Wireless connection method based on WPA3, electronic equipment and storage medium

By automatically generating a password identification code and simultaneously generating an algorithm in WPA3 wireless connections, the problem of users having to manually enter the password identification code is solved, achieving a more efficient and secure wireless connection.

CN122073685APending Publication Date: 2026-05-22AMLOGIC (SHANGHAI) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
AMLOGIC (SHANGHAI) CO LTD
Filing Date
2024-11-22
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

In existing wireless connection methods, users need to manually enter a password and password identification code, which results in high connection complexity, low security, and poor user experience.

Method used

The WPA3-based wireless connection method ensures the security and efficiency of the wireless connection by automatically generating a password identification code after the password is entered and synchronizing the password identification code generation algorithm between the client and the wireless access point.

Benefits of technology

It simplifies the user operation process, improves the security and efficiency of wireless connections, and enhances the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122073685A_ABST
    Figure CN122073685A_ABST
Patent Text Reader

Abstract

The invention discloses a WPA3-based wireless connection method, electronic equipment and a storage medium, the WPA3-based wireless connection method is used for a client, and the wireless connection method comprises the following steps: in response to an input password, determining a password identification code target generation algorithm; obtaining a first password identification code corresponding to the input password according to a password identification code target generation algorithm; and establishing connection with the wireless access point according to the input password and the first password identification code. According to the method, the corresponding password identification code is automatically generated after the password is input, and the device client can be safely connected with the wireless access point by using the correct input password and the password identification code only by inputting the password to the device client, so that the wireless connection safety and efficiency are improved, the wireless connection complexity is reduced, and the user experience is improved. And the user experience is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of wireless communication, and in particular to a wireless connection method based on WPA3 (Wi-Fi Protected Access 3), as well as electronic devices and storage media. Background Technology

[0002] In related technologies, the introduction of password identification codes in wireless connections allows multiple passwords to be configured for the same wireless access point under the same security mechanism. In daily use, users first obtain the password of the wireless access point they want to connect to, and then enter the password into the device client. After the introduction of password identification codes, users also need to obtain the corresponding password identification code, and then enter the password identification code into the device client. This forces the device client to use the password and the corresponding password identification code to connect to the wireless access point, which increases the possibility of password leakage, makes the wireless connection complex and inefficient, and results in a poor user experience. Summary of the Invention

[0003] This invention aims to at least solve one of the technical problems existing in the prior art. Therefore, one objective of this invention is to propose a WPA3-based wireless connection method that automatically generates a corresponding password identification code after a password is entered. The device client only needs to input the password to establish a secure connection with the wireless access point using the correct password and password identification code, thereby improving wireless connection security and efficiency, reducing wireless connection complexity, and enhancing the user experience.

[0004] The second objective of this invention is to propose a WPA3 wireless connection method.

[0005] The third objective of this invention is to provide an electronic device.

[0006] The fourth objective of this invention is to provide a computer storage medium.

[0007] To address the aforementioned problems, a first aspect of the present invention provides a WPA3-based wireless connection method for a client. The wireless connection method includes: in response to an input password, determining a password identification code target generation algorithm; obtaining a first password identification code corresponding to the input password according to the password identification code target generation algorithm; and establishing a connection with a wireless access point based on the input password and the first password identification code.

[0008] According to the wireless connection method of the present invention, after receiving the input password, the device client determines the password identification code target generation algorithm based on the input password, and obtains the first password identification code corresponding to the input password through the password identification code target generation algorithm. The device client only needs to input the password to the device client, and the device client can use the correct input password and the first password identification code to establish a secure connection with the wireless access point, thereby improving the security and efficiency of wireless connection, reducing the complexity of wireless connection, and enhancing the user experience.

[0009] In some embodiments, the password identification code target generation algorithm takes the input password as input and the password identification code corresponding to the input password as the calculation result.

[0010] In some embodiments, the first password identification code uniquely corresponds to the input password.

[0011] In some embodiments, the password identification code target generation algorithm is the default password identification code generation algorithm between the client and the wireless access point.

[0012] In some embodiments, the default password identification code generation algorithm is a password identification code generation algorithm bound to a security mechanism; wherein, the security mechanism is the security mechanism to be used after the client and the wireless access point establish a connection.

[0013] In some embodiments, the security mechanism includes at least one of an authentication mechanism, an encryption mechanism, a key specification used in the authentication or encryption process, a key generation mechanism used in the authentication or encryption process, and a key distribution mechanism used in the authentication or encryption process.

[0014] In some embodiments, determining the target password identification code generation algorithm includes: selecting a configured AKM (Authentication and Key Management) suite and obtaining the password identification code generation algorithm bound to the AKM component; sending the selection information of the AKM component to the wireless access point to synchronize the password identification code generation algorithm; and upon receiving confirmation information from the wireless access point in response to the selection information of the AKM component, the password identification code generation algorithm bound to the currently selected AKM component is the target password identification code generation algorithm.

[0015] In some embodiments, determining the target generation algorithm for the password identification code includes: determining the target generation algorithm for the password identification code through negotiation with the wireless access point.

[0016] In some embodiments, determining a target password identification code generation algorithm includes: receiving target broadcast information from the wireless access point, the target broadcast information carrying information about the target password identification code generation algorithm; and determining the target password identification code generation algorithm based on the information about the target password identification code generation algorithm carried in the target broadcast information.

[0017] In some embodiments, the wireless connection method further includes negotiating or synchronizing with the wireless access point input parameters other than the password required by the password identification target generation algorithm.

[0018] In some embodiments, negotiating or synchronizing with the wireless access point the input parameters other than the password required by the password identification target generation algorithm includes: explicitly or implicitly negotiating or synchronizing with the wireless access point the input parameters other than the password required by the password identification target generation algorithm.

