Access method and device for shared Wi-Fi bidirectional authentication using blockchain

Two-way authentication of terminals and access devices is solved through blockchain technology, and the problems of privacy security and access key leakage in shared WiFi access are achieved, uncentralized secure access is achieved, and the transformation cost is reduced.

CN115361684BActive Publication Date: 2025-08-29DIGITAL WORLD (SHENZHEN) TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211001190.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-19
Publication Date
2025-08-29
Estimated Expiration
2042-08-19

AI Technical Summary

Technical Problem

The existing shared WiFi access method has privacy and security problems, and it is impossible to achieve two-way authentication between the terminal and the access device, and it is impossible to effectively perform access authentication during roaming, resulting in high risk of access key leakage and high cost of transformation.

Method used

Blockchain technology is used to perform two-way authentication of terminals and access devices. By receiving and verifying signature information, using blockchain addresses for identity verification, realizing uncentralized authentication and access, reducing the risk of access key leakage, and reusing home and enterprise gateway equipment.

Benefits of technology

It realizes two-way authentication of terminals and access devices that are universal across the network, improves the security of shared WiFi, reduces the risk of access key leakage, and reduces the cost of transformation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115361684B_ABST
    Figure CN115361684B_ABST
Patent Text Reader

Abstract

The present disclosure provides a method and device for accessing shared Wi-Fi using blockchain-based bidirectional authentication, belonging to the field of blockchain technology. The method comprises: receiving a first access request from a terminal and sending a first response message to the terminal; receiving a second access request from the terminal and verifying the second access request based on the terminal's signature information; if the second access request passes the verification, sending a first query request to a preset address to authenticate the legitimacy of the terminal; and if the terminal is legitimate, sending an open access channel message to the terminal. According to the embodiments of the present disclosure, decentralized bidirectional authentication is achieved, enabling secure access to shared Wi-Fi.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of blockchain technology, and in particular to a method and device for accessing shared Wi-Fi with two-way authentication using blockchain. Background Art

[0002] WiFi (Wireless Fidelity) is a technology that wirelessly connects devices such as personal computers and handheld devices (such as PDAs and mobile phones). WiFi coverage is limited, so to maximize device access, researchers have developed shared WiFi technology.

[0003] Shared Wi-Fi technology uses a network of Wi-Fi access points (APs) belonging to different individuals or businesses to provide access to subscribed terminals (STAs). Because the APs in a shared Wi-Fi network belong to different individuals or businesses, STAs must authenticate the APs when accessing them, and the APs must authenticate the STAs themselves, improving network and privacy protection. Summary of the Invention

[0004] The present disclosure provides a shared Wi-Fi two-way authentication access method and device using blockchain.

[0005] In a first aspect, the present disclosure provides a shared WiFi access method, applied to an access device, comprising:

[0006] receiving a first access request from a terminal, and sending first return information to the terminal; wherein the first access request includes identity information of the terminal and corresponding signature information, and the first return information includes identity information of the access device and corresponding signature information;

[0007] receiving a second access request from the terminal, and verifying the second access request based on the signature information of the terminal; wherein the second access request is issued by the terminal when the first return information is verified successfully based on the signature information of the access device, and the second access request includes the identity information of the terminal and the corresponding signature information;

[0008] If the second access request passes the verification, sending a first query request to a preset address to authenticate the legitimacy of the terminal; wherein the first query request includes the identity information of the terminal;

[0009] In the case that the legitimacy authentication of the terminal is passed, an access channel message is opened to the terminal.

[0010] In a second aspect, the present disclosure provides a shared WiFi access method, applied to a terminal, comprising:

[0011] Sending a first access request to the access device; wherein the first access request includes the identity information of the terminal and corresponding signature information;

[0012] receiving first return information sent by the access device and verifying the first return information; wherein the first return information is sent by the access device when it receives the first access request, and the first return information includes the identity information of the access device and the corresponding signature information;

[0013] Sending a second access request to the access device; wherein the second access request includes the identity information of the terminal and corresponding signature information, so that the access device can authenticate the legitimacy of the terminal at a preset address based on the identity information of the terminal;

[0014] If the first returned information is verified to be successful, sending a second query request to a preset address to authenticate the legitimacy of the access device; wherein the second query request includes the identity information of the access device;

[0015] Receive an open access channel message sent by the access device; wherein the open access channel message is sent by the access device when it determines that the terminal is legitimate.

[0016] In a third aspect, the present disclosure provides a shared WiFi access device, which is applied to an access device, including:

[0017] A first receiving module is configured to receive a first access request from a terminal, wherein the first access request includes identity information of the terminal and corresponding signature information;

[0018] A first sending module is configured to send first return information to the terminal; wherein the first return information includes the identity information of the access device and the corresponding signature information;

[0019] The first receiving module is further configured to receive a second access request from the terminal, wherein the second access request is issued by the terminal when the second access request is verified based on the signature information of the access device, and the second access request includes the identity information of the terminal and the corresponding signature information;

[0020] a first verification module, configured to verify the second access request based on signature information of the terminal;

[0021] The first sending module is further configured to send a first query request to a preset address to authenticate the legitimacy of the terminal if the second access request passes the verification; wherein the first query request includes the identity information of the terminal;

[0022] The first sending module is further configured to send an open access channel message to the terminal if the terminal is legal.

[0023] In a fourth aspect, the present disclosure provides a shared WiFi access device, applied to a terminal, comprising:

[0024] A second sending module is configured to send a first access request to the access device; wherein the first access request includes the identity information of the terminal;

[0025] A second receiving module is configured to receive first return information sent by the access device; wherein the first return information is sent by the access device when receiving the first access request, and the first return information includes identity information of the access device and corresponding signature information;

[0026] A second verification module is configured to verify the first returned information;

[0027] The second sending module is further configured to send a second access request to the access device; wherein the second access request includes the identity information of the terminal and corresponding signature information, so that the access device can authenticate the legitimacy of the terminal at a preset address based on the identity information of the terminal;

[0028] The second sending module is further configured to send a second query request to a preset address to authenticate the legitimacy of the access device if the first return information verification passes; wherein the second query request includes the identity information of the access device and the corresponding signature information;

[0029] The second receiving module is configured to receive an open access channel message sent by the access device; wherein the access permission message is sent when the access device determines that the terminal is legal.

[0030] In a fifth aspect, the present disclosure provides an electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores one or more computer programs executable by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to execute the above-mentioned shared WiFi access method.

[0031] In a sixth aspect, the present disclosure provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the above-mentioned shared WiFi access method when executed by a processor / processing core.

[0032] In the embodiment provided by the present disclosure, after the access device receives the first access request from the terminal, it sends first return information to the terminal for the terminal to verify the first return information; after receiving the second access request from the terminal, it verifies the second access request, and if the verification passes, it sends a first query request to a preset address to authenticate the legitimacy of the terminal; after receiving the third access request from the terminal and if the legitimacy of the terminal passes, it sends an access permission message to the terminal, that is, the access device and the terminal perform two-way authentication at the preset address, realizing decentralized authentication and access, reducing the risk of access key leakage, and realizing secure access to shared WiFi. At the same time, existing home gateway devices and enterprise gateway devices can be reused, reducing the transformation cost of shared WiFi networks.

[0033] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] The accompanying drawings are used to provide a further understanding of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the present disclosure and do not constitute a limitation of the present disclosure. The above and other features and advantages will become more apparent to those skilled in the art by describing detailed example embodiments with reference to the accompanying drawings. In the accompanying drawings:

[0035] Figure 1 A flowchart of a shared WiFi access method provided in an embodiment of the present disclosure;

[0036] Figure 2 A flowchart of a shared WiFi access method provided in an embodiment of the present disclosure;

[0037] Figure 3 A block diagram of a shared WiFi access device provided in an embodiment of the present disclosure;

[0038] Figure 4 A block diagram of a shared WiFi access device provided by an embodiment of the present disclosure;

[0039] Figure 5 A flowchart of a shared WiFi access method provided in an embodiment of the present disclosure;

[0040] Figure 6A flowchart of another shared WiFi access method provided in an embodiment of the present disclosure;

[0041] Figure 7 This is a flow chart of another authentication method of a terminal to an access device according to an embodiment of the present disclosure;

[0042] Figure 8 A flowchart of a payment method for a terminal and an access device provided in an embodiment of the present disclosure;

[0043] Figure 9 A block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0044] To enable those skilled in the art to better understand the technical solutions of the present disclosure, exemplary embodiments of the present disclosure are described below in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0045] In the absence of conflict, the various embodiments of the present disclosure and the various features therein may be combined with each other.

[0046] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0047] The terms used herein are only used to describe specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a" and "the" are also intended to include the plural forms, unless the context clearly indicates otherwise. It will also be understood that when the terms "comprising" and / or "made of" are used in this specification, the presence of the features, wholes, steps, operations, elements and / or components is specified, but the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof is not excluded. Similar words such as "connected" or "connected" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect.

[0048] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined as such herein.

[0049] Shared Wi-Fi uses Wi-Fi access devices (hereinafter referred to as access devices) from various individuals or businesses to provide network services to terminals. Before access devices connect to terminals, the access device (AP) or the AP and AP control device (hereinafter collectively referred to as AP) typically authenticates and controls the terminals using a centralized control device.

[0050] The authentication methods provided in related fields are as follows:

[0051] (1) There is no central authentication, but there is a centralized key database. Each individual Wi-Fi AP has a corresponding SSID / MAC and authentication method and password stored in the center. The center tells the terminal the access method and key, and then the AP performs access authentication independently. In this method, the center knows the access authentication method and key of the AP, which is easy to leak the access authentication secret of the AP. In real life, such keys are often stolen when accessing one's own AP through mobile phone software or brute force cracking the AP access key (this method relies on short-term or long-term preset passwords, which has low security strength, is easy to leak and easy to crack).

[0052] (2) In centralized authentication, each AP is connected to an access control center and interacts with the center through web authentication or 802.1x. AP access is controlled by the center. Therefore, the AP has no autonomy. Access is determined by the center. The center allows anyone to connect. Once the center leaks secrets or is untrustworthy, the security of the AP is threatened.

