Information processing method, first access point, station, second access point, storage medium, and program product
Patent Information
- Application Number
- PCT/CN2026/074104
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-24
- Filing Date
- 2026-01-22
- Publication Date
- 2026-08-27
Smart Images

Figure CN2026074104_27082026_PF_FP_ABST
Abstract
Description
Information processing methods, first access point, site, second access point, storage medium and program products Technical Field
[0001] This application relates to the field of communication technology, such as information processing methods, first access points, sites, second access points, storage media, and program products. Background Technology
[0002] In wireless communication systems, stations (STAs) connect wirelessly to access points. Third-party devices can sniff out unencrypted information transmitted from STAs to the access point, posing a risk of information leakage.
[0003] Currently, the STA and its associated access points use unicast for encrypted transmission to prevent sniffing attacks from third-party devices. However, how to achieve encrypted protection of information between the STA and non-associated access points is a problem that urgently needs to be solved. Summary of the Invention
[0004] This application provides an information processing method, a first access point, a site, a second access point, a storage medium, and a program product, which realizes encrypted protection of information between STA and non-associated access points.
[0005] In a first aspect, embodiments of this application provide an information processing method applied to a first access point, the method comprising:
[0006] Transmit a first information frame to the site, the first information frame including key information;
[0007] Transmit a second information frame to the second access point, the second information frame including the key information;
[0008] Transmit frame sequence number information to the site and the second access point;
[0009] Obtain encrypted information, which includes information encrypted based on the key information and the frame sequence number information of the multicast frame;
[0010] The encrypted information is decrypted based on the key information and the frame sequence number information to obtain the multicast frame.
[0011] Secondly, embodiments of this application provide an information processing method applied to a website, the method comprising:
[0012] Obtain a first information frame, the first information frame including key information;
[0013] Obtain frame sequence number information;
[0014] The multicast frame is encrypted based on the key information and the frame sequence number information to obtain encrypted information;
[0015] Transmit the encrypted information.
[0016] Thirdly, embodiments of this application provide an information processing method applied to a second access point, the method comprising:
[0017] Obtain a second information frame, the second information frame including key information;
[0018] Obtain frame sequence number information;
[0019] Obtain encrypted information, which includes information encrypted based on the key information and the frame sequence number information of the multicast frame;
[0020] The encrypted information is decrypted based on the key information and the frame sequence number information to obtain the multicast frame.
[0021] Fourthly, embodiments of this application provide a first access point, including:
[0022] One or more processors;
[0023] Storage device for storing one or more programs;
[0024] When the one or more programs are executed by the one or more processors, the one or more processors implement the method provided in the first aspect of the embodiments of this application.
[0025] Fifthly, embodiments of this application provide a site, including:
[0026] One or more processors;
[0027] Storage device for storing one or more programs;
[0028] When the one or more programs are executed by the one or more processors, the one or more processors implement the method provided in the second aspect of the embodiments of this application.
[0029] Sixthly, embodiments of this application provide a second access point, including:
[0030] One or more processors;
[0031] Storage device for storing one or more programs;
[0032] When the one or more programs are executed by the one or more processors, the one or more processors implement the method provided in the third aspect of the embodiments of this application.
[0033] In a seventh aspect, embodiments of this application provide a storage medium, characterized in that the storage medium stores a computer program, which, when executed by a processor, implements the method provided in embodiments of this application.
[0034] Eighthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method provided according to embodiments of this application.
[0035] Further details regarding the above embodiments and other aspects of this application, as well as their implementations, are provided in the accompanying drawings, detailed description, and claims. Attached Figure Description
[0036] Figure 1 is a flowchart illustrating an information processing method provided in an embodiment of this application;
[0037] Figure 2 is a MAP cooperative network topology diagram provided in an embodiment of this application;
[0038] Figure 3 is a schematic diagram of a sequential channel detection process provided in an embodiment of this application;
[0039] Figure 4 is a schematic diagram of a joint channel detection process provided in an embodiment of this application;
[0040] Figure 5 is a schematic diagram of a multi-link connection establishment process provided in an embodiment of this application;
[0041] Figure 6 is a flowchart illustrating another information processing method provided in an embodiment of this application;
[0042] Figure 7 is a flowchart illustrating another information processing method provided in an embodiment of this application;
[0043] Figure 8 is a schematic diagram of an RSNXE field containing element ID, field length, and RSNXE capability set field provided in this application;
[0044] Figure 9 is a schematic diagram of OBSS authentication transmission and OBSS channel information detection provided in an embodiment of this application;
[0045] Figure 10 is a schematic diagram of joint positioning provided in an embodiment of this application;
[0046] Figure 11 is a schematic diagram of the structure of an information processing device provided in an embodiment of this application;
[0047] Figure 12 is a schematic diagram of the structure of another information processing device provided in an embodiment of this application;
[0048] Figure 13 is a schematic diagram of another information processing device provided in an embodiment of this application;
[0049] Figure 14 is a schematic diagram of the structure of a first access point provided in an embodiment of this application;
[0050] Figure 15 is a schematic diagram of the structure of a site provided in an embodiment of this application;
[0051] Figure 16 is a schematic diagram of the structure of a second access point provided in an embodiment of this application. Detailed Implementation
[0052] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in detail below with reference to the accompanying drawings. It should be noted that, unless otherwise specified, the embodiments and features described in these embodiments can be arbitrarily combined with each other.
[0053] The steps illustrated in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases the steps shown or described may be performed in a different order than that presented here.
[0054] In this application, the terms "first," "second," etc., are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence.
[0055] In one exemplary embodiment, FIG1 is a schematic flowchart of an information processing method provided in an embodiment of this application. This method can be applied to situations where information encryption is implemented between a site and a non-associated access point. This method can be executed by an information processing device, which can be implemented by software and / or hardware and integrated on a first access point. In this application, the communication system may include a first access point, a second access point, and a site. The first access point and the second access point can be different access points. The first access point may be associated with a site or may not be associated with a site, such as the first access point and the site being in the same basic service set or in different basic service sets. The second access point may not be associated with a site.
[0056] This application does not limit the number of the first access point, the second access point, and the site. The number of the first access point, the second access point, and the site can all be at least one.
[0057] The first access point, the second access point, and the site can exchange key information. The method of exchange is not limited here; for example, the first access point can send key information to both the second access point and the site. Alternatively, the site can send key information to both the first and second access points. Yet another example is the site sending key information to the first access point. The first access point can then send key information to the second access point.
[0058] Key information may be transmitted separately to the second access point and the site within a single information frame. Alternatively, key information may be transmitted separately to the second access point and the site in different information frames.
[0059] Building upon the above implementation, frame sequence number information can also be sent along with the key information. Alternatively, the frame sequence number information can be sent in a separate information frame. The interaction method for the frame sequence number information can be the same as that for the key information, and will not be elaborated here.
[0060] The key information can be considered as the information used for encryption and decryption during communication between the access point and the site. The frame sequence number information can be related to the frame sequence number; its specific content is not limited here. For example, it can be the value of the frame sequence number and / or the range of values for the frame sequence number.
[0061] The following describes the technologies involved in this application:
[0062] Fiber-to-the-room (FTTR) technology connects wireless router access points (APs) in different rooms or locations in homes or small and medium-sized enterprises using fiber optic cables, thereby providing high-bandwidth and high-reliability connections between multiple APs. It can utilize point-to-multipoint optical distribution networks to achieve connections between master control APs and slave APs.
[0063] Figure 2 is a MAP cooperative network topology diagram provided in an embodiment of this application. Referring to Figure 2, in the Multi-AP Coordination (MAPC) scenario, STA1 is wirelessly connected to AP1, and Basic Service Set (BSS) 1 includes AP1 and STA1; similarly, STA2 is wirelessly connected to AP2; BSS2 includes AP2 and STA2.
[0064] Before AP1 and AP2 perform Coordination Beamforming (Co-BF) data transmission, the channel information of the STA needs to be obtained by the associated AP and the overlapping base service set (OBSS) AP.
[0065] Figure 3 is a schematic diagram of a sequential channel sounding process provided in an embodiment of this application. During the sequential channel sounding process, AP1 / AP2 can directly obtain the channel state information (CSI) fed back by its associated STA1 / STA2; AP1 / AP2 can also obtain the CSI information fed back by unassociated STA2 / STA1 through sniffing mode (overhearing mode).
[0066] Figure 4 is a schematic diagram of a joint channel sounding process provided in an embodiment of this application. In a joint sounding process, AP1 sends a Null Data PPDU announcement (NDPA) frame to trigger the channel sounding process. AP1 and AP2 jointly send Null Data PPDU (NDP) messages, and AP1 sends a beamforming report poll (BFRP). STA1 feeds back channel information to AP1 based on the joint NDP frame. At the same time, AP2 obtains the channel information sent by STA1 through sniffing mode.
[0067] Multi-link operation (MLO) technology allows multiple-link devices (MLDs), including network devices (AP MLDs) and terminal devices (non-AP MLDs), to transmit data simultaneously on multiple links, thereby improving data transmission throughput and reducing latency.
[0068] After the AP and non-AP perform a four-way handshake on a link, they generate a pairwise transient key (PTK) at the MLO level and a group temporary key (GTK) at the link level. These keys are used to encrypt and decrypt unicast and multicast frames, respectively, ensuring the security of data transmission.
[0069] Figure 5 is a schematic diagram of a multi-link connection establishment process provided in an embodiment of this application. Referring to Figure 5, both the AP MLD and the non-AP MLD include three links operating at 2.4GHz, 5GHz and 6GHz. The AP MLD and the non-AP MLD complete the authentication, connection and four-way handshake process on the 2.4GHz link. After the multi-link connection is established, data can be transmitted on the three links.
[0070] To enhance the data encryption and authentication performance of Wireless Local Area Networks (WLANs), the concept of Robust Security Network (RSN) was defined, and various improvements were made to address the shortcomings of the Wired Equivalent Privacy (WEP) encryption mechanism, such as encryption technology and security authentication functions.
[0071] The Robust Secure Network Element (RSN element, RSNE) indicates the elements included in an RSN and related to key suites and RSN capabilities. The RSN Extension Element (RSNXE) indicates additional key suites and RSN capability sets information for an RSN.
[0072] Because there is a certain probability of packet loss and retransmission during wireless transmission, the order of data packets received by the receiving end is not consistent with the order in which the data packets were sent. However, in order to ensure that the data packets are received in order, a cumulatively increasing sequence number (SN) value is set in each message. The receiving end buffers and sorts the received messages according to their SN values and sends them to the upper-layer protocol stack.
[0073] To prevent fourth-party replay attacks, the protocol stipulates that each wireless packet contains a sequentially increasing packet number (PN) value. When two packets with the same PN are received, they are considered to be fourth-party replay attack packets and can be discarded directly.
