Device, method and computer program for starting a group of node devices for wireless local area networking
By designing node devices that automatically obtain status allocation and calculate set membership test function values, the cumbersome and time-consuming problem of IoT device startup process is solved, and the automated startup of multiple node devices and rapid network joining is realized.
Patent Information
- Application Number
- CN202080094681.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-01-30
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2040-01-30
AI Technical Summary
In the prior art, IoT devices that start wireless local networking need to be manually operated one by one, especially when there are many devices and difficult to reach the location, resulting in users facing cumbersome and time-consuming startup processes.
By designing a node device, which includes a processor and a transceiver, it can automatically obtain the master or slave node status allocation, calculate the set membership test function value, and realize the automatic startup of multiple node devices through wireless communication broadcast or connecting to related access points.
This method can automatically start multiple node devices without the need for a separate connection between the controller device and each node device, significantly reducing user interaction and startup time, and improving support capabilities for hard-to-reach location devices.
Smart Images

Figure CN115039386B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of wireless communications, and more specifically to starting a group of node devices for wireless local area networking and related devices, methods and computer programs. Background Art
[0002] Internet of Things (IoT) devices such as sensors and actuators are now ubiquitous and part of our lives. IoT devices used in the home environment can include, for example, smart locks, light bulbs, home appliances, weather sensors, and so on. A home can include dozens of IoT devices. These devices need to be placed in suitable locations and configured to be operated by the end user (such as the owner of the household). For example, some devices may have to be mounted on the ceiling, while others can be placed in easy-to-reach locations, such as on top of a drawer or next to a TV cabinet.
[0003] Typically, in order for users to access and use IoT devices, they first need to be configured in working mode. The process of switching a device from non-working mode to working mode is called bootstrapping.
[0004] Currently, the startup process is done individually, so each step in the startup process needs to be repeated for each IoT device. In addition, the user needs to have physical access to each IoT device, for example, in order to press one or more buttons on each IoT device and / or observe / scan one or more codes on each IoT device. That is, even if the IoT devices are installed in an inaccessible location (such as on the ceiling), the user must reach each IoT device and then start them. In addition, the average user may have limited knowledge of technology, so starting all IoT devices individually is likely to be a physical and mental burden, especially when there are many IoT devices. Summary of the invention
[0005] The purpose of this Summary is to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter.
[0006] The object of the present invention is to enable a group of node devices for wireless local area networking. The above and other objects are achieved by the features of the independent claims. Other implementations are obvious in the dependent claims, the description and the drawings.
[0007] According to a first aspect of the present invention, a node device for wireless local area networking is provided. The node device includes a processor and a transceiver. The node device is configured to be included in a group of node devices for wireless local area networking. The processor is used to obtain one of a master node state allocation or a slave node state allocation for a startup process of the group of node devices. When obtaining the master node state allocation, the processor is also used to: calculate a set membership test function value based on a unique device identifier of the node device and unique device identifiers of other node devices in the group of node devices; broadcast a first service set identifier associated with a first access point for wireless local area networking via the transceiver, wherein the first service set identifier is based on the calculated set membership test function value, so that the node device is used as the first access point associated with the broadcasted first service set identifier. When obtaining the slave node state allocation, the processor is also used to connect to a second access point for wireless local area networking associated with a second service set identifier via the transceiver. The processor is used to obtain the slave node state allocation in the following manner: determining that the second service set identifier is based on a set membership test function value, and further determining that the unique device identifier of the node device is a member of the set represented by the set membership test function value. The present invention can start multiple node devices for wireless local area networking without requiring a controller device to establish a connection with each node device separately. The present invention can also start multiple node devices with minimal user interaction. Usually, the user who performs the startup only needs to physically access one of the multiple node devices. The present invention can also easily start node devices located in difficult-to-reach locations, such as node devices installed on the ceiling. The present invention can also significantly reduce the time required to start all node devices, because the user does not need to start each node device one by one, but only needs to scan one node device to join the network and start all node devices. The present invention can also safely start multiple node devices. For example, the master node uses a unique service set identifier in the format of a set membership test function value, thereby reducing the possibility of an identifier misbinding attack, because the node devices only join the group when their unique device identifiers are verified according to the service set identifier (set membership test function value). The present invention can also implement a reliable mechanism for resetting node devices and / or releasing node devices from a group. That is, if a device needs to be removed from a group, the user can remove the device while the group attributes (ie, trust relationship and startup) remain unchanged.
[0008] In an implementation of the first aspect, the processor is further used to: receive the unique device identification of the other node devices when the unique device identification is broadcast by the other node devices; the processor is further used to obtain the master node state allocation by receiving a master node election indication from a general election protocol, wherein the general election protocol is periodically applied by the processor using the unique device identification of the node device and the received unique device identification of the other node devices. When the master node device collects the unique device identifications of node devices that join the SSID network based on the set membership test function value, the master node device may be able to reject connection requests from unknown devices, thereby reducing the possibility of misbinding.
[0009] In an implementation of the first aspect, the universal election protocol includes one of a mega-merger protocol or a yo-yo protocol. The universal election protocol can be used to efficiently elect a master node.
[0010] In an implementation of the first aspect, the processor is also used to obtain the master node state allocation by receiving a master node selection instruction and the unique device identifier of the other node device from an external device. When the master node device is selected by an external device, the selected master node device can be used as an auxiliary controller device, which can be used to restore the factory settings of the node device that has been started, for example, when the user's device (controller device) changes. For example, in a hotel room with IoT devices, users (guests) change frequently, so the IoT device needs to be restarted using the controller device of the new user, which requires the above function.
[0011] In an implementation of the first aspect, when the master node status allocation is obtained and at least one of the other node devices establishes a secure connection with the node device used as the first access point, the processor is also used to exchange the unique device identifier and operation credentials with the at least one of the other node devices via the transceiver, thereby obtaining ownership of the at least one of the other node devices for startup. When a slave node device is connected to an access point, the master node device can verify whether the unique device identifier of the connected slave node device is in the received identifier list. In addition, the master node device that obtains ownership of the slave node device can perform a portion of the startup process before the end user participates, thereby simplifying and speeding up the startup process from the end user's perspective.
[0012] In an implementation of the first aspect, when the master node state assignment is obtained and the node device is subsequently used as the first access point, the processor is further configured to receive a unique device identifier and a startup key of at least one of the other node devices from a controller device outside the group of node devices via the transceiver, thereby obtaining ownership of the at least one of the other node devices for startup. The master node device that obtains ownership of the slave node device can perform a portion of the startup process before the end user participates, thereby simplifying and speeding up the startup process from the end user's perspective.
[0013] In an implementation of the first aspect, the processor is further configured to: receive the second service set identifier when scanning an infrastructure mode wireless local area network. The scanning can effectively obtain the second service set identifier.
[0014] In an implementation of the first aspect, the set membership test function includes a Bloom filter. A Bloom filter is an effective implementation of the set membership test function.
