TW201743639A - Wireless local area network access control method and device - Google Patents
Wireless local area network access control method and device Download PDFInfo
- Publication number
- TW201743639A TW201743639A TW106111914A TW106111914A TW201743639A TW 201743639 A TW201743639 A TW 201743639A TW 106111914 A TW106111914 A TW 106111914A TW 106111914 A TW106111914 A TW 106111914A TW 201743639 A TW201743639 A TW 201743639A
- Authority
- TW
- Taiwan
- Prior art keywords
- signal strength
- received signal
- terminal
- area network
- local area
- Prior art date
Links
- 238000000034 method Methods 0.000 title claims abstract description 98
- 238000001514 detection method Methods 0.000 claims description 118
- 238000012795 verification Methods 0.000 claims description 20
- 238000004590 computer program Methods 0.000 claims description 14
- 230000004044 response Effects 0.000 claims description 9
- 238000011217 control strategy Methods 0.000 claims description 3
- 230000008569 process Effects 0.000 description 35
- 238000010586 diagram Methods 0.000 description 18
- 238000012545 processing Methods 0.000 description 14
- 238000004891 communication Methods 0.000 description 8
- 238000005516 engineering process Methods 0.000 description 6
- 230000006870 function Effects 0.000 description 5
- 238000012986 modification Methods 0.000 description 5
- 230000004048 modification Effects 0.000 description 5
- 238000009434 installation Methods 0.000 description 4
- 230000008054 signal transmission Effects 0.000 description 4
- 238000011161 development Methods 0.000 description 2
- 230000002093 peripheral effect Effects 0.000 description 2
- 238000000060 site-specific infrared dichroism spectroscopy Methods 0.000 description 2
- 238000003491 array Methods 0.000 description 1
- 230000002238 attenuated effect Effects 0.000 description 1
- 230000000052 comparative effect Effects 0.000 description 1
- 238000012905 input function Methods 0.000 description 1
- 230000007774 longterm Effects 0.000 description 1
- 238000004519 manufacturing process Methods 0.000 description 1
- 230000007246 mechanism Effects 0.000 description 1
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
- H04W12/068—Authentication using credential vaults, e.g. password manager applications or one time password [OTP] applications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W24/00—Supervisory, monitoring or testing arrangements
- H04W24/04—Arrangements for maintaining operational condition
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/06—Authentication
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W24/00—Supervisory, monitoring or testing arrangements
- H04W24/08—Testing, supervising or monitoring using real traffic
Landscapes
- Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Security & Cryptography (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
Description
本發明關於通信技術領域,尤其關於無線區域網路存取控制方法及裝置。 The present invention relates to the field of communication technologies, and in particular, to a wireless area network access control method and apparatus.
隨著無線網路以及互聯網等技術的發展,從計算和管理資料到網上購物和社交應用都存在著來自各種場合的無線網路存取需求。為了滿足日益增長的對無線網路的使用需求,無線網路存取設備的部署和使用越來越普及,尤其是無線區域網路存取設備的普及,使得用戶存取無線網路的成本降低。 With the development of technologies such as wireless networks and the Internet, there are wireless network access requirements from various occasions, from computing and management materials to online shopping and social applications. In order to meet the increasing demand for wireless networks, the deployment and use of wireless network access devices has become more and more popular, especially the popularity of wireless local area network access devices, which has reduced the cost of users accessing wireless networks. .
無線區域網路存取設備,通常也稱為無線路由器或無線閘道,可以是單純型AP(Access Point,存取點)與寬頻路由器(閘道)的一種結合體,是帶有無線覆蓋功能的路由器,主要應用於用戶上網和無線覆蓋。無線區域網路存取設備可以看作一個轉發器,連接寬頻網路通信介面,將寬頻網路信號通過天線轉發給附近的終端,比如,個人電腦、手持設備(如平板電腦、手機)等。 A wireless area network access device, also commonly referred to as a wireless router or wireless gateway, can be a combination of a simple AP (Access Point) and a broadband router (gateway) with wireless coverage. The router is mainly used for users to access the Internet and wireless coverage. The wireless local area network access device can be regarded as a transponder that connects to the broadband network communication interface and forwards the broadband network signal through the antenna to nearby terminals, such as personal computers, handheld devices (such as tablets, mobile phones).
無線區域網路存取設備採用Wi-Fi技術將終端以無線 方式互相連接或者存取互聯網。目前,一種無線區域網路存取控制方法是,對於無線區域網路存取設備信號覆蓋範圍內的終端,無需提供存取密碼,進行無條件存取,這種存取控制方法安全性較差;另一種是需要終端提供存取密碼,但對於未配置鍵盤或觸控式螢幕等輸入裝置的終端來說,由於無法輸入存取密碼因而無法存取無線區域網路,或者需要借助手機等終端進行存取,操作複雜。 Wireless LAN access devices use Wi-Fi technology to wirelessly connect terminals Ways to connect to each other or access the Internet. At present, a wireless local area network access control method is that, for a terminal within a coverage area of a wireless local area network access device, an access password is not required to provide an unconditional access, and the access control method is less secure; One is that the terminal needs to provide an access password, but for a terminal that does not have an input device such as a keyboard or a touch screen, the wireless local area network cannot be accessed because the access code cannot be input, or the terminal needs to be stored by using a mobile phone or the like. Take, the operation is complicated.
隨著技術的發展,目前越來越多種類的終端,比如各種智慧家居設備,需要透過無線區域網路存取設備存取互聯網,因而如何在兼顧安全性的情況下,簡化終端存取無線區域網路的操作,是目前亟需解決的問題。 With the development of technology, more and more types of terminals, such as various smart home devices, need to access the Internet through wireless local area network access devices, so how to simplify the terminal access wireless area while taking into consideration security The operation of the network is an urgent problem to be solved.
本發明實施例提供了一種無線區域網路存取控制方法及裝置,用以實現在兼顧安全性的情況下,無需對終端進行驗證即可存取無線區域網路。 The embodiment of the invention provides a wireless local area network access control method and device, which can be used to access a wireless local area network without verifying the terminal in consideration of security.
本發明實施例提供的無線區域網路存取控制方法,包括:獲取終端對無線區域網路存取設備發送的信號的接收信號強度;將所述接收信號強度與第一門限要求進行比較;若所述接收信號強度符合所述第一門限要求,則將所述終端存取無線區域網路;否則,對所述終端進行驗證。 The wireless local area network access control method provided by the embodiment of the present invention includes: acquiring a received signal strength of a signal sent by a terminal to a wireless local area network access device; comparing the received signal strength with a first threshold requirement; And if the received signal strength meets the first threshold requirement, the terminal accesses the wireless area network; otherwise, the terminal is verified.
可選地,所述第一門限為第一設定值;所述接收信號 強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值。 Optionally, the first threshold is a first set value; the receiving signal The strength meets the first threshold requirement, and the received signal strength is greater than or equal to the first set value.
可選地,所述第一門限為第一設定區間;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內。 Optionally, the first threshold is a first set interval; the received signal strength meets the first threshold requirement, and the received signal strength is within the first set interval.
可選地,若判定所述接收信號強度符合所述第一門限要求且將所述終端存取無線區域網路之後,還包括:將所述接收信號強度與第二門限要求進行比較,若所述接收信號強度符合所述第二門限要求,則對所述終端進行存取控制。 Optionally, if it is determined that the received signal strength meets the first threshold requirement and the terminal accesses the wireless local area network, the method further includes: comparing the received signal strength with a second threshold requirement, if When the received signal strength meets the second threshold requirement, access control is performed on the terminal.
可選地,對所述終端進行存取控制,包括:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度,並當檢測到接收信號強度不符合所述第一門限要求時,執行以下步驟之一:中斷所述終端的無線區域網路連接;對所述終端進行驗證,若驗證通過,則保持所述終端的無線區域網路連接,否則中斷所述終端的無線區域網路連接。 Optionally, performing access control on the terminal, including: detecting, according to a detection period, a received signal strength of a signal sent by the terminal to a wireless local area network access device, and detecting that the received signal strength does not meet the foregoing When a threshold is required, one of the following steps is performed: interrupting the wireless local area network connection of the terminal; verifying the terminal, if the verification is passed, maintaining the wireless local area network connection of the terminal, otherwise interrupting the terminal Wireless LAN connection.
可選地,根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度之前,還包括:根據所述接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度;其中,一個取值區間對應一個檢測週期長度,按照信號強度從大到小的順序,排列在前的取值區間所對應的檢測週期長度大於排列在後的取值區間所對應 的檢測週期長度。 Optionally, before detecting, by the detection period, the received signal strength of the signal sent by the terminal to the WLAN access device, the method further includes: determining, according to the value interval of the received signal strength, the corresponding value interval The length of the detection period; wherein, one value interval corresponds to a detection period length, and the length of the detection period corresponding to the previous value interval is greater than the value range corresponding to the arrangement according to the signal strength from large to small. The length of the detection cycle.
可選地,根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合所述第二門限要求,則還包括:根據當前檢測到的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度,根據確定出的檢測週期長度更新所述終端的檢測週期長度。 Optionally, when detecting the received signal strength of the signal sent by the terminal to the WLAN access device according to the detection period, if the detected received signal strength meets the second threshold requirement, the method further includes: according to the current The value interval of the detected received signal strength is determined, the length of the detection period corresponding to the value interval is determined, and the length of the detection period of the terminal is updated according to the determined length of the detection period.
可選地,根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合所述第一門限要求但不符合所述第二門限要求,則還包括:停止檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度。 Optionally, when the received signal strength of the signal sent by the terminal to the WLAN access device is detected according to the detection period, if the detected received signal strength meets the first threshold requirement but does not meet the second The threshold requirement further includes: stopping detecting the received signal strength of the signal sent by the terminal to the wireless local area network access device.
可選地,所述第一門限為第一設定值、所述第二門限為第二設定值,且所述第一設定值小於所述第二設定值;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度小於所述第二設定值。 Optionally, the first threshold is a first set value, the second threshold is a second set value, and the first set value is smaller than the second set value; A threshold requirement includes: the received signal strength is greater than or equal to the first set value; and the received signal strength meets the second threshold requirement, including: the received signal strength is less than the second set value.
可選地,所述第一門限為第一設定區間、所述第二門限為第二設定區間,且所述第二設定區間的上限小於所述第一設定區間的上限;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度在所述第二設定區間內。 Optionally, the first threshold is a first set interval, the second threshold is a second set interval, and an upper limit of the second set interval is smaller than an upper limit of the first set interval; the received signal strength Compliance with the first threshold requirement, including: the received signal strength is within the first set interval; and the received signal strength meets the second threshold requirement, including: the received signal strength is in the second setting Within the interval.
本發明實施例提供的無線區域網路存取設備,包括:獲取模組,用於獲取終端對無線區域網路存取設備發送的信號的接收信號強度;比較模組,用於將所述接收信號強度與第一門限要求進行比較;存取控制模組,用於在所述接收信號強度符合所述第一門限要求的情況下,將所述終端存取無線區域網路;否則,對所述終端進行驗證。 The wireless local area network access device provided by the embodiment of the present invention includes: an acquisition module, configured to acquire a received signal strength of a signal sent by the terminal to the wireless local area network access device; and a comparison module, configured to receive the The signal strength is compared with a first threshold requirement; the access control module is configured to access the wireless local area network when the received signal strength meets the first threshold requirement; otherwise, The terminal is verified.
本發明另外的實施例提供的無線區域網路存取設備,包括:收發器,用於收發無線信號;記憶體,用於儲存電腦程式指令;處理器,耦合到所述記憶體,用於讀取所述記憶體儲存的電腦程式指令,並作為回應,執行如下操作:獲取終端對無線區域網路存取設備發送的信號的接收信號強度;將所述接收信號強度與第一門限要求進行比較;若所述接收信號強度符合所述第一門限要求,則將所述終端存取無線區域網路;否則,對所述終端進行驗證。 A wireless local area network access device provided by another embodiment of the present invention includes: a transceiver for transmitting and receiving wireless signals; a memory for storing computer program instructions; and a processor coupled to the memory for reading Taking the computer program instructions stored in the memory, and in response, performing the following operations: acquiring the received signal strength of the signal sent by the terminal to the wireless local area network access device; comparing the received signal strength with the first threshold requirement And if the received signal strength meets the first threshold requirement, the terminal accesses the wireless area network; otherwise, the terminal is verified.
本發明的上述實施例中,無線區域網路存取設備可獲取終端對無線區域網路存取設備發送的信號的接收信號強度,將該接收信號強度與第一門限要求進行比較,若該接收信號強度符合第一門限要求,表明該終端當前距離無線區域網路存取設備在一設定範圍的可信區域內,此種情況 下,可將該終端存取無線區域網路,而無需對該終端進行驗證,否則,表明該終端當前距離無線區域網路存取設備在該設定範圍的可信區域外,此種情況下,需要對該終端進行驗證,從而在兼顧安全性的情況下,無需驗證即可存取無線區域網路,簡化了終端的存取操作。 In the above embodiment of the present invention, the wireless local area network access device may acquire the received signal strength of the signal sent by the terminal to the wireless local area network access device, and compare the received signal strength with the first threshold requirement, if the receiving The signal strength meets the first threshold requirement, indicating that the terminal is currently within a trusted area of the set range of the wireless local area network access device. In this case, the terminal can access the wireless local area network without verifying the terminal, otherwise, the terminal is currently located outside the trusted area of the set range from the wireless local area network access device, in this case, The terminal needs to be verified, so that the security of the terminal can be accessed without authentication, which simplifies the access operation of the terminal.
本發明實施例還提供了一種無線區域網路存取控制方法及裝置,用以針對不同情況採用不同的存取控制策略。 The embodiment of the invention further provides a wireless local area network access control method and device, which are used to adopt different access control strategies for different situations.
本發明實施例提供的無線區域網路存取控制方法,包括:獲取終端對無線區域網路存取設備發送的信號的接收信號強度;根據所述接收信號強度,確定對應的存取控制策略;根據確定出的存取控制策略,對所述終端進行無線區域網路存取控制。 The wireless local area network access control method provided by the embodiment of the present invention includes: acquiring a received signal strength of a signal sent by a terminal to a wireless local area network access device; and determining a corresponding access control policy according to the received signal strength; Performing wireless area network access control on the terminal according to the determined access control policy.
