WO2015103748A1 - 认证关联方法及系统 - Google Patents

认证关联方法及系统 Download PDF

Info

Publication number
WO2015103748A1
WO2015103748A1 PCT/CN2014/070326 CN2014070326W WO2015103748A1 WO 2015103748 A1 WO2015103748 A1 WO 2015103748A1 CN 2014070326 W CN2014070326 W CN 2014070326W WO 2015103748 A1 WO2015103748 A1 WO 2015103748A1
Authority
WO
WIPO (PCT)
Prior art keywords
authentication
sta
service device
association
request
Prior art date
Application number
PCT/CN2014/070326
Other languages
English (en)
French (fr)
Inventor
杨浔
陶源
赵牧
Original Assignee
华为技术有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 华为技术有限公司 filed Critical 华为技术有限公司
Priority to CN201480068887.6A priority Critical patent/CN105850095B/zh
Priority to PCT/CN2014/070326 priority patent/WO2015103748A1/zh
Publication of WO2015103748A1 publication Critical patent/WO2015103748A1/zh
Priority to US15/205,333 priority patent/US10187796B2/en

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04WWIRELESS COMMUNICATION NETWORKS
    • H04W12/00Security arrangements; Authentication; Protecting privacy or anonymity
    • H04W12/06Authentication
    • H04W12/062Pre-authentication