[0015] According to a second aspect of the present invention, a method is provided. The method comprises: a node device for wireless local area networking configured to be included in a group of node devices for wireless local area networking obtains one of a master node state allocation or a slave node state allocation for a startup process of the group of node devices. When obtaining the master node state allocation, the method further comprises: the node device calculates a set membership test function value according to a unique device identifier of the node device and unique device identifiers of other node devices in the group of node devices; the node device broadcasts a first service set identifier associated with a first access point for wireless local area networking, wherein the first service set identifier is based on the calculated set membership test function value, so that the node device is used as the first access point associated with the broadcasted first service set identifier. When obtaining the slave node state allocation, the method further comprises: the node device connects to a second access point for wireless local area networking associated with a second service set identifier. The obtaining of the slave node state allocation comprises determining that the second service set identifier is based on the set membership test function value, and further determining that the unique device identifier of the node device is a member within the set represented by the set membership test function value. The present invention can start multiple node devices for wireless local area networking without requiring the controller device to establish a connection with each node device separately. The present invention can also start multiple node devices with minimal user interaction. Generally, the user who performs the startup only needs to physically access one of the multiple node devices. The present invention can also easily start node devices located in difficult-to-reach locations, such as node devices installed on the ceiling. The present invention can also significantly reduce the time required to start all node devices, because the user does not need to start each node device one by one, but only needs to scan one node device to join the network and start all node devices. The present invention can also safely start multiple node devices. For example, the master node uses a unique service set identifier in the format of a set membership test function value, thereby reducing the possibility of an identity misbinding attack, because the node devices only join the group when their unique device identifiers are verified according to the service set identifier (set membership test function value). The present invention can also implement a reliable mechanism for resetting node devices and / or releasing node devices from the group. That is, if a device needs to be removed from the group, the user can remove the device while the group attributes (i.e., trust relationship and startup) remain unchanged.
[0016] In an implementation of the second aspect, when the unique device identification of the other node device is broadcast by the other node device, the unique device identification is received; the method further includes: obtaining the master node state allocation by receiving a master node election indication from a general election protocol, wherein the general election protocol is periodically applied by the node device using the unique device identification of the node device and the received unique device identification of the other node device. When the master node device collects the unique device identifications of node devices that join the SSID network based on the set membership test function value, the master node device may be able to reject connection requests from unknown devices, thereby reducing the possibility of misbinding.
[0017] In an implementation of the second aspect, the general election protocol includes one of a super large merge protocol or a yo-yo protocol. The general election protocol can be used to efficiently elect a master node.
[0018] In an implementation of the second aspect, the method further includes: obtaining the master node status allocation by receiving a master node selection instruction and the unique device identifier of the other node device from an external device. When the master node device is selected by an external device, the selected master node device can be used as an auxiliary controller device, which can be used to restore the factory settings of the already started node device, for example, when the user's device (controller device) changes. For example, in a hotel room with IoT devices, users (guests) change frequently, so the IoT device needs to be restarted using the controller device of the new user, which requires the above function.
[0019] In an implementation of the second aspect, when the master node status allocation is obtained and at least one of the other node devices establishes a secure connection with the node device used as the first access point, the method further includes: the node device exchanges the unique device identifier and operation credentials with the at least one of the other node devices, thereby obtaining ownership of the at least one of the other node devices for startup. When a slave node device is connected to an access point, the master node device can verify whether the unique device identifier of the connected slave node device is in the received identifier list. In addition, the master node device that obtains ownership of the slave node device can perform a portion of the startup process before the end user participates, thereby simplifying and speeding up the startup process from the end user's perspective.
[0020] In an implementation of the second aspect, when the master node state assignment is obtained and the node device is subsequently used as the first access point, the method further includes: the node device receives a unique device identification and a startup key of at least one of the other node devices from a controller device outside the group of node devices, thereby obtaining ownership of the at least one of the other node devices for startup. The master node device that obtains ownership of the slave node device can perform a portion of the startup process before the end user participates, thereby simplifying and speeding up the startup process from the end user's perspective.
[0021] In an implementation of the second aspect, the method further includes: when scanning the infrastructure mode wireless local area network, receiving the second service set identifier. The scanning can effectively obtain the second service set identifier.
[0022] In an implementation of the second aspect, the set membership test function includes a Bloom filter. A Bloom filter is an effective implementation of the set membership test function.
[0023] According to a third aspect of the present invention, a computer program product is provided. The computer program product includes a program code, and when the computer program product is executed on a computer, the program code is used to execute the method according to the second aspect. The present invention can start multiple node devices for wireless local area networking without requiring a controller device to establish a connection with each node device separately. The present invention can also start multiple node devices with minimal user interaction. Usually, the user who performs the startup only needs to physically access one of the multiple node devices. The present invention can also easily start node devices located in difficult-to-reach locations, such as node devices installed on the ceiling. The present invention can also significantly reduce the time required to start all node devices, because the user does not need to start each node device one by one, but only needs to scan one node device to join the network and start all node devices. The present invention can also safely start multiple node devices. For example, the master node uses a unique service set identifier in the format of a set membership test function value, thereby reducing the possibility of identity misbinding attacks, because node devices only join the group when their unique device identifiers are verified according to the service set identifier (set membership test function value). The present invention can also implement a reliable mechanism for resetting node devices and / or releasing node devices from a group. That is, if a device needs to be removed from a group, the user can remove the device while the group attributes (ie, trust relationship and startup) remain unchanged.
[0024] According to a fourth aspect of the present invention, a controller device for a group of node devices for wireless local area networking is provided. The group of node devices includes a master node device, which is assigned a master node state for the startup process of the group of node devices and serves as an access point for wireless local area networking. The controller device includes a transceiver and a processor. The processor is used to obtain a unique device identifier and a startup key of a node device in the group of node devices and a service set identifier associated with the access point and based on a set membership test function value. The processor is also used to verify whether the acquired unique device identifier is a member of the set represented by the set membership test function value. When the acquired unique device identifier is a member of the set represented by the set membership test function value, the processor is also used to: establish an infrastructure mode connection for wireless communication with the access point via the transceiver; perform authentication on the node device in the group of node devices through the acquired startup key; and when the authentication is successful, start the authenticated node device. The present invention can start multiple node devices for wireless local area networking without requiring the controller device to establish a connection with each node device separately. The present invention can also start multiple node devices with minimal user interaction. Typically, the user who performs the startup only needs to physically access one of the multiple node devices. The present invention can also easily start node devices located in difficult-to-reach locations, such as node devices installed on the ceiling. The present invention can also significantly reduce the time required to start all node devices, because the user does not need to start each node device one by one, but only needs to scan one node device to join the network and start all node devices. The present invention can also safely start multiple node devices. For example, the master node uses a unique service set identifier in the format of a set membership test function value, thereby reducing the possibility of an identity misbinding attack, because the node devices only join the group when their unique device identifiers are verified according to the service set identifier (set membership test function value). The present invention can also implement a reliable mechanism for resetting node devices and / or releasing node devices from the group. That is, if a device needs to be removed from the group, the user can remove the device while the group attributes (i.e., trust relationship and startup) remain unchanged.
[0025] In an implementation of the fourth aspect, the group of node devices further includes at least one slave node device, and the at least one slave node device is assigned a slave node state for the startup process. The processor is also used to: perform authentication on at least one other node device through corresponding operation credentials; when the authentication is successful, obtain ownership of the at least one other node device and start it. Using the controller device to start other node devices can quickly and efficiently complete the startup process.
[0026] In an implementation of the fourth aspect, the controller device further includes a machine-readable code scanner. The unique device identifier, the startup key, and the service set identifier of the node device in the group of node devices are obtained by scanning a machine-readable code associated with the node device in the group of node devices by the machine-readable code scanner. The code scanner can accurately and effectively obtain the unique device identifier, the startup key, and the service set identifier of the node device.
[0027] In an implementation of the fourth aspect, the set membership test function includes a Bloom filter. A Bloom filter is an effective implementation of the set membership test function.
