Wi-fi sensing based network configuration method, embedded chip system and medium
By using Wi-Fi sensing technology to select anchor master devices in a nearby sensing network cluster, and utilizing key negotiation and encryption/decryption processes, the problems of complex and insecure smart device network configuration operations are solved, enabling fast and secure batch network configuration, and improving user experience and success rate.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ESPRESSIF SYST SHANGHAI
- Filing Date
- 2022-10-21
- Publication Date
- 2026-05-22
AI Technical Summary
Existing methods for configuring smart devices have problems such as complex operation, poor security, and low success rate, especially when configuring multiple devices.
A Wi-Fi-sensing-based network configuration method is adopted. An anchor master device is selected in the neighboring sensing network cluster. Through key negotiation and encryption/decryption processes, multiple devices to be configured are configured quickly and securely. This includes negotiating a shared key, generating encrypted ciphertext, and decrypting it to obtain the network configuration key and information.
It enables fast and secure batch network configuration, improves the success rate and operational stability of network configuration, reduces manual operation steps for users, enhances user experience, and ensures data security during the encryption process.
Smart Images

Figure CN115604700B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of this disclosure generally relate to the field of wireless communication, and more specifically to a Wi-Fi-sensing-based distribution network method. Background Technology
[0002] Currently, most smart hardware products on the market are based on Wi-Fi communication. These Wi-Fi devices typically lack a user interface, unlike personal computers and mobile phones, which provide users with an interface to select and connect to Wi-Fi hotspots. To enable these user-uninterrupted smart devices to connect to the network, the problem of correctly connecting them to a router must first be solved. In other words, it is necessary to solve the problem of how to securely and reliably transmit information used for router connection, such as the wireless network's SSID (Service Set Identifier) and access password, to these smart devices. This invention aims to solve this problem.
[0003] For these smart hardware devices that lack a human-computer interaction interface, there are currently two main methods for network configuration:
[0004] The first method is to set the smart hardware to Soft AP mode, that is, set the mobile phone to Station mode, and then use the mobile phone to connect to the Soft AP on the smart hardware. After the connection is successful, the SSID and password of the wireless access point are transmitted to the smart device. After receiving the SSID and password of the wireless access point, the smart device switches from Soft AP mode back to Station mode and uses the received SSID and password of the wireless access point to connect to the wireless access point to complete the network configuration.
[0005] The second method involves setting the smart hardware to promiscuous mode, in which it can receive qualified wireless packets. On the mobile phone, the SSID and access password are encoded into a UDP (User Datagram Protocol) packet and transmitted via wireless broadcast or multicast. Upon receiving the wireless packet, the smart hardware decodes it to obtain the correct SSID and access password, and then uses this information to connect to the wireless access point, completing network configuration.
[0006] The traditional Soft AP network configuration and promiscuous mode network configuration methods described above are slow and have poor security. Especially when faced with the need to configure multiple smart devices simultaneously, the network configuration efficiency is very low. Their main disadvantages include the following:
[0007] Poor user experience: While the Soft AP-based network configuration method can guarantee successful configuration, the user experience is not user-friendly because this method requires the mobile phone to connect to the Soft AP first, whether manually (iOS) or automatically (Android), and then switch back after configuration. The whole operation process is very cumbersome and complicated.
[0008] Poor security and low success rate: Although smart configuration is convenient, there is a certain probability of failure in complex Wi-Fi environments. The mobile phone has to transmit the router password to the Wi-Fi module. If it is in plaintext, it can be easily intercepted, thus posing a great security risk to the Wi-Fi network.
[0009] Slow speed: When using Soft AP and promiscuous mode for network configuration, each device needs to interact with the cloud and complete the binding process one by one. A single network configuration usually takes about 10 seconds. If there are dozens or even hundreds of devices to be configured, the configuration time will be very long. Summary of the Invention
[0010] Therefore, it is desirable to provide a Wi-Fi-aware batch network configuration method and system, which aims to solve the problems of complex operation, poor security and low success rate of existing smart devices when performing single device network configuration or batch network configuration.
[0011] In a first aspect, a Wi-Fi-aware network configuration method is disclosed, which is executed in a proximity-aware network cluster formed by multiple devices to be configured, wherein one of the multiple devices to be configured is selected as the anchor master device. The method includes: a) at least one device to be configured negotiates with the anchor master device to obtain a first shared key; b) at least one device to be configured obtains a first encrypted ciphertext from the anchor master device, the first encrypted ciphertext including ciphertext obtained by encrypting the network configuration key generated by the anchor master device according to the first shared key; c) at least one device to be configured obtains a third encrypted ciphertext from a mobile terminal, the third encrypted ciphertext being ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal according to the network configuration key; d) at least one device to be configured decrypts the first encrypted ciphertext according to the first shared key to obtain a network configuration key; e) at least one device to be configured decrypts the third encrypted ciphertext according to the network configuration key to obtain network configuration information.
[0012] Preferably, step a) further includes: at least one device to be configured sends configuration information to the anchor master device, wherein the configuration information indicates whether at least one device to be configured has encrypted access.
[0013] More preferably, if at least one device to be configured for network access is configured with encrypted access, then at least one device to be configured for network access is configured with a private key, which is obtained by a mobile terminal by scanning a QR code on the device to be configured for network access, or by the user entering it on the mobile terminal, or by anchoring the master device.
[0014] More preferably, if at least one device to be configured for network configuration is equipped with encrypted access, step c) further includes: at least one device to be configured for network configuration obtains a third encrypted ciphertext from the mobile terminal, wherein the third encrypted ciphertext is ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal with an updated network configuration key obtained by performing calculations based on the private key and the network configuration key.
[0015] More preferably, if at least one device to be configured for network access is equipped with encrypted access, then step e) further includes: at least one device to be configured for network access decrypts the third encrypted ciphertext according to the private key and the network access key to obtain the network access information.
[0016] In a second aspect, a Wi-Fi-aware network configuration method is disclosed, which is executed in a proximity-aware network cluster formed by multiple devices to be configured, wherein one of the multiple devices to be configured is selected as the anchor master device. The method includes: a) the anchor master device negotiating with at least one device to be configured to obtain a first shared key; b) the anchor master device sending a first encrypted ciphertext to at least one device to be configured, the first encrypted ciphertext being ciphertext obtained by encrypting the network configuration key generated by the anchor master device according to the first shared key; c) the anchor master device negotiating with a mobile terminal to obtain a second shared key; d) the anchor master device sending a second encrypted ciphertext to the mobile terminal, the second encrypted ciphertext being ciphertext obtained by encrypting the network configuration key according to the second shared key.
