Identity recognition method

By assigning identity information to workstations, the problem of identifying non-AP MLD devices in the 802.11be standard when the link state changes is solved, thus enabling successful PASN authentication and effective resource management.

WO2026031639A1PCT designated stage Publication Date: 2026-02-12ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/089620
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-08-08
Filing Date
2025-04-17
Publication Date
2026-02-12

AI Technical Summary

Technical Problem

In the 802.11be standard, non-AP MLD devices cannot effectively identify themselves in PASN authentication when the link state changes, resulting in PASN authentication failure.

Method used

Assign identity information to workstations for pre-association security negotiation PASN, and perform identity verification based on this identity information during PASN authentication.

Benefits of technology

This solves the problem of identity recognition when the workstation link status changes, ensures the successful execution of PASN authentication, and avoids resource waste and network function failure.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025089620_12022026_PF_FP_ABST
    Figure CN2025089620_12022026_PF_FP_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure provide an identity recognition method, comprising: allocating, to a workstation, identifier information for pre-association security negotiation (PASN); and, on the basis of the identifier information, during PASN authentication, performing identity recognition of the workstation for which a link state has changed.
Need to check novelty before this filing date? Find Prior Art

Description

An identity recognition method

[0001] Cross-reference to related disclosures

[0002] The present disclosure is based on Chinese Patent Publication 2024110930157 entitled "An identity recognition method" filed on August 08, 2024, and claiming priority to the patent publication, the disclosure of which is incorporated herein by reference in its entirety. TECHNICAL FIELD

[0003] Embodiments of the present disclosure relate to the technical field of wireless communication, in particular, to an identity recognition method. BACKGROUND

[0004] In 802.11be, it is required to support the form switching of non-AP (Access Point, AP) MLD (Multicast Listener Discover) and non-AP STA (Station), specifically as follows: non-AP MLD1 and AP MLD1 connection, when the non-AP MLD1 needs to communicate with the non-MLD AP2 single-link access point in the extended service set (ESS), the non-AP MLD1 multi-link device will become a non-AP STA single-link device, and vice versa.

[0005] Although PASN authentication is not supported in the multi-link scenario, when the non-AP MLD multi-link device becomes a single-link device non-AP STA through the above Case1, the non-AP STA can use pre-association security negotiation (PASN) authentication, and since the AP MLD only allocates a device ID to the non-AP MLD in the multi-link scenario, the non-AP STA cannot provide valid identity information to the AP in the PASN authentication, and cannot perform PASN authentication.

[0006] There is no solution to the problem that the identity cannot be recognized in the PASN authentication when the link state of the workstation changes in the related art. SUMMARY

[0007] Embodiments of the present disclosure provide an identity recognition method to at least solve the problem that the identity cannot be recognized in the PASN authentication when the link state of the workstation changes in the related art.

[0008] According to an embodiment of the present disclosure, an identity recognition method is provided, the method comprising:

[0009] In a scenario of association, identity information of a pre-association security negotiation (PASN) is allocated to the workstation;

[0010] The workstation with the link state changed is identified based on the identity information in the PASN authentication.

[0011] According to another embodiment of the present disclosure, a method for identity identification is also provided, which is applied to a workstation and includes the following steps:

[0012] In a scenario of association, identity information of a pre-association security negotiation (PASN) allocated by an access point device is received;

[0013] When the link state changes, the workstation is identified based on the identity information in the PASN authentication with the access point device.

[0014] According to still another embodiment of the present disclosure, a computer program product is also provided, which includes computer program instructions, and the computer program instructions enable a computer to implement the steps in any of the above method embodiments.

[0015] According to still another embodiment of the present disclosure, a computer readable storage medium is also provided, which stores a computer program, and the computer program is configured to execute the steps in any of the above method embodiments when running.

[0016] According to still another embodiment of the present disclosure, an electronic device is also provided, which includes a memory and a processor, the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any of the above method embodiments.

