Wireless communication method, station, and access point
Identity verification using first secret and time information in wireless frames addresses spoofed AP attacks, enhancing security and privacy in wireless networks.
Patent Information
- Application Number
- JP2025530796
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2022-12-02
- Publication Date
- 2025-12-05
AI Technical Summary
The risk of user privacy leakage due to spoofed access points (APs) in wireless local area networks, where attackers impersonate a familiar SSID to track user locations.
Implementing identity verification based on first secret and time information in beacon or probe response frames to determine if an access point is being spoofed, or to securely associate with a known access point.
Prevents user privacy leakage by ensuring secure association with genuine access points, with minimal impact on system throughput and signaling overhead.
Smart Images

Figure 2025539406000001_ABST
Abstract
Description
[Technical Field]
[0001] TECHNICAL FIELD Embodiments of the present application relate to the field of communications, and more particularly to a wireless communication method, a station, and an access point. [Background technology]
[0002] In a wireless local area network (WLAN), when a station (STA) receives a beacon frame or a probe response frame transmitted by an access point (AP), if the service set identifier (SSID) included in the beacon frame or the probe response frame belongs to an SSID that the station has previously connected to, the STA may automatically send an association request frame to the AP. An attacker exploits this mechanism to set up an AP, which may be called a "spoofed AP." The "spoofed AP" carries an SSID that a user has previously connected to (e.g., the SSID of the user's home WLAN) in the beacon frame or the probe response frame. When the "spoofed AP" receives an association request frame transmitted by a STA, regardless of the media access control (MAC) address used by the STA, the "spoofed AP" can infer that the user is likely within the coverage area of the "spoofed AP," thereby enabling it to identify and track the specific user.
[0003] When the SSID included in a beacon frame or probe response frame belongs to an SSID that the station has previously connected to, the issue of how to resolve the risk of user privacy leakage due to a "spoofed AP" attack, or how the STA associates with the AP, is an issue that needs to be resolved. Summary of the Invention
[0004]
[0009] Embodiments of the present application provide a wireless communication method, a station, and an access point. If the SSID in a first frame transmitted by an access point is an SSID that the station has previously connected to, the station can determine whether the access point is being spoofed by another device based on identity information carried in the first frame. This can resolve the risk of user privacy leakage due to a "spoofed AP" attack. Alternatively, if the SSID in the first frame transmitted by the access point is an SSID that the station has previously connected to, the station can associate with the access point based on the identity information carried in the first frame. This can improve the security of the process in which the station associates with the access point.
[0005] In a first aspect, a wireless communication method is provided, the method including: a station receives a first frame; the first frame includes identity information, and the identity information is determined based on a first secret and time information of an access point; if a service set identifier (SSID) in the first frame is an SSID that the station has previously connected to, the station determines whether the access point is being spoofed by another device based on the station's time information, the first secret, and the identity information, or the station associates with the access point based on the station's time information, the first secret, and the identity information.
[0006] In a second aspect, a wireless communication method is provided, the method including: an access point transmits a first frame; the first frame includes identity information, and the identity information is determined based on first secret information and time information of the access point; if a service set identifier (SSID) in the first frame is an SSID to which a station has previously connected, the identity information is used by the station to determine whether the access point is being spoofed by another device, or the identity information is used by the station to associate with the access point.
[0007] In a third aspect, there is provided a station for carrying out the method of the first aspect, the station comprising a functional module for carrying out the method of the first aspect.
[0008] In a fourth aspect, there is provided an access point for performing the method in the second aspect, the access point comprising a functional module for performing the method in the second aspect.
[0009] In a fifth aspect, there is provided a station comprising a processor and a memory, the memory configured to store a computer program, the processor configured to access and execute the computer program stored in the memory to cause the station to perform the method of the first aspect.
[0010] In a sixth aspect, there is provided an access point comprising a processor and a memory, the memory configured to store a computer program, the processor configured to access and execute the computer program stored in the memory to cause the access point to perform the method of the second aspect.
[0011] In a seventh aspect, there is provided an apparatus for performing the method of the first or second aspect. Specifically, the apparatus includes a processor configured to call and execute a computer program stored in a memory, thereby causing a device equipped with the apparatus to perform the method of the first or second aspect.
[0012] In an eighth aspect, there is provided a computer-readable storage medium configured to store a computer program that causes a computer to perform the method of the first or second aspect.
[0013] In a ninth aspect, there is provided a computer program product comprising computer program instructions that cause a computer to perform the method of the first or second aspect above.
[0014] In a tenth aspect, there is provided a computer program which, when run on a computer, causes the computer to carry out the method of the first or second aspect.
[0015] According to the above technical solution, if the SSID in the first frame transmitted by the access point is an SSID that the station has previously connected to, the station can determine whether the access point is being spoofed by another device based on the identity information carried in the first frame. This can solve the risk of user privacy leakage caused by a "spoofed AP" attack, and is easy to implement because the increased signaling overhead is relatively small and the impact on system throughput is minimal. Alternatively, if the SSID in the first frame transmitted by the access point is an SSID that the station has previously connected to, the station associates with the access point based on the station's time information, first secret information, and identity information. This can improve the security of the process of the station associating with the access point. [Brief explanation of the drawings]
[0016] [Figure 1] FIG. 1 is a schematic diagram illustrating a communication system architecture to which an embodiment of the present application is applied. [Figure 2] FIG. 2 is an interaction flowchart illustrating a wireless communication method according to an embodiment of the present application. [Figure 3] FIG. 3 is a schematic diagram illustrating an identity information element according to an embodiment of the present application. [Figure 4] FIG. 4 is a schematic diagram illustrating that a beacon frame carries identity information according to an embodiment of the present application. [Figure 5] FIG. 5 is a schematic diagram illustrating that a probe response frame according to an embodiment of the present application carries identity information. [Figure 6] FIG. 6 is a schematic diagram illustrating a management frame according to an embodiment of the present application. [Figure 7] FIG. 7 is a block diagram illustrating a station according to an embodiment of the present application. [Figure 8]FIG. 8 is a block diagram illustrating an access point according to an embodiment of the present application. [Figure 9] FIG. 9 is a block diagram illustrating a communication device according to an embodiment of the present application. [Figure 10] FIG. 10 is a block diagram illustrating an apparatus according to an embodiment of the present application. [Figure 11] FIG. 11 is a block diagram illustrating a communication system according to an embodiment of the present application. DETAILED DESCRIPTION OF THE INVENTION
[0017] Hereinafter, the technical solutions of the embodiments of the present application will be described with reference to the drawings of the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments that can be obtained by those skilled in the art without creative efforts all belong to the protection scope of the present application.
[0018] The technical solutions of the embodiments of the present application can be applied to various communication systems, such as wireless local area networks (WLANs), wireless fidelity (WiFi), or other communication systems.
[0019] Referring to Figure 1, Figure 1 is a schematic diagram showing a wireless communication system according to an embodiment of the present application. As shown in Figure 1, the wireless communication system may include an access point (AP) and a station (STA).
[0020] In some cases, an AP may be called an AP STA, i.e., an AP is also a type of STA in a sense. In some cases, a STA may be called a non-AP STA.
[0021] In some embodiments, STAs may include AP STAs and non-AP STAs. Communication in a communication system may be communication between an AP and a non-AP STA, communication between a non-AP STA and a non-AP STA, or communication between a STA and a peer STA. A peer STA may refer to a device that communicates with the STA on an equal footing. For example, a peer STA may be an AP or a non-AP STA.
[0022] An AP is equivalent to a bridge that connects a wired network with a wireless network. The main role of an AP is to connect various wireless network clients to each other and then connect the wireless network to the Ethernet. An AP can be a terminal device (such as a mobile phone) or a network device (such as a router) equipped with a Wireless Fidelity (Wi-Fi) chip.
[0023] However, the role of a STA in a communication system is not fixed. For example, in some scenarios, when a mobile phone connects to a router, the mobile phone is a non-AP STA. When a mobile phone is used as a hotspot for other mobile phones, the mobile phone functions as an AP.
