Configuration information synchronization method, communication node, and storage medium

By autonomously synchronizing configuration information between communication nodes, the complexity and compatibility issues of user involvement between APs are resolved, enabling efficient and secure AP collaborative operation without user intervention.

WO2026066787A1PCT designated stage Publication Date: 2026-04-02ZTE CORP
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2025-08-15
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

In existing technologies, multi-access point authentication and collaborative operation between access points (APs) require user participation in network configuration, which leads to high complexity and increased costs. Furthermore, APs from different vendors may have compatibility issues, affecting performance and user experience.

Method used

By autonomously synchronizing configuration information between communication nodes and employing authentication and encryption mechanisms, configuration information synchronization between APs can be achieved without user intervention. This includes offline or online authentication, symmetric and asymmetric key encryption methods, which resist third-party eavesdropping and imitation, thereby improving system security.

Benefits of technology

It simplifies the complexity of user participation, improves the user experience, avoids compatibility issues, and enhances system security and performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025114899_02042026_PF_FP_ABST
    Figure CN2025114899_02042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a configuration information synchronization method, a communication node, and a storage medium. The method comprises: when second identification information of a second communication node has passed verification and upon determining that first identification information of a first communication node has passed verification by the second communication node, sending first synchronization request information to the second communication node, the first synchronization request information comprising configuration information of the first communication node, or receiving second synchronization request information sent by the second communication node, the second synchronization request information comprising configuration information of the second communication node (S510).
Need to check novelty before this filing date? Find Prior Art

Description

Synchronization method of configuration information, communication node and storage medium TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, for example, to a synchronization method of configuration information, a communication node and a storage medium. BACKGROUND

[0002] At present, whether in the same network or in the non-same network, if there is a demand for multi access point (MAP) authentication and MAP coordination between access points (AP), users need to actually participate in the network configuration operation of the AP, which requires users to have certain network configuration technical background. Moreover, since the interconnection and interoperability between AP manufacturers have not been fully tested, and there may be compatibility problems after enabling MAP function, for example, after enabling MAP coordination function, the performance of APs of different manufacturers may be reduced due to compatibility problems. SUMMARY

[0003] The embodiment of the present application provides a synchronization method of configuration information, applied to a first communication node, comprising:

[0004] When the second identification information of the second communication node is verified and the first identification information of the first communication node is determined to be verified by the second communication node, first synchronization request information is sent to the second communication node, the first synchronization request information comprising configuration information of the first communication node, or second synchronization request information sent by the second communication node is received, the second synchronization request information comprising configuration information of the second communication node.

[0005] The embodiment of the present application provides a synchronization method of configuration information, applied to a second communication node, comprising:

[0006] When the second identification information of the second communication node is determined to be verified by the first communication node, and the first identification information of the first communication node is verified, first synchronization request information sent by the first communication node is received, the first synchronization request information comprising configuration information of the first communication node, or second synchronization request information is sent to the first communication node, the second synchronization request information comprising configuration information of the second communication node.

[0007] The embodiment of the present application provides a communication node, comprising: a processor; the processor is used for realizing the synchronization method of configuration information of any one of the above-mentioned embodiments when executing a computer program.

[0008] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program, and the computer program is executed by the processor to realize the method of any one of the above-mentioned embodiments.

[0009] Further explanation about the above embodiments and other aspects of the present application and implementation manners thereof is provided in the description of drawings, specific embodiments and claims. BRIEF DESCRIPTION OF DRAWINGS

[0010] FIG. 1 is a schematic diagram of a MAP cooperative operation model when an AP is located in different networks according to the related art;

[0011] FIG. 2 is a schematic diagram of a MAP cooperative operation model when an AP is located in the same network according to the related art;

[0012] FIG. 3 is a schematic diagram of a multi-link connection establishment according to an embodiment;

[0013] FIG. 4 is a schematic diagram of a structure of a PTK according to an embodiment;

[0014] FIG. 5 is a schematic diagram of a flow of a configuration information synchronization method according to an embodiment;

[0015] FIG. 6 is a schematic diagram of a flow of another configuration information synchronization method according to an embodiment;

[0016] FIG. 7 is an interaction flow diagram of a configuration information synchronization method according to an embodiment;

[0017] FIG. 8 is an interaction flow diagram of a configuration information synchronization method according to example 1;

[0018] FIG. 9 is an interaction flow diagram of a configuration information synchronization method according to example 2;

[0019] FIG. 10 is a schematic diagram of a structure of a configuration information synchronization apparatus according to an embodiment;

[0020] FIG. 11 is a schematic diagram of a structure of another configuration information synchronization apparatus according to an embodiment;

[0021] FIG. 12 is a schematic diagram of a structure of yet another configuration information synchronization apparatus according to an embodiment;

[0022] FIG. 13 is a schematic diagram of a structure of still another configuration information synchronization apparatus according to an embodiment;

[0023] FIG. 14 is a schematic diagram of a structure of an AP according to an embodiment. DETAILED DESCRIPTION

[0024] It should be understood that the specific embodiments described herein merely exemplify the present application and do not limit the present application. The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0025] FIG. 1 is a schematic diagram of a MAP cooperative operation model of an AP in a related art under different networks. As shown in FIG. 1, an extended service set (ESS) 1 includes an AP 1 and a station (STA) 1, and an ESS 2 includes an AP 2 and a STA 2. The STA 1 and the STA 2 can be terminal devices, and the AP 1 and the AP 2 need to perform MAP cooperative operation, that is, the MAP cooperative operation is under different network scenarios. Under user intervention, the same authentication information (such as a service set identifier (SSID) and key information) can be configured for the two APs based on Wi-Fi technology or non-Wi-Fi technology (such as Bluetooth, near-field communication (NFC), and Quick-Response Code scanning mode), so that the two APs can authenticate each other and then perform subsequent MAP cooperative operation.

[0026] FIG. 2 is a schematic diagram of a MAP cooperative operation model of an AP in a related art under the same network. As shown in FIG. 2, in a user home environment, the AP 1 and an optical network terminal (ONT) are network devices deployed by an operator. In order to improve the Wi-Fi signal coverage range, the user purchases and deploys the AP 2, and the AP 2 is also connected to the ONT to provide network services for terminal devices connected thereto. When the working channels of the AP 1 and the AP 2 overlap, the same authentication information can be configured for the two APs based on some Wi-Fi or non-Wi-Fi technology (such as Bluetooth, NFC, and Quick-Response Code scanning mode), so as to facilitate subsequent MAP authentication and MAP cooperative operation.

[0027] For the above two MAP cooperative operation scenarios, the following problems exist:

[0028] 1) The technology for realizing AP information synchronization based on user intervention is relatively complex and has a high cost.

[0029] The above two MAP cooperative operation scenarios require the user to actually participate in the network configuration operation of the AP, which requires the user to have a certain network configuration technical background. Moreover, if the network configuration is completed by using some non-Wi-Fi technology, the products at both ends need to add corresponding devices and chips, such as adding a Bluetooth chip and corresponding devices to the router based on the Bluetooth network configuration mode, which causes additional cost.

[0030] 2) The method for realizing AP information synchronization based on user intervention can cause social problems.

[0031] When two APs are deployed in different user homes, if a technology similar to Device Provisioning Protocol (DPP) is used for configuration, 2 users need to communicate and cooperate to complete the information synchronization of 2 APs and subsequent MAP authentication and MAP collaborative operation. In actual application, it may cause certain social problems.

[0032] 3) There may be compatibility problems between APs of different manufacturers.

[0033] Due to insufficient testing of interconnection and interoperability between AP manufacturers and possible compatibility problems after enabling MAP function, for example, after enabling the MAP collaborative operation function, the APs of different manufacturers may have performance degradation due to compatibility problems, and thus the user experience is poor.

[0034] The synchronization method of configuration information provided in the application can be applied to various wireless communication systems, such as Long Term Evolution (LTE) system, 4th-Generation (4G) system, 5th-Generation (5G) system, 5G system LTE and 5G hybrid architecture system, 5G New Radio (NR) system, and new communication systems that may appear in future communication development, such as 6th-Generation (6G) system, etc. The wireless communication system includes at least two APs, and can also include a STA accessing the AP.

