Key Update Method, Device, Equipment and Storage Medium
By generating and updating the device keys during the intelligent device distribution process, and using the symmetric calculation parameters of the information encryption key and the decryption key, the problem of insufficient identity authentication in the intelligent device distribution network is solved, real-time updated identity authentication is realized, and the security of the AP is improved.
Patent Information
- Application Number
- CN202011114151.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-18
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2040-10-18
AI Technical Summary
In the prior art, the lack of identity authentication during the network distribution process of smart devices leads to the leakage of AP's network configuration information and threatens AP's security.
By generating and updating the device key during the distribution process, using the symmetric calculation parameters of the information encryption key and the information decryption key, identity authentication between the device to be entered and the device cloud platform is realized to ensure the security of network configuration information.
Real-time updated identity authentication is realized, improving the security of the AP, avoiding the proxy device or proxy cloud platform directly using stored information encryption keys, and ensuring effective identity authentication is performed during each network distribution process.
Smart Images

Figure CN114390520B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of communication technologies, and in particular, to a method, apparatus, device, and storage medium for key update. Background Art
[0002] Intelligent devices include devices, instruments, and machines with computing and processing capabilities. Usually, when an intelligent device is used for the first time or when the usage scenario of the intelligent device is changed (such as using the intelligent device in a different network environment), the intelligent device needs to be network-configured so that it can be connected to the network, and then the intelligent device can be controlled through the network.
[0003] Related technologies provide various methods for configuring an intelligent device to access the network, including: QR code network configuration. The main process of QR code network configuration is as follows: the network configuration information of the AP to be accessed is displayed in the form of a QR code by the network configuration device; the intelligent device scans the QR code displayed by the network configuration device to obtain the network configuration information, and then accesses the AP according to the network configuration information to complete the network configuration process.
[0004] However, the above network configuration process does not involve the identity authentication of the intelligent device, so it is very likely that a counterfeit intelligent device obtains the network configuration information of the AP, resulting in the leakage of the network configuration information of the AP and posing a great threat to the security of the AP. Therefore, how to implement the identity authentication of the intelligent device to improve the security of the AP still needs further discussion and research. Summary of the Invention
[0005] The embodiments of the present application provide a method, apparatus, device, and storage medium for key update. The technical solutions are as follows:
[0006] On the one hand, the embodiments of the present application provide a key update method applied to a device to be networked. The method includes:
[0007] Scanning a first graphic code displayed by a network configuration device to obtain first key calculation parameters;
[0008] Updating the current first device key according to the first key calculation parameters to obtain an updated first device key;
[0009] Replacing the current first device key with the updated first device key.
[0010] On the other hand, the embodiments of the present application provide a key update method applied to a network configuration device. The method includes:
[0011] Receive first key calculation parameters from a distribution network cloud platform, where the first key calculation parameters are used to update the device key of a device to be networked;
[0012] Determine a first graphic code based on the first key calculation parameters;
[0013] Display the first graphic code.
[0014] On the other hand, an embodiment of the present application provides a key update method, which is applied to a device cloud platform. The method includes:
[0015] Receive an encrypted key acquisition request from a distribution network cloud platform, where the encrypted key acquisition request is used to request an information encryption key between a distribution network device and a device to be networked;
[0016] Send the information encryption key and first key calculation parameters to the distribution network cloud platform, where the first key calculation parameters are used to update the device key of the device to be networked, and the device key of the device to be networked is used to generate an information decryption key.
[0017] On yet another hand, an embodiment of the present application provides a key update device, which is set in a device to be networked. The device includes:
[0018] A graphic code scanning module, configured to scan a first graphic code displayed by a distribution network device to obtain first key calculation parameters;
[0019] A first key update module, configured to update and process a current first device key according to the first key calculation parameters to obtain an updated first device key;
[0020] A first key replacement module, configured to replace the current first device key with the updated first device key.
[0021] On yet another hand, an embodiment of the present application provides a key update device, which is set in a distribution network device. The device includes:
[0022] An information receiving module, configured to receive first key calculation parameters from a distribution network cloud platform, where the first key calculation parameters are used to update the device key of a device to be networked;
[0023] A graphic code determination module, configured to determine a first graphic code based on the first key calculation parameters;
[0024] A graphic code display module, configured to display the first graphic code.
[0025] On yet another hand, an embodiment of the present application provides a key update device, which is set in a device cloud platform. The device includes:
[0026] A request receiving module, configured to receive an encrypted key acquisition request from a distribution network cloud platform, where the encrypted key acquisition request is used to request an information encryption key between a distribution network device and a device to be networked;
[0027] An information sending module, configured to send the information encryption key and a first key calculation parameter to the distribution network cloud platform, where the first key calculation parameter is used to update the device key of the device to be networked, and the device key of the device to be networked is used to generate an information decryption key.
[0028] On the other hand, an embodiment of the present application provides a device to be networked, including: a processor, and a transceiver connected to the processor; where:
[0029] The processor is configured to scan a first graphic code displayed by the distribution network device to obtain a first key calculation parameter;
[0030] The processor is configured to update the current first device key according to the first key calculation parameter to obtain an updated first device key;
[0031] The processor is configured to replace the current first device key with the updated first device key.
[0032] On the other hand, an embodiment of the present application provides a distribution network device, including: a processor, and a transceiver connected to the processor; where:
[0033] The transceiver is configured to receive a first key calculation parameter from a distribution network cloud platform, where the first key calculation parameter is used to update the device key of the device to be networked;
[0034] The processor is configured to determine a first graphic code based on the first key calculation parameter;
[0035] The processor is configured to display the first graphic code.
[0036] On the other hand, an embodiment of the present application provides a device cloud platform, including: a processor, and a transceiver connected to the processor; where:
[0037] The transceiver is configured to receive an encrypted key acquisition request from a distribution network cloud platform, where the encrypted key acquisition request is used to request an information encryption key between a distribution network device and a device to be networked;
[0038] The transceiver is configured to send the information encryption key and a first key calculation parameter to the distribution network cloud platform, where the first key calculation parameter is used to update the device key of the device to be networked, and the device key of the device to be networked is used to generate an information decryption key.
[0039] On the other hand, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is used to be executed by a processor of a device to be networked to implement the key update method on the side of the device to be networked as described above.
[0040] On the other hand, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is used to be executed by a processor of a network configuration device to implement the key update method on the side of the network configuration device as described above.
[0041] On the other hand, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is used to be executed by a processor of a device cloud platform to implement the key update method on the side of the device cloud platform as described above.
[0042] On the other hand, an embodiment of the present application provides a chip, which includes programmable logic circuits and / or program instructions, and when the chip runs on a device to be networked, it is used to implement the key update method on the side of the device to be networked as described above.
[0043] On the other hand, an embodiment of the present application provides a chip, which includes programmable logic circuits and / or program instructions, and when the chip runs on a network configuration device, it is used to implement the key update method on the side of the network configuration device as described above.
[0044] On the other hand, an embodiment of the present application provides a chip, which includes programmable logic circuits and / or program instructions, and when the chip runs on a device cloud platform, it is used to implement the key update method on the side of the device cloud platform as described above.
[0045] On the other hand, an embodiment of the present application provides a computer program product, which is used to implement the key update method on the side of the device to be networked as described above when the computer program product runs on a device to be networked.
[0046] On the other hand, an embodiment of the present application provides a computer program product, which is used to implement the key update method on the side of the network configuration device as described above when the computer program product runs on a network configuration device.
[0047] On the other hand, an embodiment of the present application provides a computer program product, which is used to implement the key update method on the side of the device cloud platform as described above when the computer program product runs on a device cloud platform.
[0048] The technical solutions provided by the embodiments of the present application may include the following beneficial effects:
[0049] During the process of the device to be networked accessing the AP, the device to be networked and the device cloud platform respectively generate an information decryption key and an information encryption key based on the device key of the device to be networked. After that, the network configuration device encrypts the network configuration information with the information encryption key. When the information decryption key and the information encryption key of the device to be networked are consistent, the device to be networked can successfully obtain the network configuration information and access the AP, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and improving the security of the AP. Moreover, in the embodiment of the present application, after the device to be networked is successfully networked, the device to be networked and the device cloud platform respectively update the device key of the device to be networked. Therefore, in the next network configuration process for the device to be networked, the information encryption key generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from directly using the stored information encryption key by skipping the process of obtaining the information encryption key, achieving the purpose of real-time updated identity authentication and further improving the security of the AP. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0051] Figure 1 is a schematic diagram of a network configuration system provided by an embodiment of the present application;
[0052] Figure 2 is a flowchart of the scan code network configuration provided by an embodiment of the present application;
[0053] Figure 3 is a flowchart of the scan code network configuration including the identity authentication process provided by an embodiment of the present application;
[0054] Figure 4 is a flowchart of the key update method provided by an embodiment of the present application;
[0055] Figure 5 is a flowchart of the identity authentication method during the scan code network configuration provided by an embodiment of the present application;
[0056] Figure 6 is a block diagram of the key update device provided by an embodiment of the present application;
[0057] Figure 7 is a block diagram of the key update device provided by another embodiment of the present application;
[0058] Figure 8It is a block diagram of a key update device provided by another embodiment of the present application;
[0059] Figure 9 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0060] Figure 10 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0061] Figure 11 It is a structural block diagram of a device to be networked provided by an embodiment of the present application;
[0062] Figure 12 It is a structural block diagram of a network configuration device provided by an embodiment of the present application;
[0063] Figure 13 It is a structural block diagram of a device cloud platform provided by an embodiment of the present application. Detailed implementation manners
[0064] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0065] Please refer to Figure 1 , which shows a schematic diagram of a network configuration system provided by an embodiment of the present application. The network configuration system may include: a device 110 to be networked and a network configuration device 120.