[0017] In the present disclosure, in a scenario of association, identity information of a pre-association security negotiation (PASN) is allocated to the workstation; and the workstation with the link state changed is identified based on the identity information in the PASN authentication, which can solve the problem that the workstation with the link state changed cannot be identified in the PASN authentication in the related art, and the identity of the workstation with the link state changed is identified in the PASN authentication based on the allocated identity information. BRIEF DESCRIPTION OF DRAWINGS

[0018] FIG. 1 is a hardware structure block diagram of a computer device of a method for identity identification according to an embodiment of the present disclosure;

[0019] FIG. 2 is a flowchart one of a method for identity identification according to an embodiment of the present disclosure;

[0020] FIG. 3 is a flowchart two of a method for identity identification according to an embodiment of the present disclosure;

[0021] FIG. 4 is a flowchart of allocation, update and recycling of identity information according to an embodiment of the present disclosure;

[0022] FIG. 5 is a schematic diagram of PASN ID element extension according to the present embodiment;

[0023] FIG. 6 is a schematic diagram of PASN ID element extension according to the present embodiment;

[0024] FIG. 7 is a flowchart of identity information allocation according to the present embodiment;

[0025] FIG. 8 is a flowchart of identity information allocation according to the present embodiment;

[0026] FIG. 9 is a flowchart of identity information allocation according to the present embodiment. DETAILED DESCRIPTION

[0027] Hereinafter, the embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.

[0028] It should be noted that the terms "first", "second", and the like in the description and claims of the present disclosure and the above-described accompanying drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.

[0029] The method embodiments provided in the embodiments of the present disclosure can be executed in a computer device or a similar computing device. Taking an example of running on a computer device, FIG. 1 is a hardware structure block diagram of a computer device of an identity recognition method according to an embodiment of the present disclosure, as shown in FIG. 1, the computer device can include one or more (only one is shown in FIG. 1) processors 102 (the processor 102 can include but not limited to a processing device such as a microprocessor MCU or programmable logic device) and a memory 104 configured to store data, wherein the above-mentioned computer device can further include a transmission device 106 configured to have a communication function and an input and output device 108. Those skilled in the art can understand that the structure shown in FIG. 1 is only schematic, which does not limit the structure of the above-mentioned computer device. For example, the computer device can further include more or less components than those shown in FIG. 1, or have a different configuration from that shown in FIG. 1.

[0030] The memory 104 can be configured to store computer programs, such as software programs of application software and modules, such as a computer program corresponding to the identity recognition method in the embodiments of the present disclosure. The processor 102 can execute various functions of the application and the single board matching by running the computer program stored in the memory 104, that is, implement the method described above. The memory 104 can include a high-speed random access memory, and can further include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, and the remote memory can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0031] The transmission device 106 is configured to receive or send data via a network. The specific example of the network can include a wireless network provided by a communication provider of the computer device. In one example, the transmission device 106 includes a network adapter (NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is configured to communicate with the Internet in a wireless manner.

[0032] In the 802.11bh standard, the access point (AP) in the Device ID technology allocates two pieces of identification information, Device ID and pre-association security negotiation identity (PASN ID), to a station (STA) at the same time, which are used for identity recognition of the STA in the association scenario and the PASN authentication scenario, respectively. The association scenario includes four handshakes, fast transition (FT) four handshakes, and fast initial link setup (FILS) authentication. The four handshake scenarios include: in the first connection, the AP 1 allocates the Device ID and the PASN ID 1 to the non-AP STA at the same time through the third frame in the four handshakes; after the non-AP STA is connected to the AP 2, the non-AP STA reports the Device ID allocated by the AP 1 to the AP 2 in the second frame in the four handshakes; and the AP 2 informs the non-AP STA that the Device ID information reported by the non-AP STA has been identified in the third frame in the four handshakes.

[0033] In the related art, the FILS authentication includes: in the first connection, the AP1 allocates the Device ID1 and the PASN ID1 for the non-AP STA at the same time through the association response frame in the FILS authentication; the non-AP STA reports the Device ID1 allocated by the AP1 to the AP2 in the association request frame in the FILS authentication after connecting with the AP2; the AP2 informs the non-AP STA that the Device ID information reported by the non-AP STA has been identified, and allocates the new Device ID2 and the PASN ID2 in the association response frame in the FILS authentication.