可選地,根據所述信號強度,確定對應的存取控制策略,包括:將所述接收信號強度與第一門限要求進行比較;若所述接收信號強度符合所述第一門限要求,則將所述終端存取無線區域網路;否則,對所述終端進行驗證。 Optionally, determining a corresponding access control policy according to the signal strength, including: comparing the received signal strength with a first threshold requirement; if the received signal strength meets the first threshold requirement, The terminal accesses the wireless local area network; otherwise, the terminal is authenticated.
可選地,所述第一門限為第一設定值;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值;或者,所述第一門限為第一設定區間;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內。 Optionally, the first threshold is a first set value; the received signal strength meets the first threshold requirement, and the received signal strength is greater than or equal to the first set value; or A threshold is a first set interval; the received signal strength meets the first threshold requirement, and the received signal strength is within the first set interval.
可選地,根據接收信號強度,確定對應的存取控制策 略,包括以下之一:若所述接收信號強度符合第一門限要求但不符合第二門限要求,則將所述終端存取無線區域網路;若所述接收信號強度不符合第一門限要求,則對所述終端進行驗證;若所述接收信號強度符合第一門限要求且符合第二門限要求,則將所述終端存取無線區域網路,並對所述終端進行存取控制。 Optionally, determining a corresponding access control policy according to the received signal strength Slightly, including one of the following: if the received signal strength meets the first threshold requirement but does not meet the second threshold requirement, the terminal accesses the wireless local area network; if the received signal strength does not meet the first threshold requirement And verifying the terminal; if the received signal strength meets the first threshold requirement and meets the second threshold requirement, the terminal accesses the wireless area network, and performs access control on the terminal.
可選地,對所述終端進行存取控制,包括:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度,並當檢測到接收信號強度不符合所述第一門限要求時,執行以下步驟之一;中斷所述終端的無線區域網路連接;對所述終端進行驗證,若驗證通過,則保持所述終端的無線區域網路連接,否則中斷所述終端的無線區域網路連接。 Optionally, performing access control on the terminal, including: detecting, according to a detection period, a received signal strength of a signal sent by the terminal to a wireless local area network access device, and detecting that the received signal strength does not meet the foregoing When a threshold is required, perform one of the following steps: interrupt the wireless local area network connection of the terminal; verify the terminal, if the verification passes, maintain the wireless local area network connection of the terminal, otherwise interrupt the terminal Wireless LAN connection.
可選地,根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度之前,還包括:根據所述接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度;其中,一個取值區間對應一個檢測週期長度,按照信號強度從大到小的順序,排列在前的取值區間所對應的檢測週期長度大於排列在後的取值區間所對應的檢測週期長度。 Optionally, before detecting, by the detection period, the received signal strength of the signal sent by the terminal to the WLAN access device, the method further includes: determining, according to the value interval of the received signal strength, the corresponding value interval The length of the detection period; wherein, one value interval corresponds to a detection period length, and the length of the detection period corresponding to the previous value interval is greater than the corresponding value interval according to the signal strength from large to small. The length of the cycle is detected.
可選地,根據檢測週期檢測所述終端對無線區域網路 存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合所述第二門限要求,則還包括:根據當前檢測到的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度;根據確定出的檢測週期長度更新所述終端的檢測週期長度。 Optionally, detecting the terminal to the wireless local area network according to the detection period When the received signal strength of the signal sent by the device is accessed, if the detected received signal strength meets the second threshold requirement, the method further includes: determining the value according to the value interval of the currently detected received signal strength The length of the detection period corresponding to the interval; updating the length of the detection period of the terminal according to the determined length of the detection period.
可選地,根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合第一門限要求但不符合所述第二門限要求,則還包括:停止檢測所述終端對所述無線區域網路存取設備發送的信號的接收信號強度。 Optionally, when the received signal strength of the signal sent by the terminal to the WLAN access device is detected according to the detection period, if the detected received signal strength meets the first threshold requirement but does not meet the second threshold requirement And further comprising: stopping detecting the received signal strength of the signal sent by the terminal to the wireless area network access device.
可選地,所述第一門限為第一設定值、所述第二門限為第二設定值,且所述第一設定值小於所述第二設定值;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度小於所述第二設定值。 Optionally, the first threshold is a first set value, the second threshold is a second set value, and the first set value is smaller than the second set value; A threshold requirement includes: the received signal strength is greater than or equal to the first set value; and the received signal strength meets the second threshold requirement, including: the received signal strength is less than the second set value.
可選地,所述第一門限為第一設定區間、所述第二門限為第二設定區間,且所述第二設定區間的上限小於所述第一設定區間的上限;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度在所述第二設定區間內。 Optionally, the first threshold is a first set interval, the second threshold is a second set interval, and an upper limit of the second set interval is smaller than an upper limit of the first set interval; the received signal strength Compliance with the first threshold requirement, including: the received signal strength is within the first set interval; and the received signal strength meets the second threshold requirement, including: the received signal strength is in the second setting Within the interval.
本發明另外的實施例提供的無線區域網路存取設備,包括: 獲取模組,用於獲取終端對無線區域網路存取設備發送的信號的接收信號強度;確定模組,用於根據所述接收信號強度,確定對應的存取控制策略;存取控制模組,用於根據確定出的存取控制策略,對所述終端進行無線區域網路存取控制。 A wireless area network access device provided by another embodiment of the present invention includes: Obtaining a module, configured to acquire a received signal strength of a signal sent by the terminal to the wireless local area network access device; and a determining module, configured to determine a corresponding access control policy according to the received signal strength; and the access control module And performing wireless area network access control on the terminal according to the determined access control policy.
本發明另外的實施例提供的無線區域網路存取設備,包括:收發器,用於收發無線信號;記憶體,用於儲存電腦程式指令;處理器,耦合到所述記憶體,用於讀取所述記憶體儲存的電腦程式指令,並作為回應,執行如下操作:獲取終端對無線區域網路存取設備發送的信號的接收信號強度;根據所述接收信號強度,確定對應的存取控制策略;根據確定出的存取控制策略,對所述終端進行無線區域網路存取控制。 A wireless local area network access device provided by another embodiment of the present invention includes: a transceiver for transmitting and receiving wireless signals; a memory for storing computer program instructions; and a processor coupled to the memory for reading Taking the computer program instructions stored in the memory, and in response, performing the following operations: acquiring the received signal strength of the signal sent by the terminal to the wireless local area network access device; determining the corresponding access control according to the received signal strength a policy; performing wireless area network access control on the terminal according to the determined access control policy.
本發明的上述實施例中,無線區域網路存取設備可獲取終端對無線區域網路存取設備發送的信號的接收信號強度,根據該接收信號強度確定對應的存取控制策略,並根據確定出的存取控制策略,對終端進行無線區域網路存取控制,從而實現對該終端進行存取控制。上述方案中,根據終端的接收信號強度區分不同的應用場,從而可針對不同的應用情況採用對應的無線區域網路存取控制策略進行 存取控制。 In the foregoing embodiment of the present invention, the wireless local area network access device may acquire the received signal strength of the signal sent by the terminal to the wireless local area network access device, determine a corresponding access control policy according to the received signal strength, and determine according to the determined The access control policy is implemented, and the wireless local area network access control is performed on the terminal, thereby implementing access control on the terminal. In the foregoing solution, different application fields are distinguished according to the received signal strength of the terminal, so that corresponding wireless local area network access control policies can be adopted for different application situations. Access control.
100‧‧‧系統架構 100‧‧‧System Architecture
110‧‧‧無線區域網路存取設備網路 110‧‧‧Wireless Area Network Access Device Network
201、202、203、204‧‧‧方法步驟 201, 202, 203, 204‧‧‧ method steps
501、502、503、504、505、506‧‧‧方法步驟 501, 502, 503, 504, 505, 506‧‧‧ method steps
801、802、803、804、805‧‧‧方法步驟 801, 802, 803, 804, 805‧‧‧ method steps
901、902、903‧‧‧方法步驟 901, 902, 903‧‧‧ method steps
1001‧‧‧獲取模組 1001‧‧‧Getting module
1002‧‧‧比較模組 1002‧‧‧Comparative Module
1003‧‧‧存取控制模組 1003‧‧‧Access Control Module
1101‧‧‧獲取模組 1101‧‧‧Getting module
1102‧‧‧確定模組 1102‧‧‧Determining modules
1103‧‧‧存取控制模組 1103‧‧‧Access Control Module
1201‧‧‧處理器 1201‧‧‧ processor
1202‧‧‧記憶體 1202‧‧‧ memory
1203‧‧‧收發器 1203‧‧‧ transceiver
1301‧‧‧處理器 1301‧‧‧ Processor
1302‧‧‧記憶體 1302‧‧‧ memory
1303‧‧‧收發器 1303‧‧‧Transceiver
圖1為本發明實施例適用的網路架構示意圖;圖2為本發明實施例提供的無線區域網路存取控制流程示意圖;圖3為本發明實施例提供的情況一下的無線區域網路存取控制示意圖;圖4為本發明實施例提供的情況二下的無線區域網路存取控制示意圖;圖5為本發明另一實施例提供的無線區域網路存取控制流程示意圖;圖6A和圖6B分別為本發明實施例中的第一門限和第二門限的示意圖;圖7為本發明實施例提供的情況三下的無線區域網路存取控制示意圖;圖8為本發明另一實施例提供的無線區域網路存取控制流程示意圖;圖9為本發明另一實施例提供的無線區域網路存取控制流程示意圖;圖10、圖11、圖12和圖13分別為本發明實施例提供的無線區域網路存取設備的結構示意圖。 1 is a schematic diagram of a network architecture applicable to an embodiment of the present invention; FIG. 2 is a schematic diagram of a wireless local area network access control flow according to an embodiment of the present invention; FIG. 3 is a schematic diagram of a wireless local area network according to an embodiment of the present invention. FIG. 4 is a schematic diagram of wireless local area network access control according to the second embodiment of the present invention; FIG. 5 is a schematic diagram of a wireless local area network access control flow according to another embodiment of the present invention; FIG. FIG. 6B is a schematic diagram of a first threshold and a second threshold in an embodiment of the present invention; FIG. 7 is a schematic diagram of wireless local area network access control in Case 3 according to an embodiment of the present invention; FIG. 8 is another embodiment of the present invention; FIG. 9 is a schematic diagram of a wireless local area network access control flow according to another embodiment of the present invention; FIG. 10, FIG. 11, FIG. 12, and FIG. A schematic diagram of the structure of a wireless local area network access device provided by the example.
下面結合附圖對本發明實施例進行詳細描述。 The embodiments of the present invention are described in detail below with reference to the accompanying drawings.
圖1示出了本發明的一些實施例可以在其中被實現的典型的網路系統(環境)架構100。系統架構100中包括無線區域網路存取設備110、網路120,以及多個終端130a至130n。 FIG. 1 illustrates a typical network system (environment) architecture 100 in which some embodiments of the present invention may be implemented. The system architecture 100 includes a wireless area network access device 110, a network 120, and a plurality of terminals 130a through 130n.
無線區域網路存取設備110與網路120耦合在一起,使得無線區域網路存取設備110可以使終端130a至130n與網路120進行資料交互。例如,無線區域網路存取設備110和網路120可以經由雙絞線電纜網路、同軸電纜網路、電話網絡或任何適當類型的連接網路進行連接。在一些實施例中,無線區域網路存取設備110和網路120可以採用無線方式連接,例如,無線連接方式可包括使用IEEE 802.11無線網路或基於無線電話服務,例如2G,3G、3.5G、4G、LTE(Long Term Evolution,長期演進)等網路。支援無線區域存取設備110和網路120之間的通信技術可包括乙太網(例如在IEEE 802.3系列標準中描述的)和/或其他合適類型的區域網路技術。在IEEE 802.11系列標準中的不同的無線協議的示例可包括IEEE 802.11a、IEEE 802.11b、IEEE 802.11g,IEEE 802.11n、IEEE 802.11ac、IEEE 802.11af、IEEE 802.11ah和IEEE 802.11ad。 The wireless local area network access device 110 is coupled to the network 120 such that the wireless local area network access device 110 can cause the terminals 130a through 130n to interact with the network 120 for data. For example, wireless local area network access device 110 and network 120 can be connected via a twisted pair cable network, a coaxial cable network, a telephone network, or any suitable type of connected network. In some embodiments, the wireless local area network access device 110 and the network 120 may be connected in a wireless manner. For example, the wireless connection may include using an IEEE 802.11 wireless network or based on a wireless telephone service, such as 2G, 3G, 3.5G. , 4G, LTE (Long Term Evolution) and other networks. Communication techniques between the supported wireless area access device 110 and the network 120 may include Ethernet (as described, for example, in the IEEE 802.3 series of standards) and/or other suitable types of area network technologies. Examples of different wireless protocols in the IEEE 802.11 family of standards may include IEEE 802.11a, IEEE 802.11b, IEEE 802.11g, IEEE 802.11n, IEEE 802.11ac, IEEE 802.11af, IEEE 802.11ah, and IEEE 802.11ad.
終端130a~130n可以連接到無線區域網路存取設備110並與其採用無線方式進行通信,例如,使用IEEE 802.11系列標準(例如,無線區域網路)。終端130a~ 130n與無線區域網路存取設備110之間可採用無線區域網路的網路連接技術。終端130a~130n可以是任何適當的計算或移動設備,比如可包括:智慧手機、平板電腦、筆記型電腦、個人數位助理(Personal Digital Assistant,PDA)或類似設備。終端130a~130n通常包括顯示器,並且可以包括適當的輸入裝置(為簡單起見圖中未示出),例如鍵盤、滑鼠或觸控板。顯示器可以包括輸入功能的觸敏螢幕。終端130a~130n的其他例子包括網路連接相機(或稱IP相機)、家庭感測器和其他智慧家居設備(例如,智慧冰箱,它可以連接到網際網路)。智慧家居設備等類型的終端,可能未配置有輸入裝置。 The terminals 130a-130n can be connected to and communicate wirelessly with the wireless local area network access device 110, for example, using an IEEE 802.11 family of standards (e.g., a wireless local area network). Terminal 130a~ A wireless local area network connection technology may be employed between the 130n and the wireless local area network access device 110. The terminals 130a-130n may be any suitable computing or mobile device, such as a smart phone, tablet, notebook, personal digital assistant (PDA) or the like. Terminals 130a-130n typically include a display and may include suitable input devices (not shown for simplicity), such as a keyboard, mouse, or trackpad. The display can include a touch sensitive screen for input functions. Other examples of terminals 130a-130n include network connected cameras (or IP cameras), home sensors, and other smart home devices (eg, smart refrigerators that can be connected to the Internet). Terminals such as smart home devices may not be equipped with input devices.
