WO2025102707A1 - 信息处理方法、网络设备及计算机可读存储介质 - Google Patents
信息处理方法、网络设备及计算机可读存储介质 Download PDFInfo
- Publication number
- WO2025102707A1 WO2025102707A1 PCT/CN2024/098824 CN2024098824W WO2025102707A1 WO 2025102707 A1 WO2025102707 A1 WO 2025102707A1 CN 2024098824 W CN2024098824 W CN 2024098824W WO 2025102707 A1 WO2025102707 A1 WO 2025102707A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- information
- frame
- sensitive information
- beacon frame
- network device
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Pending
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
Definitions
- the embodiments of the present disclosure relate to, but are not limited to, the field of communication technology, and in particular, to an information processing method, a network device, and a computer-readable storage medium.
- beacon frames that support the strict target wake-up time (Restricted Target Wake Up Time, r-TWT) and broadcast Target Wakeup Time (b-TWT) will carry TWT grouping and service time window information by default. If a third-party device detects the TWT information in the beacon frame, it can occupy the channel within each r-TWT service time window, causing devices with low-latency services to wait for channel intervention because they cannot intervene in the channel in time in the corresponding TWT window, causing latency and power consumption problems at the application layer, which may in turn cause the risk of user privacy leakage.
- the embodiments of the present disclosure provide an information processing method, a network device, and a computer-readable storage medium, which can not only prevent other network devices or third-party devices from obtaining sensitive information in the beacon frame to a certain extent, but also effectively avoid the risk of leakage of user sensitive information.
- an embodiment of the present disclosure provides an information processing method, which is applied to a sending-side network device, comprising: encrypting a sensitive information field in a beacon frame using key configuration information to obtain an encrypted beacon frame; and sending the encrypted beacon frame.
- the embodiment of the present disclosure also provides an information processing method, which is applied to a receiving-side network device, comprising: receiving a first beacon frame sent by a sending-side network device, wherein the first beacon frame includes a sensitive information field encrypted using key configuration information; decrypting the sensitive information field in the first beacon frame using the key configuration information to obtain decrypted sensitive information; and performing corresponding information processing based on the decrypted sensitive information.
- an embodiment of the present disclosure further provides a network device, comprising: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the information processing method of the first aspect as described above is implemented or the information processing method of the second aspect as described above is implemented.
- an embodiment of the present disclosure further provides a computer-readable storage medium storing computer-executable instructions, wherein the computer-executable instructions are used to execute the information processing method as described above.
- FIG1 is a structural diagram of a NR provided in an embodiment of the present disclosure.
- FIG2 is a structural diagram of an MBSSID element provided in an embodiment of the present disclosure.
- FIG3 is a diagram of the RSNE field structure provided by an embodiment of the present disclosure.
- FIG4 is a management frame format with BIP protection added provided by an embodiment of the present disclosure.
- FIG5 is a flow chart of an information processing method provided by an embodiment of the present disclosure.
- FIG. 6 is a schematic diagram of a sending-side network device using the same secret key to generate an information integrity code and encrypt sensitive information according to an embodiment of the present disclosure
- FIG. 7 is a structural diagram of a transmitting side network device using a first key to encrypt sensitive information elements located in different IEs according to an embodiment of the present disclosure
- FIG8 is a structural diagram of an RSNE field extension provided in an embodiment of the present disclosure.
- FIG9 is a flow chart of an information processing method provided by another embodiment of the present disclosure.
- FIG10 is a structural diagram of key configuration information provided in an embodiment of the present disclosure.
- FIG11 is a flowchart of another information processing method provided by an embodiment of the present disclosure.
- FIG12 is a flowchart of information processing when the receiving side network device is an AP or an AP MLD provided by an embodiment of the present disclosure
- FIG. 13 is a structural diagram of a receiving-side network device using a second key to encrypt sensitive information elements located in different IEs according to an embodiment of the present disclosure
- FIG. 14 is a schematic diagram of a process in which a sending-side network device and a receiving-side network device use beacon frames to interact and encrypt sensitive information, provided by an embodiment of the present disclosure
- FIG. 15 is another schematic diagram of a process in which a sending-side network device and a receiving-side network device use beacon frames to interact and encrypt sensitive information, provided by an embodiment of the present disclosure.
- the Neighbor Report (NR) field contains information about other surrounding access points (APs) or multi-link access points (AP MLD, hereinafter referred to as AP). It is generally used for a terminal (STA) or a multi-link terminal (non-AP MLD, hereinafter referred to as STA) to send a query frame to the target AP to query the information of other surrounding APs.
- the target AP sends a response frame to the STA to feedback the information of other surrounding APs queried by the STA.
- the STA sends an Access Network Query Protocol (ANQP) query frame to the AP, and the AP feeds back an ANQP response frame to the STA.
- ANQP Access Network Query Protocol
- the beacon frame sent by the AP carries the NR field in the detection response frame to actively broadcast the information of other surrounding APs; or, in a roaming or multi-AP load balancing scenario, the AP actively recommends the information of other surrounding APs to the STA, and the STA confirms the information and then sends a (re)association request to the recommended AP.
- the AP sends a BSS transition management (BSS transition management, BTM) request frame to the STA, and carries the information of the recommended AP in the NR field.
- BSS transition management BSS transition management
- FIG. 1 is a diagram of the NR field structure provided in an embodiment of the present disclosure.
- the explanations of the main fields are as follows:
- Element ID used to represent the element identifier
- Length used to indicate the length of the element
- BSSID used to represent the basic service set identifier (MAC address);
- BSSID Information used to represent the basic service set identifier information field
- Operating Class used to indicate the operating channel category
- Channel Number used to indicate the channel number
- PHY Type used to indicate the physical layer type
- Optional Subelements used to represent optional subelements
- AP Reachability used to indicate whether the neighbor AP can be detected
- Security used to indicate whether the security parameters are the same as the current link
- Capabilities used to indicate the capability set information of neighboring APs
- Mobility Domain used to indicate whether the beacon frame sent by the neighbor AP carries the Mobility Domain Element (MDE) field;
- MDE Mobility Domain Element
- High Throughput used to indicate whether the neighbor AP is an HT AP, that is, whether it supports the HT capability set;
- Very High Throughput used to indicate whether the neighbor AP is a VHT AP, that is, whether it supports the VHT capability set;
- FTM used to indicate whether the neighbor AP supports the FTM (Fine Timing measurement) function
- High Efficiency used to indicate whether the neighbor AP is a HE AP, that is, whether it supports the HE capability set;
- ER BSS used to indicate whether the neighbor AP is an AP that supports the extended range (ER) function
- Colocated AP used to indicate that the neighbor AP and the AP corresponding to the current link coexist on the same physical device
- Unsolicited Probe Responses Active used to indicate that neighboring APs can send an unsolicited probe response frame every 20ms on the 6GHz band;
- OCT Supported With Reporting AP used to indicate that the AP on the current link supports exchanging MMPDUs with neighboring APs using on-channel Tunneling (OCT) technology.
- OCT on-channel Tunneling
- Colocated With 6GHz AP Used to indicate that the neighbor AP works in the 6GHz frequency band and coexists with the current AP on the same physical device;
- Extremely High Throughput used to indicate whether the neighbor AP is an EHT AP, that is, whether it supports the EHT capability set;
- the RNR (reduced neighbor report) field is correspondingly trimmed and modified based on the NR field, and only includes key information of the surrounding APs, such as working channels, SSID, BSSID information, etc.
- a STA receives a management frame such as a beacon frame or a probe response frame with an RNR field sent by an AP, the STA can quickly discover other APs around it, and then further detect on the channel where the target AP is located, thereby obtaining complete information about the AP, thus reducing the time overhead of the STA blindly scanning the channel and detecting surrounding APs.
- each AP corresponds to a different BSSID.
- the 802.11 protocol introduces the multiple basic service set identifier (MBSSID) technology, that is, the beacon frames and probe response frames sent by multiple APs on the same radio frequency are merged into the beacon frame and probe response frame of one AP. That is, the beacon frame and probe response frame of one AP carry the information of other APs on the same radio frequency. This information is placed in the multi-BSSID element field. Its structure is shown in Figure 2. In this structure, the explanations of the main fields are as follows:
- Element ID used to represent the element identifier
- Length used to indicate the length of the element
- MaxBSSID Indicator used to indicate the maximum number of basic service set identifiers (BSSIDs);
- Optional Subelements Used to represent optional subelements.
- RSN element RSNE
- RSNE Robust Security Network
- Figure 3 is a diagram of the RSNE field structure provided in the embodiment of the present disclosure. In the RSNE structure, the explanations of the main fields are as follows:
- Element ID used to uniquely identify the element
- Length used to indicate the field length information
- Group Data Cipher Suite used to indicate the multicast data frame key suite information
- Pairwise Cipher Suite Count used to indicate the number of unicast key suites
- Pairwise Cipher Suite List used to represent the unicast key suite list
- AKM (authentication and key management) Suite Count used to indicate the number of authentication and key suites
- AKM Suite List used to represent the certification and key suite list
- RSN Capabilities used to represent the RSN capability set
- PMKID Count used to indicate the number of PMKIDs
- PMKID List used to represent the PMKID list
- Group Management Cipher Suite used to represent the multicast management frame key suite information.
- the Broadcast/Multicast Integrity Protocol (BIP) is defined.
- the basic principle is that when the AP sends the GTK (group temporary key) to the STA, it also sends the integrity group temporary key (integrity group temporal key, IGTK) and a multicast frame integrity protection frame number (IGTK Packet Number, IPN) for BIP protocol protection to the STA, and then the AP adds the message integrity code (message integrity code, MIC) value of the management frame calculated using the IGTK to the end of the sent multicast frame and sends it to the STA.
- the STA uses the same IGTK to verify the MIC.
- beacon frame integrity group temporary key Beacon integrity group temporal key, BIGTK
- BIPN beacon integrity group temporal key
- BIPN beacon frame number
- PN beacon frame number
- the AP adds the MIC value of the management frame calculated using BIGTK at the end of the sent multicast frame and sends it to the STA.
- the STA uses the same BIGTK to verify the MIC. If the verification is successful, it proves that the beacon frame has not been tampered with.
- Figure 4 is the frame format of the management frame with BIP protection added, that is, on the basis of the original management frame, a management frame information integrity code element (Management MIC Element, MME) field containing MIC information, key suite index information (Key ID) and integrity protection frame sequence number frame number information (IPN) is added.
- Management MIC Element MME
- Key ID key suite index information
- IPN integrity protection frame sequence number frame number information
- the AP slices a period of service time, such as a beacon period, into smaller service time slices corresponding to different b-TWT groups, and uses different b-TWT group IDs to indicate the service time slice information, and then broadcasts the information through the beacon frame.
- the STA can join a b-TWT group through negotiation and non-negotiation.
- the STA needs to interact with the AP for data, the STA wakes up during the corresponding b-TWT group service time and interacts with the AP for uplink and downlink cache data.
- Wi-Fi 7 defines the strict target wake-up time (Restricted Target Wake Up Time, r-TWT) technology to meet the low-latency and low-power business needs.
- the basic principle is to use the b-TWT technology to slice the channel resources according to the service time, and then periodically allocate these time slices to STAs with low-latency services, and schedule the business data to be transmitted in the channel to meet the latency requirements of the business.
- the r-TWT technology adds protection measures at the starting boundary of the time slice to prevent other devices from occupying the r-TWT service time period.
