Wireless device, communication method thereof, and computer program product
By determining the target MAC address and target IP address of wireless packets in wireless devices, forged packets can be identified and discarded, thus solving the attack problem caused by GTK sharing and improving communication security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- TP-LINK INT SHENZHEN CO LTD
- Filing Date
- 2026-04-07
- Publication Date
- 2026-05-15
AI Technical Summary
In wireless LANs based on the IEEE 802.11 standard, malicious STAs can exploit the shared group temporary key GTK to launch attacks, leading to communication security issues.
By determining whether the target MAC address and target IP address of the wireless packet conform to logical rules, forged packets can be identified and discarded to prevent malicious attacks.
It improves the communication security of wireless devices, prevents spoofed message attacks, and protects victimized devices and wired devices from attacks.
Smart Images

Figure CN122054151A_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communication technology, specifically to a wireless device, its communication method, and a computer program product. Background Technology
[0002] In a Basic Service Set (BSS) of a Wireless Local Area Network (WLAN) based on the IEEE 802.11 standard, Pairwise Temporal Keys (PTKs) and Group Temporal Keys (GTKs) are used to ensure communication security. The PTK is used to encrypt unicast data frames between the AP and a single STA, while the GTK is shared among all wireless devices (including APs and STAs) within the BSS and is used by the AP and STA to encrypt and decrypt broadcast or multicast messages sent from the AP to all associated clients, respectively.
[0003] However, since GTK is shared by all wireless devices within the BSS, malicious STAs can also use GTK to encrypt wireless packets and perform multicast or broadcast attacks on wireless devices within the same multicast group. Therefore, a method is needed to identify and intercept such attacks. Summary of the Invention
[0004] According to one aspect of this disclosure, a communication method for a wireless device is provided, comprising: receiving a wireless message; determining whether the wireless message is a forged message based on whether the destination MAC address of the wireless message is a broadcast MAC address or a multicast MAC address and whether the destination IP address of the wireless message is a unicast IP address; and discarding the wireless message in response to the wireless message being a forged message.
[0005] According to another aspect of this disclosure, a wireless device is provided, including one or more processors; a memory coupled to at least one of the one or more processors; and a computer program stored in the memory, which, when executed by at least one of the one or more processors, causes the wireless device to perform the communication method as described above.
[0006] According to another aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor of a wireless device, causes the wireless device to perform the communication method as described above.
[0007] According to embodiments of this disclosure, wireless devices can accurately identify and discard forged messages, preventing attacks from malicious client devices and improving communication security. Attached Figure Description
[0008] The above and other objects, features, and advantages of this disclosure will become more apparent from the more detailed description of embodiments thereof in conjunction with the accompanying drawings. The drawings are provided to offer a further understanding of the embodiments of this disclosure and form part of the specification. The drawings, together with the embodiments of this disclosure, are used to explain this disclosure and do not constitute a limitation thereof. In the drawings, unless explicitly indicated, the same reference numerals generally represent the same parts, steps, or elements.
[0009] Figure 1 An illustrative architecture of a wireless communication system according to embodiments of the present disclosure is shown;
[0010] Figure 2 An illustrative MAC frame structure of a wireless message according to an embodiment of the present disclosure is shown;
[0011] Figure 3 A schematic flowchart illustrating a communication method according to an embodiment of the present disclosure is shown;
[0012] Figure 4 A schematic flowchart illustrating a communication method according to an embodiment of the present disclosure is shown;
[0013] Figure 5 A schematic flowchart illustrating a communication method according to an embodiment of the present disclosure is shown;
[0014] Figure 6 A schematic block diagram illustrating a wireless device according to an embodiment of the present disclosure is shown.
[0015] Those skilled in the art will understand that the elements in the accompanying drawings are illustrated for simplicity and clarity and are not necessarily drawn to scale. For example, the dimensions of some elements in the illustrations, block diagrams, or flowcharts may be exaggerated relative to other elements to aid in accurate understanding of this embodiment. Detailed Implementation
[0016] The following detailed description is illustrated in the accompanying drawings. While exemplary embodiments are described herein, modifications, adaptations, and other implementations are possible. For example, components and steps illustrated in the drawings may be replaced, added, or modified, and the exemplary methods described herein may be modified by replacing, reordering, deleting, or adding steps to the disclosed methods. Therefore, the following detailed description is not limited to the disclosed embodiments and examples. Rather, the appropriate scope of the invention is determined by the appended claims.
[0017] In the detailed description below, numerous specific details are set forth in order to provide a thorough understanding of certain aspects. However, those skilled in the art will understand that some aspects can be practiced without these specific details. In other instances, well-known methods, procedures, components, units, and / or circuits have not been described in detail to avoid obscuring the discussion.