[0034] The PASN authentication can further include: in the first connection, the AP1 allocates the Device ID1 and the PASN ID1 for the non-AP STA at the same time through the second frame in the PASN authentication; the non-AP STA reports the PASN ID1 allocated by the AP1 to the AP2 in the first frame when performing the PASN authentication with the AP2; the AP2 informs the non-AP STA that the Device ID information reported by the non-AP STA has been identified, and allocates the new PASN ID2 in the second frame in the PASN authentication; the non-AP STA reports the PASN ID2 allocated by the AP2 to the AP1 in the first frame when performing the PASN authentication with the AP1 again; the AP1 informs the non-AP STA that the Device ID information reported by the non-AP STA has been identified, and allocates the new PASN ID3 in the second frame in the PASN authentication.

[0035] In the embodiment, an identity recognition method running on the computer device is provided, and FIG. 2 is a flowchart of the identity recognition method according to the embodiment of the present disclosure, as shown in FIG. 2, the method is applied to an access point device, and the flowchart includes the following steps.

[0036] In step S202, identity identification information for PASN in a pre-association security negotiation is allocated for a workstation in an association scenario.

[0037] In step S204, the workstation with a link state change is identified based on the identity identification information in the PASN authentication.

[0038] In step S204, the execution subject of the identity recognition of the workstation with the link state change based on the identity identification information in the PASN authentication can be an access point device (that is, a current access point device) allocating the identity identification information, or can be another access point device in an ESS.

[0039] Through the steps S202 to S204, the problem that the identity of the workstation cannot be identified in the PASN authentication when the link state of the workstation changes in the related art can be solved, and the identity of the workstation can be identified in the PASN authentication based on the allocated identity information when the link state of the workstation changes.

[0040] In the embodiment of the present disclosure, the step S202 can specifically include one of the following: if the PASN authentication function or the PASN authentication is enabled, requesting to allocate the identity information for the workstation according to the identity information; and if the PASN authentication function or the PASN authentication is enabled, allocating the identity information for the workstation.

[0041] In an embodiment, before the step S202, the method further includes: receiving an identity information request sent by the workstation, the identity information request being used to request to allocate or not to allocate the identity information.

[0042] Specifically, the identity information request includes indication information, and the indication information is used to request to allocate or not to allocate the identity information.

[0043] Further, the method further includes: in a case where the indication information indicates to request to allocate the identity information, sending an identity information response carrying the identity information to the workstation; and in a case where the indication information indicates not to allocate the identity information, sending an identity information response to the workstation and not allocating the identity information.

[0044] In the embodiment, the method further includes: receiving an identity information update request sent by the workstation; and sending an identity information update response carrying updated identity information to the workstation.

[0045] In the embodiment, the method further includes: receiving an identity information recovery request sent by the workstation; and recovering the identity information according to the identity information recovery request.

[0046] The identity information request, the identity information update request, and the identity information recovery request in the embodiment are carried in one of the following messages: a second frame of four-way handshake, a second frame of FT four-way handshake, an association request frame of fast initial link setup (FILS) authentication, other management frames, and an action frame.

[0047] The identity information request, the identity information update request, and the identity information recovery request in the embodiment carry a PASN ID element, and the PASN ID element is used to indicate a request type.

[0048] In the embodiment, the identity information response is carried in one of the following messages: the third frame of the four-way handshake, the third frame of the FT four-way handshake, the association response frame of the fast initial link setup (FILS) authentication, other management frames, and the action frame.

[0049] In the embodiment of the present disclosure, the step S204 can specifically include: for the single-link case, identity identification of the workstation converted from the multi-link to the single-link in the PASN authentication based on the identity information; and for the multi-link case, identity identification of the workstation converted from the single-link to the multi-link in the PASN authentication based on the identity information. The workstation in the embodiment of the present disclosure is the multi-link workstation or the single-link workstation; the link state change includes conversion from the multi-link to the single-link or conversion from the single-link to the multi-link. The identity identification process can specifically include: the access point device receives the identity information carried in the first PASN authentication frame sent by the workstation, carries the identification state of the identity information in the second PASN authentication frame sent to the workstation, and allocates new identity information to the workstation.

