Authentication method, device and chip

The extended PASN method enhances WiFi authentication by supporting FILS shared key and public key authentication, addressing security vulnerabilities in WiFi connections and ensuring secure data transmission.

JP2025525924APending Publication Date: 2025-08-07GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025506035
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2022-08-03
Publication Date
2025-08-07

AI Technical Summary

Technical Problem

Existing wireless communication technologies lack effective methods for enhancing the security and integrity of the authentication process during the association stage of WiFi connections, particularly in infrastructure BSS networks, which can lead to vulnerabilities in data transmission.

Method used

The implementation of an extended Pre-Association Security Negotiation (PASN) method supporting Fast Initial Link Setup (FILS) shared key authentication with perfect forward secrecy, FILS public key authentication, and 802.1X authentication, utilizing enhanced authentication frames to ensure secure identity verification between Stations (STAs) and Access Points (APs).

Benefits of technology

This approach strengthens the security of WiFi connections by providing enhanced authentication methods that protect against unauthorized access and ensure data integrity, thereby improving the overall security and reliability of wireless communication systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025525924000001_ABST
    Figure 2025525924000001_ABST
Patent Text Reader

Abstract

This application discloses an authentication method, apparatus, device, and storage medium, which relate to the wireless communication field. The method is performed by a STA and an AP, and includes transmitting an authentication frame between the STA and the station AP to perform an authentication procedure, where a field in the authentication frame indicates that identity authentication is performed using at least one authentication method selected from the group consisting of an extended PASN supporting FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication. The method also uses a PTK generated in the authentication procedure to protect messages during an association establishment procedure between the STA and the AP, where the messages include one of an association request message, a response message, a 4-way handshake message, and a group key handshake message.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] The present application relates to the field of wireless communication, and in particular to an authentication method, apparatus, device and storage medium. [Background technology]

[0002] WiFi (Wireless Network Communication Technology) connection includes three stages: Probe, Authentication, and Association. In the Probe stage, a STA (Station) searches for an AP (Access Point). In the Authentication stage, the AP performs identity authentication on the STA. After passing the authentication, the STA accesses the AP in the Association stage.

[0003] Based on the IEEE (Institute of Electrical and Electronics Engineers) 802.11az protocol, in an infrastructure BSS network, a STA that has not established association with an AP can establish a Pairwise Transient Key Security Association (PTKSA) with the AP using a Pre-association Security Negotiation (PSAN) procedure. Related technology provides an extended PASN method to protect association request and response messages. This method extends the Base Authentication and Key Management (Base AKM) method used in PASN. Summary of the Invention

[0004] The present application provides an authentication method, an apparatus, a device, and a storage medium.

[0005] According to one aspect of the present application, there is provided an authentication method performed by a STA, the authentication method comprising: The authentication procedure is performed by transmitting an authentication frame between the access point (AP), and a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method selected from the group consisting of an extended pre-association security negotiation (PASN) supporting fast initial link setup (FILS) shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0006] According to one aspect of the present application, there is provided an authentication method performed by an AP, the authentication method comprising: The authentication procedure is performed by transmitting an authentication frame between the STA and the STA, and a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method selected from the group consisting of an extended pre-association security negotiation PASN supporting fast initial link setup FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0007] According to another aspect of the present application, there is provided an authentication device, the device comprising: The access point (AP) includes a first authentication module used to perform an authentication procedure by transmitting an authentication frame between the access point (AP), and a first field in the authentication frame is used to instruct identity authentication to be performed using at least one authentication method selected from the group consisting of an extended pre-association security negotiation (PASN) supporting fast initial link setup (FILS) shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0008] According to another aspect of the present application, there is provided an authentication device, the device comprising: The present invention also includes a second authentication module used to perform an authentication procedure by transmitting an authentication frame between the STA and the STA, and a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method selected from the group consisting of an extended pre-association security negotiation PASN supporting fast initial link setup FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0009] According to another aspect of the present application, there is provided a STA device, the device comprising: a processor; a transceiver coupled to the processor; a memory for storing executable instructions for said processor; Including, The processor is configured to load the executable instructions to cause the STA device to implement the authentication method according to the above aspect.

[0010] According to another aspect of the present application, there is provided an AP device, the device comprising: a processor; a transceiver coupled to the processor; a memory for storing executable instructions for said processor; Including, The processor is arranged to load the executable instructions to cause the AP device to implement the authentication method according to the above aspect.

[0011] According to another aspect of the present application, there is provided a computer-readable storage medium having executable instructions stored therein, the executable instructions being loaded and executed by a processor to cause a communication device to implement the authentication method described in the above aspect.

[0012] According to one aspect of the present application, a chip is provided, the chip including a programmable logic circuit or a program, and a communication device to which the chip is attached is used to realize the authentication method described in the above aspect by means of the programmable logic circuit or the program.

[0013] According to one aspect of the present application, a computer program product is provided, the computer program product including computer instructions stored on a computer-readable storage medium, wherein a processor of the communication device reads the computer instructions from the computer-readable storage medium and the authentication device executes the computer instructions to cause the communication device to implement the authentication method described in the above aspect.

[0014] The invention provided in the examples of this application includes at least the following beneficial effects.

[0015] By enhancing the capacity of the first field of the authentication frame, the adopted authentication method is indicated as an extended PASN supporting FILS (Fast Initial Link Setup) shared key authentication with PFS (Perfect Forward Security), an extended PASN supporting FILS public key authentication, or an extended PASN supporting 802.1X authentication. We clarified how to extend PASN to support the above authentication methods and the message format. [Brief explanation of the drawings]

[0016] In order to more clearly explain the invention in the embodiments of the present application, the following will briefly describe the drawings necessary for explaining the embodiments. However, the drawings in the following description are only some embodiments of the present application, and it is obvious to those skilled in the art that other drawings can be obtained based on these drawings without any creative work.

[0017] [Figure 1] 1 is a block diagram of a communication system provided in an exemplary embodiment of the present application; [Figure 2] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 3] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 4] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 5] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 6] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 7] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 8] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 9] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 10] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 11] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 12] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 13] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 14] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 15]1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 16] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 17] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 18] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 19] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 20] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 21] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 22] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 23] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 24] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 25] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 26] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 27] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 28] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 29] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 30] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 31] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 32] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 33] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 34] FIG. 2 is a schematic diagram of an authentication frame provided in an exemplary embodiment of the present application; [Figure 35] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 36] 1 is a flowchart of an authentication method provided in an exemplary embodiment of the present application; [Figure 37] FIG. 1 is a block diagram of an authentication device provided in an exemplary embodiment of the present application; [Figure 38] FIG. 1 is a block diagram of an authentication device provided in an exemplary embodiment of the present application; [Figure 39] 1 is a structural schematic diagram of an authentication device provided in an exemplary embodiment of the present application; DETAILED DESCRIPTION OF THE INVENTION

[0018] To clarify the objectives, features, and advantages of the present application, the following description of the embodiments of the present application will be made in more detail with reference to the accompanying drawings. Reference will now be made in detail to exemplary embodiments, examples of which are illustrated in the accompanying drawings. In the following description, unless otherwise specified with respect to the drawings, the same numerals in different drawings represent the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present application. On the contrary, these are merely examples of apparatuses and methods consistent with certain aspects of the present application, as detailed in the claims.

[0019] The terms used in this disclosure are used only for the purpose of describing particular embodiments and are not intended to limit the disclosure. As used in this disclosure and in the claims, the singular forms "a," "the," and "said" are intended to include the plural forms as well, unless the context indicates otherwise. The term "and / or," as used in this disclosure, should be understood to mean any and all possible combinations of one or more of the associated listed items.

[0020] Although the present disclosure may use terms such as first, second, third, etc. to describe various pieces of information, it should be understood that such information should not be limited to these terms. These terms are used to distinguish between the same types of information. For example, first information may also be referred to as second information, and similarly, second information may also be referred to as first information, without departing from the scope of the present disclosure. Depending on the context, for example, the word "if" used herein may be interpreted as "if...," "when...," or "in response to determining."

[0021] The invention of the present application may be applied to various communication systems (e.g., Wireless Local Area Networks (WLAN), Wireless Fidelity (WiFi), or other communication systems).

[0022] 1 is a block diagram of a communication system provided in an exemplary embodiment of the present application. The communication system includes an access point (AP) 10 and a station (STA) 20, although the present application is not limited thereto. The present application will be described as an example in which the communication system includes an AP and a STA. The AP / STA may also be called a communication device or an authentication device.

[0023] In some scenarios, an AP can also be called an AP STA, that is, in a sense, an AP is also an STA.

[0024] In some scenarios, the STA is also called a non-AP STA (non-AP STA). Communication in the communication system may be communication between an AP and a non-AP STA, communication between a non-AP STA and a non-AP STA, or communication between a STA and a peer STA, where the peer STA may refer to a device that communicates peer-to-peer with the STA. For example, the peer STA may be an AP or a non-AP STA.

[0025] It should be understood that the role of an STA in a communication system is not absolute. For example, in some scenarios, when a mobile phone is connected to a router, the mobile phone is a non-AP STA, and when the mobile phone is used as a hotspot for other mobile phones, the mobile phone plays the role of an AP.

[0026] In some embodiments, the STAs may include AP STAs and non-AP STAs.

[0027] An AP acts as a bridge between wired and wireless networks, connecting clients to each wireless network and then connecting them to Ethernet. AP devices can be terminal devices (e.g., mobile phones) or network devices (e.g., routers) with a Wireless Fidelity (Wi-Fi) chip.

[0028] It should be understood that the role of an STA in a communication system is not absolute. For example, in some scenarios, when a mobile phone is connected to a router, the mobile phone is a non-AP STA, and when the mobile phone is used as a hotspot for other mobile phones, the mobile phone plays the role of an AP.

[0029] The AP and non-AP STA may be devices applied to the Internet of Vehicles, Internet of Things nodes in the Internet of Things (IoT), sensors, etc., smart cameras, smart remote controls, smart water meters, smart electricity meters, etc. in smart homes, and sensors in smart cities.

[0030] In the present embodiment, both the station and the access point support the IEEE 802.11 standard, but are not limited to the IEEE 802.11 standard.

[0031] In some embodiments, the non-AP STAs may support, but are not limited to, the 802.11bf standard. The non-AP STAs may also support various current and future WLAN standards in the 802.11 family, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.

[0032] In some embodiments, the AP may be a device that supports the 802.11bf standard. The AP may also be a device that supports various current and future WLAN standards of the 802.11 family, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.

[0033] In an embodiment of the present application, the STA may be a mobile phone, tablet, computer, virtual reality (VR) device, augmented reality (AR) device, wireless device in industrial control, set-top box, wireless device in self-driving, in-vehicle communication device, wireless device in remote medical, wireless device in smart grid, wireless device in transportation safety, wireless device in smart city or wireless device in smart home, wireless communication chip / ASIC / SOC / etc. that supports WLAN / Wi-Fi technology.

[0034] The frequency bands that WLAN technology can support include, but are not limited to, low frequency bands (2.4 GHz, 5 GHz, 6 GHz) and high frequency bands (60 GHz).

[0035] There are one or more links between a station and an access point.

[0036] In some embodiments, stations and access points support multi-frequency band communication, e.g., simultaneously communicating in the 2.4 GHz, 5 GHz, 6 GHz, and 60 GHz frequency bands, or simultaneously communicating on different channels in the same frequency band (or different frequency bands), to improve communication throughput and / or reliability between the devices. Such devices are typically referred to as multi-frequency band devices or multi-link devices (MLDs), and are also referred to as multi-link entities or multi-frequency band entities. A multi-link device may be an access point device or a station device. If the multi-link device is an access point device, it includes one or more APs. If the multi-link device is a station device, it includes one or more non-AP STAs.

[0037] A multi-link device including one or more APs is also called an AP, and a multi-link device including one or more non-AP STAs is also called a Non-AP, and in the embodiments of the present application, a Non-AP can be called an STA.

[0038] In an embodiment of the present application, an AP may include multiple APs, a non-AP may include multiple STAs, multiple links may be formed between an AP among the APs and a STA among the non-APs, and data communication may be performed between an AP among the APs and a corresponding STA among the non-APs via the corresponding link.

[0039] An AP is a device deployed in a wireless local area network to provide wireless communication capabilities to STAs. A station may include a user device (UE), access terminal, user unit, user station, mobile station, remote station, remote terminal, mobile device, wireless communication device, user agent, or user equipment. Alternatively, a station may be a mobile phone, a cordless phone, a Session Initiation Protocol (SIP) phone, a Wireless Local Loop (WLL) station, a Personal Digital Assistant (PDA), a handheld device with wireless communication capabilities, a computing device or other processing device connected to a wireless modem, an in-vehicle device, or a wearable device, although embodiments of the present application are not limited thereto.

[0040] The following techniques according to embodiments of the present application will be described below: 1. Three stages of WiFi connection; Pre-Association Security Negotiation (PASN); 3. PMKSA (Pairwise Master Key Security Association, Pairwise Master Key Security Association Context); 4. PTKSA (Pairwise Transient Key Security Association, Pairwise Transient Key Security Association Context); 5. GTKSA (Group Transient Key Secure Association, Group Key Security Association Context); 6. IGTKSA (Integrity Group Temporal Key Security Association); 7. BIGTKSA (Beacon Integrity Group Temporal Key Security Association); 8. Fast Initial Link Setup authentication (FILS authentication); 9. FILS shared key without PFS (FILS shared key without perfect forward secrecy); 10. FILS shared key with PFS (FILS shared key with perfect forward secrecy); 11. FILS public key; 12. 802.1X authentication; 13. 4-way handshake; 14. Group key handshake; 15. SAE Certification (Simultaneous Authentication of Equals).

