Multi-access-point collaborative processing method, storage medium, electronic apparatus, and computer program product
By performing link-level secure interface authentication in a multi-access point environment, the security risks increased by separate authentication negotiation between MAPs are resolved, improving the security and efficiency of AP collaborative operation, and making it suitable for various network environments.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-08-08
- Publication Date
- 2026-04-02
AI Technical Summary
In a multi-access point environment, the separate authentication negotiation between MAPs increases the security risks of frame interaction, and existing technologies have failed to effectively address this issue.
By performing signaling interaction between the first security interface and the second security interface, MAP authentication is performed on the first access point and the second access point to ensure that their radio frequency links are the same or partially overlapped. MAP authentication between APs is performed using the link-level security interface, thereby reducing the security risks of frame interaction.
It improves the security and efficiency of AP collaborative operation in multi-link environments, is suitable for scenarios requiring high-precision data exchange, such as high-definition video conferencing systems, and can respond to network changes in a timely manner, making it suitable for dynamic network environments.
Smart Images

Figure CN2025113630_02042026_PF_FP_ABST
Abstract
Description
Multi-access point cooperative processing method, storage medium, electronic device and computer program product
[0001] Cross-reference to Related Applications
[0002] The present disclosure is based on Chinese Patent Application No. 2024113814209 entitled "Multi-access point cooperative processing method, storage medium, electronic device and computer program product" filed on September 29, 2024, and claiming priority to the patent application, the disclosure of which is incorporated herein by reference in its entirety. TECHNICAL FIELD
[0003] Embodiments of the present disclosure relate to the field of base station energy saving, in particular, to a multi-access point cooperative processing method, storage medium, electronic device and computer program product. BACKGROUND
[0004] Since each access point (AP) may create multiple other APs on the radio frequency link where it is located, these APs collectively form a co-hosted BSSID (basic service set identifier set) set or an MBSSID (basic service set identifier) set. If there are multiple APs in the set that form multiple MAP pairs (Multiple Access Points) with at least one AP in the opposite set, if each "MAP pair" performs discovery, authentication negotiation individually, the frame overhead in the system is large, and the security risk of frame interaction is also large.
[0005] To address the problem of increased security risk of frame interaction due to separate authentication negotiation between MAPs in the related art, no solution has been proposed. SUMMARY
[0006] Embodiments of the present disclosure provide a multi-access point cooperative processing method, storage medium, electronic device and computer program product to at least solve the problem of increased security risk of frame interaction due to separate authentication negotiation between MAPs in the related art.
[0007] According to one embodiment of the present disclosure, a multi-access point cooperative processing method is provided, the method comprising:
[0008] The first security interface SI signals with the second SI, and the first access point AP and the second AP are MAP authenticated, wherein the first SI and the working channel of at least one radio frequency link where the second SI is located are the same or partially overlapped, the first SI and the first AP are on the same radio frequency link or the same device, and the second SI and the second AP are on the same radio frequency link or the same device.
[0009] According to another embodiment of the present disclosure, a computer program product is also provided, comprising computer program instructions, wherein the computer program instructions enable a computer to implement the steps in any of the above method embodiments.
[0010] According to another embodiment of the present disclosure, a computer-readable storage medium is also provided, wherein the storage medium stores a computer program, and the computer program is configured to execute the steps in any of the above method embodiments when running.
[0011] According to another embodiment of the present disclosure, an electronic device is also provided, comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the steps in any of the above method embodiments. BRIEF DESCRIPTION OF DRAWINGS
[0012] FIG. 1 is a hardware structure block diagram of a computer device of a multi-access point cooperative processing method according to an embodiment of the present disclosure;
[0013] FIG. 2 is a flowchart of a multi-access point cooperative processing method according to an embodiment of the present disclosure;
[0014] FIG. 3 is a schematic diagram of a multi-link connection establishment process according to an embodiment of the present disclosure;
[0015] FIG. 4 is a flowchart of MAP cooperative operation according to an embodiment of the present disclosure;
[0016] FIG. 5 is a network topology diagram of MAP cooperation according to an embodiment of the present disclosure;
[0017] FIG. 6 is a flowchart of MAP cooperation of two network devices according to an embodiment of the present disclosure;
[0018] FIG. 7 is a flowchart of transfer authentication of three APs according to an embodiment of the present disclosure;
[0019] FIG. 8 is a network topology diagram of MAP authentication transfer based on link level according to an embodiment of the present disclosure;
[0020] FIG. 9 is a flowchart of authentication transfer between two MAP groups according to an embodiment of the present disclosure;
[0021] FIG. 10 is a network topology diagram for AP MLD passing authentication, according to an embodiment of the present disclosure;
[0022] FIG. 11 is a flow diagram for AP MLD passing authentication, according to an embodiment of the present disclosure;
[0023] FIG. 12 is a flow diagram for MAP coordination link update, according to an embodiment of the present disclosure;
[0024] FIG. 13 is a schematic diagram of a channel sounding procedure, according to an embodiment of the present disclosure;
[0025] FIG. 14 is a schematic diagram of a channel sounding procedure, according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0026] Hereinafter, the embodiments of the present disclosure will be described in detail with reference to the accompanying drawings and in conjunction with embodiments.
[0027] It should be noted that the terms "first", "second", and the like in the description and claims of the present disclosure and the above drawings are used to distinguish similar objects, and do not necessarily have to describe a specific order or sequence.
[0028] The method embodiments provided in the embodiments of the present disclosure can be executed in a computer device or a similar computing device. Taking an example of running on a computer device, FIG. 1 is a hardware structure block diagram of a computer device for a multi-access point coordination processing method according to an embodiment of the present disclosure. As shown in FIG. 1, the computer device can include one or more (only one is shown in FIG. 1) processors 102 (the processor 102 can include but is not limited to a processing device such as a microprocessor MCU or programmable logic device) and a memory 104 for storing data. The computer device can further include a transmission device 106 for communication function and an input and output device 108. Those skilled in the art can understand that the structure shown in FIG. 1 is only schematic, and does not limit the structure of the computer device. For example, the computer device can include more or less components than those shown in FIG. 1, or have a different configuration from that shown in FIG. 1.
[0029] The memory 104 can be used to store computer programs, such as software programs of application software and modules, such as a computer program corresponding to the multi-access point cooperative processing method in the embodiments of the present disclosure. The processor 102 performs various functions of applications and single board matching, that is, implements the method described above, by running the computer program stored in the memory 104. The memory 104 can include a high-speed random access memory, and can also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some examples, the memory 104 can further include a memory remotely arranged with respect to the processor 102, which can be connected to the computer device through a network. Examples of the network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
[0030] The transmission device 106 is used to receive or send data via a network. The specific examples of the network can include a wireless network provided by a communication provider of the computer device. In one example, the transmission device 106 includes a network adapter (NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet in a wireless manner.
[0031] In the embodiments, a multi-access point cooperative processing method running on the computer device is provided. FIG. 2 is a flowchart of the multi-access point cooperative processing method according to the embodiments of the present disclosure. As shown in FIG. 2, the flow includes the following steps:
[0032] In step S202, the first security interface SI performs signaling interaction with the second SI, and performs MAP authentication on the first access point AP and the second AP, wherein the working channels of at least one radio frequency link where the first SI and the second SI are located are the same or partially overlapped, the first SI and the first AP are on the same radio frequency link or the same device, and the second SI and the second AP are on the same radio frequency link or the same device.