需要說明的是,本領域的普通技術人員能夠理解,圖1中的元件只是本實施例可以在其中被實現的電腦網路環境的一種實現方式,並且各種替代實施例在本發明實施例的範圍之內。例如,系統架構100可以進一步包括無線區域網路存取設備110、網路120以及終端130a~130n之間的中繼裝置,例如,所述中繼裝置可包括:交換機、路由器、集線器,數據機(光纖通信中尤其常見)、無線存取點(AP),網路控制器(WirelessAccessPointController)等。在一些實施例中,網路120包括網際網路,企業網intranet。 It should be noted that those skilled in the art can understand that the components in FIG. 1 are only one implementation of the computer network environment in which the embodiment can be implemented, and various alternative embodiments are within the scope of the embodiments of the present invention. within. For example, the system architecture 100 may further include a wireless area network access device 110, a network 120, and a relay device between the terminals 130a-130n. For example, the relay device may include: a switch, a router, a hub, a data machine. (especially common in fiber-optic communication), wireless access point (AP), network controller (Wireless Access Point Controller) and so on. In some embodiments, network 120 includes an internetwork, a corporate intranet.
基於上述網路架構,本發明實施例提供了一種無線區域網路存取控制方法,能夠在保證安全的前提下對終端驗證操作進行精簡,尤其針對需要存取區域網路的智慧家居 設備不具備輸入裝置的情況,可以在保證安全性的前提下,無需輸入密碼即可存取無線區域網路。 Based on the foregoing network architecture, the embodiment of the present invention provides a wireless local area network access control method, which can simplify the terminal verification operation under the premise of ensuring security, especially for a smart home that needs to access a regional network. If the device does not have an input device, you can access the wireless LAN without entering a password without any security.
本發明實施例提供的無線區域網路存取控制方法可在無線區域網路存取設備上實現。具體地,可透過以下方式使無線區域網路存取設備能夠實現本發明實施例提供的無線存取控制方法:- 出廠預裝方式即,將能夠實現本發明實施例提供的無線區域網路存取控制方法的程式按照在無線區域網路存取設備中,比如植入作業系統中,從而在設備出廠前就預裝到系統裡,並可進一步允許用戶透過網頁配置方式來設定是否啟用本發明實施例提供的存取控制方法;- 出廠後安裝即,在無線區域網路存取設備出廠後,以安裝包(比如ROM包)的形式,在無線區域網路存取設備中安裝能夠實現本發明實施例提供的無線區域網路存取控制方法的程式。 The wireless local area network access control method provided by the embodiment of the present invention can be implemented on a wireless local area network access device. Specifically, the wireless local area network access device can implement the wireless access control method provided by the embodiment of the present invention in the following manner: - the factory pre-installation mode, that is, the wireless local area network storage provided by the embodiment of the present invention can be implemented The program of the control method is installed in the wireless local area network access device, such as the embedded operating system, so that the device is pre-installed in the system before leaving the factory, and further allows the user to set whether to enable the present invention through the webpage configuration mode. The access control method provided by the embodiment; - after the factory installation, after the wireless local area network access device is shipped from the factory, the installation can be implemented in the wireless local area network access device in the form of an installation package (such as a ROM package) The program of the wireless area network access control method provided by the embodiment of the invention.
參見圖2,為本發明實施例提供的無線區域網路存取控制流程示意圖,該流程可由無線區域網路存取設備執行。如圖所示,該流程可包括如下步驟: 2 is a schematic flowchart of a wireless area network access control process according to an embodiment of the present invention, which may be performed by a wireless area network access device. As shown, the process can include the following steps:
步驟201:獲取終端對無線區域網路存取設備發送的信號的接收信號強度。 Step 201: Acquire a received signal strength of a signal sent by the terminal to the WLAN access device.
該步驟中,無線區域網路存取設備也可以在發現待存取的終端時,獲取該終端對無線區域網路存取設備發送的 信號的接收信號強度;無線區域網路存取設備也可在接收到終端發送的無線區域網路存取請求後,獲取該終端對無線區域網路存取設備發送的信號的接收信號強度。 In this step, the wireless local area network access device may also acquire the terminal to send to the wireless local area network access device when discovering the terminal to be accessed. The received signal strength of the signal; the wireless local area network access device may also acquire the received signal strength of the signal sent by the terminal to the wireless local area network access device after receiving the wireless local area network access request sent by the terminal.
例如,在一些實施例中,終端可基於發現機制,按照設定週期發送發現信號,用於探測周圍是否有可存取的無線區域網路。如果該發現信號被無線區域網路存取設備接收到,則無線區域網路存取設備可向該終端返回回應信號,進一步地,該回應信號中可攜帶無線區域網路的相關標識,比如SSID(Service Set Identifier,服務集標識)。終端在接收到該回應信號後,可向該無線區域網路存取設備發送請求存取該無線區域網路的存取請求消息。 For example, in some embodiments, the terminal may transmit a discovery signal according to a discovery mechanism according to a discovery period for detecting whether there is an accessible wireless local area network. If the discovery signal is received by the wireless local area network access device, the wireless local area network access device may return a response signal to the terminal, and further, the response signal may carry a related identifier of the wireless local area network, such as an SSID. (Service Set Identifier). After receiving the response signal, the terminal may send an access request message requesting access to the wireless local area network to the wireless local area network access device.
再例如,在另一些實施例中,無線區域網路存取設備可按照設定週期廣播發現消息,其中可攜帶無線區域網路的SSID。終端接收到該發現消息後,可向該無線區域網路存取設備發送請求存取該無線區域網路的存取請求消息。 For another example, in other embodiments, the wireless local area network access device may broadcast a discovery message according to a set period, where the SSID of the wireless local area network may be carried. After receiving the discovery message, the terminal may send an access request message requesting access to the wireless local area network to the wireless local area network access device.
終端對無線區域網路存取設備發送的信號的接收信號強度,可用分貝毫伏(或稱分貝毫瓦,表示為dBm)值表示。dBm可表徵信號衰減的程度,比如,-40dBm與-30dBm相比,前者的信號衰減程度高於後者。 The received signal strength of the signal transmitted by the terminal to the wireless local area network access device may be expressed in decibel millivolts (or decibel milliwatts, expressed as dBm). dBm can characterize the degree of signal attenuation. For example, -40dBm is more attenuated than -30dBm.
無線區域網路存取設備可透過多種方式獲取終端的接收信號強度。在實際應用中,終端發送的資料包中包含信號強度相關參數,比如Rx參數(Rx參數用於描述終端對無線區域網路存取設備發送的信號的接收信號強度,具體 指接收機接收到通道頻寬上的寬頻接收功率)。該參數可被保存在無線區域網路存取設備中的Wi-Fi晶片的設備驅動參數中,因此可從Wi-Fi晶片的設備驅動參數中獲取該參數。 The wireless local area network access device can obtain the received signal strength of the terminal in multiple ways. In practical applications, the data packet sent by the terminal includes signal strength related parameters, such as Rx parameters (the Rx parameter is used to describe the received signal strength of the signal sent by the terminal to the wireless local area network access device, specifically Refers to the receiver receiving the broadband received power on the channel bandwidth). This parameter can be stored in the device driver parameters of the Wi-Fi chip in the wireless local area network access device, so this parameter can be obtained from the device driver parameters of the Wi-Fi chip.
步驟202:將終端的接收信號強度與第一門限要求進行比較,若該接收信號強度符合第一門限要求,則轉入步驟203,否則轉入步驟204。 Step 202: Compare the received signal strength of the terminal with the first threshold requirement. If the received signal strength meets the first threshold requirement, go to step 203, otherwise go to step 204.
其中,第一門限具體可以是設定值,也可以是設定區間。相應地,所述第一門限要求,則根據第一門限是設定值還是設定區間而不同,例如,如果第一門限是第一設定值,則接收信號強度符合第一門限要求,可以包括:接收信號強度大於或等於該第一設定值;若第一門限是第一設定區間,則接收信號強度符合第一門限要求,可以包括:接收信號強度在該第一設定區間內。具體實施時,第一設定區間的上限值可根據無線區域網路存取設備的發送功率進行設定,比如設定為與該發送功率相當的取值,這樣,若接收信號強度在該第一設定區間內,則認為符合第一門限要求。 The first threshold may specifically be a set value or a set interval. Correspondingly, the first threshold requirement is different according to whether the first threshold is a set value or a set interval. For example, if the first threshold is the first set value, the received signal strength meets the first threshold requirement, and may include: receiving The signal strength is greater than or equal to the first set value; if the first threshold is the first set interval, the received signal strength meets the first threshold requirement, and may include: the received signal strength is within the first set interval. In a specific implementation, the upper limit value of the first set interval may be set according to the transmit power of the wireless local area network access device, for example, set to a value corresponding to the transmit power, such that if the received signal strength is in the first setting Within the interval, it is considered to meet the first threshold requirement.
其中,第一設定值或第一設定區間的具體取值可以是用於表徵信號強度的數值,比如可以是表示dBm值。 The specific value of the first set value or the first set interval may be a value used to represent the signal strength, for example, may be a dBm value.
所述第一門限要求可用於界定以無線區域網路存取設備為中心的一個區域範圍的邊界,如圖3所示。第一門限為第一設定值時,第一設定值所界定的區域範圍內,對於無線區域網路存取設備來說,其發送的信號衰減程度不超 過第一設定值所表示的衰減程度;反之,該區域範圍外,無線區域網路存取設備發送的信號衰減程度超過第一設定值所表示的衰減程度。可將由第一設定值所界定的上述區域稱為可信區域,這樣,根據終端的接收信號強度就可以判斷該終端位於可信區域內還是可信區域外,進而可採用不同的存取控制策略進行存取控制。 The first threshold requirement can be used to define a region-wide boundary centered on a wireless local area network access device, as shown in FIG. When the first threshold is the first set value, the signal attenuation level of the wireless local area network access device is not exceeded in the area defined by the first set value. The degree of attenuation indicated by the first set value; conversely, outside the area, the degree of attenuation of the signal transmitted by the wireless local area network access device exceeds the degree of attenuation indicated by the first set value. The above-mentioned area defined by the first set value may be referred to as a trusted area, so that it is possible to determine whether the terminal is located in the trusted area or outside the trusted area according to the received signal strength of the terminal, and thus different access control strategies may be employed. Perform access control.
所述第一門限(如上述第一設定值或第一設定區間)的取值可預先設定,進一步可允許用戶根據需要進行設定或修改。 The value of the first threshold (such as the first set value or the first set interval) may be preset, and further allows the user to set or modify as needed.
步驟203:將終端存取無線區域網路。 Step 203: The terminal accesses the wireless local area network.
步驟203中,由於終端的接收信號強度符合第一門限要求,因此認為該終端位於可信區域,進而無需該終端提供存取密碼即可將該終端存取無線區域網路。 In step 203, since the received signal strength of the terminal meets the first threshold requirement, the terminal is considered to be located in the trusted area, and the terminal can access the wireless local area network without providing the access password.
步驟204:對終端進行驗證。比如,按照現有方式進行存取控制,具體地,基於存取密碼進行存取控制。更具體地,無線區域網路存取設備請求該終端發送無線區域網路存取密碼;該終端根據該請求獲取存取密碼(比如獲取用戶透過輸入裝置輸入的存取密碼),併發送給該無線區域網路存取設備;該無線區域網路存取設備對該終端發送的無線區域網路存取密碼進行驗證,若驗證通過,則將該終端存取無線區域網路,否則拒絕將該終端存取無線區域網路。 Step 204: Verify the terminal. For example, access control is performed in accordance with an existing method, and specifically, access control is performed based on an access password. More specifically, the wireless local area network access device requests the terminal to send a wireless local area network access password; the terminal acquires an access password according to the request (such as obtaining an access password input by the user through the input device), and sends the password to the a wireless local area network access device; the wireless local area network access device verifies the wireless local area network access password sent by the terminal, and if the verification passes, the terminal accesses the wireless local area network, otherwise the network device refuses to The terminal accesses the wireless local area network.
透過以上描述可以看出,無線區域網路存取設備可將終端對無線區域網路存取設備發送的信號的接收信號強度 與第一門限要求進行比較,若終端的接收信號強度符合第一門限要求,表明該終端當前距離無線區域網路存取設備在一設定範圍的可信區域內,此種情況下,可將該終端存取無線區域網路,而無需對該終端進行驗證(比如對該終端提供的存取密碼等資訊進行驗證),從而在兼顧安全性的情況下,無需驗證即可將終端存取無線區域網路,簡化了終端的存取操作。 As can be seen from the above description, the wireless local area network access device can transmit the received signal strength of the signal transmitted by the terminal to the wireless local area network access device. Comparing with the first threshold requirement, if the received signal strength of the terminal meets the first threshold requirement, it indicates that the terminal is currently within a trusted range of the wireless local area network access device, in which case the The terminal accesses the wireless local area network without verifying the terminal (such as verifying the access password and the like provided by the terminal), so that the terminal can access the wireless area without authentication without considering the security. The network simplifies the access operation of the terminal.