[0074] To distinguish between the sequence numbers of multicast management frames and beacon frames, the protocol additionally defines the Integrity Group Temporal Key (IGTK) frame sequence number (IGTK PN, IPN) and the Broadcast Integrity Group Temporal Key (BIGTK) frame number (BIGTK PN, BIPN) for beacon frames, which are increased and protected in the same way as PN.
[0075] In scenarios where the STA (Station) feeds back CSI (Content Security Information), third-party devices can sniff out the unencrypted CSI information fed back by the STA, thereby obtaining information about changes in objects between the STA and the AP (Access Point), posing a risk of privacy leakage.
[0076] To address this issue, the CSI between the STA and its associated AP is encrypted using unicast, preventing sniffing attacks from third parties. However, there is currently no way to solve the problem of CSI encryption protection between the STA and non-associated APs.
[0077] Based on this, this application provides an information processing method, as shown in Figure 1, which includes the following operations:
[0078] S110. Transmit a first information frame to the station, the first information frame including key information.
[0079] In this embodiment, the first access point can transmit key information to the site through the first information frame. The first information frame is not limited here and can be determined based on the application scenario of the first access point and the site.
[0080] The application scenario can be at least one of the following:
[0081] Channel detection process; distance measurement process; multi-point positioning process; process of the station transmitting the encrypted information to the first access point; process of the station transmitting the encrypted information to the second access point; process of the station establishing an association with the first access point; key update process.
[0082] This section does not specify which particular frame in a particular application scenario the first information frame should be, as long as it occurs before the station transmits information. For example, the first information frame could be one of the following:
[0083] The third step message of the Extended Authentication Protocol handshake (EAPOL-3); the Association Response frame; and the second frame in the Preassociation Security Negotiation (PASN) process.
[0084] S120. Transmit a second information frame to the second access point, the second information frame including the key information.
[0085] The first access point can transmit key information to the second access point through the second information frame. The second information frame is not limited here and can be determined based on the application scenario. It is not limited to which specific frame in the application scenario the second information frame should be, as long as it is transmitted before the second access point decrypts the encrypted information.
[0086] Encrypted information can be considered as information obtained by a site encrypting a multicast frame using key information. A multicast frame can be a type of frame data that is sent simultaneously to multiple targets in a network. For example, it could be a CSI (Content Instance Sequence).
[0087] The second information frame can be a negotiation request frame. The first and second information frames can be the same frame or different frames.
[0088] When the first information frame and the second information frame are the same frame, this embodiment can transmit the first information frame to the station and the second access point respectively to realize the transmission of key information.
[0089] S130, Transmit frame sequence number information to the station and the second access point.
[0090] This operation can transmit frame sequence number information to the site and the second access point.
[0091] Frame sequence number information can be included in the third information frame, which can be different from the first and second information frames. In one example, the first access point transmits the third information frame to the station and the second access point respectively, and the third information frame includes frame sequence number information.
[0092] Frame sequence number information can also be included in the first and second information frames. For example, when a first access point transmits a first information frame to a station, the first information frame includes key information and frame sequence number information. When a first access point transmits a second information frame to a second access point, the second information frame includes key information and frame sequence number information.
[0093] S140. Obtain encrypted information, the encrypted information including information after encrypting the multicast frame based on the key information and the frame sequence number information.
[0094] The key information and frame sequence number information can be used by the site to encrypt multicast frames. After obtaining the frame sequence number and key information, the site can encrypt the multicast frame to obtain encrypted information. The site can then transmit the encrypted information to the first access point and the second access point.
[0095] The first access point can obtain encrypted information from the site in order to obtain the multicast frames transmitted by the site.
[0096] S150. Decrypt the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame.
[0097] After the first access point obtains the encrypted information, it can decrypt the encrypted information based on the key information and frame sequence number information to obtain the multicast frame. The application of the key information and frame sequence number information in the decryption process is not limited here; their specific application can be associated with the decryption algorithm.
[0098] The information processing method provided in this application transmits key information and frame sequence number information to a site and a second access point, respectively. The site encrypts multicast frames based on the key information and frame sequence number information to obtain encrypted information. The second access point decrypts the encrypted information based on the key information and frame sequence number information to obtain the multicast frame. After obtaining the encrypted information, the first access point can decrypt it based on the key information and frame sequence number information to obtain the multicast frame. The first access point and the site may or may not be associated, and the second access point and the site may or may not be associated. This scheme achieves security for the site's transmission of multicast frames.
[0099] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0100] In one embodiment, the information processing method further includes:
[0101] A fourth information frame is transmitted to the site, the fourth information frame including updated key information;
[0102] A fifth information frame is transmitted to the second access point, the fifth information frame including updated key information.
[0103] If the key information is updated, the first access point can transmit the updated key information to the station via the fourth information frame. The first access point can also transmit the updated key information to the second access point via the fifth information frame.
[0104] The fourth and fifth information frames can be the same information frame or different information frames. The types of the fourth and fifth information frames are not limited here; they can be determined based on the application scenario.
[0105] In this application, the first access point, the second access point, and the station can exchange key information and updated key information. For example, the first access point transmits key information and updated key information to the second access point. The station transmits key information and updated key information to both the first and second access points. The station transmits key information and updated key information to the first access point. The first access point transmits key information and updated key information to the second access point.
[0106] In one embodiment, the first access point is one of the following:
[0107] Single-link access point; multi-link access point; non-parallel multi-link access point.
[0108] In wireless networks, a single-link access point can refer to an access point that can only transmit data through one radio frequency link at a time.
[0109] A multi-link access point is an access point that can transmit data simultaneously through multiple links.
[0110] A non-coordinated multi-link access point can be a special type of multi-link access point where the multiple access points are not physically located together, but may be distributed in different locations.
[0111] In one embodiment, the site includes one of the following:
[0112] Single-link site; multi-link site.
[0113] A single-link site is a site where only one link is used for data transmission at any given time. A multi-link site is a site that transmits data simultaneously through multiple links.
[0114] In one embodiment, transmitting the first information frame to the station includes:
[0115] During the association process with the site, a first information frame is transmitted to the site to obtain key information during the association process.
[0116] In one embodiment, transmitting the second information frame to the second access point includes:
[0117] The second information frame is transmitted to the second access point in one of the following processes:
[0118] Before establishing a connection with the second access point, AP1 (i.e., the first access point) sends the GTK1 information to AP2 (i.e., the second access point).
[0119] During the parameter negotiation process with the second access point, that is, during the parameter negotiation process between AP1 and AP2, AP1 sends the GTK1 information to AP2;
[0120] During the Authenticated Mesh Peering Exchange (AMPE) with the second access point, i.e., during the key negotiation between AP1 and AP2, AP1 sends the GTK1 information to AP2.
[0121] In one embodiment, the information processing method is applied to one of the following processes:
[0122] Channel detection process;
[0123] Distance measurement process;
[0124] Multi-point positioning process;
[0125] The process by which the site transmits the encrypted information to the first access point;
[0126] The process of the site transmitting the encrypted information to the second access point is, for example, the process of the site sending encrypted multicast frames to a non-associated access point, i.e., the process of encrypting information.
[0127] When the first access point is associated with the site, the process of the site transmitting encrypted information to the first access point can be considered as the site transmitting encrypted information to the associated access point. When the first access point is not associated with the site, the process of the site transmitting encrypted information to the first access point can be considered as the site transmitting encrypted information to the unassociated access point.
[0128] In one embodiment, the third information frame includes one of the following:
[0129] Initialize the control frame;
[0130] Empty data packet announcement frame;
[0131] Beamforming report polling.
[0132] In one embodiment, the frame sequence number information is included in the user information field or public information field of the third information frame.
[0133] Frame sequence information can be included in the user information field and / or public information field of the third information frame. The user information field can be considered as an area used to store information related to the user. The public information field can be considered as an area used to store common information, such as general information.
[0134] In one embodiment, the first information frame further includes access point identification information of the second access point, which is associated with the key information, and the key information is used by the second access point in the process of receiving the encrypted information.
[0135] Access point identification information can be considered as information used to identify access points, i.e., the identification information of the access point. Access point identification information is associated with key information and can be used to indicate that the key information is only used in the process of receiving encrypted information involving a second access point. The second access point receives the key information and decrypts the encrypted information based on the key information.
[0136] In one embodiment, there are multiple second access points, and the key information corresponding to different second access points may be the same or different.
[0137] Second access points corresponding to the same key information can be grouped together with the key information and all corresponding second access points in the second information frame. Different key information and corresponding second access points form different groups and are included in the second information frame.
[0138] In one embodiment, the second information frame further includes one of the following:
[0139] The site identification information and the key information of the site, wherein the key information is used for encryption of the multicast frames of the site;
[0140] The site information and the frame sequence number information of the site, wherein the frame sequence number information is used by the site to send the encrypted information;
[0141] The site information, the key information, and the frame sequence number information of the site are used for the encryption of the multicast frames of the site.
[0142] Site identification information can be considered as information that identifies a site, i.e., the site's identifier. The second information frame may include site identification information and key information, used to instruct the site to encrypt multicast frames using the key information. The key information may be sent along with the encrypted information.
[0143] The second information frame includes site identification information and frame sequence number information, indicating that the frame sequence number information is used by the site to encrypt multicast frames. The first access point sends the key information, frame sequence number information, and site identification information to the site, and the site uses the key information and frame sequence number information for encryption. The frame sequence number information used by the site for encryption can also be sent along with the encryption information.
[0144] The second information frame may include site information, key information, and frame sequence number information. It is used to instruct the site to encrypt the multicast frame using the key information and frame sequence number information. The encrypted information may also be transmitted along with the key information and frame sequence number information during the transmission process.
[0145] In one embodiment, the fields containing the key information include one or more of the following:
[0146] The identification information of the field is used to uniquely identify the field;
[0147] The length information of the field is used to indicate the length of the field;
[0148] The identification information of the key information is used to uniquely identify the key information;
[0149] The length information of the key information is used to indicate the length of the key information;
[0150] The frame sequence number information;
[0151] The key information.
[0152] In one embodiment, transmitting frame sequence number information to the station includes:
[0153] Different frame sequence number information is allocated and transmitted during different channel probes.
[0154] The first access point can assign and transmit different frame sequence numbers during different channel probing processes. For example, before each time the STA sends encrypted multicast data, the AP assigns and transmits different PN value information to it.
[0155] In one embodiment, the information processing method further includes:
[0156] The encrypted information is verified based on one or more of the key information and the frame sequence number information.
[0157] One or more information fields from the key information and the frame sequence number information are used to generate a MIC (Multi-Intent Messaging) segment, which is appended to the end of the encrypted multicast frame to form encrypted information for the integrity of the multicast frame. For example, the MIC field is added to the end of the encrypted multicast frame. During decryption, the integrity of the MIC field is verified using the key information.
[0158] In one embodiment, the encryption information further includes frame sequence number information used to encrypt the multicast frame.
[0159] The encrypted information transmitted by the site may also include frame sequence number information. This allows the receiver to retrieve the frame sequence number from the encrypted information and decrypt it.
