Wireless Communication Method and Device

By generating random values ​​and encrypting the distribution network equipment, the problem of insufficient authentication security in manual participation and authentication during distribution network is solved, and automated and high-security OOB authentication is realized.

CN115516893BActive Publication Date: 2025-06-03GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080100464.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2020-06-24
Publication Date
2025-06-03
Estimated Expiration
2040-06-24

AI Technical Summary

Technical Problem

The prior art has the need for manual participation and insufficient certification security in the distribution process of equipment to be distributed.

Method used

The first random value is generated by the device to be distributed, and an out-of-band OOB authentication value is generated using the encryption algorithm to avoid manual participation, and an OOB authentication value different from the time is generated through the cloud device to improve security.

Benefits of technology

The automated OOB certification process is realized, which improves the security of certification and avoids the potential risks brought by manual participation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115516893B_ABST
    Figure CN115516893B_ABST
Patent Text Reader

Abstract

A wireless communication method and device are provided. The method includes: a device to be network-configured generates a first random value; the device to be network-configured generates an out-of-band (OOB) authentication value based on the first random value by using an encryption algorithm. Based on the above technical solution, by directly generating the first random value used to calculate the OOB authentication value, it is possible to avoid the interaction between the device to be network-configured and the user, which is beneficial to the automated OOB authentication. In addition, by generating the OOB authentication value through the first random value, the OOB authentication values at different times can be made different, thereby ensuring the security of the OOB authentication. Moreover, by generating the OOB authentication value in the way of encrypting the first random value, equivalently, constructing the OOB authentication value in the form of ciphertext can further enhance the security of the OOB authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communications, and more particularly, to wireless communication methods and devices. Background Art

[0002] When a device to be network-configured enters the state of waiting for network configuration, the device to be network-configured can be added to the mesh network by using the standard Bluetooth mesh process. Moreover, during the network configuration process, out-of-band (OOB) authentication needs to be performed on the device to be network-configured. The standard process of the OOB authentication can include a no out-of-band (No OOB) authentication process, a static out-of-band (Static OOB) authentication process, an input out-of-band (Input OOB) authentication process, and an output out-of-band (Output OOB) authentication process.

[0003] As Figure 1 shown, the output OOB authentication process can include:

[0004] S110, the device to be network-configured selects a first random value.

[0005] S120, the device to be network-configured outputs the first random value.

[0006] S130, the network configuration device inputs the first random value.

[0007] S140, the device to be network-configured sends a first confirmation value to the device to be network-configured.

[0008] S150, the network configuration device sends a second confirmation value to the device to be network-configured.

[0009] S160, the network configuration device sends a second random value to the device to be network-configured, and the second random value is used for the network configuration device to generate the first confirmation value.

[0010] S170, the device to be network-configured verifies the first confirmation value based on the second random value.

[0011] S180, the device to be network-configured sends a third random value to the network configuration device, and the third random value is used for the network configuration device to generate the second confirmation value.

[0012] S190, the network configuration device verifies the second confirmation value based on the third random value.

[0013] Among them, the first random value is an OOB authentication value used to generate the first confirmation value or the second confirmation value. It can be seen that in the output OOB authentication method, the OOB authentication value is affected by the first random value output by the device to be networked. For example, if the device to be networked is a light bulb, the first random value can be that the light bulb can blink a specified number of times.

[0014] As Figure 2 shown, the input OOB authentication process may include:

[0015] S210, the network configuration device selects a first random value.

[0016] S220, the network configuration device displays the first random value.

[0017] S230, the device to be networked inputs the first random value.

[0018] S240, the device to be networked sends an input completion message to the network configuration device.

[0019] S250~S291.

[0020] Among them, the operations of S250~S291 are the same as those of Figure 1 the operations of S140~S190 shown.

[0021] Among them, the first random value is an OOB authentication value used to generate the first confirmation value or the second confirmation value. It can be seen that in the input OOB authentication method, the OOB authentication value is affected by the first random value input by the device to be networked. Taking the device to be networked as a lighting switch as an example, the first random value can be input by the user pressing the button several times within a certain period of time.

[0022] As Figure 3 shown, the static OOB or no OOB authentication process includes S310~S360. Among them, the operations of S310~S360 are the same as those of Figure 1 the operations of S140~S190 shown. Among them, the OOB authentication value used to generate the first confirmation value or the second confirmation value is a default fixed value. For example, when the static OOB authentication value is unavailable, it is directly replaced by the numerical value 0.

[0023] As can be seen from the above, the Output / Input OOB method requires the device to be networked to have the ability to input or output and requires manual participation during the process, while the security of the No OOB method is too low. Therefore, the Static OOB authentication method is usually used for OOB authentication.

[0024] However, in most cases, the Static OOB method pre-generates and directly burns it into the device to be networked during factory production. That is, the Static OOB authentication value is the same every time network configuration is performed, making the security of the network configuration process unable to be guaranteed. For example, when the Static OOB authentication value is leaked, other devices to be networked can network the device to be networked and achieve the purpose of control.

[0025] Therefore, there is an urgent need in the art for a communication method that can avoid manual participation and improve authentication security. Summary of the Invention

[0026] A wireless communication method and device are provided, which can avoid manual participation and improve authentication security.

[0027] In a first aspect, a wireless communication method is provided, including:

[0028] The device to be networked generates a first random value;

[0029] Based on the first random value, the device to be networked generates an out-of-band (OOB) authentication value using an encryption algorithm.

[0030] In a second aspect, a wireless communication method is provided, including:

[0031] The network configuration device receives the first random value sent by the device to be networked and forwards it to the cloud device;

[0032] The network configuration device receives the out-of-band (OOB) authentication value sent by the cloud device, and the out-of-band (OOB) authentication value is the authentication value generated by the cloud device based on the first random value.

[0033] In a third aspect, a wireless communication method is provided, including:

[0034] The first device receives the first random value sent by the second device;

[0035] Based on the first random value, the first device generates an out-of-band (OOB) authentication value using an encryption algorithm.

[0036] In a fourth aspect, a device to be networked is provided for performing the method in the first aspect or its various implementation manners. Specifically, the device to be networked includes functional modules for performing the method in the first aspect or its various implementation manners.

[0037] In a fifth aspect, a network configuration device is provided for performing the method in the second aspect or its various implementation manners. Specifically, the network configuration device includes functional modules for performing the method in the second aspect or its various implementation manners.

[0038] In a sixth aspect, a communication device is provided for performing the method in the above-mentioned third aspect or its various implementation manners. Specifically, the communication device includes functional modules for performing the method in the above-mentioned third aspect or its various implementation manners.

[0039] In a seventh aspect, a device to be network-configured is provided, including a processor and a memory. The memory is used for storing a computer program, and the processor is used for calling and running the computer program stored in the memory to perform the method in the above-mentioned first aspect or its various implementation manners.

[0040] In an eighth aspect, a network configuration device is provided, including a processor, a memory, and a transceiver. The memory is used for storing a computer program, and the processor is used for calling and running the computer program stored in the memory to perform the method in the above-mentioned second aspect or its various implementation manners.

[0041] In a ninth aspect, a communication device is provided, including a processor, a memory, and a transceiver. The memory is used for storing a computer program, and the processor is used for calling and running the computer program stored in the memory to perform the method in the above-mentioned third aspect or its various implementation manners.