[0041] 1. Three steps to connect to WiFi

[0042] Includes Probe, Authentication, and Association.

[0043] 1. Probe phase

[0044] The probe stage has two types of probe methods.

[0045] (1) STAs discover networks by listening to beacon frames periodically transmitted by APs. The beacon frames provide information about the AP and the BSS (Basic Service Set) in which the AP is located.

[0046] (2) The STA sequentially sends Probe Request frames on 13 channels, carrying the SSID (Service Set Identifier) and the STA's capability information, and searches for an AP with the same SSID as the STA.

[0047] The AP replies with a Probe Response frame carrying the AP's capability information.

[0048] The role of the probing phase is for the STA to acquire the capabilities of the AP and decide whether to access the network, and for the AP to acquire the capabilities of the STA and decide whether to allow the STA to join the network based on its own situation.

[0049] 2. Authentication stage

[0050] The STA receives the Probe Response frame and decides whether to join the network. If it decides to join, it sends an Authentication frame to perform identity authentication. If it decides not to join, the flow ends.

[0051] 3. Association stage

[0052] After receiving the authentication success packet, if the STA decides to join the network, it sends an Association Request frame indicating the type of network to join, the Listen Interval, and the STA's capability information.

[0053] After receiving the Association Request frame, the AP checks whether the Listen Interval is acceptable and whether the STA's capability information matches. If it is, it returns an Association Response frame carrying the AID (Association ID) and "successful" information to indicate successful association. If it is not acceptable, it returns an Association Response frame carrying the "failed" information.

[0054] Pre-Association Security Negotiation (PASN)

[0055] Based on the IEEE 802.11az protocol, in an infrastructure BSS network, as shown in Figure 2, a STA that has not established an association with an AP can establish a PTKSA with the AP using the PASN procedure.

[0056] In an alternative embodiment, as shown in FIG. 2, the PASN procedure includes the following steps:

[0057] Step 101: The AP periodically transmits a Beacon frame.

[0058] The Beacon frame includes fields such as a Robust Security Network Element (RSNE), an Authentication and Key Management (PASN AKM), a Base AKM, and a Robust Security Network Extension Element (RSNXE).

[0059] Step 102: The STA transmits an 802.11 Authentication 1 frame (first authentication frame) to the AP.

[0060] The Authentication 1 frame includes fields such as a Transaction Sequence Number of 1 (used to indicate Authentication 1), PASN, RSNE, Base AKM, PMK (Pairwise Master Key) ID, RSNXE, S-Ephemeral Pub (the public key of the authenticatee, i.e., the public key of the STA), PASN Parameters, and Base AKM Data-1.

[0061] Step 103: The AP transmits an 802.11 Authentication 2 frame (second authentication frame) to the STA.

[0062] The Authentication 2 frame includes fields such as Transaction Sequence Number (2) (used to indicate Authentication 2), PASN, RSNE, Base AKM, PMK (Pairwise Master Key) ID, RSNXE, A-Ephemeral Pub (the authenticator's public key, i.e., the AP's public key), PASN Parameters, Base AKM Data-2 (Basic AKM second data), and MIC (Messages Integrity Code).

[0063] Step 104: The AP transmits an 802.11 Authentication 3 frame (third authentication frame) to the STA.

[0064] The Authentication 3 frame includes fields such as a Transaction Sequence Number (which is 3) (used to indicate Authentication 3), Base AKM Data-3 (basic AKM third data), and MIC.

[0065] Determined by the selected Authentication and Key Management Protocol (AKMP), the PTKSA formed in the PASN procedure may be two-way authenticated (i.e., Base AKMP is the other Authentication and Key Management Protocol authenticated below) or may not be two-way authenticated (i.e., Base AKMP is the PASN AKMP identified by the identifier 00-0F-AC:21). The PASN procedure involves the transmission of other authentication and key management protocols (SAE authentication marked by identifier 00-0F-AC:8, or FILS authentication marked by identifier 00-0F-AC:14, or FILS authentication marked by identifier 00-0F-AC:15, or FT (Fast BSS Transition) authentication marked by identifier 00-0F-AC:3, or FT authentication marked by identifier 00-0F-AC:4, or FT authentication marked by identifier 00-0F-AC:13, or identifier 00-0F-AC:19) via tunneling techniques (i.e., embedding messages of other protocols into the protocol messages, specifically, for example, wrapping an EAPOL (Extensible Authentication Protocol Over Lan) frame in a Wrapped Data element, and wrapping an SAE (Simultaneous Authentication of Equals) authentication message body in a Wrapped Data element). The Pairwise Master Key Security Association (PMKSA) context is generated by the FT authentication (labeled by ). The PASN procedure also supports using a cached PMKSA for authentication.The PSAN procedure does not include the formation of GTKSA (Group Transient Key Secure Association, Group Key Security Association Context), IGTKSA (Integrity Group Transient Key Secure Association, Integrity Group Key Security Association Context), and BIGTKSA (Beacon Integrity Group Transient Key Secure Association, Beacon Frame Integrity Group Key Security Association Context). For details, please refer to IEEE 80211az_D5.0.

[0066] The way in which a PTK (Pairwise Transient Key) is formed in the PASN procedure is as follows.

[0067] PTK = KDF-HASH-NNN(PMK, “PASN PTK Derivation”, SPA || BSS ID || DHss)

[0068] KDF (Key Derivation Function); HASH; NNN is the number of digits and can be set according to actual needs. “PASN PTK Derivation” is a fixed string.

[0069] Here, if BaseAKMP is PASNAKMP, the PMK is the string "PMKz" supplemented with 28 termination characters (each of which has a value of 0) at the end. If BaseAKMP is not PASNAKMP, the PMK is the PMK generated by the corresponding authentication method (i.e., one of the other authentication and key management protocols listed above).

[0070] DHss is a shared key generated by the Diffie-Hellman (key exchange) procedure based on the prover's public key (S-Ephemeral Pub) and the authenticator's public key (A-Ephemeral Pub).

[0071] In the PASN authentication method, the PTK formed may be bidirectionally authenticated or may not be bidirectionally authenticated. If it is not bidirectionally authenticated, the PTK cannot be used to protect unicast data frames and management frames. Furthermore, since the GTKSA, IGTKSA, and BIGTKSA are not formed in this procedure, it is not possible to protect multicast data frames, and it is not possible to perform integrity checks on multicast management frames and beacon frames.

[0072] 3. PMKSA (Pairwise Master Key Security Association, Pairwise Master Key Security Association Context)

[0073] The PMKSA is typically established through the IEEE 802.1X protocol (IEEE 802.1X exchange) procedure, the Opportunistic Wireless Encryption (OWE exchange, see RFC (Request For Comments) 8110) procedure, the Simultaneous Authentication of Equals (SAE authentication) procedure, the Fast Initial Link Setup (FILS) authentication procedure, or generated using pre-shared key information. A STA and an AP maintain the same PMKSA, and different STAs and APs maintain different PMKSAs. The generated PMKSA can be cached for future use. For more information, see IEEE 80211-2020 and IEEE 80211az_D5.0.

[0074] The PMKSA typically includes a PMK ID for identifying the security context, the MAC (Media Access Control Address) addresses of the device requesting authentication (typically the non-AP or non-AP MLD (Multi-Link Device)) and the device providing authentication (typically the AP or AP MLD), the PMK, a lifetime, and an AKMP indicator.

[0075] The PMKSA may further include authorization parameters (eg, authorized SSIDs that can be accessed), an identifier of the cache in which the PMKSA is located (Cache Identifier).

[0076] 4. PTKSA (Pairwise Transient Key Security Association)

[0077] The PTKSA mainly includes one Pairwise Temporal Key (PTK) derived from the Pairwise Master Key (PMK) and multiple subkeys formed thereby, such as an EAPOL-Key, a Key Confirmation Key (KCK), an EAPOL-Key Key Encryption Key (KEK), a Temporal Key (TK), and a Key Derivation Key (KDK), where the TK is used to encrypt and decrypt protected unicast data frames and management frames, and the KDK is used to derive more keys. The PTKSA is generally established by the 4-way handshake procedure, the Fast BSS Switching 4-way handshake procedure, the Fast BSS Switching authentication sequence procedure, the Fast Initial Link Setup authentication (FILS authentication) procedure, or the PASN procedure. Specific examples can be found in IEEE 80211-2020 and IEEE 80211az_D5.0.

[0078] A PTKSA typically includes a PTK, a pairwise cipher suite selector for identifying the algorithm to be used, a Key ID for identifying the key, the MAC addresses of the device requesting authentication (typically the non-AP or non-AP MLD), and the device providing authentication (typically the AP or AP MLD). A PTKSA may also include an R1KH-ID (the authenticator's MAC address) for fast BSS switch authentication, an S1KH-ID (the authenticatee's MAC address) for fast BSS switch authentication, a PTKName for fast BSS switch authentication, and a WTK for wake-up radio (WUR).

[0079] 5. GTKSA (Group Transient Key Secure Association, Group Key Security Association Context)

[0080] A GTKSA mainly contains a Group Transient Key (GTK) for encrypting and decrypting protected multicast data frames. The use of the GTK is generally unidirectional: the AP encrypts and the STA decrypts. A GTKSA is generally established by the 4-way handshake procedure, the Fast BSS Switching 4-way handshake procedure, the Fast BSS Switching Protocol (FT protocol) procedure, the Fast BSS Switching Resource Request Protocol (FT resource request protocol) procedure, the Group Key Handshake procedure, or the Fast Initial Link Setup Authentication (FILS authentication) procedure. For details, see IEEE 80211-2020.

[0081] The GTKSA typically contains a direction vector indicating whether the GTK is used for encryption on the sending side or decryption on the receiving side, a group cipher suite selector to indicate the algorithm to be used, the GTK, a Key ID to identify the key, and the MAC address of the device providing authentication (typically the AP or AP MLD). The GTKSA may also contain authorization parameters (e.g., authorized SSIDs that can be accessed).

[0082] 6. IGTKSA (Integrity Group Temporal Key Security Association)

[0083] The IGTKSA mainly contains an Integrity Group Temporal Key (IGTK) and a Message Integrity Code (MIC) for generating multicast management frames. The use of the IGTK is generally unidirectional; the AP generates the MIC for the multicast management frame, and the STA checks it.

[0084] The IGTKSA typically contains a direction vector indicating whether the IGTK is used to generate a MIC on the sending side or to check a MIC on the receiving side, the IGTK, an identifier (Key ID) for identifying the key, and the MAC address of the device providing authentication (typically the AP or AP MLD).

[0085] 7. BIGTKSA (Beacon Integrity Group Temporal Key Security Association)

[0086] The BIGTKSA mainly contains one Beacon Integrity Group Temporal Key (BIGTK) and is used to generate the MIC for the beacon frame. The use of the BIGTK is generally unidirectional: the AP generates the MIC for the beacon frame and the STA checks it.

[0087] The BIGTKSA typically contains a direction vector indicating whether the BIGTK is being used to generate a MIC on the sending side or to check a MIC on the receiving side, the BIGTK, an identifier for identifying the key (Key ID), and the MAC address of the device providing authentication (typically the AP or AP MLD).

[0088] 8. Fast initial link setup authentication (FILS authentication)

[0089] Based on the IEEE 802.11 protocol, in an infrastructure BSS network, STAs and APs can adopt the FILS method for authentication.

[0090] In the shared key authentication method, the STA and a Trusted Third Party (TTP) first establish the same key, rRK (re-authentication Root Key), through Extensible Authentication Protocol (EAP) authentication. After receiving the STA's authentication frame, the AP obtains the rRK from the TTP. The STA and AP then generate a PMKSA and a PTKSA based on the rRK and a random number generated during their interaction. The shared key authentication method can be further divided into two types: without PFS (Perfect Forward Security) and with PFS.

[0091] In the case of using public key authentication, the STA and AP exchange their respective public keys in the authentication frame and check the public key signature, and the STA and AP generate PMKSA and PTKSA based on both public keys and the random numbers of both interactions.

[0092] Here, when the FILS shared key method is adopted, both the STA and the AP interact with the TTP.

[0093] In an alternative embodiment, as shown in FIG. 3, the method includes the following steps:

[0094] Both the STA and the TTP have one rRK from the full EAP authentication.

[0095] Step 201: The STA sends an IEEE 802.11 authentication frame to the AP.

[0096] After receiving the authentication frame, the AP obtains the rRK from the TTP via an interface outside the scope of this standard, for example, the interface may be RADIUS / Diameter.

[0097] Step 202: The AP sends an IEEE 802.11 authentication frame to the STA.

[0098] Step 203: The STA sends an IEEE 802.11 association request to the AP.

[0099] Step 204: The AP sends an IEEE 802.11 association response to the STA.

[0100] Here, when the FILS public key method is adopted, the STA and the AP do not have any interaction with the TTP, and as shown in FIG. 4, the method includes the following steps:

[0101] Step 301: The STA sends an IEEE 802.11 authentication frame to the AP.

[0102] Step 302: The AP sends an IEEE 802.11 authentication frame to the STA.

[0103] Step 303: The STA sends an IEEE 802.11 association request to the AP.

[0104] Step 304: The AP sends an IEEE 802.11 association response to the STA.

[0105] The AP and the STA perform secure data communication.

[0106] 9. FILS shared key without PFS (FILS shared key without perfect forward secrecy)

[0107] When the FILS shared key without PFS authentication method is adopted, the authentication frame of step 201 in FIG. 3 is shown in FIG. 5, and the authentication frame of step 202 in FIG. 3 is shown in FIG.

[0108] In an alternative embodiment, as shown in FIG. 5, the MAC frame header of the authentication frame of step 201 includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT (High-Throughput) Control fields.