[0160] In one embodiment, the third information frame further includes indication information, which instructs the site to return the encrypted information in one of the following ways:
[0161] Unicast method;
[0162] Multicast mode;
[0163] Unicast encryption method;
[0164] Multicast encryption method;
[0165] Broadcast method;
[0166] Broadcast encryption method.
[0167] If the third information frame indicates that the frame transmitted by the station does not need to be encrypted, then the key information in the first information frame can be omitted.
[0168] The third information frame can be an Initial Control Frame (ICF), NDPA, or BFRP.
[0169] In one embodiment, the first access point establishes an association with the site; or the first access point does not establish an association with the site.
[0170] The relationship is not limited here. If they belong to the same BSS, they are considered to have a relationship. If they do not belong to the same BSS, they are considered not to have a relationship.
[0171] In one embodiment, the step of decrypting the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame includes:
[0172] The frame sequence number information is transformed in association with the station to obtain the transformed frame sequence number information;
[0173] The encrypted information is decrypted based on the transformed frame sequence number information and the key information to obtain the multicast frame.
[0174] After the first access point transmits the frame sequence number information to the station, the station can transform the frame sequence number information to encrypt multicast frames using the transformed frame sequence number. Therefore, the first access point can perform the same transformation method as the station to transform the frame sequence number information in order to decrypt the encrypted information.
[0175] The transformation method is not limited here. It can be adding the frame sequence number information to a set value, or adding the value corresponding to the order in which the station appears in the information frame containing the frame sequence information.
[0176] In one example, when the first access point schedules two STAs simultaneously, the first user info field in the ICF frame stores information about STA1, and the second user info field stores information about STA2. Each STA then performs corresponding transformations based on its position in the frame; for example, STA1 directly uses the PN value, while STA2 uses the PN+1 value.
[0177] In this embodiment, the frame sequence number information transmitted by the first access point can be considered as the reference frame sequence number information, also known as the frame sequence number reference value or reference frame sequence number information. The station, the first access point, and the second access point can be transformed based on this frame sequence number information.
[0178] In one embodiment, transmitting frame sequence number information to the station includes:
[0179] The reference frame sequence number information and the value range of the frame sequence number information are transmitted to the station, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range.
[0180] In this application, the frame sequence number information transmitted by the first access point can be frame sequence number information directly used by the station, or it can be frame sequence number information used as a reference for the station to perform transformations, so as to obtain the required frame sequence number information.
[0181] In this embodiment, the frame sequence number information transmitted to the station can be reference frame sequence number information for the station to use for transformation. Additionally, a range of frame sequence number values can also be transmitted. The range of frame sequence number values can be considered as representing the range of frame sequence number information that can be used during the frame sequence number information transformation process. The station can transform the frame sequence number information within this range. Explicit representation can be the direct transmission of the frame sequence number information value range. Implicit representation can be achieved by further determining the frame sequence number information value range.
[0182] In one example, the displayed representation can take values in the range [PN1, PN1+x]. x can be a positive integer.
[0183] In one example, the implicit representation range can be indicated by only a subset of bits that indicate the reference sequence number information. The unindicated portions of the reference sequence number information can take any value at the station. For example, the lower i bits can be set for the frame sequence number information. The higher j bits can be determined by the station. There are no restrictions on the bits set by the first access point here. i and j can be positive integers.
[0184] When setting frame sequence number information, the site can set the unset bits sequentially from low to high or from high to low. The values used for each setting are not limited here; for example, it can start from 0.
[0185] In one embodiment, the information processing method further includes:
[0186] Before the station uses the frame sequence number information with the largest value in the frame sequence number information range, it transmits the updated reference frame sequence number information and the updated frame sequence number information value range.
[0187] There is no limitation on when the site uses the largest frame sequence number information. It can be determined based on the number of interactions between the first access point and the site, such as the number of times encrypted information is exchanged.
[0188] In this embodiment, the first access point actively transmits the updated reference frame sequence number information and the updated frame sequence number information value range to the site.
[0189] In this application, the first access point can also transmit reference frame sequence number information and the value range of the frame sequence number information to the second access point. The first access point can also transmit updated reference frame sequence number information and the updated value range of the frame sequence number information to the second access point.
[0190] During the process of decrypting encrypted information, the second access point determines the frame sequence number information used by the site based on the base frame sequence number information and the range of frame sequence number information values, and uses it for decryption.
[0191] In one embodiment, it also includes:
[0192] Obtain the request information transmitted by the site;
[0193] Transmit response information, which includes updated reference frame sequence number information and the value range of the updated frame sequence number information.
[0194] The request information can be considered as information transmitted by the site to the first access point to request the transmission of updated reference frame sequence number information and the range of values for the updated frame sequence number information. After receiving the request information, the first access point can transmit the updated reference frame sequence number information and the range of values for the updated frame sequence number information back to the site through response information. The response information can be considered as information responding to the request information.
[0195] In one embodiment, the frame sequence number information is contained in a first information frame and a second information frame, or the frame sequence number information is contained in a third information frame.
[0196] In this embodiment, frame sequence number information and key information can be transmitted simultaneously using the first and second information frames. Alternatively, the frame sequence number information can be transmitted separately using the third information frame.
[0197] In one exemplary embodiment, this application also provides an information processing method. Figure 6 is a flowchart illustrating another information processing method provided in an embodiment of this application. This method can be applied to the situation of encrypting information between a site and unrelated access points. This method can be executed by the information processing device provided in this application. The information processing device can be implemented by software and / or hardware and integrated on the site. Details not covered in this embodiment can be found in the above embodiments and will not be elaborated upon here.
[0198] As shown in Figure 6, the information processing method provided in this application includes the following operations:
[0199] S610. Obtain a first information frame, wherein the first information frame includes key information.
[0200] This operation can acquire the first information frame transmitted by the first access point.
[0201] S620, Obtain frame sequence number information.
[0202] This operation can obtain the frame sequence number information transmitted by the first access point through the first information frame or the third information frame. This operation can also obtain the frame sequence number locally from the site.
[0203] S630. Encrypt the multicast frame based on the key information and the frame sequence number information to obtain encrypted information.
[0204] After obtaining the frame sequence number information, the site can directly encrypt the multicast frame using the site and key information to obtain encrypted information. Alternatively, the frame sequence number information can be transformed, and the multicast frame can be encrypted based on the key information and the transformed frame sequence number information to obtain encrypted information.
[0205] The transformation method is not limited here. For example, the frame sequence number information can be summed with the position of the station in the information frame transmitting the frame sequence number information to obtain the transformed frame sequence number information. Alternatively, the frame sequence number information can be selected from the range of values of the reference frame sequence number information.
[0206] In this application, the first access point may also transmit only the range of frame sequence number information values to the station, so that the station can select frame sequence number information from the range of frame sequence number information values. The station can select different frame sequence number information from the range of frame sequence number information values each time.
[0207] S640, Transmit the encrypted information.
[0208] After obtaining the encrypted information, it can be transmitted to the first access point and the second access point.
[0209] The information processing method provided in this embodiment obtains key information and frame sequence number information, encrypts multicast frames using the key information and frame sequence number information to obtain encrypted information, and transmits the encrypted information to the first access point and the second access point, thereby realizing encrypted transmission of information between the site and the access point and ensuring the security of communication.
[0210] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0211] In one embodiment, the multicast frame is encrypted based on the key information and the frame sequence number information to obtain encrypted information, including:
[0212] Generate a message integrity code based on the key information and the frame sequence number information;
[0213] The message integrity code is appended to the end of the encrypted multicast frame to obtain an encrypted message.
[0214] In this embodiment, a message integrity code can be generated based on key information and frame sequence number information. Then, the message integrity code is added to the end of the encrypted multicast frame to form an encrypted message, thereby ensuring the integrity of the multicast frame.
[0215] In one embodiment, encrypting the multicast frame based on the key information and the frame sequence number information to obtain encrypted information includes:
[0216] The frame sequence number information is transformed to obtain the transformed frame sequence number information;
[0217] The multicast frame is encrypted based on the transformed frame sequence number information and the key information to obtain encrypted information.
[0218] The station can be transformed to obtain the transformed frame sequence information based on the station's order in the information frame containing the frame sequence information.
[0219] The specific method by which key information and frame sequence number information are used to encrypt multicast frames is not limited and can be related to the encryption algorithm.
[0220] In one embodiment, the frame sequence number information is included in the first information frame or the third information frame.
[0221] In one embodiment, the information processing method further includes:
[0222] Transmit request information;
[0223] Obtain response information, which includes updated reference frame sequence number information and the value range of the updated frame sequence number information.
[0224] In one embodiment, obtaining the frame sequence number information includes:
[0225] Obtain the reference frame sequence number information and the value range of the frame sequence number information, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range.
[0226] In one embodiment, the information processing method further includes:
[0227] Obtain the updated baseline frame sequence number information and the range of values for the updated frame sequence number information;
[0228] During each transmission of encrypted information, different frame sequence numbers within the range of the frame sequence number information are used.
[0229] In this embodiment, the frame sequence number information used each time is not limited. The frame sequence number information can be selected from the range of frame sequence number information values in descending order, ascending order, or randomly.
[0230] In one embodiment, obtaining the frame sequence number information includes:
[0231] Different frame sequence number information is obtained during different channel probing processes.
[0232] In one embodiment, the information processing method further includes:
[0233] Obtain the fourth information frame, which includes the updated key information.
[0234] In one embodiment, the first access point is one of the following:
[0235] Single-link access point;
[0236] Multi-link access points;
[0237] Non-co-located multi-link access points.
[0238] In one embodiment, the site includes one of the following:
[0239] Single-link site;
[0240] Multi-link site.
[0241] In one embodiment, obtaining the first information frame includes:
[0242] During the association process with the first access point, the first information frame is acquired.
[0243] In one embodiment, the information processing method is applied to one of the following processes:
[0244] Channel detection process;
[0245] Distance measurement process;
[0246] Multi-point positioning process;
[0247] The process by which the site transmits the encrypted information to the first access point;
[0248] The process of the site transmitting the encrypted information to the second access point.
[0249] In one embodiment, the third information frame includes one of the following:
[0250] Initialize the control frame;
[0251] Empty data packet announcement frame;
[0252] Beamforming report polling.
[0253] In one embodiment, the frame sequence number information is included in the user information field or public information field of the third information frame.
[0254] In one embodiment, the first information frame further includes access point identification information of the second access point, which is associated with the key information, and the key information is used by the second access point in the process of receiving the encrypted information.
[0255] In one embodiment, the second information frame further includes one of the following:
[0256] The site identification information and the key information of the site, wherein the key information is used for encryption of the multicast frames of the site;
[0257] The site information and the frame sequence number information of the site, wherein the frame sequence number information is used by the site to send the encrypted information;
[0258] The site information, the key information, and the frame sequence number information of the site are used for the encryption of the multicast frames of the site.