Definitions

  • the present application relates to the field of communications, and in particular, to an authentication association method and system.
  • a station that requests a service needs to communicate with other service devices, it needs to be authenticated and associated with each service device separately, even if it is required to simultaneously connect or need to switch the connected service device. This is also true if they belong to the same network or have the same authentication method.
  • the process of the authentication is a process of determining whether the station STA requesting the connection has the connection qualification.
  • the process of association is the process of establishing a connection between two parties to exchange information. As shown in Figure 1, the site includes the STA 101.
  • the first printer 102, the second printer 103, and the notebook 104 if the STA 101 needs to communicate with the first printer 102, the second printer 103, and the notebook 104, the STA 101 needs to separately authenticate and associate with each of the service devices, that is, the first printer 102, the second printer 103, and the notebook 104; if the STA The 101 needs to switch the first printer 102 connected thereto to be connected to the second printer 103, and the STA also needs to re-authenticate and associate with the second printer 103 again. Moreover, if the service device first printer 102, the second printer 103, and the notebook 104 are to communicate, authentication and association must be performed one by one.
  • the second printer 103 needs to authenticate with the first printer 102 and the notebook 104. And associated, the second printer 103 is required to authenticate and associate with the first printer 102 and the notebook 104, respectively. Therefore, when the STA needs to switch services or needs multiple services at the same time, it is necessary to perform repeated authentication with multiple service devices, which will cause great trouble to the user.
  • the technical problem mainly solved by the present application is to provide a method and system for authentication association, which can avoid repeated authentication.
  • the first aspect of the present application provides an authentication association method, including the following steps:
  • the access point AP receives the authentication result query request sent by the service device, where the authentication result query request is used to query whether the STA that sends the association request to the service device passes the authentication of the AP, and whether the STA is queried. Passing the authentication of the AP; sending the result of the authentication result query request to the service device, so that the service device determines whether to establish an association with the station STA according to the result of the authentication query request.
  • the step of the access point AP receiving the authentication result query sent by the service device includes: the AP and the station STA performing authentication .
  • the second aspect of the present application provides an authentication association method, including the following steps:
  • the service device receives the association request sent by the STA, and sends an authentication result query request to the AP, where the authentication result query request is used to query whether the STA that sends the association request to the service device passes the authentication of the AP; And receiving a result of the authentication result query sent by the AP, and determining, according to a result of the authentication query request, whether to establish an association with the station STA.
  • the service device if the STA passes the authentication of the AP, the service device establishes an association with the STA; or if the STA is If the authentication by the AP is not performed, the service device refuses to establish an association with the STA.
  • the third aspect of the present application provides an access point AP, including a receiving module, a querying module, and a sending module.
  • the receiving module is configured to receive an authentication result query request sent by a service device, where the authentication result query request is used for Querying whether the STA that sends the association request to the service device passes the authentication of the AP;
  • the querying module is configured to query whether the STA passes the authentication of the AP;
  • the sending module is used to send the service device And sending the result of the authentication result query request, so that the service device determines whether to establish an association with the station STA according to the result of the authentication query request.
  • the AP further includes an authentication module, where the authentication module is configured to perform authentication with the STA and the service device.
  • the fourth aspect of the present application provides a service device, including a receiving module, a sending module, and an association module, where the receiving module is configured to receive an association request sent by the STA, and the sending module is configured to send an authentication result query request to the AP, where The authentication result query request is used to query whether an STA that sends the association request to the service device passes the authentication of the AP; the receiving module is further configured to receive a result that the AP sends the authentication result query request Determining whether to establish an association with the station STA according to the result of the authentication query request.
  • the association module is configured to establish an association with the STA
  • the service device refuses to establish an association with the STA.
  • a fifth aspect of the present application provides an access point AP, including a receiver, a processor, and a transmitter;
  • the receiver is configured to receive an authentication result query request sent by the service device, where the authentication result query is used to query whether a site STA that sends an association request to the service device passes the authentication of the AP; Querying whether the STA passes the authentication of the AP; the sender is configured to send a result of the authentication result query request to the service device, so that the service device determines, according to a result of the authentication query request, whether The site STA establishes an association.
  • the processor is further configured to perform authentication with the STA and the service device.
  • a sixth aspect of the present application provides a service device, including a receiver, a transmitter, and a processor, where the receiver is configured to receive an association request sent by a STA, and the sender is configured to send an authentication result query request to the AP, where the The authentication result query request is used to query whether the STA that sent the association request to the service device passes the authentication of the AP; the receiver is further configured to receive a result of the AP sending the authentication result query request, according to Determining, by the result of the authentication query request, whether to establish an association with the STA of the station; if the STA passes the authentication of the AP, the processor is used to establish an association with the STA; or if the STA fails to pass The authentication of the AP, the service device refuses to establish an association with the STA.
  • the seventh aspect of the present application provides an authentication method, including the following steps: an access point AP receives a request for acquiring authentication information sent by a service device, where the request for obtaining authentication information is sent by the service device to the STA Sending an authentication information response to the service device, wherein the authentication information response includes authentication information that the service device must have when performing authentication, so that the service device is configured according to the The authentication information authenticates the STA.
  • An eighth aspect of the present application provides an authentication method, including the following steps:
  • the service device receives the authentication request sent by the STA; sends a request for obtaining the authentication information to the AP; and receives the authentication information response sent by the AP, where the authentication information response includes the information that the service device must have when performing the authentication.
  • Authentication information ; authenticating the STA that sent the authentication request.
  • the ninth aspect of the present application provides an access point AP, including a receiving module and a sending module;
  • the receiving module is configured to receive a request for acquiring an authentication message sent by the service device, where the request for acquiring the authentication information is sent by the service device after receiving the authentication request sent by the STA; Sending an authentication information response to the service device, where the authentication information response includes authentication information that the service device must have when performing authentication, so that the service device performs the STA on the STA according to the authentication information. Certification.
  • a tenth aspect of the present application provides a service device, including: a receiving module, a sending module, and an authentication module;
  • the receiving module is configured to receive an authentication request sent by the STA, where the sending module is configured to send a request for acquiring the authentication information to the AP, where the receiving module is further configured to receive the authentication information response sent by the AP, where The authentication information response includes authentication information that the service device must have when performing authentication, and the authentication module is configured to perform authentication with the STA.
  • An eleventh aspect of the present application provides an access point AP, including: a receiver and a sender; the receiver is configured to receive a request for acquiring an authentication message sent by a service device, where the request for obtaining the authentication information is And being sent by the service device after receiving the authentication request sent by the STA; the sender is configured to send an authentication information response to the service device, where the authentication information response includes the service device performing authentication Authentication information that must be provided to enable the service device to authenticate the STA according to the authentication information.
  • the twelfth aspect of the present application provides a service device, including: a receiver, a transmitter, and a processor; the receiver is configured to receive an authentication request sent by the STA; and the sender is configured to send, to the AP, a request for acquiring the authentication information; The receiver is further configured to receive an authentication information response sent by the AP, where the authentication information response includes authentication information that the service device must have when performing authentication, and the processor is configured to perform with the STA. Certification.
  • the service device after receiving the association request sent by the STA, the service device only needs to obtain the result of the authentication query request from the access point AP to determine whether to associate with the STA. In this manner, the trouble caused by repeated authentication can be avoided.
  • FIG. 1 is a schematic structural diagram of a prior art authentication association
  • FIG. 2 is a schematic structural diagram of an implementation manner of an authentication association system of the present application.
  • FIG. 3 is a flowchart of a first possible implementation manner of the authentication association method of the present application.
  • FIG. 5 is a flowchart of a third possible implementation manner of the authentication association method of the present application.
  • FIG. 6 is a schematic structural diagram of a first possible implementation manner of an access point AP of the present application.
  • FIG. 7 is a schematic structural diagram of a second possible implementation manner of an access point AP of the present application.
  • FIG. 8 is a schematic structural diagram of a third possible implementation manner of an access point AP of the present application.
  • FIG. 9 is a schematic structural diagram of a first possible implementation manner of a service device of the present application.
  • FIG. 10 is a schematic structural diagram of a second possible implementation manner of a service device of the present application.
  • FIG. 11 is a schematic structural diagram of a device according to a first possible implementation manner of an access point AP of the present application.
  • FIG. 12 is a schematic structural diagram of a device according to a first possible implementation manner of the service device of the present application.
  • FIG. 13 is a schematic structural diagram of another embodiment of an authentication association system of the present application.
  • 15 is a flow chart of a second possible implementation manner of the authentication method of the present application.
  • 16 is a flow chart of a third possible implementation manner of the authentication method of the present application.
  • FIG. 17 is a schematic structural diagram of a fourth possible implementation manner of an access point AP according to the present application.
  • FIG. 18 is a schematic structural diagram of a fifth possible implementation manner of an access point AP according to the present application.
  • FIG. 19 is a schematic structural diagram of a third possible implementation manner of a service device of the present application.
  • FIG. 20 is a schematic structural diagram of a third possible implementation manner of a service device of the present application.
  • 21 is a schematic structural diagram of a second possible implementation manner of an access point AP of the present application.
  • FIG. 22 is a schematic structural diagram of a second possible implementation manner of a service device of the present application.
  • FIG. 2 is a schematic structural diagram of an embodiment of an authentication association system of the present application.
  • the authentication association system 200 in this embodiment includes: an access point AP 201, a station STA 202 and the first service device 203 and the second service device 204. Wherein, whether the first service device 203 or the second service device 204 is a special site STA 202.
  • the access point 201 and the site 202, between the access point 201 and the first service device 203 and the second service device 204, and between the site 202 and the first service device 203 and the second service device 204 can be performed. Wireless communication.
  • Access point AP of the present embodiment 201 is a network control device, which is a management unit for authenticating a service device or a STA that needs to establish a connection with the service device. It can form a base station subsystem BSS and can be connected to the distributed system DS.
  • Site STA 202 is a communication device having a communication function, such as a mobile phone, capable of communicating with an access point and a service device through authentication association.
  • the first service device 203 and the second service device 204 are service devices having a communication function, and the service devices in the present invention can be seen as special STAs. Such as printers, laptops, etc.
  • the access point 201 is a WiFi access point provided by the hotel
  • the site 202 is a mobile phone provided by the guest, and the like
  • the first service device 203 and the second service device 204 are Service equipment provided by the hotel. Therefore, the first service device 203 and the second service device 204 have typically been authenticated and associated with the access point 202 and can communicate directly.
  • the guest After obtaining the access password of the access point 201, the guest connects the site 202 with the access point 201 by using the access password. Therefore, the station 202 issues an authentication request and an association request to the access point 201. After the site 201 and the access device 201 are authenticated and associated, the connection is established.
  • the site 202 issues an association request to the first service device 203 and the second service device 204, respectively.
  • the site 202 is able to pass the request of the access point 201, it can be known that the owner of the site 202 is a guest of the hotel, and therefore should have access to the service equipment provided by the hotel. Therefore, after receiving the association request, the first service device 203 and the second service device 204 only need to send an authentication result query request to the access point 201 to query whether the site 202 has passed the authentication of the access point 201.
  • the site 202 If the site 202 has passed the authentication of the access point 201, it is deemed to have passed the authentication of the first service device 203 and the second service device 204. After the first service device 203 and the second service device 204 are respectively associated with the site 202, the first service device 203 and the second service device 204 establish a connection with the site 202. If the site 202 does not have authentication through the access point 201, then the association with the first service device 203 and the second service device 204 cannot be established.
  • the STA 101 in FIG. 1 needs to be connected to the first printer 102 or the computer 104, the STA 101 must be authenticated and associated with the first printer 102 or computer 104, when the STA When 101 needs to establish a connection with both, it needs to be authenticated and associated with the two.
  • the STA When the 202 needs to be connected to the first service device 203 or the second service device 204, after receiving the association request sent by the STA 202, the first service device 203 or the second service device 204 only needs to access the AP from the access point.
  • the 201 can obtain the authentication query result to determine whether the STA 202 is authenticated.
  • the STA can directly associate with the service device.
  • service devices from AP The process of obtaining the result of the authentication query is much simpler than the authentication with the station STA, and when the STA This advantage is more apparent when 202 and a plurality of service devices, such as STAs, need to establish a connection with the first service device 203 and the second service device 204 at the same time. Therefore, the present application greatly simplifies the process of establishing a connection between a station STA and a service device.
  • FIG. 3 is a flowchart of a first possible implementation manner of the authentication association method of the present application.
  • the implementation manner includes the following steps:
  • the access point AP receives an authentication result query request sent by the service device, where the authentication result query request is used to query whether the STA that sends the association request to the service device passes the authentication of the AP.
  • the site Since the STA is authenticated by the access point if it is authenticated by the access point, the site is considered to be eligible to establish a connection with the serving device. Therefore, when the service device receives the association request sent by the site, the service device sends an authentication result query request to the access point, and the access point correspondingly receives the authentication result query request sent by the service device.
  • S302 Query whether the STA passes the authentication of the AP.
  • the access point AP sends the result of the authentication result query request to the service device, so that the service device determines whether to establish association with the station STA according to the result of the authentication query request.
  • the AP After receiving the authentication result query request sent by the service device, the AP determines whether the STA that sends the association request to the service device has passed the authentication, and sends the authentication result to the service device. If the authentication result shows that the STA has passed the authentication of the AP, it indicates that the STA has the right to associate with the service device. If the authentication result indicates that the STA does not pass the AP authentication, the STA cannot establish an association with the service device, and the process ends.
  • the service device can directly query whether the STA that sends the authentication request to the service device passes the authentication by performing the result query to the AP, and does not need to perform repeated authentication with the STA again, so that the STA performs the service with the same authentication mode.
  • it When switching communication or communicating with multiple service devices at the same time, it only needs to be authenticated once with the AP, which avoids the trouble caused by repeated authentication.
  • FIG. 4 is a flowchart of a second possible implementation manner of the authentication association method of the present application.
  • S401 The AP completes mutual authentication with the service device in the same network.
  • the AP can be mutually authenticated by the AP and the service devices on the same network.
  • the hotel's access point and the service equipment provided in the hotel can be pre-set to complete mutual authentication.
  • the AP sends the information of the service device to the STA, where the service device has completed mutual authentication with the AP. For example, after the guest enters the hotel, the hotel access point AP will send the guest information about the service equipment that the hotel can use, such as a printer, for the residents to refer to whether there is a need for use, when the guest determines that it is necessary to establish with the service equipment. When connecting, authenticate with the AP.
  • S403 The AP performs an authentication message with the STA to complete the authentication.
  • the AP establishes an association with the STA, where the association includes the AP and the STA exchange device name, address, speed, and power, and the STA further completes registration on the distributed system DS.
  • the access point AP receives the authentication result query request sent by the service device, where the authentication result query is used to query whether the STA that sends the association request to the service device passes the authentication of the AP.
  • the station STA can be considered to be eligible to establish a connection with the service device. Therefore, when the service device receives the association request sent by the site, the service device sends an authentication result query request to the access point to determine whether the STA has the right to associate with the service device.
  • the access point AP queries whether the STA passes the authentication of the AP.
  • the access point AP sends the result of the authentication result query request to the service device, so that the service device determines whether to establish an association with the station STA according to the result of the authentication query request.
  • the access point AP sends the result of the authentication result query to the service device. If the authentication result shows that the STA has passed the authentication of the AP, it indicates that the STA has the right to associate with the service device. If the authentication result indicates that the STA does not pass the AP authentication, the STA cannot associate with the service device.
  • the service device can directly determine whether the STA is authenticated by querying the AP. If the STA passes the AP authentication, the service device associates with the STA. If the STA fails to pass the STA. If the AP is authenticated, the service device refuses to associate with the STA. Optionally, the service device may send a reply message to the STA to refuse to establish an association, and the service device itself does not need to perform repeated authentication with the STA again, thereby causing the STA to have the same authentication mode. When the service device performs handover communication or communicates with multiple service devices at the same time, it only needs to be authenticated once with the AP, which avoids the trouble caused by repeated authentication.
  • FIG. 5 is a flowchart of a third possible implementation manner of the authentication association method of the present application.
  • the embodiment includes the following steps:
  • S501 The service device receives an association request sent by the STA.
  • the service device sends an authentication result query request to the AP, where the authentication result query is used to query whether the STA that sends the association request to the service device passes the authentication of the AP.
  • the station STA Since the site STA is authenticated by the access point AP, the station STA can be considered to be eligible to establish a connection with the service device. Therefore, the service device sends an authentication result query to the access point to determine whether the STA is eligible to associate with the service device.
  • step S503 The service device receives a result of the authentication result query request sent by the AP, and determines whether to establish an association with the station STA according to the result of the authentication query request. If the result of the authentication query indicates that the STA has passed the authentication of the AP, step S504 is performed. If the STA does not pass the authentication of the AP, step S105 is performed.
  • the serving device sends an association confirmation message to the STA, and associates with the STA, where the establishing the association includes the STA and the service device exchanging the device name, the address, the speed, and the power.
  • the service device refuses to associate with the STA.
  • the service device may send a reply message to the STA to refuse to associate with the STA.
  • the service device determines whether the STA that sends the authentication request to the service device passes the authentication by querying the AP. If the STA passes the authentication, the service device establishes an association with the STA. If the STA fails to pass the authentication, the service device rejects the STA. Establishing an association, in the above manner, when the STA performs handover communication with a service device having the same authentication mode or communicates with multiple service devices at the same time, it only needs to authenticate with the AP once, and does not need to perform authentication again with each service device to avoid The trouble caused by repeated verifications.