[0050] The association scenario in the embodiment includes at least one of the following: the four-way handshake, the FT four-way handshake, and the fast initial link setup (FILS) authentication.

[0051] The embodiment of the present disclosure provides an identity identification method, and FIG. 3 is a flowchart two of the identity identification method according to the embodiment of the present disclosure, as shown in FIG. 3, applied to a workstation, the method includes:

[0052] In step S302, in the association scenario, identity identification information for the pre-association security negotiation (PASN) allocated by the access point device is received.

[0053] In step S304, when the link state changes, identity identification with the access point device in the PASN authentication based on the identity information is performed.

[0054] Further, the identity identification process can specifically include: the identity information carried in the first PASN authentication frame sent by the workstation to the access point device, the identification state of the identity information carried in the second PASN authentication frame sent by the access point device, and the new identity information allocated by the access point device.

[0055] In the step S304, identity identification with the access point device in the PASN authentication based on the identity information, wherein the access point device can be the access point device allocating the identity information (i.e., the current access point device), or can be other access point devices in the ESS.

[0056] Through the steps S302 to S304, the problem that the identity cannot be identified in the PASN authentication when the link state of the workstation changes in the related art can be solved, and the identity can be identified in the PASN authentication based on the allocated identity identification information when the link state of the workstation changes.

[0057] In the embodiment of the present disclosure, the step S302 can specifically include:

[0058] The access point device is configured to allocate the identity identification information according to the identity identification information request.

[0059] In an embodiment, before the step S302, the method further includes: sending an identity identification information request to the access point device, the identity identification information request being used to request allocation or non-allocation of the identity identification information.

[0060] Specifically, the identity identification information request includes indication information, the indication information being used to request allocation or non-allocation of the identity identification information.

[0061] In an embodiment, the method further includes: in a case where the indication information indicates that the identity identification information is requested to be allocated, receiving an identity identification information response sent by the access point device, the identity identification information response carrying the identity identification information.

[0062] In an embodiment, the method further includes: sending an identity identification information update request to the access point device; and receiving an identity identification information update response sent by the access point device, the identity identification information update response carrying updated identity identification information.

[0063] In another embodiment, the method further includes: sending an identity identification information recovery request to the access point device, the identity identification information recovery request being used to request the access point device to recover the identity identification information.

[0064] The identity identification information request, the identity identification information update request and the identity identification information recovery request in the embodiment are carried in one of the following messages: a second frame of four-way handshake, a second frame of FT four-way handshake, an association request frame of fast initial link setup FILS authentication, other management frames, and an action frame.

[0065] The identity identification information request, the identity identification information update request and the identity identification information recovery request in the embodiment carry a PASN ID element, and the PASN ID element is used to indicate a request type.

[0066] The identity information response in the embodiment and the identity information update response are carried in one of the following messages: the third frame of the four-way handshake, the third frame of the FT four-way handshake, the association response frame of the fast initial link setup FILS authentication, other management frames, and the action frame. The association scenarios in the embodiment include at least one of the following: the four-way handshake, the FT four-way handshake, and the fast initial link setup FILS authentication.

[0067] In the embodiment, the step S304 can specifically include: when the multi-link device is converted into the single-link device, identity identification is performed when the single-link access point device is authenticated by the PASN; or when the single-link device is converted into the multi-link device, identity identification is performed when the multi-link access point device is authenticated by the PASN.

[0068] The access point device in the embodiment is a multi-link access point device or a single-link access point device; and the link state change includes conversion from the multi-link to the single-link or conversion from the single-link to the multi-link.