[0019] In some embodiments, the password identification code target generation algorithm is any one of the following algorithms: a single-input parameter CRC (Cyclic Redundancy Check) algorithm or a hash algorithm; a multi-input parameter Hash MAC (Hash-based Message Authentication) algorithm; or a method for generating a key based on the input password and using the key to encrypt all or part of the input password to obtain a password identification code.

[0020] A second aspect of the present invention provides a WPA3-based wireless connection method for a wireless access point. The wireless connection method includes: synchronizing a password identification code target generation algorithm with a client; receiving an input password and a first password identification code from the client; obtaining a second password identification code based on the input password and the password identification code target generation algorithm; the second password identification code being identical to the first password identification code; and establishing a connection with the client.

[0021] According to the wireless connection method of the present invention, the wireless access point first synchronizes the password identification code target generation algorithm with the client. After the wireless access point receives the input password and the first password identification code sent by the client, it obtains the second password identification code through the input password and the password identification code target generation algorithm. It then compares whether the second password identification code is consistent with the first password identification code. When the second password identification code is consistent with the first password identification code, the wireless access point establishes a connection with the client, thereby improving the security and efficiency of the wireless connection, reducing the complexity of the wireless connection, and enhancing the user experience.

[0022] In some embodiments, the password identification code target generation algorithm is the default password identification code generation algorithm between the client and the wireless access point.

[0023] In some embodiments, the default password identification code generation algorithm is a password identification code generation algorithm bound to a security mechanism; wherein, the security mechanism is the security mechanism to be used after the wireless access point and the client establish a connection; the security mechanism includes at least one of an authentication mechanism, an encryption mechanism, a key specification used in the authentication or encryption process, a key generation mechanism used in the authentication or encryption process, and a key distribution mechanism used in the authentication or encryption process.

[0024] In some embodiments, synchronizing the password identification code target generation algorithm with the client includes: receiving AKM component selection information sent by the client; sending confirmation information for the selection information of the AKM component to the client, so as to use the currently confirmed password identification code generation algorithm bound to the AKM component as the password identification code target generation algorithm.

[0025] In some embodiments, synchronizing the password identification code target generation algorithm with the client includes: determining the password identification code target generation algorithm through negotiation with the client.

[0026] In some embodiments, synchronizing a password identification code target generation algorithm with a client includes: determining the password identification target generation algorithm; and broadcasting target broadcast information carrying information about the password identification code target generation algorithm.

[0027] In some embodiments, the target broadcast information includes at least one of the following: periodic broadcast information or periodically transmitted information packets from the wireless access point; broadcast information packets or single information packets transmitted by the wireless access point to the client.

[0028] In some embodiments, the wireless connection method further includes: explicitly or implicitly negotiating or synchronizing with the client input parameters other than the password required by the password identification target generation algorithm.

[0029] A third aspect of the present invention provides an electronic device, comprising: at least one processor; a memory communicatively connected to the at least one processor; the memory storing a computer program executable by the at least one processor, wherein the at least one processor executes the computer program to implement the WPA3-based wireless connection method described in the above embodiments.

[0030] According to the electronic device of the present invention, a corresponding WPA3-based wireless connection program can be stored in a memory. When implementing the WPA3-based wireless connection method, the processor runs the program in the memory, obtains a first password identification code and a second password identification code based on the input password, and when the first password identification code and the second password identification code are consistent, the wireless access point establishes a connection with the client, thereby improving the security and efficiency of wireless connection, reducing the complexity of wireless connection, and enhancing the user experience.

[0031] A fourth aspect of the present invention provides a computer storage medium having a computer program stored thereon, characterized in that, when the computer program is executed, it implements the WPA3-based wireless connection method described in the above embodiments.

[0032] Additional aspects and advantages of the invention will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of the invention. Attached Figure Description

[0033] The above and / or additional aspects and advantages of the present invention will become apparent and readily understood from the description of the embodiments taken in conjunction with the following drawings, in which: Figure 1 This is a flowchart of a WPA3-based wireless connection method according to an embodiment of the present invention; Figure 2 This is a schematic diagram of a password identification code generation algorithm according to an embodiment of the present invention; Figure 3 This is a schematic diagram of a negotiation-based password identification code generation algorithm according to an embodiment of the present invention; Figure 4 This is a schematic diagram of a wireless access point broadcasting process according to an embodiment of the present invention; Figure 5 This is a flowchart of a WPA3-based wireless connection method according to another embodiment of the present invention; Figure 6 This is a schematic diagram of a password identification code input process according to an embodiment of the present invention; Figure 7 This is a structural block diagram of an electronic device according to an embodiment of the present invention.

[0034] Figure label: 100 electronic devices; Processor 101; Memory 102. Detailed Implementation

[0035] The embodiments of the present invention are described in detail below. The embodiments described with reference to the accompanying drawings are exemplary. The embodiments of the present invention are described in detail below.

[0036] The new WPA3-Personal security mechanism introduced by the Wi-Fi (Wireless Fidelity) Alliance introduces a new security element: a password identifier. Traditional Wi-Fi's WPA2-Personal (Wi-Fi Protected Access 2) and earlier WPA3-Personal security mechanisms did not have a password identifier; that is, when connected to the same access point (AP), no password identifier was required. All STAs (Stations, clients) using the same security mechanism share the same password. With the introduction of password identification codes, a single wireless access point, under the same security mechanism, can be configured with multiple passwords, assigned to different clients, and each client is assigned a corresponding password identification code. This allows different clients to notify the access point of the password identification code during the connection process, enabling the access point to determine which password to use for a secure connection. One advantage of using different passwords for different clients is that the access point can group clients, with different passwords used in different groups. For example, in a home setting, two passwords can be set: one for family members and one for guests. This avoids leaking everyday family passwords and allows for easy switching to the guest password without affecting family members' use.

