Key determination method, storage medium, and electronic apparatus
By negotiating the determination of the target AP's target key in the Wi-Fi Mesh network, the network delay problem of terminals when switching Mesh nodes is solved, and faster switching time and better user experience are achieved.
Patent Information
- Application Number
- PCT/CN2024/120128
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-10-30
- Filing Date
- 2024-09-20
- Publication Date
- 2025-05-08
AI Technical Summary
In Wi-Fi Mesh network, the terminal needs to negotiate the key with the target node when switching the Mesh node, resulting in network delay and user experience problems.
The target key of the target AP is determined through the first AP through negotiation with the mobile terminal, so that the mobile terminal does not need to conduct key negotiation when switching to the target AP.
It reduces the key negotiation time when terminals switch between APs, reduces network delay, and improves user experience.
Smart Images

Figure CN2024120128_08052025_PF_FP_ABST
Abstract
Description
Key determination method, storage medium and electronic device
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This disclosure is based on Chinese patent application CN202311435973.3, filed on October 30, 2023, entitled “Key determination method, storage medium and electronic device”, and claims the priority of the patent application, and all the contents disclosed therein are incorporated into this disclosure by reference. Technical Field
[0003] The present disclosure relates to the field of communications, and in particular to a key determination method, a storage medium, and an electronic device. Background Art
[0004] One of the most important goals of a Wireless Fidelity (Wi-Fi) mesh network (Mesh network) is to extend wireless coverage. When a wireless terminal moves within the coverage area of a Mesh network, it must switch between different Mesh nodes. However, each time a terminal switches between Mesh nodes, it must negotiate a key with the new node. This can lengthen the switching time and make the terminal susceptible to network latency issues, such as game lag and video stuttering.
[0005] Summary of the Invention
[0006] The embodiments of the present disclosure provide a key determination method, a storage medium, and an electronic device to at least solve the problem of a terminal performing Mesh node switching in a Mesh network in the related art.
[0007] According to one embodiment of the present disclosure, a key determination method is provided, comprising: when a mobile terminal joins a wireless mesh network, instructing a target wireless access point (AP) in the mesh network to negotiate with the mobile terminal through a first AP to determine a corresponding target key; wherein the first AP is an AP in the mesh network that currently establishes a communication connection with the mobile terminal, and the target key corresponding to the target AP node is a key used when the target AP communicates with the mobile terminal.
[0008] According to another embodiment of the present disclosure, a key determination method is also provided, including: when a mobile terminal joins a Mesh network, determining a target key corresponding to the target AP through negotiation between a first AP and a target AP in the Mesh network; wherein, the first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key is the key used when the mobile terminal communicates with the target AP.
[0009] According to another embodiment of the present disclosure, a computer-readable storage medium is provided, in which a computer program is stored. The computer program is configured to execute the steps of any one of the above method embodiments when running.
[0010] According to another embodiment of the present disclosure, an electronic device is provided, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any one of the above method embodiments. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] FIG1 is a schematic diagram of a hardware structure block diagram of a mobile terminal according to a key determination method according to an embodiment of the present disclosure;
[0012] FIG2 is a schematic diagram of the timing of Wi-Fi connection between a mobile terminal and an AP node;
[0013] FIG3 is a schematic diagram of a scenario according to an embodiment of the present disclosure;
[0014] FIG4 is a flow chart of a key determination method according to an embodiment of the present disclosure;
[0015] FIG5 is a schematic diagram of a scenario according to another embodiment of the present disclosure;
[0016] FIG6 is a timing diagram of roaming control right negotiation between a mobile terminal and a Mesh network according to an embodiment of the present disclosure;
[0017] FIG7 is a flow chart of a key determination method according to another embodiment of the present disclosure;
[0018] FIG8 is a flow chart of a key determination method according to another embodiment of the present disclosure;
[0019] FIG9 is a schematic diagram of a user interface according to an embodiment of the present disclosure;
[0020] FIG10 is a schematic block diagram of a key determination device according to an embodiment of the present disclosure;
[0021] FIG11 is a schematic block diagram of a key determination device according to another embodiment of the present disclosure;
[0022] FIG12 is a schematic block diagram of a key determination device according to another embodiment of the present disclosure;
[0023] FIG13 is a schematic structural block diagram of a key determination system according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0024] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.
[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.
[0026] The method embodiments provided in the embodiments of the present disclosure can be executed in a mobile terminal, a computer terminal, or a similar computing device. Taking operation on a mobile terminal as an example, FIG1 is a schematic block diagram of the hardware structure of a mobile terminal according to a key determination method of an embodiment of the present disclosure. As shown in FIG1 , the mobile terminal may include one or more (only one is shown in FIG1 ) processors 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor (Central Processing Unit, MCU) or a programmable logic device (Field Programmable Gate Array, FPGA)) and a memory 104 for storing data, wherein the mobile terminal may also include a transmission device 106 and an input / output device 108 for communication functions. It will be understood by those skilled in the art that the structure shown in FIG1 is merely illustrative and does not limit the structure of the mobile terminal. For example, the mobile terminal may also include more or fewer components than shown in FIG1 , or have a configuration different from that shown in FIG1 .
[0027] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the key determination method in the embodiment of the present disclosure. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, implementing the above-mentioned method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely located relative to the processor 102, and these remote memories can be connected to the mobile terminal via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0028] The transmission device 106 is used to receive or send data via a network. A specific example of the aforementioned network may include a wireless network provided by the mobile terminal's communications provider. In one embodiment, the transmission device 106 includes a network interface controller (NIC), which can be connected to other network devices via a base station to enable communication with the Internet. In another embodiment, the transmission device 106 may be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0029] For a better understanding, the following is a brief description of the relevant technologies:
[0030] Figure 2 illustrates the series of interactions involved in establishing a Wi-Fi connection between a mobile terminal and an AP. It should be noted that these interactions can all be completed over the air. The "start 4-way handshake" and "start group handshake" processes in Figure 2 are the installation of encryption keys on the wireless access point (AP) and wireless LAN terminal (STA), respectively. These keys are used to encrypt 802.11 data packets. Only after key installation can IP address allocation, Transmission Control Protocol (TCP) / User Datagram Protocol (UDP) communication, and other services be performed.
[0031] It's important to note that three 802.11 protocols (802.11k, 802.11v, and 802.11r) are all related to roaming, focusing on different aspects. 802.11k focuses on acquiring air interface environment information, providing data support for roaming decision algorithms; 802.11v focuses on roaming control, specifically implementing and guiding roaming operations; and 802.11r, also known as Fast Transition (FT), is designed to simplify the handshake protocol and improve roaming speeds.
[0032] The current Mesh network has a tree structure. There is only one device in the entire network, called the controller (i.e., the manager of the Mesh network), which is generally located at the root node of the tree. The other nodes are called agents (i.e., the executors of the Mesh network). The controller is the manager of the network, and the other nodes are managed.