[0109] The frame body of the authentication frame includes a Body field.

[0110] The authentication frame further includes an FCS (Frame Check Sequences) field.

[0111] Here, the Body field contains the following fields: Authentication Algonrithm Number = 4, Transaction Sequence Number = 1, Status Code = 0, RSNE, MDE (Mobility Domain element), FILS Nonce, FILS Session, and FILS Wrapped Data. Authentication Algonrithm Number = 4 is used to indicate FILS shared key without PFS.

[0112] Here, the FILS Wrapped Data field includes Element ID, Length, Element ID Extension, and EAP-Initiate / Re-auth Packet.

[0113] In an alternative embodiment, as shown in FIG. 6, the MAC frame header of the authentication frame of step 202 includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT (High-Throughput) Control fields.

[0114] The frame body of the authentication frame includes a Body field.

[0115] The authentication frame further includes an FCS (Frame Check Sequences) field.

[0116] Here, the Body field includes the following fields: Authentication Algonrithm Number=4, Transaction Sequence Number=2, Status Code=0, RSNE, MDE, FILS Nonce, FILS Session, FILS Wrapped Data, and Association Delay Info.

[0117] Here, the FILS Wrapped Data field includes Element ID, Length, Element ID Extension, and EAP-Finish / Re-auth Packet.

[0118] The above EAP-Initiate / Re-auth and EAP-Finish / Re-auth message formats are defined by the RFC 6696 protocol.

[0119] In this case, the PMK is generated as follows.

[0120] rMSK = KDF(rRK, “Re-authentication Master Session Key@ietf.org” || “¥0” || SEQ || length) PMK = HMAC-Hash(SNonce || ANonce, rMSK) PMK ID = Truncate-128(Hash(EAP-Initiate / Reauth)).

[0121] Here, rMSK (re-authentication Master Session Key); Snonce is a random number generated by the STA, and Anonce is a random number generated by the AP.

[0122] In this case, the FILS-Key-Data (equivalent to PTK) is generated as follows:

[0123] FILS-Key-Data = PRF-X(PMK, “FILS PTK Derivation”, SPA || AA || SNonce || ANonce) ICK = L(FILS-Key-Data, 0, ICK_bits) KEK = L(FILS-Key-Data, ICK_bits, KEK_bits) TK = L(FILS-Key-Data, ICK_bits + KEK_bits, TK_bits) FILS-FT = L(FILS-Key-Data, ICK_bits + KEK_bits + TK_bits, FILS-FT_bits) KDK = L(FILS-Key-Data, ICK_bits + KEK_bits + TK_bits + [ FILS-FT_bits ], KDK_bits).

[0124] 10. FILS shared key with PFS (FILS shared key with perfect forward secrecy)

[0125] When the FILS shared key with PFS authentication method is adopted, the authentication frame of step 201 in FIG. 3 is shown in FIG. 7, and the authentication frame of step 202 in FIG. 3 is shown in FIG.

[0126] In an alternative embodiment, as shown in FIG. 7, the MAC frame header of the authentication frame of step 201 includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT (High-Throughput) Control fields.

[0127] The frame body of the authentication frame includes a Body field.

[0128] The authentication frame further includes an FCS (Frame Check Sequences) field.

[0129] Here, the Body field contains the following fields: Authentication Algonrithm Number = 5, Transaction Sequence Number = 1, Status Code = 0, Finite Cyclic Group, FFE field (Finite Field Element field), RSNE, MDE (Mobility Domain element), FILS Nonce, FILS Session, and FILS Wrapped Data. Authentication Algonrithm Number = 5 is used to indicate a FILS shared key with PFS.

[0130] Here, the FFE field contains an encoded ephermeral public key field.

[0131] Here, the FILS Wrapped Data field includes Element ID, Length, Element ID Extension, and EAP-Initiate / Re-auth Packet.

[0132] Note that the term "Element" in FFE refers to an element (a mathematical concept) in a finite domain, not an element in an 802.11 frame. A "field" in an 802.11 frame (e.g., an authentication frame) generally refers to a field with a fixed format, while an "Element" refers to a field with a variable length and format, which has an element ID + length.

[0133] In an alternative embodiment, as shown in FIG. 8, the MAC frame header of the authentication frame of step 202 includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT (High-Throughput) Control fields.

[0134] The frame body of the authentication frame includes a Body field.

[0135] The authentication frame further includes an FCS (Frame Check Sequences) field.

[0136] Here, the Body field includes the following fields: Authentication Algonrithm Number=5, Transaction Sequence Number=2, Status Code=0, Finite Cyclic Group, FFE field, RSNE, MDE, FILS Nonce, FILS Session, FILS Wrapped Data, and Association Delay Info.

[0137] Here, the FFE field contains an encoded ephermeral public key field.

[0138] Here, the FILS Wrapped Data field includes Element ID, Length, Element ID Extension, and EAP-Finish / Re-auth Packet.

[0139] In this case, the PMK is generated as follows.

[0140] rMSK = KDF(rRK, “Re-authentication Master Session Key@ietf.org” || “¥0” || SEQ || length) PMK = HMAC-Hash(SNonce || ANonce, rMSK || DHss) PMKID = Truncate-128(Hash(EAP-Initiate / Reauth)).

[0141] Here, DHss is a shared key generated by the Diffie-Hellman key exchange procedure.

[0142] In this case, the FILS-Key-Data (equivalent to PTK) is generated as follows:

[0143] FILS-Key-Data = PRF-X(PMK, “FILS PTK Derivation”, SPA || AA || SNonce || ANonce || DHss ) ICK = L(FILS-Key-Data, 0, ICK_bits) KEK = L(FILS-Key-Data, ICK_bits, KEK_bits) TK = L(FILS-Key-Data, ICK_bits + KEK_bits, TK_bits) FILS-FT = L(FILS-Key-Data, ICK_bits + KEK_bits + TK_bits, FILS-FT_bits) KDK = L(FILS-Key-Data, ICK_bits + KEK_bits + TK_bits + [ FILS-FT_bits ], KDK_bits).

[0144] 11. FILS public key

[0145] When the FILS public key authentication method is adopted, the authentication frame of step 301 in FIG. 4 is shown in FIG. 9, and the authentication frame of step 302 in FIG. 4 is shown in FIG.

[0146] In an alternative embodiment, as shown in FIG. 9, the MAC frame header of the authentication frame of step 301 includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT (High-Throughput) Control fields.

[0147] The frame body of the authentication frame includes a Body field.

[0148] The authentication frame further includes an FCS (Frame Check Sequences) field.

[0149] Here, the Body field contains the following fields: Authentication Algonrithm Number = 6, Transaction Sequence Number = 1, Status Code = 0, Finite Cyclic Group, FFE field, RSNE, MDE, FILS Nonce, and FILS Session. The Authentication Algonrithm Number = 6 is used to indicate the FILS public key.

[0150] Here, the FFE field contains an encoded ephermeral public key field.

[0151] In an alternative embodiment, as shown in FIG. 10, the MAC frame header of the authentication frame of step 302 includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT (High-Throughput) Control fields.

[0152] The frame body of the authentication frame includes a Body field.

[0153] The authentication frame further includes an FCS (Frame Check Sequences) field.

[0154] Here, the Body field includes the following fields: Authentication Algonrithm Number = 6, Transaction Sequence Number = 2, Status Code = 0, Finite Cyclic Group, FFE field, RSNE, MDE, FILS Nonce, and FILS Session.

[0155] Here, the FFE field contains an encoded ephermeral public key field.

[0156] In this case, the PMK is generated as follows.

[0157] PMK = HMAC-Hash(SNonce || ANonce, DHss) PMKID = Truncate-128(Hash(gSTA || gAP)).

[0158] Here, gSTA is the Diffie-Hellman value of the STA, gAP is the Diffie-Hellman value of the AP, and DHss is the shared key generated by the Diffie-Hellman key exchange procedure.

[0159] In this case, the FILS-Key-Data (equivalent to PTK) is generated as follows:

[0160] FILS-Key-Data = PRF-X(PMK, “FILS PTK Derivation”, SPA || AA || SNonce || ANonce || DHss ) ICK = L(FILS-Key-Data, 0, ICK_bits) KEK = L(FILS-Key-Data, ICK_bits, KEK_bits) TK = L(FILS-Key-Data, ICK_bits + KEK_bits, TK_bits) FILS-FT = L(FILS-Key-Data, ICK_bits + KEK_bits + TK_bits, FILS-FT_bits) KDK = L(FILS-Key-Data, ICK_bits + KEK_bits + TK_bits + [ FILS-FT_bits ], KDK_bits).

[0161] 12. 802.1X Authentication

[0162] In an infrastructure BSS network based on the IEEE 802.11 protocol, STAs and APs can use the 802.1X authentication method for authentication. The station and the 802.1X authentication server (AS) establish a common PMK through Extensible Authentication Protocol (EAP) authentication. During this authentication procedure, the AS transmits the established PMK to the AP via another protocol.

[0163] In an alternative embodiment, as shown in FIG. 11, performing authentication using the 802.1X authentication procedure includes the following steps:

[0164] Step 401: The STA sends an IEEE Std 802.11 probe request to the AP.

[0165] Step 402: The AP sends an IEEE Std 802.11 probe response to the STA, which carries security parameters.

[0166] Step 403: The STA sends an IEEE Std 802.11 open system authentication request to the AP.

[0167] Step 404: The AP sends an IEEE Std 802.11 open system authentication response to the STA.

[0168] Step 405: The STA sends an IEEE Std 802.11 association request to the AP, and the association request carries security parameters.

[0169] Step 406: The AP sends an IEEE Std 802.11 association response to the STA.

[0170] Step 407: The AP sends an IEEE Std 802.11 EAP Request to the STA.

[0171] Step 408: The STA sends an IEEE Std 802.11 EAP Response to the AP.

[0172] Step 409: The AP sends a success request / EAP request to the AS.

[0173] Step 410: The AS and the STA perform an EAP authentication control exchange.

[0174] Step 411: The AS sends an Accept / EAP Success / Keying Material message to the AP.

[0175] Step 412: The AP sends an IEEE Std 802.11 EAP Success to the STA.

[0176] The STA and AP perform a four-way handshake procedure.

[0177] Here, the EAP Request / Response / Success message formats are defined by the 802.1X-2020 protocol and the RFC 3748 protocol, and are carried in the frame body of an IEEE 802.11 data frame for transmission.

[0178] As an option, before the AP sends the EAP Request message to the STA, the STA can send an EAPOL-START message to the AP. The EAPOL-START message format is specified by the 802.1X-2020 protocol, and the EAPOL-START message is carried in the frame body of an IEEE 802.11 data frame and transmitted. The EAPOL-START message includes the Protocol Version, Packet Type() data pack type = EAPOL-Start, and Packet Body Length fields.

[0179] If the Protocol Version field value is 2 or less, the message body length of the message is 0.

[0180] If the Protocol Version field value is 3 or greater, the message body contains authentication information related to authorization and authentication strategies.

[0181] 13. 4-way handshake

[0182] Based on the IEEE 802.11 protocol, in an infrastructure BSS network, after an association between a STA and an AP is established, the AP (authenticator) initiates a 4-way handshake procedure to establish a PTKSA, GTKSA, IGTKSA, and BIGTKSA with the STA (supplicant). For details, please refer to IEEE 802.11-2020.

[0183] In an alternative embodiment, as shown in FIG. 12, the four-way handshake procedure includes the following steps:

[0184] After the association between the requestor and the authenticator is established, the requestor and the authenticator each have a PMK. The requestor generated an Snonce, and the authenticator generated an Anonce.

[0185] Step 501: The authenticator sends a message 1 to the requester.

[0186] The authenticator sends an EAPOL-Key frame carrying the Anonce and Individual to the requestor.

[0187] The requestor generates a device PTK (Derive PTK).

[0188] Step 502: The requester sends a message 2 to the authenticator.

[0189] The requestor sends an EAPOL-Key frame to the authenticator, which carries an SNonce, an Individual, and a MIC.

[0190] The authenticator generates a device PTK (Derive PTK), and if necessary, a GTK, IGTK, or BIGTSK.

[0191] Step 503: The authenticator sends a message 3 to the requester.

[0192] The authenticator sends an EAPOL-Key frame to the requestor, which contains the Install PTK, Individual, MIC, Wrapped GTK, Wrapped IGTK, and Wrapped BIGTK.

[0193] Step 504: The requestor sends Message 4 to the authenticator.

[0194] The requestor sends an EAPOL-Key frame carrying an Individual and a MIC to the authenticator.

[0195] The requestor and authenticator establish the PTK, GTK, IGTK, and BIGTK, respectively.

[0196] 14. Group Key Handshake

[0197] In an infrastructure BSS network based on the IEEE 802.11 protocol, after an association between a STA and an AP is established, if, for example, the GTKSA and / or IGTKSA and / or BIGTKSA needs to be changed, the AP, which is the authenticator, initiates a group key handshake procedure to establish new GTKSA and / or IGTKSA and / or BIGTKSA with the STA, which is the supplicant. Specifically, see IEEE 802.11-2020.

[0198] In an alternative embodiment, as shown in FIG. 13, the group key handshake procedure includes the following steps:

[0199] The authenticator generates a GTK, IGTK, or BIGTK and wraps the GTK, IGTK, or BIGTK with a KEK.

[0200] Step 601: The authenticator sends a message 1 to the requester.

[0201] The authenticator sends an EAPOL-Key frame to the requestor, which contains a Wrapped GTK, a Wrapped IGTK, a Wrapped BIGTK, and a MIC.

[0202] The requestor establishes the GTK, IGTK, and BIGTK.