舉例來說,無線區域網路存取設備的信號覆蓋範圍為以該無線區域網路存取設備為中心的圓形區域,其半徑為100米。該無線區域網路存取設備在一面積為100m2的房間中使用,需要存取的終端包括智慧家居設備、手機和筆記型電腦等。這種情況下,可將以無線區域網路存取設備為中心的半徑為30米的區域視為可信區域,根據該半徑、無線區域網路存取設備的信號發送功率以及信號衰減規律計算得到對應的第一門限。採用上述實施例,該房間內的智慧家居設備或者房間內的用戶所攜帶的手機,由於位於該可信區域內,其接收信號強度通常會大於第一門限,因此無需存取密碼即可透過該無線區域網路存取設備存取網路。而該可信區域外的終端被視為不可控終端,則需要存取密碼才能透過該無線區域網路存取網路。可以看出,對於可信區域內的終端,比如智慧家居設備、家庭成員的手機、來訪者的手機等,簡化了其存取區域網路操作的複雜度,尤其對無輸入裝置的智慧家居設備來說,方便了智慧家居設備的存取操作。 For example, the coverage area of the wireless local area network access device is a circular area centered on the wireless local area network access device, and has a radius of 100 meters. The wireless local area network access device is used in a room of 100 m 2 , and the terminals that need to be accessed include smart home devices, mobile phones, and notebook computers. In this case, an area with a radius of 30 meters centered on the wireless local area network access device can be regarded as a trusted area, and the signal transmission power and signal attenuation law of the wireless local area network access device are calculated according to the radius. Get the corresponding first threshold. According to the above embodiment, the smart home device in the room or the mobile phone carried by the user in the room is located in the trusted area, and the received signal strength is usually greater than the first threshold, so the password can be accessed without accessing the password. The wireless local area network access device accesses the network. If the terminal outside the trusted area is regarded as an uncontrollable terminal, an access password is required to access the network through the wireless local area network. It can be seen that the terminals in the trusted area, such as the smart home device, the mobile phone of the family member, the mobile phone of the visitor, etc., simplify the complexity of the operation of the access area network, especially the smart home device without the input device. In this case, it facilitates the access operation of smart home devices.
進一步地,在一些實施例中,還可以將可信區域進一步細分為絕對可信區域(即無條件可信區域)和有條件可信區域,如圖4所示。其中,有條件可信區域的外邊界可透過第一門限界定,絕對可信區域的邊界可透過第二門限界定。其中,第二門限具體可以是設定值,也可以是設定區間。相應地,第二門限要求,則根據第二門限是設定值還是設定區間而不同。 Further, in some embodiments, the trusted area may be further subdivided into an absolutely trusted area (ie, an unconditional trusted area) and a conditional trusted area, as shown in FIG. The outer boundary of the conditionally trusted region may be defined by a first threshold, and the boundary of the absolute trusted region may be defined by a second threshold. The second threshold may specifically be a set value or a set interval. Correspondingly, the second threshold requirement is different depending on whether the second threshold is a set value or a set interval.
舉例來說,無線區域網路存取設備的信號覆蓋範圍為以該無線區域網路存取設備為中心的圓形區域,其半徑為100米。該無線區域網路存取設備在一面積為100m2的房間中使用,需要存取的終端包括智慧家居設備、手機和筆記型電腦等。這種情況下,可將以無線區域網路存取設備為中心的半徑為30米的區域視為可信區域,根據該半徑、無線區域網路存取設備的信號發送功率以及信號衰減演算法公式可計算得到對應的第一門限,並將以無線區域網路存取設備為中心的半徑為10米的區域視為可信區域,根據該半徑、無線區域網路存取設備的信號發送功率以及信號衰減規律計算得到對應的第二門限。 For example, the coverage area of the wireless local area network access device is a circular area centered on the wireless local area network access device, and has a radius of 100 meters. The wireless local area network access device is used in a room of 100 m 2 , and the terminals that need to be accessed include smart home devices, mobile phones, and notebook computers. In this case, an area with a radius of 30 meters centered on the wireless local area network access device can be regarded as a trusted area, according to the radius, the signal transmission power of the wireless local area network access device, and the signal attenuation algorithm. The formula can calculate the corresponding first threshold, and treat the area with a radius of 10 meters centered on the wireless local area network access device as a trusted area, according to which the signal transmission power of the wireless local area network access device And the signal attenuation law is calculated to obtain a corresponding second threshold.
可選地,所述第一門限(如第一設定值或第一設定區間)和所述第二門限(如第二設定值或第二設定區間)的取值可預先設定,進一步可允許用戶根據需要進行設定或修改。 Optionally, the values of the first threshold (such as the first set value or the first set interval) and the second threshold (such as the second set value or the second set interval) may be preset, and further allow the user Make settings or modifications as needed.
基於此,圖5示出了本發明實施例提供的存取控制流程,該流程可由無線區域網路存取設備執行,該流程包括 如下步驟: Based on this, FIG. 5 shows an access control procedure provided by an embodiment of the present invention, which may be performed by a wireless area network access device, and the process includes The following steps:
步驟501:獲取終端對無線區域網路存取設備發送的信號的接收信號強度。該步驟的具體實現過程與圖2中的步驟201相同,在此不在重複。 Step 501: Acquire a received signal strength of a signal sent by the terminal to the WLAN access device. The specific implementation process of this step is the same as step 201 in FIG. 2, and is not repeated here.
步驟502:將終端的接收信號強度與第一門限要求進行比較,若該信號強度符合第一門限要求,則轉入步驟503。 Step 502: Compare the received signal strength of the terminal with the first threshold requirement. If the signal strength meets the first threshold requirement, proceed to step 503.
步驟503:將終端存取無線區域網路,並轉入步驟504。 Step 503: The terminal accesses the wireless local area network, and proceeds to step 504.
該步驟中,如果終端的接收信號強度符合第一門限要求,表明該終端位於可信區域,進而無需該終端提供存取密碼即可將該終端存取無線區域網路。 In this step, if the received signal strength of the terminal meets the first threshold requirement, the terminal is located in the trusted area, and the terminal can access the wireless local area network without providing the access password.
步驟504:將步驟501中獲取到的終端的接收信號強度與第二門限要求進行比較,若該接收信號強度符合第二門限要求,則轉入步驟505,否則可保持該終端的網路存取狀態,結束本流程。 Step 504: Compare the received signal strength of the terminal acquired in step 501 with the second threshold requirement. If the received signal strength meets the second threshold requirement, proceed to step 505, otherwise the network access of the terminal may be maintained. Status, end this process.
如前所述,第一門限和第二門限可分別是設定值或設定區間,相應地,步驟504可包括以下幾種典型情況: As described above, the first threshold and the second threshold may be set values or set intervals, respectively. Accordingly, step 504 may include the following typical cases:
情況1:第一門限為第一設定值、第二門限為第二設定值,且第一設定值小於第二設定值。此種情況下,若接收信號強度大於或等於第一設定值,則認為接收信號強度符合第一門限要求;若接收信號強度小於第二設定值,則認為接收信號強度符合第二門限要求。 Case 1: The first threshold is the first set value, the second threshold is the second set value, and the first set value is less than the second set value. In this case, if the received signal strength is greater than or equal to the first set value, the received signal strength is considered to meet the first threshold requirement; if the received signal strength is less than the second set value, the received signal strength is considered to meet the second threshold requirement.
如圖6A所示,如果接收信號強度落入區間A,則認 為符合第一門限要求,即終端位於可信區域(有可能位於有條件可信區域,也有可能位於絕對可信區域),此種情況下,進行存取時可不對該終端進行驗證;如果接收信號強度落入區間B,則認為符合第二門限要求,則終端位於可信區域中的有條件可信區域,此種情況下,存取時可不對該終端進行驗證,但後續可對該終端進行存取控制。 As shown in FIG. 6A, if the received signal strength falls within the interval A, then In order to meet the first threshold requirement, that is, the terminal is located in the trusted area (possibly located in the conditionally trusted area or in the absolute trusted area). In this case, the terminal may not be authenticated when accessing; if receiving If the signal strength falls within the interval B, it is considered that the second threshold is met, and the terminal is located in the conditionally trusted area in the trusted area. In this case, the terminal may not be authenticated during access, but the terminal may be subsequently Perform access control.
情況2:第一門限為第一設定區間、第二門限為第二設定區間,且第二設定區間的上限小於第一設定區間的上限。此種情況下,若接收信號強度在第一設定區間內,則認為接收信號強度符合第一門限要求;若接收信號強度在第二設定區間內,則認為接收信號強度符合第二門限要求。 Case 2: The first threshold is the first setting interval, the second threshold is the second setting interval, and the upper limit of the second setting interval is smaller than the upper limit of the first setting interval. In this case, if the received signal strength is within the first set interval, the received signal strength is considered to meet the first threshold requirement; if the received signal strength is within the second set interval, the received signal strength is considered to meet the second threshold requirement.
如圖6B所示,如果接收信號強度落入第一設定區間,則認為符合第一門限要求,即終端位於可信區域(有可能位於有條件可信區域,也有可能位於絕對可信區域),此種情況下,進行存取時可不對該終端進行驗證;如果接收信號強度落入第二設定區間,則認為符合第二門限要求,則終端位於可信區域中的有條件可信區域,此種情況下,存取時可不對該終端進行驗證,但後續可對該終端進行存取控制。 As shown in FIG. 6B, if the received signal strength falls within the first set interval, it is considered to meet the first threshold requirement, that is, the terminal is located in the trusted area (possibly located in the conditionally trusted area, and may also be located in the absolute trusted area). In this case, the terminal may not be verified when accessing; if the received signal strength falls within the second set interval, it is considered that the second threshold is met, and the terminal is located in the conditionally trusted area in the trusted area. In this case, the terminal may not be authenticated during access, but subsequent access control may be performed on the terminal.
當然,上述情況僅給出了實際應用中比較典型的情況,其他情況下的處理方式可參照上述原理實現,在此不再一一列舉。 Of course, the above situation only gives a typical situation in practical applications. In other cases, the processing manner can be implemented by referring to the above principle, and will not be enumerated here.
步驟505:對該終端進行存取控制。 Step 505: Perform access control on the terminal.
可選地,步驟505中,可採用以下方式對終端進行存取控制:根據檢測週期檢測該終端對無線區域網路存取設備發送的信號的接收信號強度,並當檢測到信號強度不符合第一門限要求(如小於第一設定值時,表明終端位於不可信區域),執行以下操作中的一種:操作1:中斷該終端的無線區域網路連接;操作2:對該終端進行驗證,若驗證通過,則保持該終端的無線區域網路連接,否則中斷該終端的無線區域網路連接。更具體地,可請求該終端發送無線區域網路進入帳號,根據該帳號對該終端進行驗證。 Optionally, in step 505, the terminal may be accessed and controlled by: detecting, according to the detection period, a received signal strength of the signal sent by the terminal to the wireless area network access device, and detecting that the signal strength does not meet the A threshold requirement (if less than the first set value, indicating that the terminal is in an untrusted area), performing one of the following operations: operation 1: interrupting the wireless local area network connection of the terminal; operation 2: verifying the terminal, if If the verification is passed, the wireless local area network connection of the terminal is maintained, otherwise the wireless local area network connection of the terminal is interrupted. More specifically, the terminal may be requested to send a wireless local area network to enter an account, and the terminal is verified according to the account.
上述流程中,透過將終端的接收信號強度與第二門限要求進行比較,可以確定終端當前處於絕對可信區域還是位於有條件可信區域。如果終端的接收信號強度符合第二門限要求,則表明終端位於有條件可信區域,為了提高安全性,可按照設定的檢測週期對該終端的接收信號強度進行檢測,一旦檢測到終端的接收信號強度不符合第一門限要求時,表明該終端已經移出可信區域,此種情況下,為提高安全性,可斷開該終端的無線區域網路連接,或者對該終端進行驗證,只有驗證通過的情況下才允許該終端透過該無線區域網路存取設備進行網路存取。 In the above process, by comparing the received signal strength of the terminal with the second threshold requirement, it can be determined whether the terminal is currently in an absolute trusted area or in a conditionally trusted area. If the received signal strength of the terminal meets the second threshold requirement, it indicates that the terminal is located in the conditionally trusted area. In order to improve security, the received signal strength of the terminal may be detected according to the set detection period, and the received signal of the terminal is detected once the terminal is detected. If the strength does not meet the first threshold requirement, it indicates that the terminal has been removed from the trusted area. In this case, to improve security, the wireless area network connection of the terminal may be disconnected, or the terminal may be verified, and only the verification is passed. In this case, the terminal is allowed to access the network through the wireless local area network access device.
可選地,在一些實施例中,如果步驟505中,無線區域網路存取設備根據檢測週期度該終端的接收信號強度進行檢測時,若檢測到接收信號強度符合第一門限要求但不符合第二門限要求(如圖6A中的區間C,或者圖6B中的 絕對可信區域所對應的區間),則表明終端此時處於絕對可信區域,此種情況下,可停止檢測該終端對該無線區域網路存取設備發送的信號的接收信號強度。 Optionally, in some embodiments, if the wireless local area network access device detects the received signal strength of the terminal according to the detection period in step 505, if the received signal strength is detected to meet the first threshold requirement, the data does not match. The second threshold requirement (such as interval C in Figure 6A, or in Figure 6B) The interval corresponding to the absolute trusted area indicates that the terminal is in an absolute trusted area at this time. In this case, the received signal strength of the signal sent by the terminal to the wireless local area network access device may be stopped.
進一步地,若步驟502中,將終端的存取信號強度與第一門限要求進行比較的結果為:終端的接收信號強度不符合第一門限要求,表明終端位於不可信區域,則可轉入步驟506:對該終端進行驗證,比如,基於存取密碼進行存取控制。具體地,無線區域網路存取設備請求該終端發送無線區域網路存取密碼;該終端根據該請求獲取存取密碼(比如獲取用戶透過輸入裝置輸入的存取密碼),併發送給該無線區域網路存取設備;該無線區域網路存取設備對該終端發送的無線區域網路存取密碼進行驗證,若驗證通過,則將該終端存取無線區域網路,否則拒絕將該終端存取無線區域網路。 Further, if the access signal strength of the terminal is compared with the first threshold requirement in step 502, the received signal strength of the terminal does not meet the first threshold requirement, indicating that the terminal is located in the untrusted area, and the step may be transferred to the step. 506: Verify the terminal, for example, access control based on the access password. Specifically, the wireless local area network access device requests the terminal to send a wireless local area network access password; the terminal acquires an access password according to the request (such as acquiring an access password input by the user through the input device), and sends the wireless password to the wireless device. a regional network access device; the wireless local area network access device verifies the wireless local area network access password sent by the terminal, and if the verification passes, the terminal accesses the wireless local area network, otherwise the terminal is rejected. Access wireless local area network.