[0042] In a tenth aspect, a chip is provided for implementing the method in any one of the above-mentioned first to third aspects or its various implementation manners. Specifically, the chip includes: a processor for calling and running a computer program from a memory, such that a device installed with the chip performs the method in any one of the above-mentioned first to third aspects or its various implementation manners.

[0043] In an eleventh aspect, a computer-readable storage medium is provided for storing a computer program, and the computer program causes a computer to perform the method in any one of the above-mentioned first to third aspects or its various implementation manners.

[0044] In a twelfth aspect, a computer program product is provided, including computer program instructions, and the computer program instructions cause a computer to perform the method in any one of the above-mentioned first to third aspects or its various implementation manners.

[0045] In a thirteenth aspect, a computer program is provided, which when running on a computer, causes the computer to perform the method in any one of the above-mentioned first to third aspects or its various implementation manners.

[0046] Based on the above technical solutions, by directly generating the first random value for calculating the OOB authentication value, it is possible to avoid the interaction between the device to be networked and the user, which is beneficial to the automated OOB authentication. In addition, by generating the OOB authentication value through the first random value, the OOB authentication values at different times can be made different, thereby ensuring the security of the OOB authentication. Moreover, by generating the OOB authentication value through the encryption operation of the first random value, equivalently, constructing the OOB authentication value in the form of ciphertext can further enhance the security of the OOB authentication. Brief Description of the Drawings

[0047] Figures 1-3 is a schematic diagram of the OOB authentication process related to the present application.

[0048] Figure 4 is a schematic block diagram of the system architecture provided by an embodiment of the present application.

[0049] Figure 5 is a schematic flow interaction diagram of the wireless communication method provided by an embodiment of the present application.

[0050] Figure 6 is a schematic structural diagram of the network beacon to be networked provided by an embodiment of the present application.

[0051] Figure 7 is another schematic flow interaction diagram of the wireless communication method provided by an embodiment of the present application.

[0052] Figure 8 is a schematic block diagram of the device to be networked provided by an embodiment of the present application.

[0053] Figure 9 is a schematic block diagram of the network configuration device provided by an embodiment of the present application.

[0054] Figure 10 is a schematic block diagram of the first device provided by an embodiment of the present application.

[0055] Figure 11 is a schematic block diagram of a communication device provided by an embodiment of the present application.

[0056] Figure 12 is a schematic block diagram of the chip provided by an embodiment of the present application. Detailed Embodiments

[0057] Next, the technical solutions in the present application will be described with reference to the accompanying drawings.

[0058] Figure 4 is a schematic structural diagram of the system architecture 400 provided by an embodiment of the present application.

[0059] It should be noted that the system architecture 400 can be applied to a wireless mesh network. The mesh network can also be referred to as a multi-hop network.

[0060] As Figure 4 shown, the system architecture 400 includes a device to be networked 410, a network configuration device 420, and a cloud device 430. The device to be networked 410 can communicate with the cloud device 430 through the network configuration device 420.

[0061] Among them, the device to be networked 410 can be a device waiting to join the mesh network, and the network configuration device 420 can be a device that has already joined the mesh network.

[0062] In other words, the device to be networked 410 can be configured to have routing characteristics (Route), that is, it can receive and forward low Bluetooth (BT) Mesh messages and Mesh beacons. In addition, the network configuration device 420 can be configured with certain node features, and the certain node features can be at least one of relay, proxy, friend, and low power characteristics.

[0063] Exemplarily, the network configuration device 420 can be a gateway router, that is, a router with gateway / bridge functions, and the gateway router can be used to establish a network connection with the Internet. For example, the gateway router can communicate with the Internet through a high-speed wired link. The network configuration device 420 can also be a wireless router, that is, the wireless router is connected to other wireless routers in the mesh network in a multi-hop interconnection manner. The network configuration device 420 can also communicate with a mesh client. The network configuration device can also communicate with a local area network.

[0064] Exemplarily, the device to be networked 410 can be a smart phone or a tablet computer, or can also be health, sports and fitness equipment, and can also be home appliance equipment. The health, sports and fitness equipment includes but is not limited to sports tracking devices, and wearable devices such as smart watches. The home appliance equipment includes but is not limited to devices such as table lamps, air conditioners, water heaters, and air purifiers.

[0065] The network configuration device 420 can establish a connection with the cloud device 430. For example, the way to establish a connection can be through the configuration server information built in the network configuration device 420, or the network configuration device 420 receives externally input configuration server information and establishes a connection with the corresponding cloud device 430 according to the configuration server information.

[0066] Exemplarily, the cloud device 430 can be used to manage the network configuration device 420 and other network configuration devices in the mesh network. The cloud device 430 can be an independent physical device or software installed on other devices. For example, the cloud device 430 can be a network configuration device with management functions in the mesh network.

[0067] It should be noted that in the embodiments of the present application, the network configuration device 420 can be used as a node in the mesh network that has the qualification to provide authentication services for nodes that want to join the mesh network.

[0068] In other words, the network configuration device 420 can be used to discover new nodes or neighbor nodes in the mesh network and establish a corresponding information list. For example, the network configuration device 420 can use network scanning to discover new nodes or neighbor nodes. Network scanning means that the network configuration device 420 actively sends or listens for beacon signals to listen for neighbor nodes around it. Another example is that the network configuration device 420 can add the information of neighbor nodes belonging to the same mesh network discovered through network scanning to the list.

[0069] The device to be network-configured 410 is only allowed to initiate communication in the mesh network after passing identity authentication and establishing a set of key systems.

[0070] In the embodiments of the present application, the device to be network-configured 410 can join the mesh network by starting a secure provisioning process. In other words, the network configuration device 420 can also be called a provisioning device, and the device to be network-configured 410 can also be called a new device or an unprovisioned device. The provisioning process will transform a device that wants to join the mesh network into a network configuration device, making it a formal member of the mesh network. The provisioning process can be implemented through an application program, or the provisioning process can be started on a smart phone or tablet, or other forms can also be used, such as a desktop or web application program.

[0071] Figure 5 It is a schematic flowchart of the wireless communication method 500 provided by the embodiments of the present application. The method 500 can be executed interactively by the device to be network-configured and the network configuration device. Figure 5 The device to be network-configured shown in Figure 4 can be the device to be network-configured 410 shown in Figure 5 The network configuration device shown in Figure 4 can be the network configuration device 420 shown in

[0072] Such as Figure 5As shown, the method 500 includes some or all of the following:

[0073] S510, the device to be network - configured generates a first random value.

[0074] S550, the device to be network - configured generates an out - of - band (OOB) authentication value based on the first random value using an encryption algorithm.

[0075] For example, the device to be network - configured can use a random number generator to generate the first random value, and then perform an encryption operation on the first random value to generate the OOB authentication value.

[0076] Exemplarily, the encryption algorithm can be a Hash algorithm, which is also called a hash function. The Hash algorithm can be used to map plaintext to ciphertext irreversibly, that is, the Hash algorithm only has an encryption process and no decryption process. At the same time, the Hash algorithm can change an input of any length to obtain an output of a fixed length. This one - way feature and the feature of fixed - length output data of the Hash algorithm enable it to generate messages or data.

[0077] Exemplarily, the Hash algorithm can be a Secure Hash Algorithm (SHA), and the Secure Hash Algorithm can include SHA - 1 and SHA2. Optionally, SHA2 can include SHA - 224, SHA - 256, SHA - 384, and SHA - 512. Among them, SHA2 can be named by adding the length of the message digest after the original name. For example, SHA - 256 will generate a message digest with a length of 256 bits. In other words, for a message of any length, through SHA - 256, a 256 - bit hash value can be generated, and the 256 - bit hash value can also be called a message digest. The message digest can be an array with a length of 32 bytes, for example, a hexadecimal string with a length of 64.