[0018] The use of terms such as “on one aspect,” “an aspect,” “example aspect,” and “various aspects” indicates that an aspect described in this way may include a specific feature, structure, or characteristic, but not every aspect necessarily includes the implementation of that specific feature, structure, or characteristic. Furthermore, the repeated use of the phrase “on one aspect” does not necessarily refer to the same aspect, although it may.
[0019] As used herein, unless otherwise stated, ordinal adjectives such as “first,” “second,” “third,” etc., are used to describe general objects only to indicate different instances of similar objects mentioned, and are not intended to imply that the objects described in this way must have a given order in time, space, sequence, or any other way.
[0020] Furthermore, the technical features involved in the different embodiments of this disclosure described below can be combined with each other, provided that there is no conflict between them.
[0021] Figure 1 An illustrative architecture of a wireless communication system 100 according to an embodiment of the present disclosure is shown.
[0022] The wireless communication system 100 according to embodiments of this disclosure may include a Basic Service Set (BSS) of a wireless local area network (WLAN) based on the IEEE 802.11 standard, and wired devices connected to access point (AP) devices within the BSS via Ethernet ports or the like. The BSS may include multiple client devices (Stations (STAs) associated with the APs within the BSS. In the following description, the BSS may also be referred to as a group. Figure 1 The diagram shows AP 110, STA 120, STA 130 belonging to the same BSS (indicated by dashed lines), and wired device 140 connected to AP 110, but the number of STAs and wired devices is not limited to this.
[0023] In this disclosure, an access point (AP) can wirelessly communicate with one or more non-access point devices (e.g., STAs) in a WLAN and allow non-AP devices to connect to the network. Additionally, an AP can also communicate via wired means with one or more wired devices and allow those wired devices to connect to the network. An AP is typically connected to a router via a wired network as a standalone device, but it can also be integrated with or used within a router.
[0024] In this disclosure, the STA can be any device that includes IEEE 802.11 compliant Media Access Control (MAC) and Physical Layer (PHY) interfaces to the wireless medium (WM). For example, an STA can be a laptop computer, desktop personal computer (PC), personal digital assistant (PDA), access point, or Wi-Fi phone in a WLAN environment. The STA can be fixed or mobile. In a WLAN environment, the terms "STA," "STA device," "client device," "wireless client," "user," and "user equipment" are generally used interchangeably.
[0025] In this disclosure, a STA in a WLAN can function as an AP in different situations, and vice versa. This is because communication devices in the context of IEEE 802.11 (Wi-Fi) technology may include both STA and AP hardware components. In this way, the communication device can switch between STA mode and AP mode based on the actual WLAN conditions and / or requirements.
[0026] In this disclosure, wired devices can access the network through the Ethernet interface of the AP. The same AP device can simultaneously communicate wirelessly with multiple STAs and with multiple wired devices. These STAs and wired devices share the network access services provided by the AP at the data link layer. However, the communication between the wired devices and the AP does not rely on the aforementioned GTK / PTK encryption and decryption, but is transmitted through physical wired media.
[0027] As described above, between AP 110 and STA 120 / 130, unicast radio packets are encrypted and decrypted using a unique pairwise temporary key (PTK), while multicast or broadcast radio packets are encrypted and decrypted using a shared group temporary key (GTK). Figure 2 The structure of a wireless message according to an embodiment of the present disclosure will be described.
[0028] Figure 2A schematic MAC frame structure of a wireless message 200 according to an embodiment of the present disclosure is illustrated. In this disclosure, the structure of the wireless message may conform to the IEEE 802.11 standard. Those skilled in the art will understand that, for the sake of brevity, Figure 2 A portion of the fields in the MAC frame of the IEEE 802.11 standard are omitted, and only the fields related to the communication method of the embodiments of this disclosure are shown. Furthermore, the various fields are... Figure 2 The width shown is for illustrative purposes only and does not represent the actual field length.
[0029] In this disclosure, no particular limitation is made on the type of wireless message; a wireless message may be, for example, a data frame. Figure 2 As shown, a wireless message 200 according to an embodiment of this disclosure may include a source MAC address field and a destination MAC address field transmitted in plaintext. The source MAC address field may be used to represent the MAC address of the wireless device sending the wireless message 200. The destination MAC address field may be used to represent the MAC address of the target device of the wireless message 200. The positions of the source MAC address field and the destination MAC address field are not limited to... Figure 2 For example, the order of the two fields can be interchanged, and other fields can be included between them. Furthermore, the wireless message 200 may also include a frame body encrypted with GTK or PTK. The frame body may include a source IP address field, a destination IP address field, and a payload. The source IP field can be used to indicate the IP address of the wireless device sending the wireless message 200. The destination IP address field can be used to indicate the IP address of the destination device of the wireless message 200. Those skilled in the art will understand that the destination device of the wireless message 200 can be either a wireless device or a wired device. The payload can be used to carry upper-layer protocol data.