[0203] Step 602: The requestor sends a message 2 to the authenticator.

[0204] The requesting party sends an EAPOL-Key frame containing the Group and MIC to the authenticating party.

[0205] 15. SAE Certification (Simultaneous Authentication of Equals)

[0206] Based on the IEEE 802.11 protocol, in an infrastructure BSS network, the TA and AP can perform authentication using the SAE procedure. In this procedure, the device requesting authentication (typically the non-AP or non-AP MLD) and the device providing authentication (typically the AP or AP MLD) have the same network key (password), complete the authentication through four authentication message exchanges, and form a PMKSA based on the password.

[0207] In the SAE authentication method, the PTK that encrypts / decrypts unicast data frames and management frames is generally generated after the 4-way handshake, so frames before the 4-way handshake cannot be protected.

[0208] 14 is a flowchart of an authentication method provided in an exemplary embodiment of the present application. The method can be performed by a STA, and includes the following steps:

[0209] Step 210: An authentication procedure is performed by transmitting an authentication frame between the AP, and a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method among an extended PASN supporting FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0210] An authentication frame is a message transmitted between an STA and an AP during an authentication procedure. Exemplarily, the authentication frame includes at least one of a first authentication frame, a second authentication frame, a third authentication frame, and a fourth authentication frame.

[0211] As an alternative, the first field is present in at least one of the first authentication frame, the second authentication frame, the third authentication frame, and the fourth authentication frame. In one alternative embodiment, the first field is present in the first authentication frame and the second authentication frame. In another alternative embodiment, the first field is present in the first authentication frame, the second authentication frame, the third authentication frame, and the fourth authentication frame.

[0212] As an option, the authentication procedure includes a total of three authentication frames, for example, the STA probes the Beacon frame transmitted by the accessible AP, then transmits a first authentication frame to the AP, after which the AP transmits a second authentication frame to the STA, and the STA transmits a third authentication frame to the AP to complete the authentication procedure.

[0213] As an option, the authentication procedure includes a total of four authentication frames, for example, after the STA probes the Beacon frame transmitted by the accessible AP, it transmits a first authentication frame to the AP, after which the AP transmits a second authentication frame to the STA, the STA transmits a third authentication frame to the AP, and the AP transmits a fourth authentication frame to the STA to complete the authentication procedure.

[0214] Illustratively, an extended PASN supporting FILS shared key authentication with perfect forward secrecy and an extended PASN supporting FILS public key authentication have three authentication frames.

[0215] Illustratively, an extended PASN supporting 802.1X authentication has four authentication frames.

[0216] The different possible values of the first field correspond to an extended PASN supporting FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication, respectively.

[0217] By reading the possible values of the first field, the AP or STA can know that the authentication method adopted in the authentication procedure is an extended PASN supporting FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, or an extended PASN supporting 802.1X authentication. In this way, the AP and STA can adopt one of the three authentication methods to perform the authentication procedure and complete the identity authentication for the STA.

[0218] As described above, the method provided in this embodiment adds possible values to the first field of the authentication frame to indicate the adoption of an authentication method, such as an extended PASN supporting FILS (Fast Initial Link Setup) shared key authentication with PFS (Perfect Forward Security), an extended PASN supporting FILS public key authentication, or an extended PASN supporting 802.1X authentication. We have clarified how to extend PASN to support the above authentication methods.

[0219] 15 is a flowchart of an authentication method provided in an exemplary embodiment of the present application. The method can be performed by an AP, and includes the following steps:

[0220] Step 220: An authentication procedure is performed by transmitting an authentication frame between the STA, and a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method among an extended PASN supporting FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0221] As an option, the first field may be an identity authentication algorithm number field and a wrapped data format field in an authentication frame.

[0222] Here, the identity authentication algorithm number field is used to indicate a PASN or an extended PASN, and the wrapped data format field is used to indicate a specific authentication method, i.e., the specific authentication method is one of an extended PASN supporting FILS shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0223] As described above, the method provided in this embodiment indicates the adoption of an authentication method, such as an extended PASN supporting FILS (Fast Initial Link Setup) shared key with PFS (Perfect Forward Security), an extended PASN supporting FILS public key authentication, or an extended PASN supporting 802.1X authentication, by adding a possible value to the first field in the authentication frame. We have clarified how to extend PASN to support the above authentication methods.

[0224] Three authentication methods are provided in the present embodiment:

[0225] 1. Extended PASN supporting FILS shared key authentication with perfect forward secrecy; 2. Extended PASN to support FILS public key authentication; 3, Extended PASN to support 802.1X authentication.

[0226] Below, we will explain each of the three authentication methods.

[0227] 1. Extended PASN supporting FILS shared key authentication with perfect forward secrecy

[0228] For illustrative purposes, two possible value schemes for the first field are shown, such that the first field indicates an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

[0229] First type of possible value scheme: The identity authentication algorithm number field is 7 and the wrapped data format field is the first newly created value, which is used to indicate that the authentication scheme employed is an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

[0230] Here, the first newly set value may be any one of 4 to 255. 1 to 3 are the possible values already used by the wrap data format field, and 4 to 255 is the currently reserved value of the wrap data format field. For example, the first newly set value is 4.

[0231] The Authentication Algorithm Number field in the authentication frame of this embodiment can adopt the value 7 (7 represents PASN authentication), and both authenticators (the authenticator and the authenticatee) identify that the adopted method is extended PASN, which supports FILS shared key authentication with perfect forward secrecy, by the newly created value 4 (4 to 255 are currently reserved values) in the Wrapped Data Format field.

[0232] For example, the identity authentication algorithm number field being 7 is used to indicate that the identity authentication algorithm of PASN is used, and the wrap data format field being the first newly created value is used to indicate that the authentication method is extended PASN supporting FILS shared key authentication with perfect forward secrecy.

[0233] The second type of possible value scheme: The identity authentication algorithm number field having the second newly created value and the wrapped data format field having the first newly created value is used to indicate that the authentication scheme employed is an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

[0234] Here, the second newly set value may be any one of 8 to 65534. 1 to 7 are the possible values already used by the identity authentication algorithm number field, and 8 to 65534 is the currently reserved value of the identity authentication algorithm number. For example, the second newly set value is 8.

[0235] The Authentication Algorithm Number field in the authentication frame of this embodiment can also adopt a new value of 8 (representing Extended PASN authentication, i.e., extended PASN, 8-65534 is the currently reserved value), and both authenticators (the authenticator and the authenticatee) identify the adopted method as extended PASN, which supports FILS shared key authentication with perfect forward secrecy, by a new value of 4 (4-255 is the currently reserved value) in the Wrapped Data Format field.

[0236] For example, the identity authentication algorithm number field having the second newly created value is used to indicate that an identity authentication algorithm of an extended PASN is used, and the wrapped data format field having the first newly created value is used to indicate that the authentication method is an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

[0237] For illustrative purposes, one specific flow using an extended PASN that supports FILS shared key authentication with perfect forward secrecy is shown.

[0238] 16 is a flowchart of an authentication method provided in an exemplary embodiment of the present application. The method can be performed by a STA and an AP, and includes the following steps:

[0239] Step 701: The AP periodically transmits a beacon frame.

[0240] Step 702: The STA sends a first authentication frame to the AP.

[0241] Step 703: The AP sends a second authentication frame to the STA.

[0242] Alternatively, after the STA receives the second authentication frame, the STA generates a PMK and a PTK.

[0243] Step 704: The STA sends a third authentication frame to the AP.

[0244] Alternatively, after the AP receives the third authentication frame, the AP generates a PMK and a PTK.

[0245] In an alternative embodiment, the authentication frame includes at least one of the following fields added: PMK public key, PMK public key length, PMK finite cyclic group, PMK group and key present.

[0246] First type authentication frame format:

[0247] As shown in FIG. 17, the MAC frame header of the first authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control (high throughput control) fields.

[0248] The frame body of the first authentication frame includes a body field.

[0249] The first authentication frame further includes an FCS (Frame Check Sequences) field.

[0250] Here, the Body field of the first authentication frame includes: Authentication Algonrithm Number=7, Transaction Sequence Number=1, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data element, and PASN Parameters element. As an option, the Authentication Algonrithm Number can be equal to 8.

[0251] The Wrapped Data element field of the first authentication frame includes Element ID, Length, Element ID Extension, and EAP-Initiate / Re-auth Packet fields.

[0252] The PASN Parameters element field of the first authentication frame includes Element ID, Length, Element ID Extension, Control, Wrapped Data Format=4, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, Ephemeral Public Key (=FILS SNonce), PMK Finite Cyclic Group, PMK public key length, and PMK public key.

[0253] The Control field of the first authentication frame includes come back info Present (return information valid bit), Group and Key Present (group and key valid bit), PMK Group and Key Present (PMK group and key valid bit), and Reserved.

[0254] As shown in FIG. 18, the MAC frame header of the second authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control (high throughput control) fields.

[0255] The frame body of the second authentication frame includes a Body field.

[0256] The second authentication frame further includes a MIC and an FCS (Frame Check Sequences code) field.

[0257] Here, the Body field of the second authentication frame includes: Authentication Algonrithm Number=7, Transaction Sequence Number=2, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data element, and PASN Parameters element. As an option, the Authentication Algonrithm Number can be equal to 8.

[0258] The Wrapped Data element field of the second authentication frame includes Element ID, Length, Element ID Extension, and EAP-Finish / Re-auth Packet fields.

[0259] The PASN Parameters element field of the second authentication frame contains Element ID, Length, Element ID Extension, Control, Wrapped Data Format=4, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, Ephemeral Public Key (=FILS ANonce), PMK Finite Cyclic Group, PMK public key length, and PMK public key.

[0260] The Control field of the second authentication frame includes come back info Present (return information valid bit), Group and Key Present (group and key valid bit), PMK Group and Key Present (PMK group and key valid bit), and Reserved.

[0261] As shown in FIG. 19, the MAC frame header of the third authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control (high throughput control) fields.

[0262] The frame body of the third authentication frame includes a Body field.

[0263] The third authentication frame further includes a MIC and an FCS (Frame Check Sequences code) field.

[0264] Here, the Body field of the third authentication frame includes: Authentication Algonrithm Number=7, Transaction Sequence Number=3, Status Code=0, and PASN Parameters element. As an option, the Authentication Algonrithm Number can be equal to 8.

[0265] The PASN Parameters element field of the third authentication frame includes Element ID, Length, Element ID Extension, Control, and Wrapped Data Format=0.

[0266] In another alternative embodiment, no fields are added to the authentication frame.

[0267] Second type of authentication frame format:

[0268] As shown in FIG. 20, the MAC frame header of the first authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0269] The Frame Body of the first authentication frame includes a Body field.

[0270] The first authentication frame further includes an FCS field.

[0271] Here, the Body field of the first authentication frame includes the following elements: Authentication Algorithm Number=7, Transaction Sequence Number=1, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data, and PASN Parameters. Alternatively, the Authentication Algorithm Number can be equal to 8.

[0272] The Wrapped Data field of the first authentication frame includes Element ID, Length, Element ID Extension, and EAP-Initiate / Re-auth Packet fields.

[0273] The PASN Parameters element field of the first authentication frame includes Element ID, Length, Element ID Extension, Control, Wrapped Data Format=4, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, and Ephemeral Public Key (=FILS SNonce).

[0274] As shown in FIG. 21, the MAC frame header of the second authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0275] The Frame Body of the second authentication frame includes a Body field.

[0276] The second authentication frame further includes a MIC and an FCS field.

[0277] Here, the Body field of the second authentication frame includes the following elements: Authentication Algorithm Number=7, Transaction Sequence Number=2, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data, and PASN Parameters. Alternatively, the Authentication Algorithm Number can be equal to 8.

[0278] The Wrapped Data field of the second authentication frame includes Element ID, Length, Element ID Extension, and EAP-Finish / Re-auth Packet fields.

[0279] The PASN Parameters element field of the second authentication frame includes Element ID, Length, Element ID Extension, Control, Wrapped Data Format = 4, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, and Ephemeral Public Key (= FILS ANonce).

[0280] As shown in FIG. 22, the MAC frame header of the third authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0281] The Frame Body of the third authentication frame includes a Body field.

[0282] The third authentication frame further includes a MIC and an FCS field.

[0283] Here, the Body field of the third authentication frame includes: Authentication Algonrithm Number=7, Transaction Sequence Number=3, Status Code=0, and PASN Parameters element. Alternatively, the Authentication Algonrithm Number can be equal to 8.

[0284] The PASN Parameters element field of the third authentication frame includes Element ID, Length, Element ID Extension, Control, and Wrapped Data Format=0.

[0285] It should be noted that the frame format schematic diagram in this embodiment of the present application is only used to explain the fields included in the authentication frame, and is not used to restrict the arrangement order of each field in the authentication frame.

[0286] Regarding the first type of authentication frame format, First type PMK and PTK generation method are provided:

[0287] (1) PMK generation:

[0288] The AP and / or STA generates a first PMK based on a first DHss (shared key), where the first DHss is a shared key generated based on the STA's PMK public key and the AP's PMK public key.

[0289] rMSK=KDF(rRK, “Re-authentication Master Session Key@ietf.org” || “¥0” || SEQ || length ) PMK=HMAC-Hash(SNonce || ANonce, rMSK || DHss) PMKID = Truncate-128(Hash(EAP-Initiate / Reauth ))

[0290] Here, HMAC is a hash-based message authentication code, SNonce is a random number generated by the STA, and ANonce is a random number generated by the AP. SNonce (also called FILS SNonce) is replaced with the public key (S-Ephemeral Pub) of the authenticatee, and ANonce (also called FILS ANonce) is replaced with the public key (A-Ephemeral Pub) of the authenticator. DHss is a shared key generated by the Diffie-Hellman (key exchange) procedure based on the newly established PMK public keys of both parties (PMK public key field in Figures 17 and 18).