[0017] Preferably, step a) further includes: the anchoring master device obtaining configuration information from at least one device to be configured, wherein the configuration information indicates whether at least one device to be configured has encrypted access.
[0018] Preferably, step d) further includes: the anchoring master device sending a second encrypted ciphertext to the mobile terminal, the second encrypted ciphertext being ciphertext obtained by encrypting configuration information and network key according to the second shared key.
[0019] In the third aspect, a Wi-Fi-aware network configuration method is disclosed, which is executed in a proximity-aware network cluster formed by multiple devices to be configured, wherein one of the multiple devices to be configured is selected as the anchor master device. The method includes: a) a mobile terminal negotiating with the anchor master device to obtain a second shared key; b) the mobile terminal obtaining a second encrypted ciphertext from the anchor master device, the second encrypted ciphertext being ciphertext obtained by encrypting the network configuration key according to the second shared key; c) the mobile terminal decrypting the second encrypted ciphertext according to the second shared key to obtain the network configuration key; d) the mobile terminal sending a third encrypted ciphertext to at least one device to be configured, the third encrypted ciphertext being ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal according to the network configuration key.
[0020] Preferably, step b) further includes: the mobile terminal obtaining a second encrypted ciphertext from the anchoring master device, the second encrypted ciphertext being ciphertext obtained by encrypting configuration information and a network configuration key according to a second shared key; wherein the configuration information indicates whether at least one device to be configured for network configuration is configured with encrypted access, wherein if at least one device to be configured for network configuration is configured with encrypted access, then at least one device to be configured for network configuration is configured with a private key.
[0021] More preferably, step c) further includes: the mobile terminal decrypting the second encrypted ciphertext according to the second shared key to obtain configuration information and network configuration key.
[0022] More preferably, if at least one device to be configured for network access is configured with encrypted access, step d) further includes: the mobile terminal obtaining the private key of the device to be configured for network access, and performing a calculation on the private key and the network access key to obtain an updated network access key; and encrypting the network access information according to the updated network access key to obtain a third encrypted ciphertext.
[0023] In a fourth aspect, a computer-readable storage medium is disclosed, on which a computer program is stored, which, when executed, causes a device to perform the method of the first aspect as described above, or causes the device to perform the method of the second aspect as described above, or causes the device to perform the method of the third aspect as described above.
[0024] In a fifth aspect, an embedded chip system is disclosed, comprising: a processor for calling and running a computer program from a memory, causing a communication device equipped with the embedded chip system to perform the methods of the first, second, or third aspects described above.
[0025] It should be noted that, where appropriate, any feature of any embodiment of the embodiments disclosed herein may be applied to any other embodiment. Similarly, any advantage of any embodiment of the embodiments may be applied to other embodiments, and vice versa. Other objects, features, and advantages of the appended embodiments will be apparent from the following description.
[0026] Some embodiments are intended to address, mitigate, or eliminate at least some of the above or other disadvantages.
[0027] Specifically, addressing the aforementioned issues, the Wi-Fi-sensing-based network configuration method provided in this disclosure can achieve highly secure network configuration. Furthermore, by accurately selecting the network configuration target, this disclosure effectively improves the success rate of network configuration and ensures high operational stability. In addition, the method provided in this disclosure can achieve batch network configuration when multiple devices requiring encryption access exist. For devices requiring encryption access, the method of this disclosure can also effectively prevent erroneous network configuration operations. Therefore, the technical solution of this disclosure can serve different network configuration application scenarios and reduces the number of manual network configuration steps for users throughout the process, improving the user experience. The technical solution of this disclosure can effectively and quickly realize network configuration for multiple Wi-Fi devices, and the data exchange during the network configuration process is encrypted; only the devices to be configured can decrypt the data, thus ensuring network configuration security. Moreover, utilizing Wi-Fi sensing technology, this disclosure can complete network configuration for all devices in as little as tens of seconds. Attached Figure Description
[0028] Figure 1 A schematic diagram of a proximity sensing network cluster consisting of multiple devices to be configured on the network is shown.
[0029] Figure 2 This shows the addition of mobile terminals, such as Figure 1 The diagram shows a proximity sensing network cluster consisting of multiple devices to be configured on the network.
[0030] Figure 3 A schematic diagram illustrating the communication process between any device to be configured on the network, the anchoring master device, and the mobile terminal in one embodiment is shown.
[0031] Figure 4 This diagram illustrates how a device in a proximity sensing network cluster sends configuration information to an anchoring master device via Wi-Fi sensing frames.
[0032] Figure 5 A schematic diagram of the communication process between any device to be configured on the network, the anchoring master device, and the mobile terminal in another embodiment is shown.
[0033] Figure 6A schematic flowchart of a Wi-Fi-sensing-based network distribution method according to an embodiment of the present disclosure is shown.
[0034] Figure 7 A schematic flowchart of a Wi-Fi-aware network distribution method according to another embodiment of the present disclosure is shown.
[0035] Figure 8 A schematic flowchart of a Wi-Fi-sensing-based network distribution method according to another embodiment of the present disclosure is shown.
[0036] Figure 9 A schematic block diagram of a network device 900 according to one embodiment is shown.
[0037] Figure 10 A schematic diagram of the hardware structure of a network device 1000 according to one embodiment is shown. Detailed Implementation
[0038] This disclosure will now be discussed with reference to several exemplary embodiments. It should be understood that these embodiments are discussed only to enable those skilled in the art to better understand and thus achieve the purposes of this disclosure, and not to imply any limitation on the scope of this disclosure.
[0039] It should be understood that although the terms “first” and “second”, etc., may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used only to distinguish elements from one another. For example, without departing from the scope of the exemplary embodiments, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element. As used herein, the term “and / or” includes any and all combinations of one or more of the associated listed items.
[0040] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments. As used herein, the singular forms “a,” “an,” and “the” are intended to also include the plural forms unless the context clearly indicates otherwise. It will be further understood that, when used herein, the terms “comprising,” “including,” “having,” “with,” “containing,” and / or “incorporated” indicate the presence of the stated features, elements, and / or components, but do not exclude the presence or addition of one or more other features, elements, components, and / or combinations thereof.
