Heterogeneous network terminal self-organizing IoT network system and technology
By leveraging the digital certificate chain and network data issued by the IoT Alliance, the system enables automatic networking and management of smart terminals under different network standards. This solves the networking difficulties caused by manual configuration in existing technologies and improves the convenience and flexibility of IoT networks.
Patent Information
- Application Number
- CN202511724454.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-23
- Publication Date
- 2026-02-03
AI Technical Summary
Existing smart devices require manual configuration when forming a network, which is especially labor-intensive when there are many devices, making zero-configuration IoT network management difficult.
By leveraging the digital certificate chain and distribution network data issued by the IoT Alliance, automatic authentication and connection between smart terminals and access devices can be achieved, supporting zero-configuration joining, leaving, roaming, and switching of IoT networks.
It enables automatic networking and management of smart terminals under different network standards, reducing manual configuration workload and improving the convenience and flexibility of IoT networks.
Smart Images

Figure CN121463149A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of IoT, and more specifically, to a technology for an IoT network composed of various heterogeneous network terminals, IoT access devices, cloud platforms, IoT alliances, etc. Background Technology
[0002] More and more devices are supporting connectivity and intelligence. Currently, these smart devices typically communicate using wireless transmission protocols such as WiFi, Bluetooth, Bluetooth Mesh, Zigbee, Thread, NearLink, and LoRa, or wired transmission protocols such as Ethernet and RS485, and then connect directly or through a gateway to a specific cloud platform or server. In these solutions, smart terminals need to be manually configured to connect to the gateway or network device and subsequently to the specific cloud platform or server. This configuration includes configuring the SSID and password for WiFi devices connecting to the access point (AP), configuring Bluetooth devices connecting to the Bluetooth gateway, and configuring the Bluetooth gateway connecting to the AP. When there are many devices in the network, the configuration workload becomes considerable. Therefore, how to achieve zero-configuration IoT network management is a valuable technical problem. Summary of the Invention
[0003] The purpose of this invention is to provide a system and technology for heterogeneous network terminals to self-organize an IoT network, so as to solve the problems mentioned in the background art and realize the zero-configuration integration and management of smart terminals of various network standards and cloud platforms into an IoT network.
[0004] To achieve the above objectives, this invention proposes an IoT system comprising various network-standard smart terminals, access devices, cloud platforms, IoT networks, terminal manufacturers, IoT alliances, and other entities. It supports users in creating IoT networks on the cloud platform, allows smart terminals of various network standards to join IoT networks with zero configuration, allows smart terminals to easily leave IoT networks, allows smart terminals to roam across networks with zero configuration, and allows smart terminals to switch IoT networks with zero configuration.
[0005] Furthermore, the IoT Alliance, as the builder of this technical solution, provides the following functions within the IoT network: acting as a trusted third party, it issues digital certificates to smart terminal manufacturers and cloud platform vendors; the IoT Alliance provides interface A (IoT network certificate chain, smart terminal certificate chain) for attributing a smart terminal to a specific IoT network, interface B (IoT network certificate chain, smart terminal certificate chain) for deregistering a smart terminal's attribution, interface C (IoT network A certificate chain, smart terminal certificate chain, IoT network B certificate chain) for changing a smart terminal's attribution, and interface D (IoT network certificate chain, IoT network terminal certificate chain) for checking whether a smart terminal has joined the IoT network and obtaining its address, etc. The IoT Alliance includes its root certificate and private key.
[0006] Furthermore, the smart terminal and access device are manufactured by a terminal manufacturer, which is the manufacturer of the smart terminal and access device; the certificate chain issued by the IoT Alliance serves as the identity verification of the terminal manufacturer.
[0007] Furthermore, the cloud platform, which provides IoT network services, can be an IoT cloud platform operated by the IoT Alliance, a cloud platform built by an IoT integrator or owner, or an IoT platform integrated into access devices. The certificate chain issued by the IoT Alliance serves as the identity verification for the cloud platform.
[0008] Furthermore, the aforementioned smart terminal is a smart terminal that can access the IoT network, and the certificate chain issued by the smart terminal manufacturer serves as the identity verification of the smart terminal. When the smart terminal leaves the factory, in addition to the certificate chain and its private key issued by the terminal manufacturer, it also has a built-in IoT Alliance certificate for verifying the authenticity of connected peer devices, and a built-in QR code or NFC for zero-configuration IoT network formation; the QR code and NFC store network configuration data, which mainly includes the certificate issued by the smart terminal manufacturer to the device and a randomly generated pairing code (such as a 128-bit decimal number). The QR code and NFC are different carriers of the network configuration data.
