Pairing methods and wireless devices for short-range communication systems

By sharing the initial password among wireless devices and using the PAKE protocol, the cumbersome pairing process for wireless devices is solved, enabling a fast and secure pairing process and improving the user experience.

CN115315968BActive Publication Date: 2026-04-03HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-04-24
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing wireless device pairing methods are cumbersome, requiring user input and operation, resulting in long pairing times and a poor user experience.

Method used

The Password Authentication Key Exchange (PAKE) protocol is adopted, and the first wireless device and the second wireless device are paired by sharing a first password, which reduces the number of information exchanges and uses the PAKE protocol to negotiate a more secure session key.

Benefits of technology

It enables rapid pairing of wireless devices, reduces user input and operations, improves user experience, and enhances the security and efficiency of the pairing process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115315968B_ABST
    Figure CN115315968B_ABST
Patent Text Reader

Abstract

This application discloses a pairing method and wireless device for short-range communication systems in the field of wireless communication. The method includes: a first wireless device acquiring a first password, wherein the first password is shared by the first wireless device and a second wireless device; the first wireless device pairing with the second wireless device based on a Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption cipher for the key exchange process. In this application embodiment, since the first wireless device and the second wireless device share the first password, the first wireless device can pair with the second wireless device based on the PAKE protocol and using the first password as the encryption cipher for the key exchange process; no user input or operation is required, which can reduce the time spent on pairing and improve the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of wireless communication, and more particularly to a pairing method and wireless device for use in short-range communication systems. Background Technology

[0002] With the advent of the Internet of Things (IoT) era, achieving secure and rapid wireless connectivity between devices has become an increasingly important issue. Currently, there are numerous wireless interconnection physical layer technologies for IoT, including Wireless Fidelity (WiFi), Zigbee, Near Field Communication (NFC), and Narrowband Internet of Things (NB-IoT). Taking Bluetooth technology as an example, from the user's perspective, on the one hand, impeccable security is required; on the other hand, users desire convenience.

[0003] Currently, common wireless device pairing methods, such as Bluetooth pairing, require user input and operation, which is cumbersome and results in a poor user experience. A mainstream Bluetooth pairing solution currently uses the Bluetooth Simple Pairing protocol. When using the Bluetooth Simple Pairing protocol, both devices need to confirm that the 6-digit random number displayed on the screen matches, and there are numerous exchanges of information. For increasingly demanding users, current popular pairing methods often require user input or operation and are time-consuming. Therefore, there is a need to research new wireless device pairing methods. Summary of the Invention

[0004] This application provides a pairing method and wireless device for short-range communication systems, which can shorten the time spent on pairing wireless devices and improve user experience.

[0005] In a first aspect, embodiments of this application provide a pairing method for a short-range communication system. The method includes: a first wireless device acquiring a first password, wherein the first password is shared by the first wireless device and a second wireless device; the first wireless device pairing with the second wireless device based on a Password Authentication Key Exchange (PAKE) protocol and using the first password as an encryption cipher for the key exchange process.

[0006] Both the first and second wireless devices are devices capable of short-range wireless communication. Both devices may store a first password or both may obtain the first password from the same private information. It should be understood that users typically only store private information, such as account information, passwords, biometric information, digital signatures, and digital certificates, on one or more devices they trust. Furthermore, only devices trusted by the user are allowed access to their private information. That is, only devices trusted by the user (i.e., trusted devices) can obtain and / or store the first password. The first and second wireless devices can be considered trusted devices of the same user. Since multiple trusted devices of the same user are all trusted, the method provided in this application embodiment can be executed to achieve pairing more quickly, i.e., achieve fast pairing. The method provided in this application embodiment is applicable to two or more devices that store or can obtain the same first password. For example, the first wireless device is a mobile phone, and the second wireless device is a tablet computer. Both devices store a first password obtained by encrypting the same private information using secure one-way encryption algorithms such as Message-Digest Algorithm (MD) and Secure Hash Algorithm (SHA). Since the first and second wireless devices store or can obtain the same first password, they can quickly complete the pairing process using this first password without requiring user input or operation. This reduces the time spent on pairing and improves the user experience. The Password-based Authenticated Key Exchange (PAKE) protocol uses a pre-shared password to negotiate a highly secure session key (also called a session key). Furthermore, when the PAKE protocol is applied to short-range communication systems where two or more wireless devices are paired, these devices can quickly negotiate a highly secure session key using a shared password, requiring fewer information exchanges.

[0007] In this embodiment, since the first wireless device and the second wireless device share the first password, the first wireless device can pair with the second wireless device based on the PAKE protocol and using the first password as the encryption password for the key exchange process; no user input or operation is required, which can reduce the time spent on pairing and improve the user experience.

[0008] In one possible implementation, the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information.

[0009] In this implementation, users can use different information as the first password, meaning that the specific form of the first password is not limited, which can meet the needs of different users.

[0010] In one possible implementation, the first wireless device, based on a Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process, pairs with the second wireless device. This pairing includes: the first wireless device sending first information to the second wireless device, the first information being information obtained by encrypting a first public key using the first password; the first information being used by the second wireless device to obtain a first session key based on the first public key; the first wireless device receiving second information in response to the first information from the second wireless device; the second information being information obtained by the second wireless device in response to the first information using the first session key; and the first wireless device pairing with the second wireless device using the first password and the second information. The first public key is a public key pre-stored or generated by the first wireless device.

[0011] Optionally, before sending the first information to the second wireless device, the first wireless device encrypts the first public key using a first password to obtain the first information. It should be understood that the second wireless device can decrypt the first information using the first password to obtain the first public key. Optionally, before sending the first information to the second wireless device, the first wireless device encrypts the first public key using the first password to obtain first intermediate information, and then compresses the first intermediate information to obtain the first information. That is, the first information is compressed, which reduces the time required for the first wireless device to send information to the second wireless device. By sending the first information to the second wireless device, the first wireless device enables the second wireless device to accurately obtain the first public key of the first wireless device, resulting in higher security. In this implementation, the first wireless device only needs to send the first information to the second wireless device to enable the second wireless device to obtain the first session key using the first information, reducing the number of information exchanges.

[0012] In this implementation, the first wireless device uses a first password as the encryption cipher for the key exchange process during the pairing process with the second wireless device, which provides high security and reduces the number of information exchanges.

[0013] In one possible implementation, pairing with the second wireless device using the first password and the second information includes: the first wireless device obtaining third information based on the first password and the second information; the third information being used by the second wireless device to obtain a first random number generated by the first wireless device; the first wireless device sending the third information to the second wireless device; the first wireless device receiving fourth information fed back by the second wireless device in response to the third information; the fourth information being used by the first wireless device to obtain a second random number fed back by the second wireless device in response to the first random number; and the first wireless device determining that pairing with the second wireless device is successful if the first random number and the second random number are the same.

[0014] The second random number can be understood as the first random number sent by the second wireless device from the first wireless device. It should be understood that if the second random number is the same as the first random number, it indicates that the second wireless device has received the third information sent by the first wireless device and correctly obtained the first random number generated by the first wireless device based on the third information. Therefore, when the second random number is the same as the first random number, the second wireless device passes authentication (i.e., passes identity verification). If the second random number is different from the first random number, it indicates that the second wireless device has not received the third information sent by the first wireless device, or that the second wireless device failed to obtain the first random number generated by the first wireless device from the received third information. It should be understood that when the second random number is different from the first random number, the second wireless device fails authentication (fails identity verification), thus determining that pairing with the second wireless device has failed.

[0015] In this implementation, by comparing the second random number and the first random number, the success or failure of pairing with the second wireless device can be quickly and accurately determined, and the pairing process can be terminated in a timely manner through the second wireless device.

[0016] In one possible implementation, the first wireless device obtains the third information based on the first password and the second information by: processing the second information using the first password to obtain a second public key; obtaining a second session key using the second public key and the first private key; and encrypting the first random number using the second session key to obtain the third information.

[0017] In this implementation, the second public key can be obtained quickly by processing the second information using the first password, resulting in high security.

[0018] In one possible implementation, the first wireless device processes the second information using the first password to obtain the second public key, including: the first wireless device processes the second information using the first password to obtain the second public key and a third random number; the third random number corresponds to a fourth random number generated by the second wireless device; the first wireless device encrypts the first random number using the second session key to obtain the third information, including: the first wireless device processes the first random number and the third random number using the second session key to obtain the third information; the third random number is used by the second wireless device to determine whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

[0019] Optionally, the first wireless device decrypts the second information using the first password to obtain the second public key and the third random number. Optionally, the first wireless device first decompresses the second information to obtain second intermediate information, and then decrypts the second intermediate information using the first password to obtain the second public key and the third random number.

[0020] In this implementation, a second message is sent to the second wireless device, enabling the second wireless device to obtain a third random number, so that the second wireless device can promptly determine whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

[0021] In one possible implementation, before the first wireless device sends the first information to the second wireless device, the method further includes: the first wireless device sending a feature exchange confirmation message to the second wireless device, the feature exchange confirmation message including a first encryption algorithm; the first wireless device using the first password as an encryption cipher and employing the first encryption algorithm to encrypt the first public key to obtain the first information.