[0078] Taking SHA - 256 as an example, the device to be network - configured can calculate based on SHA - 256 for the first random value and use the output 256 - bit hash value as the OOB authentication value.

[0079] Based on the above technical solution, by directly generating the first random value for calculating the OOB authentication value, it is possible to avoid the interaction between the device to be networked and the user, which is beneficial to the automatic OOB authentication. In addition, by generating the OOB authentication value through the first random value, the OOB authentication values at different times can be made different, thus ensuring the security of the OOB authentication. Additionally, by generating the OOB authentication value through the encryption operation on the first random value, equivalently, constructing the OOB authentication value in the form of ciphertext can further enhance the security of the OOB authentication.

[0080] For S520, in some embodiments of the present application, the device to be networked generates the OOB authentication value based on a target value using an encryption algorithm, where the target value includes the first random value and the first information, and the first information includes the device unique identifier DID of the device to be networked and / or the secret key (Secret) for encrypting the OOB authentication value.

[0081] In other words, the first random value and the first information serve as the input information of the encryption algorithm, and the OOB authentication value serves as the output information of the encryption algorithm.

[0082] In some embodiments of the present application, the target value is a value formed by connecting the first random value and the first information in a preset order.

[0083] In other words, the target value may be a bit string formed by the first random value, the DID, and the secret key for encrypting the OOB authentication value in a preset order.

[0084] It should be noted that the present application embodiments do not limit the specific order of the first random value, the DID, and the secret key for encrypting the OOB authentication value.

[0085] For example, the target value is a bit string formed by sequentially connecting the first random value, the DID, and the secret key for encrypting the OOB authentication value. Another example is that the target value is a bit string formed by sequentially connecting the first random value, the secret key for encrypting the OOB authentication value, and the DID. Another example is that the target value is a bit string formed by sequentially connecting the DID, the secret key for encrypting the OOB authentication value, and the first random value.

[0086] Of course, the device to be networked may also adopt other methods to process the first random value, the DID, and the secret key for encrypting the OOB authentication value to form the target value.

[0087] For example, the target value may be a value formed by performing a hashing operation on the first random value, the DID, and the secret key for encrypting the OOB authentication value using at least one of additive hash, bitwise operation hash, multiplicative hash, division hash, lookup table hash, mixed hash, and array hash.

[0088] In some embodiments of the present application, the first information is the information stored in the device to be provisioned.

[0089] In other words, the device to be provisioned may generate the OOB authentication value based on the stored first information and the generated first random value.

[0090] As Figure 5 shown, in some embodiments of the present application, the method 500 may further include:

[0091] S530, the device to be provisioned sends the first random value to the provisioning device.

[0092] In other words, the provisioning device receives the first random value sent by the device to be provisioned.

[0093] In some embodiments of the present application, in the operation of S530, the device to be provisioned sends an unprovisioned beacon to the provisioning device. The unprovisioned beacon is used to indicate that the device to be provisioned is a device waiting to be provisioned. The unprovisioned beacon includes a universally unique identifier (UUID), and the UUID includes the first random value.

[0094] In other words, the provisioning device receives the unprovisioned beacon sent by the device to be provisioned and sent to the cloud device. The unprovisioned beacon is used to indicate that the device to be provisioned is a device waiting to be provisioned. The unprovisioned beacon includes a universally unique identifier (UUID), and the UUID includes the first random value.

[0095] Figure 6 is a schematic structural diagram of the unprovisioned beacon provided by an embodiment of the present application.

[0096] As Figure 6 shown, the unprovisioned beacon may include a 0X00 field, a universally unique identifier (UUID), OOB information, and a uniform resource identifier (URI) hash.

[0097] Among them, the 0X00 field may also be referred to as the 0X00 field, and information such as the broadcast type information of the network device to be configured and / or the name of the network device to be configured may be stored in the 0X00 field. The UUID further includes at least one of the following: the device unique identifier (device id, DID) of the network device to be configured, the company identifier, and the reserved bit. The URI may be a string for identifying the name of a certain Internet resource.

[0098] As Figure 5 shown, in some embodiments of the present application, the method 500 may further include:

[0099] S540, the network device to be configured receives the first confirmation value sent by the network configuration device;

[0100] S570, the network device to be configured receives the second random value sent by the network configuration device;

[0101] S580, the network device to be configured verifies the first confirmation value based on the OOB authentication value and the second random value.

[0102] In short, after the network device to be configured receives the first confirmation value sent by the network configuration device, it receives the second random value sent by the network configuration device, and generates a confirmation value based on the second random value to verify the received first confirmation value.

[0103] In other words, the network configuration device sends the first confirmation value and the second random value to the network device to be configured, and the second random value is used by the network configuration device to generate the first confirmation value.

[0104] As Figure 5 shown, in some embodiments of the present application, the method 500 may further include:

[0105] S560, the network configuration device receives the second confirmation value sent by the network device to be configured;

[0106] S590, the network configuration device receives the third random value sent by the network device to be configured;

[0107] S591, the network configuration device verifies the second confirmation value based on the OOB authentication value and the third random value.

[0108] In short, after the network configuration device receives the second confirmation value sent by the network device to be configured, it receives the third random value sent by the network device to be configured, and generates a confirmation value based on the third random value to verify the received second confirmation value.

[0109] In other words, the device to be networked sends the second confirmation value and the third random value to the network configuration device. The third random value is used by the device to be networked to generate the second random value.

[0110] As Figure 5 shown, in some embodiments of the present application, the method 500 may further include:

[0111] S530, the network configuration device obtains an OOB authentication value, and the OOB authentication value is used to generate the first confirmation value.

[0112] Specifically, after receiving the first random value sent by the device to be networked, the network configuration device may obtain the OOB authentication value based on the first random value.

[0113] In some embodiments of the present application, the network configuration device receives the first random value sent by the device to be networked and forwards it to the cloud device; the network configuration device receives the out-of-band OOB authentication value sent by the cloud device, and the out-of-band OOB authentication value is an authentication value generated by the cloud device based on the first random value.

[0114] In other words, the network configuration device forwards the received first random value to the cloud device so that the cloud device generates the OOB based on the first random value. After that, the network configuration device receives the OOB authentication value sent by the cloud device.

[0115] In some other embodiments of the present application, the network configuration device generates the OOB authentication value based on the first random value sent by the device to be networked.

[0116] For ease of description, hereinafter, the network configuration device or the cloud device used to generate the OOB authentication value is collectively referred to as the first device.

[0117] In some embodiments of the present application, the first device receives the first random value sent by the second device; and based on the first random value, uses an encryption algorithm to generate an out-of-band OOB authentication value.

[0118] For example, the first device generates the OOB authentication value based on a target value, and the target value includes the first random value and the first information. The first information includes the device unique identifier DID of the device to be networked and / or the secret key for encrypting the OOB authentication value. Optionally, the target value is a value formed by connecting the first random value and the first information in a preset order. Optionally, the DID and the first information are information stored in the first device.