[0053] (3) Some related authentication technologies rely on the home network (the network to which the terminal belongs, usually the network that issues the terminal's identity) to authenticate the access terminal. When the terminal roams to other networks, once the home network is offline or disconnected from the roaming access network, access authentication cannot be performed.

[0054] (4) The relevant WiFi access authentication does not authenticate the network and access devices. There are behaviors in which the network and access devices deceive the terminals. For example, a free AP allows the terminal to access, and then pushes various advertisements and captures the user's film and television information.

[0055] In summary, centralized control devices directly control access to devices, for example, through web authentication or 802.1x authentication. This negatively impacts the privacy and security of individual / enterprise access devices. Another common shared Wi-Fi network even has only centralized access points and access password information. When a terminal moves within the access range of an AP, it searches the AP's SSID, MAC address, and other information to retrieve the access method and key from the central server, allowing the terminal to access based on this information. Some shared Wi-Fi networks even require authentication-free access on the AP. These access methods are unfair and insecure for individual / enterprise owned APs. Another problem with existing shared Wi-Fi access is that only the network or access device authenticates the terminal, while the terminal cannot authenticate the network or access device. This allows for the existence of many fake networks that illegally collect and push information to the terminal. Therefore, the challenge is to protect the privacy of individual / enterprise access devices while providing a universal access authentication method across the entire network. In addition to privacy and security issues, current shared Wi-Fi or roaming Wi-Fi access methods also suffer from the problem of not being able to work outside the home network. This means that the terminal can access a non-home network, but ultimately relies on the home network for access authentication.

[0056] The embodiments of the present disclosure provide a shared WiFi access method that can implement two-way authentication of terminals and access devices that are universal across the entire network, protect the privacy of individual / enterprise access devices, and thus improve the access security of shared WiFi.

[0057] In the embodiments of the present disclosure, the terminal device may be a mobile terminal such as a mobile phone, a pad, a notebook, or a fixed terminal such as a desktop computer, a server, etc. The access device may be a router with WiFi function.

[0058] It should be noted that the access devices participating in the shared WiFi pre-agreed on the WiFi service network identifier, for example, using the Service Set Identifier (SSID) as the network identifier. The terminal can detect the access device in the shared network through the agreed WiFi SSID, and then initiate an access request to the access device to achieve decentralized shared WiFi access authentication.

[0059] Figure 1 This is a flow chart of a shared WiFi access method provided by an embodiment of the present disclosure. Figure 1 As shown, an embodiment of the present disclosure provides a shared WiFi access method, which is applied to an access device and includes:

[0060] Step S101: receiving a first access request from a terminal and sending first return information to the terminal.

[0061] The first access request includes the identity information of the terminal and the corresponding signature information, and the first return information includes the identity information of the access device and the corresponding signature information.

[0062] In some embodiments, the terminal's identity information includes one or more of the terminal's blockchain address and the terminal's MAC address. The terminal's blockchain address is a unique address pre-acquired by the terminal on the blockchain, and the terminal's identity can be determined based on the blockchain address. The terminal's MAC address is an Ethernet address or physical address that can be used by access devices to confirm whether the terminal in the authentication information matches the terminal actually receiving the message, and to filter messages sent by the terminal.

[0063] In some embodiments, the signature information in the first access request is information obtained by signing the identity information of the terminal, wherein the private key used for the signature is the private key corresponding to the blockchain address of the terminal; or the private key corresponding to the public key used for authentication at the blockchain address of the terminal registered on the blockchain. The terminal registered on the blockchain is a legitimate terminal that has completed registration procedures on the blockchain.

[0064] For example, the first access request includes the blockchain address of the terminal, the MAC address of the terminal, and the signature information obtained by the terminal signing the above blockchain address and MAC address.

[0065] In some embodiments, the access device's identity information includes one or more of the access device's blockchain address and the access device's MAC address. The access device's blockchain address is a unique address pre-acquired by the access device on the blockchain, and the access device's identity can be determined based on the blockchain address. The access device's MAC address is an Ethernet address or physical address, which can be used by the terminal to determine whether the access device in the authentication interaction information matches the access device that actually received or sent the message. In some embodiments, the access device encrypts the first return message using the terminal's public key and sends it to the terminal.

[0066] In some embodiments, after the access device receives the first access request from the terminal, if the signature and identity information in the first access request match, and the MAC address used by the terminal to send and receive messages matches the MAC address of the terminal carried in the first access request, a first return message is sent to the terminal.

[0067] In some embodiments, the signature information in the first return information is information obtained by the access device signing the identity information of the access device, wherein the private key used for the signature is the private key corresponding to the blockchain address of the access device.

[0068] For example, the first returned information includes the blockchain address of the access device, the MAC address of the access device, and the signature information of the access device for the above information.

[0069] In some embodiments, when the terminal moves in a shared WiFi network, upon searching for an access device with an agreed SSID, the terminal submits a first access request to the access device.

[0070] Step S102: Receive a second access request from the terminal, and verify the second access request based on signature information of the terminal.

[0071] The second access request is sent by the terminal when the first return message is verified successfully based on the signature information of the access device. The second access request includes the identity information of the terminal and the corresponding signature information.

[0072] In some embodiments, the access device verifies the signature information in the second access request to verify whether the second access request originates from the terminal's blockchain address. For example, if the access device determines that the terminal's signature is the terminal's blockchain address, it verifies the second access request. The access device can verify the second access request using the terminal's blockchain address and a public key derived from the signature information. This disclosure does not limit the specific verification method.

[0073] In the embodiment of the present disclosure, a blockchain tool may be used to verify whether the second access request comes from the blockchain address of the terminal. The embodiment of the present disclosure does not limit the blockchain tool used to perform the verification.

[0074] Step S103: If the second access request passes the verification, a first query request is sent to a preset address to authenticate the legitimacy of the terminal.

[0075] In some embodiments, the first query request includes the terminal's identity information. A preset address stores a list of legitimate shared network users. The terminal's reputation, account type, and account balance may also be stored. The account type is used to determine the terminal's service type, such as regular account or VIP account. The account balance is used to determine whether the terminal has sufficient funds to provide minimum services. Both the access device and the terminal can query each other's identity and legitimacy on the blockchain.

[0076] In some embodiments, the access device can send a first query request to a preset address. The preset address queries a storage space based on the terminal's identity information to authenticate the terminal's legitimacy and obtain a query result. For example, if the terminal is on a list of legitimate shared network users, its credibility exceeds a credibility threshold, and its account balance meets the minimum service requirement, the terminal is considered legitimate. If the authentication is successful, the terminal is allowed to query the blockchain. In some embodiments, the access device analyzes the received query result to obtain an authentication result.

[0077] Optionally, a second return message is sent in response to the second access request, indicating that the terminal can send a query message to the blockchain. That is, the terminal can know more clearly when to send the query message through the second return message to avoid congestion.

[0078] Step S104: When the legitimacy authentication of the terminal is passed, an open access channel message is sent to the terminal.

[0079] The Open Access Channel message can be either a Command Stream Access Channel Open message or a Service Stream Access Channel Open message. The Open Command Stream Access Channel message allows the access device to open a command stream channel. The command stream sent by the terminal can be transmitted to other addresses through the access device, but the service stream remains unopened. The Open Service Stream Access Channel message allows the access device to open a service stream channel. The service stream sent by the terminal can be transmitted to other addresses through the access device.

[0080] When the access device opens the command flow, the access device receives the third access request from the terminal, and sends an access permission message to the terminal if the terminal is legal.

[0081] The third access request is sent by the terminal when the legitimacy authentication of the access device at the preset address is passed. The third access request includes the identity information of the terminal and the corresponding signature information.

[0082] In some embodiments, after receiving the third access request, the access device can verify the signature information to verify the third access request, ensure that the third access request comes from the blockchain address corresponding to the terminal, and if the third access request is verified, send an access permission message to the terminal, thereby releasing the terminal's business message.

[0083] When the access device opens the service flow, the access device receives a second query request sent by the terminal to query the legitimacy of the access device, and forwards the second query request to the preset address; and receives a verification result returned by the preset address, and forwards the verification result to the terminal.

[0084] The shared WiFi access method provided by the embodiment of the present disclosure is as follows: after receiving a first access request from a terminal, the access device sends first return information to the terminal for the terminal to verify the first return information; after receiving a second access request from the terminal, the second access request is verified, and if the verification passes, a first query request is sent to a preset address to authenticate the legitimacy of the terminal; after receiving a third access request from the terminal and if the legitimacy of the terminal is authenticated, an access permission message is sent to the terminal, wherein the terminal sends the third access request to the access device if the legitimacy of the access device is authenticated, that is, the access device and the terminal perform two-way authentication on the legitimacy of the other party at the preset address, and the access device sends the access permission message to the terminal if both parties pass the authentication, thereby realizing decentralized authentication and access, reducing the risk of access key leakage, and realizing secure access to shared WiFi. At the same time, existing home gateway devices and enterprise gateway devices can be reused, reducing the cost of transforming the shared WiFi network.

[0085] In some embodiments, step S103, when the second access request passes the verification, sending a first query request to a preset address to authenticate the legitimacy of the terminal includes:

[0086] If the second access request passes the verification, sending a first query request to the preset address, so that the preset address obtains a first query result according to the identity information of the terminal; wherein the first query request includes the identity information of the terminal;

[0087] A first query result returned by a preset address is received, and whether the terminal is legitimate is authenticated based on the first query result.

[0088] In some embodiments, the first query result includes a determination result of whether the terminal is a legitimate terminal, or the first query result includes basic information for determining whether the terminal is a legitimate terminal, and the legitimacy of the terminal can be accurately determined based on the basic information.

[0089] When the first query result includes a judgment result, the access device can directly determine the legitimacy of the terminal based on the judgment result. When the first query result includes basic information for determining whether the terminal is a legal terminal, the access device determines the legitimacy of the terminal based on the basic information.

[0090] In some embodiments, the preset address includes one or more of a blockchain and a smart contract.

[0091] For example, the access device sends a first query request to the blockchain network. The blockchain network queries the blockchain record based on the terminal's identity information, including but not limited to whether the terminal is on the list of legal shared network users recorded on the blockchain, whether the account type and account balance are sufficient to provide minimum services, and reputation. If the terminal is on the list of legal shared network users recorded on the blockchain, and the account type and account balance are sufficient to provide minimum services, the terminal is confirmed to be a legal terminal.