- the research direction of the Ultra high reliability (UHR) study group (SG) established by IEEE is mainly focused on improving transmission stability, including reducing latency, increasing throughput and reducing packet loss rate.
- UHR Ultra high reliability
- One of the ways is non-Wi-Fi signal (such as Bluetooth signal) interference avoidance technology.
- ISM Industrial, Scientific and Medical
- the STA connected to the AP informs the AP of the characteristics of its non-Wi-Fi service (including start and end time, period, etc.), and the AP broadcasts the characteristics through beacon frames. After other STAs receive this information, they automatically avoid transmitting Wi-Fi signals during the period of non-Wi-Fi services, thereby reducing the packet loss rate caused by mutual interference and improving the stability of the system.
- Bluetooth calls (based on Bluetooth connection-oriented technology, i.e., BT SCO profile) have a typical period of 3.75ms or 7.5ms. If a third-party device obtains this information, it can infer that there are STAs using Bluetooth phones around the BSS based on the characteristics of the Bluetooth business. Obviously, the use of Bluetooth phones is user privacy information, and directly broadcasting this information creates the risk of user privacy leakage.
- TWT target wake-up time since the beacon frames that support r-TWT and b-TWT (hereinafter referred to as: TWT target wake-up time) functions carry TWT grouping and service time window information by default, if a third-party device detects the TWT information in the beacon frame, it can occupy the channel within each r-TWT service time window, causing devices containing low-latency services to wait for channel intervention because they cannot intervene in the channel in time in the corresponding TWT window, causing delay problems and power consumption problems at the application layer, which may in turn cause the risk of user privacy leakage.
- the present disclosure provides an information processing method, a network Device and computer-readable storage medium, wherein the sending-side network device can encrypt the sensitive information field in the beacon frame by using the corresponding key configuration information to obtain the corresponding encrypted beacon frame, and then the sending-side network device sends the encrypted beacon frame in the network, so that the receiving-side network device uses the corresponding key configuration information to decrypt the sensitive information field of the encrypted beacon frame during the process of decrypting the sensitive information of the encrypted beacon frame, that is, when protecting the transmission of sensitive information of the beacon frame in the network, it is only necessary to use the corresponding key configuration information to encrypt the sensitive information of the beacon frame, thereby preventing other network devices or third-party devices from obtaining the sensitive information in the beacon frame to a certain extent, and effectively avoiding the risk of leakage of user sensitive information.
- FIG. 5 is a flowchart of an information processing method provided by an embodiment of the present disclosure.
- the information processing method can be applied to a sending-side network device.
- the information processing method may include but is not limited to step S100 and step S200.
- Step S100 Use the key configuration information to encrypt the sensitive information field in the beacon frame to obtain an encrypted beacon frame.
- the beacon frame can be a management frame periodically sent in the wireless local area network.
- the beacon frame contains information about the network and is usually sent by an access point device to announce the existence of the network.
- the sending side network device may be an access point (AP) or a multi-link access point (AP multi-link device, AP MLD), such as a wireless router, etc., but this embodiment does not specifically limit this.
- AP access point
- AP MLD multi-link access point
- the information in the sensitive information domain may include: information closely related to the user's non-Wi-Fi services, such as the time and period of the non-Wi-Fi services using the channel; and information related to the user's Wi-Fi services, such as the time information of the target wake-up time TWT of the network device.
- the channel is the transmission medium connecting the sending side network device and the receiving side network device, that is, the channel for signal transmission.
- TWT a schedule is established between STA and AP, which is an agreement between STA and AP and consists of TWT time periods.
- the TWT time period negotiated by STA and AP includes one or more beacon periods.
- STA will wake up, wait for the trigger frame sent by AP, and exchange data.
- this transmission is completed, it returns to sleep state.
- Each STA and AP will conduct independent negotiations, and each STA has a separate TWT time period.
- AP can also group according to the TWT time periods set by multiple STAs, and transmit data with multiple STAs at a time, thereby improving energy saving efficiency.
- the terminal can inform the AP of its energy-saving scheduling information, and then the AP will allocate a TWT period and feed the period back to the terminal. Then the terminal will wake up at the specified TWT period and exchange data frames with the AP.
- the TWT period information may be obtained by a third-party device during the transmission process.
- the third-party device obtains the TWT period information, it can occupy the channel in each r-TWT service time window, causing the device containing low-latency services to wait for channel intervention because it cannot intervene in the channel in time in the corresponding TWT window, thereby causing delay problems and power consumption problems at the application layer.
- the TWT period information is encrypted as sensitive information of the beacon frame and then transmitted.
- Other network devices or third-party devices cannot decrypt the encrypted sensitive information field because they cannot obtain the key information of the sensitive information field, so that the network devices containing low-latency services can intervene in the channel in time in the corresponding TWT window, thereby improving transmission stability and throughput, while reducing latency and packet loss rate.
- the sensitive information domain may include only the sensitive information domain of the present device, or may include the first sensitive information domain of the sending side network device and the second sensitive information domain of the neighboring network device.
- the secret key configuration information may be used to encrypt the first sensitive information and the second sensitive information domain in the beacon frame to obtain an encrypted beacon frame.
- the sending side network device when protecting the transmission of sensitive information of a beacon frame, can use corresponding key configuration information to encrypt the sensitive information field of the beacon frame, and then send the encrypted beacon frame and the key configuration information.
- the receiving side network device After the receiving side network device receives the encrypted beacon frame and the key configuration information, it can directly use the corresponding key configuration information to decrypt the sensitive information field of the beacon frame, thereby preventing other network devices or third-party devices from obtaining sensitive information of the beacon frame to a certain extent, thereby effectively avoiding the risk of leakage of user sensitive information.
- the key configuration information may use the same frame number information, key suite information and/or key information as the BIP technology, that is, the sending side network device uses the key information, such as the beacon frame integrity group temporary key (Beacon integrity group temporal key, BIGTK), to generate a message integrity code (message integrity code, MIC) and encrypt sensitive information.
- the key information such as the beacon frame integrity group temporary key (Beacon integrity group temporal key, BIGTK)
- a message integrity code messages integrity code, MIC
- MIC message integrity code
- FIG. 6 is a schematic diagram of the sending side network device using the same secret key to generate an information integrity code and encrypt sensitive information.
- the basic principle is: when the AP sends the group temporary key (Group Temporal Key, GTK) to the STA, it sends the beacon frame integrity group temporary key and a frame sequence number (BIPN, BIGTK PN) used for beacon frame integrity protection to the STA, and then the AP adds the MIC value of the management frame calculated by using BIGTK to the end of the sent multicast frame and sends it to the STA.
- the STA uses the same BIGTK to verify the MIC value. If the verification is successful, it proves that the beacon frame has not been tampered with. If the verification fails, it proves that the beacon frame has been tampered with.
- the beacon frame sent by the sending side network device carries sensitive information of a neighbor AP in a neighbor report (NR), a reduced neighbor report (RNR) or a multiple basic service set identifier (MBSSID)
- the first sensitive information field of the current AP and the second sensitive information field of the neighbor AP can be encrypted using the first secret key information.
- MBSSID technology can reduce the channel resource overhead of each AP sending beacon frames and detection response frames.
- Figure 7 exemplarily shows a structural diagram of the sending side network device using the same secret key to encrypt sensitive information elements located in different IEs.
- the MBSSID field in the beacon frame sent by the sending side network device carries the sensitive information of the neighbor AP.
- the sending side network device can use the first secret key information to encrypt the sensitive information field in the beacon frame and the sensitive information field of the neighbor AP respectively.
- the beacon frame sent by the sending side network device carries key suite indication information
- the key suite indication information can be used to indicate the key suite information selected when encrypting the sensitive information domain, so that after the receiving side network device receives the beacon frame sent by the sending side network device, it can use the key suite indication information carried in the beacon frame to indicate the decryption of the sensitive information domain.
- Step S200 Send an encrypted beacon frame.
- the encrypted beacon frame includes at least the encrypted sensitive information field and the key suite indication information for indicating the key suite information selected when encrypting the sensitive information field.
- the encrypted beacon frame may be sent in a network including but not limited to the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.
- a STA connected to an AP can inform the AP of the characteristics of its non-Wi-Fi service (including start and end time, period, etc.), and the AP encrypts the characteristics and broadcasts them through a beacon frame. After receiving the information, other STAs automatically avoid transmitting Wi-Fi signals during the period of non-Wi-Fi services, thereby reducing the problem of packet loss caused by mutual interference. problem and improve the stability of the system.
- the information processing method may include but is not limited to the following step S110.
- S110 Interacting with the receiving-side network device through management frames to support the protection of sensitive information.
- the management frame includes at least one of the following: beacon frame, probe request frame, probe response frame, multi-link probe request frame (ML probe request), multi-link probe response frame (ML probe response), association request frame, reassociation request frame, association response frame, reassociation response frame, authentication frame and action frame.
- a supported capability set for sensitive information protection may be carried in an RSNE field, where RSNE may be used to indicate elements related to a key suite and RSN capabilities carried in a robust security network (RSN), thereby enhancing data encryption and authentication performance of a WLAN.
- RSNE may be used to indicate elements related to a key suite and RSN capabilities carried in a robust security network (RSN), thereby enhancing data encryption and authentication performance of a WLAN.
- RSN robust security network
- the management frame may include a robust security network element field, as shown in FIG8 , FIG8 exemplarily shows the structure of the RSNE field extension, in the RSN Capabilities capability set field of the RSNE, there may be multiple Reserved bit indication bits, such as the B10 flag bit, the B11 flag bit, the B12 flag bit, and the B15 flag bit shown in FIG8 , these flag bits can be used as sensitive information protection capability indication flag bits, used to indicate whether sensitive information protection in the beacon frame is supported. When indicating that sensitive information protection in the beacon frame is supported, you can arbitrarily select one of the reserved flag bits, and then set the bit of the flag bit to 1.
- the bit of the flag bit can be set to 0.
- the B10 flag bit in FIG8 sets the original Reserved bit indication bit to the sensitive information protection capability indication flag bit (Sensitive Info Protection).
- the sensitive information protection capability indication flag bit is 1, it means that sensitive information protection in the beacon frame can be supported; when the sensitive information protection capability indication flag bit is 0, it means that sensitive information protection in the beacon frame is not supported.
- FIG. 9 is a flow chart of an information processing method provided by another embodiment of the present disclosure.
- the information processing method may include but is not limited to steps S300 to S400 .
- Key ID used to indicate key suite indication information
- PN used to indicate the frame number
- Key used to represent key information.
- the secret key information can be used to generate a message integrity code and to encrypt sensitive information fields in the beacon frame.
- the key suite information may include at least one of the following: AES-128-CMAC, AES-128-GMAC, AES-256-CMAC, AES-256-GMAC, and SM4.
- S400 Send the key configuration information to the receiving-side network device via an information frame.
- the type of information frame can include any of the following: authentication frame; EAPOL frame; action frame.
- the receiving side network device can be an access point (AP), a multi-link access point (AP multi-link device, AP MLD), a terminal (STA) and a multi-link terminal (non-AP MLD).
- the sending side network device can communicate with the receiving side network device through the information frame to exchange key configuration information.
- the receiving-side network device interacts so that it can obtain the corresponding key configuration information and use the key information in the key configuration information to decrypt the sensitive information field of the received beacon frame to obtain the decrypted information.
- the information processing method of the sending side network device may further include: not initiating competition and using channel resources within the time window of the service access channel corresponding to the sensitive information carried by the sensitive information domain.