[0022] The feature exchange confirmation information may include at least one parameter for pairing between the first wireless device and the second wireless device, such as an encryption algorithm, decryption algorithm, compression algorithm, etc. The first wireless device can negotiate the pairing parameters with the second wireless device to execute the pairing process using the negotiated parameters. In practical applications, the capabilities of the first and second wireless devices may differ (e.g., they may support different types of encryption algorithms), therefore, the first and second wireless devices need to negotiate the pairing parameters to ensure successful information exchange between the two devices.

[0023] In this implementation, the first wireless device sends a feature exchange confirmation message to the second wireless device so that they can successfully exchange information, enabling pairing between wireless devices with different capabilities.

[0024] In one possible implementation, before the first wireless device sends feature exchange confirmation information to the second wireless device, the method further includes: the first wireless device sending a feature exchange request to the second wireless device; the first wireless device receiving feature exchange response information from the second wireless device in response to the feature exchange request; the feature exchange response information including at least one parameter used by the second wireless device when performing pairing operations; the first wireless device sending feature exchange confirmation information to the second wireless device includes: the first wireless device sending the feature exchange confirmation information to the second wireless device in response to the feature exchange response information.

[0025] In this implementation, the first wireless device can quickly confirm the parameters used when pairing with the second wireless device, with minimal information exchange.

[0026] In one possible implementation, the feature exchange confirmation information further includes a second encryption algorithm; before the first wireless device uses the first password as an encryption cipher to encrypt the first public key using the first encryption algorithm to obtain the first information, the method further includes: the first wireless device uses the second encryption algorithm to perform one-way encryption on the private information to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

[0027] In this implementation, the first wireless device can use a second encryption algorithm negotiated with the second wireless device to unidirectionally encrypt private information to obtain a first password; it is simple to implement and highly secure.

[0028] In one possible implementation, the feature exchange confirmation information further includes a first compression algorithm; the first wireless device uses the first password as an encryption cipher to encrypt the first public key using the first encryption algorithm to obtain the first information, including: the first wireless device uses the first password to encrypt the first public key using the first encryption algorithm to obtain first intermediate information; the first wireless device uses the first compression algorithm to compress the first intermediate information to obtain the first information.

[0029] In this implementation, the first wireless device compresses the information to be sent to the second wireless device before sending it to the second wireless device, which can reduce the number of information transmissions and improve pairing efficiency.

[0030] In one possible implementation, the first wireless device processes the first random number and the third random number using the second session key to obtain the third information, including: the first wireless device encrypts the first random number and the third random number using the second session key to obtain third intermediate information; the first wireless device compresses the third intermediate information to obtain the third information.

[0031] In this implementation, the first wireless device compresses the information to be sent to the second wireless device before sending it to the second wireless device, which can reduce the number of information transmissions and improve pairing efficiency.

[0032] In one possible implementation, before the first wireless device determines that it has successfully paired with the second wireless device when the first random number is the same as the second random number, the method further includes: the first wireless device decompressing the fourth information to obtain fourth intermediate information; and the first wireless device decrypting the fourth intermediate information using the session key to obtain the second random number.

[0033] In this implementation, the first wireless device decompresses the information to be sent to the second wireless device before sending it to the second wireless device, which can reduce the number of information transmissions and improve pairing efficiency.

[0034] Secondly, embodiments of this application provide another wireless device pairing method for short-range communication systems. The method includes: a second wireless device acquiring a first password, wherein the first password is shared by the second wireless device and the first wireless device; the second wireless device pairing with the first wireless device based on a Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process. The second wireless device can be a pairing receiver.

[0035] In this embodiment, since the second wireless device and the first wireless device share the first password, the second wireless device can pair with the first wireless device based on the PAKE protocol and using the first password as the encryption password for the key exchange process; no user input or operation is required, which can reduce the time spent on pairing and improve the user experience.

[0036] In one possible implementation, the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information.

[0037] In this implementation, users can use different information as the first password, meaning that the specific form of the first password is not limited, which can meet the needs of different users.

[0038] In one possible implementation, the second wireless device is paired with the first wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process. The pairing process includes: the second wireless device receiving first information from the first wireless device; the second wireless device processing the first information using the first password to obtain a first session key; and the second wireless device pairing with the first wireless device using the first password and the first session key.

[0039] In this implementation, during the pairing process between the second wireless device and the first wireless device, the second wireless device can quickly obtain the first session key by using the first password to process the first information, which has high security and fewer information exchanges.

[0040] In one possible implementation, pairing the second wireless device with the first wireless device using the first password and the first session key includes: the second wireless device encrypting a fourth random number generated by the second wireless device using the first session key to obtain a first encrypted random number; the second wireless device encrypting the first encrypted random number using the first password as an encryption password to obtain second information; the second wireless device sending the second information to the first wireless device; the second wireless device receiving third information fed back by the first wireless device in response to the second information; and the second wireless device pairing with the first wireless device using the first session key and the third information.

[0041] In this implementation, the fourth random number generated by the second wireless device is first encrypted using the first session key to obtain the first encrypted random number; then the first password is used as the encryption key to encrypt the first encrypted random number to obtain the second information; this method offers high security.

[0042] In one possible implementation, the second wireless device uses the first password as an encryption cipher to encrypt the first encrypted random number to obtain the second information, which includes: the second wireless device using the first password as an encryption cipher to encrypt the first encrypted random number and the second public key to obtain the second information; the second public key is used by the first wireless device to obtain the second session key; the second session key is the information required by the first wireless device to respond to the second information.

[0043] In one possible implementation, pairing the second wireless device with the first wireless device using the first session key and the third information includes: the second wireless device processing the third information using the first session key to obtain a third random number; the third random number being a random number fed back by the first wireless device in response to the fourth random number; and the second wireless device determining, based on the third random number and the fourth random number, whether to end the pairing process with the first wireless device or to continue the pairing process with the first wireless device.

[0044] In this implementation, by comparing the third and fourth random numbers, it is possible to quickly and accurately determine whether pairing with the first wireless device has succeeded or failed.

[0045] In one possible implementation, before the second wireless device processes the first information using the first password to obtain the first session key, the method further includes: the second wireless device receiving feature exchange confirmation information from the first wireless device, the feature exchange confirmation information including a first decryption algorithm; the second wireless device processing the first information using the first password to obtain the first session key includes: the second wireless device using the first password and the first decryption algorithm to decrypt the first information to obtain a first public key; the first wireless device obtaining the first session key based on the first public key and a second private key.

[0046] In this implementation, the second wireless device receives a feature exchange confirmation message sent by the first wireless device so that it can successfully exchange information with the first wireless device, enabling pairing between wireless devices with different capabilities.

[0047] In one possible implementation, before the second wireless device receives feature exchange confirmation information from the first wireless device, the method further includes: the second wireless device receiving a feature exchange request from the first wireless device; the second wireless device, in response to the feature exchange request, sending feature exchange response information to the first wireless device; the feature exchange response information includes at least one parameter used by the second wireless device when performing pairing operations; the feature exchange confirmation information is information fed back by the first wireless device in response to the feature exchange response information.

[0048] In this implementation, the first wireless device can quickly confirm the parameters used when pairing with the second wireless device, with minimal information exchange.

[0049] In one possible implementation, the feature exchange confirmation information further includes a second encryption algorithm; before the second wireless device is paired with the first wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption cipher for the key exchange process, the method further includes: the second wireless device using the second encryption algorithm to unidirectionally encrypt the private information to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

[0050] In this implementation, the first wireless device can use a second encryption algorithm negotiated with the second wireless device to unidirectionally encrypt private information to obtain a first password; it is simple to implement and highly secure.

[0051] In one possible implementation, the feature exchange confirmation information further includes a first decompression algorithm; the second wireless device processes the first information using the first password to obtain the first session key, including: the second wireless device decompresses the first information using the first decompression algorithm to obtain first intermediate information; the second wireless device processes the first intermediate information using the first password to obtain the first session key.

[0052] In one possible implementation, the second wireless device processes the third information using the first session key to obtain a third random number by: the second wireless device decompressing the third information to obtain third intermediate information; and the second wireless device decrypting the third information using the first session key to obtain a third random number.

[0053] In this implementation, compressed information is transmitted between the first wireless device and the second wireless device, which can reduce the number of information transmissions and improve pairing efficiency.

[0054] In one possible implementation, the second wireless device determining whether to end or continue the pairing process with the first wireless device based on the third random number and the fourth random number includes: if the second wireless device determines to end the pairing process with the first wireless device when the third random number and the third random number are different; if the second wireless device sends fourth information in response to the third information to the first wireless device when the third random number and the third random number are the same; the fourth information is used by the first wireless device to determine whether the pairing with the second wireless device is successful or failed.

[0055] Optionally, the fourth information is information obtained by the second wireless device encrypting a second random number using the first session key, where the second random number is a random number fed back by the second wireless device in response to a first random number from the first wireless device. For example, the second wireless device processes the third information to obtain the first random number generated by the first wireless device.