[0092] The present disclosure provides a unique challenge response method, as follows:

[0093] The two parties to the challenge agree in advance on the secrets used for the challenge, which are usually information hash, encryption method and shared key. When one party gives a message and requires the other party to use the agreed hash algorithm to calculate the message to obtain a hash value, or to encrypt the hash value with a key, the other party uses the same algorithm to obtain the result of the message it sent. When the other party returns the challenge result as required, the hash values ​​generated by itself and the other party are compared. If they are consistent, the challenge is considered successful.

[0094] Since both parties in the present disclosure have blockchain addresses, although the two parties do not need to discuss the encryption method for the challenge in advance, due to the special nature of the blockchain address, it is easy to verify the signature information of the corresponding private key. Therefore, this feature can be used to achieve the purpose of verifying the challenge response without having to negotiate the hash algorithm and encryption algorithm in advance.

[0095] For example, the first end A sends a challenge message (referred to as a challenge value) to the second end B. The second end B uses the private key corresponding to its own address to sign the challenge value to obtain a signature result. The second end B returns the signature result to the first end A. The original challenge value does not need to be included in the return message because the first end A has its own challenge value. The first end A verifies the signature of the second end B, verifying both the authenticity of the signature of the second end B and whether the signature information is the signature of the original challenge value.

[0096] In some embodiments, the first access request, the second access request, and the third access request also include a challenge value (random number) generated by the terminal, and each challenge value is different. The first return message, the second return message, and the access permission message corresponding to the first access request, the second access request, and the third access request include not only a response to the challenge value proposed by the terminal but also a challenge value proposed by the access device. Each challenge value response in the reply corresponds to the challenge value proposed in the previous message sent by the terminal, and the challenge proposed by each access device is different in each message. The message sent by the terminal needs to carry a response to the challenge value in the message sent by the previous access device. Such mutually locked challenges and responses can prevent replay attacks. For example, (the example of the challenge in the first interactive message sequence: A1i, B1i'x, A2jx', B2j'y, A3ky', B3k'; where A represents the message sent by the terminal to the access device, B represents the message responded by the access device, 1, 2, 3 represent the message sequence numbers, i, j, k represent the challenge values ​​generated by the terminal for each message; I', j', k' represent the challenge response generated by the access device for each challenge value (that is, the signature information of the original challenge value); x, y represent the challenge values ​​generated by the access device, and x', y' represent the challenge response generated by the terminal for each challenge value. For another example, in the case where there is no response to the second access request: A1i, B1i'x, A2jx', empty, A3kx', B3k'; "empty" means that the access device does not respond to the terminal's access request, that is, no second return message is generated.

[0097] Step S102, after receiving the second access request from the terminal, further includes: verifying the second access request based on the challenge value, the challenge value response and the corresponding signature information.

[0098] In some embodiments, when the access device confirms that the challenge value and challenge value response sent by the terminal are correct, and the signature information is the blockchain address signature of the terminal, the second access request is verified.

[0099] In the disclosed embodiment, the challenge value and the challenge value response can reduce the possibility of the transmitted message being copied and replayed in the intermediate communication link, and can even completely avoid replay attacks.

[0100] In some embodiments, if the second access request passes the verification, after sending the first query request to the preset address to authenticate the legitimacy of the terminal, the method further includes:

[0101] Send a release query message to the terminal so that the terminal can authenticate the legitimacy of the access device to the preset address through the access device.

[0102] When the access device passes the legitimacy authentication of the terminal, a release query message is sent to the terminal so that the terminal can authenticate the legitimacy of the access device to the preset address through the access device. When the terminal passes the legitimacy authentication of the access device, a third access request is sent to the access device.

[0103] It should be noted that the release query message is the access device's release of the terminal's query message, which is different from the access permission message. After the terminal receives the release query message, it can send a first query request to the blockchain network through the access device.

[0104] In some embodiments, when the access device receives the first access request sent by the terminal, the access device sends first return information to the terminal in the form of a blockchain transaction;

[0105] And / or, when the access device receives the third access request sent by the terminal, the access device sends an access permission message to the terminal in the form of a blockchain transaction.

[0106] In the disclosed embodiment, the access device and the terminal exchange information in the form of blockchain transactions, but this information is not uploaded to the blockchain.

[0107] In some embodiments, after sending the access permission message to the terminal, the method further includes:

[0108] Receive the payment credentials of the terminal, where the payment credentials are generated based on the payment method pre-agreed between the access device and the terminal; monitor the status of the terminal and send a stop access service message to the terminal when the terminal status reaches a preset trigger condition.

[0109] In the disclosed embodiment, when the access device allows a terminal to access the shared Wi-Fi, it can receive payment credentials from the terminal and collect the payment credentials. Furthermore, the access device can continuously monitor the terminal's status and, when the terminal's status reaches a preset trigger condition, send a stop access service message to the terminal to terminate the access service.

[0110] In some embodiments, the access device and the terminal may agree on the form of payment credentials during the access process, for example, payment based on service duration or forwarded data volume. When incremental payment credentials are agreed upon, when incremental payment is triggered, the terminal sends the payment credentials to the access device, which then collects them.

[0111] While providing access services to terminals, access devices continuously monitor their status, such as account balances and creditworthiness, to see if they are experiencing any anomalies. When a terminal's access ends, or an anomaly occurs—for example, if the terminal fails to submit payment credentials after the agreed-upon number of incremental payment cycles—the access device submits the final payment credentials to the blockchain for settlement and simultaneously shuts down the terminal's access service. The blockchain can also record penalties and credit deductions for individual device behaviors, such as abnormal device offlines and terminal timeouts for non-payment. Credit scores can also be continuously increased based on the cumulative amount of services and payments honestly completed.

[0112] An embodiment of the present disclosure provides a shared WiFi access method applied to a terminal. Figure 2 This is a flow chart of a shared WiFi access method provided by an embodiment of the present disclosure. Figure 2 As shown, an embodiment of the present disclosure provides a shared WiFi access method, which is applied to a terminal and includes:

[0113] Step S201: Send a first access request to an access device.

[0114] In some embodiments, the access request includes the terminal's identity information and corresponding signature information. The terminal's identity information includes one or more of the terminal's blockchain address, the terminal's MAC address, and the terminal's signature. The terminal's blockchain address is a unique address pre-acquired by the terminal on the blockchain, and the terminal's identity can be determined based on the blockchain address. The terminal's MAC address is an Ethernet address or physical address, which can be used by the access device to confirm whether the terminal in the authentication information matches the terminal actually receiving the message, and to filter messages sent by the terminal.

[0115] In some embodiments, the signature information in the first access request is information obtained by the terminal signing the identity information of the terminal, wherein the private key used for the signature is the private key corresponding to the blockchain address of the terminal; or the private key corresponding to the public key used for the authentication under the blockchain address of the terminal registered on the blockchain, wherein the terminal registered on the blockchain is a legitimate terminal that has completed the registration procedures at the terminal.

[0116] For example, the first access request includes the blockchain address of the terminal, the MAC address of the terminal, and the signature information obtained by the terminal signing the above blockchain address and MAC address.

[0117] Step S202: Receive the first return information sent by the access device, perform signature verification on the first return information, and verify whether the MAC address of the access device contained in the first return information matches the MAC address actually used by the access device; wherein, the first return information is sent by the access device when it receives the first access request, and the first return information includes the identity information of the access device and the corresponding signature information.

[0118] In some embodiments, the access device's identity information includes one or more of the access device's blockchain address and the access device's MAC address. The access device's blockchain address is a unique address pre-acquired by the access device on the blockchain, and the access device's identity can be determined based on the blockchain address. The access device's MAC address is an Ethernet address or physical address, and can be used by the terminal to confirm whether the access device in the authentication interaction information matches the access device that actually received or sent the message. In some embodiments, the access device encrypts the first return message using the terminal's public key and sends it to the terminal.

[0119] In some embodiments, the signature information in the first return information is information obtained by the access device signing the access device's identity information, wherein the private key used for the signature is the private key corresponding to the access device's blockchain address, or the private key corresponding to the public key used for authentication at the access device's blockchain address registered on the blockchain by the access device. The access device registered on the blockchain is a legitimate access device that has completed registration and other procedures on the blockchain.

[0120] For example, the first returned information includes the blockchain address of the access device, the MAC address of the access device, and the signature information of the access device to the blockchain address and MAC address of the access device.

[0121] Step S203: Send a second access request to the access device; wherein the second access request includes the identity information of the terminal and corresponding signature information, so that the access device can authenticate the legitimacy of the terminal at a preset address based on the identity information of the terminal.

[0122] In the disclosed embodiment, after receiving the first response message, the terminal verifies that the signature of the first response message is the signature of the access device's blockchain address and then sends a second access request to the access device. The terminal may verify the first response message using the access device's blockchain address and a public key derived based on the signature information. The public key of the access device's blockchain address may be a public key derived from the access device's blockchain address and signature. The disclosed embodiment does not limit the method for deriving the public key.

[0123] Step S204: If the first returned information is verified to be successful, a second query request is sent to a preset address to authenticate the legitimacy of the access device and obtain a second query result; wherein the second query request includes the identity information of the access device.

[0124] The pre-set address stores a list of legitimate shared network users and can also store the reputation of connected devices. Each terminal can query the identity and legitimacy of the connected device on the blockchain. The terminal analyzes the second query result to confirm whether the connected device is legitimate.

[0125] Step S205: Receive an open access channel message sent by the access device.

[0126] The open access channel message is sent when the access device determines that the terminal is legitimate.

[0127] In some embodiments, step S204, after sending the second query request to the preset address, also includes: sending a third access request to the access device if the access device is legal; and receiving an access permission message sent by the access device; wherein the third access request includes the identity information of the terminal and the corresponding signature information; the access permission message is sent when the access device determines that the terminal is legal.

[0128] If the access device is legal, a third access request is sent to the access device; wherein the third access request includes the identity information of the terminal and the corresponding signature information.

[0129] In some embodiments, after step S204, sending the second query request to the preset address, the method further includes: sending a service flow to the access device if the access device is legal.

