Network distribution method, device, system, apparatus and storage medium
By receiving and encrypting the probe response frames of WiFi devices and using identity keys to achieve network configuration without disconnecting the current connection, the problem of high network configuration failure rate in complex network environments is solved, the success rate and speed of network configuration are improved, and the user experience is enhanced.
Patent Information
- Application Number
- CN202110583688.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-05-27
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2041-05-27
AI Technical Summary
The existing WiFi device configuration mode has a high failure rate in complex network environments and requires disconnecting the current connection, affecting the user experience.
By receiving the detection response frame of the device to be connected to the network, the attribute information is used to determine the identity key and encrypt the router's network configuration information. Without disconnecting the current connection, it is directly sent to the device to be connected to the network for access.
It improves the success rate of network configuration, reduces frame interaction, and improves network configuration speed and user experience.
Smart Images

Figure CN115412887B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application generally relates to the technical field of wireless communication, and particularly relates to a network configuration method, device, system, equipment and storage medium. BACKGROUND
[0002] With the progress of science and technology and the continuous development of computer technology, smart phones, smart televisions and other smart devices have been widely popularized and applied. Among them, the network connection of smart devices is an essential condition for smart devices to realize various intelligent needs, and therefore higher requirements are put forward for network configuration technology and operability.
[0003] At present, the network configuration of WiFi devices in the related art includes three modes, namely, STA mode, AP mode and AP+STA mode. However, the three modes all need a station (Station, STA) to be connected to an access point (Access Point, AP) to perform network configuration information interaction, and in the process of network configuration, there are many frame interactions, and the network configuration failure rate is high in a complex network environment. Moreover, when the STA is connected to the AP, the current WiFi connection needs to be disconnected, which affects the user experience. SUMMARY
[0004] In view of the above defects or deficiencies in the prior art, it is desirable to provide a network configuration method, device, system, equipment and storage medium.
[0005] In a first aspect, the present application provides a network configuration method applied to a network configuration device, which comprises:
[0006] receiving a probe response frame sent by the device to be networked, wherein the probe response frame comprises a first probe information field, the first probe information field is filled with attribute information of the device to be networked, and a second probe information field comprises preset reserved information;
[0007] determining an identity key of the device to be networked based on the attribute information;
[0008] encrypting network configuration information of a router according to the identity key, obtaining encrypted network configuration information, and sending the encrypted network configuration information to the device to be networked, so that the device to be networked accesses the router according to the encrypted network configuration information.
[0009] In a second aspect, the present application provides a network configuration method applied to a device to be networked, which comprises:
[0010] sending a probe response frame containing attribute information of the device to be networked, so that a network configuration device determines an identity key of the device to be networked based on the attribute information;
[0011] receiving encrypted network configuration information sent by the network configuration device;
[0012] decrypt the encrypted network configuration information to obtain the network configuration information;
[0013] access the router corresponding to the network configuration information according to the network configuration information.
[0014] In a third aspect, the present application provides a network configuration device, which comprises:
[0015] a receiving module configured to receive a probe response frame sent by the device to be networked, the probe response frame comprising a first probe information field, the first probe information field being filled with attribute information of the device to be networked, and the second probe information field containing preset reserved information;
[0016] a determining module configured to determine an identity key of the device to be networked based on the attribute information;
[0017] a processing module configured to encrypt network configuration information of a router according to the identity key, to obtain encrypted network configuration information and send the encrypted network configuration information to the device to be networked, so that the device to be networked accesses the router according to the encrypted network configuration information.
[0018] In a fourth aspect, the present application provides a network configuration device, which comprises:
[0019] a sending module configured to send a probe response frame containing attribute information of a device to be networked, so that a network configuration device determines an identity key of the device to be networked based on the attribute information;
[0020] a receiving module configured to receive encrypted network configuration information sent by the network configuration device;
[0021] an obtaining module configured to decrypt the encrypted network configuration information to obtain the network configuration information;
[0022] an accessing module configured to access a router corresponding to the network configuration information according to the network configuration information.
[0023] In a fifth aspect, the present application provides a network configuration system, which comprises a network configuration device, a device to be networked and a router;
[0024] the device to be networked is configured to send a probe response frame containing attribute information of the device to be networked, and receive encrypted network configuration information sent by the network configuration device, decrypt the encrypted network configuration information to obtain the network configuration information, and access a router corresponding to the network configuration information according to the network configuration information;
[0025] The network device is configured to receive the probe response frame sent by the device to be commissioned, determine the identity key of the device to be commissioned based on the attribute information, encrypt the network configuration information of the router according to the identity key, obtain the encrypted network configuration information, and send the encrypted network configuration information to the device to be commissioned.
[0026] In a sixth aspect, an embodiment of the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the network configuration method described above when executing the program.
[0027] In a seventh aspect, an embodiment of the present application provides a computer readable storage medium, which stores a computer program for implementing the network configuration method described above.