[0028] According to a fifth aspect of the present invention, a method is provided. The method comprises: a controller device of a group of node devices for wireless local area networking obtains a unique device identification and a startup key of one node device in the group of node devices and a service set identification associated with an access point for wireless local area networking and based on a set membership test function value. The group of node devices comprises a master node device, the master node device is assigned a master node state for the startup process of the group of node devices and serves as the access point. The method further comprises: the controller device verifies whether the obtained unique device identification is a member of the set represented by the set membership test function value. When the obtained unique device identification is a member of the set represented by the set membership test function value, the method further comprises: the controller device establishes an infrastructure mode connection of wireless communication with the access point; the controller device performs authentication on the node device in the group of node devices through the obtained startup key; when the authentication succeeds, the controller device starts the authenticated node device. The present invention can start multiple node devices for wireless local area networking without requiring the controller device to establish a connection with each node device separately. The present invention can also start multiple node devices with minimal user interaction. Typically, the user who performs the startup only needs to physically access one of the multiple node devices. The present invention can also easily start node devices located in difficult-to-reach locations, such as node devices installed on the ceiling. The present invention can also significantly reduce the time required to start all node devices, because the user does not need to start each node device one by one, but only needs to scan one node device to join the network and start all node devices. The present invention can also safely start multiple node devices. For example, the master node uses a unique service set identifier in the format of a set membership test function value, thereby reducing the possibility of an identity misbinding attack, because the node devices only join the group when their unique device identifiers are verified according to the service set identifier (set membership test function value). The present invention can also implement a reliable mechanism for resetting node devices and / or releasing node devices from the group. That is, if a device needs to be removed from the group, the user can remove the device while the group attributes (i.e., trust relationship and startup) remain unchanged.
[0029] In an implementation of the fifth aspect, the group of node devices further includes at least one slave node device, and the at least one slave node device is assigned a slave node state for the startup process. The method further includes: performing authentication on at least one other node device through corresponding operation credentials; when the authentication is successful, obtaining ownership of the authenticated at least one other node device and starting it. Using a controller device to start other node devices can quickly and efficiently complete the startup process.
[0030] In an implementation of the fifth aspect, the controller device further includes a machine-readable code scanner. The unique device identifier, the startup key, and the service set identifier of the node device in the group of node devices are obtained by scanning a machine-readable code associated with the node device in the group of node devices by the machine-readable code scanner. The code scanner can accurately and effectively obtain the unique device identifier, the startup key, and the service set identifier of the node device.
[0031] In an implementation of the fifth aspect, the set membership test function includes a Bloom filter. A Bloom filter is an effective implementation of the set membership test function.
[0032] According to a sixth aspect of the present invention, a computer program product is provided. The computer program product includes a program code, and when the computer program product is executed on a computer, the program code is used to execute the method according to the fifth aspect. The present invention can start multiple node devices for wireless local area networking without requiring a controller device to establish a connection with each node device separately. The present invention can also start multiple node devices with minimal user interaction. Usually, the user who performs the startup only needs to physically access one of the multiple node devices. The present invention can also easily start node devices located in difficult-to-reach locations, such as node devices installed on the ceiling. The present invention can also significantly reduce the time required to start all node devices, because the user does not need to start each node device one by one, but only needs to scan one node device to join the network and start all node devices. The present invention can also safely start multiple node devices. For example, the master node uses a unique service set identifier in the format of a set membership test function value, thereby reducing the possibility of an identity misbinding attack, because the node devices only join the group when their unique device identifiers are verified according to the service set identifier (set membership test function value). The present invention can also implement a reliable mechanism for resetting node devices and / or releasing node devices from a group. That is, if a device needs to be removed from a group, the user can remove the device while the group attributes (ie, trust relationship and startup) remain unchanged.
[0033] Many features will be more readily appreciated as the same are better understood by reference to the following detailed description considered in conjunction with the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In the following, exemplary embodiments are described in more detail with reference to the accompanying drawings, in which:
[0035] Figure 1A is a block diagram of an exemplary system in which various embodiments of the present invention may be implemented;
[0036] Figure 1B It is a block diagram of a node device used for wireless local area networking;
[0037] Figure 1C It is a block diagram of a controller device for a group of node devices used in wireless local area networking;
[0038] Figure 2 is a flow chart of the method provided by the present invention;
[0039] Figure 3 is another flow chart of the method provided by the present invention;
[0040] FIG. 4A to FIG. 4D is a schematic diagram of a startup mechanism of an exemplary embodiment.
[0041] In the following, identical reference numerals refer to identical features or at least functionally equivalent features. DETAILED DESCRIPTION
[0042] The following description will be made in conjunction with the accompanying drawings, which form a part of the present invention and illustrate specific aspects of the present invention by way of diagrammatic illustration. It should be understood that other aspects may be utilized and structural or logical changes may be made without departing from the scope of the present invention. Therefore, the following detailed description should not be understood in a restrictive sense, as the scope of the present invention is defined by the appended claims.
[0043] For example, it should be understood that the disclosure related to the described method is also applicable to the corresponding device or system for performing the method, and vice versa. For example, if a specific method step is described, the corresponding device may include a unit for performing the described method step, even if such a unit is not explicitly described or illustrated in the figure. On the other hand, for example, if a specific device is described in terms of functional units, the corresponding method may include steps for performing the described function, even if such steps are not explicitly described or illustrated in the figure. In addition, it should be understood that the features of the various exemplary aspects described herein may be combined with each other unless otherwise explicitly stated.
[0044] The following provides a general description of traditional bootstrapping of Internet of Things (IoT) devices.
[0045] As mentioned above, in order for users to access and use IoT devices, it is usually necessary to first configure these devices to be in working mode. Here, the process of switching a device from non-working mode to working mode is called booting.
[0046] Typically, the startup of an IoT device can include 3 main stages:
[0047] (1) Pairing resource-constrained IoT devices with controller devices (e.g., smartphones);
[0048] (2) Acquire ownership of IoT devices by exchanging identities and credentials required for mutual authentication of entities and protect communications between these entities;
[0049] (3) Configure the device to work, that is, enable the user to monitor, control and command the device.
[0050] IoT devices can support Internet Protocol (IP), etc. Generally, the startup process of a device that supports IP can include the following steps:
[0051] – IoT devices start up in Wi-Fi access point (AP) mode and advertise their network using a human-readable service set identifier (SSID) name;
[0052] – The controller device joins the network with the SSID advertised by the IoT device;
[0053] – The controller device boots the IoT device through the SSID network and follows steps (1) to (3) described above. As a result, the IoT device now has the credentials required to join the user’s home network;
[0054] –IoT devices switch from AP mode to working mode;
[0055] – IoT devices join the user’s private home Wi-Fi network;
[0056] – Users gain access and can now control IoT devices over their private home Wi-Fi network.
[0057] Therefore, the traditional startup process is completed individually, so that the controller device needs to establish a connection with each IoT device separately. In addition, the user needs to have physical access to each IoT device. That is, even if the IoT device is installed in an inaccessible location (such as on the ceiling), the user must reach each IoT device and then start the devices.
[0058] As described in detail below, the startup process provided by the present invention can start multiple node devices for wireless local area networking without requiring the controller device to establish a connection with each node device separately. The startup process provided by the present invention can also start multiple node devices with minimal user interaction. For example, the user performing the startup may only need to physically access one of the multiple node devices.
[0059] An exemplary use case of the present invention is a smart home / building, where IoT devices are installed for each apartment by a building maintenance company and then used by the apartment owners / residents. This installation is usually completed before the apartment owners / residents move into the apartment. That is, the user (e.g., apartment owner / resident) may not participate in the installation and may not even have physical access to all the installed IoT devices. These devices can be installed on the ceiling of the room, the roof and / or other locations that are not easily accessible. The startup process provided by the present invention allows these users (e.g., apartment owners / residents) who move into the apartment to put the IoT devices into operation (startup) at any time.
[0060] As described in detail below, in at least some embodiments of the present invention, the startup process may include 3 stages, etc., such that the first 2 stages may occur in advance without the participation of the user (or end user), while the last stage (i.e., the stage in which the user obtains ownership of the IoT device) may occur later with the participation of the user.