[0066] The device 110 to be networked refers to a device with network access capabilities. For example, a device with WiFi (Wireless Fidelity) access capabilities. Optionally, the device 110 to be networked is a smart device (such as a VR (Virtual Reality) glasses, a smart wearable device, etc.), a terminal device, or other devices with network access capabilities. The embodiments of the present application do not limit this. In one example, as Figure 1 shown, when the network configuration system is applied to a smart home life, the device 110 to be networked may be a smart home device such as a smart TV, a smart speaker, a smart air conditioner, a smart light, a smart door and window, a smart curtain, a smart socket, etc. Optionally, the device 110 to be networked is one, or the device 110 to be networked is multiple. The embodiments of the present application do not limit this. In actual applications, the number of devices 110 to be networked may be determined in combination with application requirements or the maximum number of devices that the network configuration device 120 can manage, etc.
[0067] The network configuration device 120 refers to a device with the ability to configure network access. Optionally, the network configuration device 120 can be a server, a terminal device, a router, a terminal device, a mobile phone, a tablet computer, a wearable device, or other devices with the ability to configure network access. The embodiments of the present application do not limit this. In practical applications, the implementation form of the network configuration device 120 can be determined in combination with the application scenario of the network configuration system. In one example, as Figure 1 shown, when the network configuration system is applied to smart home life, considering the characteristics of the home environment such as small area and frequent activities, using a network configuration device 120 that occupies a large space will affect normal home life. The network configuration device 120 can be implemented as a router, a terminal device, a mobile phone, a tablet computer, a wearable device, etc. Optionally, for a certain network configuration system, the number of network configuration devices corresponding to this network configuration system can be one or multiple. The embodiments of the present application do not limit this. Generally, for considerations such as resource conservation, the number of network configuration devices corresponding to a certain network configuration system is one. Optionally, the network configuration devices corresponding to different network configuration systems are different, so that the device to be networked 110 under a certain network configuration system is bound to the network configuration device 120 under this network configuration system. For example, when the network configuration system is implemented as smart home life, taking a family as a unit, the device to be networked in a certain family is bound to the network configuration device of this family.
[0068] In the embodiments of the present application, the network configuration device 120 can configure the device to be networked 110 to access the AP, that is, configure the device to be networked 110 to access the network. In the related art, there are mainly two ways to configure the device to be networked 110 to access the network: soft AP network configuration and QR code scanning network configuration. Below, the QR code scanning network configuration method will be introduced and explained.
[0069] Please refer to Figure 2 , which shows the flowchart of QR code scanning network configuration provided by an embodiment of the present application. As Figure 2 shown, the process of QR code scanning network configuration mainly includes the following steps:
[0070] Step 210, the network configuration device scans the QR code of the device to be networked.
[0071] When the device to be networked has a screen display function, the device to be networked can display the QR code on its screen; when the device to be networked does not have a screen display function, the device manufacturer of the device to be networked can attach a QR code to the device to be networked when it leaves the factory. In the embodiments of the present application, the QR code of the device to be networked indicates the device information of the device to be networked. Optionally, the device information includes at least one of the following: the device type of the device to be networked, the device public key. The network configuration device can obtain the device information of the device to be networked by scanning the QR code of the device to be networked.
[0072] Step 220: The network configuration device generates a QR code according to the network configuration information and displays the QR code.
[0073] The network configuration device can determine the AP to which the device to be networked is connected and determine the network configuration information corresponding to the AP. Optionally, the network configuration information includes at least one of the following: the SSID field of the AP to which the device to be networked is connected, the authentication information of the AP to which the device to be networked is connected. Optionally, the authentication information of the AP to which the device to be networked is connected includes the password of the AP to which the device to be networked is connected. The network configuration device can encrypt the network configuration information according to the device public key of the device to be networked obtained by scanning, and generate a QR code for the device to be networked to scan according to the encrypted network configuration information.
[0074] Step 230: The device to be networked scans the QR code provided by the network configuration device to obtain the network configuration information.
[0075] When the device to be networked scans the QR code provided by the network configuration device, it can obtain the network configuration information provided by the network configuration device. Since the QR code provided by the network configuration device is generated after encrypting the network configuration information with the device public key of the device to be networked, after the device to be networked scans the QR code provided by the network configuration device, the obtained network configuration information is encrypted, and the network configuration information can be obtained by decrypting it with the device public key.
[0076] Step 240: The device to be networked connects to the AP.
[0077] According to the authentication information of the AP obtained by scanning, it can connect to the AP indicated by the network configuration information. After the device to be networked connects to the AP, it can further connect to the cloud platform for authentication and the like.
[0078] It can be seen from the above network configuration process that the above network configuration process does not involve the identity authentication of intelligent devices, so it is very likely that counterfeit intelligent devices obtain the network configuration information of the AP, resulting in the leakage of the network configuration information of the AP and posing a great threat to the security of the AP. Therefore, adding a process related to identity authentication during the network configuration process can effectively avoid the leakage of network configuration information and improve the security of the AP. Next, the method of adding a process related to identity authentication during the network configuration process will be introduced.
[0079] Please refer to Figure 3 , which shows the flowchart of QR code-based network configuration provided by an embodiment of the present application. As Figure 3 shown, the process of QR code-based network configuration mainly includes the following steps:
[0080] Step 301: The network configuration device scans the QR code of the device to be networked.
[0081] When the device to be networked has a screen display function, the device to be networked can display a QR code on its screen; when the device to be networked does not have a screen display function, the device manufacturer of the device to be networked can attach a QR code to the device to be networked when the device to be networked leaves the factory. In the embodiments of the present application, the QR code of the device to be networked indicates the device information of the device to be networked. Optionally, the device information includes at least one of the following: the device type of the device to be networked, the device public key. The network configuration device scans the QR code of the device to be networked and parses the QR code to obtain the device information of the device to be networked.
[0082] Step 302, the network configuration device sends a key acquisition request to the network configuration cloud platform.
[0083] The key acquisition request is used to request to obtain an information encryption key, which is used to encrypt network configuration information, and the network configuration information is used to configure the device to be networked to access the AP. Optionally, as Figure 3 shown, if there is no secure connection established between the network configuration device and the network configuration cloud platform, the network configuration device needs to first establish a secure connection with the network configuration cloud platform, and then send a key acquisition request to the network configuration cloud platform.
[0084] Step 303, the network configuration cloud platform determines the device cloud platform.
[0085] The key acquisition request sent by the network configuration device to the network configuration cloud platform may include the device manufacturer name of the device to be networked. Furthermore, the network configuration cloud platform can determine the corresponding device cloud platform according to the device manufacturer name of the device to be networked.
[0086] Step 304, the network configuration cloud platform sends a key acquisition request to the device cloud platform.
[0087] After the network configuration cloud platform determines the device cloud platform corresponding to the device to be networked, it can forward the key acquisition request sent by the network configuration device to the device cloud platform. Optionally, the key acquisition request includes key calculation parameters and / or the device identifier of the device to be networked. Optionally, as Figure 3 shown, if there is no secure connection established between the network configuration cloud platform and the device cloud platform, the network configuration cloud platform needs to first establish a secure connection with the device cloud platform, and then send a key acquisition request to the device cloud platform.
[0088] Step 305, the device cloud platform calculates the information encryption key.
[0089] After receiving the key acquisition request, the device cloud platform can determine the second device key according to the device identifier of the device to be networked. The second device key is the device key of the device to be networked stored by the device cloud platform. Then, the device cloud platform processes the key calculation parameters and the second device key to obtain the information encryption key.
[0090] Step 306, the device cloud platform sends the information encryption key to the distribution network cloud platform.
[0091] After the device cloud platform calculates the information encryption key, it sends the information encryption key to the distribution network cloud platform in response to the key acquisition request sent by the distribution network cloud platform.
[0092] Step 307, the distribution network cloud platform sends the information encryption key to the distribution network device.