[0119] In other words, if the first device is a cloud device and the second device is a network configuration device; the cloud device receives the first random value sent by the device to be network-configured through the network configuration device. For example, the first device receives a network configuration beacon sent by the second device, where the network configuration beacon is used to indicate that the device to be network-configured is waiting for network configuration, and the network configuration beacon includes a Universally Unique Identifier (UUID), and the UUID includes the first random value. The cloud device sends the OOB authentication value to the network configuration device. If the first device is a network configuration device and the second device is a device to be network-configured; the network configuration device can directly generate the OOB authentication value based on the first random value.

[0120] It should be noted that the method for the first device to generate the OOB authentication value can be the same as the method for the device to be network-configured to generate the OOB authentication value. To avoid repetition, it will not be elaborated here.

[0121] Figure 7 It is a schematic flowchart of the wireless communication method 400 provided by an embodiment of the present application. The following will be combined with Figure 7 to illustrate the implementation manner of generating the OOB authentication value through the cloud device.

[0122] As Figure 7 shown, the method 600 may include:

[0123] S601, the device to be network-configured generates a first random value, where the first random value is used to calculate the OOB authentication value.

[0124] S602, the device to be network-configured sends a network configuration beacon to the network configuration device, where the network configuration beacon includes a UUID, and the UUID includes the first random value.

[0125] For example, the device to be network-configured may send the network configuration beacon in a broadcast form to declare that it is a device to be network-configured or a device that can be started for configuration. Optionally, the device to be network-configured can send the network configuration beacon through the bearer layer supported by the device to be network-configured.

[0126] S603, the network configuration device forwards the network configuration beacon to the cloud device.

[0127] S604, if the UUID in the network configuration beacon is legal, the cloud device calculates the OOB authentication value based on the first random value.

[0128] Specifically, after receiving the network configuration beacon, the cloud device can verify the legality of the UUID in the network configuration beacon, and after determining that the UUID is legal, calculate the OOB authentication value based on the first random value in the UUID.

[0129] For example, if the historical random values stored in the cloud device include the first random value, determine that the UUID is legal information; if the historical random values stored in the cloud device do not include the first random value, determine that the UUID is illegal information.

[0130] S605. The cloud device sends the OOB authentication value to the network configuration device.

[0131] S606. The network configuration device sends LinkOpen to the device to be network-configured.

[0132] After receiving the OOB authentication value sent by the cloud device, the network configuration device triggers the establishment of a link between the network configuration device and the device to be network-configured. The first link can be identified by the UUID of the device to be network-configured. In other words, the establishment of the link starts from the LinkOpen message sent by the network configuration device to the device to be network-configured. The LinkOpen message may include the UUID of the device to be network-configured. The process of establishing the link is used to establish a session for the bearer layer. A session is uniquely identified by a link ID. Optionally, the link ID can be static information during the session time.

[0133] S607. The device to be network-configured sends a link confirmation to the network configuration device.

[0134] Specifically, after receiving the LinkOpen message, the network configuration device can reply with a LinkACK message to the network configuration device using the same link ID.

[0135] S608. The network configuration device sends a Provisioning Invite to the device to be network-configured.

[0136] Specifically, the network configuration device invites the device to be network-configured to send configuration function information. After sending the network configuration beacon, a provisioning bearer can be established between the network configuration device and the device to be network-configured. Based on this, the network configuration device can use the established provisioning bearer to send a Provisioning Invite Protocol Data Unit (PDU) to the device to be network-configured so that the device to be network-configured can respond to the configuration function PDU.

[0137] Exemplarily, the configuration function PDU may include at least one of the following:

[0138] The number of elements supported by the device to be network-configured;

[0139] The security algorithms supported by the device to be network-configured;

[0140] The availability of the public key implemented by the device to be provisioned using out-of-band (OOB) technology;

[0141] The ability of the device to be provisioned to output a value to the user; and

[0142] The ability of the device to be provisioned to allow the user to input a value.

[0143] S609, the device to be provisioned sends ProvisioningCapabilities to the provisioning device.

[0144] Specifically, after receiving the invitation PDU sent by the provisioning device, the device to be provisioned can respond to the invitation PDU, that is, provide information about the functions of the device to be provisioned to the provisioning device.

[0145] S610, the provisioning device sends the Provisioning State to the device to be provisioned.

[0146] S611, the device to be provisioned sends the Provisioning Public Key to the provisioning device.

[0147] S612, the provisioning device sends the Provisioning Public Key to the device to be provisioned.

[0148] In S611 and S612, the device to be provisioned and the provisioning device exchange public keys. Optionally, the public key can be an elliptic curves Diffie-Hellman (ECDH) public key. Optionally, the ECDH public key can be exchanged through a Bluetooth link or an OOB tunnel.

[0149] Specifically, in S609, the provisioning device can select a suitable exchange method according to the provisioning capability information of the device to be provisioned and notify the device to be provisioned of the method to be taken. After that, the provisioning device and the device to be provisioned can create an elliptic curve public-private key pair and exchange public keys. Then, the provisioning device or the device to be provisioned can use its own private key and the public key of the peer device to calculate a symmetric key, and the symmetric key is used to verify the identity of the peer device.

[0150] It should be noted that symmetric encryption uses the same key for both encryption and decryption. As long as the sending device and the receiving device know the key, they can decrypt all the information encrypted with this key. Asymmetric encryption uses two related keys, namely a key pair, which includes a public key and a private key. The public key is freely provided to any sender who may want to send a message to the receiver. The private key is a confidential key. Any message (text, binary file, or symmetric key) encrypted with the public key can only be decrypted by applying the same algorithm and using only the matching private key. Equivalently, there is no need to worry about the process of passing the public key through the link.

[0151] S613a, the device to be networked calculates ECDH.

[0152] Specifically, the device to be networked can use its own private key and the public key sent by the network configuration device to calculate a symmetric key, and the symmetric key is used to verify the identity of the network configuration device.

[0153] S613b, the network configuration device calculates ECDH.

[0154] Specifically, the network configuration device can use its own private key and the public key sent by the device to be networked to calculate a symmetric key, and the symmetric key is used to verify the identity of the device to be networked.

[0155] S614, the network configuration device sends a first confirmation value to the device to be networked.

[0156] S615, the device to be networked sends a second confirmation value to the network configuration device.

[0157] S616, the network configuration device sends a second random value to the device to be networked.

[0158] S617, the device to be networked verifies the first confirmation value based on the second random value.

[0159] In other words, the device to be networked checks the first confirmation value (Check Confirmation Value). The first confirmation value is the confirmation value generated by the network configuration device based on the second random value. The first confirmation value can also be called the confirmation value of the network configuration device (ConfirmationProvisioner), and the second random value can also be called the random value of the device (RandomDevice).

[0160] Specifically, the distribution network device sends the second random value to the device to be network - configured. The device to be network - configured recalculates the confirmation value using the second random value and compares it with the previously received first confirmation value for verification. If the confirmation value calculated by the device to be network - configured does not match the first confirmation value, the configuration process will be aborted. If the confirmation value calculated by the device to be network - configured matches the first confirmation value, the device to be network - configured sends the random value used to calculate the second confirmation value to the distribution network device.

[0161] In other words, the device to be network - configured generates a confirmation value for verifying the first confirmation value based on the second random value.

[0162] Exemplarily, the distribution network device and the device to be network - configured can generate the confirmation value based on multiple parameters and a confirmation value generation function during the provisioning process. For example, the device to be network - configured can generate the second confirmation value based on the OOB authentication value generated from the above - mentioned first random value and a third random value.