[0041] In the following description and claims, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. Some exemplary embodiments of this disclosure will now be described with reference to the accompanying drawings.
[0042] Before introducing the embodiments of this disclosure, the basic concepts to be applied in this invention will be explained in order to better explain the implementation process of the solutions of this disclosure.
[0043] Wi-Fi Aware Protocol: The Wi-Fi Aware protocol is a neighboring device discovery protocol customized by the Wi-Fi Alliance based on the IEEE 802.11 protocol. This protocol works on IEEE 802.11 devices, but it is not an enhancement or revision of the IEEE 802.11 standard, and Wi-Fi Aware only requires IEEE 802.11 end-device manufacturers to modify and upgrade their driver software. The Wi-Fi Aware function enables devices to discover each other and connect directly without any other type of connection between them. Wi-Fi Aware is also known as a Neighborhood Aware Network (NAN).
[0044] Neighbor Awareness Network Cluster (NAN Cluster): A Neighbor Awareness Network Cluster is a collection of multiple adjacent devices that share a common set of NAN parameters, are synchronized with the same discovery window time schedule, and have a unique NAN Cluster ID.
[0045] NAN Devices: Devices that support the implementation of the NAN protocol. NAN devices can function as either a Master or a Non-Master. In a NAN cluster, the highest-priority Master is the Anchor Master, which maintains timing for a synchronized cluster, and other NAN devices in the cluster must adhere to its Time Synchronization Function (TSF). Every NAN device in a NAN cluster should have the capability to become an Anchor Master. Devices that inherit the title of Anchor Master must maintain their original TSF.
[0046] Furthermore, devices that support Wi-Fi sensing can autonomously detect, alert, and connect to other devices without needing a Wi-Fi access point (AP). Specifically, Wi-Fi sensing applications can be configured to alert users to nearby devices running the same application. Wi-Fi sensing discovery can be based on various parameters such as distance; for example, alerting the user when another device running the same application is less than 10 feet (approximately 3.048 meters) away. Applications can also be configured to establish a secure, point-to-point data connection with another device for application data exchange.
[0047] Example 1
[0048] Figure 1 This diagram illustrates a proximity sensing network cluster composed of multiple Wi-Fi-sensing devices. Figure 1 As shown, multiple devices awaiting network configuration enable Wi-Fi sensing service and negotiate to form a proximity sensing network cluster. Among these devices, the one with the highest Master priority is elected as the AnchorMaster, while the remaining devices (e.g., device A, device B, ..., device N) are non-AnchorMaster devices. The AnchorMaster can send beacon frames to allow other devices seeking to join the proximity sensing network cluster to discover it, and these other devices can reply with Wi-Fi sensing frames to allow the AnchorMaster to discover them as well.
[0049] Figure 2 This shows the addition of mobile terminals, such as Figure 1 The diagram illustrates a proximity sensing network cluster. When a mobile terminal enables Wi-Fi sensing service, it joins the cluster, which consists of multiple devices awaiting network configuration, upon receiving a beacon frame from the cluster. As an example and not a limitation, the mobile terminal can be a smartphone, tablet, laptop, or other mobile device that supports Wi-Fi sensing service.
[0050] As an example, and not a limitation, the mobile terminal obtains distribution network information. The mobile terminal may obtain the distribution network information in advance through human-computer interaction, or through any other applicable method.
[0051] Figure 3 A schematic diagram illustrates the communication process between any device to be distributed to the network, the anchoring master device, and the mobile terminal, in order to ultimately achieve the purpose of network distribution.
[0052] A. The anchoring master device distributes the distribution key to the device to be distributed.
[0053] Step S110: The device to be configured on the network negotiates with the anchor master device to obtain a first shared key. Here, the device to be configured on the network has not yet obtained a network configuration key. As an example and not a limitation, the anchor master device and the device to be configured on the network negotiate and calculate the first shared key using a symmetric key algorithm.
[0054] Step S114: The anchoring master device generates a network configuration key. As an example and not a limitation, the anchoring master device can generate the network configuration key in a random manner.
[0055] Step S116: The anchoring master device encrypts the distribution key according to the first shared key to obtain the first encrypted ciphertext.
[0056] Step S118: The anchoring master device sends the first encrypted ciphertext to the device to be distributed.
[0057] Step S134: The device to be configured decrypts the received first encrypted ciphertext according to the first shared key, thereby obtaining the configuration key.
[0058] As an example and not a limitation, the process of the anchoring master device distributing the network distribution key to the device to be configured may also include the following steps:
[0059] Step S112: The device to be configured sends configuration information to the anchor master device.
[0060] It is worth noting that, unless otherwise specified, the steps of the above method are not limited in the order of execution. For example, step S112 can be performed before or after any of steps S114 to S134.
[0061] As an example, and not a limitation, step S112 can be performed when the device to be configured on the network has just joined the proximity sensing network cluster. Alternatively, this step can be performed at any other suitable time. Figure 4 The diagram illustrates how a device in a proximity sensing network cluster sends configuration information to an anchoring master device via Wi-Fi sensing frames.
[0062] For example, the anchoring master device can organize and save the configuration information of all devices to be configured after receiving Wi-Fi sensing frames from each device to be configured.
[0063] In some embodiments, the Wi-Fi sensing frame can be a publish frame, a follow-up frame, or a subscribe frame, and all of these sensing frames can carry custom information.
[0064] As an example and not a limitation, in step S110, the device to be configured and the anchor master device negotiate to obtain the first shared key, including: establishing a data channel and calculating the first shared key through a key negotiation algorithm; wherein the key negotiation can be based on the four-way handshake of the pairwise secure key negotiation process in NAN to negotiate the key, or it can be generated through asymmetric encryption algorithms such as DH, RSA, or ECC.
[0065] As an example, and not a limitation, the configuration information may include address information for each device to be configured, such as MAC address information. As an example, and not a limitation, the configuration information may also include encrypted access information, indicating whether the device to be configured has encrypted access configured. If the device to be configured has encrypted access configured, it indicates that the device has a private key configured. Furthermore, the configuration information may also include configuration information obtained by the anchoring master device from other devices to be configured in the neighboring sensing network cluster, such as address information and encrypted access information of the other devices to be configured.