[0009] Furthermore, the access device is essentially a smart terminal. It can connect to smart terminals with various network standards to the south and access multiple cloud platforms to the north. The certificate chain issued by the smart terminal manufacturer serves as the access device's identity verification. At the time of manufacture, in addition to the built-in certificate chain and its private key issued by the terminal manufacturer, the access device also includes an IoT Alliance certificate for verifying the authenticity of connected peer devices. It also includes a built-in QR code or NFC for zero-configuration IoT network formation. The QR code and NFC store network configuration data, which mainly includes the certificate issued by the smart terminal manufacturer and a randomly generated pairing code (such as a 128-bit decimal number). The QR code and NFC are different carriers of this network configuration data.
[0010] Furthermore, the IoT network is a digital twin of the real IoT network running on the cloud platform. The real IoT network consists of several smart terminals, access devices, and a control hub. The IoT network is a control hub created by the user on the cloud platform, and the certificate chain issued by the cloud platform serves as the identity verification for the IoT network. The cloud platform registers the newly created IoT network identity with the IoT Alliance for future use.
[0011] Furthermore, the zero-configuration addition of smart terminals supporting various network standards to the IoT network refers to the process where, after a user purchases a new smart terminal, they scan the smart terminal's QR code or obtain the device's network configuration data by reading the NFC through an order or after powering on, and store it in the user's IoT network control center, and submit a tuple (cloud platform certificate chain, IoT network certificate chain, smart terminal certificate chain) to the IoT Alliance. Once the smart terminal is powered on, it will automatically join the IoT network through the following steps: 1) The smart terminal powers on; 2) The smart terminal automatically scans for surrounding access devices via broadcast and selects the access device with the best signal to perform subsequent actions until it successfully joins the IoT network; 3) The smart terminal sends its certificate chain to the access device. The access device verifies whether the smart terminal's identity can be verified by the IoT Alliance. If the verification is successful, it continues; 4) The access device sends its certificate chain to the smart terminal. The smart terminal verifies whether the access device's identity can be verified by the IoT Alliance. If the verification is successful, it continues; 5) The smart terminal requests to join the IoT network from the access device. The access device requests the address of the IoT network to which the smart terminal belongs and the IoT network's certificate from the IoT Alliance or other pre-defined addresses. If the acquisition is successful, it continues; 6) The access device and the IoT... The network establishes an encrypted connection and then requests the pairing code of the smart terminal. The IoT network encrypts the pairing code using the smart terminal's public key and sends it to the access device, which then forwards it to the smart terminal. 7) The smart terminal decrypts the pairing code using its private key and verifies its pairing. If the pairing is correct, it requests the access device to send network configuration information. 8) After receiving the request for network configuration information from the smart terminal, the access device can send the network configuration information to the smart terminal. 9) After receiving the network configuration information, the smart terminal establishes a point-to-point connection with the access device. 10) The smart terminal sends a join request to the IoT network control center. 11) The IoT network control center issues the IoT network terminal's certificate chain and private key to the smart terminal. 12) Then, the smart terminal establishes a point-to-point IoT connection with the IoT network through the access device. At this point, the smart terminal has successfully joined the IoT network with zero configuration.
[0012] Furthermore, the zero-configuration joining of smart terminals supporting various network standards to the IoT network is achieved if the smart terminal has already obtained network configuration information and is connected to the access device. The main steps are as follows: 1) The smart terminal attempts to establish a point-to-point connection with the access device. First, the smart terminal sends its certificate chain to the access device. The access device verifies whether the smart terminal's identity can be verified by the IoT Alliance. If the verification is successful, the process continues. 2) The access device sends its certificate chain to the smart terminal. The smart terminal verifies whether the access device's identity can be verified by the IoT Alliance. If the verification is successful, the process continues. 3) The smart terminal requests to join the IoT network from the access device. The access device requests to obtain the necessary information from the IoT Alliance or other pre-defined addresses. 4) The access device establishes an encrypted connection with the IoT network and then requests the pairing code of the smart terminal. The IoT network encrypts the pairing code using the smart terminal's public key and sends it to the access device, which then forwards it to the smart terminal. 5) The smart terminal decrypts the pairing code with its private key and verifies whether the pairing code is correct. If the pairing is correct, the smart terminal sends a join request to the IoT network control center. 6) The IoT network control center issues the IoT network terminal's certificate chain and private key to the smart terminal. 7) Then, the smart terminal establishes a point-to-point IoT connection with the IoT network through the access device. At this point, the smart terminal has successfully joined the IoT network with zero configuration.