[0035] The synchronization method of configuration information, communication node and storage medium provided in the application can autonomously complete the synchronization of configuration information between APs without the participation of users, thereby simplifying the complexity of user participation while improving the user experience by applying the MAP collaborative operation technology. Further, the application can also resist the listening and imitation of air interface interaction information by third parties, and improve the security of the system.

[0036] Next, the synchronization method of configuration information, communication node and its technical effects are described.

[0037] In order to facilitate the understanding and description of the scheme, the technical terms in the application are explained as follows:

[0038] Fiber-To-The-Room (FTTR) technology: connecting wireless routers APs in different rooms or positions in a home or small and medium-sized enterprise scene through optical fibers, thereby providing high-bandwidth and high-reliability connection between multi-AP networking, which can utilize point-to-multipoint optical distribution network to realize the connection between master control AP and slave AP.

[0039] 802.11be protocol: The 802.11be (Wi-Fi 7) protocol introduces multi-link operation (MLO) technology, that is, a multi-link device (MLD) including an AP MLD (such as a network device) and a non-AP MLD (such as a terminal device) can simultaneously transmit data on multiple links, thereby improving the throughput of data transmission and reducing the latency.

[0040] After the AP MLD and the non-AP MLD complete a four-way handshake on one link, the AP MLD and the non-AP MLD generate an MLO-level pairwise transient key (PTK) and a link-level group temporal key (GTK), which are respectively used for encrypting and decrypting transmitted unicast data frames and groupcast data frames, thereby ensuring the security of data transmission. For example, FIG. 3 is a schematic diagram of multi-link connection establishment provided in an embodiment. As shown in FIG. 3, the AP MLD and the non-AP MLD each include three links operating at 2.4 GHz, 5 GHz, and 6 GHz. The AP MLD and the non-AP MLD complete the authentication, connection, and four-way handshake process on any one link (such as the 2.4 GHz link), and after the multi-link connection is established, data can be transmitted on the three links.

[0041] Configuration of an AP: In a network model including an access controller (AC), that is, in an AP-AC network architecture model, in order to solve the compatibility problem between the AP and the AC, the Internet Engineering Task Force (IETF) defines a control and configuration protocol of a wireless access point (Control And Provisioning of Wireless Access Points Protocol Specification, CAPWAP), which defines the information format of the interaction between the AP and the AC, and implements operations such as discovery of the AP in the AC, obtaining of configuration information from the AC, and information synchronization.

[0042] Configuration of a STA: In order to improve the difficulty of cracking a Wi-Fi password, the AP end generally configures a relatively complex password, but the complexity of the password can cause the legitimate user to have difficulty in actually inputting the password. Therefore, the Wi-Fi Alliance (WFA) Easy Connection Working Group formulates DPP, which can reduce the complexity of the user in inputting the password to connect to the AP and improve the user experience.

[0043] FIG. 4 is a structural diagram of a PTK according to an embodiment. As shown in FIG. 4, the PTK can be further decomposed into a “temporal key” (TK) for encryption and decryption of unicast data and management frames, a “key confirmation key” (KCK) for calculating a “message integrity code” (MIC), a “key derivation key” (KDK) for generating other key information, and a “key encryption key” (KEK) for encrypting authentication frames or EAPOL (Extensible Authentication Protocol Over LAN) frames.

[0044] Robust Security Network Element (RSNE) and RSN Extension Element (RSNXE): In order to enhance the data encryption and authentication performance of a wireless local area network (WLAN), the Institute of Electrical and Electronics Engineers (IEEE) 802.11i working group is committed to developing a new generation of security standard called IEEE 802.11i, which defines the concept of a robust security network (RSN) and makes various improvements to the various defects of the wired equivalent privacy (WEP) encryption mechanism, such as encryption technology and security authentication functions.

[0045] RSNE is used to indicate elements related to key suites and RSN capabilities included in the RSN. RSNXE is used to indicate additional key suites and RSN capability set information of the RSN.

[0046] MAP coordination operation in 802.11bn (Wi-Fi 8): The task of the Ultra High Reliability (UHR) study group of IEEE is to draft the definition of Wi-Fi 8 protocol. The MAP coordination operation technology is widely discussed by the working group as an important technology of Wi-Fi 8, aiming to improve channel utilization, improve the throughput of the entire system, and reduce latency through the MAP coordination operation technology.

[0047] FIG. 5 is a flowchart of a method for synchronizing configuration information according to an embodiment. As shown in FIG. 5, the method is applicable to a first communication node, such as a first AP, a first STA, a first multi-link station, or a first multi-link AP. The method includes the following steps:

[0048] S510. When the second identification information of the second communication node is verified and the first identification information of the first communication node is determined to be verified by the second communication node, first synchronization request information is sent to the second communication node, or second synchronization request information is received from the second communication node, wherein the first synchronization request information includes configuration information of the first communication node, and the second synchronization request information includes configuration information of the second communication node.

[0049] In this application, the configuration information can be synchronized between two communication nodes (i.e., the first communication node and the second communication node). If the configuration information needs to be synchronized among three or more communication nodes, the configuration information can be synchronized between two communication nodes first, and then synchronized to other communication nodes. The first communication node and the second communication node can be in the same network, such as in the same extended service set (ESS), or in different networks, such as in different ESSs.

[0050] Before the first communication node and the second communication node synchronize the configuration information, the identity of each other needs to be verified. In this application, the second identification information of the second communication node is verified by the first communication node, indicating that the identity of the second communication node is verified. Similarly, the first identification information of the first communication node is verified by the second communication node, indicating that the identity of the first communication node is verified. Only when the identity of each other is verified, the subsequent configuration information synchronization can be performed.

[0051] In an embodiment, one of the first communication node and the second communication node is a master device (or referred to as a configurator), and the other is a slave device (or referred to as an enrollee). The master device can be determined by negotiation between the first communication node and the second communication node, or determined according to high-level signaling indication.

[0052] When the first communication node is the master device, the second communication node is the slave device, and the first communication node sends the first synchronization request information to the second communication node, the first synchronization request information including the configuration information of the first communication node, so that the second communication node can synchronize the configuration information of the first communication node, and the configuration information synchronization between APs is realized. Further, the second communication node can also send the first synchronization response information to the first communication node after the synchronization is completed, the first synchronization response information indicating the synchronization state of the configuration information of the first communication node by the second communication node.

[0053] When the first communication node is the slave device, the second communication node is the master device, and the first communication node receives the second synchronization request information sent by the second communication node, the second synchronization request information including the configuration information of the second communication node, so that the first communication node can synchronize the configuration information of the second communication node, and the configuration information synchronization between APs is realized. Further, the first communication node can also send the second synchronization response information to the second communication node after the synchronization is completed, the second synchronization response information indicating the synchronization state of the configuration information of the second communication node by the first communication node.

[0054] In an embodiment, for the method of verifying the identities of the first communication node and the second communication node to each other, the first communication node can first receive the first information frame sent by the second communication node, the first information frame including the second identification information and the configuration capability selection information; verify the second identification information; and then send the second information frame to the second communication node, the second information frame including at least one of the first identification information and the first indication information, the first indication information being used to indicate whether the second identification information passes the verification of the first communication node. The configuration capability selection information reflects the configuration capability to be used by the first communication node and the second communication node when verifying.

[0055] The first communication node can verify the second identification information in an offline verification manner or an online verification manner. If the second identification information passes the verification, the first communication node needs to continue verifying the first identification information by sending the second information frame to the second communication node, the second information frame including the first identification information. The second information frame can further include the first indication information indicating that the second identification information passes the verification of the first communication node. Optionally, in order to save the overhead, the first communication node and the second communication node can agree that if the first identification information is carried in the second information frame, it is implicitly indicated that the second identification information has passed the verification of the first communication node, and the first indication information does not need to be carried in the second information frame.