[0056] In this implementation, by comparing the third and fourth random numbers, it is possible to quickly and accurately determine whether pairing with the first wireless device has succeeded or failed.

[0057] Thirdly, embodiments of this application provide a wireless device, including: a processing module, configured to acquire a first password, wherein the first password is shared by a first wireless device and a second wireless device; the processing module is further configured to pair with the second wireless device based on a Password Authentication Key Exchange (PAKE) protocol and using the first password as an encryption cipher for the key exchange process; and a transceiver module, configured to perform transceiver operations during the pairing process with the second wireless device under the control of the processing module.

[0058] In one possible implementation, the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information.

[0059] In one possible implementation, the transceiver module is configured to send first information to a second wireless device, wherein the first information is information obtained by the first wireless device encrypting a first public key using a first password; the first information is used by the second wireless device to obtain a first session key based on the first public key; receive second information fed back by the second wireless device in response to the first information; the second information is information obtained by the second wireless device in response to the first information using the first session key; and the processing module is specifically configured to pair with the second wireless device using the first password and the second information.

[0060] In one possible implementation, the processing module is specifically configured to obtain third information based on the first password and the second information; the third information is used by the second wireless device to obtain a first random number generated by the first wireless device; the transceiver module is further configured to send the third information to the second wireless device under the control of the processing module; receive fourth information fed back by the second wireless device in response to the third information; the fourth information is used by the first wireless device to obtain a second random number fed back by the second wireless device in response to the first random number; the processing module is specifically configured to determine that pairing with the second wireless device is successful when the first random number and the second random number are the same.

[0061] In one possible implementation, the processing module is specifically used to process the second information using the first password to obtain a second public key; to obtain a second session key based on the second public key and the first private key; and to encrypt the first random number using the second session key to obtain the third information.

[0062] In one possible implementation, the processing module is specifically used to process the second information using the first password to obtain the second public key and a third random number; the third random number corresponds to a fourth random number generated by the second wireless device; the first random number and the third random number are processed using the second session key to obtain the third information; the third random number is used by the second wireless device to determine whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

[0063] In one possible implementation, the transceiver module is further configured to send feature exchange confirmation information to the second wireless device, the feature exchange confirmation information including a first encryption algorithm; the processing module is further configured to use the first password as an encryption cipher and encrypt the first public key using the first encryption algorithm to obtain the first information.

[0064] In one possible implementation, the feature exchange confirmation information further includes a second encryption algorithm; the processing module is further configured to use the second encryption algorithm to perform one-way encryption on the private information by the first wireless device to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

[0065] For information on the technical effects of the third aspect or various implementation methods, please refer to the introduction of the technical effects of the first aspect or corresponding implementation methods.

[0066] Fourthly, embodiments of this application provide a wireless device, including: a processing module, configured to acquire a first password, wherein the first password is shared by a second wireless device and a first wireless device; the processing module is further configured to pair with the first wireless device based on a Password Authentication Key Exchange (PAKE) protocol and using the first password as an encryption cipher for the key exchange process; and a transceiver module, configured to perform transceiver operations during the pairing process with the first wireless device under the control of the processing module.

[0067] In one possible implementation, the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information.

[0068] In one possible implementation, the transceiver module is specifically used to receive first information from the first wireless device; the processing module is specifically used to process the first information using the first password to obtain a first session key; and to pair with the first wireless device using the first password and the first session key.

[0069] In one possible implementation, the processing module is specifically used to encrypt a fourth random number generated by the second wireless device using the first session key to obtain a first encrypted random number; and to encrypt the first encrypted random number using the first password as an encryption cipher to obtain second information; the transceiver module is specifically used to send the second information to the first wireless device; and to receive third information fed back by the first wireless device in response to the second information; the processing module is specifically used to pair with the first wireless device using the first session key and the third information.

[0070] In one possible implementation, the processing module is specifically used to encrypt the first encrypted random number and the second public key using the first password as an encryption cipher to obtain the second information; the second public key is used by the first wireless device to obtain the second session key; the second session key is the information required by the first wireless device to respond to the second information.

[0071] In one possible implementation, the processing module is specifically used to process the third information using the first session key to obtain a third random number; the third random number is a random number fed back by the first wireless device in response to the fourth random number; based on the third random number and the fourth random number, it determines whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

[0072] In one possible implementation, the transceiver module is further configured to receive feature exchange confirmation information from the first wireless device, the feature exchange confirmation information including a first decryption algorithm; the processing module is specifically configured to use the first password and the first decryption algorithm to decrypt the first information to obtain a first public key; and obtain the first session key based on the first public key and the second private key.

[0073] In one possible implementation, the feature exchange confirmation information further includes a second encryption algorithm; the processing module is further configured to use the second encryption algorithm to perform one-way encryption on the private information to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

[0074] For the technical effects of the fourth aspect or various implementation methods, please refer to the introduction of the technical effects of the second aspect or corresponding implementation methods.

[0075] Fifthly, embodiments of this application provide another wireless device, including a processor and a memory interconnected, wherein the memory is used to store a computer program, the computer program including program instructions, and the processor is configured to invoke the program instructions to execute the method described in the first aspect.

[0076] In a sixth aspect, embodiments of this application provide another wireless device, including a processor and a memory interconnected, wherein the memory is used to store a computer program, the computer program including program instructions, and the processor is configured to invoke the program instructions to execute the method described in the second aspect.

[0077] In a seventh aspect, embodiments of this application provide a computer-readable storage medium storing a computer program, the computer program including program instructions that, when executed by a processor, cause the processor to perform the method described in the first aspect.

[0078] Eighthly, embodiments of this application provide a computer-readable storage medium storing a computer program, the computer program including program instructions that, when executed by a processor, cause the processor to perform the method described in the second aspect.

[0079] Ninthly, embodiments of this application provide a short-range communication system, which includes the wireless device described in the first aspect and any optional implementation thereof, and the network device described in the second aspect and any optional implementation thereof.

[0080] In a tenth aspect, a chip is provided, the chip including a processor and a communication interface, the processor being coupled to the communication interface for implementing the method provided in the first aspect or any of the optional implementations described above.

[0081] Eleventhly, a chip is provided, the chip including a processor and a communication interface, the processor being coupled to the communication interface for implementing the method provided in the second aspect or any alternative implementation thereof.

[0082] In a twelfth aspect, embodiments of this application provide a computer program product including program instructions that, when executed by a processor, cause the processor to perform the method described in the first aspect and any optional implementation thereof.

[0083] In a thirteenth aspect, embodiments of this application provide a computer program product including program instructions that, when executed by a processor, cause the processor to perform the method described in the second aspect and any optional implementation thereof. Attached Figure Description

[0084] Figure 1 A flowchart illustrating a pairing method for a short-range communication system provided in this application embodiment;

[0085] Figure 2 A feature exchange flowchart is provided for an embodiment of this application;

[0086] Figures 3A to 3C A flowchart illustrating another pairing method for a short-range communication system provided in this application embodiment;

[0087] Figure 4 This application provides a schematic diagram of a user's trusted device list as an embodiment;

[0088] Figure 5 A schematic diagram illustrating the generation of a password from private information, provided as an embodiment of this application;

[0089] Figure 6 A schematic diagram illustrating the generation of an encryption key for data encryption using private data, provided as an embodiment of this application;

[0090] Figure 7 This is a schematic diagram of the structure of a wireless device provided in an embodiment of this application;

[0091] Figure 8 This is a schematic diagram of the structure of another wireless device provided in an embodiment of this application;

[0092] Figure 9 This is a schematic diagram of the structure of another wireless device provided in an embodiment of this application. Detailed Implementation

[0093] As described in the background section, current pairing methods commonly used in short-range communication systems, such as Bluetooth pairing, require multiple information exchanges to achieve pairing and connection, resulting in a long pairing and connection time. This leads to a poor user experience for increasingly demanding users. Taking traditional Bluetooth simple pairing as an example, from the moment two wireless devices discover each other to the completion of pairing, numerous message exchanges and even user operations are required, including a public key exchange process. In this process, both parties exchange public keys, which are 48 or 64 bytes long. This one-way transmission of the public key requires 3 or 4 messages to complete (the Bluetooth standard control packet can only transmit a maximum of 16 bytes of valid data). Considering that the other end also needs to transmit its public key back to the local end, also requiring 3 or 4 messages, the pairing process generally requires at least 6 (or 8) message transmissions. Assuming a message transmission time of 50 milliseconds, this amounts to approximately 300 or 400 milliseconds, a considerable amount of time that significantly impacts the user experience. Currently, common number comparison pairing methods require five air interface message exchanges, and both users need to click to confirm the prompted numbers. Assuming each message exchange takes 50 milliseconds, five air interface message exchanges would consume 250 milliseconds, not including user actions and message transmission / reception latency. Passkey entry pairing also suffers from the drawbacks of long air interface message exchange times and the need for user action. In other words, current pairing methods used in short-range communication systems all suffer from cumbersome processes and long pairing times. Therefore, there is a need to research pairing methods with shorter pairing times, i.e., quick pairing methods.

