The content of the invention
The technical scheme that the present invention is provided is as follows:
The present invention provides a kind of WDS authentication methods, comprises the following steps:The association request message that S20, basis have been sent,
Check;S30, when there is institute in the association request message
When stating WDS authentication informations, then the WDS authentication informations are obtained from the association request message;The WDS that S40, basis get
Authentication information, is authenticated to the WDS authentication informations.
It is further preferred that step S20 is further included:S21, check and whether there is in the association request message
WDS certifications mark in the WDS authentication informations;
Step S30 is further included:S31, in it there is the WDS authentication informations in the association request message
When WDS certifications are identified, then the user account and account for obtaining in the WDS authentication informations from the association request message is close
Code;
Step S40 is further included:User account and account number cipher that S41, basis get, to user's account
Number and account number cipher be authenticated.
It is further preferred that step S40 is further comprised:S42, when the user account and account number cipher certification
When successful, then, after secondary access device associates main access device, the secondary access device may have access to outer net;S43, when user's account
Number and during account number cipher authentification failure, then after the secondary access device associates main access device, the secondary access device can not be visited
Ask outer net.
It is further preferred that also including before step S20:S01, the addition in the association request message in advance
The WDS authentication informations, the WDS authentication informations include WDS certification marks, user account and account number cipher.
It is further preferred that further comprising the steps of:S11, send the association request message when, to the association please
Message and/or WDS authentication informations is asked to be encrypted transmission.
The present invention also provides a kind of WDS Verification Systems, including secondary access device and main access device:The main access device
Including message receiver module and check module, the message receiver module is used to receiving message on the secondary access device and sends mould
The association request message that block has been sent, it is described to check module for checking in the association request message with the presence or absence of the WDS
Authentication information;The main access device also includes acquisition module, there is the WDS certifications for working as in the association request message
During information, then the WDS authentication informations are obtained from the association request message;Authentication module, for according to the WDS for getting
Authentication information, is authenticated to the WDS authentication informations.
It is further preferred that described check module, recognize with the presence or absence of the WDS for checking in the association request message
WDS certifications mark in card information;, there is the WDS certifications letter in the association request message for working as in the acquisition module
When WDS certifications in breath are identified, then the user account and account in the WDS authentication informations is obtained from the association request message
Number password;The authentication module, it is for according to the user account and account number cipher for getting, close to the user account and account
Code is authenticated.
It is further preferred that also including:Relating module, for when the user account and account number cipher certification success when,
After then secondary access device associates main access device, the secondary access device may have access to outer net;The relating module, is additionally operable to work as institute
When stating user account and account number cipher authentification failure, then after the secondary access device associates main access device, the secondary access sets
It is standby to access outer net.
It is further preferred that the secondary access device also includes:Information add module, in advance in the association request
The WDS authentication informations, the WDS authentication informations is added to include WDS certification marks, user account and account number cipher in message.
It is further preferred that also including:Encrypted transmission module, for when the association request message is sent, to described
Association request message and/or WDS authentication informations are encrypted transmission.
Compared with prior art, the present invention provides a kind of WDS authentication methods and system, has the advantages that:
1) WDS authentication informations are added in the association request message that secondary access device sends in the present invention, then to WDS certifications
Information is authenticated, so as to realize that secondary access device accesses WDS certifications.Secondary access device not only can realize that associating main access sets
It is standby, WDS certifications can also be realized.
2) check in the present invention in association request message and identify with the presence or absence of WDS certifications, when there is WDS certifications mark,
User account and account number cipher are obtained, and is authenticated;Otherwise, only it is associated, is not authenticated;So as to not affect normal pass
Linkage is made.
3) transmission is encrypted to association request message and/or WDS authentication informations in the present invention, it can be ensured that user account
With the security of account number cipher;So as to realize safety certification.
Specific embodiment
In order to be illustrated more clearly that the embodiment of the present invention or technical scheme of the prior art, below by control description of the drawings
The specific embodiment of the present invention.It should be evident that drawings in the following description are only some embodiments of the present invention, for
For those of ordinary skill in the art, on the premise of not paying creative work, can be obtaining other according to these accompanying drawings
Accompanying drawing, and obtain other embodiments.
To make simplified form, part related to the present invention in each figure, is only schematically show, they do not represent
Its practical structures as product.In addition, so that simplified form is readily appreciated, with identical structure or function in some figures
Part, only symbolically depicts one of those, or has only marked one of those.Herein, " one " is not only represented
" only this ", it is also possible to represent the situation of " more than one ".
As shown in figure 1, according to one embodiment of present invention, a kind of WDS authentication methods, comprise the following steps:Preferably,
Also include step S01, in the association request message (Association Request messages) add the WDS to recognize in advance
Card information (Vendor Specific IE), the WDS authentication informations (Vendor Specific IE) are including WDS certification marks
Knowledge, user account and account number cipher.