[0030] return Figure 1In the wireless communication system 100, typically only AP 110 can send GTK-encrypted broadcast or multicast wireless messages to its associated STAs. Correspondingly, STAs 120 and 130 associated with AP 110 can receive GTK-encrypted broadcast or multicast wireless messages from AP 110. Taking STA 130 as an example, after receiving a wireless message, STA 130 first determines whether the wireless message is a multicast or broadcast message based on the destination MAC address, and checks whether the destination MAC address is a joined multicast MAC address (or broadcast MAC address). If the destination MAC address is indeed a joined multicast MAC address (or broadcast MAC address), STA 130 uses GTK to decrypt the wireless message, thereby extracting the destination IP address and payload. Further, STA 130 checks whether the destination IP address of the wireless message is a joined multicast IP address (or broadcast IP address). If so, it delivers the payload to the corresponding application or performs other processing.
[0031] However, if a malicious STA (hereinafter referred to as the attacking STA) exists within the BSS and intends to attack other STAs, the attacking STA cannot obtain the unique PTK between the target STA and the AP. Therefore, it can only rely on the GTK shared within the BSS to potentially launch an attack using multicast or broadcast radio packets. For example, after joining the BSS, the attacking STA can obtain the GTK. The attacking STA can impersonate the AP (i.e., by forging the source MAC address field of the radio packet to the AP's MAC address), use the obtained GTK to encrypt the radio packets used for the attack, and send them via multicast or broadcast. At this time, the attacked STA receives such radio packets and can successfully decrypt them using the corresponding GTK.
[0032] by Figure 1Taking STA 120 and STA 130 as an example, where STA 120 is the attacking STA and STA 130 is the victim (hereinafter referred to as the victim device), the injection attack process will be explained. STA 120 first constructs a forged message. This forged message can be a multicast or broadcast wireless message, with the destination MAC address field set to the multicast MAC address or broadcast MAC address of the multicast group that STA 120 has joined. Furthermore, in the frame body of the forged message, the destination IP address field is set to the IP address of the victim device, i.e., STA 130, and the payload field contains data used for the injection attack. In particular, the source MAC address field of this forged message is not STA 120's own MAC address, but is set (forged) to the MAC address of AP 110, which STA 120 is currently associated with. STA 120 uses the valid GTK of its current BSS to encrypt the frame body of the forged message and then sends it.
[0033] AP 110 can receive this forged message. First, AP 110 can extract the target MAC address field from the received forged message to determine that it is a multicast or broadcast wireless message. Since STA 120, acting as the attacking STA, shares the same GTK (Getting Things Done) with AP 110, AP 110 can successfully decrypt the frame body of the forged message using the same GTK. Then, AP 110 can extract the target IP address from the decrypted frame body and forward the forged message to the target device corresponding to that IP address, i.e., STA 130.
[0034] Because the source MAC address of the forged message is spoofed as the MAC address of AP 110, STA 130 does not filter the forged message. Therefore, it can receive the forged message forwarded from AP 110 and / or directly receive the forged message from STA 120. After receiving the forged message, STA 130 can first extract the target MAC address field from the forged message to determine whether it is a multicast wireless message (and that it has joined the multicast group corresponding to the target MAC address) or a broadcast wireless message. Since STA 130, AP 110, and STA 120 are in the same BSS, they can successfully decrypt the frame body of the forged message using the same GTK. Then, STA 130 can extract the target IP address from the decrypted frame body to determine that it is the target device of the forged message, and therefore deliver the payload to the corresponding application or perform corresponding processing. Thus, an injection attack from STA 120 to STA 130 is achieved.
[0035] Furthermore, wired devices connected to the access point (AP) can also be attacked due to the AP forwarding wireless packets. For example, when AP110 receives a wireless packet, if the destination IP address of the wireless packet is the IP address of wired device 140, AP110 will forward the payload containing the attack data in the wireless packet to wired device 140 via Ethernet or other means. Since wired device 140 lacks GTK / PTK encryption / decryption mechanisms, it directly delivers the payload of the wired frame forwarded by AP110 to the corresponding application, thus making wired device 140 vulnerable to attack as well.