- FIG. 11 is a flowchart of another information processing method provided by an embodiment of the present disclosure.
- the information processing method is applied to a receiving-side network device.
- the information processing method may include but is not limited to steps A100 to A300.
- Step A100 Receive a first beacon frame sent by a sending-side network device, wherein the first beacon frame includes a sensitive information field encrypted using key configuration information.
- the first beacon frame sent by the sending network device and received by the receiving network device may carry key suite indication information, wherein the key suite indication information is used to indicate the key suite information selected when decrypting the sensitive information field of the first beacon frame.
- the relevant introduction and explanation of the first beacon frame and the sensitive information field in this embodiment are consistent with the relevant introduction and explanation of the beacon frame and sensitive information in the embodiment shown in the aforementioned step S100.
- the relevant introduction and explanation of the first beacon frame and the sensitive information field in this embodiment reference can be made to the relevant introduction and explanation of the beacon frame and sensitive information in the embodiment shown in the aforementioned step S100, and no further details will be given here.
- Step A200 Use the key configuration information to decrypt the sensitive information field in the first beacon frame to obtain decrypted sensitive information.
- the key configuration information may include key information, beacon frame numbering information and key suite information, wherein the key information may be used to verify the information integrity code and to decrypt the sensitive information field in the first beacon frame.
- the key configuration information may include key information used to encrypt the sensitive information field in the first beacon frame and generate the information integrity code in the first beacon frame, number information of the first beacon frame, and key suite information.
- the receiving side network device when the receiving side network device receives the encrypted beacon frame sent by the sending side network device, the receiving side network device can use the key information of the key configuration information previously received from the sending side network device to decrypt the sensitive information field in the encrypted beacon frame and verify its MIC information. If the verification is successful, it proves that the beacon frame has not been tampered with; if the verification fails, it proves that the beacon frame has been tampered with.
- the receiving side network device can use the key information of the received key configuration information to decrypt the first sensitive information field and the second sensitive information field to obtain corresponding decrypted sensitive information, so that corresponding operations can be performed subsequently based on the decrypted sensitive information.
- Step A300 Perform corresponding information processing according to the decrypted sensitive information.
- the receiving side network device performing corresponding information processing may include: not initiating competition and using channel resources within a time window of a service access channel corresponding to decryption of sensitive information.
- network device communication can be random channel access, that is, network devices do not occupy fixed resources.
- the time window for the service access channel corresponding to the decrypted sensitive information refers to the period of time during which the channel resources are occupied by the service corresponding to the decrypted sensitive information.
- the receiving side network device can, according to the indication of the decrypted sensitive information, During the time window of the service access channel corresponding to the information, no contention is initiated and channel resources are not used so that the corresponding service can use the channel resources.
- FIG. 12 exemplarily shows an information processing flow chart when the receiving side network device is an AP or an AP MLD.
- the corresponding information processing may include but is not limited to steps A310 to A320.
- A310 Use the key configuration information generated locally by the receiving side network device to encrypt the decryption sensitive information to obtain encrypted information.
- the key configuration information generated locally by the receiving side network device may include second key information used to encrypt the sensitive information field in the second beacon frame and generate the information integrity code in the second beacon frame, the numbering information of the second beacon frame, and the key suite information.
- the receiving side network device uses the first key information in the received key configuration information to decrypt the sensitive information field in the first beacon frame and obtains the decrypted information
- the second key information generated locally by the receiving side network device can be used again to encrypt the obtained decrypted information, and then the re-encrypted decrypted information is copied to the field for storing the sensitive information of the sending side network device in the second beacon frame. Then, the receiving side network device can send the second beacon frame in the network.
- A320 Generate a second beacon frame according to the encrypted information, where the second beacon frame includes a sensitive information field for storing the encrypted information.
- a field for storing sensitive information of a sending side network device is provided in the second beacon frame, wherein the field for storing may include: an NR field, an RNR field, or an MBSSID field.
- the NR field, the RNR field, or the MBSSID field may be used to indicate that a neighboring AP contains sensitive information, where the neighboring AP is a sending side network device.
- Figure 13 exemplarily shows a structural diagram of the receiving side network device using the second secret key to encrypt sensitive information elements located in different IEs.
- the NR field in the second beacon frame is used to store the sensitive information of the sending side network device.
- the second secret key information can be used to encrypt the sensitive information field in the second beacon frame and the sensitive information field of the sending side network device respectively.
- the corresponding information processing may further include: not initiating competition and not using channel resources within a time window of a service access channel corresponding to decryption of sensitive information.
- the beacon frame received by the receiving side network device can support r-TWT and b-TWT functions.
- the beacon frame carries TWT grouping and service time window information by default.
- the receiving side network device can decrypt the sensitive information according to the instructions.
- Within the time window of the service access channel corresponding to the decrypted sensitive information if it is not a member of the corresponding r-TWT and b-TWT group, it will not initiate competition and use channel resources, so that the corresponding service can intervene in the channel in time in the corresponding TWT window, thereby reducing transmission delay, improving throughput and reducing packet loss rate.
- the corresponding information processing may include but is not limited to the following two types: the receiving side network device does not initiate competition and use channel resources within the time window of the service access channel corresponding to the decrypted sensitive information; the receiving side network device uses the locally generated key configuration information to encrypt the decrypted sensitive information to obtain encrypted information, and then generates a second beacon frame based on the encrypted information, wherein the second beacon frame includes a sensitive information field for storing the encrypted information, and then sends the second beacon frame.
- A330 Send the second beacon frame.
- the second beacon frame can include at least the sensitive information field in the encrypted second beacon frame and the encrypted sensitive information field of the sending side network device, and the key suite indication information for indicating the key suite information selected when encrypting the sensitive information field.
- the receiving side network device can interact with the third receiving side network device to discuss the support capabilities of both parties for the protection of sensitive information, and the third receiving side network device can also receive and save the second key configuration information sent by the receiving side network device through the second information frame, so that when the third receiving side network device receives the encrypted second beacon frame, it can decrypt and verify the encrypted sensitive information field of the second beacon frame according to the key information in the second key configuration information, and then perform subsequent information processing according to the decrypted sensitive information after obtaining the decrypted sensitive information.
- the third receiving side network device can interact with the third receiving side network device to discuss the support capabilities of both parties for the protection of sensitive information
- the third receiving side network device can also receive and save the second key configuration information sent by the receiving side network device through the second information frame, so that when the third receiving side network device receives the encrypted second beacon frame, it can decrypt and verify the encrypted sensitive information field of the second beacon frame according to the key information in the second key configuration information, and then perform subsequent information processing according to the decrypted sensitive information after
- step A100 before executing step A100, the step of interacting with the sending-side network device through management frames to determine the support capabilities of both parties for sensitive information protection may be further included.
- the receiving-side network device exchanges the support capability of sensitive information protection with the sending-side network device by setting the bit of the flag in the robust security network element field of the management frame to 1.
- step A100 before executing step A100, the step of receiving key configuration information sent by the sending side network device through an information frame may be further included.
- the key configuration information may include: key information used to encrypt the sensitive information field in the beacon frame and generate the information integrity code in the beacon frame, the numbering information of the beacon frame, and key suite information.
- the key suite information may include at least one of the following: AES-128-CMAC, AES-128-GMAC, AES-256-CMAC, AES-256-GMAC and SM4.
- the type of the information frame may include any one of the following: authentication frame, EAPOL frame, action frame.
- the sending side network device can send updated key configuration information via an information frame in the network at any time.
- the receiving side network device receives the information frame, it can obtain the updated key configuration information and then replace the originally saved key configuration information with the updated key configuration information.
- the STA device can obtain the sensitive information by directly using the corresponding key information to decrypt the protected sensitive information domain, and can prevent the same channel from being used during its working time period.
- the STA device can obtain sensitive information by directly using the corresponding key information to decrypt the protected sensitive information domain, and can prevent the same channel from being used during its working time period.
- the STA or third-party devices because they do not obtain the corresponding key, they cannot obtain sensitive information related to the user's business, thereby effectively avoiding the risk of leakage of user sensitive information.
- FIG 14 is a schematic diagram of the process of the sending side network device and the receiving side network device using beacon frames to interact and encrypt sensitive information.
- the sending side network device shown in Figure 14 can be an access point or a multi-link access point, and the receiving side network device can be a terminal or a multi-link terminal.
- the specific example of the interaction process is as follows:
- Step 1 The sending-side network device exchanges sensitive information protection support capabilities with the receiving-side network device through management frames.
- Step 2 The sending side network device locally generates key configuration information 1 for encrypting and decrypting sensitive information in the beacon frame.
- Step 3 During the frame interaction between the sending side network device and the receiving side network device, the sending side network device sends an information frame to the receiving side network device, and sends the above-mentioned secret key configuration information 1 to the receiving side network device.
- Step 4 The receiving-side network device saves the above-mentioned key configuration information 1 locally.
- Step 5 The sending network device sends a beacon frame whose sensitive information field has been encrypted using the above-mentioned key configuration information 1.
- Step 6 After receiving the beacon frame, the receiving network device uses the key configuration information 1 to decrypt its sensitive information.
- Step 7 The receiving network device performs corresponding information processing according to the decrypted sensitive information indication.
- the sending side network device in the above interaction process can be AP or AP MLD
- the receiving side network device can be any one of AP, AP MLD, STA, and non-AP MLD.
- the sending side network device needs to use the same key information to encrypt the first sensitive information and the second sensitive information
- the receiving side network device is an AP or AP MLD, after the receiving side network device decrypts the sensitive information field according to the key configuration information, it needs to use the second key information generated locally to encrypt the decrypted information field again.
- the sending side network device shown in Figure 15 can be an access point or a multi-link access point
- the receiving side network device can be an access point or a multi-link access point.
- the receiving side network device shown in Figure 15 can repeat the operation of the sending side network device shown in Figure 14, and correspondingly, the sending side network device shown in Figure 15 repeats the operation of the receiving side network device shown in Figure 14. Therefore, based on the interaction process shown in Figure 14, the interaction process shown in Figure 15 specifically also includes the following steps:
- Step A The receiving-side network device exchanges sensitive information protection support capabilities with the sending-side network device through management frames.
- Step B The receiving-side network device locally generates key configuration information 2 for encrypting and decrypting sensitive information in the beacon frame.
- Step C During the frame interaction between the receiving side network device and the sending side network device, the receiving side network device sends an information frame to the sending side network device, and sends the above-mentioned secret key configuration information 2 to the sending side network device.
- Step D The sending side network device stores the above-mentioned secret key configuration information 2 locally.
- Step E The receiving-side network device sends a beacon frame whose sensitive information field has been encrypted using the above-mentioned key configuration information 2.
- Step F After receiving the beacon frame, the sending network device uses the key configuration information 2 to decrypt its sensitive information.
- Step G The sending side network device performs corresponding information processing according to the decrypted sensitive information indication.
- the sending-side network device and the receiving-side network device in the present disclosure respectively include a memory and a processor, wherein the memory and the processor may be connected via a bus or other means.
- the memory as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs.
- the memory may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device.
- the memory may optionally include a memory remotely disposed relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
- the application scenario of sensitive information encrypted by the sending-side network device and the receiving-side network device using beacon frames described in the embodiment of the present disclosure is for the purpose of more clearly illustrating the technical solution of the embodiment of the present disclosure, and does not constitute a limitation on the technical solution provided by the embodiment of the present disclosure.
- Those skilled in the art will appreciate that with the emergence of new application scenarios, the technical solution provided by the embodiment of the present disclosure is equally applicable to similar technical problems.