[0033] Through the above step S202, the problem that the security risk of frame interaction is increased due to separate authentication negotiation between MAPs in the related art can be solved. The MAP authentication between APs based on the link-level security interface reduces the security risk existing in the frame interaction between MAPs.
[0034] For example, the first SI and the first AP belong to the same co-hosted BSSID set or MBSSID set, that is, are on the same radio frequency link.
[0035] Wireless networks can more efficiently manage the coordinated operation of APs in a multi-link environment, especially in industrial automation scenarios, the use of multi-link can significantly improve the reliability of data transmission and the coverage of the network.
[0036] In the step S202, the MAP authentication can be performed in the following way: the first SI sends a first information frame to the second SI, wherein the first information frame contains information of at least one single-link AP or multi-link AP; the first SI receives a second information frame sent by the second SI, wherein the second information frame contains information of at least one single-link AP or multi-link AP; the first SI and the second SI confirm the information of APs with each other, and the MAP authentication of the first AP and the second AP is completed. This process ensures the synchronization of information between APs, improves the accuracy and security of coordinated operation, and is suitable for scenarios that require high-precision data exchange, such as high-definition video conference systems.
[0037] In an embodiment, the above method further comprises: the first SI and the second SI perform signaling interaction, and de-authenticate the first AP and the second AP. This mechanism can respond to network changes such as device failure or security threats in time, quickly release unnecessary AP coordination, ensure the effective use and security of network resources, and is particularly suitable for dynamic network environments such as mobile office networks.
[0038] Further, the first SI sends a third information frame to the second SI, or receives a third information frame sent by the second SI, wherein the third information frame contains operation end indication information of at least one MAP; the first SI receives a third information frame response frame sent by the second SI, or sends a third information frame response frame to the second SI, and completes the de-authentication of the first AP and the second AP. This mechanism provides flexible de-authentication operation and can quickly adapt to network topology changes, and is suitable for scenarios that require high dynamic adjustment capability, such as temporary network deployment in large-scale exhibitions. In an optional embodiment, the coordinated link update process is also performed by the corresponding AP or Access Point Multi-Link Device (AP MLD) to perform the frame interaction process, and the SI does not need to participate in the process. For example, the first AP and the second AP directly perform de-authentication request and response interaction, and the SI does not need to participate.
[0039] In an embodiment, the method further comprises: the first SI sending a fourth information frame to the second SI, wherein the fourth information frame is used to request to add or delete link information of at least one multi-link AP; and the first SI receiving a fourth information response frame sent by the second SI, wherein the fourth information response frame is used to indicate link state information corresponding to the added or deleted link information of the at least one multi-link AP. This function allows the network administrator to dynamically adjust the link configuration to optimize the network performance and resource allocation, and is suitable for scenarios that require frequent adjustment of network structure, such as intelligent transportation systems.
[0040] In another embodiment, the method further comprises: the first SI sending a fifth information frame to the second SI, wherein the fifth information frame is used to request to add or delete link information between the first SI and the second SI; and the first SI receiving a fifth information response frame sent by the second SI, wherein the fifth information response frame is used to indicate link state information corresponding to the added or deleted link information between the first SI and the second SI. This mechanism provides more fine-grained link management, which helps to improve the flexibility and response speed of the network, and is suitable for scenarios that require fine-grained management, such as internal networks of data centers.
[0041] After the AP MLD and the non-AP MLD complete the four-way handshake on one link, a MLO-level temporary pairwise transient key (PTK) and a link-level group temporal key (GTK) are generated, which are respectively used for encrypting and decrypting transmitted unicast frames and groupcast frames, to ensure the security of data transmission. For example, FIG. 3 is a schematic diagram of a multi-link connection establishment process according to an embodiment of the present disclosure. As shown in FIG. 3, the AP MLD and the non-AP MLD each include three links operating at 2.4 GHz, 5 GHz and 6 GHz. The AP MLD and the non-AP MLD complete the authentication, connection and four-way handshake process on the 2.4 GHz link, and after establishing the multi-link connection, data can be transmitted on the three links.
[0042] FIG. 4 is a flowchart of MAP cooperative operation according to an embodiment of the present disclosure. As shown in FIG. 4, the specific steps of security cooperation include:
[0043] S401, interface creation process, when participating in MAP cooperation, creating an SI (denoted as SI1) on the first network device. Similarly, an SI interface (denoted as SI2) is also created on the second network device, wherein the working channels of at least one radio frequency link where the SI1 and the SI2 are located are the same or partially overlapped.
[0044] S402, AP authentication delivery process, including:
[0045] 1) Based on the related technology, SI1 and SI2 complete the mutual authentication process, and generate key information that can encrypt information frame transmission;
[0046] 2) SI1 sends a first information frame to SI2, containing at least one AP or AP MLD information (denoted as API);
[0047] 3) SI2 sends a second information frame to SI1, containing at least one AP or AP MLD information (denoted as AP2);
[0048] 4) After SI1 and SI2 confirm each other's AP (or AP MLD) information delivered by the other party, the authentication process of API and AP2 is completed.
[0049] S403, collaborative link update process of multi-link device, specifically including:
[0050] 1) SI1 (SI2) sends a third information frame to SI2 (or SI1), requesting to add or delete at least one link information of at least one AP MLD delivered by it;
[0051] 2) SI2 (or SI1) sends a third information response frame, indicating the state information of adding and deleting link operations requiring MAP collaborative operation.
[0052] S404, SI communication interface update process, specifically including:
[0053] 1) SI1 (or SI2) sends a fourth information frame to SI2 (or SI1), requesting to add or delete information of its communication sub-interface (i.e. affiliated STA);
[0054] 2) SI2 (or SI1) responds to the fourth information response frame, indicating the state information of adding and deleting sub-interfaces requiring SI;
[0055] 3) After the above interaction is completed, SI1 and SI2 update the communication interface information locally respectively.
[0056] S405, de-authentication and interface deletion process, specifically including:
[0057] 1) SI1 sends a third information frame to SI2 (or SI2 to SI1), containing at least one multi-AP operation end indication information;
[0058] 2) SI2 sends a third information response frame to SI1 (or SI1 to SI2), confirming the de-authentication process between API and AP2;
[0059] 3) Delete the interfaces of SI1 and SI2 respectively.
[0060] In an embodiment, the first SI and the second SI are one of the following types: single-link AP, single-link terminal device STA, multi-link AP, multi-link device non-AP MLD; when the first SI and the second SI are multi-link AP or multi-link terminal device, an affiliated AP or STA is included on at least one radio frequency link, and when the first SI and the second SI are single-link AP or single-link STA, they are respectively located on the same radio frequency link of the first AP and the second AP. When the SI is a multi-link interface / device (non-AP MLD or AP MLD), a sub-interface needs to be further created on at least one radio frequency link (i.e., its affiliated non-AP or AP), and the first SI signals with the second SI through the affiliated AP or the affiliated STA. This design can fully utilize the advantages of multi-link, improve the throughput and stability of the network, and is suitable for scenarios that require high bandwidth and low delay, such as virtual reality games.