[0094] Research on various pairing processes currently employed reveals that a major reason for the long pairing time between two wireless devices is the large number of message exchanges and the lengthy message transmission time. The large number of message exchanges is due to the need for multiple message exchanges during the pairing process to verify the other device's trustworthiness, ensuring security. This application provides a pairing method applicable to two or more trusted devices, enabling rapid pairing between them—a fast pairing method. In this application, two or more trusted devices refer to wireless devices that store one or more identical private information and / or a first password. The main principle of the pairing method for short-range communication systems provided in this application is to achieve rapid pairing through a shared first password among multiple wireless devices, reducing the message exchange operations required to verify the other device's trustworthiness. The pairing method for short-range communication systems provided in this application is applicable to short-range communication scenarios where two or more devices share the same first password. A short-range communication system can be a system including two or more Bluetooth devices (e.g., mobile phones); a system including a wireless hotspot and terminal devices (e.g., mobile phones, tablets); or other communication systems. The following describes a short-range communication scenario where two or more devices share the same first password.

[0095] In short-range communication scenarios where two or more devices share the same first password: each wireless device stores or has access to the first password. For example, each wireless device generates a first password (hereinafter referred to as a passcode) by performing one-way encryption on private information, and uses this first password to encrypt and transmit air interface messages, thereby protecting the secure transmission of encrypted information. Additionally, the PAKE protocol is used to mutually authenticate each other by using random numbers generated by the other party, ensuring the authenticity and trustworthiness of both communicating parties, thus achieving pairing. Optionally, longer messages such as public keys and random numbers in the air interface messages are transmitted using lossless encryption to save air interface message transmission time and improve pairing speed. The following describes the pairing method for short-range communication systems provided in the embodiments of the application.

[0096] Figure 1 This is a flowchart illustrating a pairing method for a short-range communication system, as provided in an embodiment of this application. Figure 1 As shown, the method includes:

[0097] 101. The first wireless device and the second wireless device exchange features.

[0098] The main purpose of step 101 is for both devices (i.e., the first wireless device and the second wireless device) to notify each other of the other device's capabilities, and for the pairing initiator (i.e., the first wireless device) to ultimately confirm the parameters used during pairing, such as supported encryption algorithms and supported lossless compression algorithms. The implementation of step 101 will be detailed later. The first wireless device can be the electronic device that initiates pairing, i.e., the pairing initiator; the second wireless device can be the electronic device that receives pairing, i.e., the pairing receiver. The first wireless device can be a mobile phone, wearable device (e.g., a wristband, watch, etc.), tablet computer, speaker, smart home appliance, etc.; the second wireless device may be the same as or different from the first wireless device. For example, the first wireless device may be a mobile phone, and the second wireless device may be a smart wristband. Another example is that both the first and second wireless devices may be mobile phones.

[0099] 102. The first wireless device obtains the first password.

[0100] The aforementioned first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information. The first password is shared by the first wireless device and the second wireless device. The first wireless device can obtain the first password by acquiring a pre-stored first password (i.e., a password); by processing private information using an encryption algorithm to obtain the first password; by obtaining the first password from another device (e.g., a server) via a network; or by obtaining the first password through other means, which are not limited in this application. For example, the first and second wireless devices can use information under the same account system to perform a hash operation to generate the first password (e.g., a Huawei account (username and / or password), a Tencent account, which can be logged into on different devices). Another example is that the first and second wireless devices each collect biometric information from the same user and use this collected biometric information to generate the first password. Because biometric information is uniquely identifiable, the information collected by each device is the same; therefore, the first and second wireless devices can use their respective collected biometric information to generate the same password (i.e., the first password). In some embodiments, the first password is generated by the first wireless device using private information through one-way encryption, so as to facilitate the encrypted transmission of air interface messages using the first password. The second wireless device may also store or obtain the first password, which is generated by the second wireless device using private information through one-way encryption. That is, the first wireless device and the second wireless device can encrypt and / or decrypt the transmitted data using the first password during the pairing process.

[0101] 103. The first wireless device is paired with the second wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process.

[0102] In one embodiment, a possible implementation of step 103 is as follows: The first wireless device sends first information to the second wireless device, the first information being information obtained by the first wireless device encrypting the first public key using the first password; the first information is used by the second wireless device to obtain a first session key based on the first public key; the first wireless device receives second information from the second wireless device in response to the first information; the second information is information obtained by the second wireless device in response to the first information using the first session key; the first wireless device pairs with the second wireless device using the first password and the second information. During the pairing process between the first and second wireless devices, the parameters used (e.g., encryption algorithm, compression algorithm) are the parameters determined in step 101. A complete example of the process of step 103 will be described later with reference to the accompanying drawings.

[0103] In this embodiment, since the first wireless device and the second wireless device share the first password, the first wireless device can pair with the second wireless device based on the PAKE protocol and using the first password as the encryption password for the key exchange process; no user input or operation is required, which can reduce the time spent on pairing and improve the user experience.

[0104] The following describes the process of feature exchange between the first wireless device and the second wireless device, namely, one implementation of step 101.

[0105] Figure 2 This is a feature exchange flowchart provided for an embodiment of this application. Figure 2 This is one embodiment of step 101. For example... Figure 2 As shown, the feature exchange process includes:

[0106] 201. The first wireless device sends a feature exchange request to the second wireless device.

[0107] 202. The second wireless device responds to the above feature exchange request by sending feature exchange response information to the first wireless device.

[0108] The aforementioned feature exchange response information includes at least one parameter that the second wireless device can use when performing pairing operations. Optionally, if the second wireless device supports the fast pairing feature, it responds to the feature exchange request and sends feature exchange response information to the first wireless device; if it does not support fast pairing, it responds to the feature exchange request and sends a rejection message or a message type not supported message to the first wireless device. The rejection message or message type not supported message is used to indicate that the second wireless device does not support the fast pairing feature. The fast pairing feature refers to having or being able to obtain a first password and being able to perform... Figure 1 The pairing method in [the context].

[0109] 203. The first wireless device sends a feature exchange confirmation message.

[0110] The aforementioned feature exchange confirmation information is used to instruct the first wireless device and the second wireless device to match at least one parameter to be used.

[0111] For example, the parameters contained in each message in the feature exchange process are shown in Table 1:

[0112] Table 1

[0113]

[0114]

[0115] In the feature exchange process, the pairing initiator (i.e., the first wireless device) first initiates a feature exchange request; if the peer device (i.e., the second wireless device) supports the fast pairing feature, it responds with a feature exchange response message upon receiving the request; if it does not support it, it responds with a rejection message or a message type not supported message; after receiving the feature exchange response, the pairing initiator sends a feature exchange confirmation message to notify the subsequent fast pairing message parameters, i.e., at least one parameter to be used in the pairing.

[0116] In this embodiment of the application, the first wireless device and the second wireless device perform... Figure 2 The process allows for quick confirmation of at least one parameter to be used, with minimal signaling interaction.

[0117] The following describes one possible implementation of step 103 with reference to the accompanying drawings.

[0118] Figures 3A to 3C This is a flowchart illustrating a pairing method for a short-range communication system, as provided in an embodiment of this application. Figure 3A , Figure 3B as well as Figure 3C A flowchart illustrating a complete pairing method for short-range communication systems is provided. Figures 3A to 3C This is one embodiment of step 103. For example... Figures 3A to 3C As shown, the pairing process includes:

[0119] A1. The first wireless device generates a first public key PK1 and a first private key PV1.

[0120] The aforementioned first public key and the aforementioned first private key are matched. That is, the first wireless device generates a cryptographic pair. The public key and private key are a cryptographic pair (i.e., a public key and a private key) obtained through an algorithm. The public key is the publicly disclosed part of the cryptographic pair, and the private key is the non-public part. For example, the first public key PK1 and the first private key PV1 generated by the first wireless device satisfy the following formula:

[0121] y = g x modp (1);

[0122] Where y represents the public key (e.g., the first public key), x represents the private key (e.g., the first private key), g is the production rule, and p is a large prime number. Both the production rule g and the prime number p are public.

[0123] For example, 15 = 3 x Mod 17, then x = 6; where 15 is the public key, x = 6 is the private key, g is 3, and p is a prime number 17. It should be understood that the actual algorithm for generating the cipher pair is more complex; this is only a simple example to illustrate the principle of the algorithm. It should be understood that the first wireless device can use any algorithm to generate the first public key PK1 and the first private key PV1; this application embodiment does not limit this.

[0124] A2. The first wireless device encrypts the first public key using the first password to obtain the first ciphertext E(pk1).

[0125] In some embodiments, the first wireless device stores a first password. In some embodiments, the first password is generated using private information before performing step A2. In some embodiments, the first wireless device uses a first encryption algorithm to encrypt the first password as an encryption key with the first public key to obtain first ciphertext. The first encryption algorithm is an algorithm for encrypting the public key negotiated by the first and second wireless devices through feature exchange, i.e., the algorithm for encrypting the public key negotiated in step 101.

[0126] A3. The first wireless device compresses the first ciphertext (e.g., lossless compression) to obtain the first compressed text C(pk1), and sends the first compressed text to the second wireless device.