- an embodiment of the present disclosure provides a network device, which includes: a memory, a processor, and a computer program stored in the memory and executable on the processor.
- the processor and the memory may be connected via a bus or other means.
- the network device in this embodiment can be applied to the sending side network device, the receiving side network device and the third receiving side network device in the embodiments of the present disclosure. These embodiments all belong to the same inventive concept, so these embodiments have the same implementation principles and technical effects, and will not be described in detail here.
- the non-transitory software programs and instructions required to implement the information processing method of the above-mentioned embodiment are stored in the memory.
- the information processing method of the above-mentioned embodiment is executed, for example, method steps S100 to S200 in Figure 5, method steps S300 to S400 in Figure 9, method steps A100 to A300 in Figure 11, and method steps A310 to A330 in Figure 12 described above are executed.
- the device embodiments described above are merely illustrative, and the units described as separate components may or may not be physically separated, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
- an embodiment of the present disclosure also provides a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are executed by a processor or a controller, for example, by a processor in the above-mentioned network device embodiment, so that the above-mentioned processor can execute the information processing method in the above-mentioned embodiment, for example, execute the method steps S100 to S200 in Figure 5 described above, the method steps S300 to S400 in Figure 9, the method steps A100 to A300 in Figure 11, and the method steps A310 to A330 in Figure 12.
- Volatile and non-volatile, removable and non-removable media implemented in any method or technology of storing computer-readable storage media (such as memory, data structure, program module or other data).
- Computer storage media include but are not limited to RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disk (DVD) or other optical disk storage, magnetic cassettes, magnetic tapes, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by the computer.
- communication media typically contains computer-readable instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Mobile Radio Communication Systems (AREA)
Abstract
本公开提供了一种信息处理方法、网络设备及计算机可读存储介质。其中,信息处理方法应用于发送侧网络设备,包括:使用秘钥配置信息对信标帧中的敏感信息域进行加密,得到加密信标帧;发送所述加密信标帧。本公开实施例中,发送侧网络设备可以直接使用相应的秘钥配置信息对信标帧中的敏感信息域添加保护。因此,仅需使用相应的秘钥配置信息加密信标帧中的敏感信息域,从而能够防止其他网络设备或者第三方设备对该信标帧中的敏感信息的获取,进而有效规避用户敏感信息外泄的风险。
Description
相关申请的交叉引用
本公开基于2023年11月16日提交的发明名称为“信息处理方法、网络设备及计算机可读存储介质”的中国专利申请CN202311535924.7,并且要求该专利申请的优先权,通过引用将其所公开的内容全部并入本公开。
本公开实施例涉及但不限于通信技术领域,尤其涉及一种信息处理方法、网络设备及计算机可读存储介质。
目前,支持严格目标唤醒时间(Restricted Target Wake Up Time,r-TWT)以及群组唤醒时间(broadcast Target Wakeup Time,b-TWT)(以下统一简称:TWT目标唤醒时间)功能的信标帧中会默认携带TWT分组以及服务时间窗口信息,如果第三方设备检测到信标帧中的TWT信息后,可以在每次r-TWT服务时间窗口内占用信道,从而造成包含低时延业务的设备因为无法在对应的TWT窗口及时介入信道而一直等待信道介入,造成应用层的时延问题和功耗问题,进而可能会造成用户隐私外泄的风险。
发明内容
以下是对本文详细描述的主题的概述。本概述并非是为了限制权利要求的保护范围。
本公开实施例提供了一种信息处理方法、网络设备及计算机可读存储介质,不仅能够在一定程度上防止其他网络设备或者第三方设备对该信标帧中的敏感信息的获取,还能有效规避用户敏感信息外泄的风险。
第一方面,本公开实施例提供了一种信息处理方法,应用于发送侧网络设备,包括:使用秘钥配置信息对信标帧中的敏感信息域进行加密,得到加密信标帧;发送所述加密信标帧。
第二方面,本公开实施例还提供了一种信息处理方法,应用于接收侧网络设备,包括:接收发送侧网络设备发送的第一信标帧,其中,所述第一信标帧包括使用秘钥配置信息进行加密后的敏感信息域;使用所述秘钥配置信息对所述第一信标帧中的所述敏感信息域进行解密,得到解密敏感信息;根据所述解密敏感信息执行相应的信息处理。
第三方面,本公开实施例还提供了一种网络设备,包括:存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述计算机程序时实现如上所述第一方面的信息处理方法或者实现如上所述第二方面的信息处理方法。
第四方面,本公开实施例还提供一种计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令用于执行如上所述的信息处理方法。
图1是本公开实施例提供的NR的结构图;
图2是本公开实施例提供的MBSSID元素的结构图;
图3是本公开实施例提供的RSNE字段结构图;
图4是本公开实施例提供的添加了BIP保护的管理帧格式;
图5是本公开实施例提供的一种信息处理方法的流程图;
图6是本公开实施例提供的发送侧网络设备利用同一秘钥生成信息完整性代码和加密敏感信息的示意图;
图7是本公开实施例提供的发送侧网络设备利用第一秘钥加密位于不同IE的敏感信息元素的结构图;
图8是本公开实施例提供的RSNE字段扩展的结构图;
图9是本公开另一个实施例提供的信息处理方法流程图;
图10是本公开实施例提供的秘钥配置信息的结构图;
图11是本公开实施例提供的另一种信息处理方法的流程图;
图12是本公开一个实施例提供的接收侧网络设备为AP或者AP MLD时的信息处理流程图;
图13是本公开一个实施例提供的接收侧网络设备利用第二秘钥加密位于不同IE的敏感信息元素的结构图;
图14是本公开一个实施例提供的发送侧网络设备与接收侧网络设备利用信标帧交互加密敏感信息的过程示意图;
图15是本公开一个实施例提供的发送侧网络设备与接收侧网络设备利用信标帧交互加密敏感信息的另一过程示意图。
为了使本公开的目的、技术方案及优点更加清楚明白,以下结合附图及实施例,对本公开进行进一步详细说明。应当理解,此处所描述的具体实施例仅用以解释本公开,并不用于限定本公开。
需要说明的是,虽然在装置示意图中进行了功能模块划分,在流程图中示出了逻辑顺序,但是在某些情况下,可以以不同于装置中的模块划分,或流程图中的顺序执行所示出或描述的步骤。说明书和权利要求书及上述附图中的术语“第一”、“第二”等是用于区别类似的对象,而不必用于描述特定的顺序或先后次序。
值得注意的是,在目前的无线通信技术中,光纤到房间(fiber-to-the-room,FTTR)技术是通过光纤连接家庭或中小企业等场景下不同房间或位置的无线路由器AP,从而提供多AP之间组网的高带宽、高可靠性的连接,在此基础上,可以利用点到多点的光分配网络实现主控制AP和从AP的连接。
目前,邻居报告(NR,Neighbour report)字段包含周围其他接入点(AP)或者多链路接入点(AP MLD,以下简称AP)的信息,一般用于终端(STA)或者多链路终端(non-AP MLD,以下简称STA)向目标AP发送查询帧,查询周围其他AP的信息,目标AP向STA发送响应帧,反馈STA所查询的周围其他AP的信息。比如STA向AP发送接入网络查询协议(ANQP,Access Network Query Protocol)查询帧,AP向STA反馈ANQP响应帧。或者,
AP发送的信标帧,探测响应帧中携带NR字段主动广播周围其他AP的信息;或者,在发生漫游或者多AP负载均衡场景下,AP向STA主动推荐周围其他AP的信息,而STA对该信息进行确认,然后向所推荐的一个AP发送(重)关联请求。比如,AP向STA发送的BSS转移管理请求(BSS transition management,BTM)request帧,并在NR字段中携带所推荐的AP的信息,STA发送BTM response帧,其包含的NR字段中携带所期望连接的AP的信息,以及随后发送认证帧和(重)关联帧与目标AP建立连接。如图1所示,图1是本公开实施例提供的NR字段结构图,在该NR结构中,各主要字段的解释如下:
Element ID:用于表示元素标识符;
Length:用于表示元素长度;
BSSID:用于表示基本服务集合识别符(MAC地址);
BSSID Information:用于表示基本服务集合识别符信息字段;
Operating Class:用于表示工作信道类别;
Channel Number:用于表示信道编号;
PHY Type:用于表示物理层类型;
Optional Subelements:用于表示可选子元素;
AP Reachability:用于表示指示邻居AP是否可以被探测到;