[0061] In some application instances, two SIs (for example, the first SI and the second SI) interact at least one information frame on the channel on which they work, such as (beacon frame, probe request frame, (multi-link) probe request frame, probe response frame, (multi-link) probe response frame) to obtain the information of the other party and the information of the AP that needs to be transmitted. Among them, the information frame can only contain authentication information (such as: identification information SSID, key suite, RSNE (robust Security network element, robust security network element), RSNXE (RSN extension element, extended robust security network element) and the like) and MAP cooperation capability set related information (such as C-SR (Coordination Spatial Reuse, joint spatial reuse), C-BF (Coordination Beamforming, joint beamforming) and the like) transmitted by MAP, and does not contain information related to STA (Station) connection, such as 802.11n, 802.11ac, 802.11ax, 802.11be capability set information.
[0062] In an embodiment, when the first SI and the second SI are multi-link AP or multi-link device, the signaling interaction between the first SI and the second SI is transmitted and retransmitted on any radio frequency link. This feature enhances the robustness of the network, that is, even if part of the link fails, communication can be maintained through other links, and is suitable for scenarios that require high reliability, such as medical device networks.
[0063] In an embodiment, the first SI indicates the maximum number of SIs allowed to be created on each radio link or the maximum number of SIs allowed to be created on the network device, and / or the number of APs participating in the cooperation in each MAP cooperation group through the beacon frame or other information frame sent. This function allows the network administrator to dynamically adjust the network configuration according to the actual needs, optimize the network performance, and is suitable for scenarios that require dynamic adjustment of network capacity, such as the audience network of large-scale sports events. The SI or the SI sends the beacon frame or other information frame sent by the AP or STA (hereinafter referred to as SI) attached to it, indicating the maximum number of SIs allowed to be created on each link (currently) or the maximum number of SIs allowed to be created on the device (currently) (or expressed as the number of MAP cooperation groups) and / or the number of APs participating in the cooperation in each MAP cooperation group. Among them, for a multi-link SI, the maximum number does not exceed the total number of attached STAs for authentication communication on all links of the network device. For example, a device contains 2 radio links, and the first link and the second link allow a maximum of 2 and 3 attached STAs for authentication communication, respectively, so the maximum number of multi-link SIs that can be created is 5.
[0064] In an embodiment, the first SI and the second SI interact at least one information frame on the operating channel of the radio link, wherein the information frame is used to obtain the information of the second AP and the information to be transmitted. This process ensures the synchronization of information between APs, helps to improve the efficiency and accuracy of cooperation, and is suitable for scenarios that require real-time data synchronization, such as online education platforms.
[0065] In an embodiment, the first SI performs MAP cooperation with the third SI and the fourth SI, or the first SI performs MAP cooperation with the fourth SI, wherein the third SI and the first AP are on the same radio link or the same device, and the fourth SI and the third AP are on the same radio link or the same device. This design allows more complex network structures, improves the scalability and flexibility of the network through multi-level cooperation, and is suitable for scenarios that require large-scale network deployment, such as smart city infrastructure.
[0066] In the scenario of MAP cooperation among 3 or more network devices, the first network device creates SI1 (corresponding to the first SI) to perform MAP cooperation with SI2 (corresponding to the second SI) of the second network device, and creates SI3 (corresponding to the third SI) to perform MAP cooperation with the interface (corresponding to the fourth SI) of the third network device. In some other application examples, the first network device uses the same SI1 to perform MAP cooperation with multiple third network devices.
[0067] In an embodiment, the first SI and the second SI are only used for MAP coordination, and the terminal device is not allowed to establish a connection. This mechanism can effectively prevent unauthorized terminal access and improve network security, and is suitable for scenarios that require strict access control.
[0068] Further, the first SI indicates that the terminal device is not allowed to establish a connection by sending an additional information frame, or transmits an information frame in a newly defined frame format, so that the terminal device cannot establish a connection. This strategy further enhances the security of the network, and through explicit indication and customized frame format, it can effectively avoid illegal access and is suitable for scenarios that require high security protection, such as financial transaction networks. The SI interface of the radio frequency link is only used for MAP coordination process, and the terminal device is not allowed to establish a connection with it, such as: by sending an additional information frame to display an indication that the terminal device is not allowed to connect, or transmitting an information frame in a newly defined frame format, causing other devices to seamlessly parse the information frame format and thus unable to find and establish a connection with it.
[0069] In an embodiment, the first SI indicates the identification information of the radio frequency link of the network device on which the affiliated STA is created by the beacon frame or other information frame sent by the first SI. This function helps the terminal device to quickly find the optimal connection link, improves the connection efficiency and user experience, and is suitable for scenarios that require fast response, such as instant messaging applications.
[0070] In an embodiment, when the first information frame is an authentication request frame and the first SI and the second SI are both APs, the authentication request is initiated by the first SI or the second SI; when the first SI is an AP type interface and the second SI is an STA type interface, the authentication request is initiated by the second SI. That is, when both ends are AP type interfaces, both ends can initiate an authentication request; when one end is an AP interface and the other end is a non-AP STA type interface, the authentication request is initiated by the non-AP STA end. This mechanism ensures the flexibility and efficiency of the authentication process, and is suitable for the coordination between different types of network devices, such as frequent authentication and re-authentication between APs and STAs in enterprise campus networks.
[0071] In an embodiment, the information of the single-link AP or the multi-link AP is at least one of: AP information, multi-link AP information, AP set information, and multi-link AP set information. This design allows more complex information transmission, including not only the information of a single AP, but also the characteristics of an AP set, and is suitable for scenarios that require processing a large number of AP coordination operations, such as wireless networks in large commercial complexes.
[0072] In an embodiment, the first information frame and / or the second information frame comprises an AP set information or a multi-link AP set information, the AP set information is used to indicate AP set characteristic information, and the multi-link AP set information is used to indicate characteristic and identifier information of each multi-link AP in the set; after completing the MAP authentication, the APs in the AP set information can perform MAP cooperative operation with one or more APs authenticated by the opposite end, and the multi-link APs in the multi-link AP set information can perform MAP cooperative operation with one or more multi-link APs authenticated by the opposite end. This mechanism improves the flexibility and efficiency of AP cooperative operation, and is suitable for scenarios that require rapid response to network changes, such as production scheduling networks of intelligent factories.
[0073] The first information frame and / or the second information frame sent by the SI1 or the SI2 comprises at least one AP set information (such as information of an MBSSID or a co-hosted BSSID set, which is used to indicate AP set characteristic information such as AP MAC address characteristics and AP quantity information in the AP set) (denoted as AP Set1) or AP MLD set information (such as AP MLD MAC address, AP MLD ID, Link ID, and Link MAC address, which are used to indicate characteristic and identifier information of each AP MLD (and each link) in the set) (denoted as AP MLD Set1), instead of information of a single AP. After completing the authentication transmission operation, the APs (or AP MLDS) in the AP Set1 (or the AP MLD Set1) can perform MAP cooperative operation with one or more APs (or AP MLDS) authenticated by the opposite end.