[0127] Optionally, A3 can be replaced with: the first wireless device sends the first ciphertext to the second wireless device. Figure 3AMessage M1 (corresponding to the first information) is either the first compressed text or the first ciphertext.

[0128] B1. The second wireless device generates a second public key PK2 and a second private key PV2.

[0129] The aforementioned second public key and the aforementioned second private key are matched. That is, the second wireless device generates a password pair. The order in which steps B1 and steps A1 to A3 are executed is not limited. That is, B1 has no order with steps A1, A2, and A3. The implementation method of step B1 can be the same as the implementation method of step A1. That is, the first wireless device and the second wireless device use the same algorithm to generate the password pair. For example, the first wireless device uses formula (1) to generate the first public key and the first private key, and the second wireless device uses formula (1) to generate the second public key and the second private key.

[0130] B2. The second wireless device receives the first compressed text, decompresses the first compressed text to obtain the first ciphertext, and decrypts the first ciphertext using the first password to obtain the first public key PK1.

[0131] In some embodiments, the second wireless device receives a first compressed text, decompresses the first compressed text to obtain a first ciphertext, and then decrypts the first ciphertext using a first password to obtain a first public key. In some embodiments, the second wireless device receives the first ciphertext and decrypts it using a first password to obtain a first public key. In some embodiments, the first wireless device stores a first password. In some embodiments, the first password is generated using private information before performing step B2.

[0132] B3. The second wireless device generates a random number R1 (corresponding to the fourth random number) and uses the first public key PK1 and the second private key PV2 to determine the first session key.

[0133] The random number R1 can be an integer randomly generated by the second wireless device, such as a 256-bit or 128-bit integer. For example, the formula for determining the first session key using the first public key PK1 and the second private key PV2 is as follows:

[0134] K1 = PK1^PV2 mod p (2);

[0135] Where PK1 represents the first public key, PV2 represents the second private key, and p is a publicly known large prime number (i.e., a known prime number). For example, if PK2 is 3, PV1 is 6, and p is 17, then K1 = PK2^PV1 mod 17 = 3 6 mod 17 = 15.

[0136] B4. The second wireless device encrypts the random number R1 using the first session key to obtain N1 (corresponding to the first encrypted random number), and encrypts the second public key PK2 and N1 using the first password to obtain E(PK2, N1).

[0137] B5. The second wireless device performs lossless compression on E(PK2, N1) to obtain compressed text C(PK2, N1); and sends the compressed text C(PK2, N1) to the first wireless device.

[0138] Lossless compression of E(PK2, N1) by the second wireless device is optional, not necessary. In some embodiments, the second wireless device sends E(PK2, N1) to the first wireless device instead of C(PK2, N1). Figure 3B The message M2 (corresponding to the second message) is either E(PK2, N1) or C(PK2, N1).

[0139] A4. The first wireless device decompresses the received C(PK2, N1) to obtain E(PK2, N1), and decrypts E(PK2, N1) using the first password to obtain the second public key PK2 and N1.

[0140] A5. The first wireless device determines the second session key using the second public key and the first private key.

[0141] For example, the first wireless device determines the second session key using the second public key and the first private key using the following formula:

[0142] K2 = PK2^PV1 mod p (3);

[0143] Where PK2 represents the second public key, PV1 represents the first private key, and p is a publicly known large prime number (i.e., a known prime number). In some embodiments, both the first wireless device and the second wireless device generate the cipher pair using the above formula (1). That is, PK1, PV1, and p satisfy PK1 = g PV1 mod p, PK2, PV2, and p satisfy PK2 = g PV2 mod p. Let PK2 = g PV2 Substituting mod p into formula (3), we get K2 = (g PV2 mod p)^PV1 mod p, PK1=g PV1 Substituting mod p into formula (2) above, we can obtain K1 = (g PV1 mod p)^PV2 mod p, since (g PV2 mod p)^PV1 mod p and (g PV1Since mod p)^PV2 mod p are equal, the session keys calculated using formulas (2) and (3) are the same. It can be understood that the first session key K1 determined by the second wireless device in step B3 using the first public key and the second private key PV2 is the same as the second session key K2 determined by the first wireless device in step A5 using the second public key and the first private key. That is, the first and second wireless devices can generate the same session key. It should be understood that formula (3) is an example for determining the second session key. The first wireless device can use the Diffie-Hellman key exchange algorithm or an asymmetric encryption algorithm such as ECDH to determine the second session key, or it can use other methods to determine the second session key; this application does not limit this.

[0144] A6. The first wireless device generates a random number R2 (corresponding to the first random number) and decrypts N1 using the first session key to obtain a random number R1' (corresponding to the second random number).

[0145] A7. The first wireless device encrypts random numbers R1' and R2 using the first session key to obtain E(C1, C2).

[0146] A8. The first wireless device performs lossless compression on E(C1, C2) and sends the compressed text C(C1, C2) to the second wireless device.

[0147] Lossless compression of E(C1, C2) by the first wireless device is optional, not necessary. Step A8 can be replaced by: the first wireless device sending E(C1, C2) to the second wireless device. Figure 3B The message M3 (corresponding to the third information) is either E(C1, C2) or C(C1, C2).

[0148] B6. The second wireless device decompresses the received message (corresponding to the third information) to obtain E(C1, C2), i.e., C1 and C2; and decrypts C1 using the first session key to obtain R1 (corresponding to the third random number).

[0149] B7. If R1” is not equal to R1, the second wireless device sends a first pairing failure message; if R1” is equal to R1, continue to execute step B8.

[0150] The aforementioned first pairing failure message is used to indicate that pairing between the first wireless device and the second wireless device has failed, or to indicate that the first wireless device terminates the pairing process with the second wireless device. Figure 3BMessage M4.1 in the message indicates a first pairing failure. It can be understood that "R1" not equal to R1 indicates that the first wireless device failed to decrypt and obtain R1, or that a data transmission error occurred between the first and second wireless devices. If the first wireless device failed to decrypt and obtain R1, resulting in "R1" not equal to R1, then the first wireless device is not a trusted device (i.e., it did not store or obtain the first password), and therefore the pairing process needs to be terminated. If a data transmission error occurred between the first and second wireless devices, resulting in "R1" not equal to R1, then the communication quality between the first and second wireless devices cannot be guaranteed, and pairing is unnecessary. By executing step B7, the second wireless device can quickly terminate the pairing process with the first wireless device, reducing unnecessary operations and saving power.

[0151] B8. The second wireless device decrypts C2 using the first session key to obtain R2' (corresponding to the second random number), and encrypts R2' using the first session key to obtain E(R2').

[0152] B9. The second wireless device performs lossless compression on E(R2') to obtain a second compressed text, and sends the second compressed text to the first wireless device. Figure 3C The message M4.2 (corresponding to the fourth message) is the second compressed text or E(R2').

[0153] A9. Upon receiving a first pairing failure message, the first wireless device terminates the pairing process with the second wireless device.

[0154] A10. The first wireless device decompresses the second compressed text to obtain E(R2'), and decrypts E(R2') using the second session key to obtain R2" (i.e., the second random number).

[0155] A11. If R2 is not equal to R2", the first wireless device sends a second pairing failure message and ends the pairing process; if R2 is equal to R2", it executes step A12.

[0156] Figure 3C Message M5.1 in the message indicates a second pairing failure.

[0157] A12. The first wireless device sends a pairing success message and uses private data to generate an encryption key for data encryption.

[0158] Figure 3C The message M5.2 in the message indicates a successful pairing.

[0159] B10. Upon receiving a second pairing failure message, the second wireless device terminates the pairing process with the first wireless device.

[0160] B11. Upon receiving a pairing success message, the second wireless device uses private data to generate an encryption key for data encryption.

[0161] The method for generating the encryption key for data encryption in steps B11 and A12 can be the same. It should be understood that the first wireless device and the second wireless device can use the same private data (e.g., R1, R2) and the same algorithm to generate the same key, i.e., the encryption key.

[0162] In the pairing process described above, asymmetric encryption algorithms can be used to exchange the public key, such as Diffie-Hellman key exchange or Elliptic-curve Diffie-Hellman (ECDH) algorithms. In practical applications, the choice of which key exchange algorithm to use for exchanging the public key can be determined by... Figure 2 The characteristic exchange process is determined. Random numbers R1 and R2 can be generated using a secure random number generation algorithm. Whether compressed transmission is used in the above pairing process is determined by... Figure 2 The characteristic exchange process is determined. Compressed transmission is only used if both trusted devices support the same compression algorithm. After the first and second wireless devices successfully pair, they share the session key K, random numbers R1 and R2, and the MAC (Media Access Control Address) addresses of both communicating parties. Both parties can generate encryption keys for data encryption based on these parameters. For various wireless specifications, the method of generating encryption keys should be kept as consistent as possible with the original standard, so that the pairing process can be independently integrated into the existing security architecture.