[0066] As an example and not a limitation, the above method and steps for the anchored master device to distribute the network distribution key to the device to be configured can be further extended to any device to be configured that has already obtained the network distribution key to distribute the network distribution key to other devices to be configured. After the device to be configured decrypts the first encrypted ciphertext according to the first shared key to obtain the network distribution key and the address information of at least one device to be configured that has not obtained the network distribution key, the following steps are performed to distribute the network distribution key to at least one device to be configured that has not obtained the network distribution key:
[0067] (1) At least one device to be configured without a configuration key negotiates with at least one device to be configured that has a configuration key to obtain a corresponding first shared key;
[0068] (2) At least one device to be configured without obtaining a configuration key obtains a corresponding first encrypted ciphertext from at least one device to be configured that has obtained a configuration key. The corresponding first encrypted ciphertext is the ciphertext obtained by encrypting the configuration key according to the corresponding first shared key.
[0069] (3) At least one device to be configured to receive network data that has not obtained the network key shall decrypt the corresponding first encrypted ciphertext according to the corresponding first shared key in order to obtain the network key.
[0070] As described above, in this scenario, firstly, the device that has obtained the network configuration key negotiates with the device to be configured to obtain a first shared key. Secondly, the device that has obtained the network configuration key encrypts the network configuration key according to the first shared key to obtain a first encrypted ciphertext. Then, the device that has obtained the network configuration key sends the first encrypted ciphertext to the device to be configured. The device to be configured decrypts the received first encrypted ciphertext according to the first shared key, thereby obtaining the network configuration key. Further optimized, the device that has obtained the network configuration key can also send the configuration information of other devices in the proximity sensing network cluster to be configured, such as address information and encryption access information, obtained from the anchoring master device. This distribution method facilitates the rapid acquisition of network configuration keys for multiple devices in the proximity sensing network cluster. Compared to the previous method where the anchoring master device needs to connect to the device to be configured and send the network configuration key each time, this optimized method can exponentially improve the distribution speed of the network configuration key.
[0071] B. The anchoring master device sends configuration information and network configuration key to the mobile terminal.
[0072] Step S120: The anchoring master device negotiates with the mobile terminal to obtain the second shared key.
[0073] Step S122: The anchoring master device encrypts the distribution key according to the second shared key to obtain the second encrypted ciphertext.
[0074] Step S124: The anchored master device sends the second encrypted ciphertext to the mobile terminal.
[0075] Step S126: The mobile terminal decrypts the second encrypted ciphertext according to the second shared key to obtain the network configuration key.
[0076] Further optimized, in step S126, the mobile terminal decrypts the second encrypted ciphertext according to the second shared key to obtain the network configuration key and network configuration information. Here, by example and not limitation, the configuration information may include the address information of each device to be configured, such as MAC address information. By example and not limitation, the configuration information may also include encryption access information, indicating whether the device to be configured is configured with encryption access. If the device to be configured is configured with encryption access, it indicates that the device to be configured has a private key.
[0077] It is worth noting that, unless otherwise specified, the steps of the above method are not limited in the order of execution. For example, the communication steps between the mobile terminal and the anchoring master device can be executed via Wi-Fi sensing frames.
[0078] C. The mobile terminal sends network distribution information to the device to be networked.
[0079] Step S128: The mobile terminal obtains the network distribution information.
[0080] Step S130: The mobile terminal encrypts the obtained network configuration information according to the network configuration key to obtain the third encrypted ciphertext.
[0081] Step S132: The mobile terminal sends a third encrypted ciphertext to at least one device to be configured on the network.
[0082] As an example rather than a limitation, mobile terminals can obtain network distribution information through human-computer interaction.
[0083] In another embodiment, after the mobile terminal completes step S132 above, if the device to be configured for network access is configured with encryption access control, the following steps are also performed: obtaining the private key of the device to be configured for network access control, and performing a calculation on the private key and the network access control key to obtain an updated network access control key; and encrypting the network access control information according to the updated network access control key to obtain a third encrypted ciphertext. If the device to be configured for network access control is not configured with encryption access control, the following steps are performed: encrypting the network access control information according to the network access control key to obtain a third encrypted ciphertext.
[0084] As an example, and not a limitation, a mobile terminal can obtain the private key of a device to be configured by scanning a QR code on the device, or by having the user enter the private key on the mobile terminal, or by anchoring to a master device. Alternatively, the mobile terminal can also obtain the private key of a device to be configured by scanning other identifiable code patterns on the device. Each device configured with encrypted access has a unique private key.
[0085] It is worth noting that, unless otherwise specified, the steps of the above method are not limited in the order of execution. For example, the communication steps between the mobile terminal and the device to be configured on the network can be executed via Wi-Fi sensing frames.
[0086] D. The device to be distributed obtains distribution network information.
[0087] As described above, the device to be configured executes step S134 to obtain the configuration key: at least one device to be configured obtains a third encrypted ciphertext from the mobile terminal. The third encrypted ciphertext is the ciphertext obtained by encrypting the configuration information obtained by the mobile terminal according to the configuration key.
[0088] After receiving the third encrypted ciphertext sent from the mobile terminal, the device to be configured further executes step S136: at least one device to be configured decrypts the third encrypted ciphertext according to the configuration key to obtain the configuration information.
[0089] In another embodiment, after receiving the third encrypted ciphertext from the mobile terminal, if the device to be configured for network configuration has encrypted access control, it further performs the following steps: performing a calculation on the private key and the network configuration key to obtain an updated network configuration key, and decrypting the third encrypted ciphertext according to the updated network configuration key to obtain network configuration information. If the device to be configured for network configuration has not been configured for encrypted access control, it performs the following step: decrypting the third encrypted ciphertext according to the network configuration key to obtain network configuration information.
[0090] As an example and not a limitation, after obtaining network configuration information, the device to be configured scans for the target router and connects to it using the network configuration information to complete the network configuration. Optionally, the device to be configured may send a Wi-Fi sensing frame to the mobile terminal to notify the mobile terminal to stop sending other Wi-Fi sensing frames.
[0091] Example 2
[0092] Figure 5 A schematic diagram of the communication process between any device to be distributed to the network, the anchoring master device, and the mobile terminal in another embodiment is shown to ultimately achieve the purpose of network distribution.