[0056] If the second identification information fails to pass the verification, the subsequent configuration information synchronization cannot be performed, and the second communication node does not need to continue verifying the first identification information. At this time, the first communication node sends the second information frame to the second communication node, and the second information frame includes the first indication information indicating that the second identification information fails to pass the verification of the first communication node.

[0057] Optionally, in order to further save the overhead, the first communication node and the second communication node can agree that if the second identification information fails to pass the verification, the first communication node can no longer send the second information frame. At this time, the entire configuration information synchronization process ends.

[0058] In an embodiment, before the first communication node and the second communication node verify each other's identities, a device discovery process can also be included to determine whether the configuration information synchronization between the first communication node and the second communication node can be performed, so as to avoid the problem of performance degradation of the MAP function enabled AP due to the incompatibility of the first communication node and the second communication node, and improve the user experience.

[0059] The first communication node and the second communication node can exchange each other's configuration capability set information, so as to determine whether they can be compatible with each other according to the configuration capability set information. If the first communication node and the second communication node support the same or partially same configuration capability set, it indicates that the first communication node and the second communication node can be compatible. When compatible, the configuration capability to be adopted by the first communication node and the second communication node can be determined by negotiation or selected by any one party.

[0060] Further, in order to save the signaling overhead and reduce the latency, the first communication node can send a third information frame to the second communication node, and the third information frame includes the configuration capability set information of the first communication node. At this time, the second communication node no longer needs to send the configuration capability set information of the second communication node to the first communication node, that is, the fourth information frame is omitted, and after determining the configuration capability selection information according to the configuration capability set information of the first communication node and the configuration capability set information of the second communication node, only the configuration capability set information is carried in the first information frame. In this way, the overhead of one information frame can be saved.

[0061] In an embodiment, the configuration capability set information includes at least one of the following: verification identification information of the online verification mode, verification identification information of the offline verification mode, encryption identification information of the symmetric key encryption mode, encryption identification information of the asymmetric key encryption mode, and multi-access point (MAP) capability set information.

[0062] In an embodiment, the first communication node can receive the fifth information frame sent by the second communication node, and the fifth information frame comprises second indication information, which is used to indicate whether the first identification information passes the verification of the second communication node. Thus, whether the first identification information passes the verification of the second communication node is determined by the second indication information.

[0063] Optionally, in order to further save the overhead, the first communication node and the second communication node can agree that if the first identification information passes the verification, the second communication node can not send any information frame. If the first communication node does not receive any information frame within a period of time after sending the second information frame, it is implied that the first identification information has passed the verification of the second communication node.

[0064] In an embodiment, the second identification information comprises the identification of the second communication node, and the first identification information comprises the identification of the first communication node; or the second identification information comprises the encrypted identification of the second communication node, and the first identification information comprises the encrypted identification of the first communication node. The encryption of the identification of the communication node can resist the eavesdropping and imitation of the third party to the air interface interaction information, and improve the security of the system.

[0065] The identification of the communication node comprises at least one of the following: device identifier information (such as a device factory identification code), padding field information, check information (such as check information generated based on the device identifier and the padding information according to certain algorithm), time information (such as local time, target beacon transmission time (TBTT) information, etc.), random information (such as random pseudo code information).

[0066] When the second identification information comprises the encrypted identification of the second communication node, and the first identification information comprises the encrypted identification of the first communication node, after receiving the first information frame sent by the second communication node, the first communication node also needs to decrypt the second identification information by using the encryption mode indicated by the configuration capability selection information to obtain the identification of the second communication node. Similarly, before sending the second information frame to the second communication node, the first communication node also needs to encrypt the identification of the first communication node by using the encryption mode indicated by the configuration capability selection information to obtain the first identification information.

[0067] When the encryption mode indicated by the configuration capability selection information is the symmetric key encryption mode, the key for encryption and decryption of the first communication node is PTK, such as the KEK of PTK, or the TK of PTK, etc. The PTK is generated based on the first public key of the first communication node and the second public key of the second communication node.

[0068] When the encryption mode indicated by the configuration capability selection information is the asymmetric key encryption mode, the encryption key of the first communication node is the second public key of the second communication node, and the decryption key is the first private key of the first communication node.

[0069] In the present application, the first communication node needs to send the first public key to the second communication node, and the second communication node needs to send the second public key to the first communication node. Exemplarily, the first public key can be carried in a third information frame, and the second public key can be carried in a fourth information frame.

[0070] In an embodiment, when the encryption mode indicated by the configuration capability selection information is the asymmetric key encryption mode, the first public key and the second public key can be a string, or determined according to an X point coordinate on an elliptic curve and a specific finite cyclic group. The specific determination method is that the first communication node can calculate the Y coordinate in the specific finite cyclic group according to the X point coordinate on the elliptic curve, and further determine the first public key; and the second communication node can calculate the Y coordinate in the specific finite cyclic group according to the X point coordinate on the elliptic curve, and further determine the second public key.

[0071] In an embodiment, when the first communication node and the second communication node are multi-link devices, the configuration information of the communication node is the configuration information corresponding to at least one link.

[0072] The configuration information of the communication node includes at least one of the following: AP MLD address, basic service set identifier (BSSID), SSID, medium access control (MAC) address information, key information, working channel information, MAP capability set information, BSSID information, RSNE information, and RSNXE information.

[0073] FIG. 6 is a flowchart of another configuration information synchronization method provided in an embodiment. As shown in FIG. 6, the method provided in the present embodiment is applicable to a second communication node, such as a second AP, a second STA, a second multi-link station, or a second multi-link access point. The method includes the following steps:

[0074] S610, when the second identification information of the second communication node is determined to pass the verification of the first communication node, and the first identification information of the first communication node is determined to pass the verification, receiving the first synchronization request information sent by the first communication node, or sending the second synchronization request information to the first communication node, the first synchronization request information including the configuration information of the first communication node, or the second synchronization request information including the configuration information of the second communication node.

[0075] In the present application, the configuration information can be synchronized between two communication nodes (i.e. the first communication node and the second communication node), if the configuration information needs to be synchronized among three or more communication nodes, two communication nodes can be selected to synchronize first, and then the configuration information can be synchronized to other communication nodes. The first communication node and the second communication node can be under the same network, for example, the two communication nodes are under the same extended service set (ESS); or can be under different networks, for example, the two communication nodes are under different ESSs.

[0076] Before the first communication node and the second communication node synchronize the configuration information, the identity of each other needs to be verified. In the present application, the first communication node verifies the second identification information of the second communication node successfully, which means that the identity of the second communication node is verified; similarly, the second communication node verifies the first identification information of the first communication node successfully, which means that the identity of the first communication node is verified. Only when the identity of each other is verified, the subsequent configuration information synchronization can be performed.

[0077] In an embodiment, one of the first communication node and the second communication node is a master device (or called a configurator), and the other is a slave device (or called an admittee). The master device can be determined by negotiation between the first communication node and the second communication node, or determined according to high layer signaling indication.

[0078] When the first communication node is the master device and the second communication node is the slave device, the second communication node receives the first synchronization request information sent by the first communication node, the first synchronization request information includes the configuration information of the first communication node, and the second communication node can synchronize the configuration information of the first communication node to realize the configuration information synchronization between APs. Further, the second communication node can also send the first synchronization response information to the first communication node after completing the synchronization, the first synchronization response information indicates the synchronization state of the configuration information of the first communication node by the second communication node.

[0079] When the first communication node is the slave device and the second communication node is the master device, the second communication node sends the second synchronization request information to the first communication node, the second synchronization request information includes the configuration information of the second communication node, so that the first communication node can synchronize the configuration information of the second communication node to realize the configuration information synchronization between APs. Further, the first communication node can also send the second synchronization response information to the second communication node after completing the synchronization, the second synchronization response information indicates the synchronization state of the configuration information of the second communication node by the first communication node.

[0080] In an embodiment, for the method of authenticating the identity of each other by the first communication node and the second communication node, the second communication node can send a first information frame to the first communication node, the first information frame comprising the second identification information and the configuration capability selection information; receive the second information frame sent by the first communication node, the second information frame comprising at least one of the first identification information and the first indication information, the first indication information being used to indicate whether the second identification information is verified by the first communication node; and then verify the first identification information. The configuration capability selection information reflects the configuration capability to be used by the first communication node and the second communication node during the verification.