[0291] (2) PTK generation:

[0292] The AP and / or STA generates a first pairwise temporary key PTK based on the first PMK and the second DHss, where the second DHss is a shared key generated based on the public key of the STA's authenticatee and the public key of the AP's authenticator.

[0293] PTK=KDF-HASH-NNN (PMK, “PASN PTK Derivation”, SPA || BSSID || DHss)

[0294] Here, DHss is a shared key generated based on the public key of the prover (S-Ephemeral Pub) and the public key of the authenticator (A-Ephemeral Pub) through the Diffie-Hellman procedure. The Diffie-Hellman procedure is included in the authentication frame interaction procedure, that is, in the authentication frame interaction procedure, the AP and the STA exchange A-Ephemeral Pub and S-Ephemeral Pub.

[0295] In the FILS shared key authentication extended PASN with perfect forward secrecy, the public key of the prover (S-Ephemeral Pub) and the public key of the authenticator (A-Ephemeral Pub) are public keys independently generated by the same or similar mechanisms as those of the PMK public key of the STA and the PMK public key of the AP. Illustratively, the public key of the prover (S-Ephemeral Pub) and the public key of the authenticator (A-Ephemeral Pub) are not signed by a certificate issuing authority.

[0296] Regarding the second type of authentication frame format, Second type of PMK and PTK generation method are provided:

[0297] (1) PMK generation:

[0298] The AP and / or STA generates a second PMK based on the third DHss;

[0299] Here, the third DHss is a shared key generated based on the public key of the STA to be authenticated and the public key of the AP to be authenticated.

[0300] rMSK=KDF(rRK, “Re-authentication Master Session Key@ietf.org” || “¥0” || SEQ || length) PMK = HMAC-Hash(SNonce || ANonce, rMSK || DHss) PMKID = Truncate-128(Hash(EAP-Initiate / Reauth))

[0301] Here, SNonce (also called FILS SNonce) is replaced with the prover's public key (S-Ephemeral Pub), and ANonce (also called FILS ANonce) is replaced with the authenticator's public key (A-Ephemeral Pub). DHss is a shared key generated by the Diffie-Hellman procedure based on the prover's public key (S-Ephemeral Pub) and the authenticator's public key (A-Ephemeral Pub).

[0302] (2) PTK generation:

[0303] A second PTK is generated based on the second PMK and the third DHss.

[0304] PTK=KDF-HASH-NNN(PMK, “PASN PTK Derivation”, SPA || BSSID || DHss)

[0305] Here, DHss is a shared key generated based on the public key of the prover (S-Ephemeral Pub) and the public key of the authenticator (A-Ephemeral Pub) by the Diffie-Hellman procedure.

[0306] As described above, the method provided in this embodiment clarifies the specific flow and message format of how to extend PASN to support the FILS shared key authentication method with perfect forward secrecy (FILS shared key with PFS), and also shows the method of generating PMK and PTK.

[0307] 2. Extended PASN supporting FILS public key authentication

[0308] For illustrative purposes, two possible value schemes for the first field are shown, so that the first field indicates an extended PASN that supports FILS public key authentication.

[0309] Third type of possible value scheme: The identity authentication algorithm number field is 7 and the wrapped data format field is the third newly created value, which is used to indicate that the authentication scheme employed is an extended PASN that supports FILS public key authentication.

[0310] Here, the third newly added value may be any one of 4 to 255. 1 to 3 are the values already used by the wrap data format field, and 4 to 255 is the currently reserved value of the wrap data format field. For example, the third newly added value is 5.

[0311] In this embodiment, the Authentication Algorithm Number field in the authentication frame can adopt the value 7 (7 represents PASN authentication), and both the authenticator and the authenticatee identify that the adopted method is extended PASN, which supports FILS public key authentication, by creating a new value of 5 (4-255 is an existing reserved value) in the Wrapped Data Format field.

[0312] For example, the identity authentication algorithm number field is set to 7 to indicate that the PASN identity authentication algorithm is used. The wrap data format field is set to the third newly created value to indicate that the authentication method is an extended PASN that supports FILS public key authentication.

[0313] Fourth type of possible value scheme: The identity authentication algorithm number field has the newly created value 4 and the wrapped data format field has the newly created value 3, which is used to indicate that the authentication scheme employed is an extended PASN that supports FILS public key authentication.

[0314] Here, the fourth newly added value may be any one of 8 to 65534. 1 to 7 are the possible values already occupied by the identity authentication algorithm number field, and 8 to 65534 are the currently reserved values of the identity authentication algorithm number. For example, the fourth newly added value is 8.

[0315] In this embodiment, the Authentication Algorithm Number field in the authentication frame can also adopt a new value of 8 (8 represents Extended PASN authentication, and 8-65534 is the currently reserved value), and both sides of the authentication (the authenticator and the authenticatee) identify that the adopted method is Extended PASN for FILS public key authentication by a new value of 5 (4-255 is the existing reserved value) in the Wrapped Data Format field.

[0316] For example, the fourth newly created value of the identity authentication algorithm number field is used to indicate that an extended PASN identity authentication algorithm is used, and the third newly created value of the wrapped data format field is used to indicate that the authentication method is an extended PASN that supports FILS public key authentication.

[0317] For illustrative purposes, one specific flow using an extended PASN that supports FILS public key authentication is shown.

[0318] 23 is a flowchart of an authentication method provided in an exemplary embodiment of the present application. The method can be performed by a STA and an AP, and includes the following steps:

[0319] Step 801: The AP periodically transmits a beacon frame.

[0320] Step 802: The STA sends a first authentication frame to the AP.

[0321] Step 803: The AP sends a second authentication frame to the STA.

[0322] Alternatively, after the STA receives the second authentication frame, the STA generates a PMK and a PTK.

[0323] Step 804: The STA transmits a third authentication frame to the AP.

[0324] Alternatively, after the AP receives the third authentication frame, the AP generates a PMK and a PTK.

[0325] In an alternative embodiment, the authentication frame includes at least one of the following fields added: PMK public key, PMK public key length, PMK finite cyclic group, PMK group and key present.

[0326] Third type of authentication frame format: At least one field of the PMK public key, PMK public key length, and PMK finite cyclic group is carried in the wrap data element field of the authentication frame.

[0327] As shown in FIG. 24, the MAC frame header of the first authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0328] The Frame Body of the first authentication frame includes a Body field.

[0329] The first authentication frame further includes an FCS field.

[0330] Here, the Body field of the first authentication frame includes: Authentication Algorithm Number=7, Transaction Sequence Number=1, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data element, and PASN Parameters element. As an option, the Authentication Algorithm Number can be equal to 8.

[0331] The Wrapped Data element field of the first authentication frame includes Element ID, Length, Element ID Extension, PMK Finite Cyclic Group, PMK public key length, and PMK public key fields.

[0332] The PASN Parameters element field of the first authentication frame includes Element ID, Length, Element ID Extension, Control, Wrapped Data Format = 5, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, and Ephemeral Public Key (= FILS SNonce) fields.

[0333] The Control field of the first authentication frame includes come back info present (return information valid bit), group and key present (group and key valid bit), and reserved.

[0334] As shown in FIG. 25, the MAC frame header of the second authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0335] The Frame Body of the second authentication frame includes a Body field.

[0336] The second authentication frame further includes a MIC and an FCS field.

[0337] Here, the Body field of the second authentication frame includes: Authentication Algorithm Number=7, Transaction Sequence Number=2, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data element, and PASN Parameters element. As an option, the Authentication Algorithm Number can be equal to 8.

[0338] The Wrapped Data element field of the second authentication frame includes the Element ID, Length, Element ID Extension, PMK Finite Cyclic Group, PMK public key length, and PMK public key fields.

[0339] The PASN Parameters element field of the second authentication frame includes Element ID, Length, Element ID Extension, Control, Wrapped Data Format = 5, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, and Ephemeral Public Key (= FILS ANonce) fields.

[0340] The Control field of the second authentication frame includes come back info present (return information valid bit), group and key present (group and key valid bit), and reserved.

[0341] As shown in FIG. 26, the MAC frame header of the third authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0342] The Frame Body of the third authentication frame includes a Body field.

[0343] The third authentication frame further includes a MIC and an FCS field.

[0344] Here, the Body field of the third authentication frame includes: Authentication Algonrithm Number=7, Transaction Sequence Number=3, Status Code=0, and PASN Parameters element. Alternatively, the Authentication Algonrithm Number can be equal to 8.

[0345] The PASN Parameters element field of the second authentication frame includes Element ID, Length, Element ID Extension, Control, and Wrapped Data Format=0.

[0346] Fourth type of authentication frame format: At least one field of the PMK public key, PMK public key length, and PMK finite cyclic group is carried in the wrap data element field of the authentication frame, and the PMK finite cyclic group field is carried in the control field of the authentication frame.

[0347] As shown in FIG. 27, the MAC frame header of the first authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0348] The Frame Body of the first authentication frame includes a Body field.

[0349] The first authentication frame further includes an FCS field.

[0350] Here, the Body field of the first authentication frame includes: Authentication Algorithm Number=7, Transaction Sequence Number=1, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, and PASN Parameters element. As an option, the Authentication Algorithm Number can be equal to 8.

[0351] The PASN Parameters element field of the first authentication frame includes the following fields: Element ID, Length, Element ID Extension, Control, Wrapped Data Format = 5, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, Ephemeral Public Key (= FILS SNonce), PMK Finite Cyclic Group, PMK public key length, and PMK public key.

[0352] The Control field of the first authentication frame includes come back info, Group and Key Present (Group and Key valid bit), PMK Group and Key Present (PMK Group and Key valid bit), and Reserved.

[0353] As shown in FIG. 28, the MAC frame header of the second authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0354] The Frame Body of the second authentication frame includes a Body field.

[0355] The second authentication frame further includes a MIC and an FCS field.

[0356] Here, the Body field of the second authentication frame includes: Authentication Algorithm Number=7, Transaction Sequence Number=2, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, and PASN Parameters element. As an option, the Authentication Algorithm Number can be equal to 8.

[0357] The PASN Parameters element field of the second authentication frame includes the following fields: Element ID, Length, Element ID Extension, Control, Wrapped Data Format = 5, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, Ephemeral Public Key (= FILS ANonce), PMK Finite Cyclic Group, PMK public key length, and PMK public key.

[0358] The Control field of the second authentication frame includes come back info, Group and Key Present (Group and Key valid bit), PMK Group and Key Present (PMK Group and Key valid bit), and Reserved.

[0359] As shown in FIG. 29, the MAC frame header of the third authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0360] The Frame Body of the third authentication frame includes a Body field.

[0361] The third authentication frame further includes a MIC and an FCS field.

[0362] Here, the Body field of the third authentication frame includes: Authentication Algonrithm Number=7, Transaction Sequence Number=3, Status Code=0, and PASN Parameters element. Alternatively, the Authentication Algonrithm Number can be equal to 8.

[0363] The PASN Parameters element field of the second authentication frame includes Element ID, Length, Element ID Extension, Control, and Wrapped Data Format=0.

[0364] It should be noted that the frame format schematic diagram in this embodiment of the present application is only used to explain the fields included in the authentication frame, and is not used to restrict the arrangement order of each field in the authentication frame.

[0365] Regarding the above third and fourth authentication frame formats, Third type PMK and PTK generation method are provided:

[0366] (1) PMK generation:

[0367] The AP and / or STA generates a third PMK based on the fourth DHss, where the fourth DHss is a shared key generated based on the STA's PMK public key and the AP's PMK public key.

[0368] PMK=HMAC-Hash(SNonce || ANonce, DHss) PMKID=Truncate-128(Hash(gSTA || gAP))

[0369] Here, gSTA is the STA's Diffie-Hellman (key exchange) value, and gAP is the AP's Diffie-Hellman value. SNonce (also called FILS SNonce) is replaced with the prover's public key (S-Ephemeral Pub), and ANonce (also called FILS ANonce) is replaced with the authenticator's public key (A-Ephemeral Pub). DHss is a shared key generated by the Diffie-Hellman procedure based on both parties' newly established PMK public keys (the PMK public key fields in Figures 24 and 25, or Figures 27 and 28).

[0370] In an extended PASN that supports FILS public key authentication, the public key of the prover (S-Ephemeral Pub) and the public key of the certifier (A-Ephemeral Pub) are either pre-installed internally or pre-obtained out-of-band. Generally, the public keys here are signed by a Certificate Authority (CA).

[0371] (2) PTK generation:

[0372] The AP and / or STA generates a third PTK based on the third PMK and the fifth DHss, where the fifth DHss is a shared key generated based on the public key of the STA's authenticatee and the public key of the AP's authenticator.

[0373] PTK=KDF-HASH-NNN(PMK, “PASN PTK Derivation”, SPA || BSSID || DHss)

[0374] DHss is a shared key generated based on the public key of the prover (S-Ephemeral Pub) and the public key of the authenticator (A-Ephemeral Pub) by the Diffie-Hellman procedure.

[0375] As described above, the method provided in this embodiment clarifies the specific flow and message format of how to extend PASN to support the FILS public key authentication method, and also shows the method of generating PMK and PTK.

[0376] 3. Extended PASN supporting 802.1X authentication

[0377] For illustrative purposes, two possible value schemes for the first field are shown, so that the first field indicates an extended PASN that supports 802.1X authentication.

[0378] Fifth Possible Value Scheme: The Identity Authentication Algorithm Number field is 7 and the Wrapped Data Format field is the fifth newly created value, which is used to indicate that the authentication scheme employed is an extended PASN that supports 802.1X authentication.

