Key Update Method, Device, Equipment and Storage Medium
By performing identity authentication based on the device key during the distribution process of smart device networking and updating the device key, the problem of not involving identity authentication during the distribution process in the existing technology is solved, which significantly improves the security of the AP.
Patent Information
- Application Number
- CN202011114152.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-18
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2040-10-18
AI Technical Summary
The prior art does not involve identity authentication during the smart device distribution process, resulting in the possibility of counterfeiting devices to obtain network configuration information, endangering the security of the AP.
By generating identity authentication information based on the device key between the device to be entered and the device cloud platform and comparing identity authentication, it is ensured that identity authentication is achieved during the distribution process. At the same time, after the identity authentication is passed, the device key of the device to be entered is updated to ensure that the identity authentication is updated in real time every time the network is distributed.
It effectively improves the security of AP, prevents counterfeit devices from obtaining network configuration information, and ensures that identity authentication is updated in real time during the distribution process.
Smart Images

Figure CN114390521B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present application relate to the field of communication technologies, and in particular, to a method, apparatus, device, and storage medium for key update. Background Art
[0002] Intelligent devices include devices, instruments, machines, etc. with computing and processing capabilities. Usually, when an intelligent device is used for the first time or when the usage scenario of the intelligent device is changed (such as changing the intelligent device from one network environment to another network environment for use), etc., the intelligent device needs to be network-configured so that the intelligent device can be connected to the network, and then the intelligent device can be controlled through the network.
[0003] Related technologies provide various methods for configuring an intelligent device to access the network, including: Soft AP (Access Point) network configuration (hereinafter referred to as "soft AP network configuration"). The main process of soft AP network configuration is as follows: The intelligent device turns on the soft AP and broadcasts the beacon of the soft AP; after the network configuration device scans the beacon of the soft AP, it joins the soft AP; through the soft AP, the network configuration device can send the network configuration information of the AP to be accessed to the intelligent device. After that, the intelligent device turns off the soft AP and accesses the AP according to the network configuration information, thereby completing the network configuration process.
[0004] However, the above network configuration process does not involve the identity authentication of the intelligent device, so it is very likely that a counterfeit intelligent device obtains the network configuration information of the AP, resulting in the leakage of the network configuration information of the AP and posing a great threat to the security of the AP. Therefore, how to implement the identity authentication of the intelligent device to improve the security of the AP still needs further discussion and research. Summary of the Invention
[0005] Embodiments of the present application provide a method, apparatus, device, and storage medium for key update. The technical solution is as follows:
[0006] On the one hand, embodiments of the present application provide a key update method applied to a device to be networked. The method includes:
[0007] Updating the current first device key according to the first key calculation parameter to obtain an updated first device key;
[0008] Replacing the current first device key with the updated first device key.
[0009] On the other hand, an embodiment of the present application provides a key update method, which is applied to a network configuration device. The method includes:
[0010] Receiving first key calculation parameters from a network configuration cloud platform, where the first key calculation parameters are used to update the device key of a device to be networked;
[0011] Sending the first key calculation parameters to the device to be networked.
[0012] On the other hand, an embodiment of the present application provides a key update method, which is applied to a device cloud platform. The method includes:
[0013] Updating the current second device key according to the first key calculation parameters to obtain an updated second device key;
[0014] Storing the updated second device key.
[0015] On the other hand, an embodiment of the present application provides a key update method, which is applied to a device to be networked. The method includes:
[0016] When accessing a first access point and the identity authentication for the device cloud platform is passed, processing the current first device key according to the first key calculation parameters to obtain an updated first device key;
[0017] Replacing the current first device key with the updated first device key.
[0018] On the other hand, an embodiment of the present application provides a key update method, which is applied to a network configuration cloud platform. The method includes:
[0019] Receiving first key calculation parameters from a device cloud platform, where the first key calculation parameters are used to update the device key of a device to be networked;
[0020] Sending the first key calculation parameters to the device to be networked.
[0021] On the other hand, an embodiment of the present application provides a key update method, which is applied to a device cloud platform. The method includes:
[0022] Updating the current second device key according to the first key calculation parameters to obtain an updated second device key;
[0023] Replacing the current second device key with the updated second device key.
[0024] On the other hand, an embodiment of the present application provides a key update device, which is set in a device to be networked. The device includes:
[0025] The first key update module is used to update the current first device key according to the first key calculation parameter to obtain the updated first device key;
[0026] The first key replacement module is used to replace the current first device key with the updated first device key.
[0027] On the other hand, an embodiment of the present application provides a key update device, which is set in the network configuration device. The device includes:
[0028] The first parameter receiving module is used to receive the first key calculation parameter from the network configuration cloud platform. The first key calculation parameter is used to update the device key of the device to be networked;
[0029] The first parameter sending module is used to send the first key calculation parameter to the device to be networked.
[0030] On the other hand, an embodiment of the present application provides a key update device, which is set in the device cloud platform. The device includes:
[0031] The second key update module is used to update the current second device key according to the first key calculation parameter to obtain the updated second device key;
[0032] The second key storage module is used to store the updated second device key.
[0033] On the other hand, an embodiment of the present application provides a key update device, which is set in the device to be networked. The device includes:
[0034] The first key update module is used to process the current first device key according to the first key calculation parameter to obtain the updated first device key when accessing the first access point and the identity authentication for the device cloud platform is passed;
[0035] The first key replacement module is used to replace the current first device key with the updated first device key.
[0036] On the other hand, an embodiment of the present application provides a key update device, which is set in the network configuration cloud platform. The device includes:
[0037] The first parameter receiving module is used to receive the first key calculation parameter from the device cloud platform. The first key calculation parameter is used to update the device key of the device to be networked;
[0038] The first parameter sending module is used to send the first key calculation parameter to the device to be networked.
[0039] On the other hand, an embodiment of the present application provides a key update device, which is set in a device cloud platform. The device includes:
[0040] A second key update module, configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key;
[0041] A second key replacement module, configured to replace the current second device key with the updated second device key.
[0042] On the other hand, an embodiment of the present application provides an equipment to be networked. The equipment to be networked includes: a processor, and a transceiver connected to the processor; wherein:
[0043] The processor is configured to update the current first device key according to the first key calculation parameter to obtain an updated first device key;
[0044] The processor is configured to replace the current first device key with the updated first device key.
[0045] On the other hand, an embodiment of the present application provides a network configuration device. The network configuration device includes: a processor, and a transceiver connected to the processor; wherein:
[0046] The transceiver is configured to receive a first key calculation parameter from a network configuration cloud platform, and the first key calculation parameter is used to update the device key of the equipment to be networked;
[0047] The transceiver is configured to send the first key calculation parameter to the equipment to be networked.
[0048] On the other hand, an embodiment of the present application provides a device cloud platform. The device cloud platform includes: a processor, and a transceiver connected to the processor; wherein:
[0049] The processor is configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key;
[0050] The processor is configured to store the updated second device key.
[0051] On the other hand, an embodiment of the present application provides an equipment to be networked. The equipment to be networked includes: a processor, and a transceiver connected to the processor; wherein:
[0052] The processor is configured to, when accessing a first access point and the identity authentication for the device cloud platform passes, process the current first device key according to the first key calculation parameter to obtain an updated first device key;
[0053] The processor is configured to replace the current first device key with the updated first device key.
[0054] In another aspect, an embodiment of the present application provides a network configuration cloud platform, which includes: a processor and a transceiver connected to the processor; wherein:
[0055] The transceiver is configured to receive first key calculation parameters from a device cloud platform, and the first key calculation parameters are used to update the device key of a device to be networked.
[0056] The transceiver is configured to send the first key calculation parameters to the device to be networked.
[0057] In another aspect, an embodiment of the present application provides a device cloud platform, which includes: a processor and a transceiver connected to the processor; wherein:
[0058] The processor is configured to update the current second device key according to the first key calculation parameters to obtain an updated second device key.
[0059] The processor is configured to replace the current second device key with the updated second device key.
[0060] In another aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to be executed by a processor of a device to be networked to implement the key update method on the device to be networked side as described above.
[0061] In another aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to be executed by a processor of a network configuration device to implement the key update method on the network configuration device side as described above.
[0062] In another aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to be executed by a processor of a device cloud platform to implement the key update method on the device cloud platform side as described above.
[0063] In another aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and the computer program is configured to be executed by a processor of a network configuration cloud platform to implement the key update method on the network configuration cloud platform side as described above.
[0064] On the other hand, an embodiment of the present application provides a chip, which includes programmable logic circuits and / or program instructions, and is used to implement the key update method on the side of the device to be networked as described above when the chip runs on the device to be networked.
[0065] On the other hand, an embodiment of the present application provides a chip, which includes programmable logic circuits and / or program instructions, and is used to implement the key update method on the side of the network configuration device as described above when the chip runs on the network configuration device.
[0066] On the other hand, an embodiment of the present application provides a chip, which includes programmable logic circuits and / or program instructions, and is used to implement the key update method on the side of the device cloud platform as described above when the chip runs on the device cloud platform.
[0067] On the other hand, an embodiment of the present application provides a chip, which includes programmable logic circuits and / or program instructions, and is used to implement the key update method on the side of the network configuration cloud platform as described above when the chip runs on the network configuration cloud platform.
[0068] On the other hand, an embodiment of the present application provides a computer program product, which is used to implement the key update method on the side of the device to be networked as described above when the computer program product runs on the device to be networked.
[0069] On the other hand, an embodiment of the present application provides a computer program product, which is used to implement the key update method on the side of the network configuration device as described above when the computer program product runs on the network configuration device.
[0070] On the other hand, an embodiment of the present application provides a computer program product, which is used to implement the key update method on the side of the device cloud platform as described above when the computer program product runs on the device cloud platform.
[0071] On the other hand, an embodiment of the present application provides a computer program product, which is used to implement the key update method on the side of the network configuration cloud platform as described above when the computer program product runs on the network configuration cloud platform.
[0072] The technical solution provided by the embodiment of the present application may include the following beneficial effects:
[0073] Before the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and perform identity authentication by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and improving the security of the AP. Moreover, in the embodiment of the present application, after successful identity authentication and successful network configuration for the device to be networked, the device to be networked and the device cloud platform respectively update the device key of the device to be networked. Therefore, in the next network configuration process for the device to be networked, the relevant authentication information for identity authentication generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining the authentication information and directly using the stored authentication information, achieving the purpose of performing identity authentication with real-time update and further improving the security of the AP. BRIEF DESCRIPTION OF THE DRAWINGS
[0074] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for description in the embodiments. Obviously, the following described drawings are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0075] Figure 1 is a schematic diagram of a network configuration system provided by an embodiment of the present application;
[0076] Figure 2 is a flowchart of soft AP network configuration provided by an embodiment of the present application;
[0077] Figure 3 is a flowchart of soft AP network configuration including an identity authentication process provided by an embodiment of the present application;
[0078] Figure 4 is a flowchart of soft AP network configuration including an identity authentication process provided by another embodiment of the present application;
[0079] Figure 5 is a flowchart of a device key update method provided by an embodiment of the present application;
[0080] Figure 6 is a flowchart of identity authentication provided by an embodiment of the present application;
[0081] Figure 7 is a flowchart of retaining the device key set at the factory of the device to be networked provided by an embodiment of the present application;
[0082] Figure 8It is a flowchart for determining the device key used in the identity authentication process provided by an embodiment of the present application;
[0083] Figure 9 It is a flowchart for soft AP network configuration of identity authentication before network configuration provided by an embodiment of the present application;
[0084] Figure 10 It is a flowchart for soft AP network configuration of identity authentication before network configuration provided by another embodiment of the present application;
[0085] Figure 11 It is a flowchart for soft AP network configuration of identity authentication before network configuration provided by yet another embodiment of the present application;
[0086] Figure 12 It is a flowchart for the key update method provided by another embodiment of the present application;
[0087] Figure 13 It is a flowchart for soft AP network configuration of identity authentication after network configuration provided by still another embodiment of the present application;
[0088] Figure 14 It is a block diagram of a key update device provided by an embodiment of the present application;
[0089] Figure 15 It is a block diagram of a key update device provided by another embodiment of the present application;
[0090] Figure 16 It is a block diagram of a key update device provided by yet another embodiment of the present application;
[0091] Figure 17 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0092] Figure 18 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0093] Figure 19 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0094] Figure 20 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0095] Figure 21 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0096] Figure 22 It is a block diagram of a key update device provided by still another embodiment of the present application;
[0097] Figure 23It is a block diagram of a key update device provided by another embodiment of the present application;
[0098] Figure 24 It is a block diagram of a key update device provided by an embodiment of the present application;
[0099] Figure 25 It is a structural block diagram of a device to be networked provided by an embodiment of the present application;
[0100] Figure 26 It is a structural block diagram of a network configuration device provided by an embodiment of the present application;
[0101] Figure 27 It is a structural block diagram of a device cloud platform provided by an embodiment of the present application;
[0102] Figure 28 It is a structural block diagram of a network configuration cloud platform provided by an embodiment of the present application. Detailed implementation manners
[0103] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0104] Please refer to Figure 1 , which shows a schematic diagram of a network configuration system provided by an embodiment of the present application. The network configuration system may include: a device to be networked 110 and a network configuration device 120.
[0105] The device to be networked 110 refers to a device with network access capabilities. For example, a device with WiFi (Wireless Fidelity) access capabilities. Optionally, the device to be networked 110 is a smart device (such as a VR (Virtual Reality) headset, a smart wearable device, etc.), a terminal device, or other devices with network access capabilities. The embodiments of the present application do not limit this. In one example, as Figure 1 shown, when the network configuration system is applied to a smart home life, the device to be networked 110 may be smart home devices such as a smart TV, a smart speaker, a smart air conditioner, a smart light, a smart door and window, a smart curtain, a smart socket, etc. Optionally, the device to be networked 110 is one, or the device to be networked 110 is multiple. The embodiments of the present application do not limit this. In actual applications, the number of devices to be networked 110 can be determined in combination with application requirements or the maximum number of devices that the network configuration device 120 can manage, etc.
[0106] The network configuration device 120 refers to a device with the ability to configure network access. Optionally, the network configuration device 120 can be a server, a terminal device, a router, a terminal device, a mobile phone, a tablet computer, a wearable device, or other devices with the ability to configure network access. The embodiments of the present application do not limit this. In practical applications, the implementation form of the network configuration device 120 can be determined in combination with the application scenario of the network configuration system. In one example, as Figure 1 shown, when the network configuration system is applied to smart home life, considering the characteristics of a small area and frequent activities in the home environment, using a network configuration device 120 that occupies a large space will affect normal home life. The network configuration device 120 can be implemented as a router, a terminal device, a mobile phone, a tablet computer, a wearable device, etc. Optionally, for a certain network configuration system, the number of network configuration devices corresponding to the network configuration system can be one or multiple. The embodiments of the present application do not limit this. Generally, for the consideration of resource saving and other aspects, the number of network configuration devices corresponding to a certain network configuration system is one. Optionally, the network configuration devices corresponding to different network configuration systems are different, so that the device to be networked 110 under a certain network configuration system is bound to the network configuration device 120 under the network configuration system. For example, when the network configuration system is implemented as smart home life, taking a family as a unit, the device to be networked in a certain family is bound to the network configuration device of the family.
[0107] In the embodiments of the present application, the network configuration device 120 can configure the device to be networked 110 to access the AP, that is, configure the device to be networked 110 to access the network. In the related art, there are mainly two ways to configure the device to be networked 110 to access the network: soft AP network configuration and QR code network configuration. Below, the soft AP network configuration method will be introduced and explained.
[0108] Please refer to Figure 2 , which shows a flowchart of soft AP network configuration provided by an embodiment of the present application. As Figure 2 shown, the process of soft AP network configuration mainly includes the following steps:
[0109] Step 210, the device to be networked starts the soft AP and broadcasts the beacon of the soft AP.
[0110] In the embodiments of the present application, a device to be networked can start a soft AP when entering the network configuration mode. After the device to be networked starts the soft AP, it can broadcast the beacon of the soft AP. Optionally, the beacon of the soft AP includes at least one of the following: the device ID (Identifier) of the device to be networked, the user-defined network name, the protocol name of the application protocol, etc. Among them, the device ID can be the MAC (Media Access Control) address of the device to be networked. Optionally, the beacon of the soft AP includes at least one of the following fields: the BSSID (Basic Service Set Identifier) field, the SSID (Service Set Identifier) field, and the Vendor Specific field.
[0111] Step 220: When the network configuration device scans the beacon of the soft AP, it joins the soft AP.
[0112] The network configuration device can scan the beacons broadcast by other devices on different channels. When the network configuration device scans the beacon of the soft AP on the channel where the device to be networked broadcasts the soft AP, it can join the soft AP. Optionally, after the network configuration device scans the beacon of the soft AP, it confirms whether the SSID field in the beacon conforms to the preset format. If the SSID field conforms to the preset format, it joins the soft AP.
[0113] Step 230: Establish a communication connection between the network configuration device and the device to be networked.
[0114] After accessing the soft AP, the network configuration device can establish a communication connection with the device to be networked through the soft AP. Optionally, the communication between the network configuration device and the device to be networked satisfies the TCP (Transmission Control Protocol) protocol. Therefore, the communication connection between the network configuration device and the device to be networked can also be called a TCP connection; or the communication between the network configuration device and the device to be networked satisfies the UDP (User Datagram Protocol) protocol. Therefore, the communication connection between the network configuration device and the device to be networked can also be called a UDP connection.
[0115] Step 240: The network configuration device sends an information acquisition request to the device to be networked.
[0116] The information acquisition request is used to request information related to the APs that the device to be networked can access. Optionally, the information acquisition request is used to request the SSID field of the AP that the device to be networked can access and / or the signal strength of the AP that the device to be networked can access. In the embodiments of the present application, after the device to be networked enters the network configuration mode, it can scan the beacons of the APs at a certain period (such as 10 seconds), and determine whether it can access an AP according to the SSID field in the beacon.
[0117] Step 250, the device to be networked sends the information of the accessible AP to the network configuration device.
[0118] After receiving the information acquisition request, the device to be networked, in response to the information acquisition request, sends the information related to the AP that the device to be networked can access to the network configuration device, that is, the information of the accessible AP. Optionally, the information of the accessible AP includes at least one of the following: the SSID field of the accessible AP, the signal strength of the accessible AP.
[0119] Step 260, the network configuration device sends network configuration information to the device to be networked.
[0120] After receiving the information of the accessible AP sent by the device to be networked, the network configuration device can select the AP for the device to be networked to access according to the information of the accessible AP. The embodiments of the present application do not limit the manner in which the network configuration device selects the AP for the device to be networked to access. Optionally, the network configuration device determines the AP with the highest signal strength indicated by the information of the accessible AP as the AP for the device to be networked to access. After the network configuration device selects the AP for the device to be networked to access, it can send network configuration information to the device to be networked to configure the device to be networked to access the AP it selects. Optionally, the network configuration information includes at least one of the following: the SSID field of the AP that the device to be networked accesses, the authentication information of the AP that the device to be networked accesses. Optionally, the authentication information of the AP that the device to be networked accesses includes the password of the AP that the device to be networked accesses.
[0121] Step 270, the device to be networked sends a configuration response message to the network configuration device.
[0122] The configuration response message is used to respond to the network configuration information sent by the network configuration device to indicate to the network configuration device whether the device to be networked has received the network configuration information. Optionally, the network configuration device defaults that the device to be networked has received the network configuration information after sending the network configuration information to the device to be networked. In the case where the device to be networked successfully receives the network configuration information, it may not send a configuration response message to the network configuration device; in the case where the device to be networked does not successfully receive the network configuration information, such as in the case where the device to be networked cannot parse the network configuration information, it may send a configuration response message to the network configuration device.
[0123] Step 280, the network configuration device cancels accessing the soft AP.
[0124] After the network configuration information is sent from the distribution network device to the device to be networked, the connection with the soft AP started by the device to be networked can be disconnected, that is, the access to the soft AP is cancelled. Optionally, after sending the network configuration information, the distribution network device cancels the access to the soft AP; or, after receiving the configuration response message, the distribution network device cancels the access to the soft AP. The embodiments of the present application do not limit the timing for the distribution network device to cancel the access to the soft AP.
[0125] Step 290, the device to be networked turns off the soft AP.
[0126] Since the device to be networked usually cannot access two APs simultaneously, the device to be networked needs to turn off the soft AP to access the AP indicated by the network configuration information. Optionally, after receiving the network configuration information, the device to be networked turns off the soft AP; or, after sending the configuration response message to the distribution network device, the device to be networked turns off the soft AP; or, after the distribution network device cancels the access to the soft AP, the device to be networked turns off the soft AP. The embodiments of the present application do not limit the timing for the device to be networked to turn off the soft AP.
[0127] After the device to be networked cancels the access to the soft AP, it can access the AP indicated by the network configuration information according to the authentication information in the network configuration information. After the distribution network device cancels the access to the soft AP, in order to continue to control and manage the device to be networked, etc., it can also access the AP indicated by the network configuration information. Thus, the distribution network device and the device to be networked establish a communication connection through the accessed AP.
[0128] It can be seen from the above distribution network process that the above distribution network process does not involve the identity authentication of intelligent devices. As a result, it is very likely that a counterfeit intelligent device obtains the network configuration information of the AP, leading to the leakage of the network configuration information of the AP and posing a great threat to the security of the AP. Therefore, adding an identity authentication-related process during the distribution network process can effectively avoid the leakage of network configuration information and improve the security of the AP. Next, several ways to add an identity authentication-related process during the distribution network process are introduced.
[0129] Please refer to Figure 3 , which shows the flowchart of the soft AP distribution network including the identity authentication process provided by an embodiment of the present application. As Figure 3 shown, the process of the soft AP distribution network including the identity authentication process mainly includes the following steps:
[0130] Step 301, the device to be networked starts the soft AP and broadcasts the beacon of the soft AP.
[0131] In the embodiments of the present application, the device to be networked can start a soft AP when entering the network configuration mode. After the device to be networked starts the soft AP, it can broadcast the beacon of the soft AP. Optionally, the beacon of the soft AP is used to indicate the device information of the device to be networked. Optionally, the device information of the device to be networked includes at least one of the following: the MAC address of the device to be networked, the product ID (product ID) of the device to be networked, and a random value. Optionally, the beacon of the soft AP includes at least one of the following fields: the BSSID field, the SSID field, and the manufacturer-defined field.