[0061] Dividing the onboarding process into these three phases in this way can increase the freedom of when the end user can take ownership of the IoT device. For example, the IoT device can first be installed by a third party (such as a building maintenance company), and then the end user can complete the onboarding process at their convenience with only minimal interaction with the IoT device.
[0062] Next, refer to Figure 1A , Figure 1B and Figure 1C An exemplary embodiment of a node device 110A for wireless local area networking and a controller device 120 for a group of node devices 110A to 110F for wireless local area networking is described. Some features of the described devices are optional features that provide further advantages.
[0063] Figure 1A1 is a block diagram of an exemplary system 100 in which various embodiments of the present invention may be implemented. System 100 includes a wireless local area network (WLAN) or Wi-Fi network 150, such as an IEEE 802.11 network. A set of node devices 110A to 110F, a controller device 120, and another external device (e.g., an installer device 130) are wirelessly connected to network 150. As described in detail below, node devices 110A to 110F may include Internet-of-Things (IoT) devices, and controller device 120 and installer device 130 may be used to assist in the boot process.
[0064] Figure 1B 1 is a block diagram of a node device 110A for wireless local area networking. In one embodiment, the node device 110A may include an Internet of Things (IoT) device capable of communicating via wireless local area networking. These IoT devices may include, but are not limited to, sensors, actuators, smart locks, light bulbs, household appliances, weather sensors, and the like. The node device 110A is configured to be included in a group of node devices 110A to 110F for wireless local area networking.
[0065] The node device 110A for wireless local area networking includes at least one processor or processing unit 112A, and optionally includes at least one memory 113A coupled to the at least one processor 112A, which can be used to implement the functions described in detail below. The node device 110A also includes at least one transceiver 111A (or receiving unit / receiver and / or sending unit / transmitter) coupled to the at least one processor 112A.
[0066] At least one processor 112A may include, for example, one or more of various processing devices, such as a coprocessor, a microprocessor, a controller, a digital signal processor (DSP), a processing circuit including or not including a DSP, or various other processing devices including integrated circuits, including application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), microcontroller units (MCUs), hardware accelerators, special-purpose computer chips, and the like.
[0067] At least one memory 113A may be used to store computer programs, etc. At least one memory 113A may include one or more volatile memory devices, one or more non-volatile memory devices, and / or a combination of one or more volatile memory devices and non-volatile memory devices. For example, at least one memory 113A may be embodied as a magnetic storage device (e.g., a hard disk drive, etc.), an optical magnetic storage device, and a semiconductor memory (e.g., a mask ROM, a programmable ROM (PROM), an erasable PROM (EPROM), a flash ROM, a random access memory (RAM), etc.).
[0068] The processor 112A may be used to broadcast the unique device identification of the node device 110A via the transceiver 111A. The processor 112A may also be used to scan other node devices via the transceiver 111A. Figures 1A to 1C In the example of , other node devices 110B to 110F may also broadcast their respective unique device identifications, so when scanning other node devices, processor 112A may receive the unique device identifications of at least some of the other node devices 110B to 110F via transceiver 111A. The unique device identifications of at least some of the node devices 110A to 110F may include, for example, a universally unique identifier (UUID).
[0069] The processor 112A may also be configured to scan for infrastructure mode wireless local area networks via the transceiver 111A. Figures 1A to 1C In the example of FIG. 1 , at least some of the other node devices 110B to 110F may also scan for the infrastructure mode wireless LAN.
[0070] For example, in order for the node devices 110A to 110F to form a network, the node devices may first discover each other, for example, by exchanging messages via IEEE 802.11 management frames. That is, the node devices 110A to 110F may use 802.11 management frames to advertise their identities while listening to 802.11 frames to discover other devices nearby. Once the node devices 110A to 110F have discovered each other, they may, for example, form an ad-hoc network and then, for example, interact with each other to establish a group master node (described in detail below).
[0071] In other words, the IEEE 802.11 network can operate in ad-hoc mode or infrastructure mode. The ad-hoc mode is also referred to as an independent basic service set (IBSS) mode, in which all devices operate in peer-to-peer mode. In infrastructure mode, all devices are connected to an access point. In at least some disclosed exemplary embodiments, node devices 110A to 110F can be connected to each other in ad-hoc mode to exchange their identities and select a master node device. Optionally, node devices 110A to 110F can use infrastructure mode, thereby using IEEE 802.11 management frames to announce their identities, listen to IEEE 802.11 management frames to discover other devices nearby, and scan available SSID networks. As described in detail below, when using ad-hoc mode, the first node device (the elected master node device) becomes an access point, and other node devices switch to infrastructure mode. When using infrastructure mode, the elected master node can change its access point SSID to a calculated set membership test function value (described in detail below).
[0072] The processor 112A is further configured to obtain a master node status allocation or a slave node status allocation for a boot process of a group of node devices 110A to 110F.
[0073] In one embodiment of the node device 110A, the processor 112A may be used to obtain the master node state allocation by receiving a master node election indication from a general election protocol. The general election protocol may be periodically applied by the processor 112A using the unique device identification of the node device 110A and the received unique device identifications of other node devices 110B to 110F. For example, the general election protocol may include a mega-merger protocol or a yo-yo protocol.
[0074] In one embodiment, the node devices 110A to 110F may exchange election protocol messages to complete the election protocol, and such election protocol message exchanges may include multiple rounds of messages determined according to the protocol. An example includes a probabilistic method, in which a node with abundant resources sets a bit to indicate that the node is likely to become a master node, and nodes with less resources set the bit to 0, etc. to indicate that these nodes will not become master nodes. In the case of indicating that there are two or more nodes with abundant resources to become master nodes, these nodes may set or unset bits by using a probabilistic algorithm, etc., or these nodes may randomly set bits to 1 or 0 until a master node is selected among them.
[0075] The super-large merge protocol is a general election protocol that works by building a root spanning tree of the network, where the root is the elected master node in the final spanning tree. The root spanning trees are merged together until a tree covering the entire network is built.
[0076] The yo-yo protocol is a distributed protocol (or algorithm) that aims to perform minimum value finding and master node election in a universal connected undirected graph. The yo-yo protocol is performed by successive elimination and graph reduction techniques (called pruning). The yo-yo protocol is divided into a preprocessing phase and a subsequent cyclically repeated forward phase, called "Yo-", and a backward phase, called "-Yo".
[0077] In other words, processor 112A can be used to use the received unique device identification and the unique device identification of node device 110A to periodically evaluate the general election protocol. Periodic evaluation can be performed within a predefined time. If the general election protocol indicates that node device 110A is elected as the master node device, processor 112A can be used to stop broadcasting the unique device identification of node device 110A, and stop scanning other node devices and infrastructure mode wireless local area network. Accordingly, node device 110A becomes the master node.
[0078] Therefore, when a master node device is elected using a universal election protocol, the elected master node device can provide a gateway via an access point to connect with the slave node devices.
[0079] Figure 4A This is further illustrated in the schematic diagram 410 of FIG. Figure 4A In the example of , the node devices 110A to 110F support and participate in general master node election protocols, such as super large merge or yo-yo protocols. These protocols can, for example, build a root spanning tree or implement a minimum value search protocol. Therefore, the root of the tree can become the master node of the network (group). The elected master node device 110A can collect the unique device identifiers D1 to D5 of other node devices 110B to 110F as network members. Optionally, for example, when other node devices 110B to 110F are configured to trust the master node, the elected master node device 110A can also collect the corresponding startup keys (such as passphrases, shared keys, etc.) S1 to S5 of other node devices 110B to 110F. This can have the following advantages: in the final startup phase, the master node device can verify that the controller device knows the shared key of one of the node devices that the controller device interacts with, etc., without having to send a query message to the node device. Optionally, in the verification phase, the master node device can request a specific node device to verify whether the controller device has interacted with it.