[0024] The AP and non-AP STA may be devices applied to V2X (Vehicle to Everything), IoT nodes in IoT (Internet of Things), sensors, etc., smart cameras, smart remote controls, smart water meters, smart electricity meters, etc. in smart homes, sensors in smart cities, etc.
[0025] In some embodiments, the non-AP STAs may support the 802.11be standard, and may support multiple current and future 802.11 family WLAN standards, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.
[0026] In some embodiments, the AP may be a device that supports the 802.11be standard, or may be a device that supports multiple current and future 802.11 family WLAN standards, such as 802.11ax, 802.11ac, 802.11n, 802.11g, 802.11b, and 802.11a.
[0027] In an embodiment of the present application, the STA may be a mobile phone, a tablet computer (Pad), a computer, a virtual reality (VR) device, an augmented reality (AR) device, a wireless device in industrial control, a set top box (STB), a wireless device in self driving, an in-vehicle communication device, a wireless device in remote medical, a wireless device in a smart grid, a wireless device in transportation safety, a wireless device in a smart city, or a wireless device in a smart home, a wireless communication chip, an application specific integrated circuit (ASIC), a system-on-chip (SOC), etc. that supports WLAN / WIFI technology.
[0028] Frequency bands that may be supported by WLAN technology may include, but are not limited to, low frequency bands (2.4 GHz (Giga Hertz), 5 GHz, 6 GHz), high frequency bands (45 GHz, 60 GHz).
[0029] There may be one or more links between a station and an access point. In some embodiments, the station and access point support multi-band communication, e.g., simultaneously communicating in frequency bands 2.4 GHz, 5 GHz, 6 GHz, 45 GHz, and 60 GHz, or simultaneously communicating in different channels of the same frequency band (or different frequency bands), thereby improving the throughput and / or reliability of communication between the devices. Such devices are often referred to as multi-band devices or multi-link devices (MLDs), and may also be referred to as multi-link entities or multi-band entities. An MLD may be an access point or a station. If the MLD is an access point, the MLD includes one or more APs. If the MLD is a station, the MLD includes one or more non-AP STAs.
[0030] An MLD that includes one or more APs may be referred to as an AP MLD, and an MLD that includes one or more non-AP STAs may be referred to as a non-AP MLD.
[0031] In the embodiment of the present application, an AP may include multiple APs, and a non-AP may include multiple STAs. Multiple links may be formed between the APs in the AP and the STAs in the non-AP, and data communication can be performed between the APs in the AP and the corresponding STAs in the non-AP through the corresponding links.
[0032] An AP is a device deployed in a WLAN to provide wireless communication capabilities to STAs. A station may include a user equipment (UE), access terminal, user unit, user station, mobile station, remote station, remote terminal, mobile device, wireless communication device, user agent, or user equipment. Alternatively, a station may be a cellular phone, a cordless phone, a session initiation protocol (SIP) phone, a wireless local loop (WLL) station, a personal digital assistant (PDA), a handheld device with wireless communication capabilities, a computing device, or other processing device connected to a wireless modem, an in-vehicle device, or a wearable device, and embodiments of the present application are not limited thereto.
[0033] Optionally, both the stations and the access points support the IEEE (Institute of Electrical and Electronics Engineers) 802.11 standard.
[0034] It should be understood that the terms "system" and "network" are always used interchangeably herein. In this specification, the term "and / or" simply describes the relationship between related objects and indicates the existence of three types of relationships. For example, A and / or B indicates three situations: the presence of only A, the simultaneous presence of A and B, and the presence of only B. Also, in this specification, the symbol " / " generally indicates that the related objects before and after it are in an "or" relationship.
[0035] It should be understood that the "indicate" referred to in the embodiments of the present application may be a direct indication, an indirect indication, or an indication that there is an associative relationship. For example, when A indicates B, it may mean that A directly indicates B (e.g., B can be obtained by A), or that A indirectly indicates B (e.g., A indicates C, and B can be obtained by C), or that there is an associative relationship between A and B.
[0036] The terms used in the embodiments of this application are used only to describe specific embodiments of this application and are not intended to limit this application. Terms such as "first," "second," "third," and "fourth" in the specification, claims, and drawings of this application are used to distinguish different objects, not to describe a specific sequence. Furthermore, terms such as "include," "comprise," and any other variants are intended to cover, without excluding, the inclusion of other components.
[0037] In describing the embodiments of the present application, the term "corresponding" may mean that there is a direct or indirect corresponding relationship between the two, or that there is an association relationship between the two, or that there is a relationship such as indicating and being indicated, setting and not setting, etc.
[0038] In the embodiments of the present application, "predefined" or "preset" may be realized by pre-storing a corresponding code or a corresponding table in a device (including, for example, an STA and a network device), or by other methods that can be used to indicate related information, and the present application does not limit the specific realization method. For example, "predefined" may mean being defined in a protocol.
[0039] In the embodiments of the present application, "protocol" may refer to standard protocols in the communications field, and may include, for example, the WiFi protocol and related protocols applied to future WiFi communication systems, and the present application is not limited thereto.
[0040] In order to facilitate understanding of the technical solutions of the embodiments of the present application, the problems to be solved by the present application are described below.
[0041] STAs discover the presence of APs in two ways: the first method is passive scanning, in which the AP broadcasts a beacon frame to announce the presence of the AP; the second method is active scanning, in which the STA sends a probe request frame with an empty SSID or a specific SSID, and upon receiving the probe request frame, the AP sends a probe response frame to the STA to announce the presence of the AP. The beacon frame or probe response frame sent by the AP contains an SSID element, which is used to identify the Basic Service Set (BSS).
[0042] After a STA associates with an AP for the first time, the STA saves the SSID of the AP. These SSIDs saved by the STA may be called saved SSIDs or preferred SSIDs. When the STA receives a beacon frame or a probe response frame, if the SSID included in the beacon frame or probe response frame belongs to the saved SSIDs and the user has configured the network to "automatically connect when the network is in range," the upper-layer application controls the device's WiFi driver to perform related connection operations (including authentication and association). For example, using the WLAN management program wpa_supplicant, a user can configure network parameters through a graphical interface or terminal commands, and wpa_supplicant can automatically control the device's Wi-Fi driver to perform network connection based on the parameters in its configuration file.
[0043] An attacker can exploit potential security risks in the current discovery and AP association mechanism to identify and track specific users. Assuming an attacker knows one or more SSIDs to which a user has connected (e.g., the SSID of the user's home network), the attacker can configure an AP and use that AP to broadcast the SSID of the user's home network. When a STA receives a beacon frame or probe response frame transmitted by the attacker-configured AP, if the STA finds that the SSID in the beacon frame or probe response frame is a saved SSID, the STA may automatically send an association request frame to the AP. Regardless of whether the STA has associated with the attacker-configured AP or the STA's MAC address, as long as the STA sends an association request frame to the AP, the user is indicated as being within the coverage of the attacker-configured AP.
[0044] In light of the above problems, this application proposes a wireless communication solution. If the SSID in the first frame transmitted by an access point is an SSID that a station has previously connected to, the station can determine whether the access point is being impersonated by another device based on the identity information carried in the first frame. This can resolve the risk of user privacy leakage caused by a "spoofed AP" attack. Alternatively, if the SSID in the first frame transmitted by an access point is an SSID that a station has previously connected to, the station can associate with the access point based on the identity information carried in the first frame. This can improve the security of the process in which a station associates with an access point.
[0045] In order to facilitate understanding of the technical solutions of the embodiments of the present application, the technical solutions of the present application will be described in detail below through specific embodiments. Hereinafter, the related arts can be arbitrarily combined with the technical solutions of the embodiments of the present application as alternatives, and all of them fall within the protection scope of the embodiments of the present application. The embodiments of the present application include at least part of the following contents:
[0046] 2 is a flowchart illustrating a wireless communication method 200 according to an embodiment of the present application. As shown in FIG. 2, the wireless communication method 200 may include at least part of the following contents:
[0047] S210: The access point transmits a first frame, the first frame including identity information, the identity information being determined based on first secret information and time information of the access point.