[0028] The network configuration method, device, system, equipment and storage medium provided by the embodiments of the present application receive the probe response frame sent by the device to be commissioned, the probe response frame includes a first probe information field and a second probe information field, the attribute information of the device to be commissioned is filled in the first probe information field, the identity key of the device to be commissioned is determined based on the attribute information, the network configuration information of the router is encrypted according to the identity key, the encrypted network configuration information is obtained and sent to the device to be commissioned, so that the device to be commissioned accesses the router according to the encrypted network configuration information. The scheme does not need to disconnect the current router connection of the network device, only needs to receive the probe response frame sent by the device to be commissioned, so that the attribute information of the device to be commissioned can be automatically obtained, and then the device to be commissioned accesses the router, the frame interaction is less, the network configuration success rate is improved, and the network configuration speed is accelerated, so that the user experience is greatly improved. BRIEF DESCRIPTION OF DRAWINGS
[0029] Other characteristics, objects and advantages of the present application will become more apparent from the following detailed description of the non-restrictive embodiments, made with reference to the accompanying drawings:
[0030] Figure 1 The structure diagram of the network configuration system provided by the embodiments of the present application is shown;
[0031] Figure 2 The flowchart of the network configuration method provided by the embodiments of the present application is shown;
[0032] Figure 3 The structure diagram of the network configuration method provided by the embodiments of the present application is shown;
[0033] Figure 4 The flowchart of the network configuration method provided by the embodiments of the present application is shown;
[0034] Figure 5 The interaction diagram of the network configuration method provided by the embodiments of the present application is shown;
[0035] Figure 6 A structural schematic diagram of a network configuration device provided for an embodiment of the present application is shown in FIG. 1.
[0036] Figure 7 A structural schematic diagram of a network configuration device provided for another embodiment of the present application is shown in FIG. 2.
[0037] Figure 8 A structural schematic diagram of a computer device provided for an embodiment of the present application is shown in FIG. 3. DETAILED DESCRIPTION
[0038] The present application will be further described below in conjunction with the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related application, and not to limit the application. In addition, it should be noted that only the parts related to the application are shown in the drawings for ease of description.
[0039] It should be noted that the embodiments in the present application and the features in the embodiments can be combined with each other without conflict. The present application will be described in detail below with reference to the accompanying drawings and in conjunction with the embodiments.
[0040] It can be understood that with the continuous development of the network, the use of WiFi in daily life is more and more common. Among them, the networking of Internet of Things (IOT) devices generally depends on WiFi connection, but in actual application, IOT devices often do not carry a screen or a key for human-computer interaction, so users cannot directly set the network configuration information of the device to be networked by manual input, so it is necessary to use wireless network configuration or other auxiliary means to let the device to be networked obtain the network configuration information, which can include the SSID and password of the wireless access point AP. Among them, WiFi network configuration refers to providing the SSID and password to the WiFi module externally, so that the WiFi module can connect to the specified hotspot or router and join the relevant WiFi network established by the latter.
[0041] Currently, related technologies include three modes for Wi-Fi device configuration: STA configuration mode, AP configuration mode, and AP+STA configuration mode. Taking the AP configuration mode as an example, the device to be configured starts in AP mode. The user device Provisioner discovers nearby devices to be configured, disconnects the current connection with the router, and connects to the wireless access point (AP) of the device to be configured, allowing the device to obtain configuration information and completing the configuration process. However, this mode involves a high number of frame interactions during the configuration process, resulting in a high configuration failure rate in complex network environments. Furthermore, since the user device Provisioner can only connect to one AP at a time, it needs to disconnect the current AP connection before connecting to the AP of the device to be configured. During this process, the user device will be unavailable, impacting the user experience.
[0042] Based on the above-mentioned defects, the present application provides a network configuration method. Compared with the existing technology, this solution does not require the network configuration device to disconnect the current router connection. It only needs to receive the detection response frame sent by the device to be connected to the network, so that it can automatically obtain the attribute information of the device to be connected to the network, and then enable the device to be connected to the network to access the router. This process has fewer frame interactions, which not only improves the success rate of network configuration, but also speeds up the network configuration speed, thereby greatly improving the user experience.
[0043] The network configuration method provided in the embodiment of the present application can be applied to Figure 1 The distribution network system shown.
[0044] Figure 1 This is a schematic diagram of the structure of the distribution network system provided in the embodiment of the present application. Figure 1 As shown, the system includes: a network distribution device 10, a device to be connected to the network 20 and a router 30.
[0045] The above-mentioned network distribution device 10 may include user terminal devices such as smart phones and tablet computers. The network distribution device 10 can be connected to a wireless network through network devices such as routers. For example, the user's mobile phone has been connected to the home WiFi network through the wireless router installed at home.
[0046] Optionally, the network configuration device 10 may be a terminal device without a human-computer interaction screen, such as a smart refrigerator or smart speaker that is already connected to a wireless network. In this case, the network configuration device may locally store the network configuration information of the router it is connected to, so as to provide network configuration for devices that are not yet connected to the network and are waiting to be connected. It should be noted that the network configuration device 10 may run a network configuration application, and network configuration for the devices 20 waiting to be connected may be implemented through this network configuration application.
[0047] The to-be-networked device 20 can be various IOT devices supporting WiFi functions such as a smart refrigerator, a smart speaker, a robot, a smart air purifier, a smart electric fan, a smart air conditioner, a smart camera, a smart socket, and the like, and can be mobile or fixed. The to-be-networked device 20 has not been connected to a certain wireless network, and is thus referred to as a to-be-networked device.
[0048] The commissioning device 10 and the to-be-networked device 20 can be two devices belonging to the same user, and the main difference between the two devices is that the commissioning device has accessed a wireless network, while the to-be-networked device has not accessed a wireless network.
[0049] The router 30 is also referred to as a gateway device, and is configured to store and forward packets between different networks.
[0050] Further, the system can further include a server, which can be a separate server or a server cluster located in the cloud.
[0051] For ease of understanding and description, the commissioning method, device, system, and storage medium provided by the embodiments of the present application are described below. Figure 2 to Figure 8 The commissioning method, device, system, and storage medium provided by the embodiments of the present application are described in detail.