[0130] The shared WiFi access method provided by the embodiment of the present disclosure comprises the following steps: a terminal initiates a first access request to an access device; upon receiving first return information returned by the access device, a second access request is sent to the access device if the first return information is verified successfully; and the access device sends a first query request to a preset address if the second access request is verified successfully based on signature information of the terminal to authenticate the legitimacy of the terminal; and, upon verifying successfully the first return information, a second query request is sent to the preset address to authenticate the legitimacy of the access device; and upon successfully authenticating the legitimacy of the access device, a third access request is sent to the access device, and an access permission message is received from the access device, wherein the access device sends the access permission message to the terminal if the legitimacy of the terminal is authenticated successfully, i.e., the access device and the terminal perform two-way authentication at the preset address, thereby realizing decentralized authentication and access, reducing the risk of access key leakage, and realizing secure access to shared WiFi. At the same time, existing home gateway devices and enterprise gateway devices can be reused, thereby reducing the cost of transforming the shared WiFi network.

[0131] In some embodiments, step S204, when the first returned information passes verification, sending a second query request to a preset address to authenticate the legitimacy of the access device, includes:

[0132] If the first returned information is verified, a second query request is sent to the preset address, so that the preset address obtains a second query result according to the identity information of the access device; wherein the second query request includes the identity information of the access device;

[0133] A second query result returned by the preset address is received, and the legitimacy of the access device is authenticated based on the second query result.

[0134] In some embodiments, the preset address stores a list of legal shared network users (which may include both a terminal list and an access device list), and may also store information such as the credibility of the access device. The terminal can query the identity and legitimacy of the access device at the preset address.

[0135] In some embodiments, the terminal can send a second query request to a preset address. The preset address queries a storage space based on the access device's identity information to authenticate the access device's legitimacy and obtain a second query result. For example, if the access device is on a list of legitimate shared network users and its credibility exceeds a credibility threshold, the access device is deemed legitimate. After obtaining the second query result, the terminal analyzes it to determine whether the access device is legitimate.

[0136] In some embodiments, the preset address includes one or more of a blockchain and a smart contract.

[0137] When the terminal queries the legitimacy of the access device on the blockchain network and the smart contract, a second query request can be sent to the blockchain network and the smart contract through the access device.

[0138] When the terminal is not connected to the access device, since the terminal has no other data channel to access the blockchain network, the terminal can forward the second query request and obtain the second query result through the access device.

[0139] Since the second query request is forwarded and the second query result is obtained through the access device, the access device may forge the query result based on the blockchain network information. Therefore, the terminal can obtain the second query result through the public authentication server.

[0140] In some embodiments, a public authentication server forwards the second query request to a preset address and receives the query result. The public authentication server obtains a blockchain address on the blockchain and can be a blockchain node or a service device with a blockchain address, such as a server containing a blockchain wallet. The public authentication server can query the blockchain network for information and send smart contract transactions to monitor transactions sent to it and monitor transaction execution results.

[0141] When the terminal authenticates the legitimacy of the access device on the public authentication server, it sends a second query request to the public authentication server. The public authentication server forwards the second query request to a preset address, such as the blockchain network and smart contract, and returns the query result to the terminal. The message returned by the public authentication server includes the public authentication server's blockchain address and signature information, allowing the terminal to perform signature verification and information integrity verification on the returned information. The public authentication server can be a third-party server trusted by the terminal or a server built by the individual or enterprise corresponding to the terminal. The public authentication server reads relevant information about the participating access devices and terminals on the blockchain through a preset address, including the blockchain and smart contract. This relevant information includes, but is not limited to, the identity information and credibility of the access devices and terminals.

[0142] In some embodiments, by forwarding the second query request to a preset address to multiple public authentication servers and receiving the query results, single point failure and single point fraud of the public authentication server can be avoided, and the query result of each public authentication server can be finally determined by combining the combined strategy.

[0143] In some embodiments, a public authentication server acts as a bridge between the terminal and the blockchain, sending query requests from the terminal to the blockchain network and receiving query results returned by the blockchain network to authenticate the connected device. Connecting to the blockchain network through the public authentication server can reduce the performance requirements of the terminal, meaning that the terminal does not need to meet the performance requirements of a blockchain node to connect to the blockchain network. Furthermore, the public authentication server can serve multiple terminals simultaneously, increasing the flexibility of terminal access to shared WiFi.

[0144] In some embodiments, the terminal can also authenticate the legitimacy of the access device through a simplified proof method. The terminal includes a verification module that verifies the correctness of the relevant transactions and blocks contained in the access device information by verifying the block header chain relationship and transaction hash, based on the block header information and specific transaction information. In some embodiments, the access device provides its own provable records on the blockchain, such as the legitimate access device identity and reputation recorded on the blockchain in the form of transactions, as well as the corresponding blocks and information related to these transactions, for the terminal to perform a simplified verification. For example, the system stipulates that legitimate access devices must send a transaction to a specific address or smart contract containing specific registration instructions and access device information. In this case, the transaction, as well as the source and destination address information, can be found on the blockchain. By searching for transactions with registration instructions related to the target address, all legitimate access devices can be found. Block information includes block headers and block body information. The terminal can compare this information with its own stored block headers, confirming the legitimacy of the block containing the target transaction by deriving the block header chain. The terminal then authenticates the legitimacy of the access device based on the target transaction within the target block. For example, a terminal stores a certain number of block headers. It finds a block header (referred to as block header n) among its stored block headers that is newer than the block containing identity and reputation information provided by the access device (referred to as block header ni, where i = 0, 1, 2, 3, etc.). The terminal can select a block header that is as close as possible. If the terminal does not store block header information from block header n to block header ni, it can request the access device to provide it. The block header chain chain link can be used to verify whether the block provided by the access device is falsified. The transaction information can also be verified by verifying whether the transaction hash value is included in the Merkle tree within the block header. Transactions related to the access device's identity and reputation are provided by the access device, and the terminal verifies the transaction using the Merkle tree within the block header. If the verification is correct, the identity information and credibility submitted by the access device on the blockchain will be recognized, that is, the access device will be authenticated.

[0145] In some embodiments, since the identity information and credibility of the access device are provided by the access device itself, the preset address of the terminal authentication access terminal can be considered as the access device address. Based on this, step S204, if the first return information verification passes, sends a second query request to the preset address to authenticate the legitimacy of the access device, including:

[0146] If the first returned information is verified to be successful, a second query request is sent to the access device address; the block information of the access device is received, and the legitimacy of the access device is authenticated based on the block header information in the block information and using the Merkle tree.

[0147] In some embodiments, step S204, before sending a second query request to a preset address to authenticate the legitimacy of the access device if the first returned information passes verification, further includes:

[0148] Receive a release query message; wherein the release query message is sent when the access device determines that the terminal is legal.

[0149] In some embodiments, when the access device passes the legitimacy authentication of the terminal, a release query message is sent to the terminal, and the terminal authenticates the legitimacy of the access device to a preset address through the access device.

[0150] In some embodiments, the first return message and the access-granted message also include a response challenge value. The response challenge value is generated by the access device and is unique for each access device. Carrying the response challenge value in the first return message and the access-granted message can prevent replay attacks.

[0151] In some embodiments, the return message of the access device includes both the response challenge value and the challenge value corresponding to the access request, which can reduce the number of challenges and improve access efficiency.

[0152] Step S202, after receiving the first return information sent by the access device, further includes: verifying the first return message and the access permission message based on the response challenge value.

[0153] The response challenge value, also known as a response random number, is generated by the access device. Upon confirming that the response challenge value sent by the access device is correct and that the signature information is the blockchain address signature of the access device, the terminal deems the first return message and the access permission message to be verified.

[0154] For example, A1i, B1i'x, A2jx', B2j'y, A3ky', B3k'; where A represents the message sent by the terminal to the access device, B represents the message responded by the access device, 1, 2, and 3 represent the message sequence numbers, i, j, and k represent the challenge values ​​generated by the terminal for each message; I', j', and k' represent the challenge responses generated by the access device for each challenge value (that is, the signature information of the original challenge value); x and y represent the response challenge values ​​generated by the access device, and x' and y' represent the challenge responses generated by the terminal for each challenge value. For another example, if there is no response to the second access request: A1i, B1i'x, A2jx', empty, A3kx', B3k'.

[0155] In some embodiments, the identity information of the terminal includes one or more of the blockchain address of the terminal and the MAC address of the terminal; the characteristic information of the access device includes one or more of the blockchain address of the access device and the MAC address of the access device.

[0156] The terminal's blockchain address is a unique address pre-acquired by the terminal on the blockchain. The terminal's identity can be determined based on the blockchain address. The terminal's MAC address is an Ethernet address or physical address, which can be used by the access device to confirm whether the terminal in the authentication information matches the actual terminal receiving and sending messages, and to filter messages sent by the terminal. The access device's blockchain address is a unique address pre-acquired by the access device on the blockchain. The access device's identity can be determined based on the blockchain address. The access device's MAC address is an Ethernet address or physical address, which can be used by the terminal to confirm whether the access device in the authentication interaction information matches the access device actually receiving and sending messages.

[0157] In some embodiments, the signature information in the first return information is information obtained by the access device signing the identity information of the access device, wherein the private key used for the signature is the private key corresponding to the blockchain address of the access device.

[0158] For example, the first returned information includes the blockchain address of the access device, the MAC address of the access device, and the signature information of the access device for the above information.

[0159] In some embodiments, after receiving the access permission message sent by the access device, the method further includes:

[0160] Sending a payment credential to the access device, where the payment credential is generated using a payment method pre-agreed between the access device and the terminal;

[0161] Receive access service stop information; wherein, the access service stop information is information generated by the access device based on the monitored terminal status and when the terminal status reaches a preset trigger condition.

[0162] In some embodiments, the terminal directly sends the payment to the access device through a blockchain transaction. In order to reduce the number of times and costs of blockchain uploads, the following credential accumulation method can be used:

[0163] The payment credential is the information that the blockchain can identify and cannot deny, which is paid from the terminal address to the access device address. The signature with the terminal address is used by the blockchain to process the payment for the payment credential. For example, it can be a blockchain payment transaction sent from the terminal address to the access device address, or a blockchain transaction sent from the terminal address to an agreed address (such as a smart contract), the purpose of which is to pay the access device address, or the access terminal uses the private key corresponding to the blockchain address to pay the information to the access device blockchain address and the signature of this information. In order to avoid frequent transactions on the chain, the cumulative payment credential method can be used, that is, the current amount payable is the sum of the previously completed service amounts payable, and the access device only needs to submit the last payment credential to the blockchain to obtain the amount payable.