[0037] In existing technologies, the use of password identification codes by ordinary users presents the following problems: In daily use, users first obtain the password for the connected Wi-Fi access point and then input it into the device client. With the introduction of password identification codes, users must also obtain the corresponding password identification code and then input it into the device client, requiring the device client to use both the password and the corresponding password identification code to connect to the Wi-Fi access point. This is clearly different from current user habits when using Wi-Fi, complicating several aspects of the user experience. In typical home use, users manually set the password for the Wi-Fi access point. This necessitates either manually setting the corresponding password identification code or having the Wi-Fi access point automatically generate the corresponding password identification code, and the user needs to remember the corresponding password identification code.

[0038] When a user connects a device client to a wireless access point, in addition to entering a password, a password identification code is also required. In particular, when a user connects a device client to a wireless access point, unlike the existing method of only entering a password on the device interface, a way is needed to distinguish whether the user is entering a password or a password identification code.

[0039] Existing possible methods for users to enter password identification codes include: using a special separator to separate the password and password identification code, such as a semicolon, and providing different input fields on the device interface; using a special separator requires users to enter the password and corresponding identity information in the correct order, and it is also necessary to prevent the special separator from being used as part of the password when setting the password; or, using different input fields on the device interface, it would require changing the current user's habit of only entering the password, requiring users to distinguish between the password and identity information and fill them in their respective correct input fields.

[0040] To address the above issues, a first aspect of this invention provides a WPA3-based wireless connection method. This method can be used on a client device, which may include smart home devices, automotive electronics, etc. Smart home devices may include, but are not limited to, smart set-top boxes, smart TVs, etc.

[0041] The method of this invention automatically generates a corresponding password identification code after the password is entered. The device client only needs to enter the password to enable the device client to use the correct password and password identification code to securely connect to the wireless access point, thereby improving the security and efficiency of wireless connection, reducing the complexity of wireless connection, and enhancing the user experience.

[0042] The following is for reference. Figure 1 A WPA3-based wireless connection method according to an embodiment of the first aspect of the present invention is described, such as... Figure 1 As shown, the method includes at least steps S1 to S3.

[0043] Step S1: In response to the input password, determine the password identification code target generation algorithm.

[0044] Specifically, WPA3 is a new generation security standard developed by the Wi-Fi Alliance for personal networks. It aims to improve the overall security of wireless LANs by using modern security algorithms and stronger encryption suites. It evolved from WPA2, addressing some security vulnerabilities and providing higher encryption strength and better security features. A wireless access point is an access point for a wireless network, commonly known as a "hotspot." It mainly includes integrated routing and switching access devices and pure access point devices. Integrated devices handle access and routing, while pure access devices only handle wireless client access and are typically used as wireless network extensions. When a client connects wirelessly to a wireless access point, it enters a password. Since there are various password identification code generation algorithms, the entered password determines the password identification code generation algorithm. The password identification code generation algorithm can be understood as the algorithm that ultimately generates the password identification code based on the entered password.

[0045] Step S2: Obtain the first password identification code corresponding to the input password according to the password identification code target generation algorithm.

[0046] Specifically, the user first enters a password, which can be a string composed of letters, numbers, special characters, etc. The input password is processed by a password identification code target generation algorithm, which may be based on a hash function, encryption algorithm, hash algorithm, or other types of mathematical functions. After processing by the algorithm, an output value corresponding to the input password is obtained. This value is the first password identification code. The first password identification code can be understood as the password identification code generated by the client through the password identification code target generation algorithm. The first password identification code is usually a fixed-length string that uniquely corresponds to the input password.

[0047] Step S3: Establish a connection with the wireless access point based on the entered password and the first password identification code.

[0048] Specifically, after ensuring the wireless access point is powered on and in a connectable state, the user sends the input password and the first password identification code to the wireless access point. The wireless access point verifies the password and the first password identification code. After successful verification, the client establishes a connection with the wireless access point. The first password identification code does not need to be directly entered by the user; it is generated in the background by the device or software based on the user-input password and a specific algorithm.

[0049] According to the wireless connection method of the present invention, after receiving the input password, the device client determines the password identification code target generation algorithm based on the input password, and obtains the first password identification code corresponding to the input password through the password identification code target generation algorithm. The device client only needs to input the password to the device client, and the device client can use the correct input password and the first password identification code to establish a secure connection with the wireless access point, thereby improving the security and efficiency of wireless connection, reducing the complexity of wireless connection, and enhancing the user experience.

[0050] In some embodiments, the password identification code target generation algorithm takes the input password as input and the password identification code corresponding to the input password as the calculation result.

[0051] Specifically, when making a wireless connection, the client enters a password, and the password identification code target generation algorithm converts the entered password into a corresponding password identification code. The password identification code target generation algorithm ensures the security and uniqueness of the password, while making the generated password identification code difficult to guess or crack.

[0052] In some embodiments, the first password identification code uniquely corresponds to the input password.

[0053] Specifically, during the wireless connection process, it is necessary to ensure a unique correspondence between the first password identification code and the input password to enhance security and determinism. The first password identification code and the password are stored in a secure database, and the first password identification code is obtained based on the input password after the client enters the password.

[0054] For example, to ensure usability and security, a password identification code generation algorithm needs to meet the following conditions: It must guarantee that a unique password identification code can be generated from the password. This one-way uniqueness can be guaranteed by the algorithm itself or by additional constraints added to the algorithm; it must also guarantee that the password cannot be deduced from the password identification code, because the password identification code is exchanged in plaintext between the wireless access point and the client.