[0052] Figure 2 As shown in the flowchart of the commissioning method provided by the embodiments of the present application, the method is applied to a commissioning device, such as a smart phone or a smart tablet computer. Figure 2 As shown in the flowchart, the method includes the following steps.
[0053] S101, receiving a probe response frame sent by a to-be-networked device, the probe response frame including a first probe information field, the first probe information field being filled with attribute information of the to-be-networked device, and a second probe information field including preset reserved information.
[0054] Specifically, the to-be-networked device can have an AP mode, and when the to-be-networked device needs to be commissioned, the AP mode can be started. In the AP mode, the to-be-networked device continuously detects probe frame signals around. The commissioning device can send a probe request frame including a probe information field to the to-be-networked device, and the probe request frame is used to probe available basic service set (BSS) networks around and discover the to-be-networked device.
[0055] It should be noted that the range covered by an access point AP is referred to as a BSS, each BBS is uniquely identified by a service set identifier (Service Set Identifier, SSID), and the BSS is a basic component in the 802.11 standard protocol network, which is composed of a group of mutually communicating workstations. The SSID technology can divide a wireless local area network into several sub-networks that require different identity authentication. Each sub-network requires independent identity authentication, and only users who pass the identity authentication can enter the corresponding sub-network, thereby preventing unauthorized users from entering the network.
[0056] In the 802.11 standard protocol definition, a vendor-defined field Vendor IE can be specified, and the frame format of the vendor-defined field Vendor IE can be seen from the following table:
[0057]
[0058] In the process of the probe request frame and the probe response frame, the Vendor IE field can be used to exchange information, thereby completing data communication. The Vendor IE field includes a first probe information field and a second probe information field. The first probe information field is filled with attribute information of the device to be networked, for example, the Payload field. The second probe information field includes preset reserved information, for example, a fixed value Element ID, a message length Length, a manufacturer number OUI, and the like. The service data can be filled into the Payload field of the above-mentioned vendor-defined field Vendor IE, and the frame format of the service data of the Payload field can be seen from the following table:
[0059] byte offset field name length value 0 version 2 bytes protocol version, value 0x2131, network order 2 length 2 bytes total length of the packet, network order 4 did 8 bytes device did, network order 12 ts 4 bytes device UTC timestamp, seconds, network order 16 sign 16 bytes data integrity signature 32 data N bytes encrypted payload, N < 234
[0060] In this step, the user can start the network configuration application in the network configuration device, click the function button similar to "start network configuration" in the machine, and send a probe request frame to the device to be networked to discover the surrounding device to be networked. The other IOT device, for example, a smart robot, can also periodically initiate a search for the device to be networked.
[0061] It should be noted that the first probe information field included in the probe request frame can include the following table content:
[0062] byte offset field name length value 0 version 2 bytes protocol version, value 0x2131, network order 2 length 2 bytes total length of the packet, network order 4 did 8 bytes 0xFF....FF 12 ts 4 bytes 0xFF....FF 16 sign 16 bytes 0xFF....FF
[0063] The first probe information field agrees that when the relevant field is all FF, it means requesting the value corresponding to the field, such as did is 0xFF....FF, which means requesting the did of the device. Wherein, did means requesting to obtain the device to be networked, ts means the time stamp corresponding to the current time, and sign means the corresponding signature.
[0064] After the device to be networked receives the probe request frame, the attribute information of the device to be networked is filled in the first probe information field, and a probe response frame is obtained based on the second probe information field, so that the attribute information of the device to be networked is obtained by the network configuration device. The first probe information field filled with the attribute information of the device to be networked can include the following table content:
[0065] byte offset field name length value 0 version 2 bytes protocol version, value 0x2131, network order 2 length 2 bytes total length of the packet, network order 4 did 8 bytes device did, network order 12 ts 4 bytes device UTC timestamp, seconds, network order 16 sign 16 bytes random token generated by the device
[0066] S102, determining the identity key of the device to be networked based on the attribute information.
[0067] The attribute information of the device to be networked includes device to be networked identifier did, time stamp ts, and verification key token.
[0068] After obtaining the attribute information of the device to be networked, the network configuration device can determine the security level and verification key token of the device to be networked based on the attribute information. When the security level is greater than the preset level, the verification key is obtained according to the attribute information to determine the identity key of the device to be networked; when the security level is less than or equal to the preset level, the verification key is determined as the identity key of the device to be networked. Wherein, the preset level can be a security level determined according to actual experience value.
[0069] For example, when the device to be networked is a smart camera, a smart door lock or other high security product greater than the preset level, the verification key needs to be obtained according to the attribute information to determine the identity key of the device to be networked; for example, for a temperature and humidity sensor or other low security product with a security level less than or equal to the preset level, the verification key can be directly determined as the corresponding identity key.
[0070] Optionally, on the basis of the above embodiment, as shown in Figure 3 When the security level is greater than the preset level, the identity key of the device to be networked can be determined by the following steps, which include:
[0071] S201, determining the device to be networked identifier from the attribute information of the device to be networked.
[0072] S202, performing security verification on the device to be networked based on the device to be networked identifier and the preset verification library.
[0073] S203, when the verification is passed, obtaining the verification key corresponding to the device to be networked.
[0074] S204, the preset algorithm is used to process the check key and the verification key, and the identity key of the to-be-networked device is obtained.