[0033] It should be noted that the current common roaming process can be described as follows:
[0034] 1. Connect your mobile phone to any node in the Wi-Fi Mesh network and start data services (voice / video, etc.).
[0035] 2. The mobile phone starts to move within the coverage area of the Mesh network.
[0036] 3. At this time, the mobile phone itself chooses whether to disconnect from a hotspot and connect to another hotspot based on the threshold value.
[0037] There are two defects in the above switching process:
[0038] (1) The handover threshold of the mobile phone itself is often different from the handover threshold of the Mesh network. When the mobile phone independently determines whether to handover, it can only consider fewer external factors;
[0039] (2) When using 802.11k switching, each time the mobile phone reconnects to a new hotspot (i.e., the AP in the Mesh network), it needs to renegotiate the installation key. The entire connection process will take longer, which is reflected in the user's perception as game delays, video freezes, etc.
[0040] It should be noted that Figure 3 illustrates a scenario diagram of the present disclosure. A mesh network can be composed of several routers (APs). As shown in Figure 3, there is a controller (i.e., the main AP in the mesh network) and two agents. Data is exchanged within the mesh network using the 1905 protocol. A mobile terminal can be connected to Agent 1, and the messages exchanged between the mobile terminal and Agent 1 are messages defined by the 802.11 protocol.
[0041] In this embodiment, a key determination method running on a Mesh network is provided. FIG4 is a flow chart of the key determination method according to an embodiment of the present disclosure. As shown in FIG4 , the flow may include the following step S402:
[0042] Step S402: When the mobile terminal joins a wireless mesh network, instruct a target wireless access point AP in the mesh network to negotiate with the mobile terminal through a first AP to determine a corresponding target key.
[0043] It should be noted that the first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key corresponding to the target AP node is the key used when the target AP communicates with the mobile terminal.
[0044] It should be noted that the first AP may be a controller in the Mesh network or another Mesh node. If the mobile terminal currently establishes a communication connection with the controller in the Mesh network, the first AP is the controller in the Mesh network.
[0045] It should be noted that, during the process of establishing a communication connection between the target AP and the mobile terminal, the corresponding target key needs to be determined. After the target AP establishes a communication connection with the mobile terminal, when transmitting data between the target AP and the mobile terminal, the corresponding target key needs to be used to encrypt the transmitted data.
[0046] Through the above steps, after the mobile terminal joins the wireless mesh Mesh network, the target AP in the Mesh network will negotiate with the mobile terminal through the first AP to determine the corresponding target key, so that after the mobile terminal switches from the first AP to the target AP, there is no need to negotiate the key again, thereby solving the problem of the terminal switching the Mesh node.
[0047] The execution subject of the above step S402 may be a master AP in the Mesh network (ie, a controller in the Mesh network), etc., but is not limited thereto.
[0048] In an exemplary embodiment, before the above-mentioned step S402, the method may further include: determining any AP in the Mesh network other than the first AP as the target AP; or determining an AP in the Mesh network other than the first AP whose distance from the mobile terminal is less than a preset distance as the target AP; or determining an AP designated by the target object in the Mesh network as the target AP.
[0049] That is to say, the controller (i.e., the main AP) can send key pre-negotiation requests to all online agents. In special cases, the controller will send key pre-negotiation requests for one or several specific agents. The judgment basis can be the agents closest to the mobile phone or several agents specified by the user.
[0050] It should be noted that, before determining the target AP, the master AP needs to first determine the network structure of the Mesh network, and then determine the target AP for key pre-negotiation with the mobile terminal based on the network structure.
[0051] In an exemplary embodiment, step S402 may include: sending a key pre-negotiation instruction to the target AP, wherein the key pre-negotiation instruction is used to instruct the target AP to send a first message to the mobile terminal through a first AP, and generate a reference key based on a first random number, a pre-shared key, and a second random number generated by the mobile terminal in the second message when a second message sent by the mobile terminal is obtained through the first AP; sending a third message to the mobile terminal through the first AP, and determining the reference key as the target key when a fourth message sent by the mobile terminal in response to the third message is obtained through the first AP;
[0052] Among them, the first message carries at least a first random number generated by the target AP, the pre-shared key is a key pre-negotiated between the target AP and the mobile terminal, and the fourth message is used to instruct the mobile terminal to successfully decrypt the third message using the reference key generated by itself; after obtaining the first message, the mobile terminal generates the reference key based on the first random number, the pre-shared key and the second random number.
[0053] That is, after receiving the key pre-negotiation instruction, the target AP may need to pre-negotiate the key with the mobile terminal. In an exemplary embodiment, the target AP generates a first random number and sends the first random number to the mobile terminal via a first message; after receiving the first message, the mobile terminal generates a second random number accordingly and sends the second random number to the target AP via a second message; the target AP and the mobile terminal respectively generate a reference key based on the first random number, the second random number, and the pre-shared key; in order to verify the correctness of the reference key, the target AP encrypts a message using the reference key and sends it to the mobile terminal. If the mobile terminal successfully decrypts the message using the reference key generated by itself, it indicates that the target key has been successfully negotiated and determined, and the reference key is then determined as the target key.
[0054] The following is a detailed explanation of the "start 4-way handshake" in Figure 2. The pre-installed key node (i.e., the target AP) first sends a 1 / 4 eapol key 802.11i message. In order to be transmitted in the Mesh network, this message needs to be encapsulated into a 1905 protocol message and transmitted to the node currently connected to the mobile terminal (i.e., the first AP). The 1905 encapsulation is removed at the node and sent to the mobile terminal. After receiving the message, the mobile terminal confirms that this is a pre-installed key behavior, uses the message content to generate its own key, saves it separately, and then sends 2 / 4 eapol key 802.11i to the directly connected node (i.e., the first AP). The directly connected node encapsulates it into a 1905 message and transmits it to the pre-installed key node. The pre-installed key node also generates its own key. The encapsulation and decapsulation process of 3 / 4 and 4 / 4 EAPOL is the same as above. It should be noted that EAPOL stands for Extensible Authentication Protocol over LAN (EAPOL for short). EAPOL is a network authentication protocol used for identity authentication and key exchange in wireless local area networks (WLANs).
[0055] In an exemplary embodiment, the target AP interacts with the first AP via a first protocol, and the first AP interacts with the mobile terminal via a second protocol, wherein the first protocol is the protocol used for communication between APs in the Mesh network, and the second protocol is the protocol used for communication between the AP and the mobile terminal.
[0056] As an optional example, the first protocol is the 1905 protocol and the second protocol is the 802.11 protocol. All messages exchanged between the target AP and the mobile terminal need to pass through the first AP. That is, the target AP uses the 1905 protocol to send messages to the first AP. The first AP then converts the 1905 protocol messages into 802.11 protocol messages and sends them to the mobile terminal. Similarly, the mobile terminal uses the 802.11 protocol to send messages to the first AP. The first AP then converts the 802.11 protocol messages into 1905 protocol messages and sends them to the target AP. In other words, the first AP needs to convert 1905 messages into 802.11 messages.
