Identity recognition method, and device and storage medium
Patent Information
- Application Number
- PCT/CN2024/126944
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-08
- Filing Date
- 2024-10-24
- Publication Date
- 2025-10-02
AI Technical Summary
In the existing technology, the same Device ID is used as the identifier of non-AP STAs during PASN authentication and 4-way handshake. This makes it impossible for the AP to confirm its usage in different scenarios, resulting in wasted computing resources and the risk of sensitive information leakage.
A separate identification information solution is adopted to separate the identification information in the PASN authentication and 4-way handshake processes, and PASN ID and Device ID are allocated to non-AP STAs respectively to ensure identity recognition in different communication scenarios.
It reduces the amount of encryption operations, saves computing resources, improves the security of communication equipment and the accuracy of identity recognition, and reduces the risk of sensitive information leakage.
Smart Images

Figure CN2024126944_02102025_PF_FP_ABST
Abstract
Description
Identity identification method, device and storage medium Technical Field
[0001] The present application relates to the field of communication technology, and in particular to an identity recognition method, device, and storage medium. Background Art
[0002] During both the Preassociation Security Negotiation (PASN) authentication and the post-association 4-way handshake, the same parameter (Device ID) is used to identify non-AP STAs. Because the access point (AP) cannot confirm whether a non-AP STA will subsequently use the Device ID for PASN authentication or the post-association 4-way handshake, to ensure security, the AP must protect the Device ID using a short period and encryption of sensitive information. (If the STA subsequently primarily performs the 4-way handshake, this wastes computing resources on the AP side.) Therefore, a method is urgently needed to separate the identification information of non-AP STAs during PASN authentication and the 4-way handshake.
[0003] Summary of the Invention
[0004] In view of this, the embodiments of the present application provide an identity recognition method, device and storage medium, which effectively reduce the amount of encryption operations and thus save computing resources.
[0005] This embodiment of the present application provides an identity recognition method, applied to a first communication device, including:
[0006] Allocating at least two pieces of identification information to the second communication device;
[0007] The second communication device is identified based on the identification information.
[0008] This embodiment of the present application provides an identity recognition method, applied to a second communication device, including:
[0009] At least two pieces of identification information allocated by the first communication device are received.
[0010] An embodiment of the present application provides an identity recognition device, applied to a first communication device, including:
[0011] an allocating module, configured to allocate at least two pieces of identification information to the second communication device;
[0012] The identification module is configured to perform identity identification on the second communication device based on the identification information.
[0013] An embodiment of the present application provides an identity recognition device, applied to a second communication device, including:
[0014] The receiving module is configured to receive at least two pieces of identification information allocated by the first communication device.
[0015] An embodiment of the present application provides a communication device, comprising: a memory, and one or more processors;
[0016] The memory is configured to store one or more programs;
[0017] When the one or more programs are executed by the one or more processors, the one or more processors implement the method described in any one of the above embodiments.
[0018] An embodiment of the present application provides a storage medium storing a computer program. When the computer program is executed by a processor, the method described in any one of the above embodiments is implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] FIG1 is a schematic diagram of an implementation of a Device ID solution provided by the related art;
[0020] FIG2 is a schematic diagram of an implementation of a PASN authentication process provided by the related art;
[0021] FIG3 is a schematic diagram of a 4-way handshake process provided by the related art;
[0022] FIG4 is a schematic diagram of an implementation of a FILS authentication process provided by related art;
[0023] FIG5 is a schematic diagram of another implementation of a PASN authentication process provided by the related art;
[0024] FIG6 is a flow chart of an identity recognition method provided in an embodiment of the present application;
[0025] 7 is a schematic diagram of a configuration of a frame structure corresponding to a second frame authentication frame provided in an embodiment of the present application;
[0026] FIG8 is a schematic diagram of a configuration of a frame structure corresponding to a third frame EAPOL-Key according to an embodiment of the present application;
[0027] FIG9 is a schematic diagram of a configuration of a frame structure corresponding to newly added element information provided in an embodiment of the present application;
[0028] FIG10 is a flowchart of another identity recognition method provided in an embodiment of the present application;
[0029] FIG11 is a schematic diagram of an interaction for distributing identification information provided in an embodiment of the present application;
[0030] FIG12 is a schematic diagram of another allocation interaction of identification information provided in an embodiment of the present application;
[0031] FIG13 is a structural block diagram of an identity recognition device provided in an embodiment of the present application;
[0032] FIG14 is a structural block diagram of another identity recognition device provided in an embodiment of the present application;
[0033] FIG15 is a schematic structural diagram of a communication device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0034] The following describes the embodiments of the present application in conjunction with the accompanying drawings. The following describes the present application in conjunction with the accompanying drawings. The examples are only used to explain the present application and are not used to limit the scope of the present application.
[0035] Fiber to the Remote (FTTR) technology: FTTR technology uses optical fiber to connect wireless routers (APs) in different rooms or locations in homes, small and medium-sized enterprises, etc., thereby providing high-bandwidth, high-reliability connections between multiple APs. It can use a point-to-multipoint optical distribution network to achieve connections between master control APs and slave APs.
[0036] MAC address security and risk technology: On traditional Wi-Fi devices, each device uses a globally unique fixed Media Access Control (MAC) address to establish a connection with the AP. Identification and authentication technologies based on fixed device MAC addresses have been widely used in the Wi-Fi industry. For example, technologies such as access control and client steering based on device MAC addresses have been included in the Wi-Fi Alliance (WFA) Easy Mesh standard and the Wi-Fi Broadband Alliance (WBA) white paper.
[0037] In recent years, user privacy and security have received increasing attention. The use of a fixed MAC address for each device can allow third parties to use MAC address sniffing technology to track and locate specific users, resulting in a series of security issues.
[0038] Random MAC address (RMA) technology: allows users to use a random MAC address before the device connects to the AP, thereby avoiding sniffing attacks and tracking problems caused by fixed MAC address technology.
[0039] General in Regulatory Compliance Mark (RCM) technology: A Device ID solution is proposed to address the issue of random MAC address technology causing the failure of device MAC address-based functions defined by the Wi-Fi Alliance and WBA, resulting in the network being unable to manage devices.
[0040] Figure 1 is a schematic diagram of an implementation of a Device ID solution provided by the relevant technology. As shown in Figure 1, the associated AP assigns an identification ID (Device ID) to STA1 (using MAC1). When the AP uses a random address (MAC2) to associate with an access point in the same extended service set (ESS), the access point is informed of the Device ID information to ensure that the access point side can match the STA1 using MAC2 with the STA1 previously using MAC1, thereby ensuring that network side functions such as admission control and remote diagnosis can work normally.