[0075] Specifically, after obtaining the attribute information of the to-be-networked device, the network configuration device can send the attribute information to the cloud, determine the to-be-networked device identifier from the attribute information of the to-be-networked device through the cloud, and perform security check on the to-be-networked device based on the to-be-networked device identifier and the preset check library.
[0076] In the process of security check, it can be judged whether the to-be-networked device identifier is legal first, and when it is determined that the to-be-networked device identifier is legal, it is checked from the preset check library whether there is a check key corresponding to the to-be-networked device identifier; when it is determined that the to-be-networked device identifier is not legal, the to-be-networked device is not configured, and if the check key corresponding to the to-be-networked device identifier is found in the preset check library, it is determined that the to-be-networked device passes the check, and if not, it is determined that the to-be-networked device does not pass the check.
[0077] It can be understood that the cloud or the network configuration device pre-stores a preset check library, and the preset check library stores the mapping relationship between the to-be-networked device identifier did and the check key key. Based on the mapping relationship, the cloud can obtain the check key corresponding to the to-be-networked device identifier did based on the to-be-networked device identifier did.
[0078] When the check passes, the check key corresponding to the to-be-networked device can be obtained, and then the preset algorithm is used to process the check key key and the verification key token, and the identity key of the to-be-networked device is obtained, for example, the identity key of the to-be-networked device can be obtained by using the HKDF (HMAC-based KDF) algorithm. The HKDK algorithm is a key derivation function based on HMAC, which can derive one or more keys with cryptographic strength based on the original key.
[0079] S103, encrypt the network configuration information of the router according to the identity key, obtain the encrypted network configuration information, and send it to the to-be-networked device, so that the to-be-networked device accesses the router according to the encrypted network configuration information.
[0080] After obtaining the identity key, the network configuration device can construct the network configuration information, and the format of the network configuration information is as follows:
[0081]
[0082]
[0083] Wherein, id is a message identifier, ssid represents a wireless access point identifier, for example, a router identifier, uid represents a user identifier, method represents a method declaration format in a programming language, passwd represents a user password, and params represents a keyword in the method declaration, which can be understood as a computer function. The configuration device encrypts the configuration information of the router according to the identity key, thereby obtaining encrypted configuration information, and sends the encrypted configuration information to the device to be networked. The device to be networked can reply to the following format content, indicating that the encrypted configuration information is obtained successfully:
[0084]
[0085] Wherein, id represents a message identifier, and result represents a result of whether the device to be networked receives the configuration information. After obtaining the encrypted configuration information, the device to be networked is enabled to access the corresponding router according to the encrypted configuration information.
[0086] The configuration method provided in the embodiment receives a probe response frame sent by the device to be networked, the probe response frame includes a first probe information field and a second probe information field, the first probe information field is filled with attribute information of the device to be networked, the identity key of the device to be networked is determined based on the attribute information, the configuration information of the router is encrypted according to the identity key, the encrypted configuration information is obtained and sent to the device to be networked, and the device to be networked is enabled to access the router according to the encrypted configuration information. The scheme does not need the configuration device to disconnect the current router connection, only needs to receive the probe response frame sent by the device to be networked, thereby automatically obtaining the attribute information of the device to be networked, and enabling the device to be networked to access the router. The frame interaction is less, the configuration success rate is improved, the configuration speed is accelerated, and the user experience is greatly improved.
[0087] Figure 4 A flowchart of a configuration method provided in the embodiment is shown in FIG. 1. Figure 4 As shown in FIG. 1, the method can be executed by the device to be networked, and includes the following steps.
[0088] S301, a probe response frame containing attribute information of the device to be networked is sent, so that the configuration device determines the identity key of the device to be networked based on the attribute information.
[0089] Specifically, the device to be networked can open an AP mode, and in the AP mode, the device to be networked continuously detects a probe frame signal around. When the device to be networked receives a probe request frame sent by the network configuration device, the probe request frame contains a first probe information field and a second probe information field, the device to be networked discovers that it is not configured, parses the probe request frame, fills the attribute information of the device to be networked into the first probe information field, and generates a probe response frame based on the second probe information field.
[0090] The device to be networked sends the probe response frame containing the attribute information of the device to be networked to the network configuration device, so that the network configuration device determines the identity key of the device to be networked based on the attribute information. Wherein, the network configuration device can determine the security level and the verification key of the device to be networked based on the attribute information; when the security level is greater than the preset level, the verification key is obtained based on the attribute information to determine the identity key of the device to be networked; when the security level is not greater than the preset level, the verification key is determined as the identity key of the device to be networked. The network configuration device encrypts the obtained network configuration information by using the identity key to obtain encrypted network configuration information, and sends the encrypted network configuration information to the device to be networked.
[0091] S302, receiving the encrypted network configuration information sent by the network configuration device.
[0092] S303, decrypting the encrypted network configuration information to obtain the network configuration information.
[0093] S304, accessing the router corresponding to the network configuration information according to the network configuration information.
[0094] In this step, after the device to be networked receives the encrypted network configuration information, the device to be networked decrypts the encrypted network configuration information to obtain the network configuration information.
[0095] When the security level of the device to be networked is greater than the preset level, the network configuration device has performed security verification on the device to be networked, and the device to be networked generates a corresponding identity key based on the verification key and the token stored by itself and the pre-defined verification key, and decrypts the encrypted network configuration information sent by the network configuration device by using the identity key, so as to obtain the network configuration information. When the security level of the device to be networked is not greater than the preset level, the network configuration device does not perform security verification on the device to be networked, and the device to be networked can decrypt the encrypted network configuration information sent by the network configuration device based on the verification key and the token stored by itself, so as to obtain the network configuration information.