透過以上描述可以看出,無線區域網路存取設備可將終端對無線區域網路存取設備發送的信號的接收信號強度與第一門限要求進行比較,若終端的接收信號強度符合第一門限要求,表明該終端當前距離無線區域網路存取設備在一設定範圍的可信區域內,此種情況下,可將該終端存取無線區域網路,而無需對該終端進行驗證,從而在兼顧安全性的情況下,無需對終端驗證即可將終端存取無線區域網路,簡化了終端的存取操作。進一步地,可將可信區域劃分為絕對可信區域和有條件可信區域,對於絕對可信區域內的終端,將其存取無線區域網路後不再進行存取控 制,而對於有條件可信區域內的終端,在將其存取無線區域網路後可對接收信號強度進行檢測,若檢測其移出可信區域,則為了安全性考慮,對其進行存取控制,比如對其進行基於存取密碼的網路存取控制。 As can be seen from the above description, the wireless local area network access device can compare the received signal strength of the signal sent by the terminal to the wireless local area network access device with the first threshold requirement, if the received signal strength of the terminal meets the first threshold. The request indicates that the terminal is currently within a set range of trusted area from the wireless local area network access device. In this case, the terminal can access the wireless local area network without verifying the terminal, thereby In the case of security, the terminal can access the wireless local area network without verifying the terminal, which simplifies the access operation of the terminal. Further, the trusted area can be divided into an absolute trusted area and a conditionally trusted area, and the terminal in the absolutely trusted area is not accessed after accessing the wireless local area network. For the terminal in the conditional trusted area, the received signal strength can be detected after accessing the wireless local area network, and if it is detected to be removed from the trusted area, it is accessed for security reasons. Control, such as accessing password-based network access control.
進一步地,在一些實施例中,還可以將有條件可信區域進一步細分為多個不同可信等級的區域,為描述方便,下面以按照無線區域網路存取設備的信號發送方向,將可信區域區分為:絕對可信區域、第一等級可信區域、第二等級可信區域,以此類推,按照該順序,可信度依次降低。 Further, in some embodiments, the conditional trusted area may be further subdivided into multiple areas of different trusted levels. For convenience of description, the following may be performed according to the signal sending direction of the wireless local area network access device. The letter area is divided into: an absolute trusted area, a first-level trusted area, a second-level trusted area, and so on, and in this order, the credibility is sequentially reduced.
如圖7所示,以第一門限和第二門限為用於表徵信號強度的數值(比如可為dBm值)為例,其中,有條件可信區域的最外邊界可透過第一門限界定,絕對可信區域的邊界可透過第二門限界定,第二門限大於第一門限,所述第二門限到第一門限之間的信號強度被劃分為N個取值區間,N為大於1的整數,一個取值區間對應一種等級的可信區域,一種等級的可信區域(也即一個取值區間)對應一個檢測週期長度,按照信號強度從大到小的順序,排列在前的取值區間所對應的檢測週期長度大於排列在後的取值區間所對應的檢測週期長度。若第一門限和第二門限分別為第一設定區間和第二設定區間(如圖6B所示),則第二設定區間可被劃分為N個取值區間。 As shown in FIG. 7, the first threshold and the second threshold are used as values for characterizing the signal strength (for example, a dBm value), wherein the outermost boundary of the conditionally trusted region can be defined by the first threshold. The boundary of the absolute trusted area may be defined by a second threshold, the second threshold being greater than the first threshold, and the signal strength between the second threshold and the first threshold is divided into N value intervals, and N is an integer greater than 1. One value interval corresponds to a level of trusted area, and a level of trusted area (ie, an value interval) corresponds to a detection period length, and the previous value interval is arranged according to the order of signal strength from large to small. The length of the corresponding detection period is greater than the length of the detection period corresponding to the subsequent value interval. If the first threshold and the second threshold are the first set interval and the second set interval respectively (as shown in FIG. 6B), the second set interval may be divided into N value intervals.
舉例來說,無線區域網路存取設備的信號覆蓋範圍為以該無線區域網路存取設備為中心的圓形區域,其半徑為 100米。該無線區域網路存取設備在一面積為100m2的房間中使用,需要存取的終端包括智慧家居設備、手機和筆記型電腦等。這種情況下,如圖6所示,可將以無線區域網路存取設備為中心的半徑為10米的區域視為絕對可信區域,根據該半徑、無線區域網路存取設備的信號發送功率以及信號衰減規律計算得到對應的第二門限;將以無線區域網路存取設備為中心的半徑為30、50米的區域分別視為不同等級的有條件可信區域,根據這些半徑、無線區域網路存取設備的信號發送功率以及信號衰減演算法公式可計算得到對應的第一門限(由50米半徑界定),以及不同等級的有條件可信區域邊界所對應的門限。 For example, the coverage area of the wireless local area network access device is a circular area centered on the wireless local area network access device, and has a radius of 100 meters. The wireless local area network access device is used in a room of 100 m 2 , and the terminals that need to be accessed include smart home devices, mobile phones, and notebook computers. In this case, as shown in FIG. 6, an area having a radius of 10 meters centered on the wireless local area network access device can be regarded as an absolutely trusted area, and the signal of the wireless local area network access device is used according to the radius. The transmit power and the signal attenuation law are calculated to obtain a corresponding second threshold; the regions with a radius of 30 and 50 meters centered on the wireless local area network access device are regarded as different levels of conditional trusted regions, according to these radii, The signal transmission power and signal attenuation algorithm formula of the wireless local area network access device can calculate a corresponding first threshold (defined by a radius of 50 meters) and a threshold corresponding to a boundary of a conditional trusted area of different levels.
可選地,所述第一門限和所述第二門限以及各等級的可信區域的邊界所對應的接收信號強度門限的取值可預先設定,進一步可允許用戶根據需要進行設定或修改。 Optionally, the value of the received signal strength threshold corresponding to the boundary of the first threshold and the second threshold and the trusted area of each level may be preset, and further may allow the user to perform setting or modification as needed.
基於此,圖8示出了本發明實施例提供的存取控制流程,該流程可由無線區域網路存取設備執行,該流程包括如下步驟: Based on this, FIG. 8 shows an access control procedure provided by an embodiment of the present invention, which may be performed by a wireless area network access device, and the process includes the following steps:
步驟801:獲取終端對無線區域網路存取設備發送的信號的接收信號強度。該步驟的具體實現過程與圖2中的步驟201相同,在此不在重複。 Step 801: Acquire a received signal strength of a signal sent by the terminal to the WLAN access device. The specific implementation process of this step is the same as step 201 in FIG. 2, and is not repeated here.
步驟802:將終端的接收信號強度與第一門限要求以及第二門限要求進行比較,若該接收信號強度符合第一門限要求,表明終端位於可信區域,則轉入步驟803;若該接收信號強度符合第二門限要求,表明終端位於可信區域 中的有條件可信區域,則轉入步驟804。進一步地,若該接收信號強度不符合第一門限要求,表明終端位於不可信區域,則轉入步驟805; Step 802: Compare the received signal strength of the terminal with the first threshold requirement and the second threshold requirement. If the received signal strength meets the first threshold requirement, indicating that the terminal is located in the trusted area, proceed to step 803; if the received signal The strength meets the second threshold requirement, indicating that the terminal is located in the trusted area If there is a conditional trusted area, then go to step 804. Further, if the received signal strength does not meet the first threshold requirement, indicating that the terminal is located in the untrusted area, then proceeds to step 805;
步驟803:將終端存取無線區域網路。 Step 803: The terminal accesses the wireless local area network.
該步驟中,如果終端的接收信號強度符合第一門限要求,表明該終端位於可信區域,進而無需對該終端進行驗證即可將該終端存取無線區域網路。 In this step, if the received signal strength of the terminal meets the first threshold requirement, the terminal is located in the trusted area, and the terminal can access the wireless local area network without verifying the terminal.
步驟804:將終端存取無線區域網路後,對該終端進行存取控制。 Step 804: After accessing the wireless local area network, the terminal performs access control on the terminal.
具體地,根據該終端的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度,將終端存取無線區域網路,並根據確定出的檢測週期檢測該終端對無線區域網路存取設備發送的信號的接收信號強度,並根據檢測結果進行相應控制處理。 Specifically, the length of the detection period corresponding to the value interval is determined according to the value interval of the received signal strength of the terminal, and the terminal accesses the wireless area network, and detects the terminal to the wireless area network according to the determined detection period. The received signal strength of the signal transmitted by the road access device is subjected to corresponding control processing according to the detection result.
當檢測到接收信號強度不符合第一門限要求時,中斷該終端的無線區域網路連接。或者,當檢測到接收信號強度不符合第一門限要求時,表明終端當前位於不可信區域,則對該終端進行驗證(比如,請求該終端發送無線區域網路存取密碼,對該終端發送的無線區域網路存取密碼進行驗證),若驗證通過,則保持該終端的無線區域網路連接,否則中斷該終端的無線區域網路連接。 When it is detected that the received signal strength does not meet the first threshold requirement, the wireless local area network connection of the terminal is interrupted. Or, when it is detected that the received signal strength does not meet the first threshold requirement, indicating that the terminal is currently located in the untrusted area, the terminal is authenticated (for example, requesting the terminal to send a wireless local area network access password, and sending the terminal to the terminal The wireless local area network access password is verified. If the verification is passed, the wireless local area network connection of the terminal is maintained, otherwise the wireless local area network connection of the terminal is interrupted.
進一步地,根據檢測週期檢測終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合第一門限要求但不符合第二門限要求,則表 明終端移入絕對可信區域,此種情況下,無線區域網路存取設備可停止檢測該終端對該無線區域網路存取設備發送的信號的接收信號強度。 Further, when detecting the received signal strength of the signal sent by the terminal to the wireless local area network access device according to the detection period, if the detected received signal strength meets the first threshold requirement but does not meet the second threshold requirement, the table The terminal is moved into the absolute trusted area. In this case, the wireless local area network access device can stop detecting the received signal strength of the signal sent by the terminal to the wireless local area network access device.
步驟805:對該終端進行驗證。 Step 805: Verify the terminal.
具體地,可請求該終端發送無線區域網路存取密碼,對該終端發送的無線區域網路存取密碼進行驗證。進一步地,若驗證通過,則將該終端存取無線區域網路,否則拒絕將該終端存取無線區域網路。 Specifically, the terminal may be requested to send a wireless local area network access password, and verify the wireless local area network access password sent by the terminal. Further, if the verification is passed, the terminal accesses the wireless local area network, otherwise the terminal is denied access to the wireless local area network.
進一步地,考慮到終端可能在不同可信等級的區域間移動,為此,本發明實施例中可選地,在根據檢測週期檢測終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合第二門限要求,則可根據當前檢測到的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度,並根據確定出的檢測週期長度更新該終端的檢測週期長度。這樣,可根據終端當前所在的可信區域的可信等級,調整該終端的檢測週期,進而調整針對該終端的存取控制策略。 Further, in the embodiment of the present invention, optionally, the received signal strength of the signal sent by the terminal to the wireless local area network access device is detected according to the detection period. If the detected received signal strength meets the second threshold requirement, the length of the detection period corresponding to the value interval may be determined according to the value interval of the currently detected received signal strength, and according to the determined detection period. The length updates the detection cycle length of the terminal. In this way, the detection period of the terminal can be adjusted according to the trusted level of the trusted area where the terminal is currently located, and then the access control policy for the terminal is adjusted.
例如,圖7所示的情況中,第一門限為-80dBm,第二門限為-30dBm,第一等級有條件可信區域與第二等級有條件可信區域的邊界對應的門限為-40dBm。 For example, in the case shown in FIG. 7, the first threshold is -80 dBm, and the second threshold is -30 dBm. The threshold corresponding to the boundary of the first-level conditional trusted region and the second-level conditional trusted region is -40 dBm.
如果終端的接收信號強度S>=-30dBm,則在無需該終端提供存取密碼,將該終端存取無線區域網路;如果終端的接收信號強度S的大小為:-30dBm<S=<-40dBm,則在無需該終端提供存取密碼,將該終端存取 無線區域網路,並按照檢測週期T=8小時,對該終端的接收信號強度進行檢測,並根據檢測結果進行相應的存取控制;如果終端的接收信號強度S的大小為:-40dBm<S=<-80dBm,則在無需該終端提供存取密碼,將該終端存取無線區域網路,並按照檢測週期T=1小時,對該終端的接收信號強度進行檢測,並根據檢測結果進行相應的存取控制;如果終端的接收信號強度S<-80dBm,則需要該終端提供存取密碼,並在對該存取密碼驗證通過的基礎上,將該終端存取無線區域網路。 If the received signal strength of the terminal is S>=-30dBm, the terminal is allowed to access the wireless local area network without providing the access password; if the received signal strength S of the terminal is -30dBm<S=<- 40dBm, the terminal is accessed without providing the access password for the terminal. The wireless local area network detects the received signal strength of the terminal according to the detection period T=8 hours, and performs corresponding access control according to the detection result; if the received signal strength S of the terminal is: -40 dBm<S =<-80dBm, the terminal is not required to provide an access password, the terminal accesses the wireless local area network, and according to the detection period T=1 hours, the received signal strength of the terminal is detected, and correspondingly according to the detection result Access control; if the received signal strength of the terminal is S<-80dBm, the terminal needs to provide an access password, and the terminal accesses the wireless local area network based on the verification of the access password.