[0041] Device ID in PASN in RCM technology: Figure 2 is a schematic diagram of the implementation of a PASN authentication process provided by the relevant technology. As shown in Figure 2, the non-AP STA uses the MAC1 address and AP1 for authentication. AP1 carries the encrypted DeviceID 1 as the Device ID information of the non-AP STA in the second authentication frame; then the non-AP STA uses the MAC2 address and AP2 for authentication. The non-AP STA carries the plaintext DeviceID 1 in the first authentication frame. AP2 identifies the non-AP STA through the reported information and provides the encrypted Device ID 2 to the non-AP STA in the second authentication frame.
[0042] Device ID in 4-way handshake in RCM technology: Figure 3 is a schematic diagram of the implementation of a 4-way handshake process provided by related technologies. As shown in Figure 3, when a non-AP STA associates with AP1 and performs a 4-way handshake, AP1 carries the encrypted DeviceID 1 in the third key information frame (EAPOL-Key) as the non-AP STA's Device ID information. Subsequently, the non-AP STA disassociates from AP1 and successfully associates with AP2. In the 4-way handshake with AP2, the non-AP STA carries the encrypted DeviceID 1 in the second EAPOL-Key frame. AP2 identifies the non-AP STA based on this reported information. AP2 then optionally carries the new DeviceID 2 in the third EAPOL-Key frame as the non-AP STA's new Device ID.
[0043] Device ID in Fast Initial Link Setup (FILS) authentication in RCM technology: Figure 4 is a schematic diagram of the implementation of a FILS authentication process provided by the relevant technology. As shown in Figure 4, the non-AP STA uses the MAC1 address and AP1 for FILS authentication. AP1 carries the encrypted DeviceID 1 as the Device ID information of the non-AP STA in the fourth frame association response. Subsequently, the non-AP STA disconnects from AP1 and uses the MAC2 address and AP2 for FILS authentication. The non-AP STA carries the encrypted DeviceID 1 in the third frame association request. AP2 identifies the non-AP STA through the reported information and provides the encrypted DeviceID 2 to the non-AP STA in the fourth frame association response.
[0044] Generally speaking, the Device ID is used to identify non-AP STAs. It is assigned by the AP to a non-AP STA during PASN authentication and the 4-way handshake after association as its identification information. If the non-AP STA's MAC address subsequently changes and PASN authentication or the 4-way handshake after association are repeated, the Device ID information is reported to the AP for identification of the non-AP STA.
[0045] After a non-AP STA has been assigned a Device ID, the specific frame exchange process differs when performing PASN authentication or a 4-way handshake after association:
[0046] During PASN authentication, a non-AP STA must carry its Device ID (plaintext) in the first frame it sends. For security reasons, the AP must assign a new Device ID (encrypted text) to the non-AP STA in the second frame. Specifically, considering that the Device ID may contain sensitive user information, the AP encrypts this sensitive information using a specific key and encryption algorithm (herein referred to as "Encryption A") when providing the Device ID. For example, Figure 5 illustrates another implementation of the PASN authentication process provided by the related art. As shown in Figure 5, the Device ID assigned by the AP to user Xiaoming's phone is Xiaoming's phone number. However, the Device ID information actually transmitted to the non-AP STA via Encryption A is displayed as "00aacc42" in plaintext. Therefore, the non-AP STA will not carry Xiaoming's phone number in plaintext in the first frame of the subsequent PASN authentication, preventing the leakage of sensitive information to third-party monitoring devices.
[0047] In a 4-way handshake, the non-AP STA reports its Device ID (encrypted text) to the AP in the second frame. The AP may assign a new Device ID (encrypted text) to the non-AP STA in the third frame. The Device ID is plaintext information generated using a key encryption key (KEK) and a specified encryption algorithm (herein referred to as encryption B).
[0048] Therefore, the AP cannot guarantee that the STA will not use the device ID in PASN, which could lead to sensitive information leakage. The device ID has the following differences in PASN authentication and 4-way handshake (as shown in Table 1):
[0049] Regarding the lifecycle, since the Device ID reported by the non-AP STA in the 4-way handshake is in encrypted form, there is no risk of sensitive information leakage. Therefore, to save computing resources, the AP usually does not allocate a new Device ID to the non-AP STA. In this scenario, the Device ID has a "long" lifecycle. However, during each PASN authentication, the AP must allocate a new Device ID to the non-AP STA (assigning new identification information and synchronizing this information with other APs). Therefore, the Device ID lifecycle in this scenario is "short".
[0050] Regarding the encryption requirements on the AP side, the Device ID in the 4-way handshake only needs to be encrypted with B, while the Device ID sent by the AP in PASN authentication needs to be encrypted with both A and B.
[0051] Table 1
[0052] During PASN authentication and the four-way handshake after association, the same parameter (Device ID) is used to identify non-AP STAs. Because the access point (AP) cannot confirm whether a non-AP STA will subsequently use the Device ID for PASN authentication or the four-way handshake after association, the AP must protect the Device ID using a short period and encryption of sensitive information to ensure security. (If the STA subsequently primarily performs the four-way handshake, this wastes computing resources on the AP side.) Therefore, a method is urgently needed to separate the identification information of non-AP STAs during PASN authentication and the 4-way handshake.
[0053] In view of this, the present application proposes an identity identification (PASN ID) scheme for a workstation (non-AP STA) supporting random address access (RMA) technology in PASN authentication, which distinguishes the workstation identity identification process in PASN authentication from the traditional 4-way handshake and Device ID processes under FILS, ensuring that the workstation can request, maintain and update independent identity information in PASN authentication; further, the identity identification scheme supports the AP to simultaneously allocate second identification information (denoted as Device ID) and first identification information (denoted as PASN ID) for the identity identification of the non-AP STA in non-associated (e.g., PASN authentication) or associated (e.g., 4-way handshake and FILS authentication) scenarios.
[0054] In one embodiment, Figure 6 is a flowchart of an identity identification method provided by an embodiment of the present application. This embodiment is applied to the situation where identity identification is performed on a second communication device in different communication scenarios. This embodiment can be performed by a first communication device. Exemplarily, the first communication device can be an AP. In the actual communication process, it can include a first authentication or association process, as well as a non-first authentication or association process. The first communication device that establishes a first authentication or association process with the second communication device, and the first communication device that establishes a non-first authentication or association process with the second communication device, can be the same first communication device (for example, AP1), or different first communication devices (for example, AP1 and AP2).