[0081] When the second information frame only comprises the first identification information, it is implied that the second identification information has passed the verification of the first communication node, and thus the first indication information does not need to be carried in the second information frame. When the second information frame comprises the first identification information and the first indication information, the first indication information indicates that the second identification information passes the verification of the first communication node. When the second information frame only comprises the first indication information, the first indication information indicates that the second identification information does not pass the verification of the first communication node.

[0082] For the case that the second information frame comprises the first identification information, the second communication node can verify the first identification information in an offline verification manner or an online verification manner. The second communication node can send a fifth information frame to the first communication node, the fifth information frame comprising the second indication information, the second indication information being used to indicate whether the first identification information passes the verification of the second communication node.

[0083] Optionally, in order to save the overhead, the first communication node and the second communication node can agree that if the first identification information passes the verification, the second communication node can not send any information frame. The first communication node, after sending the second information frame, if no information frame is received within a period of time, it is implied that the first identification information has passed the verification of the second communication node.

[0084] In an embodiment, before the first communication node and the second communication node authenticate the identity of each other, a device discovery process can be further included to determine whether the synchronization of the configuration information between the first communication node and the second communication node can be performed, so as to avoid the problem that the performance of the MAP function enabled AP is reduced due to the incompatibility between the first communication node and the second communication node, and improve the user experience.

[0085] The first communication node and the second communication node can exchange each other's configuration capability set information, and determine whether they can be compatible with each other according to the configuration capability set information. If the first communication node and the second communication node support the same or partially same configuration capability set, it indicates that the first communication node and the second communication node can be compatible. When compatible, the configuration capability to be adopted by the first communication node and the second communication node can be determined by negotiation or selected by any one of them.

[0086] Further, in order to save the signaling overhead and reduce the time delay, the third information frame sent by the first communication node can be received by the second communication node, and the third information frame includes the configuration capability set information of the first communication node. At this time, the second communication node no longer needs to send the configuration capability set information of the second communication node to the first communication node, i.e. the fourth information frame is omitted, and only the configuration capability set information is carried in the first information frame after the configuration capability selection information is determined according to the configuration capability set information of the first communication node and the configuration capability set information of the second communication node. In this way, the overhead of one information frame can be saved.

[0087] In an embodiment, the configuration capability set information includes at least one of the following: authentication identification information of the online authentication mode, authentication identification information of the offline authentication mode, encryption identification information of the symmetric key encryption mode, encryption identification information of the asymmetric key encryption mode, and multi-access point (MAP) capability set information.

[0088] In an embodiment, the second identification information includes the identification of the second communication node, and the first identification information includes the identification of the first communication node; or the second identification information includes the encrypted identification of the second communication node, and the first identification information includes the encrypted identification of the first communication node. The identification of the communication node is encrypted, which can resist the eavesdropping and imitation of the third party to the air interface interaction information, and improve the security of the system.

[0089] The identification of the communication node includes at least one of the following: device identifier information (such as device factory identification code), padding field information, check information (such as check information generated based on the device identifier and padding information according to certain algorithm), time information (such as local time, TBTT information, etc.), random information (such as random pseudo code information).

[0090] When the second identification information comprises the encrypted identification of the second communication node and the first identification information comprises the encrypted identification of the first communication node, before sending the first information frame to the first communication node, the second communication node also needs to encrypt the identification of the second communication node by using the encryption mode indicated by the configuration capability selection information to obtain the second identification information. Similarly, after receiving the second information frame sent by the first communication node, the second communication node also needs to decrypt the first identification information by using the encryption mode indicated by the configuration capability selection information to obtain the identification of the first communication node.

[0091] When the encryption mode indicated by the configuration capability selection information is the symmetric key encryption mode, the key for encryption and decryption of the second communication node is PTK, such as the KEK of PTK or the TK of PTK. The PTK is generated based on the first public key of the first communication node and the second public key of the second communication node.

[0092] When the encryption mode indicated by the configuration capability selection information is the asymmetric key encryption mode, the key for encryption of the second communication node is the first public key of the first communication node, and the key for decryption is the second private key of the second communication node.

[0093] In the present application, the first communication node needs to send the first public key to the second communication node, and the second communication node needs to send the second public key to the first communication node. Exemplarily, the first public key can be carried in the third information frame, and the second public key can be carried in the fourth information frame.

[0094] In an embodiment, when the encryption mode indicated by the configuration capability selection information is the asymmetric key encryption mode, the first public key and the second public key can be a string or determined according to the X point coordinate on the elliptic curve and a specific finite cyclic group. The specific determination method is that the first communication node can calculate the Y coordinate in the specific finite cyclic group according to the X point coordinate on the elliptic curve, and further determine the first public key; and the second communication node can calculate the Y coordinate in the specific finite cyclic group according to the X point coordinate on the elliptic curve, and further determine the second public key.

[0095] In an embodiment, when the first communication node and the second communication node are multi-link devices, the configuration information of the communication node is the configuration information corresponding to at least one link.

[0096] The configuration information of the communication node comprises at least one of the following: AP MLD address, BSSID, SSID, MAC address information, key information, working channel information, MAP capability set information, BSSID information, RSNE information, and RSNXE information.

[0097] FIG. 7 is an interaction flowchart of a method for synchronizing configuration information according to an embodiment. As shown in FIG. 7, the method is applicable to synchronizing configuration information between a first communication node and a second communication node. The method comprises the following steps:

[0098] S701. The first communication node sends a third information frame to the second communication node, wherein the third information frame comprises configuration capability set information of the first communication node.

[0099] In an embodiment, the configuration capability set information comprises at least one of the following: authentication identification information of an online authentication mode, authentication identification information of an offline authentication mode, encryption identification information of a symmetric key encryption mode, encryption identification information of an asymmetric key encryption mode, and multi-access point (MAP) capability set information.

[0100] S702. The second communication node receives the third information frame sent by the first communication node.

[0101] S703. The second communication node sends a fourth information frame to the first communication node, wherein the fourth information frame comprises configuration capability set information of the second communication node.

[0102] S704. The first communication node receives the fourth information frame sent by the second communication node.

[0103] S705. The second communication node sends a first information frame to the first communication node, wherein the first information frame comprises second identification information and configuration capability selection information.

[0104] Specifically, the configuration capability selection information can be determined by the second communication node according to the configuration capability set information of the first communication node and the configuration capability set information of the second communication node.

[0105] If the first communication node and the second communication node support the same or partially same configuration capability set, it indicates that the first communication node and the second communication node are compatible. The second communication node can determine the configuration capability selection information according to the same configuration capability set supported by the first communication node and the second communication node.

[0106] For example, selecting an online authentication mode / offline authentication mode; selecting whether to use an encryption mode; using a symmetric key encryption mode or an asymmetric key encryption mode.

[0107] In a possible implementation, the second identification information comprises an identification of the second communication node. Correspondingly, the subsequent first identification information comprises an identification of the first communication node. This indicates that the configuration capability selection information indicates that the identification of the communication node is not encrypted by using an encryption mode.

[0108] In another possible implementation, the second identification information comprises an encrypted identity of the second communication node. Correspondingly, the first identification information comprises an encrypted identity of the first communication node. This indicates that the configuration capability selection information indicates that the identity of the communication node is encrypted in an encryption mode. The encryption mode indicated by the configuration capability selection information is a symmetric key encryption mode or an asymmetric key encryption mode.

[0109] The identity of the communication node comprises at least one of the following: device identifier information (such as a device factory identification code), padding field information, check information (such as check information generated based on the device identifier and the padding information according to certain algorithms), time information (such as local time, TBTT information, etc.), random information (such as random pseudo code information). The identity of the communication node can be understood as a temporary identifier generated by the communication node, which is discarded after each interaction. This can ensure that the communication node generates different temporary identifiers each time, thereby avoiding the theft of sensitive information by a third party and ensuring system security.