[0132] Step 302: When the network configuration device scans the beacon of the soft AP, it obtains the device information of the device to be networked.
[0133] The network configuration device can scan the beacons broadcast by other devices on different channels. When the network configuration device scans the beacon of the soft AP on the channel where the device to be networked broadcasts the soft AP, the network configuration device discovers the device to be networked. Moreover, the network configuration device can parse the beacon of the soft AP to obtain the device information of the device to be networked. Optionally, after the network configuration device scans the beacon of the soft AP, it confirms whether the SSID field in the beacon conforms to a preset format. If the SSID field conforms to the preset format, the network configuration device obtains the device information of the device to be networked.
[0134] Step 303: The network configuration device sends a first parameter acquisition request to the network configuration cloud platform.
[0135] The first parameter acquisition request is used to request to obtain the first authentication parameter used for authenticating the device to be networked. The first authentication parameter is calculated by the device cloud platform. Since the device cloud platform is the cloud platform corresponding to the device to be networked, direct communication between the network configuration device and the device cloud platform is usually not possible. Therefore, the network configuration device needs to indirectly obtain the first authentication parameter from the device cloud platform through the network configuration cloud platform. Optionally, the first parameter acquisition request sent by the network configuration device to the network configuration cloud platform includes the device information of the device to be networked. Optionally, as Figure 3 shown, if no secure connection is established between the network configuration device and the network configuration cloud platform, the network configuration device needs to first establish a secure connection with the network configuration cloud platform and then send a first parameter acquisition request to the network configuration cloud platform.
[0136] Step 304: The network configuration cloud platform sends a first parameter acquisition request to the device cloud platform.
[0137] After the distribution network cloud platform receives the first parameter acquisition request, it further sends the first parameter acquisition request to the device cloud platform to request the acquisition of the first authentication parameter. In the embodiments of the present application, when the distribution network cloud platform sends the first parameter acquisition request to the device cloud platform, it is necessary to first determine the device cloud platform corresponding to the device to be networked. Optionally, the first parameter acquisition request sent by the distribution network device to the distribution network cloud platform includes the device manufacturer name of the device to be networked. Furthermore, the distribution network cloud platform can determine the device cloud platform corresponding to the device to be networked according to the device manufacturer name of the device to be networked. Optionally, as Figure 3 shown, if there is no secure connection established between the distribution network cloud platform and the device cloud platform, the distribution network cloud platform needs to first establish a secure connection with the device cloud platform, and then send the first parameter acquisition request to the device cloud platform.
[0138] Step 305, the device cloud platform calculates the first authentication parameter.
[0139] After the device cloud platform receives the first parameter acquisition request, it parses the first parameter acquisition request to obtain the MAC address and / or product number of the device to be networked. The device cloud platform can query the device certificate (license) of the device to be networked according to the MAC address and / or product number of the device to be networked. After that, the device cloud platform calculates the first authentication parameter according to at least one of the following calculation parameters: the device certificate of the device to be networked, the product number of the device to be networked, the MAC address of the device to be networked, and the random value. Optionally, the calculation process of the first authentication parameter Hc is as follows: Hc = HMAC (Hash-based Message Authentication Code, hash message authentication code) (the device certificate of the device to be networked, the product number of the device to be networked + the MAC address of the device to be networked + the random value).
[0140] Step 306, the device cloud platform sends the first authentication parameter to the distribution network cloud platform.
[0141] After the device cloud platform calculates the first authentication parameter, it sends the first authentication parameter to the distribution network cloud platform to respond to the first parameter acquisition request sent by the distribution network cloud platform to the device cloud platform.
[0142] Step 307, the distribution network cloud platform sends the first authentication parameter to the distribution network device.
[0143] After the distribution network cloud platform receives the first authentication parameter, it further sends the first authentication parameter to the distribution network device to respond to the first parameter acquisition request sent by the distribution network device to the distribution network cloud platform.
[0144] Step 308, the distribution network device establishes a communication connection with the device to be networked.
[0145] After the distribution network device obtains the first authentication parameter, it accesses the soft AP started by the device to be networked and establishes a communication connection with the device to be networked through the soft AP. Optionally, the communication between the distribution network device and the device to be networked satisfies the TCP protocol. Therefore, the communication connection between the distribution network device and the device to be networked can also be referred to as a TCP connection; or, the communication between the distribution network device and the device to be networked satisfies the UDP protocol. Therefore, the communication connection between the distribution network device and the device to be networked can also be referred to as a UDP connection.
[0146] Step 309, the distribution network device sends a second parameter acquisition request to the device to be networked.
[0147] The second parameter acquisition request is used to request the acquisition of a second authentication parameter used for authenticating the identity of the device to be networked, and the second authentication parameter is calculated by the device to be networked. After establishing a communication connection between the distribution network device and the device to be networked, a second parameter acquisition request can be sent to the device to be networked.
[0148] Step 310, the device to be networked calculates the second authentication parameter.
[0149] In the embodiments of the present application, in order to be able to authenticate the identity of the device to be networked, the calculation methods and calculation parameters of the second authentication parameter and the first authentication parameter need to be kept consistent. When the calculation process of the first authentication parameter Hc is Hc = HMAC(device certificate of the device to be networked, product number of the device to be networked + MAC address of the device to be networked + random value), the calculation process of the second authentication parameter Hc' is Hc' = HMAC(device certificate of the device to be networked, product number of the device to be networked + MAC address of the device to be networked + random value). Among them, the difference between the calculation processes of the first authentication parameter Hc and the second authentication parameter Hc' is that the first authentication parameter Hc is calculated based on the device certificate of the device to be networked stored at the device cloud platform, and the second authentication parameter Hc' is calculated based on the device certificate of the device to be networked stored at the device to be networked. That is, if the device certificate of the device to be networked stored at the device cloud platform is the same as the device certificate of the device to be networked stored at the device to be networked, the first authentication parameter Hc and the second authentication parameter Hc' can also be the same.
[0150] Step 311, the device to be networked sends the second authentication parameter to the distribution network device.
[0151] The device to be networked can send a second authentication parameter to the network configuration device in response to the second parameter acquisition request sent by the network configuration device. In the embodiments of the present application, the device to be networked can pre-calculate the second authentication parameter and directly send the second authentication parameter to the network configuration device when receiving the second parameter acquisition request sent by the network configuration device; alternatively, the device to be networked calculates the second authentication parameter after receiving the second parameter acquisition request sent by the network configuration device and sends the calculated second authentication parameter to the network configuration device.
[0152] Step 312, the network configuration device performs identity authentication on the device to be networked according to the first authentication parameter and the second authentication parameter.
[0153] After the network configuration device obtains the first authentication parameter and the second authentication parameter from the device cloud platform and the device to be networked respectively, it performs identity authentication on the device to be networked based on these two authentication parameters. When the first authentication parameter and the second authentication parameter are consistent, the identity authentication of the device to be networked passes; when the first authentication parameter and the second authentication parameter are inconsistent, the identity authentication of the device to be networked fails.
[0154] Step 313, the network configuration device sends network configuration information to the device to be networked.
[0155] When the first authentication parameter and the second authentication parameter are consistent, that is, when the identity authentication of the device to be networked passes, the network configuration device sends network configuration information to the device to be networked. In the embodiments of the present application, in order to further ensure the security of the network configuration information, the network configuration information is the network configuration information encrypted with an encryption key. Based on this, the network configuration device and the device to be networked need to perform a security negotiation to negotiate the key used for encrypting data between the network configuration device and the device to be networked. Optionally, the security negotiation between the network configuration device and the device to be networked can be performed before the above step 311. Optionally, the network configuration information includes at least one of the following: the SSID field of the AP to which the device to be networked is to be connected, the authentication information of the AP to which the device to be networked is to be connected. Optionally, the authentication information of the AP to which the device to be networked is to be connected includes at least one of the following: the password of the AP to which the device to be networked is to be connected.
[0156] Step 314, the device to be networked turns off the soft AP.
[0157] Since the device to be networked usually cannot be connected to two APs simultaneously, the device to be networked needs to turn off the soft AP to connect to the AP indicated by the network configuration information.
[0158] Step 315, the network configuration device cancels the connection to the soft AP.
[0159] The embodiments of the present application do not limit the timing for the network configuration device to cancel accessing the soft AP. Optionally, the network configuration device cancels accessing the soft AP after sending network configuration information to the device to be networked; or, the network configuration device cancels accessing the soft AP after the device to be networked turns off the soft AP.
[0160] Step 316, the device to be networked accesses the AP indicated by the network configuration information.
[0161] After the device to be networked turns off the soft AP it starts, it can access the AP indicated by the network configuration information according to the network configuration information sent by the network configuration device. Optionally, the network configuration information includes the SSID field and / or password of the AP to which the device to be networked will access, and the device to be networked accesses the AP according to the SSID field and / or password of the AP.
[0162] The above Figure 3 In the embodiments, before the device to be networked accesses the AP, identity authentication is performed on the device to be networked, which can improve the security of the AP to a certain extent. However, Figure 3 the authentication process in the embodiments is one-way authentication and does not involve the identity authentication process of the device cloud platform, so there are certain limitations in improving the security of the AP. To further improve the security of the AP, the embodiments of the present application provide a flowchart of soft AP network configuration including a two-way identity authentication process. Next, the process of soft AP network configuration including a two-way identity authentication process will be introduced and described.
[0163] Please refer to Figure 4 , which shows a flowchart of soft AP network configuration including an identity authentication process provided by an embodiment of the present application. As Figure 4 shown, the process of soft AP network configuration including an identity authentication process mainly includes the following steps:
[0164] Step 401, the device to be networked starts the soft AP and broadcasts the beacon of the soft AP.
[0165] For the introduction and description of step 401, please refer to the introduction and description of step 210 above, and details will not be repeated here.
[0166] Step 402, when the network configuration device scans the beacon of the soft AP, a communication connection is established between the network configuration device and the device to be networked.
[0167] For the introduction and description of step 402, please refer to the introduction and description of steps 220 to 230 above, and details will not be repeated here.
[0168] Step 403, the network configuration device sends network configuration information to the device to be networked.
[0169] After the power distribution device establishes a communication connection with the soft AP started by the device to be networked and with the device to be networked, it can send network configuration information to the device to be networked to configure information related to the AP that the device to be networked will join. In the embodiments of the present application, in order to ensure the security of the network configuration information, the network configuration information is the network configuration information encrypted with an encryption key. Based on this, a security negotiation needs to be performed between the power distribution device and the device to be networked to negotiate the key used for encrypting data between the power distribution device and the device to be networked. Optionally, the network configuration information includes at least one of the following: the SSID field of the AP to which the device to be networked is to be connected, the password of the AP to which the device to be networked is to be connected, and the URL (Uniform Resource Locator) of the power distribution cloud platform.
[0170] Step 404, the device to be networked turns off the soft AP.
[0171] For the introduction and description of step 404, please refer to the introduction and description of step 290 and step 314 above, and details are not elaborated here.
[0172] Step 405, the power distribution device cancels the access to the soft AP.
[0173] For the introduction and description of step 405, please refer to the introduction and description of step 280 and step 315 above, and details are not elaborated here.
[0174] Step 406, the device to be networked accesses the AP indicated by the network configuration information.
[0175] After the device to be networked turns off the soft AP it started, it can access the AP indicated by the network configuration information according to the network configuration information sent by the power distribution device. Optionally, the network configuration information includes the SSID field and / or password of the AP to which the device to be networked is to be connected, and the device to be networked accesses the AP according to the SSID field and / or password of the AP.
[0176] Step 407, the device to be networked establishes a communication connection with the power distribution cloud platform.
[0177] The network configuration information sent by the distribution network device to the device to be networked may include the URL of the distribution network cloud platform. According to the URL of the distribution network cloud platform, the device to be networked can determine the distribution network cloud platform and establish a communication connection with the distribution network cloud platform. Optionally, the communication between the device to be networked and the distribution network cloud platform complies with the TLS (Transport Layer Security) protocol. Therefore, the communication connection between the device to be networked and the distribution network cloud platform can also be referred to as a TLS connection; or, the communication between the device to be networked and the distribution network cloud platform complies with the DTLS (Datagram Transport Layer Security) protocol. Therefore, the communication connection between the device to be networked and the distribution network cloud platform can also be referred to as a DTLS connection.
[0178] Step 408, the device to be networked calculates the second authentication parameter.
[0179] The second authentication parameter is used to authenticate the device to be networked, and the second authentication parameter is calculated by the device to be networked side. Optionally, the device to be networked calculates the second authentication parameter according to at least one of the following calculation parameters: the device certificate of the device to be networked, the product number of the device to be networked, the MAC address of the device to be networked, the first random value. Optionally, the calculation process of the second authentication parameter Hc’ is as follows: Hc’ = HMAC (the device certificate of the device to be networked, the product number of the device to be networked + the MAC address of the device to be networked + the first random value).
[0180] Step 409, the device to be networked sends the second authentication parameter and the device information of the device to be networked to the distribution network cloud platform.
[0181] After the device to be networked calculates the second authentication parameter Hc’, it needs to send the second authentication parameter and the device information related to the device to be networked to the distribution network cloud platform, and then the distribution network cloud platform further forwards it to the device cloud platform. Optionally, the device information of the device to be networked includes at least one of the following: the MAC address of the device to be networked, the product number of the device to be networked, the first random value.
[0182] Step 410, the distribution network cloud platform sends the second authentication parameter and the device information of the device to be networked to the device cloud platform.
[0183] After the distribution network cloud platform receives the second authentication parameter and the device information of the device to be networked sent by the device to be networked, it further forwards them to the device cloud platform. Optionally, as Figure 4 shown, if there is no secure connection established between the distribution network cloud platform and the device cloud platform, the distribution network cloud platform needs to first establish a secure connection with the device cloud platform, and then send the second authentication parameter and the device information of the device to be networked to the device cloud platform.
[0184] Step 411, the device cloud platform calculates the first authentication parameter.
[0185] The first authentication parameter is used to authenticate the device to be networked, and the first authentication parameter is calculated by the device cloud platform side. In the embodiments of the present application, in order to be able to authenticate the device to be networked, the calculation methods and calculation parameters of the second authentication parameter and the first authentication parameter need to be consistent. When the calculation process of the second authentication parameter Hc' is Hc' = HMAC(device certificate of the device to be networked, product number of the device to be networked + MAC address of the device to be networked + first random value), the calculation process of the first authentication parameter Hc is Hc = HMAC(device certificate of the device to be networked, product number of the device to be networked + MAC address of the device to be networked + first random value). Among them, the device information of the device to be networked sent by the network configuration cloud platform to the device cloud platform includes the MAC address of the device to be networked and / or the product identifier of the device to be networked, and the device cloud platform can query the device certificate of the device to be networked according to the MAC address and / or product identifier of the device to be networked. Thus, the difference between the calculation processes of the first authentication parameter Hc and the second authentication parameter Hc' is that: the first authentication parameter Hc is calculated based on the device certificate of the device to be networked stored at the device cloud platform, and the second authentication parameter Hc' is calculated based on the device certificate of the device to be networked stored at the device to be networked. That is, if the device certificate of the device to be networked stored at the device cloud platform is the same as the device certificate of the device to be networked stored at the device to be networked, the first authentication parameter Hc and the second authentication parameter Hc' can also be the same.
[0186] Step 412, the device cloud platform calculates the third authentication parameter.
[0187] The third authentication parameter is used to authenticate the device cloud platform, and the third authentication parameter is calculated by the device cloud platform side. Optionally, the device cloud platform calculates the third authentication parameter according to at least one of the following calculation parameters: the device certificate of the device to be networked, the product number of the device to be networked, the MAC address of the device to be networked, the second random value. Among them, the second random value is a random value generated by the device cloud platform. Optionally, the calculation process of the third authentication parameter Hs is as follows: Hs = HMAC(device certificate of the device to be networked, product number of the device to be networked + MAC address of the device to be networked + third random value).
[0188] Step 413, the device cloud platform sends the third authentication parameter, the second random value, and the identity authentication result to the network configuration cloud platform.
[0189] When the first authentication parameter is consistent with the second authentication parameter, the device cloud platform may determine that the identity authentication of the device to be networked is passed; when the first authentication parameter is inconsistent with the second authentication parameter, the device cloud platform may determine that the identity authentication of the device to be networked fails. After that, the device cloud platform may feedback the identity authentication result to the network configuration cloud platform for the network configuration cloud platform to forward to the device to be networked. Optionally, in the embodiments of the present application, when the identity authentication of the device to be networked is passed, the device cloud platform may send the third authentication parameter and the second random value simultaneously during the process of sending the identity authentication result to the network configuration cloud platform; when the identity authentication of the device to be networked fails, the device cloud platform directly sends the identity authentication result to the network configuration cloud platform.
[0190] Step 414, the network configuration cloud platform sends the third authentication parameter, the second random value, and the identity authentication result to the device to be networked.
[0191] After receiving the third authentication parameter, the second random value, and the identity authentication result, the network configuration cloud platform further forwards them to the device to be networked.
[0192] Step 415, the device to be networked calculates the fourth authentication parameter.
[0193] The fourth authentication parameter is used to authenticate the identity of the device cloud platform, and the fourth authentication parameter is calculated by the device to be networked side. In the embodiments of the present application, in order to be able to authenticate the identity of the device cloud platform, the calculation methods and calculation parameters of the fourth authentication parameter and the third authentication parameter need to be kept consistent. When the calculation process of the third authentication parameter Hs is Hs = HMAC(device certificate of the device to be networked, product number of the device to be networked + MAC address of the device to be networked + second random value), the calculation process of the fourth authentication parameter Hs' is Hs' = HMAC(device certificate of the device to be networked, product number of the device to be networked + MAC address of the device to be networked + second random value). The difference between the calculation processes of the third authentication parameter Hs and the fourth authentication parameter Hs' is that: the third authentication parameter Hs is calculated according to the device certificate of the device to be networked stored at the device cloud platform, and the fourth authentication parameter Hs' is calculated according to the device certificate of the device to be networked stored at the device to be networked. That is, if the device certificate of the device to be networked stored at the device cloud platform is consistent with the device certificate of the device to be networked stored at the device to be networked, the third authentication parameter Hs and the fourth authentication parameter Hs' can also be consistent, and thus the identity authentication of the device cloud platform is passed.
[0194] However, in Figure 4In the embodiment, after the above step 414, the network configuration cloud platform may save the third authentication parameter and the second random value, which may cause the device to be networked to directly send the saved third authentication parameter and the second random value to the device to be networked when the device to be networked requests to access the AP again, instead of requesting the device cloud platform to authenticate the device to be networked. Therefore, Figure 4 The embodiment may not be able to achieve the purpose of real-time updated authentication during each network configuration process, which brings limitations to the improvement of the security of the AP. Based on this, the embodiment of the present application provides a key update method, which can be used for real-time updated authentication to fully improve the security of the AP.
[0195] Next, a key update method for authenticating the identity before configuring the device to be networked is introduced. Since Figure 5 the embodiment, Figure 6 the embodiment, Figure 7 the embodiment, and Figure 8 the embodiment are improvements to the above Figure 3 embodiment, for the identity authentication process and network configuration process not described in Figure 5 the embodiment, Figure 6 the embodiment, Figure 7 the embodiment, and Figure 8 the embodiment, reference can be made to the introduction of the above Figure 3 embodiment, which will not be elaborated here.
[0196] Please refer to Figure 5 , which shows a flowchart of a key update method provided by an embodiment of the present application. This method can be applied to the network configuration system shown in Figure 1 . This method may include the following steps (steps 510-550 and steps 501-505):
[0197] Step 510, the device cloud platform sends the first key calculation parameter to the network configuration cloud platform, and the first key calculation parameter is used to update the device key of the device to be networked.
[0198] In the embodiment of the present application, the device manufacturer of the device to be networked may uniquely assign a key K to the device to be networked and pre-configure the key K into the device to be networked. Since the device identifier of the device to be networked is used to uniquely identify the device to be networked, there is a one-to-one correspondence between the device identifier of the device to be networked and the key K of the device to be networked. The device manufacturer of the device to be networked may upload the device identifier of the device to be networked and the key K of the device to be networked to the cloud platform of the device manufacturer (i.e., the cloud platform corresponding to the device to be networked).
[0199] Since the device key of the device to be networked can be used to uniquely identify the device to be networked, and the device key of the device to be networked is both pre - set in the device to be networked and stored in the device cloud platform, before configuring the device to be networked to access the first access point, identity authentication can be performed based on the device key of the device to be networked. However, if the device key of the device to be networked remains unchanged all the time, the authentication information generated based on the device key of the device to be networked may also remain unchanged. During the process of configuring the device to be networked to access the first access point multiple times, the proxy device or proxy cloud platform between the device to be networked and the device cloud platform may directly use the previously stored authentication information, rather than requesting and obtaining the authentication information from the device cloud platform or the device to be networked during each process of configuring the device to be networked to access the first access point. Such skipping of obtaining the authentication information will bring limitations to the improvement of the security of the AP. Therefore, the embodiments of the present application propose to update the device key of the device to be networked during the process of configuring the device to be networked to access the first access point, so as to achieve the purpose of updating the authentication information.
[0200] The embodiments of the present application use the first key calculation parameter to update the device key of the device to be networked. Optionally, the length of the first key calculation parameter is greater than or equal to one byte. For example, the length of the first key calculation parameter is 1 byte; or, the length of the first key calculation parameter is 2 bytes; or, the length of the first key calculation parameter is 3 bytes. In practical applications, the length of the first key calculation parameter can be determined according to the specific content setting of the first key calculation parameter, and the embodiments of the present application do not make any limitations in this regard. Optionally, the first key calculation parameter includes a random number, and the random number can be either pre - set or updated in real time, and the embodiments of the present application do not make any limitations in this regard.
[0201] In one example, the first key calculation parameter is generated by the device cloud platform (the cloud platform corresponding to the device to be networked). Based on this, in order to enable the device to be networked to also update the device key, the device cloud platform needs to send the first key calculation parameter to the device to be networked. Before configuring the device to be networked to access the first access point, the information transmission between the device cloud platform and the device to be networked needs to pass through the network configuration cloud platform and the network configuration device. Therefore, the device cloud platform needs to first send the first key calculation parameter to the network configuration cloud platform (the cloud platform corresponding to the first access point).
[0202] Step 520, the network configuration cloud platform sends the first key calculation parameter to the network configuration device.
[0203] After receiving the first key calculation parameter, the network configuration cloud platform further forwards the first key calculation parameter to the network configuration device.