[0163] Figures 3A to 3C The pairing process can utilize the PAKE protocol. As long as both parties share a common private account, biometric information, or a primary password, seamless and rapid pairing of trusted devices is possible. It should be understood that... Figures 3A to 3C This is just one example of a pairing method. Other schemes that utilize a shared password between two devices to achieve quick pairing are also protected by this application, but they are not listed here.

[0164] In this embodiment, since the first wireless device and the second wireless device share the first password, both the first wireless device and the second wireless device are trusted devices to the user; therefore, the first wireless device and the second wireless device can execute... Figures 3A to 3CThe quick pairing process improves pairing speed. In this embodiment, sharing private information can mean that two or more people store the same private information or can obtain the same private information; in this embodiment, sharing the first password can mean that two or more people store the same password or can obtain the same password, for example, generating the same password.

[0165] It should be understood that since both the first and second wireless devices are trusted devices for the user, the pairing process provided in this application embodiment reduces the number of message interactions compared to the current pairing process, and further reduces message transmission time by compressing the transmitted messages, which can reduce the time spent on pairing and improve user experience.

[0166] The pairing method provided in this application is applicable to pairing between multiple trusted devices, i.e., two or more wireless devices sharing the same password. It should be understood that only devices trusted by the user will store one or more identical private information or passwords (e.g., PINs). In other words, for the user, two or more wireless devices sharing the same password are trusted and therefore can be quickly paired. Figure 4 This application provides a schematic diagram of a user's trusted device list as an embodiment. For example, Figure 4 All wireless devices in the system possess the same and valid password (i.e., passcode). In other words, user devices that share a consistent and valid password are considered trusted devices. In some embodiments, the password shared by trusted devices is not a "password" that requires user input in the conventional sense, but rather a password generated by one-way encryption (e.g., one-way hashing) of private information. Private information refers to biometric information (e.g., a user's fingerprint, iris scan, etc.), username and password, digital signature, digital certificate, etc. In some embodiments, a user's trusted devices are dynamic. When a device obtains a user's password through some means (wireless or wired transmission, reading from a memory card device, or one-way encryption of private information by the device), that device is considered a trusted device for that user. When a device cannot obtain the password or the password expires, the device is removed from the user's list of trusted devices. From the user's perspective, the user maintains a list of trusted devices, and any two devices in this list can execute the quick pairing process provided in this application embodiment.

[0167] In the aforementioned embodiments, the first wireless device and the second wireless device share the first password. That is, the first wireless device and the second wireless device jointly possess a consistent and valid password. The following section uses the first wireless device as an example to describe how to generate a password from private information.

[0168] Figure 5 This is a schematic diagram illustrating the generation of a password from private information, provided as an embodiment of this application. Figure 5 As shown, the first wireless device can use secure one-way encryption algorithms such as MD and SHA to generate a password using private information. In some embodiments, the two wireless devices communicate via... Figures 3A to 3C Before pairing, the devices can independently generate or obtain passwords (i.e., the first password). In some embodiments, the password shared by the trusted devices (corresponding to the first wireless device and the second wireless device) is obtained through... Figure 5 The password is generated in the manner described in the embodiments of this application. It should be understood that after two wireless devices generate or obtain the same password, they can quickly pair up using the pairing method provided in the embodiments of this application.

[0169] The following describes specific application scenarios to illustrate how a user's multiple trusted devices can be paired seamlessly and quickly.

[0170] Application Scenario 1: When a user first activates the quick pairing function of the first wireless device, the first wireless device displays a private information input interface. The user enters private information, and the first wireless device generates a first password using the received private information. When a user first activates the quick pairing function of the second wireless device, the second wireless device displays a private information input interface. The user enters the same private information, and the second wireless device generates a first password using the received private information. In other words, the user needs to enter the same private information into both devices that support quick pairing so that the devices can generate and save the same password. With the quick pairing function enabled on both the first and second wireless devices, the first and second wireless devices can... Figures 3A to 3C The quick pairing process in the software implements pairing. Personal information can include account details, biometric data, digital signatures, digital certificates, etc. In practical applications, when a user activates the quick pairing function of a wireless device, they need to enter personal information so that the wireless device can generate the password required for quick pairing.

[0171] Application Scenario 2: When a user first activates the quick pairing function of the first wireless device, the first wireless device displays a password input interface. The user enters a password (i.e., the initial password), and the first wireless device saves the entered password. When a user first activates the quick pairing function of the second wireless device, the second wireless device displays a password input interface. The user enters the same password (i.e., the initial password), and the second wireless device saves the entered password. In other words, the user needs to enter the same password for both devices that support quick pairing. When both the first and second wireless devices have their pairing functions enabled, the first and second wireless devices can... Figures 3A to 3CThe quick pairing method in the document implements pairing.

[0172] Users can also use other methods to ensure that devices supporting the quick pairing function obtain the same private information or password, thereby facilitating the pairing method provided in this application. In practical applications, users can set a device as a trusted device according to their needs, corresponding to adding the device to the trusted device list; or they can set a trusted device as an untrusted device, corresponding to deleting the device from the trusted device list. In practical applications, any two trusted devices can quickly complete pairing after activating the pairing function. That is, as long as both communicating parties possess shared private information or passwords, pairing can be achieved quickly. This pairing method is based on the PAKE protocol and can support lossless compression transmission of messages such as public keys transmitted over the air interface; the air interface message transmission time is greatly reduced, and the pairing has strong anti-interference capabilities.

[0173] The foregoing embodiments did not detail the implementation of generating encryption keys for data encryption using private data. The following, in conjunction with the accompanying drawings, provides an example of generating a cipher for data encryption.

[0174] Figure 6 This is a schematic diagram illustrating the generation of an encryption key for data encryption using private data, provided as an embodiment of this application. Figure 6 As shown, successfully paired wireless devices can use a data encryption key generation algorithm to generate an encryption key using the session key K, random numbers R1 and R2, and private data such as the MAC addresses of both partners. The session key K can be obtained by the wireless devices through an asymmetric key exchange algorithm, such as Diffie-Hellman key exchange, ECDH, or other key exchange algorithms.

[0175] After the first and second wireless devices successfully pair, they jointly possess private data such as the session key K, random number R1, random number R2, and the MAC (Media Access Control Address) addresses of both communicating parties. The first and second wireless devices can then generate encryption keys for data encryption based on these parameters. For various wireless standards, the method of generating data encryption keys should be kept as consistent as possible with the original standard, allowing the pairing process to be independently integrated into the existing security architecture.

[0176] The following description, using a structural diagram of the first wireless device, illustrates the functions implemented by each module in the first wireless device during the pairing process. Figure 7 This is a schematic diagram of the structure of a wireless device provided in an embodiment of this application. Figure 7 As shown, the wireless device includes:

[0177] Processing module 701 is used to obtain a first password, wherein the first password is shared by the first wireless device and the second wireless device;

[0178] The processing module 701 is also used to pair with the second wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption password for the key exchange process.

[0179] The transceiver module 702 is used to perform transceiver operations during the pairing process with the second wireless device under the control of the processing module.

[0180] In one possible implementation, the aforementioned first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information.

[0181] In one possible implementation, the transceiver module 702 is configured to send first information to a second wireless device, wherein the first information is information obtained by the first wireless device encrypting a first public key using the first password; the first information is used by the second wireless device to obtain a first session key based on the first public key; and to receive second information fed back by the second wireless device in response to the first information; wherein the second information is information obtained by the second wireless device in response to the first information using the first session key.

[0182] The processing module 701 is specifically used to pair with the second wireless device using the first password and the second information.

[0183] In one possible implementation, the processing module 701 is specifically used to obtain third information based on the first password and the second information; the third information is used by the second wireless device to obtain the first random number generated by the first wireless device.

[0184] The transceiver module 702 is further configured to send the third information to the second wireless device under the control of the processing module; receive the fourth information fed back by the second wireless device in response to the third information; the fourth information is used by the first wireless device to obtain the second random number fed back by the second wireless device in response to the first random number;

[0185] The processing module 701 is specifically used to determine that the pairing with the second wireless device is successful when the first random number and the second random number are the same.

[0186] In one possible implementation, the processing module 701 is specifically used to process the second information using the first password to obtain a second public key; to obtain a second session key based on the second public key and the first private key; and to encrypt the first random number using the second session key to obtain the third information.

[0187] In one possible implementation, the processing module 701 is specifically used to process the second information using the first password to obtain the second public key and the third random number; the third random number corresponds to the fourth random number generated by the second wireless device; the first random number and the third random number are processed using the second session key to obtain the third information; the third random number is used by the second wireless device to determine whether to end the pairing process with the first wireless device or to continue the pairing process with the first wireless device.

[0188] In one possible implementation, the transceiver module 702 is further configured to send feature exchange confirmation information to the second wireless device, the feature exchange confirmation information including a first encryption algorithm.

[0189] The processing module 701 is further configured to use the first password as an encryption key and the first encryption algorithm to encrypt the first public key to obtain the first information.