[0055] In some embodiments, the password identification code target generation algorithm is the default password identification code generation algorithm between the client and the wireless access point.

[0056] Specifically, there can be multiple password identification code generation algorithms. When a client connects to a wireless access point, a default password identification code generation algorithm is usually set. After the password is entered, a password identification code is generated according to the default password identification code generation algorithm. With the development of technology and the upgrading of wireless network equipment, when selecting and using wireless network equipment, it is important to carefully understand the security standards and functions it supports, and to configure and optimize it according to actual needs.

[0057] In some embodiments, the default password identification code generation algorithm is a password identification code generation algorithm bound to a security mechanism; wherein, the security mechanism is the security mechanism that will be used after the client and the wireless access point establish a connection.

[0058] Specifically, the default password identification code generation algorithm is indeed usually tied to a security mechanism. This binding ensures that the generation, storage, and use of the password identification code comply with specific security standards. The default password identification code generation algorithm is usually selected based on current security standards. The algorithm is tested to ensure that it can resist various known attack methods. The default password identification code generation algorithm usually has the ability to automatically generate keys. It can automatically call the algorithm and generate keys that meet security requirements to ensure overall security.

[0059] In some embodiments, the security mechanism includes at least one of an authentication mechanism, an encryption mechanism, a key specification used in the authentication or encryption process, a key generation mechanism used in the authentication or encryption process, and a key distribution mechanism used in the authentication or encryption process.

[0060] Specifically, authentication mechanisms are the process of verifying the identity of a user or device to ensure that only legitimate users or devices can access the system or data. This typically involves verifying whether the credentials provided by the user (such as username and password) match the information stored in the system. Common authentication methods include message authentication, digital signatures, and identity authentication. Encryption mechanisms are the process of ensuring the confidentiality of data by encoding it. Only legitimate users with the corresponding decryption key can decrypt and access the data. Key specifications involve the key's length, format, and algorithm. The key length directly affects the security of the encryption; generally, the longer the key, the higher the security. Different encryption algorithms also have different requirements for key format and algorithm. Key generation mechanisms are the process of generating keys for encryption and decryption. This typically involves using a random number generator and a proven secure algorithm to generate keys. Key generation should ensure randomness and unpredictability to prevent attackers from obtaining keys through guessing or brute-force attacks. Key distribution mechanisms are the process of ensuring the secure transmission of keys to legitimate users or devices. Common key distribution methods include pre-distribution and online distribution.

[0061] In some embodiments, determining the target password identification code generation algorithm includes: selecting a configured AKM kit and obtaining the password identification code generation algorithm bound to the AKM component; sending the selection information of the AKM component to the wireless access point to synchronize the password identification code generation algorithm; and upon receiving confirmation information from the wireless access point in response to the selection information of the AKM component, the password identification code generation algorithm bound to the currently selected AKM component is the target password identification code generation algorithm.

[0062] Specifically, in Wi-Fi security, AKM refers to the Authentication and Key Management Protocol. It is a mechanism used to determine the authentication methods in a Wi-Fi network and how to generate and manage encryption keys. The AKM protocol plays a key role in Wi-Fi security protocols such as WPA3, ensuring the security and integrity of wireless networks.

[0063] The synchronization of password identification code generation algorithms between the wireless access point and the device client is typically related to the authentication and key management of the key management component. This ensures that both parties use the same algorithm to generate password identification codes, thereby enhancing the security of wireless communication. The device client first selects a password identification code generation algorithm bound to the AKM component, and then sends the AKM component's selection information to the wireless access point. The AKM component's selection information includes the password identification code generation algorithm bound to the AKM component to ensure that the algorithm is not eavesdropped or tampered with during transmission. After receiving the AKM component's selection information, the wireless access point verifies the algorithm's validity and compatibility. If the algorithm is successfully verified and deemed secure, the wireless access point sends a confirmation message to the device client in response to the AKM component's selection information. Upon receiving the confirmation message from the wireless access point, the device client confirms that the currently selected password identification code generation algorithm is the target password identification code generation algorithm. Simultaneously, the wireless access point updates its internal algorithm to the received target password identification code generation algorithm to ensure that both parties use the same algorithm.

[0064] For example, the synchronization of the generation algorithm can include one of the following methods: the wireless access point and the client can use only a fixed password identification code generation algorithm by default. This fixed password identification code generation algorithm can be bound to the security mechanism to be used between the AP / STA. This security mechanism can include an authentication mechanism, and / or an encryption mechanism, and / or the key specification used in the authentication / encryption process, and / or the key generation / distribution mechanism used in the authentication / encryption process.

[0065] 802.11 devices refer to wireless local area network (WLAN) devices based on the 802.11 standard. 802.11 is a WLAN standard developed and released in June 1997 by the Institute of Electrical and Electronics Engineers (IEEE) to address the interconnection of wireless network devices.

[0066] like Figure 2 The image shows an example of a password identification code generation algorithm bound to a security mechanism. In this example, using an 802.11 secure connection, the security mechanism selected by the AP and STA during a secure connection is determined by the AKM suite used. The AP / STA side has one or more supported AKM suites. Before triggering the STA connection to the AP, the STA first determines which AKM suite to use and subsequently confirms the bound password identification code generation algorithm. The synchronization of the password identification code generation algorithm is completed simultaneously when the STA and AP perform AKM interaction protocol communication.

[0067] In some embodiments, determining the target password identification code generation algorithm includes: determining the target password identification code generation algorithm by negotiating with a wireless access point.