[0163] Taking the distribution network device calculating the first confirmation value as an example, the distribution network device can calculate the first confirmation value based on the following formula:

[0164] ConfirmationProvisioner = AES - CMAC confirmationKey (RandomProvisioner||Aut

[0165] hValue).

[0166] Wherein, the ConfirmationProvisioner represents the first confirmation value, the || represents concatenation, the ES - CMAC confirmationKey represents the ECDH public key, the AuthValue represents the OOB authentication value obtained by the distribution network device, and the RandomProvisioner represents the second random value. RandomProvisioner is a string of random bits and can be generated by the random value generator of the distribution network device. The AuthValue can be determined based on the type of encryption calculation. For example, when the encryption calculation is SHA - 256, the AuthValue is a 256 - bit long string.

[0167] For example, the network device to be configured may connect the second random value and the obtained OOB authentication value; then, the network device uses the Advanced Encryption Standard - Cypher Based Message Authentication Code (AES-CMAC) to calculate the result of the connection and the ECDH public key to generate the first confirmation value.

[0168] It should be noted that the OOB authentication value may be the OOB authentication value involved above. To avoid repetition, it will not be elaborated here. Similarly, for the device to be networked, the second random value may be used as the input, and the first confirmation value may be used as the output.

[0169] S618, the device to be networked sends a third random value to the network device.

[0170] S619, the device to be networked verifies the second confirmation value based on the third random value.

[0171] Specifically, the device to be networked sends the third random value to the network device. The network device recalculates the confirmation value using the third random value and compares it with the previously received second confirmation value for verification. If the confirmation value calculated by the network device does not match the second confirmation value, the configuration process will be aborted. If the confirmation value calculated by the network device matches the second confirmation value, it indicates that the verification of the second confirmation value is successful.

[0172] It should be understood that the network device and the device to be networked need to use the same calculation method to calculate the confirmation value to ensure that the network device and the device to be networked can verify the received confirmation value based on the confirmation value calculated from the received random value.

[0173] S620, the network device sends provisioning data to the device to be networked.

[0174] For example, the network device exports and distributes the configuration data. The configuration data may include multiple data items, and the multiple data items may include a network key (NetKey). The network key may also be referred to as the "IV Index", and the network key may be used as a mesh security parameter and include a unicast address assigned by the network device.

[0175] After successful authentication, the device to be network - provisioned and the network - provisioning device can generate a session key using their respective private keys and the exchanged peer public keys. The session key can be used to protect the data sent subsequently.

[0176] In other words, the network - provisioning device and the device to be network - provisioned can generate a session key and a session nonce. When the session key and the session nonce are ready, the network - provisioning device can encrypt the configuration data PDU containing the configuration data and send it to the device to be network - provisioned. Optionally, the device to be network - provisioned can decrypt the received data using the same session key and session nonce.

[0177] S621, the device to be network - provisioned sends "Provisioning complete" to the network - provisioning device.

[0178] After the start - up configuration is completed, the network - provisioning device can be a member in the mesh network. For example, the device to be network - provisioned can have a network key (NetKey).

[0179] S622, the network - provisioning device sends "LinkClose" to the device to be network - provisioned.

[0180] In other words, after the start - up configuration is completed, the link can be closed at any time by sending a LinkClose message. Optionally, either side of the link can send a LinkClose message.

[0181] The preferred embodiments of the present application have been described in detail above with reference to the accompanying drawings. However, the present application is not limited to the specific details in the above - mentioned embodiments. Within the scope of the technical concept of the present application, various simple modifications can be made to the technical solutions of the present application, and these simple modifications all fall within the protection scope of the present application.

[0182] For example, for each of the specific technical features described in the above - mentioned specific embodiments, they can be combined in any suitable way without contradiction. To avoid unnecessary repetition, the present application does not separately describe various possible combination methods.

[0183] Also, for example, any combination can be made between various different embodiments of the present application as long as it does not violate the idea of the present application, and it should also be regarded as the content disclosed by the present application.

[0184] It should be understood that in various method embodiments of the present application, the magnitudes of the serial numbers of the above processes do not imply the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0185] As described above in conjunction with Figures 1-7 , the method embodiments of the present application have been described in detail. Below, in conjunction with Figures 8-12 , the apparatus embodiments of the present application will be described in detail.

[0186] Figure 8 FIG. is a schematic block diagram of a device 700 to be networked according to an embodiment of the present application.

[0187] Please refer to Figure 8 , the device 700 to be networked may include:

[0188] A processing unit 710, where the processing unit 710 is configured to:

[0189] Generate a first random value;

[0190] Based on the first random value, use an encryption algorithm to generate an out-of-band (OOB) authentication value.

[0191] In some embodiments of the present application, the processing unit 710 is specifically configured to:

[0192] Based on a target value, use an encryption algorithm to generate the OOB authentication value, where the target value includes the first random value and first information, and the first information includes the device unique identifier (DID) of the device to be networked and / or the secret key for encrypting the OOB authentication value.

[0193] In some embodiments of the present application, the target value is a value formed by connecting the first random value and the first information in a preset order.

[0194] In some embodiments of the present application, the first information is information stored in the device to be networked.

[0195] In some embodiments of the present application, the device to be networked further includes:

[0196] A communication unit, configured to send the first random value to the network configuration device.

[0197] In some embodiments of the present application, the communication unit is specifically configured to:

[0198] Send a network configuration beacon to the network configuration device, where the network configuration beacon is used to indicate that the device to be networked is a device waiting for network configuration, and the network configuration beacon includes a universally unique identifier (UUID), and the UUID includes the first random value.

[0199] In some embodiments of the present application, the UUID further includes at least one of the following:

[0200] The device unique identifier DID, company identifier, and reserved bit positions of the device to be networked.

[0201] In some embodiments of the present application, the processing unit 710 is further configured to:

[0202] Receive a first confirmation value sent by the network configuration device;

[0203] Receive a second random value sent by the network configuration device;

[0204] Verify the first confirmation value based on the OOB authentication value and the second random value.

[0205] In some embodiments of the present application, the processing unit 710 is further configured to:

[0206] Send a second confirmation value to the network configuration device;

[0207] Send a third random value to the network configuration device, where the third random value is used to generate the second confirmation value.

[0208] Figure 9 It is a schematic block diagram of the network configuration device 800 provided by an embodiment of the present application.

[0209] As Figure 9 shown, the network configuration device 800 may include:

[0210] A communication unit 810, where the communication unit 810 is configured to:

[0211] Receive a first random value sent by the device to be networked and forward it to the cloud device;

[0212] Receive an out-of-band OOB authentication value sent by the cloud device, where the out-of-band OOB authentication value is an authentication value generated by the cloud device based on the first random value.

[0213] In some embodiments of the present application, the communication unit 810 is specifically configured to:

[0214] Receive a device network configuration beacon sent by the device to be networked and send it to the cloud device. The device network configuration beacon is used to indicate that the device to be networked is a device waiting for network configuration. The device network configuration beacon includes a universally unique identifier UUID, and the UUID includes the first random value.

[0215] In some embodiments of the present application, the UUID further includes at least one of the following:

[0216] The device unique identifier DID, company identifier, and reserved bit of the device to be networked.

[0217] In some embodiments of the present application, the networking device further includes a processing unit, and the processing unit is configured to:

[0218] Receive a second confirmation value sent by the device to be networked;

[0219] Receive a third random value sent by the device to be networked;

[0220] Verify the second confirmation value based on the OOB authentication value and the third random value.