[0013] Furthermore, the point-to-point IoT connection refers to an application layer connection, which operates on top of WebSocket, TCP / IP, Bluetooth protocol stacks, etc. The two ends of the IoT network are two smart terminals, or a smart terminal and an IoT network control center. The address of the smart terminal is the IoT network terminal certificate, and the address of the IoT network control center is the IoT network certificate; the IoT connection is an encrypted connection.
[0014] Furthermore, the support for convenient exit of smart terminals from the IoT network refers to a user deleting a joined smart terminal from the IoT network control center and notifying the smart terminal to exit the IoT network, restoring it to factory settings, and allowing it to rejoin other IoT networks. The process is as follows: 1) The user confirms the deletion of a joined smart terminal in the IoT network control center; 2) The IoT network control center notifies the smart terminal to exit the IoT network via a point-to-point connection; 3) Upon receiving the exit command, the smart terminal reports successful exit to the IoT network control center via a point-to-point connection, then clears the IoT network terminal certificate chain and its private key issued by the IoT network, restoring it to factory settings, and can rejoin other IoT networks; 4) Upon receiving the smart terminal's response that it has exited the IoT network, the IoT network control center marks the smart terminal as successfully exited and submits a tuple (cloud platform certificate chain, IoT network certificate chain, smart terminal certificate chain) to the IoT Alliance, requesting the cancellation of the smart terminal's ownership in the IoT Alliance.
[0015] Furthermore, the support for zero-configuration cross-network roaming for smart terminals refers to the automatic and successful network configuration of a smart terminal automatically switching from network environment A to another network environment B (the network configuration information of the two network environments is completely different) after a smart device that has joined the IoT network switches from one network environment A to another network environment B (the network configuration information of the two network environments is completely different), ensuring uninterrupted IoT services. The main steps are as follows: 1) When a smart terminal that has joined the IoT network leaves its original network environment, it triggers a scan of surrounding access devices; 2) The smart terminal automatically scans for surrounding access devices via broadcast and selects the access device with the best signal one by one to perform subsequent actions until it successfully joins the IoT network; 3) The smart terminal sends its certificate chain to the access device, and the access device verifies whether the identity of the smart terminal can be verified by the IoT Alliance. If the verification is successful, it continues; 4) The access device sends its certificate chain to the smart terminal, and the smart terminal verifies whether the identity of the access device can be verified by the IoT Alliance. If the verification is successful, it continues; 5) The smart terminal… The terminal sends the certificate chain of the IoT network terminal to the access device. The access device queries the IoT Alliance or a certain location for the address of the IoT network. If the address of the IoT network is found, the process continues. 6) The access device establishes a point-to-point connection with the IoT network and queries whether the smart terminal has joined the IoT network. If it is confirmed that it has joined, the process continues. 7) The access device sends the configuration network information and the address of the IoT network to the smart terminal. 8) The smart terminal establishes a point-to-point connection with the access device based on the configuration network information. 9) Then, the smart terminal establishes a point-to-point IoT connection with the IoT network through the access device. At this point, the smart terminal has successfully gone online on the IoT network.
[0016] Furthermore, the so-called support for zero-configuration switching of IoT networks by smart terminals refers to supporting the zero-configuration transfer of smart terminals originally belonging to IoT network A to IoT network B. The main steps are as follows: 1) IoT network A sends a tuple (the smart terminal's certificate chain) to IoT network B requesting the transfer to the smart terminal; 2) IoT network B randomly generates a pairing code and encrypts it using the smart terminal's public key before sending it to IoT network A; 3) IoT network A sends the new pairing code, encrypted with the smart terminal's public key, to the smart terminal and notifies it that it will switch IoT networks; 4) After receiving the IoT network switching command, the smart terminal reports successful exit to the IoT network control center via a point-to-point connection, then clears the IoT network terminal certificate chain and its private key issued to it by that IoT network, and can rejoin other IoT networks using the new pairing code; 5) After receiving the smart terminal's notification of exiting the IoT network, the IoT network control center marks the smart terminal as successfully exited and submits a tuple (cloud platform certificate chain, IoT network A certificate chain, smart terminal certificate chain, IoT network B certificate chain) to the IoT Alliance, requesting a change of ownership for the smart terminal within the IoT Alliance. Attached Figure Description
[0017] The invention is further illustrated with reference to the accompanying drawings, but the content of the drawings does not constitute any limitation on the invention. For those skilled in the art, other drawings can be obtained based on the following drawings without any creative effort.
[0018] Figure 1 This is a schematic diagram of a topology of an existing IoT network.