[0259] In one embodiment, the fields containing the key information include one or more of the following:
[0260] The identification information of the field;
[0261] The length information of the field;
[0262] The identification information of the key information;
[0263] The length information of the key information;
[0264] The frame sequence number information;
[0265] The key information.
[0266] In one embodiment, the encryption information further includes frame sequence number information used to encrypt the multicast frame.
[0267] In one embodiment, the third information frame further includes indication information, which instructs the site to return the encrypted information in one of the following ways:
[0268] Unicast method;
[0269] Multicast mode;
[0270] Unicast encryption method;
[0271] Multicast encryption method;
[0272] Broadcast method;
[0273] Broadcast encryption method.
[0274] In one embodiment, the first access point establishes an association with the site; or the first access point does not establish an association with the site.
[0275] In one embodiment, the information processing method further includes:
[0276] Before the site uses the frame sequence number information with the largest value in the frame sequence number information value range, it obtains the updated baseline frame sequence number information and the updated frame sequence number information value range.
[0277] In one embodiment, the frame sequence number information is contained in a first information frame and a second information frame, or the frame sequence number information is contained in a third information frame.
[0278] In one exemplary embodiment, this application provides an information processing method. Figure 7 is a schematic flowchart of another information processing method provided in an embodiment of this application; this method can be applied to the situation of encrypting information between a site and an unrelated access point. This method can be executed by an information processing device, which can be executed by software and / or hardware, and the information processing device can be integrated on a second access point. Where this embodiment is not detailed in detail, please refer to the above embodiments, which will not be repeated here.
[0279] As shown in Figure 7, the information processing method provided in this application includes the following operations:
[0280] S710. Obtain a second information frame, the second information frame including key information.
[0281] This operation can obtain the second information frame transmitted by the first access point.
[0282] S720, Obtain frame sequence number information.
[0283] This operation can obtain the frame sequence number information transmitted by the first access point through the second or third information frame. This operation can also obtain frame sequence number information from the site.
[0284] S730. Obtain encrypted information, the encrypted information including information after encrypting the multicast frame based on the key information and the frame sequence number information.
[0285] The second access point can obtain encrypted information from the site to obtain the multicast frames transmitted by the site.
[0286] S740. Decrypt the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame.
[0287] After obtaining the encrypted information, the second access point can decrypt it based on the key information and frame sequence number information to obtain the multicast frame. The application of the key information and frame sequence number information in the decryption process is not limited here; their specific application can be associated with the decryption algorithm.
[0288] The information processing method provided in this embodiment obtains key information and frame sequence number information to decrypt encrypted information transmitted by the station to obtain multicast frames. This achieves encrypted transmission of multicast frames between the second access point and the station, ensuring the security of communication between the station and unrelated access points (such as the second access point and / or the first access point).
[0289] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0290] In one embodiment, the information processing method further includes:
[0291] Five information frames are obtained, the fifth information frame including the updated key information.
[0292] In one embodiment, the first access point is one of the following:
[0293] Single-link access point;
[0294] Multi-link access points;
[0295] Non-co-located multi-link access points.
[0296] In one embodiment, the site includes one of the following:
[0297] Single-link site;
[0298] Multi-link site.
[0299] In one embodiment, obtaining the second information frame includes:
[0300] The second information frame is acquired through one of the following processes:
[0301] The security negotiation process before connecting to the first access point;
[0302] During parameter negotiation with the first access point.
[0303] In one embodiment, the information processing method is applied to one of the following processes:
[0304] Channel detection process;
[0305] Distance measurement process;
[0306] Multi-point positioning process;
[0307] The process by which the site transmits the encrypted information to the first access point;
[0308] The process of the site transmitting the encrypted information to the second access point.
[0309] In one embodiment, the third information frame includes one of the following:
[0310] Initialize the control frame;
[0311] Empty data packet announcement frame;
[0312] Beamforming report polling.
[0313] In one embodiment, the frame sequence number information is included in the user information field or public information field of the third information frame.
[0314] In one embodiment, the first information frame further includes access point identification information of the second access point, which is associated with the key information, and the key information is used by the second access point in the process of receiving the encrypted information.
[0315] In one embodiment, there are multiple second access points, and the key information corresponding to different second access points may be the same or different.
[0316] In one embodiment, the second information frame further includes one of the following:
[0317] The site identification information and the key information of the site, wherein the key information is used for encryption of the multicast frames of the site;
[0318] The site information and the frame sequence number information of the site, wherein the frame sequence number information is used by the site to send the encrypted information;
[0319] The site information, the key information, and the frame sequence number information of the site are used for the encryption of the multicast frames of the site.
[0320] In one embodiment, the fields containing the key information include one or more of the following:
[0321] The identification information of the field;
[0322] The length information of the field;
[0323] The identification information of the key information;
[0324] The length information of the key information;
[0325] The frame sequence number information;
[0326] The key information.
[0327] In one embodiment, obtaining frame sequence number information includes:
[0328] Different frame sequence number information is obtained during different channel probing processes.
[0329] In one embodiment, the information processing method further includes:
[0330] The encrypted information is verified based on one or more of the key information and the frame sequence number information.
[0331] In one embodiment, the encryption information further includes frame sequence number information used to encrypt the multicast frame.
[0332] In one embodiment, the third information frame further includes indication information, which instructs the site to return the encrypted information in one of the following ways:
[0333] Unicast method;
[0334] Multicast mode;
[0335] Unicast encryption method;
[0336] Multicast encryption method;
[0337] Broadcast method;
[0338] Broadcast encryption method.
[0339] In one embodiment, the first access point establishes an association with the site; or the first access point does not establish an association with the site.
[0340] In one embodiment, the step of decrypting the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame includes:
[0341] The frame sequence number information is transformed in association with the station to obtain the transformed frame sequence number information;
[0342] The encrypted information is decrypted based on the transformed frame sequence number information and the key information to obtain the multicast frame.
[0343] In one embodiment, obtaining frame sequence number information includes:
[0344] Obtain the reference frame sequence number information and the value range of the frame sequence number information, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range.
[0345] In one embodiment, the information processing method further includes:
[0346] Before the site uses the frame sequence number information with the largest value in the frame sequence number information value range, it obtains the updated baseline frame sequence number information and the updated frame sequence number information value range.
[0347] In one embodiment, the frame sequence number information is contained in a first information frame and a second information frame, or the frame sequence number information is contained in a third information frame.
[0348] The following is an exemplary description of this application:
[0349] This application proposes a method for a STA to receive a multicast key transmitted by an AP, encrypt multicast frames using the multicast key, and send them to the AP. This application can be applied to network devices with distributed multilink APs and multilink terminal devices.
[0350] a) Before each encrypted multicast frame received from the STA, the AP sends an information frame containing PN information, which is used by the STA for the PN value during the encryption process.
[0351] b) Before each time multiple STAs simultaneously send encrypted multicast frames, the information frame sent by the AP contains baseline PN information. This information is used by multiple STAs to calculate their respective PN values for the encryption process based on a certain algorithm.
[0352] c) The AP shares the multicast key with at least one OBSS AP participating in receiving the multicast and at least one associated or unassociated STA participating in sending encrypted multicast frames. That is, the first access point transmits the first information frame to the station and the second information frame to the second access point.
[0353] d) The OBSS AP uses the received multicast key to decrypt encrypted multicast messages sent by non-associated STAs.
[0354] In one example, this application proposes a method for an AP to send a multicast key GTK1 to a STA, which uses GTK1 to encrypt and transmit multicast frames. The features of this method include the following aspects:
[0355] 1) STA1 and AP2 obtain the multicast encryption and decryption keys transmitted by AP1;
[0356] 2) AP1 dynamically specifies PN information to avoid PN confusion caused by using the process simultaneously or not simultaneously on multiple associated STAs;
[0357] 3) STA1 uses the acquired multicast key and PN to encrypt the multicast frame and sends it out via multicast.
[0358] 4) After AP1 and AP2 receive the encrypted multicast frame information, they decrypt it using the corresponding PN and multicast key, that is, they decrypt the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame.
[0359] The specific methods provided in this application are as follows:
[0360] 1. AP1, i.e., the first access point, sends a first information frame to at least one associated (or unassociated) STA1, i.e., a station, containing GTK1, i.e., key information, for multicast encryption and decryption;
[0361] 2. STA1 replies to AP1 with a response frame, responding to the above information (optional step);
[0362] 3. AP1 sends a second information frame to AP2, the second access point, which contains the key information GTK1 used for multicast encryption and decryption;
[0363] 4. AP2 replies to AP1 with a response frame, responding to the above information (optional step);
[0364] 5. AP1 sends PN information, i.e., frame sequence number information (or PN update information), to STA1 and AP2 simultaneously or at different times in the first information frame, the second information frame and / or the third information frame;
[0365] 6. STA1, based on GTK1 and PN information, encrypts the multicast frames according to a certain algorithm and sends them to AP1 and AP2 via multicast / broadcast.
[0366] 7. After AP1 and AP2 receive the encrypted multicast information frame, they respectively use GTK1 to decrypt the above information and obtain the corresponding information, that is, decrypt the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame;
[0367] 8. AP1 sends a fourth information frame to AP2 and STA1 to update GTK1 to GTK2 (optional step);
[0368] 9. AP2 and STA1 send a response frame to AP2 to respond to the above information and update GTK1 to GTK2, which will be used in the subsequent multicast frame encryption and decryption process (optional step).
[0369] The order of steps 1-2 and 3-4 above can be switched; there is no restriction on the execution order here.
[0370] Before AP1 sends the first information frame to STA, it receives the sixth information frame sent by the station, i.e. STA, indicating whether STA supports key sharing mode. For example, if the connection request frame sent by STA contains the RSNE / RSNXE field, indicating that it has key sharing capability, then AP1 executes step 1 and sends the first information frame containing GTK1 to STA1; otherwise, the first information frame does not contain GTK1.
[0371] Similarly, before AP1 sends the second information frame to AP2, it receives the seventh information frame sent by AP2, indicating whether AP2 supports key sharing mode. For example, during the authentication process, if the authentication frame sent by AP2 contains the RSNE / RSNXE field, indicating that it has key sharing capability, then AP1 sends the second information frame containing GTK1 to AP2; otherwise, the second information frame does not contain GTK1.
[0372] In addition, the key sharing mode may be one of three indicators: unicast key sharing, multicast key sharing, or key sharing.
[0373] The scheme for STAs to share their GTK (i.e., the scheme for STAs to send information frames containing GTK) is similar and will not be described in detail here.
[0374] Figure 8 is a schematic diagram of an RSNXE field provided in this application, which includes an element ID, a field length, and an RSNXE capability set field. The RSNXE capability set field of the RSNXE field includes a key sharing indicator (security key info.sharing), used to indicate whether key sharing capability is available.
[0375] The following provides a further explanation of the above steps:
[0376] (1) In some application examples, AP may be a single-link access point, a multi-link access point (AP MLD), or a non-collocated multi-link access point (non-collocated AP MLD); STA may be a single-link site, a multi-link site (non-AP MLD), a single-radio, multi-radio, enhanced single-radio, enhanced multi-radio, and other multi-link terminal devices.