[0080] When the master node device collects unique device identifiers of node devices that join a SSID network based on a bloom filter, the master node device may be able to reject connection requests from unknown devices to reduce the possibility of erroneous binding.
[0081] In another embodiment of the node device 110A, the processor 112A may be used to obtain the master node status assignment by receiving the master node selection instruction and the unique device identification of other node devices 110B to 110F from an external device 130 (e.g., an installer device). The installer device 130 may include, for example, a device (e.g., a smart phone, a tablet computer, a smart watch or other wearable device, a laptop computer, etc.) being used by a party (e.g., a building maintenance company) that installs the node devices 110A to 110F. In one embodiment, the installer device 130 and the controller device 120 (described in detail below) may be integrated into a single device.
[0082] In other words, the processor 112A may be operable to receive an indication that the node device 110A has been selected as the master node and a list of unique device identifications of other node devices 110B to 110F from the external / installer device 130. Accordingly, the node device 110A becomes the master node.
[0083] Figure 4B This is further illustrated in the schematic diagram 420 of FIG. Figure 4B In the example of , the processor 112A in the selected master node 110A may also be used to authenticate the installer device 130. To do so, the master node 110A may be configured with a trust anchor, etc., so that the certificate of the installer device 130 can be verified, etc. After authenticating the installer device 130, the two entities (i.e., the master node 110A and the installer device 130) may establish a secure communication channel. The installer device 130 may send the unique device identifications D1 to D5 of the other node devices 110B to 110F forming the network to the master node 110A. The installer device 130 may, for example, obtain the unique device identification information and optional corresponding startup keys (e.g., passphrases, shared keys, etc.) S1 to S5 of the other node devices 110B to 110F by scanning each node device or from other node devices (e.g., a centralized server).
[0084] In other words, when the master node device is selected by the installer device 130, the selected master node device can provide a gateway via its access point to connect to the slave node device. In this embodiment, the master node device may not directly participate in the startup. That is, there is no partial startup with the slave node device. Instead, the master node device serves as an access point to which all slave node devices and controller devices can connect. The controller device knows the slave nodes, including unique device identification and startup keys, etc. This information can be obtained from a centralized server, etc., or the user can scan this information from the slave node device, etc. or scan this information from printed paper, etc. having this information. When the controller device joins a network operated by the master node device, the controller device can receive information about how to connect to the slave node device. For example, the controller device can query the master node device using the identification of the slave node device, and receive the IP address of the slave node device in the network in response.
[0085] In this case, the slave devices do not need to trust the master device for booting. The master device acts as an access point facilitator. This can have the advantage of avoiding a situation where the slave devices start in access point mode and the controller device joins the network of each slave device to boot those devices. However, the booting still occurs between the slave devices and the controller device within a single network operated by the master device.
[0086] The controller device 120 can be used to, for example, scan (or the end user can manually enter using the controller device 120) startup keys (such as passphrases, shared keys, etc.) S1 to S6 of at least some of the node devices 110A to 110F. To achieve this, at least some of the node devices 110A to 110F may also include elements for displaying human-readable or machine-readable codes (such as QR codes) that include information that can be used to protect startup. Here, this element is referred to as an out-of-band channel. For example, the out-of-band channel may include a label attached to the outer surface of the node devices 110A to 110F. As another example, the out-of-band channel may include a display device included in the node devices 110A to 110F for displaying a human-readable or machine-readable code. In both cases, the code can be static, but in the latter case, the code can also be dynamic (for example, a code that is only activated within a specific time).
[0087] When the master node device is selected by the installer device, the selected master node device can be used as an auxiliary controller device, which can be used, for example, to restore the factory settings of the node device that has been started when the user's device (controller device) changes. For example, in a hotel room with IoT devices, users (guests) change frequently, so the IoT device needs to be restarted using the controller device of the new user, which requires the above function.
[0088] When acquiring the master node status allocation, the processor 112A is used to calculate the set membership test function value according to the unique device identification of the node device 110A and the unique device identifications of other node devices 110B to 110F in a group of node devices 110A to 110F.
[0089] For example, the set membership test function may include a Bloom filter. A Bloom filter is a space-efficient probabilistic data structure that can be used, for example, to check set membership, ie, whether an element x is a member of a set S.
[0090] An example of a Bloom filter B is implemented by a single array of M bits, where M is the filter size. When creating the filter, all M bits are set to 0. B m represents the bit with index m, where m is in the range [0,M–1]. The Bloom filter is then parameterized by a constant k that defines the number of hash functions. Then, each hash function h 0 、h 1 ……h k–1 Maps input elements to indices in the range [0, M–1]. Only insertion (or append) and query operations are allowed. No deletion or removal operations are allowed.
[0091] To query an element in a set, pass the element to each of the k hash functions to obtain k integer array indices. If any of the bits at these indices are 0, the element is not in the set. If all bits are 1, the element may be in the set.
[0092] For example, when acquiring the master node state allocation through the general master node election protocol, the master node 110A may calculate the Bloom filter value according to the collected unique device identifiers D1 to D5 and the unique device identifier D6 of the master node 110A.
[0093] As another example, when acquiring the master node status assignment through the selection instruction of the external device 130 , the master node 110A may calculate the Bloom filter value using the unique device identifiers D1 to D5 sent by the installer device 130 and the unique device identifier D6 of the master node 110A.
[0094] In addition, when acquiring the master node state assignment, the processor 112A is configured to broadcast, via the transceiver 111A, a first service set identifier (SSID) associated with a first access point for wireless local area networking, so that the node device 110A functions as a first access point associated with the broadcasted first SSID. The first SSID is based on the calculated set membership test function value.
[0095] In other words, the master node device 110A may calculate a set membership test function value using the received identifier and its own identifier, and start a Wi-Fi access point whose SSID is based on the calculated value.
[0096] For example, when obtaining the master node state assignment through the general master node election protocol, the master node 110A can switch to access point (AP) mode and announce the calculated Bloom filter value as the SSID of the network. Therefore, the SSID of each network is unique. Then, other node devices can join the SSID network after verifying that their respective unique device identifiers are members of the Bloom filter value.
[0097] For another example, when acquiring the master node state assignment through the selection instruction of the external device 130, the master node 110A may enter the AP mode and announce the calculated Bloom filter value as the SSID of its network. Then, other node devices may connect to the SSID network after verifying that their respective unique device identifiers are members of the Bloom filter value. In order to prevent unknown node devices from joining the network, the master node 110A may refuse to connect to any node device that is not in the sent unique device identifier list.
[0098] When acquiring slave node state allocation, processor 112A is used to connect to a second access point for wireless local area networking associated with a second service set identifier (SSID) via transceiver 111A. When scanning for infrastructure mode wireless local area networks, processor 112A can be used to receive a second SSID. Processor 112A is used to acquire slave node state allocation by determining that the second SSID is based on a set membership test function value, and further determining that the unique device identifier of node device 110A is a member of the set represented by the set membership test function value.
[0099] In other words, if any node device among the node devices 110A to 110F finds that the SSID is a Wi-Fi network including the set membership test function value of the unique device identification of the node device, the node device may stop broadcasting its own identification and stop scanning, and then become a slave device.
[0100] For example, node devices 110A to 110F can scan for networks whose SSIDs are based on Bloom filter values. When node devices find such networks, they verify that their own unique device identifiers are part of the Bloom filter value. If the verification is successful, the node device knows that it is connecting to the correct network. Other node devices can trust the master node device based on the principle of the "resurrecting duckling" imprint model. That is, "when a device is powered on, the device identifies the first entity it connects to as its owner."