[0036] This disclosure recognizes that in the injection attack described above, because the attacking STA 120 forges the source MAC address in the wireless packet as the MAC address of AP 110, and encrypts and sends it using the GTK shared within the BSS, the victim device (STA 130 or wired device 140) cannot determine whether the packet comes from a legitimate AP or a malicious attacking STA based on the source MAC address. Furthermore, the attacker can successfully decrypt multicast or broadcast wireless packets using the GTK shared within the BSS, thus causing a security problem. Therefore, a method is needed to identify and intercept such packet forgery attacks to ensure communication security.
[0037] To address the problems described above, this disclosure recognizes that even if an attacking STA can launch an attack by forging specific address fields of a wireless packet, the logical semantics or logical relationships between the constructed fields may still fail to meet the correct rules. Therefore, this disclosure provides a communication method for a wireless device that, even if a wireless packet has a forged source MAC address, can still use the destination MAC address and destination IP address of the wireless packet to logically determine whether the multiple address fields of the wireless packet meet the correct rules, thereby determining whether it is a forged packet and discarding it, thus ensuring communication security.
[0038] Figure 3 A schematic flowchart illustrating a communication method 300 according to an embodiment of the present disclosure is shown. The communication method 300 can, for example, be... Figure 1 In the case of STA 120 being used as an attacking STA, the attack is carried out by AP 110 or STA 130, but not limited to these two.
[0039] like Figure 3As shown, the communication method 300 according to an embodiment of the present disclosure may include: step S310, receiving a wireless message; step S320, determining whether the wireless message is a forged message based on whether the destination MAC address of the wireless message is a broadcast MAC address or a multicast MAC address and whether the destination IP address of the wireless message is a unicast IP address; and step S330, discarding the wireless message in response to the wireless message being a forged message.
[0040] In some embodiments, the wireless device can be a STA or an AP. The wireless message is a wireless frame sent by an attacking STA within the BSS set where the wireless device is located, and the source MAC address in the wireless message is set to the MAC address of the AP within the BSS set where the wireless device is located.
[0041] Within the BSS, all wireless devices share the same GTK (Gross Detection and Decryption Key) and use the same GTK to encrypt and decrypt multicast or broadcast wireless packets. In other words, after an attacking STA associates with an AP, it can only succeed by encrypting forged packets with the GTK and then broadcasting or multicasting them. Only then can the victim device decrypt the forged packets using the same GTK, thus achieving the attack. If the target MAC address of the forged packet is a unicast MAC address, meaning the forged packet is a unicast wireless packet, the attacking STA can only encrypt the forged packet using the PTK (Plain Oldest Key). Other client devices within the BSS cannot obtain the attacking STA's PTK and therefore will not use the same PTK to decrypt the forged packets. Thus, unicast forged packets cannot achieve the attack.
[0042] According to the communication method 300 of this disclosure, when a wireless device receives a wireless message, it determines whether it needs to use the GTK public address within the BSS to decrypt the wireless message based on whether the destination MAC address of the wireless message is a broadcast MAC address or a multicast MAC address. If the wireless device needs to use GTK to decrypt the wireless message, there is a risk that an attacked STA may use the GTK-encrypted forged message for attack. Therefore, the wireless device performs a subsequent judgment based on the destination IP address to further determine whether the wireless message is a forged message.
[0043] Furthermore, for multicast or broadcast radio messages (non-forged messages) actually sent by the AP to each STA within the BSS, the destination IP address contained in the frame body should also be a multicast IP address or a broadcast IP address, and there will be no case where the destination IP address is a unicast IP address. Based on this characteristic and reasonable rules among multiple address fields, this disclosure proposes to identify forged messages by further combining the determination of the destination MAC address with whether the destination IP address is a unicast IP address.
[0044] Therefore, according to the communication method 300 of the embodiments of this disclosure, the wireless device can effectively identify and discard forged messages by using a combination of logical rules such as whether the target MAC address of the wireless message is a broadcast MAC address or a multicast MAC address, and whether the target IP address is a unicast IP address. This avoids the wireless device delivering the payload in the forged message to the application and thus being attacked, thereby improving the security of communication.
[0045] In some embodiments, in response to the target MAC address being a broadcast MAC address and the target IP address being a unicast IP address, the wireless device determines that the wireless packet is a forged packet; or in response to the target MAC address being a multicast MAC address and the target IP address being a unicast IP address, the wireless device determines that the wireless packet is a forged packet.