[0074] In an embodiment, the first information frame and / or the second information frame comprises an AP list, and the AP list comprises information of at least one AP; after completing the MAP authentication, any AP in the AP list can perform MAP cooperative operation with any AP in the AP list of the opposite end (under the condition that the MAP capabilities are the same). This design allows more flexible AP combination, improves the adaptability and expansibility of the network, and is suitable for scenarios that require dynamic adjustment of AP cooperation, such as remote medical networks.
[0075] In the authentication transmission process, the transmitted AP information in the first information frame and the second information frame is exchanged in the SI1 and the SI2 authentication process, and the number of frame exchanges is reduced.
[0076] In some application instances, the AP1 or the AP2 initiates an information exchange process of the opposite end (such as authentication information or key negotiation information) by using a link between the SI1 and the SI2, and the SI1 and the SI2 are only responsible for forwarding the information frames exchanged by the AP1 and the AP2.
[0077] In some application instances, SI2 sends a second information frame to SI1 to indicate a failure of the authentication (may not contain information of AP2 when indicating a failure), and the status information of the failure is one of the following: the number of SIs exceeds the maximum capability value; the number of APs participating in the cooperation exceeds the maximum capability value.
[0078] In some application instances, a third network device creates SI3, and performs authentication negotiation with SI1, SI1 sends information of APs (denoted as AP1) it delivers and information of SI2 and APs (denoted as AP2) it delivers to SI3, SI3 sends information of AP1 and AP2 to AP3 through an internal communication manner, and AP3 performs one-way authentication (one-way authentication delivery method) for AP1 and AP2. If SI3 sends information of AP3 to AP1 and AP2 through a direct or indirect manner, one-way authentication of AP1 and AP2 for AP3 is implemented. The combination of the above-mentioned two-way delivery manner implements two-way authentication delivery.
[0079] In an embodiment, the first information frame and / or the second information frame contains information of at least one pair of APs that need to perform MAP cooperation. After the MAP authentication is completed, each pair of APs negotiated can perform MAP cooperation. For example, the information frame sent by SI1 and / or SI2 contains information of at least one pair of APs that need to perform MAP cooperation (such as <AP1, AP2>). After the authentication delivery process is completed, each pair of APs negotiated can perform MAP cooperation. This mechanism provides more refined AP cooperation management, and is suitable for scenarios that need to accurately control AP cooperation, such as remote control networks of precision instruments.
[0080] In an embodiment, the first SI generates or delivers at least one set of secret key information, wherein the at least one set of secret key information is used only for encryption or authentication of information interaction frames between the first SI and the second SI. The information of the delivered APs in the first and second information frames needs to be encrypted before transmission, for example, secret key information is generated during the authentication process of SI1 and SI2, and the first and second information frames are encrypted. At least one set of secret key information, such as PTK, GTK, IGTK, and BIGTK, is generated or delivered, wherein GTK, IGTK, and BIGTK are generated by the AP or the SI locally and then delivered to the other party. Specifically, only one set of secret key information is generated and is used only for protecting (encrypting or authenticating) information interaction frames between SIs, for example, information frames that need to be encrypted and protected by using secret key information, such as robust management frames (robust management frame) and beacon frames (Beacon frame). This mechanism ensures the security of communication between APs, and is suitable for scenarios that need to protect sensitive data, such as financial data transmission networks in enterprises.
[0081] In an embodiment, the first SI shares at least one set of key information to all APs. After the end of the delivery of the authentication, the SI shares only one set of key information to all APs, so that the SI and / or AP and the peer SI and / or AP can interact with each other to exchange information frames that need to be encrypted or protected, such as robust management frames. A uniform numbering mode of SN, PN, IPN, BIPN is adopted. (Uniform numbering: the PN, SN, IPN, BIPN values of the information frames sent by the SI and / or AP on one radio link or multiple links that need to be encrypted or protected are maintained in a set.) This mechanism improves the overall security of the network and ensures that the communication between all APs is protected, and is suitable for scenarios that need global security protection, such as public security monitoring networks.
[0082] For example, a sequentially increasing value of a cumulative growth sequence number (SN) is set in each packet, and the receiving end buffers and sorts the received packets according to the SN values and sends them to the upper layer protocol stack. In order to avoid third-party replay attacks, the protocol stipulates that each wireless packet contains a sequentially increasing frame sequence number (PN) value, and when two packets with the same PN are received, it is considered that they are third-party replay attack packets, which can be directly discarded.
[0083] In an embodiment, the first SI generates different key information for each pair of APs that need to be cooperatively operated by the MAP, wherein the APs in each group use different key information when interacting with the peer APs, and a separate numbering mode of SN, PN, IPN, BIPN is adopted. After the end of the delivery of the authentication, the SI generates or delivers different key information for each pair of APs that need to be cooperatively operated by the MAP, and the APs in each group use different key information when interacting with the peer APs, and a separate numbering mode of SN, PN, IPN, BIPN is adopted. This mechanism provides a higher level of security protection and is suitable for scenarios that need high security and privacy protection, such as personal health data transmission networks.
[0084] In an embodiment, the frame type that the first SI interacts with the second SI is a control frame or a management frame; or the frame type that the first SI interacts with the second SI is a control frame, a management frame, and a data frame. After the end of the delivery of the authentication, only control frames and management frames can be interacted on the SI, and data frames cannot be interacted. In some other application examples, after the end of the delivery of the authentication, the frame type that is interacted on the SI is not limited, that is, any frame type can be interacted. This design allows more comprehensive network management, not limited to control and management, but also direct data transmission, and is suitable for scenarios that need real-time data transmission and management, such as real-time video monitoring networks.
[0085] In an embodiment, the interface update procedure of a multi-link AP contains both the addition and deletion of affiliated APs. This mechanism allows network administrators to dynamically adjust the network structure without affecting existing services, and is suitable for scenarios that require quick response to changes in business, such as online gaming platforms. In the interface update procedure of a multi-link SI, both the addition and deletion of sub-interfaces (affiliated STAs) can be included. For example, SI1 sends a fourth information frame to SI2 through a first interface (on a first link), containing the addition of a new communication sub-interface on a second link and the deletion of a communication sub-interface on the first link. SI1 receives a response frame to the above information frame sent by SI2, and after including the status information as "success", creates a sub-interface on the second link and deletes the communication sub-interface on the first link. Subsequent information exchange between SIs is carried out on the corresponding sub-interfaces (affiliated STAs) on the second link.
[0086] In an embodiment, the change of the type of affiliated STAs or APs of the first SI and / or the second SI includes at least one of the following: the affiliated STAs or APs remain unchanged when a MAP coordination link is added or deleted; the affiliated STAs or APs are added on the corresponding radio link when a MAP coordination link is added; the affiliated STAs or APs are deleted on the corresponding radio link when a MAP coordination link is deleted; the affiliated STAs or APs are added on the corresponding radio link when a MAP coordination link is added, and at least one affiliated STA or AP of the SI on another coordination link is deleted. This mechanism provides more flexible link management and helps to optimize the allocation of network resources, and is suitable for scenarios that require dynamic adjustment of network resources, such as the internal network of a cloud data center.