  • FIG. 6 is a schematic structural diagram of a first possible implementation manner of an access point AP according to the present application.
  • the 600 includes a receiving module 610, a query module 620, and a sending module 630.
  • the receiving module 610 is configured to receive an authentication result query request sent by the service device, where the authentication result query request is used to query whether the station STA that sends the association request to the service device passes the AP 600 certification;
  • the site Because if the site passes the access point AP For the 600 certification, the site is considered to be eligible to establish a connection with the service device. Therefore, when the service device receives the association request sent by the site, the service device sends an authentication result query to the access point, and the receiving module 610 correspondingly receives the authentication result query sent by the service device.
  • the querying module 620 is configured to query whether the STA passes the authentication of the AP 600.
  • the sending module 630 is configured to send the result of the authentication result query request to the service device, so that the service device determines whether to establish an association with the station STA according to the result of the authentication query request.
  • the receiving module 610 receives, by the serving device, an STA for querying whether to send an association request to the serving device, whether the STA passes the AP.
  • the query module 820 queries whether the STA passes the AP.
  • the authentication of 600 and then the sending module 830 sends the result to the service device, so that the service device determines whether to establish an association with the station STA according to the result of the authentication query request. If the authentication result shows that the STA has passed the authentication of the AP, it indicates that the STA has the right to associate with the service device. If the authentication result indicates that the STA does not pass the AP authentication, the STA cannot associate with the service device, and the association includes the service device. Exchange device name, address, speed, and power with the STA.
  • the service device can directly determine whether the STA is authenticated by querying the AP. If the STA passes the AP authentication, the service device associates with the STA. If the STA fails to pass the STA. The authentication of the AP, the service device refuses to establish association with the STA, and the service device itself does not need to perform repeated authentication with the STA again, so that the STA performs handover communication with the service device having the same authentication mode or simultaneously communicates with multiple service devices. It only needs to be authenticated once with the AP, which avoids the trouble of repeated authentication.
  • FIG. 7 is a schematic structural diagram of a second possible implementation manner of an access point AP of the present application.
  • Access point AP in this embodiment The 700 includes an authentication module 710, an association module 720 receiving module 9730, a query module 740, and a sending module 750.
  • the authentication module 710 is configured to perform authentication with the STA and the service device. For example, after the guest enters the hotel, the hotel access point AP will send the guest information about the service equipment that the hotel can use, such as a printer, for the residents to refer to whether there is a need for use, when the guest determines that it is necessary to establish with the service equipment. When connected, it can be authenticated with the AP.
  • the hotel access point AP will send the guest information about the service equipment that the hotel can use, such as a printer, for the residents to refer to whether there is a need for use, when the guest determines that it is necessary to establish with the service equipment. When connected, it can be authenticated with the AP.
  • the association module 720 is configured to establish an association with the STA, where the establishing the association includes the AP and the STA exchanging the device name, the address, the speed, and the power, and further including the STA completing the registration on the distributed system DS.
  • the query module 730 is configured to query whether the STA passes the authentication of the AP 700.
  • the receiving module 740 is configured to receive an authentication result query request sent by the service device, where the authentication result query request is used to query whether the station STA that sends the association request to the service device passes the AP 700 certification.
  • the station STA can be considered to be eligible to establish a connection with the service device. Therefore, when the service device receives the association request sent by the site, the service device sends an authentication result query to the access point to determine whether the STA has the right to associate with the service device.
  • the sending module 740 is configured to send a result of the authentication result query to the service device, so that the service device determines whether to establish an association with the station STA according to a result of the authentication query request.
  • the authentication result shows that the STA has passed the authentication of the AP, it indicates that the STA has the right to associate with the service device. If the authentication result indicates that the STA does not pass the AP authentication, the STA cannot associate with the service device.
  • FIG. 8 is a schematic structural diagram of a third possible implementation manner of the access point AP of the present application, which is an AP in FIG. 700 for further refinement description.
  • the 800 includes a first sending module 810 and an authentication module 820.
  • the authentication module 820 includes a first authentication module 8201 and a second authentication module 8202, an association module 830, a receiving module 840, and a second sending module 860.
  • the first sending module 810 is configured to send information about the service device to the STA. For example, after the guest enters the hotel, the hotel access point AP sends information about the service device that the hotel can use, such as a printer, for the reference of the guest. There is a need to use, when the guest determines that there is a need to establish a connection with the service device, it can be authenticated with the AP.
  • the first authentication module 8201 is configured to perform an authentication session with the STA to complete the authentication, where the STA sends the information of the service device to the AP, and the STA that needs to connect to the service device has been selected from the necessary information.
  • the second authentication module 8202 is configured to complete the authentication by the service device in the same network as the AP 800.
  • the association module 830 is configured to establish an association with the STA, where the association includes the AP and the STA exchange device name, address, speed, and work, and the STA further completes registration on the distributed system DS.
  • the receiving module 840 is configured to receive an authentication result query request sent by the service device, where the authentication result query request is used to query whether the STA that sends the association request to the service device passes the authentication of the AP.
  • the query module 850 is configured to query whether the STA passes the authentication of the AP 800.
  • the station STA can be considered to be eligible to establish a connection with the service device. Therefore, when the service device receives the association request sent by the site, the service device sends an authentication result query to the access point to determine whether the STA has the right to associate with the service device.
  • the second sending module 860 is configured to send a result of the authentication result query to the service device, so that the service device determines whether to establish an association with the station STA according to a result of the authentication query request.
  • the authentication result shows that the STA has passed the authentication of the AP, it indicates that the STA has the right to associate with the service device. If the authentication result indicates that the STA does not pass the AP authentication, the STA cannot associate with the service device.
  • the second authentication module 8402 and the same AP The service device of the same network performs authentication.
  • the first sending module 810 sends the information of the service device to the STA, where the service device is the AP and the AP.
  • the 810 completes the mutual authentication service device.
  • the first authentication module 8201 performs an interaction of the authentication message with the STA to complete the authentication, and then associates the mode 830 with The STA establishes an association, and after the STA sends the association request to the service device, the receiving module 840 receives the authentication result query sent by the service device, where the authentication result query is used to query whether the STA that sends the association request to the service device passes.
  • the authentication of the AP the query module 850 queries whether the STA passes the AP.
  • the authentication of 800 is performed, and the result of the authentication query is sent to the service device by the second sending module 860, so that the service device determines whether to establish an association with the station STA according to the result of the authentication query request.
  • the service device can directly determine whether the STA is authenticated by querying the AP. If the STA passes the AP authentication, the service device associates with the STA. If the STA fails to pass the STA. The authentication of the AP, the service device refuses to establish association with the STA, and the service device itself does not need to perform repeated authentication with the STA again, so that the STA performs handover communication with the service device having the same authentication mode or simultaneously communicates with multiple service devices. It only needs to be authenticated once with the AP, which avoids the trouble of repeated authentication.
  • FIG. 9 is a schematic structural diagram of a first possible implementation manner of a service device according to the present application.
  • the service device 900 of the present embodiment includes a receiving module 910, a sending module 920, and an association module 930.
  • the receiving module 910 is configured to receive an association request sent by the STA.
  • the sending module 920 is configured to send an authentication result query request to the AP, where the authentication result query is used to query whether the STA that sends the association request to the service device passes the authentication of the AP. Since the site STA is authenticated by the access point AP, the station STA can be considered to be eligible to establish a connection with the service device. Therefore, the sending module 920 sends an authentication result query to the access point to determine whether the STA has the right to associate with the service device.
  • the receiving module 910 is further configured to receive a result of the authentication result query sent by the AP, and determine, according to a result of the authentication query request, whether to establish an association with the station STA.
  • the service device 900 If the result of the authentication query indicates that the STA that sent the association request to the serving device has passed the authentication of the AP, the service device 900 considers that the station STA has the right to establish a connection with the service device 900, and the sending module 920 is configured to send the STA to the STA. Associate confirmation message.
  • the association module 930 is configured to establish an association with the STA, where establishing the association includes the service device and the STA exchanging the device name, address, speed, and power.
  • the association module 930 refuses to associate with the STA.
  • the sending module 920 sends a reply message to the STA to refuse to associate with the STA.
  • FIG. 10 is a schematic structural diagram of a second possible implementation manner of the service device of the present application, and the service device 1000 in FIG. 10 is the service device 900 of FIG. Further refinement.
  • the service device 1000 of the present embodiment includes: a first receiving module 1010, a first sending module 1020, a second receiving module 1030, a second sending module 1040, and an associating module 1050.
  • the first receiving module 1010 is configured to receive an association request sent by the STA.
  • the first sending module 1020 is configured to send an authentication result query request to the AP, where the authentication result query is used to query whether the STA that sends the association request to the service device passes the authentication of the AP. Since the site STA is authenticated by the access point AP, the station STA can be considered to be eligible to establish a connection with the service device.
  • the second receiving module 1030 is configured to receive a result of the authentication result query request sent by the AP, and determine, according to a result of the authentication query request, whether to establish an association with the station STA.
  • the service device 1000 If the STA of the STA passes the authentication of the access point AP, the service device 1000 considers that the STA has the right to establish a connection with the service device 1000. At this time, the first sending module 1020 is configured to send an association confirmation message to the STA.
  • the STA cannot establish an association with the service device 1000, and the second sending module 1040 is configured to send a reply message to the STA to reject the association request.
  • the association module 1050 is configured to establish an association with the STA, wherein establishing the association includes the service device and the STA exchanging the device name, address, speed, and power.
  • the first receiving module 1010 receives the association request sent by the STA.
  • the first sending module 1020 sends an authentication result query request to the AP, in order to determine whether the STA that sends the association request to the serving device passes the AP authentication.
  • the second receiving module 1030 receives the result of the authentication result query request sent by the AP, and determines whether to establish an association with the station STA according to the result of the authentication query request. If the result of the authentication query indicates that the STA that sent the association request to the serving device has passed the authentication of the AP, the second sending module 1020 sends an association confirmation message to the STA, and the association module 1050 establishes an authentication with the STA. If the STA does not pass the AP authentication, The service device sends a reply message to the STA rejecting the association request.
  • the service device determines whether the STA that sends the authentication request to the service device passes the authentication by querying the AP. If the STA passes the authentication, the service device establishes an association with the STA. If the STA fails to pass the authentication, the service device rejects the STA. Establishing an association, in the above manner, when the STA performs handover communication with a service device having the same authentication mode or communicates with multiple service devices at the same time, it only needs to authenticate with the AP once, and does not need to perform authentication again with each service device to avoid The trouble caused by repeated verifications.
  • FIG. 11 is a schematic structural diagram of a device according to a first possible implementation manner of an access point AP of the present application.
  • AP of the present embodiment 1100 includes a receiver 1110, a transmitter 1120, and a processor 1130.
  • the receiver 1110 is configured to receive an authentication result query request sent by the service device, where the authentication result query request is used to query whether the site STA that sends the association request to the service device passes the authentication of the AP.
  • the STA can be considered to be eligible to establish a connection with the service device. Therefore, when the service device receives the association request sent by the STA, the service device sends an authentication result query request to the access point, and the receiver 1110 correspondingly receives the authentication result query request sent by the service device.
  • the processor 1130 is configured to query whether the STA passes the authentication of the AP.
  • the sender 1120 is configured to send a result of the authentication result query to the service device, so that the service device determines whether to establish an association with the station STA according to a result of the authentication query request.
  • the authentication of the 1100 indicates that the STA has the right to associate with the service device. If the authentication result shows that the STA does not pass the authentication of the AP 1100, the STA cannot associate with the service device.
  • the processor 1130 is further configured to perform authentication with the STA and the serving device, and further for establishing an association with the STA.
  • the establishing the association includes the AP and the STA exchanging the device name, the address, the speed, and the power, and further including the STA completing the registration on the distributed system DS.
  • the hotel access point AP will send the guest information about the service equipment that the hotel can use, such as a printer, for the residents to refer to whether there is a need for use, when the guest determines that it is necessary to establish with the service equipment.
  • the AP can be authenticated.
  • the processor 1130 and the STA are required to perform authentication, and before that, the AP The 1100 needs to be authenticated and associated with the service device.
  • bus 1140 which may include, in addition to the data bus, a power bus, a control bus, a status signal bus, and the like. However, for clarity of description, various buses are labeled as bus 1140 in the figure.
  • the service device of the 1100 is authenticated by the service device.
  • the sender 1110 sends the information of the service device to the STA, where the service device is the AP.
  • the service device of the mutual authentication is completed.
  • the processor 1130 performs an authentication message interaction with the STA to complete the authentication, and then associates with the STA.
  • the receiver 1110 receives the authentication result query request sent by the service device, where the authentication result query request is used to query whether the station STA that sends the association request to the service device passes the AP authentication.
  • the server queries whether the STA has passed the AP. If the authentication result shows that the STA has passed the AP authentication, the STA has the qualification to associate with the service device. At this time, the sender 1120 sends the authentication result of the STA that sends the association request to the service device to the service device. And causing the service device to determine whether to establish an association with the station STA according to a result of the authentication query request. Then, the processor 1130 establishes an association with the STA and registers the STA on the distributed system. If the authentication result indicates that the STA does not pass the AP authentication, the STA cannot associate with the service device.
  • the service device can directly determine whether the STA is authenticated by querying the AP. If the STA passes the AP authentication, the service device associates with the STA. If the STA fails to pass the STA. The authentication of the AP, the service device refuses to establish association with the STA, and the service device itself does not need to perform repeated authentication with the STA again, so that the STA performs handover communication with the service device having the same authentication mode or simultaneously communicates with multiple service devices. It only needs to be authenticated once with the AP, which avoids the trouble of repeated authentication.
  • FIG. 12 is a schematic structural diagram of a device according to a first possible implementation manner of the service device of the present application.
  • the service device 1200 of the present embodiment includes a transmitter 1210, a receiver 1220, and a processor 1230.
  • the various components of the service device 1200 are coupled together by a bus 1240, which may include, in addition to the data bus, a power bus, a control bus, a status signal bus, and the like. However, for clarity of description, various buses are labeled as bus 1240 in the figure.
  • the receiver 1220 is configured to receive an association request sent by the STA.
  • the sender 1210 is configured to send an authentication result query to the AP, where the authentication result query is used to query whether the STA that sends the association request to the service device passes the authentication of the AP.
  • the station STA Since the site STA is authenticated by the access point AP, the station STA can be considered to be eligible to establish a connection with the service device. Therefore, the service device sends an authentication result query to the access point to determine whether the STA is eligible to associate with the service device.
  • the receiver 1220 is further configured to receive a result of the authentication result query sent by the AP, and determine, according to the result of the authentication query request, whether to establish an association with the STA of the station;
  • the sender 1210 is configured to send an association confirmation message to the STA.
  • the processor 1230 uses Establishing an association with the STA, wherein establishing the association includes the service device 1200 and the STA exchanging the device name, address, speed, and power.
  • the STA does not pass the authentication of the AP, the STA cannot establish an association with the service device 1200, and the sender 1210 is configured to send a reply message to the STA to reject the association request.
  • the receiver 1220 receives the association request sent by the STA. After receiving the request, the sender 1210 sends an authentication result query to the AP to determine whether the STA that sends the association request to the service device passes the AP authentication. After the device 1200 sends the result of the authentication, the receiver 1220 receives the result of the authentication result query sent by the AP, and determines whether to establish an association with the station STA according to the result of the authentication query request. If the result of the authentication query indicates that the STA that sent the association request to the serving device has passed the authentication of the AP, the sender 1210 sends an association confirmation message to the STA, and the server 1230 establishes an authentication with the STA. If the STA does not pass the AP's authentication, the service device may send a reply message to the STA to reject the association request.
  • the service device determines whether the STA that sends the authentication request to the service device passes the authentication by querying the AP. If the STA passes the authentication, the service device establishes an association with the STA. If the STA fails to pass the authentication, the service device rejects the STA. Establishing an association, in the above manner, when the STA performs handover communication with a service device having the same authentication mode or communicates with multiple service devices at the same time, it only needs to authenticate with the AP once, and does not need to perform authentication again with each service device to avoid The trouble caused by repeated verifications.
  • FIG. 13 is a schematic structural diagram of another embodiment of the authentication association system of the present application.
  • the authentication association system 1300 in this embodiment includes: an access point AP 1301, a station STA 1302.
  • the first service device 1303 and the second service device 1304 are both special site STAs, whether the first service device 1303 or the second service device 1304.
  • Access point AP of the present embodiment is a network control device, and is a management unit for authenticating a service device or a STA that needs to establish a connection with the service device.
  • the base station subsystem BSS can be set up and can be connected to the distributed system DS.
  • Access point AP 1301 includes WiFi and the like.
  • the 1302 is a communication device having a communication function, such as a mobile phone, capable of communicating with an access point and a service device through authentication and association.
  • the first service device 1303 and the second service device 1804 are service devices having a communication function, such as a printer, a notebook computer, and the like. It should be noted that the service devices in the present invention are all special STAs.
  • the access point 1301 is a WiFi access point provided by the hotel
  • the site 1302 is a mobile phone provided by the guest, and the like
  • the first service device 1303 and the second service device 1304 are Service equipment provided by the hotel.
  • the authentication information of the service devices is generally stored in the access point AP that is in the same network as the service device.
  • Site STA when the guest needs to use the first service device 1303 and the second service device 1304 1302 sends an authentication request to the first serving device 1303 and the second serving device 1304, respectively.
  • the first serving device 1303 and the second serving device 1304 receive the authentication request, and the STA The 1302 interactive authentication message completes the authentication.
  • the first service device 1303 and the second service device 1304 do not have their own authentication message, and therefore need to obtain the authentication message from the AP 1301, and then cooperate with the STA. 1302 completed the certification.
  • FIG. 14 is a flowchart of a first possible implementation manner of the authentication method of the present application. This embodiment includes the following steps:
  • the access point AP receives the request for acquiring the authentication information sent by the service device, where the request for acquiring the authentication information is sent by the service device after receiving the authentication request sent by the STA.