[0057] In an exemplary embodiment, after step S402, the method may further include: after a preset time, instructing the target AP to re-negotiate with the mobile terminal to determine the corresponding target key, so that the target AP uses the newly determined target key to update the original target key.
[0058] That is to say, in this embodiment, after the target key is successfully installed, the Mesh master node will set a refresh period for the target key, and will re-initiate the key update operation in each refresh period, replacing the old key with the negotiated new key to ensure the security of the key.
[0059] In an exemplary embodiment, after step S402, the method may further include: instructing the target AP to delete the target key determined through negotiation with the mobile terminal when detecting that the mobile terminal leaves the Mesh network.
[0060] As an optional example, when the Mesh master node finds that the mobile terminal has left the Mesh network, it may request the target AP to delete all key information about the mobile terminal (the key information includes the target key) after a timeout period.
[0061] In an exemplary embodiment, the method may further include the following steps S11-S12:
[0062] Step S11: When the mobile terminal joins the wireless mesh network, a first request message is sent to the mobile terminal through the first AP, wherein the first request message is used to request roaming control rights of the mobile terminal;
[0063] Step S12: determining whether the Mesh network has the roaming control right for the mobile terminal according to the first response message sent by the mobile terminal in response to the first request message.
[0064] It should be noted that since the switching threshold of the mobile terminal itself and the switching threshold of the Mesh network are often different, when the mobile terminal determines whether to switch alone, it can only consider fewer external factors; while the Mesh master node will consider more external factors at the same time when considering whether to switch, such as topology results, the quality of wireless links between nodes, etc. Therefore, the switching judgment made by the Mesh master node should be more comprehensive and accurate. In this embodiment, the Mesh master node can send a first request message to the mobile terminal to request roaming control rights of the mobile terminal.
[0065] To better understand the above steps S11-S12, the following description is made with reference to FIG5 and FIG6 , which may include the following steps:
[0066] Step 1: The Controller sends a control request message of the 1905 protocol to Agent 1 (i.e., the first AP);
[0067] The 1905 message sent by the Controller should include the following fields:
[0068] sourceMacAddress:XX:XX:XX:XX:XX:XX:XX controller address sending the request;
[0069] targetMacAddress:XX:XX:XX:XX:XX:XX:XX mobile phone address requesting control;
[0070] action: 0 / 1, where 0: request to give up roaming control rights; 1: request to obtain roaming control rights;
[0071] Step 2: After receiving the control request message, Agent 1 removes the 1905 packet header information, extracts the TargetMacAddress and Action values, adds the header information of the 802.11 action frame, and sends the message to the mobile terminal (such as a mobile phone).
[0072] Step 3: After receiving the action frame, the mobile terminal checks the targetMacAddress and action, and responds to Agent 1 with a control request message using the 802.11 protocol based on the following conditions:
[0073] (1) If the mobile phone agrees to the controller's request: When action is 1, it temporarily shuts down its roaming-related logic and does not actively roam; if action is 0, it restores its roaming-related logic. It replies with an 802.11 action ack frame and the execution result is 0 (indicating success).
[0074] (2) If the mobile phone rejects the controller's request, it directly returns an 802.11 action ack result of 1 (indicating rejection).
[0075] Step 4: After receiving the 802.11 action Ack frame from the mobile phone, Agent 1 removes the 802.11 frame header information, adds the 1905 header information, and feeds the result back to the Controller.
[0076] In an exemplary embodiment, the method may further include steps S21-S23:
[0077] Step S21: When it is determined according to the first response message that the Mesh network has roaming control for the mobile terminal, and when it is detected that the signal strength of the signal sent by the mobile terminal is less than a first threshold and / or the signal quality of the signal is less than a second threshold, a second request message is sent to the mobile terminal, wherein the signal quality is used to indicate the stability and interference level of the signal, and the second request message is used to request information about wireless networks detected by the mobile terminal in the environment in which it is located;
[0078] Step S22: upon obtaining the wireless network information sent by the mobile terminal, determining a second AP from the Mesh network according to the wireless network information;
[0079] Step S23: Send a handover message to the mobile terminal, wherein the handover message carries the identifier of the second AP, and the handover message is used to instruct the mobile terminal to disconnect the communication connection established with the first AP and establish a communication connection with the second AP.
[0080] That is to say, in this embodiment, when it is determined based on the first response message that the Mesh network has the roaming control right of the mobile terminal, the Mesh network can perform roaming control on the mobile terminal based on the network status of the mobile terminal. Specifically, the Mesh master node will determine the roaming threshold of the mobile terminal. If the switching condition is met, the Mesh master node will require the mobile terminal to report the surrounding wireless environment / service set identifier (SSID) (through the 802.11k protocol). The Mesh master node searches for a new node suitable for the mobile terminal to switch based on the reported situation. If found, 802.11v is used to guide the mobile terminal to connect to another node, and then the mobile terminal disconnects from the original node and connects to the new node.
[0081] In an exemplary embodiment, after the above-mentioned step S402, the method may further include: in a case where it is determined that the target AP has successfully negotiated with the mobile terminal to determine the corresponding target key, sending an indication message to the target AP, wherein the indication information is used to instruct the target AP to determine whether the third request message carries pre-installation information when obtaining the third request message sent by the mobile terminal, and to send a second response message to the mobile terminal when the third request message carries the pre-installation information and the target AP has the target key; wherein the pre-installation information is used to indicate that the mobile terminal has the target key corresponding to the target AP, the third request message is used to request to establish a communication connection between the mobile terminal and the target AP, and the second response message is used to indicate that the mobile terminal has successfully established a communication connection with the target AP, and the second response message carries indication information for indicating that the target AP has the target key.
[0082] It should be noted that when a mobile terminal switches nodes, it disconnects from the previous node (sending a deauth frame) and then sends an Association request frame to the new node. If the mobile terminal finds that it has already negotiated a key with the target node in advance, it adds a key pre-installation message to the Association request frame, indicating that the mobile terminal is a pre-negotiated mobile phone and selects the corresponding key from the saved keys for installation. If it is found that the target key corresponding to the target AP is not saved, a normal Association request frame is sent.
[0083] After the target AP has pre-negotiated the key with the mobile terminal, if the target AP obtains the Association Request frame sent by the mobile terminal (i.e., the third request message mentioned above), it will first check whether there is key pre-installation information and detect its own saved key. If the check is successful (i.e., there is key pre-installation information in the Association Request frame and the corresponding target key is included in its own saved key), the key installation flag will be returned in the returned Association Response (i.e., the second response message mentioned above).
