WPS协议阅读之第五章initial WLAN setup

本文详细介绍了WPS协议在初始化WLAN网络中的应用,包括standalone AP和使用外部Registrar的情况。standalone AP自动选择SSID和信道,开启WPS则不允许使用其他接入控制。外部Registrar用于发布认证信息,扩展网络成员。WPS提供了便捷的网络配置方式,但也需要注意安全风险,如使用强密码防止攻击。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

存在两种用WPS配置WLAN网络的场景:
第一种情况是standalone AP使用WPS,standalone AP是指AP中内置一个Registrar并且不使用外置的Registrar,第二种情况是WPS AP使用一个或者多个外置的Registrar。AP授权外置Registrar向Enrollees发布认证信息并管理AP的配置。
打开了WPS的AP必须在其beacon中包含SSID,如果用户人为关闭AP的广播SSID,则会同时自动关闭WPS,如果关闭WPS,那么beacon帧和其他管理帧中将不会包含WPS IE,也不会有WPS协议帧交互。
一旦打开WPS,AP不能使用其他接入控制机制(如MAC过滤机制)。
5.1 Standalone AP
最简单地使用WPS进行初始化网络配置的是standalone AP,在这种情况下,WPS AP必须自动地选择一个SSID和信道,同时默认打开随机生成PSK的WPA2-Personal,如果需要向下兼容不支持WPA2-Personal的client,AP可以配置成混合模式。standalone AP包含一个WPS Registrar,利用Registrar Protocol向Enrollees发布keys,同时包含一个安全的开关键,包含一个恢复出厂设置的按键。
如果standalone AP使用网页输入Enrollee密码或者执行其他Registrar功能,需遵从以下建议:
a. AP的Registrar管理页面经过TLS加密
b. 至少使用在TLS基础上的response-auth摘要认证
c. 可以在registrar的网页管理界面关闭添加新的Enrollees
如果AP用一个统一的内置的device password用于登录管理网页和启动外置Registar,这个密码对于这个AP必须是独一无二的,然而也允许用户把这个密码改为更强的密码,如果默认密码被改变,那么原来的默认密码将被改变,除非恢复出厂设置。
安全考量
当standalone AP作为一个Registrar时,存在一些可能的风险,理想情况下,在设置AP的时候需要一步一步不断询问用户,但standalone AP与用户交互不够,导致用户可

# [ 33.344784] rtl8723bs: acquire FW from file:rtlwifi/rtl8723bs_nic.bin cat > /tmp/wpa.conf <<EOF > network={ > ssid="Xiaomi_6E67" > psk="15022688" > key_mgmt=WPA-PSK > proto=RSN # 强制使用WPA2 > pairwise=CCMP # 强制AES加密 > group=CCMP > scan_ssid=1 # 扫描隐藏网络 > freq_list=2427 # 指定2.4GHz频段 > } > EOF # wpa_supplicant -d -Dnl80211 -iwlan0 -c/tmp/wpa.conf wpa_supplicant v2.10 random: Trying to read entropy from /dev/random Successfully initialized wpa_supplicant Initializing interface 'wlan0' conf '/tmp/wpa.conf' driver 'nl80211' ctrl_interface 'N/A' bridge 'N/A' Configuration file '/tmp/wpa.conf' -> '/tmp/wpa.conf' Reading configuration file '/tmp/wpa.conf' Priority group 0 id=0 ssid='Xiaomi_6E67' nl80211: Supported cipher 00-0f-ac:1 nl80211: Supported cipher 00-0f-ac:5 nl80211: Supported cipher 00-0f-ac:2 nl80211: Supported cipher 00-0f-ac:4 nl80211: Supported cipher 00-0f-ac:6 nl80211: Using driver-based off-channel TX nl80211: key_mgmt=0xd0f enc=0x10f auth=0x7 flags=0x800d0c0 rrm_flags=0x0 probe_resp_offloads=0x0 max_stations=0 max_remain_on_chan=5000 max_scan_ssids=9 nl80211: interface wlan0 in phy phy0 nl80211: Set mode ifindex 2 iftype 2 (STATION) nl80211: Subscribe to mgmt frames with non-AP handle 0x53cf78 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=0801 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=06 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=0a07 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=0a11 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=1101 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=1102 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=0505 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=0500 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=1301 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=1305 multicast=0 nl80211: Register frame type=0xd0 (WLAN_FC_STYPE_ACTION) nl_handle=0x53cf78 match=7e506f9a1a multicast=0 