[0221] In some embodiments of the present application, the communication unit is further configured to:

[0222] Send a first confirmation value to the device to be networked;

[0223] Send a second random value to the device to be networked, and the second random value is used to generate the first confirmation value.

[0224] Figure 10 It is a schematic block diagram of the first device 900 provided by an embodiment of the present application.

[0225] As Figure 10 shown, the first device 900 may include:

[0226] A communication unit 910, configured to receive a first random value sent by a second device;

[0227] A processing unit 920, configured to generate an out-of-band OOB authentication value based on the first random value using an encryption algorithm.

[0228] In some embodiments of the present application, the processing unit 920 is specifically configured to:

[0229] Generate the OOB authentication value based on a target value using an encryption algorithm, where the target value includes the first random value and first information, and the first information includes the device unique identifier DID of the device to be networked and / or a secret key for encrypting the OOB authentication value.

[0230] In some embodiments of the present application, the target value is a value formed by connecting the first random value and the first information in a preset order.

[0231] In some embodiments of the present application, the DID and the first information are information stored in the communication device.

[0232] In some embodiments of the present application, the communication unit 910 is specifically configured to:

[0233] Receive the network configuration beacon to be sent by the second device, where the network configuration beacon to be sent is used to indicate that the device to be network-configured is a device waiting for network configuration, and the network configuration beacon to be sent includes a Universally Unique Identifier (UUID), and the UUID includes the first random value.

[0234] In some embodiments of the present application, the UUID further includes at least one of the following:

[0235] The device unique identifier (DID) of the device to be network-configured, the company identifier, and reserved bit positions.

[0236] In some embodiments of the present application, the first device 900 is a cloud device, and the second device is a network configuration device; wherein, the communication unit 910 is specifically configured to:

[0237] Receive the first random value sent by the device to be network-configured through the network configuration device.

[0238] In some embodiments of the present application, the communication unit 910 is further configured to:

[0239] Send the OOB authentication value to the network configuration device.

[0240] In some embodiments of the present application, the first device 900 is a network configuration device, and the second device is a device to be network-configured.

[0241] It should be understood that the apparatus embodiments and method embodiments can correspond to each other, and similar descriptions can refer to the method embodiments. Specifically, Figure 8 The device to be network-configured 700 shown can correspond to the device to be network-configured in the method 200 of the embodiments of the present application, Figure 9 The network configuration device 800 shown can correspond to the network configuration device in the method of the embodiments of the present application, Figure 10 The first device 900 shown can correspond to the cloud device or the network configuration device in the method of the embodiments of the present application, and the foregoing and other operations and / or functions of each unit in the device to be network-configured 700, the network configuration device 800, and the first device 900 respectively implement the corresponding processes in the respective methods of the embodiments of the present application. For the sake of brevity, they will not be described in detail here.

[0242] In the foregoing, the communication device of the embodiments of the present application has been described from the perspective of functional modules. It should be understood that the functional modules can be implemented in the form of hardware, can also be implemented by instructions in the form of software, and can also be implemented by a combination of hardware and software modules.

[0243] Specifically, each step of the method embodiment in the embodiments of the present application can be completed by the integrated logic circuit in the hardware of the processor and / or instructions in the form of software. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor.

[0244] Optionally, the software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps in the above method embodiment.

[0245] For example, the processing unit and the communication unit involved above can be implemented by a processor and a transceiver respectively.

[0246] Figure 11 It is a schematic structural diagram of the communication device 1000 provided by the embodiments of the present application.

[0247] Please refer to Figure 11 , the communication device 1000 may include a processor 1010.

[0248] Among them, the processor 1010 can call and run a computer program from the memory to implement the method in the embodiments of the present application.

[0249] Please continue to refer to Figure 11 , the communication device 1000 may further include a memory 1020.

[0250] Among them, the memory 1020 can be used to store indication information, and can also be used to store codes, instructions, etc. executed by the processor 1010. Among them, the processor 1010 can call and run a computer program from the memory 1020 to implement the method in the embodiments of the present application. The memory 1020 can be a separate device independent of the processor 1010, or integrated in the processor 1010.

[0251] Please continue to refer to Figure 11 , the communication device 1000 may further include a transceiver 1030.

[0252] Among them, the processor 1010 can control the transceiver 1030 to communicate with other devices. Specifically, it can send information or data to other devices, or receive information or data sent by other devices. The transceiver 1030 can include a transmitter and a receiver. The transceiver 1030 may further include an antenna, and the number of antennas can be one or more.

[0253] It should be understood that the various components in the communication device 1000 are connected through a bus system. Among them, the bus system includes not only a data bus, but also a power bus, a control bus, and a status signal bus.

[0254] It should also be understood that the communication device 1000 can be the terminal device of the embodiment of the present application, and the communication device 1000 can implement the corresponding processes implemented by the device to be networked in the various methods of the embodiment of the present application. That is to say, the communication device 1000 of the embodiment of the present application can correspond to the device to be networked 700 in the embodiment of the present application, and can correspond to the corresponding entity that executes the methods according to the embodiment of the present application. For the sake of brevity, it will not be elaborated here. Similarly, the communication device 1000 can be the network configuration device or the cloud device of the embodiment of the present application, and the communication device 1000 can implement the corresponding processes implemented by the network configuration device or the cloud device in the various methods of the embodiment of the present application. That is to say, the communication device 1000 of the embodiment of the present application can correspond to the network configuration device 800 or the first device 900 in the embodiment of the present application, and can correspond to the corresponding entity that executes the methods according to the embodiment of the present application. For the sake of brevity, it will not be elaborated here.

[0255] In addition, an integrated circuit chip is provided in the embodiment of the present application.

[0256] For example, the chip may be an integrated circuit chip with signal processing capabilities, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiment of the present application. The chip can also be referred to as a system-on-chip, system chip, chip system, or system-on-chip. Optionally, the chip can be applied to various communication devices, so that the communication device installed with the chip can execute the various methods, steps, and logic block diagrams disclosed in the embodiment of the present application.

[0257] Figure 12 is a schematic structural diagram of the chip 1100 according to the embodiment of the present application.

[0258] Please refer to Figure 12 , the chip 1100 includes a processor 1110.

[0259] Among them, the processor 1110 can call and run a computer program from the memory to implement the methods in the embodiment of the present application.

[0260] Please continue to refer to Figure 12 , the chip 1100 may further include a memory 1120.

[0261] Among them, the processor 1110 can call and run a computer program from the memory 1120 to implement the methods in the embodiments of the present application. The memory 1120 can be used to store indication information, and can also be used to store code, instructions, etc. executed by the processor 1110. The memory 1120 can be a separate device independent of the processor 1110, or can be integrated in the processor 1110.

[0262] Please continue to refer to Figure 12 , the chip 1100 may further include an input interface 1130.

[0263] Among them, the processor 1110 can control the input interface 1130 to communicate with other devices or chips. Specifically, it can obtain information or data sent by other devices or chips.

[0264] Please continue to refer to Figure 12 , the chip 1100 may further include an output interface 1140.

[0265] Among them, the processor 1110 can control the output interface 1140 to communicate with other devices or chips. Specifically, it can output information or data to other devices or chips.