[0069] The embodiment supports the allocation, update, and recycling of the identity information (PASN ID) of the workstation supporting the random address access (RMA) technology. FIG. 4 is a flowchart of the allocation, update, and recycling of the identity information according to the embodiment of the present disclosure. As shown in FIG. 4, the process includes the following steps:

[0070] S401, the AP sends an identity information request to the STA;

[0071] S402, the STA performs identity identification in the PASN authentication after the link state changes;

[0072] S403, the STA sends an identity information update request to the AP;

[0073] S404, the AP sends an identity information update response to the STA;

[0074] S405, the STA sends an identity information recycling request to the AP;

[0075] S406, the AP recycles the identity information of the STA.

[0076] In the association scenario, the AP assigns an identity information (PASN ID) to the STA through the first frame, and identifies the STA whose link state changes in the PASN authentication based on the identity information (PASN ID). In the association scenario, the STA sends an identity information (PASN) update request to the AP, and requests to update the identity information (PASN ID). The AP sends an identity information (PASN ID) update response to the STA, and the response contains the updated identity information (PASN ID) assigned by the AP to the STA. In the association scenario, the STA sends an identity information (PASN ID) recovery to the AP. The AP recovers the identity information (PASN ID) of the STA.

[0077] In some application embodiments, the association scenario includes at least one of the following: four-way handshake, FT four-way handshake, and FILS authentication.

[0078] In some application embodiments, the link state change of the STA includes that the STA changes from a multi-link device (non-AP MLD) to a single-link device (non-AP STA), or the STA changes from a single-link device to a multi-link device.

[0079] In some application embodiments, before the AP assigns an identity information (PASN ID) to the STA through the first information frame, the method further includes that the STA sends an identity information request to the AP.

[0080] In a multi-link scenario, the non-AP MLD does not support the PASN authentication, but when the non-AP MLD multi-link device becomes a single-link device non-AP STA, the non-AP STA can use the PASN authentication. However, since the AP MLD only allocates the Device ID to the non-AP MLD in the multi-link scenario, the non-AP STA cannot provide valid identity information to the AP in the PASN authentication, that is, the AP considers the non-AP STA as a new device, and cannot identify the non-AP STA and the previous non-AP MLD as the same device, which finally leads to the failure of the network diagnosis, service binding and other functions. In the embodiment, the identity information request includes indication information, and the indication information is used to indicate whether the identity information is allocated. When the indication indicates that the identity information is allocated, the AP sends the identity information response to the STA, and carries the identity information in the identity information response, so as to facilitate the identity identification in the PASN authentication when the link state changes. In a single-link scenario, the non-AP STA can not support the PASN authentication, or although it supports the PASN authentication, it decides not to use the authentication mode subsequently. In 802.11bh, the AP will allocate the PASN ID to the non-AP STA by default, which will cause the non-AP STA and the AP to maintain the unused PASN ID parameter, causing waste of additional resources. When the indication information requests not to allocate the identity information, the AP does not send the identity information response to the STA and does not allocate the identity information, thereby effectively avoiding the waste of resources.

[0081] FIG. 5 is a schematic diagram of the PASN ID element extension according to the embodiment, as shown in FIG. 5, the identity information request includes indication information, and the indication information only indicates that the identity information is not allocated. When the indication indicates that the identity information is not allocated, the AP does not send the identity information response to the STA and does not allocate the identity information, as shown in Table 1.

[0082] Table 1

[0083] The non-AP STA can lose the PASN ID information during operation, and there is currently no update process. When the PASN authentication is performed, if the previously allocated PASN ID information (such as PASN ID1) is lost, the AP will identify the non-AP STA as a new station in the next PASN authentication, and cannot bind the non-AP STA with the station to which the PASN ID (PASN ID1) is previously allocated.

[0084] Non-AP STA may lose the PASN ID information during running. When performing PASN authentication, if the previously allocated PASN ID information (such as PASN ID1) is lost, the AP will identify the Non-AP STA as a new station in the next PASN authentication, and cannot bind the Non-AP STA with the station to which the PASN ID (PASN ID1) is allocated. To solve the problem, the identity information is updated in the embodiment, that is, the identity information is updated through an identity information update request.