[0084] After receiving such an Association Response, the mobile terminal no longer attempts the four-way handshake, but directly uses the pre-installed key (i.e., the above-mentioned target key) to encrypt the data and then sends it out for direct data communication; if the Association Response received by the mobile terminal does not contain the key installed flag, the regular four-way handshake operation is started.
[0085] It should be noted that, since the mobile terminal does not need to negotiate a key after switching from the first AP to the target AP, the switching time of the mobile terminal between APs is reduced, thereby reducing the network delay of the mobile terminal.
[0086] It should be noted that this embodiment also provides a key determination method running on a mobile terminal. FIG7 is a flow chart of a key determination method according to another embodiment of the present disclosure. As shown in FIG7 , the flow may include the following step S702:
[0087] Step S702: When the mobile terminal joins the Mesh network, a target key corresponding to the target AP is determined through negotiation between the first AP and the target AP in the Mesh network.
[0088] It should be noted that the first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key is the key used when the mobile terminal communicates with the target AP.
[0089] Through the above steps, after the mobile terminal joins the wireless mesh Mesh network, the mobile terminal will determine the corresponding target key through the first AP and the target AP in the Mesh network, so that after the mobile terminal switches from the first AP to the target AP, there is no need to negotiate the key, which solves the problem of the terminal switching the Mesh node in the Mesh network.
[0090] The execution subject of the above step S702 may be a mobile terminal, etc., but is not limited thereto.
[0091] In an exemplary embodiment, the above-mentioned step S702 may include: when the first AP obtains the first message sent by the target AP for requesting to negotiate with the mobile terminal to determine the corresponding target key, the first AP negotiates with the target AP to determine the target key corresponding to the target AP.
[0092] It should be noted that, after the mobile terminal negotiates with the target AP through the first AP to determine the target key corresponding to the target AP, the mobile terminal will store the target key corresponding to the target AP.
[0093] In an exemplary embodiment, determining the target key corresponding to the target AP through negotiation between the first AP and the target AP may be implemented by the following steps S31-S34:
[0094] Step S31: Generate a second random number;
[0095] Step S32: Generate a reference key based on the first random number, the pre-shared key, and the second random number, and send a second message to the target AP node, wherein the second message carries the second random number, the pre-shared key is a key pre-negotiated between the mobile terminal and the target AP, and the first message carries the first random number generated by the target AP;
[0096] Step S33: When a third message sent by the target AP node is obtained through the first AP, decrypt the third message using the reference key;
[0097] Step S34: When the third message is successfully decrypted, the reference key is determined as the target key, and a fourth message is sent to the target AP, wherein the fourth message is used to instruct the mobile terminal to successfully decrypt the third message using the reference key.
[0098] That is to say, after the target AP obtains the key pre-negotiation instruction, it needs to pre-negotiate the key with the mobile terminal. First, it sends a first message to the mobile terminal (the first message carries the first random number generated by the target AP). After the mobile terminal obtains the first message, it will generate a second random number accordingly, and then send the second random number to the target AP through the second message; then the target AP and the mobile terminal will respectively generate a reference key based on the first random number, the second random number and the pre-shared key. In order to verify the correctness of the reference key, the target AP will use the reference key to encrypt a message and send it to the mobile terminal. If the mobile terminal successfully decrypts the message using the reference key generated by itself, it means that the target key has been successfully negotiated and determined, and the reference key is determined as the target key.
[0099] In an exemplary embodiment, after step S704, the method may further include: when the mobile terminal leaves the Mesh network, deleting the target key corresponding to the target AP in the mobile terminal.
[0100] That is, in this embodiment, when the mobile terminal finally leaves the Mesh network, the mobile terminal will automatically delete the key information of all nodes in the Mesh network.
[0101] In an exemplary embodiment, the method may also include: when a first request message sent by the Mesh network is obtained through the first AP, determining whether the Mesh network is allowed to perform roaming control on the mobile terminal, and sending a first response message to the Mesh network; wherein, the first request message is used to request roaming control rights for the mobile terminal, and the first response message is used to indicate whether the Mesh network has roaming control rights for the mobile terminal.
[0102] As an optional example, after the mobile terminal obtains the first request message, it can display a prompt message "Determine whether to allow the Mesh network to perform roaming control on the mobile terminal" on the display of the mobile terminal, and then when the first instruction is obtained through the display, it is determined that the Mesh network is allowed to perform roaming control on the mobile terminal, and when the second instruction is obtained through the display, it is determined that the Mesh network is not allowed to perform roaming control on the mobile terminal.
[0103] In an exemplary embodiment, after the above-mentioned step S702, the method may further include: in a case where a second request message sent by the Mesh network is obtained through the first AP, detecting the wireless network in the environment where the mobile terminal is located, and sending the information of the detected wireless network to the Mesh network through the first AP, wherein the second request message is a message sent by the Mesh network when it is detected that the signal strength of the signal sent by the mobile terminal is less than a first threshold, and / or the signal quality of the signal is less than a second threshold; in a case where the Mesh network has roaming control rights for the mobile terminal and obtains a switching message sent by the Mesh network through the first AP, disconnecting the communication connection established with the first AP and establishing a communication connection with the target AP, wherein the switching message carries the identifier of the target AP.
[0104] That is to say, in this embodiment, the Mesh master node will determine the roaming threshold of the mobile terminal. If the switching condition is met, the Mesh master node will require the mobile terminal to report the surrounding wireless environment / SSID status (through the 802.11k protocol). Then the Mesh master node will search for a new node suitable for the mobile terminal to switch based on the reported situation. If found, it will use 802.11v to send a switching message to the mobile terminal, guiding the mobile terminal to connect to another node. Then, when the mobile terminal obtains the switching message, it will disconnect the communication connection with the currently connected first AP and request to establish a communication connection with the target AP.
[0105] In an exemplary embodiment, the above-mentioned establishment of a communication connection with the target AP may be implemented by the following steps S41-S42:
[0106] Step S41: Sending a third request message to the target AP, wherein the third request message carries pre-installation information of a target key corresponding to the target AP, wherein the pre-installation information is used to indicate that the mobile terminal has the target key corresponding to the target AP, and the third request message is used to request establishment of a communication connection between the mobile terminal and the target AP;
[0107] Step S42: upon obtaining a second response message sent by the target AP, determining that a communication connection with the target AP is successfully established;
[0108] It should be noted that after obtaining the second response message sent by the target AP, the mobile terminal allows the target key to be used directly to communicate with the target AP. The second response message is the message sent by the target AP when it determines that the third request message carries the pre-installation information and the target AP has the target key.
[0109] It should be noted that when a mobile terminal needs to establish a communication connection with a target AP, it will send an Association Request frame (i.e., the third request message mentioned above) to the target AP. If the mobile terminal finds that it has already negotiated a key with the target AP in advance, it will add a key pre-installation message to the Association Request frame, indicating that the mobile terminal is a pre-negotiated mobile phone and select the corresponding key from the saved keys for installation. If it is found that the target key corresponding to the target AP is not saved, it will send a normal Association Request frame.