透過以上描述可以看出,無線區域網路存取設備可將終端對無線區域網路存取設備發送的信號的接收信號強度與第一門限要求進行比較,若終端的接收信號強度符合第一門限要求,表明該終端當前距離無線區域網路存取設備在一設定範圍的可信區域內,此種情況下,可將該終端存取無線區域網路,而無需對該終端進行驗證,從而在兼顧安全性的情況下,無需對終端進行驗證即可將終端存取無線區域網路,簡化了終端的存取操作。進一步地,可將可信區域劃分為絕對可信區域和有條件可信區域,對於絕對可信區域內的終端,將其存取無線區域網路後不再進行存取控制,而對於有條件可信區域內的終端,在將其存取無線區域網路後可對的接收信號強度其進行週期性檢測,一旦檢測其移出可信區域,則為了安全性考慮,對其進行驗 證以決定是否允許該終端保持無線區域網路連接。 As can be seen from the above description, the wireless local area network access device can compare the received signal strength of the signal sent by the terminal to the wireless local area network access device with the first threshold requirement, if the received signal strength of the terminal meets the first threshold. The request indicates that the terminal is currently within a set range of trusted area from the wireless local area network access device. In this case, the terminal can access the wireless local area network without verifying the terminal, thereby In the case of security, the terminal can access the wireless local area network without verifying the terminal, which simplifies the access operation of the terminal. Further, the trusted area may be divided into an absolute trusted area and a conditionally trusted area. For the terminal in the absolute trusted area, access to the wireless local area network is not performed, and the access control is performed. The terminal in the trusted area periodically checks the received signal strength after accessing the wireless local area network. Once it is detected to move out of the trusted area, it is checked for security reasons. The card determines whether the terminal is allowed to maintain a wireless local area network connection.
參見圖9,為本發明另一實施例提供的無線區域網路存取控制流程,該流程可由無線區域網路存取設備執行,該流程可包括如下步驟: FIG. 9 is a flowchart of a wireless area network access control process according to another embodiment of the present invention. The process may be performed by a wireless area network access device, and the process may include the following steps:
步驟901:獲取終端對無線區域網路存取設備發送的信號的接收信號強度。該步驟的具體實現過程與圖2中的步驟201相同,在此不在重複。 Step 901: Acquire a received signal strength of a signal sent by the terminal to the WLAN access device. The specific implementation process of this step is the same as step 201 in FIG. 2, and is not repeated here.
步驟902:根據接收信號強度,確定對應的存取控制策略。 Step 902: Determine a corresponding access control policy according to the received signal strength.
步驟903:根據確定出的存取控制策略,對該終端進行無線區域網路存取控制。 Step 903: Perform wireless area network access control on the terminal according to the determined access control policy.
可選地,上述流程中的步驟902中,無線區域網路存取設備可將終端的接收信號強度與第一門限要求進行比較;若該接收信號強度符合第一門限要求,則將該終端存取無線區域網路;否則,對終端進行驗證。具體地,可請求該終端發送無線區域網路存取密碼,對該終端發送的無線區域網路存取密碼進行驗證,若驗證通過,則將該終端存取無線區域網路,否則拒絕將該終端存取無線區域網路。該流程的具體實現過程可參見圖2所示的流程。 Optionally, in step 902 in the foregoing process, the wireless area network access device may compare the received signal strength of the terminal with the first threshold requirement; if the received signal strength meets the first threshold requirement, the terminal saves the terminal. Take the wireless LAN; otherwise, verify the terminal. Specifically, the terminal may be requested to send a wireless local area network access password, and verify the wireless local area network access password sent by the terminal. If the verification is passed, the terminal accesses the wireless local area network, otherwise the network is refused. The terminal accesses the wireless local area network. The specific implementation process of the process can be seen in the process shown in FIG. 2.
可選地,上述流程中的步驟902中,無線區域網路存取設備可將終端的接收信號強度分別與第一門限要求和第二門限要求進行比較,並根據比較結果執行以下步驟之一:若接收信號強度符合第一門限要求但不符合第二門限 要求,則將該終端存取無線區域網路;若接收信號強度不符合第一門限要求,則對該終端進行驗證,比如,可對該終端發送的無線區域網路存取密碼進行驗證,若驗證通過,則將該終端存取無線區域網路,否則拒絕將該終端存取無線區域網路;若接收信號強度符合第一門限要求且符合第二門限要求,則將該終端存取無線區域網路,並對該終端進行存取控制。可選地,對該終端進行存取控制的過程可包括:根據檢測週期檢測終端對無線區域網路存取設備發送的信號的接收信號強度,並當檢測到接收信號強度不符合第一門限要求時,執行第一處理過程或第二處理過程;其中,所述第一處理過程包括:中斷該終端的無線區域網路連接;所述第二處理過程包括:對所述終端進行驗證,若驗證通過,則保持所述終端的無線區域網路連接,否則中斷所述終端的無線區域網路連接,具體地,可請求該終端發送無線區域網路存取密碼,對該終端發送的無線區域網路存取密碼進行驗證,若驗證通過,則保持該終端的無線區域網路連接,否則中斷該終端的無線區域網路連接。上述流程的具體實現過程可參見圖5或圖8。 Optionally, in step 902 in the foregoing process, the wireless area network access device may compare the received signal strength of the terminal with the first threshold requirement and the second threshold requirement, and perform one of the following steps according to the comparison result: If the received signal strength meets the first threshold requirement but does not meet the second threshold If required, the terminal accesses the wireless local area network; if the received signal strength does not meet the first threshold requirement, the terminal is verified, for example, the wireless local area network access password sent by the terminal may be verified, if If the verification is passed, the terminal accesses the wireless local area network, otherwise the terminal is denied access to the wireless local area network; if the received signal strength meets the first threshold requirement and meets the second threshold requirement, the terminal accesses the wireless area. The network and access control of the terminal. Optionally, the process of performing access control on the terminal may include: detecting, according to the detection period, a received signal strength of the signal sent by the terminal to the wireless local area network access device, and detecting that the received signal strength does not meet the first threshold requirement. And performing a first processing process or a second processing process, where the first processing procedure includes: interrupting a wireless local area network connection of the terminal; and the second processing process includes: verifying the terminal, if the verification Passing, maintaining the wireless local area network connection of the terminal, otherwise interrupting the wireless local area network connection of the terminal, specifically, requesting the terminal to send a wireless local area network access password, and the wireless area network sent by the terminal The access password is verified, and if the verification is passed, the wireless local area network connection of the terminal is maintained, otherwise the wireless local area network connection of the terminal is interrupted. The specific implementation process of the above process can be seen in FIG. 5 or FIG. 8.
進一步地,無線區域網路存取設備根據檢測週期檢測終端對無線區域網路存取設備發送的信號的接收信號強度之前,還可根據終端的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度,從而根據該檢測週期長度進行接收信號強度檢測。 Further, the wireless local area network access device may determine the value according to the value range of the received signal strength of the terminal before detecting the received signal strength of the signal sent by the wireless local area network access device according to the detection period. The length of the detection period corresponding to the interval is such that the received signal strength is detected according to the length of the detection period.
進一步地,無線區域網路存取設備根據檢測週期檢測終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合第二門限要求,則可根據當前檢測到的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度,並根據確定出的檢測週期長度更新該終端的檢測週期長度。 Further, when the wireless local area network access device detects the received signal strength of the signal sent by the terminal to the wireless local area network access device according to the detection period, if the detected received signal strength meets the second threshold requirement, the current local area network access device may The value interval of the received received signal strength is determined, the length of the detection period corresponding to the value interval is determined, and the length of the detection period of the terminal is updated according to the determined length of the detection period.
進一步地,無線區域網路存取設備根據檢測週期檢測終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合第一門限要求但不符合第二門限要求,則可停止檢測該終端對所述無線區域網路存取設備發送的信號的接收信號強度。 Further, when the wireless local area network access device detects the received signal strength of the signal sent by the terminal to the wireless local area network access device according to the detection period, if the detected received signal strength meets the first threshold requirement but does not comply with the second The threshold requirement may stop detecting the received signal strength of the signal sent by the terminal to the wireless local area network access device.
上述第一門限、第二門限,以及第一門限要求和第二門限要求的具體定義可參見前述實施例,在此不再重複。 For the specific definitions of the first threshold, the second threshold, and the first threshold requirement and the second threshold requirement, refer to the foregoing embodiment, which is not repeated here.
透過以上描述可以看出,無線區域網路存取設備可接收終端發送的無線區域網路存取請求,根據無線區域網路存取設備發送的信號到達所述終端時的信號強度,確定對應的存取控制策略,並根據確定出的存取控制策略,對所述終端發送的無線區域網路存取請求進行處理,從而實現對該終端進行存取控制。上述方案中,根據無線區域網路存取設備發送的信號到達所述終端時的信號強度,區分不同的應用情況,從而可針對不同的應用情況採用對應的無線區域網路存取控制策略進行存取控制。 As can be seen from the above description, the wireless local area network access device can receive the wireless local area network access request sent by the terminal, and determine the corresponding signal strength according to the signal strength when the wireless local area network access device sends the signal to the terminal. Accessing the control policy, and processing the wireless local area network access request sent by the terminal according to the determined access control policy, thereby implementing access control on the terminal. In the foregoing solution, according to the signal strength when the signal sent by the wireless area network access device reaches the terminal, different application scenarios are distinguished, so that corresponding wireless local area network access control policies can be used for different application scenarios. Take control.
本發明的上述各實施例中,可允許用戶對相關門限進行設定。以圖7所示的情況為例,無線區域網路存取設備 的配置介面中可提供給用戶如下設定選項:選項1:房間大於60平米,小於100平米;選項2:房間大於100平米,小於300平米。 In the above embodiments of the present invention, the user may be allowed to set the relevant threshold. Taking the situation shown in Figure 7 as an example, a wireless local area network access device The configuration interface can be provided to the user as follows: Option 1: Room is more than 60 square meters, less than 100 square meters; Option 2: Room is more than 100 square meters, less than 300 square meters.
如果用戶選擇選項2,則無線區域網路存取設備可確定出:第二等級有條件可信區域邊界r1=50,對應的門限為-80dBm;第一等級有條件可信區域邊界r1=30,對應的門限為-40dBm;絕對可信區域邊界r1=10,對應的門限為-30dBm。 If the user selects option 2, the wireless local area network access device may determine that the second level conditional trusted area boundary r1=50, the corresponding threshold is -80 dBm; the first level conditional trusted area boundary r1=30 The corresponding threshold is -40dBm; the absolute trusted region boundary is r1=10, and the corresponding threshold is -30dBm.
如果用戶選擇選項2,則無線區域網路存取設備可確定出:第二等級有條件可信區域邊界r1=70,對應的門限為-100dBm;第一等級有條件可信區域邊界r1=50,對應的門限為-80dBm;絕對可信區域邊界r1=20,對應的門限為-25dBm。 If the user selects option 2, the wireless local area network access device may determine that the second level conditional trusted area boundary r1=70, the corresponding threshold is -100 dBm; the first level conditional trusted area boundary r1=50 The corresponding threshold is -80dBm; the absolute trusted region boundary is r1=20, and the corresponding threshold is -25dBm.
當然,上述設定方法僅為一種示例,本發明還允許採用其他設定方式,比如,允許用戶輸入:r1=50米,r2=30米,若=10米,相應地,無線區域網路存取設備根據用戶輸入的上述參數計算得到:第二等級有條件可信區域邊界r1=50,對應的門限為-80dBm;第一等級有條件可信區域邊界r1=30,對應的門限為 -40dBm;絕對可信區域邊界r1=10,對應的門限為-30dBm。 Of course, the above setting method is only an example, and the invention also allows other setting methods to be adopted, for example, allowing the user to input: r1=50 meters, r2=30 meters, if=10 meters, correspondingly, the wireless local area network access device According to the above parameters input by the user, the second level conditional trusted area boundary r1=50, the corresponding threshold is -80dBm; the first level conditional trusted area boundary r1=30, the corresponding threshold is -40dBm; absolute trusted region boundary r1=10, corresponding threshold is -30dBm.
基於相同的技術構思,本發明實施例提供了一種無線區域網路存取設備。 Based on the same technical concept, an embodiment of the present invention provides a wireless area network access device.
參見圖10,為本發明實施例提供的無線區域網路存取設備的結構示意圖,該設備可實現前述實施例描述的流程。 FIG. 10 is a schematic structural diagram of a wireless area network access device according to an embodiment of the present invention. The device can implement the process described in the foregoing embodiment.
如圖所示,該設備可包括:獲取模組1001、比較模組1002、存取控制模組1003,其中:獲取模組1001,用於獲取終端對無線區域網路存取設備發送的信號的接收信號強度;比較模組1002,用於將所述接收信號強度與第一門限要求進行比較;存取控制模組1003,用於在所述接收信號強度符合所述第一門限要求的情況下,將所述終端存取無線區域網路;否則,對所述終端進行驗證。 As shown in the figure, the device may include: an acquisition module 1001, a comparison module 1002, and an access control module 1003, wherein: the acquisition module 1001 is configured to acquire a signal sent by the terminal to the wireless local area network access device. Receiving a signal strength; a comparison module 1002, configured to compare the received signal strength with a first threshold requirement; and an access control module 1003, configured to: when the received signal strength meets the first threshold requirement And accessing the wireless local area network; otherwise, verifying the terminal.
可選地,所述第一門限為第一設定值;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值。 Optionally, the first threshold is a first set value; and the received signal strength meets the first threshold requirement, and the received signal strength is greater than or equal to the first set value.
可選地,所述第一門限為第一設定區間;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內。 Optionally, the first threshold is a first set interval; the received signal strength meets the first threshold requirement, and the received signal strength is within the first set interval.
可選地,存取控制模組1003可還用於:判定所述接收信號強度符合所述第一門限要求且將所述終端存取無線 區域網路之後,將所述接收信號強度與第二門限要求進行比較;若所述接收信號強度符合所述第二門限要求,則對所述終端進行存取控制。 Optionally, the access control module 1003 is further configured to: determine that the received signal strength meets the first threshold requirement and access the terminal to the wireless After the regional network, the received signal strength is compared with a second threshold requirement; if the received signal strength meets the second threshold requirement, access control is performed on the terminal.
可選地,存取控制模組1003可具體用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度,並當檢測到接收信號強度不符合所述第一門限要求時,執行以下步驟之一:中斷所述終端的無線區域網路連接;對所述終端進行驗證,若驗證通過,則保持所述終端的無線區域網路連接,否則中斷所述終端的無線區域網路連接。 Optionally, the access control module 1003 is specifically configured to: detect, according to the detection period, a received signal strength of the signal sent by the terminal to the wireless local area network access device, and when detecting that the received signal strength does not meet the foregoing When a threshold is required, one of the following steps is performed: interrupting the wireless local area network connection of the terminal; verifying the terminal, if the verification is passed, maintaining the wireless local area network connection of the terminal, otherwise interrupting the terminal Wireless LAN connection.