[0164] In the disclosed embodiment, when the access device allows a terminal to access the shared Wi-Fi, it can receive payment credentials from the terminal and collect the payment credentials. Furthermore, the access device can continuously monitor the terminal's status and, when the terminal's status reaches a preset trigger condition, send a stop access service message to the terminal to terminate the access service.

[0165] In the disclosed embodiment, when the access device provides access services to the terminal, it continuously checks the status of the status, such as whether the account balance and reputation are in an abnormal state. When the terminal's access ends, or an abnormal situation occurs, such as when the agreed number of incremental payment cycles arrives and the terminal does not send the payment credentials, the access device submits the last payment credentials to the blockchain for settlement and simultaneously shuts down the terminal's access service. The blockchain can also set up records for penalties and credit score deductions for each device's behavior, such as abnormal offline access devices and terminal timeouts without payment. It can also continuously increase the credit score record of each device based on the cumulative amount of services and payments completed honestly.

[0166] It is understood that the above-mentioned various method embodiments mentioned in this disclosure can be combined with each other to form combined embodiments without violating the principle logic. Due to space limitations, this disclosure will not go into details. It is understood by those skilled in the art that in the above-mentioned methods of specific implementation, the specific execution order of each step should be determined by its function and possible internal logic.

[0167] It should be noted that the access device in this disclosure refers to a device that includes a WiFi access point (AP). One end of the device provides WiFi wireless access for connecting to a WiFi terminal (STA). The other end directly or indirectly connects to the business network and blockchain network, such as the internet. In a home environment, such a device is typically a gateway or router with a WiFi access point. In an enterprise environment, it is typically an AP device or an AP device and its corresponding controller.

[0168] The access device obtains a blockchain address on the blockchain. It can be a blockchain node or a device with a blockchain address, such as a device with blockchain wallet functionality. Blockchain wallet functionality generally refers to the ability to generate blockchain addresses, send and receive blockchain transactions, monitor transactions sent to it, and transmit the results of transactions sent to it. Unlike blockchain nodes, it doesn't necessarily connect directly to the blockchain, but can achieve these functions through trusted blockchain services.

[0169] Access devices can also delegate the execution of the above blockchain functions to devices they trust, but this article does not describe these cases in detail.

[0170] It should also be noted that the public authentication server disclosed herein obtains a blockchain address on the blockchain and can be a blockchain node or a service device with a blockchain address, such as a server containing a blockchain wallet. The public authentication server can query information from the blockchain network, send smart contract transactions, monitor transactions sent to it, and monitor transaction execution results. Numerous public authentication servers exist online. These servers, based on historical credit or collateralized credit, provide open services on shared WiFi networks and can simultaneously serve multiple terminals. Terminals can also independently select different public authentication servers for service. Therefore, public authentication servers are the subject of decentralized applications. Furthermore, if end users do not trust other public authentication servers, they can deploy their own.

[0171] The public authentication server acts as a bridge between the terminal and the blockchain. It can send query requests sent by the terminal to the blockchain network, receive query results returned by the blockchain network and send blockchain query results with its own signature to the terminal; or authenticate the access device and send authentication results with its own signature to the terminal; the terminal can utilize the blockchain network through the public authentication server, which can reduce the performance and functional requirements of the terminal, that is, the terminal does not need to be a blockchain node to utilize the blockchain network.

[0172] In addition, the present disclosure also provides a shared WiFi access device, an electronic device, and a computer-readable storage medium, all of which can be used to implement any shared WiFi access method provided by the present disclosure. The corresponding technical solutions and descriptions are referred to the corresponding records in the method section and will not be repeated here.

[0173] The embodiments of the present disclosure provide a shared WiFi access device that can implement two-way authentication of terminals and access devices that are universal across the entire network, protect the privacy of personal / enterprise access devices, and thus improve the access security of shared WiFi.

[0174] Figure 3 This is a block diagram of a shared WiFi access device provided by an embodiment of the present disclosure. Figure 3 As shown, an embodiment of the present disclosure provides a shared WiFi access device 300, which is applied to an access device and includes:

[0175] The first receiving module 301 is configured to receive a first access request from a terminal, wherein the first access request includes the terminal's identity information and corresponding signature information. The terminal's identity information and corresponding signature information are used by the access device to verify the first access request and whether the terminal's signature and identity match.

[0176] In some embodiments, the terminal's identity information includes one or more of the terminal's blockchain address and the terminal's MAC address. The terminal's blockchain address is a unique address pre-acquired by the terminal on the blockchain, and the terminal's identity can be determined based on the blockchain address. The terminal's MAC address is an Ethernet address or physical address that can be used by access devices to confirm whether the terminal in the authentication information matches the terminal actually receiving the message, and to filter messages sent by the terminal.

[0177] In some embodiments, the signature information in the first access request is information obtained by signing the identity information of the terminal, wherein the private key used for the signature is the private key corresponding to the blockchain address of the terminal; or the private key corresponding to the public key used for authentication at the blockchain address of the terminal registered on the blockchain. The terminal registered on the blockchain is a legitimate terminal that has completed the terminal registration procedures.

[0178] The first sending module 302 is configured to send first return information to the terminal; wherein the first return information includes the identity information of the access device and the corresponding signature information;

[0179] The first receiving module 301 is further configured to receive a second access request from the terminal, wherein the second access request is issued by the terminal when the second access request is verified based on the signature information of the access device, and the second access request includes the identity information of the terminal and the corresponding signature information;

[0180] A first verification module 303 is configured to verify the second access request based on the signature information of the terminal;

[0181] The first sending module 302 is further configured to send a first query request to a preset address to authenticate the legitimacy of the terminal if the second access request is verified, wherein the first query request includes the identity information of the terminal;

[0182] The first sending module 302 is further configured to send an open access channel message to the terminal if the terminal is legal.

[0183] The shared WiFi access device provided by the embodiment of the present disclosure has the following characteristics: after the first receiving module access device receives the first access request of the terminal, the first return information is sent to the terminal through the first sending module, so that the terminal can verify the first return information; after the first receiving module receives the second access request of the terminal, the second access request is verified by the first verification module, and if the verification passes, the first query request is sent to a preset address through the first sending module to authenticate the legitimacy of the terminal; after the first receiving module receives the third access request of the terminal and the legitimacy of the terminal is authenticated, the first sending module sends an access permission message to the terminal, wherein the terminal sends the third access request to the access device if the legitimacy of the access device is authenticated, that is, the access device and the terminal perform two-way authentication at the preset address, realizing decentralized authentication and access, reducing the risk of access key leakage, and realizing secure access to shared WiFi. At the same time, existing home gateway devices and enterprise gateway devices can be reused, reducing the transformation cost of the shared WiFi network.

[0184] In some embodiments, the first receiving module 301 is further configured to receive a third access request from the terminal; wherein the third access request is sent when the terminal passes the legitimacy authentication of the access device, and the third access request includes the identity information of the terminal and the corresponding signature information.

[0185] In some embodiments, the first sending module 302 is further configured to send a first query request to a preset address if the second access request is verified, so that the preset address obtains a first query result according to the identity information of the terminal; wherein the first query request includes the identity information of the terminal;

[0186] The first receiving module 301 is further configured to receive a first query result returned by a preset address, and authenticate whether the terminal is legitimate based on the first query result.

[0187] In some embodiments, the preset address includes one or more of a blockchain and a smart contract.

[0188] In some embodiments, the first access request, the second access request and the third access request further include a challenge value; the first verification module 303 is further configured to verify the second access request based on the challenge value and the corresponding signature information.

[0189] In some embodiments, the first sending module 302 is further configured to send a release query message to the terminal, so that the terminal can authenticate the legitimacy of the access device to a preset address through the access device.

[0190] The first receiving module 301 is further configured to receive a payment credential of the terminal, wherein the payment credential is generated using a payment method pre-agreed between the access device and the terminal.

[0191] In some embodiments, the shared WiFi access device further includes: a detection module configured to monitor the status of the terminal.

[0192] The first sending module 302 is further configured to send access service stop information to the terminal when the terminal status reaches a preset trigger condition.

[0193] The present disclosure also provides a shared WiFi access device for a terminal. Figure 4 This is a block diagram of the principle of a shared WiFi access device provided by an embodiment of the present disclosure. Figure 4 As shown, an embodiment of the present disclosure provides a shared WiFi access device 400, which is applied to a terminal and includes:

[0194] The second sending module 401 is configured to send a first access request to the access device; wherein the access request includes signature information corresponding to the identity information of the terminal.

[0195] In some embodiments, the terminal's identity information includes one or more of the terminal's blockchain address and the terminal's MAC address. The terminal's blockchain address is a unique address pre-acquired by the terminal on the blockchain, and the terminal's identity can be determined based on the blockchain address. The terminal's MAC address is an Ethernet address or physical address that can be used by access devices to confirm whether the terminal in the authentication information matches the terminal actually receiving the message, and to filter messages sent by the terminal.

[0196] In some embodiments, the signature information in the first access request is information obtained by signing the identity information of the terminal, wherein the private key used for the signature is the private key corresponding to the blockchain address of the terminal; or the private key corresponding to the public key used for authentication at the blockchain address of the terminal registered on the blockchain. The terminal registered on the blockchain is a legitimate terminal that has completed registration procedures on the blockchain.

[0197] The second receiving module 402 is configured to receive first return information sent by the access device, wherein the first return information is sent by the access device when receiving the first access request, and the first return information includes identity information of the access device and corresponding signature information.

[0198] In some embodiments, the access device's identity information includes one or more of the access device's blockchain address and the access device's MAC address. The access device's blockchain address is a unique address pre-acquired by the access device on the blockchain, and the access device's identity can be determined based on the blockchain address. The access device's MAC address is an Ethernet address or physical address, which can be used by the terminal to determine whether the access device in the authentication interaction information matches the access device that actually received or sent the message. In some embodiments, the access device encrypts the first return message using the terminal's public key and sends it to the terminal.