[0379] Here, the fifth newly added value may be any one of 4 to 255. 1 to 3 are the values already used by the wrap data format field, and 4 to 255 is the currently reserved value of the wrap data format field. For example, the third newly added value is 6.

[0380] In this embodiment, the Authentication Algorithm Number field in the authentication frame can adopt the value 7 (7 represents PASN authentication), and both the authenticator and the authenticated party identify the adopted method as the extended PASN of the 802.1X authentication method by the newly created value 6 (4-255 is the currently reserved value) in the Wrapped Data Format field.

[0381] For example, the identity authentication algorithm number field is set to 7 to indicate that the PASN identity authentication algorithm is used. The wrap data format field is set to the newly created value 5 to indicate that the authentication method is an extended PASN that supports 802.1X authentication.

[0382] Sixth type of possible value scheme: The newly created value 6 in the identity authentication algorithm number field and the newly created value 5 in the wrapped data format field are used and adopted to indicate that the authentication scheme is an extended PASN that supports 802.1X authentication.

[0383] Here, the sixth newly added value may be any one of 8 to 65534. 1 to 7 are the possible values already occupied by the identity authentication algorithm number field, and 8 to 65534 are the currently reserved values of the identity authentication algorithm number. For example, the sixth newly added value is 8.

[0384] In this embodiment, the Authentication Algorithm Number field in the authentication frame can also adopt a new value of 8 (representing Extended PASN authentication, where 8-65534 is the currently reserved value), and both authentication parties (the authenticator and the authenticated party) identify that the adopted method is Extended PASN of the 802.1X authentication method by a new value of 6 (4-255 is the currently reserved value) in the Wrapped Data Format field.

[0385] For example, the newly defined value 6 in the identity authentication algorithm number field is used to indicate that an extended PASN identity authentication algorithm is used, and the newly defined value 5 in the wrap data format field is used to indicate that the authentication method is an extended PASN that supports 802.1X authentication.

[0386] For illustrative purposes, one specific flow using an extended PASN that supports 802.1X authentication is shown.

[0387] 30 is a flowchart of an authentication method provided in an exemplary embodiment of the present application. The method can be performed by a STA and an AP, and includes the following steps:

[0388] Step 901: The AP periodically transmits a Beacon frame.

[0389] The Beacon frame includes fields such as RSNE, Extended PASN AKM, Base AKM, and RSNXE.

[0390] Step 902: The STA sends a first authentication frame to the AP.

[0391] The first authentication frame includes fields such as Transaction Sequence Number which is 1 (used to indicate Authentication 1), Extended PASN, RSNE, PASN AKM, PMK ID, RSNXE, S-Ephemeral Pub (the public key of the authenticatee, i.e., the public key of the STA), PASN Parameters, and Base AKM Data-1.

[0392] Step 903: The AP sends a second authentication frame to the STA.

[0393] The second authentication frame includes fields such as Transaction Sequence Number (2) (used to indicate Authentication 2), Extended PASN, RSNE, PASN AKM, PMK ID, RSNXE, A-Ephemeral Pub (the authenticator's public key, i.e., the AP's public key), PASN Parameters, Base AKM Data-2, and MIC.

[0394] Alternatively, after the STA receives the second authentication frame, the STA generates a PMK and a PTK.

[0395] Step 904: The STA sends a third authentication frame to the AP.

[0396] The third authentication frame includes fields such as a Transaction Sequence Number of 3 (used to indicate Authentication 3), Base AKM Data-3, and MIC.

[0397] Alternatively, after the AP receives the third authentication frame, the AP generates a PMK and a PTK.

[0398] Step 905: The AP sends a fourth authentication frame to the STA.

[0399] The fourth authentication frame includes fields such as Transaction Sequence Number (which is 4) (used to indicate Authentication 4), Base AKM Data-4 (Basic AKM fourth data), and MIC.

[0400] Fifth type of authentication frame format: The wrapped data format field of the first authentication frame indicates an Extensible Authentication Protocol (EAPOL) start based on a local area network, the wrapped data format field of the second authentication frame indicates an Extensible Authentication Protocol (EAP) request / identity information, the wrapped data format field of the third authentication frame indicates an EAP response, and the wrapped data format field of the fourth authentication frame indicates an EAP success.

[0401] As shown in FIG. 31, the MAC frame header of the first authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0402] The Frame Body of the first authentication frame includes a Body field.

[0403] The first authentication frame further includes an FCS field.

[0404] Here, the Body field of the first authentication frame includes: Authentication Algorithm Number=7, Transaction Sequence Number=1, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data element, and PASN Parameters element. As an option, the Authentication Algorithm Number can be equal to 8.

[0405] The Wrapped Data element field of the first authentication frame includes an Element ID, Length, an Element ID Extension, and EAPOL-Start.

[0406] The PASN Parameters element field of the first authentication frame includes Element ID, Length, Element ID Extension, Control, Wrapped Data Format=6, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, and Ephemeral Public Key fields.

[0407] As shown in FIG. 32, the MAC frame header of the second authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0408] The Frame Body of the second authentication frame includes a Body field.

[0409] The second authentication frame further includes a MIC and an FCS field.

[0410] Here, the Body field of the second authentication frame includes: Authentication Algorithm Number=7, Transaction Sequence Number=2, Status Code=0, RSNE, TIE (key lifetime interval), RSNXE, Wrapped Data element, and PASN Parameters element. As an option, the Authentication Algorithm Number can be equal to 8.

[0411] The Wrapped Data element field of the second authentication frame includes Element ID, Length, Element ID Extension, and EAP Request / Identity message (EAP-Request / Identity Information) fields.

[0412] The PASN Parameters element field of the second authentication frame includes Element ID, Length, Element ID Extension, Control, Wrapped Data Format=6, come back info, Finite Cyclic Group ID, Ephemeral Public Key Length, and Ephemeral Public Key fields.

[0413] As shown in FIG. 33, the MAC frame header of the third authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0414] The Frame Body of the third authentication frame includes a Body field.

[0415] The third authentication frame further includes a MIC and an FCS field.

[0416] Here, the Body field of the third authentication frame includes: Authentication Algonrithm Number=7, Transaction Sequence Number=3, Status Code=0, Wrapped Data, and PASN Parameters element. As an option, the Authentication Algonrithm Number can be equal to 8.

[0417] The Wrapped Data field of the third authentication frame includes an Element ID, a Length, an Element ID Extension, and an EAP-Response field.

[0418] The PASN Parameters element field of the third authentication frame includes Element ID, Length, Element ID Extension, Control, and Wrapped Data Format=6 fields.

[0419] As shown in FIG. 34, the MAC frame header of the fourth authentication frame includes Frame Control, Duration, Address 1, Address 2, Address 3, Sequence Control, and HT Control fields.

[0420] The Frame Body of the fourth authentication frame includes a Body field.

[0421] The fourth authentication frame further includes a MIC and an FCS field.

[0422] Here, the Body field of the fourth authentication frame includes: Authentication Algorithm Number=7, Transaction Sequence Number=4, Status Code=0, Wrapped Data, and PASN Parameters element. Alternatively, the Authentication Algorithm Number can be equal to 8.

[0423] The Wrapped Data field of the fourth authentication frame includes an Element ID, a Length, an Element ID Extension, and an EAP-Success field.

[0424] The PASN Parameters element field of the fourth authentication frame includes Element ID, Length, Element ID Extension, Control, and Wrapped Data Format=6 fields.

[0425] Regarding the above fifth type of authentication frame format, The fourth type of PMK and PTK generation method are provided:

[0426] (1) PMK generation:

[0427] The method for forming a PMK in this embodiment is the same as the method for forming a PMK in 802.1X. The STA and the 802.1X authentication server (AS) form the same PMK through authentication using the Extensible Authentication Protocol (EAP). During the authentication procedure, the AS transmits the formed PMK to the AP via another protocol.

[0428] (2) PTK generation:

[0429] PTK=KDF-HASH-NNN(PMK, “PASN PTK Derivation”, SPA || BSSID || DHss)

[0430] Here, DHss is a shared key generated based on the public key of the prover (S-Ephemeral Pub) and the public key of the authenticator (A-Ephemeral Pub) by the Diffie-Hellman procedure.

[0431] As described above, the method provided in this embodiment clarifies the specific flow and message format of how to extend PASN to support the 802.1X authentication method, and also shows the method of generating PMK and PTK.

[0432] In some embodiments of the present application, an extended PASN method is provided for protecting messages during a procedure for establishing an association between a STA and a network, including association request and response messages, and / or 4-way handshake messages, and / or group key handshake messages.

[0433] Illustratively, the PTK generated in the authentication procedure is used to encrypt and decrypt association procedure messages, and / or the PTK generated in the authentication procedure is used to encrypt and decrypt data communication messages.

[0434] In one alternative embodiment, the data communication message comprises a group key handshake message, which is used to distribute at least one of a GTK, an IGTK, and a BIGTK key.

[0435] 35 is a flowchart of an authentication method provided in an exemplary embodiment of the present application. The method can be performed by a STA and an AP, and includes the following steps:

[0436] Step 1001: The AP periodically transmits a Beacon frame.

[0437] The Beacon frame includes fields such as RSNE, extended PASN AKM, Base AKM, and RSNXE.

[0438] Step 1002: The STA sends a first authentication frame to the AP.

[0439] The first authentication frame includes fields such as Transaction Sequence Number which is 1 (used to indicate Authentication 1), Extended PASN, RSNE, PASN AKM, PMK ID, RSNXE, S-Ephemeral Pub (the public key of the authenticatee, i.e., the public key of the STA), PASN Parameters, and Base AKM Data-1.

[0440] Step 1003: The AP sends a second authentication frame to the STA.

[0441] The second authentication frame includes fields such as Transaction Sequence Number (2) (used to indicate Authentication 2), Extended PASN, RSNE, PASN AKM, PMK ID, RSNXE, A-Ephemeral Pub (the authenticator's public key, i.e., the AP's public key), PASN Parameters, Base AKM Data-2, and MIC.

[0442] Alternatively, after the STA receives the second authentication frame, the STA generates a PMK and a PTK.

[0443] Step 1004: The STA sends a third authentication frame to the AP.

[0444] The third authentication frame includes fields such as a Transaction Sequence Number of 3 (used to indicate Authentication 3), Base AKM Data-3, and MIC.

[0445] Alternatively, after the AP receives the third authentication frame, the AP generates a PMK and a PTK.

[0446] This embodiment takes as an example only the authentication procedure shown in step 1001 to step 1004. Of course, this authentication procedure can be replaced with step 701 to step 704 shown in Fig. 16, or replaced with step 801 to step 804 shown in Fig. 23, or replaced with step 901 to step 905 shown in Fig. 30. After the replacement, the STA and AP can perform the authentication procedure by adopting the corresponding extended PASN authentication method.

[0447] Step 1005: The STA and AP use the PTK generated in the authentication procedure to encrypt and decrypt messages in the association procedure.

[0448] The STA encrypts the association request message using the PTK and sends the encrypted association request message to the AP.

[0449] The AP uses the PTK to decrypt the association request message and uses the PTK to encrypt the association response message, and then sends the encrypted association response message to the STA.

[0450] The STA uses the PTK to decrypt the association response message and completes the association procedure.

[0451] Step 1006: The AP encrypts Message 1 of the group key handshake procedure using the PTK generated in the authentication procedure, and sends the encrypted Message 1 to the STA.

[0452] The AP encrypts the EAPOL-Key frame using the PTK generated in the authentication procedure, and the EAPOL-Key frame includes the wrapped GTK, wrapped IGTK, wrapped BIGTK, Group, and MIC.

[0453] The STA decrypts message 1 using the PTK generated in the authentication procedure.

[0454] Step 1007: The STA encrypts Message 2 of the group key handshake procedure using the PTK generated in the authentication procedure, and sends the encrypted Message 2 to the AP.

[0455] The STA encrypts the EAPOL-Key frame using the PTK generated in the authentication procedure, and the EAPOL-Key frame includes a Group and a MIC.

[0456] The AP decrypts message 2 using the PTK generated in the authentication procedure.

[0457] The method provided in this embodiment provides an extension to the Basic Authentication and Key Management Method (Base AKM) used in PASN, as shown in Table 1.

[0458] [Table 1]

[0459] As described above, the method provided in this embodiment uses the PTK generated in the extended PASN authentication procedure to encrypt and decrypt association request and response messages. After association is complete, secure data communication is immediately performed, i.e., unicast data frames and management frames are both encrypted and decrypted using the PTK. After association is complete, the GTK, IGTK, and BIGTK are distributed using the group key handshake procedure. Group key handshake messages, which belong to unicast data frames, can be encrypted and decrypted using the PTK.

[0460] Illustratively, the PTK generated in the authentication procedure is used to encrypt and decrypt four-way handshake messages, and the four-way handshake procedure is used to create an updated PTK, where the updated PTK is used to encrypt and decrypt data communication messages.

[0461] 36 is a flowchart of an authentication method provided in an exemplary embodiment of the present application. The method can be performed by a STA and an AP, and includes the following steps:

[0462] Step 1101: The AP periodically transmits a Beacon frame.

[0463] The Beacon frame includes fields such as RSNE, extended PASN AKM, Base AKM, and RSNXE.

[0464] Step 1102: The STA sends a first authentication frame to the AP.

[0465] The first authentication frame includes fields such as Transaction Sequence Number which is 1 (used to indicate Authentication 1), Extended PASN, RSNE, PASN AKM, PMK ID, RSNXE, S-Ephemeral Pub (the public key of the authenticatee, i.e., the public key of the STA), PASN Parameters, and Base AKM Data-1.