[0096] It can be understood that in order to complete the commissioning of the to-be-networked device, a commissioning tool package (which can be referred to as SDK) will run in the to-be-networked device, and the commissioning tool package can be upgraded, so that the commissioning protocols required by different versions of the commissioning tool package can be different. The commissioning application of the commissioning device can also be upgraded to be compatible with multiple versions of the commissioning tool package.
[0097] After the to-be-networked device obtains the commissioning information, the to-be-networked device accesses the router corresponding to the commissioning information based on the commissioning information. There can be more than one commissioning mode that can be used for commissioning, such as a smartconfig mode, a device hotspot mode, and the like. Different to-be-networked devices can support different commissioning modes, and therefore the commissioning protocols required to support different commissioning modes can be supported in the commissioning application.
[0098] In the commissioning method in this embodiment, the to-be-networked device only needs to send a probe response frame containing attribute information of the to-be-networked device, so that the commissioning device can automatically obtain the attribute information of the to-be-networked device, and then the to-be-networked device accesses the router. The frame interaction in this process is less, which not only improves the commissioning success rate, but also speeds up the commissioning speed, thereby greatly improving the user experience. Further, the scheme has low dependence on the underlying of the commissioning module in the to-be-networked device, and only needs to send a probe request frame and receive a probe response frame to complete data communication, thereby quickly implementing commissioning of the to-be-networked device.
[0099] In order to more clearly describe the present application, Figure 5 The interaction flowchart of the commissioning method provided by the embodiment of the present application is shown in FIG. 1. Figure 5 As shown in the figure, the method comprises the following steps.
[0100] S401, the to-be-networked device opens an AP mode to discover the commissioning device.
[0101] S402, the commissioning device sends a probe request frame containing a first probe information field and a second probe information field to the to-be-networked device.
[0102] S403, the to-be-networked device receives the probe request frame, parses the probe request frame, fills the attribute information of the to-be-networked device into the first probe information field, and generates a probe response frame based on the second probe information field.
[0103] S404, the to-be-networked device sends a probe response frame containing the attribute information of the to-be-networked device.
[0104] S405, the commissioning device receives the probe response frame, and determines the identity key of the to-be-networked device based on the attribute information.
[0105] S406, the network device encrypts the network device information of the router based on the identity key to obtain encrypted network device information.
[0106] S407, the network device sends the encrypted network device information to the device to be networked.
[0107] S408, the device to be networked receives the encrypted network device information sent by the network device, decrypts the encrypted network device information, and obtains the network device information.
[0108] S409, access the router corresponding to the network device information according to the network device information.
[0109] Specifically, the device to be networked opens the AP mode, and in the AP mode, the device to be networked continuously detects the surrounding probe frame signal to discover the network device. The network device sends a probe request frame probe request containing a first probe information field and a second probe information field to the device to be networked. When the device to be networked receives the probe request frame probe request sent by the network device, it discovers that it is not networked, parses the probe request frame, fills the attribute information of the device to be networked into the first probe information field, generates a probe response frame probe response based on the second probe information field, and sends the probe response frame to the network device. The attribute information of the device to be networked can include device to be networked identifier did, time stamp ts, and verification key token.
[0110] Optionally, after receiving the attribute information of the device to be networked, the network device can determine whether to perform security verification based on the attribute information of the device to be networked. When security verification is not required, the network device takes the verification key token as the identity key of the device to be networked, then encrypts the obtained network device information by using the verification key token to obtain encrypted network device information, and sends the encrypted network device information to the device to be networked.
[0111] When security verification is required, the attribute information of the device to be networked is subjected to security verification. When the security verification is passed, the verification key key corresponding to the device to be networked is obtained from a preset verification library, and the verification key key and the verification key token are processed by using a preset algorithm to obtain the identity key of the device to be networked. The obtained network device information is encrypted by using the identity key to obtain encrypted network device information, and the encrypted network device information is sent to the device to be networked.
[0112] The to-be-networked device receives the encrypted network configuration information sent by the network configuration device, decrypts the network configuration information by using the identity key of the to-be-networked device to obtain the network configuration information, and then connects the router based on the network configuration information, so as to complete network configuration and binding of the to-be-networked device.
[0113] In the embodiment, the network configuration device does not need to disconnect the current router connection, and only needs to receive the probe response frame, so that the attribute information of the to-be-networked device can be automatically obtained, and then the to-be-networked device accesses the router. The process frame interaction is less, the network configuration success rate is improved, the network configuration speed is accelerated, and the user experience is greatly improved.
[0114] It should be noted that although the operations of the method of the present application are described in a specific order in the accompanying drawings, this does not require or imply that the operations must be performed in this specific order, or that all of the shown operations must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart can change the order of execution. Additionally or alternatively, certain steps can be omitted, combined into one step, and / or divided into multiple steps.
[0115] In another aspect, Figure 6 A structural schematic diagram of a network configuration device is provided for the embodiments of the present application. The device can be a device in a terminal device, such as Figure 6 As shown, the device 600 includes:
[0116] The receiving module 610 is configured to receive a probe response frame sent by the to-be-networked device, the probe response frame including a first probe information field and a second probe information field, the first probe information field being filled with attribute information of the to-be-networked device, and the second probe information field containing preset reserved information.
[0117] The determining module 620 is configured to determine an identity key of the to-be-networked device based on the attribute information.