[0110] Optionally, before the second communication node sends the first information frame to the first communication node, the second communication node can also encrypt the identity of the second communication node by using the encryption mode indicated by the configuration capability selection information, to obtain the second identification information.

[0111] Specifically, when the encryption mode indicated by the configuration capability selection information is the symmetric key encryption mode, the key used by the second communication node for encryption and decryption is PTK, such as a KEK of the PTK or a TK of the PTK. The PTK is generated based on the first public key of the first communication node and the second public key of the second communication node. When the encryption mode indicated by the configuration capability selection information is the asymmetric key encryption mode, the key used by the second communication node for encryption is the first public key of the first communication node, and the key used by the second communication node for decryption is the second private key of the second communication node.

[0112] S706, the first communication node receives the first information frame sent by the second communication node.

[0113] Optionally, the first communication node can also decrypt the second identification information by using the encryption mode indicated by the configuration capability selection information, to obtain the identity of the second communication node. The identity of the second communication node is verified by using the online verification mode / offline verification mode.

[0114] Specifically, when the encryption mode indicated by the configuration capability selection information is the symmetric key encryption mode, the key encrypted and decrypted by the first communication node is the PTK, such as the KEK of the PTK, or the TK of the PTK, and the like. The PTK is generated based on the first public key of the first communication node and the second public key of the second communication node. When the encryption mode indicated by the configuration capability selection information is the asymmetric key encryption mode, the key encrypted by the first communication node is the second public key of the second communication node, and the key decrypted by the first communication node is the first private key of the first communication node.

[0115] In the present application, the first communication node needs to send the first public key to the second communication node, and the second communication node needs to send the second public key to the first communication node. Exemplarily, the first public key can be carried in the third information frame, and the second public key can be carried in the fourth information frame.

[0116] S707, the first communication node sends a second information frame to the second communication node, the second information frame including at least one of the first identification information and the first indication information, the first indication information being used to indicate whether the second identification information passes the verification of the first communication node.

[0117] If the second identification information passes the verification, the second communication node needs to continue to verify the first identification information, i.e., the first communication node sends a second information frame to the second communication node, the second information frame including the first identification information. The second information frame can further include the first indication information indicating that the second identification information passes the verification of the first communication node. Optionally, in order to save overhead, the first communication node and the second communication node can agree that if the first identification information is carried in the second information frame, it is implicitly indicated that the second identification information has passed the verification of the first communication node, and it is not necessary to carry the first indication information in the second information frame.

[0118] If the second identification information does not pass the verification, subsequent configuration information synchronization cannot be performed, and the second communication node also does not need to continue to verify the first identification information. At this time, the first communication node sends a second information frame to the second communication node, the second information frame including the first indication information indicating that the second identification information does not pass the verification of the first communication node.

[0119] Optionally, in order to further save overhead, the first communication node and the second communication node can agree that if the second identification information does not pass the verification, the first communication node can no longer send the second information frame. At this time, the entire configuration information synchronization process ends.

[0120] Optionally, before the first communication node sends the second information frame to the second communication node, the first communication node can also encrypt the identification of the first communication node by using the encryption mode indicated by the configuration capability selection information to obtain the first identification information. The key used can refer to the description in S706, which will not be described here again.

[0121] S708, the second communication node receives the second information frame sent by the first communication node.

[0122] If the second information frame comprises the first identification information, the second communication node verifies the identification of the first communication node in the online verification mode / offline verification mode.

[0123] Optionally, the second communication node can also decrypt the first identification information by using the encryption mode indicated by the configuration capability selection information to obtain the identification of the first communication node. The key used can refer to the description in S705, which will not be repeated here.

[0124] S709, the second communication node sends a fifth information frame to the first communication node, and the fifth information frame comprises second indication information, which is used to indicate whether the first identification information passes the verification of the second communication node.

[0125] Optionally, in order to save overhead, the first communication node and the second communication node can agree that if the first identification information passes the verification, the second communication node can not send any information frame. The first communication node, after sending the second information frame, if no information frame is received within a period of time, it is implicitly indicated that the first identification information has passed the verification of the second communication node.

[0126] S710, the first communication node receives the fifth information frame sent by the second communication node.

[0127] S711, when the second identification information passes the verification of the first communication node, the first identification information passes the verification of the second communication node, and the first communication node is the master device, the first communication node sends a first synchronization request information to the second communication node, and the first synchronization request information comprises the configuration information of the first communication node.

[0128] S712, the second communication node receives the first synchronization request information sent by the first communication node.

[0129] S713, the second communication node synchronizes the configuration information of the first communication node.

[0130] When the second identification information passes the verification of the first communication node, and the first identification information passes the verification of the second communication node, for the case that the first communication node is the master device, the first communication node initiates synchronization, sends the first synchronization request information to the second communication node, so that the second communication node synchronizes the configuration information of the first communication node.

[0131] Further, after completing the synchronization, the second communication node can also send a first synchronization response information to the first communication node, and the first synchronization response information indicates the synchronization state of the configuration information of the first communication node by the second communication node.

[0132] S714, when the second identification information passes the verification of the first communication node, the first identification information passes the verification of the second communication node, and the second communication node is the master device, the second communication node sends second synchronization request information to the first communication node, the second synchronization request information comprising configuration information of the second communication node.

[0133] S715, the first communication node receives the second synchronization request information sent by the second communication node.

[0134] S716, the first communication node synchronizes the configuration information of the second communication node.

[0135] When the second identification information passes the verification of the first communication node, and the first identification information passes the verification of the second communication node, for the case that the second communication node is the master device, the second communication node initiates synchronization, sends second synchronization request information to the first communication node, so that the first communication node synchronizes the configuration information of the second communication node.

[0136] Further, after completing the synchronization, the first communication node can also send second synchronization response information to the second communication node, the second synchronization response information indicating the synchronization state of the first communication node to the configuration information of the second communication node.

[0137] In an embodiment, when the first communication node and the second communication node are multi-link devices, the configuration information of the communication node is the configuration information corresponding to at least one link.

[0138] The configuration information of the communication node comprises at least one of the following: AP MLD address, basic service set identifier (BSSID), SSID, medium access control (MAC) address information, key information (such as password, certificate, etc.), working channel information, MAP capability set information, BSSID information, RSNE information, RSNXE information.

[0139] The first communication node and the second communication node can realize subsequent mutual authentication according to the SSID and the key information. The opposite party is identified according to unique identification information such as an AP MLD MAC address and BSSID information; the subsequent discovery of the opposite party is realized according to a working channel, or the channel number that needs to be scanned; the MAP coordination group features established are determined according to the MAP capability set information (for example, features such as support for coordination spatial reuse (Co-SR), coordination beamforming (Co-BF), coordination time division multiple access (Co-TDMA), and the like), and coordination of a restricted target wake-up time (Co-rTWT); and the key suite, key length, and key algorithm (for example, Hybrid Public Key Encryption (HPKE), and Advanced Encryption Standard-Synthetic Initialization Vector (AES-SIV) algorithm) and the like in the mutual authentication process are determined according to the RSNE and RSNXE information.

[0140] In addition, the information frame mentioned in the embodiments of the present application can be a beacon frame, a (multi-link) probe request frame, a (multi-link) probe response frame, a public action frame, an authentication frame, or other types of management frames.

[0141] In the device discovery process, the first communication node can obtain the same vendor information element (Vendor IE) carried in the second communication node information, and initiate a verification process based on the same Vendor IE.

[0142] After the configuration is completed, the first communication node and the second communication node can synchronize the configuration information to other communication nodes (such as a third communication node) connected to the same network. For example, the first communication node synchronizes the configuration information to the third communication node connected to the same network, and the third communication node can directly perform a MAP coordination prior authentication process with the second communication node using the configuration information, thereby skipping the configuration process with the second communication node.

[0143] Below, some examples are provided to illustrate the method of synchronizing configuration information provided in the present application. In the following examples, the first communication node is AP1 and the second communication node is AP2.