[0085] For Non-AP STA, even if the PASN authentication function is supported, it may dynamically decide whether to continue to perform the PASN authentication operation subsequently. For example, the Non-AP STA is allocated with a PASN ID, and performs the PASN authentication operation at T1. Subsequently, it is decided at T2 (T2>T1) that the PASN authentication operation is not performed subsequently, causing the Non-AP STA and the AP to maintain the unused PASN ID parameter, and causing the waste of additional resources. Based on this, the identity information can also be recycled in the embodiment.

[0086] FIG. 6 is a schematic diagram of the PASN ID element extension according to the embodiment. As shown in FIG. 6, the existing PASN ID element is extended, and a type field is added to support the request, update and recycle of the identity information. The identity information request, the identity information update request and the identity information recycle are shown in Table 2.

[0087] Table 2

[0088] Message carrying mode 1: the identity information request, the identity information update request and the identity information recycle can be carried in the following messages: the second frame of the four-way handshake, the second frame of the FT four-way handshake, the association request frame of the FILS authentication or other management frames or action frames;

[0089] Message carrying mode 2: the identity information response and the identity information update response can be carried in the following messages: the third frame of the four-way handshake, the third frame of the FT four-way handshake, the association response frame of the FILS authentication or other management frames or action frames.

[0090] In an embodiment, the identity information allocation can also not require the STA to send the identity information request to the AP, and the AP allocates the identity information,

[0091] In some application embodiments, the STA can be a single-link workstation non-AP STA, or a multi-link workstation non-AP MLD; the AP can be a single-link access point device, or a multi-link access point device AP MLD.

[0092] In some application embodiments, the multi-link access point (AP MLD) allocates identity information (PASN ID) to the multi-link station (non-AP MLD) for subsequent identity identification when the multi-link station switches to a single-link station (non-AP STA) for communication with a single-link access point (AP) for PASN authentication.

[0093] In some application embodiments, the single-link access point (AP) allocates identity information (PASN ID) to the single-link station (non-AP STA) for subsequent identity identification when the single-link station switches to a multi-link station (non-AP MLD) for communication with a multi-link access point (AP MLD) for PASN authentication.

[0094] The identity identification request sent by the STA contains the PASN ID element as shown in FIG. 5, which contains the PASN ID status as indication information. Specifically, when set to 2, it indicates that no PASN ID is allocated. When the STA sends the PASN ID element, it does not contain the PASN ID field.

[0095] When the STA sends the identity identification information request, update and recycling, it carries the PASN ID element as shown in FIG. 6, which contains the Request type field indicating the corresponding request type. When the STA sends the PASN ID element, it does not contain the PASN ID field.

[0096] FIG. 7 is a flowchart of identity identification information allocation according to the present embodiment, as shown in FIG. 7, which includes:

[0097] S701, the STA performs authentication association with the AP MLD1 in the form of a multi-link device non-AP MLD;

[0098] S702, the STA carries the identity identification information request in the second frame of the FT four-way handshake, as shown in FIG. 6.

[0099] S703, the AP carries the identity information PASN ID1 allocated to the STA in the third frame of the FT four-way handshake;

[0100] S704, after disassociating with the AP MLD1, the STA switches to a single-link device form and performs PASN authentication with the AP2 as a non-AP STA;

[0101] S705, in the PASN authentication, the STA carries the PASN ID1 allocated by the previous AP MLD1 in a first PASN authentication frame;

[0102] S706, the AP2 allocates a new PASN ID2 for the STA in a second PASN authentication frame.

[0103] FIG. 8 is a flowchart II of identity information allocation according to the present embodiment, as shown in FIG. 8, which includes:

[0104] S801, the STA performs authentication and association with the AP MLD1 as a non-AP MLD in a multi-link device form;

[0105] S802, the AP allocates identity information PASN ID1 to the STA by default in a third frame of the FT four-way handshake;

[0106] S803, after disassociating with the AP MLD1, the STA switches to a single-link device form and performs PASN authentication with the AP2 as a non-AP STA;

[0107] S804, in the PASN authentication, the STA carries the PASN ID1 allocated by the previous AP MLD1 in a first PASN authentication frame;

[0108] S805, the AP2 allocates a new PASN ID2 for the STA in a second PASN authentication frame.