[0055] As shown in FIG6 , this embodiment includes: S610 - S620 .
[0056] S610: Allocate at least two pieces of identification information to a second communication device.
[0057] For example, the second communication device may be a non-AP STA. The first communication device and the second communication device may be single-link devices or multi-link devices. During actual communication, the second communication device may be in an associated scenario or a non-associated scenario. To accurately identify the second communication device in different scenarios, the first communication device may assign at least two pieces of identification information to the second communication device, one piece of identification information corresponding to each communication scenario.
[0058] S620: Perform identity recognition on the second communication device based on the identification information.
[0059] In one embodiment, identifying the second communication device based on the identification information includes: identifying the second communication device in a corresponding communication scenario based on the identification information. The first communication device can identify the second communication device in the corresponding communication scenario based on the identification information. That is, two independent identification information are used to identify the second communication device in two scenarios, respectively, thereby ensuring accurate identification of the second communication device in different communication scenarios.
[0060] In one embodiment, the identity identification method applied to the first communication device further includes:
[0061] Receiving first support capability information sent by a second communication device, wherein the first support capability information is used to indicate capability information of the second communication device supporting different identification information types;
[0062] Sending second support capability information to the second communication device; wherein the second support capability information is used to indicate the capability information of the first communication device to support different identification information types. The first communication device receives the first support capability information sent by the second communication device, so that the first communication device can know the identification information of the identification information types that the second communication device can support based on the first support capability information; at the same time, the first communication device also needs to send the second support capability information to the second communication device, so that the second communication device can know the identification information of the identification information types that the first communication device can support.
[0063] In one embodiment, different flag bits are used to indicate the ability to support different identification information types;
[0064] Alternatively, the same flag bit is used to uniformly indicate the ability to support different types of identification information. In one example, different flag bits are used to respectively indicate the ability to support identification information of different types of identification information. It can be understood that the support status of identification information of different types of identification information is indicated separately, that is, the number of flag bits is equal to the number of identification information types. For example, in the case where the identification information type includes two types, two flag bits are used to respectively indicate the support status of identification information of the two types of identification information. In one example, the same flag bit is used to uniformly indicate the ability to support different types of identification information. It can be understood that when the flag bit is 0, it indicates that identification information of all types of identification information is not supported; when the flag bit is 1, it indicates that identification information of all types of identification information is supported.
[0065] In one embodiment, the carrying mode of the first support capability information includes at least one of the following: a probe request frame; an authentication frame; an association request frame;
[0066] The second supported capability information may be carried in one of the following ways: a beacon frame; a probe response frame; an authentication frame; or an association response frame. In one example, the first supported capability information may be carried in the RSNE or RSNXE element of a probe request frame, an authentication frame, or an association request frame; and the second supported capability information may be carried in the RSNE or RSNXE element of a beacon frame, a probe response frame, an authentication frame, or an association response frame.
[0067] In one embodiment, in the first communication scenario, the communication scenario includes one of the following: an associated scenario; an unassociated scenario. In one example, the first communication scenario may include: an initial authentication unassociated scenario; and an initial authentication associated scenario. The initial authentication unassociated scenario can be understood as the initial unassociated scenario, and the initial authentication associated scenario can be understood as the initial associated scenario.
[0068] In one embodiment, the non-association scenario includes PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and FILS authentication. In one example, in an initial communication scenario, the association scenario may include at least one of the following: a four-way handshake in an initial association scenario; and FILS authentication. In another example, in an initial communication scenario, the non-association scenario may include PASN authentication in an initial authentication scenario.
[0069] In one embodiment, in the first communication scenario, the identification information type of the identification information includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to represent the identification information of the second communication device in a non-associated scenario; and the second identification information is used to represent the identification information of the second communication device in an associated scenario. Exemplarily, the first identification information can be recorded as PASN ID; and the second identification information can be recorded as Device ID. In one example, the PASN ID can be the identification information assigned by the first communication device to identify the second communication device in the next Fine Timing Measurement (FTM); and the Device ID can be the identification information assigned by the first communication device to identify the second communication device after the next association. In one example, the names of the first identification information and the second identification information are different.
[0070] In one embodiment, in an initial communication scenario, the identity identification method applied to the first communication device further includes: receiving an identification information allocation request carrying an identification information type sent by a second communication device; and allocating corresponding identification information to the second communication device based on the identification information type. In one example, the identification information type corresponds one-to-one to the communication scenario, that is, in different communication scenarios, the corresponding identification information type is also different. In the initial communication scenario, the identification information allocated by the first communication device to the second communication device can be determined based on the identification information type carried by the identification information allocation request sent by the second communication device to the first communication device. In one example, if the identification information type carried by the identification information allocation request is the first identification information, the first communication device allocates the first identification information to the second communication device; if the identification information type carried by the identification information allocation request is the second identification information, the first communication device allocates the second identification information to the second communication device; if the identification information type carried by the identification information allocation request includes the first identification information and the second identification information, the first communication device allocates the first identification information and the second identification information to the second communication device.
[0071] In one embodiment, in an initial communication scenario, the identity verification method applied to the first communication device further includes: assigning identification information of all identification information types to the second communication device by default. In one example, in an initial communication scenario, the first communication device may directly assign identification information of all identification information types to the second communication device by default. In another example, in an initial communication scenario, if the first communication device does not receive an identification information assignment request sent by the second communication device, the first communication device may assign identification information of all identification information types to the second communication device by default.
[0072] In one embodiment, in the first communication scenario, the frame carrying the identification information includes one of the following: a second authentication frame for PASN authentication in a non-association scenario; a third key information frame for a four-way handshake in an association scenario; or an association response frame for FILS authentication in an association scenario. In one example, the third key information frame may be a third EAPOL-Key frame. In one example, in the first communication scenario, the first communication device may carry the identification information assigned by the first communication device in the second authentication frame for PASN authentication in a non-association scenario, the third key information frame for a four-way handshake in an association scenario, or the association response frame for FILS authentication in an association scenario. FIG7 is a schematic diagram of the configuration of a frame structure corresponding to a second authentication frame provided in an embodiment of the present application. As shown in FIG7, when the identification information is a PASN ID, the frame structure of the second authentication frame carries at least a PASN ID status and a PASN ID, wherein the PASN ID status is used to indicate whether the first communication device recognizes the PASN ID; and the PASN ID is used to indicate the PASN ID information assigned by the first communication device to the second communication device. In one example, when the identification information is Device ID, the frame structure of the second frame authentication frame carries at least Device ID status and Device ID, wherein Device ID status is used to indicate whether the first communication device recognizes the Device ID; and Device ID is used to indicate the Device ID information assigned by the first communication device to the second communication device.