[0190] In one possible implementation, the aforementioned feature exchange confirmation information also includes a second encryption algorithm;

[0191] The processing module 701 is further configured to use the first wireless device to perform one-way encryption on the private information using the second encryption algorithm to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

[0192] It should be understood that Figure 7 The wireless device in this context can be the first wireless device in the aforementioned embodiments. The transceiver module 702 can implement the operation of the first wireless device sending and / or receiving messages, and the processing module 701 can implement operations other than sending and receiving messages, such as data encryption, data decryption, data compression, and data decompression. Exemplarily, the transceiver module 702 can include a sending module and a receiving module. The sending module and the receiving module can be different functional modules, or they can be the same functional module but capable of performing different functions. For example, the transceiver module can also be implemented using a transceiver, and the processing module can also be implemented using a processor. Alternatively, the sending module can be implemented using a transmitter, and the receiving module can be implemented using a receiver. The transmitter and the receiver can be different functional modules, or they can be the same functional module but capable of performing different functions.

[0193] The following description, using a structural diagram of the second wireless device, illustrates the functions of each module within the second wireless device during the pairing process. Figure 8 The diagram shows the structure of two wireless devices provided in the embodiments of this application. Figure 8 As shown, the wireless device includes:

[0194] Processing module 801 is used to obtain a first password, wherein the first password is shared by the second wireless device and the first wireless device;

[0195] The processing module 801 is also used to pair with the first wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process.

[0196] The transceiver module 802 is used to perform transceiver operations during the pairing process with the first wireless device under the control of the processing module.

[0197] In one possible implementation, the aforementioned first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information.

[0198] In one possible implementation, the transceiver module 802 is specifically used to receive first information from the aforementioned first wireless device;

[0199] The processing module 801 is specifically used to process the first information using the first password to obtain the first session key; and to pair with the first wireless device using the first password and the first session key.

[0200] In one possible implementation, the processing module 801 is specifically used to encrypt the fourth random number generated by the second wireless device using the first session key to obtain a first encrypted random number; and to encrypt the first encrypted random number using the first password as an encryption key to obtain second information.

[0201] The transceiver module 802 is specifically used to send the second information to the first wireless device and receive the third information fed back by the first wireless device in response to the second information.

[0202] The processing module 801 is specifically used to pair with the first wireless device using the first session key and the third information.

[0203] In one possible implementation, the processing module 801 is specifically used to encrypt the first encrypted random number and the second public key using the first password as an encryption key to obtain the second information; the second public key is used by the first wireless device to obtain the second session key; the second session key is the information required by the first wireless device to respond to the second information.

[0204] In one possible implementation, the processing module 801 is specifically used to process the third information using the first session key to obtain a third random number; the third random number is a random number fed back by the first wireless device in response to the fourth random number; based on the third random number and the fourth random number, it is determined whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

[0205] In one possible implementation, the transceiver module 802 is further configured to receive feature exchange confirmation information from the first wireless device, the feature exchange confirmation information including a first decryption algorithm.

[0206] The processing module 801 is specifically used to decrypt the first information using the first password and the first decryption algorithm to obtain the first public key; and to obtain the first session key based on the first public key and the second private key.

[0207] In one possible implementation, the aforementioned feature exchange confirmation information also includes a second encryption algorithm;

[0208] The processing module 801 is further configured to perform one-way encryption on the private information using the second encryption algorithm to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

[0209] Figure 8 The wireless device in this context can be the second wireless device in the aforementioned embodiments. The transceiver module 802 can implement the operation of the second wireless device sending and / or receiving messages, and the processing module 801 can implement operations of the second wireless device other than sending and receiving messages, such as data encryption, data decryption, data compression, and data decompression. The first wireless device is the pairing initiator, and the second wireless device is the pairing receiver. Exemplarily, the transceiver module 802 can include a sending module and a receiving module. The sending module and the receiving module can be different functional modules, or they can be the same functional module but capable of performing different functions. For example, the transceiver module can also be implemented using a transceiver, and the processing module can also be implemented using a processor. Alternatively, the sending module can be implemented using a transmitter, and the receiving module can be implemented using a receiver. The transmitter and the receiver can be different functional modules, or they can be the same functional module but capable of performing different functions.

[0210] In some embodiments, a wireless device may act solely as a pairing initiator, and the structure of that wireless device is similar to... Figure 7 The structures of wireless devices in the same way are identical; if a wireless device can act solely as a paired receiver, then the structure of that wireless device is the same as... Figure 8 The structure of the wireless devices in this application is the same. In some embodiments, a wireless device can act as both a pairing initiator and a pairing receiver. That is, a wireless device can perform the functions of both a first wireless device and a second wireless device. This application also provides another wireless device, whose structure is similar to... Figure 7 The wireless devices in the above are the same; the transceiver module 702 can also perform the functions of the transceiver module 802, and the processing module 701 can also perform the functions of the processing module 801. It should be understood that the wireless device can initiate a pairing process as a pairing initiator (corresponding to the first wireless device) or receive a pairing process initiated by a pairing initiator as a pairing receiver (corresponding to the second wireless device).

[0211] Figure 9 This is a schematic diagram of the structure of another wireless device provided in an embodiment of this application. Figure 9 As shown, the wireless device 90 includes a processor 901, a memory 902, and a communication interface 903; the processor 901, the memory 902, and the communication interface 903 are interconnected via a bus. Figure 9 The wireless device mentioned can be either the first wireless device or the second wireless device in the foregoing embodiments.

[0212] The memory 902 includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), or compact disc read-only memory (CDROM). This memory 902 is used for related instructions and data. The communication interface 903 is used for receiving and sending data. The communication interface 903 can implement... Figure 7 The functions of the transceiver module 702 can also be achieved. Figure 8 The functions of the transceiver module 802.

[0213] Processor 901 can be one or more central processing units (CPUs). If processor 901 is a CPU, it can be a single-core CPU or a multi-core CPU. Specifically, processor 901 can implement... Figure 7 The function of the processing module 701 can also be realized. Figure 8 The functions of the processing module 801.

[0214] The processor 901 in the wireless device 90 is used to read the program code stored in the memory 902 and execute the pairing method flow in the aforementioned embodiments. The wireless device 90 can read the program code stored in the memory 902 and execute the operations performed by the first wireless device and / or the second wireless device in the aforementioned embodiments to achieve pairing.

[0215] In the embodiments of this application, a computer-readable storage medium is provided, which stores a computer program that, when executed by a processor, implements the pairing method for short-range communication systems provided in the foregoing embodiments.

[0216] This application provides a computer program product containing instructions that, when run on a computer, cause the computer to execute the pairing method for short-range communication systems provided in the foregoing embodiments.

[0217] It should be understood that the processor mentioned in the embodiments of this application can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor.

[0218] It should also be understood that the memory mentioned in the embodiments of this application can be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static RAM (SRAM), Dynamic RAM (DRAM), Synchronous DRAM (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced Synchronous DRAM (ESDRAM), Synchlink DRAM (SLDRAM), and Direct Rambus RAM (DR RAM).

[0219] It should be noted that when the processor is a general-purpose processor, DSP, ASIC, FPGA, or other programmable logic device, discrete gate or transistor logic device, or discrete hardware component, the memory (storage module) is integrated into the processor.

[0220] It should be noted that the memories described herein are intended to include, but are not limited to, these and any other suitable types of memories.

[0221] It should also be understood that the first, second, third, fourth and various numerical designations used herein are merely for descriptive convenience and are not intended to limit the scope of this application.

[0222] It should be understood that the term "and / or" in this article is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this article generally indicates that the preceding and following related objects have an "or" relationship.

[0223] It should be understood that, in the various embodiments of this application, the sequence number of each process does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this invention.

[0224] Those skilled in the art will recognize that the modules and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0225] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and modules described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0226] In the embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules described above is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces, or indirect coupling or communication connection between apparatuses or modules, and may be electrical, mechanical, or other forms.

[0227] The modules described above as separate components may or may not be physically separate. Similarly, the components shown as modules may or may not be physical modules; they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0228] In addition, the functional modules in the various embodiments of this application can be integrated into one processing module, or each module can exist physically separately, or two or more modules can be integrated into one module.

[0229] If the aforementioned functions are implemented as software functional modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0230] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A pairing method for short-range communication systems, characterized in that, include: The first wireless device obtains a first password, wherein the first password is shared by the first wireless device and the second wireless device, and the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information; The first wireless device is paired with the second wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process. The method further includes: The first wireless device uses a second encryption algorithm to unidirectionally encrypt the private information to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

2. The method according to claim 1, characterized in that, The first wireless device, based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process, pairs with the second wireless device, including: The first wireless device sends first information to the second wireless device, the first information being information obtained by the first wireless device encrypting the first public key using the first password; the first information is used by the second wireless device to obtain the first session key based on the first public key; The first wireless device receives second information fed back by the second wireless device in response to the first information; the second information is information obtained by the second wireless device in response to the first information using the first session key. The first wireless device uses the first password and the second information to pair with the second wireless device.

3. The method according to claim 2, characterized in that, The pairing with the second wireless device using the first password and the second information includes: The first wireless device obtains third information based on the first password and the second information; the third information is used by the second wireless device to obtain a first random number generated by the first wireless device. The first wireless device sends the third information to the second wireless device; The first wireless device receives fourth information fed back by the second wireless device in response to the third information; the fourth information is used by the first wireless device to obtain a second random number fed back by the second wireless device in response to the first random number; If the first random number is the same as the second random number, the first wireless device determines that it has successfully paired with the second wireless device.