rfkill: initial event: idx=0 type=1 op=0 soft=0 hard=0 netlink: Operstate: ifindex=2 linkmode=1 (userspace-control), operstate=5 (IF_OPER_DORMANT) Add interface wlan0 to a new radio phy0 nl80211: Regulatory information - country=00 nl80211: 2402-2472 @ 40 MHz 20 mBm nl80211: 2457-2482 @ 20 MHz 20 mBm (no IR) nl80211: 2474-2494 @ 20 MHz 20 mBm (no OFDM) (no IR) nl80211: 5170-5250 @ 80 MHz 20 mBm (no IR) nl80211: 5250-5330 @ 80 MHz 20 mBm (DFS) (no IR) nl80211: 5490-5730 @ 160 MHz 20 mBm (DFS) (no IR) nl80211: 5735-5835 @ 80 MHz 20 mBm (no IR) nl80211: 57240-63720 @ 2160 MHz 0 mBm nl80211: Added 802.11b mode based on 802.11g information nl80211: Mode IEEE 802.11g: 2412 2417 2422 2427 2432 2437 2442 2447 2452 2457 2462 2467 2472 2484[DISABLED] nl80211: Mode IEEE 802.11b: 2412 2417 2422 2427 2432 2437 2442 2447 2452 2457 2462 2467 2472 2484[DISABLED] wlan0: Own MAC address: cc:b8:5e:f5:a6:86 wpa_driver_nl80211_set_key: ifindex=2 (wlan0) alg=0 addr=(nil) key_idx=0 set_tx=0 seq_len=0 key_len=0 key_flag=0x10 nl80211: DEL_KEY broadcast key wpa_driver_nl80211_set_key: ifindex=2 (wlan0) alg=0 addr=(nil) key_idx=1 set_tx=0 seq_len=0 key_len=0 key_flag=0x10 nl80211: DEL_KEY broadcast key wpa_driver_nl80211_set_key: ifindex=2 (wlan0) alg=0 addr=(nil) key_idx=2 set_tx=0 seq_len=0 key_len=0 key_flag=0x10 nl80211: DEL_KEY broadcast key wpa_driver_nl80211_set_key: ifindex=2 (wlan0) alg=0 addr=(nil) key_idx=3 set_tx=0 seq_len=0 key_len=0 key_flag=0x10 nl80211: DEL_KEY broadcast key wpa_driver_nl80211_set_key: ifindex=2 (wlan0) alg=0 addr=(nil) key_idx=4 set_tx=0 seq_len=0 key_len=0 key_flag=0x10 nl80211: DEL_KEY broadcast key wpa_driver_nl80211_set_key: ifindex=2 (wlan0) alg=0 addr=(nil) key_idx=5 set_tx=0 seq_len=0 key_len=0 key_flag=0x10 nl80211: DEL_KEY broadcast key wlan0: RSN: flushing PMKID list in the driver nl80211: Flush PMKIDs wlan0: Setting scan request: 0.100000 sec TDLS: TDLS operation not supported by driver TDLS: Driver uses internal link setup TDLS: Driver does not support TDLS channel switching wlan0: Added interface wlan0 wlan0: State: DISCONNECTED -> DISCONNECTED nl80211: Set wlan0 operstate 0->0 (DORMANT) netlink: Operstate: ifindex=2 linkmode=-1 (no change), operstate=5 (IF_OPER_DORMANT) nl80211: Skip set_supp_port(unauthorized) while not associated random: Got 20/20 bytes from /dev/random RTM_NEWLINK: ifi_index=2 ifname=wlan0 operstate=2 linkmode=1 ifi_family=0 ifi_flags=0x1003 ([UP]) wlan0: State: DISCONNECTED -> SCANNING Scan SSID - hexdump_ascii(len=11): 58 69 61 6f 6d 69 5f 36 45 36 37 Xiaomi_6E67 wlan0: Starting AP scan for wildcard SSID wlan0: Add radio work 'scan'@0x53f718 wlan0: First radio work item in the queue - schedule start immediately wlan0: Starting radio work 'scan'@0x53f718 after 0.000095 second wait wlan0: nl80211: scan request Scan requested (ret=0) - scan timeout 10 seconds nl80211: Drv Event 33 (NL80211_CMD_TRIGGER_SCAN) received for wlan0 wlan0: nl80211: Scan trigger wlan0: Event SCAN_STARTED (47) received wlan0: Own scan request started a scan in 0.000210 seconds RTM_NEWLINK: ifi_index=2 ifname=wlan0 wext ifi_family=0 ifi_flags=0x1003 ([UP]) nl80211: Drv Event 34 (NL80211_CMD_NEW_SCAN_RESULTS) received for wlan0 wlan0: nl80211: New scan results available nl80211: Scan probed for SSID 'Xiaomi_6E67' nl80211: Scan probed for SSID '' nl80211: Scan included frequencies: 2412 2417 2422 2427 2432 2437 2442 2447 2452 2457 2462 2467 2472 wlan0: Event SCAN_RESULTS (3) received wlan0: Scan completed in 1.536741 seconds nl80211: Received scan results (1 BSSes) wlan0: BSS: Start scan result update 1 wlan0: BSS: Add new id 0 BSSID cc:d8:43:81:b9:9e SSID 'Xiaomi_6E67' freq 2432 BSS: last_scan_res_used=1/32 wlan0: New scan results available (own=1 ext=0) wlan0: Radio work 'scan'@0x53f718 done in 1.541366 seconds wlan0: radio_work_free('scan'@0x53f718): num_active_works --> 0 wlan0: Selecting BSS from priority group 0 wlan0: 0: cc:d8:43:81:b9:9e ssid='Xiaomi_6E67' wpa_ie_len=0 rsn_ie_len=20 caps=0x1431 level=-66 freq=2432 wps wlan0: selected based on RSN IE wlan0: skip - frequency not allowed wlan0: No suitable network found wlan0: Setting scan request: 5.000000 sec Scan SSID - hexdump_ascii(len=11): 58 69 61 6f 6d 69 5f 36 45 36 37 Xiaomi_6E67 wlan0: Starting AP scan for wildcard SSID wlan0: Add radio work 'scan'@0x5404d8 wlan0: First radio work item in the queue - schedule start immediately wlan0: Starting radio work 'scan'@0x5404d8 after 0.000087 second wait wlan0: nl80211: scan request Scan requested (ret=0) - scan timeout 30 seconds nl80211: Drv Event 33 (NL80211_CMD_TRIGGER_SCAN) received for wlan0 wlan0: nl80211: Scan trigger wlan0: Event SCAN_STARTED (47) received wlan0: Own scan request started a scan in 0.000248 seconds RTM_NEWLINK: ifi_index=2 ifname=wlan0 wext ifi_family=0 ifi_flags=0x1003 ([UP]) nl80211: Drv Event 34 (NL80211_CMD_NEW_SCAN_RESULTS) received for wlan0 wlan0: nl80211: New scan results available nl80211: Scan probed for SSID 'Xiaomi_6E67' nl80211: Scan probed for SSID '' nl80211: Scan included frequencies: 2412 2417 2422 2427 2432 2437 2442 2447 2452 2457 2462 2467 2472 wlan0: Event SCAN_RESULTS (3) received wlan0: Scan completed in 1.761073 seconds nl80211: Received scan results (1 BSSes) wlan0: BSS: Start scan result update 2 BSS: last_scan_res_used=1/32 wlan0: New scan results available (own=1 ext=0) wlan0: Radio work 'scan'@0x5404d8 done in 2.204339 seconds wlan0: radio_work_free('scan'@0x5404d8): num_active_works --> 0 wlan0: Selecting BSS from priority group 0 wlan0: 0: cc:d8:43:81:b9:9e ssid='Xiaomi_6E67' wpa_ie_len=0 rsn_ie_len=20 caps=0x1431 level=-66 freq=2432 wps wlan0: selected based on RSN IE wlan0: skip - frequency not allowed wlan0: No suitable network found wlan0: Setting scan request: 5.000000 sec journalctl -f | grep -E 'wpa_supplicant|rtl8723bs' Scan SSID - hexdump_ascii(len=11): 58 69 61 6f 6d 69 5f 36 45 36 37 Xiaomi_6E67 wlan0: Starting AP scan for wildcard SSID wlan0: Add radio work 'scan'@0x541ff0 wlan0: First radio work item in the queue - schedule start immediately wlan0: Starting radio work 'scan'@0x541ff0 after 0.000076 second wait wlan0: nl80211: scan request Scan requested (ret=0) - scan timeout 30 seconds
最新发布
06-09
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值