Communication channel management methods and apparatuses
A computer-implemented method for communication channel management performed by a wireless access point (AP) device is described. An original management frame that carries a target information element is constructed, where the target information element includes an information element related to communication channel management. When determined that one or more clients are connected to the AP device, for each of the determined clients: A destination address of the original management frame is set to a MAC address of the client. To obtain an encrypted management frame by using a key corresponding to the client, information in the target information element is encrypted. The encrypted management frame is sent in a WiFi network, so that a connected client in the WiFi network determines, based on the destination address, whether to process the encrypted management frame.
1 . A computer-implemented method for communication channel management, comprising:
performed by a wireless access point (AP) device in an open wireless local area network (WLAN):
constructing an original management frame that carries information elements in a target information element, wherein the target information element comprises an information element related to communication channel management and the information element comprises at least one of:
a channel switch announcement element, a channel switch wrapper element, a wide bandwidth channel switch element, a mesh channel switch parameters element, a channel switch timing element, a max channel switch time element, and a future channel guidance element; and
when a determination is reached that one or more clients are connected to the AP device, performing, for each client of the one or more clients:
setting a destination address of the original management frame to a media access control (MAC) address of the client;
encrypting, to obtain an encrypted management frame by using a key unique to the client, only part of the information elements in the target information element while leaving at least part of the information elements unencrypted, wherein the key unique to the client is generated using a four-way handshake process between the client and the AP device; and
sending the encrypted management frame in the open WLAN, so that a connected client in the open WLAN determines, based on the destination address, whether to process the encrypted management frame.
2 . The computer-implemented method of claim 1 , comprising:
broadcasting the original management frame in the open WLAN when no client is determined to have established a connection to the AP device.
3 . The computer-implemented method of claim 1 , wherein encrypting, to obtain an encrypted management frame by using a key corresponding to the client, information in the target information element, wherein the key corresponding to the client is generated using a four-way handshake process between the client and the AP device, comprises:
obtaining a dedicated key generated in the four-way handshake process when establishing a connection to the client; and
encrypting the information in the target information element by using the dedicated key.
4 . The computer-implemented method of claim 1 , wherein:
the target information element is stored in a tag-length-value data format; and
the encrypting, to obtain an encrypted management frame by using a key corresponding to the client, information in the target information element, wherein the key corresponding to the client is generated using a four-way handshake process between the client and the AP device, comprises:
encrypting a value in the target information element by using the key corresponding to the client.
5 . The computer-implemented method of claim 1 , wherein the original management frame comprises a beacon frame and a probe response frame.
6 . The computer-implemented method of claim 1 , comprising:
when the original management frame is a beacon frame and the target information element is a channel switch announcement element:
in response to determining that channel switch is completed, sending, in the open WLAN, a beacon frame whose destination address is a broadcast address and that carries no channel switch announcement element.
7 . A non-transitory, computer-readable medium storing one or more instructions executable by a computer system to perform operations for communication channel management, comprising:
performing by a wireless access point (AP) device in an open wireless local area network (WLAN):
constructing an original management frame that carries information elements in a target information element, wherein the target information element comprises an information element related to communication channel management and the information element comprises at least one of:
a channel switch announcement element, a channel switch wrapper element, a wide bandwidth channel switch element, a mesh channel switch parameters element, a channel switch timing element, a max channel switch time element, and a future channel guidance element; and
when a determination is reached that one or more clients are connected to the AP device, performing, for each client of the one or more clients:
setting a destination address of the original management frame to a media access control (MAC) address of the client;
encrypting, to obtain an encrypted management frame by using a key unique to the client, only part of the information elements in the target information element while leaving at least part of the information elements unencrypted, wherein the key unique to the client is generated using a four-way handshake process between the client and the AP device; and
sending the encrypted management frame in the open WLAN, so that a connected client in the open WLAN determines, based on the destination address, whether to process the encrypted management frame.
8 . The non-transitory, computer-readable medium of claim 7 , comprising:
broadcasting the original management frame in the open WLAN when no client is determined to have established a connection to the AP device.
9 . The non-transitory, computer-readable medium of claim 7 , wherein encrypting, to obtain an encrypted management frame by using a key corresponding to the client, information in the target information element, wherein the key corresponding to the client is generated using a four-way handshake process between the client and the AP device, comprises:
obtaining a dedicated key generated in the four-way handshake process when establishing a connection to the client; and
encrypting the information in the target information element by using the dedicated key.
10 . The non-transitory, computer-readable medium of claim 7 , wherein:
the target information element is stored in a tag-length-value data format; and
the encrypting, to obtain an encrypted management frame by using a key corresponding to the client, information in the target information element, wherein the key corresponding to the client is generated using a four-way handshake process between the client and the AP device, comprises:
encrypting a value in the target information element by using the key corresponding to the client.
11 . The non-transitory, computer-readable medium of claim 7 , wherein the original management frame comprises a beacon frame and a probe response frame.
12 . The non-transitory, computer-readable medium of claim 7 , comprising:
when the original management frame is a beacon frame and the target information element is a channel switch announcement element:
in response to determining that channel switch is completed, sending, in the open WLAN, a beacon frame whose destination address is a broadcast address and that carries no channel switch announcement element.
13 . A computer-implemented system for communication channel management, comprising:
one or more computers; and
one or more computer memory devices interoperably coupled with the one or more computers and having tangible, non-transitory, machine-readable media storing one or more instructions that, when executed by the one or more computers, perform one or more operations comprising:
performing by a wireless access point (AP) device in an open wireless local area network (WLAN):
constructing an original management frame that carries information elements in a target information element, wherein the target information element comprises an information element related to communication channel management and the information element comprises at least one of:
a channel switch announcement element, a channel switch wrapper element, a wide bandwidth channel switch element, a mesh channel switch parameters element, a channel switch timing element, a max channel switch time element, and a future channel guidance element; and
when a determination is reached that one or more clients are connected to the AP device, performing, for each client of the one or more clients:
setting a destination address of the original management frame to a media access control (MAC) address of the client;
encrypting, to obtain an encrypted management frame by using a key unique to the client, only part of the information elements in the target information element while leaving at least part of the information elements unencrypted, wherein the key unique to the client is generated using a four-way handshake process between the client and the AP device; and
sending the encrypted management frame in the open WLAN, so that a connected client in the open WLAN determines, based on the destination address, whether to process the encrypted management frame.
14 . The computer-implemented method of claim 13 , comprising:
broadcasting the original management frame in the open WLAN when no client is determined to have established a connection to the AP device.
15 . The computer-implemented system of claim 13 , wherein encrypting, to obtain an encrypted management frame by using a key corresponding to the client, information in the target information element, wherein the key corresponding to the client is generated using a four-way handshake process between the client and the AP device, comprises:
obtaining a dedicated key generated in the four-way handshake process when establishing a connection to the client; and
encrypting the information in the target information element by using the dedicated key.
16 . The computer-implemented system of claim 13 , wherein:
the target information element is stored in a tag-length-value data format; and
the encrypting, to obtain an encrypted management frame by using a key corresponding to the client, information in the target information element, wherein the key corresponding to the client is generated using a four-way handshake process between the client and the AP device, comprises:
encrypting a value in the target information element by using the key corresponding to the client.
17 . The computer-implemented system of claim 13 , wherein the original management frame comprises a beacon frame and a probe response frame.