[0073] FIG8 is a schematic diagram illustrating the configuration of a frame structure corresponding to a third EAPOL-Key frame provided in an embodiment of the present application. As shown in FIG8 , when the identification information is a PASN ID, the frame structure of the third EAPOL-Key frame carries at least a PASN ID status and a PASN ID, wherein the PASN ID status indicates whether the first communication device recognizes the PASN ID; and the PASN ID indicates the PASN ID information assigned by the first communication device to the second communication device. In one example, when the identification information is a Device ID, the frame structure of the third EAPOL-Key frame carries at least a Device ID status and a Device ID, wherein the Device ID status indicates whether the first communication device recognizes the Device ID; and the Device ID indicates the Device ID information assigned by the first communication device to the second communication device.
[0074] In one embodiment, in the first communication scenario, the request method for identification information of different identification information types includes one of the following: a specific flag bit; newly added element information;
[0075] The newly added element information includes at least: a first identification request flag and a second identification request flag. In one example, a specific flag or newly added element information can be used to indicate the type of identification information that the second communication device requests the first communication device to allocate. The newly added element information includes at least a first identification request flag and a second identification request flag; wherein the first identification request flag is used to indicate whether to request the allocation of the first identification information; and the second identification request flag is used to indicate whether to request the allocation of the second identification information. Figure 9 is a configuration diagram of a frame structure corresponding to a newly added element information provided in an embodiment of the present application. As shown in Figure 9, the newly added element information includes at least a first identification request flag (such as request PASN ID) and a second identification request flag (request Device ID), wherein request PASN ID is used to indicate whether to request the allocation of the first identification information (such as PASN ID); and request Device ID is used to indicate whether to allocate the second identification information (such as Device ID).
[0076] In one embodiment, in an initial communication scenario, the bearer frame of the identification information allocation request includes one of the following: a first authentication frame of PASN authentication in a non-association scenario; a second key information frame of a four-way handshake in an association scenario; or an association request frame of FILS authentication in an association scenario. In one example, in an initial communication scenario, the second communication device sends the identification information allocation request to the first communication device, which can be carried in the first authentication frame of PASN authentication in a non-association scenario, i.e., the first authentication frame of PASN authentication in a non-association scenario carries the identification information type requested by the second communication device. In one example, in an initial communication scenario, the second communication device sends the identification information allocation request to the first communication device, which can be carried in the second key information frame of a four-way handshake in an association scenario, i.e., the second key information frame of the four-way handshake in an association scenario carries the identification information type requested by the second communication device. In one example, in an initial communication scenario, the second communication device sends the identification information allocation request to the first communication device, which can be carried in the association request frame of FILS authentication in an association scenario, i.e., the association request frame of FILS authentication in an association scenario carries the identification information type requested by the second communication device.
[0077] In one embodiment, in a non-first communication scenario, the identity recognition method applied to the first communication device further includes: receiving identification information reported by the second communication device. In one example, the non-first communication scenario can include a non-first authentication-unassociated scenario and a non-first authentication-associated scenario. The non-first authentication-unassociated scenario can be understood as a non-first non-associated scenario, and the non-first authentication-associated scenario can be understood as a non-first association scenario.
[0078] In one embodiment, in a non-first communication scenario, the association scenario may include at least one of the following: a four-way handshake in a non-first association scenario and FILS authentication in a non-first association scenario; in a non-first communication scenario, the non-association scenario may include PASN authentication in a non-first authentication scenario. In one example, in a non-first communication scenario, a first communication device receives assigned identification information reported by a second communication device.
[0079] In one embodiment, in a non-initial communication scenario, the identity recognition method applied to a first communication device further includes: receiving an identification information allocation request carrying an identification information type from a second communication device; and allocating new identification information to the second communication device based on the identification information type. In a non-initial communication scenario, the first communication device, upon receiving the allocated identification information reported by the second communication device, also receives an identification information allocation request carrying the identification information type from the second communication device, and the first communication device allocates new identification information to the second communication device based on the identification information type. In one example, in a non-first communication scenario, if the identification information in one scenario is lost, the identification information in another scenario can be requested to be allocated based on the current scenario. Specifically, at the beginning of the process of establishing a non-first communication between the first communication device and the second communication device, both the first identification information and the second identification information exist, but in the process of the second communication device establishing a non-first communication with another first communication device (or the first communication device establishing the first communication), the second identification information allocated by the first communication device to the second communication device is lost. If the second communication device does not actively report the identification information type of the second identification information, then in the process of establishing a four-way handshake with the first communication device, the first communication device only allocates new first identification information to the second communication device. At this time, the second communication device can send an identification information allocation request carrying the identification information type of the second identification information to the first communication device, so that the first communication device allocates new second identification information to the second communication device.
[0080] In one embodiment, in a non-first communication scenario, the identification information type of the identification information reported by the second communication device includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to identify the identification information of the second communication device in an authentication scenario; and the second identification information is used to identify the identification information of the second communication device in an association scenario. In one example, if in a first communication scenario, the first communication device has allocated first identification information to the second communication device, then correspondingly, in a non-first communication scenario, the second communication device may report the allocated first identification information to the first communication device; in one example, if in a first communication scenario, the first communication device has allocated second identification information to the second communication device, then correspondingly, in a non-first communication scenario, the second communication device may report the allocated second identification information to the first communication device; in one example, if in a first communication scenario, the first communication device has allocated first identification information and second identification information to the second communication device, then correspondingly, in a non-first communication scenario, the second communication device may report the allocated first identification information and second identification information to the first communication device.
[0081] In one embodiment, in a non-first communication scenario, the method for requesting identification information of different identification information types includes one of the following: a specific flag; newly added element information; the newly added element information at least includes: a first identification request flag and a second identification request flag. In a non-first communication scenario, the method for requesting identification information of different identification information types from the second communication device to the first communication device is similar to the method for requesting identification information of different identification information types from the second communication device to the first communication device in a first communication scenario. For details, please refer to the request method in the first communication scenario described above (i.e., Figure 9), which will not be repeated here.