[0093] Step S210: The device to be configured with the network negotiates and obtains a first shared key with the anchor master device. Here, the device to be configured with the network has not yet obtained a network configuration key. As an example and not a limitation, the anchor master device and the device to be configured with the network negotiate and calculate the first shared key using a symmetric key algorithm.
[0094] Step S212: The device to be configured sends configuration information to the anchor master device. This configuration information, by way of example and not limitation, may include address information for each device to be configured, such as MAC address information. The configuration information also includes encryption access information, indicating whether the device to be configured has encryption access configured. If the device to be configured has encryption access configured, it indicates that the device to be configured has a private key.
[0095] Step S214: The anchoring master device generates a network configuration key. As an example and not a limitation, the anchoring master device can generate the network configuration key in a random manner.
[0096] Step S216: The anchoring master device encrypts the distribution key according to the first shared key to obtain the first encrypted ciphertext.
[0097] Step S218: The anchoring master device sends the first encrypted ciphertext to the device to be distributed.
[0098] Step S220: The anchoring master device negotiates with the mobile terminal to obtain the second shared key.
[0099] Step S222: The anchoring master device encrypts the configuration information and the distribution key according to the second shared key to obtain the second encrypted ciphertext.
[0100] Step S224: The anchoring master device sends the second encrypted ciphertext to the mobile terminal.
[0101] Step S226: The mobile terminal decrypts the second encrypted ciphertext according to the second shared key to obtain configuration information and network configuration key.
[0102] Step S228: The mobile terminal obtains the network distribution information.
[0103] Step S230: The mobile terminal determines whether the device to be configured for network access is configured with encrypted access based on the configuration information.
[0104] If the device to be configured for network access is configured with encrypted access, then step S230a is executed: obtain the private key of the device to be configured for network access, and perform a calculation on the private key and the network access key to obtain an updated network access key; and encrypt the network access information according to the updated network access key to obtain a third encrypted ciphertext.
[0105] If the device to be configured for network distribution is not configured with encrypted access, then execute step S230b: encrypt the network distribution information according to the network distribution key to obtain the third encrypted ciphertext.
[0106] Step S232: The mobile terminal sends a third encrypted ciphertext to the device to be configured on the network.
[0107] Step S234: The device to be configured decrypts the received first encrypted ciphertext according to the first shared key, thereby obtaining the configuration key.
[0108] If the device to be configured for network access is configured with encrypted access, then step S236a is executed: the device to be configured performs a calculation on the private key and the network access key to obtain an updated network access key, and decrypts the third encrypted ciphertext according to the updated network access key to obtain the network access information.
[0109] If the device to be configured for network distribution is not equipped with encrypted access, then step S236b is executed: the device to be configured for network distribution decrypts the third encrypted ciphertext according to the network distribution key to obtain the network distribution information.
[0110] As an example and not a limitation, after obtaining network configuration information, the device to be configured scans for the target router and connects to it using the network configuration information to complete the network configuration. Optionally, the device to be configured may send a Wi-Fi sensing frame to the mobile terminal to notify the mobile terminal to stop sending other Wi-Fi sensing frames.
[0111] It is worth noting that, unless otherwise specified, the steps of the above method are not limited in the order of execution.
[0112] For example, the communication steps between the device to be configured, the anchoring master device, and the mobile terminal can be executed through a Wi-Fi sensing frame. For instance, in step S234, the device to be configured can parse the custom payload portion of the Wi-Fi sensing frame received from the anchoring master device to obtain the first encrypted ciphertext, and further decrypt the received first encrypted ciphertext according to the first shared key to obtain the configuration key.
[0113] Example 3
[0114] According to a third aspect of this disclosure, a Wi-Fi-sensing-based network configuration method is disclosed, which is executed in a proximity-sensing network cluster formed by multiple devices to be configured, wherein one of the multiple devices to be configured is selected as the anchoring master device, such as... Figure 6 As shown, the method includes:
[0115] a) At least one device to be configured on the network negotiates with the anchoring master device to obtain a first shared key;
[0116] b) At least one device to be configured on the network obtains a first encrypted ciphertext from the anchoring master device, the first encrypted ciphertext including ciphertext obtained by encrypting the network configuration key generated by the anchoring master device according to the first shared key;
[0117] c) At least one device to be configured on the network obtains a third encrypted ciphertext from the mobile terminal. The third encrypted ciphertext is the ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal according to the network configuration key.
[0118] d) At least one device to be configured on the network decrypts the first encrypted ciphertext using the first shared key to obtain the configuration key;
[0119] e) At least one device to be configured decrypts the third encrypted ciphertext according to the configuration key to obtain the configuration information.
[0120] Optionally, step a) further includes: at least one device to be configured sends configuration information to the anchor master device, wherein the configuration information indicates whether at least one device to be configured has encrypted access.
[0121] Further optionally, if at least one device to be configured for network configuration is configured with encrypted access, then at least one device to be configured for network configuration is configured with a private key, which is obtained by the mobile terminal by scanning a QR code on the device to be configured for network configuration, or by the user entering it on the mobile terminal, or by anchoring the master device.
[0122] Further optionally, if at least one device to be configured for network configuration is configured with encrypted access, step c) further includes: at least one device to be configured for network configuration obtains a third encrypted ciphertext from the mobile terminal, the third encrypted ciphertext being ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal with an updated network configuration key obtained by performing calculations based on the private key and the network configuration key.
[0123] Further optionally, if at least one device to be configured for network access is configured with encrypted access, then step e) further includes: at least one device to be configured for network access decrypts the third encrypted ciphertext according to the private key and the network access key to obtain the network access information.
[0124] Optionally, the configuration information may also include the address information of the devices to be configured on the network.
[0125] Further optionally, the method further includes: f) at least one device to be configured feeds back the result of configuration based on configuration information to the mobile terminal.
[0126] Optionally, the first encrypted ciphertext also includes ciphertext obtained by encrypting the address information of at least one device to be configured in the network that has not obtained a configuration key, based on the first shared key.