[0048] S220: The station receives the first frame.
[0049] S230: If the SSID in the first frame is an SSID that the station has connected to before, the station determines whether the access point is being impersonated by another device based on the station's time information, the first secret information, and the identity information, or the station associates with the access point based on the station's time information, the first secret information, and the identity information.
[0050] That is, in an embodiment of the present application, if the SSID in the first frame is an SSID that the station has previously connected to, the identity information carried in the first frame is used by the station to determine whether the access point is being impersonated by another device, or the identity information carried in the first frame is used by the station to associate with the access point.
[0051] In addition, the identity information in the embodiment of the present application may be called an identity identifier (ID), an identity parameter, or similar names, and the embodiment of the present application is not limited thereto. For example, the identity information may be Verify_ID.
[0052] In the embodiments of the present application, a “field” may be referred to as a “field” or a “subfield.” A field may occupy one or more bytes / octets, or may occupy one or more bits.
[0053] In some embodiments, the first frame includes an identity information element, which includes an identity field, and the identity field is used to indicate the identity information (e.g., Verify_ID).
[0054] In some embodiments, the first frame is a beacon frame, or the first frame is a probe response frame. Of course, the first frame may be other frames, and the embodiments of the present application are not limited thereto.
[0055] Specifically, for example, the format of the identity information element may be shown in FIG. 3. When the value of the element identifier (Element ID) is 255, values 114-255 of the element ID extension are reserved and unused. For example, the identity information element can be represented by Element ID = 255 and Element ID Extension = 114. The identity information element is present in beacon frames and probe response frames. The access point uses identity information (e.g., Verify_ID) to verify the identity of the access point to the station. When a station receives a beacon frame or probe response frame, if the SSID included in the beacon frame or probe response frame is an SSID that the station has previously connected to, the station verifies whether the access point is being impersonated by another device based on the identity information (e.g., Verify_ID) included in the beacon frame or probe response frame before transmitting an association request frame to the access point. If the access point is not being impersonated by another device, the station transmits an association request frame. Otherwise, the station does not transmit an association request frame.
[0056] In some embodiments, the first frame is a beacon frame. The interaction flow of a beacon frame containing identity information (e.g., Verify_ID) can be shown in Figure 4. An AP transmits a beacon frame containing the AP's SSID and identity information (e.g., Verify_ID). The transmitter address (TA) of the beacon frame is the MAC address of the AP, and the receiver address (RA) of the beacon frame is a broadcast address.
[0057] In some embodiments, the first frame is a probe response frame. The interaction flow of a probe response frame including identity information (e.g., Verify_ID) can be shown in Figure 5. A STA sends a probe request frame, and an AP sends a probe response frame including the AP's SSID and identity information (e.g., Verify_ID). The TA of the probe response frame is the MAC address of the AP, and the RA of the probe response frame is the MAC address of the STA.
[0058] In some embodiments, in S230, the station's determining whether the access point is being impersonated by another device based on the station's time information, the first secret information, and the identity information includes: the station determines verification information based on the first secret information and the station's time information; if the verification information is the same as the identity information, the station determines that the access point is not being impersonated by another device; and / or if the verification information is different from the identity information, the station determines that the access point is being impersonated by another device.
[0059] Specifically, for example, the comparison between the verification information and the identity information may be performed in the MAC layer of the station because the MAC layer has high execution efficiency. Of course, the comparison between the verification information and the identity information may be performed in other layers of the station, such as the application layer, and the embodiments of the present application are not limited thereto.
[0060] In some embodiments, if the station determines that the access point is not being spoofed by another device, the station transmits an association request frame to the access point.
[0061] In some embodiments, if the station determines that the access point is being impersonated by another device, the station does not send an association request frame to the access point, or the station ignores the first frame.
[0062] In a wireless local area network (WLAN), when a STA receives a beacon frame or a probe response frame transmitted by an AP, if the SSID included in the beacon frame or the probe response frame belongs to an SSID that the station has previously connected to, the STA may automatically transmit an association request frame to that AP. An attacker exploits this mechanism to set up an AP, which may be called a "spoofed AP." The "spoofed AP" carries an SSID that a user has previously connected to (e.g., the SSID of the user's home WLAN) in the beacon frame or the probe response frame. When the "spoofed AP" receives an association request frame transmitted by a STA, regardless of the MAC address used by the STA, the "spoofed AP" can infer that the user is likely within the coverage area of the "spoofed AP," thereby enabling it to identify and track the specific user.
[0063] In this embodiment, the access point adds identity information (e.g., Verify_ID) to the first frame to verify the identity of the access point to the station. The identity information (e.g., Verify_ID) is determined based on the first secret and the access point's time information. If the SSID in the first frame is an SSID that the station has previously connected to, the station uses the identity information (e.g., Verify_ID) to verify whether the access point is being spoofed by another device, i.e., whether the access point is a "spoof AP," before transmitting an association request frame. This solves the risk of user privacy leakage caused by a "spoof AP" attack, and is easy to implement because the increased signaling overhead is relatively small and the impact on system throughput is minimal.
[0064] In some embodiments, in S230, the station associating with the access point based on the station's time information, the first secret, and the identity information includes: the station determines verification information based on the first secret and the station's time information; if the verification information is the same as the identity information, the station associates with the access point by directly sending an association request frame; and / or if the verification information is different from the identity information, the station associates with the access point by initial access.
[0065] Specifically, for example, the comparison between the verification information and the identity information may be performed in the MAC layer of the station because the MAC layer has high execution efficiency. Of course, the comparison between the verification information and the identity information may be performed in other layers of the station, such as the application layer, and the embodiments of the present application are not limited thereto.
[0066] In some embodiments, the verification information differs from the identity information if the access point performs a system reset, i.e., the verification information differs from the identity information may be due to the access point performing a system reset.
[0067] Alternatively, the verification information may differ from the identity information due to a time out of sync between the station and the access point.
[0068] Specifically, if the AP performs an operation such as a system reset, the AP and STA will lose time synchronization. In this case, the STA will treat the actual AP that it has previously connected to as an unconnected AP, and will no longer automatically connect to the AP. If the user needs to connect to the AP, they can manually click the network name to reconnect after confirming the security (the same workflow as connecting to an AP for the first time).
[0069] In this embodiment, if the SSID in the first frame transmitted by the access point is an SSID that the station has previously connected to, the station can associate with the access point based on the identity information carried in the first frame. This improves the security of the process in which the station associates with the access point. Specifically, for example, if the access point performs a system reset or if the station and the access point are not time-synchronized, the verification information differs from the identity information. In this case, the station can associate with the access point through initial access. Alternatively, for example, if the verification information is the same as the identity information, the station can associate with the access point by directly transmitting an association request frame.
[0070] In some embodiments, the time information of the access point is determined based on the system time of the access point and the time interval at which the access point updates the identity information.
[0071] The system time of an access point is the system time when the access point identifies the identity information.
[0072] Specifically, for example, the current system time T ap_now is T ap_now =[D:H:M:S] AP D represents the date, H represents the hour, M represents the minute, and S represents the second.
[0073] Optionally, the access point sets its system time based on the current time obtained from a universal time server.
[0074] In some embodiments, the time interval at which the access point updates the identity information may be specified by the access point, or may be promised by a protocol, or may be specified by negotiation between the station and the access point. Optionally, to avoid a situation where the time interval at which the access point updates the identity information is too long and an attacker has enough time to directly copy the identity information and apply it to a "spoofed AP," the value of the time interval at which the access point updates the identity information should be small, for example, within the time range of [1, 2047] (unit: seconds (s)).