[0118] The processing module 630 is configured to encrypt network configuration information of the router according to the identity key, obtain encrypted network configuration information, and send the encrypted network configuration information to the to-be-networked device, so that the to-be-networked device accesses the router according to the encrypted network configuration information.
[0119] Optionally, the network configuration device is further configured to:
[0120] The network configuration device is further configured to:
[0121] Optionally, the determination module 620 is configured to:
[0122] determine the security level and the verification key of the to-be-networked device based on the attribute information;
[0123] when the security level is greater than the preset level, acquire the verification key based on the attribute information to determine the identity key of the to-be-networked device;
[0124] when the security level is less than or equal to the preset level, determine the verification key as the identity key of the to-be-networked device.
[0125] Optionally, the determination module 620 is further configured to:
[0126] determine the to-be-networked device identifier from the attribute information of the to-be-networked device;
[0127] perform security verification on the to-be-networked device based on the to-be-networked device identifier and a preset verification library;
[0128] when the verification is passed, acquire the verification key corresponding to the to-be-networked device;
[0129] perform processing on the verification key and the verification key by using a preset algorithm to obtain the identity key of the to-be-networked device.
[0130] Optionally, the determination module 620 is further configured to:
[0131] determine whether the to-be-networked device identifier is legal;
[0132] when the to-be-networked device identifier is legal, search the preset verification library to determine whether the verification key corresponding to the to-be-networked device identifier exists;
[0133] if the verification key exists, determine that the to-be-networked device passes the verification.
[0134] It can be understood that the functions of each functional module of the network configuration device provided in this embodiment can be specifically implemented according to the method in the above method embodiment, and the specific implementation process can be referred to the related description of the above method embodiment, which will not be described here.
[0135] Figure 7 A structural schematic diagram of a network configuration device provided in an embodiment of the present application is shown in FIG. 7. Figure 7 As shown in FIG. 7, the device can include:
[0136] a sending module 710 configured to send a probe response frame containing attribute information of a to-be-networked device, so that a network configuration device determines an identity key of the to-be-networked device based on the attribute information;
[0137] a receiving module 720 configured to receive encrypted network configuration information sent by the network configuration device;
[0138] The acquisition module 730 is configured to decrypt the encrypted network configuration information to obtain the network configuration information.
[0139] The access module 740 is configured to access the router corresponding to the network configuration information according to the network configuration information.
[0140] Optionally, the network configuration device further includes:
[0141] The network configuration device receives the probe request frame including the first probe information field and the second probe information field sent by the network configuration equipment.
[0142] The network configuration device analyzes the probe request frame, fills the attribute information of the device to be configured into the first probe information field, and generates a probe response frame based on the second probe information field.
[0143] It can be understood that the functions of each functional module of the network configuration device provided in the embodiment can be specifically implemented according to the method in the above method embodiment, and the specific implementation process can be referred to the related description of the above method embodiment, which will not be described here.
[0144] On the other hand, the present application provides a network configuration system, which can be seen from Figure 1 The system includes a network configuration equipment 10, a device to be configured 20 and a router 30.
[0145] The device to be configured 20 is configured to send a probe response frame including the attribute information of the device to be configured 20, receive the encrypted network configuration information sent by the network configuration equipment 10, decrypt the encrypted network configuration information to obtain the network configuration information, and access the router 30 corresponding to the network configuration information according to the network configuration information.
[0146] The network configuration equipment 10 is configured to receive the probe response frame sent by the device to be configured 20, determine the identity key of the device to be configured based on the attribute information, encrypt the network configuration information of the router according to the identity key, obtain the encrypted network configuration information, and send the encrypted network configuration information to the device to be configured 20.
[0147] The network configuration system of the terminal equipment provided in the embodiment of the present application does not need the network configuration equipment to disconnect the current router connection, only needs to receive the probe response frame, so that the attribute information of the device to be configured can be automatically obtained, and then the device to be configured is accessed to the router, the frame interaction is less, not only improves the network configuration success rate, but also speeds up the network configuration speed, thereby greatly improves the user experience.
[0148] On the other hand, Figure 8 A hardware structure schematic diagram of a computer equipment is provided for the embodiment of the present application, and the computer equipment provided in the embodiment of the present application includes a memory, a processor, and a computer program stored in the memory and executable on the processor, and the processor implements the network configuration method as described above when executing the program.
[0149] Reference below Figure 8 , Figure 8 A schematic diagram of the structure of the computer system of the terminal device of an embodiment of the present application.
[0150] like Figure 8 As shown, the computer system 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage unit 703 into a random access memory (RAM) 703. Various programs and data required for the operation of the system 700 are also stored in the RAM 703. The CPU 701, ROM 702, and RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0151] The following components are connected to the I / O interface 705: an input section 706 including a keyboard, a mouse, and the like; an output section 707 including devices such as a cathode ray tube (CRT), a liquid crystal display (LCD), and a speaker; a storage section 708 including a hard disk; and a communication section 709 including a network interface card such as a LAN card or a modem. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, or a semiconductor memory, is installed in the drive 710 as needed, so that computer programs read therefrom can be installed into the storage section 708 as needed.
[0152] In particular, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a machine-readable medium, and the computer program includes program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 703, and / or installed from a removable medium 711. When the computer program is executed by the central processing unit (CPU) 701, the above-mentioned functions defined in the system of the present application are executed.