[0046] Figure 4 A schematic flowchart illustrating a communication method 400 according to an embodiment of the present disclosure is shown. Figure 4 As shown, the communication method 400 according to an embodiment of this disclosure may include steps S410-S460. In step S410, the wireless device receives a wireless message. In step S420, the wireless device extracts the destination MAC address of the wireless message and determines whether the destination MAC address is a multicast MAC address or a broadcast MAC address. If the determination is yes, proceed to step S430. In step S430, the wireless device uses the valid GTK of the current BSS to decrypt the wireless message to extract the destination IP address. In step S440, the wireless device determines whether the destination IP address is a unicast IP address. If the determination is yes, the wireless device determines that the currently received wireless message is a forged message, and therefore discards the wireless message in step S450. If the determination is no in step S420 or step S440, proceed to step S460, where the wireless device can determine that the currently received wireless message is not forged, and therefore performs the general processing specified in the IEEE 802.11 standard on the wireless message.
[0047] According to the communication method 400 of this disclosure, when a wireless device receives a wireless message, it can accurately identify whether the wireless message is a forged message by sequentially determining the target MAC address of the wireless message, and further determining whether the target IP address is a unicast IP address if the target MAC address is a multicast MAC address or a broadcast MAC address. Thus, if a forged message is identified, it discards the forged message and does not deliver the payload of the forged message to the application or forward the forged message to the victim device. This effectively prevents the attacking STA from using GTK to launch an attack on a single victim device in the same group as the attacking STA, thereby improving the security of communication.
[0048] Furthermore, according to the communication method 400 of the embodiments of this disclosure, the wireless device can identify forged messages simply by using the target MAC address and target IP address of the wireless message, without the need for other complex judgment logic or processing steps. Therefore, it has low requirements for the hardware capabilities of the wireless device and is compatible with the existing IEEE 802.11 standard.
[0049] More specifically, a wireless device can determine whether a target MAC address is a broadcast MAC address or a multicast MAC address based on whether the target MAC address falls within the address range corresponding to these two types of MAC addresses. That is, in some embodiments, in response to the target MAC address falling within a preset first MAC address range, the wireless device determines that the target MAC address is a broadcast MAC address; in response to the target MAC address falling within a preset second MAC address range, the wireless device determines that the target MAC address is a multicast MAC address.
[0050] As an example, if the destination MAC address of a wireless message is ff:ff:ff:ff:ff:ff, then the wireless message is a broadcast wireless message. That is, in this disclosure, the first MAC address range can be ff:ff:ff:ff:ff:ff:ff.
[0051] Furthermore, for multicast wireless packets, the range of the second MAC address can be determined, for example, by the network layer protocol followed by the wireless packet. For instance, for a wireless packet under the IPv4 protocol, if the destination MAC address of the wireless packet is 01:00:5e:xx:xx:xx (where "xx" represents any valid address), then the wireless packet is a multicast wireless packet. That is, in one example of this disclosure, the range of the second MAC address can be from 01:00:5e:00:00:00 to 01:00:5e:7f:ff:ff. For a multicast wireless packet under the IPv6 protocol, its destination MAC address can be 33:33:yy:yy:yy:yy (where "yy" represents any valid address). That is, in another example of this disclosure, the range of the second MAC address can be from 33:33:00:00:00:00 to 33:33:FF:FF:FF:FF. Furthermore, the first MAC address range and the second MAC address range mentioned above are merely examples, and the first MAC address range and the second MAC address range are not limited to these. For example, a larger or smaller second MAC address range can also be preset.
[0052] After receiving a wireless packet, the wireless device can determine whether it is a broadcast or multicast packet by judging whether the destination MAC address of the wireless packet falls within the first or second MAC address range mentioned above. Therefore, after determining that the wireless packet is a broadcast or multicast packet, the wireless device can use GTK to decrypt it, extract the destination IP address, and perform further judgment. If the destination MAC address of the wireless packet is neither within the first nor the second MAC address range, the wireless device can determine that it is a unicast wireless packet, and there is no risk of an attacking STA using GTK encryption to carry out an attack. Therefore, the wireless packet can be processed according to the general subsequent processing specified in the IEEE 802.11 standard.
[0053] Furthermore, in some embodiments, in response to the target IP address being within a preset IP address range, the wireless device determines that the target IP address is a unicast IP address.
[0054] As an example, if the wireless message is a broadcast wireless message, the destination IP address could be 255.255.255.255.
