request response is an association response frame. For example, when the access request sent by STA120 is a probe request frame, AP110 can send a probe response frame to STA120 whose frame header includes an indication that the sender's BSSID is BSSID_160, and whose frame body includes information elements indicating that the second wireless network 160 with BSSID_160 supports WPA and WPA2 mixed modes. As previously mentioned, STA120 can be configured to select the highest protocol among two or more wireless networks when establishing a wireless connection, as higher protocols offer greater security. Therefore, upon receiving the probe response frame, STA120 can establish a wireless connection with the second wireless network 160 according to the WPA2 protocol. During the connection establishment process, STA120 can also refuse access to the second wireless network 160 if the encryption information carried in the probe response frame received from the second wireless network 160 is inconsistent with the encryption information carried in the beacon frame received from the second wireless network 160, thus mitigating potential risks, including downgrade attacks.

[0053] After successfully establishing a wireless connection with the second wireless network 160, AP110 can execute sub-step S306 to disconnect the network connection with STA120. The "disconnection" can be done in various ways. In this step, AP110 can disconnect STA120 from the second wireless network 160 by sending a Deauth frame to STA120 to actively kick it out, or by waiting for STA120 to actively reconnect. Once STA120 is disconnected from the second wireless network 160, STA120 resends the access request to AP110, and method 300 returns to step S301.

[0054] Executing sub-step S301 again, AP110 will discover that STA120 has already associated with the first wireless network 150, and proceed to sub-step S307. In sub-step S307, AP110 will discover that STA120 has already associated with the second wireless network 160, and proceed to sub-step S310. In sub-step S310, AP110 can query the private PSK in the unique mapping relationship recorded by the first wireless network 150. Then, proceeding to sub-step S311, AP110 uses the third wireless network 170 and the queried private PSK to establish a wireless connection with STA120. In sub-step S311, AP110 can use the third wireless network 170 to send an access request response to STA120. When the access request sent by STA120 is a probe request frame, AP110 replies with an access request response frame. When the access request sent by STA120 is an association request frame, AP110 replies with an access request response frame. For example, when STA120 sends an access request frame that is a probe request frame, AP110 can send STA120 a probe response frame whose frame header includes information indicating that the sender's BSSID is BSSID_170, and whose frame body includes information indicating that the third wireless network 170 with BSSID_170 supports WPA2 and WPA3 mixed modes. As mentioned earlier, STA120 can be configured to choose to establish a wireless connection with a wireless network that supports two or more protocols when establishing a wireless connection with that network. Therefore, when STA120 receives the probe response frame, it can establish a wireless connection with the third wireless network 170 in accordance with the WPA3 protocol. During the process of establishing a wireless connection with the third wireless network 170, STA120 can also refuse access to the third wireless network 170 if the encryption method information carried in the probe response frame received from the third wireless network 170 is inconsistent with the encryption method information carried in the beacon frame received from the third wireless network 170, thereby avoiding potential risks, including downgrade attacks. It should be understood that, in most cases, once STA120 successfully associates and establishes a network connection using a private PSK, it will save this private PSK in its local network configuration file. Furthermore, on subsequent connections, STA120 will use the private PSK used during the last connection establishment, unless the user manually modifies the local network configuration file. Therefore, the private PSK retrieved in substep S308 will essentially be the private PSK that STA120 will use to establish a wireless network with the second wireless network 160 in WPA2 mode, and the private PSK retrieved in substep S310 will also essentially be the private PSK that STA120 will use to establish a wireless network with the third wireless network 170 in WPA3 mode.Therefore, in sub-step S311, STA120 and AP110 will use the same proprietary PSK to perform SAE authentication, thereby ensuring successful SAE authentication.

[0055] In this way, on the AP side, three wireless networks with the same SSID but different BSSIDs are provided, supporting WPA, WPA and WPA2 mixed mode, and WPA2 and WPA3 mixed mode respectively. The STA is guided to establish wireless connections with these three wireless networks in WPA, WPA2 and WPA3 mode respectively, so that the STA can finally establish a network connection with the AP in WPA3 mode using a private PSK.

[0056] Figure 4 illustrates a schematic interaction between the AP and STA according to a first embodiment of the present disclosure.