[0110] After the target AP has pre-negotiated the key with the mobile terminal, if the target AP receives the Association Request frame sent by the mobile terminal, it will first check whether there is key pre-installation information and detect its own saved key. If the check is successful (that is, there is key pre-installation information in the Association Request frame and the corresponding target key is included in its own saved key), the key installation flag will be returned in the returned Association Response (that is, the above-mentioned second response message).
[0111] After receiving such an Association Response, the mobile terminal no longer attempts the four-way handshake, but directly uses the pre-installed key (i.e., the above-mentioned target key) to encrypt the data and then sends it out for direct data communication; if the Association Response received by the mobile terminal does not contain the key installed flag, the regular four-way handshake operation is started.
[0112] It should be noted that, since the mobile terminal does not need to negotiate a key after switching from the first AP to the target AP, the switching time of the mobile terminal between APs is reduced, thereby reducing the network delay of the mobile terminal.
[0113] It should be noted that this embodiment also provides a key determination method running on the target AP. FIG8 is a flow chart of the key determination method according to another embodiment of the present disclosure. As shown in FIG8 , the flow may include the following step S802:
[0114] Step S802: upon obtaining a key pre-negotiation instruction sent by a master AP in the Mesh network, determining a target key through negotiation between the first AP and the mobile terminal;
[0115] It should be noted that the first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key is the key used by the target AP to communicate with the mobile terminal after establishing a communication connection with the mobile terminal.
[0116] The execution subject of the above step S802 may be a target AP, etc., but is not limited thereto.
[0117] It should be noted that the target AP is any AP other than the first AP in the Mesh network, or an AP other than the first AP in the Mesh network whose distance from the mobile terminal is less than a preset distance, or an AP designated by the target object in the Mesh network.
[0118] Through the above steps, after the mobile terminal joins the wireless mesh Mesh network, the target AP in the Mesh network will negotiate with the mobile terminal through the first AP to determine the corresponding target key, so that after the mobile terminal switches from the first AP to the target AP, there is no need to negotiate the key again, solving the problem of the terminal switching the Mesh node in the Mesh network.
[0119] It should be noted that, since the mobile terminal does not need to negotiate a key after switching from the first AP to the target AP, the switching time of the mobile terminal between APs is reduced, thereby reducing the network delay of the mobile terminal.
[0120] In an exemplary embodiment, step S802 can be implemented in the following manner: sending a first message to the mobile terminal through a first AP, and when a second message sent by the mobile terminal is obtained through the first AP, generating a reference key based on a first random number, a pre-shared key, and a second random number generated by the mobile terminal in the second message; sending a third message to the mobile terminal through the first AP, and when a fourth message sent by the mobile terminal in response to the third message is obtained through the first AP, determining the reference key as the target key; wherein the first message carries at least the first random number generated by the target AP, the pre-shared key is a key pre-negotiated between the target AP and the mobile terminal, and the fourth message is used to instruct the mobile terminal to successfully decrypt the third message using the reference key generated by itself; after obtaining the first message, the mobile terminal generates the reference key based on the first random number, the pre-shared key, and the second random number.
[0121] In an exemplary embodiment, the method may further include: upon obtaining a key renegotiation instruction sent by the master AP, re-negotiating with the mobile terminal to determine a corresponding target key, and updating the original target key with the newly determined target key.
[0122] In an exemplary embodiment, the method may further include: upon obtaining a key deletion instruction sent by the master AP, deleting the target key determined through negotiation with the mobile terminal.
[0123] In an exemplary embodiment, the method may also include: in a case where a third request message sent by the mobile terminal is obtained through the first AP, determining whether the third request message carries pre-installation information, and in a case where the third request message carries the pre-installation information and the target AP has the target key, sending a second response message to the mobile terminal; wherein the pre-installation information is used to indicate that the mobile terminal has the target key corresponding to the target AP, the third request message is used to request to establish a communication connection between the mobile terminal and the target AP, the second response message is used to indicate that the mobile terminal has successfully established a communication connection with the target AP, and the second response message carries indication information for indicating that the target AP has the target key.
[0124] To facilitate understanding of the technical solutions provided by the present disclosure, embodiments of specific scenarios will be described in detail below.
[0125] One of the most important purposes of Wi-Fi Mesh technology is to expand the wireless coverage range. When a wireless terminal moves within the coverage range of the Mesh network, the terminal needs to switch between different Mesh nodes (factors such as the distance, direction, and number of hops between the terminal and the Mesh node need to be considered). On the one hand, the switching process will cause delays, which will affect the user experience of ongoing real-time applications; on the other hand, the AP and STA sides have their own considerations for switching strategies, which leads to different roaming experiences for different terminals. The present disclosure uses a method for pre-negotiation between the terminal and the AP node, which, on the one hand, reduces the delay in the switching process, and on the other hand, unifies the roaming strategies of different terminals, which can improve the user experience when roaming. The method described in the present disclosure can also be used as a part of the supplement to the EasyMesh protocol (Simple Mesh Protocol).
[0126] Optionally, taking a mobile phone as an example, the roaming control negotiation process between the Mesh network and the mobile phone is as follows:
[0127] 1. The mobile phone is connected to the Mesh network, and the Controller is notified of the mobile phone connection;
[0128] 2. The Controller sends a roaming control negotiation request to the mobile phone. It should be noted that this request is sent in the Mesh network using the 1905 protocol. The 802.11 protocol is used from the directly connected node to the mobile phone. When transmitting 802.11 protocol content in the Mesh network, it must be encapsulated using 1905.
[0129] 3. After receiving the roaming control negotiation request, the mobile phone can choose to retain or give up its control rights and report its selection result to the controller.
[0130] The above interaction process is described in detail below with reference to FIG6 :
[0131] (1) The 1905 message sent by the Controller should include the following fields:
[0132] sourceMacAddress:XX:XX:XX:XX:XX:XX:XX controller address sending the request;
[0133] targetMacAddress:XX:XX:XX:XX:XX:XX:XX mobile phone address requesting control;
[0134] action: 0 / 1, where 0: requests to give up roaming control rights; 1: requests to obtain roaming control rights.
[0135] (2) After receiving this message, Agent 1 removes the 1905 packet header information, extracts the TargetMacAddress and Action values, adds the header information of the 802.11 action frame, and sends the message to the mobile phone.
[0136] (3) After receiving the action frame, the mobile phone checks the targetMacAddress and action. If the mobile phone agrees to the controller's request: if action is 1, it temporarily shuts down its roaming-related logic and does not actively roam. If action is 0, it restores its roaming-related logic and replies with an 802.11 action ack frame with an execution result of 0 (indicating success). If the mobile phone rejects the controller's request, it directly returns an 802.11 action ack result of 1 (indicating rejection).