[0199] In some embodiments, after the access device receives the first access request from the terminal, if the signature and identity information in the first access request match, and the MAC address used by the terminal to send and receive messages matches the MAC address of the terminal carried in the first access request, a first return message is sent to the terminal.

[0200] The second verification module 403 is configured to verify the first returned information based on the identity information of the access device.

[0201] The second sending module 401 is further configured to send a second access request to the access device; wherein the second access request includes the identity information of the terminal and the corresponding signature information, so that the access device can authenticate the legitimacy of the terminal at a preset address based on the identity information of the terminal.

[0202] The second sending module 401 is further configured to send a second query request to a preset address to authenticate the legitimacy of the access device when the first return information is verified; wherein the second query request includes the identity information of the access device and the corresponding signature information.

[0203] The second receiving module 402 is configured to receive an access permission message sent by the access device; wherein the access permission message is sent when the access device determines that the terminal is legal.

[0204] In a shared WiFi access device provided by an embodiment of the present disclosure, a terminal initiates a first access request to an access device via a second sending module, receives first return information returned by the access device via a second receiving module, verifies the first return information via a second verification module, and, if the first return information is verified successfully, sends a second access request to the access device via the second sending module. The access device, if the second access request is verified successfully based on signature information of the terminal, sends a first query request to a preset address to authenticate the legitimacy of the terminal; and, if the first return information is verified successfully, sends a second query request to the preset address via the second sending module to authenticate the legitimacy of the access device. If the legitimacy of the access device is authenticated successfully, the second sending module sends a third access request to the access device, and receives an access permission message sent by the access device via the second receiving module. The access device sends the access permission message to the terminal if the legitimacy of the terminal is authenticated successfully. That is, the access device and the terminal perform bidirectional authentication at the preset address, thereby achieving decentralized authentication and access, reducing the risk of access key leakage, and achieving secure access to shared WiFi. Existing home gateway devices and enterprise gateway devices can be reused, reducing the cost of modifying a shared WiFi network.

[0205] In some embodiments, the second sending module 401 is further configured to send a third access request to the access device if the access device is legal; wherein the third access request includes the identity information of the terminal and the corresponding signature information.

[0206] In some embodiments, the second sending module 401 is further configured to send a second query request to a preset address when the first return information is verified, so that the preset address can obtain a second query result based on the identity information of the access device; wherein the second query request includes the identity information of the access device.

[0207] The second receiving module 402 is further configured to receive a second query result returned by the preset address, and authenticate the legitimacy of the access device based on the second query result.

[0208] In some embodiments, the preset address includes one or more of a blockchain, a smart contract, and a public authentication server.

[0209] When the preset address is the access device address, and the first returned information passes verification, the second sending module 401 is further configured to send a second query request to the access device address.

[0210] The second receiving module 402 is further configured to receive block information of the access device.

[0211] The brief authentication module 404 is configured to authenticate the legitimacy of the access device based on the block header information in the block information and using the Merkle tree.

[0212] In some embodiments, the second receiving module 402 is further configured to receive a release query message; wherein the release query message is sent when the access device determines that the terminal is legitimate.

[0213] In some embodiments, the first return message and the access permission message further include a response challenge value. The second verification module is further configured to verify the first return message and the access permission message based on the response challenge value.

[0214] In some embodiments, the identity information of the terminal includes one or more of the blockchain address of the terminal and the MAC address of the terminal; the characteristic information of the access device includes one or more of the blockchain address of the access device and the MAC address of the access device.

[0215] In some embodiments, the second sending module 401 is further configured to send payment credentials to the access device, wherein the payment credentials are generated based on a payment method pre-agreed between the access device and the terminal; the second receiving module 402 is further configured to receive information on stopping access service; wherein the information on stopping access service is information generated by the access device based on the monitored status of the terminal and when the status of the terminal reaches a preset trigger condition.

[0216] To better understand the shared WiFi access method and apparatus according to the embodiments of the present disclosure, the following describes the shared WiFi access method according to the embodiments of the present disclosure, using a terminal, an access device, and a blockchain as objects for information interaction.

[0217] Figure 5 This is a flow chart of a shared WiFi access method provided by an embodiment of the present disclosure. Figure 5 As shown, the shared WiFi access method includes:

[0218] In step S501, the terminal sends a first access request to the access device, wherein the first access includes (carries) the blockchain address of the terminal and a first challenge value.

[0219] In step S501, when a terminal searches for an access device with an agreed SSID while moving in a shared WiFi network, the terminal sends a first access request to the access device.

[0220] In step S502, the access device sends a first return message to the terminal, wherein the first return message includes the access device's blockchain address, MAC address, first challenge value, first challenge response value, and corresponding signature information. The signature information is obtained by signing the access device's blockchain address, MAC address, first challenge value, and first challenge response value using the private key of the access device's blockchain address.

[0221] It should be noted that the access device sends the first return information to the terminal in the form of a blockchain transaction, and the first return information is not transmitted on the blockchain.

[0222] In step S503, the terminal receives the first response information from the access device, verifies the first response information, and if the verification passes, sends a second access request to the access device. The second access request includes the terminal's blockchain address, MAC address, first response challenge value, second challenge value, and corresponding signature information. The signature information is obtained by signing the terminal's blockchain address, MAC address, first response challenge value, and second challenge value using the private key of the terminal's blockchain address.

[0223] In step S503, the terminal verifies the first return information, including verifying whether the first challenge value and the first response challenge value are correct, and verifying whether the signature information is the signature of the blockchain address of the access device. When the verification passes, it can be determined that the first return information comes from the access device.

[0224] It should be noted that the terminal sends the second access request to the access device in the form of a blockchain transaction, and the second access request is not transmitted on the blockchain.

[0225] In step S504, the access device verifies the second access request. If the verification passes, it sends a first query request to the blockchain. The blockchain authenticates the legitimacy of the access device and returns the authentication result to the access device. The first query request includes the access device's identity information. The access device's identity information includes, but is not limited to, the access device's blockchain address and MAC address.

[0226] In step S504, if the first response challenge value and the second challenge value are correct, and the signature information is the signature of the terminal's blockchain address, then the second access request is verified. The access device queries the blockchain for the terminal's record, i.e., the access device sends a first query request to the blockchain. The blockchain then queries the terminal's blockchain address for a list of legitimate shared network users, the terminal's reputation, and whether the account type and balance are sufficient to provide minimum services. This authenticates the terminal's legitimacy and returns the authentication result to the access device.

[0227] In step S505, the terminal sends a second query request to the blockchain. The blockchain verifies the legitimacy of the access device and returns the authentication result to the terminal. The second query request includes the access device's identity information. The blockchain then checks whether the access device is on the list of legitimate shared network users and its credibility, obtaining the authentication result for the access device.

[0228] In step S506, when the terminal confirms that the access device is legitimate, it sends a third access request to the access device; wherein, the third access request includes the blockchain address, Mac address, first response challenge value, third challenge value and corresponding signature information of the terminal.

[0229] The signature information in step S506 is information obtained by signing the terminal's blockchain address, Mac address, first response challenge value, and third challenge value using the private key of the terminal's blockchain address.

[0230] Step S507: The access device receives and verifies the third access request. If the verification passes, it sends an access permission message to the terminal, where the access permission message includes the blockchain address, Mac address, third challenge value, second response challenge value and corresponding signature information of the access device.

[0231] In step S507, the signature information is the information obtained by signing the blockchain address, MAC address, third challenge value, and second response challenge value of the access device using the private key of the access device. If the first response challenge value is correct and the signature information is the signature of the blockchain address of the terminal, the verification of the third access request passes.

[0232] It should be noted that the terminal sends the third access request to the access device in the form of a blockchain transaction, and the third access request is not transmitted on the blockchain.

[0233] Through the above steps S501 to S507, the terminal and the access device achieve two-way authentication in a decentralized manner through blockchain, and the terminal accesses the shared WiFi network and achieves secure access.

[0234] Figure 6 This is a flow chart of another shared WiFi access method provided by an embodiment of the present disclosure. Figure 6 As shown, the terminal and access device implement two-way authentication through smart contracts. The shared WiFi access method includes:

[0235] Step S601: The terminal sends a first access request to the access device, wherein the first access includes (carries) the blockchain address of the terminal and a first challenge value.

[0236] In step S601, when a terminal searches for an access device with an agreed SSID while moving in a shared WiFi network, the terminal sends a first access request to the access device.

[0237] In step S602, the access device sends a first return message to the terminal, wherein the first return message includes the access device's blockchain address, MAC address, first challenge value, first challenge response value, and corresponding signature information. The signature information is obtained by signing the access device's blockchain address, MAC address, first challenge value, and first challenge response value using the private key of the access device's blockchain address.

[0238] In step S602, the first return message carries the first challenge value and the first response challenge value, which helps reduce the number of challenges and thus improve access efficiency. The private key used for the signature is the private key corresponding to the blockchain address of the access device, or the private key corresponding to the public key used for authentication at the blockchain address of the access device registered on the blockchain.

[0239] It should be noted that the access device sends the first return information to the terminal in the form of a blockchain transaction, and the first return information is not transmitted on the blockchain.

[0240] In step S603, the terminal receives the first response information from the access device, verifies the first response information, and if the verification passes, sends a second access request to the access device. The second access request includes the terminal's blockchain address, MAC address, first response challenge value, second challenge value, and corresponding signature information. The signature information is obtained by signing the terminal's blockchain address, MAC address, first response challenge value, and second challenge value using the private key of the terminal's blockchain address, or using the private key corresponding to the public key used for authentication at the terminal's blockchain address registered on the blockchain.

[0241] In step S603, the terminal verifies the first return information, including verifying whether the first challenge value and the first response challenge value are correct, and verifying whether the signature information is the signature of the blockchain address of the access device. If the verification passes, it can be determined that the first return information comes from the access device. If the signature and identity information in the first return information match, and the MAC address used by the access device for sending and receiving messages matches the MAC address of the access device carried in the first return information, the verification of the first return information passes.

[0242] It should be noted that the terminal sends the second access request to the access device in the form of a blockchain transaction, and the second access request is not transmitted on the blockchain.

[0243] In step S604, the access device verifies the second access request. If the verification passes, it sends a first query request to the smart contract. The smart contract authenticates the legitimacy of the access device and returns the authentication result to the access device. The first query request includes the access device's identity information. The access device's identity information includes, but is not limited to, the access device's blockchain address and MAC address.