[0068] Specifically, by negotiating with the wireless access point to determine the target generation algorithm for the password identification code, the security of wireless network communication can be ensured. In practical applications, the latest and more secure encryption algorithms and protocols (such as WPA3) should be selected, and relevant security standards and best practices should be followed when configuring and managing the wireless network. At the same time, users should also pay attention to protecting their network security and avoid using weak passwords or performing sensitive operations in insecure network environments.

[0069] For example, such as Figure 3 As shown, in the password identification code generation algorithm used by AP and STA for negotiation, once the negotiation is successful, the synchronization of the password identification code generation algorithm is completed.

[0070] In some embodiments, determining the target generation algorithm for the password identification code includes: receiving target broadcast information from a wireless access point, the target broadcast information carrying information about the target generation algorithm for the password identification code; and determining the target generation algorithm for the password identification code based on the information about the target generation algorithm for the password identification code carried in the target broadcast information.

[0071] Specifically, in wireless network communication, receiving the target broadcast information of the wireless access point and parsing the password identification code target generation algorithm information from it is an important step to ensure a secure connection. Device clients (such as smartphones, laptops, etc.) will listen to the surrounding wireless channels to find available wireless access points. In the broadcast information, there are usually one or more fields indicating the encryption methods supported by the access point. Based on the encryption methods provided in the broadcast information, the client can determine the password identification code target generation algorithm to use.

[0072] For example, the AP needs to notify the STA of its password identification code generation algorithm via broadcast or unicast. The STA then uses this AP-specified password identification code generation algorithm for subsequent secure connections. The AP can notify the STA of the password identification code algorithm in the following ways: by including it in its periodic broadcast / sent packets, such as the periodic Beacon packets sent by the AP; or by including it in broadcast or unicast packets sent to the STA, such as the probe response packets sent by the AP in response to the STA.

[0073] like Figure 4As shown, the AP can notify the client of the selected password identification code generation algorithm (and possible corresponding parameters) in its Beacon / Probe response frames by placing it in a Vendor-Specific IE (Information Element).

[0074] In some embodiments, the wireless connection method further includes negotiating or synchronizing with the wireless access point the input parameters other than the password required by the password identification code target generation algorithm.

[0075] Specifically, in the process of negotiating or synchronizing password identification codes between wireless access points and client devices, in addition to the password itself, a series of input parameters are required to ensure the normal operation of the security protocol and the correct generation of keys. These parameters usually involve various aspects of the network authentication and key exchange process.

[0076] In some embodiments, the input parameters other than the ciphertext required to negotiate or synchronize the ciphertext target generation algorithm with the wireless access point include: the input parameters other than the ciphertext required to negotiate or synchronize the ciphertext target generation algorithm with the wireless access point, either explicitly or implicitly.

[0077] Specifically, in wireless network communication, when negotiating or synchronizing the target generation algorithm of the password identification code with the wireless access point, in addition to the password itself, a series of other input parameters are indeed needed to ensure the correctness and security of the algorithm. These parameters can be negotiated or synchronized with the wireless access point in an explicit or implicit manner. Parameters negotiated explicitly include: device identification information, pre-shared key or master key, encryption algorithm and protocol; parameters synchronized implicitly include: timestamp, authentication information, network configuration and policy.

[0078] For example, this invention supports automatically generating a corresponding password identification code based on the password value. An 802.11 device, including the AP side and STA side, can generate a corresponding password identification code by taking a password as input and using a target password identification code algorithm.

[0079] Password_Identifier = Fun(Password,Vargin); In the above formula, "Fun" represents the password identification code target generation algorithm to be used, "Password" represents the input password, "Vargin" represents other input parameters required by this password identification code target generation algorithm, and these one or more parameters are optional. "Password_Identifier" is the password identification code corresponding to the input password output.

[0080] When distributing password identification codes to general users, this method requires the same password identification code generation algorithm to be used on both the AP and STA sides. When a user receives a password, it is equivalent to receiving the corresponding password identification code. To ensure that the password identification codes generated by both sides are identical, the password identification code generation algorithm needs to be synchronized on both the AP and STA sides. The synchronized information may include: the specific generation algorithm, including the aforementioned "Fun"; and / or the input parameters used by the specific generation algorithm, other than the password, including the aforementioned "Vargin". During the synchronization process of the generation algorithm, the information synchronized according to security requirements can be explicitly negotiated or synchronized; or the information can be implicitly negotiated or synchronized, meaning the synchronized information can be inferred from other parameters or information.

[0081] In some embodiments, the password identification code target generation algorithm is any one of the following algorithms: a single-input parameter CRC algorithm or Hash algorithm; a multi-input parameter Hash MAC algorithm; a method for generating a key based on the input password and using the key to encrypt all or part of the input password to obtain a password identification code.

[0082] Specifically, CRC is a method for detecting errors in data transmission or storage. It achieves this by adding a checksum to the data. This checksum is calculated based on the original data and a preset polynomial. The CRC algorithm belongs to linear block codes, with simple encoding and decoding methods and strong error detection and correction capabilities, and is widely used in the field of communication for error control. A hash algorithm is an algorithm that converts an input of arbitrary length (also called a message) into a fixed-length output (also called a hash value, digest). Hash algorithms have wide applications in computer science, including data storage, data retrieval, data integrity verification, and cryptography. The multi-input parameter hash MAC algorithm is a message authentication code algorithm that uses a key. It combines a one-way hash function and a key to verify data integrity and confirm the sender's identity.

[0083] For example, a password identification code target generation algorithm may include: a CRC algorithm with a single input parameter, or a Hash algorithm, or an HMAC (Hash MAC) algorithm with multiple input parameters, or other algorithms.

[0084] Using CRC / Hash only requires the password as an input parameter. As long as the AP and STA use the same CRC / Hash algorithm, it can be guaranteed that the same password identification code will be generated from the same password. However, a drawback is that using the CRC / Hash algorithm may generate the same password identification code from different input passwords.