[0153] It should be noted that the computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium or a combination thereof. The computer-readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a computer-readable storage medium can include, but are not limited to, the following: an electrical connection having one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing. In the present application, a computer-readable storage medium can be any tangible medium that can contain, or store a program for use by or in connection with an instruction execution system, apparatus, or device. In the present application, a computer-readable signal medium can include a computer-readable storage medium and / or a computer-readable transmission medium. In the present application, a computer-readable transmission medium can include any computer-readable medium that is not a computer-readable storage medium. In the present application, a computer-readable storage medium can be any computer-readable medium excluding propagating signals per se. The computer-readable storage medium of the present application can be a computer program product.
[0154] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functional processes, and operations that can be implemented in systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flow diagrams, and combinations thereof, can be implemented by special purpose hardware-based systems that perform the specified functions or operations, or combinations of special purpose hardware and computer instructions.
[0155] The units or modules described in the embodiments of the present application can be implemented in the form of software or in the form of hardware. The described units or modules can also be arranged in a processor, for example, can be described as: a processor comprising a receiving module, a determining module and a processing module. In some cases, the names of these units or modules do not constitute a limitation on the units or modules themselves, for example, the receiving module can also be described as "configured to receive a probe response frame sent by the to-be-networked device, the probe response frame comprising a first probe information field and a second probe information field, the first probe information field being filled with attribute information of the to-be-networked device, and the second probe information field comprising preset reserved information".
[0156] As another aspect, the present application also provides a computer readable storage medium, which can be included in the electronic device described in the above embodiments, or can exist independently without being assembled into the electronic device. The computer readable storage medium stores one or more programs, and when the programs are used by one or more processors to execute the network configuration method described in the present application:
[0157] receiving a probe response frame sent by the to-be-networked device, the probe response frame comprising a first probe information field and a second probe information field, the first probe information field being filled with attribute information of the to-be-networked device, and the second probe information field comprising preset reserved information;
[0158] determining an identity key of the to-be-networked device based on the attribute information;
[0159] encrypting network configuration information of the router according to the identity key, obtaining encrypted network configuration information and sending the encrypted network configuration information to the to-be-networked device, so that the to-be-networked device accesses the router according to the encrypted network configuration information.
[0160] In summary, the network configuration method, apparatus, system, equipment and storage medium provided by the embodiments of the present application receive a probe response frame sent by the device to be connected to the network, the probe response frame includes a first probe information field and a second probe information field, and the first probe information field is filled with the attribute information of the device to be connected to the network, and the identity key of the device to be connected to the network is determined based on the attribute information, and the network configuration information of the router is encrypted according to the identity key, and the encrypted network configuration information is obtained and sent to the device to be connected to the network, so that the device to be connected to the network can access the router according to the encrypted network configuration information. This solution does not require the network configuration device to disconnect the current router connection, but only needs to receive the probe response frame sent by the device to be connected to the network, so that the attribute information of the device to be connected to the network can be automatically obtained, and then the device to be connected to the router can be connected to the network. This process has fewer frame interactions, which not only improves the success rate of network configuration, but also speeds up the network configuration speed, thereby greatly improving the user experience.
[0161] The above description is merely a preferred embodiment of the present application and an illustration of the technical principles employed. Those skilled in the art should understand that the scope of the invention herein is not limited to the technical solutions formed by the specific combination of the above-mentioned technical features, but also encompasses other technical solutions formed by any combination of the above-mentioned technical features or their equivalents without departing from the inventive concept. For example, a technical solution formed by replacing the above-mentioned features with (but not limited to) technical features having similar functions disclosed in this application.
Claims
1. A network distribution method, characterized in that: Applied to a distribution network device, the method includes: Receive a probe response frame sent by a device to be networked, the probe response frame including a first probe information field and a second probe information field, the first probe information field being filled with attribute information of the device to be networked, and the second probe information field including preset reserved information, the probe response frame being generated by the device to be networked by parsing the probe request frame to obtain the first probe information field and the second probe information field, filling the attribute information of the device to be networked into the first probe information field, and based on the second probe information field; the probe request frame is sent by the network configuration device to the device to be networked; Determining a security level and a verification key of the device to be networked based on the attribute information; when the security level is greater than a preset level, performing a security verification on the device to be networked, and when the security verification passes, obtaining a verification key based on the attribute information to determine the identity key of the device to be networked; when the security level is less than or equal to the preset level, determining the verification key as the identity key of the device to be networked; Encrypting the network configuration information of the router according to the identity key, obtaining the encrypted network configuration information and sending it to the device to be networked, so that the device to be networked can access the router according to the encrypted network configuration information; The preset reserved information includes: a fixed value, a message length, and a manufacturer number; the attribute information of the device to be networked includes: an identifier of the device to be networked, a timestamp, and a verification key.
2. The method according to claim 1, characterized in that Obtaining a verification key according to the attribute information to determine the identity key of the device to be networked includes: Determine the identifier of the device to be connected to the network from the attribute information of the device to be connected to the network; Performing a security check on the device to be connected to the network based on the device identifier and a preset verification library; When the verification is passed, the verification key corresponding to the device to be connected to the network is obtained; The verification key and the authentication key are processed using a preset algorithm to obtain the identity key of the device to be networked.
3. The method according to claim 2, characterized in that Based on the identifier of the device to be connected to the network and a preset verification library, a security verification is performed on the device to be connected to the network, including: Determine whether the identifier of the device to be connected to the network is legal; When the identifier of the device to be connected to the network is legal, searching the preset verification library for a verification key corresponding to the identifier of the device to be connected to the network; If so, it is determined that the device to be connected to the network has passed the verification.