[0101] In one embodiment of the node device 110A, when obtaining the master node state allocation and at least one of the other node devices 110B to 110F establishes a secure connection (e.g., transport layer security (TLS) / datagram transport layer security (DTLS) connection) with the node device 110A used as the first access point, the processor 112A can also be used to exchange a unique device identifier and an operation credential key with at least one of the other node devices 110B to 110F via the transceiver 111A, thereby obtaining ownership of at least one of the other node devices 110B to 110F for startup. When a slave node device is connected to an access point, the master node device can verify that the unique device identifier of the connected slave node device is in the received identifier list.
[0102] For example, slave devices can establish a TLS / DTLS connection to pair with a master device that they may already trust. In turn, the master device can gain ownership of the slave device. In one embodiment, the master and slave devices can exchange identities, and the master device can provide the slave device with operational credentials for authentication and protection of future communications, such as Figure 4C 430. Examples of operating credentials may include an asymmetric key pair (e.g., generated by one or more slave node devices or imported from a master node device), optionally including a certificate associated with the asymmetric key pair and issued by the master node device. In addition, one or more slave node devices may be configured with a root of trust, such as a root certificate that is explicitly trusted by the slave node and used to verify the certificates of other entities. These locally issued certificates can form a local public key infrastructure (PKI), which can be used in various protocols to perform mutual authentication and secure communication of endpoints.
[0103] In another embodiment of the node device 110A, when the master node status assignment is obtained and the node device 110A is subsequently used as a first access point, the processor 112A can also be used to receive the unique device identification and startup key of at least one node device among other node devices 110B to 110F from a controller device 120 outside a group of node devices 110A to 110F via the transceiver 111A, thereby obtaining ownership of at least one node device among other node devices 110B to 110F for startup.
[0104] In other words, the master node device can receive and maintain a list of unique device identifiers D1 to D5 and corresponding startup keys (e.g., passphrases, shared keys, etc.) S1 to S5 of slave node devices 110B to 110F in the network from the controller device 120 (e.g., a user's smartphone). The controller device 120 can a priori obtain the unique device identifier of the slave node device that will join the master node device. In turn, the master node device can obtain ownership of the slave node device. More specifically, the slave node devices can exchange identifiers, and the master node device can provide the slave node device with operational credentials for authentication and protection of future communications.
[0105] Figure 1C 1 is a block diagram of a controller device 120 for a group of node devices 110A to 110F for wireless local area networking. In one embodiment, the controller device 120 may include a client device, which may be any of a variety of devices that can communicate via wireless local area networking and is directly used by an end-user entity, such as user equipment (UE). These devices include, but are not limited to, smartphones, tablet computers, smart watches and other wearable devices, laptops, etc.
[0106] As above combined Figure 1A and Figure 1B As described, a group of node devices 110A to 110F includes a master node device 110A, which has been assigned a master node state for a startup process of a group of node devices 110A to 110F. The master node device 110A is used as an access point for wireless local area networking. A group of node devices 110A to 110F may also include at least one slave node device 110B to 110F, and at least one slave node device 110B to 110F is assigned a slave node state for a startup process.
[0107] The controller device 120 includes at least one processor or processing unit 122, and optionally at least one memory 123 coupled to the at least one processor 122, which can be used to implement the functions described in detail below. The controller device 120 also includes at least one transceiver 121 (or receiving unit / receiver and / or sending unit / transmitter) coupled to the at least one processor 122. The controller device 120 may also include a machine-readable code scanner 124, such as a digital camera.
[0108] At least one processor 122 may include, for example, one or more of a variety of processing devices, such as a coprocessor, a microprocessor, a controller, a digital signal processor (DSP), a processing circuit including or not including a DSP, or various other processing devices including integrated circuits, including application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), microcontroller units (MCUs), hardware accelerators, dedicated computer chips, and the like.
[0109] At least one memory 123 may be used to store computer programs, etc. At least one memory 123 may include one or more volatile memory devices, one or more non-volatile memory devices, and / or a combination of one or more volatile memory devices and non-volatile memory devices. For example, at least one memory 123 may be embodied as a magnetic storage device (such as a hard disk drive, etc.), an optical magnetic storage device, and a semiconductor memory (such as a mask ROM, a programmable ROM (programmable ROM, PROM), an erasable PROM (erasable PROM, EPROM), a flash ROM, a random access memory (random access memory, RAM), etc.).
[0110] The processor 122 is used to obtain a unique device identifier and a startup key (such as a passphrase, a shared key, etc.) of a node device in a group of node devices 110A to 110F and a service set identifier (SSID) associated with the access point and based on a set membership test function value.
[0111] For example, the unique device identification and activation key of a node device in a group of node devices 110A to 110F and the SSID may be obtained by scanning a machine-readable code associated with a node device in a group of node devices 110A to 110F by a machine-readable code scanner 124. The machine-readable code may include a quick response (QR) code, a barcode, etc. The machine-readable code may be printed or otherwise set on the node device.
[0112] The processor 122 is further configured to verify whether the acquired unique device identifier is a member of the set represented by the set membership test function value. The set membership test function may include a Bloom filter, as described above in conjunction with Figure 1B Describe in detail.
[0113] For example, Figure 4D As shown in the schematic diagram 440 of FIG. 1 , the controller device 120 may scan the QR code of any node device among the node devices 110A to 110F. The QR code may include the unique identification of the node device itself, a pass phrase, etc., and Bloom filter parameters.
[0114] When the acquired unique device identifier is a member of the set represented by the set membership test function value, the processor 122 is further configured to establish an infrastructure mode connection for wireless communication with the access point via the transceiver 121 .
[0115] For example, Figure 4D As shown in schematic diagram 440 , if the node device scanned by the controller device 120 is a member of the Bloom filter value, the controller device 120 may identify the scanned node device and join a network with the Bloom filter value as the SSID.
[0116] After establishing the infrastructure mode, the processor 122 is further configured to authenticate a node device (e.g., the master node device 110A) in a group of node devices 110A to 110F using the acquired startup key. When the authentication is successful, the processor 122 is further configured to determine the node device that initiated the authentication. The processor 122 may also be configured to authenticate at least one node device (e.g., at least one slave node device 110B to 110F) using the corresponding operation credentials acquired from the master node device 110A, etc. Figure 1BAs described above, the master node device 110A can provide the slave node devices 110B to 110F with operation credentials including the public key in the asymmetric key pair. The controller device 120 can receive the same one or more public keys of the slave node devices 110B to 110F from the master node device 110A for use in authenticating the slave node devices 110B to 110F. In addition, at the end of the startup, the controller device 120 can issue a certificate for the public key. In addition to receiving the public key, the controller device 120 can also receive information (such as an IP address) on how to connect to the slave node devices 110B to 110F within the network (i.e., the SSID network operated by the master node device 110A).
[0117] When the authentication is successful, the processor 122 may also be configured to obtain ownership of at least one other authenticated node device and start the device.
[0118] For example, Figure 4D As shown in the schematic diagram 440, the controller device 120 can use the passphrase obtained above to authenticate itself to the master node device 110A. The node device scanned by the controller device 120 may or may not be the master node device 110A. The passphrase, etc. enables the controller device 120 to bind to the master node device 110A, and thus to bind to the slave devices 110B to 110F. For example, the master node 110A can rely on the scanned device to verify the passphrase, or the master node 110A has accessed the passphrase, etc. through other means to verify the passphrase. These other means may include, for example, the master node device 110A is able to scan the passphrase, etc., or the passphrase, etc. has been provided to the master node device 110A by the controller device 120 or the installer device 130. Optionally, the authentication mechanism can be based on PKI, in which case the master node device 110A only needs the root certificate or the certificate authority (CA) certificate of the device certificate of the slave node device. These root certificates and CA certificates can be considered to be explicitly trusted by the master node device 110A. The master node device 110A may verify the device certificate of the slave node device and then use a PKI mechanism to authenticate the slave node device.