[0075] In some embodiments, if the time interval at which an access point updates its identity information is less than 60 seconds, the time information of the access point is determined based on Equation (1).
number
[0076] In some embodiments, if the time interval at which an access point updates its identity information is 60 seconds or more, the time information of the access point is determined based on Equation (2).
number
[0077] In some embodiments, the access point determines the identity information based on the following equation:
number
[0078] Specifically, for example, the algorithm corresponding to the hash calculation in the above equation 3 may be Secure Hash Algorithm 2 (SHA-2) or Secure Hash Algorithm 3 (SHA-3).
[0079] In some embodiments, the m bits are m bits truncated in a first order from the result of HASH(X).
[0080] In some embodiments, the first order is front to back, or the first order is back to front.
[0081] Specifically, for example, HASH(X) 16 represents a 16-bit truncation from the result of HASH(X). For example, the 16 bits may be 16 bits truncated backward from the 0th bit, or 16 bits may be 16 bits truncated forward from the last bit, or 16 bits may be 16 bits truncated forward or backward from the xth bit, where x may be agreed upon by the protocol or specified by negotiation between the station and the access point.
[0082] In some embodiments, the station's time information is determined based on the station's system time and the time interval at which the access point updates the identity information.
[0083] Specifically, for example, the current system time T STA_now is T STA_now =[D:H:M:S] STA D represents the date, H represents the hour, M represents the minute, and S represents the second.
[0084] Optionally, the station sets its system time based on the current time obtained from a universal time server.
[0085] In some embodiments, a STA may locally maintain a list as shown in Table 1. The first column of the list is the SSID of the AP with which the STA has associated, and the second column of the list is the time interval at which the AP with which the STA has associated updates its identity information (e.g., Verify_ID).
[0086] [Table 1]
[0087] In some embodiments, if the time interval at which the access point updates the identity information is less than 60 seconds, the station's time information is determined based on the following equation:
number
[0088] In some embodiments, if the time interval at which the access point updates the identity information is 60 seconds or more, the station's time information is determined based on the following equation:
number
[0089] In some embodiments, if the error between the system time of the station and the system time of the access point has a significant impact on the time information used to calculate the identity information (for example, if the time interval at which the access point updates the identity information is 10 seconds and the error is 5 seconds), the time information of the station is determined based on the system time of the station, the time interval at which the access point updates the identity information, and the error value between the system time of the station and the system time of the access point.
[0090] Optionally, the error value is determined based on the system time of the station and the system time of the access point, that is, after the station obtains the system time of the access point, the station can determine the error value based on the system time of the station and the system time of the access point.
[0091] Specifically, for example, the error value (unit: seconds) between the system time of the station and the system time of the access point is +1, that is, the system time of the station is 1 second earlier than the system time of the access point.
[0092] Specifically, for example, the error value (unit: seconds) between the system time of the station and the system time of the access point is -5, that is, the system time of the station is 5 seconds slower than the system time of the access point.
[0093] In some embodiments, a STA may locally maintain a list as shown in Table 2. The first column of the list is the SSID of an AP with which the STA has been associated, the second column is the error value between the system time of the STA and the system time of an AP with which the STA has been associated, and the third column is the time interval at which an AP with which the STA has been associated updates its identity information (e.g., Verify_ID).
[0094] [Table 2]
[0095] In some embodiments, if the time interval at which the access point updates the identity information is less than 60 seconds, the station's time information is determined based on the following equation:
number
[0096] In some embodiments, if the time interval at which the access point updates the identity information is 60 seconds or more, the station's time information is determined based on the following equation:
number
[0097] In some embodiments, the station determines the verification information based on the following number 8:
number
[0098] In some embodiments, the m bits are m bits truncated in a first order from the result of HASH(X).
[0099] In some embodiments, the first order is front to back, or the first order is back to front.
[0100] Specifically, for example, HASH(X) 16 represents a 16-bit truncation from the result of HASH(X). For example, the 16 bits may be 16 bits truncated backward from the 0th bit, or 16 bits may be 16 bits truncated forward from the last bit, or 16 bits may be 16 bits truncated forward or backward from the xth bit, where x may be agreed upon by the protocol or specified by negotiation between the station and the access point.
[0101] In some embodiments, before the station receives the first frame, the station receives a second frame transmitted by the access point after initial access to the access point, the second frame including at least one of a time interval during which the access point updates the identity information and a system time of the access point.
[0102] In some embodiments, the second frame is a management frame, or the second frame is a control frame. Of course, the second frame may be other frames, and the embodiments of the present application are not limited thereto.
[0103] In some embodiments, the second frame includes a first time presence field and a second time presence field, the first time presence field being used to indicate whether the first time field is present in the second frame, and the second time presence field being used to indicate whether the second time field is present in the second frame. The first time field is used to indicate the time interval at which the access point updates the identity information, and the second time field is used to indicate the system time of the access point.
[0104] Optionally, the first-time presence field occupies 1 bit. For example, a value of 1 in the first-time presence field indicates that the first-time field is present in the second frame, and a value of 0 in the first-time presence field indicates that the first-time field is not present in the second frame. As another example, a value of 0 in the first-time presence field indicates that the first-time field is present in the second frame, and a value of 1 in the first-time presence field indicates that the first-time field is not present in the second frame.
[0105] Optionally, the second time presence field occupies 1 bit. For example, a value of 1 in the second time presence field indicates that the second time field is present in the second frame, and a value of 0 in the second time presence field indicates that the second time field is not present in the second frame. As another example, a value of 0 in the second time presence field indicates that the second time field is present in the second frame, and a value of 1 in the second time presence field indicates that the second time field is not present in the second frame.
[0106] In some embodiments, the time interval at which the access point updates the identity information and / or the access point's system time included in the second frame are encrypted by the access point, specifically by a secret value specified in negotiation between the station and the access point.
[0107] In some embodiments, the first secret is a secret value shared between the access point and a station that has associated with the access point.
[0108] Specifically, for example, the second frame is a management frame. The frame format of the management frame may be shown in FIG. 6. The management frame is an action frame. Since the values "30 to 125" of the action category field in the action frame are reserved, in this embodiment, a value (e.g., "32") is selected from the values "30 to 125" and displayed. When the first time present field is set to "1," this indicates that the first time field is present later. When the first time present field is not set to "1," this indicates that the first time field is not present later. The value of the first time field indicates the time interval at which the access point changes its identity information (Verify_ID). In the first time field, the first 11 bits are valid, and the last 5 bits are unused and reserved. The value range of Time1 is 1 to 2047, and the unit of Time1 is seconds. A Time2 Present field value of "1" indicates that a Time2 field follows. A Time2 Present field value not set to "1" indicates that a Time2 field does not follow. The value of Time2 is the access point's system time, with the first byte / octet representing the hour value, the second byte / octet representing the minute value, and the third byte / octet representing the second value.
[0109] In some embodiments, the first secret is agreed upon by a protocol, or the first secret is specified by negotiation between the station and the access point, or the first secret is set by the access point.
[0110] In some embodiments, the first secret is a preshared key (PSK) or a simultaneous authentication of equals (SAE) key.
[0111] In some embodiments, the first secret is a key derived from a PSK or an SAE key.
[0112] Specifically, after a STA accesses an AP for the first time, the STA negotiates a secret value IV with the AP. The secret value IV may be a network key (e.g., a PSK or SAE key) or a secret key derived from the network key (e.g., a PSK or SAE key). All STAs that have previously associated with the AP have the same IV value. After the STA completes secure association with the AP, the AP can encrypt the time interval for changing the identity information (Verify_ID) and the AP's current system time in the management frame shown in FIG. 6 and send the management frame to the STA. Upon receiving the management frame, the STA decrypts it to obtain the time interval for changing the identity information (Verify_ID) and also obtains the AP's current system time directly from the second time (Time2) field in the management frame. Alternatively, the STA can determine an error value based on the STA's current system time and the AP's current system time and maintain the error value in Table 2 above.