  • the request for the authentication message of the service device must be obtained from the AP, corresponding to the AP. A request to receive an authentication message for the service device.
  • the access point AP sends the acquisition authentication information response to the service device, where the authentication information response includes authentication information that the service device must have when performing authentication, so that the service device is configured according to the The authentication information authenticates the STA.
  • the corresponding service device After the AP sends the authentication information that is required to be authenticated by the service device to the service device, the corresponding service device receives the authentication message and performs authentication with the STA.
  • the authentication information that must be possessed by the service device to obtain the service device can be authenticated with the STA, so that the authentication process is more flexible and the service device is not available.
  • the authentication information that must be possessed at the time of authentication cannot cause connection and affect the use of the customer.
  • FIG. 15 is a flowchart of a second possible implementation manner of the authentication method of the present application. This embodiment includes the following steps:
  • the access point AP sends the information of the service device to the STA. For example, after the guest enters the hotel, the hotel access point AP will send information about the service equipment that the hotel can use to the guest's mobile phone, such as a printer, for the residents to refer to whether there is a need for use, if necessary, the guest can directly Send an authentication request to the service device through the mobile phone.
  • the hotel access point AP will send information about the service equipment that the hotel can use to the guest's mobile phone, such as a printer, for the residents to refer to whether there is a need for use, if necessary, the guest can directly Send an authentication request to the service device through the mobile phone.
  • the access point AP receives the request for acquiring the authentication message sent by the service device, where the request for obtaining the authentication information is sent by the service device after receiving the authentication request sent by the STA.
  • the service device receives the authentication request sent by the STA and the service device does not have the authentication message that is authenticated by the STA, in order to establish a connection with the STA, the authentication message of the service device must be obtained from the AP.
  • the access point AP sends the acquisition authentication information response to the service device, where the authentication information response includes authentication information that the service device must have when performing authentication, so that the service device is configured according to the The authentication information authenticates the STA.
  • the access point AP authenticates with the STA and establishes association.
  • the access point AP sends a response to the service device to obtain an authentication message that includes the authentication message that is required to be authenticated by the service device
  • the AP may perform authentication and association with the STA, so as to facilitate the STA and other users to have their own authentication.
  • a service device that must have an authentication message establishes a connection.
  • the establishing association includes the AP and the STA exchanging device name, address, speed, and power, and further including that the STA completes registration on the distributed system DS.
  • the service device after receiving the authentication request of the STA, the service device only needs to obtain the authentication information that the service device must have when authenticating the service device, and can establish the authentication with the STA, and further establish the association, so that the authentication association process is more flexible. This avoids the trouble of not being able to establish a connection or affecting the use of the customer due to the authentication information that the service device does not have when it is certified.
  • Figure 16 is a flow chart of a third possible implementation of the authentication method of the present application. This embodiment includes the following steps:
  • S1601 The service device receives an authentication request sent by the STA.
  • the STA After determining the service device that needs to be connected, the STA needs to send an authentication request to the service device. Correspondingly, the service device receives the authentication request.
  • the service device sends a request for obtaining the authentication information to the AP.
  • the service device When the service device receives the authentication message and the authentication message is authenticated by the STA and the STA, the service device must obtain the authentication message of the service device from the AP in order to establish a connection with the STA.
  • the service device receives the acquisition authentication information response sent by the AP, where the authentication information response includes authentication information that the service device must have when performing authentication.
  • S1604 The service device performs authentication with the STA that sends the authentication request. After obtaining the authentication message that must be obtained from the AP, the service device can authenticate with the STA.
  • the service device receives the association request sent by the authenticated STA.
  • the serving device determines whether to agree to establish an association with the STA, and if it agrees to establish an association with the STA, replies to the STA with an association response and associates with the STA.
  • the establishing association includes the service device exchanging device name, address, speed, and power with the STA. If the service device does not agree to establish an association with the STA, the STA is replied to the veto message.
  • the STA may also authenticate and associate with the AP before the service device establishes authentication and association with the STA.
  • the service device that does not have the authentication information of the STA receives the authentication request of the STA, it only needs to obtain the authentication information that the service device must have when authenticating the service device, and can establish the authentication with the STA, and further establish the association.
  • Establishing a connection makes the authentication association process more flexible, and avoids the trouble that the service device does not have the authentication information that must be possessed when the authentication device is required to establish a connection and affect the use of the client.
  • FIG. 17 is a schematic structural diagram of a fourth possible implementation manner of an access point AP according to the present application.
  • Access point AP in this embodiment 1700 includes a receiving module 1710 and a transmitting module 1720.
  • the receiving module 1710 is configured to receive a request for acquiring an authentication message sent by the service device, where the request for acquiring the authentication information is sent by the service device after receiving the authentication request sent by the STA.
  • the service device If, if the service device receives the authentication request sent by the STA and the service device does not have the authentication message that is authenticated by the STA, in order to establish a connection with the STA, the service device must obtain a request for the authentication message of the service device from the AP, correspondingly, receiving Module 1710 needs to receive a request for an authentication message for the service device.
  • the sending module 1720 is configured to send the acquiring authentication information response to the service device, where the authentication information response includes authentication information that the service device must have when performing authentication, so that the service device is configured according to the The authentication information authenticates the STA.
  • the corresponding service device After the AP sends the authentication information that is required to be authenticated by the service device to the service device, the corresponding service device receives the authentication message and performs authentication with the STA.
  • the sending module 1720 correspondingly sends the authentication message of the service device to the service device, so that the service device can receive the authentication message and further cooperate with the STA. Establish an association.
  • FIG. 18 is a schematic structural diagram of a fifth possible implementation manner of an access point AP according to the present application.
  • the AP of the present embodiment includes a receiving module 1810, and the sending module 1820 further includes an authentication module 1830 and an associated module 1840.
  • the receiving module 1810 is configured to receive a request for acquiring an authentication message sent by the service device, where the request for acquiring the authentication information is sent by the service device after receiving the authentication request sent by the STA.
  • the service device receives the authentication request sent by the STA and the service device does not have the authentication message that the STA is authenticated with the STA, in order to establish a connection with the STA, the request for the authentication message of the service device must be obtained from the AP, correspondingly, The receiving module 1810 needs to receive a request for an authentication message of the service device.
  • the sending module 1820 is configured to send the acquiring authentication information response to the service device, where the authentication information response includes authentication information that the service device must have when performing authentication.
  • the authentication module 1830 is configured to perform authentication with the STA while the service device receives the authentication message and performs authentication with the STA.
  • the association module 1840 is configured to establish an association with the STA when the STA establishes an association with the service device after completing the authentication, where the establishing the association includes the switching device name, the address, the speed, and the power, and further including the STA being distributed. Registration is completed on the system DS.
  • the sending module 1820 is further configured to send a message of the service device to the STA that enters the network.
  • the hotel access point AP will send information about the service equipment that the hotel can use to the guest's mobile phone, such as a printer, for the residents to refer to whether there is a need for use, if necessary, the guest can directly Send an authentication request to the service device through the mobile phone.
  • the sending module 1820 of the access point AP1800 sends a message of the serving device in the network to the STA that enters the network, for the STA to select whether there is a required service device, and the STA selects the service device and sends the authentication request corresponding to the service device.
  • the receiving module 1810 receives the request for acquiring the authentication message sent by the service device, and then sends the authentication message of the service device to the service device by using the sending module 1820, so that the service device and the sending authentication are sent.
  • the requesting STA performs authentication and establishes an association.
  • the authentication module 1830 may also perform an authentication message with the STA to establish an authentication.
  • the association device 1840 may also be associated with the STA. The STA establishes an association to facilitate the STA to establish a connection with other service devices that have authentication messages that must be possessed by the STA.
  • the service device that does not have the authentication information of the STA receives the authentication request of the STA, it only needs to obtain the authentication information that the service device must have when authenticating the service device, and can establish the authentication with the STA, and further establish the association.
  • the authentication association process is more flexible, and the trouble that the service device does not have the authentication information necessary for the authentication cannot be established and affects the use of the client is avoided.
  • FIG. 19 is a schematic structural diagram of a third possible implementation manner of the service device of the present application.
  • the service device 1900 in this embodiment includes a receiving module 1910, a sending module 1920, and an authentication module 1930.
  • the receiving module 1910 is configured to receive an authentication request sent by the STA.
  • the sending module 1920 is configured to send a request for acquiring authentication information to the AP.
  • the receiving module 1910 is further configured to receive an authentication information response sent by the AP, where the authentication information response includes authentication information that the service device must have when performing authentication.
  • the authentication module 1930 is configured to perform authentication with the STA.
  • FIG. 20 is a schematic structural diagram of a third possible implementation manner of the service device of the present application. It should be understood that the service device of FIG. A further refinement of the service equipment in 19.
  • the service device in this embodiment includes a first receiving module 2010, a sending module 2020, a second receiving module 2030, an authentication module 2040, and a third receiving module 2050, and further includes a determining module 2060, a second sending module 2070, and an associating module 2080.
  • the first receiving module 2010 is configured to receive an authentication request sent by the STA.
  • the STA After the STA determines the service device to be connected, it needs to send an authentication request to the service device. Correspondingly, the first receiving module 2010 of the service device receives the authentication request.
  • the sending module 2020 is configured to send a request for acquiring the authentication information to the AP.
  • the service device After receiving the authentication request, the service device does not have the authentication message for authenticating with the STA.
  • the sending module 2020 In order to establish a connection with the STA, the sending module 2020 must obtain the authentication message of the service device from the AP.
  • the second receiving module is configured to receive the obtaining authentication information response sent by the AP, where the authentication information response includes authentication information that the service device must have when performing authentication.
  • the authentication module 2040 authenticates with the STA. After obtaining the authentication message that must be obtained from the AP, the service device authenticates with the STA.
  • the STA needs to establish a connection with the service device. After the authentication is completed, the STA needs to be further associated with the service device. Therefore, the association request needs to be sent to the service device. Correspondingly, the third receiving module 2050 of the service device needs to receive the association request.
  • the determining module 2060 is configured to determine whether to agree to establish an association with the STA.
  • the second sending module 2070 is configured to reply to the STA corresponding to the STA. If the determining module 2060 agrees to establish an association with the STA, the association module 2080 associates with the STA, if the determining module 2060 does not agree to establish an association with the STA.
  • the second sending module 2070 is configured to send a reject message to the STA, where the establishing the association includes the service device and the STA exchanging the device name, address, speed, and power.
  • the sending module 2020 sends a request for acquiring the authentication information to the AP, and then receives the request through the second receiving module 2030.
  • the authentication information sent by the AP is authenticated by the authentication module 2040 and the STA interaction authentication message.
  • the third receiving module 2050 receives the association request sent by the STA.
  • the determining module 2060 determines whether to agree to establish an association with the STA, and then the second sending module 2070 returns an association corresponding to the STA.
  • the association module 2080 establishes an association with the STA, if the determining module 2060 does not agree to establish an association with the STA, and the second sending module 2070 sends a reject message to the STA.
  • the service device that does not have the self-authentication message receives the authentication request of the STA, it only needs to obtain the authentication information that the service device must have when authenticating the service device, and can establish the authentication with the STA, and further establish the association.
  • the authentication association process is more flexible and convenient, and the trouble that the service device does not have the authentication information necessary for the authentication cannot be established and affects the customer's use is avoided.
  • FIG. 21 is a schematic structural diagram of a second possible implementation manner of an access point AP of the present application.
  • the AP of the present embodiment includes a receiver 2110 and a transmitter 2120.
  • the receiver 2110 is configured to receive a request for acquiring an authentication message sent by the service device, where the request for acquiring the authentication information is sent by the service device after receiving the authentication request sent by the STA.
  • the service device If, if the service device receives the authentication request sent by the STA and the service device does not have the authentication message that is authenticated by the STA, in order to establish a connection with the STA, the service device must obtain a request for the authentication message of the service device from the AP, correspondingly, receiving The device 2110 needs to receive a request for an authentication message of the service device.
  • the sender 2120 is configured to send the obtaining authentication information response to the service device, where the authentication information response includes authentication information that the service device must have when performing authentication, so that the service device is configured according to the The authentication information authenticates the STA.
  • the receiver 2120 of the corresponding service device receives the authentication message and performs authentication with the STA.
  • the sender 2120 correspondingly sends the authentication message of the service device to the service device, so that the service device receives the authentication message and further establishes with the STA. Association.
  • the AP of this embodiment further includes a processor 2130, where the processor 2130 is configured to perform authentication and association with the STA, where establishing association includes exchanging device name, address, speed, and power with the STA, and further including The STA completes registration on the distributed system DS.
  • a bus 2140 which may include, in addition to the data bus, a power bus, a control bus, a status signal bus, and the like. However, for clarity of description, various buses are labeled as bus 2140 in the figure.
  • the transmitter 2120 is further configured to send a message of the service device to the STA that enters the network.
  • the hotel access point AP will send information about the service equipment that the hotel can use to the guest's mobile phone, such as a printer, for the residents to refer to whether there is a need for use, if necessary, the guest can directly Send an authentication request to the service device through the mobile phone.
  • the access point AP The transmitter 2120 of the 2100 sends a message of the service device in the network to the STA that enters the network, and the STA selects whether the service device is required.
  • the service device that selects the service device and sends the authentication request to the service device receives the authentication request.
  • the receiver 2110 receives the request for acquiring the authentication message sent by the service device, and then sends the authentication message of the service device to the service device by using the sender 3220, so that the service device authenticates and establishes the STA that sends the authentication request.
  • the server 2130 may also perform an authentication message with the STA to establish an authentication.
  • the server 2130 may also establish an association with the STA to facilitate the STA and the other.
  • the service device that does not have the authentication information of the STA receives the authentication request of the STA, it only needs to obtain the authentication information that the service device must have when authenticating the service device, and can establish the authentication with the STA, and further establish the association.
  • the authentication association process is more flexible and convenient, and the trouble that the service device does not have the authentication information necessary for the authentication cannot be established and affects the customer's use is avoided.
  • FIG. 22 is a schematic structural diagram of a second possible implementation manner of a service device according to the present application.
  • the service device 2200 of the present embodiment includes a receiver 2210, a transmitter 2220, and a processor 2230.
  • the various components of the service device 2200 are coupled together by a bus 2240, which may include, in addition to the data bus, a power bus, a control bus, a status signal bus, and the like. However, for clarity of description, various buses are labeled as bus 2240 in the figure.
  • the receiver 2210 is configured to receive an authentication request sent by the STA.
  • the STA After the STA determines the service device to be connected, it needs to send an authentication request to the service device. Correspondingly, the receiver 2210 of the service device receives the authentication request.
  • the sender 2220 is configured to send a request for acquiring authentication information to the AP.
  • the service device After the receiver 2210 receives the authentication request, the service device itself must obtain the authentication message of the service device from the AP through the transmitter 2220 in order to establish a connection with the STA.
  • the receiver 2210 is further configured to receive an authentication information response sent by the AP, where the authentication information response includes authentication information that the service device must have when performing authentication.
  • the processor 2230 is configured to authenticate the STA. After obtaining the authentication message that must be obtained from the AP, the service device authenticates with the STA.
  • the STA needs to establish a connection with the service device. After the authentication is completed, the STA needs to be further associated with the service device. Therefore, the association request needs to be sent to the service device. Therefore, the receiver 2210 is further configured to receive the association request sent by the authenticated STA.
  • the processor 2230 is further configured to determine that the service device agrees to establish an association with the STA.
  • the processor If the processor agrees to establish an association with the STA, the processor establishes an association with the STA.
  • the processor 2230 does not agree to establish an association with the STA, and the transmitter 2220 sends a reject message to the STA.
  • the establishing the association includes the service device and the STA exchanging the device name, address, speed, and power.
  • the transmitter 2220 sends a request for acquiring the authentication information to the AP, and then receives the AP from the receiver 2210.
  • the processor 2230 performs authentication with the STA interaction authentication message.
  • the receiver 3410 receives the association request sent by the STA, and the processor 2230 determines whether the processor 2230 determines whether Assuming that the association processor with the STA agrees to establish an association with the STA, the processor 2230 associates with the STA, and the processor 2230 does not agree to establish an association with the STA, and the sender sends a reject message to the STA.
  • the authentication information that must be possessed by the service device to obtain the authentication information can be established with the STA, so that the authentication association process is more flexible and convenient. This avoids the inconvenience caused by the certification information that the service equipment does not have when it is certified.
  • the disclosed system, apparatus, and method may be implemented in other manners.
  • the device implementations described above are merely illustrative.
  • the division of the modules or units is only a logical function division.
  • there may be another division manner for example, multiple units or components may be used. Combinations can be integrated into another system, or some features can be ignored or not executed.
  • the mutual coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interface, device or unit, and may be in an electrical, mechanical or other form.
  • the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, may be located in one place, or may be distributed to multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of the present embodiment.
  • each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.
  • the above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
  • the integrated unit if implemented in the form of a software functional unit and sold or used as a standalone product, may be stored in a computer readable storage medium.
  • a computer readable storage medium A number of instructions are included to cause a computer device (which may be a personal computer, server, or network device, etc.) or a processor to perform all or part of the steps of the methods described in various embodiments of the present application.
  • the foregoing storage medium includes: a U disk, a mobile hard disk, a read only memory (ROM, Read-Only) Memory, random access memory (RAM), disk or optical disk, and other media that can store program code.