[0085] In addition to the password, the HMAC (Hash MAC) algorithm can also accept one or more key parameters as input, i.e., ID = HMAC(Password, key). This allows the AP to ensure that different passwords generate different password identification codes by changing the value of the key. The disadvantage of HMAC is that the AP needs to notify the STA of the key value used to ensure that the STA uses the same HMAC algorithm and key value.

[0086] To prevent the password identification code from leaking more password-related information, the password identification code target generation algorithm can also use a more complex algorithm, such as generating a key based on the password and then using the key to encrypt all or part of the password to obtain the password identification code.

[0087] A second aspect of the present invention provides a WPA3-based wireless connection method, which can be used for a wireless access point.

[0088] The following is for reference. Figure 5 A WPA3-based wireless connection method according to an embodiment of the second aspect of the present invention is described, such as... Figure 5 As shown, the method includes at least steps S4 to S7.

[0089] Step S4: Synchronize the password identification code target generation algorithm with the client.

[0090] Specifically, to ensure that the password identification codes generated by the wireless access point and the client can correspond to each other, the wireless access point and the client synchronize the password identification code target generation algorithm.

[0091] Step S5: Receive the input password and first password identification code from the client.

[0092] Specifically, after the wireless access point and the client synchronize the password identification code target generation algorithm, the wireless access point receives the input password and the first password identification code sent by the client to ensure the security and reliability of the wireless connection.

[0093] Step S6: Obtain the second password identification code based on the input password and the password identification code target generation algorithm.

[0094] Specifically, the second password identification code can be understood as the password identification code generated by the wireless access point through the input password and the password identification code target generation algorithm. The process of generating the second password identification code based on the input password and the password identification code target usually involves cryptographic algorithms such as encryption. The security and reliability of the password identification code are ensured through complex processing and more security measures.

[0095] Step S7: The second password identification code is consistent with the first password identification code, and a connection is established with the client.

[0096] Specifically, in wireless communication, two devices, such as a wireless access point and a client, need to use the same identification code to confirm each other's identity. If the second password identification code generated by the wireless access point matches the first password identification code, the wireless access point and the client establish a connection.

[0097] According to the wireless connection method of the present invention, the wireless access point first synchronizes the password identification code target generation algorithm with the client. After the wireless access point receives the input password and the first password identification code sent by the client, it obtains the second password identification code through the input password and the password identification code target generation algorithm. It then compares whether the second password identification code is consistent with the first password identification code. When the second password identification code is consistent with the first password identification code, the wireless access point establishes a connection with the client, thereby improving the security and efficiency of the wireless connection, reducing the complexity of the wireless connection, and enhancing the user experience.

[0098] In some embodiments, the password identification code target generation algorithm is the default password identification code generation algorithm between the client and the wireless access point.

[0099] Specifically, there can be multiple password identification code generation algorithms. When the client connects to the wireless access point, a default password identification code generation algorithm is usually set. After the password is entered, the password identification code is generated according to the default password identification code generation algorithm.

[0100] In some embodiments, the default password identification code generation algorithm is a password identification code generation algorithm bound to a security mechanism; wherein, the security mechanism is the security mechanism to be used after the wireless access point and the client establish a connection; the security mechanism includes at least one of an authentication mechanism, an encryption mechanism, a key specification used in the authentication or encryption process, a key generation mechanism used in the authentication or encryption process, and a key distribution mechanism used in the authentication or encryption process.

[0101] Specifically, the default password generation algorithm is usually tied to a security mechanism. This binding ensures that the generation, storage, and use of passwords comply with specific security standards. Authentication mechanisms verify the identity of users or devices to ensure that only legitimate users or devices can access the system or data. This typically involves verifying whether the credentials provided by the user (such as username and password) match the information stored in the system. Common authentication methods include message authentication, digital signatures, and identity authentication. Encryption mechanisms ensure the confidentiality of data by encoding it. Only legitimate users with the corresponding decryption key can decrypt and access the data. Key specifications involve the key's length, format, and algorithm. The key length directly affects the security of the encryption; generally, the longer the key, the higher the security. Different encryption algorithms have different requirements for key format and algorithm. Key generation mechanisms are the process of generating keys for encryption and decryption. This typically involves using a random number generator and a verified secure algorithm to generate keys. Key generation should ensure randomness and unpredictability to prevent attackers from obtaining keys through guessing or brute-force attacks. A key distribution mechanism is the process of ensuring that keys are securely transmitted to legitimate users or devices. Common key distribution methods include pre-distribution and online distribution.

[0102] In some embodiments, synchronizing the password identification code target generation algorithm with the client includes: receiving AKM component selection information sent by the client; sending confirmation information for the AKM component selection information to the client, so as to use the password identification code generation algorithm bound to the currently confirmed AKM component as the password identification code target generation algorithm.

[0103] Specifically, such as Figure 2 As shown, the device client first selects a password identification code generation algorithm bound to the AKM component, and then sends the AKM component selection information to the wireless access point. The AKM component selection information includes the password identification code generation algorithm bound to the AKM component. The wireless access point receives the AKM component selection information sent by the client, and then sends confirmation information for the AKM component selection information to the client. The wireless access point receives the confirmation information from the client. After receiving the client's confirmation information, the wireless access point confirms that the currently selected password identification code generation algorithm is the target password identification code generation algorithm to ensure that both parties use the same algorithm.

[0104] In some embodiments, synchronizing the password identification code target generation algorithm with the client includes: determining the password identification code target generation algorithm through negotiation with the client.