Security:用于表示与当前链路安全参数是否相同;
Key Scope:用于指示与当前链路对应的认证者信息是否相同;
Capabilities:用于表示邻居AP的能力集信息;
Mobility Domain:用于指示邻居AP发送的信标帧是否携带移动域元素(MDE,Mobility Domain Element)字段;
High Throughput:用于指示邻居AP是否为HT AP,即是否支持HT能力集;
Very High Throughput:用于指示邻居AP是否为VHT AP,即是否支持VHT能力集;
FTM:用于指示邻居AP是否支持FTM(Fine Timing measurement,精细时间测量)功能;
High Efficiency:用于指示邻居AP是否为HE AP,即是否支持HE能力集;
ER BSS:用于指示邻居AP是否为支持扩展覆盖范围(ER,Extended range)功能的AP;
Colocated AP:用于指示邻居AP与当前链路对应的AP共存在一个物理设备上;
Unsolicited Probe Responses Active:用于指示邻居AP可以在6GHz频段上每隔20ms发送一个非请求的探测响应帧;
Members of ESS with 2.4/5GHz Colocated AP:用于指示邻居AP为工作在2.4GHz或者5GHz频段,并与当前AP共存在一个物理设备上;
OCT Supported With Reporting AP:用于指示当前链路上的AP与邻居AP支持利用频道隧道(on-channel Tunneling,OCT)技术交互MMPDU;
Colocated With 6GHz AP:用于表示邻居AP为工作在6GHz频段,并与当前AP共存在一个物理设备上;
Extremely High Throughput:用于指示邻居AP是否为EHT AP,即是否支持EHT能力集;
Reserved:用于表示预留字段。
进一步地,为了降低字段长度造成的信道资源开销,在NR字段的基础上,RNR(reduced neighbour report)字段进行了相应的裁剪和修改,只包括周围AP的关键信息,比如工作信道、
SSID,BSSID信息等。当STA接收到一个AP发送的携带RNR字段的信标帧、探测响应帧等管理帧时,STA能够快速发现周围其他AP,进而在目标AP所在的信道上进一步进行探测,从而获取该AP的完整信息,这样降低了STA盲目扫描信道并探测周围AP的时间开销。
由于在Wi-Fi的一个射频链路上可以创建多个AP,每个AP对应不同的BSSID,为了降低每个AP发送信标帧、探测响应帧的信道资源开销,802.11协议引入了多基本服务集合识别符(multiple BSSID,MBSSID)技术,即同一个射频上多个AP发送的信标帧、探测响应帧合并到一个AP的信标帧和探测响应帧中发送,即一个AP的信标帧、探测响应帧中携带同射频其他AP的信息,这些信息放在多BSSID元素字段中,其结构如图2所示,在该结构中,各主要字段的解释如下:
Element ID:用于表示元素标识符;
Length:用于表示元素长度;
MaxBSSID Indicator:用于表示最大基本服务集合识别符(BSSID)数量指示;
Optional Subelements:用于表示可选子元素。
其中,其他AP的详细信息存放在Optional Subelements之中。
为了增强WLAN的数据加密和认证性能,IEEE通过新一代安全标准,定义了强健安全网络(Robust Security Network,RSN)的概念,并且针对WEP加密机制的各种缺陷做了多方面的改进,比如:加密技术和安全认证功能。强健安全网络元素(RSN element,RSNE),用于指示RSN中携带的和秘钥套件以及RSN能力相关的元素。如图3所示,图3是本公开实施例提供的RSNE字段结构图,在该RSNE结构中,各主要字段的解释如下:
Element ID:用于表示唯一标识该元素;
Length:用于表示字段长度信息;
Version:用于表示RSN版本信息;
Group Data Cipher Suite:用于表示组播数据帧秘钥套件信息;
Pairwise Cipher Suite Count:用于表示单播秘钥套件数量;
Pairwise Cipher Suite List:用于表示单播秘钥套件列表;
AKM(authentication and key management)Suite Count:用于表示认证和秘钥套件数量;
AKM Suite List:用于表示认证和秘钥套件列表;
RSN Capabilities:用于表示RSN能力集;
PMKID Count:用于表示PMKID数量;
PMKID List:用于表示PMKID列表;
Group Management Cipher Suite:用于表示组播管理帧秘钥套件信息。
进一步地,为了给组播管理帧和信标帧(Beacon)提供数据完整性和重放保护,定义了广播/多播完整性协议(BIP,Broadcast/Multicast Integrity Protocol)。其基本原理是AP在向STA发送GTK(组临时秘钥)的同时,发送完整性组临时秘钥(integrity group temporal key,IGTK)以及一个用于BIP协议保护的组播帧完整性保护帧序号(IGTK Packet Number,IPN)给STA,然后AP在发送的组播帧最后添加利用IGTK计算出的管理帧的信息完整性代码(message integrity code,MIC)值后发送给STA。STA利用相同的IGTK验证MIC,如果验证成功后,证明该组播帧未被篡改。同样的,对于保护信标帧来说,AP在向STA发送GTK的同时,发送信标帧完整性组临时秘钥(Beacon integrity group temporal key,BIGTK)以及
一个用于信标帧完整性保护的帧序号(BIPN,BIGTK PN)给STA,然后AP在发送的组播帧最后添加利用BIGTK计算出的管理帧的MIC值后发送给STA。STA利用相同的BIGTK验证MIC,如果验证成功后,证明该信标帧未被篡改。如图4所示,图4是添加了BIP保护的管理帧的帧格式,即在原来的管理帧的基础上,添加了包含MIC信息、秘钥套件索引信息(Key ID)和完整性保护帧序号帧编号信息(IPN)的管理帧信息完整性代码元素(Management MIC Element,MME)字段。
在上述的基础上,Wi-Fi 6引入的群组唤醒时间(broadcast Target Wakeup Time,b-TWT)技术中,AP将一段服务时间,比如一个信标周期进行切片,分成更小的服务时间片,对应不同的b-TWT组,并用不同的b-TWT组ID来指示服务时间片信息,然后将该信息通过信标帧广播出去,STA可以通过协商和非协商方式加入一个b-TWT组。当STA需要与AP进行数据交互时,STA在对应的b-TWT组服务时间内醒来,与AP交互上下行缓存数据,在非对应的b-TWT组服务时间,STA不需要周期性醒来检测信标信息,也不需要通过CSMA/CA方式竞争信道资源并接收缓存数据,因此降低了STA周期性醒来检测信标帧的和抢占信道产生的功耗,实现超低功耗的目标。进一步地,Wi-Fi 7在b-TWT技术基础上,定义了严格目标唤醒时间(Restricted Target Wake Up Time,r-TWT)技术来满足低时延、低功耗业务需求,基本原理是利用b-TWT技术,将信道资源按照服务时间进行切片,然后将这些时间切片周期性地分配给具有低时延业务的STA,调度业务数据在信道中传输,满足业务的时延要求,并且r-TWT技术在时间切片开始边界添加保护措施,防止其他设备占用r-TWT服务时间段。
在目前的无线通信技术中,IEEE成立的超高可靠性(UHR,Ultra high reliability)研究组(SG,study group)的研究方向主要集中在提高传输稳定性,包括降低时延、提高吞吐量和降低丢包率。其中一种方式是非Wi-Fi信号(比如蓝牙信号)干扰避免技术。具体来说,由于非Wi-Fi信号与Wi-Fi信号工作在相同的工业、科学和医学(Industrial Scientific Medical Band,ISM)频段上,当两种信号重叠时,势必相互干扰,造成接收端接收到上述重叠信号非常困难,进而导致了丢包率上升。为了解决上述问题,UHR研究小组正在研究一种非Wi-Fi信号干扰避免的方式,具体来说,连接到AP的STA将自身的非Wi-Fi业务的特征(包括起止时间、周期等)告知AP,AP将该特征通过信标帧的方式广播出去,其他STA接收到该信息后,自动避免在非Wi-Fi业务的周期内传输Wi-Fi信号,进而降低了因相互干扰产生的丢包率的问题,提升了系统的稳定性。
但由于不同非Wi-Fi信号具有其典型的业务特征,比如蓝牙通话(基于蓝牙面向连接技术,即BT SCO profile),其典型特征为周期3.75ms或者7.5ms,如果第三方设备获取到该信息后,根据蓝牙业务的特征即可推断出该BSS周围有STA使用了蓝牙电话,显然,使用蓝牙电话属于用户隐私信息,直接将该信息广播出去即造成了用户隐私外泄的风险。
此外,由于支持r-TWT以及b-TWT(以下统一简称:TWT目标唤醒时间)功能的信标帧中默认携带TWT分组以及服务时间窗口信息,如果第三方设备检测到信标帧中的TWT信息后,可以在每次r-TWT服务时间窗口内占用信道,从而造成包含低时延业务的设备因为无法在对应的TWT窗口及时介入信道而一直等待信道介入,造成应用层的时延问题和功耗问题,进而可能会造成用户隐私外泄的风险。
为了能够在一定程度上防止其他网络设备或者第三方设备对信标帧中的敏感信息的获取,并且有效规避用户敏感信息外泄的风险,本公开实施例提供了一种信息处理方法、网络
设备及计算机可读存储介质,其中,发送侧网络设备可以通过使用相应的秘钥配置信息加密信标帧中的敏感信息域,得到对应的加密信标帧,然后,发送侧网络设备在网络中发送该加密信标帧,以使接收侧网络设备在解密该加密信标帧的敏感信息的过程中利用对应的秘钥配置信息对该加密信标帧的敏感信息域解密,即,在网络中保护信标帧的敏感信息传输时,可以仅需使用相应的秘钥配置信息对该信标帧的敏感信息进行加密,从而能够在一定程度上防止其他网络设备或者第三方设备对该信标帧中的敏感信息的获取,有效规避用户敏感信息外泄的风险。
基于上述分析,下面结合附图,对本公开实施例作进一步阐述。
如图5所示,图5是本公开实施例提供的一种信息处理方法的流程图,该信息处理方法可以应用于发送侧网络设备,该信息处理方法可以包括但不限于步骤S100和步骤S200。
步骤S100:使用秘钥配置信息对信标帧中的敏感信息域进行加密,得到加密信标帧。
本步骤中,可以理解的是,信标帧可以是无线局域网中定期发送的一个管理帧,信标帧包含有关该网络的信息,通常由接入点设备发送,可用于宣布该网络的存在。
在一实施例中,发送侧网络设备可以为接入点(Access Point,AP)或者多链路接入点(AP multi-link device,AP MLD),例如无线路由器等,本实施例对此并不作具体限定。
在一实施例中,敏感信息域中的信息可以包括:和用户非Wi-Fi业务紧密相关的信息,比如非Wi-Fi业务使用信道的时间和周期;和用户Wi-Fi业务相关的信息,比如网络设备的目标唤醒时间TWT的时间信息。
本实施例中,可以理解的是,信道是连接发送侧网络设备和接收侧网络设备之间的传输媒介,即信号传输的通道。此外,在TWT中,STA和AP之间建立了一张时间表,该时间表是STA和AP协定,并由TWT时间周期所组成。通常STA和AP所协商的TWT时间周期包含一个或者多个beacon周期。当STA和AP所协商的时间周期到达后,STA会醒来,并等待AP发送的触发帧,并进行一次数据交换。当本次传输完成后,返回睡眠状态。每一个STA和AP都会进行独立的协商,每一个STA都具有单独的TWT时间周期。AP也可以根据多个STA设定的TWT时间周期进行分组,一次和多个STA进行数据传输,从而提高节能效率。
在一实施例中,终端想要建立一个TWT连接,该终端可以将自己的节能调度信息告知给AP,然后AP将会分配TWT周期,并将该周期反馈给终端,接着终端会在指定的TWT周期时苏醒,并和AP进行数据帧交换。在本轮交换中,TWT周期信息在传输的过程中可能被第三方设备获取,当第三方设备获取到TWT周期信息后,可以在每次r-TWT服务时间窗口内占用信道,从而造成包含低时延业务的设备因为无法在对应的TWT窗口及时介入信道而一直等待信道介入,进而造成应用层的时延问题和功耗问题。因此,将TWT周期信息作为信标帧的敏感信息进行加密后再传输,其他网络设备或者第三方设备因未能获得该敏感信息域的秘钥信息,无法对加密的敏感信息域进行解密,从而使得包含低时延业务的网络设备能够在对应的TWT窗口及时介入信道,提高了传输稳定性和吞吐量,同时降低时延和丢包率。