[0137] (4) After receiving the 802.11 action Ack frame (action confirmation frame) from the mobile phone, Agent 1 removes the 802.11 frame header information, adds the 1905 header information, and feeds the result back to the controller.
[0138] Optionally, the key pre-negotiation process between the Mesh network and the mobile phone is as follows:
[0139] 1. The phone connects to any device in the Mesh network (either the controller or the agent) through the entire authentication, association, and key exchange process. At this point, a pair of keys is stored on the phone and the node device.
[0140] 2. The phone's connection event reaches the controller through the mesh network. The controller is informed that a phone has connected to the mesh network for the first time. The communication channel used between mesh nodes is the IEEE 1905 protocol.
[0141] 3. The controller uses the IEEE 1905 protocol to transmit pre-installed keys to all other nodes for newly joined mobile phones. It should be noted that information transmission between Mesh nodes requires the 1905 protocol, while the key negotiation process requires the 802.11i protocol. The following is a description of the four-way handshake process transmitted between Mesh nodes:
[0142] (1) The pre-installed key node first sends a 1 / 4 eapol key 802.11i message. In order to be transmitted in the Mesh network, this message needs to be encapsulated into a 1905 message and transmitted to the node to which the mobile phone is currently connected. The 1905 encapsulation is removed at the node and sent to the mobile phone.
[0143] (2) After receiving the message, the mobile phone confirms that this is a pre-installed key behavior, generates its own key using the message content, saves it separately, and then sends 2 / 4 eapol key 802.11i to the directly connected node, which encapsulates it into 1905 message and transmits it to the pre-installed key node. The pre-installed key node also generates its own key.
[0144] (3) The encapsulation and decapsulation process of 3 / 4 and 4 / 4 eapol process is the same as above.
[0145] It should be noted that after the key exchange, the connections established between the mobile phone and all nodes are different. The only difference is that there is only one actual connection, while all others are virtual connections. The difference lies in which set of keys the mobile phone and router use to exchange.
[0146] 4. When the mobile phone finally leaves the Mesh network, it will automatically delete the key information of all nodes. When the Mesh master node detects that the mobile phone has left the Mesh network, and after a timeout period, the master node requires all other nodes to delete all key information about this mobile phone.
[0147] 5. Each time a set of keys is successfully installed, the Mesh master node sets a refresh cycle for this set of keys. During each refresh cycle, the key update operation will be re-initiated, and the new key will be used to replace the old key to ensure the security of the key.
[0148] 6. By default, the controller will send key pre-negotiation requests to all online agents. In special cases, the controller will send key pre-negotiation requests to one or more specific agents. The basis for the judgment can be the agents closest to the phone or the agents specified by the user.
[0149] It should be noted that after the mobile phone is connected to any Mesh device for the first time, it can already start data services. After that, if the Mesh master node needs to pre-install the key for each node, this action is a background process and will not affect the normal service of the mobile phone.
[0150] Optionally, the roaming key activation process for the Mesh network and mobile phone is as follows:
[0151] 1. After the mobile phone moves, the controller calculates the node it is ready to connect to next, which is called the target node.
[0152] 2. After receiving the roaming command, the mobile phone checks that it has coordinated with the target node and installed the key in advance;
[0153] 3. The phone disconnects from the previous node (sending a deauth frame) and then sends an Association Request frame to the new node. If the phone finds that it has already negotiated a key with the target node, it adds a key pre-installation message to the Association Request frame, indicating that the phone is a pre-negotiated phone and selects the corresponding key from the saved keys to install. If it finds that the target node has not saved a key, it sends a normal Association Request frame.
[0154] 4. After receiving the Association Request frame from the mobile phone, the target node first checks whether there is any key pre-installation information and checks its own saved key. If the check is successful, the key installation flag is returned in the returned Association Response.
[0155] 5. When the mobile phone receives such an Association Response, it no longer attempts the four-way handshake, but directly encrypts the data using the pre-installed key and sends it out, directly conducting data communication; if the Association Response received by the mobile phone does not contain the key installed flag, the regular four-way handshake operation is started.
[0156] Optionally, the user interface on the mobile terminal may be as shown in FIG9 . Two information displays may be added to the access list information sample column: (1) key pre-installed / fast roaming supported; (2) roaming control authority: Mesh AP or terminal.
[0157] It should be noted that in this disclosure, after a mobile phone accesses the network, the Mesh network takes over roaming operations, and the mobile phone's autonomous roaming function can be temporarily disabled through negotiation. When the roaming function is fully taken over by the Mesh AP, more controllable roaming control functions can be achieved: such as more reasonable roaming decisions and more flexible roaming strategies (for example, the roaming range can be limited for specific terminals, or an alarm can be issued if roaming outside a specific range).
[0158] It's important to note that in this disclosure, when a terminal connects to any device in the mesh network via WiFi, the mesh network master node, upon receiving notification of this event, requires all other mesh nodes to connect with the terminal in advance to negotiate a key. This process allows each device in the mesh to store a set of keys specific to the terminal, while the terminal itself stores the corresponding keys for all mesh nodes. When roaming, the terminal only needs to exchange a single Association Request / Response before data transmission can begin, without requiring key generation and installation.
[0159] It should be noted that compared with the existing multi-device key installation solution, the present disclosure uses the 1905 protocol to transmit information in multiple Mesh nodes, and encapsulates and decapsulates the 1905 protocol and the 802.11 protocol on the Mesh device directly connected to the mobile phone.
[0160] It should be noted that the use of the technology in this disclosure can enable the Mesh network to have stronger control over terminals such as mobile phones and provide faster switching time during roaming.
[0161] It should be noted that the technical solution disclosed herein can be combined with roaming control functions to restrict user roaming areas, such as limiting terminal 1 to the first floor and terminal 2 to the second floor. The Mesh master node can monitor the signal strength of a terminal and the location of the connected node. When the terminal's signal strength falls below a certain value, it can determine whether the terminal has moved away. Based on this, an electronic fence application based on the Wi-Fi Mesh network can be established. This mesh-based electronic fence can increase the monitoring range, etc.
[0162] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus the necessary general hardware platform, and of course it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present disclosure is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product is stored in a storage medium (such as read-only memory / random access memory (ROM / RAM), a magnetic disk, or an optical disk), and can include a number of instructions to enable a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in the various embodiments of the present disclosure.
[0163] This embodiment also provides a key determination device for implementing the above-mentioned embodiments and preferred embodiments. Details already described will not be repeated. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0164] FIG10 is a schematic block diagram of a key determination device according to an embodiment of the present disclosure. As shown in FIG10 , the device may include:
[0165] The instruction module 102 is configured to, when the mobile terminal joins a wireless mesh network, instruct a target wireless access point AP in the mesh network to negotiate with the mobile terminal through a first AP to determine a corresponding target key;
[0166] The first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key corresponding to the target AP node is the key used by the target AP to communicate with the mobile terminal after establishing a communication connection with the mobile terminal.