4. The method according to claim 3, characterized in that, The third information obtained by the first wireless device based on the first password and the second information includes: The first wireless device processes the second information using the first password to obtain the second public key; The first wireless device obtains a second session key based on the second public key and the first private key, wherein the first private key matches the first public key; The first wireless device uses the second session key to encrypt the first random number to obtain the third information.

5. The method according to claim 4, characterized in that, The first wireless device processes the second information using the first password to obtain the second public key, including: The first wireless device processes the second information using the first password to obtain the second public key and a third random number; the third random number corresponds to a fourth random number generated by the second wireless device. The first wireless device uses the second session key to encrypt the first random number to obtain the third information, which includes: The first wireless device uses the second session key to process the first random number and the third random number to obtain the third information; the third random number is used by the second wireless device to determine whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

6. The method according to any one of claims 2 to 5, characterized in that, Before the first wireless device sends the first information to the second wireless device, the method further includes: The first wireless device sends a feature exchange confirmation message to the second wireless device, the feature exchange confirmation message including a first encryption algorithm; The first wireless device uses the first password as an encryption key and the first encryption algorithm to encrypt the first public key to obtain the first information.

7. The method according to claim 6, characterized in that, The feature exchange confirmation information also includes the second encryption algorithm.

8. A wireless device pairing method for short-range communication systems, characterized in that, include: The second wireless device obtains the first password, wherein the first password is shared by the second wireless device and the first wireless device, and the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information; The second wireless device is paired with the first wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process. The method further includes: The second wireless device uses a second encryption algorithm to unidirectionally encrypt the private information to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

9. The method according to claim 8, characterized in that, The second wireless device, based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process, pairs with the first wireless device, including: The second wireless device receives first information from the first wireless device; The second wireless device uses the first password to process the first information and obtains the first session key; The second wireless device uses the first password and the first session key to pair with the first wireless device.

10. The method according to claim 9, characterized in that, The second wireless device pairs with the first wireless device using the first password and the first session key, including: The second wireless device uses the first session key to encrypt the fourth random number generated by the second wireless device to obtain the first encrypted random number; The second wireless device uses the first password as an encryption key to encrypt the first encrypted random number to obtain the second information; The second wireless device sends the second information to the first wireless device; The second wireless device receives third information fed back by the first wireless device in response to the second information; The second wireless device uses the first session key and the third information to pair with the first wireless device.

11. The method according to claim 10, characterized in that, The second wireless device uses the first password as the encryption key to encrypt the first encrypted random number, obtaining the second information including: The second wireless device uses the first password as an encryption key to encrypt the first encrypted random number and the second public key to obtain the second information; the second public key is used by the first wireless device to obtain the second session key; the second session key is the information required by the first wireless device to respond to the second information.

12. The method according to claim 10 or 11, characterized in that, The second wireless device, using the first session key and the third information, pairs with the first wireless device, including: The second wireless device processes the third information using the first session key to obtain a third random number; the third random number is a random number fed back by the first wireless device in response to the fourth random number; The second wireless device determines, based on the third and fourth random numbers, whether to end the pairing process with the first wireless device or to continue the pairing process with the first wireless device.

13. The method according to any one of claims 9 to 11, characterized in that, Before the second wireless device processes the first information using the first password to obtain the first session key, the method further includes: The second wireless device receives feature exchange confirmation information from the first wireless device, the feature exchange confirmation information including a first decryption algorithm; The second wireless device processes the first information using the first password to obtain the first session key, including: The second wireless device uses the first password and the first decryption algorithm to decrypt the first information to obtain the first public key; The first wireless device obtains the first session key based on the first public key and the second private key.

14. The method according to claim 13, characterized in that, The feature exchange confirmation information also includes the second encryption algorithm.

15. A wireless device, characterized in that, include: The processing module is used to obtain a first password, wherein the first password is shared by a first wireless device and a second wireless device, and the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information; The processing module is also used to pair with the second wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption cipher for the key exchange process. A transceiver module, under the control of the processing module, is used to perform transmit and receive operations during the pairing process with the second wireless device; The processing module is further configured to use a second encryption algorithm to perform one-way encryption on the private information to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

16. The wireless device according to claim 15, characterized in that, The transceiver module is configured to send first information to a second wireless device, wherein the first information is information obtained by the first wireless device encrypting a first public key using the first password; The first information is used by the second wireless device to obtain the first session key based on the first public key; Receive the second information fed back by the second wireless device in response to the first information; The second information is the response information obtained by the second wireless device using the first session key in response to the first information; The processing module is specifically used to pair with the second wireless device using the first password and the second information.

17. The wireless device according to claim 16, characterized in that, The processing module is specifically used to obtain third information based on the first password and the second information; the third information is used by the second wireless device to obtain the first random number generated by the first wireless device. The transceiver module is also used to send the third information to the second wireless device under the control of the processing module; The first wireless device receives fourth information in response to the third information; the fourth information is used by the first wireless device to obtain a second random number fed back by the second wireless device in response to the first random number. The processing module is specifically used to determine that pairing with the second wireless device is successful when the first random number is the same as the second random number.

18. The wireless device according to claim 17, characterized in that, The processing module is specifically used to process the second information using the first password to obtain a second public key; and to obtain a second session key based on the second public key and the first private key, wherein the first private key matches the first public key. The first random number is encrypted using the second session key to obtain the third information.

19. The wireless device according to claim 18, characterized in that, The processing module is specifically used to process the second information using the first password to obtain the second public key and the third random number; the third random number corresponds to the fourth random number generated by the second wireless device; and to process the first random number and the third random number using the second session key to obtain the third information. The third random number is used by the second wireless device to determine whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

20. The wireless device according to any one of claims 16 to 19, characterized in that, The transceiver module is further configured to send feature exchange confirmation information to the second wireless device, the feature exchange confirmation information including a first encryption algorithm; The processing module is further configured to use the first password as an encryption key and the first encryption algorithm to encrypt the first public key to obtain the first information.

21. The wireless device according to claim 20, characterized in that, The feature exchange confirmation information also includes the second encryption algorithm.

22. A wireless device, characterized in that, include: The processing module is used to obtain a first password, wherein the first password is shared by the second wireless device and the first wireless device, and the first password includes at least one of the following: account, password, digital signature, biometric information, digital certificate, and voice information; The processing module is also used to pair with the first wireless device based on the Password Authentication Key Exchange (PAKE) protocol and using the first password as the encryption key for the key exchange process. A transceiver module is used to perform transceiver operations during the pairing process with the first wireless device under the control of the processing module; The processing module is further configured to use a second encryption algorithm to perform one-way encryption on the private information to obtain the first password; the private information is shared by the first wireless device and the second wireless device.

23. The wireless device according to claim 22, characterized in that, The transceiver module is specifically used to receive first information from the first wireless device; The processing module is specifically used to process the first information using the first password to obtain the first session key; and to pair with the first wireless device using the first password and the first session key.

24. The wireless device according to claim 23, characterized in that, The processing module is specifically used to encrypt the fourth random number generated by the second wireless device using the first session key to obtain a first encrypted random number; and to encrypt the first encrypted random number using the first password as the encryption key to obtain second information. The transceiver module is specifically used to send the second information to the first wireless device and receive the third information fed back by the first wireless device in response to the second information. The processing module is specifically used to pair with the first wireless device using the first session key and the third information.

25. The wireless device according to claim 24, characterized in that, The processing module is specifically used to encrypt the first encrypted random number and the second public key using the first password as the encryption password to obtain the second information; the second public key is used by the first wireless device to obtain the second session key; the second session key is the information required by the first wireless device to respond to the second information.

26. The wireless device according to claim 24 or 25, characterized in that, The processing module is specifically used to process the third information using the first session key to obtain a third random number; the third random number is a random number fed back by the first wireless device in response to the fourth random number; based on the third random number and the fourth random number, it determines whether to end the pairing process with the first wireless device or continue the pairing process with the first wireless device.

27. The wireless device according to any one of claims 23 to 25, characterized in that, The transceiver module is further configured to receive feature exchange confirmation information from the first wireless device, the feature exchange confirmation information including a first decryption algorithm; The processing module is specifically used to decrypt the first information using the first password and the first decryption algorithm to obtain the first public key; and to obtain the first session key based on the first public key and the second private key.

28. The wireless device according to claim 27, characterized in that, The feature exchange confirmation information also includes the second encryption algorithm.

29. A short-range communication system, characterized in that, Includes the wireless device according to any one of claims 15 to 21, and the wireless device according to any one of claims 22 to 28.

30. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, the computer program including program instructions that, when executed by a processor of a wireless device, cause the processor to perform the method according to any one of claims 1 to 14.

Citation Information

Patent Citations

  • Methods and devices for computing a shared encryption key

    CN102170636A

  • Method for generating high-entropy shared password between intelligent devices in short-distance wireless environment

    CN110061830A