[0057] Referring to Figure 4, in step S401, STA120 can send an access request to AP110. In step S402, in response to determining that STA120 has not been associated with the first wireless network 150, AP110 can send an access request response to STA120 using the first wireless network 150. In step S403, in response to receiving the access request response, STA120 establishes a wireless connection with the first wireless network 150 in accordance with the WPA protocol. During this process, AP110 only establishes the wireless connection with STA120 and records the unique mapping relationship between STA120 and its private PSK if it determines that the private PSK used by STA120 is correct; otherwise, AP110 rejects STA120's access. In step S404, AP110 can disconnect STA120 from the first wireless network 150. In step S405, STA120 resends the access request to AP110. In step S406, AP110, in response to determining that STA120 has been associated with the first wireless network 150 but not with the second wireless network 160, may send an access request response to STA120 using the second wireless network 160. In step S407, in response to receiving the access request response, STA120 may establish a wireless connection with the second wireless network 160 using the same proprietary PSK used in step S430, as specified in the WPA2 protocol. In step S408, AP110 may disconnect STA120 from the second wireless network 160. In step S409, STA120 resends the access request to AP110. In step S410, in response to determining that STA120 has been associated with both the first wireless network 150 and the second wireless network 160, AP110 may send an access request response to STA120 using the third wireless network 170. In step S411, STA120 establishes a wireless connection with the third wireless network 170 using the same proprietary PSK used in step S430, as specified in the WPA3 protocol. The details of each step in Figure 4 have been described in detail above with reference to Figure 3, and will not be repeated here to avoid repetition.

[0058] As can be seen, in this embodiment, no special configuration is required for the STA to access the WPA2 and WPA3 hybrid wireless network provided by the AP using a private PSK in WPA3 mode. The STA only needs to follow the normal operation, receiving an access request response from the wireless network on the AP, and then performing the process of establishing a wireless connection with that network in accordance with the protocol supported by that wireless network or the method specified by the highest protocol.

[0059] Furthermore, the current protocol requires that BSSIDs operating in the 6GHz band only allow WPA3 protocol access for STAs. In other words, the 6GHz wireless network is a WPA3-only network (also known as a WPA3-only wireless network), rather than a hybrid WPA2 and WPA3 network like the third wireless network 170. Therefore, to facilitate STAs using a private PSK to connect to such a WPA3-only wireless network, this disclosure provides a second embodiment.

[0060] Figure 5 illustrates a schematic system for implementing a WPA3 protocol wireless network with a private PSK according to a second embodiment of the present disclosure.

[0061] Referring to Figure 5, the only difference from Figure 1 is that, in addition to the first wireless network 150, the second wireless network 160, and the third wireless network 170 mentioned above, AP110 also includes a fourth wireless network 180 that only supports WPA3 (i.e., a WPA3-only wireless network). The fourth wireless network 180 has the same SSID as the first to third wireless networks, but has a different BSSID than the first to third wireless networks, which is denoted here as BSSID_180.

[0062] Figure 6 shows a schematic flowchart of a method for wireless connectivity performed by an AP according to a second embodiment of the present disclosure.

[0063] Referring to FIG6, the method 600 for wireless connection executed by AP110 according to the second embodiment of the present disclosure may include steps S610 to S640. Among them, steps S620 and S630 are the same as steps S220 and S230 in FIG2, and to avoid repetition, these two steps will not be described in detail here.

[0064] As shown in Figure 6, in step S610, AP110 provides a first wireless network 150, a second wireless network 160, a third wireless network 170, and a fourth wireless network 180. In step S620, AP110 receives an access request from STA120. In step S630, AP110 sequentially establishes a wireless connection with STA120 using the first wireless network 150, the second wireless network 160, and the third wireless network 170.