Abstract

本申请公开了一种认证关联方法及系统,接入点AP接收需要与服务设备建立连接的站点STA所发送的认证请求,AP与STA建立认证,在STA向服务设备发送关联请求后,AP接收服务设备所发出的认证结果查询请求,并向服务设备发送所述认证结果查询请求的结果使服务设备确定是否与STA建立关联,如果结果显示STA通过了AP的认证,则服务设备可与STA建立关联,如果结果表明STA没有通过AP的认证,则STA不能与服务设备建立关联。利用本发明,能够使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与接入点AP认证一次就可实现,避免了重复认证带来的麻烦。

Description

认证关联方法及系统
【技术领域】
本申请涉及通信领域,特别是涉及认证关联方法及系统。
【背景技术】
在现有的基础网络设施中,请求服务的站点(station,STA)如果需要和其他服务设备通信,则需要与每一个服务设备分别进行认证和关联,即使需要同时连接或者需要切换连接的服务设备属于同一网络或者具有相同的认证方式也如此。其中,认证的过程为确定请求连接的站点STA是否具有连接资格的过程。关联的过程为双方互相交换信息建立连接的过程。如图1所示,网络中包括站点STA 101、第一打印机102、第二打印机103以及笔记本104,如果STA 101需要与第一打印机102、第二打印机103以及笔记本104通信,则STA 101需要单独与每一个服务设备即第一打印机102、第二打印机103以及笔记本104分别进行认证和关联;如果STA 101需要将与其连接的第一打印机102切换成与第二打印机103连接,那么STA也需要再次重新与第二打印机103进行认证和关联。而且,服务设备第一打印机102、第二打印机103以及笔记本104之间如果要通信,也必须一一进行认证和关联,例如,第二打印机103需要和第一打印机102以及笔记本104之间进行认证和关联,则第二打印机103需分别和第一打印机102以及笔记本104之间进行认证和关联。因此,当STA需要切换服务或者同时需要多种服务时,必须与多个服务设备进行重复认证,这将为用户带来很大的麻烦。
【发明内容】
本申请主要解决的技术问题是提供认证关联的方法及系统,能够避免重复认证。
为解决上述技术问题,本申请第一方面提供一种认证关联方法,包括如下步骤:
接入点AP接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证;查询所述STA是否通过了所述AP的认证;向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
结合第一方面,本申请第一方面的第一种可能的实施方式中,所述接入点AP接收服务设备所发出的认证结果查询的步骤之前包括:所述AP与所述站点STA进行认证。
本申请第二方面提供一种认证关联方法,包括如下步骤:
服务设备接收STA所发送的关联请求;向AP发送认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证;接收所述AP所发送的所述认证结果查询的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
结合第二方面,本申请第二方面的第一种可能的实施方式中,如果所述STA通过了所述AP的认证,则所述服务设备与所述STA建立关联;或,如果所述STA没有通过所述AP的认证,则所述服务设备拒绝与所述STA建立关联。
本申请第三方面提供一种接入点AP,包括接收模块、查询模块以及发送模块;所述接收模块用于接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证;所述查询模块用于查询所述STA是否通过了所述AP的认证;所述发送模块用于向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
结合第三方面,本申请第三方面的第一种可能的实施方式中,所述AP还包括认证模块;所述认证模块用于与所述STA和所述服务设备进行认证。
本申请第四方面提供一种服务设备,包括接收模块、发送模块以及关联模块;所述接收模块用于接收STA所发送的关联请求;所述发送模块用于向AP发送认证结果查询请求,其中所述认证结果查询请求用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证;所述接收模块还用于接收所述AP发送所述认证结果查询请求的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
结合第四方面,本申请第四方面的第一种可能的实施方式中,如果所述STA通过了所述AP的认证,则所述关联模块用于与所述STA建立关联;
或,如果所述STA没有通过所述AP的认证,则所述服务设备拒绝与所述STA建立关联。
本申请第五方面提供一种接入点AP,包括接收器、处理器以及发送器;
所述接收器用于接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证;所述处理器用于查询所述STA是否通过了所述AP的认证;所述发送器用于向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
结合第五方面,本申请第五方面的第一种可能的实施方式中,所述处理器还用于与所述STA和所述服务设备进行认证。
本申请第六方面提供一种服务设备,包括接收器、发送器以及处理器;所述接收器用于接收STA所发送的关联请求;所述发送器用于向AP发送认证结果查询请求,其中所述认证结果查询请求用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证;所述接收器还用于接收所述AP发送所述认证结果查询请求的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联;如果所述STA通过了所述AP的认证,则所述处理器用于与所述STA建立关联;或,如果所述STA没有通过所述AP的认证,则所述服务设备拒绝与所述STA建立关联。
本申请第七方面提供一种认证方法,包括如下步骤:接入点AP接收服务设备所发送的获取认证信息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的;向所述服务设备发送认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
本申请第八方面提供一种认证方法,包括如下步骤:
服务设备接收STA所发送的认证请求;向AP发送获取认证信息的请求;接收所述AP所发送的认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息;对发送所述认证请求的STA进行认证。
本申请第九方面提供一种接入点AP,包括接收模块和发送模块;
所述接收模块用于接收服务设备所发送的获取认证消息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的;所述发送模块用于向所述服务设备发送认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
本申请第十方面提供一种服务设备包括:接收模块、发送模块、认证模块;
所述接收模块用于接收STA所发送的认证请求;所述发送模块用于向AP发送获取认证信息的请求;所述接收模块还用于接收所述AP所发送的认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息;所述认证模块用于与所STA进行认证。
本申请第十一方面提供一种接入点AP,包括:接收器以及发送器;所述接收器用于用于接收服务设备所发送的获取认证消息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的;所述发送器用于向所述服务设备发送认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
本申请第十二方面提供一种服务设备,包括:接收器、发送器以及处理器;所述接收器用于接收STA所发送的认证请求;所述发送器用于向AP发送获取认证信息的请求;所述接收器还用于接收所述AP所发送的认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,所述处理器用于与所STA进行认证。
上述方案中,服务设备在接收到站点STA发送的关联请求后,只需从接入点AP获取认证查询请求结果即可确定是否与STA建立关联,通过上述方式能够避免重复认证带来的麻烦。
【附图说明】
图1是现有技术认证关联的结构示意图;
图2是本申请认证关联系统一实施方式的结构示意图;
图3是本申请认证关联方法第一种可能的实施方式的流程图;
图4是本申请认证关联方法第二种可能的实施方式的流程图;
图5是本申请认证关联方法第三种可能的实施方式的流程图;
图6是本申请接入点AP第一种可能的实施方式的结构示意图;
图7是本申请接入点AP第二种可能的实施方式的结构示意图;
图8是本申请接入点AP第三种可能的实施方式的结构示意图;
图9是本申请服务设备第一种可能的实施方式的结构示意图;
图10是本申请服务设备第二种可能的实施方式的结构示意图;
图11是本申请接入点AP第一种可能的实施方式装置结构示意图;
图12是本申请服务设备第一种可能的实施方式装置结构示意图;
图13是本申请认证关联系统另一实施方式的结构示意图;
图14是本申请认证方法第一种可能的实施方式的流程图;
图15是本申请认证方法第二种可能的实施方式的流程图;
图16是本申请认证方法第三种可能的实施方式的流程图;
图17是本申请接入点AP第四种可能的实施方式的结构示意图;
图18是本申请接入点AP第五种可能的实施方式的结构示意图;
图19是本申请服务设备第三种可能的实施方式的结构示意图;
图20是本申请服务设备第三种可能的实施方式的结构示意图;
图21是本申请接入点AP第二种可能的实施方式装置结构示意图;
图22是本申请服务设备第二种可能的实施方式装置结构示意图。
【具体实施方式】
以下描述中,为了说明而不是为了限定,提出了诸如特定系统结构、接口、技术之类的具体细节,以便透彻理解本申请。然而,本领域的技术人员应当清楚,在没有这些具体细节的其它实施方式中也可以实现本申请。在其它情况中,省略对众所周知的装置、电路以及方法的详细说明,以免不必要的细节妨碍本申请的描述。
参阅图2,图2是本申请认证关联系统一实施方式的结构示意图。
在本实施方式中的认证关联系统200包括:接入点AP 201,站点STA 202以及第一服务设备203和第二服务设备204。其中,无论是第一服务设备203或第二服务设备204均为特殊的站点STA 202。其中,接入点201与站点202之间,接入点201与第一服务设备203以及第二服务设备204之间,站点202与第一服务设备203以及第二服务设备204之间均可以进行无线通信。
本实施方式的接入点AP 201为网络控制设备,是一种对服务设备或者需要与服务设备建立连接的STA进行身份认证的管理单元,能够组建一个基站子系统BSS,并且能够连接在分布式系统DS上。
站点STA 202为具有通讯功能的通讯设备,如手机,能够通过认证关联后与接入点以及服务设备进行通信。
第一服务设备203以及第二服务设备204为具有通讯功能的服务设备,本发明中的服务设备均可以看出是特殊的STA。如打印机、笔记本电脑等。在通常的应用场景下,例如,在宾馆,接入点201是宾馆提供的WiFi接入点,站点202是住客自带的手机等等,第一服务设备203以及和第二服务设备204是宾馆提供的服务设备。所以,第一服务设备203以及第二服务设备204通常已经和接入点202通过认证和关联,可以直接进行通信。住客在获得接入点201的接入密码后,利用接入密码将站点202与接入点201进行连接。所以,站点202向接入点201发出认证请求以及关联请求。站点201与接入设备201通过认证和关联后,完成建立连接。
当住客需要使用第一服务设备203以及第二服务设备204时,站点202分别向第一服务设备203以及第二服务设备204发出关联请求。原则上,如果站点202能够通过接入点201的请求,则可知站点202的拥有者为宾馆的住客,所以,应该有权使用宾馆所提供的服务设备。所以,第一服务设备203以及第二服务设备204在收到关联请求后,只需向接入点201发送认证结果查询请求以查询站点202是否已经通过了接入点201的认证即可。如果站点202已经通过了接入点201的认证,则视同已经通过第一服务设备203以及第二服务设备204的认证。第一服务设备203和第二服务设备204分别和站点202关联后,第一服务设备203和第二服务设备204即与站点202建立了连接。如果站点202没有通过接入点201的认证,则不能与第一服务设备203和第二服务设备204建立关联。
相较于现有技术,当图1中STA 101需要与第一打印机102或计算机104连接时,STA 101必须与第一打印机102或计算机104进行认证和关联,当STA 101需要与二者同时建立连接时,则需要分别与二者进行认证和关联。而本申请中,如图2所示,当STA 202需要与第一服务设备203或者第二服务设备204连接时,在接收到STA 202发送的关联请求后,第一服务设备203或者第二服务设备204只需从接入点AP 201获取认证查询结果即可判断出STA 202 是否通过认证,如果STA通过了AP的认证,则STA可直接与服务设备建立关联。而众所周知的,服务设备从AP 201获取认证查询的结果的过程远比与站点STA进行认证简单的多,并且当STA 202与多个服务设备如STA需要与第一服务设备203、第二服务设备204同时建立连接时,此优势显示地更加明显。因此,本申请在很大程度上简化了站点STA与服务设备建立连接的过程。
参阅图3,图3是本申请认证关联方法第一种可能的实施方式的流程图,本实施方式包括如下步骤:
S301:接入点AP接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证。
由于如果STA通过了接入点的认证,则可认为站点具有和服务设备建立连接的资格。所以,当服务设备接收到站点所发出的关联请求时,服务设备向接入点发出认证结果查询请求,而接入点相应接收服务设备所发出的认证结果查询请求。
S302:查询所述STA是否通过了所述AP的认证。
S303:接入点AP向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
AP接收到服务设备发出的认证结果查询请求后,确定向服务设备发出关联请求的STA是否已通过认证,并将认证结果发送给服务设备。如果认证结果显示STA已经通过了AP的认证,则说明了STA有与服务设备建立关联的资格,如果认证结果显示STA没有通过AP的认证,则STA不能与服务设备建立关联,结束流程。
上述方案中能够使服务设备直接通过向AP进行结果查询便可获知向服务设备发送认证请求的STA是否通过认证,而无需再次与STA进行重复认证,进而使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次就可实现,避免了重复认证带来的麻烦。
参阅图4,图4是本申请认证关联方法第二种可能的实施方式的流程图。
本实施方式包括如下步骤:
S401:AP与处于同一网络的服务设备完成互相认证。
可通过人为设置使得AP与处于同一网络的服务设备完成互相认证。例如,可预先设置酒店的接入点和酒店内提供的服务设备完成互相认证。
S402:AP向STA发送服务设备的信息,其中,服务设备已经与AP完成互相认证。比如,住客进入酒店后,酒店接入点AP会向住客发送酒店可以使用的服务设备的信息,如打印机,供住客参考是否有使用的需要,当住客确定有需要与服务设备建立连接时,与AP进行认证。
S403:AP与STA进行认证消息的交互,完成认证。
S404:AP与STA建立关联,所述建立关联包括AP与STA交换设备名称、地址、速度和功率,还包括STA在分布式系统DS上完成注册。
S405:接入点AP接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证。
由于如果站点STA通过了接入点AP的认证,则可认为站点STA具有和服务设备建立连接的资格。所以,当服务设备接收到站点所发出的关联请求时,服务设备向接入点发出认证结果查询请求以判断STA是否有与服务设备建立关联的资格。
S406:接入点AP查询所述STA是否通过了所述AP的认证。
S407:接入点AP向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
接入点AP向所述服务设备发送所述认证结果查询的结果。如果认证结果显示STA已经通过了AP的认证,则说明了STA有与服务设备建立关联的资格,如果认证结果显示STA没有通过AP的认证,则STA不能与服务设备建立关联。
上述方案中在服务设备接收到STA发送的关联请求后,服务设备直接通过向AP进行查询便可确定STA是否通过认证,如果STA通过AP的认证,则服务设备与STA建立关联,如果STA没有通过AP的认证,则服务设备拒绝与STA建立关联,可选的,服务设备可以向STA发送回复消息拒绝建立关联,而服务设备本身无需再次与STA进行重复认证,进而使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次就可实现,避免了重复认证带来的麻烦。
参阅图5,图5是本申请认证关联方法第三种可能的实施方式的流程图.本实施方式包括如下步骤:
S501:服务设备接收STA所发送的关联请求。
S502:服务设备向AP发送认证结果查询请求,其中,所述认证结果查询用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证。
由于如果站点STA通过了接入点AP的认证,则可认为站点STA具有和服务设备建立连接的资格。所以,服务设备向接入点发出认证结果查询以判断STA是否有与服务设备建立关联的资格。
S503:服务设备接收AP所发送的所述认证结果查询请求的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。如果所述认证查询的结果表明向STA已通过AP的认证,则执行步骤S504。如果STA没有通过AP的认证,则执行步骤S105。
S504:服务设备向STA发送关联确认消息,并与STA建立关联,其中,所述建立关联包括STA与服务设备交换设备名称、地址、速度和功率。
S105:服务设备拒绝与STA建立关联。可选的,服务设备可向STA发送回复消息拒绝与STA建立关联。
上述方案中,服务设备通过向AP进行查询确定向服务设备发送认证请求的STA是否通过认证,如果STA通过了认证,则服务设备与STA建立关联,如果STA没有通过认证,则服务设备拒绝与STA建立关联,通过上述方式,使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次,无需再次与每个服务设备都进行认证,避免了多次重复认证带来的麻烦。