[0082] In one embodiment, in a non-initial communication scenario, the identity recognition method applied to the first communication device further includes: assigning, by default, to the second communication device new identification information corresponding to the same identification information type as the reported identification information. In one example, in a non-initial communication scenario, the second communication device does not send an identification information assignment request, indicating that the second communication device requests assignment of new identification information of the same identification information type as the reported identification information. In another example, in a non-initial communication scenario, the first communication device directly assigns, by default, to the second communication device new identification information corresponding to the same identification information type as the reported identification information.
[0083] In one embodiment, the communication device with which the second communication device is communicating for the first time and the communication device with which the second communication device is communicating for the non-first time are the same first communication device, or are two different first communication devices. In one example, the communication device with which the second communication device is communicating for the first time and the communication device with which the second communication device is communicating for the non-first time are the same first communication device, such as AP1. In another example, the communication device with which the second communication device is communicating for the first time and the communication device with which the second communication device is communicating for the non-first time are two different first communication devices, such as AP1 and AP2.
[0084] In one embodiment, Figure 10 is a flowchart of another identity identification method provided by an embodiment of the present application. This embodiment is applicable to identifying a second communication device in different communication scenarios. This embodiment can be performed by the second communication device. Exemplarily, the second communication device can be a non-AP STA. As shown in Figure 10, this embodiment includes: S1010.
[0085] S1010: Receive at least two pieces of identification information allocated by a first communication device.
[0086] In one embodiment, the identity identification method applied to the second communication device further includes:
[0087] Sending first support capability information to the first communication device; wherein the first support capability information is used to indicate capability information of the second communication device supporting different identification information types;
[0088] Second support capability information sent by the first communication device is received; wherein the second support capability information is used to indicate capability information of the first communication device supporting different identification information types.
[0089] In one embodiment, different flag bits are used to indicate the ability to support different identification information types;
[0090] Alternatively, the same flag bit is used to uniformly indicate the ability to support different identification information types.
[0091] In one embodiment, the carrying mode of the first support capability information includes at least one of the following: a probe request frame; an authentication frame; an association request frame;
[0092] The second support capability information is carried in one of the following ways: a beacon frame; a probe response frame; an authentication frame; or an association response frame.
[0093] In one embodiment, the identity identification method applied to the second communication device, in the first communication scenario, further includes: sending an identification information allocation request carrying an identification information type to the first communication device, so that the first communication device allocates corresponding identification information to the second communication device according to the identification information type; wherein the identification information type corresponds to the communication scenario in which the second communication device is located.
[0094] In one embodiment, in the first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
[0095] In one embodiment, in the first communication scenario, the non-association scenario includes: PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and FILS authentication.
[0096] In one embodiment, in the first communication scenario, the identification information type of the identification information includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to represent the identification information of the second communication device in a non-associated scenario; and the second identification information is used to represent the identification information of the second communication device in an associated scenario.
[0097] In one embodiment, in the first communication scenario, the frame carrying the identification information includes one of the following: the second frame authentication frame of PASN authentication in a non-association scenario; the third frame key information frame of the four-way handshake in an association scenario; and the association response frame of FILS authentication in an association scenario.
[0098] In one embodiment, in the first communication scenario, the request method for identification information of different identification information types includes one of the following: a specific flag bit; newly added element information;
[0099] The newly added element information includes at least: a first identification request flag bit and a second identification request flag bit.
[0100] In one embodiment, in the first communication scenario, the bearer frame of the identification information allocation request includes one of the following: the first frame authentication frame of PASN authentication in a non-association scenario; the second frame key information frame of the four-way handshake in an association scenario; and the association request frame of FILS authentication in an association scenario.
[0101] In one embodiment, in a non-first communication scenario, the identity recognition method applied to the second communication device further includes: reporting identification information to the first communication device.
[0102] In one embodiment, in a non-first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
[0103] In one embodiment, the non-association scenario includes: PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and FILS authentication.
[0104] In one embodiment, in a non-first communication scenario, the identity identification method applied to the second communication device further includes:
[0105] An identification information allocation request carrying the identification information type is sent to the first communication device, so that the first communication device allocates new identification information to the second communication device according to the identification information type.
[0106] In one embodiment, in a non-first communication scenario, the identification information type of the identification information reported by the second communication device includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to identify the identification information of the second communication device in an authentication scenario; and the second identification information is used to identify the identification information of the second communication device in an association scenario.
[0107] In one embodiment, in a non-first communication scenario, the request method for identification information of different identification information types includes one of the following: a specific flag; new element information; the new element information at least includes: a first identification request flag and a second identification request flag.
[0108] In one embodiment, in a non-first communication scenario, the identity recognition method applied to the first communication device further includes: receiving new identification information corresponding to the same identification information type as the reported identification information allocated by the first communication device.
[0109] In one embodiment, the communication device with which the second communication device communicates for the first time and the communication device with which the second communication device communicates for the non-first time are the same first communication device, or are two different first communication devices.
[0110] It should be noted that for the explanation of parameters such as identification information, identification information type, first support capability information, second support capability information, associated scenarios, non-associated scenarios, identification information allocation requests, and newly added elements involved in the embodiment corresponding to the identity identification method applied to the second communication device, please refer to the description of the corresponding parameters in the above-mentioned embodiment corresponding to the identity identification method applied to the first communication device, and will not be repeated here.
[0111] In one embodiment, FIG11 is a schematic diagram of an interaction for allocating identification information provided by an embodiment of the present application. As shown in FIG11 , in this embodiment, both the first communication and the non-first communication of the second communication device are completed by interacting with the same first communication device. Taking the first communication device including AP1 and AP2, the second communication device being a non-AP STA, the first communication device for the first authentication or association of the non-AP STA being AP1, and the first communication device for the non-AP STA being AP2 for the non-first authentication or association as an example, the process of allocating identification information is described. This embodiment includes the following steps:
[0112] S1110 . AP1 receives first support capability information sent by a non-AP STA.
[0113] S1120. AP1 sends second support capability information to the non-AP STA.
[0114] S1130 . AP1 receives an identification information allocation request carrying an identification information type sent by a non-AP STA.
[0115] S1140 . AP1 allocates multiple identification information to the non-AP STA according to the identification information type.
[0116] S1150 : AP2 receives the identification information reported by the non-AP STA and the identification information allocation request carrying the identification information type.
[0117] S1160 . AP2 allocates new identification information to the non-AP STA according to the identification information type.