[0244] In step S604, if the first response challenge value and the second challenge value are correct, and the signature information is the signature corresponding to the terminal's blockchain address, then the second access request is verified. The access device queries the terminal's record in the smart contract, that is, the access device sends a first query request to the smart contract. The smart contract queries the list of legal shared network users based on the terminal's smart contract address, and verifies the terminal's legitimacy by checking the terminal's reputation, account type, and account balance to see if they are sufficient to provide minimum services. The authentication result is then returned to the access device.

[0245] In step S605, if the terminal passes the authentication, the access device sends a release query message to the terminal. At this time, the terminal and the smart contract can send information through the access device.

[0246] In step S605, the release query message includes the access device's identity information, the second challenge value, the second challenge response value, and the corresponding signature information. The signature information is obtained by signing the access device's blockchain address, MAC address, second challenge value, and second challenge response value using the access device's private key.

[0247] It should be noted that the access device sends the release query message to the terminal in the form of a blockchain transaction, and the release query message is not transmitted on the blockchain.

[0248] In step S606, the terminal first verifies the release query message. If the verification passes, it sends a second query message to the smart contract and receives the authentication result returned by the smart contract.

[0249] In step S606, the terminal verifies the second challenge value, second response challenge value, and signature information in the release query message. If the second challenge value and second response challenge value are correct and the signature information corresponds to the blockchain address of the access device, the access device's identity is authenticated. The second query message includes the access device's identity information. After receiving the second query message, the smart contract queries the blockchain record. If the access device is on the list of legitimate shared network users and its credibility meets the preset threshold, the legitimacy of the access device is authenticated and the smart contract returns the authentication result to the access device. In step S606, the access device forwards the communication between the terminal and the access device.

[0250] In step S607, if the terminal confirms that the access device is legitimate, it sends a third access request to the access device; wherein, the third access request includes the terminal's blockchain address, Mac address, second response challenge value, third challenge value and corresponding signature information.

[0251] The signature information in step S607 is information obtained by signing the terminal's blockchain address, Mac address, second response challenge value, and third challenge value using the private key of the terminal's blockchain address.

[0252] Step S608: The access device receives and verifies the third access request. If the verification passes, it sends an access permission message to the terminal, where the access permission message includes the blockchain address, Mac address, third challenge value and corresponding signature information of the access device.

[0253] In step S608, the signature information is obtained by signing the blockchain address, MAC address, and third challenge value of the access device using the private key of the access device. If the second response challenge value and the third challenge value are correct, and the signature information is the signature corresponding to the blockchain address of the terminal, the third access request is verified.

[0254] It should be noted that the terminal sends the third access request to the access device in the form of a blockchain transaction, and the third access request is not transmitted on the blockchain.

[0255] The access device sends an access permission message to the terminal in the form of a blockchain transaction, and the access permission message is not transmitted on the blockchain.

[0256] Through the above steps S601 to S608, the terminal and the access device achieve two-way authentication in a decentralized manner, and the terminal accesses the shared WiFi network and achieves secure access.

[0257] When a terminal authenticates an access device through a smart contract, the query transaction sent by the smart contract to the terminal may be forged, which has a significant impact on the terminal's security. Therefore, the disclosed embodiments also provide another method for authenticating an access device by a terminal, in which a Public Authentication Server (PAS) forwards the interaction information between the terminal and the smart contract.

[0258] Figure 7 This is a flow chart of another authentication method of a terminal to an access device according to an embodiment of the present disclosure. Figure 7 As shown in the figure, the terminal authentication process for the access device includes:

[0259] Step S701: The terminal sends a second query request to a public authentication server (PAS), wherein the second query request includes identity information of an access device.

[0260] It should be noted that before step S701, the terminal has sent a first access request and a second access request to the access device, the access device has sent a first return message to the terminal, and the access device has released the terminal's query information, that is, the information interaction similar to steps S601 to S605 has been completed. To save space, it will not be repeated here.

[0261] In step S702, the PAS forwards the second query request to the smart contract. The smart contract queries the records in the blockchain to authenticate the access device and obtains the authentication result.

[0262] In the disclosed embodiment, PAS can determine the query result of the smart contract based on the consensus of the entire blockchain.

[0263] In step S703, the smart contract sends the authentication result to PAS.

[0264] Step S704: The PAS forwards the authentication result to the terminal, and the terminal obtains the authentication result of the access device.

[0265] After step S704, the terminal sends a third access request to the access device, and the access device sends an access permission message to the terminal, which is similar to step S607 and step S608. To save space, they are not repeated here.

[0266] It should be noted that any protocol can be used for communication between the terminal and PAS, such as TLS, HTTPs, or even direct blockchain transactions, but query transactions are not uploaded to the chain.

[0267] In the embodiment of the present disclosure, during the access process between the terminal and the access device, the terminal and the access device may agree on a payment method, for example, payment based on the service duration period, payment based on the forwarded data volume period, and other payment methods.

[0268] After the terminal and access device complete the connection, when the incremental payment reaches the agreed payment threshold, the payment is triggered, the terminal sends the payment credentials to the access device, and the access device collects the payment credentials.

[0269] In some embodiments, after the terminal and the access device complete access, the access device continuously monitors the status of the terminal, for example, the terminal account balance and creditworthiness. When an abnormal situation occurs, for example, after the agreed number of payment cycles arrives, the terminal does not send the payment credentials, the access device submits the last payment credentials to the blockchain for settlement and closes the terminal's access at the same time.

[0270] In some embodiments, the blockchain can also set up records of penalties and credit score deductions for behaviors such as abnormal offline access devices and terminal timeouts without payment. It can also continuously increase the credit score records of access devices and terminals based on the cumulative amount of services and payments completed honestly.

[0271] In some embodiments, when the terminal's access ends or an abnormal situation occurs, the terminal disconnects from the access device, and the access device stops providing access services to the terminal.

[0272] Figure 8 This is another authentication flow chart provided by the embodiment of the present disclosure. Figure 8 As shown in the figure, the terminal authentication process for the access device includes:

[0273] In step S801, the terminal sends a first access request to the access device, wherein the first access includes (carries) the blockchain address of the terminal and a first challenge value.

[0274] In step S802, the access device sends a first return message to the terminal, where the first return message includes the access device's blockchain address, Mac address, first challenge value, first challenge response value, and corresponding signature information. The signature information is obtained by signing the access device's blockchain address, Mac address, first challenge value, and first challenge response value using the private key of the access device's blockchain address. It should be noted that the access device sends the first return message to the terminal in the form of a blockchain transaction, and the first return message is not transmitted on the blockchain.

[0275] In step S803, the terminal receives the first response information from the access device, verifies the first response information, and if the verification passes, sends a second access request to the access device, where the second access request includes the terminal's blockchain address, MAC address, first response challenge value, second challenge value, and corresponding signature information. The signature information is information obtained by signing the terminal's blockchain address, MAC address, first response challenge value, and second challenge value using the private key of the terminal's blockchain address.

[0276] The terminal verifies the first returned information, including verifying whether the first challenge value and the first response challenge value are correct, and verifying whether the signature information is the signature of the blockchain address of the access device. If the verification passes, it can be determined that the first returned information originated from the access device. It should be noted that the terminal sends the second access request to the access device in the form of a blockchain transaction, and the second access request is not transmitted on the blockchain.

[0277] In step S804, the access device verifies the second access request. If the verification passes, it sends a first query request to the blockchain. The blockchain authenticates the legitimacy of the terminal and returns the authentication result to the access device. The first query request includes the terminal's identity information. This terminal's identity information includes, but is not limited to, the terminal's blockchain address, Mac address, and physical address.

[0278] In step S804, if the first response challenge value and the second challenge value are correct, and the signature information is the signature of the terminal's blockchain address, then the second access request is verified. The access device queries the blockchain for the terminal's record, i.e., the access device sends a first query request to the blockchain. The blockchain then queries the terminal's identity information to verify the legitimacy of the terminal by checking the list of legal shared network users, the terminal's reputation, and whether the account type and balance are sufficient to provide minimum services. The blockchain then verifies the legitimacy of the terminal and returns the authentication result to the access device.

[0279] In step S805, when the access device determines that the terminal is legitimate, it sends an open access channel message to the terminal, which is signed by the access device using its own private key.

[0280] It should be noted that the access device sends the open access channel message to the terminal in the form of a blockchain transaction, and the open access channel message is not transmitted on the blockchain.

[0281] In step S806, after receiving the open access channel message, the terminal sends a second query request to the blockchain to query the legitimacy of the access device.

[0282] The terminal can forward the query request to the blockchain address, smart contract address or PAS address with the help of the access device, that is, forward the second query request to the blockchain address, smart contract address or PAS address through the access device, and forward the corresponding query result through the access device.

[0283] In step S807, the terminal receives the query result forwarded by the access device, and if the query result shows that the access device is legal, the terminal sends a service message to the access device.

[0284] Through the above steps S801 to S807, the terminal and the access device achieve two-way authentication in a decentralized manner through blockchain, and the terminal accesses the shared WiFi network and achieves secure access.

[0285] Steps S801 to S803 essentially involve the terminal and access device exchanging their identities. However, in a wireless environment, there may be devices that copy messages and attempt to replay them to impersonate the access device or terminal. To prevent this, both parties use a challenge-response mechanism. The response mechanism for challenges uses the private key corresponding to their own blockchain address to sign the challenge. The characteristic of digital signatures is that only the entity with the private key can sign the challenge. Therefore, an imposter cannot generate responses to other challenges. Because each interactive message contains a random, non-repeating challenge, replay attacks by imposters are easily filtered out. The receiving end determines the legitimacy of the challenge response by checking whether it corresponds to the challenge it previously sent and whether the challenge response is signed by the other party.

[0286] For the access device, steps S801 to S803 are to enable the access device to obtain the terminal's identification (blockchain address and MAC), and the challenge and return can ensure that the terminal's application is the latest and not a copy; in addition, obtaining the MAC can determine that the application message corresponds to the MAC address of the actual sent and received message, that is, the other party of communication can be determined at the access link layer.