[0087] In an embodiment, the trigger for de-authentication includes at least one of the following: one of the radio links switches to a working channel that has no intersection (overlap) with the working channel; one of the radio links enters a power saving state; the device is unexpectedly powered off or restarted. This mechanism can respond to network changes in a timely manner, such as device failure or security threats, quickly remove unnecessary AP coordination, and ensure efficient use and security of network resources, and is particularly suitable for dynamic network environments, such as mobile office networks, where devices are frequently moved and their states change. After de-authentication between the multi-link SIs 1 and 2, the SIs 1 and 2 and their affiliated STAs are also deleted.
[0088] In an embodiment, the type of information frame that the first SI interacts with the second SI includes: a beacon frame, a probe request frame, a probe response frame, an authentication frame, an association request / response frame, a re-association request / response frame, a de-authentication frame, a disassociation frame, and other types of management frames. This design allows more comprehensive network management and control, not limited to authentication and de-authentication, but also including probe, association, and other operations, suitable for scenarios that require comprehensive management, such as wireless networks in intelligent buildings, where various devices need to be monitored and controlled comprehensively.
[0089] In an embodiment, when the information frame that the first SI interacts with the second SI contains information of the single-link AP, the information of the single-link AP at least contains one of the following: an AP ID (Access Point Identifier), a BSSID, a MAC address, MAC address index information, key generation and key configuration information, a MAP capability set, and MAP parameters, wherein the AP ID, the BSSID, the MAC address, and the MAC address index information are AP identification information or assigned identification information, the key generation and key configuration information are key generation parameters and key configuration parameter information for information transfer between APs, and the MAP capability set and the MAP parameters are used to indicate the MAP capability and configuration information of each AP. This mechanism ensures synchronization and secure communication of information between APs, suitable for scenarios that require precise control and secure communication, such as internal networks in banks, where strict identity verification and data encryption of APs are required.
[0090] In an embodiment, when the first SI and the second SI interact in the information frame containing the information of the multi-link AP, the information of the multi-link AP contains at least one of the following: MAC address information of the multi-link AP, MLD ID information, MLD index information, at least one link information (such as BSSID, Link ID, etc.) of the multi-link AP, MAP capability set, MAP configuration parameter information, SSID information, key information (such as GTK (Group Temporal Key), PTK (Pairwise Transient Key), IGTK (Integrity Group Temporal Key), etc.), frame sequence number information (PN (Packet Number), IPN (IGTK Packet Number), BIPN (BIGTK Packet Number), BIGTK (Beacon Integrity Group Temporal Key)), key configuration information (such as RSNE, RSNXE, key suite information, etc.). This design allows more complex multi-link AP coordination, improves the throughput and stability of the network, and is suitable for scenarios that require high bandwidth and low delay, such as virtual reality game platforms, where the use of multi-link can significantly improve the game experience and the reliability of data transmission.
[0091] The multi-access point cooperative processing provided by the embodiments of the present disclosure effectively improves the cooperative efficiency and security of the wireless network by implementing cooperative authentication and de-authentication between APs in a multi-link environment. This method allows flexible signaling interaction between multiple radio frequency links, not only enhancing the robustness of the network, but also ensuring the stability of network communication and the security of data transmission by dynamically adjusting link information and key configuration. In addition, by limiting the connection of terminal devices, unauthorized access can be effectively avoided, further enhancing the security protection of the network. This scheme is particularly suitable for multi-link wireless communication scenarios that require high bandwidth, low delay, and high security, such as industrial automation, high-definition video transmission, and virtual reality applications, which can significantly improve user experience and network performance. Furthermore, this method can adapt to various network environments and needs, from simple home networks to complex industrial networks, providing efficient, secure, and flexible AP cooperative operation, ensuring the efficiency and reliability of wireless communication, and providing strong technical support for the development of future wireless networks.
[0092] Based on the link level MAP cooperation, FIG. 5 is a network topology diagram of MAP cooperation according to an embodiment of the present disclosure, as shown in FIG. 5, the first and second network devices respectively include two radio links, wherein the working channels of the first radio link (Radio1) are the same, and the working channels of the second radio link (Radio2) are different.
[0093] SI1 and SI2 interfaces are respectively created on the first radio link (Radio1), SI1 is located on the same radio as AP1, and similarly, SI2 is located on the first radio link of the second device as AP2.
[0094] FIG. 6 is a flowchart of MAP cooperation of two network devices according to an embodiment of the present disclosure, as shown in FIG. 6, the specific description is as follows:
[0095] S601, interface creation process: the first and second network devices respectively create SI1 and SI2 interfaces on the first radio link; and SI1 and SI2 are both configured as AP type interfaces, and the SSIDs, key suites and key information configured on the SI interfaces at both ends are the same; for example, the SSID is "backhaul123".
[0096] S602, MAP discovery process: SI1 and SI2 respectively broadcast a beacon frame containing the SSID "backhaul123" on their respective main channels, and the beacon frame contains the MAP capability set of the corresponding SI; SI1 and / or SI2 can also discover the other party by using probe request and response frame interaction on the entire working channel.
[0097] S603, authentication delivery process: SI1 and SI2 interact authentication request frames, authentication response frames and the like to complete authentication, and generate key information and SI1 and SI2 multicast key information (such as GTK, IGTK, BIGTK) and multicast frame number information (such as PN, IPN, BIPN information). According to the above information, SI1 and SI2 can deliver encrypted unicast frames and authenticated multicast frames to each other. SI1 sends a first information frame to SI2, which contains the information of AP1, including the address of AP1, SSID, unicast key generation parameter random number 1 or public key 1, RSNE, RSNXE information. After receiving the above first information frame, SI2 delivers the information of AP1 to AP2 through internal communication to realize the authentication of AP2 to AP1. SI2 sends a second information frame to SI1, which contains the information of AP2, including the address of AP2, SSID, unicast key generation parameter random number 2 or public key 2, RSNE, RSNXE information. After receiving the above second information frame, SI1 delivers the information of AP2 to AP1 through internal communication to realize the authentication of AP1 to AP2.
[0098] S604, MAP cooperation operation.
[0099] S605, deauthentication delivery process: SI1 sends a deauthentication frame to SI2, containing the information of AP1 and AP2, SI2 delivers the deauthentication information of AP1 to AP2 through internal communication mode, and realizes the deauthentication of AP1 and AP2. SI2 sends a deauthentication response frame to SI1, containing the information of AP1 and AP2, SI1 delivers the deauthentication information of AP2 to AP1 through internal communication mode, and realizes the deauthentication of AP2 and AP1. The first and second network devices delete SI1 and SI2 respectively on the radio link.
[0100] Based on the level of link, the MAP authentication delivery is completed, and FIG. 7 is a flowchart of delivery authentication of three APs according to an embodiment of the present disclosure. As shown in FIG. 7, the MAP authentication delivery process of three devices is described as follows:
[0101] S701, interface creation: the first and second network devices create SI1 and SI2 interfaces respectively on the first radio link; after the authentication negotiation of AP1 and AP2 is completed through the delivery mode, AP1 and AP2 perform MAP collaborative operation. AP3 of the third device needs to join the MAP collaboration group of AP1 and AP2, and the third device creates SI3 on the first radio link.