[0118] In one example, S1130 in the embodiment shown in FIG11 may be omitted, and the identification information allocation request carrying the identification information type in S1150 may also be omitted, that is, the non-AP STA does not send the identification information allocation request, so that AP1 allocates identification information of all identification information types, and AP2 allocates new identification information of the same identification information type as the identification information reported by the non-AP STA.
[0119] In one embodiment, FIG12 is a schematic diagram of another type of interaction for assigning identification information provided by an embodiment of the present application. As shown in FIG12, in this embodiment, the first communication and non-first communication of the second communication device are completed by interaction between two different first communication devices. Taking the first communication device as AP1, the second communication device as a non-AP STA, the first communication device for the non-AP STA to authenticate or associate for the first time, and the first communication device for the non-AP STA to authenticate or associate for the non-first time as AP1 as an example, the process of assigning identification information is described. This embodiment includes the following steps:
[0120] S1210. AP1 receives first support capability information sent by a non-AP STA.
[0121] S1220. AP1 sends second support capability information to the non-AP STA.
[0122] S1230 . AP1 receives an identification information allocation request carrying an identification information type sent by a non-AP STA.
[0123] S1240. AP1 allocates multiple identification information to the non-AP STA according to the identification information type.
[0124] S1250 : AP1 receives the identification information reported by the non-AP STA and the identification information allocation request carrying the identification information type.
[0125] S1260 . AP1 allocates new identification information to the non-AP STA according to the identification information type.
[0126] In one example, S1230 in the embodiment shown in Figure 12 can be omitted, and the identification information allocation request carrying the identification information type in S1250 can also be omitted, that is, the non-AP STA does not send the identification information allocation request, so that AP1 allocates identification information of all identification information types in the first communication scenario, and enables AP1 to allocate new identification information of the same type as the identification information corresponding to the identification information reported by the non-AP STA in a non-first communication scenario.
[0127] In one embodiment, FIG13 is a block diagram of an identity recognition device provided by an embodiment of the present application. This embodiment is applied to a first communication device. As shown in FIG13 , the identity recognition device in this embodiment includes: an allocation module 1310 and an identification module 1320.
[0128] The allocation module 1310 is configured to allocate at least two pieces of identification information to the second communication device.
[0129] The identification module 1320 is configured to perform identity identification on the second communication device based on the identification information.
[0130] In one embodiment, the identification module 1320 is further configured to perform identity identification on the second communication device in the corresponding communication scenario based on the identification information.
[0131] In one embodiment, the identity recognition device applied to the first communication device further includes:
[0132] a receiving module configured to receive first support capability information sent by a second communication device; wherein the first support capability information is used to indicate capability information of the second communication device supporting different identification information types;
[0133] The sending module is configured to send second support capability information to the second communication device; wherein the second support capability information is used to indicate capability information of the first communication device supporting different identification information types.
[0134] In one embodiment, different flag bits are used to indicate the ability to support different identification information types;
[0135] Alternatively, the same flag bit is used to uniformly indicate the ability to support different identification information types.
[0136] In one embodiment, the carrying mode of the first support capability information includes at least one of the following: a probe request frame; an authentication frame; an association request frame;
[0137] The second support capability information is carried in one of the following ways: a beacon frame; a probe response frame; an authentication frame; or an association response frame.
[0138] In one embodiment, in the first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
[0139] In one embodiment, in the first communication scenario, the non-association scenario includes: PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and FILS authentication.
[0140] In one embodiment, the identification information type of the identification information includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to represent the identification information of the second communication device in a non-associated scenario; and the second identification information is used to represent the identification information of the second communication device in an associated scenario.
[0141] In one embodiment, the identity recognition device applied to the first communication device further includes:
[0142] The receiving module is further configured to receive an identification information allocation request carrying the identification information type sent by the second communication device;
[0143] The allocation module is further configured to allocate corresponding identification information to the second communication device according to the type of the identification information.
[0144] In one embodiment, the identity recognition apparatus applied to the first communication device further includes: an allocation module, further configured to allocate identification information of all identification information types to the second communication device by default.
[0145] In one embodiment, the frame carrying the identification information includes one of the following: the second authentication frame of PASN authentication in a non-association scenario; the third key information frame of a four-way handshake in an association scenario; or the association response frame of FILS authentication in an association scenario.
[0146] In one embodiment, the request method for identification information of different identification information types includes one of the following: a specific flag bit; newly added element information;
[0147] The newly added element information includes at least: a first identification request flag bit and a second identification request flag bit.
[0148] In one embodiment, the bearer frame of the identification information allocation request includes one of the following: the first authentication frame of PASN authentication in a non-association scenario; the second key information frame of a four-way handshake in an association scenario; or the association request frame of FILS authentication in an association scenario.
[0149] In one embodiment, in a non-first communication scenario, the identity recognition apparatus applied to the first communication device further includes: a receiving module, further configured to receive identification information reported by the second communication device.
[0150] In one embodiment, in a non-first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
[0151] In one embodiment, in a non-first communication scenario, the non-association scenario includes: PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and FILS authentication.
[0152] In one embodiment, in a non-first communication scenario, the identity recognition device applied to the first communication device further includes:
[0153] The receiving module is further configured to receive an identification information allocation request carrying the identification information type sent by the second communication device;
[0154] The allocation module is further configured to allocate new identification information to the second communication device according to the type of the identification information.
[0155] In one embodiment, in a non-first communication scenario, the identification information type of the identification information reported by the second communication device includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to identify the identification information of the second communication device in an authentication scenario; and the second identification information is used to identify the identification information of the second communication device in an association scenario.
[0156] In one embodiment, in a non-first communication scenario, the request method for identification information of different identification information types includes one of the following: a specific flag; new element information; the new element information at least includes: a first identification request flag and a second identification request flag.
[0157] In one embodiment, in a non-first communication scenario, the identity recognition device applied to the first communication device further includes:
[0158] The allocation module is further configured to allocate new identification information corresponding to the same identification information type as the reported identification information to the second communication device by default.
[0159] In one embodiment, the communication device with which the second communication device communicates for the first time and the communication device with which the second communication device communicates for the non-first time are the same first communication device, or are two different first communication devices.
[0160] The identity recognition device provided in this embodiment is configured to implement the identity recognition method applied to the first communication device in the embodiment shown in FIG6 . The implementation principle and technical effects of the identity recognition device provided in this embodiment are similar and will not be described in detail here.
[0161] In one embodiment, FIG14 is a block diagram of another identity recognition device provided by an embodiment of the present application. This embodiment is applied to a second communication device. As shown in FIG14 , the identity recognition device in this embodiment includes: a receiving module 1410.