[0119] When authenticating the master node device 110A, the controller device 120 can start the master node device 110A. Therefore, the controller device 120 can authenticate all node devices in the SSID network based on the previously exchanged operation credentials. Finally, the controller device 120 can obtain ownership of the node devices and configure the credentials required to join the user's private home network to these node devices. In other words, the master node device 110A can no longer be an access point, but can be connected to the user's private home network.
[0120] Figure 2is a flowchart of a method 200 provided by an embodiment.
[0121] In optional operation 201, a node device configured for wireless local area networking and included in a group of node devices for wireless local area networking may start broadcasting its own unique device identification, scanning other node devices and scanning an infrastructure mode wireless local area network.
[0122] The node device may obtain master node status allocation in operation 202. Optionally, the node device may obtain slave node status allocation in operation 210. The master node status allocation and the slave node status allocation are both used in the startup process of the group of node devices.
[0123] When the master node status allocation is obtained in operation 202, in optional operation 203, the master node device may stop broadcasting its own unique device identification, and stop scanning other node devices and the infrastructure mode wireless local area network.
[0124] In operation 204, the master node device calculates a set membership test function value according to its own unique device identifier and the unique device identifier of the slave node device.
[0125] In operation 205, the master node device broadcasts a first service set identifier associated with a first access point for wireless local area networking, so that the master node device serves as the first access point associated with the broadcasted first service set identifier. The first service set identifier is based on the calculated set membership test function value.
[0126] In optional operation 206, the master node device may exchange the unique device identification and operation credentials with at least one connected slave node device, thereby obtaining ownership of the connected slave node device for startup in optional operation 207. In addition, if the unique device identification of the connected slave node device is not among the unique device identifications used to calculate the membership function value in operation 204, the master node may reject the connection. If the unique device identification of the connected slave node device is among the unique device identifications used to calculate the membership function value in operation 204, the master node may accept the connection.
[0127] In optional operation 208, the master node device may perform authentication through the controller device.
[0128] In optional operation 209, the master node device may be started by the controller device.
[0129] When the slave node state allocation is acquired in operation 210, the slave node device may stop broadcasting its own unique device identification and stop scanning other node devices and the infrastructure mode wireless local area network in optional operation 211. The acquisition of the slave node state allocation includes determining that a second service set identification associated with a second access point for wireless local area networking is based on a set membership test function value, and further determining that the unique device identification of the slave node device is a member of a set represented by the set membership test function value.
[0130] In operation 212, the slave node device is connected to the second access point, so that the master node device of the second access point optionally obtains ownership of the slave node device.
[0131] In optional operation 213, the slave node device may perform authentication through the controller device.
[0132] In optional operation 214, the slave node device may perform startup via the controller device.
[0133] Method 200 may be performed by node devices 110A to 110F. Operations 201 to 214 may be performed by at least one processor 112A, a transceiver 111A, a memory 113A, etc. More features of method 200 are directly obtained from the functions and parameters of node devices 110A to 110F, and are not described here. Method 200 may be performed by a computer program.
[0134] Figure 3 is another flow chart of a method provided by an embodiment.
[0135] In operation 301, a controller device of a group of node devices for wireless local area networking obtains a unique device identifier and a startup key of a node device in the group of node devices and a service set identifier associated with an access point for wireless local area networking and based on a set membership test function value. The group of node devices includes a master node device, the master node device is assigned a master node state for a startup process of the group of node devices and serves as the access point. The group of node devices also includes at least one slave node device, the at least one slave node device is assigned a slave node state for the startup process.
[0136] In operation 302 , the controller device verifies whether the acquired unique device identification is a member of the set represented by the set membership test function value.
[0137] When the acquired unique device identifier is a member of the set represented by the set membership test function value, the controller device establishes an infrastructure mode connection for wireless communication with the access point in operation 303. Otherwise, the method may return to operation 301 or exit.
[0138] In operation 304, the controller device authenticates one of the node devices using the acquired startup key. Figure 3 In the example, the controller device performs authentication on the master node device.
[0139] When the authentication is successful, in operation 305, the controller device starts the master node device.
[0140] In optional operation 306, the controller device may perform authentication on one or more slave node devices using corresponding operation credentials obtained from the master node device.
[0141] When the authentication is successful, the controller device may determine to start the one or more slave node devices in optional operation 307 .
[0142] The method 300 may be performed by the controller device 120. Operations 301 to 307 may be performed by at least one processor 122, a transceiver 121, a memory 123, and a machine-readable code scanner 124, etc. More features of the method 300 are directly obtained from the functions and parameters of the controller device 120 and are not described here. The method 300 may be performed by a computer program.
[0143] The functions described herein may be performed at least in part by one or more computer program product components (e.g., software components). According to one embodiment, node devices 110A to 110F and controller device 120 include corresponding processors configured by the program code when executing the program code to perform the described operations and embodiments of the functions. Alternatively, or in addition, the functions described herein may be performed at least in part by one or more hardware logic components. For example, without limitation to this, exemplary types of hardware logic components that can be used include field programmable gate arrays (FPGA), program-specific integrated circuits (ASIC), program-specific standard products (ASSP), system-on-a-chip (SOC), complex programmable logic devices (CPLD) and graphics processing units (GPU).
[0144] Any range or device value given here may be extended or changed without losing the effect sought. Unless explicitly prohibited, any embodiment may also be combined with another embodiment.
[0145] Although the subject matter has been described in structural features and / or action-specific language, it should be understood that the subject matter defined in the claims is not necessarily limited to the specific features or actions described above. Instead, the specific characteristics and actions described above are disclosed as examples of implementing the claims, and other equivalent features and actions are intended to be included within the scope of the claims.
[0146] It should be understood that the advantages and benefits described above may relate to one embodiment, or may relate to multiple embodiments. The embodiments are not limited to solving any or all of the problems described, nor are they limited to embodiments having any or all of the advantages and benefits described. It should also be understood that reference to "an" item may refer to one or more of these items.
[0147] The steps of the methods described herein may be performed in any suitable order, or simultaneously when appropriate. In addition, individual boxes may be deleted from any of the methods without departing from the spirit and scope of the subject matter described herein. Aspects of any of the embodiments described above may be combined with aspects of any of the other embodiments described to form further embodiments without affecting the desired effect.
[0148] The term "comprising" as used herein is intended to include the relevant methods, blocks, or elements, but such blocks or elements do not include an exclusive list and the method or apparatus may include additional blocks or elements.
[0149] It should be understood that the above description is provided as an example only, and various modifications may be made by those skilled in the art. The above description, examples and data fully describe the structure and use of the exemplary embodiments. Although various embodiments are described above in relative detail or in conjunction with one or more separate embodiments, those skilled in the art may make various changes to the disclosed embodiments without departing from the scope of the present invention.