[0065] After STA120 successfully establishes a wireless connection with the third wireless network 170, in step S640, AP110 can disconnect STA120 from the third wireless network 170. Then, in response to receiving an access request from the STA, AP110 establishes a wireless connection with STA120 using the fourth wireless network 180. This allows STA120 to ultimately establish a wireless connection with the fourth wireless network 180, which is a WPA3-only wireless network, using WPA3. It should be noted that the encryption method used by STA120 to access the third wireless network 170 (which uses both WPA2 and WPA3) is exactly the same as the encryption method used by STA120 to access the fourth wireless network 180; both use WPA3 encryption. STA120 can actively or passively switch and roam between different frequency bands while maintaining the same encryption method. Therefore, AP110 can also disconnect STA120 from a third wireless network 170 on one frequency band by sending a Deauth frame to actively kick out STA120 or by waiting for STA120 to actively reconnect, and then establish a wireless connection with STA120 using a fourth wireless network 180 on another frequency band. Similarly, to avoid potential risks, including downgrade attacks, STA120 can also refuse to access the fourth wireless network 180 during the process of establishing a wireless connection with the fourth wireless network 180 if the encryption method information carried in the probe response frame received from the fourth wireless network 180 is inconsistent with the encryption method information carried in the beacon frame received from the fourth wireless network 180.

[0066] Figure 7 shows a schematic flowchart of steps S630 and S640 in Figure 6.

[0067] Referring to Figure 7, substeps S701 to S709 in Figure 7 are the same as substeps S301 to S309 in Figure 3, and will not be repeated here to avoid repetition. As shown in Figure 7, the difference from substeps S310 and S311 in Figure 3 is that if it is determined in substep S707 that STA120 has been associated with the second wireless network 160, then proceed to substep S710 to determine whether STA120 has been associated with the third wireless network 170. For example, in a similar manner as described above, AP110 can determine whether STA120 has been associated with the third wireless network 170 by querying association records or historical logs that contain the MAC addresses of currently connected and recently connected STAs. If it is determined in this step that STA120 has not been associated with the third wireless network 170, then proceed to substep S711. Conversely, if it is determined in this step that STA120 has been associated with the third wireless network 170, then proceed to substep S713. In substep S711 or substep S731, AP110 queries the private PSK in the unique mapping relationship recorded by the first wireless network 150. However, after executing substep S711, AP110 executes substep S712 to establish a wireless connection with STA120 using the third wireless network 170. And after executing substep S731, AP110 executes substep S734 to establish a wireless connection with STA120 using the fourth wireless network 180.

[0068] In this way, method 600 according to the second embodiment of this disclosure can enable access to a WPA3-only wireless network using a private PSK. It should be noted that method 600 is applicable not only to the 6GHz band but also to other frequency bands besides 6GHz.

[0069] Figure 8 illustrates a schematic interaction between the AP and STA according to a second embodiment of the present disclosure.

[0070] Referring to Figure 8, steps S801 to S811 are the same as steps S401 to S411 in Figure 4, and will not be repeated here to avoid repetition. As shown in Figure 8, after STA120 successfully establishes a wireless connection with the third wireless network 170 of AP110, in step S812, AP110 can disconnect STA120 from the third wireless network 170. In step S813, STA120 resends an access request to AP110. In step S814, AP110 can, based on the determination that STA120 has been associated with the first wireless network 150, the second wireless network 160, and the third wireless network 170, send an access request response to STA120 using the fourth wireless network 180. In step S815, STA120 can establish a wireless connection with the fourth wireless network 180 in accordance with the WPA3 protocol (the same method as in step S811) and using the same private PSK used in step S430.

[0071] As can be seen, in this embodiment, no special configuration is required for the STA to access the WPA3-only wireless network provided by the AP using a private PSK in WPA3 mode. The STA only needs to follow the normal operation, receiving an access request response from the wireless network on the AP, and then performing the process of establishing a wireless connection with that network in accordance with the protocol supported by that wireless network or the method specified by the highest protocol.

[0072] Furthermore, considering a multi-AP scenario, multiple APs located in different locations may provide the same SSID, allowing STAs to access and use networks with that SSID from different locations. In this scenario, synchronizing the association status between the STA and each network (each BSSID) with that SSID among these APs helps simplify the wireless connection process between the AP and the STA. Based on this, this disclosure proposes a third embodiment.

[0073] Figure 9 is a schematic diagram of synchronizing client association status information among multiple APs according to at least one embodiment of the present disclosure.