[0162] The receiving module 1410 is configured to receive at least two pieces of identification information allocated by the first communication device.
[0163] In one embodiment, the identity recognition device applied to the second communication device further includes:
[0164] a sending module configured to send first support capability information to the first communication device; wherein the first support capability information is used to indicate capability information of the second communication device supporting different identification information types;
[0165] The receiving module is further configured to receive second support capability information sent by the first communication device; wherein the second support capability information is used to indicate capability information of the first communication device supporting different identification information types.
[0166] In one embodiment, different flag bits are used to indicate the ability to support different identification information types;
[0167] Alternatively, the same flag bit is used to uniformly indicate the ability to support different identification information types.
[0168] In one embodiment, the carrying mode of the first support capability information includes at least one of the following: a probe request frame; an authentication frame; an association request frame;
[0169] The second support capability information is carried in one of the following ways: a beacon frame; a probe response frame; an authentication frame; or an association response frame.
[0170] In one embodiment, the identity recognition device applied to the second communication device, in the first communication scenario, further includes:
[0171] The sending module is also configured to send an identification information allocation request carrying an identification information type to the first communication device, so that the first communication device allocates corresponding identification information to the second communication device according to the identification information type; wherein the identification information type corresponds to the communication scenario in which the second communication device is located.
[0172] In one embodiment, in the first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
[0173] In one embodiment, in the first communication scenario, the non-association scenario includes: PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and FILS authentication.
[0174] In one embodiment, in the first communication scenario, the identification information type of the identification information includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to represent the identification information of the second communication device in a non-associated scenario; and the second identification information is used to represent the identification information of the second communication device in an associated scenario.
[0175] In one embodiment, in the first communication scenario, the frame carrying the identification information includes one of the following: the second frame authentication frame of PASN authentication in a non-association scenario; the third frame key information frame of the four-way handshake in an association scenario; and the association response frame of FILS authentication in an association scenario.
[0176] In one embodiment, in the first communication scenario, the request method for identification information of different identification information types includes one of the following: a specific flag bit; newly added element information;
[0177] The newly added element information includes at least: a first identification request flag bit and a second identification request flag bit.
[0178] In one embodiment, in the first communication scenario, the bearer frame of the identification information allocation request includes one of the following: the first frame authentication frame of PASN authentication in a non-association scenario; the second frame key information frame of the four-way handshake in an association scenario; and the association request frame of FILS authentication in an association scenario.
[0179] In one embodiment, in a non-first communication scenario, the identity recognition method applied to the second communication device further includes: reporting identification information to the first communication device.
[0180] In one embodiment, in a non-first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
[0181] In one embodiment, in a non-first communication scenario, the non-association scenario includes: PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and FILS authentication.
[0182] In one embodiment, in a non-first communication scenario, the identity recognition device applied to the second communication device further includes:
[0183] The sending module is further configured to send an identification information allocation request carrying the identification information type to the first communication device, so that the first communication device allocates new identification information to the second communication device according to the identification information type.
[0184] In one embodiment, in a non-first communication scenario, the identification information type of the identification information reported by the second communication device includes at least one of the following: first identification information and second identification information; wherein the first identification information is used to identify the identification information of the second communication device in an authentication scenario; and the second identification information is used to identify the identification information of the second communication device in an association scenario.
[0185] In one embodiment, in a non-first communication scenario, the request method for identification information of different identification information types includes one of the following: a specific flag; new element information; the new element information at least includes: a first identification request flag and a second identification request flag.
[0186] In one embodiment, in a non-first communication scenario, the identity recognition device applied to the first communication device further includes:
[0187] The receiving module is further configured to receive new identification information corresponding to the same identification information type as the reported identification information, which is allocated by the first communication device.
[0188] In one embodiment, the communication device with which the second communication device communicates for the first time and the communication device with which the second communication device communicates for the non-first time are the same first communication device, or are two different first communication devices.
[0189] The identity recognition device provided in this embodiment is configured to implement the identity recognition method applied to the second communication device in the embodiment shown in FIG10 . The implementation principle and technical effects of the identity recognition device provided in this embodiment are similar and will not be described in detail here.
[0190] In one embodiment, Figure 15 is a schematic diagram of the structure of a communication device provided by an embodiment of the present application. As shown in Figure 15, the device provided by the present application includes: a processor 1510, a memory 1520, and a communication module 1530. The number of processors 1510 in the device can be one or more, and Figure 15 uses one processor 1510 as an example. The number of memories 1520 in the device can be one or more, and Figure 15 uses one memory 1520 as an example. The processor 1510, memory 1520, and communication module 1530 of the device can be connected via a bus or other means, and Figure 15 uses a bus connection as an example. In this embodiment, the device can be a first communication device or a second communication device.
[0191] The memory 1520, as a computer-readable storage medium, can be configured to store software programs, computer executable programs, and modules, such as program instructions / modules corresponding to the device of any embodiment of the present application (for example, the allocation module 1310 and the identification module 1320 applied to the identity recognition device of the first communication device). The memory 1520 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and applications required for at least one function; the data storage area may store data created based on the use of the device, etc. In addition, the memory 1520 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage device. In some instances, the memory 1520 may further include a memory remotely located relative to the processor 1510, and these remote memories may be connected to the device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0192] In the case where the communication device is a first communication device, the device provided above can be configured to execute the identity recognition method applied to the first communication device provided in any of the above embodiments, and have corresponding functions and effects.
[0193] In the case where the communication device is a second communication device, the device provided above can be configured to execute the identity recognition method applied to the second communication device provided in any of the above embodiments, and have corresponding functions and effects.
[0194] An embodiment of the present application also provides a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to execute an identity identification method applied to a first communication device, the method comprising: assigning at least two identification information to a second communication device; and performing identity identification on the second communication device based on the identification information.
[0195] An embodiment of the present application also provides a storage medium containing computer-executable instructions. When the computer-executable instructions are executed by a computer processor, they are used to execute an identity recognition method applied to a second communication device. The method includes: receiving at least two identification information assigned by a first communication device.
[0196] It will be appreciated by those skilled in the art that the term user equipment encompasses any suitable type of wireless user equipment, such as a mobile phone, a portable data processing device, a portable web browser or a car-mounted mobile station.
[0197] In general, various embodiments of the present application may be implemented in hardware or dedicated circuits, software, logic, or any combination thereof. For example, some aspects may be implemented in hardware, while other aspects may be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device, although the present application is not limited thereto.