[0266] It should be understood that the chip 1100 can be applied to the network device in the embodiments of the present application, and the chip can implement the corresponding processes implemented by the network device in the various methods of the embodiments of the present application, and can also implement the corresponding processes implemented by the terminal device in the various methods of the embodiments of the present application. For the sake of brevity, it will not be elaborated here.

[0267] It should also be understood that the various components in the chip 1100 are connected through a bus system. Among them, the bus system includes, in addition to the data bus, a power bus, a control bus, and a status signal bus.

[0268] The processors mentioned above may include, but are not limited to:

[0269] General-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and so on.

[0270] The processor can be used to implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The steps of the methods disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, flash memory, read-only memory, programmable read-only memory, or erasable programmable memory, register, etc. This storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above methods.

[0271] The memories mentioned above include, but are not limited to:

[0272] Volatile memory and / or non-volatile memory. Among them, the non-volatile memory can be a read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).

[0273] It should be noted that the memories described herein are intended to include these and any other suitable types of memories.

[0274] In the embodiments of the present application, a computer-readable storage medium is also provided for storing a computer program. The computer-readable storage medium stores one or more programs, and the one or more programs include instructions that, when executed by a portable electronic device including a plurality of application programs, can enable the portable electronic device to execute the methods of the method embodiments.

[0275] Optionally, the computer-readable storage medium can be applied to the network device in the embodiments of the present application, and the computer program causes the computer to execute the corresponding processes implemented by the network device in the various methods of the embodiments of the present application. For the sake of brevity, details are not described herein again.

[0276] Optionally, the computer-readable storage medium can be applied to the mobile terminal / terminal device in the embodiments of the present application, and the computer program causes the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of the present application. For the sake of brevity, details are not described herein again.

[0277] An embodiment of the present application also provides a computer program product, including a computer program.

[0278] Optionally, the computer program product can be applied to the network device in the embodiments of the present application, and the computer program causes the computer to execute the corresponding processes implemented by the network device in the various methods of the embodiments of the present application. For the sake of brevity, details are not described herein again.

[0279] Optionally, the computer program product can be applied to the mobile terminal / terminal device in the embodiments of the present application, and the computer program causes the computer to execute the corresponding processes implemented by the mobile terminal / terminal device in the various methods of the embodiments of the present application. For the sake of brevity, details are not described herein again.

[0280] An embodiment of the present application also provides a computer program. When the computer program is executed by a computer, the computer can execute the methods in the method embodiments.

[0281] Optionally, the computer program can be applied to the network device in the embodiments of the present application. When the computer program runs on the computer, it causes the computer to execute the corresponding processes implemented by the network device in the various methods of the embodiments of the present application. For the sake of brevity, details are not described herein again.

[0282] In addition, an embodiment of the present application also provides a communication system, which may include the above-mentioned terminal device and network device to form a communication system 100 as shown in Figure 1 For the sake of brevity, details are not described herein again. It should be noted that terms such as "system" in this article may also be referred to as "network management architecture" or "network system", etc.

[0283] It should also be understood that the terms used in the embodiments of the present application and the appended claims are only for the purpose of describing specific embodiments, and are not intended to limit the embodiments of the present application.

[0284] For example, the singular forms "a", "the", "above-mentioned", and "this" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0285] Those skilled in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the embodiments of the present application.

[0286] If it is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in the embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories, random access memories, magnetic disks, or optical discs that can store program codes.

[0287] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.

[0288] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways.

[0289] For example, the division of units, modules, or components in the device embodiments described above is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units, modules, or components can be combined or integrated into another system, or some units, modules, or components can be ignored or not executed.

[0290] Again, for example, the units / modules / components described as separate / display components may or may not be physically separated, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units / modules / components can be selected according to actual needs to achieve the purpose of the embodiments of the present application.

[0291] Finally, it should be noted that the couplings, direct couplings or communication connections shown or discussed above between each other can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.

[0292] The above content is only the specific implementation manner of the embodiments of the present application, but the protection scope of the embodiments of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the embodiments of the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the embodiments of the present application. Therefore, the protection scope of the embodiments of the present application shall be subject to the protection scope of the claims.

Claims

1. A wireless communication method, characterized in that, comprising: A device to be networked generates a first random value; The device to be networked generates an out-of-band (OOB) authentication value based on a target value by using an encryption algorithm, where the target value includes the first random value and first information, and the first information includes the device unique identifier (DID) of the device to be networked and / or a secret key for encrypting the OOB authentication value.

2. The method according to claim 1, characterized in that, The target value is a value formed by connecting the first random value and the first information in a preset order.

3. The method according to claim 2, characterized in that, The first information is information stored in the device to be networked.

4. The method according to claim 1, characterized in that, The method further comprises: The device to be networked sends the first random value to the network configuration device.

5. The method according to claim 4, characterized in that, The device to be networked sending the first random value to the network configuration device includes: The device to be networked sends a network configuration beacon to the network configuration device, where the network configuration beacon is used to indicate that the device to be networked is a device waiting for network configuration, and the network configuration beacon includes a universally unique identifier (UUID), and the UUID includes the first random value.

6. The method according to claim 5, characterized in that, The UUID further includes at least one of the following: The device unique identifier (DID) of the device to be networked, a company identifier, and reserved bit positions.

7. The method according to claim 1, characterized in that, The method further comprises: The device to be networked receives a first confirmation value sent by the network configuration device; The device to be networked receives a second random value sent by the network configuration device; The device to be networked verifies the first confirmation value based on the OOB authentication value and the second random value.

8. The method according to claim 1, characterized in that, The method further comprises: The device to be networked sends a second confirmation value to the network configuration device; The device to be networked sends a third random value to the network configuration device, where the third random value is used to generate the second confirmation value.

9. The method according to any one of claims 1 to 8, characterized in that, The encryption algorithm includes a hash algorithm.

10. A wireless communication method, characterized in that, comprising: A network configuration device receives a network configuration beacon sent by a device to be networked and sent to a cloud device, where the network configuration beacon is used to indicate that the device to be networked is a device waiting for network configuration, the network configuration beacon includes a universally unique identifier (UUID), the UUID includes a first random value, and at least one of the device unique identifier (DID) of the device to be networked, a company identifier, and reserved bit positions; The network configuration device receives an out-of-band (OOB) authentication value sent by the cloud device, where the out-of-band (OOB) authentication value is an authentication value generated by the cloud device based on the first random value.

11. The method according to claim 10, characterized in that, The method further comprises: The network configuration device receives a second confirmation value sent by the device to be networked; The distribution network device receives a third random value sent by the device to be networked. The distribution network device verifies the second confirmation value based on the OOB authentication value and the third random value.

12. The method according to claim 10 or 11, wherein, the method further includes: The distribution network device sends a first confirmation value to the device to be networked; The distribution network device sends a second random value to the device to be networked, and the second random value is used to generate the first confirmation value.

13. A wireless communication method, wherein, includes: The first device receives a first random value sent by the second device; The first device generates an out-of-band (OOB) authentication value based on a target value using an encryption algorithm, where the target value includes the first random value and first information, and the first information includes the device unique identifier (DID) of the device to be networked and / or a secret key for encrypting the OOB authentication value.

14. The method according to claim 13, wherein, the target value is a value formed by connecting the first random value and the first information in a preset order.

15. The method according to claim 13, wherein, the DID and the first information are information stored in the first device.

16. The method according to claim 13, wherein, the first device receiving the first random value sent by the second device includes: The first device receives a device-to-be-networked beacon sent by the second device, where the device-to-be-networked beacon is used to indicate that the device to be networked is a device waiting to be networked, and the device-to-be-networked beacon includes a universally unique identifier (UUID), and the UUID includes the first random value.