[0102] S702, authentication delivery process: SI3 sends an authentication request frame to SI1, and the frame is transmitted in plaintext and does not contain any delivery AP information. After receiving the authentication request frame, SI1 sends an authentication response frame to SI3, and the frame contains the information of SI1 and AP1; the information of SI2 and AP2. After receiving the authentication response frame, SI3 sends an authentication confirmation frame, containing the information of SI3 and AP3. After receiving the authentication confirmation frame, SI1 sends a delivery information request frame to SI2, containing the information of SI3 and AP3. After receiving the delivery information request frame, SI2 feeds back a delivery information response frame.
[0103] S703, MAP collaborative operation: after the authentication of AP1, AP2 and AP3 is completed through the authentication information delivery mode, AP1, AP2 and AP3 can perform subsequent MAP operation.
[0104] FIG. 8 is a network topology diagram of MAP authentication delivery based on the level of link according to an embodiment of the present disclosure. As shown in FIG. 8, AP1 and AP2 are connected through wired or wireless connection and form a first MAP collaborative working group, and AP3 and AP4 are connected through wired or wireless connection and form a second MAP collaborative working group.
[0105] Figure 9 is a flow chart of authentication passing between two MAP groups according to an embodiment of the present disclosure. As shown in Figure 9, the creation process of a third MAP cooperative group (containing AP1, AP2, AP3 and AP4) is completed by MAP authentication passing between two MAP cooperative groups, which includes:
[0106] S901, the second and third network devices create SI1 and SI2 interfaces respectively on the first radio frequency link;
[0107] S902, the authentication process of SI1 and SI2 is completed.
[0108] S903, SI1 sends a first information frame containing information of AP2 to SI2.
[0109] S904, after receiving the first information frame, SI2 sends the information of AP2 to AP3 through an internal interface, and completes the one-way authentication of AP3 to AP2. SI2 sends a second information frame containing information of AP3 to SI1.
[0110] S905, after receiving the second information frame, SI1 sends the information of AP3 to AP2 through an internal interface, and completes the one-way authentication of AP2 to AP3. SI2 sends the information of AP3 to AP3 through an internal interface.
[0111] S906, AP2 sends the information of AP1 through the link between AP2 and AP3.
[0112] S907, after receiving the information of AP1, AP3 completes the authentication of AP1, and AP3 sends the information of AP1 and AP2 to AP4 through the link between AP3 and AP4. After receiving the information, AP4 completes the authentication of AP1 and AP2.
[0113] S908, AP3 sends the information of AP4 through the link between AP2 and AP3.
[0114] S909, after receiving the information of AP4, AP2 completes the authentication of AP4, and AP2 sends the information of AP3 and AP4 to AP1 through the link between AP1 and AP2. After receiving the information, AP1 completes the authentication of AP3 and AP4.
[0115] After completing the mutual authentication of all APs in the two MAP cooperative groups by the passing method, AP1, AP2, AP3 and AP4 form a new group and perform MAP cooperative operation.
[0116] Figure 10 is a network topology diagram based on AP MLD passing authentication according to an embodiment of the present disclosure, as shown in Figure 10, the first and second network devices (Router1, Router2) create SI1 and SI2 respectively on the first radio link and their attached AP1, AP2 sub-interfaces; SI1 communicates with AP MLD1, AP MLD1.1, etc. through the bridge mode; SI2 communicates with AP MLD2, AP MLD2.1, AP MLD2.2, etc. through the bridge mode.
[0117] Figure 11 is a flowchart based on AP MLD passing authentication according to an embodiment of the present disclosure, as shown in Figure 11, the application example of MAP cooperation based on AP MLD type interface is described as follows:
[0118] S1101, in the AP MLD passing authentication process, SI1 sends an authentication request frame to SI2 through the AP1 sub-interface, without containing any passing AP MLD information;
[0119] S1102, after receiving the above authentication request frame, SI2 sends an authentication response frame to SI1 through the AP2 sub-interface, containing the information of the passing AP MLD(2), wherein the information of the AP MLD(2) is transmitted in encrypted form.
[0120] S1103, after receiving the above authentication response frame, SI1 sends an authentication frame confirmation frame to SI2 through the AP1 sub-interface, containing the information of the passing AP MLD(1), wherein the information of the AP MLD(1) is transmitted in encrypted form.
[0121] The above S1101 to S1103 are the AP MLD passing authentication process.
[0122] S1104, AP MLD de-authentication passing process: in the MAP de-authentication process, SI1 sends a de-authentication frame to SI2 through the AP1 sub-interface, indicating the de-authentication operation between all passing AP MLDs on the two network devices. SI2 sends a response frame of the de-authentication frame, indicating the status as successful. After the AP MLD(1) and the AP MLD(2) complete the de-authentication operation, the corresponding secret key information and other context information are deleted. After the AP MLD(1) and the AP MLD(2) are de-authenticated, the SI1 and the SI2 and their attached AP1 and AP2 sub-interfaces are also deleted.
[0123] Figure 12 is a flowchart of MAP cooperative link update according to an embodiment of the present disclosure, as shown in Figure 12, the MAP link update process includes:
[0124] T1: AP MLD(X) and AP MLD(Y) are both dual-link devices, the first link operating channel is the same, and the second link operating channel is different. SI1 and SI2 complete the transfer of authentication for AP MLD(X) and AP MLD(Y) on the first link, and AP MLD(X) and AP MLD(Y) can perform MAP coordination on the first link.
[0125] T2: Due to the AP MLD switching the second link operating channel of the transferred authentication, AP MLD(X) and AP MLD(Y) need to perform MAP coordination on two different links, respectively.
[0126] S1201, SI1 sends a MAP link update information frame to SI2 on the first link, adds the second link of AP MLD(X) and AP MLD(Y) as a MAP coordination link, and contains the configuration information on the link, and indicates that the second link of SI does not create a corresponding AP sub-interface.
[0127] S1202, after SI2 receives the above MAP link update information frame on the first link, responds to the MAP link update information response frame, indicates that the information shows that the request is agreed, and also does not create a corresponding AP sub-interface on the second link of SI.
[0128] After the above interaction, AP MLD(X) and AP MLD(Y) can perform MAP corresponding operations on the first link and the second link, respectively. But SI1 and SI2 can only interact information frames on the first link.
[0129] FIG. 13 is a schematic diagram of a channel sounding process according to an embodiment of the present disclosure. As shown in FIG. 13, the AP set (i.e., co-hosted BSSID / MBSSID set) on one radio link of a network device includes AP11, AP12...AP1X; and the AP set on one radio link of a second network device includes (AP2, AP22...AP2Y).
[0130] When AP11 in the first set needs to perform channel sounding process required by MAP coordination operation with AP21, AP11 sends NDPA (Null Data Packet Announcement) and NDP frame (Null Data Packet) to AP21 in sequence, AP11 receives CBF (Compressed Beamforming) frame fed back by AP21, and completes the channel sounding process. When AP12 in the first set needs to perform channel sounding with AP22 in the second set, the sounding result of AP11 and AP21 can be directly inherited, the number of channel sounding frames exchanged in the air interface is saved, and the utilization efficiency of the air interface is improved.