[0198] Embodiments of the present application may be implemented by executing computer program instructions by a data processor of a mobile device, for example, in a processor entity, or by hardware, or by a combination of software and hardware. The computer program instructions may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages.
[0199] The block diagram of any logic flow in the drawings of the present application may represent program steps, or may represent interconnected logic circuits, modules and functions, or may represent a combination of program steps and logic circuits, modules and functions. A computer program may be stored on a memory. The memory may be of any type suitable for the local technical environment and may be implemented using any suitable data storage technology, such as, but not limited to, read-only memory (ROM), random access memory (RAM), optical storage devices and systems (digital versatile discs (DVD) or compact disks (CD)), etc. Computer-readable media may include non-transient storage media. A data processor may be of any type suitable for the local technical environment, such as, but not limited to, a general-purpose computer, a special-purpose computer, a microprocessor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), and a processor based on a multi-core processor architecture.
[0200] An embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, can implement the identity recognition method provided in any embodiment of the present application.
[0201] The computer program product may be implemented in a computer program code that performs the operations of the present application written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0202] The above are merely optional embodiments of the present application and are not intended to limit the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application.
Claims
1. An identity identification method, applied to a first communication device, comprising: Allocating at least two pieces of identification information to the second communication device; The second communication device is identified based on the identification information.
2. The method according to claim 1, wherein The performing identity identification on the second communication device based on the identification information includes: The identity of the second communication device in the corresponding communication scenario is identified based on the identification information.
3. The method according to claim 1, further comprising: Receiving first support capability information sent by the second communication device; wherein the first support capability information is used to indicate capability information of the second communication device supporting different identification information types; Sending second support capability information to the second communication device; wherein the second support capability information is used to indicate capability information of the first communication device supporting different identification information types.
4. The method according to claim 3, wherein: Different flag bits are used to indicate the ability to support different identification information types; Alternatively, the same flag bit is used to uniformly indicate the ability to support different identification information types.
5. The method according to claim 3, wherein The carrying mode of the first support capability information includes at least one of the following: a probe request frame; an authentication frame; an association request frame; The carrying manner of the second support capability information includes one of the following: a beacon frame; a probe response frame; an authentication frame; and an association response frame.
6. The method according to any one of claims 1 to 5, wherein: In the first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
7. The method according to claim 6, wherein: The non-association scenario includes: pre-association security negotiation PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; and fast initial link establishment FILS authentication.
8. The method according to claim 6, wherein: The identification information type of the identification information includes at least one of the following: first identification information and second identification information; wherein, the first identification information is used to represent the identification information of the second communication device in a non-associated scenario; and the second identification information is used to represent the identification information of the second communication device in an associated scenario.
9. The method according to claim 6, further comprising: receiving an identification information allocation request carrying an identification information type sent by the second communication device; Corresponding identification information is allocated to the second communication device according to the identification information type.
10. The method according to claim 6, further comprising: By default, identification information of all identification information types is allocated to the second communication device.
11. The method according to claim 6, wherein: The identification information bearing frame includes one of the following: the second frame authentication frame of PASN authentication in the non-association scenario; the third frame key information frame of the four-way handshake in the association scenario; and the association response frame of FILS authentication in the association scenario.
12. The method according to claim 9, wherein The request method for identification information of different identification information types includes one of the following: a specific flag bit; newly added element information; The newly added element information includes at least: a first identification request flag bit and a second identification request flag bit.
13. The method according to claim 9, wherein: The bearer frame of the identification information allocation request includes one of the following: the first authentication frame of PASN authentication in the non-association scenario; the second key information frame of the four-way handshake in the association scenario; and the association request frame of FILS authentication in the association scenario.
14. The method according to any one of claims 1 to 5, further comprising: Receive identification information reported by the second communication device.
15. The method according to claim 14, wherein In the non-first communication scenario, the communication scenario includes one of the following: an associated scenario; a non-associated scenario.
16. The method according to claim 15, wherein The non-association scenario includes: PASN authentication; the association scenario includes at least one of the following: a four-way handshake after association; FILS authentication.
17. The method according to claim 14, further comprising: receiving an identification information allocation request carrying an identification information type sent by a second communication device; New identification information is allocated to the second communication device according to the identification information type.
18. The method according to claim 14, wherein The identification information type of the identification information reported by the second communication device includes at least one of the following: first identification information and second identification information; wherein, the first identification information is used to identify the identification information of the second communication device in the authentication scenario; the second identification information is used to identify the identification information of the second communication device in the association scenario.
19. The method according to claim 14, wherein The request method for identification information of different identification information types includes one of the following: a specific flag bit; newly added element information; The newly added element information includes at least: a first identification request flag bit and a second identification request flag bit.
20. The method of claim 14, further comprising: By default, new identification information corresponding to the same identification information type as the reported identification information is allocated to the second communication device.
21. The method according to claim 14, wherein The communication device with which the second communication device communicates for the first time and the communication device with which the second communication device communicates for the non-first time are the same first communication device, or are two different first communication devices.
22. An identity recognition method, applied to a second communication device, comprising: At least two pieces of identification information allocated by the first communication device are received.
23. The method according to claim 22, further comprising: Sending first support capability information to the first communication device; wherein the first support capability information is used to indicate capability information of the second communication device supporting different identification information types; Receive second support capability information sent by the first communication device; wherein the second support capability information is used to indicate capability information of the first communication device supporting different identification information types.
24. The method according to claim 22, in the first communication scenario, further comprising: An identification information allocation request carrying an identification information type is sent to the first communication device, so that the first communication device allocates corresponding identification information to the second communication device according to the identification information type; wherein the identification information type corresponds to the communication scenario in which the second communication device is located.
25. The method according to claim 22, in a non-first communication scenario, further comprising: Report identification information to the first communication device.
26. The method according to claim 22, in a non-first communication scenario, further comprising: An identification information allocation request carrying an identification information type is sent to the first communication device, so that the first communication device allocates new identification information to the second communication device according to the identification information type.
27. The method according to claim 22, in a non-first communication scenario, further comprising: Receive new identification information corresponding to the same identification information type as the reported identification information allocated by the first communication device.
28. A communication device comprising: memory, and one or more processors; The memory is configured to store one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as claimed in any one of claims 1 to 21 or 22 to 27.
29. A storage medium storing a computer program, wherein when the computer program is executed by a processor, the method according to any one of claims 1 to 21 or 22 to 27 is implemented.