[0055] If the wireless message is a multicast wireless message, the default IP address range may depend on the network layer protocol followed by the wireless message. For example, for a wireless message under the IPv4 protocol, the destination IP address of its multicast wireless message can be from 224.0.0.0 to 239.255.255.255. Therefore, in one example, the default IP address range (i.e., the IP address range corresponding to unicast) can include any valid IP address range other than the broadcast IP address 255.255.255.255 and the multicast IP address range 224.0.0.0 to 239.255.255.255. As another example, for a wireless message under the IPv6 protocol, the destination IP address of its multicast wireless message can be FF00:: / 8. Therefore, in another example, the default IP address range can include any valid IP address range other than FF00:: / 8 (and reserved IP addresses for special purposes). Furthermore, the default IP address ranges described above are merely examples, and the default IP address ranges are not limited to these. For example, there may be reserved IP addresses with special functions within the unicast IP address range. In this case, the preset IP address range can further exclude such IP addresses with special functions.
[0056] As described above, for a typical wireless packet (non-forged packet), if its destination MAC address is a broadcast MAC address or a multicast MAC address, its destination IP address should also be a broadcast IP address or a multicast IP address. However, if its destination IP address falls within the aforementioned preset IP address range, the wireless device can determine that the currently received wireless packet corresponds to a unicast IP address, and therefore is a forged packet, thus discarding it.
[0057] The communication method 400 according to embodiments of the present disclosure has been described above. In the above description, no distinction was made between the wireless device and the STA; both can identify and discard forged messages based on the communication method 400. For example, Figure 1 Both AP 110 and STA 130 shown can identify and discard spoofed wireless messages sent by STA 120 based on communication method 400. However, this is not the only limitation; if the wireless device is an AP, spoofed messages can also be identified using the communication method described below.
[0058] In some embodiments, the wireless device is an access point device, and the communication method may further include: in response to the target MAC address being a multicast MAC address or a broadcast MAC address, and the source MAC address of the wireless message being the same as the MAC address of the wireless device, the wireless device determines that the wireless message is a forged message.
[0059] Figure 5 An exemplary flowchart illustrates a communication method 500 when the wireless device is an access point (AP). Figure 4 Compared to the communication method 400 shown, after the wireless device extracts the target MAC address from the received wireless packet, in addition to determining whether the target MAC address is a multicast MAC address or a broadcast MAC address (step S520), it also determines whether the source MAC address of the wireless packet is the same as its own MAC address (step S530). If the source MAC address of the wireless packet is not the same as its own MAC address (S530 is not true), the subsequent steps S540-S570 are further executed. Among them, S540-S570 and... Figure 4Steps S430-S460 are the same and will not be repeated here. If the source MAC address of the wireless packet is the same as the AP's own MAC address (yes in S530), proceed directly to step S560 and discard the wireless packet, without needing to execute subsequent steps S540-S570. This is because, in order to launch an injection attack, the attacking STA forges the source MAC address in the wireless packet into the AP's MAC address. However, generally speaking, the AP will not receive wireless packets sent by itself. Once it receives a wireless packet with its own MAC address as the source MAC address, it can determine that the wireless packet is illegal (possibly a forged packet). Therefore, when the wireless device is an AP, by judging the source MAC address of the wireless packet, forged packets can be effectively identified without further decryption and target IP address determination steps, thus simplifying the AP's process of identifying forged packets. Furthermore, according to communication method 500, the AP can discard the forged packet after extracting the target MAC address and source MAC address, without needing to perform GTK decryption on the forged packet, thereby preventing the attacking STA from using forged packets to launch injection attacks against the AP.
[0060] Understandable, Figure 5 In the illustrated communication method 500, the wireless device executes step 520 first, followed by step S530. However, this is not a limitation, and the order of steps S520 and S530 can be interchanged. Alternatively, the wireless device can execute step S530 first. If, in step S530, it is determined that the source MAC address of the wireless packet is the same as its own MAC address, then subsequent steps S520 and S540-S570 are not performed. This reduces the processing time for the AP to identify forged packets and allows for earlier identification. In other words, in the embodiments of this disclosure, the AP can employ a determination mechanism based solely on the source MAC address, a determination mechanism based on the target MAC address and the target IP address, or a combination of both mechanisms to identify forged packets.
[0061] Furthermore, when the wireless device is an access point (AP), it can issue a notification when it identifies a forged message. Specifically, in some embodiments, the communication method 500 may further include step S580. In step S580, in response to the wireless message being a forged message, the wireless device can issue a notification indicating that a forged message has been received.
[0062] Some existing access points (APs) can provide display modules such as screens and / or management interfaces with user interaction functions. Therefore, when the AP identifies a wireless packet as a forged packet, it can issue a prompt to the user through the display module and / or management interface, reminding the user that a forged packet has been received and that an attacking STA exists within the BSS, so that the user can be aware of the potential network security risks in a timely manner and take countermeasures.