[0287] For the terminal, steps S801 to S803 are to obtain the identification (blockchain address and MAC) of the access device, challenge and return to ensure that the message returned by the other party is the latest and not a copy; the access MAC can determine the other party of communication at the access link layer.

[0288] Figure 9 A block diagram of an electronic device provided in an embodiment of the present disclosure.

[0289] Reference Figure 9 An embodiment of the present disclosure provides an electronic device, comprising: at least one processor 901; at least one memory 902; and one or more I / O interfaces 903 connected between the processor 901 and the memory 902; wherein the memory 902 stores one or more computer programs executable by the at least one processor 901, and the one or more computer programs are executed by the at least one processor 901 to enable the at least one processor 901 to perform the above-mentioned shared WiFi access method.

[0290] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor / processing core, implements the above-mentioned shared WiFi access method. The computer-readable storage medium may be a volatile or non-volatile computer-readable storage medium.

[0291] It will be understood by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In a hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable storage medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium).

[0292] As is well known to those skilled in the art, the term computer storage media includes volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information (such as computer-readable program instructions, data structures, program modules or other data). Computer storage media includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), static random access memory (SRAM), flash memory or other memory technology, portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical disc storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those skilled in the art, communication media typically contains computer-readable program instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0293] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in the computer-readable storage medium in each computing / processing device.

[0294] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, and conventional procedural programming languages ​​such as "C" language or similar programming languages. Computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., utilizing an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be personalized by utilizing the state information of the computer-readable program instructions. The electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.

[0295] The computer program product described herein may be implemented in hardware, software, or a combination thereof. In one embodiment, the computer program product is implemented as a computer storage medium. In another embodiment, the computer program product is implemented as a software product, such as a software development kit (SDK).

[0296] Various aspects of the present disclosure are described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.

[0297] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device is generated that implements the functions / actions specified in one or more blocks in the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, where these instructions cause the computer, programmable data processing device, and / or other device to operate in a specific manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks in the flowchart and / or block diagram.

[0298] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more blocks in the flowchart and / or block diagram.

[0299] The flow charts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the systems, methods and computer program products according to multiple embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a part of a module, program segment or instruction, and a part of a module, program segment or instruction includes one or more executable instructions for realizing the prescribed logical function. In some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart, can be implemented by a dedicated hardware-based system that performs the prescribed function or action, or can be implemented by a combination of dedicated hardware and computer instructions.

[0300] Example embodiments have been disclosed herein, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly indicated, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, it will be understood by those skilled in the art that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.

Claims

1. A shared WiFi access method, characterized in that: Applicable to access devices, including: receiving a first access request from a terminal, and sending first return information to the terminal; wherein the first access request includes identity information of the terminal and corresponding signature information, and the first return information includes identity information of the access device and corresponding signature information; receiving a second access request from the terminal, and verifying the second access request based on the signature information of the terminal; wherein the second access request is issued by the terminal when the first return information is verified successfully based on the signature information of the access device, and the second access request includes the identity information of the terminal and the corresponding signature information; If the second access request passes the verification, sending a first query request to a preset address to authenticate the legitimacy of the terminal; wherein the first query request includes the identity information of the terminal, and the preset address includes one or more of a blockchain and a smart contract; In the case that the legitimacy authentication of the terminal is passed, an open access channel message is sent to the terminal.

2. The method according to claim 1, characterized in that The step of sending a first query request to a preset address to authenticate the legitimacy of the terminal when the second access request passes verification includes: If the second access request passes the verification, sending a first query request to the preset address, so that the preset address obtains a first query result according to the identity information of the terminal; wherein the first query request includes the identity information of the terminal; A first query result returned by the preset address is received, and based on the first query result, whether the terminal is legitimate is authenticated.

3. The method according to claim 1, characterized in that The first access request and the second access request further include a challenge value; After receiving the second access request from the terminal, the method further includes: The second access request is verified based on the challenge value and the corresponding signature information.

4. The method according to claim 1, wherein After sending the first query request to a preset address to authenticate the legitimacy of the terminal if the second access request passes verification, the method further includes: A release query message is sent to the terminal, so that the terminal can authenticate the legitimacy of the access device to the preset address through the access device.

5. The method according to any one of claims 1 to 4, characterized in that The identity information of the terminal includes one or more of the blockchain address of the terminal and the MAC address of the terminal; The characteristic information of the access device includes one or more of the blockchain address of the access device and the MAC address of the access device.

6. The method according to any one of claims 1 to 4, characterized in that: After sending an open access channel message to the terminal when the legitimacy authentication of the terminal passes, the method further includes: receiving a third access request from the terminal, and sending an access permission message to the terminal if the terminal is legitimate; wherein the third access request is sent by the terminal if the legitimacy of the access device at the preset address is authenticated successfully, and the third access request includes the identity information of the terminal and corresponding signature information; Alternatively, receiving a second query request sent by the terminal to query the legitimacy of the access device, and forwarding the second query request to the preset address; and receiving a verification result returned by the preset address, and forwarding the verification result to the terminal.

7. The method according to claim 6, characterized in that When the access device receives the first access request sent by the terminal, the access device sends the first return information to the terminal in the form of a blockchain transaction; And / or, when the access device receives the third access request sent by the terminal, the access device sends the access permission message to the terminal in the form of a blockchain transaction.

8. A shared WiFi access method, characterized in that: Applied to terminals, including: Sending a first access request to the access device; wherein the first access request includes the identity information of the terminal and corresponding signature information; receiving first return information sent by the access device and verifying the first return information; wherein the first return information is sent by the access device when it receives the first access request, and the first return information includes the identity information of the access device and the corresponding signature information; Sending a second access request to the access device; wherein the second access request includes the identity information of the terminal and corresponding signature information, so that the access device can authenticate the legitimacy of the terminal at a preset address based on the identity information of the terminal, and the preset address includes one or more of a blockchain and a smart contract; If the first returned information is verified to be successful, sending a second query request to a preset address to authenticate the legitimacy of the access device; wherein the second query request includes the identity information of the access device; Receive an open access channel message sent by the access device; wherein the open access channel message is sent by the access device when it determines that the terminal is legitimate.

9. The method according to claim 8, characterized in that The step of sending a second query request to a preset address to authenticate the legitimacy of the access device when the first returned information verification passes includes: If the first returned information passes the verification, sending a second query request to a preset address, so that the preset address obtains a second query result according to the identity information of the access device; wherein the second query request includes the identity information of the access device; A second query result returned by the preset address is received, and the legitimacy of the access device is authenticated based on the second query result.

10. The method according to claim 8, characterized in that The sending of the second query request to the preset address includes: The second query request is forwarded to the preset address through at least one public authentication server.

11. The method according to claim 8, characterized in that The preset address is the access device address; The step of sending a second query request to a preset address to authenticate the legitimacy of the access device when the first returned information verification passes includes: If the first returned information passes verification, sending a second query request to the access device address; Receive block information of the access device, and authenticate the legitimacy of the access device based on block header information in the block information and using a Merkle tree.

12. The method according to claim 8, characterized in that Before sending the second query request to the preset address, the method further includes: Receive a release query message; wherein, the release query message is sent when the access device determines that the terminal is legal.

13. The method according to claim 12, characterized in that After sending the second query request to the preset address, the method further includes: If the access device is legitimate, sending a third access request to the access device; wherein the third access request includes the identity information of the terminal and the corresponding signature information; receiving an access permission message sent by the access device; wherein the access permission message is sent by the access device when the access device determines that the terminal is legitimate; Alternatively, if the access device is legal, the service flow is sent to the access device.

14. The method according to claim 13, characterized in that The first return information and the access permission message also include a response challenge value; After receiving the first return information sent by the access device, the method further includes: The first returned information and the access permission message are verified based on the response challenge value.

15. The method according to any one of claims 8 to 9, characterized in that: The identity information of the terminal includes one or more of the blockchain address of the terminal and the MAC address of the terminal; The characteristic information of the access device includes one or more of the blockchain address of the access device and the MAC address of the access device.

16. A shared WiFi access device, characterized in that: Applicable to access devices, including: A first receiving module is configured to receive a first access request from a terminal, wherein the first access request includes identity information of the terminal and corresponding signature information; A first sending module is configured to send first return information to the terminal; wherein the first return information includes the identity information of the access device and the corresponding signature information; The first receiving module is further configured to receive a second access request from the terminal, wherein the second access request is issued by the terminal when the second access request is verified based on the signature information of the access device, and the second access request includes the identity information of the terminal and the corresponding signature information; a first verification module, configured to verify the second access request based on the signature information of the terminal; The first sending module is further configured to, if the second access request passes verification, send a first query request to a preset address to authenticate the legitimacy of the terminal; wherein the first query request includes identity information of the terminal, and the preset address includes one or more of a blockchain and a smart contract; The first sending module is further configured to send an open access channel message to the terminal if the terminal is legal.

17. A shared WiFi access device, characterized in that: Applied to terminals, including: A second sending module is configured to send a first access request to the access device; wherein the first access request includes the identity information of the terminal; A second receiving module is configured to receive first return information sent by the access device; wherein the first return information is sent by the access device when receiving the first access request, and the first return information includes identity information of the access device and corresponding signature information; A second verification module is configured to verify the first returned information; The second sending module is further configured to send a second access request to the access device; wherein the second access request includes the identity information of the terminal and corresponding signature information, so that the access device can authenticate the legitimacy of the terminal at a preset address based on the identity information of the terminal, and the preset address includes one or more of a blockchain and a smart contract; The second sending module is further configured to send a second query request to a preset address to authenticate the legitimacy of the access device if the first return information verification passes; wherein the second query request includes the identity information of the access device and the corresponding signature information; The second receiving module is configured to receive an open access channel message sent by the access device; wherein the open access channel message is sent by the access device when it determines that the terminal is legitimate.

18. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs executable by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to perform the shared WiFi access method according to any one of claims 1 to 7, and / or the shared WiFi access method according to any one of claims 8 to 15.

19. A computer-readable storage medium having a computer program stored thereon, characterized in that: When executed by a processor, the computer program implements the shared WiFi access method according to any one of claims 1 to 7, and / or the shared WiFi access method according to any one of claims 8 to 15.

Citation Information

Patent Citations

  • Authentication method and apparatus and electronic device

    CN105636037A