[0109] FIG. 9 is a flowchart III of identity information allocation according to the present embodiment, as shown in FIG. 9, which includes:

[0110] S901, the AP allocates PASN ID to the STA by default;

[0111] S902, the STA carries the PASN ID element in the identity information request, as shown in FIG. 5, wherein the PASN ID status is set to 2, indicating not request;

[0112] S903, the AP does not allocate PASN ID to the STA in the identity information response.

[0113] The present disclosure also provides a computer program product comprising computer program instructions, wherein the computer program instructions cause a computer to implement the steps in any of the above method embodiments.

[0114] The embodiments of the present disclosure further provide a computer readable storage medium, which stores a computer program, and the computer program is configured to execute the steps in any of the above method embodiments when running.

[0115] In an example embodiment, the above computer readable storage medium can include, but is not limited to, a U disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.

[0116] The embodiments of the present disclosure further provide an electronic device, which comprises a memory storing a computer program and a processor configured to execute the computer program to perform the steps in any of the above method embodiments.

[0117] In an example embodiment, the above electronic device can further comprise a transmission device connected to the processor and an input / output device connected to the processor.

[0118] The specific examples in the embodiments can refer to the examples described in the above embodiments and example embodiments, and the embodiments will not be described here again.

[0119] Obviously, those skilled in the art should understand that the above modules or steps of the present disclosure can be realized by general computing devices, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and they can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps can be manufactured into a single integrated circuit module. Therefore, the present disclosure is not limited to any specific combination of hardware and software.

[0120] The above only describes the preferred embodiments of the present disclosure and is not intended to limit the present disclosure. For those skilled in the art, the present disclosure can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the principles of the present disclosure shall be included in the protection scope of the present disclosure.

Claims

1. An identity recognition method applied to an access point device, the method comprising: allocating identity information for pre-association security negotiation (PASN) to a station in an association scenario; and recognizing the station with a link state change in a PASN authentication based on the identity information.

2. The method of claim 1, wherein, The allocating of the identity information for the PASN to the station comprises one of: requesting the allocation of the identity information to the station according to identity information if a PASN authentication function or a PASN authentication enablement is supported; and allocating the identity information to the station if the PASN authentication function or the PASN authentication enablement is supported.

3. The method of claim 2, wherein, Before the allocating of the identity information for the PASN to the station, the method further comprises: receiving a request of the identity information from the station, wherein the request is for requesting the allocation or non-allocation of the identity information.

4. The method of claim 3, wherein the request of the identity information comprises indication information, wherein the indication information is for requesting the allocation or non-allocation of the identity information.

5. The method of claim 4, wherein, The method further comprises: sending a response of the identity information to the station if the indication information indicates the request of the allocation of the identity information, wherein the response of the identity information carries the identity information.

6. The method of claim 2, wherein, The method further comprises: receiving a request of identity information update from the station; sending a response of the identity information update to the station, wherein the response of the identity information update carries updated identity information.

7. The method of claim 6, wherein, The method further comprises: receiving a request of identity information recovery from the station; retrieving the identity information according to the request of the identity information recovery.

8. The method of claim 7, wherein the request of the identity information, the request of the identity information update and the request of the identity information recovery are carried in one of: a second frame of four-way handshake, a second frame of FT four-way handshake, an association request frame of fast initial link setup (FILS) authentication, other management frames, and an action frame.

9. The method of claim 7, wherein the request of the identity information, the request of the identity information update and the request of the identity information recovery carry a PASN ID element, wherein the PASN ID element is for indicating a request type.

10. The method of claim 6, wherein the response of the identity information and the response of the identity information update are carried in one of: a third frame of four-way handshake, a third frame of FT four-way handshake, an association response frame of fast initial link setup (FILS) authentication, other management frames, and an action frame.