[0144] Example 1: using online verification mode + asymmetric key encryption mode

[0145] AP1 and AP2 are connected to the first network and the second network respectively through wired or wireless means; using a public key and private key algorithm, AP1 generates a pair of public key (denoted as K1) and private key (denoted as pri1), the public key is used for information encryption and the private key is used for information decryption. Similarly, AP2 generates a pair of public key (denoted as K1) and private key (denoted as pri2).

[0146] The principle of online verification mode is: 1) each device receives a device identifier from the network, encrypts and sends it to the other party for verification; 2) the receiving party receives the device identifier of the other party, decrypts and transmits it to the network for verification, and determines whether the other party is a legal device according to the verification result of the network side.

[0147] Figure 8 is an interaction flow chart of a method of synchronizing configuration information provided in Example 1. As shown in Figure 8, the following steps are included:

[0148] 1. AP1 sends beacon frame 1 to AP2, the beacon frame 1 including the configuration capability set information of AP1 and the public key K1.

[0149] The configuration capability set information of AP1 includes the encryption identification information of the asymmetric key encryption mode and the verification identification information of the online verification mode.

[0150] 2. AP2 sends beacon frame 2 to AP1, the beacon frame 2 including the configuration capability set information of AP2 and the public key K2.

[0151] The configuration capability set information of AP2 includes the encryption identification information of the asymmetric key encryption mode and the verification identification information of the online verification mode.

[0152] 3. AP2 obtains the one-time identification information Device ID1 (denoted as DID_1) from network 2, and sends an authentication request frame to AP1, the authentication request frame containing the information block (denoted as blob1) formed by DID_1 encrypted using K1.

[0153] 4. AP1 decrypts blob1 using pri1 to restore DID_1 and sends it to network 1 for online verification.

[0154] 5. After receiving the successful verification indication from Network 1, AP1 obtains the one-time identification information Device ID2 (denoted as DID_2) from Network 1 and sends an authentication response frame to AP2. The authentication response frame contains an information block (denoted as blob2) formed by encrypting DID_2 using K2 and the indication information that DID_1 was successfully verified.

[0155] 6. AP2 uses priv2 to decrypt blob2, restores DID_2, and sends it to network 2 for online verification.

[0156] 7. After receiving the successful verification indication from network 2, AP2 sends an authentication confirmation frame to AP1. The authentication confirmation frame contains the indication information that DID_2 has been successfully verified and indicates that AP1 is the master AP.

[0157] 8. AP1 configures an SSID, key information, and key suite information for AP2 to use for subsequent authentication, and sends it to AP2 through a configuration information request frame.

[0158] 9. AP2 sends a configuration information response frame, indicating that the configuration information synchronization was successful.

[0159] Example 2: Using offline verification mode + symmetric key encryption method

[0160] AP1 and AP2 are configured with a unique fixed identifier, 0001 and 0002 respectively, and are configured with the same peer key information K.

[0161] The principle of offline verification mode is as follows: 1) Each device is configured with a device identifier at the factory, allowing each device to generate a unique encrypted information block according to a certain key generation algorithm; 2) The receiver can determine whether the other party is a legitimate device by decrypting the encrypted information block according to the same key algorithm.

[0162] Figure 9 is an interactive flowchart of a configuration information synchronization method provided in Example 2. As shown in Figure 9, it includes the following steps:

[0163] 1. AP1 sends beacon frame 1 to AP2. Beacon frame 1 includes AP1's configuration capability set information.

[0164] The configuration capability set information of AP1 includes encryption identification information of symmetric key encryption method, verification identification information of offline verification mode and time information TSF1.

[0165] 2. AP2 generates a cryptographic block blob2 = K(0002, TSF1) locally and sends beacon frame 2 to AP1. Beacon frame 2 includes AP2's configuration capability set information.

[0166] The configuration capability set information of the AP2 includes encryption identification information of the symmetric key encryption mode, verification identification information of the offline verification mode and time information TSF2.

[0167] 3. The AP1 locally generates a cipher block blob1=K(0001,TSF2), and sends an authentication request frame to the AP2, wherein the authentication request frame includes a first public key (pub1) and indication information indicating that the AP1 is a configurator of the configuration process.

[0168] 4. The AP2 sends an authentication response frame, wherein the authentication response frame includes a second public key (pub2) and an encrypted blob2.

[0169] Wherein, the AP2 can generate a PTK according to the SAE algorithm by using the first public key and the second public key, and encrypt the blob2 by using a KEK in the PTK.

[0170] 5. The AP1 locally generates a PTK and the same KEK, decrypts the blob2 by using the KEK, and obtains 0002 and TSF1 by decrypting K(blob2), that is, it is determined that the identification is successful. The AP1 sends a first authentication confirmation frame to the AP2, wherein the first authentication confirmation frame includes the blob1 encrypted by using the KEK and indication information indicating that the verification of the blob2 is successful.

[0171] 6. The AP2 decrypts the blob1 by using the KEK, and obtains 0001 and TSF2 by decrypting K(blob1), that is, it is determined that the identification is successful. The AP2 sends a second authentication confirmation frame to the AP1, wherein the second authentication confirmation frame includes indication information indicating that the verification of the blob1 encrypted by using the KEK is successful.

[0172] 7. The AP1 configures a SSID, key information and key suite information used by the AP2 for subsequent authentication, and sends the configuration information to the AP2 by using a configuration information request frame.

[0173] 8. The AP2 feeds back a configuration information response frame, and indicates that the configuration information is successfully synchronized.

[0174] 9. The AP1 sends a de-authentication request frame to the AP2, and completes the de-authentication process of the two parties.

[0175] Fig. 10 is a structural schematic diagram of a configuration information synchronization device provided by an embodiment, which can be configured in a first communication node. As shown in Fig. 10, the device includes a communication module 101.

[0176] The communication module 101 is configured to send first synchronization request information to the second communication node when the second identification information of the second communication node is verified and the first identification information of the first communication node is determined to be verified by the second communication node, the first synchronization request information comprising configuration information of the first communication node, or receive second synchronization request information sent by the second communication node, the second synchronization request information comprising configuration information of the second communication node.

[0177] The configuration information synchronization device provided in the embodiment is used to implement the configuration information synchronization method shown in FIG. 5, and the implementation principle and technical effects of the configuration information synchronization device provided in the embodiment are similar to those of the above embodiment, which will not be described here.

[0178] In an embodiment, the communication module 101 is further configured to receive a first information frame sent by the second communication node, the first information frame comprising the second identification information and configuration capability selection information; and send a second information frame to the second communication node, the second information frame comprising at least one of the first identification information and first indication information, the first indication information being used to indicate whether the second identification information is verified by the first communication node.

[0179] In an embodiment, the communication module 101 is further configured to send a third information frame to the second communication node, the third information frame comprising configuration capability set information of the first communication node; and receive a fourth information frame sent by the second communication node, the fourth information frame comprising configuration capability set information of the second communication node.

[0180] In an embodiment, the configuration capability set information comprises at least one of the following: verification identification information of an online verification mode, verification identification information of an offline verification mode, encryption identification information of a symmetric key encryption mode, encryption identification information of an asymmetric key encryption mode, and multi-access point (MAP) capability set information.

[0181] In an embodiment, the communication module 101 is further configured to receive a fifth information frame sent by the second communication node, the fifth information frame comprising second indication information, the second indication information being used to indicate whether the first identification information is verified by the second communication node.

[0182] In an embodiment, in combination with FIG. 10, FIG. 11 is a structural schematic diagram of another configuration information synchronization device provided in an embodiment, as shown in FIG. 11, the device further comprises a processing module 102.

[0183] The processing module 102 is configured to synchronize configuration information of the second communication node.

[0184] In an embodiment, the second identification information comprises an identity of the second communication node, and the first identification information comprises an identity of the first communication node; or,

[0185] The second identification information includes an encrypted identity of the second communication node, and the first identification information includes an encrypted identity of the first communication node.