在一实施例中,敏感信息域可以仅包含本设备的敏感信息域,也可以包括发送侧网络设备的第一敏感信息域和邻居网络设备的第二敏感信息域,而对于第二种情况,发送侧网络设备在利用秘钥配置信息对信标帧中的敏感信息域进行加密时,可以使用秘钥配置信息对信标帧中的第一敏感信息、第二敏感信息域进行加密,得到加密信标帧。
在一实施例中,在保护信标帧的敏感信息传输时,发送侧网络设备可以使用相应的秘钥配置信息对该信标帧的敏感信息域进行加密,然后发送该加密信标帧和该秘钥配置信息,接收侧网络设备接收到该加密信标帧和该秘钥配置信息后,能够直接利用对应的秘钥配置信息对该信标帧的敏感信息域进行解密,从而能够在一定程度上防止其他网络设备或者第三方设备对该信标帧的敏感信息的获取,进而有效规避了用户敏感信息外泄的风险。
在一实施例中,秘钥配置信息可以采用与BIP技术相同的帧编号信息、秘钥套件信息和/或秘钥信息,即发送侧网络设备利用该秘钥信息,例如信标帧完整性组临时秘钥(Beacon integrity group temporal key,BIGTK),同时生成信息完整性代码(message integrity code,MIC)和加密敏感信息。
参见图6,图6是发送侧网络设备利用同一秘钥生成信息完整性代码和加密敏感信息的示意图,其基本原理是:AP在向STA发送组临时密钥(Group Temporal Key,GTK)的同时,发送信标帧完整性组临时秘钥以及一个用于信标帧完整性保护的帧序号(BIPN,BIGTK PN)给STA,然后AP在发送的组播帧最后添加利用BIGTK计算出的管理帧的MIC值后发送给STA,STA利用相同的BIGTK验证MIC值,如果验证成功后,证明该信标帧未被篡改,如果验证失败,则证明该信标帧被篡改。
在一实施例中,当发送侧网络设备发送的信标帧中在邻居报告(neighbour report,NR)、缩减邻居报告(Reduced neighbour report,RNR)或者多基本服务集合识别符(MBSSID)中携带邻居AP的敏感信息时,可以使用第一秘钥信息对本AP的第一敏感信息域以及邻居AP的第二敏感信息域进行加密。
其中,MBSSID技术能够降低每个AP发送信标帧、探测响应帧的信道资源开销。
本实施例中,参见图7,图7示例性地给出发送侧网络设备利用同一秘钥加密位于不同IE的敏感信息元素的结构图。其中,发送侧网络设备发送的信标帧中的MBSSID字段携带邻居AP的敏感信息,在使用秘钥配置信息中的第一秘钥信息对信标帧中的敏感信息域和邻居AP的敏感信息域加密时,发送侧网络设备可以使用第一秘钥信息分别对信标帧中的敏感信息域和邻居AP的敏感信息域加密。
在一实施例中,发送侧网络设备发送的信标帧中携带秘钥套件指示信息,秘钥套件指示信息可以用于指示对敏感信息域进行加密时所选择的秘钥套件信息,以便接收侧网络设备接收到发送侧网络设备发送的信标帧后,能够利用信标帧中携带的秘钥套件指示信息指示对敏感信息域进行解密。
步骤S200:发送加密信标帧。
在一实施例中,通过采用上述步骤S100的信息处理方法,使得加密信标帧中至少包括加密后的敏感信息域、用于指示对敏感信息域进行加密时所选择的秘钥套件信息的秘钥套件指示信息,从而在网络传输的过程中,能够防止其他网络设备或者第三方设备对该加密信标帧的敏感信息的获取,规避了用户敏感信息外泄的风险。
在一实施例中,加密信标帧可以在包括但不限于互联网、企业内部网、局域网、移动通信网及其组合中发送。
在一实施例中,连接到AP的STA可以将自身的非Wi-Fi业务的特征(包括起止时间、周期等)告知AP,AP将该特征通过信标帧加密后广播出去,其他STA接收到该信息后,自动避免在非Wi-Fi业务的周期内传输Wi-Fi信号,进而降低了因相互干扰产生的丢包率的问
题,提升了系统的稳定性。
在一实施例中,在执行步骤S100之前,该信息处理方法可以包括但不限于以下步骤S110。
S110:通过管理帧与接收侧网络设备交互双方对于敏感信息保护的支持能力。
本步骤中,可以理解的是,管理帧至少包括以下一种:信标帧(Beacon frame)、探测请求帧(probe request)、探测响应帧(probe response)、多链路探测请求帧(ML probe request)、多链路探测响应帧(ML probe response)、关联请求(association request)帧、重关联请求(reassociation request)帧、关联响应(association response)帧、重关联响应(reassociation response)帧、认证(authentication)帧和行动帧(action frame)。
在一实施例中,敏感信息保护的支持能力集可以携带于RSNE字段中,其中,RSNE可以用于指示强健安全网络(robust security network,RSN)中携带的和秘钥套件以及RSN能力相关的元素,有利于增强WLAN的数据加密和认证性能。
在一实施例中,管理帧可以包括强健安全网络元素字段,如图8所示,图8示例性地给出了RSNE字段扩展的结构,在RSNE的RSN Capabilities能力集字段中,可以存在多个Reserved比特指示位,如图8所示的B10标志位,B11标志位,B12标志位,B15标志位,这些标志位都可以用来作为敏感信息保护能力指示标志位,用于指示是否支持信标帧中的敏感信息保护。在指示支持信标帧中的敏感信息保护时,可以在预留的标志位中任意选择一个,然后将该标志位的比特置1即可。此外,如果指示不支持信标帧中的敏感信息保护,可以将该标志位的比特置0。例如图8中的B10标志位,把原来的Reserved比特指示位设置为敏感信息保护能力指示标志位(Sensitive Info Protection),当该敏感信息保护能力指示标志位置1,说明能够支持信标帧中的敏感信息保护;当该敏感信息保护能力指示标志位置0,说明不支持信标帧中的敏感信息保护。
如图9所示,图9是本公开另一个实施例提供的信息处理方法流程图,在步骤S100中的加密信标帧之前,该信息处理方法可以包括但不限于步骤S300至步骤S400。
S300:生成秘钥配置信息。
在一实施例中,发送侧网络设备可以在本地生成用于加密、解密信标帧中敏感信息的秘钥配置信息。其中,秘钥配置信息包括秘钥信息、信标帧编号信息和秘钥套件信息。如图10所示,图10示例性地给出了秘钥配置信息的结构,在该结构中,各主要字段的解释如下:
Key ID:用于表示秘钥套件指示信息;
PN:用于表示帧编号;
Key:用于表示秘钥信息。
其中,秘钥信息可以用于生成信息完整性代码以及用于对信标帧中的敏感信息域进行加密。
在一实施例中,秘钥套件信息可以至少包括以下一种:AES-128-CMAC、AES-128-GMAC、AES-256-CMAC、AES-256-GMAC和SM4。
S400:通过信息帧将秘钥配置信息发送给接收侧网络设备。
本步骤中,信息帧的类型可以包括以下任意一种:认证帧;EAPOL帧;动作帧。另外,接收侧网络设备可以为接入点(Access Point,AP)、多链路接入点(AP multi-link device,AP MLD)、终端(Station,STA)和多链路终端(non-AP MLD)。
在一实施例中,发送侧网络设备可以通过信息帧与接收侧网络设备进行秘钥配置信息的
交互,以使接收侧网络设备获取到对应的秘钥配置信息,并使用该秘钥配置信息中的秘钥信息对接收到的信标帧的敏感信息域进行解密,得到解密信息。
在一实施例中,发送侧网络设备的信息处理方法还可以包括:不在敏感信息域承载的敏感信息所对应的业务接入信道的时间窗口内发起竞争以及使用信道资源。
此外,如图11所示,图11是本公开实施例提供的另一种信息处理方法的流程图,该信息处理方法应用于接收侧网络设备,该信息处理方法可以包括但不限于步骤A100至步骤A300。
步骤A100:接收发送侧网络设备发送的第一信标帧,其中,第一信标帧包括使用秘钥配置信息进行加密后的敏感信息域。
在一实施例中,接收侧网络设备接收到发送侧网络设备发送的第一信标帧可以携带秘钥套件指示信息,其中,秘钥套件指示信息用于指示对第一信标帧的敏感信息域进行解密时所选择的秘钥套件信息。
值得注意的是,本实施例中对第一信标帧、敏感信息域的相关介绍及解释,与前述步骤S100中所示的实施例中对于信标帧、敏感信息的相关介绍及解释相一致,针对本实施例中对第一信标帧、敏感信息域的相关介绍及解释,可参照前述步骤S100中所示的实施例中对于信标帧、敏感信息的相关介绍及解释,此处不再做赘述。
步骤A200:使用秘钥配置信息对第一信标帧中的敏感信息域进行解密,得到解密敏感信息。
本步骤中,需要说明的是,秘钥配置信息可以包括秘钥信息、信标帧的编号信息和秘钥套件信息,其中,秘钥信息可以用于验证信息完整性代码以及用于对第一信标帧中的敏感信息域进行解密。
在一实施例中,秘钥配置信息可以包括用于加密第一信标帧中的敏感信息域和生成第一信标帧中的信息完整性代码的秘钥信息、第一信标帧的编号信息以及秘钥套件信息。
在一实施例中,当接收侧网络设备接收到发送侧网络设备发送的加密信标帧后,接收侧网络设备可以利用先前接收到的发送侧网络设备发送的秘钥配置信息的秘钥信息,对该加密信标帧中的敏感信息域进行解密,并对其MIC信息进行验证。如果验证成功,证明该信标帧未被篡改;如果验证失败,则证明该信标帧被篡改。
在一实施例中,当第一信标帧中的敏感信息域包括发送侧网络设备的第一敏感信息域,以及发送侧网络设备的邻居网络设备的第二敏感信息域时,接收侧网络设备可以利用所接收到的秘钥配置信息的秘钥信息对第一敏感信息域和第二敏感信息域进行解密,得到对应的解密敏感信息,以便后续可以根据解密敏感信息执行相应的操作。
步骤A300:根据解密敏感信息执行相应的信息处理。
在一实施例中,当接收侧网络设备为终端或者多链路终端时,接收侧网络设备执行相应的信息处理可以包括:不在解密敏感信息对应的业务接入信道的时间窗口内发起竞争以及使用信道资源。
本实施例中,可以理解的是,网络设备通信可以是随机信道接入,即网络设备不占据固定的资源,为了安排不同网络设备之间对资源的使用,通常需要通过“竞争”的过程来完成。解密敏感信息对应的业务接入信道的时间窗口指的是,在一段时间内,信道资源是被解密敏感信息对应的业务占用的,接收侧网络设备能够根据该解密敏感信息的指示,在该解密敏感
信息对应的业务接入信道的时间窗口内,不去发起竞争以及使用信道资源,以便对应的业务能够使用信道资源。
参见图12,图12示例性地给出了接收侧网络设备为AP或者AP MLD时的信息处理流程图。在一实施例中,当接收侧网络设备为接入点或者多链路接入点时,相应的信息处理可以包括但不限于步骤A310至步骤A320。
A310:使用接收侧网络设备本地生成的秘钥配置信息对解密敏感信息进行加密,得到加密信息。
在一实施例中,由接收侧网络设备本地生成的秘钥配置信息可以包括用于加密第二信标帧中的敏感信息域和生成第二信标帧中的信息完整性代码的第二秘钥信息、第二信标帧的编号信息以及秘钥套件信息。
在一实施例中,当接收侧网络设备利用接收到的秘钥配置信息中的第一秘钥信息对第一信标帧中的敏感信息域进行解密,得到解密信息后,可以再次使用该接收侧网络设备本地生成的第二秘钥信息对所得到的解密信息进行加密,接着将再次加密后的解密信息复制到第二信标帧中的存放发送侧网络设备敏感信息字段中,然后,接收侧网络设备可以将该第二信标帧在网络中发送。
A320:根据加密信息生成第二信标帧,第二信标帧包括用于存放加密信息的敏感信息字段。
在一实施例中,第二信标帧中存放发送侧网络设备敏感信息的字段,其中,用于存放的字段可以包括:NR字段、RNR字段或者MBSSID字段,NR字段、RNR字段或者MBSSID字段可以用于表示邻居AP包含了敏感信息,此处的邻居AP为发送侧网络设备。
在一实施例中,参见图13,图13示例性地给出接收侧网络设备利用第二秘钥加密位于不同IE的敏感信息元素的结构图。其中,第二信标帧中的NR字段用于存放发送侧网络设备敏感信息,接收侧网络设备在使用秘钥配置信息中的秘钥信息对第二信标帧中的敏感信息域和发送侧网络设备敏感信息域加密时,可以使用第二秘钥信息分别对第二信标帧中的敏感信息域和发送侧网络设备敏感信息域加密。
在一实施例中,当接收侧网络设备为接入点或者多链路接入点时,相应的信息处理还可以包括:不在解密敏感信息对应的业务接入信道的时间窗口内发起竞争以及使用信道资源。