[0167] Through the above-mentioned device, after the mobile terminal joins the wireless mesh Mesh network, the target AP in the Mesh network will negotiate with the mobile terminal through the first AP to determine the corresponding target key, so that after the mobile terminal switches from the first AP to the target AP, there is no need to negotiate the key again, which solves the problem of the terminal switching the Mesh node in the Mesh network.
[0168] FIG11 is a schematic block diagram of a key determination device according to another embodiment of the present disclosure. As shown in FIG11 , the device may include:
[0169] The first determination module 112 is configured to determine the target key corresponding to the target AP through negotiation between the first AP and the target AP in the Mesh network when the mobile terminal joins the Mesh network; wherein the first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key is the key used by the mobile terminal to communicate with the target AP after establishing a communication connection with the target AP.
[0170] Through the above-mentioned device, after the mobile terminal joins the wireless mesh Mesh network, the mobile terminal will determine the corresponding target key through the first AP and the target AP in the Mesh network, so that after the mobile terminal switches from the first AP to the target AP, there is no need to negotiate the key, which solves the problem of the terminal switching the Mesh node in the Mesh network.
[0171] FIG12 is a schematic block diagram of a key determination device according to another embodiment of the present disclosure. As shown in FIG12 , the device includes:
[0172] The second determination module 122 is configured to determine the target key through negotiation with the mobile terminal through the first AP when a key pre-negotiation instruction sent by the main AP in the Mesh network is obtained; wherein the first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key is the key used by the target AP to communicate with the mobile terminal after establishing a communication connection with the mobile terminal.
[0173] Through the above-mentioned device, after the mobile terminal joins the wireless mesh Mesh network, the target AP in the Mesh network will negotiate with the mobile terminal through the first AP to determine the corresponding target key, so that after the mobile terminal switches from the first AP to the target AP, there is no need to negotiate the key again, which solves the problem of the terminal switching the Mesh node in the Mesh network.
[0174] This embodiment further provides a key determination system, which is used to implement the above embodiments and preferred implementations. FIG13 is a schematic block diagram of the key determination system according to an embodiment of the present disclosure. As shown in FIG13 , the system may include:
[0175] A master AP 132 in the Mesh network is configured to send a key pre-negotiation instruction to a target AP in the Mesh network when a mobile terminal joins the Mesh network;
[0176] The target AP 134 is configured to determine a corresponding target key through negotiation with the mobile terminal through the first AP when the key pre-negotiation instruction is obtained;
[0177] The mobile terminal 136 is used to determine the target key corresponding to the target AP through negotiation with the target AP through the first AP when joining the Mesh network; wherein, the first AP is the AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key corresponding to the target AP node is the key used by the target AP to communicate with the mobile terminal after establishing a communication connection with the mobile terminal.
[0178] Through the above system, after the mobile terminal joins the wireless mesh Mesh network, the target AP in the Mesh network will negotiate with the mobile terminal through the first AP to determine the corresponding target key, so that after the mobile terminal switches from the first AP to the target AP, there is no need to negotiate the key again, solving the problem of the terminal switching the Mesh node in the Mesh network.
[0179] It should be noted that the above modules can be implemented through software or hardware. For the latter, it can be implemented in the following ways, but not limited to: the above modules are all located in the same processor; or the above modules are located in different processors in any combination.
[0180] An embodiment of the present disclosure further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps of any one of the above method embodiments when run.
[0181] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk, or an optical disk.
[0182] An embodiment of the present disclosure further provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.
[0183] In an exemplary embodiment, the electronic device may further include a transmission device and an input / output device, wherein the transmission device is connected to the processor, and the input / output device is connected to the processor.
[0184] For specific examples in this embodiment, reference may be made to the examples described in the above embodiments and exemplary implementation modes, and this embodiment will not be described in detail here.
[0185] Obviously, those skilled in the art should understand that the modules or steps of the present disclosure described above can be implemented using a general-purpose computing device, they can be concentrated on a single computing device, or distributed across a network composed of multiple computing devices, they can be implemented using program code executable by the computing device, and thus, they can be stored in a storage device and executed by the computing device, and in some cases, the steps shown or described can be performed in a different order than herein, or they can be fabricated into separate integrated circuit modules, or multiple modules or steps can be fabricated into a single integrated circuit module for implementation. Thus, the present disclosure is not limited to any particular combination of hardware and software.
[0186] The foregoing description is merely a preferred embodiment of the present disclosure and is not intended to limit the present disclosure. Those skilled in the art will readily appreciate that various modifications and variations of the present disclosure are possible. Any modifications, equivalent substitutions, or improvements made within the principles of the present disclosure shall be included within the scope of protection of the present disclosure.
Claims
1. A key determination method, comprising: When the mobile terminal joins the wireless mesh Mesh network, instruct a target wireless access point AP in the Mesh network to negotiate with the mobile terminal through the first AP to determine a corresponding target key; The first AP is an AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key corresponding to the target AP is a key used when the target AP communicates with the mobile terminal.
2. The method according to claim 1, wherein: Before instructing the target wireless access point AP in the Mesh network to negotiate with the mobile terminal through the first AP to determine the corresponding target key, the method further includes: Determine any AP other than the first AP in the Mesh network as the target AP; or Determine an AP other than the first AP in the Mesh network and having a distance from the mobile terminal less than a preset distance as the target AP; or An AP designated by a target object in the Mesh network is determined as the target AP.
3. The method according to claim 1, wherein: Instructing a target wireless access point AP in the Mesh network to negotiate with the mobile terminal through the first AP to determine a corresponding target key, including: Sending a key pre-negotiation instruction to a target AP, wherein the key pre-negotiation instruction is used to instruct the target AP to send a first message to the mobile terminal through a first AP, and to generate a reference key according to a first random number, a pre-shared key, and a second random number generated by the mobile terminal in the second message when a second message sent by the mobile terminal is obtained through the first AP; sending a third message to the mobile terminal through the first AP, and to determine the reference key as the target key when a fourth message sent by the mobile terminal in response to the third message is obtained through the first AP; Among them, the first message carries at least a first random number generated by the target AP, the pre-shared key is a key pre-negotiated by the target AP and the mobile terminal, and the fourth message is used to instruct the mobile terminal to successfully decrypt the third message using the reference key generated by itself; after obtaining the first message, the mobile terminal generates the reference key according to the first random number, the pre-shared key and the second random number.
4. The method according to claim 3, wherein: The target AP exchanges messages with the first AP through a first protocol, and the first AP exchanges messages with the mobile terminal through a second protocol, wherein the first protocol is a protocol used for communication between APs in the Mesh network, and the second protocol is a protocol used for communication between APs and mobile terminals.