[0113] The technical solution of the present application will be described in detail below through specific embodiments. Specifically, when a STA receives a beacon frame or a probe response frame, if the SSID included in the beacon frame or the probe response frame belongs to an SSID that the STA has previously connected to, the STA needs to verify the validity of the beacon frame or the probe response frame based on the identity information (Verify_ID) in the beacon frame or the probe response frame before sending an association request frame to the AP, that is, to verify whether the AP is impersonated by other devices. The steps of the STA verifying the validity of the beacon frame and the probe response frame are as follows:
[0114] Step 1: The STA obtains the current system time. STA_now =[D:H:M:S] STA where D, H, M and S represent the date, hour, minute and second respectively.
[0115] Step 2: Based on the SSID contained in the beacon frame or probe response frame, the STA retrieves the corresponding error value and the time interval T for the AP to update the identity information (eg, Verify_ID) from Table 2 above.
[0116] Step 3: STA STA_now Subtract the error value obtained in step 2 from the time T now’ Get T now’ =[D':H':M':S'].
[0117] JPEG2025539406000015.jpg19163
[0118] Step 5: STA checks the verification information Verify_ID' = HASH(IV || Time STA ) 16The IV is a secret value between the STA and the AP, and if the calculated value of Verify_ID' is equal to the value of Verify_ID in the beacon frame or probe response frame, the STA sends an association request frame; otherwise, the STA does not send an association request frame.
[0119] Therefore, in an embodiment of the present application, the access point adds identity information (e.g., Verify_ID) to the first frame to verify the identity of the access point to the station. The identity information (e.g., Verify_ID) is determined based on the first secret and the access point's time information. If the SSID in the first frame is an SSID that the station has previously connected to, the station verifies whether the access point is being spoofed by another device based on the identity information (e.g., Verify_ID) before transmitting an association request frame. This solves the risk of user privacy leakage due to a "spoof AP" attack. Furthermore, adding only the Verify_ID field to the first frame (e.g., a beacon frame or a probe response frame) solves the "spoof AP" problem. Furthermore, the value of Verify_ID is obtained by hash calculation, which has the advantages of simple implementation and low communication overhead. Furthermore, it is easy to implement, as the additional signaling overhead is relatively small and the impact on system throughput is minimal.
[0120] Alternatively, in an embodiment of the present application, if the SSID in the first frame transmitted by the access point is an SSID to which the station has previously connected, the station can associate with the access point based on the identity information carried in the first frame. This can improve the security of the process in which the station associates with the access point. Specifically, for example, if the access point performs a system reset or if the station and the access point are not time-synchronized, the verification information may differ from the identity information. In this case, the station can associate with the access point through initial access. Alternatively, for example, if the verification information is the same as the identity information, the station can associate with the access point by directly transmitting an association request frame.
[0121] The method embodiments of the present application have been described in detail above with reference to Figures 2 to 6. Hereinafter, the device embodiments of the present application will be described in detail with reference to Figures 7 to 11. Note that the device embodiments correspond to the method embodiments, and for similar descriptions, reference can be made to the method embodiments.
[0122] 7 is a block diagram showing a station 300 according to an embodiment of the present application. As shown in FIG. 7, the station 300 includes a communication unit 310 and a processing unit 320. The communication unit 310 is configured to receive a first frame, the first frame including identity information, and the identity information being determined based on first secret information and time information of an access point. If a service set identifier (SSID) in the first frame is an SSID that the station has previously connected to, the processing unit 320 is specifically configured to determine whether the access point is impersonated by another device based on the station's time information, the first secret information, and the identity information, or to associate with the access point based on the station's time information, the first secret information, and the identity information.
[0123] In some embodiments, the processing unit 320 specifically: determining verification information based on the first secret information and time information of the station; The access point is configured to determine that the access point is not impersonated by another device if the verification information is the same as the identity information, and / or to determine that the access point is impersonated by another device if the verification information is different from the identity information.
[0124] In some embodiments, if the station determines that the access point is not being spoofed by another device, the communication unit 310 is further configured to send an association request frame to the access point.
[0125] In some embodiments, if the station determines that the access point is being impersonated by another device, the station does not send an association request frame to the access point, or the station ignores the first frame.
[0126] In some embodiments, the processing unit 320 specifically: determining verification information based on the first secret information and time information of the station; If the verification information is the same as the identity information, the access point is configured to associate with the access point by directly transmitting an association request frame, and / or if the verification information is different from the identity information, the access point is configured to associate with the access point by initial access.
[0127] In some embodiments, the verification information differs from the identity information if the access point performs a system reset.
[0128] In some embodiments, the processing unit 320 specifically: Verify_ID′=HASH(IV||Time STA ) m The verification information is identified based on the following formula: Verify_ID' represents the verification information, IV represents the first secret information, and Time STA represents the time information of the station, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
[0129] In some embodiments, the identity information is: Verify_ID=HASH(IV||Time AP ) mVerify_ID represents the identity information, IV represents the first secret information, and Time AP represents the time information of the access point, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
[0130] In some embodiments, the m bits are m bits truncated in a first order from the result of HASH(X).
[0131] In some embodiments, the first order is front to back, or the first order is back to front.
[0132] In some embodiments, the station's time information is determined based on the station's system time and the time interval at which the access point updates the identity information.
[0133] JPEG2025539406000016.jpg58162
[0134] In some embodiments, the station's time information is determined based on the station's system time, the time interval at which the access point updates the identity information, and an error value between the station's system time and the access point's system time.
[0135] JPEG2025539406000017.jpg63162
[0136] In some embodiments, the error value is determined based on the system time of the station and the system time of the access point.
[0137] In some embodiments, before the station receives the first frame, the communication unit 310 is further configured to receive a second frame transmitted by the access point after initial access to the access point, the second frame including at least one of a time interval during which the access point updates the identity information and a system time of the access point.
[0138] In some embodiments, the second frame includes a first time presence field and a second time presence field, where the first time presence field is used to indicate whether a first time field is present in the second frame and the second time presence field is used to indicate whether a second time field is present in the second frame, the first time field is used to indicate a time interval at which the access point updates the identity information, and the second time field is used to indicate the system time of the access point.
[0139] In some embodiments, the time interval at which the access point updates the identity information and / or the system time of the access point included in the second frame is encrypted by the access point.
[0140] In some embodiments, the second frame is a management frame, or the second frame is a control frame.
[0141] In some embodiments, the time information of the access point is determined based on the system time of the access point and the time interval at which the access point updates the identity information.
[0142] JPEG2025539406000018.jpg58162
[0143] In some embodiments, the first secret is a secret value shared between the access point and a station that has associated with the access point.
[0144] In some embodiments, the first secret is a pre-shared key (PSK) or an SAE key, or the first secret is a key derived from a PSK or an SAE key.
[0145] In some embodiments, the first secret is agreed upon by a protocol, or the first secret is specified by negotiation between the station and the access point, or the first secret is set by the access point.
[0146] In some embodiments, the first frame includes an identity information element, the identity information element including an identity field, and the identity field is used to indicate the identity information.
[0147] In some embodiments, the first frame is a beacon frame or the first frame is a probe response frame.
[0148] In some embodiments, the communication unit may be a communication interface or transceiver, or an input / output interface of a communication chip or a system-on-chip.The processing unit may be one or more processors.
[0149] It should be noted that the station 300 according to the embodiment of the present application may correspond to the station in the method embodiment of the present application, and the above and other operations and / or functions of each unit in the station 300 are for implementing the corresponding process of the station in the method 200 shown in Fig. 2. For the sake of brevity, they will not be repeated here.
[0150] 8 is a block diagram illustrating an access point 400 according to an embodiment of the present application. As shown in FIG. 8, the access point 400 includes a communication unit 410. The communication unit 410 is configured to transmit a first frame, the first frame including identity information, the identity information being determined based on first secret information and time information of the access point. If the service set identifier (SSID) in the first frame is an SSID that the station has previously connected to, the identity information is used by the station to determine whether the access point is being impersonated by another device, or the identity information is used by the station to associate with the access point.
[0151] In some embodiments, the identity information used by the station to determine whether the access point is being impersonated by another device includes: if the verification information is the same as the identity information, the station determines that the access point is not being impersonated by another device, and / or if the verification information is different from the identity information, the station determines that the access point is being impersonated by another device, and the verification information is determined based on the first secret and time information of the station.