[0093] After receiving the information encryption key, the distribution network cloud platform further forwards the information encryption key to the distribution network device in response to the key acquisition request sent by the distribution network device.
[0094] Step 308, the distribution network device encrypts the network configuration information with the information encryption key to obtain the encrypted network configuration information.
[0095] After the distribution network device obtains the information encryption key, it encrypts the network configuration information with the information encryption key to ensure the security of the network configuration information.
[0096] Step 309, the distribution network device generates a two-dimensional code based on the encrypted network configuration information and displays the two-dimensional code.
[0097] Since the method of scanning the code for network configuration is adopted, after the distribution network device generates the encrypted network configuration information, it needs to generate a two-dimensional code based on the encrypted network configuration information for the device to be networked to scan.
[0098] Step 310, the device to be networked scans the graphic code provided by the distribution network device.
[0099] The device to be networked scans the graphic code provided by the distribution network device to obtain the network configuration information encrypted with the information encryption key. Then, the device to be networked needs to decrypt the encrypted network configuration information to obtain the network configuration information to access the AP.
[0100] Step 311, the device to be networked calculates the information decryption key.
[0101] The information decryption key is used to decrypt the encrypted network configuration information. In the embodiments of the present application, in order to ensure that the information encryption key and the information decryption key are consistent, the information encryption key and the information decryption key need to be obtained using the same calculation parameters and calculation methods. When the information encryption key is calculated from the key calculation parameters and the second device key, the information decryption key is calculated from the key calculation parameters and the first device key. Wherein, the first device key is the device key of the device to be networked stored by the device to be networked. That is, when the first device key and the second device key are consistent, the information decryption key and the information encryption key are also consistent. Furthermore, the device to be networked can use the information decryption key to decrypt the network configuration information and use the network configuration information to access the AP.
[0102] However, in Figure 3 the embodiment, the first device key and the second device key are fixed. After receiving the information encryption key obtained from the first device key, the network configuration cloud platform may save the information encryption key. Subsequently, during the process of network configuration again, the network configuration cloud platform directly sends the previously saved information encryption key to the network configuration device, instead of requesting the information encryption key from the device cloud platform. Therefore, Figure 3 the embodiment may not be able to achieve the purpose of real-time updated identity authentication during each network configuration process, which brings limitations to the improvement of the security of the AP. Based on this, the embodiments of the present application provide a key update method, which can be used for real-time updated identity authentication and fully improve the security of the AP. Next, the technical solutions of the present application will be introduced and described in combination with several embodiments.
[0103] Since Figure 4 the embodiment is an improvement over the above Figure 3 embodiment, for the identity authentication process and the network configuration process not described in the Figure 4 embodiment, reference can be made to the introduction and description of the above Figure 3 embodiment, and details will not be elaborated here.
[0104] Please refer to Figure 4 , which shows a flowchart of the key update method provided by an embodiment of the present application. This method can be applied to the Figure 1 network configuration system shown. This method may include the following steps (steps 410 to 480 and steps 401 to 405):
[0105] Step 410, the network configuration cloud platform sends an encryption key acquisition request to the device cloud platform.
[0106] For a device to be networked with scanning or camera functions, it can also access the network by scanning a code for network configuration. The device to be networked first displays a second graphic code. Optionally, when the device to be networked has a screen display function, the second graphic code is displayed by the device to be networked on its screen; when the device to be networked does not have a screen display function, the second image code can be pasted on the surface of the device to be networked by the device manufacturer of the device to be networked, or pasted on the packaging box of the device to be networked. This application embodiment does not limit this. Optionally, the second graphic code is in the form of a two-dimensional code, a bar code, etc. Optionally, the second graphic code includes the device information of the device to be networked, where the device information of the device to be networked includes at least one of the following: the name of the device manufacturer of the device to be networked, the device ID of the device to be networked, and the second key calculation parameter.
[0107] The second key calculation parameter is used to determine the information encryption key and information decryption key between the network configuration device and the device to be networked. Optionally, the length of the second key calculation parameter is greater than or equal to one byte. For example, the length of the second key calculation parameter is 1 byte; or, the length of the second key calculation parameter is 2 bytes; or, the second key calculation parameter is 3 bytes. In practical applications, the length of the second key calculation parameter can be determined according to the specific content setting of the second key calculation parameter. This application embodiment does not limit this. Optionally, the second key calculation parameter includes a random number, which can be either pre-set or updated in real time. This application embodiment does not limit this. This application embodiment does not limit the determination method of the second key calculation parameter. Optionally, the second key calculation parameter is pre-configured by the device cloud platform; or, the second key calculation parameter is generated by the device to be networked. When the device to be networked does not have a screen display function, the second key calculation parameter can be pre-configured by the device cloud platform corresponding to the device to be networked; when the device to be networked has a screen display function, the second key calculation parameter can be generated by the device to be networked itself.
[0108] In this application embodiment, the device manufacturer of the device to be networked can uniquely allocate a key K to the device to be networked and pre-configure the key K into the device to be networked. Since the device identifier of the device to be networked is used to uniquely identify the device to be networked, there is a one-to-one correspondence between the device identifier of the device to be networked and the key K of the device to be networked. The device manufacturer of the device to be networked can upload the device identifier of the device to be networked and the key K of the device to be networked to the cloud platform of the device manufacturer (that is, the cloud platform corresponding to the device to be networked).
[0109] After the distribution network device scans the graphic code of the device to be networked and obtains the device information of the device to be networked, it further sends an encrypted key acquisition request to the distribution network cloud platform to request the information encryption key between the distribution network device and the device to be networked. The content of the encrypted key acquisition request is not limited in the embodiments of the present application. Optionally, the encrypted key acquisition request includes the device information of the device to be networked; or, the encrypted key acquisition request further includes the device manufacturer name of the device to be networked, the device name of the device to be networked, the product serial number of the device to be networked, etc. Optionally, if there is no secure connection established between the distribution network device and the distribution network cloud platform, the distribution network device needs to first establish a secure connection with the distribution network cloud platform and then send an encrypted key acquisition request to the distribution network cloud platform.
[0110] After receiving the encrypted key acquisition request, the distribution network cloud platform further sends the encrypted key acquisition request to the device cloud platform. In the embodiments of the present application, the distribution network cloud platform needs to first determine the device cloud platform corresponding to the device to be networked. Optionally, the encrypted key acquisition request sent by the distribution network device to the distribution network cloud platform includes the device manufacturer name of the device to be networked, and then the distribution network cloud platform can determine the corresponding device cloud platform according to the device manufacturer name of the device to be networked. Optionally, if there is no secure connection established between the distribution network cloud platform and the device cloud platform, the distribution network cloud platform needs to first establish a secure connection with the device cloud platform and then send an encrypted key acquisition request to the device cloud platform.
[0111] Step 420, the device cloud platform sends an information encryption key and a first key calculation parameter to the distribution network cloud platform. The first key calculation parameter is used to update the device key of the device to be networked, and the device key of the device to be networked is used to generate an information decryption key.
[0112] As can be seen from the above introduction, since the device key of the device to be networked can be used to uniquely identify the device to be networked, and the device key of the device to be networked is both pre-set in the device to be networked and stored in the device cloud platform, during the process of configuring the device to be networked to access the first access point, identity authentication can be performed based on the device key of the device to be networked. However, if the device key of the device to be networked remains unchanged all the time, the information encryption key generated based on the device key of the device to be networked may also remain unchanged. During the process of configuring the device to be networked to access the first access point multiple times, the proxy device or proxy cloud platform between the device to be networked and the device cloud platform may directly use the previously stored information encryption key without requesting the information encryption key from the device cloud platform every time the device to be networked is configured to access the first access point. Such skipping the acquisition of the information encryption key will bring limitations to the improvement of the security of the AP. Therefore, the embodiments of the present application propose to update the device key of the device to be networked during the process of configuring the device to be networked to access the first access point, so as to achieve the purpose of updating the information encryption key and the information decryption key.
[0113] In an embodiment of the present application, the device key of the device to be networked is updated using the first key calculation parameter. Optionally, the length of the first key calculation parameter is greater than or equal to one byte. For example, the length of the first key calculation parameter is 1 byte; or, the length of the first key calculation parameter is 2 bytes; or, the length of the first key calculation parameter is 3 bytes. In practical applications, the length of the first key calculation parameter can be determined according to the specific content setting of the first key calculation parameter, and the embodiments of the present application do not limit this. Optionally, the first key calculation parameter includes a random number, which can be either pre-set or updated in real time, and the embodiments of the present application do not limit this.
[0114] In one example, the first key calculation parameter is generated by the device cloud platform (the cloud platform corresponding to the device to be networked). Based on this, in order to enable the device to be networked to update the device key, the device cloud platform needs to send the first key calculation parameter to the device to be networked. Before configuring the device to be networked to access the first access point, the information transmission between the device cloud platform and the device to be networked needs to pass through the network configuration cloud platform and the network configuration device. Therefore, the device cloud platform needs to first send the information encryption key and the first key calculation parameter to the network configuration cloud platform (the cloud platform corresponding to the first access point).