S10, transmission association request message (Association Request messages), the association request message
(Association Request messages) includes the association request report containing WDS authentication informations (Vendor Specific IE)
Literary (Association Request messages) and the association request of WDS authentication informations (Vendor Specific IE) is not contained
Message (Association Request messages);
The association request message (Association Request messages) that S20, basis are received, checks that the association please
Whether there is the WDS authentication informations (Vendor Specific IE) in seeking message (Association Request messages);
S30, when there is the WDS authentication informations in the association request message (Association Request messages)
When (Vendor Specific IE), then institute is obtained from the association request message (Association Request messages) is middle
State WDS authentication informations (Vendor Specific IE);
S32, when there is no WDS certifications letter in the association request message (Association Request messages)
During breath (Vendor Specific IE), then secondary access device (secondary access device can be secondary router) associates main access device
After (active router), the secondary access device (secondary router) can not access outer net.
The WDS authentication informations (Vendor Specific IE) that S40, basis get, to the WDS authentication informations
(Vendor Specific IE) is authenticated.
Specifically, WDS certifications be based on User Defined (Vendor Specific), namely user oneself association please
WDS authentication informations defined in message are sought, when secondary router connects active router, secondary router sends association to active router please
Message is sought, when active router receives association request message, is checked;
When there is WDS authentication informations, WDS authentication informations are obtained from association request message, and is authenticated.
As shown in Fig. 2 according to still a further embodiment, a kind of WDS authentication methods, comprise the following steps:It is preferred that
, the WDS is also added including step S01, in advance in the association request message (Association Request messages)
Authentication information (Vendor Specific IE), the WDS authentication informations (Vendor Specific IE) are including WDS certification marks
Knowledge, user account and account number cipher.
S10, transmission association request message (Association Request messages), the association request message
(Association Request messages) includes the association request report containing WDS authentication informations (Vendor Specific IE)
Literary (Association Request messages) and the association request of WDS authentication informations (Vendor Specific IE) is not contained
Message (Association Request messages);
S11, send association request message (the Association Request messages) when, using 802.11w encrypt
Mode or other cipher modes are to the association request message (Association Request messages) and/or WDS authentication informations
(Vendor Specific IE) is encrypted transmission.
The association request message (Association Request messages) that S21, basis are received, checks that the association please
Whether there is the WDS authentication informations (Vendor Specific IE) in seeking message (Association Request messages)
In WDS certifications mark;
S31, when there is the WDS authentication informations in the association request message (Association Request messages)
When WDS certifications in (Vendor Specific IE) are identified, then from the association request message (Association
Request messages) the middle user account and account number cipher obtained in the WDS authentication informations (Vendor Specific IE);
S32, when there is no WDS certifications letter in the association request message (Association Request messages)
When WDS certifications in breath (Vendor Specific IE) are identified, then secondary access device (secondary router) associates main access device
After (active router), the secondary access device (secondary router) can not access outer net;
User account and account number cipher that S41, basis get, are authenticated to the user account and account number cipher.
Specifically, User Defined WDS authentication informations include WDS certification marks, user account and account number cipher, except this it
Outward, WDS authentication informations can also be defined as other guide by user.When association request message is received, association is first looked at
Identifying with the presence or absence of WDS certifications in request message, when there is WDS certifications mark, further obtaining from association request message
User account and account number cipher, and which is authenticated;Otherwise, it is not carried out obtaining user account and account number cipher step, directly
Connect execution association request step.In verification process, if active router serves as fat AP (WAP), in active router
It is upper that corresponding user account and account number cipher are set, and be authenticated on active router;If it is (wireless that active router serves as thin AP
Access point) when, then corresponding user account and account number cipher are set on wireless controller (AC), and at wireless controller (AC)
On be authenticated.
As shown in figure 3, according to another embodiment of the invention, a kind of WDS authentication methods, comprise the following steps:It is preferred that
, the WDS is also added including step S01, in advance in the association request message (Association Request messages)
Authentication information (Vendor Specific IE), the WDS authentication informations (Vendor Specific IE) are including WDS certification marks
Knowledge, user account and account number cipher.
S10, transmission association request message (Association Request messages), the association request message
(Association Request messages) includes the association request report containing WDS authentication informations (Vendor Specific IE)
Literary (Association Request messages) and the association request of WDS authentication informations (Vendor Specific IE) is not contained
Message (Association Request messages);
S11, send association request message (the Association Request messages) when, using 802.11w encrypt
Mode or other cipher modes are to the association request message (Association Request messages) and/or WDS authentication informations
(Vendor Specific IE) is encrypted transmission.
The association request message (Association Request messages) that S21, basis are received, checks that the association please
Whether there is the WDS authentication informations (Vendor Specific IE) in seeking message (Association Request messages)
In WDS certifications mark;
S31, when there is the WDS authentication informations in the association request message (Association Request messages)
When WDS certifications in (Vendor Specific IE) are identified, then from the association request message (Association
Request messages) the middle user account and account number cipher obtained in the WDS authentication informations (Vendor Specific IE);
S32, when there is no WDS certifications letter in the association request message (Association Request messages)
When WDS certifications in breath (Vendor Specific IE) are identified, then secondary access device (secondary router) associates main access device
After (active router), the secondary access device (secondary router) can not access outer net;
User account and account number cipher that S41, basis get, are authenticated to the user account and account number cipher.