[0131] FIG. 14 is a schematic diagram of channel sounding process II according to an embodiment of the present disclosure. As shown in FIG. 14, the AP set (i.e., co-hosted BSSID / MBSSID set) on one radio link of a network device includes AP11, AP12,..., and AP1X; and the AP set on one radio link of a second network device includes (AP21, AP22,..., and AP2Y).
[0132] When AP11 in the first set needs to perform channel sounding process required by MAP coordination operation with STA1 associated with AP21, AP11 sends NDPA and NDP frame to STA1 in sequence, AP11 receives CBF frame fed back by STA1, and completes the channel sounding process. When AP12 in the first set needs to perform channel sounding with STA1 associated with AP21, the sounding result of AP11 and STA1 can be directly inherited, the number of channel sounding frames exchanged in the air interface is saved, and the utilization efficiency of the air interface is improved.
[0133] The co-hosted BSSID (AP identifier) set, i.e., multiple SSIDs / BSSIDs are created on the same radio link, the working channels of these BSSIDs are the same, the receiving and transmitting antennas are the same, and one radio channel is time-division multiplexed. According to the 11ax protocol definition, a maximum of 2 8 = 256 BSSIDs.
[0134] Since in Co-hosted BSSID network topology, each BSSID needs to send Beacon and Probe response frames, the channel access overhead of additional management frames will cause the problem of network channel utilization decline. The multiple BSSID set aims to solve the problem of channel utilization decline caused by frequent Beacon and Probe response frame interaction, and defines two concepts of transmitted BSSID and non-transmitted BSSID.
[0135] Non-transmitted BSSID: a BSSID that does not send Beacon and Probe response frames, and the information in the Beacon and Probe response frames is sent by the transmitted BSSID in the same multiple BSSID set.
[0136] Transmitted BSSID: a BSSID that normally sends Beacon and Probe response frames, and its Beacon and Probe response frames contain information of the non-transmitted BSSID in the same multiple BSSID set at the same time. The information is stored in the multiple BSSID (MBSSID) field, including element identifier element ID, element length length, maximum BSSID number indicator MaxBSSID Indicator, and optional subelement Optional Subelements, wherein the detailed information of other APs is stored in the Optional Subelements.
[0137] The embodiments of the present disclosure also provide a computer program product, comprising computer program instructions, wherein the computer program instructions enable a computer to implement the steps in any of the above method embodiments.
[0138] The embodiments of the present disclosure also provide a computer readable storage medium, which stores a computer program, wherein the computer program is configured to execute the steps in any of the above method embodiments when running.
[0139] In an example embodiment, the above computer readable storage medium can include, but is not limited to, a U disk, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk, and various media that can store computer programs.
[0140] The embodiments of the present disclosure also provide an electronic device, comprising a memory and a processor, the memory stores a computer program, and the processor is configured to run the computer program to perform the steps in any of the above method embodiments.
[0141] In an example embodiment, the electronic device described above can further comprise a transmission device connected to the processor and an input / output device connected to the processor.
[0142] The specific examples in the embodiments can refer to the examples described in the above embodiments and example implementations, which will not be repeated here.
[0143] Obviously, those skilled in the art should understand that the modules or steps of the present disclosure described above can be realized by general computing devices, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and can be realized by program codes executable by the computing devices, so that they can be stored in storage devices and executed by the computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be manufactured into individual integrated circuit modules, or multiple modules or steps can be manufactured into a single integrated circuit module. Therefore, the present disclosure is not limited to any specific combination of hardware and software.
[0144] The above only describes the preferred embodiments of the present disclosure and is not intended to limit the present disclosure. Those skilled in the art can make various modifications and changes to the present disclosure. Any modification, equivalent replacement, improvement, etc. within the principles of the present disclosure shall be included in the protection scope of the present disclosure.
Claims
1. A multi-access point cooperative processing method, the method comprising: a first security interface (SI) signaling with a second SI to perform MAP authentication of a first access point (AP) and a second AP, wherein the first SI and the second SI are on the same or partially overlapping operating channels of at least one radio frequency link, the first SI and the first AP are on the same radio frequency link or the same device, and the second SI and the second AP are on the same radio frequency link or the same device.
2. The method of claim 1, wherein, The first security interface (SI) signaling with the second SI to perform MAP authentication of the first access point (AP) and the second AP comprises: the first SI sending a first information frame to the second SI, wherein the first information frame contains information of at least one single-link AP or multi-link AP; the first SI receiving a second information frame sent by the second SI, wherein the second information frame contains information of at least one single-link AP or multi-link AP; the first SI and the second SI confirming the information of the APs with each other, and completing the MAP authentication of the first AP and the second AP.
3. The method of claim 1, wherein, After the first security interface (SI) signaling with the second SI to perform MAP authentication of the first access point (AP) and the second AP, the method further comprises: the first SI signaling with the second SI to perform de-authentication of the first AP and the second AP.
4. The method of claim 3, wherein, The first SI signaling with the second SI to perform de-authentication of the first AP and the second AP comprises: the first SI sending a third information frame to the second SI, or receiving a third information frame sent by the second SI, wherein the third information frame contains operation end indication information of at least one MAP; the first SI receiving a third information frame response frame sent by the second SI, or sending a third information frame response frame to the second SI, to complete the de-authentication of the first AP and the second AP.
5. The method of claim 1, wherein, The method further comprises: the first SI sending a fourth information frame to the second SI, wherein the fourth information frame is used to request to add or delete link information of at least one multi-link AP; the first SI receiving a fourth information response frame sent by the second SI, wherein the fourth information response frame is used to indicate link state information corresponding to the addition or deletion of the link information of the at least one multi-link AP.
6. The method of claim 1, wherein, The method further comprises: the first SI sending a fifth information frame to the second SI, wherein the fifth information frame is used to request to add or delete link information between the first SI and the second SI; the first SI receiving a fifth information response frame sent by the second SI, wherein the fifth information response frame is used to indicate link state information corresponding to the addition or deletion of the link information between the first SI and the second SI.
7. The method of claim 1, wherein, The method further comprises: the first SI and the second SI are one of the following types: single-link AP, single-link terminal device (STA), multi-link AP, and non-access point multi-link device (non-AP MLD). When the first SI and the second SI are the multi-link AP or multi-link terminal device, the first SI and the second SI are contained in one sub-AP or STA on at least one radio frequency link, and when the first SI and the second SI are the single-link AP or single-link STA, the first SI and the second SI are respectively located on the same radio frequency link of the first AP and the second AP; The first SI performs signaling interaction with the second SI through the sub-AP or the sub-STA.
8. The method of claim 7, wherein, When the first SI and the second SI are the multi-link AP or multi-link device, the signaling interaction between the first SI and the second SI is transmitted and retransmitted on any radio frequency link.
9. The method of claim 7, wherein, The beacon frame or other information frame sent by the first SI through the sub-AP or the sub-STA indicates the maximum number of SIs allowed to be created on each radio frequency link or the maximum number of SIs allowed to be created on the network device, and / or the number of APs participating in cooperative operation in each MAP cooperative group.