[0152] In some embodiments, if the station determines that the access point is not being spoofed by another device, the communication unit 410 is further configured to receive an association request frame sent by the station.
[0153] In some embodiments, the identity information used by the station to associate with the access point includes: if verification information is the same as the identity information, the station associates with the access point by directly transmitting an association request frame; and / or if verification information is different from the identity information, the station associates with the access point by initial access, where the verification information is determined based on the first secret and time information of the station.
[0154] In some embodiments, the verification information differs from the identity information if the access point performs a system reset.
[0155] In some embodiments, the verification information is determined based on the first secret information and the station's time information by: Verify_ID'=HASH(IV||Time STA ) m Verify_ID' represents the verification information, IV represents the first secret information, and Time STA represents the time information of the station, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
[0156] In some embodiments, the station's time information is determined based on the station's system time and the time interval at which the access point updates the identity information.
[0157] JPEG2025539406000019.jpg56163
[0158] In some embodiments, the station's time information is determined based on the station's system time, the time interval at which the access point updates the identity information, and an error value between the station's system time and the access point's system time.
[0159] JPEG2025539406000020.jpg64162
[0160] In some embodiments, the error value is determined based on the system time of the station and the system time of the access point.
[0161] In some embodiments, after the station initially accesses the access point and before the access point transmits the first frame, the communication unit 410 is further configured to transmit a second frame including at least one of a time interval during which the access point updates the identity information and a system time of the access point.
[0162] In some embodiments, the second frame includes a first time presence field and a second time presence field, where the first time presence field is used to indicate whether a first time field is present in the second frame and the second time presence field is used to indicate whether a second time field is present in the second frame, the first time field is used to indicate a time interval at which the access point updates the identity information, and the second time field is used to indicate the system time of the access point.
[0163] In some embodiments, the time interval at which the access point updates the identity information and / or the system time of the access point included in the second frame is encrypted by the access point.
[0164] In some embodiments, the second frame is a management frame, or the second frame is a control frame.
[0165] In some embodiments, the access point 400 further comprises a processing unit 420. The processing unit 420 performs the following: Verify_ID=HASH(IV||Time AP ) m The identity information is identified based on the formula: Verify_ID represents the identity information, IV represents the first secret information, and Time AP represents the time information of the access point, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
[0166] In some embodiments, the m bits are m bits truncated in a first order from the result of HASH(X).
[0167] In some embodiments, the first order is front to back, or the first order is back to front.
[0168] In some embodiments, the time information of the access point is determined based on the system time of the access point and the time interval at which the access point updates the identity information.
[0169] JPEG2025539406000021.jpg57162
[0170] In some embodiments, the first secret is a secret value shared between the access point and a station that has associated with the access point.
[0171] In some embodiments, the first secret is a pre-shared key (PSK) or an SAE key, or the first secret is a key derived from a PSK or an SAE key.
[0172] In some embodiments, the first secret is agreed upon by a protocol, or the first secret is specified by negotiation between the station and the access point, or the first secret is set by the access point.
[0173] In some embodiments, the first frame includes an identity information element, the identity information element including an identity field, and the identity field is used to indicate the identity information.
[0174] In some embodiments, the first frame is a beacon frame or the first frame is a probe response frame.
[0175] In some embodiments, the communication unit may be a communication interface or transceiver, or an input / output interface of a communication chip or a system-on-chip.The processing unit may be one or more processors.
[0176] It should be noted that the access point 400 according to the embodiment of the present application may correspond to the access point in the method embodiment of the present application, and the above and other operations and / or functions of each unit in the access point 400 are for implementing the corresponding process of the access point in the method 200 shown in Fig. 2, respectively. For the sake of brevity, they will not be repeated here.
[0177] 9 is a schematic diagram showing the structure of a communication device 500 according to an embodiment of the present application. The communication device 500 shown in FIG. 9 includes a processor 510. The processor 510 can implement the method according to the embodiment of the present application by calling and executing a computer program stored in a memory.
[0178] 9, the communication device 500 further includes a memory 520. The processor 510 can call and execute a computer program stored in the memory 520 to implement the method in the embodiment of the present application.
[0179] The memory 520 may be separate and distinct from the processor 510 or may be integrated into the processor 510 .
[0180] 9, the communication device 500 may further include a transceiver 530. The processor 510 may control the transceiver 530 to communicate with other devices. Specifically, the transceiver 530 may transmit information or data to other devices or receive information or data transmitted by other devices.
[0181] The transceiver 530 may include a transmitter and a receiver. The transceiver 530 may further include an antenna. The number of antennas may be one or more.
[0182] In some embodiments, the processor 510 may perform the functions of a processing unit in a station, or the processor 510 may perform the functions of a processing unit in an access point, which will not be repeated here for the sake of brevity.
[0183] In some embodiments, the transceiver 530 may perform the functions of a communication unit in a station, which will not be repeated here for the sake of brevity.
[0184] In some embodiments, the transceiver 530 may perform the functions of a communication unit in an access point, which will not be repeated here for the sake of brevity.
[0185] In some embodiments, the communication device 500 may specifically be an access point in the embodiments of the present application, and may implement the corresponding processes implemented by the access point in each method in the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0186] In some embodiments, the communication device 500 may specifically be a station in the embodiments of the present application, and may implement the corresponding processes implemented by the station in each method in the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0187] Fig. 10 is a schematic diagram showing the structure of an apparatus according to an embodiment of the present application. The apparatus 600 shown in Fig. 10 includes a processor 610. The processor 610 can implement the method according to the embodiment of the present application by calling and executing a computer program stored in a memory.
[0188] 10, the device 600 may further include a memory 620. The processor 610 may call and execute a computer program stored in the memory 620 to implement the method in the embodiment of the present application.
[0189] The memory 620 may be separate and distinct from the processor 610 or may be integrated into the processor 610 .
[0190] In some embodiments, the processor 610 may perform the functions of a processing unit in a station, or the processor 610 may perform the functions of a processing unit in an access point, which will not be repeated here for the sake of brevity.
[0191] In some embodiments, the device 600 may further include an input interface 630. The processor 610 may control the input interface 630 to communicate with other devices or chips. Specifically, the input interface 630 may receive information or data transmitted by other devices or chips. Optionally, the processor 610 may be located within the chip or off-chip.
[0192] In some embodiments, the input interface 630 may implement the functionality of a communication unit in a station, or the input interface 630 may implement the functionality of a communication unit in an access point.
[0193] In some embodiments, the device 600 further includes an output interface 640. The processor 610 can control the output interface 640 to communicate with other devices or chips. Specifically, the output interface 640 can output information or data to other devices or chips. Optionally, the processor 610 can be located on-chip or off-chip.
[0194] In some embodiments, the output interface 640 may implement the functionality of a communication unit in a station, or the output interface 640 may implement the functionality of a communication unit in an access point.
[0195] In some embodiments, the device can be applied to an access point in the embodiments of the present application, and can implement the corresponding processes implemented by the access point in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0196] In some embodiments, the device can be applied to the station in the embodiments of the present application, and can implement the corresponding processes implemented by the station in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0197] In some embodiments, an apparatus according to embodiments of the present application may be a chip, such as a system level chip, a system chip, a chip system, or a system on a chip (SOC).
[0198] 11 is a block diagram illustrating a communication system 700 according to an embodiment of the present application. As shown in FIG. 11, the communication system 700 includes a station 710 and an access point 720.
[0199] The station 710 may be configured to implement the corresponding functions implemented by the station in the above method, and the access point 720 may be configured to implement the corresponding functions implemented by the access point in the above method, which will not be repeated here for the sake of brevity.