[0019] Figure 2 This is a schematic diagram of an IoT network topology provided in an embodiment of the present invention.
[0020] Figure 3 This invention provides an identity authentication system for the subject of an IoT system.
[0021] Figure 4 This is a flowchart provided by an embodiment of the present invention to support users in creating IoT networks on a cloud platform.
[0022] Figure 5 This is a flowchart illustrating the zero-configuration process for smart terminals supporting various network standards to join an IoT network, as provided in an embodiment of the present invention.
[0023] Figure 6 This is a flowchart provided by an embodiment of the present invention to support the convenient exit of smart terminals from the IoT network.
[0024] Figure 7 This is a flowchart illustrating the support for zero-configuration cross-network roaming for smart terminals provided in an embodiment of the present invention.
[0025] Figure 8 This is a flowchart illustrating the support for zero-configuration switching of IoT networks by smart terminals, provided in an embodiment of the present invention.
Claims
1. A system and technology for forming an IoT network with zero configuration of heterogeneous network terminals, characterized in that, The system includes various network standard smart terminals, access devices, cloud platforms, IoT networks, smart terminal manufacturers, IoT alliances, and other entities; the technologies include technologies that support users in creating IoT networks on cloud platforms, technologies that support smart terminals of various network standards in joining IoT networks, technologies that support smart terminals in leaving IoT networks, technologies that support smart terminals in roaming across networks, and technologies that support smart terminals in switching IoT networks.
2. The IoT alliance as described in claim 1, characterized in that, The IoT Alliance possesses the root certificate and private key of this system, and can issue digital certificates to smart terminal manufacturers and cloud platform vendors. It provides interface A (IoT network certificate chain, smart terminal certificate chain) for attributing a smart terminal to a specific IoT network, interface B (IoT network certificate chain, smart terminal certificate chain) for deregistering a smart terminal's attribution, interface C (IoT network A certificate chain, smart terminal certificate chain, IoT network B certificate chain) for changing a smart terminal's attribution, and interface D (IoT network certificate chain, IoT network terminal certificate chain) for checking whether a smart terminal has joined an IoT network and obtaining the address of the IoT network control center, etc.
3. The smart terminal manufacturer as described in claim 1, characterized in that, The smart terminal manufacturer is the manufacturer of the smart terminal or access device in this system, and has a certificate chain and corresponding private key issued by the IoT Alliance; the smart terminal manufacturer issues digital certificates for the smart terminals or access devices it manufactures.
4. The various network-standard smart terminals as described in claim 1, characterized in that, The smart terminal is manufactured by a smart terminal manufacturer and contains a certificate chain and corresponding private key issued by the manufacturer. It also contains the IoT Alliance's root certificate. When the smart terminal connects to the IoT network, the IoT network issues it an IoT network terminal certificate chain and corresponding private key. The smart terminal is equipped with a QR code, NFC, or other methods for storing network configuration data at the factory. Various network standard smart terminals connect to the access device via one or more network standards such as WiFi, Bluetooth, and Bluetooth Mesh. The network configuration data mainly includes the certificate issued by the smart terminal manufacturer and a randomly generated pairing code (e.g., a 128-bit decimal number). The access device is a special smart terminal with the characteristics of a smart terminal. The access device can directly access the IoT network and the IoT Alliance, while other smart terminals need to access the IoT network and the IoT Alliance indirectly through the access device.
5. The cloud platform as described in claim 1, characterized in that, The cloud platform, also known as the IoT platform, can be deployed on public clouds, private clouds, servers, or access devices. The cloud platform possesses a certificate chain and corresponding private keys issued by the IoT Alliance, and can run multiple IoT networks. These IoT networks are digital twins of the real IoT networks running on the cloud platform. The real IoT network consists of several smart terminals, access devices (essentially special smart terminals), and a control center; the term "IoT network" can also refer to the control center within the real IoT network system running on the cloud platform.
6. The technology as described in claim 1 that supports users in creating IoT networks on a cloud platform, characterized in that, The steps for a user to create an IoT network on the cloud platform include: 1) A user creates an IoT network on the cloud platform, which is equivalent to creating a digital twin instance of a real IoT network; 2) The cloud platform issues a certificate chain and a corresponding private key for the IoT network; 3) The cloud platform also registers the IoT network with the IoT Alliance.