[0074] Referring to Figure 9, taking a scenario with two access points (APs) as an example, the multiple wireless networks provided by AP110 are all or part of the same as at least one wireless network provided by AP910. In one example, the at least one wireless network provided by AP910 also includes the aforementioned first wireless network 150 to third wireless network 170. When AP110 or AP910 performs method 200 as described above, it can additionally send client association status information indicating whether STA120 has been associated with each of the first wireless network 150, second wireless network 160, and third wireless network 170 directly or indirectly to the other party. In another example, the at least one wireless network provided by AP910 also includes the aforementioned first wireless network 150 to fourth wireless network 180. When AP110 or AP910 performs method 600 as described above, it can additionally send STA association status information indicating whether STA120 has been associated with each of the first wireless network 150, second wireless network 160, third wireless network 170, and fourth wireless network directly or indirectly to the other party. Preferably, for example, AP110 or AP910 can send the client association status information when STA120 successfully establishes a wireless connection with any of these wireless networks, but this disclosure is not limited thereto, and AP110 or AP910 can also send the client association status information at other suitable times.

[0075] Thus, when AP110 or AP910 receives an access request from STA120, it can comprehensively determine which BSSIDs the STA120 has been associated with on wireless networks based on the STA association status information it has received, thereby omitting some steps shown in Figure 3 or Figure 7.

[0076] In one example, when AP110 or AP910 receives an access request from STA120, it determines from the received client association status information that STA120 has already associated with the first wireless network 150 with BSSID_150 and the second wireless network with BSSID_160. Therefore, it can directly send an access request response to STA120 using the third wireless network 170, guiding STA120 to establish a wireless connection with the third wireless network 170 provided by it in accordance with the WPA3 protocol. AP910 and AP110 are connected to the same server 130; therefore, AP110 or AP910 can also query server 130 to obtain the unique mapping relationship between STA120 and its private PSK, as recorded by the first wireless network of AP910 or AP110.

[0077] STA-related status information can be synchronized between AP110 and AP910 using Ethernet layer broadcast message synchronization, controller synchronization, and combinations thereof.

[0078] Ethernet layer broadcast message synchronization method: For example, when STA120 successfully establishes a wireless connection with the first wireless network 150 provided by AP110, AP110 can send client association status information indicating that STA120 has associated with the first wireless network 150 but not with the second wireless network 160 via an Ethernet layer broadcast message to AP910. Furthermore, this Ethernet layer broadcast message also carries STA120's unique identifier (e.g., MAC address), the SSID and BSSID of the first wireless network 150. AP910 can receive this Ethernet layer broadcast message. Subsequently, when AP910 receives an access request from STA120, AP910 can determine, based on the STA association status information in the Ethernet layer broadcast message, that STA120 has associated with the first wireless network 150 but not with the second wireless network 160. Therefore, AP910 can use its second wireless network 160 to send an access request response to STA120, allowing STA120 to directly attempt to establish a wireless connection with AP910's second wireless network 160 without having to establish a wireless connection with AP910's first wireless network 150.

[0079] Controller Synchronization Method: As shown in Figure 9, a controller 140 is also present to centrally manage and configure both AP110 and AP910. When STA120 successfully establishes a wireless connection with the first wireless network 150 provided by AP110, AP110 can push STA association status information, indicating that STA120 has associated with the first wireless network 150 but not with the second wireless network 160, to controller 140. AP910 can obtain the latest STA association status information from controller 140 and store it locally. Subsequently, when AP910 receives an access request from STA120, it can determine from the STA association status information that STA120 has associated with the first wireless network 150 but not with the second wireless network 160. Therefore, AP910 can use its provided second wireless network 160 to send an access request response to STA120, allowing STA120 to directly attempt to establish a wireless connection with AP910's second wireless network 160 without having to establish a wireless connection with the first wireless network 150 provided by AP910.

[0080] In this way, by synchronizing the association between the STA and the wireless network across multiple APs, the process of establishing a wireless connection between the AP and the STA can be simplified, thus improving efficiency.