[0200] It should be noted that the processor in the embodiments of the present application may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method embodiments may be completed by an integrated logic circuit in the form of hardware of the processor or instructions in the form of software. The processor may be a general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component. The processor may implement or execute various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of the present application may be performed and completed directly by a hardware decoding processor, or may be performed and completed by a combination of hardware and software modules in the decoding processor. The software module can be stored in a storage medium well known in the art, such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, etc. The storage medium is stored in the memory. The processor reads the information in the memory and completes the steps of the above method in cooperation with the processor hardware.
[0201] As can be appreciated, the memory of the embodiments of the present application can be volatile or nonvolatile memory, or can include both volatile and nonvolatile memory. The nonvolatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM) that functions as an external high-speed cache. By way of illustrative, but non-limiting example, various RAMs are available, including static random access memory (static RAM, SRAM), dynamic random access memory (dynamic RAM, DRAM), synchronous dynamic random access memory (synchronous DRAM, SDRAM), double data rate synchronous dynamic random access memory (double data rate SDRAM, DDRSDRAM), enhanced synchronous dynamic random access memory (enhanced SDRAM, ESDRAM), synchronous link dynamic random access memory (synchlink DRAM, SLDRAM), and direct rambus random access memory (direct rambus RAM, DRRAM). It should be noted that the memory of the systems and methods described herein may include, but is not limited to, these and any other suitable types of memory.
[0202] It should be understood that the above memories are exemplary and not limiting. For example, the memories of the embodiments of the present application may be static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous-link dynamic random access memory (synch-link DRAM, SLDRAM), direct rambus random access memory (DRRAM), etc. That is, the memories of the embodiments of the present application may include, but are not limited to, these and any other suitable types of memory.
[0203] An embodiment of the present application further provides a computer-readable storage medium used to store a computer program.
[0204] In some embodiments, the computer-readable storage medium can be applied to the access point of the embodiments of the present application, and the computer program causes a computer to execute corresponding processes implemented by the access point in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0205] In some embodiments, the computer-readable storage medium can be applied to the station of the embodiments of the present application, and the computer program causes a computer to execute corresponding processes implemented by the station in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0206] Embodiments of the present application further provide a computer program product including computer program instructions.
[0207] In some embodiments, the computer program product can be applied to the access point of the embodiments of the present application, and the computer program instructions cause a computer to execute corresponding processes implemented by the access point in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0208] In some embodiments, the computer program product can be applied to the station of the embodiments of the present application, and the computer program instructions cause a computer to perform corresponding processes implemented by the station in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0209] An embodiment of the present application further provides a computer program.
[0210] In some embodiments, the computer program can be applied to the access point of the embodiments of the present application, and when the computer program is executed on a computer, the computer executes corresponding processes implemented by the access point in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0211] In some embodiments, the computer program can be applied to the station of the embodiments of the present application, and when the computer program is executed on a computer, the computer executes the corresponding processes implemented by the station in each method of the embodiments of the present application, which will not be repeated here for the sake of brevity.
[0212] It is clear to those skilled in the art that the present application can be realized by electronic hardware or a combination of computer software and electronic hardware in conjunction with each exemplary unit and algorithm operation described in the embodiments disclosed herein. Whether these functions are performed by hardware or software depends on the specific application of the technical solution and the design constraints. Those skilled in the art can realize the described functions using different methods for each specific application, but these realizations should not be considered beyond the scope of the present application.
[0213] Those skilled in the art can understand that for ease and conciseness of description, the specific operation procedures of the above systems, devices and units can be referred to the corresponding processes of the above method embodiments, which will not be repeated here.
[0214] It should be understood that in some embodiments of the present application, the disclosed systems, devices, and methods may be realized in other forms. For example, the above-described device embodiments are merely illustrative. For example, the division of units represents merely a division of logical functions, and actual implementations may have other division forms. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not implemented. Furthermore, the couplings, direct couplings, and communication connections shown or discussed may be indirect couplings or communication connections through several interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0215] Units described as separate components may or may not be physically separated. Components shown as units may or may not be physical units, i.e., they may be located in one place or may be distributed across multiple network units. Some or all of the units may be selected according to actual needs to achieve the objectives of the technical solution of this embodiment.
[0216] Furthermore, each functional unit according to each embodiment of the present application may be integrated into one processing unit, each unit may exist physically alone, or two or more units may be integrated into one unit.
[0217] The functions may be implemented as software function modules and stored in a computer-readable storage medium when sold or used as an independent product. According to this understanding, an essential part of the technical solution of the present application, a part that contributes to the prior art, or a part of the technical solution may be expressed as a software product. This computer software product is stored in a storage medium and includes a plurality of instructions for causing a computer device (which may be a personal computer, a server, a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The storage medium includes various types of media capable of storing program code, such as a universal serial bus (USB) flash disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0218] The above is only a specific embodiment of the present application, and the scope of protection of the present application is not limited thereto. Any modifications or replacements that can be easily conceived by those skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be determined by the scope of protection of the claims.
Claims
1. 1. A wireless communication method, comprising: receiving, by a station, a first frame, the first frame including identity information, the identity information being determined based on first secret information and access point time information; If the service set identifier (SSID) in the first frame is an SSID that the station has previously connected to, the station determines whether the access point is impersonated by another device based on the time information, the first secret information, and the identity information of the station, or the station associates with the access point based on the time information, the first secret information, and the identity information of the station; Including, A wireless communication method comprising:
2. The step of determining whether the access point is impersonated by another device by the station based on time information, the first secret information, and the identity information of the station includes: determining verification information based on the first secret and time information of the station; If the verification information is the same as the identity information, the station determines that the access point is not impersonated by another device, and / or if the verification information is different from the identity information, the station determines that the access point is impersonated by another device; Including, 2. The method of claim 1 .
3. The method comprises: If the station determines that the access point is not being spoofed by another device, the station transmits an association request frame to the access point.
3. The method of claim 2.
4. The method comprises: If the station determines that the access point is being impersonated by another device, the station does not transmit an association request frame to the access point, or the station ignores the first frame.
3. The method of claim 2.
5. the station associating with the access point based on time information, the first secret information, and the identity information of the station; determining verification information based on the first secret and time information of the station; If the verification information is the same as the identity information, the station associates with the access point by directly sending an association request frame, and / or if the verification information is different from the identity information, the station associates with the access point by initial access; Including, 2. The method of claim 1 .
6. If the access point performs a system reset, the verification information is different from the identity information.
6. The method of claim 5.
7. determining verification information based on the first secret information and time information of the station, The station verifies the ID of the object by using the Verify_ID parameter. STA ) m determining the verification information based on a formula: Verify_ID' represents the verification information, IV represents the first secret information, and Time STA represents the time information of the station, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
7. The method according to any one of claims 2 to 6.
8. The identity information is Verify_ID=HASH(IV||Time AP ) m It is determined based on the formula: Verify_ID represents the identity information, IV represents the first secret information, and Time AP represents the time information of the access point, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
8. The method according to any one of claims 1 to 7.
9. The m bits are m bits cut from the result of HASH(X) in a first order.
9. The method according to claim 7 or 8.
10. The first order is from front to back, or the first order is from back to front.
10. The method of claim 9.
11. The time information of the station is determined based on a system time of the station and a time interval at which the access point updates the identity information.
11. The method according to any one of claims 1 to 10.
12.
13. The time information of the station is determined based on a system time of the station, a time interval at which the access point updates the identity information, and an error value between the system time of the station and the system time of the access point.
11. The method according to any one of claims 1 to 10.
14.
15. the error value is determined based on a system time of the station and a system time of the access point; 15. The method according to claim 13 or 14.
16. Before the station receives the first frame, the method further comprises: receiving, by the station, a second frame transmitted by the access point after an initial access to the access point; the second frame includes at least one of a time interval during which the access point updates the identity information and a system time of the access point; 16. The method according to any one of claims 11 to 15.
17. the second frame includes a first time presence field and a second time presence field; the first time presence field is used to indicate whether a first time field is present in the second frame, and the second time presence field is used to indicate whether a second time field is present in the second frame; the first time field is used to indicate a time interval at which the access point updates the identity information, and the second time field is used to indicate a system time of the access point; 17. The method of claim 16.