[0115] Step 430, the network configuration cloud platform sends the information encryption key and the first key calculation parameter to the network configuration device.
[0116] After receiving the information encryption key and the first key calculation parameter, the network configuration cloud platform further forwards the information encryption key and the first key calculation parameter to the network configuration device.
[0117] Step 440, the network configuration device determines the first graphic code based on the first key calculation parameter.
[0118] Since the network configuration device configures the device to be networked by scanning the code for network configuration, after obtaining the information encryption key and the first key calculation parameter, the network configuration device needs to further display the first graphic code for the device to be networked to scan and obtain the first key calculation parameter. Optionally, the above method further includes: the network configuration device processes the first key calculation parameter using the first encryption algorithm and the information encryption key to obtain the encrypted configuration information; and generates the first graphic code according to the encrypted configuration information.
[0119] Among them, while encrypting the first key calculation parameter, the distribution network device can also encrypt the network configuration information. That is, in the embodiments of the present application, the information encryption key is used to encrypt the network configuration information and the first key calculation parameter. That is, the distribution network device can use the first encryption algorithm and the information encryption key to process the network configuration information and the first key calculation parameter to obtain the encrypted network configuration information and the encrypted first key calculation parameter, and then generate the first graphic code according to the encrypted network configuration information and the encrypted first key calculation parameter. Optionally, the first encryption algorithm is a symmetric encryption algorithm. Optionally, the first encryption algorithm includes but is not limited to any one of the following: AES (Advanced Encryption Standard) 128-CMAC (Cypher-Based Message Authentication Code), AES128-CBC (Cipher Block Chaining), AES128-GCM (Galois / Counter Mode), AES256-CMAC, AES256-CBC, AES256-GCM.
[0120] Step 450, the distribution network device displays the first graphic code.
[0121] After generating the first graphic code, the distribution network device can display the first graphic code for the device to be networked to scan.
[0122] Step 460, the device to be networked scans the first graphic code displayed by the distribution network device to obtain the first key calculation parameter.
[0123] When the device to be networked scans the first image code, it can obtain the network configuration information and the first key calculation parameter encrypted with the information encryption key. Since the device to be networked determines the information decryption key itself, the device to be networked decrypts the network configuration information and the first key calculation parameter with the information decryption key. Optionally, when the information decryption key is the same as the information encryption key, the device to be networked successfully obtains the network configuration information and the first key calculation parameter; when the information decryption key is different from the information encryption key, the device to be networked fails to obtain the network configuration information and the first key calculation parameter.
[0124] Step 470, the device to be networked updates the current first device key according to the first key calculation parameter to obtain the updated first device key.
[0125] In the embodiments of the present application, the device key of the device to be networked pre - set in the device to be networked is referred to as the first device key. After the device to be networked obtains the first key calculation parameter, it can update the current first device key according to the first key calculation parameter to obtain the updated first device key.
[0126] In one example, the device to be networked can use a key generation algorithm to process the first key calculation parameter and the current first device key to obtain the updated first device key. Based on this, step 470 includes: the device to be networked uses the first key generation algorithm to process the first key calculation parameter and the current first device key to obtain the updated first device key. Optionally, the first key generation algorithm includes any one of the following: AES128 - CMAC, HKDF (HMAC (Hash - based Message Authentication Code) - based KDF (Key Derivation Function), key derivation function based on HMAC), PBKDF (Password - Based Key Derivation Function), SHA (Secure Hash Algorithm), DES (Data Encryption Standard) algorithm, 3DES (Triple DES) algorithm.
[0127] Step 480, the device to be networked replaces the current first device key with the updated first device key.
[0128] After the device to be networked updates the current first device key, it immediately replaces the current first device key with the updated first device key. Thus, the information decryption key determined based on the first device key can also be updated, avoiding the process that the network configuration cloud platform and / or the network configuration device skips obtaining the information encryption key, effectively improving the security of the AP.
[0129] During the process of identity authentication, by generating consistent information encryption keys and information decryption keys between the device to be networked and the device cloud platform, it is ensured that the device to be networked can decrypt the network configuration information encrypted with the information encryption key using the information decryption key, so as to pass the identity authentication. Therefore, the device to be networked and the device cloud platform need to generate information decryption keys and information encryption keys respectively. Therefore, the device key of the device to be networked needs to be updated both at the device to be networked and the device cloud platform to ensure that the information decryption keys and information encryption keys respectively generated by the device to be networked and the device cloud platform can be consistent. Based on this, as Figure 4As shown, in one example, the above method further includes the following steps:
[0130] Step 401, the device cloud platform updates the current second device key according to the first key calculation parameter to obtain the updated second device key.
[0131] In the embodiment of the present application, the device key of the device to be networked stored in the device cloud platform is referred to as the second device key. After the device cloud platform generates the first key calculation parameter, it immediately updates the current second device key according to the first key calculation parameter to obtain the updated second device key.
[0132] In one example, the device cloud platform may use a key generation algorithm to process the first key calculation parameter and the current second device key to obtain the updated second device key. In addition, in order to ensure that the device keys separately updated by the device to be networked and the device cloud platform are consistent, the device to be networked and the device cloud platform should use the same key generation algorithm and key calculation parameter to update the device key of the device to be networked. Based on this, the above step 501 includes: the device cloud platform uses the first key generation algorithm to process the first key calculation parameter and the current second device key to obtain the updated second device key. Optionally, the first key generation algorithm includes any one of: AES128-CMAC, HKDF-based KDF, PBKDF, SHA, DES algorithm, 3DES algorithm.
[0133] Step 402, the device cloud platform stores the updated second device key.
[0134] After the device cloud platform obtains the updated second device key, it first stores the updated second device key. Optionally, the device cloud platform stores the updated second device key in the cache to avoid occupying the memory storage space of the device cloud platform.
[0135] Step 403, when the device to be networked is connected to the first access point, it sends the first identity authentication result to the network configuration cloud platform, and the first identity authentication result is used to indicate that the identity authentication for the device cloud platform has passed.
[0136] Since the device to be networked can obtain network configuration information and access the first access point only when the information decryption key is the same as the information encryption key, that is, when the identity authentication is passed, the access of the device to be networked to the first access point indicates that the identity authentication for the device to be networked has passed. In addition, after the device to be networked accesses the first access point, a secure connection can be established with the network configuration cloud platform. Therefore, in the embodiments of the present application, after the device to be networked accesses the first access point, it can send a first identity authentication result to the network configuration cloud platform to indicate that the identity authentication for the device cloud platform has passed.
[0137] Step 404: The network configuration cloud platform sends the first identity authentication result to the device cloud platform.
[0138] When the network configuration cloud platform receives the first identity authentication result, it further forwards the first identity authentication result to the device cloud platform.
[0139] Step 405: The device cloud platform replaces the current second device key with the updated second device key.
[0140] When the device cloud platform receives the first identity authentication result, it is clear that the device to be networked has accessed the first access point. And since the device to be networked updates the first device key after accessing the first access point, in order to synchronize the key update between the device cloud platform and the device to be networked, after receiving the first identity authentication result, the device cloud platform replaces the current second device key with the second device key stored in the cache to implement the update process of the second device key.
[0141] During the process of configuring the device to be networked to access the first access point, due to various reasons, the device cloud platform may not receive the results related to identity authentication, such as network disconnection, identity authentication failure, etc. In this case, the device to be networked cannot update the first device key and keeps the current first device key. To ensure that the device keys of the device cloud platform and the device to be networked are consistent, the device cloud platform should also keep the current second device key in this case. Based on this, after the above step 402, it further includes: when the device cloud platform does not receive the first identity authentication result from the network configuration cloud platform within a preset time interval, it deletes the updated second device key. Wherein, the start time of the preset time interval includes the generation time of the updated second device key and the time after the generation time of the updated second device key; or, the start time of the preset time interval includes the sending time of the first key calculation parameter and the time after the sending time of the first key calculation parameter.
[0142] In summary, the technical solution provided by the embodiments of the present application, during the process of a device to be networked accessing an AP, the device to be networked and the device cloud platform respectively generate an information decryption key and an information encryption key based on the device key of the device to be networked. After that, the network configuration device encrypts network configuration information with the information encryption key. When the information decryption key and the information encryption key of the device to be networked are consistent, the device to be networked can successfully obtain the network configuration information and access the AP, achieving the purpose of identity authentication between the device to be networked and the device cloud platform, and improving the security of the AP. Moreover, in the embodiments of the present application, after successful network configuration for the device to be networked, the device to be networked and the device cloud platform respectively update the device key of the device to be networked. Therefore, in the next network configuration process for the device to be networked, the information encryption key generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining the information encryption key and directly using the stored information encryption key, achieving the purpose of real-time updated identity authentication and further improving the security of the AP.