[0466] Step 1103: The AP sends a second authentication frame to the STA.

[0467] The second authentication frame includes fields such as Transaction Sequence Number (2) (used to indicate Authentication 2), Extended PASN, RSNE, PASN AKM, PMK ID, RSNXE, A-Ephemeral Pub (the authenticator's public key, i.e., the AP's public key), PASN Parameters, Base AKM Data-2, and MIC.

[0468] Alternatively, after the STA receives the second authentication frame, the STA generates a PMK and a PTK1.

[0469] Step 1104: The STA sends a third authentication frame to the AP.

[0470] The third authentication frame includes fields such as a Transaction Sequence Number of 3 (used to indicate Authentication 3), Base AKM Data-3, and MIC.

[0471] Alternatively, after the AP receives the third authentication frame, the AP generates a PMK and a PTK1.

[0472] This embodiment takes as an example only the authentication procedure shown in step 1101 to step 1104. Of course, this authentication procedure can be replaced with step 701 to step 704 shown in Fig. 16, or replaced with step 801 to step 804 shown in Fig. 23, or replaced with step 901 to step 905 shown in Fig. 30. After the replacement, the STA and AP can perform the authentication procedure by adopting the corresponding extended PASN authentication method.

[0473] Step 1105: The STA and AP use the PTK1 generated in the authentication procedure to encrypt and decrypt messages in the association procedure.

[0474] The STA encrypts the association request message using PTK1 and sends the encrypted association request message to the AP.

[0475] The AP decrypts the association request message using PTK1 and encrypts the association response message using PTK1, and sends the encrypted association response message to the STA.

[0476] The STA uses PTK1 to decrypt the association response message and completes the association procedure.

[0477] Step 1106: The AP encrypts Message 1 of the four-way handshake procedure using the PTK1 generated in the authentication procedure, and sends the encrypted Message 1 to the STA.

[0478] The AP encrypts the EAPOL-Key frame using PTK1 generated in the authentication procedure, and the EAPOL-Key frame includes A Nonce and Individual.

[0479] The STA decrypts Message 1 using PTK1 generated in the authentication procedure.

[0480] The STA generates PTK2 based on the Anonce in message 1 and the Snonce it generates.

[0481] Step 1107: The STA encrypts Message 2 of the 4-way handshake procedure using the PTK1 generated in the authentication procedure, and sends the encrypted Message 2 to the AP.

[0482] The STA encrypts the EAPOL-Key frame using the PTK1 generated in the authentication procedure, and the EAPOL-Key frame includes an SNonce, an Individual, and a MIC.

[0483] The AP decrypts message 2 using PTK1, which is generated in the authentication procedure.

[0484] The AP generates PTK2 based on the Snonce in message 2 and the Anonce it generates.

[0485] If necessary, the AP generates GTK, IGTK, and BIGTS.

[0486] Step 1108: The AP encrypts Message 3 of the 4-way handshake procedure using the PTK1 generated in the authentication procedure, and sends the encrypted Message 3 to the STA.

[0487] The AP encrypts the EAPOL-Key frame using PTK1 generated during the authentication procedure, and the EAPOL-Key frame contains the installed PTK, Individual, MIC, wrapped GTK, wrapped IGTK, and wrapped BIGTK.

[0488] The STA decrypts message 3 using PTK1, which is generated in the authentication procedure.

[0489] Step 1109: The STA encrypts Message 4 of the 4-way handshake procedure using the PTK1 generated in the authentication procedure, and sends the encrypted Message 4 to the AP.

[0490] The STA encrypts the EAPOL-Key frame using the PTK1 generated in the authentication procedure, and the EAPOL-Key frame includes an Individual and a MIC.

[0491] The AP decrypts message 4 using PTK1, which is generated in the authentication procedure.

[0492] The STA and AP install PTK2 (PTK1 is replaced by PTK2), GTK, IGTK, and BIGTK, respectively.

[0493] After this, the STA and AP use PTK2 to encrypt and decrypt data communication messages.

[0494] Here, PTK1 is the PTK generated in the authentication procedure, and PTK2 is the updated PTK created by the 4-way handshake procedure.

[0495] The method provided in this embodiment provides an extension to the Basic Authentication and Key Management Method (Base AKM) used in PASN, as shown in Table 2.

[0496] [Table 2]

[0497] As described above, the method provided in this embodiment uses PTK1 generated in the extended PASN authentication procedure to encrypt and decrypt association request and response messages. After association is complete, a new PTK2 is generated using the four-way handshake procedure to replace the PTK1 generated by the PASN. Four-way handshake messages are encrypted and decrypted using PTK1. Secure data communication begins immediately after the four-way handshake is complete; both unicast data frames and management frames are encrypted and decrypted using PTK2.

[0498] 37 is a block diagram of an authentication device provided in an exemplary embodiment of the present application. The device is used to be implemented as a STA or a part of a STA, and includes:

[0499] The first authentication module 1201 is used to perform an authentication procedure by transmitting an authentication frame between the station AP, and a first field in the authentication frame is used to indicate that identity authentication is performed by adopting at least one authentication method among an extended pre-association security negotiation PASN supporting shared key authentication with perfect forward secrecy (FILS fast initial link setup), an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0500] In an alternative design, the first field includes an identity authentication algorithm number field and a wrap data format field.

[0501] In an alternative design, the identity authentication algorithm number field is 7 and the wrapped data format field is a first newly created value, which is used to indicate that the authentication method employed is an extended PASN that supports FILS shared key authentication with perfect forward secrecy; or, The identity authentication algorithm number field is the second newly created value, and the wrap data format field is the first newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

[0502] In an alternative design, the identity authentication algorithm number field is 7 and the wrapped data format field is a third newly created value, which is used to indicate that the authentication method employed is an extended PASN that supports FILS public key authentication; or, The identity authentication algorithm number field having the fourth newly created value and the wrap data format field having the third newly created value are used to indicate that the authentication method adopted is an extended PASN that supports FILS public key authentication.

[0503] In an alternative design, the identity authentication algorithm number field is set to 7 and the wrapped data format field is set to a newly created value of 5 to indicate that the authentication method employed is an extended PASN that supports 802.1X authentication; or, The identity authentication algorithm number field having the sixth newly created value and the wrap data format field having the fifth newly created value are used to indicate that the authentication method adopted is an extended PASN that supports 802.1X authentication.

[0504] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication scheme that supports FILS shared key authentication with perfect forward secrecy; The authentication frame further includes at least one field of a Pairwise Master Key PMK public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit.

[0505] In an alternative design, the authentication frame further includes a PMK public key; The apparatus further includes a first key module 1202 for generating a first PMK based on a first shared key DHss; The first DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

[0506] In an alternative design, the device comprises: a first key module 1202 for generating a first pairwise transient key PTK based on the first PMK and the second DHss; The second DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

[0507] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication scheme that supports FILS shared key authentication with perfect forward secrecy; The apparatus further includes a first key module 1202 for generating a second PMK based on the third DHss; The third DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

[0508] In an alternative design, the device further includes a first key module 1202 for generating a second PTK based on the second PMK and the third DHss.

[0509] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication scheme that supports FILS public key authentication; The authentication frame further includes at least one field of a PMK public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit.

[0510] In an alternative design, at least one of the fields of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame.

[0511] In an alternative design, at least one of the fields of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame; The PMK Finite Cyclic Group field is carried in the control field of the authentication frame.

[0512] In an alternative design, the authentication frame further includes a PMK public key; The apparatus further includes a first key module 1202 for generating a third PMK based on the fourth DHss; The fourth DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

[0513] In selectable designs, The device further includes a first key module 1202 for generating a third PTK based on the third PMK and a fifth DHss; The fifth DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

[0514] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication method that supports 802.1X authentication; The authentication frames include a fourth authentication frame transmitted by the AP to the STA.

[0515] In an alternative design, the authentication frames include a first authentication frame transmitted by the STA to the AP, a second authentication frame transmitted by the AP to the STA, a third authentication frame transmitted by the STA to the AP, and the fourth authentication frame; a wrapped data format field of the first authentication frame indicating an Extensible Authentication Protocol over Local Area Network (EAPOL) start; the wrapped data format field of the second authentication frame indicates Extensible Authentication Protocol (EAP) request / identity information; the wrapped data format field of the third authentication frame indicates an EAP response; The wrapped data format field of the fourth authentication frame indicated EAP success.

[0516] In an alternative design, the PTK generated in the authentication procedure is used to encrypt and decrypt association procedure messages.

[0517] In an alternative design, the PTK generated in the authentication procedure is used to encrypt and decrypt data communication messages.

[0518] In an alternative design, the data communication message includes a group key handshake message; The group key handshake message is used to distribute at least one of a group transient key GTK, an integrity group transient key IGTK, and a beacon frame integrity group transient key BIGTK.

[0519] In an alternative design, the PTK generated in the authentication procedure is used to encrypt and decrypt four-way handshake messages.

[0520] In selectable designs, the apparatus further includes a first handshake module 1203 for creating an updated PTK using a four-way handshake procedure; The updated PTK is used to encrypt and decrypt data communication messages.

[0521] 38 is a block diagram of an authentication device provided in an exemplary embodiment of the present application. The device is used to be implemented as an AP or a part of an AP, and includes:

[0522] The second authentication module 1204 is used to perform an authentication procedure by transmitting an authentication frame between the STA, and a first field in the authentication frame is used to instruct identity authentication to be performed by adopting at least one authentication method among an extended pre-association security negotiation PASN supporting FILS (Fast Initial Link Setup) shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication.

[0523] In an alternative design, the first field includes an identity authentication algorithm number field and a wrap data format field.

[0524] In an alternative design, the identity authentication algorithm number field is 7 and the wrapped data format field is a first newly created value, which is used to indicate that the authentication method employed is an extended PASN that supports FILS shared key authentication with perfect forward secrecy; or, The identity authentication algorithm number field is the second newly created value, and the wrap data format field is the first newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

[0525] In an alternative design, the identity authentication algorithm number field is 7 and the wrapped data format field is a third newly created value, which is used to indicate that the authentication method employed is an extended PASN that supports FILS public key authentication; or, The identity authentication algorithm number field having the fourth newly created value and the wrap data format field having the third newly created value are used to indicate that the authentication method adopted is an extended PASN that supports FILS public key authentication.

[0526] In an alternative design, the identity authentication algorithm number field is set to 7 and the wrapped data format field is set to a newly created value of 5 to indicate that the authentication method employed is an extended PASN that supports 802.1X authentication; or, The identity authentication algorithm number field having the sixth newly created value and the wrap data format field having the fifth newly created value are used to indicate that the authentication method adopted is an extended PASN that supports 802.1X authentication.

[0527] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication scheme that supports FILS shared key authentication with perfect forward secrecy; The authentication frame further includes at least one field of a Pairwise Master Key PMK public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit.

[0528] In an alternative design, the authentication frame further includes a PMK public key; The apparatus further includes a second key module 1205 for generating a first PMK based on a first shared key DHss; The first DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

[0529] In selectable designs, The apparatus further includes a second key module 1205 for generating a first pairwise transient key PTK based on the first PMK and the second DHss; The second DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

[0530] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication scheme that supports FILS shared key authentication with perfect forward secrecy; The apparatus further includes a second key module 1205 for generating a second PMK based on the third DHss; The third DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

[0531] In an alternative design, the device further includes a second key module 1205 for generating a second PTK based on the second PMK and the third DHss.

[0532] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication scheme that supports FILS public key authentication; The authentication frame further includes at least one field of a PMK public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit.

[0533] In an alternative design, at least one of the fields of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame.

[0534] In an alternative design, at least one of the fields of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame; The PMK Finite Cyclic Group field is carried in the control field of the authentication frame.

[0535] In an alternative design, the authentication frame further includes a PMK public key; the apparatus further includes a second key module 1205 for generating a third PMK based on the fourth DHss; The fourth DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

[0536] In selectable designs, The device further includes a second key module 1205 for generating a third PTK based on the third PMK and a fifth DHss; The fifth DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

[0537] In an alternative design, the first field is used to indicate the adoption of an extended PASN authentication method that supports 802.1X authentication; The authentication frames include a fourth authentication frame transmitted by the AP to the STA.

[0538] In an alternative design, the authentication frames include a first authentication frame transmitted by the STA to the AP, a second authentication frame transmitted by the AP to the STA, a third authentication frame transmitted by the STA to the AP, and the fourth authentication frame; a wrapped data format field of the first authentication frame indicating an Extensible Authentication Protocol over Local Area Network (EAPOL) start; the wrapped data format field of the second authentication frame indicates Extensible Authentication Protocol (EAP) request / identity information; the wrapped data format field of the third authentication frame indicates an EAP response; The wrapped data format field of the fourth authentication frame indicated EAP success.

[0539] In an alternative design, the PTK generated in the authentication procedure is used to encrypt and decrypt association procedure messages.

[0540] In an alternative design, the PTK generated in the authentication procedure is used to encrypt and decrypt data communication messages.

[0541] In an alternative design, the data communication message includes a group key handshake message; The group key handshake message is used to distribute at least one of a group transient key GTK, an integrity group transient key IGTK, and a beacon frame integrity group transient key BIGTK.

[0542] In an alternative design, the PTK generated in the authentication procedure is used to encrypt and decrypt four-way handshake messages.

[0543] In selectable designs, the apparatus further includes a second handshake module 1206 for creating an updated PTK using a four-way handshake procedure; The updated PTK is used to encrypt and decrypt data communication messages.

[0544] It should be noted that when the device provided in the above embodiments realizes its functions, only the division of each of the above functional modules is taken as an example for description. In actual applications, the above functions are realized by different functional modules according to actual needs, that is, the device configuration is divided into different functional modules to complete all or part of the functions described above.