[0186] In an embodiment, when the second identification information includes an encrypted identity of the second communication node and the first identification information includes an encrypted identity of the first communication node, the processing module 102 is further configured to decrypt the second identification information by using the encryption mode indicated by the configuration capability selection information to obtain the identity of the second communication node, and encrypt the identity of the first communication node by using the encryption mode indicated by the configuration capability selection information to obtain the first identification information.

[0187] In an embodiment, when the encryption mode indicated by the configuration capability selection information is a symmetric key encryption mode, the key for encryption and decryption of the first communication node is a pairwise transmission key PTK, and the PTK is generated based on a first public key of the first communication node and a second public key of the second communication node.

[0188] When the encryption mode indicated by the configuration capability selection information is an asymmetric key encryption mode, the key for encryption of the first communication node is the second public key of the second communication node, and the key for decryption is the first private key of the first communication node.

[0189] In an embodiment, the third information frame further includes the first public key of the first communication node, and the fourth information frame further includes the second public key of the second communication node.

[0190] In an embodiment, the first public key and the second public key are strings or are determined according to an X-point coordinate on an elliptic curve and a specific finite cyclic group.

[0191] In an embodiment, the identity of the communication node includes at least one of the following: device identifier information, padding field information, check information, time information, and random information.

[0192] In an embodiment, when the first communication node and the second communication node are multi-link devices, the configuration information of the communication node is configuration information corresponding to at least one link.

[0193] In an embodiment, the configuration information of the communication node includes at least one of the following: an access point multi-link device AP MLD address, a basic service set identifier BSSID, a service set identifier SSID, media access control MAC address information, key information, operating channel information, a set of MAP capabilities, BSSID information, robust security network element RSNE information, and extended robust security network element RSNXE information.

[0194] FIG. 12 is a structural schematic diagram of a synchronization device of another configuration information according to an embodiment, which can be configured in the second communication node, as shown in FIG. 12, the device includes a communication module 201.

[0195] The communication module 201 is configured to receive the first synchronization request information sent by the first communication node when it is determined that the second identification information of the second communication node is verified by the first communication node and the first identification information of the first communication node is verified, the first synchronization request information comprising configuration information of the first communication node, or send the second synchronization request information to the first communication node, the second synchronization request information comprising configuration information of the second communication node.

[0196] The configuration information synchronization device provided in the embodiment is used to implement the configuration information synchronization method shown in FIG. 6, and the implementation principle and technical effects of the configuration information synchronization device provided in the embodiment are similar to those of the above embodiment, which will not be described here.

[0197] In an embodiment, the communication module 201 is further configured to send a first information frame to the first communication node, the first information frame comprising the second identification information and configuration capability selection information; and receive a second information frame sent by the first communication node, the second information frame comprising at least one of the first identification information and first indication information, the first indication information being used to indicate whether the second identification information is verified by the first communication node.

[0198] In an embodiment, in combination with FIG. 12, FIG. 13 is a structural schematic diagram of another configuration information synchronization device provided in an embodiment, as shown in FIG. 13, the device further comprises a processing module 202.

[0199] The communication module 201 is further configured to receive a third information frame sent by the first communication node, the third information frame comprising configuration capability set information of the first communication node; and send a fourth information frame to the first communication node, the fourth information frame comprising configuration capability set information of the second communication node.

[0200] In an embodiment, the communication module 201 is further configured to send a fifth information frame to the first communication node, the fifth information frame comprising second indication information, the second indication information being used to indicate whether the first identification information is verified by the second communication node.

[0201] In an embodiment, the processing module 202 is further configured to synchronize the configuration information of the first communication node.

[0202] In an embodiment, when the second identification information comprises an encrypted identity of the second communication node and the first identification information comprises an encrypted identity of the first communication node; the processing module 202 is further configured to encrypt the identity of the second communication node by using an encryption mode indicated by the configuration capability selection information to obtain the second identification information; and decrypt the first identification information by using the encryption mode indicated by the configuration capability selection information to obtain the identity of the first communication node.

[0203] In an embodiment, when the encryption mode indicated by the configuration capability selection information is a symmetric key encryption mode, the encryption and decryption key of the second communication node is a pairwise transmission key (PTK), and the PTK is generated based on the first public key of the first communication node and the second public key of the second communication node.

[0204] When the encryption mode indicated by the configuration capability selection information is an asymmetric key encryption mode, the encryption key of the second communication node is the first public key of the first communication node, and the decryption key is the second private key of the second communication node.

[0205] In an embodiment, the third information frame further includes the first public key of the first communication node, and the fourth information frame further includes the second public key of the second communication node.

[0206] The embodiments of the present application further provide a communication node, comprising: a processor, which is configured to implement the method provided by any of the embodiments of the present application when executing a computer program.

[0207] For example, FIG. 14 is a structural schematic diagram of an AP provided by an embodiment, as shown in FIG. 14, the AP includes a processor 60, a memory 61 and a communication interface 62; the number of processors 60 in the AP can be one or more, and one processor 60 is taken as an example in FIG. 14; the processor 60, the memory 61 and the communication interface 62 in the AP can be connected through a bus or other manners, and the connection through the bus is taken as an example in FIG. 14. The bus represents one or more of several bus structures, including a memory bus or a memory controller, a peripheral bus, a graphics acceleration port, a processor or a local bus using any of the bus structures.

[0208] The memory 61 is a kind of computer readable storage medium, which can be configured to store software programs, computer executable programs and modules, such as program instructions / modules corresponding to the method in the embodiments of the present application. The processor 60 executes the software programs, instructions and modules stored in the memory 61, thereby performing at least one function application and data processing of the AP, i.e. implementing the above method.

[0209] The memory 61 can include a program storage area and a data storage area, wherein the program storage area can store an operating system and at least one application required by a function; the data storage area can store data created according to the use of the terminal, etc. In addition, the memory 61 can include a high-speed random access memory, and can also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device or other non-volatile solid-state memory device. In some examples, the memory 61 can include a memory remotely arranged with respect to the processor 60, and these remote memories can be connected to the AP through a network. Examples of the above network include but are not limited to the Internet, an intranet, a network, a mobile communication network and a combination thereof.

[0210] The communication interface 62 can be configured to receive and send data.

[0211] The embodiment of the present application further provides a computer readable storage medium, and the computer readable storage medium stores a computer program. The computer program is executed by a processor to implement the method provided by any of the embodiments of the present application.

[0212] The computer storage medium of the embodiment of the present application can adopt any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. The computer readable storage medium can be, but is not limited to, for example, an electrical, a magnetic, an optical, an electromagnetic, an infrared, or a semiconductor system, device or apparatus, or any combination of the above. The computer readable storage medium includes, but is not limited to, for example, a wired communication network, a portable computer diskette, a hard disk, a Random Access Memory (RAM), a Read-Only Memory (ROM), an electrically erasable programmable Read-Only Memory (EEPROM), a flash memory, an optical fiber, a Compact Disc Read-Only Memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, device or apparatus.

[0213] The computer readable signal medium can include a data signal conveyed in a baseband or as part of a carrier wave transporting the computer readable program code. The data signal can be transmitted by any medium of transmission, including, but not limited to, wireless, wired, optical fiber cable, Radio Frequency (RF), and the like, or any suitable combination of the above. The computer readable signal medium can also be any computer readable medium that can send, receive, or transfer a program for use by or in connection with an instruction execution system, apparatus, or device.

[0214] The program code contained in the computer readable medium can be transmitted by any suitable medium, including, but not limited to, wireless, wire, optical cable, Radio Frequency (RF), and the like, or any suitable combination of the above.

[0215] Computer program code for carrying out operations of the present disclosure can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++, Ruby, Go, or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0216] The embodiments of the present application also provide a computer program product, comprising a computer program which, when executed by a processor, implements the method provided by any of the embodiments of the present application.

[0217] The computer program product, in its implementation, can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, Smalltalk, C++, or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0218] Those skilled in the art will appreciate that the term user terminal encompasses any appropriate type of wireless user equipment, such as a mobile phone, a portable data processing apparatus, a portable web browser, or a vehicle mounted mobile station.