[0127] Optionally, after at least one device to be configured on the network obtains the configuration key and the address information of at least one device to be configured on the network that has not obtained the configuration key by decrypting the first encrypted ciphertext according to the first shared key, the following steps are performed to distribute the configuration key to at least one device to be configured on the network that has not obtained the configuration key:
[0128] (a) At least one device to be configured without a configuration key negotiates with at least one device to be configured that has a configuration key to obtain a corresponding first shared key;
[0129] (b) At least one device to be configured without a configuration key obtains a corresponding first encrypted ciphertext from at least one device to be configured with a configuration key that has obtained a configuration key, wherein the corresponding first encrypted ciphertext is ciphertext obtained by encrypting the configuration key according to the corresponding first shared key;
[0130] (c) At least one device to be configured to obtain a network key is obtained by decrypting the corresponding first encrypted ciphertext according to the corresponding first shared key.
[0131] Optionally, at least one device to be configured on the network and the anchoring master device obtain a first shared key through asymmetric key negotiation.
[0132] Optionally, multiple devices to be networked and / or multiple devices to be networked and mobile terminals communicate via Wi-Fi sensing frames.
[0133] Example 4
[0134] According to a fourth aspect of this disclosure, a Wi-Fi-sensing-based network configuration method is disclosed, which is executed in a proximity-sensing network cluster formed by multiple devices to be configured, wherein one of the multiple devices to be configured is selected as the anchoring master device, such as... Figure 7 As shown, the method includes:
[0135] a) The anchoring master device negotiates with at least one device to be configured on the network to obtain a first shared key;
[0136] b) The anchoring master device sends a first encrypted ciphertext to at least one device to be distributed to the network. The first encrypted ciphertext is the ciphertext obtained by encrypting the distribution key generated by the anchoring master device according to the first shared key.
[0137] c) The anchored master device and the mobile terminal negotiate to obtain a second shared key;
[0138] d) The anchoring master device sends a second encrypted ciphertext to the mobile terminal. The second encrypted ciphertext is the ciphertext obtained by encrypting the distribution key according to the second shared key.
[0139] Optionally, step a) further includes: the anchoring master device obtaining configuration information from at least one device to be configured, wherein the configuration information indicates whether at least one device to be configured has encrypted access.
[0140] Optionally, step d) further includes: the anchoring master device sending a second encrypted ciphertext to the mobile terminal, the second encrypted ciphertext being ciphertext obtained by encrypting configuration information and network key according to the second shared key.
[0141] Optionally, the configuration information may also include configuration information obtained by the anchoring master device from other devices to be configured in the neighboring sensing network cluster.
[0142] Example 5
[0143] According to the fifth aspect of this disclosure, a Wi-Fi-sensing-based network distribution method is disclosed, which is executed in a proximity-sensing network cluster formed by multiple devices to be distributed, wherein one of the multiple devices to be distributed is selected as the anchoring master device, such as... Figure 8 As shown, the method includes:
[0144] a) The mobile terminal negotiates with the anchored master device to obtain a second shared key;
[0145] b) The mobile terminal obtains the second encrypted ciphertext from the anchored master device. The second encrypted ciphertext is the ciphertext obtained by encrypting the distribution key according to the second shared key.
[0146] c) The mobile terminal decrypts the second encrypted ciphertext using the second shared key to obtain the network configuration key;
[0147] d) The mobile terminal sends a third encrypted ciphertext to at least one device to be configured on the network. The third encrypted ciphertext is the ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal according to the network configuration key.
[0148] Optionally, step b) further includes: the mobile terminal obtaining a second encrypted ciphertext from the anchoring master device, the second encrypted ciphertext being ciphertext obtained by encrypting configuration information and a network configuration key according to a second shared key; wherein the configuration information indicates whether at least one device to be configured for network configuration is configured with encrypted access, wherein if at least one device to be configured for network configuration is configured with encrypted access, then at least one device to be configured for network configuration is configured with a private key.
[0149] Optionally, step c) further includes: the mobile terminal decrypting the second encrypted ciphertext according to the second shared key to obtain configuration information and network configuration key.
[0150] Further optionally, if at least one device to be configured for network access is configured with encrypted access, step d) further includes: the mobile terminal obtaining the private key of the device to be configured for network access, and performing a calculation on the private key and the network access key to obtain an updated network access key; and encrypting the network access information according to the updated network access key to obtain a third encrypted ciphertext.
[0151] Alternatively, the mobile terminal can obtain the private key of the device to be configured by scanning the QR code on the device, or by the user entering the private key on the mobile terminal, or by anchoring the master device.
[0152] Example 6
[0153] like Figure 9As shown, a network configuration device 900 is illustrated, including: a receiving module 902, a sending module 904, a key negotiation module 906, a storage module 908, an encryption / decryption module 910, and a parsing module 912.
[0154] The system comprises the following modules: a receiving module for discovering Wi-Fi sensing services in the wireless environment and receiving Wi-Fi sensing frames from other devices to be configured, anchoring devices, or mobile terminals; a sending module for enabling other devices in the neighboring sensing network cluster to discover the device to be configured by sending Wi-Fi sensing frames, and for sending Wi-Fi sensing frames to other devices to be configured, anchoring devices, or mobile terminals; for example, after obtaining configuration information, the sending module can send the configuration result back to the mobile terminal; a key negotiation module for negotiating a shared key during asymmetric encryption interactions between the device to be configured and other devices (e.g., anchoring devices, mobile terminals) to obtain a shared key; a storage module for storing the obtained shared key, configuration key, configuration information, etc.; an encryption / decryption module for encrypting or decrypting ciphertext, for example, encrypting the configuration key using the first shared key to obtain the first encrypted ciphertext, or decrypting the first encrypted ciphertext using the first shared key to obtain the configuration key; and a parsing module for parsing received beacon frames, Wi-Fi sensing frames, etc., to obtain the information carried in the payload portion.
[0155] As mentioned earlier, by way of example and not limitation, one of the multiple devices to be configured in a proximity sensing network cluster is selected as the anchor master device. During the configuration process of multiple devices, other devices can be selected as anchor master devices, rather than being limited to recommending a fixed device as the anchor master device.
[0156] As an example and not a limitation, the device to be configured on the network may include smart devices without a human-computer interaction interface, such as smart network cameras, smart TV boxes, and smart speakers, or other smart devices with a human-computer interaction interface.
[0157] Example 7
[0158] like Figure 10 As shown, a hardware structure of a device 1000 to be configured on a network is illustrated, including: a processor 1002, a wireless communication interface 1004, a universal serial bus interface 1006, a memory 1008, and a communication bus for implementing communication connections between these components.