本实施例中,接收侧网络设备接收到的信标帧可以支持r-TWT以及b-TWT功能,此时,信标帧中默认携带TWT分组以及服务时间窗口信息,接收侧网络设备能够根据该解密敏感信息的指示,在该解密敏感信息对应的业务接入信道的时间窗口内,如果不是对应的r-TWT以及b-TWT组成员,则不去发起竞争以及使用信道资源,以便对应的业务能够在对应的TWT窗口及时介入信道,从而可以降低传输时延、提高吞吐量和降低丢包率。
在一实施例中,当接收侧网络设备为接入点或者多链路接入点时,相应的信息处理可以包括但不限于以下两种:接收侧网络设备不在解密敏感信息对应的业务接入信道的时间窗口内发起竞争以及使用信道资源;接收侧网络设备使用本地生成的秘钥配置信息对解密敏感信息进行加密,得到加密信息,紧接着根据加密信息生成第二信标帧,其中,第二信标帧包括用于存放加密信息的敏感信息字段,然后发送第二信标帧。
值得注意的是,本实施例中,相应的信息处理的具体实施方式和技术效果的相关介绍及解释,与上述步骤A300、A310和A320中任意一项实施例所描述的信息处理方法的具体实
施方式和技术效果的相关介绍及解释相一致,针对本实施例中相应的信息处理的具体实施方式和技术效果的相关介绍及解释,可参照上述步骤A300、A310和A320中任意一项实施例所描述的信息处理方法的具体实施方式和技术效果的相关介绍及解释,此处不再赘述。
A330:发送第二信标帧。
在一实施例中,通过采用包括有上述步骤A310和步骤A320的信息处理方法,可以使得第二信标帧中至少包括加密后的第二信标帧中的敏感信息域和加密后的发送侧网络设备的敏感信息域、用于指示对敏感信息域进行加密时所选择的秘钥套件信息的秘钥套件指示信息。
在一实施例中,接收侧网络设备可以和第三接收侧网络设备交互双方对于敏感信息保护的支持能力,并且第三接收侧网络设备也可以接收并保存接收侧网络设备通过第二信息帧发送的第二秘钥配置信息,从而使得当第三接收侧网络设备接受到加密的第二信标帧时,能够根据第二秘钥配置信息中的秘钥信息对第二信标帧的加密敏感信息域进行解密和验证,得到解密的敏感信息后再根据解密信息作出后续的信息处理。如此,不仅能够防止其他网络设备或者第三方设备获取该加密的第二信标帧的敏感信息,还有效规避了用户敏感信息外泄的风险。
在一实施例中,在执行步骤A100之前还可以包括步骤:通过管理帧与发送侧网络设备交互双方对于敏感信息保护的支持能力。
在一实施例中,接收侧网络设备通过将管理帧的强健安全网络元素字段中的标志位的比特置1,与发送侧网络设备交互敏感信息保护的支持能力。
值得注意的是,本实施例中涉及的信息处理的具体实施方式和技术效果的相关介绍及解释,与上述步骤S110中任意一项实施例所描述的信息处理方法的具体实施方式和技术效果的相关介绍及解释相一致,针对本实施例中涉及的具体实施方式和技术效果的相关介绍及解释,可参照上述步骤S110中任意一项实施例所描述的信息处理方法的具体实施方式和技术效果的相关介绍及解释,此处不再赘述。
在一实施例中,在执行步骤A100之前还可以包括步骤:接收发送侧网络设备通过信息帧发送的秘钥配置信息。
其中,秘钥配置信息可以包括:用于加密该信标帧中的敏感信息域和生成该信标帧中的信息完整性代码的秘钥信息、该信标帧的编号信息以及秘钥套件信息。
在一实施例中,秘钥套件信息可以至少包括以下一种:AES-128-CMAC、AES-128-GMAC、AES-256-CMAC、AES-256-GMAC和SM4。此外,信息帧的类型可以包括以下任意一种:认证帧,EAPOL帧,动作帧。
在一实施例中,发送侧网络设备可以随时在网络中通过信息帧发送更新后的秘钥配置信息,当接收侧网络设备接收到该信息帧后,可以获得更新的秘钥配置信息,然后将更新的秘钥配置信息替换原来保存的秘钥配置信息。
本公开实施例中,对于连接到该AP的STA设备来说,STA设备直接使用对应的秘钥信息解密保护的敏感信息域,即可获得该敏感信息,并且能够防止在其工作时间周期内使用相同的信道,而对于其他STA或者第三方设备来说,因为没有获得相应的秘钥,也就无法获取和用户业务有关的敏感信息,从而有效规避了用户敏感信息外泄的风险。
针对上述实施例所提供的信息处理方法,下面以具体的示例进行详细的描述:
示例一:
参见图14,图14是发送侧网络设备与接收侧网络设备利用信标帧交互加密敏感信息的过程示意图。其中,图14所示的发送侧网络设备可以是接入点或者多链路接入点,接收侧网络设备可以是终端或者多链路终端,该交互过程具体示例如下:
步骤1:发送侧网络设备通过管理帧与接收侧网络设备交互敏感信息保护支持能力。
步骤2:发送侧网络设备本地生成用于加密、解密信标帧中敏感信息的秘钥配置信息1。
步骤3:发送侧网络设备与接收侧网络设备在进行帧的交互过程中,发送侧网络设备向接收侧网络设备发送一个信息帧,将上述秘钥配置信息1发送给接收侧网络设备。
步骤4:接收侧网络设备将上述秘钥配置信息1本地保存。
步骤5:发送侧网络设备发送已使用上述秘钥配置信息1加密其敏感信息域的信标帧。
步骤6:接收侧网络设备接收到上述信标帧后,使用上述秘钥配置信息1解密其敏感信息。
步骤7:接收侧网络设备根据解密的敏感信息指示,做出相应的信息处理。
需要说明的是,上述交互过程中的发送侧网络设备可以为AP或者AP MLD,接收侧网络设备可以是AP、AP MLD、STA、non-AP MLD中的任意一个。
在一实施例中,当步骤(5)中的信标帧的敏感信息域包括本发送侧网络设备的第一敏感信息和邻居AP的第二敏感信息时,发送侧网络设备需要使用同一秘钥信息对第一敏感信息、第二敏感信息进行加密,而当接收侧网络设备为AP或者AP MLD时,接收侧网络设备在根据秘钥配置信息对敏感信息域进行解密之后,需要再次利用其本地生成的第二秘钥信息对该解密信息域进行加密。
值得注意的是,由于本示例一中所涉及的具体实施方式和技术效果的相关介绍及解释,包括有上述任意一项实施例所描述的信息处理方法,因此,有关本示例一中所涉及的具体实施方式和技术效果的相关介绍及解释,可参照上述任意一项实施例所描述的信息处理方法,在此不做赘述。
示例二:
参见图15,图15是发送侧网络设备与接收侧网络设备利用信标帧交互加密敏感信息的另一过程示意图。其中,图15所示的发送侧网络设备可以是接入点或者多链路接入点,接收侧网络设备可以是接入点或者多链路接入点。此时,图15所示的接收侧网络设备可以重复图14中所示的发送侧网络设备的操作,对应的,图15所示的发送侧网络设备重复图14中所示的接收侧网络设备的操作。因此,在图14所示的交互过程的基础上,图15所示的交互过程具体还包括如下步骤:
步骤A:接收侧网络设备通过管理帧与发送侧网络设备交互敏感信息保护支持能力。
步骤B:接收侧网络设备本地生成用于加密、解密信标帧中敏感信息的秘钥配置信息2。
步骤C:接收侧网络设备与发送侧网络设备在进行帧的交互过程中,接收侧网络设备向发送侧网络设备发送一个信息帧,将上述秘钥配置信息2发送给发送侧网络设备。
步骤D:发送侧网络设备将上述秘钥配置信息2本地保存。
步骤E:接收侧网络设备发送已使用上述秘钥配置信息2加密其敏感信息域的信标帧。
步骤F:发送侧网络设备接收到上述信标帧后,使用上述秘钥配置信息2解密其敏感信息。
步骤G:发送侧网络设备根据解密的敏感信息指示,做出相应的信息处理。
值得注意的是,由于本示例二中所涉及的具体实施方式和技术效果的相关介绍及解释,包括有上述任意一项实施例所描述的信息处理方法,因此,有关本示例二中所涉及的具体实施方式和技术效果的相关介绍及解释,可参照上述任意一项实施例所描述的信息处理方法,在此不做赘述。
本公开中的发送侧网络设备和接收侧网络设备分别包括有存储器和处理器,其中,存储器和处理器可以通过总线或者其他方式连接。
存储器作为一种非暂态计算机可读存储介质,可用于存储非暂态软件程序以及非暂态性计算机可执行程序。此外,存储器可以包括高速随机存取存储器,还可以包括非暂态存储器,例如至少一个磁盘存储器件、闪存器件、或其他非暂态固态存储器件。在一些实施方式中,存储器可选包括相对于处理器远程设置的存储器,这些远程存储器可以通过网络连接至该处理器。上述网络的实例包括但不限于互联网、企业内部网、局域网、移动通信网及其组合。
本公开实施例描述的发送侧网络设备和接收侧网络设备利用信标帧交互加密的敏感信息的应用场景是为了更加清楚的说明本公开实施例的技术方案,并不构成对于本公开实施例提供的技术方案的限定,本领域技术人员可知,随着新应用场景的出现,本公开实施例提供的技术方案对于类似的技术问题,同样适用。
基于上述信息处理方法,本公开的一个实施例提供了一种网络设备,该网络设备包括:存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序。
处理器和存储器可以通过总线或者其他方式连接。
需要说明的是,本实施例中的网络设备,可以应用于本公开实施例中的发送侧网络设备、接收侧网络设备以及第三接收侧网络设备,这些实施例均属于相同的发明构思,因此这些实施例具有相同的实现原理以及技术效果,此处不再详述。
实现上述实施例的信息处理方法所需的非暂态软件程序以及指令存储在存储器中,当被处理器执行时,执行上述实施例的信息处理方法,例如,执行以上描述的图5中的方法步骤S100至S200、图9中的方法步骤S300至S400、图11中的方法步骤A100至A300、图12中的方法步骤A310至A330。
以上所描述的装置实施例仅仅是示意性的,其中作为分离部件说明的单元可以是或者也可以不是物理上分开的,即可以位于一个地方,或者也可以分布到多个网络单元上。可以根据实际的需要选择其中的部分或者全部模块来实现本实施例方案的目的。
此外,基于上述信息处理方法,本公开的一个实施例还提供了一种计算机可读存储介质,该计算机可读存储介质存储有计算机可执行指令,该计算机可执行指令被一个处理器或控制器执行,例如,被上述网络设备实施例中的一个处理器执行,可使得上述处理器执行上述实施例中的信息处理方法,例如,执行以上描述的图5中的方法步骤S100至S200、图9中的方法步骤S300至S400、图11中的方法步骤A100至A300、图12中的方法步骤A310至A330。
本领域普通技术人员可以理解,上文中所公开方法中的全部或某些步骤、系统可以被实施为软件、固件、硬件及其适当的组合。某些物理组件或所有物理组件可以被实施为由处理器,如中央处理器、数字信号处理器或微处理器执行的软件,或者被实施为硬件,或者被实施为集成电路,如专用集成电路。这样的软件可以分布在计算机可读介质上,计算机可读介质可以包括计算机存储介质(或非暂时性介质)和通信介质(或暂时性介质)。如本领域普通技术人员公知的,术语计算机存储介质包括在用于存储信息(诸如计算机可读指令、数据
结构、程序模块或其他数据)的任何方法或技术中实施的易失性和非易失性、可移除和不可移除介质。计算机存储介质包括但不限于RAM、ROM、EEPROM、闪存或其他存储器技术、CD-ROM、数字多功能盘(DVD)或其他光盘存储、磁盒、磁带、磁盘存储或其他磁存储装置、或者可以用于存储期望的信息并且可以被计算机访问的任何其他的介质。此外,本领域普通技术人员公知的是,通信介质通常包含计算机可读指令、数据结构、程序模块或者诸如载波或其他传输机制之类的调制数据信号中的其他数据,并且可包括任何信息递送介质。
以上是对本公开的较佳实施进行了具体说明,但本公开并不局限于上述实施方式,熟悉本领域的技术人员在不违背本公开精神的前提下还可作出种种的等同变形或替换,这些等同的变形或替换均包含在本公开权利要求所限定的范围内。
Claims (25)
- 一种信息处理方法,应用于发送侧网络设备,所述方法包括:使用秘钥配置信息对信标帧中的敏感信息域进行加密,得到加密信标帧;发送所述加密信标帧。
- 根据权利要求1所述的方法,其中,所述使用秘钥配置信息对信标帧中的敏感信息域进行加密之前,所述方法还包括:通过管理帧与接收侧网络设备交互双方对于敏感信息保护的支持能力。
- 根据权利要求2所述的方法,其中,所述管理帧包括强健安全网络元素字段,所述强健安全网络元素字段包括敏感信息保护能力指示标志位,所述敏感信息保护能力指示标志位用于指示是否支持对所述信标帧的所述敏感信息域进行保护。
- 根据权利要求3所述的方法,其中,所述管理帧包括如下之一:信标帧;探测请求帧;探测响应帧;多链路探测请求帧;多链路探测响应帧;关联请求帧;重关联请求帧;关联响应帧;重关联响应帧;认证帧;行动帧。
- 根据权利要求1所述的方法,其中,所述使用秘钥配置信息对信标帧中的敏感信息域进行加密之前,所述方法还包括:生成所述秘钥配置信息;通过信息帧将所述秘钥配置信息发送给接收侧网络设备。
- 根据权利要求5所述的方法,其中,所述秘钥配置信息包括秘钥信息、信标帧编号信息和秘钥套件信息。
- 根据权利要求6所述的方法,其中,所述秘钥信息用于生成信息完整性代码以及用于对所述信标帧中的所述敏感信息域进行加密。