[0105] Specifically, by negotiating with the client to determine the target algorithm for generating the password identification code, the security of wireless network communication can be ensured. In practical applications, the latest and more secure encryption algorithms and protocols (such as WPA3) should be selected, and relevant security standards and best practices should be followed when configuring and managing the wireless network.

[0106] In some embodiments, synchronizing the password identification code target generation algorithm with the client includes: determining the password identification target generation algorithm; and broadcasting target broadcast information carrying information about the password identification code target generation algorithm.

[0107] Specifically, the wireless access point first determines the password identification target generation algorithm. After determining the password identification target generation algorithm, the wireless access point broadcasts target broadcast information carrying information about the password identification target generation algorithm. The device client will listen to the surrounding wireless channels, look for available wireless access points, and obtain the broadcast information of the wireless access points.

[0108] In some embodiments, the target broadcast information includes at least one of the following: periodic broadcast information or periodically transmitted information packets from a wireless access point; broadcast information packets or single-use information packets transmitted by a wireless access point to a client.

[0109] Specifically, the periodic broadcast messages or periodically sent packets from a wireless access point refer to information automatically sent by the wireless access point at certain time intervals. This information may include basic information such as the wireless access point's service set identifier, supported encryption methods, and signal strength, so that nearby client devices can discover and connect to the network. Periodic broadcasting ensures network discoverability and connectivity. The broadcast packets or single packets sent by the wireless access point to the client are notifications to the client. When the network status changes (such as access point restarts, network load increases, etc.), the wireless access point may send broadcast packets to notify the client of these changes.

[0110] In some embodiments, the wireless connection method further includes: explicitly or implicitly negotiating or synchronizing input parameters other than the password required by the password identification target generation algorithm with the client.

[0111] Specifically, in wireless network communication, when a wireless access point negotiates or synchronizes a password identification code target generation algorithm with a client, in addition to the password itself, a series of other input parameters are indeed needed to ensure the correctness and security of the algorithm. These parameters can be negotiated or synchronized with the wireless access point in an explicit or implicit manner. Parameters negotiated explicitly include: device identification information, pre-shared key or master key, encryption algorithm and protocol; parameters synchronized implicitly include: timestamp, authentication information, network configuration and policy.

[0112] For example, in this invention, when a user connects a device client to a wireless access point, they can directly enter the password in the existing way.

[0113] After obtaining the password, the device client can acquire the code recognition code generation algorithm based on the different code recognition code generation algorithms, and automatically generate a code recognition code. Then, it can use the generated code recognition code to establish a secure connection with the wireless access point.

[0114] If the AP / STA side uses a generation algorithm that does not change the parameters, the STA directly uses this generation algorithm to generate a password identification code and uses this password identification code and password to complete a secure connection with the AP. If the STA needs to know the AP's password identification code generation algorithm and corresponding parameters first, the STA must first obtain this information from the AP's message carrying the corresponding generation algorithm and parameters, and then generate the password identification code based on the obtained generation algorithm information.

[0115] like Figure 6 As shown, the device STA uses the password identification code generation algorithm broadcast by the AP to generate its own password identification code and establish a secure connection with the AP.

[0116] A third aspect of the present invention provides an electronic device, such as... Figure 7 As shown, the electronic device 100 includes at least one processor 101 and a memory 102.

[0117] In this embodiment, at least one processor 101 is communicatively connected to a memory 102, which stores a computer program that can be executed by at least one processor 101. When at least one processor 101 executes the computer program, it implements a WPA3-based wireless connection method.

[0118] According to the electronic device of the present invention, a corresponding WPA3-based wireless connection program can be stored in a memory. When implementing the WPA3-based wireless connection method, the processor runs the program in the memory, obtains a first password identification code and a second password identification code based on the input password, and when the first password identification code and the second password identification code are consistent, the wireless access point establishes a connection with the client, thereby improving the security and efficiency of wireless connection, reducing the complexity of wireless connection, and enhancing the user experience.

[0119] A fourth aspect of the present invention provides a computer storage medium having a computer program stored thereon, characterized in that the computer program, when executed, implements the WPA3-based wireless connection method of the above embodiments.

[0120] In the description of this specification, any process or method described in the flowcharts or otherwise herein may be understood as representing a module, segment, or portion of code comprising one or more executable instructions for implementing custom logic functions or processes, and the scope of the preferred embodiments of the invention includes additional implementations in which functions may be performed not in the order shown or discussed, including substantially simultaneously or in reverse order according to the functions involved, as will be understood by those skilled in the art to which embodiments of the invention pertain.

[0121] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0122] It should be understood that various parts of the present invention can be implemented in hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented in software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware as in another embodiment, it can be implemented using any of the following techniques known in the art, or a combination thereof: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0123] Those skilled in the art will understand that all or part of the steps of the methods in the above embodiments can be implemented by a program instructing related hardware. The program can be stored in a computer-readable storage medium, and when executed, the program includes one or a combination of the steps of the method embodiments.

[0124] Furthermore, the functional units in the various embodiments of the present invention can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into a module. The integrated module can be implemented in hardware or as a software functional module. If the integrated module is implemented as a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium.

[0125] The storage medium mentioned above can be a read-only memory, a disk, or an optical disk, etc. Although embodiments of the present invention have been shown and described above, it is to be understood that the above embodiments are exemplary and should not be construed as limiting the present invention. Those skilled in the art can make changes, modifications, substitutions, and variations to the above embodiments within the scope of the present invention.

[0126] In the description of this specification, references to terms such as "one embodiment," "some embodiments," "illustrative embodiment," "example," "specific example," or "some examples," etc., indicate that a specific feature, substrate, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example.

[0127] Although embodiments of the invention have been shown and described, those skilled in the art will understand that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the claims and their equivalents.