S42, when the user account and account number cipher certification success, then secondary access device (secondary router) association master connects
After entering equipment (active router), the secondary access device (secondary router) may have access to outer net;
S43, when the user account and account number cipher authentification failure, then the secondary access device (secondary router) can not
Access outer net.
Specifically, when association request message is sent, in order to ensure the security of WDS authentication informations, can adopt
802.11w cipher modes are transmitted after being encrypted to association request message, or using other cipher modes to WDS authentication informations
It is encrypted transmission.When user account and account number cipher pass through certification, secondary router association above, after active router, can be accessed
Outer net;When user account and account number cipher authentification failure, secondary router only associates active router, it is impossible to access outer net.
As shown in figure 4, according to one embodiment of present invention, a kind of WDS Verification Systems, including secondary access device 10 and master
Access device 20:
Preferably, the secondary access device 10 includes information add module 11, in advance in the association request message
The WDS authentication informations (Vendor Specific IE) are added in (Association Request messages), the WDS recognizes
Card information (Vendor Specific IE) is including WDS certification marks, user account and account number cipher.
The secondary access device 10 also includes message sending module 12, for sending association request message (Association
Request messages), the association request message (Association Request messages) is included containing WDS authentication informations
The association request message (Association Request messages) of (Vendor Specific IE) and do not contain WDS certifications letter
The association request message (Association Request messages) of breath (Vendor Specific IE);
Encrypted transmission module 30, for send association request message (the Association Request messages) when,
Using 802.11w cipher modes or other cipher modes to the association request message (Association Request messages)
And/or WDS authentication informations (Vendor Specific IE) are encrypted transmission.
The main access device 20 includes message receiver module 21 and checks module 22, and the message receiver module is used to connect
The association request message (Association Request messages) for receiving, it is described to check module for checking the association request
With the presence or absence of in the WDS authentication informations (Vendor Specific IE) in message (Association Request messages)
WDS certifications mark;
The main access device 20 also includes acquisition module 23, for as the association request message (Association
Request messages) in when there is WDS certifications in the WDS authentication informations (Vendor Specific IE) and identifying, then from institute
WDS authentication informations (the Vendor Specific are obtained in stating association request message (Association Request messages)
IE the user account and account number cipher in);
Authentication module 40, for being authenticated to the user account and account number cipher.
Relating module 50, for when the user account and account number cipher certification success, then secondary access device 10 is associated
After main access device 20, the secondary access device 10 may have access to outer net;
The relating module 50, does not deposit in the association request message (Association Request messages) for working as
When WDS certifications in the WDS authentication informations (Vendor Specific IE) are identified, or work as the user account and account
When cipher authentication fails, then, after the secondary access device 10 associates main access device 20, the secondary access device 10 can not be accessed
Outer net.
Specifically, secondary access device can be secondary router, main access device can be active router;When active router fills
When fat AP (WAP), then corresponding user account and account number cipher are set on active router, and in active router
On be authenticated, its authentication module 40 is arranged on active router;When active router serves as thin AP (WAP), then in nothing
Corresponding user account and account number cipher are set on lane controller (AC), and are authenticated on wireless controller (AC), which is recognized
Card module 40 is arranged on wireless controller (AC).
According to still another embodiment of the invention, a kind of WDS authentication methods, comprise the following steps:Send in secondary router
Association Request messages in add Vendor Specific IE, the content bag of Vendor Speicfic IE
Include:WDS certification marks, user account, user cipher.
Active router can check this Vendor Specific IE after Assoication Request are received, and find
WDS certifications are identified, then illustrate this Vendor Specific IE for WDS certifications, then obtain user account and password, enter
Row certification, if certification passes through, this secondary router need not carry out Portal certifications, directly allow him to access outer net after association.
Certainly the account and password for directly transmitting plaintext by Vendor Specific IE has safety problem, can pass through 802.11w
Or other modes are encrypted to WIFI modes.
General active router has opened Portal certifications, and when client STA accesses active router, client STA is first closed
Connection active router, under Portal certifications, the SSID mono- of active router is well matched for Open, so association must success, but nothing
Method accesses outer net, only after Portal successes, could surf the Net.
Its secondary router association active router is also that, using this flow process, but secondary router cannot initiate Portal certifications,
Also no interface is input into username and password, causes secondary router normally access outer net.
It should be noted that above-described embodiment can independent assortment as needed.The above is only the preferred of the present invention
Embodiment, it is noted that for those skilled in the art, in the premise without departing from the principle of the invention
Under, some improvements and modifications can also be made, these improvements and modifications also should be regarded as protection scope of the present invention.