可選地,存取控制模組1003可還用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度之前,根據所述接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度;其中,一個取值區間對應一個檢測週期長度,按照信號強度從大到小的順序,排列在前的取值區間所對應的檢測週期長度大於排列在後的取值區間所對應的檢測週期長度。 Optionally, the access control module 1003 is further configured to: before detecting the received signal strength of the signal sent by the wireless local area network access device by the terminal according to the detection period, according to the value interval of the received signal strength Determining the length of the detection period corresponding to the value interval; wherein, one value interval corresponds to a detection period length, and the length of the detection period corresponding to the previous value interval is greater than the arrangement according to the order of the signal strength from large to small The length of the detection period corresponding to the subsequent value interval.
可選地,存取控制模組1003可還用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合所述第二門限要求,則根據當前檢測到的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度,並根據確定出的檢測週期長度更新所述終端的檢測週期長度。 Optionally, the access control module 1003 is further configured to: when detecting, according to the detection period, the received signal strength of the signal sent by the terminal to the WLAN access device, if the detected received signal strength meets the The second threshold is required to determine the length of the detection period corresponding to the value interval according to the value interval of the currently detected received signal strength, and update the detection period length of the terminal according to the determined length of the detection period.
可選地,存取控制模組1003可還用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合所述第一門限要求但不符合所述第二門限要求,則停止檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度。 Optionally, the access control module 1003 is further configured to: when detecting, according to the detection period, the received signal strength of the signal sent by the terminal to the WLAN access device, if the detected received signal strength meets the If the first threshold requirement but does not meet the second threshold requirement, the detection of the received signal strength of the signal sent by the terminal to the wireless local area network access device is stopped.
可選地,所述第一門限為第一設定值、所述第二門限為第二設定值,且所述第一設定值小於所述第二設定值;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度小於所述第二設定值。 Optionally, the first threshold is a first set value, the second threshold is a second set value, and the first set value is smaller than the second set value; A threshold requirement includes: the received signal strength is greater than or equal to the first set value; and the received signal strength meets the second threshold requirement, including: the received signal strength is less than the second set value.
可選地,所述第一門限為第一設定區間、所述第二門限為第二設定區間,且所述第二設定區間的上限小於所述第一設定區間的上限;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度在所述第二設定區間內。 Optionally, the first threshold is a first set interval, the second threshold is a second set interval, and an upper limit of the second set interval is smaller than an upper limit of the first set interval; the received signal strength Compliance with the first threshold requirement, including: the received signal strength is within the first set interval; and the received signal strength meets the second threshold requirement, including: the received signal strength is in the second setting Within the interval.
基於相同的技術構思,本發明實施例還提供了一種無線區域網路存取設備。 Based on the same technical concept, an embodiment of the present invention further provides a wireless area network access device.
參見圖11,為本發明實施例提供的無線區域網路存取設備的結構示意圖,該設備可實現前述實施例描述的流程。 FIG. 11 is a schematic structural diagram of a wireless area network access device according to an embodiment of the present invention. The device can implement the process described in the foregoing embodiment.
如圖所示,該設備可包括:獲取模組1101、確定模組1102、存取控制模組1103,其中: 獲取模組1101,用於獲取終端對無線區域網路存取設備發送的信號的接收信號強度;確定模組1102,用於根據所述接收信號強度,確定對應的存取控制策略;存取控制模組1103,用於根據確定出的存取控制策略,對所述終端進行無線區域網路存取控制。 As shown in the figure, the device may include: an obtaining module 1101, a determining module 1102, and an access control module 1103, wherein: The acquiring module 1101 is configured to acquire a received signal strength of a signal sent by the terminal to the wireless local area network access device, and the determining module 1102 is configured to determine a corresponding access control policy according to the received signal strength; and access control The module 1103 is configured to perform wireless area network access control on the terminal according to the determined access control policy.
可選地,確定模組1102可具體用於:將所述接收信號強度與第一門限要求進行比較,若所述接收信號強度符合所述第一門限要求,則將所述終端存取無線區域網路,否則,對所述終端進行驗證。 Optionally, the determining module 1102 is specifically configured to: compare the received signal strength with a first threshold requirement, and if the received signal strength meets the first threshold requirement, access the wireless area by using the terminal. Network, otherwise, verify the terminal.
可選地,所述第一門限為第一設定值;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值。或者,所述第一門限為第一設定區間;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內。 Optionally, the first threshold is a first set value; and the received signal strength meets the first threshold requirement, and the received signal strength is greater than or equal to the first set value. Or the first threshold is a first set interval; the received signal strength meets the first threshold requirement, and the received signal strength is within the first set interval.
可選地,確定模組1102可具體用於執行以下操作之一:若所述接收信號強度符合第一門限要求但不符合第二門限要求,則將所述終端存取無線區域網路;若所述接收信號強度不符合第一門限要求,則對所述終端進行驗證;若所述接收信號強度符合第一門限要求且符合第二門限要求,則將所述終端存取無線區域網路,並對所述終端進行存取控制。 Optionally, the determining module 1102 is specifically configured to perform one of the following operations: if the received signal strength meets the first threshold requirement but does not meet the second threshold requirement, the terminal is accessed by using the wireless local area network; If the received signal strength does not meet the first threshold requirement, the terminal is verified; if the received signal strength meets the first threshold requirement and meets the second threshold requirement, the terminal accesses the wireless local area network, And performing access control on the terminal.
可選地,存取控制模組1103可具體用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度,並當檢測到接收信號強度不符合所述第一門限要求時,執行以下步驟之一;中斷所述終端的無線區域網路連接;對所述終端進行驗證,若驗證通過,則保持所述終端的無線區域網路連接,否則中斷所述終端的無線區域網路連接。 Optionally, the access control module 1103 is specifically configured to: detect, according to the detection period, a received signal strength of the signal sent by the terminal to the WLAN access device, and when detecting that the received signal strength does not meet the foregoing When a threshold is required, perform one of the following steps: interrupt the wireless local area network connection of the terminal; verify the terminal, if the verification passes, maintain the wireless local area network connection of the terminal, otherwise interrupt the terminal Wireless LAN connection.
可選地,存取控制模組1103還可用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度之前,根據所述接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度;其中,一個取值區間對應一個檢測週期長度,按照信號強度從大到小的順序,排列在前的取值區間所對應的檢測週期長度大於排列在後的取值區間所對應的檢測週期長度。 Optionally, the access control module 1103 is further configured to: before detecting, according to the detection period, the value of the received signal strength of the signal sent by the wireless local area network access device, according to the value interval of the received signal strength, Determining the length of the detection period corresponding to the value interval; wherein, one value interval corresponds to a detection period length, and the length of the detection period corresponding to the previous value interval is greater than the arrangement according to the signal strength from the largest to the smallest The length of the detection period corresponding to the value interval.
可選地,存取控制模組1103可還用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接收信號強度時,若所檢測到的接收信號強度符合所述第一門限要求且符合所述第二門限要求,則根據當前檢測到的接收信號強度所在的取值區間,確定該取值區間對應的檢測週期長度,並根據確定出的檢測週期長度更新所述終端的檢測週期長度。 Optionally, the access control module 1103 is further configured to: when detecting, according to the detection period, the received signal strength of the signal sent by the terminal to the WLAN access device, if the detected received signal strength meets the The first threshold is required to meet the second threshold requirement, and the length of the detection period corresponding to the value interval is determined according to the value interval of the currently detected received signal strength, and the length of the detection period is updated according to the determined detection period length. The length of the detection cycle of the terminal.
可選地,存取控制模組1103還可用於:根據檢測週期檢測所述終端對無線區域網路存取設備發送的信號的接 收信號強度時,若所檢測到的接收信號強度符合第一門限要求但不符合所述第二門限要求,則停止檢測所述終端對所述無線區域網路存取設備發送的信號的接收信號強度。 Optionally, the access control module 1103 is further configured to: detect, according to the detection period, the connection of the signal sent by the terminal to the wireless local area network access device. Receiving a signal strength, if the detected received signal strength meets the first threshold requirement but does not meet the second threshold requirement, stopping detecting the received signal of the signal sent by the terminal to the wireless local area network access device strength.
可選地,所述第一門限為第一設定值、所述第二門限為第二設定值,且所述第一設定值小於所述第二設定值;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度大於或等於所述第一設定值;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度小於所述第二設定值。 Optionally, the first threshold is a first set value, the second threshold is a second set value, and the first set value is smaller than the second set value; A threshold requirement includes: the received signal strength is greater than or equal to the first set value; and the received signal strength meets the second threshold requirement, including: the received signal strength is less than the second set value.
可選地,所述第一門限為第一設定區間、所述第二門限為第二設定區間,且所述第二設定區間的上限小於所述第一設定區間的上限;所述接收信號強度符合所述第一門限要求,包括:所述接收信號強度在所述第一設定區間內;所述接收信號強度符合所述第二門限要求,包括:所述接收信號強度在所述第二設定區間內。 Optionally, the first threshold is a first set interval, the second threshold is a second set interval, and an upper limit of the second set interval is smaller than an upper limit of the first set interval; the received signal strength Compliance with the first threshold requirement, including: the received signal strength is within the first set interval; and the received signal strength meets the second threshold requirement, including: the received signal strength is in the second setting Within the interval.
基於相同的技術構思,本發明實施例提供了一種無線區域網路存取設備。 Based on the same technical concept, an embodiment of the present invention provides a wireless area network access device.
參見圖12,為本發明實施例提供的無線區域網路存取設備的結構示意圖,該設備可實現前述實施例描述的流程。 FIG. 12 is a schematic structural diagram of a wireless area network access device according to an embodiment of the present invention. The device can implement the process described in the foregoing embodiment.
如圖所示,該設備可包括:處理器1201,記憶體1202、收發器1203。 As shown, the device can include a processor 1201, a memory 1202, and a transceiver 1203.
其中,處理器1201可以是通用處理器(比如微處理器或者任何常規的處理器等)、數位訊號處理器、專用積 體電路、現場可程式設計閘陣列或者其他可程式設計邏輯器件、分立門或者電晶體邏輯器件、分立硬體元件。記憶體1202具體可包括內部記憶體和/或外部記憶體,比如隨機記憶體,快閃記憶體、唯讀記憶體,可程式設計唯讀記憶體或者電可讀寫可程式設計記憶體、寄存器等本領域成熟的儲存媒體。收發器1203用於實現無線信號收發功能。 The processor 1201 may be a general-purpose processor (such as a microprocessor or any conventional processor, etc.), a digital signal processor, and a dedicated product. Body circuits, field programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. The memory 1202 may specifically include an internal memory and/or an external memory, such as a random memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically readable and writable programmable memory, a register. Such as the mature storage media in this field. The transceiver 1203 is configured to implement a wireless signal transceiving function.
處理器1201與其他各模組之間存在資料通信連接,比如可基於匯流排架構進行資料通信。匯流排架構可以包括任意數量的互聯的匯流排和橋,具體由處理器1201代表的一個或多個處理器和記憶體1202代表的記憶體的各種電路連結在一起。匯流排架構還可以將諸如週邊設備、穩壓器和功率管理電路等之類的各種其他電路連結在一起,這些都是本領域所公知的,因此,本文不再對其進行進一步描述。匯流排界面提供介面。處理器1201負責管理匯流排架構和通常的處理,記憶體1202可以儲存處理器1201在執行操作時所使用的資料。 There is a data communication connection between the processor 1201 and other modules, for example, data communication can be performed based on the bus bar architecture. The busbar architecture can include any number of interconnected busbars and bridges, specifically linked by one or more processors represented by processor 1201 and various circuits of memory represented by memory 1202. The busbar architecture can also couple various other circuits, such as peripherals, voltage regulators, and power management circuits, as is well known in the art, and therefore, will not be further described herein. The bus interface provides an interface. The processor 1201 is responsible for managing the bus bar architecture and the usual processing, and the memory 1202 can store the data used by the processor 1201 when performing operations.
本發明實施例揭示的流程,可以應用於處理器1201中,或者由處理器1201實現。在實現過程中,前述實施例描述的流程的各步驟可以透過處理器1201中的硬體的整合邏輯電路或者軟體形式的指令完成。可以實現或者執行本發明實施例中的揭示的各方法、步驟及邏輯方塊圖。結合本發明實施例所揭示的方法的步驟可以直接體現為硬體處理器執行完成,或者用處理器中的硬體及軟體模組組 合執行完成。軟體模組可以位於隨機記憶體,快閃記憶體、唯讀記憶體,可程式設計唯讀記憶體或者電可讀寫可程式設計記憶體、寄存器等本領域成熟的儲存媒體中。 The flow disclosed in the embodiment of the present invention may be applied to the processor 1201 or implemented by the processor 1201. In the implementation process, the steps of the process described in the foregoing embodiment may be completed by using hardware integrated logic in the processor 1201 or in the form of software. The methods, steps, and logical block diagrams disclosed in the embodiments of the present invention may be implemented or executed. The steps of the method disclosed in the embodiment of the present invention may be directly implemented as a hardware processor, or a hardware and software module group in the processor. The execution is completed. The software module can be located in a random storage medium, a flash memory, a read-only memory, a programmable read-only memory, or an electrically readable and writable programmable memory, a register, and the like.
具體地,處理器1201,耦合到記憶體1202,用於讀取記憶體1202儲存的電腦程式指令,並作為回應,執行如下操作:獲取終端對無線區域網路存取設備發送的信號的接收信號強度;將接收信號強度與第一門限要求進行比較;若接收信號強度符合第一門限要求,則將終端存取無線區域網路;否則,對終端進行驗證。 Specifically, the processor 1201 is coupled to the memory 1202 for reading the computer program instructions stored in the memory 1202, and in response, performs the following operations: acquiring the receiving signal of the signal sent by the terminal to the wireless local area network access device. Intensity; compares the received signal strength with the first threshold requirement; if the received signal strength meets the first threshold requirement, the terminal accesses the wireless local area network; otherwise, the terminal is verified.