[0377] (2) In some application instances, STA1 obtains GTK1 information during the association process or key update process, that is, during the association process with the site, it transmits the first information frame to the site. For example, AP1 sends the GTK1 information in EAPOL-3 to STA1, and STA1 sends an EAPOL-4 frame in response to the above information; or, AP sends the GTK1 information in (re)association response frame to STA1.
[0378] (3) In some application examples, the first information frame contains at least one set of AP2 identification information (such as AP2's AP ID, MAC address, BSSID, BSS color, etc.) and GTK1 information, for example...<AP2 ID,GTK1> This is used to indicate that GTK1 is only used in the encrypted multicast frame reception process involving AP2, that is, the access point identification information of the second access point. The access point identification information is associated with the key information, and the key information is used in the process of receiving the encrypted information involving the second access point.
[0379] (4) In some application examples, the second information frame contains at least one set of STA1 identification information (such as the STA's association identifier (AID), MAC address, etc.) and GTK1 information, for example...<STA1 AID,GTK1> This is used to instruct GTK1 to be used only for the process of receiving encrypted multicast frames sent by STA1, namely the site identification information of the site and the key information, the key information being used for encrypting the multicast frames of the site.
[0380] (5) In some application examples, the second information frame contains at least one set of STA1 identification information (such as the STA's AID, MAC address, etc.) and PN information, for example<STA1 AID,PN1> This is used to indicate that STA1 is currently sending encrypted multicast frames using PN1, namely the site information and the frame sequence number information of the site, and the frame sequence number information is used by the site to send the encrypted information.
[0381] (6) In some application examples, the second information frame contains at least one set of STA1 identification information (such as the STA's AID, MAC address, etc.) and PN and GTK1 information, for example<STA1 AID,PN1,GTK1> This is used to instruct STA1 to currently send encrypted multicast frames using PN1 and GTK1, namely the site information, the key information, and the frame sequence number information of the site. The key information and the frame sequence number information are used for encrypting the multicast frames of the site.
[0382] (7) In some application examples, Table 1 is a table of field formats containing GTK1 information. The frame format containing GTK1 information is shown in Table 1; the fields containing GTK1 include field ID information (Subelement D, i.e., field identification information), field length information (Length), key ID information (i.e., key information identification information) used to indicate the key algorithm (Key ID), GTK1 key length information (Key Length, i.e., key information length information), frame (received) number information (Received Sequence Counter / Packet Number, RSC / PN), and GTK1 key information (Wrapped Key).
[0383] Table 1 contains the field format table for GTK1 information.
[0384] (8) In some application instances, during the security negotiation process before AP1 and AP2 connect, AP1 sends the GTK1 information to AP2. For example, AP1 sends the GTK1 information to AP2 through the encryption field of the second or third authentication frame.
[0385] (9) In some application instances, during the parameter negotiation process between AP1 and AP2, AP1 sends GTK1 information to AP2. For example, AP1 sends GTK1 information to AP2 through an encrypted management frame, and AP2 responds to the above information or does not respond.
[0386] (10) In some application instances, the above process can be adapted to the channel sounding process or the range measurement and location process, i.e., the multipoint location process, as well as the process in which any STA sends encrypted multicast frames to associated and unassociated APs simultaneously / at different times.
[0387] (11) In some application instances, AP1 sends PN information to STA1 and AP2 through an Initial Control Frame (ICF), a Null Packet Delivery Announcement (NPDA) frame, or a BFRP frame, and its characteristics include one of the following:
[0388] a) PN information is contained in a specific user info field, that is, the user info field is identified by a specific AID11 or AID12, such as AID=2044.
[0389] b) PN information is contained in the common info field, such as in the Trigger Dependent Common Info field.
[0390] (12) In some application instances, in order to address the potential risk of key leakage caused by PN reuse, one of the following methods may be adopted:
[0391] a) Before each STA sends encrypted multicast data, the AP assigns and transmits different PN value information to it. For example, in the first Joint Sounding (JS) process, AP1 assigns PN value PN1 to STA1, and in the second JS process, AP1 assigns PN value PN1+1 to STA1 (or STA2). That is, in each JS process, the scheduled STAs may be the same or different, and the number of scheduled STAs may be the same or different.
[0392] b) The AP assigns a PN base value to each STA, explicitly including a PN value range, i.e., the frame sequence number information value range. For example, in the first information frame, the AP assigns PN1 to STA1 with a value range of [PN1, PN1+10000], and assigns PN2 to STA2 with a value range of [PN2, PN2+10000]. The PN value ranges of STA1 and STA2 do not overlap. Each time STA1 or STA2 sends encrypted multicast data, it automatically increments its PN by PN+1. This method does not require the AP to assign a new PN value each time, reducing the complexity of implementation.
[0393] c) The AP assigns a PN base value to each STA, implicitly including a range of PN values. For example, the AP assigns a PN to each STA in the first information frame, which only includes the high 24 bits of PN information. Each time the STA sends encrypted multicast data, it automatically sets its low 24 bits of PN to start from 0 and gradually performs the PN+1 operation (the high 24 bits remain unchanged). This method does not require the AP to assign a new PN value each time, reducing the complexity of implementation.
[0394] (13) In some application instances, in methods (10)b) and c), to avoid the potential out-of-bounds problem caused by the gradual accumulation of STA PN, one of the following methods can be adopted:
[0395] a) Before the STA reaches the maximum value of the PN range, the AP assigns a new PN value to the STA, which is the updated reference frame sequence number information.
[0396] b) Before the STA reaches the maximum value of the PN range, the STA sends a request to the AP to request the allocation of a new PN value. The AP sends a corresponding response containing the new PN value information, that is, the updated base frame sequence number information.
[0397] (14) In some application examples, when multiple STAs are scheduled to participate in multicast frame transmission simultaneously, such as in a channel probing process involving multiple STAs or when multiple STAs are scheduled to provide CSI information, AP1 sends a reference PN value. STAs then perform transformation operations on the reference PN according to their order of appearance in ICF, NPDA, or BFRP frames using a specific algorithm. This transformation transforms the frame sequence number information to obtain the transformed frame sequence number information, thereby obtaining different PN values to address the potential key leakage risk caused by PN reuse. For example, when AP1 sends a BFRP frame and simultaneously schedules STA1, STA2, and STA3 to provide CSI information, AP1 provides a reference PN value (assumed to be PN1) in the BFRP. STA1, STA2, and STA3 use the PN value increment method, obtaining PN values of PN1, PN1+1, and PN1+2 respectively.
[0398] (15) In some application examples, GTK1 can be used not only for the encryption of multicast frames, but also for the integrity of multicast frames. For example, GTK1 can be used to generate Message Integrity Code (MIC) information and append it to the end of the encrypted multicast frame.
[0399] (16) In some application instances, the encrypted multicast frames sent by the STA contain the PN information it uses.
[0400] (17) In some application examples, during the channel detection process, the ICF, NDPA or BFRP information frames sent by AP1 contain an indication message, instructing the STA it schedules to feed back CSI information in one of the following ways, and the STA performs corresponding operations according to different indication messages:
[0401] 1) CSI information is fed back via unicast;
[0402] 2) Multicast method to feed back CSI information;
[0403] 3) Unicast encryption method for feeding back CSI information;
[0404] 4) Multicast encryption method feeds back CSI information.
[0405] In one embodiment, the STA only sends multicast encryption and decryption information such as GTK1 and PN to the AP1. The specific process is as follows:
[0406] 1) STA1 sends a first information frame to its associated (or unassociated) AP1, which contains information such as GTK1 and PN for multicast encryption and decryption; that is, the station transmits the first information frame to the first access point. The first information frame includes key information and may also include frame sequence number information.
[0407] 2) AP1 replies to STA1 with a response frame, responding to the above information (optional step);
[0408] 3) AP1 or STA1 sends a second information frame to AP2, containing key information such as GTK1 and PN for multicast encryption and decryption of STA1; that is, the first access point transmits the second information frame to the second access point.
[0409] 4) AP2 replies with a response frame to AP1 or STA1, responding to the above information (optional step);
[0410] 5) Based on GTK1 and PN information, STA1 encrypts the multicast frames according to a certain algorithm and sends them to AP1 and AP2 via multicast / broadcast.
[0411] 6) After AP1 and AP2 receive the encrypted multicast information frame, i.e., after encrypting the information, they respectively use GTK1 to decrypt the information and obtain the corresponding information.
[0412] 7) STA1 sends a fourth information frame to AP1 to update GTK1 to GTK2 (optional step);
[0413] 8) AP1 sends a response frame to STA1 to respond to the above information and updates GTK1 to GTK2, which is used in the subsequent multicast frame encryption and decryption process (optional step);
[0414] 9) STA1 or AP1 sends a fifth information frame to AP2, containing an indication that STA1 will update GTK1 to GTK2 (optional step);
[0415] 10) AP2 responds to the above information and updates GTK1 to GTK2, which is then used in the subsequent multicast frame encryption and decryption process (optional step).
[0416] In this embodiment, STA1 may also send a fourth information frame to AP2 to update GTK1 to GTK2 (optional step).
[0417] In one embodiment, the STA sends GTK1, PN, and other information for multicast encryption and decryption to AP1 and AP2 respectively. The specific process is as follows:
[0418] 1) STA1 sends a first information frame and a second information frame to its associated (or unassociated) AP1 and AP2 respectively, containing information such as GTK1 and PN for multicast encryption and decryption; that is, STA1 sends a first information frame to AP1 containing information such as GTK1 and PN for multicast encryption and decryption, and STA1 sends a second information frame to AP2 containing information such as GTK1 and PN for multicast encryption and decryption.
[0419] 2) AP1 and AP2 respectively reply to STA1 with response frames to respond to the above information (optional step);
[0420] 3) Based on GTK1 and PN information, STA1 encrypts the multicast frames according to a certain algorithm and sends them to AP1 and AP2 via multicast / broadcast.
[0421] 4) After receiving the encrypted multicast information frame, AP1 and AP2 respectively use GTK1 to decrypt the above information and obtain the corresponding information;
[0422] 5) STA1 sends the fourth information frame to AP1 and AP2 respectively, updating GTK1 to GTK2 (optional step);
[0423] 6) AP1 and AP2 respectively send response frames to STA1 to respond to the above information, and update GTK1 to GTK2, which will be used in the subsequent multicast frame encryption and decryption process (optional step).
[0424] Further explanation of the above steps:
[0425] 1) In some application instances, STA1 simultaneously sends the first information frame to AP1 and AP2, which contains multicast encryption and decryption information such as GTK1 and PN.
[0426] 2) In some application instances, AP1 and AP2 simultaneously reply to STA1 with response frames, responding to the above information.