[0204] Step 530, the network configuration device sends the first key calculation parameter to the device to be networked.
[0205] After receiving the first key calculation parameter, the distribution network device further forwards the first key calculation parameter to the device to be networked.
[0206] Step 540: The device to be networked updates the current first device key according to the first key calculation parameter to obtain an updated first device key.
[0207] In the embodiment of the present application, the device key of the device to be networked preset in the device to be networked is called the first device key. After receiving the first key calculation parameter, the device to be networked can update the current first device key according to the first key calculation parameter to obtain an updated first device key. Optionally, when the device to be networked receives the first key calculation parameter, it does not immediately update the current first device key according to the first key calculation parameter, but updates the current first device key according to the first key calculation parameter after passing the identity authentication and accessing the first access point, so as to ensure that the device to be networked and the device cloud platform synchronously update the device key of the device to be networked.
[0208] In one example, the device to be networked may use a key generation algorithm to process the first key calculation parameter and the current first device key to obtain an updated first device key. Based on this, the above step 540 includes: the device to be networked uses a first key generation algorithm to process the first key calculation parameter and the current first device key to obtain an updated first device key. Optionally, the first key generation algorithm includes any one of the following: AES (Advanced Encryption Standard) 128-CMAC (Cypher-Based Message Authentication Code), HKDF (HMAC (Hash-based Message Authentication Code)-based KDF (Key Derivation Function), key derivation function based on HMAC), PBKDF (Password-Based Key Derivation Function), SHA (Secure Hash Algorithm), DES (Data Encryption Standard) algorithm, 3DES (Triple DES) algorithm.
[0209] Step 550: The device to be networked replaces the current first device key with the updated first device key.
[0210] After the device to be networked updates the current first device key, it replaces the current first device key with the updated first device key. Thus, the authentication information determined based on the first device key can also be updated, avoiding the process of the network configuration cloud platform and / or the network configuration device skipping the acquisition of authentication information, effectively enhancing the security of the AP.
[0211] During the process of identity authentication, it is determined whether the identity authentication is passed by comparing whether the authentication information generated by the device to be networked and the device cloud platform respectively is consistent. Therefore, the device to be networked and the device cloud platform need to generate authentication information respectively. Therefore, the device key of the device to be networked needs to be updated at both the device to be networked and the device cloud platform to ensure that the authentication information generated by the device to be networked and the device cloud platform respectively can be consistent. Based on this, as Figure 5 shown, in one example, the above method further includes the following steps:
[0212] Step 501, the device cloud platform updates the current second device key according to the first key calculation parameter to obtain the updated second device key.
[0213] In the embodiment of the present application, the device key of the device to be networked stored in the device cloud platform is called the second device key. After the device cloud platform generates the first key calculation parameter, it immediately updates the current second device key according to the first key calculation parameter to obtain the updated second device key.
[0214] In one example, the device cloud platform can use a key generation algorithm to process the first key calculation parameter and the current second device key to obtain the updated second device key. In addition, in order to ensure that the device keys updated by the device to be networked and the device cloud platform respectively are consistent, the device to be networked and the device cloud platform should use the same key generation algorithm and key calculation parameter to update the device key of the device to be networked. Based on this, the above step 501 includes: the device cloud platform uses the first key generation algorithm to process the first key calculation parameter and the current second device key to obtain the updated second device key. Optionally, the first key generation algorithm includes any one of: AES128-CMAC, HKDF-based KDF, PBKDF, SHA, DES algorithm, 3DES algorithm.
[0215] Step 502, the device cloud platform stores the updated second device key.
[0216] After the device cloud platform obtains the updated second device key, it first stores the updated second device key. Optionally, the device cloud platform stores the updated second device key in the cache to avoid occupying the memory storage space of the device cloud platform.
[0217] It should be noted that the embodiments of the present application do not limit the execution sequence of the above steps 501 to 502 and the above steps 510 to 540. Optionally, the above steps 501 to 502 are executed before the above steps 510 to 540; or, the above steps 501 to 502 and the above steps 510 to 540 are executed synchronously; or, the above steps 501 to 502 are executed after the above steps 510 to 540. It should be understood that all possible execution sequences that satisfy the key update logic fall within the protection scope of the present application.
[0218] Step 503: After the network configuration device configures the device to be networked to access the first access point, it sends a third identity authentication result to the network configuration cloud platform, and the third identity authentication result is used to indicate that the identity authentication for the device to be networked is passed.
[0219] Since the network configuration device will configure the device to be networked to access the first access point only after the identity authentication for the device to be networked is passed, then the network configuration device configuring the device to be networked to access the first access point indicates that the identity authentication for the device to be networked is passed. Therefore, in the embodiments of the present application, after the network configuration device configures the device to be networked to access the first access point, it sends a third identity authentication result to the network configuration cloud platform to indicate that the identity authentication for the device to be networked is passed.
[0220] Step 504: The network configuration cloud platform sends the third identity authentication result to the device cloud platform.
[0221] After receiving the third identity authentication result, the network configuration cloud platform further forwards the third identity authentication result to the device cloud platform.
[0222] Step 505: The device cloud platform replaces the current second device key with the updated second device key.
[0223] After receiving the third identity authentication result, the device cloud platform determines that the device to be networked has accessed the first access point. And since the device to be networked updates the first device key after accessing the first access point, in order to realize synchronous key update between the device cloud platform and the device to be networked, after receiving the third identity authentication result, the device cloud platform replaces the current second device key with the second device key stored in the cache to realize the update process of the second device key.
[0224] In the process of configuring an unconnected device to access a first access point, the device cloud platform may fail to receive the results related to identity authentication for various reasons. For example, due to network disconnection, identity authentication failure, etc. In this case, the unconnected device cannot update the first device key and maintains the current first device key. To ensure that the device keys of the device cloud platform and the unconnected device are consistent, the device cloud platform should also maintain the current second device key in this case. Based on this, after step 502 above, it further includes: when the device cloud platform does not receive the third identity authentication result from the network configuration cloud platform within a preset time interval, delete the updated second device key. Wherein, the starting moment of the preset time interval includes the generation moment of the updated second device key and the moments after the generation moment of the updated second device key; or, the starting moment of the preset time interval includes the sending moment of the first key calculation parameter and the moments after the sending moment of the first key calculation parameter.
[0225] In summary, the technical solution provided by the embodiments of the present application, before the unconnected device accesses the AP, the unconnected device and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the unconnected device, and perform identity authentication by comparing the authentication information generated by the unconnected device and the device cloud platform respectively, achieving the purpose of identity authentication between the unconnected device and the device cloud platform, and improving the security of the AP. Moreover, in the embodiments of the present application, after successful identity authentication and successful network configuration for the unconnected device, the unconnected device and the device cloud platform respectively update the device key of the unconnected device. Thus, in the next network configuration process for the unconnected device, the relevant authentication information for identity authentication generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the unconnected device and the device cloud platform from directly using the stored authentication information by skipping the process of obtaining authentication information, achieving the purpose of real-time updated identity authentication and further improving the security of the AP.
[0226] As described above Figure 3 It can be seen from the embodiments that only the identity authentication of the unconnected device is involved in the process of identity authentication before configuring the unconnected device to access the network. To improve the security of the AP, the embodiments of the present application also add an identity authentication process for the device cloud platform before configuring the unconnected device to access the network. Next, the identity authentication process for the device cloud platform will be introduced and described.
[0227] In one example, as Figure 6 shown, the above method further includes the following steps:
[0228] Step 610, the device cloud platform generates the first cloud authentication information. The first cloud authentication information is used for the unconnected device to authenticate the device cloud platform before accessing the first access point.
[0229] For the identity authentication of the device cloud platform, the first cloud authentication information and the second cloud authentication information are required. Among them, the first cloud authentication information is generated by the device cloud platform, and the second cloud authentication information is generated by the device to be networked. In the embodiments of the present application, neither the calculation parameters nor the calculation methods of the first cloud authentication information and the second cloud authentication information are limited. In practical applications, in order to ensure that the first cloud authentication information and the second cloud authentication information can be consistent, the calculation parameters and calculation methods of the first cloud authentication information and the second cloud authentication information only need to be kept consistent.
[0230] Optionally, the calculation parameters of the first cloud authentication information include the second key calculation parameter, the third key calculation parameter, and the current second device key. Based on this, the above step 610 includes: The device cloud platform generates the first cloud authentication information according to the second key calculation parameter, the third key calculation parameter, and the current second device key.
[0231] The second key calculation parameter is generated by the device to be networked. Based on this, the device to be networked needs to send the second key calculation parameter to the device cloud platform. Optionally, the beacon broadcast by the device to be networked includes the second key calculation parameter. The networking device can obtain the second key calculation parameter after receiving the beacon of the device to be networked, and further send the second key calculation parameter to the device cloud platform through the networking cloud platform. Optionally, the length of the second key calculation parameter is greater than or equal to one byte. For example, the length of the second key calculation parameter is 1 byte; or the length of the second key calculation parameter is 2 bytes; or the length of the second key calculation parameter is 3 bytes. In practical applications, the length of the second key calculation parameter can be determined according to the specific content setting of the second key calculation parameter. The embodiments of the present application do not limit this. Optionally, the second key calculation parameter includes a random number, which can be either pre-set or updated in real time. The embodiments of the present application do not limit this.
[0232] The third key calculation parameter is generated by the device cloud platform. Optionally, the length of the third key calculation parameter is greater than or equal to one byte. For example, the length of the third key calculation parameter is 1 byte; or the length of the third key calculation parameter is 2 bytes; or the length of the third key calculation parameter is 3 bytes. In practical applications, the length of the third key calculation parameter can be determined according to the specific content setting of the third key calculation parameter. The embodiments of the present application do not limit this. Optionally, the third key calculation parameter includes a random number, which can be either pre-set or updated in real time. The embodiments of the present application do not limit this.
[0233] Optionally, the above device cloud platform generates the first cloud authentication information according to the second key calculation parameter, the third key calculation parameter, and the current second device key, including the following steps:
[0234] Step 612, the device cloud platform combines the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter.
[0235] After receiving the second key calculation parameter, the device cloud platform may generate the third key calculation parameter, and then combine the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter. The embodiments of the present application do not limit the manner of combining the second key calculation parameter and the third key calculation parameter. The following exemplarily shows several manners of combining the second key calculation parameter and the third key calculation parameter. Optionally, the above step 612 includes any one of the following:
[0236] (1) The device cloud platform performs data splicing processing on the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter;
[0237] (2) The device cloud platform performs multiplication operation processing on the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter;
[0238] (3) The device cloud platform uses the second key calculation parameter as an encryption key to encrypt the third key calculation parameter to obtain a combined key calculation parameter;
[0239] (4) The device cloud platform uses the third key calculation parameter as an encryption key to encrypt the second key calculation parameter to obtain a combined key calculation parameter.
[0240] The embodiments of the present application do not limit the manner of encryption processing. The device cloud platform may perform encryption processing using an encryption algorithm. Optionally, the encryption algorithm includes, but is not limited to, any one of the following: AES128-CMAC, AES256-CMAC, AES128-CBC (Cipher Block Chaining), AES256-CBC, AES128-GCM (Galois / Counter Mode), AES256-GCM.
[0241] Step 614, the device cloud platform processes the combined key calculation parameter and the current second device key using a second key generation algorithm to obtain a second encryption key.
[0242] The device cloud platform may process the combined key calculation parameter and the current second device key using a second key generation algorithm to obtain a second encryption key. Optionally, the second key generation algorithm includes any one of the following: AES128-CMAC, HKDF-based KDF, PBKDF, SHA, DES algorithm, 3DES algorithm.
[0243] Step 616, the device cloud platform processes the second encryption key using a first encoding method to obtain first cloud authentication information.
[0244] Since the second encryption key obtained through the second key generation algorithm is usually binary data, in order to obtain authentication information in the form of a visible string, the second encryption key needs to be encoded. In the embodiments of the present application, the second encryption key is encoded using a first encoding method to obtain first cloud authentication information. Optionally, the first encoding method includes: Base64 (representing binary data based on 64 printable characters).
[0245] Step 620, the device cloud platform sends the first cloud authentication information and the third key calculation parameter to the network configuration cloud platform.
[0246] In the process of authenticating the identity of the device cloud platform, the device cloud platform and the device to be connected to the network need to generate cloud authentication information respectively. In order for the cloud authentication information generated by the device to be connected to the network and the cloud authentication information generated by the device cloud platform to be consistent, in the embodiments of the present application, the device cloud platform needs to send the third key calculation parameter used in the calculation process of the cloud authentication information to the device to be connected to the network. In addition, since in the embodiments of the present application, the authentication of the identity of the device cloud platform is performed by the device to be connected to the network, the device cloud platform also needs to send the first cloud authentication information it determines to the device to be connected to the network. Therefore, the device cloud platform needs to send the first cloud authentication information and the third key calculation parameter to the network configuration cloud platform.
[0247] Step 630, the network configuration cloud platform sends the first cloud authentication information and the third key calculation parameter to the network configuration device.
[0248] After receiving the first cloud authentication information and the third key calculation parameter, the network configuration cloud platform can further forward the first cloud authentication information and the third key calculation parameter to the network configuration device.
[0249] Step 640, the network configuration device sends the first cloud authentication information and the third key calculation parameter to the device to be connected to the network.
[0250] After receiving the first cloud authentication information and the third key calculation parameter, the network configuration device can further forward the first cloud authentication information and the third key calculation parameter to the device to be connected to the network.
[0251] It should be noted that in the embodiments of the present application, the first cloud authentication information, the third key calculation parameter, and the first key calculation parameter can be sent to the device to be networked simultaneously. That is, the first cloud authentication information, the third key calculation parameter, and the first key calculation parameter can be carried in the same information or signaling and sent to the device to be networked in a packaged manner; or, the first cloud authentication information, the third key calculation parameter, and the first key calculation parameter can also be sent to the device to be networked separately. That is, the first cloud authentication information, the third key calculation parameter, and the first key calculation parameter are sent to the device to be networked as different information or signaling.
[0252] Step 650: The device to be networked generates the second cloud authentication information.
[0253] The second cloud authentication information is used to authenticate the identity of the device cloud platform. In the embodiments of the present application, in order to ensure that the first cloud authentication information and the second cloud authentication information can be consistent, the calculation parameters and calculation methods of the first cloud authentication information and the second cloud authentication information need to be kept consistent. Based on this, the above step 650 includes: The device to be networked generates the second cloud authentication information according to the second key calculation parameter, the third key calculation parameter, and the current first device key. For the introduction of the second key calculation parameter and the third key calculation parameter, etc., please refer to the above embodiments and will not be elaborated here.
[0254] Optionally, the above-mentioned device to be networked generates the second cloud authentication information according to the second key calculation parameter, the third key calculation parameter, and the current first device key, including: The device to be networked combines the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter; uses the second key generation algorithm to process the combined key calculation parameter and the current first device key to obtain a first encryption key; uses the first coding method to process the first encryption key to obtain the second cloud authentication information. Optionally, the above step 652 includes any one of the following: The device to be networked performs data splicing processing on the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter; The device to be networked performs a multiplication operation on the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter; The device to be networked uses the second key calculation parameter as the encryption key to encrypt the third key calculation parameter to obtain a combined key calculation parameter; The device to be networked uses the third key calculation parameter as the encryption key to encrypt the second key calculation parameter to obtain a combined key calculation parameter. For the introduction of the device to be networked to determine the second cloud authentication information, please refer to the above introduction of the device cloud platform to determine the first cloud authentication information and will not be elaborated here.
[0255] Step 660: Before the device to be networked accesses the first access point, it authenticates the identity of the device cloud platform based on the first cloud authentication information and the second cloud authentication information.
[0256] On the one hand, the device to be networked receives the first cloud authentication information determined by the device cloud platform. On the other hand, the device to be networked determines the second cloud authentication information by itself. After that, before the device to be networked accesses the first access point, it authenticates the identity of the device cloud platform based on the first cloud authentication information and the second cloud authentication information. Optionally, when the first cloud authentication information and the second cloud authentication information are consistent, the identity authentication of the device cloud platform passes; when the first cloud authentication information and the second cloud authentication information are inconsistent, the identity authentication of the device cloud platform fails.
[0257] When the identity authentication of the device cloud platform fails, the device to be networked will not access the first access point. As a result, the device to be networked and the device cloud platform do not need to update the device key of the device to be networked. Therefore, when the identity authentication of the device cloud platform fails, the device to be networked needs to notify the device cloud platform to avoid the device cloud platform updating the device key of the device to be networked. Based on this, after the above step 660, the following steps are further included:
[0258] Step 670, when the identity authentication of the device cloud platform fails, the device to be networked sends the first identity authentication result to the network configuration device.
[0259] The first identity authentication result is used to indicate that the identity authentication of the device cloud platform fails. When the first cloud authentication information and the second cloud authentication information are inconsistent, the identity authentication of the device cloud platform fails, and the device to be networked sends the first identity authentication result to the network configuration device.
[0260] Since the identity authentication of the device cloud platform fails, the device to be networked cannot successfully access the first access point, and thus the network configuration device does not need to configure the device to be networked to access the first access point anymore. Based on this, after the above step 670, the following is further included: The network configuration device cancels accessing the second access point. The second access point is the access point started by the device to be networked. For example, the soft AP described in the above embodiment.
[0261] Step 680, the network configuration device sends the first identity authentication result to the network configuration cloud platform.
[0262] After receiving the first identity authentication result, the network configuration device further forwards the first identity authentication result to the network configuration cloud platform.
[0263] Step 690, the network configuration cloud platform sends the first identity authentication result to the device cloud platform.
[0264] After receiving the first identity authentication result, the network configuration cloud platform further forwards the first identity authentication result to the device cloud platform.
[0265] Step 600, the device cloud platform deletes the updated second device key.
[0266] In the case where the identity authentication for the device cloud platform fails, the device to be networked will not be connected to the first access point, and thus it is not necessary for the device to be networked and the device cloud platform to update the device key of the device to be networked. Therefore, after receiving the first identity authentication result, the device cloud platform deletes the stored updated second device key and retains the current second device key. Optionally, the first identity authentication result includes the device identifier of the device to be networked. For example, the device ID of the device to be networked, so that after the device cloud platform receives the first identity authentication result, it resolves the device identifier of the device to be networked, and then finds the corresponding updated second device key according to the device identifier of the device to be networked and deletes the updated second device key.
[0267] Since the device to be networked performs two-way identity authentication before accessing the first access point, that is, it performs identity authentication for both the device cloud platform and the device to be networked. The identity authentication for the device to be networked is performed by the network configuration device. Next, the identity authentication for the device to be networked will be introduced.
[0268] In one example, as Figure 6 shown, the above method further includes the following steps:
[0269] Step 601, the device cloud platform sends the second device authentication information to the network configuration cloud platform.
[0270] The identity authentication for the device to be networked requires the use of the first device authentication information and the second device authentication information. Among them, the first device authentication information is generated by the device to be networked, and the second device authentication information is generated by the device cloud platform. For the introduction of the first device authentication information and the second device authentication information, please refer to the introduction of the first authentication parameter and the second authentication parameter in the above Figure 3 embodiment, which will not be elaborated here. After generating the second device authentication information, the device cloud platform sends the second device authentication information to the network configuration cloud platform.
[0271] Step 602, the network configuration cloud platform sends the second device authentication information to the network configuration device.
[0272] After receiving the second device authentication information, the network configuration cloud platform further sends the second device authentication information to the network configuration device.
[0273] Step 603, the device to be networked sends the first device authentication information to the network configuration device.
[0274] After generating the first device authentication information, the device to be networked also sends the first device authentication information to the network configuration device.
[0275] Step 604: Before configuring the device to be networked to access the first access point, the network configuration device authenticates the identity of the device to be networked based on the first device authentication information and the second device authentication information.
[0276] On the one hand, the network configuration device receives the second device authentication information from the device cloud platform. On the other hand, the network configuration device receives the first device authentication information from the device to be networked. After that, before configuring the device to be networked to access the first access point, the network configuration device authenticates the identity of the device to be networked based on the first device authentication information and the second device authentication information. In the embodiments of the present application, when the first device authentication information is consistent with the second device authentication information, the identity authentication of the device to be networked passes; when the first device authentication information is inconsistent with the second device authentication information, the identity authentication of the device to be networked fails.
[0277] In the case where the identity authentication of the device to be networked fails, the device to be networked will not access the first access point. As a result, the device to be networked and the device cloud platform do not need to update the device key of the device to be networked. Therefore, in the case where the identity authentication of the device to be networked fails, the network configuration device needs to notify the device cloud platform to prevent the device cloud platform from updating the device key of the device to be networked. Based on this, after the above step 604, the following steps are further included:
[0278] Step 605: When the identity authentication of the device to be networked fails, the network configuration device sends a second identity authentication result to the network configuration cloud platform.
[0279] The second identity authentication result is used to indicate that the identity authentication of the device to be networked fails. When the first device authentication information is inconsistent with the second device authentication information, the identity authentication of the device to be networked fails, and the network configuration device sends the second identity authentication result to the network configuration cloud platform.
[0280] Since the identity authentication of the device to be networked fails, the device to be networked cannot successfully access the first access point. Consequently, the network configuration device does not need to configure the device to be networked to access the first access point anymore. Based on this, after the above step 604, the following is further included: The network configuration device cancels accessing the second access point.
[0281] Step 606: The network configuration cloud platform sends the second identity authentication result to the device cloud platform.
[0282] After receiving the second identity authentication result, the network configuration cloud platform further forwards the second identity authentication result to the device cloud platform.
[0283] Step 607: The device cloud platform deletes the updated second device key.
[0284] In the case where the identity authentication of the device to be networked fails, the device to be networked will not be connected to the first access point, and thus the device to be networked and the device cloud platform do not need to update the device key of the device to be networked. Therefore, after receiving the second identity authentication result, the device cloud platform deletes the stored updated second device key and retains the current second device key. Optionally, the second identity authentication result includes the device identifier of the device to be networked. For example, the device ID of the device to be networked. After the device cloud platform receives the second identity authentication result, it parses out the device identifier of the device to be networked, and then finds the corresponding updated second device key according to the device identifier of the device to be networked, and deletes the updated second device key.