[0545] Regarding the apparatus in the above embodiment, the specific manner in which each module performs an operation has already been described in detail in the embodiment relating to the method, and detailed description thereof will be omitted here.

[0546] FIG. 39 is a structural schematic diagram of an authentication device (STA and / or AP) provided in an exemplary embodiment of the present application, where the authentication device 3300 includes a processor 3301, a receiver 3302, a transmitter 3303, a memory 3304 and a bus 3305.

[0547] The processor 3301 includes one or more processing cores, and executes various functional applications and information processing by running software programs and modules.

[0548] The receiver 3302 and the transmitter 3303 can be implemented as one communication component, which may be one communication chip.

[0549] The memory 3304 is connected to the processor 3301 via a bus 3305. The memory 3304 can be used to store at least one instruction, and the processor 3301 is used to execute the at least one instruction to implement each step in the above method embodiments.

[0550] It should be noted that the memory 3304 can be realized by any type of volatile or non-volatile storage device or a combination thereof, including, but not limited to, a disk or optical disk, an Electrically Erasable Programmable Read Only Memory (EEPROM), an Erasable Programmable Read-Only Memory (EPROM), a Static Random-Access Memory (SRAM), a Read-Only Memory (ROM), a magnetic memory, a flash memory, and a Programmable Read-Only Memory (PROM).

[0551] In an exemplary embodiment, a computer-readable storage medium is further provided, wherein at least one program is stored in the computer-readable storage medium, and the at least one program is loaded and executed by a processor to implement the authentication method provided in each of the above method embodiments.

[0552] In an exemplary embodiment, a chip is further provided, the chip including programmable logic circuitry and / or program instructions, which when operating on a communications device is used to implement the authentication methods provided in each of the method embodiments above.

[0553] In an exemplary embodiment, a computer program product is further provided, which, when running on a processor of a communications device, causes the communications device to perform the authentication method described above.

[0554] Those skilled in the art will appreciate that the functions described in the embodiments of the present application, in one or more examples above, can be implemented in hardware, software, firmware, or any combination thereof. If implemented using software, these functions may be stored on or transmitted as one or more instructions or code on a computer-readable medium. Computer-readable media includes computer storage media and communication media, where communication media includes any medium that facilitates transfer of a computer program from one place to another. Storage media may be any available medium accessible by a general-purpose or special-purpose computer.

[0555] The above are merely selectable examples of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application are intended to be included within the scope of the present invention.

Claims

1. An authentication method performed by a station STA, comprising: The method comprises: An authentication procedure is performed by transmitting an authentication frame between the access point (AP) and the access point (AP), and a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method selected from the group consisting of an extended pre-association security negotiation (PASN) supporting fast initial link setup (FILS) shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication. Including, Authentication method.

2. the first field includes an identity authentication algorithm number field and a wrap data format field; 2. The method of claim 1 .

3. The identity authentication algorithm number field is set to 7, and the wrapped data format field is set to the first newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS shared key authentication with perfect forward secrecy; Alternatively, the identity authentication algorithm number field is a second newly created value, and the wrapped data format field is the first newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

3. The method of claim 2.

4. The identity authentication algorithm number field is set to 7, and the wrapped data format field is set to a third newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS public key authentication; Alternatively, the identity authentication algorithm number field having the fourth newly created value and the wrapped data format field having the third newly created value are used to indicate that the authentication method adopted is an extended PASN that supports FILS public key authentication.

3. The method of claim 2.

5. The identity authentication algorithm number field is set to 7, and the wrapped data format field is set to the fifth newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports 802.1X authentication; Alternatively, the identity authentication algorithm number field having the sixth newly created value and the wrapped data format field having the fifth newly created value are used to indicate that the authentication method adopted is an extended PASN that supports 802.1X authentication.

3. The method of claim 2.

6. The first field is used to indicate that an extended PASN authentication method that supports FILS shared key authentication with perfect forward secrecy is adopted; The authentication frame further includes at least one field of a Pairwise Master Key (PMK) public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit.

6. The method according to any one of claims 1 to 5.

7. The authentication frame further includes a PMK public key; The method includes generating a first PMK based on a first shared key DHss; The first DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

7. The method of claim 6.

8. The method further includes generating a first pairwise transient key (PTK) based on the first PMK and the second DHss; The second DHss is a shared key generated based on a public key of the authenticatee of the STA and a public key of the authenticator of the AP.

8. The method of claim 7.

9. The first field is used to indicate that an extended PASN authentication method that supports FILS shared key authentication with perfect forward secrecy is adopted; The method further includes generating a second PMK based on the third DHss; The third DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

6. The method according to any one of claims 1 to 5.

10. The method further includes generating a second PTK based on the second PMK and the third DHss.

10. The method of claim 9.

11. The first field is used to indicate that an extended PASN authentication method that supports FILS public key authentication is adopted; the authentication frame further includes at least one field of a PMK public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit; 6. The method according to any one of claims 1 to 5.

12. At least one field of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame.

12. The method of claim 11 .

13. At least one field of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame; The PMK finite cyclic group field is carried in the control field of the authentication frame.

12. The method of claim 11 .

14. The authentication frame further includes a PMK public key; The method further includes generating a third PMK based on a fourth DHss; The fourth DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

14. The method according to any one of claims 11 to 13.

15. The method further includes generating a third PTK based on the third PMK and a fifth DHss; The fifth DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

15. The method of claim 14.

16. The first field is used to indicate that an authentication method of an extended PASN that supports 802.1X authentication is adopted; The authentication frame includes a fourth authentication frame transmitted by the AP to the STA.

6. The method according to any one of claims 1 to 5.

17. the authentication frames include a first authentication frame transmitted by the STA to the AP, a second authentication frame transmitted by the AP to the STA, a third authentication frame transmitted by the STA to the AP, and the fourth authentication frame; a wrapped data format field of the first authentication frame indicating an Extensible Authentication Protocol (EAPOL) start based on a local area network; the Wrapped Data Format field of the second authentication frame indicates Extensible Authentication Protocol (EAP) Request / Identity Information; the wrapped data format field of the third authentication frame indicates an EAP response; The wrapped data format field of the fourth authentication frame indicated EAP success.

17. The method of claim 16.

18. The PTK generated in the authentication procedure is used to encrypt and decrypt association procedure messages.

18. The method according to any one of claims 1 to 17.

19. The PTK generated in the authentication procedure is used to encrypt and decrypt data communication messages.

18. The method according to any one of claims 1 to 17.

20. the data communication message includes a group key handshake message; The group key handshake message is used to distribute at least one of a group transient key (GTK), an integrity group transient key (IGTK), and a beacon frame integrity group transient key (BIGTK).

20. The method of claim 19.

21. The PTK generated in the authentication procedure is used to encrypt and decrypt four-way handshake messages.

18. The method according to any one of claims 1 to 17.

22. The method further includes creating an updated PTK using a four-way handshake procedure; The updated PTK is used to encrypt and decrypt data communication messages.

22. The method of claim 21 .

23. An authentication method performed by an AP, comprising: The method comprises: An authentication procedure is performed by transmitting an authentication frame between the STA and the STA, and a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method selected from the group consisting of an extended pre-association security negotiation (PASN) supporting fast initial link setup (FILS) shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication. Including, Authentication method.

24. The first field includes an identity authentication algorithm number field and a wrap data format field.

24. The method of claim 23.

25. The identity authentication algorithm number field is set to 7, and the wrapped data format field is set to the first newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS shared key authentication with perfect forward secrecy; Alternatively, the identity authentication algorithm number field is a second newly created value, and the wrapped data format field is the first newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS shared key authentication with perfect forward secrecy.

25. The method of claim 24.

26. The identity authentication algorithm number field is set to 7, and the wrapped data format field is set to a third newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports FILS public key authentication; Alternatively, the identity authentication algorithm number field having the fourth newly created value and the wrapped data format field having the third newly created value are used to indicate that the authentication method adopted is an extended PASN that supports FILS public key authentication.

25. The method of claim 24.

27. The identity authentication algorithm number field is set to 7, and the wrapped data format field is set to the fifth newly created value, which is used to indicate that the authentication method adopted is an extended PASN that supports 802.1X authentication; Alternatively, the identity authentication algorithm number field having the sixth newly created value and the wrapped data format field having the fifth newly created value are used to indicate that the authentication method adopted is an extended PASN that supports 802.1X authentication.

25. The method of claim 24.

28. The first field is used to indicate that an extended PASN authentication method that supports FILS shared key authentication with perfect forward secrecy is adopted; The authentication frame further includes at least one field of a Pairwise Master Key (PMK) public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit.

28. The method of any one of claims 23 to 27.

29. The authentication frame further includes a PMK public key; The method further includes generating a first PMK based on a first shared key DHss. The first DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

29. The method of claim 28.

30. The method further includes generating a first pairwise transient key (PTK) based on the first PMK and the second DHss; The second DHss is a shared key generated based on a public key of the authenticatee of the STA and a public key of the authenticator of the AP.

30. The method of claim 29.

31. The first field is used to indicate that an extended PASN authentication method that supports FILS shared key authentication with perfect forward secrecy is adopted; The method further includes generating a second PMK based on the third DHss; The third DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

28. The method of any one of claims 23 to 27.

32. The method further includes generating a second PTK based on the second PMK and the third DHss.

32. The method of claim 31 .

33. The first field is used to indicate that an extended PASN authentication method that supports FILS public key authentication is adopted; the authentication frame further includes at least one field of a PMK public key, a PMK public key length, a PMK finite cyclic group, a PMK group, and a key validity bit; 28. The method of any one of claims 23 to 27.

34. At least one field of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame.

34. The method of claim 33.

35. At least one field of the PMK public key, the PMK public key length, and the PMK finite cyclic group is carried in a wrap data element field of the authentication frame; The PMK finite cyclic group field is carried in the control field of the authentication frame.

34. The method of claim 33.

36. The authentication frame further includes a PMK public key; The method further includes generating a third PMK based on a fourth DHss; The fourth DHss is a shared key generated based on the PMK public key of the STA and the PMK public key of the AP.

36. The method of any one of claims 33 to 35.

37. The method further includes generating a third PTK based on the third PMK and a fifth DHss; The fifth DHss is a shared key generated based on the public key of the authenticatee of the STA and the public key of the authenticator of the AP.

37. The method of claim 36.

38. The first field is used to indicate that an authentication method of an extended PASN that supports 802.1X authentication is adopted; The authentication frame includes a fourth authentication frame transmitted by the AP to the STA.

28. The method of any one of claims 23 to 27.

39. the authentication frames include a first authentication frame transmitted by the STA to the AP, a second authentication frame transmitted by the AP to the STA, a third authentication frame transmitted by the STA to the AP, and the fourth authentication frame; a wrapped data format field of the first authentication frame indicating an Extensible Authentication Protocol (EAPOL) start based on a local area network; the Wrapped Data Format field of the second authentication frame indicates Extensible Authentication Protocol (EAP) Request / Identity Information; the wrapped data format field of the third authentication frame indicates an EAP response; The wrapped data format field of the fourth authentication frame indicated EAP success.

39. The method of claim 38.

40. The PTK generated in the authentication procedure is used to encrypt and decrypt association procedure messages.

40. The method of any one of claims 23 to 39.

41. The PTK generated in the authentication procedure is used to encrypt and decrypt data communication messages.

40. The method of any one of claims 23 to 39.

42. the data communication message includes a group key handshake message; The group key handshake message is used to distribute at least one of a group transient key (GTK), an integrity group transient key (IGTK), and a beacon frame integrity group transient key (BIGTK).

42. The method of claim 41 .

43. The PTK generated in the authentication procedure is used to encrypt and decrypt four-way handshake messages.

40. The method of any one of claims 23 to 39.

44. The method further includes creating an updated PTK using a four-way handshake procedure; The updated PTK is used to encrypt and decrypt data communication messages.

44. The method of claim 43.

45. a first authentication module used to perform an authentication procedure by transmitting an authentication frame between the access point AP and the first authentication module; a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method among an extended pre-association security negotiation (PASN) supporting fast initial link setup (FILS) shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication; Authentication device.

46. Executed by the AP, The apparatus includes a second authentication module used to perform an authentication procedure by transmitting an authentication frame between the apparatus and a STA; a first field in the authentication frame is used to indicate that identity authentication is performed using at least one authentication method among an extended pre-association security negotiation (PASN) supporting fast initial link setup (FILS) shared key authentication with perfect forward secrecy, an extended PASN supporting FILS public key authentication, and an extended PASN supporting 802.1X authentication; Authentication device.

47. a processor; a transceiver coupled to the processor; a memory for storing executable instructions for said processor; 1. An STA device comprising: The processor is arranged to load the executable instructions to cause the STA device to implement the authentication method of any one of claims 1 to 22. STA device.

48. a processor; a transceiver coupled to the processor; a memory for storing executable instructions for said processor; An AP device comprising: The processor is arranged to load the executable instructions to cause the AP device to implement the authentication method of any one of claims 23 to 44. AP device.

49. Executable instructions are stored, The executable instructions are loaded and executed by a processor to cause a communications device to implement the authentication method of any one of claims 1 to 44. A computer-readable storage medium.

50. A chip containing a programmable logic circuit or program, The communication device to which the chip is attached is used to implement the authentication method according to any one of claims 1 to 44 by the programmable logic circuit or program. Tips.

51. computer instructions stored on a computer-readable storage medium; a processor of a communications device reading the computer instructions from the computer-readable storage medium and executing the computer instructions to cause the communications device to implement the authentication method of any one of claims 1 to 44; Computer program products.