[0427] 3) In some application instances, STA1 sends different GTK and PN information to different AP groups. For example, STA1 sends...<AP1,AP2> Send GTK1, PN1; to<AP1,AP3> Send GTK2 and PN2. STA1 selects different GTK and corresponding PN information based on the target receiver information. For example, during channel probing, if the NDPA sent by AP1 contains AP2's AP2 ID information and STA1's AID information, then STA1 determines that the target receiving APs for the multicast frame are AP1 and AP2, and uses GTK1 and PN1 for encryption when sending the encrypted multicast frame.
[0428] Figure 9 is a schematic diagram of OBSS authentication transmission and OBSS channel information detection provided in an embodiment of this application. Referring to Figure 9, STA1 is associated with AP1. The flowchart of AP1 and AP2 performing JS operation on STA1 is shown in Figure 9, and the specific steps are described as follows:
[0429] (1) During the connection process, AP1 sends GTK1 to STA1 via EAPOL-3;
[0430] (2) STA1 sends an EAPOL-4 frame in response to the above information;
[0431] (3) During the MAP negotiation process, AP1 sends GTK1 to AP2 in the negotiation request frame;
[0432] (4) AP2 sends a response frame to AP1 in response to the above information;
[0433] (5) During the JS process, AP1 sends ICF frames containing PN information to STA1 and AP2;
[0434] (6) STA1 and AP2 simultaneously send ICRs to respond accordingly;
[0435] (7) AP1 sends an NDPA frame containing STA1 and AP2 information;
[0436] (8) AP1 and AP2 together send the NDP signal to STA1;
[0437] (9) AP1 sends a BFRP trigger frame, triggering AP2 to prepare to receive the CSI sent by STA1, and at the same time triggering STA1 to prepare to send CSI information;
[0438] (10) After receiving the above information, STA1 uses GTK1 and PN information to encrypt the CSI feedback information and then sends it out via multicast.
[0439] (11) After AP1 and AP2 receive the encrypted CSI information frame, they use GTK1 and PN to verify and decrypt the information.
[0440] Figure 10 is a schematic diagram of joint positioning provided in an embodiment of this application. STA1 is not associated with AP1 or AP2. The flowchart of the joint positioning process of AP1 and AP2 for STA1 is shown in Figure 10. The specific steps in the connection process are described as follows:
[0441] 1) STA1 sends the first PASN frame, which is the security negotiation before establishing a connection with AP1.
[0442] 2) AP1 sends GTK1 and PN1 to STA1 through the 2nd PASN frame, i.e., the 2-PASN frame;
[0443] 3) STA1 sends the 3rd PASN frame, i.e., the 3-PASN frame, in response to the above information;
[0444] 4) During the MAP negotiation process, AP1 sends GTK1,PN1 to AP2 in the negotiation request frame;
[0445] 5) AP2 sends a response frame to AP1 in response to the above information;
[0446] 6) AP1 sends a trigger frame, triggering AP2 to prepare to receive the FTM sent by STA1, and at the same time triggering STA1 to prepare to send FTM information;
[0447] 7) After receiving the above information, STA1 encrypts the FTM information using GTK1 and PN information and sends it out via multicast;
[0448] 8) After AP1 and AP2 receive the encrypted FTM information frame, they use GTK1 and PN to verify and decrypt the information.
[0449] In one exemplary embodiment, this application provides an information processing device that can be integrated into a first access point. Figure 11 is a schematic diagram of the structure of an information processing device provided in an embodiment of this application. The information processing device includes:
[0450] The first transmission module 1010 is configured to transmit a first information frame to the station, the first information frame including key information;
[0451] The second transmission module 1020 is configured to transmit a second information frame to the second access point, the second information frame including the key information;
[0452] The third transmission module 1030 is configured to transmit frame sequence number information to the station and the second access point;
[0453] The acquisition module 1040 is configured to acquire encrypted information, the encrypted information including information after encrypting the multicast frame based on the key information and the frame sequence number information;
[0454] The decryption module 1050 is configured to decrypt the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame.
[0455] The information processing device provided in this embodiment is used to implement the information processing method shown in Figure 1. The implementation principle and technical effect of the information processing device provided in this embodiment are similar to those of the information processing method shown in Figure 1, and will not be repeated here.
[0456] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0457] In one embodiment, the information processing apparatus further includes:
[0458] A fourth transmission device is configured to transmit a fourth information frame to the station, the fourth information frame including updated key information;
[0459] The fifth transmission device is configured to transmit a fifth information frame to the second access point, the fifth information frame including updated key information.
[0460] In one embodiment, the first access point is one of the following:
[0461] Single-link access point;
[0462] Multi-link access points;
[0463] Non-co-located multi-link access points.
[0464] In one embodiment, the site includes one of the following:
[0465] Single-link site;
[0466] Multi-link site.
[0467] In one embodiment, the first transmission module 1010 is specifically configured as follows:
[0468] During the association process with the site, a first information frame is transmitted to the site.
[0469] In one embodiment, the second transmission module 1020 is specifically configured as follows:
[0470] The second information frame is transmitted to the second access point in one of the following processes:
[0471] The security negotiation process before connecting to the second access point;
[0472] During parameter negotiation with the second access point;
[0473] During the key negotiation process with the second access point.
[0474] In one embodiment, the information processing method is applied to one of the following processes:
[0475] Channel detection process;
[0476] Distance measurement process;
[0477] Multi-point positioning process;
[0478] The process by which the site transmits the encrypted information to the first access point;
[0479] The process of the site transmitting the encrypted information to the second access point.
[0480] In one embodiment, the third information frame includes one of the following:
[0481] Initialize the control frame;
[0482] Empty data packet announcement frame;
[0483] Beamforming report polling.
[0484] In one embodiment, the frame sequence number information is included in the user information field or public information field of the third information frame.
[0485] In one embodiment, the first information frame further includes access point identification information of the second access point, which is associated with the key information, and the key information is used by the second access point in the process of receiving the encrypted information.
[0486] In one embodiment, there are multiple second access points, and the key information corresponding to different second access points may be the same or different.
[0487] In one embodiment, the second information frame further includes one of the following:
[0488] The site identification information and the key information of the site, wherein the key information is used for encryption of the multicast frames of the site;
[0489] The site information and the frame sequence number information of the site, wherein the frame sequence number information is used by the site to send the encrypted information;
[0490] The site information, the key information, and the frame sequence number information of the site are used for the encryption of the multicast frames of the site.
[0491] In one embodiment, the fields containing the key information include one or more of the following:
[0492] The identification information of the field;
[0493] The length information of the field;
[0494] The identification information of the key information;
[0495] The length information of the key information;
[0496] The frame sequence number information;
[0497] The key information.
[0498] In one embodiment, the third transmission module 1030 is configured as follows:
[0499] Different frame sequence number information is allocated and transmitted during different channel probes.
[0500] In one embodiment, the information processing apparatus further includes:
[0501] The verification module is configured to verify the encrypted information based on one or more of the key information and the frame sequence number information.
[0502] In one embodiment, the encryption information further includes frame sequence number information used to encrypt the multicast frame.
[0503] In one embodiment, the third information frame further includes indication information, which instructs the site to return the encrypted information in one of the following ways:
[0504] Unicast method;
[0505] Multicast mode;
[0506] Unicast encryption method;
[0507] Multicast encryption method;
[0508] Broadcast method;
[0509] Broadcast encryption method.
[0510] In one embodiment, the first access point establishes an association with the site; or the first access point does not establish an association with the site.
[0511] In one embodiment, the decryption module 1050 is specifically configured as follows:
[0512] The frame sequence number information is transformed in association with the station to obtain the transformed frame sequence number information;
[0513] The encrypted information is decrypted based on the transformed frame sequence number information and the key information to obtain the multicast frame.
[0514] In one embodiment, the third transmission module 1030 is specifically configured as follows:
[0515] The reference frame sequence number information and the value range of the frame sequence number information are transmitted to the station, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range.
[0516] In one embodiment, the information processing apparatus further includes:
[0517] The fourth transmission module is configured to transmit updated reference frame sequence information and updated frame sequence information value range before the station uses the frame sequence information with the largest value range.
[0518] In one embodiment, the information processing apparatus further includes an acquisition module, configured to:
[0519] Obtain the request information transmitted by the site;
[0520] Transmit response information, which includes updated reference frame sequence number information and the value range of the updated frame sequence number information.
[0521] In one embodiment, the frame sequence number information is contained in a first information frame and a second information frame, or the frame sequence number information is contained in a third information frame.
[0522] In one exemplary embodiment, this application also provides an information processing apparatus that can be integrated into a website. Figure 12 is a schematic diagram of the structure of yet another information processing apparatus provided in an embodiment of this application. Referring to Figure 12, the information processing apparatus includes:
[0523] The first acquisition module 1110 is configured to acquire a first information frame, wherein the first information frame includes key information;
[0524] The second acquisition module 1120 is configured to acquire frame sequence number information;
[0525] Encryption module 1130 is configured to encrypt multicast frames based on the key information and the frame sequence number information to obtain encrypted information;
[0526] The transmission module 1140 is configured to transmit the encrypted information.
[0527] The information processing device provided in this embodiment is used to implement the information processing method shown in Figure 6. The implementation principle and technical effect of the information processing device provided in this embodiment are similar to those of the information processing method shown in Figure 6, and will not be repeated here.
[0528] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0529] In one embodiment, the encryption module 1130 is specifically configured as follows:
[0530] Generate a message integrity code based on the key information and the frame sequence number information;
[0531] The message integrity code is appended to the end of the encrypted multicast frame to obtain an encrypted message.
[0532] In one embodiment, the encryption module 1130 is specifically configured as follows:
[0533] The frame sequence number information is transformed to obtain the transformed frame sequence number information;
[0534] The multicast frame is encrypted based on the transformed frame sequence number information and the key information to obtain encrypted information.
[0535] In one embodiment, the frame sequence number information is included in the first information frame or the third information frame.
[0536] In one embodiment, the information processing apparatus further includes a third acquisition module, configured as follows:
[0537] Transmit request information;
[0538] Obtain response information, which includes updated reference frame sequence number information and the value range of the updated frame sequence number information.
[0539] In one embodiment, the second acquisition module 1120 is specifically configured as follows:
[0540] Obtain the reference frame sequence number information and the value range of the frame sequence number information, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range.
[0541] In one embodiment, the information processing apparatus further includes a fourth acquisition module, configured as follows:
[0542] Obtain the updated baseline frame sequence number information and the range of values for the updated frame sequence number information;
[0543] During each transmission of encrypted information, different frame sequence numbers within the range of the frame sequence number information are used.
[0544] In one embodiment, the second acquisition module 1120 is specifically configured as follows:
[0545] Different frame sequence number information is obtained during different channel probing processes.
[0546] In one embodiment, the information processing apparatus further includes a third acquisition module, configured as follows:
[0547] Obtain the fourth information frame, which includes the updated key information.