11. The method of claim 1, wherein, The recognizing of the station with the link state change in the PASN authentication based on the identity information comprises: For a single-link case, identity of the workstation converted from the multi-link to the single-link is identified in the PASN authentication based on the identity information. For a multi-link case, identity of the workstation converted from the single-link to the multi-link is identified in the PASN authentication based on the identity information.

12. The method of any one of claims 1 to 11, wherein, The association scenario includes at least one of the following: four-way handshake, FT four-way handshake, and fast initial link setup (FILS) authentication.

13. The method of any of claims 1-11, wherein, The workstation is a multi-link workstation or a single-link workstation. The link state change includes conversion from the multi-link to the single-link or conversion from the single-link to the multi-link.

14. An identity identification method applied to a workstation, the method comprising: In an association scenario, receiving identity information for pre-association security negotiation (PASN) allocated by an access point device; When a link state change occurs, identity is identified with the access point device in a PASN authentication based on the identity information.

15. The method of claim 14, wherein, Receiving identity information for pre-association security negotiation (PASN) allocated by an access point device includes: Receiving the identity information allocated by the access point device according to an identity information request; Receiving the identity information allocated by the access point device.

16. The method of claim 15, wherein, Before receiving the identity information for pre-association security negotiation (PASN) allocated by an access point device, the method further comprises: Sending the identity information request to the access point device, wherein the identity information request is used to request allocation or non-allocation of the identity information.

17. The method of claim 16, wherein, The identity information request includes indication information, wherein the indication information is used to request allocation or non-allocation of the identity information.

18. The method of claim 17, wherein, The method further comprises: In a case where the indication information indicates a request for allocation of the identity information, receiving an identity information response sent by the access point device, wherein the identity information response carries the identity information.

19. The method of claim 15, wherein, The method further comprises: Sending an identity information update request to the access point device; Receiving an identity information update response sent by the access point device, wherein the identity information update response carries updated identity information.

20. The method of claim 19, wherein, The method further comprises: Sending an identity information recycling request to the access point device, wherein the identity information recycling request is used to request the access point device to recycle the identity information.

21. The method of claim 20, wherein: The identity information request, the identity information update request, and the identity information recycling request are carried in one of the following messages: a second frame of four-way handshake, a second frame of FT four-way handshake, an association request frame of fast initial link setup (FILS) authentication, other management frames, and action frames.

22. The method of claim 20, wherein, The identity information request, the identity information update request and the identity information recycling request carry a PASN ID element, wherein the PASN ID element is used to indicate the request type.

23. The method of claim 19, wherein, The identity information response and the identity information update response are carried in one of the following messages: a third frame of four-way handshake, a third frame of FT four-way handshake, an association response frame of fast initial link setup (FILS) authentication, other management frames, and an action frame.

24. The method of claim 14, wherein, When a link state changes, identity identification with the access point device in PASN authentication based on the identity information comprises: When a multi-link device is converted into a single-link device, identity identification with a single-link access point device in PASN authentication; or When a single-link device is converted into a multi-link device, identity identification with a multi-link access point device in PASN authentication.

25. The method of any one of claims 14 to 24, wherein, The association scenario comprises at least one of the following: four-way handshake, FT four-way handshake, and fast initial link setup (FILS) authentication.

26. The method of any one of claims 14-24, wherein, The access point device is a multi-link access point device or a single-link access point device; The link state change comprises conversion from multi-link to single-link or conversion from single-link to multi-link.

27. A computer readable storage medium having stored therein a computer program, wherein, The computer program is configured to execute the method of any one of claims 1-13, 14-26 when the computer program is run.

28. An electronic device comprising a memory and a processor, the memory having stored therein a computer program, and the processor being configured to execute the computer program to perform the method of any one of claims 1-13, 14-26.

Citation Information

Patent Citations

  • Identifier distribution method and system

    CN102905253A

  • Wireless communication method and device

    CN118402271A

  • Address randomization schemes for multi-link devices

    US20230085657A1

  • Authentication method and apparatus, device, and storage medium

    WO2024026735A1