10. The method of claim 1, wherein, Before the first access point AP and the second AP perform MAP authentication in the signaling interaction between the first security interface SI and the second SI, the method further comprises: The first SI and the second SI interact at least one information frame on the operating channel of the radio frequency link, wherein the information frame is used to obtain the information of the second AP and the information of the AP to be transmitted.
11. The method of claim 1, wherein, The method further comprises: The first SI performs MAP cooperative operation with the third SI and the fourth SI; or The first SI performs MAP cooperative operation with the fourth SI; Wherein the third SI and the first AP are on the same radio frequency link or the same device, and the fourth SI and the third AP are on the same radio frequency link or the same device.
12. The method of claim 1, wherein, The first SI and the second SI are only used for MAP cooperative operation, and the terminal device is not allowed to establish a connection.
13. The method of claim 12, wherein, The method further comprises: The first SI indicates that the terminal device is not allowed to establish a connection by sending an additional information frame, or sends an information frame in a newly defined frame format to make the terminal device unable to establish a connection.
14. The method of claim 7, wherein, The method further comprises: The first SI indicates the identification information of the radio frequency link on which the sub-STA is recommended to be created on the network device through the beacon frame or other information frame sent by the first SI.
15. The method of claim 2, wherein, When the first information frame is an authentication request frame and the first SI and the second SI are both APs, the authentication request is initiated by the first SI or the second SI; When the first SI is an AP type interface and the second SI is a STA type interface, the authentication request is initiated by the second SI.
16. The method of claim 2, wherein, The information of the single-link AP or multi-link AP is at least one of the following: AP information, multi-link AP information, AP set information, and multi-link AP set information.
17. The method of claim 16, wherein, The first information frame and / or the second information frame comprises an AP set information or a multi-link AP set information, the AP set information is used to indicate AP set characteristic information, and the multi-link AP set information is used to indicate characteristic and identifier information of each multi-link AP in the set; After the MAP authentication is completed, the APs in the AP set information can perform MAP cooperative operation with one or more APs authenticated by the opposite end, and the multi-link APs in the multi-link AP set information can perform MAP cooperative operation with one or more multi-link APs authenticated by the opposite end.
18. The method of claim 2, wherein, The first information frame and / or the second information frame comprises an AP list, and the AP list comprises information of at least one AP; After the MAP authentication is completed, any AP in the AP list can perform MAP cooperative operation with any AP in the AP list of the opposite end.
19. The method of claim 2, wherein, The first information frame and / or the second information frame comprises information of at least one pair of APs that need to perform MAP cooperative operation; After the MAP authentication is completed, each pair of APs negotiated can perform MAP cooperative operation.
20. The method of claim 2, wherein, The method further comprises: The transmitted AP information in the first information frame and / or the second information frame is transmitted after encryption.
21. The method of claim 2, wherein, The transmitted AP information in the first information frame and / or the second information frame is exchanged in the MAP authentication process.
22. The method of claim 1, wherein, The method further comprises: The first SI and the second SI forward the information frame exchanged by the first AP and the second AP.
23. The method of claim 1, wherein, The method further comprises: The first SI and a fourth SI perform transmission authentication, wherein the fourth SI is on the same radio frequency link or the same device as the third AP; The first SI sends the transmitted first AP information and the second AP information transmitted by the second SI to the fourth SI, wherein the first AP information and the second AP information are used to indicate that the third AP performs one-way authentication on the first AP and the second AP.
24. The method of claim 1, wherein, The method further comprises: The first SI sends an additional information frame, wherein the additional information frame comprises information of at least one AP, and is used to indicate that the information of the at least one AP is added to or deleted from an authentication list; The method further comprises:
25. The method of claim 1, wherein, After the first security interface SI and the second SI perform signaling interaction and the first access point AP and the second AP perform MAP authentication, the method further comprises: The first SI generates or transmits at least one set of key information, wherein the at least one set of key information is only used to encrypt or authenticate information interaction frames between the first SI and the second SI.
26. The method of claim 25, wherein, The method further comprises: The first SI shares the at least one set of key information to all APs.
27. The method of claim 1, wherein, The method further comprises: The first SI generates different key information for each pair of APs requiring MAP cooperative operation, wherein the APs in each group use different key information to interact with the opposite APs, and the APs use SN, PN, IPN, BIPN to be individually numbered.
28. The method of claim 1, wherein, The method further comprises: The frame type for the interaction between the first SI and the second SI is a control frame, a management frame, or The frame type for the interaction between the first SI and the second SI is a control frame, a management frame, and a data frame.
29. The method of claim 7, wherein, The method further comprises: In the interface updating process of the multi-link AP, both the addition and deletion of the affiliated AP are included.
30. The method of claim 7, wherein, The interface change of the affiliated STA or AP type of the first SI and / or the second SI comprises at least one of the following: When the MAP cooperative link is added or deleted, the affiliated STA or AP does not change; When the MAP cooperative link is added, the affiliated STA or AP is added on the corresponding radio frequency link; When the MAP cooperative link is deleted, the affiliated STA or AP is deleted on the corresponding radio frequency link; When the MAP cooperative link is added, the affiliated STA or AP is added on the corresponding radio frequency link, and at least one affiliated STA or AP of the SI on the other cooperative link is deleted.
31. The method of claim 3, wherein, The trigger cause of the deauthentication comprises at least one of the following: one of the radio frequency links switches to a working channel resulting in no intersection of the working channels; one of the radio frequency links enters a power saving state; device unexpected power-off or restart.
32. The method of claim 1, wherein, When the type of the information frame for the interaction between the first SI and the second SI comprises: a beacon frame, a probe request frame, a probe response frame, an authentication frame, an association request / response frame, a re-association request / response frame, a deauthentication frame, a disassociation frame, and other types of management frames.
33. The method of claim 1, wherein, When the information frame for the interaction between the first SI and the second SI contains information of a single-link AP, the information of the single-link AP at least contains one of the following: AP ID, BSSID, MAC address, MAC address index information, key generation and key configuration information, MAP capability set, and MAP parameter, wherein the AP ID, the BSSID, the MAC address, and the MAC address index information are AP identification information or assigned identification information, the key generation and key configuration information are key generation parameters and key configuration parameter information for information transmission between APs, and the MAP capability set and the MAP parameter are used to indicate MAP capability and configuration information of each AP.
34. The method of claim 1, wherein, When the information frame for the interaction between the first SI and the second SI contains information of a multi-link AP, the information of the multi-link AP contains at least one of the following: MAC address information of the multi-link AP, MLD ID information, MLD index information, at least one link information of the multi-link AP, MAP capability set, MAP configuration parameter information, SSID information, key information, frame sequence number information, and key configuration information.
35. A computer readable storage medium having stored therein a computer program, wherein, The computer program is arranged to perform the method as claimed in any one of claims 1 to 34 when run.
36. An electronic device comprising a memory and a processor, the memory having stored therein a computer program, the processor being arranged to run the computer program to perform the method as claimed in any one of claims 1 to 34.
37. A computer program product comprising a computer program which, when executed by a processor, implements the steps of the method as claimed in any one of claims 1 to 34.