4. A network distribution method, characterized in that: Applied to a device waiting to be connected to the network, the method includes: Send a probe response frame containing the attribute information of the device to be connected to the network, so that the network configuration device determines the security level and verification key of the device to be connected to the network based on the attribute information; when the security level is greater than the preset level, perform a security verification on the device to be connected to the network, and when the security verification passes, obtain a verification key based on the attribute information to determine the identity key of the device to be connected to the network; when the security level is less than or equal to the preset level, determine the verification key as the identity key of the device to be connected to the network; the probe response frame is generated by the device to be connected to the network by parsing the probe request frame to obtain the first probe information field and the second probe information field, filling the attribute information of the device to be connected to the network into the first probe information field, and based on the second probe information field, the second probe information field includes preset retention information; the probe request frame is sent by the network configuration device to the device to be connected to the network; Receiving encrypted network configuration information sent by the network configuration device; Decrypting the encrypted network configuration information to obtain the network configuration information; Accessing a router corresponding to the network distribution information according to the network distribution information; The preset reserved information includes: a fixed value, a message length, and a manufacturer number; the attribute information of the device to be networked includes: an identifier of the device to be networked, a timestamp, and a verification key.
5. A network distribution device, characterized in that: The device includes: A receiving module, configured to receive a probe response frame sent by a device to be networked, the probe response frame comprising a first probe information field and a second probe information field, the first probe information field being filled with attribute information of the device to be networked, the second probe information field comprising preset reserved information, the probe response frame being generated by the device to be networked by parsing the probe request frame to obtain the first probe information field and the second probe information field, filling the attribute information of the device to be networked into the first probe information field, and based on the second probe information field, the second probe information field comprising preset reserved information; the probe request frame being sent by a network configuration device to the device to be networked; a determination module, configured to determine a security level and a verification key of the device to be networked based on the attribute information; when the security level is greater than a preset level, perform a security verification on the device to be networked, and when the security verification passes, obtain a verification key based on the attribute information to determine the identity key of the device to be networked; when the security level is less than or equal to the preset level, determine the verification key as the identity key of the device to be networked; a processing module, configured to encrypt the network configuration information of the router according to the identity key, obtain the encrypted network configuration information, and send it to the device to be networked, so that the device to be networked can access the router according to the encrypted network configuration information; The preset reserved information includes: a fixed value, a message length, and a manufacturer number; the attribute information of the device to be networked includes: an identifier of the device to be networked, a timestamp, and a verification key.
6. A network distribution device, characterized in that: The device includes: A sending module, configured to send a probe response frame containing attribute information of a device to be networked, so that a network configuration device determines a security level and a verification key of the device to be networked based on the attribute information; when the security level is greater than a preset level, a security verification is performed on the device to be networked, and when the security verification passes, a verification key is obtained based on the attribute information to determine the identity key of the device to be networked; when the security level is less than or equal to the preset level, the verification key is determined as the identity key of the device to be networked; the probe response frame is generated by the device to be networked by parsing a probe request frame to obtain a first probe information field and a second probe information field, filling the attribute information of the device to be networked into the first probe information field, and based on the second probe information field, the second probe information field includes preset reserved information; the probe request frame is sent by the network configuration device to the device to be networked; A receiving module, configured to receive the encrypted network configuration information sent by the network configuration device; An acquisition module is used to decrypt the encrypted network configuration information to obtain the network configuration information; An access module, configured to access a router corresponding to the network configuration information according to the network configuration information; The preset reserved information includes: a fixed value, a message length, and a manufacturer number; the attribute information of the device to be networked includes: an identifier of the device to be networked, a timestamp, and a verification key.
7. A distribution network system, characterized in that: include: Network distribution equipment, devices to be connected to the network, and routers; The device to be connected to the network is used to send a probe response frame containing attribute information of the device to be connected to the network, receive the encrypted network configuration information sent by the network configuration device, decrypt the encrypted network configuration information to obtain the network configuration information, and access the router corresponding to the network configuration information according to the network configuration information. The probe response frame is generated by the device to be connected to the network parsing the probe request frame to obtain a first probe information field and a second probe information field, filling the attribute information of the device to be connected to the network into the first probe information field, and based on the second probe information field, the second probe information field includes preset reserved information; The detection request frame is sent by the network configuration device to the device to be networked; The network distribution device is used to receive the probe response frame sent by the device to be networked, and determine the security level and verification key of the device to be networked based on the attribute information; When the security level is greater than the preset level, a security check is performed on the device to be networked, and when the security check passes, a verification key is obtained according to the attribute information to determine the identity key of the device to be networked; When the security level is less than or equal to the preset level, determining the verification key as the identity key of the device to be networked; and encrypting the network configuration information of the router according to the identity key, obtaining the encrypted network configuration information and sending it to the device to be networked; The preset reserved information includes: a fixed value, a message length, and a manufacturer number; the attribute information of the device to be networked includes: an identifier of the device to be networked, a timestamp, and a verification key.
8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the program, the network distribution method according to any one of claims 1 to 3 or claim 4 is implemented.
9. A computer-readable storage medium having a computer program stored thereon, wherein when the program is executed by a processor, the network distribution method according to any one of claims 1 to 3 or any one of claim 4 is implemented.
Citation Information
Patent Citations
Wireless device configuration method and system
CN103607751A
Rapid access method and system for wireless network
CN108924827A
Network configuration method, device, equipment and system
CN112020120A
Bidirectional identity verification method, system and device and storage medium
CN112351000A