[0548] In one embodiment, the first access point is one of the following:
[0549] Single-link access point;
[0550] Multi-link access points;
[0551] Non-co-located multi-link access points.
[0552] In one embodiment, the site includes one of the following:
[0553] Single-link site;
[0554] Multi-link site.
[0555] In one embodiment, the first acquisition module 1110 is specifically configured as follows:
[0556] During the association process with the first access point, the first information frame is acquired.
[0557] In one embodiment, the information processing method is applied to one of the following processes:
[0558] Channel detection process;
[0559] Distance measurement process;
[0560] Multi-point positioning process;
[0561] The process by which the site transmits the encrypted information to the first access point;
[0562] The process of the site transmitting the encrypted information to the second access point.
[0563] In one embodiment, the third information frame includes one of the following:
[0564] Initialize the control frame;
[0565] Empty data packet announcement frame;
[0566] Beamforming report polling.
[0567] In one embodiment, the frame sequence number information is included in the user information field or public information field of the third information frame.
[0568] In one embodiment, the first information frame further includes access point identification information of the second access point, which is associated with the key information, and the key information is used by the second access point in the process of receiving the encrypted information.
[0569] In one embodiment, the second information frame further includes one of the following:
[0570] The site identification information and the key information of the site, wherein the key information is used for encryption of the multicast frames of the site;
[0571] The site information and the frame sequence number information of the site, wherein the frame sequence number information is used by the site to send the encrypted information;
[0572] The site information, the key information, and the frame sequence number information of the site are used for the encryption of the multicast frames of the site.
[0573] In one embodiment, the fields containing the key information include one or more of the following:
[0574] The identification information of the field;
[0575] The length information of the field;
[0576] The identification information of the key information;
[0577] The length information of the key information;
[0578] The frame sequence number information;
[0579] The key information.
[0580] In one embodiment, the encryption information further includes frame sequence number information used to encrypt the multicast frame.
[0581] In one embodiment, the third information frame further includes indication information, which instructs the site to return the encrypted information in one of the following ways:
[0582] Unicast method;
[0583] Multicast mode;
[0584] Unicast encryption method;
[0585] Multicast encryption method;
[0586] Broadcast method;
[0587] Broadcast encryption method.
[0588] In one embodiment, the first access point establishes an association with the site; or the first access point does not establish an association with the site.
[0589] In one embodiment, the information processing apparatus further includes a fourth acquisition module, configured as follows:
[0590] Before the site uses the frame sequence number information with the largest value in the frame sequence number information value range, it obtains the updated baseline frame sequence number information and the updated frame sequence number information value range.
[0591] In one embodiment, the frame sequence number information is contained in a first information frame and a second information frame, or the frame sequence number information is contained in a third information frame.
[0592] In one exemplary embodiment, this application further provides an information processing apparatus, and FIG13 is a schematic diagram of the structure of yet another information processing apparatus provided in an embodiment of this application. The information processing apparatus includes:
[0593] The first acquisition module 1210 is configured to acquire a second information frame, wherein the second information frame includes key information.
[0594] The second acquisition module 1220 is configured to acquire frame sequence number information;
[0595] The third acquisition module 1230 is configured to acquire encrypted information, the encrypted information including information after encrypting the multicast frame based on the key information and the frame sequence number information;
[0596] The decryption module 1240 is configured to decrypt the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame.
[0597] The information processing device provided in this embodiment is used to implement the information processing method shown in Figure 7. The implementation principle and technical effect of the information processing device provided in this embodiment are similar to those of the information processing method shown in Figure 7, and will not be repeated here.
[0598] Based on the above embodiments, modified embodiments of the above embodiments are proposed. It should be noted that, in order to keep the description brief, only the differences from the above embodiments are described in the modified embodiments.
[0599] In one embodiment, the information processing apparatus further includes a fourth acquisition module, configured as follows:
[0600] Five information frames are obtained, the fifth information frame including the updated key information.
[0601] In one embodiment, the first access point is one of the following:
[0602] Single-link access point;
[0603] Multi-link access points;
[0604] Non-co-located multi-link access points.
[0605] In one embodiment, the site includes one of the following:
[0606] Single-link site;
[0607] Multi-link site.
[0608] In one embodiment, the first acquisition module 1210 is specifically configured as follows:
[0609] The second information frame is acquired through one of the following processes:
[0610] The security negotiation process before connecting to the first access point;
[0611] During parameter negotiation with the first access point.
[0612] In one embodiment, the information processing method is applied to one of the following processes:
[0613] Channel detection process;
[0614] Distance measurement process;
[0615] Multi-point positioning process;
[0616] The process by which the site transmits the encrypted information to the first access point;
[0617] The process of the site transmitting the encrypted information to the second access point.
[0618] In one embodiment, the third information frame includes one of the following:
[0619] Initialize the control frame;
[0620] Empty data packet announcement frame;
[0621] Beamforming report polling.
[0622] In one embodiment, the frame sequence number information is included in the user information field or public information field of the third information frame.
[0623] In one embodiment, the first information frame further includes access point identification information of the second access point, which is associated with the key information, and the key information is used by the second access point in the process of receiving the encrypted information.
[0624] In one embodiment, there are multiple second access points, and the key information corresponding to different second access points may be the same or different.
[0625] In one embodiment, the second information frame further includes one of the following:
[0626] The site identification information and the key information of the site, wherein the key information is used for encryption of the multicast frames of the site;
[0627] The site information and the frame sequence number information of the site, wherein the frame sequence number information is used by the site to send the encrypted information;
[0628] The site information, the key information, and the frame sequence number information of the site are used for the encryption of the multicast frames of the site.
[0629] In one embodiment, the fields containing the key information include one or more of the following:
[0630] The identification information of the field;
[0631] The length information of the field;
[0632] The identification information of the key information;
[0633] The length information of the key information;
[0634] The frame sequence number information;
[0635] The key information.
[0636] In one embodiment, the second acquisition module 1220 is specifically configured as follows:
[0637] Different frame sequence number information is obtained during different channel probing processes.
[0638] In one embodiment, the information processing apparatus further includes a verification module:
[0639] The encrypted information is verified based on one or more of the key information and the frame sequence number information.
[0640] In one embodiment, the encryption information further includes frame sequence number information used to encrypt the multicast frame.
[0641] In one embodiment, the third information frame further includes indication information, which instructs the site to return the encrypted information in one of the following ways:
[0642] Unicast method;
[0643] Multicast mode;
[0644] Unicast encryption method;
[0645] Multicast encryption method;
[0646] Broadcast method;
[0647] Broadcast encryption method.
[0648] In one embodiment, the first access point establishes an association with the site; or the first access point does not establish an association with the site.
[0649] In one embodiment, the decryption module 1240 is specifically configured as follows:
[0650] The frame sequence number information is transformed in association with the station to obtain the transformed frame sequence number information;
[0651] The encrypted information is decrypted based on the transformed frame sequence number information and the key information to obtain the multicast frame.
[0652] In one embodiment, the second acquisition module 1220 is specifically configured as follows:
[0653] Obtain the reference frame sequence number information and the value range of the frame sequence number information, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range.
[0654] In one embodiment, the information processing apparatus further includes a fifth acquisition module configured as follows:
[0655] Before the site uses the frame sequence number information with the largest value in the frame sequence number information value range, it obtains the updated baseline frame sequence number information and the updated frame sequence number information value range.
[0656] In one embodiment, the frame sequence number information is contained in a first information frame and a second information frame, or the frame sequence number information is contained in a third information frame.
[0657] In one exemplary embodiment, this application provides a first access point, and FIG14 is a schematic diagram of the structure of a first access point provided in this application embodiment. As shown in FIG14, this application provides a first access point including one or more processors 51 and a storage device 52; the processors 51 in the first access point may be one or more, and FIG14 takes one processor 51 as an example; the storage device 52 is used to store one or more programs; the one or more programs are executed by the one or more processors 51, so that the one or more processors 51 implement the information processing method as described in the embodiment of this application.
[0658] The first access point also includes: a communication device 53, an input device 54, and an output device 55.
[0659] The processor 51, storage device 52, communication device 53, input device 54, and output device 55 in the first access point can be connected by a bus or other means. Figure 14 shows an example of connection via a bus.
[0660] The input device 54 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the first access point. The output device 55 may include a display screen or other display device.
[0661] The communication device 53 may include a receiver and a transmitter. The communication device 53 is configured to perform information transmission and reception communication under the control of the processor 51.
[0662] Storage device 52, as a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the information processing method described in the embodiments of this application (e.g., the first transmission module 1010, the second transmission module 1020, the third transmission module 1030, the acquisition module 1040, and the decryption module 1050 in the information processing device). Storage device 52 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the first access point, etc. In addition, storage device 52 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, storage device 52 may further include memory remotely located relative to processor 51, and these remote memories can be connected to the first access point via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0663] In one exemplary embodiment, this application also provides a site. FIG15 is a schematic diagram of the structure of a site provided in this application embodiment. As shown in FIG15, the site provided in this application includes one or more processors 61 and a storage device 62. The processors 61 in the site may be one or more, and FIG15 takes one processor 61 as an example. The storage device 62 is used to store one or more programs. The one or more programs are executed by the one or more processors 61, so that the one or more processors 61 implement the information processing method as described in the embodiment of this application.
[0664] The site also includes: communication device 63, input device 64 and output device 65.
[0665] The processor 61, storage device 62, communication device 63, input device 64 and output device 65 in the site can be connected by a bus or other means. Figure 15 shows an example of connection via a bus.
[0666] Input device 64 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the site. Output device 65 may include display devices such as a display screen.
[0667] The communication device 63 may include a receiver and a transmitter. The communication device 63 is configured to perform information transmission and reception communication under the control of the processor 61.
[0668] Storage device 62, as a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the information processing method described in the embodiments of this application (e.g., the first acquisition module 1110, the second acquisition module 1120, the encryption module 1130, and the transmission module 1140 in the information processing device). Storage device 62 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the site, etc. In addition, storage device 62 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, storage device 62 may further include memory remotely located relative to processor 61, and these remote memories can be connected to the site via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0669] In one exemplary embodiment, this application also provides a second access point. FIG16 is a schematic diagram of the structure of a second access point provided in this application embodiment. As shown in FIG16, the second access point provided in this application includes one or more processors 71 and a storage device 72; the processors 71 in the second access point may be one or more, and FIG16 takes one processor 71 as an example; the storage device 72 is used to store one or more programs; the one or more programs are executed by the one or more processors 71, so that the one or more processors 71 implement the information processing method as described in the embodiment of this application.
[0670] The second access point also includes: a communication device 73, an input device 74, and an output device 75.
[0671] The processor 71, storage device 72, communication device 73, input device 74, and output device 75 in the second access point can be connected by a bus or other means. Figure 16 shows an example of connection via a bus.
[0672] The input device 74 can be used to receive input digital or character information, and to generate key signal inputs related to user settings and function control of the second access point. The output device 55 may include a display device such as a display screen.