17. The method according to claim 16, wherein, the UUID further includes at least one of the following: the device unique identifier (DID) of the device to be networked, a company identifier, and reserved bit positions.

18. The method according to claim 13, wherein, the first device is a cloud device, and the second device is a distribution network device; wherein, the first device receiving the first random value sent by the second device includes: The cloud device receives the first random value sent by the device to be networked through the distribution network device.

19. The method according to claim 18, wherein, the method further includes: The cloud device sends the OOB authentication value to the distribution network device.

20. The method according to claim 13, wherein, the first device is a distribution network device, and the second device is a device to be networked.

21. The method according to any one of claims 13 to 20, wherein, the encryption algorithm includes a hash algorithm.

22. A device to be networked, wherein, includes a processing unit, and the processing unit is configured to: generate a first random value; generate an out-of-band (OOB) authentication value based on a target value using an encryption algorithm, where the target value includes the first random value and first information, and the first information includes the device unique identifier (DID) of the device to be networked and / or a secret key for encrypting the OOB authentication value.

23. The device to be networked according to claim 22, characterized in that, the target value is a value formed by connecting the first random value and the first information in a preset order.

24. The device to be networked according to claim 22, characterized in that, the first information is the information stored in the device to be networked.

25. The device to be networked according to claim 22, characterized in that, the device to be networked further comprises: a communication unit, configured to send the first random value to the network configuration device.

26. The device to be networked according to claim 25, characterized in that, the communication unit is specifically configured to: send a network configuration beacon to the network configuration device, the network configuration beacon being used to indicate that the device to be networked is a device waiting for network configuration, the network configuration beacon including a Universally Unique Identifier (UUID), and the UUID including the first random value.

27. The device to be networked according to claim 26, characterized in that, the UUID further includes at least one of the following: the device unique identifier (DID) of the device to be networked, the company identifier, and the reserved bit.

28. The device to be networked according to claim 22, characterized in that, the processing unit is further configured to: receive a first confirmation value sent by the network configuration device; receive a second random value sent by the network configuration device; verify the first confirmation value based on the OOB authentication value and the second random value.

29. The device to be networked according to claim 22, characterized in that, the processing unit is further configured to: send a second confirmation value to the network configuration device; send a third random value to the network configuration device, the third random value being used to generate the second confirmation value.

30. The device to be networked according to any one of claims 22 to 29, characterized in that, the encryption algorithm includes a hash algorithm.

31. A network configuration device, characterized in that, it includes a communication unit, and the communication unit is configured to: receive a network configuration beacon sent by a device to be networked and send the network configuration beacon to a cloud device, the network configuration beacon being used to indicate that the device to be networked is a device waiting for network configuration, the network configuration beacon including a Universally Unique Identifier (UUID), the UUID including a first random value, and at least one of the device unique identifier (DID) of the device to be networked, the company identifier, and the reserved bit; receive an out-of-band (OOB) authentication value sent by the cloud device, the out-of-band (OOB) authentication value being an authentication value generated by the cloud device based on the first random value.

32. The network configuration device according to claim 31, characterized in that, the network configuration device further includes a processing unit, and the processing unit is configured to: receive a second confirmation value sent by the device to be networked; receive a third random value sent by the device to be networked; verify the second confirmation value based on the OOB authentication value and the third random value.

33. The network configuration device according to claim 31 or 32, characterized in that, the communication unit is further configured to: send a first confirmation value to the device to be networked; send a second random value to the device to be networked, the second random value being used to generate the first confirmation value.

34. A communication device, characterized in that, it includes: a communication unit for receiving a first random value sent by a second device; a processing unit for generating an out-of-band (OOB) authentication value based on a target value by using an encryption algorithm, where the target value includes the first random value and a first piece of information, and the first piece of information includes a device unique identifier (DID) of the device to be networked and / or a secret key for encrypting the OOB authentication value.

35. The communication device according to claim 34, characterized in that, the target value is a value formed by connecting the first random value and the first piece of information in a preset order.

36. The communication device according to claim 34, characterized in that, the DID and the first piece of information are information stored in the communication device.

37. The communication device according to claim 34, characterized in that, the communication unit is specifically configured to: receive a network configuration beacon to be sent by the second device, where the network configuration beacon to be sent is used to indicate that the device to be networked is a device waiting for network configuration, and the network configuration beacon to be sent includes a universally unique identifier (UUID), and the UUID includes the first random value.

38. The communication device according to claim 37, characterized in that, the UUID further includes at least one of the following: the device unique identifier (DID) of the device to be networked, a company identifier, and reserved bit positions.

39. The communication device according to claim 34, characterized in that, the communication device is a cloud device, and the second device is a network configuration device; wherein, the communication unit is specifically configured to: receive the first random value sent by the device to be networked through the network configuration device.

40. The communication device according to claim 39, characterized in that, the communication unit is further configured to: send the OOB authentication value to the network configuration device.

41. The communication device according to claim 34, characterized in that, the communication device is a network configuration device, and the second device is a device to be networked.

42. The communication device according to any one of claims 34 to 41, characterized in that, the encryption algorithm includes a hash algorithm.

43. A device to be networked, characterized in that, it includes: a processor and a memory, and the processor is configured to call and run a computer program stored in the memory to execute the method according to any one of claims 1 to 9.

44. A network configuration device, characterized in that, it includes: a processor, a memory, and a transceiver, the memory is used for storing a computer program, and the processor is configured to call and run the computer program stored in the memory to control the transceiver to execute the method according to any one of claims 10 to 12.

45. A communication device, characterized in that, it includes: a processor, a memory, and a transceiver, the memory is used for storing a computer program, and the processor is configured to call and run the computer program stored in the memory to execute the method according to any one of claims 13 to 21.

46. A chip, characterized in that, it includes: A processor for calling and running a computer program from a memory, such that a device installed with the chip executes the method according to any one of claims 1 to 9.

47. A chip, characterized in that, it comprises: A processor for calling and running a computer program from a memory, such that a device installed with the chip executes the method according to any one of claims 10 to 12.

48. A chip, characterized in that, it comprises: A processor for calling and running a computer program from a memory, such that a device installed with the chip executes the method according to any one of claims 13 to 21.

49. A computer-readable storage medium, characterized in that, it is used for storing a computer program, and the computer program causes a computer to execute the method according to any one of claims 1 to 9.

50. A computer-readable storage medium, characterized in that, it is used for storing a computer program, and the computer program causes a computer to execute the method according to any one of claims 10 to 12.

51. A computer-readable storage medium, characterized in that, it is used for storing a computer program, and the computer program causes a computer to execute the method according to any one of claims 13 to 21.

52. A computer program product, characterized in that, it includes computer program instructions, and the computer program instructions cause a computer to execute the method according to any one of claims 1 to 9.

53. A computer program product, characterized in that, it includes computer program instructions, and the computer program instructions cause a computer to execute the method according to any one of claims 10 to 12.

54. A computer program product, characterized in that, it includes computer program instructions, and the computer program instructions cause a computer to execute the method according to any one of claims 13 to 21.

Citation Information

Patent Citations

  • Bluetooth Mesh network and distribution network authentication method and device thereof, and storage medium

    CN110505606A

  • Bluetooth mesh network provisioning authentication

    US20190357043A1