[0159] Optionally, the wireless communication interface can provide wireless communication such as Wi-Fi and Bluetooth (BT). The device to be configured on the network receives and sends Wi-Fi sensing frames through the wireless communication module.
[0160] Optionally, the Universal Serial Bus (USB) interface is an interface that conforms to the USB standard specification. Specifically, it can be any one of the following: MiniUSB interface, Micro USB interface, USB Type C interface, etc. The USB interface can be used to realize functions such as data transmission with peripheral devices.
[0161] Optionally, the equipment to be distributed may also include auxiliary hardware components such as radio frequency (RF) circuits, sensors, and power management modules.
[0162] Example 8
[0163] According to an eighth aspect of this disclosure, a computer-readable storage medium is provided that, when a computer program is executed, causes an apparatus to perform the method described in Embodiment 3, or causes the apparatus to perform the method described in Embodiment 4, or causes the apparatus to perform the method described in Embodiment 5.
[0164] Computer-readable storage media include both permanent and non-permanent, removable and non-removable media, which can be used to store information by any method or technology. Examples of computer storage media include, but are not limited to: phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, read-only optical disc (CD-ROM), digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transfer medium that can be used to store information that can be accessed by a computing device.
[0165] It should be noted that the present invention can be implemented in software and / or a combination of software and hardware, for example, using an application-specific integrated circuit (ASIC), a general-purpose computer, or any other similar hardware device. In some embodiments, the method of the present invention can be executed by a processor to implement the steps or functions described above. Additionally, some steps or functions of the present invention can be implemented in hardware, for example, as circuitry that works in conjunction with a processor to perform the various steps or functions.
[0166] Example 9
[0167] According to a ninth aspect of this disclosure, an embedded chip system is provided, the embedded chip system comprising: a processor for calling and running a computer program from a memory, causing a communication device on which the embedded chip system is mounted to perform the method described in Embodiment 3; or causing the communication device on which the embedded chip system is mounted to perform the method described in Embodiment 4; or causing the communication device on which the embedded chip system is mounted to perform the method described in Embodiment 5.
[0168] It should be understood that the naming of modules and the selection of interactive modules in this disclosure are for illustrative purposes only, and nodes suitable for performing any of the methods described above can be configured in a variety of alternative ways to enable the performance of the suggested process actions.
[0169] It should also be noted that the units described in this disclosure are to be regarded as logical entities and do not necessarily have to be regarded as separate physical entities.
[0170] Certain aspects of the inventive concept have been described above with reference to several embodiments. However, as will be readily apparent to those skilled in the art, embodiments different from those disclosed above are also possible and within the scope of the inventive concept. Similarly, while many different combinations have been discussed, not all possible combinations have been disclosed. Those skilled in the art will recognize that other combinations exist and are within the scope of the inventive concept. Furthermore, as will be understood by those skilled in the art, the embodiments disclosed herein are also applicable to other standards and communication systems, and any feature disclosed from a particular drawing in combination with other features may be applicable to any other drawing and / or combined with different features.
[0171] It will be apparent to those skilled in the art that the present invention is not limited to the details of the above exemplary embodiments, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention. If these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application also intends to include these modifications and variations, and no reference numerals in the claims should be regarded as limiting the scope of the claims.
[0172] According to the present disclosure, a Wi-Fi-aware network configuration method is provided. By utilizing the characteristics of Wi-Fi-aware service to discover devices and communicate between devices through Wi-Fi-aware frames, all devices to be configured can obtain the network configuration key in a secure and reliable manner, and decrypt the ciphertext containing network configuration information based on the network configuration key, and finally connect to the wireless router, thereby improving the security of the devices to be configured during the network configuration process.
[0173] On the other hand, the technical solution disclosed herein enables batch network configuration for a large number of devices without encrypted access control, making the configuration process convenient and simple, thereby reducing the operational complexity of configuring a single device or batches, and greatly shortening the configuration time. Furthermore, due to the high-efficiency transmission characteristics of Wi-Fi sensing frames and the timely feedback mechanism of the devices after obtaining configuration information, the success rate of batch network configuration for these devices is significantly improved.
[0174] The technical solution disclosed herein has been experimentally verified and is entirely feasible. It can successfully transmit Wi-Fi network configuration information even under severe interference and high packet loss rate conditions. Tests under conditions of less interference and low packet loss rate show that the transmission of information can be completed faster.
Claims
1. A Wi-Fi-sensing-based network distribution method, executed in a proximity sensing network cluster formed by multiple devices to be distributed, wherein one of the multiple devices to be distributed is selected as the anchoring master device, characterized in that, The method includes: a) At least one of the plurality of devices to be configured on the network negotiates with the anchoring master device to obtain a first shared key; b) The at least one device to be configured on the network obtains a first encrypted ciphertext from the anchor master device, the first encrypted ciphertext including ciphertext obtained by encrypting the network configuration key generated by the anchor master device according to the first shared key; c) The at least one device to be configured on the network obtains a third encrypted ciphertext from the mobile terminal, wherein the third encrypted ciphertext is ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal according to the network configuration key; d) The at least one device to be configured on the network decrypts the first encrypted ciphertext according to the first shared key to obtain the configuration key; e) The at least one device to be configured on the network decrypts the third encrypted ciphertext according to the configuration key to obtain the configuration information.
2. The method according to claim 1, characterized in that, Step a) further includes: the at least one device to be configured to send configuration information to the anchor master device, wherein the configuration information indicates whether the at least one device to be configured to be configured to have encrypted access.
3. The method according to claim 2, characterized in that, If the at least one device to be configured for network access is configured with encrypted access, then the at least one device to be configured for network access is configured with a private key, which is obtained by the mobile terminal by scanning the QR code on the device to be configured for network access, or by the user entering it on the mobile terminal, or by the anchoring master device.
4. The method according to claim 3, characterized in that, If the at least one device to be configured for network access is configured with encrypted access, step c) further includes: the at least one device to be configured for network access obtains a third encrypted ciphertext from the mobile terminal, the third encrypted ciphertext being ciphertext obtained by encrypting the network access information obtained by the mobile terminal with an updated network access key obtained by performing calculations based on the private key and the network access key.
5. The method according to claim 3, characterized in that, If the at least one device to be configured for network access is configured with encrypted access, then step e) further includes: the at least one device to be configured for network access decrypts the third encrypted ciphertext according to the private key and the network access key to obtain the network access information.