[0219] In general, the various embodiments of the application can be implemented in hardware or special purpose circuits, software, logic or any combination thereof. For example, some aspects can be implemented in hardware, while other aspects can be implemented in

[0220] Embodiments of the application can be implemented by computer program instructions on a mobile device's data processor, for example in the processor entity, or by hardware, or by a combination of software and hardware. Computer program instructions can be in the form of assemblies, Instruction Set Architecture (ISA), machine, machine-related, microcode, firmware, state-setting data, or source code or object code written in any combination of one or more programming languages, to name a few.

[0221] Any flowchart of the figures herein can represent program steps, or can represent interconnected logic circuits, modules, and functions, or can represent a combination of program steps and logic circuits, modules, and functions. The computer program can be stored on a memory. The memory can be of any type suitable to the local technical environment and can be implemented using any suitable data storage technology, such as, but not limited to, random access memory (RAM), read only memory (ROM), optical storage devices, and systems such as digital versatile disc (DVD) or CD-ROM, and the like. The computer readable media can include non-transitory storage media. The data processor can be of any type suitable to the local technical environment, and can include, but is not limited to, a general purpose computer, a special purpose computer, a microprocessor, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), and a processor based on multi-core processor architecture, to name a few.

Claims

1. A method for synchronizing configuration information, applied to a first communication node, comprising: in response to determining that second identification information of a second communication node is verified, and determining that first identification information of the first communication node is verified by the second communication node, sending first synchronization request information to the second communication node, the first synchronization request information comprising configuration information of the first communication node, or receiving second synchronization request information sent by the second communication node, the second synchronization request information comprising configuration information of the second communication node. 2.The method of claim 1, further comprising: receiving a first information frame sent by the second communication node, the first information frame comprising the second identification information and configuration capability selection information; sending a second information frame to the second communication node, the second information frame comprising at least one of the first identification information and first indication information, the first indication information indicating whether the second identification information is verified by the first communication node.

3. The method of Claim 2, wherein, Before receiving the first information frame sent by the second communication node, further comprising: sending a third information frame to the second communication node, the third information frame comprising configuration capability set information of the first communication node; receiving a fourth information frame sent by the second communication node, the fourth information frame comprising configuration capability set information of the second communication node.

4. The method of Claim 3, wherein, The configuration capability set information comprises at least one of the following: verification identification information of an online verification mode, verification identification information of an offline verification mode, encryption identification information of a symmetric key encryption mode, encryption identification information of an asymmetric key encryption mode, and multi-access point (MAP) capability set information. 5.The method of claim 1, further comprising: receiving a fifth information frame sent by the second communication node, the fifth information frame comprising second indication information, the second indication information indicating whether the first identification information is verified by the second communication node.

6. The method of Claim 1, wherein, After receiving the second synchronization request information sent by the second communication node, further comprising: synchronizing configuration information of the second communication node.

7. The method of Claim 1, wherein, The second identification information comprises an identity of the second communication node, and the first identification information comprises an identity of the first communication node; or The second identification information comprises an encrypted identity of the second communication node, and the first identification information comprises an encrypted identity of the first communication node.

8. The method of Claim 2, wherein, in response to determining that the second identification information comprises an encrypted identity of the second communication node, and the first identification information comprises an encrypted identity of the first communication node; After receiving the first information frame sent by the second communication node, further comprising: decrypting the second identification information using an encryption mode indicated by the configuration capability selection information to obtain the identity of the second communication node; Before sending the second information frame to the second communication node, further comprising: encrypting the identity of the first communication node using an encryption mode indicated by the configuration capability selection information to obtain the first identification information.

9. The method of Claim 8, wherein, in response to determining that the encryption mode indicated by the configuration capability selection information is a symmetric key encryption mode, the encryption and decryption key of the first communication node is a pairwise transient key (PTK), and the PTK is generated based on a first public key of the first communication node and a second public key of the second communication node; in response to determining that the encryption mode indicated by the configuration capability selection information is an asymmetric key encryption mode, the encryption key of the first communication node is the second public key of the second communication node, and the decryption key is a first private key of the first communication node.

10. The method of Claim 3, wherein, The third information frame further includes the first public key of the first communication node, and the fourth information frame further includes the second public key of the second communication node.

11. The method of Claim 9, wherein, The first public key and the second public key are a string or determined according to an X-point coordinate on an elliptic curve and a specific finite cyclic group.

12. The method of Claim 7, wherein, The identification of the communication node includes at least one of the following: device identifier information, padding field information, check information, time information, and random information.

13. The method of Claim 1, wherein, In response to determining that the first communication node and the second communication node are multi-link devices, the configuration information of the communication node is configuration information corresponding to at least one link.

14. The method of Claim 1, wherein, The configuration information of the communication node includes at least one of the following: an access point multi-link device (AP MLD) address, a basic service set identifier (BSSID), a service set identifier (SSID), media access control (MAC) address information, key information, operating channel information, a set of MAP capabilities, BSSID information, robust security network element (RSNE) information, and extended robust security network element (RSNXE) information.

15. A configuration information synchronization method applied to a second communication node, comprising: in response to determining that second identification information of the second communication node is verified by first identification information of a first communication node, and the first identification information is verified, receiving first synchronization request information sent by the first communication node, the first synchronization request information including configuration information of the first communication node, or sending second synchronization request information to the first communication node, the second synchronization request information including configuration information of the second communication node.

16. The configuration information synchronization method of claim 15, further comprising: sending a first information frame to the first communication node, the first information frame including the second identification information and configuration capability selection information; receiving a second information frame sent by the first communication node, the second information frame including at least one of the first identification information and first indication information, the first indication information being used to indicate whether the second identification information is verified by the first communication node.

17. The method of synchronizing configuration information according to claim 16, wherein, Before sending the first information frame to the first communication node, further comprising: receiving a third information frame sent by the first communication node, the third information frame including a set of configuration capabilities of the first communication node; sending a fourth information frame to the first communication node, the fourth information frame including a set of configuration capabilities of the second communication node.

18. The configuration information synchronization method of claim 15, further comprising: sending a fifth information frame to the first communication node, the fifth information frame comprising second indication information, the second indication information being used to indicate whether the first identification information is verified by the second communication node.

19. The method of Claim 15, wherein, after receiving the first synchronization request information sent by the first communication node, further comprising: synchronizing configuration information of the first communication node.

20. The method of Claim 16, wherein, in response to determining that the second identification information comprises an encrypted identification of the second communication node, and the first identification information comprises an encrypted identification of the first communication node; before sending the first information frame to the first communication node, further comprising: encrypting the identification of the second communication node by using an encryption mode indicated by the configuration capability selection information to obtain the second identification information; after receiving the second information frame sent by the first communication node, further comprising: decrypting the first identification information by using the encryption mode indicated by the configuration capability selection information to obtain the identification of the first communication node.

21. The method of synchronizing configuration information according to claim 20, wherein, in response to determining that the encryption mode indicated by the configuration capability selection information is a symmetric key encryption mode, a key used by the second communication node for encryption and decryption is a pairwise transmission key (PTK), and the PTK is generated based on a first public key of the first communication node and a second public key of the second communication node; in response to determining that the encryption mode indicated by the configuration capability selection information is an asymmetric key encryption mode, a key used by the second communication node for encryption is the first public key of the first communication node, and a key used by the second communication node for decryption is a second private key of the second communication node.

22. The method of synchronizing configuration information according to claim 17, wherein, the third information frame further comprises the first public key of the first communication node, and the fourth information frame further comprises the second public key of the second communication node.

23. A communication node, comprising: a processor; the processor is configured to implement the synchronization method of the configuration information according to any one of claims 1-22 when executing the computer program. 24.A computer readable storage medium storing a computer program, the computer program being executed by a processor to implement the synchronization method of the configuration information according to any one of claims 1-22.

Citation Information

Patent Citations

  • Configuration information synchronizing method and device

    CN106341279A

  • Access point configuration method, networking system, access point and storage medium

    CN111147269A

  • Synchronization in access point (AP) coordination

    US20200137702A1

  • Access point network synchronization

    WO2024159474A1