[0081] Furthermore, considering that the introduction of controller 140 may increase the complexity of the interaction, and that transmitting Ethernet layer broadcast messages between AP110 and AP910 may also be subject to failure due to a restart of AP110 or AP910, AP110 and AP910 can also use a shared server 130 to simplify the access process, thereby omitting some steps shown in Figure 3 or Figure 7. When AP110 receives an access request from STA120, AP110 can determine whether STA120 has been associated with the first wireless network 150 provided by AP110 by querying its own association record for recording the MAC addresses of currently connected and recently connected STAs or its own historical log. If it is found that STA120 has not been associated with the first wireless network 150, STA120 is allowed to attempt to establish a wireless connection with the first wireless network 150 supporting the WPA protocol and the third wireless network 170 supporting a mixed mode of WPA2 and WPA3, for example, by allowing both the first wireless network 150 and the third wireless network 170 to reply to STA120 with an access request response. If STA120 chooses to attempt to establish a wireless connection with the first wireless network 150 that supports the WPA protocol (e.g., by sending an association request to AP110 instructing it to associate with the first wireless network 150), then AP110 sequentially uses the first wireless network 150, the second wireless network 160, and the third wireless network 170 to establish wireless connections with STA120. In other words, AP110 will execute all the steps of method 200 or 600 to guide STA120 to eventually establish a wireless connection with the third wireless network 170. If STA120 chooses to attempt to establish a wireless connection with the third wireless network 170 that supports WPA2 and WPA3 mixed modes (e.g., by sending an association request to AP110 instructing it to associate with the third wireless network 170), then AP110 queries server 130 to check if a unique mapping exists between STA120 and the private PSK used by STA120, as recorded by AP910. If AP110 finds the unique mapping relationship recorded by AP910 on server 130, AP110 allows STA120 to directly associate with the third wireless network 170, that is, to use the private PSK in the unique mapping relationship to perform SAE authentication with STA120. If AP110 does not find the unique mapping relationship recorded by AP910 on server 130, AP110 rejects STA120's association request and sends an instruction to STA120 to attempt to establish a wireless connection with the first wireless network 150 provided by AP110 in accordance with the WPA protocol. Then, it executes all the steps of method 200 or 600 to guide STA120 to finally establish a wireless connection with the third wireless network 170.

[0082] In the above process, STA120 is configured to, upon receiving access request responses from two or more wireless networks, select the wireless network with a higher protocol that it has previously associated with. Therefore, when STA120 receives access request responses from both the first wireless network 150 and the third wireless network 170 provided by AP110, if STA120 has previously associated with the third wireless network 170 provided by AP910, since the WPA3 protocol level supported by the third wireless network 170 is higher than the WAP protocol supported by the first wireless network, STA120 will choose to attempt to access the third wireless network 170. This method simplifies the process of establishing a wireless connection between the STA and the AP to the greatest extent possible. Especially for new or restarted APs, the STA may not need to connect sequentially through the first, second, and third wireless networks, but can directly establish a connection with the third wireless network, greatly improving access efficiency.

[0083] Figure 10 shows a schematic structural block diagram of an AP according to at least one embodiment of the present disclosure.

[0084] Referring to FIG10, an access point (AP) (e.g., AP110 and AP910) according to at least one embodiment of the present disclosure may include at least one processor 1010 and at least one memory 1020. The at least one memory 1010 stores instructions. The at least one processor 1010 is coupled to the at least one memory 1020, and when the at least one processor 1010 executes the instructions, it causes the access point 1000 to perform the aforementioned wireless connection method 200 or 600.

[0085] Examples of at least one processor 1010 may include a microcontroller, digital signal processor (DSP), field-programmable gate array (FPGA), programmable logic device (PLD), state machine, gated logic, discrete hardware circuit, and other hardware circuits capable of implementing instruction-level arithmetic, signal processing, or control functions. At least one processor 510 can execute software. Software should be broadly understood as instructions, instruction sets, code, code segments, program code, programs, subroutines, software modules, application programs, software applications, software packages, routines, subroutines, objects, executable files, threads of execution, procedures, functions, etc., whether referred to as software, firmware, middleware, microcode, hardware description languages, or other forms. The software may be stored in at least one memory 1020.

[0086] At least one memory 1020 may be a non-volatile computer-readable medium. For example, non-volatile computer-readable media include magnetic storage devices (such as hard disks, floppy disks, magnetic stripes), optical disks (such as optical discs (CDs) or digital versatile optical discs (DVDs)), smart cards, flash memory devices (such as cards, flash memory sticks, or USB flash drives), random access memory (RAM), read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, removable disks, and any other suitable medium that can be used to store software and / or instructions and can be accessed and read by a computer.