Claims

1. A wireless connection method based on WPA3, characterized in that, For a client, the wireless connection method includes: In response to the input password, determine the password identification code target generation algorithm; The first password identification code corresponding to the input password is obtained according to the password identification code target generation algorithm; A connection is established with the wireless access point based on the input password and the first password identification code.

2. The wireless connection method according to claim 1, characterized in that, The password identification code target generation algorithm takes the input password as input and the password identification code corresponding to the input password as the calculation result.

3. The wireless connection method according to claim 1, characterized in that, The first password identification code corresponds uniquely to the input password.

4. The wireless connection method according to claim 1, characterized in that, The password identification code target generation algorithm is the default password identification code generation algorithm between the client and the wireless access point.

5. The wireless connection method according to claim 4, characterized in that, The default password identification code generation algorithm is a password identification code generation algorithm that is bound to the security mechanism; The security mechanism is the security mechanism that will be used after the client and the wireless access point establish a connection.

6. The wireless connection method according to claim 5, characterized in that, The security mechanism includes at least one of the following: an authentication mechanism, an encryption mechanism, a key specification used in the authentication or encryption process, a key generation mechanism used in the authentication or encryption process, and a key distribution mechanism used in the authentication or encryption process.

7. The wireless connection method according to claim 5, characterized in that, The algorithm for determining the target password identification code includes: Select a configured AKM kit and obtain the password identification code generation algorithm bound to the AKM component; Send the selection information of the AKM component to the wireless access point to synchronize the password identification code generation algorithm; Upon receiving confirmation information from the wireless access point in response to the selection information of the AKM component, the password identification code generation algorithm bound to the currently selected AKM component becomes the password identification code target generation algorithm.

8. The wireless connection method according to claim 1, characterized in that, The method for determining the target generation algorithm for the password identification code includes: determining the target generation algorithm for the password identification code through negotiation with the wireless access point.

9. The wireless connection method according to claim 1, characterized in that, The algorithm for determining the target password identification code includes: Receive target broadcast information from the wireless access point, wherein the target broadcast information carries information about the password identification code target generation algorithm; The password identification code target generation algorithm is determined based on the information of the password identification code target generation algorithm carried in the target broadcast information.

10. The wireless connection method according to any one of claims 1-9, further comprising: Negotiate or synchronize with the wireless access point the input parameters other than the password required by the password identification code target generation algorithm.

11. The wireless connection method according to claim 10, characterized in that, The input parameters other than the password required to negotiate or synchronize the password identification code target generation algorithm with the wireless access point include: The input parameters other than the password required by the password identification target generation algorithm are negotiated or synchronized with the wireless access point, either explicitly or implicitly.

12. The wireless connection method according to any one of claims 1-9, characterized in that, The target generation algorithm for the password identification code is any one of the following algorithms: A CRC algorithm or Hash algorithm with a single input parameter; A hash MAC algorithm with multiple input parameters; A method for generating a key based on the input password and using the key to encrypt all or part of the input password to obtain a password identification code.

13. A wireless connection method based on WPA3, characterized in that, For a wireless access point, the wireless connection method includes: Synchronize the password identification code target generation algorithm with the client; Receive the input password and first password identification code from the client; The second password identification code is obtained based on the input password and the password identification code target generation algorithm; The second password identification code is the same as the first password identification code, and a connection is established with the client.

14. The wireless connection method according to claim 13, characterized in that, The password identification code target generation algorithm is the default password identification code generation algorithm between the client and the wireless access point.

15. The wireless connection method according to claim 14, characterized in that, The default password identification code generation algorithm is a password identification code generation algorithm that is bound to the security mechanism; The security mechanism mentioned above is the security mechanism that will be used after the wireless access point and the client establish a connection. The security mechanism includes at least one of the following: an authentication mechanism, an encryption mechanism, a key specification used in the authentication or encryption process, a key generation mechanism used in the authentication or encryption process, and a key distribution mechanism used in the authentication or encryption process.

16. The wireless connection method according to claim 15, characterized in that, The algorithm for generating the target password identification code synchronized with the client includes: Received the AKM component selection information sent by the client; A confirmation message for the selection information of the AKM component is sent to the client, so as to use the password identification code generation algorithm currently confirmed to be bound to the AKM component as the target password identification code generation algorithm.

17. The wireless connection method according to claim 13, characterized in that, Synchronizing the password identification code target generation algorithm with the client includes: determining the password identification code target generation algorithm through negotiation with the client.

18. The wireless connection method according to claim 13, characterized in that, The algorithm for generating password identification code targets synchronized with the client includes: Determine the target generation algorithm for the password recognition; Broadcast target broadcast information carrying information about the password identification code target generation algorithm.

19. The wireless connection method according to claim 18, characterized in that, The target broadcast information includes at least one of the following: The periodic broadcast information or periodically sent information packets of the wireless access point; The wireless access point sends broadcast packets or single packets to the client.

20. The wireless connection method according to any one of claims 13-19, characterized in that, The wireless connection method further includes: The input parameters other than the password required by the password identification target generation algorithm are negotiated or synchronized with the client, either explicitly or implicitly.

21. An electronic device, characterized in that, include: At least one processor; A memory that is communicatively connected to the at least one processor; The memory stores a computer program that can be executed by the at least one processor. When the at least one processor executes the computer program, it implements the WPA3-based wireless connection method according to any one of claims 1-12, or implements the WPA3-based wireless connection method according to any one of claims 13-20.

22. A computer storage medium having a computer program stored thereon, characterized in that, When the computer program is executed, it implements the WPA3-based wireless connection method according to any one of claims 1-12, or implements the WPA3-based wireless connection method according to any one of claims 13-20.