如图6所示,图6是本申请接入点AP第一种可能实施方式的结构示意图,本实施方式的AP 600包括接收模块610、查询模块620和发送模块630。
接收模块610用于接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP 600的认证;
由于如果站点通过了接入点AP 600的认证,则可认为站点具有和服务设备建立连接的资格。所以,当服务设备接收到站点所发出的关联请求时,服务设备向接入点发出认证结果查询,而接收模块610相应接收服务设备所发出的认证结果查询。
查询模块620用于查询STA是否通过了所述AP 600的认证。
发送模块630用于向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
具体的,接收模块610在接收到服务设备所发送的用于查询向服务设备发送关联请求的STA是否通过AP 600认证的认证查询结果后,查询模块820查询所述STA是否通过了AP 600的认证,而后发送模块830将结果发送给服务设备,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。如果认证结果显示STA已经通过了AP的认证,则说明了STA有与服务设备建立关联的资格,如果认证结果显示STA没有通过AP的认证,则STA不能与服务设备建立关联,建立关联包括服务设备与STA交换设备名称、地址、速度和功率。
上述方案中在服务设备接收到STA发送的关联请求后,服务设备直接通过向AP进行查询便可确定STA是否通过认证,如果STA通过AP的认证,则服务设备与STA建立关联,如果STA没有通过AP的认证,则服务设备拒绝与STA建立关联,而服务设备本身无需再次与STA进行重复认证,进而使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次就可实现,避免了重复认证带来的麻烦。
如图7所述,图7是本申请接入点AP第二种可能实施方式的结构示意图。本实施方式中的接入点AP 700包括认证模块710、关联模块720接收模块9730、查询模块740以及发送模块750。
认证模块710用于与所述STA和所述服务设备进行认证。比如,住客进入酒店后,酒店接入点AP会向住客发送酒店可以使用的服务设备的信息,如打印机,供住客参考是否有使用的需要,当住客确定有需要与服务设备建立连接时,可与AP进行认证。
关联模块720用于与所述STA建立关联,其中,所述建立关联包括AP与STA交换设备名称、地址、速度和功率,还包括所述STA在分布式系统DS上完成注册。
查询模块730用于查询STA是否通过了所述AP 700的认证
接收模块740用于接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP 700的认证。
由于如果STA 700通过了接入点AP的认证,则可认为站点STA具有和服务设备建立连接的资格。所以,当服务设备接收到站点所发出的关联请求时,服务设备向接入点发出认证结果查询以判断STA是否有与服务设备建立关联的资格。
发送模块740用于向所述服务设备发送所述认证结果查询的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
如果认证结果显示STA已经通过了AP的认证,则说明了STA有与服务设备建立关联的资格,如果认证结果显示STA没有通过AP的认证,则STA不能与服务设备建立关联。
为了更进一步地描述清楚图7的AP的工作过程,请参阅图8,图8是本申请接入点AP第三种可能实施方式的结构示意图,是对图7中的AP 700做进一步细化描述。本实施方式的AP 800包括:第一发送模块810、认证模块820,其中,认证模块820包括第一认证模块8201和第二认证模块8202、关联模块830、接收模块840、查询模块850第二发送模块860。
第一发送模块810用于向STA发送服务设备的信息,比如,住客进入酒店后,酒店接入点AP会向住客发送酒店可以使用的服务设备的信息,如打印机,供住客参考是否有使用的需要,当住客确定有需要与服务设备建立连接时,可与AP进行认证。
第一认证模块8201用于与STA进行认证消息的交互,完成认证,其中,STA为接收到AP发送服务设备的信息的,并且从必要信息中已经选择需要连接服务设备的STA。
第二认证模块8202用于与AP 800处于同一网络的服务设备完成认证。
关联模块830用于与STA建立关联,所述建立关联包括AP与STA交换设备名称、地址、速度和功,还包括所述STA在分布式系统DS上完成注册。
接收模块840用于接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证。
查询模块850用于查询STA是否通过了所述AP 800的认证。
由于如果站点STA通过了接入点AP的认证,则可认为站点STA具有和服务设备建立连接的资格。所以,当服务设备接收到站点所发出的关联请求时,服务设备向接入点发出认证结果查询以判断STA是否有与服务设备建立关联的资格。
第二发送模块860用于将向向所述服务设备发送所述认证结果查询的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
如果认证结果显示STA已经通过了AP的认证,则说明了STA有与服务设备建立关联的资格,如果认证结果显示STA没有通过AP的认证,则STA不能与服务设备建立关联。
具体的,第二认证模块8402与同AP 800处于同一网络的服务设备进行认证,完成认证后,第一发送模块810向STA发送服务设备的信息,其中,服务设备即为上述与AP 810完成互相认证的服务设备;在STA接收到服务设备的信息并根据必要信息选择需要连接的服务设备后,第一认证模块8201与STA进行认证消息的交互,完成认证,而后关联模快830与STA建立关联,在STA向服务设备发送关联请求后,接收模块840接收服务设备所发出的认证结果查询,其中,所述认证结果查询用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证,查询模块850查询所述STA是否通过了AP 800的认证,并通过第二发送模块860将认证查询的结果发送给服务设备,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
上述方案中在服务设备接收到STA发送的关联请求后,服务设备直接通过向AP进行查询便可确定STA是否通过认证,如果STA通过AP的认证,则服务设备与STA建立关联,如果STA没有通过AP的认证,则服务设备拒绝与STA建立关联,而服务设备本身无需再次与STA进行重复认证,进而使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次就可实现,避免了重复认证带来的麻烦。
参阅图9,图9是本申请服务设备第一种可能的实施方式的结构示意图。本实施方式的服务设备900包括接收模块910、发送模块920以及关联模块930。
接收模块910用于接收STA所发送的关联请求。
发送模块920用于向AP发送认证结果查询请求,其中所述认证结果查询用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证。由于如果站点STA通过了接入点AP的认证,则可认为站点STA具有和服务设备建立连接的资格。所以,发送模块920向接入点发出认证结果查询以判断STA是否有与服务设备建立关联的资格。
接收模块910还用于接收所述AP所发送所述认证结果查询的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
如果所述认证查询的结果表明向服务设备发送关联请求的STA已通过AP的认证,服务设备900认为站点STA具有与服务设备900建立连接的资格,此时发送模块920用于向所述STA发送关联确认消息。关联模块930用于与所述STA建立关联,其中,建立关联包括服务设备与STA交换设备名称、地址、速度和功率。
如果STA没有通过AP的认证,则关联模块930拒绝与STA建立关联。可选的,发送模块920向STA发送回复消息拒绝与STA建立关联。
为了进一步更详细的描述服务设备900,请参阅图10,图10是本申请服务设备第二种可能的实施方式的结构示意图,并且图10中的服务设备1000是对图9的服务设备900的进一步细化。本实施方式服务设备1000包括:第一接收模块1010、第一发送模块1020、第二接收模块1030、第二发送模块1040、关联模块1050。
第一接收模块1010用于接收STA所发送的关联请求。
第一发送模块1020用于向AP发送认证结果查询请求,其中所述认证结果查询用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证。由于如果站点STA通过了接入点AP的认证,则可认为站点STA具有和服务设备建立连接的资格。
第二接收模块1030用于接收AP所发送的所述认证结果查询请求的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
如果站点STA通过了接入点AP的认证,则服务设备1000认为站点STA具有与服务设备1000建立连接的资格,此时第一发送模块1020用于向所述STA发送关联确认消息。
如果STA没有通过AP的认证,则STA不能与服务设备1000建立关联,第二发送模块1040用于向STA发送回复消息拒绝接受关联请求。
关联模块1050用于与STA建立关联,其中,建立关联包括服务设备与STA交换设备名称、地址、速度和功率。
具体地,第一接收模块1010接收STA所发送的关联请求,接收到请求后,为了确定向服务设备发送关联请求的STA是否通过了AP的认证,第一发送模块1020向AP发送认证结果查询请求,在AP向服务设备1000发送认证的结果后,第二接收模块1030接收AP所发送的所述认证结果查询请求的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。如果所述认证查询的结果表明向服务设备发送关联请求的STA已通过AP的认证,第二发送模块1020向STA发送关联确认消息,关联模块1050与STA建立认证,如果STA没有通过AP的认证,服务设备向STA发送回复消息拒绝接受关联请求。
上述方案中,服务设备通过向AP进行查询确定向服务设备发送认证请求的STA是否通过认证,如果STA通过了认证,则服务设备与STA建立关联,如果STA没有通过认证,则服务设备拒绝与STA建立关联,通过上述方式,使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次,无需再次与每个服务设备都进行认证,避免了多次重复认证带来的麻烦。
参阅图11,图11是本申请接入点AP第一种可能的实施方式装置结构示意图。本实施方式的AP 1100包括接收器1110、发送器1120以及处理器1130。
接收器1110用于接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证。
由于如果STA通过了接入点AP 1100的认证,则可认为STA具有和服务设备建立连接的资格。所以,当服务设备接收到STA所发出的关联请求时,服务设备向接入点发出认证结果查询请求,而接收器1110相应接收服务设备所发出的认证结果查询请求。
处理器1130用于查询所述STA是否通过了所述AP的认证
发送器1120用于向所述服务设备发送所述认证结果查询的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
如果认证结果显示STA已经通过了AP 1100的认证,则说明了STA有与服务设备建立关联的资格,如果认证结果显示STA没有通过AP 1100的认证,则STA不能与服务设备建立关联。
处理器1130还用于与STA和服务设备进行认证,进一步的还用于与所述STA建立关联。其中,所述建立关联包括AP与STA交换设备名称、地址、速度和功率,还包括所述STA在分布式系统DS上完成注册。比如,住客进入酒店后,酒店接入点AP会向住客发送酒店可以使用的服务设备的信息,如打印机,供住客参考是否有使用的需要,当住客确定有需要与服务设备建立连接时,可与AP进行认证,此时,就需要处理器1130与STA进行认证,而在此之前,AP 1100需要与服务设备已经完成认证和关联。
AP 1100的各个组件通过总线1140耦合在一起,其中总线1140除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都标为总线1140。
具体的,处理器1130与同AP 1100处于同一网络的服务设备进行认证,完成认证后,发送器1110向STA发送服务设备的信息,其中,服务设备即为上述于AP 1110完成互相认证的服务设备,在STA接收到服务设备的信息并根据必要信息选择需要连接的服务设备后,处理器1130与STA进行认证消息的交互,完成认证,而后与STA建立关联。在STA向服务设备发送关联请求后,接收器1110接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证,此时服务器查询STA是否通过了AP 1110的认证如果认证结果显示STA已经通过了AP的认证,则说明了STA有与服务设备建立关联的资格,此时,发送器1120将向服务设备发送关联请求的STA的认证结果发送给服务设备,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。而后,处理器1130与STA建立关联并使STA在分布式系统上注册,如果认证结果显示STA没有通过AP的认证,则STA不能与服务设备建立关联。
上述方案中在服务设备接收到STA发送的关联请求后,服务设备直接通过向AP进行查询便可确定STA是否通过认证,如果STA通过AP的认证,则服务设备与STA建立关联,如果STA没有通过AP的认证,则服务设备拒绝与STA建立关联,而服务设备本身无需再次与STA进行重复认证,进而使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次就可实现,避免了重复认证带来的麻烦。
参阅图12,图12是本申请服务设备第一种可能的实施方式装置结构示意图。本事实施方式的服务设备1200包括发送器1210、接收器1220以及处理器1230。服务设备1200的各个组件通过总线1240耦合在一起,其中总线1240除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都标为总线1240。
接收器1220用于接收STA所发送的关联请求。
发送器1210用于向AP发送认证结果查询,其中所述认证结果查询用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证。
由于如果站点STA通过了接入点AP的认证,则可认为站点STA具有和服务设备建立连接的资格。所以,服务设备向接入点发出认证结果查询以判断STA是否有与服务设备建立关联的资格。
接收器1220还用于接收AP所所发送的认证结果查询的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联;
如果站点STA通过了接入点AP的认证,服务设备1200认为站点STA具有与服务设备1200建立连接的资格时,发送器1210用于向所述STA发送关联确认消息,此时,处理器1230用于与STA建立关联,其中,建立关联包括服务设备1200与STA交换设备名称、地址、速度和功率。
如果STA没有通过AP的认证,则STA不能与服务设备1200建立关联,发送器1210用于向STA发送回复消息拒绝接受关联请求。
具体的,接收器1220接收STA所发送的关联请求,接收到请求后,为了确定向服务设备发送关联请求的STA是否通过了AP的认证,发送器1210向AP发送认证结果查询,在AP向服务设备1200发送认证的结果后,接收器1220接收AP所发送的所述认证结果查询的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。如果所述认证查询的结果表明向服务设备发送关联请求的STA已通过AP的认证,发送器1210向STA发送关联确认消息,服务器1230与STA建立认证。如果STA没有通过AP的认证,服务设备可向STA发送回复消息拒绝接受关联请求。
上述方案中,服务设备通过向AP进行查询确定向服务设备发送认证请求的STA是否通过认证,如果STA通过了认证,则服务设备与STA建立关联,如果STA没有通过认证,则服务设备拒绝与STA建立关联,通过上述方式,使得STA与具有相同认证方式的服务设备进行切换通信或者与多个服务设备同时进行通信时,只需与AP认证一次,无需再次与每个服务设备都进行认证,避免了多次重复认证带来的麻烦。
参阅图13,图13是本申请认证关联系统另一实施方式的结构示意图。本实施方式中的认证关联系统1300包括:接入点AP 1301,站点STA 1302,第一服务设备1303和第二服务设备1304,无论第一服务设备1303还是第二服务设备1304均为特殊的站点STA。其中,接入点1301与站点1302之间,接入点1301与第一服务设备1303以及第二服务设备1304之间,站点1302与第一服务设备1303以及第二服务设备1304之间均可以进行无线通信。
本实施方式的接入点AP 1301为网络控制设备,是一种对服务设备或者需要与服务设备建立连接的STA进行身份认证的管理单元,能够组建一个基站子系统BSS,并且能够连接在分布式系统DS上。接入点AP 1301包括WiFi等等。
站点STA 1302为具有通讯功能的通讯设备,如手机,能够通过认证关联后与接入点以及服务设备进行通信。
第一服务设备1303以及第二服务设备1804为具有通讯功能的服务设备,如打印机、笔记本电脑等。需要说明的是,本发明中的服务设备均是特殊的STA。
在通常的应用场景下,例如,在宾馆,接入点1301是宾馆提供的WiFi接入点,站点1302是住客自带的手机等等,第一服务设备1303以及和第二服务设备1304是宾馆提供的服务设备。但是很多大型宾馆中的服务设备并不具备自身与站点STA或者其他服务设备建立认证的认证信息,这种服务设备的认证信息一般都存储在与服务设备处于同一网络的接入点AP中,因此,当有STA向此服务设备发送认证请求时,服务设备向AP获取服务设备的认证消息即可与向它发送认证请求的STA建立认证。
当住客需要使用第一服务设备1303和第二服务设备1304时,站点STA 1302分别向第一服务设备1303和第二服务设备1304发送认证请求。原则上,如果第一服务设备1303和第二服务设备1304在接收到认证请求后,与STA 1302交互认证消息,即可完成认证。但是第一服务设备1303和第二服务设备1304并不具备自身的认证消息,因而需要向AP 1301获取所述认证消息,再与STA 1302完成认证。
相较于现有技术,当图1中的STA 101需要与第一打印机102或计算机104连接时,或者处于同一宾馆的计算机104需要与第一打印机102建立连接时,如果第一打印机102或者计算机104不具备自身的认证消息,自然的,此次的连接过程是不能实现的,影响了客户的正常使用。本实施方式中,即使第一服务设备1303和第二服务设备1304或者其他更多的服务设备,在接收到STA或者其他服务设备的认证请求后,只需向AP 1301获取认证消息即可实现认证,使连接过程更加灵活,避免影响用户的正常使用。