[0063] More specifically, in some implementations, such prompts may include information provided through the management interface of the wireless device for changing the group ephemeral key. As mentioned above, forged packets rely on the attacking STA possessing the group ephemeral key. Therefore, when the AP receives a forged packet, it can determine that the current group ephemeral key within the BSS may have been leaked and obtained by the attacking STA. The AP provides information through a management interface (e.g., a management program installed on the user's mobile phone) to prompt the user to change the group ephemeral key in a timely manner. This information allows the user to understand the risk of GTK leakage within the current BSS and initiate the group ephemeral key update mechanism. During the group ephemeral key update process, the attacking STA is prevented from using the existing GTK to continue constructing forged packets, thus shortening the window of opportunity for the attacking STA to launch an attack and contributing to improved communication security.
[0064] As mentioned above, not only wireless devices, but also wired devices connected to the access point (AP) can be attacked if the AP forwards forged messages. Figure 1 The following example illustrates the attack process from STA 120 to wired device 140. The processes of STA 120 constructing and sending forged packets, and AP 110 extracting the target IP address from the forged packets, are the same as described above and will not be repeated here. Specifically, in this example, after AP 110 extracts the target IP address, it re-encapsulates the payload (without encryption), constructing a wired network frame (e.g., an Ethernet frame based on the IEEE 802.3 standard) with the source MAC address being AP 110's MAC address, the target MAC address being the wired device 140's MAC address, and the target IP address being the wired device 140's IP address. This frame is then sent to wired device 140. Upon receiving this wired network frame, wired device 140 determines itself as the target device based on the target MAC address and target IP address, and directly delivers the payload of the wired network frame to the application. Thus, the attack by STA 120 on wired device 140 is achieved. According to the communication method 500 disclosed herein, the forged message can be discarded immediately upon receiving it at AP110, and will not be forwarded to wired device 140, thus ensuring the communication security of wired device 140.
[0065] The communication method 500 according to embodiments of the present disclosure has been described in detail above.
[0066] According to another aspect of this disclosure, a wireless device is also provided, comprising: one or more processors; a memory coupled to at least one of the one or more processors; and a computer program stored in the memory, which, when executed by at least one of the one or more processors, causes the wireless device to perform a communication method according to an embodiment of this disclosure.
[0067] Figure 6 An exemplary block diagram of a wireless device 600 according to an embodiment of the present disclosure is illustrated. In this disclosure, the wireless device 600 may be, for example, as described above. Figure 1 The AP 110 or STA 130 are included, but not limited to these.
[0068] like Figure 6 As shown, the wireless device 600 may include a processor 610 and a memory 620. The processor 610 is communicatively coupled to the memory and configured to perform a communication method according to embodiments of the present disclosure.
[0069] Examples of processor 610 include microprocessors, microcontrollers, digital signal processors (DSPs), field-programmable gate arrays (FPGAs), programmable logic devices (PLDs), state machines, gated logic, discrete hardware circuits, and other suitable hardware configured to perform the various functions of this disclosure.
[0070] Processor 610 can execute software. Software should be broadly interpreted as instructions, instruction sets, code, code segments, program code, programs, subroutines, software modules, application programs, software applications, software packages, routines, subroutines, objects, executable files, execution threads, procedures, functions, etc., regardless of whether it is called software, firmware, middleware, microcode, hardware description languages, or something else. Software may reside on memory 620.
[0071] Memory 620 may be a non-transitory computer-readable medium. Non-transitory computer-readable media include, for example, magnetic storage devices (e.g., hard disks, floppy disks, magnetic stripes), optical disks (e.g., optical discs (CDs) or digital versatile optical discs (DVDs)), smart cards, flash memory devices (e.g., cards, memory cards, or key drives), random access memory (RAM), read-only memory (ROM), programmable ROM (PROM), erasable PROM (EPROM), electrically erasable PROM (EEPROM), registers, removable disks, and any other suitable medium for storing software and / or instructions that can be accessed and read by a computer. Memory 620 may reside in processor 610, be external to processor 610, or be distributed across multiple entities including processor 610. Memory 620 may be embodied in a computer program product. For example, a computer program product may include a computer-readable medium in packaging material. Those skilled in the art will recognize how the functionality described throughout this disclosure can be implemented based on the specific application and overall design constraints imposed on the overall system.
[0072] According to another aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor of a wireless device, causes the wireless device to perform the communication method as described above. As an example, the computer program product includes a non-transitory computer-readable storage medium containing program instructions executable by a processor of the wireless device. When executed, the program instructions cause the wireless device to perform the communication method according to embodiments of this disclosure; details are omitted here for brevity.