6. The method according to claim 2, characterized in that, The configuration information also includes the address information of the device to be configured on the network.
7. The method according to any one of claims 1-6, characterized in that, The method further includes: f) The at least one device to be configured on the network feeds back the result of the network configuration based on the network configuration information to the mobile terminal.
8. The method according to any one of claims 1-6, characterized in that, The first encrypted ciphertext also includes ciphertext obtained by encrypting the address information of at least one device to be configured on the network that has not obtained a configuration key, based on the first shared key.
9. The method according to any one of claims 1-6, characterized in that, After the at least one device to be configured on the network decrypts the first encrypted ciphertext according to the first shared key to obtain the configuration key and the address information of the at least one device to be configured on the network that has not obtained the configuration key, the following steps are performed to distribute the configuration key to the at least one device to be configured on the network that has not obtained the configuration key: The at least one device that has not obtained a network configuration key negotiates with the at least one device that has obtained a network configuration key to obtain a corresponding first shared key; The at least one device to be configured that has not obtained a configuration key obtains a corresponding first encrypted ciphertext from the at least one device to be configured that has obtained a configuration key. The corresponding first encrypted ciphertext is ciphertext obtained by encrypting the configuration key according to the corresponding first shared key. The at least one device to be configured on the network that has not obtained the configuration key decrypts the corresponding first encrypted ciphertext according to the corresponding first shared key to obtain the configuration key.
10. The method according to any one of claims 1-6, characterized in that, The at least one device to be configured on the network and the anchoring master device obtain a first shared key through asymmetric key negotiation.
11. The method according to any one of claims 1-6, characterized in that, The plurality of devices to be configured on the network communicate with each other and / or with the mobile terminal via Wi-Fi sensing frames.
12. A Wi-Fi-sensing-based network distribution method, executed in a proximity sensing network cluster formed by multiple devices to be distributed, wherein one of the multiple devices to be distributed is selected as the anchoring master device, characterized in that, The method includes: a) The anchoring master device negotiates with at least one of the plurality of network-to-network devices to obtain a first shared key; b) The anchoring master device sends a first encrypted ciphertext to at least one device to be configured on the network, wherein the first encrypted ciphertext is ciphertext obtained by encrypting the network configuration key generated by the anchoring master device according to the first shared key; c) The anchoring master device and the mobile terminal negotiate to obtain a second shared key; d) The anchoring master device sends a second encrypted ciphertext to the mobile terminal, the second encrypted ciphertext being the ciphertext obtained by encrypting the distribution key according to the second shared key; e) The mobile terminal decrypts the second encrypted ciphertext according to the second shared key to obtain the network configuration key; f) The mobile terminal encrypts the network distribution information according to the network distribution key or the updated network distribution key to obtain a third encrypted ciphertext; g) The mobile terminal sends the third encrypted ciphertext to the at least one device to be configured with the network; and h) The at least one device to be configured on the network decrypts the third encrypted ciphertext to obtain the network configuration information.
13. The method according to claim 12, characterized in that, Step a) further includes: the anchoring master device obtaining configuration information from the at least one device to be configured, wherein the configuration information indicates whether the at least one device to be configured has encrypted access.
14. The method according to claim 13, characterized in that, Step d) further includes: the anchoring master device sending a second encrypted ciphertext to the mobile terminal, the second encrypted ciphertext being ciphertext obtained by encrypting the configuration information and the network configuration key according to the second shared key.
15. The method according to claim 13, characterized in that, The configuration information also includes configuration information obtained by the anchoring master device from other network devices to be configured in the neighboring sensing network cluster.
16. A Wi-Fi-sensing-based network distribution method, executed in a proximity sensing network cluster formed by multiple devices to be distributed, wherein one of the multiple devices to be distributed is selected as the anchoring master device, characterized in that, The method includes: a) The mobile terminal negotiates with the anchored master device to obtain a second shared key; b) The mobile terminal obtains a second encrypted ciphertext from the anchoring master device, the second encrypted ciphertext being the ciphertext obtained by encrypting the distribution key according to the second shared key; c) The mobile terminal decrypts the second encrypted ciphertext according to the second shared key to obtain the network configuration key; d) The mobile terminal sends a third encrypted ciphertext to at least one device to be configured on the network, the third encrypted ciphertext being ciphertext obtained by encrypting the network configuration information obtained by the mobile terminal according to the network configuration key; and e) The at least one device to be configured on the network decrypts the third encrypted ciphertext to obtain the network configuration information.
17. The method according to claim 16, characterized in that, Step b) further includes: the mobile terminal obtaining a second encrypted ciphertext from the anchoring master device, the second encrypted ciphertext being ciphertext obtained by encrypting configuration information and the network configuration key according to the second shared key; wherein the configuration information indicates whether the at least one device to be configured for network configuration is configured with encrypted access, wherein if the at least one device to be configured for network configuration is configured with encrypted access, then the at least one device to be configured for network configuration is configured with a private key.
18. The method according to claim 17, characterized in that, Step c) further includes: the mobile terminal decrypts the second encrypted ciphertext according to the second shared key to obtain the configuration information and the network configuration key.
19. The method according to claim 17, characterized in that, If the at least one device to be configured for network access is configured with encrypted access, step d) further includes: the mobile terminal obtaining the private key of the device to be configured for network access, and performing a calculation on the private key and the network access key to obtain an updated network access key; and encrypting the network access information according to the updated network access key to obtain a third encrypted ciphertext.
20. The method according to claim 18, characterized in that, The mobile terminal obtains the private key of the device to be configured by scanning the QR code on the device, or by the user entering the private key on the mobile terminal, or by the anchoring master device.
21. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which, when executed,... Cause the device to perform the method as described in any one of claims 1 to 11, or Cause the device to perform the method as described in any one of claims 12 to 15, or This causes the device to perform the method as described in any one of claims 16 to 20.
22. An embedded chip system, characterized in that, include: A processor is used to retrieve and run computer programs from memory. This causes the communication device equipped with the embedded chip system to perform the method as described in any one of claims 1 to 11; or This causes the communication device equipped with the embedded chip system to perform the method as described in any one of claims 12 to 15; or This causes the communication device equipped with the embedded chip system to perform the method as described in any one of claims 16 to 20.