[0087] At least one processor 1010 and at least one memory 1020 can be connected via a bus for information communication. The bus can consist of a single bus or multiple different buses.

[0088] Furthermore, an embodiment of this disclosure also provides a computer program product. This computer program product stores instructions that, when executed by a processor, cause one or more steps of the wireless connectivity methods 200 and / or 600 as described above to be performed. As an example, the computer program product includes a non-volatile computer-readable storage medium having instructions executable by a processor. For example, this computer program product can be deployed in AP110 and AP910.

[0089] Furthermore, a computer-readable medium is also provided according to embodiments of this disclosure. This computer-readable medium stores instructions that, when executed by a processor, cause one or more steps of the wireless connections 200 and / or 600 as described above to be performed. For example, this computer-readable medium may be deployed in AP110 and AP910.

[0090] The embodiments of this disclosure have been described above with reference to the accompanying drawings. It should be understood that the above embodiments are merely illustrative, and those skilled in the art should understand that the combination of constituent elements and processes of this embodiment can be modified in various ways, and such modifications also fall within the scope of this disclosure.

Claims

1. A method for establishing a wireless connection, performed by a first access point (AP), comprising: Provide multiple wireless networks with the same Service Set Identifier (SSID) but different Basic Service Set Identifiers (BSSID), wherein the multiple wireless networks include a first wireless network that only supports the Wi-Fi Protected Access (WPA) protocol, a second wireless network that supports WPA and Wi-Fi Protected Access 2 (WPA2) protocols, and a third wireless network that supports WPA2 and Wi-Fi Protected Access 3 (WPA3) protocols; and in response to receiving an access request from a client, sequentially establish a wireless connection with the client using the first wireless network, the second wireless network, and the third wireless network, wherein during the establishment of a wireless connection with the client using the first wireless network, the first wireless network records a unique mapping relationship between the client and the private pre-shared key (PSK) used by the client, so as to use the private PSK in the unique mapping relationship during the establishment of a wireless connection with the client using the second wireless network and the third wireless network.

2. The method according to claim 1, wherein, The plurality of wireless networks also includes a fourth wireless network that only supports the WPA3 protocol; the method further includes disconnecting the client from the third wireless network after the client establishes a wireless connection with the third wireless network, and in response to receiving an access request from the client, establishing a wireless connection with the client using the fourth wireless network.

3. The method according to claim 1, wherein, In response to receiving an access request from a client, establishing a wireless connection with the client sequentially using the first wireless network, the second wireless network, and the third wireless network includes: determining, based on the client's unique identifier included in the access request, that the client has not been associated with the first wireless network; establishing a wireless connection with the client using the first wireless network; disconnecting the client from the first wireless network; establishing a wireless connection with the client using the second wireless network; disconnecting the client from the second wireless network; and establishing a wireless connection with the client using the third wireless network.

4. The method according to claim 1, wherein, In response to receiving an access request from a client, establishing a wireless connection with the client sequentially using the first wireless network, the second wireless network, and the third wireless network includes: determining, based on the client's unique identifier included in the access request, that the client has been associated with the first wireless network but not with the second wireless network; establishing a wireless connection with the client using the second wireless network; disconnecting the client from the second wireless network; and establishing a wireless connection with the client using the third wireless network.

5. The method according to claim 1, wherein, In response to receiving an access request from a client, establishing a wireless connection with the client sequentially using the first wireless network, the second wireless network, and the third wireless network includes: determining, based on the client's unique identifier included in the access request, that the client has been associated with both the first wireless network and the second wireless network, and establishing a wireless connection with the client using the third wireless network.

6. The method according to claim 1, wherein, Establishing a wireless connection between the client and the first wireless network includes sending an access request response from the first wireless network to the client so that the client establishes a wireless connection with the first wireless network in a manner specified by WPA. Establishing a wireless connection between the client and the second wireless network includes sending an access request response from the second wireless network to the client so that the client establishes a wireless connection with the second wireless network in a manner specified by WPA2. Establishing a wireless connection with the client using the third wireless network includes sending an access request response to the client from the third wireless network, so that the client establishes a wireless connection with the third wireless network in a manner specified by WPA3.