上述流程的具體實現過程,可參見前述實施例的描述,在此不再重複。 For the specific implementation process of the foregoing process, refer to the description of the foregoing embodiment, which is not repeated here.
基於相同的技術構思,本發明實施例還提供了一種無線區域網路存取設備。 Based on the same technical concept, an embodiment of the present invention further provides a wireless area network access device.
參見圖13,為本發明實施例提供的無線區域網路存取設備的結構示意圖,該設備可實現前述實施例描述的流程。 FIG. 13 is a schematic structural diagram of a wireless area network access device according to an embodiment of the present invention. The device can implement the process described in the foregoing embodiment.
如圖所示,該設備可包括:處理器1301,記憶體1302、收發器1303。 As shown, the device can include a processor 1301, a memory 1302, and a transceiver 1303.
其中,處理器1301可以是通用處理器(比如微處理器或者任何常規的處理器等)、數位訊號處理器、專用積體電路、現場可程式設計柵陣列或者其他可程式設計邏輯器件、分立門或者電晶體邏輯器件、分立硬體元件。記憶 體1302具體可包括內部記憶體和/或外部記憶體,比如隨機記憶體,快閃記憶體、唯讀記憶體,可程式設計唯讀記憶體或者電可讀寫可程式設計記憶體、寄存器等本領域成熟的儲存媒體。收發器1303用於實現無線信號收發功能。 The processor 1301 may be a general purpose processor (such as a microprocessor or any conventional processor, etc.), a digital signal processor, a dedicated integrated circuit, a field programmable gate array or other programmable logic device, and a discrete gate. Or transistor logic devices, discrete hardware components. memory The body 1302 may specifically include an internal memory and/or an external memory, such as a random memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically readable and writable programmable memory, a register, or the like. A mature storage medium in the field. The transceiver 1303 is configured to implement a wireless signal transceiving function.
處理器1301與其他各模組之間存在資料通信連接,比如可基於匯流排架構進行資料通信。匯流排架構可以包括任意數量的互聯的匯流排和橋,具體由處理器1301代表的一個或多個處理器和記憶體1302代表的記憶體的各種電路連結在一起。匯流排架構還可以將諸如週邊設備、穩壓器和功率管理電路等之類的各種其他電路連結在一起,這些都是本領域所公知的,因此,本文不再對其進行進一步描述。匯流排界面提供介面。處理器1301負責管理匯流排架構和通常的處理,記憶體1302可以儲存處理器1301在執行操作時所使用的資料。 There is a data communication connection between the processor 1301 and other modules, for example, data communication can be performed based on the bus bar architecture. The busbar architecture may include any number of interconnected busbars and bridges, specifically linked by one or more processors represented by processor 1301 and various circuits of memory represented by memory 1302. The busbar architecture can also couple various other circuits, such as peripherals, voltage regulators, and power management circuits, as is well known in the art, and therefore, will not be further described herein. The bus interface provides an interface. The processor 1301 is responsible for managing the bus bar architecture and the usual processing, and the memory 1302 can store the data used by the processor 1301 when performing operations.
本發明實施例揭示的流程,可以應用於處理器1301中,或者由處理器1301實現。在實現過程中,前述實施例描述的流程的各步驟可以透過處理器1301中的硬體的整合邏輯電路或者軟體形式的指令完成。可以實現或者執行本發明實施例中的揭示的各方法、步驟及邏輯方塊圖。結合本發明實施例所揭示的方法的步驟可以直接體現為硬體處理器執行完成,或者用處理器中的硬體及軟體模組組合執行完成。軟體模組可以位於隨機記憶體,快閃記憶體、唯讀記憶體,可程式設計唯讀記憶體或者電可讀寫可 程式設計記憶體、寄存器等本領域成熟的儲存媒體中。 The flow disclosed in the embodiment of the present invention may be applied to the processor 1301 or implemented by the processor 1301. In the implementation process, the steps of the process described in the foregoing embodiment may be completed by using hardware integrated logic circuits or instructions in software form in the processor 1301. The methods, steps, and logical block diagrams disclosed in the embodiments of the present invention may be implemented or executed. The steps of the method disclosed in the embodiments of the present invention may be directly implemented as a hardware processor, or may be performed by a combination of a hardware and a software module in a processor. The software module can be located in random memory, flash memory, read-only memory, programmable read-only memory or electrically readable and writable. Programming memory, registers, etc. are well-established in storage media.
具體地,處理器1301,耦合到記憶體1302,用於讀取記憶體1302儲存的電腦程式指令,並作為回應,執行如下操作:獲取終端對無線區域網路存取設備發送的信號的接收信號強度;根據接收信號強度,確定對應的存取控制策略;根據確定出的存取控制策略,對終端進行無線區域網路存取控制。 Specifically, the processor 1301 is coupled to the memory 1302, and is configured to read the computer program instructions stored in the memory 1302, and in response, perform the following operations: acquiring the receiving signal of the signal sent by the terminal to the wireless local area network access device. Intensity; determining a corresponding access control policy according to the received signal strength; and performing wireless area network access control on the terminal according to the determined access control policy.
上述流程的具體實現過程,可參見前述實施例的描述,在此不再重複。 For the specific implementation process of the foregoing process, refer to the description of the foregoing embodiment, which is not repeated here.
本發明是參照根據本發明實施例的方法、設備(系統)、和電腦程式產品的流程圖和/或方塊圖來描述的。應理解可由電腦程式指令實現流程圖和/或方塊圖中的每一流程和/或方塊、以及流程圖和/或方塊圖中的流程和/或方塊的結合。可提供這些電腦程式指令到通用電腦、專用電腦、嵌入式處理機或其他可程式設計資料處理設備的處理器以產生一個機器,使得透過電腦或其他可程式設計資料處理設備的處理器執行的指令產生用於實現在流程圖一個流程或多個流程和/或方塊圖一個方塊或多個方塊中指定的功能的裝置。 The present invention has been described with reference to flowchart illustrations and/or block diagrams of a method, apparatus (system), and computer program product according to embodiments of the invention. It will be understood that each flow and/or block of the flowcharts and/or <RTIgt; These computer program instructions can be provided to a processor of a general purpose computer, a special purpose computer, an embedded processor or other programmable data processing device to produce a machine that executes instructions executed by a processor of a computer or other programmable data processing device Means are generated for implementing the functions specified in one or more flows of the flowchart or in a block or blocks of the block diagram.
這些電腦程式指令也可儲存在能引導電腦或其他可程式設計資料處理設備以特定方式工作的電腦可讀記憶體中,使得儲存在該電腦可讀記憶體中的指令產生包括指令 裝置的製造品,該指令裝置實現在流程圖一個流程或多個流程和/或方塊圖一個方塊或多個方塊中指定的功能。 The computer program instructions can also be stored in a computer readable memory that can boot a computer or other programmable data processing device to operate in a particular manner, such that instructions stored in the computer readable memory include instructions. An article of manufacture of a device that implements the functions specified in one or more blocks of a flow or a flow and/or block diagram of the flowchart.
這些電腦程式指令也可裝載到電腦或其他可程式設計資料處理設備上,使得在電腦或其他可程式設計設備上執行一系列操作步驟以產生電腦實現的處理,從而在電腦或其他可程式設計設備上執行的指令提供用於實現在流程圖一個流程或多個流程和/或方塊圖一個方塊或多個方塊中指定的功能的步驟。 These computer program instructions can also be loaded onto a computer or other programmable data processing device to perform a series of operational steps on a computer or other programmable device to produce computer-implemented processing on a computer or other programmable device. The instructions executed on the steps provide steps for implementing the functions specified in one or more flows of the flowchart or in a block or blocks of the flowchart.
儘管已描述了本發明的較佳實施例,但本領域內的技術人員一旦得知了基本創造性概念,則可對這些實施例作出另外的變更和修改。所以,所附申請專利範圍意欲解釋為包括較佳實施例以及落入本發明範圍的所有變更和修改。 Although the preferred embodiment of the invention has been described, it will be apparent to those skilled in Therefore, the scope of the appended claims is intended to be construed as a
顯然,本領域的技術人員可以對本發明進行各種改動和變型而不脫離本發明的精神和範圍。這樣,倘若本發明的這些修改和變型屬於本發明權利要求及其等同技術的範圍之內,則本發明也意圖包含這些改動和變型在內。 It is apparent that those skilled in the art can make various modifications and variations to the invention without departing from the spirit and scope of the invention. Thus, it is intended that the present invention cover the modifications and modifications of the invention
Claims (39)
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
CN201610405248.5A CN107484165B (en) | 2016-06-08 | 2016-06-08 | Wireless local area network access control method and device |
CN201610405248.5 | 2016-06-08 |
Publications (2)
Publication Number | Publication Date |
---|---|
TW201743639A true TW201743639A (en) | 2017-12-16 |
TWI729114B TWI729114B (en) | 2021-06-01 |
Family
ID=60577570
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
TW106111914A TWI729114B (en) | 2016-06-08 | 2017-04-10 | Wireless local area network access control method and device |
Country Status (3)
Country | Link |
---|---|
CN (1) | CN107484165B (en) |
TW (1) | TWI729114B (en) |
WO (1) | WO2017211198A1 (en) |
Families Citing this family (4)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
CN110072236B (en) * | 2018-01-24 | 2022-07-22 | 阿里巴巴集团控股有限公司 | Device connection method, device and system |
CN108495322B (en) * | 2018-03-20 | 2022-02-25 | 深圳捷豹电波科技有限公司 | Network access control method, network access control device, wireless gateway equipment and storage medium |
CN114980093B (en) * | 2021-02-18 | 2024-10-25 | Oppo广东移动通信有限公司 | Device verification method, device, computer device and storage medium |
CN116456344A (en) * | 2023-03-21 | 2023-07-18 | 广东南方电信规划咨询设计院有限公司 | Wireless connection authorization management method, device and system |
Family Cites Families (10)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
TW200522596A (en) * | 2003-12-31 | 2005-07-01 | Inventec Corp | Location based service (LBS) system of wireless area network (WLAN) and method thereof |
CN101959282A (en) * | 2010-09-26 | 2011-01-26 | 杭州华三通信技术有限公司 | Wireless local area network (WLAN) access control method and device thereof |
US9161293B2 (en) * | 2011-09-28 | 2015-10-13 | Avaya Inc. | Method and apparatus for using received signal strength indicator (RSSI) filtering to provide air-time optimization in wireless networks |
US8732801B2 (en) * | 2011-12-09 | 2014-05-20 | Verizon Patent And Licensing Inc. | Wireless connection method and device |
CN103476145B (en) * | 2013-07-24 | 2017-11-03 | 深圳Tcl新技术有限公司 | wireless network connection processing method and device |
CN104349357A (en) * | 2013-08-05 | 2015-02-11 | 联想(北京)有限公司 | Method and device for updating signal intensity |
CN104519526B (en) * | 2013-09-27 | 2019-02-26 | 华为技术有限公司 | Network access point, network controller, the network equipment and its load control method |
CN104902500B (en) * | 2015-05-21 | 2019-11-22 | 南京创维信息技术研究院有限公司 | The automatic connection method and system of Wireless Communication Equipment and radio reception device |
CN105120526A (en) * | 2015-07-28 | 2015-12-02 | 深圳市宏电技术股份有限公司 | wifi connecting method and system characterized by no near-field authentication |
CN105554861A (en) * | 2015-12-02 | 2016-05-04 | 广东小天才科技有限公司 | Method and system for automatic networking based on position and time |
-
2016
- 2016-06-08 CN CN201610405248.5A patent/CN107484165B/en active Active
-
2017
- 2017-04-10 TW TW106111914A patent/TWI729114B/en not_active IP Right Cessation
- 2017-05-26 WO PCT/CN2017/086050 patent/WO2017211198A1/en active Application Filing
Also Published As
Publication number | Publication date |
---|---|
CN107484165B (en) | 2020-11-20 |
WO2017211198A1 (en) | 2017-12-14 |
TWI729114B (en) | 2021-06-01 |
CN107484165A (en) | 2017-12-15 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US11165593B2 (en) | System and method for wireless network management | |
US9763094B2 (en) | Methods, devices and systems for dynamic network access administration | |
KR101837923B1 (en) | Profiling rogue access points | |
KR101278745B1 (en) | Provisioning of wireless connectivity for devices using nfc | |
US20220083327A1 (en) | Facilitating use of a universal integrated circuit card (uicc) for secure device updates | |
US11399026B2 (en) | Permission management method and system, and related device | |
TW201743639A (en) | Wireless local area network access control method and device | |
US10447685B2 (en) | Systems, methods and computer-readable storage media facilitating mobile device guest network access | |
CN103181208A (en) | Method and system for controlling terminal device to access wireless network | |
US20210243188A1 (en) | Methods and apparatus for authenticating devices | |
US20190044950A1 (en) | Detection of Compromised Access Points | |
WO2017008580A1 (en) | Method and device for wireless station to access local area network | |
CN104185250A (en) | Wireless communication method, electronic devices and wireless communication system | |
US20190141047A1 (en) | Vehicle network access control method and infotainment apparatus therefor | |
US20150143526A1 (en) | Access point controller and control method thereof | |
KR101747927B1 (en) | System for registrating additional user for device | |
WO2015196679A1 (en) | Authentication method and apparatus for wireless access | |
US11916923B2 (en) | Method for restricting memory write access in IoT devices | |
CN106851639B (en) | WiFi access method and access point | |
CN106899543B (en) | Content access control method and related equipment | |
WO2018014555A1 (en) | Data transmission control method and apparatus | |
KR101921649B1 (en) | Wireless network access control system and method for controlling thereof | |
US20240248994A1 (en) | Denial of dynamic host configuration protocol internet protocol address allocation to an unauthorized node via cross secure boot verification | |
CN116963233A (en) | WIFI hotspot opening method and device, electronic equipment and storage medium | |
CN114258021A (en) | Authentication using wireless sensing |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
MM4A | Annulment or lapse of patent due to non-payment of fees |