[0673] The communication device 73 may include a receiver and a transmitter. The communication device 73 is configured to perform information transmission and reception communication under the control of the processor 71.
[0674] Storage device 72, as a computer-readable storage medium, can be configured to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the information processing method described in the embodiments of this application (e.g., the first acquisition module 1110, the second acquisition module 1120, the encryption module 1130, and the transmission module 1140 in the information processing device). Storage device 72 may include a program storage area and a data storage area, wherein the program storage area may store the operating system and at least one application program required for a function; the data storage area may store data created based on the use of the second access point, etc. Furthermore, storage device 72 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other non-volatile solid-state storage device. In some instances, storage device 72 may further include memory remotely located relative to processor 71, and these remote memories can be connected to the second access point via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0675] In one exemplary embodiment, this application also provides a storage medium storing a computer program that, when executed by a processor, implements any of the methods described in this application. The storage medium stores a computer program that, when executed by a processor, implements any of the information processing methods described in the embodiments of this application. Examples include an information processing method applied to a first access point, an information processing method applied to a site, and an information processing method applied to a second access point. The information processing method applied to the first access point includes: transmitting a first information frame to the site, the first information frame including key information.
[0676] Transmit a second information frame to the second access point, the second information frame including the key information;
[0677] Transmit frame sequence number information to the station and the second access point;
[0678] Obtain encrypted information, which includes information encrypted based on the key information and the frame sequence number information of the multicast frame;
[0679] The encrypted information is decrypted based on the key information and the frame sequence number information to obtain the multicast frame.
[0680] The information processing method applied to the site includes: acquiring a first information frame, wherein the first information frame includes key information;
[0681] Obtain frame sequence number information;
[0682] The multicast frame is encrypted based on the key information and the frame sequence number information to obtain encrypted information;
[0683] Transmit the encrypted information.
[0684] Information processing methods applied to the second access point include:
[0685] Obtain a second information frame, the second information frame including key information;
[0686] Obtain frame sequence number information;
[0687] Obtain encrypted information, which includes information encrypted based on the key information and the frame sequence number information of the multicast frame;
[0688] The encrypted information is decrypted based on the key information and the frame sequence number information to obtain the multicast frame.
[0689] The computer storage medium in this application embodiment can be any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. For example, a computer-readable storage medium can be, but is not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), flash memory, optical fiber, portable compact disc read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. The computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0690] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. Computer-readable signal media may also be any computer-readable medium other than computer-readable storage media, which can send, propagate, or transmit programs for use by or in connection with an instruction execution system, apparatus, or device.
[0691] Program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to: wireless, wire, optical fiber, radio frequency (RF), etc., or any suitable combination thereof.
[0692] Computer program code for performing the operations of this application can be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as "C" or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network, including a Local Area Network (LAN) or a Wide Area Network (WAN), or it can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0693] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the method provided in the embodiments of this application.
[0694] The above description is merely an exemplary embodiment of this application and is not intended to limit the scope of protection of this application.
[0695] Those skilled in the art will understand that the term terminal equipment covers any suitable type of wireless user equipment, such as mobile phones, portable data processing devices, portable web browsers, or vehicle-mounted mobile stations.
[0696] Generally, the various embodiments of this application can be implemented in hardware or dedicated circuitry, software, logic, or any combination thereof. For example, some aspects can be implemented in hardware, while others can be implemented in firmware or software that can be executed by a controller, microprocessor, or other computing device, although this application is not limited thereto.
[0697] Embodiments of this application can be implemented by executing computer program instructions through the data processor of a mobile device, for example, in a processor entity, or through hardware, or through a combination of software and hardware. The computer program instructions can be assembly instructions, Instruction Set Architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, status setting data, or source code or object code written in any combination of one or more programming languages.
[0698] Any block diagram of logical flow in the accompanying drawings of this application may represent program steps, or may represent interconnected logic circuits, modules, and functions, or may represent a combination of program steps and logic circuits, modules, and functions. The computer program may be stored on memory. Memory may be of any type suitable to the local technical environment and may be implemented using any suitable data storage technology, such as, but not limited to, read-only memory (ROM), random access memory (RAM), optical storage devices and systems (Digital Video Disc (DVD) or Compact Disk (CD)), etc. Computer-readable media may include non-transitory storage media. The data processor may be of any type suitable to the local technical environment, such as, but not limited to, general-purpose computers, special-purpose computers, microprocessors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), and processors based on multi-core processor architectures.
[0699] A detailed description of exemplary embodiments of this application has been provided above through exemplary and non-limiting examples. However, various modifications and adjustments to the above embodiments will be apparent to those skilled in the art when considered in conjunction with the accompanying drawings and claims, without departing from the scope of this disclosure.
Claims
An information processing method, applied to a first access point, the method comprising: Transmit a first information frame to the site, the first information frame including key information; Transmit a second information frame to the second access point, the second information frame including the key information; Transmit frame sequence number information to the station and the second access point; Obtain encrypted information, which includes information encrypted based on the key information and the frame sequence number information of the multicast frame; The encrypted information is decrypted based on the key information and the frame sequence number information to obtain the multicast frame. The method according to claim 1 further includes: A fourth information frame is transmitted to the site, the fourth information frame including updated key information; A fifth information frame is transmitted to the second access point, the fifth information frame including updated key information. According to the method of claim 1, wherein, The first access point is one of the following: Single-link access point; Multi-link access points; Non-co-located multi-link access points. According to the method of claim 1, wherein, The site includes one of the following: Single-link site; Multi-link site. According to the method of claim 1, wherein, The transmission of the first information frame to the station includes: During the association process with the site, a first information frame is transmitted to the site. According to the method of claim 1, wherein, The transmission of the second information frame to the second access point includes: The second information frame is transmitted to the second access point in one of the following processes: The security negotiation process before connecting to the second access point; During parameter negotiation with the second access point; During the key negotiation process with the second access point. According to the method of claim 1, wherein, The information processing method is applied to one of the following processes: Channel detection process; Distance measurement process; Multi-point positioning process; The process by which the site transmits the encrypted information to the first access point; The process of the site transmitting the encrypted information to the second access point. According to the method of claim 1, wherein, The third information frame includes one of the following: Initialize the control frame; Empty data packet announcement frame; Beamforming report polling. According to the method of claim 1, wherein, The frame sequence number information is included in the user information field or public information field of the third information frame. According to the method of claim 1, wherein, The first information frame also includes access point identification information of the second access point, which is associated with the key information. The key information is used by the second access point in the process of receiving the encrypted information. The method according to claim 10, wherein, There are multiple second access points, and the key information corresponding to different second access points may be the same or different. According to the method of claim 1, wherein, The second information frame also includes one of the following: The site identification information and the key information of the site, wherein the key information is used for encryption of the multicast frames of the site; The site information and the frame sequence number information of the site, wherein the frame sequence number information is used by the site to send the encrypted information; The site information, the key information, and the frame sequence number information of the site are used for the encryption of the multicast frames of the site. According to the method of claim 1, wherein, The fields containing the key information include one or more of the following: The identification information of the field; The length information of the field; The identification information of the key information; The length information of the key information; The frame sequence number information; The key information. According to the method of claim 1, wherein, Transmitting frame sequence number information to the station includes: Different frame sequence number information is allocated and transmitted during different channel probes. The method according to claim 1 further includes: The encrypted information is verified based on one or more of the key information and the frame sequence number information. According to the method of claim 1, wherein, The encryption information also includes the frame sequence number information used to encrypt the multicast frame. According to the method of claim 1, wherein, The third information frame also includes indication information, which instructs the site to return the encrypted information in one of the following ways: Unicast method; Multicast mode; Unicast encryption method; Multicast encryption method; Broadcast method; Broadcast encryption method. According to the method of claim 1, wherein, The first access point establishes an association with the site; or the first access point does not establish an association with the site. According to the method of claim 1, wherein, The step of decrypting the encrypted information based on the key information and the frame sequence number information to obtain the multicast frame includes: The frame sequence number information is transformed in association with the station to obtain the transformed frame sequence number information; The encrypted information is decrypted based on the transformed frame sequence number information and the key information to obtain the multicast frame. According to the method of claim 1, wherein, Transmitting frame sequence number information to the station includes: The reference frame sequence number information and the value range of the frame sequence number information are transmitted to the station, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range. The method according to claim 20 further includes: Before the station uses the frame sequence number information with the largest value in the frame sequence number information value range, it transmits the updated reference frame sequence number information and the updated frame sequence number information value range. The method according to claim 1 further includes: Obtain the request information transmitted by the site; Transmit response information, which includes updated reference frame sequence number information and the value range of the updated frame sequence number information. According to the method of claim 1, wherein, The frame sequence number information is contained in the first information frame and the second information frame, or the frame sequence number information is contained in the third information frame. An information processing method applied to a website, the method comprising: Obtain a first information frame, the first information frame including key information; Obtain frame sequence number information; The multicast frame is encrypted based on the key information and the frame sequence number information to obtain encrypted information; Transmit the encrypted information. The method according to claim 24, wherein, The multicast frame is encrypted based on the key information and the frame sequence number information to obtain encrypted information, including: Generate a message integrity code based on the key information and the frame sequence number information; The message integrity code is appended to the end of the encrypted multicast frame to obtain an encrypted message. The method according to claim 24, wherein, The encryption of the multicast frame based on the key information and the frame sequence number information to obtain encrypted information includes: The frame sequence number information is transformed to obtain the transformed frame sequence number information; The multicast frame is encrypted based on the transformed frame sequence number information and the key information to obtain encrypted information. The method according to claim 24, wherein, The frame sequence number information is contained in the first information frame or the third information frame. The method according to claim 24 further includes: Transmit request information; Obtain response information, which includes updated reference frame sequence number information and the value range of the updated frame sequence number information. The method according to claim 24, wherein, The acquisition of frame sequence number information includes: Obtain the reference frame sequence number information and the value range of the frame sequence number information, wherein the value range of the frame sequence number information is an explicit or implicit representation of the value range. The method according to claim 29 further includes: Obtain the updated baseline frame sequence number information and the range of values for the updated frame sequence number information; During each transmission of encrypted information, different frame sequence numbers within the range of the frame sequence number information are used. The method according to claim 24, wherein, The acquisition of frame sequence number information includes: Different frame sequence number information is obtained during different channel probing processes. An information processing method, applied to a second access point, the method comprising: Obtain a second information frame, the second information frame including key information; Obtain frame sequence number information; Obtain encrypted information, which includes information encrypted based on the key information and the frame sequence number information of the multicast frame; The encrypted information is decrypted based on the key information and the frame sequence number information to obtain the multicast frame. A first access point includes: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 1-23. A website includes: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any one of claims 24-31. A second access point, comprising: One or more processors; Storage device for storing one or more programs; When the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in claim 32. A storage medium storing a computer program that, when executed by a processor, implements the method of any one of claims 1-32. A computer program product includes a computer program that, when executed by a processor, implements the method according to any one of claims 1-32.