参阅图14,图14是本申请认证方法第一种可能的实施方式的流程图。本实施方式包括如下步骤:
S1401:接入点AP接收服务设备所发送的获取认证信息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的。
由于,如果服务设备接收到了站点STA发送的认证请求而服务设备不具备自身与STA进行认证的认证消息时,为了与STA建立连接,必须向AP获取服务设备的认证消息的请求,对应的,AP需要接收服务设备的认证消息的请求。
S1402:接入点AP向所述服务设备发送所述获取认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
在AP向服务设备发送包含服务设备进行认证时必须具备的认证信息后,对应的服务设备接收此认证消息,并与STA进行认证。
上述方案中,当服务设备接收到STA的认证请求后,只需从AP获取服务设备进行认证时必须具备的认证信息即可与STA建立认证,使认证过程更加灵活,避免了因服务设备不具备认证时必须具备的认证信息而带来的不能建立连接、影响客户使用的麻烦。
参阅图15,图15是本申请认证方法第二种可能的实施方式的流程图。本实施方式包括以下步骤:
S1501:接入点AP向STA发送服务设备的信息。比如,住客进入酒店后,酒店接入点AP会向住客的手机发送酒店可以使用的服务设备的信息,如打印机,供住客参考是否有使用的需要,如果有需要,住客可直接通过手机向服务设备发送认证请求。
S1502:接入点AP接收服务设备所发送的获取认证消息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的。
由于,如果服务设备接收到了站点STA发送的认证请求而服务设备不具备自身与STA进行认证的认证消息时,为了与STA建立连接,必须向AP获取服务设备的认证消息。
S1503:接入点AP向所述服务设备发送所述获取认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对STA进行认证。
S1504:接入点AP与STA进行认证并建立关联。可选的,在接入点AP向服务设备发送获取包含服务设备进行认证时必须具备的认证消息的获取认证消息响应后,可与STA进行认证并建立关联,以方便STA与其他具备自身认证时必须具备的认证消息的服务设备建立连接。其中,建立关联包括AP与STA交换设备名称、地址、速度和功率,还包括所述STA在分布式系统DS上完成注册。
上述方案中,当服务设备接收到STA的认证请求后,只需从AP获取服务设备进行认证时必须具备的认证信息即可与STA建立认证,并进一步地能够建立关联,使认证关联过程更加灵活,避免了因服务设备不具备认证时必须具备的认证信息而带来的不能建立连接、影响客户使用的麻烦。
参阅图16,图16是本申请认证方法第三种可能的实施方式的流程图。本实施方式包括以下步骤:
S1601:服务设备接收STA所发送的认证请求。
STA确定需要连接的服务设备后,需要向服务设备发送认证请求,对应地,服务设备会接收所述认证请求。
S1602:服务设备向AP发送获取认证信息的请求。
服务设备接收了上述认证请求后,服务设备自身与STA进行认证的认证消息时,为了与STA建立连接,必须向AP获取服务设备的认证消息。
S1603:服务设备接收所述AP所发送的获取认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息。
S1604:服务设备与发送所述认证请求的STA进行认证。从AP获取到认证时必须具备的认证消息后,服务设备可与STA进行认证。
进一步的如果上述STA向服务设备发送关联请求,服务设备接收通过认证的STA所发送的关联请求。服务设备确定是否同意与所述STA建立关联,如果同意与STA建立关联,则向STA回复关联响应并与STA建立关联。所述建立关联包括所述服务设备与所述STA交换设备名称、地址、速度和功率。如果服务设备不同意与STA建立关联,则向STA回复决绝消息。
可选地,在服务设备与STA建立认证和关联之前,STA也可与AP进行认证和关联。
上述方案中,当不具备自身认证信息的服务设备接收到STA的认证请求后,只需从AP获取服务设备进行认证时必须具备的认证信息即可与STA建立认证,并进一步地能够建立关联进而建立连接,使认证关联过程更加灵活,避免了因服务设备不具备认证时必须具备的认证信息而带来的不能建立连接、影响客户使用的麻烦。
参阅图17,图17是本申请接入点AP第四种可能的实施方式的结构示意图。本实施方式中的接入点AP 1700包括接收模块1710和发送模块1720。
接收模块1710用于接收服务设备所发送的获取认证消息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的。
由于,如果服务设备接收到了站点STA发送的认证请求而服务设备不具备自身与STA进行认证的认证消息时,为了与STA建立连接,必须向AP获取服务设备的认证消息的请求,对应的,接收模块1710需要接收服务设备的认证消息的请求。
发送模块1720用于向所述服务设备发送所述获取认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
在AP向服务设备发送包含服务设备进行认证时必须具备的认证信息后,对应的服务设备接收此认证消息,并与STA进行认证。
具体地,接收模块1710接收到服务设备发送来的获取认证消息的请求后,发送模块1720对应地将服务设备的认证消息发送给服务设备,以使服务设备能够接收此认证消息并进一步的与STA建立关联。
进一步地参阅图18,图18是本申请接入点AP第五种可能的实施方式的结构示意图。本实施方式的AP包括接收模块1810、发送模块1820还包括认证模块1830以及关联模块1840。
接收模块1810用于接收服务设备所发送的获取认证消息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的。
由于,如果服务设备接收到了站点STA发送的认证请求而服务设备不具备其自身与STA进行认证的认证消息时,为了与STA建立连接,必须向AP获取服务设备的认证消息的请求,对应的,接收模块1810需要接收服务设备的认证消息的请求。
发送模块1820用于向所述服务设备发送所述获取认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息。
认证模块1830用于在所述服务设备接收到所述认证消息并与STA进行认证的同时与STA进行认证。
关联模块1840用于在所述STA与所述服务设备完成认证后建立关联的时与STA建立关联,其中,所述建立关联包括交换设备名称、地址、速度和功率,还包括所述STA在分布式系统DS上完成注册。
需要补充的是,在接收模块1810接收到服务设备所发送的获取认证消息的请求之前,发送模块1820还用于向进入网络的STA发送服务设备的消息。比如,住客进入酒店后,酒店接入点AP会向住客的手机发送酒店可以使用的服务设备的信息,如打印机,供住客参考是否有使用的需要,如果有需要,住客可直接通过手机向服务设备发送认证请求。
具体地,接入点AP1800的发送模块1820向进入网络的STA发送本网络内服务设备的消息,供STA选择是否有需要的服务设备,在STA选择了服务设备并向服务设备发送认证请求对应的服务设备接收上述认证请求后,接收模块1810接收服务设备所发送的获取认证消息的请求,而后通过发送模块1820将上述服务设备的认证消息发送至服务设备,以使所述服务设备与向发送认证请求的STA进行认证并建立关联,在服务设备与STA建立关联之前,认证模块1830也可与STA交互认证消息,建立认证,对应的,服务设备与STA建立关联的同时,关联模块1840也可与STA建立关联,以方便STA与其他具备自身认证时必须具备的认证消息的服务设备建立连接。
上述方案中,当不具备自身认证信息的服务设备接收到STA的认证请求后,只需从AP获取服务设备进行认证时必须具备的认证信息即可与STA建立认证,并进一步地能够建立关联,使认证关联过程更加灵活,避免了因服务设备不具备认证时必须具备的认证信息而带来的不能建立连接、影响客户使用的麻烦。
参阅图19,图19是本申请服务设备第三种可能的实施方式的结构示意图。本实施方式中服务设备1900包括接收模块1910、发送模块1920、认证模块1930。接收模块1910用于接收STA所发送的认证请求。发送模块1920用于向AP发送获取认证信息的请求。接收模块1910还用于接收所述AP所发送的认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息。所述认证模块1930用于与所STA进行认证。
为了清楚的描述清楚本实施方式各模块的工作过程,请参阅图20,图20是本申请服务设备第三种可能的实施方式的结构示意图,应该理解的是,图20的服务设备是对图19中的服务设备的进一步细化描述。本实施方式中的服务设备包括第一接收模块2010、发送模块2020、第二接收模块2030、认证模块2040、第三接收模块2050,还包括判断模块2060,第二发送模块2070以及关联模块2080。
第一接收模块2010用于接收STA所发送的认证请求。
STA确定需要连接的服务设备后,需要向服务设备发送认证请求,对应地,服务设备的第一接收模块2010会接收所述认证请求。
发送模块2020用于向AP发送获取认证信息的请求。
服务设备接收了上述认证请求后,自身并不具备与STA进行认证的认证消息时,为了与STA建立连接,必须通过发送模块2020向AP获取服务设备的认证消息。
第二接收模块用于2030用于接收所述AP所发送的获取认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息。
认证模块2040与所STA进行认证。从AP获取到认证时必须具备的认证消息后,服务设备与STA进行认证。
STA要与服务设备建立连接,完成认证后,还需进一步地与服务设备建立关联,因此需要向服务设备发送关联请求,对应地,服务设备的第三接收模块2050需要接收所述关联请求。
判断模块2060用于确定是否同意与所述STA建立关联。
第二发送模块2070用于向所述STA回复关联相应,如果判断模块2060同意与所述STA建立关联,则关联模块2080与所述STA建立关联,如果所述判断模块2060不同意与STA建立关联,则第二发送模块2070用于向STA发送拒绝消息,所述建立关联包括所述服务设备与所述STA交换设备名称、地址、速度和功率。
具体地,服务设备2000的第一接收模块2010接收到STA发送来的认证请求后,为了与STA建立认证,会通过发送模块2020向AP发送获取认证信息的请求,进而通过第二接收模块2030接收AP发送来的认证信息,再通过认证模块2040与STA交互认证消息进行认证,为了进一步的与服务设备建立连接,在与STA完成认证后,第三接收模块2050会接收到STA发送的关联请求,此时判断模块2060确定是否同意与STA建立关联,而后第二发送模块2070向所述STA回复关联相应,如果判断模块2060同意与所述STA建立关联,则通过关联模块2080与STA建立关联,如果判断模块2060不同意与STA建立关联,则第二发送模块2070向STA发送拒绝消息。
上述方案中,当不具备自身认证消息的服务设备接收到STA的认证请求后,只需从AP获取服务设备进行认证时必须具备的认证信息即可与STA建立认证,并进一步地能够建立关联,使认证关联过程更加灵活方便,避免了因服务设备不具备认证时必须具备的认证信息而带来的不能建立连接、影响客户使用的麻烦。
参阅图21,图21是本申请接入点AP第二种可能的实施方式装置结构示意图。本实施方式的AP包括接收器2110以及发送器2120。
接收器2110用于接收服务设备所发送的获取认证消息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的。
由于,如果服务设备接收到了站点STA发送的认证请求而服务设备不具备自身与STA进行认证的认证消息时,为了与STA建立连接,必须向AP获取服务设备的认证消息的请求,对应的,接收器2110需要接收服务设备的认证消息的请求。
发送器2120用于向所述服务设备发送所述获取认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
在发送器2110向服务设备发送包含服务设备进行认证时必须具备的认证信息后,对应的服务设备的接收器2120接收此认证消息,并与STA进行认证。
具体地,接收器2110接收到服务设备发送来的获取认证消息的请求后,发送器2120对应地将服务设备的认证消息发送给服务设备,以使服务设备接收此认证消息并进一步的与STA建立关联。
进一步地,参阅图21,本实施方式的AP还包括处理器2130,处理器2130用于与STA进行认证和建立关联,其中,建立关联包括与STA交换设备名称、地址、速度和功率,还包括所述STA在分布式系统DS上完成注册。AP 2100的各个组件通过总线2140耦合在一起,其中总线2140除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都标为总线2140。
需要补充的是,在接收器2110接收到服务设备所发送的获取认证消息的请求之前,发送器2120还用于向进入网络的STA发送服务设备的消息。比如,住客进入酒店后,酒店接入点AP会向住客的手机发送酒店可以使用的服务设备的信息,如打印机,供住客参考是否有使用的需要,如果有需要,住客可直接通过手机向服务设备发送认证请求。
具体地,接入点AP 2100的发送器2120向进入网络的STA发送本网络内服务设备的消息,供STA选择是否有需要的服务设备,在STA选择了服务设备并向服务设备发送认证请求对应的服务设备接收上述认证请求后,接收器2110接收服务设备所发送的获取认证消息的请求,而后通过发送器3220将上述服务设备的认证消息发送至服务设备,以使所述服务设备与发送认证请求的STA进行认证并建立关联,在服务设备与STA建立关联之前,服务器2130也可与STA交互认证消息,建立认证,对应的,服务设备与STA建立关联之前,服务器2130也可与STA建立关联,以方便STA与其他具备自身认证时必须具备的认证消息的服务设备建立连接。
上述方案中,当不具备自身认证信息的服务设备接收到STA的认证请求后,只需从AP获取服务设备进行认证时必须具备的认证信息即可与STA建立认证,并进一步地能够建立关联,使认证关联过程更加灵活方便,避免了因服务设备不具备认证时必须具备的认证信息而带来的不能建立连接、影响客户使用的麻烦。
参阅图22,图22是本申请服务设备第二种可能的实施方式装置结构示意图。本实施方式的服务设备2200包括接收器2210、发送器2220以及处理器2230。服务设备2200的各个组件通过总线2240耦合在一起,其中总线2240除包括数据总线之外,还可以包括电源总线、控制总线和状态信号总线等。但是为了清楚说明起见,在图中将各种总线都标为总线2240。
接收器2210用于接收STA所发送的认证请求。
STA确定需要连接的服务设备后,需要向服务设备发送认证请求,对应地,服务设备的接收器2210会接收所述认证请求。
发送器2220用于向AP发送获取认证信息的请求。
接收器2210接收了上述认证请求后,由于服务设备自身并不具备与STA进行认证的认证消息时,为了与STA建立连接,必须通过发送器2220向AP获取服务设备的认证消息。
接收器2210还用于接收所述AP所发送的认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息。
处理器2230用于对所述STA进行认证。从AP获取到认证时必须具备的认证消息后,服务设备与STA进行认证。
STA要与服务设备建立连接,完成认证后,还需进一步地与服务设备建立关联,因此需要向服务设备发送关联请求,因此,接收器2210还用于接收通过认证的STA所发送的关联请求。
处理器2230还用于确定所述服务设备同意与所述STA建立关联。
如果处理器同意与所述STA建立关联,则处理器与所述STA建立关联。处理器2230不同意与所述STA建立关联,则发送器2220向STA发送拒绝消息。其中,所述建立关联包括所述服务设备与所述STA交换设备名称、地址、速度和功率。
具体地,服务设备2200的接收器2210接收到STA发送来的认证请求后,为了与STA建立认证,会通过发送器2220向AP发送获取认证信息的请求,进而通过接收器2210接收AP发送来的认证信息,则处理器2230与STA交互认证消息进行认证,为了进一步的与服务设备建立连接,在与STA完成认证后,接收器3410会接收到STA发送的关联请求,此时处理器2230判断是否同意与STA建立关联处理器同意与所述STA建立关联,则处理器2230与STA建立关联,处理器2230不同意与所述STA建立关联,则发送器向STA发送拒绝消息。
上述方案中,当自身不具备认证信息的服务设备接收到STA的认证请求后,只需从AP获取服务设备进行认证时必须具备的认证信息即可与STA建立认证,使认证关联过程更加灵活方便,避免了因服务设备不具备认证时必须具备的认证信息而带来的不便。
在本申请所提供的几个实施方式中,应该理解到,所揭露的系统,装置和方法,可以通过其它的方式实现。例如,以上所描述的装置实施方式仅仅是示意性的,例如,所述模块或单元的划分,仅仅为一种逻辑功能划分,实际实现时可以有另外的划分方式,例如多个单元或组件可以结合或者可以集成到另一个系统,或一些特征可以忽略,或不执行。另一点,所显示或讨论的相互之间的耦合或直接耦合或通信连接可以是通过一些接口,装置或单元的间接耦合或通信连接,可以是电性,机械或其它的形式。
所述作为分离部件说明的单元可以是或者也可以不是物理上分开的,作为单元显示的部件可以是或者也可以不是物理单元,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部单元来实现本实施方式方案的目的。
另外,在本申请各个实施方式中的各功能单元可以集成在一个处理单元中,也可以是各个单元单独物理存在,也可以两个或两个以上单元集成在一个单元中。上述集成的单元既可以采用硬件的形式实现,也可以采用软件功能单元的形式实现。
所述集成的单元如果以软件功能单元的形式实现并作为独立的产品销售或使用时,可以存储在一个计算机可读取存储介质中。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分或者该技术方案的全部或部分可以以软件产品的形式体现出来,该计算机软件产品存储在一个存储介质中,包括若干指令用以使得一台计算机设备(可以是个人计算机,服务器,或者网络设备等)或处理器(processor)执行本申请各个实施方式所述方法的全部或部分步骤。而前述的存储介质包括:U盘、移动硬盘、只读存储器(ROM,Read-Only Memory)、随机存取存储器(RAM,Random Access Memory)、磁碟或者光盘等各种可以存储程序代码的介质。