7. The technology for zero-configuration integration of smart terminals supporting various network standards into an IoT network as described in claim 1, characterized in that, The steps for enabling smart terminals of various network standards to join the IoT network with zero configuration include: 1) After purchasing a new smart terminal, the user scans the smart terminal's QR code or obtains the device's network configuration data by reading the NFC through an order or after powering on, and stores it in the user's IoT network control center; 2) The IoT network submits tuples (IoT network certificate chain, smart terminal certificate chain) to the IoT Alliance; 3) When the smart terminal is powered on, it will automatically join the IoT network through several steps. When the smart terminal and the access device have not established a point-to-point connection, the steps include: a) After the smart terminal powers on, it scans the surrounding access devices and selects the access device with the best signal one by one; b) The smart terminal and the access device verify the legality of the certificate chain bidirectionally; c) The access device queries the IoT Alliance or a preset address to find the IoT network address and certificate to which the smart terminal belongs; d) The access device establishes an encrypted connection with the IoT network, obtains a pairing code encrypted with the smart terminal's public key, and forwards it to the smart terminal; e) After the smart terminal decrypts the pairing code and successfully verifies it, it requests to establish a point-to-point connection with the access device; f) The access device sends network configuration information to the smart terminal and establishes a point-to-point connection; g) The smart terminal requests to join the IoT network through the access device to the IoT network control center; h) The IoT network control center issues an IoT network terminal certificate chain and private key to the smart terminal, completing the joining; i) Afterwards, the smart terminal establishes a point-to-point IoT connection with other entities in the IoT network. When a point-to-point connection has been established between the smart terminal and the access device, the steps include: a) the smart terminal and the access device mutually verify the legality of the certificate chain; b) the access device queries the IoT Alliance or a pre-set address to find the IoT network address and certificate to which the smart terminal belongs; c) the access device establishes an encrypted connection with the IoT network, obtains a pairing code encrypted with the smart terminal's public key, and forwards it to the smart terminal; d) after the smart terminal decrypts the pairing code and successfully verifies it, it requests to join the IoT network control center; f) the IoT network control center issues an IoT network terminal certificate chain and private key to the smart terminal, completing the joining process; g) thereafter, the smart terminal establishes point-to-point IoT connections with other entities in the IoT network.
8. The technology for intelligent terminals to exit the IoT network as described in claim 1, characterized in that, The steps for the smart terminal to exit the IoT network include the following: 1) The IoT network control center notifies the smart terminal to exit the IoT network via a point-to-point connection; 2) After receiving the exit command, the smart terminal sends feedback to the IoT network control center via a point-to-point connection that it has successfully exited, then clears the IoT network terminal certificate chain and its private key issued to it by the IoT network, and restores it to factory settings; 4) After receiving the smart terminal's response that it has exited the IoT network, the IoT network control center marks the smart terminal as having successfully exited, and submits a tuple (cloud platform certificate chain, IoT network certificate chain, smart terminal certificate chain) to the IoT Alliance, requesting the cancellation of the smart terminal's ownership in the IoT Alliance.
9. The technology for supporting cross-network roaming of smart terminals as described in claim 1, characterized in that, The steps for implementing cross-network roaming of the smart terminal include the following: 1) After a smart terminal that has joined the IoT network leaves its original network environment, it automatically scans for surrounding access devices via broadcast and selects the access device with the best signal one by one; 2) The smart terminal and the access device verify the legality of the certificate chain bidirectionally; 3) The smart terminal sends the certificate chain of the IoT network terminal to the access device, and the access device queries the address of the IoT network in the IoT Alliance or at a certain location; 4) The access device establishes a point-to-point connection with the IoT network, queries whether the smart terminal has joined the IoT network, and continues after confirming that it has joined; 7) The access device sends the network configuration information and the address of the IoT network to the smart terminal; 8) The smart terminal establishes a point-to-point connection with the access device according to the network configuration information; 9) Afterwards, the smart terminal establishes a point-to-point IoT connection with other entities in the IoT network.
10. The technology for supporting smart terminals to switch IoT networks as described in claim 1, characterized in that, The implementation steps for the smart terminal to switch IoT networks include the following: 1) IoT network A sends a tuple (the smart terminal's certificate chain) to IoT network B requesting that it be given to the smart terminal; 2) IoT network B generates a pairing code and sends it to IoT network A; 3) IoT network A sends the pairing code to the smart terminal and notifies it that it will switch IoT networks; 4) The smart terminal reports to the IoT network control center that it has successfully exited, and at the same time clears the IoT network terminal certificate chain and its private key issued to it by the IoT network, and uses a new pairing code to replace the factory-set pairing code; 5) The IoT network control center marks that the smart terminal has successfully exited, and submits a tuple (cloud platform certificate chain, IoT network A certificate chain, smart terminal certificate chain, IoT network B certificate chain) to the IoT Alliance to request a change of ownership of the smart terminal in the IoT Alliance.