[0073] This invention can be a system, method, and / or computer program product at any possible level of integration technical detail. The computer program product may include computer-readable program instructions for causing a processor to perform various aspects of this disclosure.
[0074] It should be noted that the flowcharts and block diagrams in the accompanying drawings illustrate the possible structure, function, and operation of the methods and apparatus according to various embodiments of this application. In this respect, each block in a flowchart or block diagram may represent a module, a program segment, or a portion of code containing at least one executable instruction for implementing a specified logical function. It should also be noted that in some alternative embodiments, the functions described in a block may occur in a different order than those described in the accompanying drawings. For example, two blocks shown consecutively may actually be executed in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, may be implemented by a dedicated hardware system that performs the specified function or operation, or by a combination of dedicated hardware and computer instructions. Furthermore, in this disclosure, terms such as “at least one of A, B, or C,” “one or more of A, B, or C,” “at least one of A, B, and C,” “one or more of A, B, and C,” “A, B, C, or any combination thereof” include any combination of A, B, and / or C, and may include multiple A, multiple B, or multiple C. Terms such as “at least one of A, B or C”, “one or more of A, B or C”, “at least one of A, B and C”, “one or more of A, B and C”, “A, B, C or any combination thereof” can be only A, only B, only C, A and B, A and C, B and C or A, B and C, where any such combination can contain one or more members of A, B or C.
[0075] The various embodiments described in this disclosure are for illustrative purposes and are not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those skilled in the art without departing from the scope of the described embodiments. The terminology used herein is chosen to best explain the principles of the embodiments, their practical application, or improvements to techniques found in the market, or to enable those skilled in the art to understand the embodiments disclosed herein.
[0076] Throughout the description and claims of this specification, the word “comprising” and variations thereof, such as “comprising” and “including,” means “including, but not limited to,” and are not intended to exclude, for example, other additives, components, integers, or steps. “Exemplary” means “an example of a preferred or ideal implementation and is not intended to convey its indication.” “Like” is not used in a limiting sense but for interpretative purposes.
Claims
1. A communication method for a wireless device, comprising: Receive wireless messages; Based on whether the target MAC address of the wireless packet is a broadcast MAC address or a multicast MAC address, and whether the target IP address of the wireless packet is a unicast IP address, it is determined whether the wireless packet is a forged packet. as well as If the wireless message is found to be a forged message, the wireless message is discarded.
2. The communication method according to claim 1, wherein, In response to the fact that the target MAC address is a broadcast MAC address and the target IP address is a unicast IP address, the wireless device determines that the wireless packet is a forged packet; or In response to the fact that the target MAC address is a multicast MAC address and the target IP address is a unicast IP address, the wireless device determines that the wireless packet is a forged packet.
3. The communication method according to claim 2, wherein, The wireless device extracts the target MAC address from the wireless packet, and in response to whether the target MAC address is a multicast MAC address or a broadcast MAC address, decrypts the wireless packet using a group temporary key to extract the target IP address.
4. The communication method according to claim 1, wherein, In response to the target MAC address being within a preset first MAC address range, the wireless device determines that the target MAC address is a broadcast MAC address; In response to the target MAC address being within a preset second MAC address range, the wireless device determines that the target MAC address is a multicast MAC address.
5. The communication method according to claim 1, wherein, In response to the target IP address being within a preset IP address range, the wireless device determines that the target IP address is a unicast IP address.
6. The communication method according to claim 1, wherein, The wireless device is an access point device. The communication method further includes: In response to the target MAC address being a multicast MAC address or a broadcast MAC address, and the source MAC address of the wireless packet being the same as the MAC address of the wireless device, the wireless device determines that the wireless packet is a forged packet.
7. The communication method according to claim 1, wherein, The wireless device is an access point device. The communication method further includes: In response to the wireless message being a forged message, a prompt is provided to indicate that a forged message has been received.
8. The communication method according to claim 7, wherein, The information includes information provided through the management interface of the wireless device for changing the group temporary key.
9. The communication method according to claim 1, wherein, The wireless message is a wireless frame sent by an attacking client device within the basic service set where the wireless device is located, and the source MAC address in the wireless message is set to the MAC address of the access point device within the basic service set where the wireless device is located.
10. A wireless device, comprising: One or more processors; Memory coupled to at least one of the one or more processors; as well as A computer program stored in the memory, which, when executed by at least one of the one or more processors, causes the wireless device to perform the communication method according to any one of claims 1 to 9.
11. A computer program product comprising a computer program that, when executed by a processor of a wireless device, causes the wireless device to perform the communication method according to any one of claims 1 to 9.