5. The method according to claim 1, wherein: After instructing the target wireless access point AP in the Mesh network to negotiate with the mobile terminal through the first AP to determine the corresponding target key, the method further includes: After a preset time, the target AP is instructed to re-negotiate with the mobile terminal to determine the corresponding target key, so that the target AP uses the newly determined target key to update the original target key.
6. The method according to claim 1, wherein: After instructing the target wireless access point AP in the Mesh network to negotiate with the mobile terminal through the first AP to determine the corresponding target key, the method further includes: In case of detecting that the mobile terminal leaves the Mesh network, the target AP is instructed to delete the target key determined by negotiation with the mobile terminal.
7. The method according to claim 1, wherein: The method further comprises: When the mobile terminal joins the wireless mesh network, sending a first request message to the mobile terminal through the first AP, wherein the first request message is used to request the roaming control right of the mobile terminal; Determine whether the Mesh network has the roaming control right of the mobile terminal according to a first response message sent by the mobile terminal in response to the first request message.
8. The method according to claim 7, wherein: The method further comprises: When it is determined according to the first response message that the Mesh network has the roaming control right of the mobile terminal and it is detected that the signal strength of the signal sent by the mobile terminal is less than a first threshold and / or the signal quality of the signal is less than a second threshold, sending a second request message to the mobile terminal, wherein the signal quality is used to indicate the stability and interference degree of the signal, and the second request message is used to request to obtain information about the wireless network detected by the mobile terminal in the environment in which it is located; In a case where the information of the wireless network sent by the mobile terminal is acquired, determining a second AP from the Mesh network according to the information of the wireless network; A handover message is sent to the mobile terminal, wherein the handover message carries an identifier of the second AP, and the handover message is used to instruct the mobile terminal to disconnect the communication connection established with the first AP and establish a communication connection with the second AP.
9. The method according to claim 1, wherein: After instructing the target wireless access point AP in the Mesh network to negotiate with the mobile terminal through the first AP to determine the corresponding target key, the method further includes: In the case where it is determined that the target AP successfully negotiates with the mobile terminal to determine the corresponding target key, sending indication information to the target AP, wherein the indication information is used to instruct the target AP to determine whether the third request message carries pre-installation information when obtaining the third request message sent by the mobile terminal, and to send a second response message to the mobile terminal when the third request message carries the pre-installation information and the target AP has the target key; Among them, the pre-installation information is used to indicate that the mobile terminal has a target key corresponding to the target AP, the third request message is used to request to establish a communication connection between the mobile terminal and the target AP, and the second response message is used to indicate that the mobile terminal has successfully established a communication connection with the target AP, and the second response message carries indication information for indicating that the target AP has the target key.
10. A key determination method, comprising: When a mobile terminal joins a Mesh network, a target key corresponding to the target AP is determined through negotiation between a first AP and a target AP in the Mesh network; The first AP is an AP in the Mesh network that currently establishes a communication connection with the mobile terminal, and the target key is a key used when the mobile terminal communicates with the target AP.
11. The method according to claim 10, wherein: Determining a target key corresponding to the target AP through negotiation between the first AP and the target AP in the Mesh network includes: In a case where a first message sent by the target AP for requesting to negotiate with the mobile terminal to determine a corresponding target key is acquired through the first AP, the target key corresponding to the target AP is determined through negotiation between the first AP and the target AP.
12. The method according to claim 11, wherein: Determining a target key corresponding to the target AP through negotiation between the first AP and the target AP includes: generating a second random number; Generate a reference key according to the first random number, the pre-shared key and the second random number, and send a second message to the target AP node, wherein the second message carries the second random number, the pre-shared key is a key pre-negotiated between the mobile terminal and the target AP, and the first message carries the first random number generated by the target AP; In a case where a third message sent by the target AP node is acquired through the first AP, decrypting the third message using the reference key; In case that the third message is successfully decrypted, the reference key is determined as the target key, and a fourth message is sent to the target AP, wherein the fourth message is used to instruct the mobile terminal to successfully decrypt the third message using the reference key.
13. The method according to claim 10, wherein: After determining a target key corresponding to the target AP through negotiation between the first AP and the target AP in the Mesh network, the method further includes: When the mobile terminal leaves the Mesh network, the target key corresponding to the target AP is deleted in the mobile terminal.
14. The method according to claim 10, wherein: The method further comprises: In a case where a first request message sent by the Mesh network is obtained through the first AP, determining whether to allow the Mesh network to perform roaming control on the mobile terminal, and sending a first response message to the Mesh network; The first request message is used to request the roaming control right of the mobile terminal, and the first response message is used to indicate whether the Mesh network has the roaming control right of the mobile terminal.
15. The method according to claim 10, wherein: After determining a target key corresponding to the target AP through negotiation between the first AP and the target AP in the Mesh network, the method further includes: In the case where the second request message sent by the Mesh network is obtained through the first AP, the wireless network in the environment where the mobile terminal is located is detected, and the information of the detected wireless network is sent to the Mesh network through the first AP, wherein the second request message is a message sent by the Mesh network when it is detected that the signal strength of the signal sent by the mobile terminal is less than a first threshold value, and / or the signal quality of the signal is less than a second threshold value; When the Mesh network has the roaming control right of the mobile terminal and obtains the handover message sent by the Mesh network through the first AP, disconnect the communication connection established with the first AP and establish a communication connection with the target AP. A communication connection is established, wherein the switching message carries an identifier of the target AP.
16. The method according to claim 15, wherein: Establishing a communication connection with the target AP includes: Sending a third request message to the target AP, wherein the third request message carries pre-installation information of a target key corresponding to the target AP, wherein the pre-installation information is used to indicate that the mobile terminal has the target key corresponding to the target AP, and the third request message is used to request to establish a communication connection between the mobile terminal and the target AP; In case of obtaining a second response message sent by the target AP, determining that a communication connection with the target AP is successfully established; Among them, after obtaining the second response message sent by the target AP, the mobile terminal allows direct use of the target key to communicate with the target AP, and the second response message is the message sent by the target AP when it is determined that the third request message carries the pre-installation information and the target AP has the target key.
17. A computer-readable storage medium having a computer program stored therein, wherein: When the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 9 are implemented, or the steps of the method described in any one of claims 10 to 16 are implemented.
18. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the method described in any one of claims 1 to 9 or the steps of the method described in any one of claims 10 to 16 when executing the computer program.
Citation Information
Patent Citations
Roaming method, AP and AP cooperative work controller
CN110519747A
Information protection method and system and communication device
CN113766495A
Rapid roaming method for WAPI wireless network
CN115915315A
Data communication method, device and equipment based on MESH network
CN116669228A
Mobile device handoff while maintaining connectivity with multiple access points
US7969953B1