7. The method according to claim 6, wherein, The access request includes a probe request frame; and the access request response includes a probe response frame.

8. The method according to claim 6, wherein, The access request includes an associated request frame; and the access request response includes an associated response frame.

9. The method according to claim 1, further comprising: During the establishment of a wireless connection between the client and the first wireless network, the correctness of the private PSK is determined by verification information received from the server associated with the first AP. In response to determining that the private PSK is correct, the unique mapping relationship is recorded using the first wireless network. In response to determining that the private PSK is incorrect, the client is rejected.

10. The method according to claim 9, wherein, The verification information is generated by determining whether the private PSK used by the client matches one or more private PSKs of the client stored on the server.

11. The method according to claim 1, wherein, In response to receiving an access request from a client, establishing a wireless connection with the client sequentially using the first wireless network, the second wireless network, and the third wireless network includes: determining, based on the client's unique identifier included in the access request, that the client has not been associated with the first wireless network, and allowing the client to choose to associate with either the first wireless network or the third wireless network; in response to the client choosing to associate with the first wireless network, or in response to the client choosing to associate with the third wireless network and there is no unique mapping relationship between the client and the private PSK used by the client recorded by a second AP different from the first AP, establishing a wireless connection with the client sequentially using the first wireless network, the second wireless network, and the third wireless network, the method further includes: in response to the client choosing to associate with the third wireless network and there is a unique mapping relationship between the client and the private PSK used by the client recorded by the second AP, establishing a wireless connection with the client using the third wireless network.

12. The method according to claim 11, wherein, Query the server shared by the first AP and the second AP to see if there exists a unique mapping relationship between the client recorded by the second AP and the private PSK used by the client.

13. The method according to any one of claims 3-5, further comprising: The system obtains client association status information indicating whether the client has been associated with at least one of the plurality of wireless networks. The client association status information originates from a second AP different from the first AP. The system determines whether the client has been associated with each of the plurality of wireless networks based on the client's unique identifier included in the access request and the client association status information.

14. The method according to claim 12, wherein, The client association status information can be obtained by receiving an Ethernet layer broadcast message including the client association status information from the second AP; or by obtaining the client association status information from a controller that controls both the first AP and the second AP.

15. A method for establishing a wireless connection performed by a client STA, comprising: Send an access request to an access point (AP), wherein the AP provides multiple wireless networks with the same Service Set Identifier (SSID) but different Basic Service Set Identifiers (BSSID), wherein the multiple wireless networks include a first wireless network that only supports the WPA protocol, a second wireless network that supports both WPA and WPA2 protocols, and a third wireless network that supports both WPA2 and WPA3 protocols; and sequentially respond to receiving an access request from the first wireless network by using a private pre-shared key (PSK) to establish a wireless connection with the first wireless network, respond to receiving an access request from the second wireless network by using the private PSK to establish a wireless connection with the second wireless network, and respond to receiving a request from the third wireless network by using the private PSK to establish a wireless connection with the third wireless network.

16. The method of claim 15, wherein the plurality of wireless networks further includes a fourth wireless network that only supports the WPA3 protocol, and the method further includes: In response to receiving an access request from a fourth wireless network, a wireless connection is established with the fourth wireless network using the private PSK.

17. The method according to claim 15 or 16, wherein, During the process of establishing a wireless connection with any of the plurality of wireless networks, access to the wireless network is refused based on the inconsistency between the encryption method information carried in the probe response frame received from the wireless network and the encryption method information carried in the beacon frame received from the wireless network.

18. The method of claim 15, further comprising: In response to receiving an access request response from two or more of the plurality of wireless networks, the system selects a wireless network with a higher protocol that has been previously associated with among the two or more wireless networks for association.

19. An access point (AP), comprising: A memory that stores instructions; and a processor coupled to the memory, the processor being configured to execute the instructions to cause the AP to perform the method according to any one of claims 1-14, wherein the AP is the first AP.

20. A computer program product having instructions stored thereon that, when executed by a processor of an access point (AP), cause the AP to perform the method according to any one of claims 1-14, wherein the AP is the first AP.