- 根据权利要求6所述的方法,其中,所述信标帧包括秘钥套件指示信息,所述秘钥套件指示信息用于指示对所述敏感信息域进行加密时所选择的所述秘钥套件信息。
- 根据权利要求5所述的方法,其中,所述信息帧包括如下之一:认证帧;EAPOL帧;动作帧。
- 根据权利要求1所述的方法,其中,所述敏感信息域包括所述发送侧网络设备的第一敏感信息域和邻居网络设备的第二敏感信息域;使用秘钥配置信息对信标帧中的敏感信息域进行加密,得到加密信标帧,包括:使用所述秘钥配置信息对所述信标帧中的所述第一敏感信息域进行加密,并且使用所述秘钥配置信息对所述信标帧中的所述第二敏感信息域进行加密,得到加密信标帧。
- 根据权利要求1所述的方法,所述方法还包括:不在所述敏感信息域承载的敏感信息所对应的业务接入信道的时间窗口内发起竞争以及使用信道资源。
- 一种信息处理方法,应用于接收侧网络设备,所述方法包括:接收发送侧网络设备发送的第一信标帧,其中,所述第一信标帧包括使用秘钥配置信息进行加密后的敏感信息域;使用所述秘钥配置信息对所述第一信标帧中的所述敏感信息域进行解密,得到解密敏感信息;根据所述解密敏感信息执行相应的信息处理。
- 根据权利要求12所述的方法,其中,所述接收发送侧网络设备发送的第一信标帧之前,所述方法还包括:通过管理帧与所述发送侧网络设备交互双方对于敏感信息保护的支持能力。
- 根据权利要求13所述的方法,其中,所述管理帧包括强健安全网络元素字段,所述强健安全网络元素字段包括敏感信息保护能力指示标志位,所述敏感信息保护能力指示标志位用于指示是否支持对所述第一信标帧的所述敏感信息域进行保护。
- 根据权利要求14所述的方法,其中,所述管理帧包括如下之一:信标帧;探测请求帧;探测响应帧;多链路探测请求帧;多链路探测响应帧;关联请求帧;重关联请求帧;关联响应帧;重关联响应帧;认证帧;行动帧。
- 根据权利要求12所述的方法,其中,所述接收发送侧网络设备发送的第一信标帧之前,所述方法还包括:接收所述发送侧网络设备通过信息帧发送的所述秘钥配置信息。
- 根据权利要求16所述的方法,其中,所述秘钥配置信息包括秘钥信息、信标帧编号信息和秘钥套件信息。
- 根据权利要求17所述的方法,其中,所述秘钥信息用于验证信息完整性代码以及用于对所述第一信标帧中的所述敏感信息域进行解密。
- 根据权利要求17所述的方法,其中,所述第一信标帧包括秘钥套件指示信息,所述秘钥套件指示信息用于指示对所述敏感信息域进行解密时所选择的所述秘钥套件信息。
- 根据权利要求16所述的方法,其中,所述信息帧包括如下之一:认证帧;EAPOL帧;动作帧。
- 根据权利要求12所述的方法,其中,所述敏感信息域包括所述发送侧网络设备的第一敏感信息域和邻居网络设备的第二敏感信息域;所述使用所述秘钥配置信息对所述第一信标帧中的所述敏感信息域进行解密,得到解密敏感信息,包括:使用所述秘钥配置信息对所述第一信标帧中的所述第一敏感信息域进行解密,并且使用所述秘钥配置信息对所述第一信标帧中的所述第二敏感信息域进行解密,得到解密敏感信息。
- 根据权利要求12所述的方法,其中,所述接收侧网络设备为终端设备,所述根据所述解密敏感信息执行相应的信息处理,包括:不在所述解密敏感信息对应的业务接入信道的时间窗口内发起竞争以及使用信道资源。
- 根据权利要求12所述的方法,其中,所述接收侧网络设备为接入点设备,所述根据所述解密敏感信息执行相应的信息处理,包括以下至少之一:不在所述解密敏感信息对应的业务接入信道的时间窗口内发起竞争以及使用信道资源;使用本地生成的秘钥配置信息对所述解密敏感信息进行加密,得到加密信息;根据所述加密信息生成第二信标帧,所述第二信标帧包括用于存放所述加密信息的敏感信息字段;发送所述第二信标帧。
- 一种网络设备,包括:存储器、处理器及存储在存储器上并可在处理器上运行的计算机程序,所述处理器执行所述计算机程序时实现如权利要求1至23任意一项所述的信息处理方法。
- 一种计算机可读存储介质,存储有计算机可执行指令,所述计算机可执行指令用于执行如权利要求1至23任意一项所述的信息处理方法。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202311535924.7A CN120017293A (zh) | 2023-11-16 | 2023-11-16 | 信息处理方法、网络设备及计算机可读存储介质 |
| CN202311535924.7 | 2023-11-16 |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2025102707A1 true WO2025102707A1 (zh) | 2025-05-22 |
Family
ID=95672161
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/098824 Pending WO2025102707A1 (zh) | 2023-11-16 | 2024-06-13 | 信息处理方法、网络设备及计算机可读存储介质 |
Country Status (2)
| Country | Link |
|---|---|
| CN (1) | CN120017293A (zh) |
| WO (1) | WO2025102707A1 (zh) |
Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101986726A (zh) * | 2010-10-25 | 2011-03-16 | 西安西电捷通无线网络通信股份有限公司 | 一种基于wapi的管理帧保护方法 |
| CN113613245A (zh) * | 2021-08-19 | 2021-11-05 | 支付宝(杭州)信息技术有限公司 | 管理通信信道的方法和装置 |
| CN113747430A (zh) * | 2021-08-31 | 2021-12-03 | 新华三技术有限公司成都分公司 | 一种接入网络的方法、终端设备和ap |
| US20230171594A1 (en) * | 2020-04-16 | 2023-06-01 | Beijing Xiaomi Mobile Software Co., Ltd. | Management frame transmission method, apparatus and storage medium |
-
2023
- 2023-11-16 CN CN202311535924.7A patent/CN120017293A/zh active Pending
-
2024
- 2024-06-13 WO PCT/CN2024/098824 patent/WO2025102707A1/zh active Pending
Patent Citations (4)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN101986726A (zh) * | 2010-10-25 | 2011-03-16 | 西安西电捷通无线网络通信股份有限公司 | 一种基于wapi的管理帧保护方法 |
| US20230171594A1 (en) * | 2020-04-16 | 2023-06-01 | Beijing Xiaomi Mobile Software Co., Ltd. | Management frame transmission method, apparatus and storage medium |
| CN113613245A (zh) * | 2021-08-19 | 2021-11-05 | 支付宝(杭州)信息技术有限公司 | 管理通信信道的方法和装置 |
| CN113747430A (zh) * | 2021-08-31 | 2021-12-03 | 新华三技术有限公司成都分公司 | 一种接入网络的方法、终端设备和ap |
Also Published As
| Publication number | Publication date |
|---|---|
| CN120017293A (zh) | 2025-05-16 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| US11647450B2 (en) | Multi-link beaconing and discovery | |
| US9894607B2 (en) | Method and apparatus for accessing channel in WLAN system | |
| US9743353B2 (en) | Method and device for accessing channel in wireless LAN system | |
| KR101632222B1 (ko) | 무선랜 시스템에서 고속 링크 동기화 방법 및 장치 | |
| US9730159B2 (en) | Method and apparatus for accessing channel in WLAN system | |
| KR101781876B1 (ko) | 무선랜 시스템에서 스테이션의 신호 수신 방법 및 장치 | |
| US8924732B2 (en) | Method and apparatus of cipher communication for management frame using quality of service mechanism in wireless local area network system | |
| US9648613B2 (en) | Method and apparatus for gaining access in wireless LAN system | |
| KR102004833B1 (ko) | 무선랜 시스템에서 채널 액세스 방법 및 장치 | |
| US20210385778A1 (en) | Method for onboarding in multiple access point network and access point using same | |
| CN106576292B (zh) | 用于在无线lan系统中扫描接入点的方法和设备 | |
| JP2016165154A (ja) | 無線lanシステムにおけるスキャニング方法とそれをサポートする装置 | |
| KR101641975B1 (ko) | 무선 통신시스템에서 스테이션의 하향링크 신호 수신 방법 | |
| KR20150105338A (ko) | 무선랜 시스템에서 채널 액세스 방법 및 장치 | |
| US20160021609A1 (en) | Method for setting up high-speed link in wlan system and apparatus for same | |
| KR20150089003A (ko) | 무선랜 시스템에서 신호 전송 방법 및 장치 | |
| KR102842558B1 (ko) | 프라이버시 향상 비콘 프레임들 | |
| KR20160007510A (ko) | 무선랜 시스템에서 액세스 수행 방법 및 장치 | |
| US20150078358A1 (en) | Method and apparatus for setting up high-speed link in wlan system | |
| US10206110B1 (en) | Techniques for network security | |
| WO2025102707A1 (zh) | 信息处理方法、网络设备及计算机可读存储介质 | |
| KR20260046472A (ko) | 통신 방법 및 장치 | |
| US20250113184A1 (en) | Mobility domain access point wide pairwise transient key | |
| US12520156B2 (en) | Neighbor awareness networking pairing termination | |
| KR20260057445A (ko) | 통신 방법 및 장치 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24890076 Country of ref document: EP Kind code of ref document: A1 |