Claims (12)

  1. 一种认证关联方法,包括如下步骤:
    接入点AP接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证;
    查询所述STA是否通过了所述AP的认证;
    向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
  2. 根据权利要求1所述的方法,其特征在于,
    所述接入点AP接收服务设备所发出的认证结果查询的步骤之前包括:所述AP与所述站点STA进行认证。
  3. 一种认证关联方法,包括如下步骤:
    服务设备接收STA所发送的关联请求;
    向AP发送认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证;
    接收所述AP所发送的所述认证结果查询请求的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
  4. 根据权利要求3所述的方法,其特征在于,如果所述STA通过了所述AP的认证,则所述服务设备与所述STA建立关联;或,如果所述STA没有通过所述AP的认证,则所述服务设备拒绝与所述STA建立关联。
  5. 一种接入点AP,其特征在于,包括接收模块、查询模块以及发送模块;
    所述接收模块用于接收服务设备所发出的认证结果查询请求,其中,所述认证结果查询请求用于查询向所述服务设备发出关联请求的站点STA是否通过所述AP的认证;
    所述查询模块用于查询所述STA是否通过了所述AP的认证;
    所述发送模块用于向所述服务设备发送所述认证结果查询请求的结果,以使所述服务设备根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
  6. 根据权利要求5所述的AP,其特征在于,
    所述AP还包括认证模块;
    所述认证模块用于与所述STA和所述服务设备进行认证。
  7. 一种服务设备,其特征在于,包括接收模块、发送模块以及关联模块;
    所述接收模块用于接收STA所发送的关联请求;
    所述发送模块用于向AP发送认证结果查询请求,其中所述认证结果查询请求用于查询向所述服务设备发出所述关联请求的STA是否通过了所述AP的认证;
    所述接收模块还用于接收所述AP发送所述认证结果查询请求的结果,根据所述认证查询请求的结果确定是否与所述站点STA建立关联。
  8. 根据权利要求7所述的服务设备,其特征在于,如果所述STA通过了所述AP的认证,则所述关联模块用于与所述STA建立关联;
    或,如果所述STA没有通过所述AP的认证,则所述服务设备拒绝与所述STA建立关联。
  9. 一种认证方法,包括如下步骤:
    接入点AP接收服务设备所发送的获取认证信息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的;
    向所述服务设备发送认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
  10. 一种认证方法,包括如下步骤:
    服务设备接收STA所发送的认证请求;
    向AP发送获取认证信息的请求;
    接收所述AP所发送的认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息;
    对发送所述认证请求的STA进行认证。
  11. 一种接入点AP,其特征在于,包括接收模块和发送模块;
    所述接收模块用于接收服务设备所发送的获取认证消息的请求,其中,所述获取认证信息的请求是所述服务设备接收到STA所发送的认证请求后所发送的;
    所述发送模块用于向所述服务设备发送认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息,以使所述服务设备根据所述认证信息对所述STA进行认证。
  12. 一种服务设备,其特征在于,包括:接收模块、发送模块、认证模块;
    所述接收模块用于接收STA所发送的认证请求;
    所述发送模块用于向AP发送获取认证信息的请求;
    所述接收模块还用于接收所述AP所发送的认证信息响应,其中,所述认证信息响应中包含了所述服务设备进行认证时必须具备的认证信息;
    所述认证模块用于对所述STA进行认证。
PCT/CN2014/070326 2014-01-08 2014-01-08 认证关联方法及系统 WO2015103748A1 (zh)

Priority Applications (3)

Application Number Priority Date Filing Date Title
CN201480068887.6A CN105850095B (zh) 2014-01-08 2014-01-08 认证关联方法及系统
PCT/CN2014/070326 WO2015103748A1 (zh) 2014-01-08 2014-01-08 认证关联方法及系统
US15/205,333 US10187796B2 (en) 2014-01-08 2016-07-08 Authentication and association method and system

Applications Claiming Priority (1)

Application Number Priority Date Filing Date Title
PCT/CN2014/070326 WO2015103748A1 (zh) 2014-01-08 2014-01-08 认证关联方法及系统

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US15/205,333 Continuation US10187796B2 (en) 2014-01-08 2016-07-08 Authentication and association method and system

Publications (1)

Publication Number Publication Date
WO2015103748A1 true WO2015103748A1 (zh) 2015-07-16

Family

ID=53523445

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/070326 WO2015103748A1 (zh) 2014-01-08 2014-01-08 认证关联方法及系统

Country Status (3)

Country Link
US (1) US10187796B2 (zh)
CN (1) CN105850095B (zh)
WO (1) WO2015103748A1 (zh)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
JP6184580B1 (ja) * 2016-01-29 2017-08-23 キヤノン株式会社 情報処理装置、制御方法およびプログラム
JP6619682B2 (ja) 2016-03-31 2019-12-11 キヤノン株式会社 情報処理装置、制御方法およびプログラム
JP2020145557A (ja) 2019-03-05 2020-09-10 キヤノン株式会社 プログラム、情報処理装置、および制御方法

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101013940A (zh) * 2006-12-22 2007-08-08 西安电子科技大学 一种兼容802.11i及WAPI的身份认证方法
CN101018174A (zh) * 2007-03-15 2007-08-15 北京安拓思科技有限责任公司 用于wapi的获取公钥证书的网络系统和方法
CN101114957A (zh) * 2006-07-27 2008-01-30 西安电子科技大学 无线局域网中的快速切换方法及系统

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN100596084C (zh) * 2006-04-20 2010-03-24 华为技术有限公司 移动电路域用户接入ims网络的系统及其接入的注册方法
CN101111056B (zh) * 2006-07-17 2010-05-12 西安电子科技大学 在无线局域网中的快速切换方法
CN101155092B (zh) * 2006-09-29 2010-09-08 西安电子科技大学 一种无线局域网接入方法、设备及系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN101114957A (zh) * 2006-07-27 2008-01-30 西安电子科技大学 无线局域网中的快速切换方法及系统
CN101013940A (zh) * 2006-12-22 2007-08-08 西安电子科技大学 一种兼容802.11i及WAPI的身份认证方法
CN101018174A (zh) * 2007-03-15 2007-08-15 北京安拓思科技有限责任公司 用于wapi的获取公钥证书的网络系统和方法

Also Published As

Publication number Publication date
CN105850095A (zh) 2016-08-10
CN105850095B (zh) 2019-04-12
US10187796B2 (en) 2019-01-22
US20160323744A1 (en) 2016-11-03

Similar Documents

Publication Publication Date Title
WO2018008943A1 (en) Method and device for managing security according to service in wireless communication system
WO2018082482A1 (zh) 一种网络共享方法、接入网络方法及系统
WO2017003096A1 (ko) 디바이스들 간의 연결 설립 방법
WO2014186986A1 (zh) 流转发方法、设备及系统
EP2781111A1 (en) Method and apparatus for managing security keys for communication authentication with mobile station in wireless communication system
WO2013058423A1 (ko) 전자기기 및 전자기기의 동작 방법
WO2016023148A1 (zh) 报文的控制方法、交换机及控制器
WO2015032091A1 (zh) 小区的切换方法、终端和网络设备
WO2011155760A2 (ko) 다른 장치와 통신 하는 방법 및 통신 기기
CN105684344A (zh) 一种密钥配置方法和装置
WO2015137637A1 (en) Method for supporting proximity-based service configuring for ue
WO2015156477A1 (ko) 무선 충전 장치와 단말, 그를 포함하는 무선 충전 시스템, 그 제어 방법 및 컴퓨터 프로그램이 기록된 기록매체
WO2019216739A1 (en) Security protection method and apparatus in wireless communication system
WO2019143081A1 (ko) 데이터 통신을 제어하는 방법 및 전자 장치
WO2021241849A1 (ko) 에지 컴퓨팅 서비스를 수행하는 전자 장치 및 전자 장치의 동작 방법
WO2018076875A1 (zh) 备份数据的同步方法、装置、存储介质、电子设备及服务器
WO2018048098A1 (en) Portable camera and controlling method therefor
WO2021060904A1 (ko) 무선 통신 시스템에서 통신을 수행하는 방법 및 장치
WO2019066343A1 (en) METHOD AND DEVICE FOR COMMUNICATION BETWEEN ELECTRONIC DEVICES
WO2015103748A1 (zh) 认证关联方法及系统
WO2011136619A2 (en) Apparatus and method of user equipment relocation
WO2014171727A1 (en) Apparatus and method for generating key hierarchy in wireless network
WO2019119374A1 (zh) 业务分流的方法、网络设备和终端设备
WO2012005490A2 (en) System and method for switching mobile station identification in wireless communication system
WO2017185482A1 (zh) 多媒体会话方法及装置

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14878007

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 14878007

Country of ref document: EP

Kind code of ref document: A1