[0285] In summary, the technical solution provided by the embodiments of the present application authenticates the identity of the device to be networked and the device cloud platform before configuring the device to be networked to access the AP, so as to achieve the purpose of two-way identity authentication, effectively avoid fake devices from accessing the AP, and improve the security of the AP. Moreover, in the embodiments of the present application, when the identity authentication of the device to be networked fails, or when the identity authentication of the device cloud platform fails, the device cloud platform will not update the device key of the device to be networked, that is, delete the stored updated device key to ensure synchronization with the device key update process on the side of the device to be networked.
[0286] From the above Figure 5 embodiment and Figure 6 description of the embodiment, it can be seen that when the device to be networked is successfully configured to access the first access point, the device key of the device to be networked will be updated, so the device key set when the device to be networked leaves the factory may be replaced by the updated device key. In one example, to ensure that the device to be networked and the device cloud platform can still use the device key set when the device to be networked leaves the factory, the device to be networked and the device cloud platform always retain the device key set when the device to be networked leaves the factory, and the device to be networked adds an identifier in the beacon it broadcasts to indicate whether to use the device key set when the device to be networked leaves the factory. Next, this example will be described.
[0287] In one example, as Figure 7 shown, the above method further includes the following steps (steps 710-760):
[0288] Step 710, the device to be networked broadcasts a beacon of the second access point, and the beacon includes a first identifier.
[0289] The second access point is the access point started by the device to be networked, such as the soft AP in the above embodiments. The device to be networked can start the second access point when entering the network configuration mode. Optionally, the device to be networked automatically enters the network configuration mode when it is first turned on, or the device to be networked is passively triggered to enter the network configuration mode by user operation. After the device to be networked starts the second access point, it can broadcast the beacon of the second access point.
[0290] In the embodiments of the present application, a first identifier is added to the beacon of the second access point broadcast by the device to be networked, and the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory. In one example, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory. Among them, the first numerical value and the second numerical value are numerical values with different values. The embodiments of the present application do not limit the specific values of the first numerical value and the second numerical value. Optionally, the first numerical value is 1 and the second numerical value is 0; or, the first numerical value is 0 and the second numerical value is 1. Optionally, the length of the first identifier is greater than or equal to one bit. For example, the length of the first identifier is 1 bit; or, the length of the first identifier is 2 bits; or, the length of the first identifier is 3 bits. In practical applications, the length of the first identifier can be determined according to the specific content setting of the first identifier, and the embodiments of the present application do not limit this.
[0291] In one example, the beacon of the second access point includes at least one of the following fields: BSSID field, SSID field, custom field (such as Vendor Specific field). Optionally, the first identifier can be set in any of the above fields, that is, the BSSID field includes the first identifier; or, the SSID field includes the first identifier; or, the custom field includes the first identifier. Usually, due to permission restrictions, the custom field sometimes cannot be obtained by other devices, and the compatibility is poor. Therefore, the first identifier can be in a field other than the custom field to avoid the network configuration device being unable to obtain it.
[0292] Step 720, the network configuration device receives the beacon of the second access point.
[0293] The network configuration device can scan the beacons broadcast by other devices on different channels. Thus, on the channel where the device to be networked broadcasts the beacon of the second access point, the network configuration device can scan the beacon of the second access point, that is, the network configuration device can receive the beacon of the second access point.
[0294] Step 730, the network configuration device sends the first identifier to the network configuration cloud platform.
[0295] After receiving the beacon of the second access point, the distribution network device can further parse the beacon of the second access point to obtain the first identifier. After that, the distribution network device can send the first identifier to the distribution network cloud platform.
[0296] Step 740, the distribution network cloud platform sends the first identifier to the device cloud platform.
[0297] After receiving the first identifier, the distribution network cloud platform further sends the first identifier to the device cloud platform.
[0298] In the embodiments of this application, the device to be networked and the device cloud platform can choose to use the device key set when the device to be networked leaves the factory, or can choose to update the device key of the device to be networked after the device to be networked is networked. Therefore, the device to be networked and the device cloud platform need to always retain the device key set when the device to be networked leaves the factory, so as to be able to choose to use the device key set when the device to be networked leaves the factory subsequently. Based on this, the above method further includes the following steps:
[0299] Step 750, the device cloud platform retains the device key set when the device to be networked leaves the factory.
[0300] The device cloud platform always retains the device key set when the device to be networked leaves the factory during the networking process of the device to be networked. Optionally, in the embodiments of this application, when the distribution network device parses the beacon of the second access point to obtain the first identifier, it can obtain the device identifier of the device to be networked, such as the device ID, and then send the device identifier of the device to be networked and the first identifier to the device cloud platform through the distribution network cloud platform at the same time. When the device cloud platform receives the device identifier of the device to be networked and the first identifier, it can determine the specific device to be networked according to the device identifier of the device to be networked and the first identifier, and then query the device key set when the device to be networked leaves the factory, and save the device key set when the device to be networked leaves the factory.
[0301] Step 760, the device to be networked retains the device key set when the device to be networked leaves the factory.
[0302] The device to be networked also always retains the device key set when the device to be networked leaves the factory. During the subsequent networking process, the device to be networked can either use the device key when the device to be networked leaves the factory as the current first device key used in this networking process, or use the first device key updated in the previous networking process as the current first device key used in this networking process.
[0303] In summary, in the technical solution provided by the embodiment of the present application, the device key set when the device to be networked leaves the factory is always retained by the device to be networked and the device cloud platform, so that in the subsequent network configuration process, it is possible to choose to use the device key set when the device to be networked leaves the factory for identity authentication, or to choose to use the device key updated in the previous network configuration process for identity authentication, realizing the recoverability of the device key set when the device to be networked leaves the factory during the network configuration process. In addition, in the beacon of the access point broadcast by the device to be networked in the embodiment of the present application, an identifier is added to indicate whether to use the device key set when the device to be networked leaves the factory, so as to ensure that the device cloud platform clearly knows whether to use the device key set when the device to be networked leaves the factory during this network configuration process, and ensure the effectiveness and accuracy of identity authentication between the device to be networked and the device cloud platform.
[0304] From the above Figure 5 embodiment to Figure 7 embodiment, it can be seen that on the device cloud platform side, whether to replace the current second device key with the updated second device key after this network configuration depends on the reporting of the identity authentication result. If the identity authentication result indicates that the identity authentication fails, the stored updated second device key is deleted. If the identity authentication result indicates that the identity authentication is successful, the current second device key is replaced with the updated second device key. In one example, in order to reduce the signaling interaction between the device to be networked and the device cloud platform and the proxy devices and proxy cloud platforms between the two, in the embodiment of the present application, a second identifier is added to the beacon broadcast by the device to be networked, and this second identifier is used to indicate the version of the current device key. Next, this example will be introduced and explained.
[0305] In one example, as Figure 8 shown, the above method further includes the following steps (steps 810 to 870):
[0306] Step 810, the device to be networked broadcasts the beacon of the second access point.
[0307] For the introduction and explanation of the second access point and the beacon of the second access point, please refer to the above embodiments and will not be elaborated here. In the embodiment of the present application, the current second identifier is added to the beacon of the second access point broadcast by the device to be networked, and this current second identifier is used to indicate the version of the current first device key. Optionally, the length of the second identifier is greater than or equal to one byte. For example, the length of the second identifier is 1 byte; or, the length of the second identifier is 2 bytes; or, the length of the second identifier is 3 bytes. In practical applications, the length of the second identifier can be determined according to the specific content setting of the second identifier, and the embodiment of the present application does not limit this.
[0308] In one example, the beacon of the second access point includes at least one of the following fields: BSSID field, SSID field, custom field. Optionally, the second identifier may be set in any of the above fields, that is, the BSSID field includes the second identifier; or, the SSID field includes the second identifier; or, the custom field includes the second identifier. Usually, due to permission restrictions, the custom field sometimes cannot be obtained by other devices, and the compatibility is poor. Therefore, the first identifier may be in a field other than the custom field to avoid the configuration device being unable to obtain it.
[0309] Step 820, the configuration device receives the beacon of the second access point.
[0310] For the introduction and description of step 820, please refer to the introduction and description of step 720 above, and will not be elaborated here.
[0311] Step 830, the configuration device sends the current second identifier to the configuration cloud platform.
[0312] After receiving the beacon of the second access point, the configuration device can further parse the beacon of the second access point to obtain the current second identifier. Then, the configuration device can send the current second identifier to the configuration cloud platform.
[0313] Step 840, the configuration cloud platform sends the current second identifier to the device cloud platform.
[0314] After receiving the current second identifier, the configuration cloud platform further sends the current second identifier to the device cloud platform.
[0315] Step 850, the device cloud platform obtains a reference third identifier.
[0316] The device cloud platform updates the current second device key during each network configuration process. If the previous network configuration process fails, it means that the device to be networked has not updated the first device key, then the second device key updated by the device cloud platform during the previous network configuration process is invalid, and the device cloud platform still uses the second device key used during the previous network configuration process for identity authentication during this network configuration process; if the previous network configuration process is successful, it means that the device to be networked has also updated the first device key, then the second device key updated by the device cloud platform during the previous network configuration process is valid, and the device cloud platform uses the second device key updated during the previous network configuration process for identity authentication during this network configuration process.
[0317] Therefore, in the embodiments of the present application, version identifiers are configured for the first device key and the second device key. The device cloud platform receives the current second identifier from the device to be networked to obtain the version of the current first device key on the side of the device to be networked. Then, the device cloud platform obtains the stored reference third identifier, which is the version of the second device key updated by the device cloud platform during the last network configuration process of the device to be networked. If the current second identifier is consistent with the reference third identifier, it indicates that the last network configuration process was successful; if the current second identifier is inconsistent with the reference third identifier, it indicates that the last network configuration process failed.
[0318] Step 860: When the current second identifier is consistent with the reference third identifier, the device cloud platform uses the second device key updated by the device cloud platform during the last network configuration process of the device to be networked as the current second device key.
[0319] When the current second identifier is consistent with the reference third identifier, the device cloud platform determines that the last network configuration process was successful, and the first device key on the side of the device to be networked was also updated during the last network configuration process. The first device key used by the device to be networked during this network configuration process is the one updated during the last network configuration process. Therefore, to ensure consistency between the device cloud platform side and the device to be networked side, the device cloud platform side also uses the second device key updated by the device cloud platform during the last network configuration process of the device to be networked as the current second device key, that is, as the second device key used during this network configuration process.
[0320] Step 870: When the current second identifier is inconsistent with the reference third identifier, the device cloud platform uses the second device key used by the device cloud platform during the last network configuration process of the device to be networked as the current second device key.
[0321] When the current second identifier is inconsistent with the reference third identifier, the device cloud platform determines that the last network configuration process failed, and the first device key on the side of the device to be networked was not updated during the last network configuration process. The first device key used by the device to be networked during this network configuration process is still the one used during the last network configuration process. Therefore, to ensure consistency between the device cloud platform side and the device to be networked side, the device cloud platform side also uses the second device key used by the device cloud platform during the last network configuration process of the device to be networked as the current second device key, that is, as the second device key used during this network configuration process.
[0322] During this power distribution process, the device cloud platform will update the current second device key; after the device to be networked successfully accesses the first access point, it will update the current first device key. Therefore, in order to ensure that the device cloud platform can know whether the power distribution process of the device to be networked is successful in the next power distribution process, the device cloud platform needs to update the reference third identifier; the device to be networked needs to update the current second identifier after accessing the first access point. Based on this, optionally, the above method further includes: after the device to be networked accesses the first access point, updating the current second identifier to obtain an updated second identifier; replacing the current second identifier with the updated second identifier.
[0323] Optionally, both the second identifier and the reference third identifier can be numbered using Arabic numerals; or, numbered using Roman numerals. For example, the second identifier is numbered using Arabic numerals. If the current second identifier is 1 during this power distribution process, the updated second identifier during this power distribution process is 2, the current second identifier during the next power distribution process is 2, and the updated second identifier during the next power distribution process is 3.
[0324] In summary, the technical solution provided by the embodiment of the present application adds a version identifier of the device key of the device to be networked to the beacon broadcast by the device to be networked to indicate the version of the current device key of the device to be networked. After receiving the version identifier, the device cloud platform compares the version identifier with the version identifier of the device key updated by the device cloud platform during the previous power distribution process of the device to be networked. If the two version identifiers are the same, it means that the previous power distribution process of the device to be networked was successful, the device to be networked updated the device key, and the current power distribution process performs identity authentication based on the device key updated during the previous power distribution process; if the two version identifiers are different, it means that the previous power distribution process of the device to be networked failed, the device to be networked did not update the device key, and the current power distribution process performs identity authentication based on the device key used during the previous power distribution process. By adding the version identifier of the device key, it is possible to indicate whether the power distribution process and identity authentication are successful through the version identifier, avoiding the need for additional information or signaling to indicate the power distribution result and identity authentication result, reducing signaling overhead, and helping to improve the power distribution efficiency and key update efficiency.
[0325] Next, taking the second access point as a soft AP and the first access point as a home WiFi network as an example, several methods of soft AP power distribution for identity authentication before power distribution will be introduced and described.
[0326] As Figure 9 shown, the soft AP power distribution method for identity authentication before power distribution provided by the embodiment of the present application includes the following steps:
[0327] Step 901, the device to be networked activates the soft AP and broadcasts the beacon of the soft AP. The beacon of the soft AP is used to indicate the device information of the device to be networked. Optionally, the beacon of the soft AP includes at least one of the following fields: BSSID field, SSID field, and manufacturer-customized field.
[0328] Step 902, when the network configuration device scans the beacon of the soft AP, it obtains the device information of the device to be networked. Optionally, the device information of the device to be networked includes at least one of the following: the device ID of the device to be networked, the device manufacturer name of the device to be networked, and the second random number.
[0329] Step 903, the network configuration device sends an authentication information acquisition request to the network configuration cloud platform. The authentication information acquisition request is used to request to obtain the identity authentication information. Optionally, the device information of the device to be networked is included in the authentication information acquisition request. Optionally, as Figure 9 shown, if there is no secure connection established between the network configuration device and the network configuration cloud platform, the network configuration device needs to first establish a secure connection with the network configuration cloud platform and then send an authentication information acquisition request to the network configuration cloud platform.
[0330] Step 904, the network configuration cloud platform determines the device cloud platform. In the embodiment of the present application, when the network configuration cloud platform sends an authentication information acquisition request to the device cloud platform, it needs to first determine the device cloud platform corresponding to the device to be networked. Optionally, the device manufacturer name of the device to be networked is included in the authentication information acquisition request sent by the network configuration device to the network configuration cloud platform, and thus the network configuration cloud platform can determine the device cloud platform corresponding to the device to be networked according to the device manufacturer name of the device to be networked.
[0331] Step 905, the network configuration cloud platform sends an authentication information acquisition request to the device cloud platform. After receiving the authentication information acquisition request, the network configuration cloud platform further sends an authentication information acquisition request to the device cloud platform to request to obtain the identity authentication information. Optionally, as Figure 9 shown, if there is no secure connection established between the network configuration cloud platform and the device cloud platform, the network configuration cloud platform needs to first establish a secure connection with the device cloud platform and then send an authentication information acquisition request to the device cloud platform.
[0332] Step 906, the device cloud platform determines the second device key. Optionally, the device ID of the device to be networked is included in the authentication information acquisition request, and the device cloud platform queries the device key of the device to be networked according to the device ID of the device to be networked. In the embodiment of the present application, the device key of the device to be networked stored at the device cloud platform is called the second device key.
[0333] Step 907: The device cloud platform determines the second device authentication information based on the second device key and the second random number. The device cloud platform may encrypt the second random number using the second device key to obtain the second device authentication information.
[0334] Step 908: The device cloud platform generates a third random number and determines the first cloud authentication information based on the second device key, the second random number, and the third random number. The device cloud platform may encrypt the second random number and the third random number using the second device key to obtain the first cloud authentication information.
[0335] Step 909: The device cloud platform generates a first random number and updates the second device key based on the first random number to obtain the updated second device key. After the device cloud platform obtains the updated second device key, it may cache the updated second device key. Subsequently, within a preset time interval, if the reported information indicating that the identity authentication of the device to be networked has passed is not received, the cached updated second device key is deleted.
[0336] Step 910: The device cloud platform sends the second device authentication information, the third random number, the first cloud authentication information, and the first random number to the network configuration cloud platform.
[0337] Step 911: The network configuration cloud platform sends the second device authentication information, the third random number, the first cloud authentication information, and the first random number to the network configuration device.
[0338] Step 912: The network configuration device sends the third random number, the first cloud authentication information, and the first random number to the device to be networked. As Figure 9 shown, if there is no soft AP connection established between the device to be networked and the network configuration device, the network configuration device needs to first connect to the soft AP started by the device to be networked and then send the third random number, the first cloud authentication information, and the first random number to the device to be networked.
[0339] Step 913: The device to be networked determines the second cloud authentication information based on the first device key, the second random number, and the third random number. In the embodiments of the present application, the device key of the device to be networked stored on the device to be networked side is referred to as the first device key. The device cloud platform may encrypt the second random number and the third random number using the first device key to obtain the second cloud authentication information.
[0340] Step 914: If the first cloud authentication information and the second cloud authentication information are consistent, the device to be networked passes the identity authentication for the device cloud platform; otherwise, the device to be networked sends the first identity authentication result to the network configuration device. The first identity authentication result is used to indicate that the identity authentication for the device cloud platform fails.
[0341] Step 915, the network configuration device sends the first identity authentication result to the network configuration cloud platform. In the embodiment of the present application, as Figure 9 shown, if the identity authentication for the device cloud platform fails, the network configuration device cancels the access to the soft AP and reconnects to the home WiFi network, that is, re - establishes a secure connection with the network configuration cloud platform. After that, the network configuration device sends the first identity authentication result to the network configuration cloud platform.
[0342] Step 916, the network configuration cloud platform sends the first identity authentication result to the device cloud platform.
[0343] Step 917, the device cloud platform deletes the updated second device key. Optionally, the first identity authentication result includes the device ID of the device to be networked. The device cloud platform can determine the updated second device key corresponding to the device to be networked in the cache according to the device ID of the device to be networked, and delete the updated second device key.
[0344] Step 918, the device to be networked determines the first device authentication information according to the first device key and the second random number. The device to be networked can encrypt the second random number with the first device key to obtain the first device authentication information.
[0345] Step 919, the device to be networked sends the first device authentication information to the network configuration device. In the embodiment of the present application, the network configuration device authenticates the identity of the device to be networked.
[0346] Step 920, if the first device authentication information is consistent with the second device authentication information, the network configuration device passes the identity authentication for the device to be networked; otherwise, the network configuration device sends the second identity authentication result to the network configuration cloud platform. The second identity authentication result is used to indicate that the identity authentication for the device to be networked fails.
[0347] Step 921, the network configuration device sends the second identity authentication result to the network configuration cloud platform. In the embodiment of the present application, as Figure 9 shown, if the identity authentication for the device to be networked fails, the network configuration device cancels the access to the soft AP and reconnects to the home WiFi network, that is, re - establishes a secure connection with the network configuration cloud platform. After that, the network configuration device sends the second identity authentication result to the network configuration cloud platform.
[0348] Step 922, the network configuration cloud platform sends the second identity authentication result to the device cloud platform.
[0349] Step 923, the device cloud platform deletes the updated second device key. Optionally, the second identity authentication result includes the device ID of the device to be networked. The device cloud platform can determine the updated second device key corresponding to the device to be networked in the cache according to the device ID of the device to be networked, and delete the updated second device key.
[0350] Step 924, the device to be networked updates the first device key according to the first random number to obtain the updated first device key, and replaces the first device key with the updated first device key. In the embodiment of the present application, as Figure 9 shown, if the identity authentication for the device to be networked passes, the network configuration device configures the device to be networked to access the home WiFi network, and then the device to be networked updates the first device key.
[0351] Step 925, the network configuration device sends the third identity authentication result to the network configuration cloud platform. The third identity authentication result is used to indicate that the identity authentication for the device to be networked passes. In the embodiment of the present application, as Figure 9 shown, after the network configuration device configures the device to be networked to access the home WiFi network, the device to be networked disconnects the soft AP connection with the network configuration device, and the network configuration device re - establishes a secure connection with the network configuration cloud platform, and then the network configuration device sends the third identity authentication result to the network configuration cloud platform.
[0352] Step 926, the network configuration cloud platform sends the third identity authentication result to the device cloud platform.
[0353] Step 927, the device cloud platform replaces the second device key with the updated second device key. Optionally, the third identity authentication result includes the device ID of the device to be networked. The device cloud platform can determine the updated second device key corresponding to the device to be networked in the cache according to the device ID of the device to be networked, and replaces the second device key with the updated second device key.
[0354] As Figure 10 shown, the soft AP network configuration method for identity authentication before network configuration provided by the embodiment of the present application includes the following steps:
[0355] Step 1001, the device to be networked starts the soft AP and broadcasts the beacon of the soft AP. The beacon includes a first identifier. The first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
[0356] Step 1002, when the network configuration device scans the beacon of the soft AP, it obtains the device information of the device to be networked. Optionally, the device information of the device to be networked includes at least one of the following: the device ID of the device to be networked, the device manufacturer name of the device to be networked, and the second random number.
[0357] Step 1003, the network configuration device sends an authentication information acquisition request to the network configuration cloud platform.
[0358] Step 1004, the network configuration cloud platform determines the device cloud platform.
[0359] Step 1005: The network configuration cloud platform sends an authentication information acquisition request to the device cloud platform.
[0360] For the descriptions of steps 1003 to 1005, please refer to the descriptions of steps 903 to 905 above, and details are not elaborated here.
[0361] Step 1006: The device cloud platform determines the second device key. And if the value of the first identifier is the first numerical value, the device key set when the device to be networked leaves the factory is used as the second device key. Optionally, the authentication information acquisition request includes the device ID of the device to be networked, and the device cloud platform queries the device key of the device to be networked according to the device ID of the device to be networked. In the embodiments of the present application, the device key of the device to be networked stored in the device cloud platform is referred to as the second device key. Optionally, when the first identifier is the first numerical value, the device key set when the device to be networked leaves the factory is used; when the first identifier is the second numerical value, the device key set when the device to be networked leaves the factory is not used.
[0362] Step 1007: The device cloud platform determines the second device authentication information according to the second device key and the second random number.
[0363] Step 1008: The device cloud platform generates a third random number, and determines the first cloud authentication information according to the second device key, the second random number and the third random number.
[0364] Step 1009: The device cloud platform generates a first random number, and updates the second device key according to the first random number to obtain the updated second device key.
[0365] Step 1010: The device cloud platform sends the second device authentication information, the third random number, the first cloud authentication information, and the first random number to the network configuration cloud platform.
[0366] Step 1011: The network configuration cloud platform sends the second device authentication information, the third random number, the first cloud authentication information, and the first random number to the network configuration device.
[0367] Step 1012: The network configuration device sends the third random number, the first cloud authentication information, and the first random number to the device to be networked.
[0368] Step 1013: The device to be networked determines the second cloud authentication information according to the first device key, the second random number and the third random number.
[0369] Step 1014: If the first cloud authentication information is consistent with the second cloud authentication information, the device to be networked passes the identity authentication for the device cloud platform; otherwise, the device to be networked sends the first identity authentication result to the network configuration device.
[0370] Step 1015, the power distribution device sends the first identity authentication result to the power distribution cloud platform.
[0371] Step 1016, the power distribution cloud platform sends the first identity authentication result to the device cloud platform.
[0372] Step 1017, the device cloud platform deletes the updated second device key.
[0373] Step 1018, the device to be networked determines the first device authentication information according to the first device key and the second random number.
[0374] Step 1019, the device to be networked sends the first device authentication information to the power distribution device.
[0375] Step 1020, if the first device authentication information is consistent with the second device authentication information, the power distribution device passes the identity authentication for the device to be networked; otherwise, the power distribution device sends the second identity authentication result to the power distribution cloud platform.
[0376] Step 1021, the power distribution device sends the second identity authentication result to the power distribution cloud platform.
[0377] Step 1022, the power distribution cloud platform sends the second identity authentication result to the device cloud platform.
[0378] Step 1023, the device cloud platform deletes the updated second device key.
[0379] For the introduction and description of steps 1007 to 1023, please refer to the introduction and description of the above steps 907 to 923, which will not be elaborated here.
[0380] Step 1024, the device to be networked updates the first device key according to the first random number to obtain the updated first device key, and replaces the first device key with the updated first device key. At the same time, the device key set when the device to be networked leaves the factory is always retained.
[0381] Step 1025, the power distribution device sends the third identity authentication result to the power distribution cloud platform.
[0382] Step 1026, the power distribution cloud platform sends the third identity authentication result to the device cloud platform.
[0383] For the introduction and description of steps 1025 and 1026, please refer to the introduction and description of the above steps 925 to 926, which will not be elaborated here.
[0384] Step 1027, the device cloud platform replaces the second device key with the updated second device key. At the same time, the device key set when the device to be networked leaves the factory is always retained.
[0385] Such asFigure 11 As shown in the figure, the soft AP network configuration method for identity authentication before network access provided by the embodiments of the present application includes the following steps:
[0386] Step 1101, the device to be networked starts the soft AP and broadcasts the beacon of the soft AP, and the beacon includes the current second identifier. The current second identifier is used to indicate the version of the current first device key of the device to be networked.
[0387] Step 1102, when the network configuration device scans the beacon of the soft AP, it obtains the device information of the device to be networked. Optionally, the device information of the device to be networked includes at least one of the following: the device ID of the device to be networked, the device manufacturer name of the device to be networked, and the second random number.
[0388] Step 1103, the network configuration device sends an authentication information acquisition request to the network configuration cloud platform.
[0389] Step 1104, the network configuration cloud platform determines the device cloud platform.
[0390] Step 1105, the network configuration cloud platform sends an authentication information acquisition request to the device cloud platform.
[0391] For the introduction and description of steps 1103 to 1105, please refer to the introduction and description of steps 903 to 905 above, and details are not elaborated here.
[0392] Step 1106, the device cloud platform determines the second device key according to the current second identifier. The device cloud platform stores the second device key K1 and its version V1 updated during the previous network configuration process, and the second device key K0 used during the previous network configuration process. Optionally, the device cloud platform can also save the version V0 of the second device key K0 used during the previous network configuration process. Optionally, the authentication information acquisition request received by the device cloud platform includes the device ID of the device to be networked and the current second identifier V. According to the device ID of the device to be networked, the device cloud platform can determine K1 and V1 as well as K0 and V0. Then, the device cloud platform compares the current second identifier V with the version V1. If V is consistent with V1, the second device key K1 updated during the previous network configuration process is used as the second device key for this network configuration process; if V is inconsistent with V1, the second device key K0 used during the previous network configuration process is used as the second device key for this network configuration process.
[0393] Step 1107, the device cloud platform determines the second device authentication information according to the second device key and the second random number.
[0394] Step 1108, the device cloud platform generates a third random number, and determines the first cloud authentication information according to the second device key, the second random number, and the third random number.
[0395] For the introduction and description of steps 1107 to 1108, please refer to the introduction and description of steps 907 to 908 above, which will not be elaborated here.
[0396] Step 1109, the device cloud platform generates a first random number, and updates the second device key according to the first random number to obtain an updated second device key, and replaces the second device key with the updated second device key. The device cloud platform updates the second device key to obtain the updated second device key K2 and its version V2. If V is the same as V1, then V2 replaces V1, V1 replaces V0, and K2 replaces K1. For the next network configuration process, K2 and V2 are the updated second device key and its version in the previous network configuration process, and K1 and V1 are the second device key and its version used in the previous network configuration process; if V is not the same as V1, then V2 replaces V0, V0 remains unchanged, and K2 replaces K0. For the next network configuration process, K2 and V2 are the updated second device key and its version in the previous network configuration process, and K0 and V0 are the second device key and its version used in the previous network configuration process.
[0397] Step 1110, the device cloud platform sends the second device authentication information, the third random number, the first cloud authentication information, and the first random number to the network configuration cloud platform.
[0398] Step 1111, the network configuration cloud platform sends the second device authentication information, the third random number, the first cloud authentication information, and the first random number to the network configuration device.
[0399] Step 1112, the network configuration device sends the third random number, the first cloud authentication information, and the first random number to the device to be networked.
[0400] Step 1113, the device to be networked determines the second cloud authentication information according to the first device key, the second random number, and the third random number.
[0401] For the introduction and description of steps 1110 to 1113, please refer to the introduction and description of steps 910 to 913 above, which will not be elaborated here.
[0402] Step 1114, if the first cloud authentication information and the second cloud authentication information are the same, the device to be networked passes the identity authentication for the device cloud platform; otherwise, the network configuration process ends.
[0403] Step 1115, the device to be networked determines the first device authentication information according to the first device key and the second random number.
[0404] Step 1116: The device to be networked sends the first device authentication information to the network configuration device.
[0405] For the introduction of steps 1115 to 1116, please refer to the introduction of steps 918 to 919 above, which will not be elaborated here.
[0406] Step 1117: If the first device authentication information is consistent with the second device authentication information, the network configuration device passes the identity authentication for the device to be networked; otherwise, the network configuration process ends.
[0407] Step 1118: The device to be networked updates the first device key according to the first random number to obtain the updated first device key, and replaces the first device key with the updated first device key. In the embodiments of the present application, as Figure 11 shown, after the network configuration device configures the device to be networked to access the home WiFi network, the soft AP connection between the device to be networked and the network configuration device is disconnected, and the network configuration process ends.
[0408] Next, a method for updating the key for identity authentication after configuring the device to be networked is introduced. Since Figure 12 the embodiment is an improvement over the above Figure 4 embodiment, for the identity authentication process and network configuration process not described in the Figure 12 embodiment, reference can be made to the introduction of the above Figure 4 embodiment, which will not be elaborated here.
[0409] Please refer to Figure 12 , which shows a flowchart of the key update method provided by an embodiment of the present application. This method can be applied to the network configuration system shown in Figure 1 . This method can include the following steps:
[0410] Step 1210: When the device to be networked accesses the first access point and the identity authentication for the device cloud platform is passed, the current first device key is processed according to the first key calculation parameter to obtain the updated first device key.
[0411] In the embodiments of the present application, the device manufacturer of the device to be networked can uniquely allocate a key K to the device to be networked and pre-configure the key K in the device to be networked. Since the device identifier of the device to be networked is used to uniquely identify the device to be networked, there is a one-to-one correspondence between the device identifier of the device to be networked and the key K of the device to be networked. The device manufacturer of the device to be networked can upload the device identifier of the device to be networked and the key K of the device to be networked to the cloud platform of the device manufacturer (i.e., the cloud platform corresponding to the device to be networked).
[0412] Since the device key of the device to be networked can be used to uniquely identify the device to be networked, and the device key of the device to be networked is both pre-set in the device to be networked and stored in the device cloud platform, after configuring the device to be networked to access the first access point, identity authentication can be performed based on the device key of the device to be networked. However, if the device key of the device to be networked remains unchanged all the time, the authentication information generated based on the device key of the device to be networked may also remain unchanged. During the process of configuring the device to be networked to access the first access point multiple times, the proxy cloud platform for identity authentication between the device to be networked and the device cloud platform may directly use the previously stored authentication information, rather than requesting and obtaining authentication information from the device cloud platform or the device to be networked during each identity authentication process. Such skipping the acquisition of authentication information will bring limitations to the improvement of the security of the AP. Therefore, the embodiments of the present application propose that after configuring the device to be networked to access the first access point and when the identity authentication for the device cloud platform is passed, update the device key of the device to be networked, so that after the next successful network configuration, identity authentication is performed between the device to be networked and the device cloud platform based on the updated device key of the device to be networked.
[0413] The embodiments of the present application use the first key calculation parameter to update the device key of the device to be networked. Optionally, the length of the first key calculation parameter is greater than or equal to one byte. For example, the length of the first key calculation parameter is 1 byte; or the length of the first key calculation parameter is 2 bytes; or the length of the first key calculation parameter is 3 bytes. In practical applications, the length of the first key calculation parameter can be determined according to the specific content setting of the first key calculation parameter, and the embodiments of the present application do not limit this. Optionally, the first key calculation parameter includes a random number, and the random number can be either pre-set or updated in real time, and the embodiments of the present application do not limit this.
[0414] In one example, the first key calculation parameter is generated by the device cloud platform (the cloud platform corresponding to the device to be networked). Based on this, in order to enable the device to be networked to also update the device key, the device cloud platform needs to send the first key calculation parameter to the device to be networked. After configuring the device to be networked to access the first access point, the information transmission between the device cloud platform and the device to be networked needs to pass through the network configuration cloud. Therefore, the device cloud platform needs to first send the first key calculation parameter to the network configuration cloud platform (the cloud platform corresponding to the first access point), and then the network configuration cloud platform further sends the first key calculation parameter to the device to be networked.
[0415] In the embodiments of the present application, the device key of the device to be networked pre - set in the device to be networked is referred to as the first device key. After the device to be networked receives the first key calculation parameter, it can update the current first device key according to the first key calculation parameter to obtain the updated first device key. Optionally, when the device to be networked receives the first key calculation parameter, it does not immediately update the current first device key according to the first key calculation parameter, but after passing the identity authentication for the device cloud platform, it updates the current first device key according to the first key calculation parameter, so as to ensure that the device to be networked and the device cloud platform synchronously update the device key of the device to be networked.
[0416] In one example, the device to be networked can use a key generation algorithm to process the first key calculation parameter and the current first device key to obtain the updated first device key. Based on this, step 540 above includes: The device to be networked uses the first key generation algorithm to process the first key calculation parameter and the current first device key to obtain the updated first device key. Optionally, the first key generation algorithm includes any one of the following: AES128 - CMAC, HKDF - basedKDF, PBKDF, SHA, DES algorithm, 3DES algorithm.
[0417] Step 1220, the device to be networked replaces the current first device key with the updated first device key.
[0418] After the device to be networked updates the current first device key, it immediately replaces the current first device key with the updated first device key. Thus, when performing identity authentication after the next successful network configuration, the authentication information determined based on the first device key can also be updated, avoiding the process that the network configuration cloud platform skips obtaining the authentication information, and effectively improving the security of the AP.
[0419] From the introduction and description of the above Figure 8 embodiments, it can be seen that if the device cloud platform can obtain the version of the first device key (the current first device key) used by the device to be networked in this identity authentication process, the device cloud platform can know whether the previous identity authentication of the device to be networked was successful and whether the key was updated, so as to facilitate the device cloud platform to determine which version of the second device key should be used for identity authentication in this identity authentication process. Based on this, in one example, as Figure 12 shown, the above - mentioned method further includes:
[0420] Step 1230, after the device to be networked accesses the first access point, it sends the current second identifier to the network configuration cloud platform.
[0421] The current second identifier is used to indicate the version of the current first device key. Optionally, the length of the second identifier is greater than or equal to one byte. For example, the length of the second identifier is 1 byte; or, the length of the second identifier is 2 bytes; or, the length of the second identifier is 3 bytes. In practical applications, the length of the second identifier can be determined according to the specific content setting of the second identifier, and the embodiments of the present application do not limit this. After the device to be networked accesses the first access point, it can establish a secure connection with the network configuration cloud platform and further send the current second identifier to the network configuration cloud platform.
[0422] Step 1240, the network configuration cloud platform sends the current second identifier to the device cloud platform.
[0423] After receiving the current second identifier, the network configuration cloud platform can further forward the current second identifier to the device cloud platform.
[0424] Step 1250, the device cloud platform obtains a reference third identifier, and the reference third identifier is the version of the second device key updated by the device cloud platform during the last network configuration process of the device to be networked.
[0425] The device cloud platform updates the current second device key during each identity authentication process. If the last identity authentication fails, it means that the device to be networked has not updated the first device key. Then, the second device key updated by the device cloud platform during the last identity authentication process is invalid, and the device cloud platform still uses the second device key used during the last identity authentication process for identity authentication during this identity authentication process; if the last identity authentication process is successful, it means that the device to be networked has also updated the first device key. Then, the second device key updated by the device cloud platform during the last identity authentication process is valid, and the device cloud platform uses the second device key updated during the last identity authentication process for identity authentication during this identity authentication process.
[0426] Therefore, the embodiments of the present application configure version identifiers for the first device key and the second device key. The device cloud platform receives the current second identifier from the device to be networked to obtain the version of the current first device key on the device to be networked side, and then the device cloud platform obtains the reference third identifier stored in itself, and the reference third identifier is the version of the second device key updated by the device cloud platform during the last identity authentication process of the device to be networked. If the current second identifier is consistent with the reference third identifier, it means that the last identity authentication process is successful; if the current second identifier is inconsistent with the reference third identifier, it means that the last identity authentication process fails.
[0427] Step 1260: When the current second identifier of the device cloud platform is consistent with the reference third identifier, the device cloud platform uses the second device key updated during the previous network configuration process on the device to be networked as the current second device key.
[0428] When the current second identifier of the device cloud platform is consistent with the reference third identifier, it is clear that the previous identity authentication process was successful, and the first device key was also updated on the device to be networked side during the previous identity authentication process. The first device key used on the device to be networked side during this identity authentication process is the one updated during the previous identity authentication process. Therefore, to ensure consistency between the device cloud platform side and the device to be networked side, the device cloud platform side also uses the second device key updated during the previous identity authentication process on the device to be networked as the current second device key, that is, as the second device key used during this identity authentication process.
[0429] Step 1270: When the current second identifier of the device cloud platform is inconsistent with the reference third identifier, the device cloud platform uses the second device key used during the previous network configuration process on the device to be networked as the current second device key.
[0430] When the current second identifier of the device cloud platform is inconsistent with the reference third identifier, it is clear that the previous identity authentication process failed, and the first device key was not updated on the device to be networked side during the previous identity authentication process. The first device key used on the device to be networked side during this identity authentication process is still the one used during the previous identity authentication process. Therefore, to ensure consistency between the device cloud platform side and the device to be networked side, the device cloud platform side also uses the second device key used during the previous identity authentication process on the device to be networked as the current second device key, that is, as the second device key used during this identity authentication process.
[0431] During the identity authentication process after this network configuration, whether the identity authentication process after the previous network configuration was successful affects which version of the second device key the device cloud platform uses as the current second device key during this identity authentication process. However, regardless of how the device cloud platform determines the current second device key, the device cloud platform needs to update the current second device key during the identity authentication process after this network configuration. This is to use the updated second device key as the current second device key for the identity authentication process after the next network configuration when the identity authentication process after this network configuration is successful. Based on this, the above method further includes the following steps:
[0432] Step 1280: The device cloud platform updates the current second device key according to the first key calculation parameter to obtain the updated second device key.
[0433] After the device cloud platform generates the first key calculation parameter, it immediately updates the current second device key according to the first key calculation parameter to obtain the updated second device key. In one example, the device cloud platform can use a key generation algorithm to process the first key calculation parameter and the current second device key to obtain the updated second device key. In addition, in order to ensure that the device keys separately updated by the device to be networked and the device cloud platform are consistent, the device to be networked and the device cloud platform should use the same key generation algorithm and key calculation parameters to update the device key of the device to be networked. Based on this, step 501 above includes: the device cloud platform uses the first key generation algorithm to process the first key calculation parameter and the current second device key to obtain the updated second device key. Optionally, the first key generation algorithm includes any one of the following: AES128-CMAC, HKDF-based KDF, PBKDF, SHA, DES algorithm, 3DES algorithm.
[0434] Step 1290, the device cloud platform replaces the current second device key with the updated second device key.
[0435] After the device cloud platform updates the current second device key, it replaces the current second device key with the updated second device key. At the same time, in the embodiments of the present application, the device cloud platform also retains the second device key used in the identity authentication process after this network configuration, that is, the current second device key. That is, after the identity authentication process after this network configuration, the second device key stored by the device cloud platform includes the updated second device key and the current second device key. Thus, in the identity authentication process after the next network configuration, if it is determined that the identity authentication process after this network configuration fails, the second device key (the current second device key) used in the identity authentication process after this network configuration is used for the identity authentication process after the next network configuration; if it is determined that the identity authentication process after this network configuration is successful, the updated second device key (the updated second device key) used in the identity authentication process after this network configuration is used for the identity authentication process after the next network configuration.
[0436] In summary, for the technical solution provided by the embodiments of the present application, after the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and the identity authentication is performed by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and improving the security of the AP. Moreover, in the embodiments of the present application, when the device to be networked accesses the AP and the identity authentication is passed, the device to be networked updates the device key of the device to be networked. Since the device cloud platform also updates the device key of the device to be networked in the identity authentication process after the device to be networked accesses the AP this time, in the next identity authentication process after the device to be networked accesses the AP, the relevant authentication information for identity authentication generated based on the device key can also be updated, preventing the proxy cloud platform between the device to be networked and the device cloud platform from directly using the stored authentication information by skipping the process of obtaining the authentication information, achieving the purpose of performing identity authentication with real-time update and further improving the security of the AP. In addition, the embodiments of the present application add a version identifier for the device key to indicate whether the identity authentication is successful after accessing the AP through the version identifier, avoiding the need for additional information or signaling to indicate the identity authentication result, reducing the signaling overhead, and helping to improve the identity authentication efficiency and the key update efficiency.
[0437] Taking the second access point as a soft AP and the first access point as a home WiFi network as an example, the method for soft AP networking with identity authentication after networking is introduced and described below.
[0438] As Figure 13 shown, the method for soft AP networking with identity authentication after networking provided by the embodiments of the present application includes the following steps:
[0439] Step 1301, the device to be networked generates a second random number, and determines first device authentication information according to the first device key and the second random number. In the embodiments of the present application, the device key of the device to be networked stored on the device to be networked side is called the first device key, and the device to be networked can encrypt the second random number with the first device key to obtain the first device authentication information. Optionally, as Figure 13 shown, if there is no secure connection established between the device to be networked and the networking cloud platform, the device to be networked needs to first establish a secure connection with the networking cloud platform, and then generate the second random number and determine the first device authentication information.
[0440] Step 1302: The device to be networked sends the first device authentication information, the current second identifier, and the device information of the device to be networked to the network configuration device. The current second identifier is used to indicate the version of the first device key of the device to be networked currently. Optionally, the device information of the device to be networked includes at least one of the following: the device manufacturer name of the device to be networked, the device ID of the device to be networked, and the second random number. In the embodiments of the present application, the network configuration device authenticates the identity of the device to be networked.
[0441] Step 1303: The network configuration cloud platform determines the device cloud platform. In the embodiments of the present application, when the network configuration cloud platform sends a request for obtaining authentication information to the device cloud platform, it needs to first determine the device cloud platform corresponding to the device to be networked. Optionally, the device information of the device to be networked sent by the device to be networked to the network configuration cloud platform includes the device manufacturer name of the device to be networked. Furthermore, the network configuration cloud platform can determine the device cloud platform corresponding to the device to be networked according to the device manufacturer name of the device to be networked.
[0442] Step 1304: The network configuration cloud platform sends a request for obtaining authentication information to the device cloud platform. The network configuration cloud platform further sends a request for obtaining authentication information to the device cloud platform to request for obtaining identity authentication information. Optionally, as Figure 13 shown, if there is no secure connection established between the network configuration cloud platform and the device cloud platform, the network configuration cloud platform needs to first establish a secure connection with the device cloud platform and then send a request for obtaining authentication information to the device cloud platform.
[0443] Step 1305: The device cloud platform determines the second device key according to the current second identifier. The device cloud platform stores the second device key K1 and its version V1 updated during the previous identity authentication process, and the second device key K0 used during the previous identity authentication process. Optionally, the device cloud platform can also save the version V0 of the second device key K0 used during the previous identity authentication process. Optionally, the request for obtaining authentication information received by the device cloud platform includes the device ID of the device to be networked and the current second identifier V. According to the device ID of the device to be networked, the device cloud platform can determine K1 and V1 as well as K0 and V0. Then, the device cloud platform compares the current second identifier V with the version V1. If V is consistent with V1, the second device key K1 updated during the previous identity authentication process is used as the second device key used during this identity authentication process; if V is inconsistent with V1, the second device key K0 used during the previous identity authentication process is used as the second device key used during this identity authentication process.
[0444] Step 1306: The device cloud platform determines the second device authentication information according to the second device key and the second random number. The device cloud platform can encrypt the second random number with the second device key to obtain the second device authentication information. AsFigure 13 As shown, if the first device authentication information is consistent with the second device authentication information, the device cloud platform passes the identity authentication for the device to be networked; otherwise, the identity authentication process ends.
[0445] Step 1307: The device cloud platform generates a third random number, and determines the first cloud authentication information according to the second device key, the second random number, and the third random number. The device cloud platform may encrypt the second random number and the third random number using the second device key to obtain the first cloud authentication information.
[0446] Step 1308: The device cloud platform generates a first random number, and updates the second device key according to the first random number to obtain an updated second device key, and replaces the second device key with the updated second device key. When the device cloud platform updates the second device key to obtain the updated second device key K2 and its version V2, if V is consistent with V1, then V2 replaces V1, V1 replaces V0, and K2 replaces K1. For the next identity authentication process, K2 and V2 are the second device key and its version updated in the previous identity authentication process, and K1 and V1 are the second device key and its version used in the previous identity authentication process; if V is inconsistent with V1, then V2 replaces V0, V0 remains unchanged, and K2 replaces K0. For the next identity authentication process, K2 and V2 are the second device key and its version updated in the previous identity authentication process, and K0 and V0 are the second device key and its version used in the previous identity authentication process.
[0447] Step 1309: The device cloud platform sends the first cloud authentication information, the first random number, and the third random number to the network configuration cloud platform.
[0448] Step 1310: The network configuration cloud platform sends the first cloud authentication information, the first random number, and the third random number to the device to be networked.
[0449] Step 1311: The device to be networked determines the second cloud authentication information according to the first device key, the second random number, and the third random number. In the embodiments of the present application, the device key of the device to be networked stored on the side of the device to be networked is called the first device key, and the device cloud platform may encrypt the second random number and the third random number using the first device key to obtain the second cloud authentication information.
[0450] Step 1312: If the first cloud authentication information is consistent with the second cloud authentication information, the device to be networked passes the identity authentication for the device cloud platform; otherwise, the identity authentication process ends, and the connection with the network configuration cloud platform is disconnected.
[0451] Step 1313: The device to be networked updates the first device key according to the first random number to obtain the updated first device key, and replaces the first device key with the updated first device key. In the embodiments of the present application, the first device key and its version used in the current identity authentication process of the device to be networked are K and V, and the updated first device key and its version in the current identity authentication process are K2 and V2. After that, the device to be networked replaces K and V with K2 and V2 respectively.
[0452] It should be noted that the embodiments of the present application introduce the key update method provided by the embodiments of the present application from the perspective of the interaction between the device to be networked, the network configuration device, the network configuration cloud platform, and the device cloud platform. The steps performed by the device to be networked as described above can be separately implemented as a key update method on the device to be networked side; the steps performed by the network configuration device as described above can be separately implemented as a key update method on the network configuration device side; the steps performed by the network configuration cloud platform as described above can be separately implemented as a key update method on the network configuration cloud platform side; the steps performed by the device cloud platform as described above can be separately implemented as a key update method on the device cloud platform side.
[0453] The following are the embodiments of the device of the present application, which can be used to execute the method embodiments of the present application. For the details not disclosed in the embodiments of the device of the present application, please refer to the method embodiments of the present application.
[0454] Please refer to Figure 14 which shows the block diagram of the key update device provided by an embodiment of the present application. This device has the function of implementing the method example on the device to be networked side as described above. This function can be implemented by hardware or by hardware executing corresponding software. This device can be the device to be networked introduced above, or can be set in the device to be networked. As Figure 14 shown, the device 1400 may include: a first key update module 1410 and a first key replacement module 1420.
[0455] In a possible implementation manner:
[0456] The first key update module 1410 is configured to update the current first device key according to the first key calculation parameter to obtain the updated first device key.
[0457] The first key replacement module 1420 is configured to replace the current first device key with the updated first device key.
[0458] In an example, the first key update module 1410 is configured to: process the first key calculation parameter and the current first device key by using a first key generation algorithm to obtain the updated first device key.
[0459] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0460] In one example, the first key calculation parameter includes a random number.
[0461] In one example, the first key calculation parameter is generated by the device cloud platform.
[0462] In one example, as Figure 15 shown, the apparatus 1400 further includes: a first cloud authentication information receiving module 1430, configured to receive first cloud authentication information from a network configuration device; a second cloud authentication information generating module 1440, configured to generate second cloud authentication information; and a device cloud platform identity authentication module 1450, configured to perform identity authentication on the device cloud platform based on the first cloud authentication information and the second cloud authentication information before accessing a first access point.
[0463] In one example, as Figure 15 shown, the second cloud authentication information generating module 1440 is configured to: generate the second cloud authentication information according to a second key calculation parameter, a third key calculation parameter, and the current first device key.
[0464] In one example, as Figure 15 shown, the second cloud authentication information generating module 1440 includes: a key combination sub-module 1442, configured to combine the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter; a key processing sub-module 1444, configured to process the combined key calculation parameter and the current first device key by using a second key generation algorithm to obtain a first encryption key; and an encoding processing sub-module 1446, configured to process the first encryption key by using a first encoding method to obtain the second cloud authentication information.
[0465] In one example, as Figure 15 shown, the key combination sub-module 1442 is configured to perform any one of the following: perform data splicing processing on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; perform multiplication operation processing on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; encrypt the third key calculation parameter by using the second key calculation parameter as an encryption key to obtain the combined key calculation parameter; encrypt the second key calculation parameter by using the third key calculation parameter as an encryption key to obtain the combined key calculation parameter.
[0466] In one example, the length of the third key calculation parameter is greater than or equal to one byte.
[0467] In one example, the third key calculation parameter includes a random number.
[0468] In one example, the third key calculation parameter is generated by the device cloud platform.
[0469] In one example, when the first cloud authentication information is consistent with the second cloud authentication information, the identity authentication for the device cloud platform passes; when the first cloud authentication information is inconsistent with the second cloud authentication information, the identity authentication for the device cloud platform fails.
[0470] In one example, as Figure 15 shown, the device 1400 further includes: a first authentication result sending module 1460, configured to send a first identity authentication result to the network configuration device when the identity authentication for the device cloud platform fails, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform fails.
[0471] In one example, as Figure 15 shown, the device 1400 further includes: a beacon broadcasting module 1470, configured to broadcast a beacon of a second access point, where the beacon includes a first identifier, and the second access point is an access point started by the device to be networked; wherein, the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
[0472] In one example, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
[0473] In one example, the device to be networked retains the device key set when the device to be networked leaves the factory.
[0474] In one example, the length of the first identifier is greater than or equal to one bit.
[0475] In one example, the first identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
[0476] In one example, as Figure 15 shown, the device 1400 further includes: a beacon broadcasting module 1470, configured to broadcast a beacon of a second access point, where the beacon includes a current second identifier, and the second access point is an access point started by the device to be networked; wherein, the current second identifier is used to indicate the version of the current first device key.
[0477] In one example, as Figure 15 shown, the device 1400 further includes: an identification update module 1480, configured to update the current second identification after accessing a first access point, to obtain an updated second identification; and an identification replacement module 1490, configured to replace the current second identification with the updated second identification.
[0478] In one example, the length of the second identification is greater than or equal to one byte.
[0479] In one example, the second identification is located in any one of the following fields included in the beacon: the BSSID field, the SSID field, and the custom field.
[0480] In another possible implementation:
[0481] A first key update module 1410, configured to process the current first device key according to a first key calculation parameter to obtain an updated first device key when accessing a first access point and the identity authentication for the device cloud platform is passed.
[0482] A first key replacement module 1420, configured to replace the current first device key with the updated first device key.
[0483] In one example, the first key update module 1410 is configured to: process the first key calculation parameter and the current first device key by using a first key generation algorithm to obtain the updated first device key.
[0484] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0485] In one example, the first key calculation parameter includes a random number.
[0486] In one example, the first key calculation parameter is generated by the device cloud platform.
[0487] In one example, as Figure 16 shown, the device 1400 further includes: a second identification sending module 1401, configured to send the current second identification to the network configuration cloud platform after accessing a first access point, where the current second identification is used to indicate the version of the current first device key.
[0488] In summary, for the technical solution provided in the embodiment of the present application, before the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and the identity authentication is performed by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and improving the security of the AP. Moreover, in the embodiment of the present application, after the identity authentication is passed and the network configuration for the device to be networked is successful, the device to be networked and the device cloud platform respectively update the device key of the device to be networked, so that in the next network configuration process for the device to be networked, the relevant authentication information for identity authentication generated based on the device key can also be updated, avoiding the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining the authentication information and directly using the stored authentication information, achieving the purpose of performing identity authentication with real-time update and further improving the security of the AP.
[0489] In addition, for the technical solution provided in the embodiment of the present application, after the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and the identity authentication is performed by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and improving the security of the AP. Moreover, in the embodiment of the present application, when the device to be networked accesses the AP and the identity authentication is passed, the device to be networked updates the device key of the device to be networked. Since in the identity authentication process after the device to be networked accesses the AP this time, the device cloud platform also updates the device key of the device to be networked, in the next identity authentication process after the device to be networked accesses the AP, the relevant authentication information for identity authentication generated based on the device key can also be updated, avoiding the proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining the authentication information and directly using the stored authentication information, achieving the purpose of performing identity authentication with real-time update and further improving the security of the AP. In addition, the embodiment of the present application adds a version identifier for the device key to indicate whether the identity authentication after accessing the AP is successful through the version identifier, avoiding the need for additional information or signaling to indicate the identity authentication result, reducing the signaling overhead, and helping to improve the identity authentication efficiency and the key update efficiency.
[0490] Please refer to Figure 17 , which shows a block diagram of a key update device provided in an embodiment of the present application. This device has the function of implementing the method example on the network configuration device side described above, and this function can be implemented by hardware or by hardware executing corresponding software. This device can be the network configuration device introduced above or can be set in the network configuration device. As Figure 17As shown, the device 1700 may include: a first parameter receiving module 1710 and a first parameter sending module 1720.
[0491] The first parameter receiving module 1710 is configured to receive first key calculation parameters from a distribution network cloud platform, and the first key calculation parameters are used to update the device key of a device to be networked.
[0492] The first parameter sending module 1720 is configured to send the first key calculation parameters to the device to be networked.
[0493] In one example, the length of the first key calculation parameters is greater than or equal to one byte.
[0494] In one example, the first key calculation parameters include random numbers.
[0495] In one example, the first key calculation parameters are generated by a device cloud platform.
[0496] In one example, as Figure 18 shown, the device 1700 further includes: a first cloud authentication information receiving module 1732, configured to receive first cloud authentication information from the distribution network cloud platform, where the first cloud authentication information is used to authenticate the identity of the device cloud platform before the device to be networked accesses a first access point; a first cloud authentication information sending module 1734, configured to send the first cloud authentication information to the device to be networked.
[0497] In one example, as Figure 18 shown, the device 1700 further includes: a third parameter receiving module 1742, configured to receive third key calculation parameters from the distribution network cloud platform, where the third key calculation parameters are used to generate cloud authentication information used for authenticating the identity of the device cloud platform; a third parameter sending module 1744, configured to send the third key calculation parameters to the device to be networked.
[0498] In one example, the length of the third key calculation parameters is greater than or equal to one byte.
[0499] In one example, the third key calculation parameters include random numbers.
[0500] In one example, the third key calculation parameters are generated by the device cloud platform.
[0501] In one example, when the first cloud authentication information and the second cloud authentication information are consistent, the authentication of the identity of the device cloud platform passes; when the first cloud authentication information and the second cloud authentication information are inconsistent, the authentication of the identity of the device cloud platform fails.
[0502] In one example, as Figure 18 shown, the apparatus 1700 further includes: a first authentication result receiving module 1752, configured to receive a first identity authentication result from the device to be networked, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform fails; and a first authentication result sending module 1754, configured to send the first identity authentication result to the network configuration cloud platform.
[0503] In one example, as Figure 18 shown, the apparatus 1700 further includes: an access module 1760, configured to cancel access to a second access point, where the second access point is an access point initiated by the device to be networked.
[0504] In one example, as Figure 18 shown, the apparatus 1700 further includes: a first device authentication information receiving module 1772, configured to receive first device authentication information from the device to be networked; a second device authentication information receiving module 1774, configured to receive second device authentication information from the network configuration cloud platform; and a device identity authentication module 1776, configured to perform identity authentication on the device to be networked based on the first device authentication information and the second device authentication information before configuring the device to be networked to access a first access point.
[0505] In one example, as Figure 18 shown, the apparatus 1700 further includes: a second authentication result sending module 1780, configured to send a second identity authentication result to the network configuration cloud platform when the identity authentication for the device to be networked fails, where the second identity authentication result is used to indicate that the identity authentication for the device to be networked fails.
[0506] In one example, as Figure 18 shown, the apparatus 1700 further includes: an access module 1760, configured to cancel access to a second access point when the identity authentication for the device to be networked fails, where the second access point is an access point initiated by the device to be networked.
[0507] In one example, as Figure 18 shown, the apparatus 1700 further includes: a third authentication result sending module 1790, configured to send a third identity authentication result to the network configuration cloud platform after configuring the device to be networked to access a first access point, where the third identity authentication result is used to indicate that the identity authentication for the device to be networked passes.
[0508] In one example, as Figure 18As shown, the device 1700 further includes: a beacon receiving module 1701, configured to receive a beacon of a second access point, where the beacon includes a first identifier, and the second access point is an access point initiated by the device to be networked; a first identifier sending module 1703, configured to send the first identifier to the network configuration cloud platform; wherein, the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
[0509] In one example, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
[0510] In one example, the length of the first identifier is greater than or equal to one bit.
[0511] In one example, the first identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
[0512] In one example, as Figure 18 As shown, the device 1700 further includes: a beacon receiving module 1701, configured to receive a beacon of a second access point, where the beacon includes a current second identifier, and the second access point is an access point initiated by the device to be networked; a second identifier sending module 1705, configured to send the current second identifier to the network configuration cloud platform; wherein, the current second identifier is used to indicate the version of the current first device key.
[0513] In one example, the length of the second identifier is greater than or equal to one byte.
[0514] In one example, the second identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
[0515] In summary, for the technical solution provided by the embodiments of the present application, before the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and perform identity authentication by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform, and improving the security of the AP. Moreover, in the embodiments of the present application, after successful identity authentication and successful network configuration for the device to be networked, the device to be networked and the device cloud platform respectively update the device key of the device to be networked, so that in the next network configuration process for the device to be networked, the relevant authentication information for identity authentication generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining authentication information and directly using the stored authentication information, achieving the purpose of performing identity authentication with real-time updates, and further improving the security of the AP.
[0516] Please refer to Figure 19 , which shows a block diagram of a key update device provided by an embodiment of the present application. This device has the function of implementing the method example on the device cloud platform side, and this function can be implemented by hardware or by hardware executing corresponding software. This device can be the device cloud platform introduced above or can be set in the device cloud platform. As Figure 19 shown, the device 1900 may include: a second key update module 1910 and a second key storage module 1920.
[0517] The second key update module 1910 is configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key.
[0518] The second key storage module 1920 is configured to store the updated second device key.
[0519] In one example, the second key update module 1910 is configured to: process the first key calculation parameter and the current second device key by using a first key generation algorithm to obtain the updated second device key.
[0520] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0521] In one example, the first key calculation parameter includes a random number.
[0522] In one example, the first key calculation parameter is generated by the device cloud platform.
[0523] In one example, as Figure 20As shown, the device 1900 further includes: a first cloud authentication information generation module 1930, configured to generate first cloud authentication information for an equipment to be networked to authenticate its identity with the equipment cloud platform before accessing a first access point; and a first cloud authentication information sending module 1940, configured to send the first cloud authentication information to a network configuration cloud platform.
[0524] In one example, as Figure 20 shown, the first cloud authentication information generation module 1930 is configured to: generate the first cloud authentication information according to a second key calculation parameter, a third key calculation parameter, and the current second device key.
[0525] In one example, as Figure 20 shown, the first cloud authentication information generation module 1930 includes: a key combination sub-module 1932, configured to combine the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter; a key processing sub-module 1934, configured to process the combined key calculation parameter and the current second device key by using a second key generation algorithm to obtain a second encryption key; and an encoding processing sub-module 1936, configured to process the second encryption key by using a first encoding method to obtain the first cloud authentication information.
[0526] In one example, as Figure 20 shown, the key combination sub-module 1932 is configured to perform any one of the following: perform data splicing processing on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; perform multiplication operation processing on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; use the second key calculation parameter as an encryption key to encrypt the third key calculation parameter to obtain the combined key calculation parameter; or use the third key calculation parameter as an encryption key to encrypt the second key calculation parameter to obtain the combined key calculation parameter.
[0527] In one example, the length of the third key calculation parameter is greater than or equal to one byte.
[0528] In one example, the third key calculation parameter includes a random number.
[0529] In one example, the third key calculation parameter is generated by the equipment cloud platform.
[0530] In one example, as Figure 20As shown, the device 1900 further includes: a third parameter sending module 1950, configured to send third key calculation parameters to the distribution network cloud platform, where the third key calculation parameters are used to generate cloud authentication information for authenticating the identity of the device cloud platform.
[0531] In one example, when the first cloud authentication information is consistent with the second cloud authentication information, the identity authentication for the device cloud platform passes; when the first cloud authentication information is inconsistent with the second cloud authentication information, the identity authentication for the device cloud platform fails.
[0532] In one example, as Figure 20 shown, the device 1900 further includes: a first authentication result receiving module 1960, configured to receive a first identity authentication result from the distribution network cloud platform, where the first identity authentication result is used to indicate that the identity authentication for the device cloud platform fails.
[0533] In one example, as Figure 20 shown, the device 1900 further includes: a second authentication result receiving module 1970, configured to receive a second identity authentication result from the distribution network cloud platform, where the second identity authentication result is used to indicate that the identity authentication for the device to be networked fails.
[0534] In one example, as Figure 20 shown, the device 1900 further includes: a key deletion module 1980, configured to delete the updated second device key.
[0535] In one example, as Figure 20 shown, the device 1900 further includes: a third authentication result receiving module 1990, configured to receive a third identity authentication result from the distribution network cloud platform, where the third identity authentication result is used to indicate that the identity authentication for the device to be networked passes.
[0536] In one example, as Figure 20 shown, the device 1900 further includes: a second key replacement module 1901, configured to replace the current second device key with the updated second device key.
[0537] In one example, as Figure 20As shown, the device 1900 further includes: a key deletion module 1980, configured to delete the updated second device key when the third identity authentication result from the network configuration cloud platform is not received within a preset time interval, where the third identity authentication result is used to indicate that the identity authentication for the device to be networked is passed; wherein, the starting moment of the preset time interval includes the generation moment of the updated second device key and the moments after the generation moment of the updated second device key; or, the starting moment of the preset time interval includes the sending moment of the first key calculation parameter and the moments after the sending moment of the first key calculation parameter.
[0538] In one example, as Figure 20 shown, the device 1900 further includes: a first identifier receiving module 1903, configured to receive a first identifier from the network configuration cloud platform; wherein, the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
[0539] In one example, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
[0540] In one example, the device cloud platform retains the device key set when the device to be networked leaves the factory.
[0541] In one example, as Figure 20 shown, the device 1900 further includes: a second identifier receiving module 1905, configured to receive the current second identifier from the network configuration cloud platform; wherein, the current second identifier is used to indicate the version of the current first device key.
[0542] In one example, as Figure 20 shown, the device 1900 further includes: a third identifier obtaining module 1907, configured to obtain a reference third identifier, where the reference third identifier is the version of the second device key updated by the device cloud platform during the last network configuration process of the device to be networked; a key determination module 1909, configured to, when the current second identifier is consistent with the reference third identifier, adopt the second device key updated by the device cloud platform during the last network configuration process of the device to be networked as the current second device key; and when the current second identifier is inconsistent with the reference third identifier, adopt the second device key used by the device cloud platform during the last network configuration process of the device to be networked as the current second device key.
[0543] In summary, for the technical solution provided by the embodiments of the present application, before the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and the identity authentication is performed by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and improving the security of the AP. Moreover, in the embodiments of the present application, after the identity authentication is passed and the network configuration for the device to be networked is successful, the device to be networked and the device cloud platform respectively update the device key of the device to be networked, so that in the next network configuration process for the device to be networked, the relevant authentication information for identity authentication generated based on the device key can also be updated, preventing the proxy device or proxy cloud platform between the device to be networked and the device cloud platform from skipping the process of obtaining the authentication information and directly using the stored authentication information, achieving the purpose of performing identity authentication with real-time update and further improving the security of the AP.
[0544] Please refer to Figure 21 , which shows a block diagram of a key update device provided by an embodiment of the present application. This device has the function of implementing the method example on the device cloud platform side described above. The function can be implemented by hardware or by hardware executing corresponding software. This device can be the device cloud platform introduced above or can be set in the device cloud platform. As Figure 21 shown, the device 2100 may include: a second key update module 2110 and a second key replacement module 2120.
[0545] The second key update module 2110 is configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key.
[0546] The second key replacement module 2120 is configured to replace the current second device key with the updated second device key.
[0547] In one example, the second key update module 2110 is configured to: process the first key calculation parameter and the current second device key by using a first key generation algorithm to obtain the updated second device key.
[0548] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0549] In one example, the first key calculation parameter includes a random number.
[0550] In one example, the first key calculation parameter is generated by the device cloud platform.
[0551] In one example, as Figure 22As shown, the device 2100 further includes: a second identifier receiving module 2130, configured to receive a current second identifier from the distribution network cloud platform, where the current second identifier is used to indicate the version of the current first device key.
[0552] In one example, as Figure 22 shown, the device 2100 further includes: a third identifier obtaining module 2140, configured to obtain a reference third identifier, where the reference third identifier is the version of the second device key updated by the device cloud platform during the previous network configuration process of the device to be networked; a key determination module 2150, configured to, when the current second identifier is consistent with the reference third identifier, adopt the second device key updated by the device cloud platform during the previous network configuration process of the device to be networked as the current second device key; and when the current second identifier is inconsistent with the reference third identifier, adopt the second device key used by the device cloud platform during the previous network configuration process of the device to be networked as the current second device key.
[0553] In summary, the technical solution provided in the embodiments of the present application, after the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and perform identity authentication by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform, and improving the security of the AP. Moreover, in the embodiments of the present application, when the device to be networked accesses the AP and the identity authentication is passed, the device to be networked updates the device key of the device to be networked. Since in the identity authentication process after the device to be networked accesses the AP this time, the device cloud platform also updates the device key of the device to be networked, in the next identity authentication process after the device to be networked accesses the AP, the relevant authentication information for identity authentication generated based on the device key can also be updated, avoiding the proxy cloud platform between the device to be networked and the device cloud platform from directly using the stored authentication information by skipping the process of obtaining the authentication information, achieving the purpose of performing identity authentication in real time and further improving the security of the AP. In addition, the embodiments of the present application add a version identifier of the device key to achieve indicating whether the identity authentication is successful after accessing the AP through the version identifier, avoiding the need for additional information or signaling to indicate the identity authentication result, reducing the signaling overhead, and helping to improve the identity authentication efficiency and the key update efficiency.
[0554] Please refer to Figure 23, which shows a block diagram of a key update device provided in an embodiment of the present application. The device has the function of implementing the method example on the side of the network configuration cloud platform, and the function can be implemented by hardware or by hardware executing corresponding software. The device can be the network configuration cloud platform introduced above or can be set in the network configuration cloud platform. As Figure 23 shown, the device 2300 may include: a first parameter receiving module 2310 and a first parameter sending module 2320.
[0555] The first parameter receiving module 2310 is configured to receive a first key calculation parameter from the device cloud platform, and the first key calculation parameter is used to update the device key of the device to be networked.
[0556] The first parameter sending module 2320 is configured to send the first key calculation parameter to the device to be networked.
[0557] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0558] In one example, the first key calculation parameter includes a random number.
[0559] In one example, the first key calculation parameter is generated by the device cloud platform.
[0560] In one example, as Figure 24 shown, the device 2300 further includes: a second identifier receiving module 2330, configured to receive a current second identifier from the device to be networked, where the second identifier is used to indicate the version of the current first device key; a second identifier sending module 2340, configured to send the current second identifier to the device cloud platform.
[0561] In summary, for the technical solution provided in the embodiment of the present application, after the device to be networked accesses the AP, the device to be networked and the device cloud platform respectively generate relevant authentication information for identity authentication based on the device key of the device to be networked, and perform identity authentication by comparing the authentication information generated by the device to be networked and the device cloud platform respectively, achieving the purpose of identity authentication between the device to be networked and the device cloud platform and improving the security of the AP. Moreover, in the embodiment of the present application, when the device to be networked accesses the AP and the identity authentication is passed, the device to be networked updates the device key of the device to be networked. Since in the identity authentication process after the device to be networked accesses the AP this time, the device cloud platform also updates the device key of the device to be networked, in the next identity authentication process after the device to be networked accesses the AP, the relevant authentication information for identity authentication generated based on the device key can also be updated, preventing the proxy cloud platform between the device to be networked and the device cloud platform from directly using the stored authentication information by skipping the process of obtaining the authentication information, achieving the purpose of performing identity authentication with real-time update and further improving the security of the AP. In addition, the embodiment of the present application adds a version identifier for the device key to indicate whether the identity authentication after accessing the AP is successful through the version identifier, avoiding the need for additional information or signaling to indicate the identity authentication result, reducing the signaling overhead, and helping to improve the identity authentication efficiency and the key update efficiency.
[0562] It should be noted that when the device provided in the above embodiment realizes its functions, only the division of the above-mentioned respective function modules is used for illustration. In actual applications, the above functions can be allocated to different function modules according to actual needs, that is, the content structure of the device is divided into different function modules to complete all or part of the functions described above.
[0563] Regarding the device in the above embodiment, the specific manners in which each module performs operations have been described in detail in the embodiment related to the method, and will not be elaborated herein.
[0564] Please refer to Figure 25 , which shows a schematic structural diagram of a device 250 to be networked provided in an embodiment of the present application. For example, the device to be networked can be used to execute the method for updating the key on the device to be networked side described above. Specifically, the device 250 to be networked may include: a processor 251, and a transceiver 252 connected to the processor 251; where:
[0565] The processor 251 includes one or more processing cores. The processor 251 executes various functional applications and information processing by running software programs and modules.
[0566] The transceiver 252 includes a receiver and a transmitter. Optionally, the transceiver 252 is a communication chip.
[0567] In one example, the device 250 to be networked further includes: a memory and a bus. The memory is connected to the processor through the bus. The memory can be used to store a computer program, and the processor is used to execute the computer program to implement each step performed by the device to be networked in the above method embodiments.
[0568] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage devices include but are not limited to: RAM (Random-Access Memory), ROM (Read-Only Memory), EPROM (Erasable Programmable Read-Only Memory), EEPROM (Electrically Erasable Programmable Read-Only Memory), flash memory or other solid-state storage technologies, CD-ROM (Compact Disc Read-Only Memory), DVD (Digital Video Disc), or other optical storage, magnetic tape cartridges, magnetic tapes, disk storage, or other magnetic storage devices. Among them:
[0569] In a possible implementation:
[0570] The processor 251 is used to update the current first device key according to the first key calculation parameter to obtain an updated first device key.
[0571] The processor 251 is used to replace the current first device key with the updated first device key.
[0572] In one example, the processor 251 is used to: process the first key calculation parameter and the current first device key by using a first key generation algorithm to obtain the updated first device key.
[0573] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0574] In one example, the first key calculation parameter includes a random number.
[0575] In one example, the first key calculation parameter is generated by a device cloud platform.
[0576] In one example, the transceiver 252 is configured to receive first cloud authentication information from a power distribution device; the processor 251 is configured to generate second cloud authentication information; and the processor 251 is configured to perform identity authentication on the device cloud platform based on the first cloud authentication information and the second cloud authentication information before accessing a first access point.
[0577] In one example, the processor 251 is configured to: generate the second cloud authentication information according to second key calculation parameters, third key calculation parameters, and the current first device key.
[0578] In one example, the processor 251 is configured to combine the second key calculation parameters and the third key calculation parameters to obtain combined key calculation parameters; process the combined key calculation parameters and the current first device key using a second key generation algorithm to obtain a first encryption key; and process the first encryption key using a first encoding method to obtain the second cloud authentication information.
[0579] In one example, the processor 251 is configured to perform any one of the following: perform data splicing processing on the second key calculation parameters and the third key calculation parameters to obtain the combined key calculation parameters; perform multiplication operation processing on the second key calculation parameters and the third key calculation parameters to obtain the combined key calculation parameters; encrypt the third key calculation parameters using the second key calculation parameters as an encryption key to obtain the combined key calculation parameters; or encrypt the second key calculation parameters using the third key calculation parameters as an encryption key to obtain the combined key calculation parameters.
[0580] In one example, the length of the third key calculation parameters is greater than or equal to one byte.
[0581] In one example, the third key calculation parameters include random numbers.
[0582] In one example, the third key calculation parameters are generated by the device cloud platform.
[0583] In one example, when the first cloud authentication information is consistent with the second cloud authentication information, the identity authentication for the device cloud platform passes; when the first cloud authentication information is inconsistent with the second cloud authentication information, the identity authentication for the device cloud platform fails.
[0584] In one example, when the identity authentication for the device cloud platform fails, the transceiver 252 is configured to send a first identity authentication result to the power distribution device, and the first identity authentication result is used to indicate that the identity authentication for the device cloud platform fails.
[0585] In one example, the transceiver 252 is configured to broadcast a beacon of a second access point, where the beacon includes a first identifier, and the second access point is an access point initiated by the device to be networked; wherein, the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
[0586] In one example, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
[0587] In one example, the device to be networked retains the device key set when the device to be networked leaves the factory.
[0588] In one example, the length of the first identifier is greater than or equal to one bit.
[0589] In one example, the first identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
[0590] In one example, the transceiver 252 is configured to broadcast a beacon of a second access point, where the beacon includes a current second identifier, and the second access point is an access point initiated by the device to be networked; wherein, the current second identifier is used to indicate the version of the current first device key.
[0591] In one example, the processor 251 is configured to update the current second identifier after accessing a first access point to obtain an updated second identifier; the identification replacement module 1490 is configured to replace the current second identifier with the updated second identifier.
[0592] In one example, the length of the second identifier is greater than or equal to one byte.
[0593] In one example, the second identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
[0594] In another possible implementation:
[0595] The processor 251 is configured to, when accessing a first access point and the identity authentication for the device cloud platform is passed, process the current first device key according to a first key calculation parameter to obtain an updated first device key.
[0596] The processor 251 is configured to replace the current first device key with the updated first device key.
[0597] In one example, the processor 251 is configured to: process the first key calculation parameter and the current first device key using a first key generation algorithm to obtain the updated first device key.
[0598] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0599] In one example, the first key calculation parameter includes a random number.
[0600] In one example, the first key calculation parameter is generated by the device cloud platform.
[0601] In one example, after accessing the first access point, the transceiver 252 is configured to send the current second identifier to the network configuration cloud platform, where the current second identifier is used to indicate the version of the current first device key.
[0602] Please refer to Figure 26 , which shows a schematic structural diagram of the network configuration device 260 provided by an embodiment of the present application. For example, the network configuration device can be used to execute the above-mentioned network configuration device-side key update method. Specifically, the network configuration device 260 may include: a processor 261, and a transceiver 262 connected to the processor 261; where:
[0603] The processor 261 includes one or more processing cores. The processor 261 executes various functional applications and information processing by running software programs and modules.
[0604] The transceiver 262 includes a receiver and a transmitter. Optionally, the transceiver 262 is a communication chip.
[0605] In one example, the network configuration device 260 further includes: a memory and a bus. The memory is connected to the processor through the bus. The memory can be used to store computer programs, and the processor is configured to execute the computer programs to implement each step executed by the network configuration device in the above method embodiments.
[0606] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage devices include, but are not limited to: RAM and ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, tape cartridges, tapes, magnetic disk storage or other magnetic storage devices. Where:
[0607] The transceiver 262 is configured to receive first key calculation parameters from a distribution network cloud platform, where the first key calculation parameters are used to update the device key of the device to be networked.
[0608] The transceiver 262 is configured to send the first key calculation parameters to the device to be networked.
[0609] In one example, the length of the first key calculation parameters is greater than or equal to one byte.
[0610] In one example, the first key calculation parameters include a random number.
[0611] In one example, the first key calculation parameters are generated by a device cloud platform.
[0612] In one example, the transceiver 262 is configured to receive first cloud authentication information from a distribution network cloud platform, where the first cloud authentication information is used to authenticate the device cloud platform before the device to be networked accesses a first access point; and send the first cloud authentication information to the device to be networked.
[0613] In one example, the transceiver 262 is configured to receive third key calculation parameters from the distribution network cloud platform, where the third key calculation parameters are used to generate cloud authentication information used for authenticating the device cloud platform; and send the third key calculation parameters to the device to be networked.
[0614] In one example, the length of the third key calculation parameters is greater than or equal to one byte.
[0615] In one example, the third key calculation parameters include a random number.
[0616] In one example, the third key calculation parameters are generated by the device cloud platform.
[0617] In one example, when the first cloud authentication information and the second cloud authentication information are consistent, the authentication of the device cloud platform passes; when the first cloud authentication information and the second cloud authentication information are inconsistent, the authentication of the device cloud platform fails.
[0618] In one example, the transceiver 262 is configured to receive a first authentication result from the device to be networked, where the first authentication result is used to indicate that the authentication of the device cloud platform fails; and send the first authentication result to the distribution network cloud platform.
[0619] In one example, the processor 261 is configured to cancel accessing a second access point, where the second access point is an access point initiated by the device to be networked.
[0620] In one example, the transceiver 262 is configured to receive first device authentication information from the device to be networked; the transceiver 262 is configured to receive second device authentication information from the network configuration cloud platform; the transceiver 262 is configured to authenticate the identity of the device to be networked based on the first device authentication information and the second device authentication information before configuring the device to be networked to access a first access point.
[0621] In one example, when the authentication of the identity of the device to be networked fails, the transceiver 262 is configured to send a second authentication result to the network configuration cloud platform, where the second authentication result is used to indicate that the authentication of the identity of the device to be networked fails.
[0622] In one example, when the authentication of the identity of the device to be networked fails, the processor 261 is configured to cancel the access to a second access point, where the second access point is the access point initiated by the device to be networked.
[0623] In one example, after configuring the device to be networked to access a first access point, the transceiver 262 is configured to send a third authentication result to the network configuration cloud platform, where the third authentication result is used to indicate that the authentication of the identity of the device to be networked is successful.
[0624] In one example, the transceiver 262 is configured to receive a beacon of a second access point, where the beacon includes a first identifier, and the second access point is the access point initiated by the device to be networked; send the first identifier to the network configuration cloud platform; where the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
[0625] In one example, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
[0626] In one example, the length of the first identifier is greater than or equal to one bit.
[0627] In one example, the first identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
[0628] In one example, the transceiver 262 is configured to receive a beacon from a second access point, where the beacon includes a current second identifier, and the second access point is an access point initiated by the device to be networked; and send the current second identifier to the network configuration cloud platform; where the current second identifier is used to indicate the version of the current first device key.
[0629] In one example, the length of the second identifier is greater than or equal to one byte.
[0630] In one example, the second identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
[0631] Please refer to Figure 27 , which shows a schematic structural diagram of a device cloud platform 270 provided by an embodiment of the present application. For example, the device cloud platform can be used to execute the device cloud platform side key update method described above. Specifically, the device cloud platform 270 may include: a processor 271, and a transceiver 272 connected to the processor 271; where:
[0632] The processor 271 includes one or more processing cores. The processor 271 executes various functional applications and information processing by running software programs and modules.
[0633] The transceiver 272 includes a receiver and a transmitter. Optionally, the transceiver 272 is a communication chip.
[0634] In one example, the device cloud platform 270 further includes: a memory and a bus. The memory is connected to the processor through the bus. The memory can be used to store a computer program, and the processor is used to execute the computer program to implement each step executed by the device cloud platform in the above method embodiments.
[0635] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage device includes but is not limited to: RAM and ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, tape cassette, tape, magnetic disk storage or other magnetic storage devices. Where:
[0636] In a possible implementation:
[0637] The processor 271 is configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key.
[0638] The processor 271 is configured to store the updated second device key.
[0639] In one example, the processor 271 is configured to process the first key calculation parameter and the current second device key by using a first key generation algorithm to obtain the updated second device key.
[0640] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0641] In one example, the first key calculation parameter includes a random number.
[0642] In one example, the first key calculation parameter is generated by the device cloud platform.
[0643] In one example, the processor 271 is configured to generate first cloud authentication information for an incoming device to authenticate the device cloud platform before accessing a first access point; the transceiver 272 is configured to send the first cloud authentication information to the network configuration cloud platform.
[0644] In one example, the processor 271 is configured to generate the first cloud authentication information according to a second key calculation parameter, a third key calculation parameter, and the current second device key.
[0645] In one example, the processor 271 is configured to combine the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter; process the combined key calculation parameter and the current second device key by using a second key generation algorithm to obtain a second encryption key; process the second encryption key by using a first encoding method to obtain the first cloud authentication information.
[0646] In one example, the processor 271 is configured to perform any one of the following: perform data splicing processing on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; perform multiplication operation processing on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; encrypt the third key calculation parameter by using the second key calculation parameter as an encryption key to obtain the combined key calculation parameter; encrypt the second key calculation parameter by using the third key calculation parameter as an encryption key to obtain the combined key calculation parameter.
[0647] In one example, the length of the third key calculation parameter is greater than or equal to one byte.
[0648] In one example, the third key calculation parameter includes a random number.
[0649] In one example, the third key calculation parameter is generated by the device cloud platform.
[0650] In one example, the transceiver 272 is configured to send the third key calculation parameter to the network configuration cloud platform, and the third key calculation parameter is used to generate cloud authentication information for authenticating the identity of the device cloud platform.
[0651] In one example, when the first cloud authentication information is consistent with the second cloud authentication information, the identity authentication for the device cloud platform passes; when the first cloud authentication information is inconsistent with the second cloud authentication information, the identity authentication for the device cloud platform fails.
[0652] In one example, the transceiver 272 is configured to receive a first identity authentication result from the network configuration cloud platform, and the first identity authentication result is used to indicate that the identity authentication for the device cloud platform fails.
[0653] In one example, the transceiver 272 is configured to receive a second identity authentication result from the network configuration cloud platform, and the second identity authentication result is used to indicate that the identity authentication for the device to be networked fails.
[0654] In one example, the processor 271 is configured to delete the updated second device key.
[0655] In one example, the transceiver 272 is configured to receive a third identity authentication result from the network configuration cloud platform, and the third identity authentication result is used to indicate that the identity authentication for the device to be networked passes.
[0656] In one example, the processor 271 is configured to replace the current second device key with the updated second device key.
[0657] In one example, when the processor 271 does not receive the third identity authentication result from the network configuration cloud platform within a preset time interval, the processor 271 is configured to delete the updated second device key, and the third identity authentication result is used to indicate that the identity authentication for the device to be networked passes; wherein, the start time of the preset time interval includes the generation time of the updated second device key and the time after the generation time of the updated second device key; or, the start time of the preset time interval includes the sending time of the first key calculation parameter and the time after the sending time of the first key calculation parameter.
[0658] In one example, the transceiver 272 is configured to receive a first identifier from the network configuration cloud platform; wherein, the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
[0659] In one example, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
[0660] In one example, the device cloud platform retains the device key set when the device to be networked leaves the factory.
[0661] In one example, the transceiver 272 is configured to receive the current second identifier from the network configuration cloud platform; wherein, the current second identifier is used to indicate the version of the current first device key.
[0662] In one example, the processor 271 is configured to obtain a reference third identifier, where the reference third identifier is the version of the second device key updated by the device cloud platform during the last network configuration process of the device to be networked; when the current second identifier is consistent with the reference third identifier, the second device key updated by the device cloud platform during the last network configuration process of the device to be networked is adopted as the current second device key; when the current second identifier is inconsistent with the reference third identifier, the second device key used by the device cloud platform during the last network configuration process of the device to be networked is adopted as the current second device key.
[0663] In another possible implementation:
[0664] The processor 271 is configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key.
[0665] The processor 271 is configured to replace the current second device key with the updated second device key.
[0666] In one example, the processor 271 is configured to process the first key calculation parameter and the current second device key by using a first key generation algorithm to obtain the updated second device key.
[0667] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0668] In one example, the first key calculation parameter includes a random number.
[0669] In one example, the first key calculation parameter is generated by the device cloud platform.
[0670] In one example, the transceiver 272 is configured to receive a current second identifier from the power distribution cloud platform, and the current second identifier is used to indicate the version of the current first device key.
[0671] In one example, the processor 271 is configured to obtain a reference third identifier, where the reference third identifier is the version of the second device key updated by the device cloud platform during the previous power distribution process of the device to be networked; when the current second identifier is consistent with the reference third identifier, the second device key updated by the device cloud platform during the previous power distribution process of the device to be networked is used as the current second device key; when the current second identifier is inconsistent with the reference third identifier, the second device key used by the device cloud platform during the previous power distribution process of the device to be networked is used as the current second device key.
[0672] Please refer to Figure 28 , which shows a schematic structural diagram of the power distribution cloud platform 280 provided by an embodiment of the present application. For example, the power distribution cloud platform can be used to execute the above-mentioned power distribution cloud platform-side key update method. Specifically, the power distribution cloud platform 280 may include: a processor 281, and a transceiver 282 connected to the processor 281; where:
[0673] The processor 281 includes one or more processing cores, and the processor 281 executes various functional applications and information processing by running software programs and modules.
[0674] The transceiver 282 includes a receiver and a transmitter. Optionally, the transceiver 282 is a communication chip.
[0675] In one example, the power distribution cloud platform 280 further includes: a memory and a bus. The memory is connected to the processor through the bus. The memory can be used to store a computer program, and the processor is configured to execute the computer program to implement each step executed by the power distribution cloud platform in the above method embodiments.
[0676] In addition, the memory can be implemented by any type of volatile or non-volatile storage device or a combination thereof. The volatile or non-volatile storage device includes but is not limited to: RAM and ROM, EPROM, EEPROM, flash memory or other solid-state storage technologies, CD-ROM, DVD or other optical storage, tape cassette, tape, magnetic disk storage or other magnetic storage devices. Where:
[0677] The transceiver 282 is configured to receive first key calculation parameters from the device cloud platform, and the first key calculation parameters are used to update the device key of the device to be networked.
[0678] The transceiver 282 is configured to send the first key calculation parameter to the device to be networked.
[0679] In one example, the length of the first key calculation parameter is greater than or equal to one byte.
[0680] In one example, the first key calculation parameter includes a random number.
[0681] In one example, the first key calculation parameter is generated by the device cloud platform.
[0682] In one example, the transceiver 282 is configured to receive the current second identifier from the device to be networked, where the second identifier is used to indicate the version of the current first device key; and send the current second identifier to the device cloud platform.
[0683] An embodiment of this application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is used to be executed by a processor of a device to be networked to implement the key update method on the device to be networked side as described above.
[0684] An embodiment of this application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is used to be executed by a processor of a network configuration device to implement the key update method on the network configuration device side as described above.
[0685] An embodiment of this application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is used to be executed by a processor of a device cloud platform to implement the key update method on the device cloud platform side as described above.
[0686] An embodiment of this application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is used to be executed by a processor of a network configuration cloud platform to implement the key update method on the network configuration cloud platform side as described above.
[0687] An embodiment of this application further provides a chip, which includes programmable logic circuits and / or program instructions. When the chip runs on a device to be networked, it is used to implement the key update method on the device to be networked side as described above.
[0688] An embodiment of this application further provides a chip, which includes programmable logic circuits and / or program instructions. When the chip runs on a network configuration device, it is used to implement the key update method on the network configuration device side as described above.
[0689] An embodiment of the present application further provides a chip, which includes a programmable logic circuit and / or program instructions, and is used to implement the key update method on the device cloud platform side as described above when the chip runs on the device cloud platform.
[0690] An embodiment of the present application further provides a chip, which includes a programmable logic circuit and / or program instructions, and is used to implement the key update method on the network configuration cloud platform side as described above when the chip runs on the network configuration cloud platform.
[0691] An embodiment of the present application further provides a computer program product, which is used to implement the key update method on the side of the device to be networked as described above when the computer program product runs on the device to be networked.
[0692] An embodiment of the present application further provides a computer program product, which is used to implement the key update method on the side of the network configuration device as described above when the computer program product runs on the network configuration device.
[0693] An embodiment of the present application further provides a computer program product, which is used to implement the key update method on the device cloud platform side as described above when the computer program product runs on the device cloud platform.
[0694] An embodiment of the present application further provides a computer program product, which is used to implement the key update method on the network configuration cloud platform side as described above when the computer program product runs on the network configuration cloud platform.
[0695] Those skilled in the art should be able to realize that in the above one or more examples, the functions described in the embodiments of the present application can be implemented by hardware, software, firmware, or any combination thereof. When implemented using software, these functions can be stored in a computer-readable medium or transmitted as one or more instructions or codes on a computer-readable medium. The computer-readable medium includes computer storage media and communication media, where the communication media includes any medium that facilitates the transfer of a computer program from one place to another. The storage media can be any available medium that can be accessed by a general-purpose or special-purpose computer.
[0696] The above are only exemplary embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.
Claims
1. A key update method, characterized in that, applied to a device to be networked, the method includes: Receiving first cloud authentication information, first key calculation parameters, and third key calculation parameters, wherein the first cloud authentication information, the first key calculation parameters, and the third key calculation parameters are sent to the device to be networked in the same information or signaling, and both the first key calculation parameters and the third key calculation parameters are generated by a device cloud platform; Generating second cloud authentication information according to second key calculation parameters, the third key calculation parameters, and a current first device key, where the second key calculation parameters are generated by the device to be networked; Before accessing a first access point, authenticating the identity of the device cloud platform based on the first cloud authentication information and the second cloud authentication information; When accessing the first access point and the identity authentication of the device cloud platform is passed, updating the current first device key according to the first key calculation parameters to obtain an updated first device key; Replacing the current first device key with the updated first device key.
2. The method according to claim 1, characterized in that, The updating the current first device key according to the first key calculation parameters to obtain an updated first device key includes: Processing the first key calculation parameters and the current first device key using a first key generation algorithm to obtain the updated first device key.
3. The method according to claim 1, characterized in that, The length of the first key calculation parameters is greater than or equal to one byte.
4. The method according to claim 1, characterized in that, The first key calculation parameters include random numbers.
5. The method according to claim 1, characterized in that, The first key calculation parameters are generated by a device cloud platform.
6. The method according to any one of claims 1 to 5, characterized in that, The generating second cloud authentication information according to second key calculation parameters, the third key calculation parameters, and a current first device key includes: Combining the second key calculation parameters and the third key calculation parameters to obtain combined key calculation parameters; Processing the combined key calculation parameters and the current first device key using a second key generation algorithm to obtain a first encryption key; Processing the first encryption key using a first encoding method to obtain the second cloud authentication information.
7. The method according to claim 6, characterized in that, The combining the second key calculation parameters and the third key calculation parameters to obtain combined key calculation parameters includes any one of the following: Performing data splicing processing on the second key calculation parameters and the third key calculation parameters to obtain the combined key calculation parameters; Performing multiplication operation processing on the second key calculation parameters and the third key calculation parameters to obtain the combined key calculation parameters; Using the second key calculation parameters as an encryption key to encrypt the third key calculation parameters to obtain the combined key calculation parameters; Using the parameter calculated from the third key as the encryption key, encrypt the parameter calculated from the second key to obtain the combined key calculation parameter.
8. The method according to any one of claims 1 to 5, wherein, the length of the third key calculation parameter is greater than or equal to one byte.
9. The method according to any one of claims 1 to 5, wherein, the third key calculation parameter includes a random number.
10. The method according to any one of claims 1 to 5, wherein, when the first cloud authentication information is consistent with the second cloud authentication information, the identity authentication for the device cloud platform passes; when the first cloud authentication information is inconsistent with the second cloud authentication information, the identity authentication for the device cloud platform fails.
11. The method according to any one of claims 1 to 5, wherein, after performing the identity authentication on the device cloud platform based on the first cloud authentication information and the second cloud authentication information, it further includes: when the identity authentication for the device cloud platform fails, sending a first identity authentication result to the network configuration device, and the first identity authentication result is used to indicate that the identity authentication for the device cloud platform fails.
12. The method according to any one of claims 1 to 5, wherein, the method further includes: broadcasting a beacon of a second access point, and the beacon includes a first identifier, and the second access point is the access point started by the device to be networked; wherein, the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
13. The method according to claim 12, wherein, when the value of the first identifier is a first value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
14. The method according to claim 12, wherein, the device to be networked retains the device key set when the device to be networked leaves the factory.
15. The method according to claim 12, wherein, the length of the first identifier is greater than or equal to one bit.
16. The method according to claim 12, wherein, the first identifier is located in any one of the following fields included in the beacon: basic service set identifier BSSID field, service set identifier SSID field, custom field.
17. The method according to any one of claims 1 to 5, wherein, the method further includes: broadcasting a beacon of a second access point, and the beacon includes a current second identifier, and the second access point is the access point started by the device to be networked; wherein, the current second identifier is used to indicate the version of the current first device key.
18. The method according to claim 17, wherein, the method further includes: after accessing the first access point, updating the current second identifier to obtain an updated second identifier; Replace the current second identifier with the updated second identifier.
19. The method according to claim 17, wherein, the length of the second identifier is greater than or equal to one byte.
20. The method according to claim 17, wherein, the second identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
21. A key update method, wherein, applied to a network configuration device, the method includes: Receiving a first key calculation parameter, a third key calculation parameter, and a first cloud authentication information from a network configuration cloud platform, wherein the first key calculation parameter is used to update the device key of the device to be networked when the device to be networked accesses a first access point and the identity authentication for the device cloud platform passes, the device key of the device to be networked and the third key calculation parameter are used to generate a second cloud authentication information with a second key calculation parameter, the first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses the first access point, both the first key calculation parameter and the third key calculation parameter are generated by the device cloud platform, and the second key calculation parameter is generated by the device to be networked; Sending the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter to the device to be networked, wherein the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling.
22. The method according to claim 21, wherein, the length of the first key calculation parameter is greater than or equal to one byte.
23. The method according to claim 21, wherein, the first key calculation parameter includes a random number.
24. The method according to claim 21, wherein, the length of the third key calculation parameter is greater than or equal to one byte.
25. The method according to claim 21, wherein, the third key calculation parameter includes a random number.
26. The method according to any one of claims 21 to 25, wherein, when the first cloud authentication information and the second cloud authentication information are consistent, the identity authentication for the device cloud platform passes; when the first cloud authentication information and the second cloud authentication information are inconsistent, the identity authentication for the device cloud platform fails.
27. The method according to any one of claims 21 to 25, wherein, the method further includes: Receiving a first identity authentication result from the device to be networked, the first identity authentication result being used to indicate that the identity authentication for the device cloud platform fails; Sending the first identity authentication result to the network configuration cloud platform.
28. The method according to claim 27, wherein, after receiving the first identity authentication result from the device to be networked, it further includes: Cancel access to the second access point, where the second access point is the access point initiated by the device to be networked.
29. The method according to any one of claims 21 to 25, characterized in that the method further includes: receiving first device authentication information from the device to be networked; receiving second device authentication information from the network configuration cloud platform; before configuring the device to be networked to access the first access point, based on the first device authentication information and the second device authentication information, performing identity authentication on the device to be networked.
30. The method according to claim 29, characterized in that after performing identity authentication on the device to be networked based on the first device authentication information and the second device authentication information, it further includes: in the case where the identity authentication for the device to be networked fails, sending a second identity authentication result to the network configuration cloud platform, where the second identity authentication result is used to indicate that the identity authentication for the device to be networked fails.
31. The method according to claim 29, characterized in that after performing identity authentication on the device to be networked based on the first device authentication information and the second device authentication information, it further includes: in the case where the identity authentication for the device to be networked fails, canceling access to the second access point, where the second access point is the access point initiated by the device to be networked.
32. The method according to any one of claims 21 to 25, characterized in that the method further includes: after configuring the device to be networked to access the first access point, sending a third identity authentication result to the network configuration cloud platform, where the third identity authentication result is used to indicate that the identity authentication for the device to be networked passes.
33. The method according to any one of claims 21 to 25, characterized in that the method further includes: receiving a beacon of the second access point, where the beacon includes a first identifier, and the second access point is the access point initiated by the device to be networked; sending the first identifier to the network configuration cloud platform; wherein the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
34. The method according to claim 33, characterized in that when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
35. The method according to claim 33, characterized in that the length of the first identifier is greater than or equal to one bit.
36. The method according to claim 33, characterized in that the first identifier is located in any one of the following fields included in the beacon: basic service set identifier BSSID field, service set identifier SSID field, custom field.
37. The method according to any one of claims 21 to 25, characterized in that the method further includes: Receive a beacon from a second access point, where the beacon includes a current second identifier, and the second access point is an access point initiated by the device to be networked; Send the current second identifier to the network configuration cloud platform; Wherein, the current second identifier is used to indicate the version of the current first device key.
38. The method according to claim 37, characterized in that, The length of the second identifier is greater than or equal to one byte.
39. The method according to claim 37, characterized in that, The second identifier is located in any one of the following fields included in the beacon: BSSID field, SSID field, custom field.
40. A key update method, characterized in that, Applied to a device cloud platform, the method includes: Generate first cloud authentication information according to second key calculation parameters, third key calculation parameters and a current second device key, wherein the second key calculation parameters and the third key calculation parameters are also used to generate second cloud authentication information with the device key of the device to be networked, and the first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses a first access point, the second key calculation parameters are generated by the device to be networked, and the third key calculation parameters are generated by the device cloud platform; Update the current second device key according to first key calculation parameters to obtain an updated second device key, wherein the first key calculation parameters are also used to update the device key of the device to be networked when the device to be networked accesses the first access point and the identity authentication for the device cloud platform passes, the first key calculation parameters are generated by the device cloud platform, and the first cloud authentication information, the first key calculation parameters and the third key calculation parameters are carried in the same information or signaling and sent to the device to be networked; Store the updated second device key; Send the first cloud authentication information, the first key calculation parameters and the third key calculation parameters to the network configuration cloud platform.
41. The method according to claim 40, characterized in that, The step of updating the current second device key according to the first key calculation parameters to obtain an updated second device key includes: Process the first key calculation parameters and the current second device key using a first key generation algorithm to obtain the updated second device key.
42. The method according to claim 40, characterized in that, The length of the first key calculation parameters is greater than or equal to one byte.
43. The method according to claim 40, characterized in that, The first key calculation parameters include a random number.
44. The method according to claim 40, characterized in that, The step of generating first cloud authentication information according to second key calculation parameters, third key calculation parameters and a current second device key includes: Combine the second key calculation parameters and the third key calculation parameters to obtain combined key calculation parameters; Process the combined key calculation parameters and the current second device key using a second key generation algorithm to obtain a second encryption key; Process the second encryption key using a first encoding method to obtain the first cloud authentication information.
45. The method according to claim 44, wherein, The combination of the second key calculation parameter and the third key calculation parameter to obtain a combined key calculation parameter includes any one of the following: Perform data splicing processing on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; Perform a multiplication operation on the second key calculation parameter and the third key calculation parameter to obtain the combined key calculation parameter; Use the second key calculation parameter as the encryption key to encrypt the third key calculation parameter to obtain the combined key calculation parameter; Use the third key calculation parameter as the encryption key to encrypt the second key calculation parameter to obtain the combined key calculation parameter.
46. The method according to any one of claims 40 to 45, wherein, The length of the third key calculation parameter is greater than or equal to one byte.
47. The method according to any one of claims 40 to 45, wherein, The third key calculation parameter includes a random number.
48. The method according to any one of claims 40 to 45, wherein, When the first cloud authentication information and the second cloud authentication information are consistent, the identity authentication for the device cloud platform passes; When the first cloud authentication information and the second cloud authentication information are inconsistent, the identity authentication for the device cloud platform fails.
49. The method according to claim 40, wherein, The method further includes: Receiving a first identity authentication result from the network configuration cloud platform, the first identity authentication result being used to indicate that the identity authentication for the device cloud platform fails.
50. The method according to claim 40, wherein, The method further includes: Receiving a second identity authentication result from the network configuration cloud platform, the second identity authentication result being used to indicate that the identity authentication for the device to be networked fails.
51. The method according to claim 49 or 50, wherein, The method further includes: Deleting the updated second device key.
52. The method according to any one of claims 40 to 45, wherein, The method further includes: Receiving a third identity authentication result from the network configuration cloud platform, the third identity authentication result being used to indicate that the identity authentication for the device to be networked passes.
53. The method according to claim 52, wherein, After receiving the third identity authentication result from the network configuration cloud platform, it further includes: Replacing the current second device key with the updated second device key.
54. The method according to any one of claims 40 to 45, wherein, The method further includes: In the case where the third identity authentication result from the network configuration cloud platform is not received within a preset time interval, the updated second device key is deleted, and the third identity authentication result is used to indicate that the identity authentication for the device to be networked is passed; Wherein, the starting moment of the preset time interval includes the generation moment of the updated second device key and the moments after the generation moment of the updated second device key; or, the starting moment of the preset time interval includes the sending moment of the first key calculation parameter and the moments after the sending moment of the first key calculation parameter.
55. The method according to any one of claims 40 to 45, characterized in that, the method further includes: receiving a first identifier from the network configuration cloud platform; Wherein, the first identifier is used to indicate whether to use the device key set when the device to be networked leaves the factory.
56. The method according to claim 55, characterized in that, when the value of the first identifier is a first numerical value, the first identifier is used to indicate using the device key set when the device to be networked leaves the factory; when the value of the first identifier is a second numerical value, the first identifier is used to indicate not using the device key set when the device to be networked leaves the factory.
57. The method according to claim 55, characterized in that, the device cloud platform retains the device key set when the device to be networked leaves the factory.
58. The method according to claim 55, characterized in that, the method further includes: receiving a current second identifier from the network configuration cloud platform; Wherein, the current second identifier is used to indicate the version of the current first device key.
59. The method according to claim 58, characterized in that, after receiving the current second identifier from the network configuration cloud platform, it further includes: obtaining a reference third identifier, which is the version of the second device key updated by the device cloud platform during the last network configuration process of the device to be networked; when the current second identifier is consistent with the reference third identifier, using the second device key updated by the device cloud platform during the last network configuration process of the device to be networked as the current second device key; when the current second identifier is inconsistent with the reference third identifier, using the second device key used by the device cloud platform during the last network configuration process of the device to be networked as the current second device key.
60. A key update method, characterized in that, applied to the network configuration cloud platform, the method includes: Receive the first key calculation parameter, the third key calculation parameter, and the first cloud authentication information from the device cloud platform. Among them, the first key calculation parameter is used to update the device key of the device to be networked when the device to be networked accesses the first access point and the identity authentication for the device cloud platform passes. The device key of the device to be networked and the third key calculation parameter are used to generate the second cloud authentication information with the second key calculation parameter. The first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses the first access point. Both the first key calculation parameter and the third key calculation parameter are generated by the device cloud platform, and the second key calculation parameter is generated by the device to be networked; Send the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter to the device to be networked. Among them, the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling.
61. The method according to claim 60, characterized in that, The length of the first key calculation parameter is greater than or equal to one byte.
62. The method according to claim 60 or 61, characterized in that, The first key calculation parameter includes a random number.
63. The method according to claim 60 or 61, characterized in that, The method further includes: Receive the current second identifier from the device to be networked, and the second identifier is used to indicate the version of the current first device key; Send the current second identifier to the device cloud platform.
64. A key update device, characterized in that, It is set in the device to be networked, and the device includes: A first cloud authentication information receiving module, configured to receive the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter. Among them, the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling, and both the first key calculation parameter and the third key calculation parameter are generated by the device cloud platform; A second cloud authentication information generating module, configured to generate the second cloud authentication information according to the second key calculation parameter, the third key calculation parameter, and the current first device key, and the second key calculation parameter is generated by the device to be networked; A device cloud platform identity authentication module, configured to authenticate the identity of the device cloud platform based on the first cloud authentication information and the second cloud authentication information before accessing the first access point; A first key update module, configured to update the current first device key according to the first key calculation parameter when accessing the first access point and the identity authentication for the device cloud platform passes, to obtain the updated first device key; A first key replacement module, configured to replace the current first device key with the updated first device key.
65. A key update device, characterized in that, It is set in the network configuration device, and the device includes: A first parameter receiving module, configured to receive a first key calculation parameter, a third key calculation parameter, and first cloud authentication information from a distribution network cloud platform. Wherein, the first key calculation parameter is used to update the device key of the device to be networked when the device to be networked accesses a first access point and the identity authentication for the device cloud platform is passed. The device key of the device to be networked and the third key calculation parameter are used to generate second cloud authentication information with a second key calculation parameter. The first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses the first access point. Both the first key calculation parameter and the third key calculation parameter are generated by the device cloud platform, and the second key calculation parameter is generated by the device to be networked; A first parameter sending module, configured to send the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter to the device to be networked. Wherein, the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling.
66. A key update device Characterized in that It is set in the device cloud platform, and the device includes: A first cloud authentication information generation module, configured to generate first cloud authentication information according to a second key calculation parameter, a third key calculation parameter, and a current second device key. Wherein, the second key calculation parameter and the third key calculation parameter are also used to generate second cloud authentication information with the device key of the device to be networked. The first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses a first access point. The second key calculation parameter is generated by the device to be networked, the third key calculation parameter is generated by the device cloud platform, the second key calculation parameter is generated by the device to be networked, and the third key calculation parameter is generated by the device cloud platform; A second key update module, configured to update the current second device key according to the first key calculation parameter to obtain an updated second device key. Wherein, the first key calculation parameter is also used to update the device key of the device to be networked when the device to be networked accesses the first access point and the identity authentication for the device cloud platform is passed. The first key calculation parameter is generated by the device cloud platform, and the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling; A second key storage module, configured to store the updated second device key; A first cloud authentication information sending module, configured to send the first cloud authentication information to the distribution network cloud platform; A third parameter sending module, configured to send the first key calculation parameter and the third key calculation parameter to the distribution network cloud platform.
67. A key update device Characterized in that It is set in the distribution network cloud platform, and the device includes: The first parameter receiving module is configured to receive a first key calculation parameter, a third key calculation parameter, and a first cloud authentication information from a device cloud platform. The first key calculation parameter is used to update the device key of the device to be networked when the device to be networked accesses a first access point and the identity authentication for the device cloud platform is passed. The device key of the device to be networked and the third key calculation parameter are used to generate a second cloud authentication information together with a second key calculation parameter. The first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses the first access point. The first key calculation parameter and the third key calculation parameter are both generated by the device cloud platform, and the second key calculation parameter is generated by the device to be networked; The first parameter sending module is configured to send the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter to the device to be networked. The first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling.
68. A device to be networked, characterized in that, the device to be networked includes: a processor, and a transceiver connected to the processor; wherein: the transceiver is configured to receive a first cloud authentication information, a first key calculation parameter, and a third key calculation parameter. The first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling. The first key calculation parameter and the third key calculation parameter are both generated by a device cloud platform; the processor is configured to generate a second cloud authentication information according to a second key calculation parameter, the third key calculation parameter, and a current first device key. The second key calculation parameter is generated by the device to be networked; the processor is further configured to authenticate the identity of the device cloud platform based on the first cloud authentication information and the second cloud authentication information before accessing a first access point; the processor is further configured to update the current first device key according to the first key calculation parameter when accessing the first access point and the identity authentication for the device cloud platform is passed, so as to obtain an updated first device key; the processor is further configured to replace the current first device key with the updated first device key.
69. A network configuration device, characterized in that, the network configuration device includes: a processor, and a transceiver connected to the processor; wherein: The transceiver is used to receive a first key calculation parameter, a third key calculation parameter, and a first cloud authentication information from a power distribution cloud platform. Among them, the first key calculation parameter is used to update the device key of the device to be networked when the device to be networked accesses a first access point and the identity authentication for the device cloud platform is passed. The device key of the device to be networked and the third key calculation parameter are used to generate a second cloud authentication information with a second key calculation parameter. The first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses the first access point. The first key calculation parameter and the third key calculation parameter are both generated by the device cloud platform, and the second key calculation parameter is generated by the device to be networked; The transceiver is used to send the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter to the device to be networked. Among them, the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling.
70. A device cloud platform, characterized in that, the device cloud platform includes: a processor, and a transceiver connected to the processor; wherein: the processor is used to generate a first cloud authentication information according to a second key calculation parameter, a third key calculation parameter, and a current second device key. Among them, the second key calculation parameter and the third key calculation parameter are also used to generate a second cloud authentication information with the device key of the device to be networked. The first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses a first access point. The second key calculation parameter is generated by the device to be networked, and the third key calculation parameter is generated by the device cloud platform; the processor is further used to update the current second device key according to the first key calculation parameter to obtain an updated second device key. Among them, the first key calculation parameter is also used to update the device key of the device to be networked when the device to be networked accesses the first access point and the identity authentication for the device cloud platform is passed. The first key calculation parameter is generated by the device cloud platform, and the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling; the processor is further used to store the updated second device key; the transceiver is used to send the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter to the power distribution cloud platform.
71. A power distribution cloud platform, characterized in that, the power distribution cloud platform includes: a processor, and a transceiver connected to the processor; wherein: The transceiver is used to receive a first key calculation parameter, a third key calculation parameter, and a first cloud authentication information from a device cloud platform. Wherein, the first key calculation parameter is used to update the device key of the device to be networked when the device to be networked accesses a first access point and the identity authentication for the device cloud platform is passed. The device key of the device to be networked and the third key calculation parameter are used to generate a second cloud authentication information with a second key calculation parameter. The first cloud authentication information and the second cloud authentication information are used to authenticate the identity of the device cloud platform before the device to be networked accesses the first access point. Both the first key calculation parameter and the third key calculation parameter are generated by the device cloud platform, and the second key calculation parameter is generated by the device to be networked; The transceiver is further used to send the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter to the device to be networked, wherein the first cloud authentication information, the first key calculation parameter, and the third key calculation parameter are sent to the device to be networked in the same information or signaling.
72. A computer-readable storage medium, characterized in that, a computer program is stored in the computer-readable storage medium, and the computer program is used to be executed by a processor of a device to be networked to implement the key update method according to any one of claims 1 to 20.
73. A computer-readable storage medium, characterized in that, a computer program is stored in the computer-readable storage medium, and the computer program is used to be executed by a processor of a device for network configuration to implement the key update method according to any one of claims 21 to 39.
74. A computer-readable storage medium, characterized in that, a computer program is stored in the computer-readable storage medium, and the computer program is used to be executed by a processor of a device cloud platform to implement the key update method according to any one of claims 40 to 59.
75. A computer-readable storage medium, characterized in that, a computer program is stored in the computer-readable storage medium, and the computer program is used to be executed by a processor of a network configuration cloud platform to implement the key update method according to any one of claims 60 to 63.
Citation Information
Patent Citations
Network key updating system, method and apparatus
CN108449756A
WIFI module network distribution method, device and system and storage medium
CN111711979A