[0143] Taking the first access point as a home WiFi network as an example, the method for identity authentication during QR code scanning for network configuration will be introduced and described as follows. As Figure 5 shown, the method for identity authentication during QR code scanning for network configuration provided by the embodiments of the present application includes the following steps:
[0144] Step 501, the network configuration device scans the second QR code of the device to be networked. The second QR code includes the device information of the device to be networked. Optionally, the device information of the device to be networked includes at least one of the following: the device manufacturer name of the device to be networked, the device ID of the device to be networked, and a second random number.
[0145] Step 502, the network configuration device parses the second QR code. By parsing the second QR code, the network configuration device can obtain the device information of the device to be networked.
[0146] Step 503, the network configuration device sends an encryption key acquisition request to the network configuration cloud platform. The encryption key acquisition request is used to request the acquisition of the information encryption key. The encryption key acquisition request includes the device information of the device to be networked. Optionally, as Figure 5 shown, if no secure connection is established between the network configuration device and the network configuration cloud platform, the network configuration device needs to first establish a secure connection with the network configuration cloud platform and then send an encryption key acquisition request to the network configuration cloud platform.
[0147] Step 504, the network configuration cloud platform determines the device cloud platform. The encryption key acquisition request sent by the network configuration device to the network configuration cloud platform includes the device manufacturer name of the device to be networked. Thus, the network configuration cloud platform can determine the corresponding device cloud platform based on the device manufacturer name of the device to be networked.
[0148] Step 505, the network configuration cloud platform sends a request for obtaining an encryption key to the device cloud platform. This request for obtaining an encryption key is used to request the acquisition of an information encryption key. Optionally, the request for obtaining an information encryption key includes the device information of the device to be networked. Optionally, as Figure 5 shown, if there is no secure connection established between the network configuration cloud platform and the device cloud platform, the network configuration cloud platform needs to first establish a secure connection with the device cloud platform and then send a request for obtaining an encryption key to the device cloud platform.
[0149] Step 506, the device cloud platform determines the second device key. Since the request for obtaining an encryption key includes the device information of the device to be networked, and the device information of the device to be networked includes the device ID of the device to be networked, the device cloud platform can obtain the stored second device key corresponding to the device to be networked according to the device ID of the device to be networked.
[0150] Step 507, the device cloud platform determines the information encryption key according to the second device key and the second random number. After receiving the request for obtaining an encryption key, the device cloud platform can determine the second device key based on the device ID of the device to be networked. Then, the device cloud platform processes the second random number and the second device key using a key generation algorithm to obtain the information encryption key.
[0151] Step 508, the device cloud platform generates a first random number and updates the second device key according to the first random number to obtain an updated second device key. After obtaining the updated second device key, the device cloud platform can cache the updated second device key. Then, within a preset time interval, if the reported information indicating that the identity authentication of the device to be networked has passed is not received, the cached updated second device key is deleted.
[0152] Step 509, the device cloud platform sends the information encryption key and the first random number to the network configuration cloud platform.
[0153] Step 510, the network configuration cloud platform sends the information encryption key and the first random number to the network configuration device.
[0154] Step 511, the network configuration device generates encrypted configuration information according to the information encryption key, the network configuration information, and the first random number. Optionally, the network configuration device encrypts the network configuration information and the first random number using the information encryption key to obtain the encrypted configuration information, which includes the encrypted network configuration information and the encrypted first random number.
[0155] Step 512, the network configuration device generates a first graphic code according to the encrypted configuration information and displays the first graphic code.
[0156] Step 513: The device to be networked scans the first graphic code. By scanning the first image code, the device to be networked can obtain the network configuration information encrypted with the information encryption key and the first random number.
[0157] Step 514: The device to be networked determines the information decryption key according to the first device key and the second random number. The device to be networked decrypts the network configuration information and the first random number with the information decryption key. When the information decryption key is consistent with the information encryption key, the device to be networked successfully obtains the network configuration information and the first random number; when the information decryption key is inconsistent with the information encryption key, the device to be networked fails to obtain the network configuration information and the first random number.
[0158] Step 515: When the information decryption key is consistent with the information encryption key, the device to be networked updates the first device key according to the first random number to obtain the updated first device key, and replaces the first device key with the updated first device key.
[0159] Step 516: The device to be networked sends the first identity authentication result to the network configuration cloud platform. As Figure 5 shown, after the device to be networked accesses the home WiFi network, it can establish a secure connection with the network configuration cloud platform. After that, the device to be networked can send the first identity authentication result to the network configuration cloud platform to indicate that the identity authentication for the device cloud platform has passed.
[0160] Step 517: The network configuration cloud platform sends the first identity authentication result to the device cloud platform.
[0161] Step 518: The device cloud platform replaces the second device key with the updated second device key. Optionally, the first identity authentication result includes the device ID of the device to be networked. The device cloud platform can determine the updated second device key corresponding to the device to be networked in the cache according to the device ID of the device to be networked, and replaces the second device key with the updated second device key.
[0162] It should be noted that the embodiments of the present application introduce the key update method provided by the embodiments of the present application from the perspective of the interaction among the device to be networked, the network configuration device, the network configuration cloud platform, and the device cloud platform. The steps performed by the device to be networked as described above can be independently implemented as a key update method on the side of the device to be networked; the steps performed by the network configuration device as described above can be independently implemented as a key update method on the side of the network configuration device; the steps performed by the network configuration cloud platform as described above can be independently implemented as a key update method on the side of the network configuration cloud platform; the steps performed by the device cloud platform as described above can be independently implemented as a key update method on the side of the device cloud platform.
[0163] The following is an apparatus embodiment of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the apparatus embodiment of the present application, please refer to the method embodiment of the present application.
[0164] Please refer to Figure 6 , which shows a block diagram of a key update apparatus provided by an embodiment of the present application. This apparatus has the function of implementing the method example on the side of the device to be networked as described above, and this function can be implemented by hardware or by hardware executing corresponding software. This apparatus can be the device to be networked introduced above, or can be provided in the device to be networked. As Figure 6 shown, the apparatus 600 may include: a graphic code scanning module 610, a first key update module 620, and a first key replacement module 620.
[0165] The graphic code scanning module 610 is configured to scan a first graphic code displayed by a network configuration device to obtain first key calculation parameters.
[0166] The first key update module 620 is configured to update the current first device key according to the first key calculation parameters to obtain an updated first device key.
[0167] The first key replacement module 630 is configured to replace the current first device key with the updated first device key.
[0168] In one example, the first key update module 620 is configured to: process the first key calculation parameters and the current first device key by using a first key generation algorithm to obtain the updated first device key.
[0169] In one example, the length of the first key calculation parameters is greater than or equal to one byte.
[0170] In one example, the first key calculation parameters include random numbers.
[0171] In one example, the first key calculation parameters are generated by a device cloud platform.
[0172] In one example, the first graphic code includes the first key calculation parameters encrypted by an information encryption key; when the information decryption key is the same as the information encryption key, the device to be networked successfully obtains the first key calculation parameters; when the information decryption key is different from the information encryption key, the device to be networked fails to obtain the first key calculation parameters.
[0173] In one example, as Figure 7As shown, the device 600 further includes: an authentication result sending module 640, configured to send a first identity authentication result to the network configuration cloud platform when accessing a first access point, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed.
[0174] In summary, for the technical solution provided in the embodiment of the present application, during the process of a device to be networked accessing an AP, the device to be networked and the device cloud platform respectively generate an information decryption key and an information encryption key based on the device key of the device to be networked. Then, the network configuration device encrypts network configuration information, etc. with the information encryption key. When the information decryption key and the information encryption key of the device to be networked are consistent, the device to be networked can successfully obtain the network configuration information and access the AP, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and enhancing the security of the AP. Moreover, in the embodiment of the present application, after the device to be networked is successfully network-configured, the device to be networked and the device cloud platform respectively update the device key of the device to be networked. Therefore, in the next network configuration process for the device to be networked, the information encryption key generated based on the device key can also be updated, preventing a proxy device or proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining the information encryption key and directly using the stored information encryption key, achieving the purpose of real-time updated identity authentication and further enhancing the security of the AP.
[0175] Please refer to Figure 8 , which shows a block diagram of a key update device provided in an embodiment of the present application. This device has the functions of implementing the method example on the network configuration device side. The functions can be implemented by hardware or by hardware executing corresponding software. This device can be the network configuration device introduced above or can be set in the network configuration device. As Figure 8 shown, the device 800 may include: an information receiving module 810, a graphic code determining module 820, and a graphic code displaying module 830.
[0176] The information receiving module 810 is configured to receive first key calculation parameters from the network configuration cloud platform, where the first key calculation parameters are used to update the device key of the device to be networked.
[0177] The graphic code determining module 820 is configured to determine a first graphic code based on the first key calculation parameters.
[0178] The graphic code displaying module 830 is configured to display the first graphic code.
[0179] In one example, the graphic code determining module 820 is configured to: process the first key calculation parameters using a first encryption algorithm and an information encryption key to obtain encrypted configuration information; and generate the first graphic code according to the encrypted configuration information.
[0180] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0181] In one example, the first key calculation parameter includes a random number.
[0182] In one example, the first key calculation parameter is generated by the device cloud platform.
[0183] In summary, the technical solution provided by the embodiments of the present application, during the process of a device to be networked accessing an AP, the device to be networked and the device cloud platform respectively generate an information decryption key and an information encryption key based on the device key generation information of the device to be networked. After that, the network configuration device encrypts the network configuration information with the information encryption key. When the information decryption key and the information encryption key of the device to be networked are consistent, the device to be networked can successfully obtain the network configuration information and access the AP, achieving the purpose of identity authentication between the device to be networked and the device cloud platform, and improving the security of the AP. Moreover, in the embodiments of the present application, after the device to be networked is successfully networked, the device to be networked and the device cloud platform respectively update the device key of the device to be networked. Therefore, in the next network configuration process for the device to be networked, the information encryption key generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from directly using the stored information encryption key by skipping the process of obtaining the information encryption key, achieving the purpose of real-time updated identity authentication and further improving the security of the AP.
[0184] Please refer to Figure 9 , which shows a block diagram of a key update device provided by an embodiment of the present application. This device has the function of implementing the method example on the device cloud platform side. The function can be implemented by hardware or by hardware executing corresponding software. This device can be the device cloud platform introduced above or can be set in the device cloud platform. As Figure 9 shown, the device 900 may include: a request receiving module 910 and an information sending module 920.
[0185] The request receiving module 910 is configured to receive an encrypted key acquisition request from the network configuration cloud platform, where the encrypted key acquisition request is used to request to obtain the information encryption key between the network configuration device and the device to be networked.
[0186] The information sending module 920 is configured to send the information encryption key and the first key calculation parameter to the network configuration cloud platform. The first key calculation parameter is used to update the device key of the device to be networked, and the device key of the device to be networked is used to generate the information decryption key.
[0187] In one example, as Figure 10As shown, the device 900 further includes: a second key update module 930, configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key; and a second key storage module 940, configured to store the updated second device key.
[0188] In one example, as Figure 10 shown, the second key update module 930 is configured to: process the first key calculation parameter and the current second device key by using a first key generation algorithm to obtain the updated second device key.
[0189] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0190] In one example, the first key calculation parameter includes a random number.
[0191] In one example, the first key calculation parameter is generated by the device cloud platform.
[0192] In one example, as Figure 10 shown, the device 900 further includes: an authentication result receiving module 950, configured to receive a first identity authentication result from the network configuration cloud platform, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed.
[0193] In one example, as Figure 10 shown, the device 900 further includes: a second key replacement module 960, configured to replace the current second device key with the updated second device key.
[0194] In one example, as Figure 10 shown, the device 900 further includes: a second key deletion module 970, configured to delete the updated second device key when the first identity authentication result from the network configuration cloud platform is not received within a preset time interval, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed; where the starting moment of the preset time interval includes the generation moment of the updated second device key and the moments after the generation moment of the updated second device key; or, the starting moment of the preset time interval includes the sending moment of the first key calculation parameter and the moments after the sending moment of the first key calculation parameter.
[0195] In summary, in the technical solution provided by the embodiment of the present application, during the process of a device to be networked accessing an AP, the device to be networked and the device cloud platform respectively generate an information decryption key and an information encryption key based on the device key of the device to be networked. After that, the network configuration device encrypts network configuration information, etc., with the information encryption key. When the information decryption key and the information encryption key of the device to be networked are consistent, the device to be networked can successfully obtain the network configuration information and access the AP, achieving the purpose of identity authentication between the device to be networked and the device cloud platform, and improving the security of the AP. Moreover, in the embodiment of the present application, after the device to be networked is successfully networked, the device to be networked and the device cloud platform respectively update the device key of the device to be networked. Thus, in the next network configuration process for the device to be networked, the information encryption key generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining the information encryption key and directly using the stored information encryption key, achieving the purpose of real-time updated identity authentication and further improving the security of the AP.
[0196] It should be noted that when the device provided in the above embodiment realizes its functions, only the division of the above-mentioned various functional modules is used for illustration. In practical applications, the above functions can be allocated to different functional modules according to actual needs, that is, the content structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0197] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment related to the method, and will not be elaborated here.
[0198] Please refer to Figure 11 , which shows a schematic structural diagram of a device 110 to be networked provided by an embodiment of the present application. For example, the device to be networked can be used to execute the above-mentioned method for updating the key on the device to be networked side. Specifically, the device 110 to be networked may include: a processor 111, and a transceiver 112 connected to the processor 111; where:
[0199] The processor 111 includes one or more processing cores. The processor 111 executes various functional applications and information processing by running software programs and modules.
[0200] The transceiver 112 includes a receiver and a transmitter. Optionally, the transceiver 112 is a communication chip.
[0201] In one example, the device to be networked 110 further includes: a memory and a bus. The memory is connected to the processor through the bus. The memory can be used to store a computer program, and the processor is used to execute the computer program to implement each step performed by the device to be networked in the above method embodiments.
[0202] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof. Volatile or non-volatile storage devices include, but are not limited to: RAM (Random-Access Memory), ROM (Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other solid-state storage technologies, CD-ROM (Compact Disc Read-Only Memory), DVD (Digital Video Disc) or other optical storage, cassette tapes, magnetic tapes, disk storage or other magnetic storage devices. Among them:
[0203] The processor 111 is configured to scan the first graphic code displayed by the network configuration device to obtain the first key calculation parameter.
[0204] The processor 111 is configured to update the current first device key according to the first key calculation parameter to obtain an updated first device key.
[0205] The processor 111 is configured to replace the current first device key with the updated first device key.
[0206] In one example, the processor 111 is configured to process the first key calculation parameter and the current first device key using a first key generation algorithm to obtain the updated first device key.
[0207] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0208] In one example, the first key calculation parameter includes a random number.
[0209] In one example, the first key calculation parameter is generated by the device cloud platform.
[0210] In one example, the first graphic code includes the first key calculation parameter encrypted by an information encryption key; when the information decryption key is the same as the information encryption key, the device to be networked successfully obtains the first key calculation parameter; when the information decryption key is different from the information encryption key, the device to be networked fails to obtain the first key calculation parameter.
[0211] In one example, the transceiver 112 is configured to send a first identity authentication result to the network configuration cloud platform when accessing a first access point, and the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed.
[0212] Please refer to Figure 12 , which shows a schematic structural diagram of the network configuration device 120 provided by an embodiment of the present application. For example, this network configuration device can be used to execute the above-mentioned network configuration device-side key update method. Specifically, the network configuration device 120 may include: a processor 121, and a transceiver 122 connected to the processor 121; wherein:
[0213] The processor 121 includes one or more processing cores. The processor 121 executes various functional applications and information processing by running software programs and modules.
[0214] The transceiver 122 includes a receiver and a transmitter. Optionally, the transceiver 122 is a communication chip.
[0215] In one example, the network configuration device 120 further includes: a memory and a bus. The memory is connected to the processor through the bus. The memory can be used to store a computer program, and the processor is used to execute the computer program to implement each step performed by the network configuration device in the above method embodiments.
[0216] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage device includes but is not limited to: RAM and ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, tape cassette, tape, magnetic disk storage or other magnetic storage devices. Wherein:
[0217] The transceiver 122 is configured to receive a first key calculation parameter from the network configuration cloud platform, and the first key calculation parameter is used to update the device key of the device to be networked.
[0218] The processor 121 is configured to determine a first graphic code based on the first key calculation parameter.
[0219] The processor 121 is configured to display the first graphic code.
[0220] In one example, the processor 121 is configured to process the first key calculation parameter by using a first encryption algorithm and an information encryption key to obtain encrypted configuration information; and generate the first graphic code according to the encrypted configuration information.
[0221] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0222] In one example, the first key calculation parameter includes a random number.
[0223] In one example, the first key calculation parameter is generated by the device cloud platform.
[0224] Please refer to Figure 13 , which shows a schematic structural diagram of the device cloud platform 130 provided in an embodiment of the present application. For example, the device cloud platform can be used to execute the above-mentioned key update method on the device cloud platform side. Specifically, the device cloud platform 130 may include: a processor 131 and a transceiver 132 connected to the processor 131; wherein:
[0225] The processor 131 includes one or more processing cores. The processor 131 executes various functional applications and information processing by running software programs and modules.
[0226] The transceiver 132 includes a receiver and a transmitter. Optionally, the transceiver 132 is a communication chip.
[0227] In one example, the device cloud platform 130 further includes: a memory and a bus. The memory is connected to the processor through the bus. The memory can be used to store computer programs, and the processor is configured to execute the computer programs to implement the various steps executed by the device cloud platform in the above method embodiments.
[0228] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage device includes, but is not limited to: RAM and ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, tape cassette, tape, magnetic disk storage or other magnetic storage devices. Wherein:
[0229] The transceiver 132 is configured to receive an encrypted key acquisition request from the network configuration cloud platform, and the encrypted key acquisition request is used to request to obtain an information encryption key between the network configuration device and the device to be networked.
[0230] The transceiver 132 is configured to send the information encryption key and the first key calculation parameter to the power distribution cloud platform. The first key calculation parameter is used to update the device key of the device to be networked, and the device key of the device to be networked is used to generate an information decryption key.
[0231] In one example, the processor 131 is configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key, and store the updated second device key.
[0232] In one example, the processor 131 is configured to process the first key calculation parameter and the current second device key by using a first key generation algorithm to obtain the updated second device key.
[0233] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0234] In one example, the first key calculation parameter includes a random number.
[0235] In one example, the first key calculation parameter is generated by the device cloud platform.
[0236] In one example, the transceiver 132 is configured to receive a first identity authentication result from the power distribution cloud platform, and the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed.
[0237] In one example, the processor 131 is configured to replace the current second device key with the updated second device key.
[0238] In one example, the processor 131 is configured to delete the updated second device key when the first identity authentication result from the power distribution cloud platform is not received within a preset time interval. The first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed. Wherein, the start time of the preset time interval includes the generation time of the updated second device key and the time after the generation time of the updated second device key; or, the start time of the preset time interval includes the sending time of the first key calculation parameter and the time after the sending time of the first key calculation parameter.
[0239] An embodiment of the present application further provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium and is configured to be executed by a processor of a device to be networked to implement the key update method on the device to be networked side as described above.
[0240] An embodiment of the present application further provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium and is used to be executed by a processor of a device to be networked to implement the key update method on the device to be networked side as described above.
[0241] An embodiment of the present application further provides a computer-readable storage medium. A computer program is stored in the computer-readable storage medium and is used to be executed by a processor of a device cloud platform to implement the key update method on the device cloud platform side as described above.
[0242] An embodiment of the present application further provides a chip. The chip includes programmable logic circuits and / or program instructions. When the chip runs on a device to be networked, it is used to implement the key update method on the device to be networked side as described above.
[0243] An embodiment of the present application further provides a chip. The chip includes programmable logic circuits and / or program instructions. When the chip runs on a device to be networked, it is used to implement the key update method on the device to be networked side as described above.
[0244] An embodiment of the present application further provides a chip. The chip includes programmable logic circuits and / or program instructions. When the chip runs on a device cloud platform, it is used to implement the key update method on the device cloud platform side as described above.
[0245] An embodiment of the present application further provides a computer program product. When the computer program product runs on a device to be networked, it is used to implement the key update method on the device to be networked side as described above.
[0246] An embodiment of the present application further provides a computer program product. When the computer program product runs on a device to be networked, it is used to implement the key update method on the device to be networked side as described above.
[0247] An embodiment of the present application further provides a computer program product. When the computer program product runs on a device cloud platform, it is used to implement the key update method on the device cloud platform side as described above.
[0248] Those skilled in the art should be able to realize that in one or more of the above examples, the functions described in the embodiments of the present application can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer storage media and communication media, where the communication media includes any medium that facilitates the transmission of a computer program from one place to another. The storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0249] The foregoing are only exemplary embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the protection scope of the present application.
Claims
1. A key update method, characterized in that, Applied to a device to be networked, the method includes: Scanning a first graphic code displayed by a network configuration device to obtain encrypted network configuration information and encrypted first key calculation parameters; wherein, the first graphic code is generated according to the encrypted network configuration information and the encrypted first key calculation parameters, and both the encrypted network configuration information and the encrypted first key calculation parameters are encrypted using an information encryption key; Decrypting the encrypted network configuration information and the encrypted first key calculation parameters using an information decryption key to obtain network configuration information and first key calculation parameters; wherein, the information decryption key is calculated based on the current first device key; Using the network configuration information to access a first access point; Updating the current first device key according to the first key calculation parameters to obtain an updated first device key; Replacing the current first device key with the updated first device key.
2. The method according to claim 1, characterized in that, The updating the current first device key according to the first key calculation parameters to obtain an updated first device key includes: Processing the first key calculation parameters and the current first device key using a first key generation algorithm to obtain the updated first device key.
3. The method according to claim 1 or 2, characterized in that, The length of the first key calculation parameters is greater than or equal to one byte.
4. The method according to claim 1 or 2, characterized in that, The first key calculation parameters include random numbers.
5. The method according to claim 1 or 2, characterized in that, The first key calculation parameters are generated by a device cloud platform.
6. The method according to claim 1 or 2, wherein When the information decryption key and the information encryption key are the same, the device to be networked successfully obtains the first key calculation parameters; When the information decryption key and the information encryption key are different, the device to be networked fails to obtain the first key calculation parameters.
7. The method according to claim 1 or 2, characterized in that, The method further includes: When accessing the first access point, sending a first identity authentication result to the network configuration cloud platform, and the first identity authentication result is used to indicate that the identity authentication for the device cloud platform has passed.
8. A key update method, characterized in that, Applied to a network configuration device, the method includes: Receiving an information encryption key and first key calculation parameters from a network configuration cloud platform, the first key calculation parameters being used to update the device key of a device to be networked, the device key of the device to be networked being used to generate an information decryption key, and the information decryption key being used to decrypt the encrypted network configuration information and the encrypted first key calculation parameters; Encrypting the network configuration information and the first key calculation parameters using the information encryption key to obtain the encrypted network configuration information and the encrypted first key calculation parameters, and the network configuration information is used to configure the device to be networked to access a first access point; Generating a first graphic code according to the encrypted network configuration information and the encrypted first key calculation parameters; Displaying the first graphic code.
9. The method according to claim 8, wherein The encrypting the network configuration information and the first key calculation parameters using the information encryption key to obtain the encrypted network configuration information and the encrypted first key calculation parameters includes: Process the network configuration information and the first key calculation parameter by using a first encryption algorithm and the information encryption key to obtain the encrypted network configuration information and the encrypted first key calculation parameter.
10. The method according to claim 8 or 9, characterized in that, The length of the first key calculation parameter is greater than or equal to one byte.
11. The method according to claim 8 or 9, characterized in that, The first key calculation parameter includes a random number.
12. The method according to claim 8 or 9, characterized in that The first key calculation parameter is generated by the device cloud platform.
13. A key update method, characterized in that Applied to the device cloud platform, the method includes: Receive an encryption key acquisition request from the network configuration cloud platform, where the encryption key acquisition request is used to request the information encryption key between the network configuration device and the device to be networked; wherein, the information encryption key is used to encrypt the network configuration information and the first key calculation parameter to obtain the encrypted network configuration information and the encrypted first key calculation parameter, the network configuration information is used to configure the device to be networked to access the first access point, the first key calculation parameter is used to update the device key of the device to be networked, the device key of the device to be networked is used to generate an information decryption key, the information decryption key is used to decrypt the encrypted network configuration information and the encrypted first key calculation parameter, and the encrypted network configuration information and the encrypted first key calculation parameter are used to generate a first graphic code displayed by the network configuration device; Send the information encryption key and the first key calculation parameter to the network configuration cloud platform.
14. The method according to claim 13, wherein The method further includes: Update the current second device key according to the first key calculation parameter to obtain an updated second device key; Store the updated second device key.
15. The method according to claim 14, wherein The updating the current second device key according to the first key calculation parameter to obtain an updated second device key includes: Process the first key calculation parameter and the current second device key by using a first key generation algorithm to obtain the updated second device key.
16. The method according to any one of claims 13 to 15, characterized in that, The length of the first key calculation parameter is greater than or equal to one byte.
17. The method according to any one of claims 13 to 15, characterized in that, The first key calculation parameter includes a random number.
18. The method according to any one of claims 13 to 15, characterized in that, The first key calculation parameter is generated by the device cloud platform.
19. The method according to any one of claims 13 to 15, characterized in that, The method further includes: Receive a first identity authentication result from the network configuration cloud platform, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed.
20. The method according to claim 19, wherein After receiving the first identity authentication result from the network configuration cloud platform, it further includes: Replace the current second device key with the updated second device key.
21. The method according to any one of claims 13 to 15, characterized in that, The method further includes: Delete the updated second device key in the case that the first identity authentication result from the network configuration cloud platform is not received within a preset time interval, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed; Wherein, the starting moment of the preset time interval includes the generation moment of the updated second device key and the moments after the generation moment of the updated second device key; or, the starting moment of the preset time interval includes the sending moment of the first key calculation parameter and the moments after the sending moment of the first key calculation parameter.
22. A key update device, characterized in that, Set in the device to be networked, the device includes: A graphic code scanning module, configured to scan a first graphic code displayed by a network configuration device to obtain encrypted network configuration information and encrypted first key calculation parameters; wherein, the first graphic code is generated according to the encrypted network configuration information and the encrypted first key calculation parameters, and both the encrypted network configuration information and the encrypted first key calculation parameters are encrypted using an information encryption key. The graphic code scanning module is further configured to decrypt the encrypted network configuration information and the encrypted first key calculation parameters using an information decryption key to obtain network configuration information and first key calculation parameters; wherein, the information decryption key is calculated based on the current first device key. A first key update module, configured to access a first access point using the network configuration information. The first key update module is further configured to update the current first device key according to the first key calculation parameters to obtain an updated first device key. A first key replacement module, configured to replace the current first device key with the updated first device key.
23. The device according to claim 22, characterized in that, The first key update module is configured to: Process the first key calculation parameters and the current first device key using a first key generation algorithm to obtain the updated first device key.
24. The device according to claim 22 or 23, characterized in that The length of the first key calculation parameter is greater than or equal to one byte.
25. The device according to any one of claims 22 or 23, characterized in that, The first key calculation parameter includes a random number.
26. The device according to any one of claims 22 or 23, characterized in that, The first key calculation parameter is generated by a device cloud platform.
27. The device according to any one of claims 22 or 23, wherein When the information decryption key is the same as the information encryption key, the device to be networked successfully obtains the first key calculation parameter. When the information decryption key is different from the information encryption key, the device to be networked fails to obtain the first key calculation parameter.
28. The device according to any one of claims 22 or 23, characterized in that, The device further includes: An authentication result sending module, configured to send a first identity authentication result to a network configuration cloud platform when accessing the first access point, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed.
29. A key update device, characterized in that, Set in the network configuration device, the device includes: An information receiving module, configured to receive an information encryption key and a first key calculation parameter from a network configuration cloud platform, where the first key calculation parameter is used to update the device key of the device to be networked, the device key of the device to be networked is used to generate an information decryption key, and the information decryption key is used to decrypt the encrypted network configuration information and the encrypted first key calculation parameters. A graphic code determination module, configured to encrypt the network configuration information and the first key calculation parameter by using the information encryption key, so as to obtain the encrypted network configuration information and the encrypted first key calculation parameter, where the network configuration information is used to configure a device to be networked to access a first access point; The graphic code determination module is further configured to generate a first graphic code according to the encrypted network configuration information and the encrypted first key calculation parameter; A graphic code display module, configured to display the first graphic code.
30. The device according to claim 29, wherein The graphic code determination module is configured to: Process the network configuration information and the first key calculation parameter by using a first encryption algorithm and the information encryption key, so as to obtain the encrypted network configuration information and the encrypted first key calculation parameter.
31. The device according to claim 29 or 30, characterized in that, The length of the first key calculation parameter is greater than or equal to one byte.
32. The device according to any one of claims 29 or 30, characterized in that, The first key calculation parameter includes a random number.
33. The device according to any one of claims 29 or 30, characterized in that The first key calculation parameter is generated by a device cloud platform.
34. A key update device, characterized in that It is disposed in a device cloud platform, and the apparatus includes: A request receiving module, configured to receive an encryption key acquisition request from a network configuration cloud platform, where the encryption key acquisition request is used to request to obtain an information encryption key between a network configuration device and a device to be networked; wherein, the information encryption key is used to encrypt network configuration information and a first key calculation parameter to obtain encrypted network configuration information and encrypted first key calculation parameter, the network configuration information is used to configure the device to be networked to access a first access point, the first key calculation parameter is used to update a device key of the device to be networked, the device key of the device to be networked is used to generate an information decryption key, the information decryption key is used to decrypt the encrypted network configuration information and the encrypted first key calculation parameter, and the encrypted network configuration information and the encrypted first key calculation parameter are used to generate a first graphic code displayed by the network configuration device; An information sending module, configured to send the information encryption key and the first key calculation parameter to the network configuration cloud platform.
35. The apparatus according to claim 34, characterized in that, The apparatus further includes: A second key update module, configured to perform an update process on a current second device key according to the first key calculation parameter, so as to obtain an updated second device key; A second key storage module, configured to store the updated second device key.
36. The device according to claim 35, wherein The second key update module is configured to: Process the first key calculation parameter and the current second device key by using a first key generation algorithm, so as to obtain the updated second device key.
37. The device according to any one of claims 34 to 36, characterized in that, The length of the first key calculation parameter is greater than or equal to one byte.
38. The device according to any one of claims 34 to 36, characterized in that, The first key calculation parameter includes a random number.
39. The device according to any one of claims 34 to 36, characterized in that, The first key calculation parameter is generated by the device cloud platform.
40. The device according to any one of claims 34 to 36, characterized in that, The apparatus further includes: An authentication result receiving module, configured to receive a first identity authentication result from the network configuration cloud platform, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform is passed.
41. The device according to claim 40, characterized in that, The apparatus further includes: A second key replacement module, configured to replace the current second device key with the updated second device key.
42. The device according to any one of claims 34 to 36, characterized in that, The apparatus further includes: A second key deletion module, configured to delete the updated second device key when the first authentication result from the network configuration cloud platform is not received within a preset time interval, where the first authentication result is used to indicate that the authentication for the device cloud platform is passed; Wherein, the starting moment of the preset time interval includes the generation moment of the updated second device key and the moments after the generation moment of the updated second device key; or, the starting moment of the preset time interval includes the sending moment of the first key calculation parameter and the moments after the sending moment of the first key calculation parameter.
43. A device to be networked, characterized in that, The device to be networked includes: a processor, and a transceiver connected to the processor; wherein: The processor is configured to scan a first graphic code displayed by a network configuration device to obtain encrypted network configuration information and encrypted first key calculation parameters; wherein, the first graphic code is generated according to the encrypted network configuration information and the encrypted first key calculation parameters, and both the encrypted network configuration information and the encrypted first key calculation parameters are encrypted using an information encryption key; The processor is configured to decrypt the encrypted network configuration information and the encrypted first key calculation parameters using an information decryption key to obtain network configuration information and a first key calculation parameter; wherein, the information decryption key is calculated based on the current first device key; The processor is configured to access a first access point using the network configuration information; The processor is configured to update the current first device key according to the first key calculation parameter to obtain an updated first device key; The processor is configured to replace the current first device key with the updated first device key.
44. A distribution network device, characterized in that, The network configuration device includes: a processor, and a transceiver connected to the processor; wherein: The transceiver is configured to receive an information encryption key and a first key calculation parameter from a network configuration cloud platform, where the first key calculation parameter is used to update the device key of the device to be networked, the device key of the device to be networked is used to generate an information decryption key, and the information decryption key is used to decrypt the encrypted network configuration information and the encrypted first key calculation parameters; The processor is configured to encrypt the network configuration information and the first key calculation parameter using the information encryption key to obtain the encrypted network configuration information and the encrypted first key calculation parameters, where the network configuration information is used to configure the device to be networked to access a first access point; The processor is configured to generate a first graphic code according to the encrypted network configuration information and the encrypted first key calculation parameters; The processor is configured to display the first graphic code.
45. A device cloud platform, characterized in that, The device cloud platform includes: a processor, and a transceiver connected to the processor; wherein: The transceiver is configured to receive an encrypted key acquisition request from a distribution network cloud platform, where the encrypted key acquisition request is used to request an information encryption key between a distribution network device and a device to be networked; wherein the information encryption key is used to encrypt network configuration information and a first key calculation parameter to obtain encrypted network configuration information and encrypted first key calculation parameter, the network configuration information is used to configure the device to be networked to access a first access point, the first key calculation parameter is used to update the device key of the device to be networked, the device key of the device to be networked is used to generate an information decryption key, the information decryption key is used to decrypt the encrypted network configuration information and the encrypted first key calculation parameter, and the encrypted network configuration information and the encrypted first key calculation parameter are used to generate a first graphic code displayed by the distribution network device. The transceiver is configured to send the information encryption key and the first key calculation parameter to the distribution network cloud platform.
46. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and the computer program is configured to be executed by a processor of a device to be networked to implement the key update method according to any one of claims 1 to 7.
47. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and the computer program is configured to be executed by a processor of a distribution network device to implement the key update method according to any one of claims 8 to 12.
48. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and the computer program is configured to be executed by a processor of a device cloud platform to implement the key update method according to any one of claims 13 to 21.
Citation Information
Patent Citations
Network key updating system, method and apparatus
CN108449756A