Claims
1. A node device (110A) for wireless local area networking, It is characterized in that The node device (110A) comprises: Processor (112A); Transceiver (111A), The node device (110A) is configured to be included in a group of node devices (110A to 110F) for wireless local area networking, and the processor (112A) is used to: Obtaining one of a master node state allocation or a slave node state allocation for a boot process of the group of node devices (110A to 110F); When obtaining the master node status assignment, Calculating a set membership test function value according to the unique device identification of the node device (110A) and the unique device identifications of other node devices (110B to 110F) in the group of node devices (110A to 110F); broadcasting, via the transceiver (111A), a first service set identifier associated with a first access point for wireless local area networking, wherein the first service set identifier is based on the calculated set membership test function value, so that the node device (110A) functions as the first access point associated with the broadcasted first service set identifier; When obtaining the slave node status assignment, Connecting to a second access point for wireless local area networking associated with a second service set identifier via the transceiver (111A); The processor (112A) is used to obtain the slave node state allocation by: determining that the second service set identifier is based on a set membership test function value, and further determining that the unique device identifier of the node device (110A) is a member within the set represented by the set membership test function value; Among them, the processor (112A) is used to obtain the master node status allocation, including: the processor (112A) is used to obtain the master node status allocation by receiving the master node selection instruction and the unique device identifier of the other node devices (110B to 110F) from the external device (130); when the master node device is selected by the external device (130), the master node device is used as an auxiliary controller device; the auxiliary controller is used to restore the started node device to factory settings when the controller device is changed.
2. The node device (110A) according to claim 1, It is characterized in that The processor (112A) is also used to: receive the unique device identifier of the other node devices (110B to 110F) when the unique device identifier is broadcast by the other node devices (110B to 110F); the processor (112A) is also used to obtain the master node status allocation by receiving a master node election indication from a general election protocol, wherein the general election protocol is periodically applied by the processor (112A) using the unique device identifier of the node device (110A) and the received unique device identifiers of the other node devices (110B to 110F).
3. The node device (110A) according to claim 2, It is characterized in that The universal election protocol includes one of a super-merger protocol or a yo-yo protocol.
4. The node device (110A) according to any one of claims 1 to 3, It is characterized in that When the master node status allocation is obtained and at least one of the other node devices (110B to 110F) establishes a secure connection with the node device (110A) used as the first access point, the processor (112A) is also used to exchange the unique device identification and operation credentials with at least one of the other node devices (110B to 110F) via the transceiver (111A), thereby obtaining ownership of at least one of the other node devices (110B to 110F) for startup.
5. The node device (110A) according to any one of claims 1 to 3, It is characterized in that When the master node status allocation is obtained and the node device (110A) is subsequently used as the first access point, the processor (112A) is also used to receive the unique device identification and startup key of at least one node device among the other node devices (110B to 110F) from a controller device (120) outside the group of node devices (110A to 110F) via the transceiver (111A), thereby obtaining ownership of the at least one node device among the other node devices (110B to 110F) for startup.
6. The node device (110A) according to claim 1, It is characterized in that The processor (112A) is further configured to: receive the second service set identifier when scanning an infrastructure mode wireless local area network.
7. The node device (110A) according to any one of claims 1 to 3 and 6, It is characterized in that The set membership testing function comprises a Bloom filter.
8. The node device (110A) according to claim 4, It is characterized in that The set membership testing function comprises a Bloom filter.
9. The node device (110A) according to claim 5, It is characterized in that The set membership testing function comprises a Bloom filter.
10. A wireless local area networking method (200), It is characterized in that The method (200) comprises: A node device for wireless local area networking configured to be included in a group of node devices for wireless local area networking obtains one of a master node state allocation (202) or a slave node state allocation (210) for a startup process of the group of node devices; When obtaining the master node status allocation (202), The node device calculates (204) a set membership test function value according to the unique device identifier of the node device and the unique device identifiers of other node devices in the group of node devices; The node device broadcasts (205) a first service set identifier associated with a first access point for wireless local area networking, wherein the first service set identifier is based on the calculated set membership test function value, so that the node device functions as the first access point associated with the broadcasted first service set identifier; When obtaining the slave node status assignment (210), The node device is connected (212) to a second access point for wireless local area networking associated with a second service set identifier; The obtaining of slave node status allocation (210) includes determining that the second service set identifier is based on a set membership test function value, and further determining that the unique device identifier of the node device is a member of the set represented by the set membership test function value; The obtaining of the master node status allocation for the startup process of the group of node devices (202) comprises: Receiving a master node selection instruction and the unique device identifier of the other node device, and acquiring the master node status allocation; The method further comprises: When the master node device is selected by the external device, the master node device serves as an auxiliary controller device; The auxiliary controller device is used to restore the factory settings of the started node device when the controller device is changed.
11. A computer program product comprising program code, It is characterized in that When the computer program product is executed on a computer, the program code is used to perform the method according to claim 10 .
12. A controller device (120) for a group of node devices (110A to 110F) for wireless local area networking, It is characterized in that The group of node devices (110A to 110F) includes a master node device (110A), the master node device (110A) is assigned a master node state for a startup process of the group of node devices (110A to 110F) and serves as an access point for wireless local area networking, the controller device (120) includes a transceiver (121) and a processor (122), wherein The processor (122) is used to: Acquire a unique device identifier and a startup key of a node device in the group of node devices (110A to 110F) and a service set identifier associated with the access point and based on a set membership test function value; Verifying whether the acquired unique device identifier is a member of the set represented by the set membership test function value; When the acquired unique device identifier is a member of the set represented by the set membership test function value, establishing an infrastructure mode connection for wireless communication with the access point via the transceiver (121); Authenticating the node device in the group of node devices (110A to 110F) by using the acquired startup key; When the authentication is successful, starting the authenticated node device; When the master node device (110A) is selected by an external device (130), the master node device (110A) serves as an auxiliary controller device; When the controller device (120) is changed, the auxiliary controller restores the started node device to factory settings.
13. The controller device (120) according to claim 12, It is characterized in that The group of node devices (110A to 110F) further includes at least one slave node device (110B to 110F), the at least one slave node device (110B to 110F) being assigned a slave node state for the startup process, and the processor (122) is further configured to: Authenticate at least one other node device using corresponding operation credentials; When the authentication is successful, the ownership of the at least one authenticated other node device is obtained and started.
14. The controller device (120) according to claim 12 or 13, It is characterized in that The controller device (120) also includes a machine-readable code scanner (124), and the unique device identifier, the startup key, and the service set identifier of the node device in the group of node devices (110A to 110F) are obtained by scanning the machine-readable code associated with the node device in the group of node devices (110A to 110F) by the machine-readable code scanner (124).
15. The controller device (120) according to claim 12 or 13, It is characterized in that The set membership test function comprises a Bloom filter.
16. The controller device (120) according to claim 14, It is characterized in that The set membership test function comprises a Bloom filter.
17. A wireless local area networking method (300), It is characterized in that The method (300) comprises: A controller device of a group of node devices for wireless local area networking obtains (301) a unique device identifier and a startup key of a node device in the group of node devices and a service set identifier associated with an access point for wireless local area networking and based on a set membership test function value, wherein the group of node devices includes a master node device, the master node device is assigned a master node state for a startup process of the group of node devices and serves as the access point; The controller device verifies (302) whether the acquired unique device identification is a member of the set represented by the set membership test function value; When the acquired unique device identifier is a member of the set represented by the set membership test function value, the controller device establishes (303) an infrastructure mode connection for wireless communication with the access point; The controller device performs (304) authentication on the node device in the group of node devices using the acquired startup key; When the authentication is successful, the controller device starts (305) the authenticated node device; When the master node device is selected by an external device, the master node device serves as an auxiliary controller device; When the controller device is changed, the auxiliary controller restores the started node device to factory settings.
18. A computer program product comprising program code, It is characterized in that When the computer program product is executed on a computer, the program code is used to perform the method according to claim 17.
Citation Information
Patent Citations
INTERNET OF THINGS (IoT) PLATFORM AND APPLICATION FRAMEWORK
US20170155703A1