18. a time interval at which the access point updates the identity information and / or a system time of the access point included in the second frame is encrypted by the access point; 18. The method according to claim 16 or 17.
19. The second frame is a management frame, or the second frame is a control frame.
19. The method according to any one of claims 16 to 18.
20. The time information of the access point is determined based on a system time of the access point and a time interval at which the access point updates the identity information.
20. The method according to any one of claims 1 to 19.
21.
22. the first secret is a secret value shared between the access point and a station that has previously associated with the access point; 22. The method according to any one of claims 1 to 21.
23. the first secret is a pre-shared key (PSK) or an SAE key, or the first secret is a key derived from a PSK or an SAE key; 23. The method of claim 22.
24. The first secret information is agreed upon by a protocol, or the first secret information is specified by negotiation between the station and the access point, or the first secret information is set by the access point.
22. The method according to any one of claims 1 to 21.
25. the first frame includes an identity information element; The identity information element includes an identity field, and the identity field is used to indicate the identity information.
25. The method according to any one of claims 1 to 24.
26. the first frame is a beacon frame, or the first frame is a probe response frame; 26. The method according to any one of claims 1 to 25.
27. 1. A wireless communication method, comprising: transmitting a first frame from an access point, the first frame including identity information, the identity information being determined based on first secret information and time information of the access point; If the service set identifier (SSID) in the first frame is an SSID that the station has previously connected to, the identity information is used by the station to determine whether the access point is being impersonated by another device, or the identity information is used by the station to associate with the access point. A wireless communication method comprising:
28. The identity information is used by the station to determine whether the access point is being impersonated by another device, If the verification information is the same as the identity information, the station determines that the access point is not impersonated by another device, and / or if the verification information is different from the identity information, the station determines that the access point is impersonated by another device; the verification information is determined based on the first secret information and time information of the station; 28. The method of claim 27.
29. The method comprises: If the station determines that the access point is not spoofed by another device, the access point receives an association request frame transmitted by the station.
29. The method of claim 28.
30. The identity information is used by the station to associate with the access point. If the verification information is the same as the identity information, the station associates with the access point by directly transmitting an association request frame, and / or if the verification information is different from the identity information, the station associates with the access point by initial access; the verification information is determined based on the first secret information and time information of the station; 28. The method of claim 27.
31. If the access point performs a system reset, the verification information is different from the identity information.
31. The method of claim 30.
32. The verification information is identified based on the first secret information and time information of the station, The verification information is Verify_ID'=HASH(IV||Time STA ) m and is determined based on the formula: Verify_ID' represents the verification information, IV represents the first secret information, and Time STA represents the time information of the station, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
32. The method according to any one of claims 28 to 31.
33. The time information of the station is determined based on a system time of the station and a time interval at which the access point updates the identity information.
33. The method according to any one of claims 28 to 32.
34.
35. The time information of the station is determined based on a system time of the station, a time interval at which the access point updates the identity information, and an error value between the system time of the station and the system time of the access point.
33. The method according to any one of claims 28 to 32.
36.
37. the error value is determined based on a system time of the station and a system time of the access point; 37. The method of claim 35 or 36.
38. Before the access point transmits the first frame, the method further comprises: the access point transmitting a second frame after the station's initial access to the access point; the second frame includes at least one of a time interval during which the access point updates the identity information and a system time of the access point; 38. The method according to any one of claims 33 to 37.
39. the second frame includes a first time presence field and a second time presence field; the first time presence field is used to indicate whether a first time field is present in the second frame, and the second time presence field is used to indicate whether a second time field is present in the second frame; the first time field is used to indicate a time interval at which the access point updates the identity information, and the second time field is used to indicate a system time of the access point; 39. The method of claim 38.
40. a time interval at which the access point updates the identity information and / or a system time of the access point included in the second frame is encrypted by the access point; 40. The method of claim 38 or 39.
41. The second frame is a management frame, or the second frame is a control frame.
41. The method according to any one of claims 38 to 40.
42. The method comprises: The access point uses Verify_ID=HASH(IV||Time AP ) m and determining the identity information based on the formula: Verify_ID represents the identity information, IV represents the first secret information, and Time AP represents the time information of the access point, || represents string concatenation, HASH(X) represents a hash operation on parameter X, and HASH(X) m represents the truncation of m bits from the result of HASH(X), where m is a positive integer.
42. The method according to any one of claims 27 to 41.
43. The m bits are m bits cut from the result of HASH(X) in a first order.
43. The method of claim 32 or 42.
44. The first order is from front to back, or the first order is from back to front.
44. The method of claim 43.
45. The time information of the access point is determined based on a system time of the access point and a time interval at which the access point updates the identity information.
45. The method according to any one of claims 27 to 44.
46.
47. the first secret is a secret value shared between the access point and a station that has previously associated with the access point; 47. The method according to any one of claims 27 to 46.
48. the first secret is a pre-shared key (PSK) or an SAE key, or the first secret is a key derived from a PSK or an SAE key; 48. The method of claim 47.
49. The first secret information is agreed upon by a protocol, or the first secret information is specified by negotiation between the station and the access point, or the first secret information is set by the access point.
47. The method according to any one of claims 27 to 46.
50. the first frame includes an identity information element; The identity information element includes an identity field, and the identity field is used to indicate the identity information.
50. The method according to any one of claims 27 to 49.
51. the first frame is a beacon frame, or the first frame is a probe response frame; 51. The method according to any one of claims 27 to 50.
52. A station comprising a communication unit and a processing unit, the communication unit is configured to receive a first frame, the first frame including identity information, the identity information being determined based on first secret information and time information of an access point; If the service set identifier (SSID) in the first frame is an SSID that the station has previously connected to, the processing unit is configured to determine whether the access point is impersonated by another device based on time information, the first secret information, and the identity information of the station, or the processing unit is configured to associate with the access point based on time information, the first secret information, and the identity information of the station. A station characterized by:
53. An access point comprising a communication unit, the communication unit is configured to transmit a first frame, the first frame including identity information, the identity information being determined based on first secret information and time information of the access point; If the service set identifier (SSID) in the first frame is an SSID that the station has previously connected to, the identity information is used by the station to determine whether the access point is being impersonated by another device, or the identity information is used by the station to associate with the access point. An access point characterized by:
54. A station comprising a processor and a memory, the memory is configured to store a computer program, and the processor is configured to call and execute the computer program stored in the memory to cause the station to perform the method of any one of claims 1 to 26. A station characterized by:
55. 1. An access point comprising a processor and a memory, The memory is configured to store a computer program, and the processor is configured to call and execute the computer program stored in the memory to cause the access point to perform the method of any one of claims 27 to 51. An access point characterized by:
56. A chip comprising a processor, The processor is configured to call and execute a computer program stored in the memory to cause the device equipped with the chip to perform the method according to any one of claims 1 to 26. A chip characterized by:
57. A chip comprising a processor, The processor is configured to call and execute a computer program stored in the memory to cause the device equipped with the chip to perform the method according to any one of claims 27 to 51. A chip characterized by:
58. 1. A computer-readable storage medium, comprising: The computer-readable storage medium is configured to store a computer program, which, when executed, performs the method of any one of claims 1 to 26. A computer-readable storage medium comprising:
59. 1. A computer-readable storage medium, comprising: The computer-readable storage medium is configured to store a computer program, which, when executed, performs the method of any one of claims 27 to 51. A computer-readable storage medium comprising:
60. 1. A computer program product comprising computer program instructions, The computer program instructions, when executed, perform the method of any one of claims 1 to 26.
1. A computer program product comprising:
61. 1. A computer program product comprising computer program instructions, When the computer program instructions are executed, the method of any one of claims 27 to 51 is performed.
1. A computer program product comprising:
62. A computer program comprising: When the computer program is executed, the method according to any one of claims 1 to 26 is carried out. A computer program characterized by:
63. A computer program comprising: When the computer program is executed, the method according to any one of claims 27 to 51 is carried out. A computer program characterized by: