Method for establishing a wireless connection, electronic device, program product and storage medium
By generating a connection key through a verification mechanism based on spatial location information, the security risks caused by the login user and the registration machine using default passwords in wireless connections are resolved, and secure connections between devices are achieved.
Patent Information
- Application Number
- CN202111032108.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-09-03
- Publication Date
- 2026-01-27
- Estimated Expiration
- 2041-09-03
AI Technical Summary
In existing technologies, the login user and the registration machine use the default password 00000000 for authentication when establishing a wireless connection, which poses a significant security risk and is vulnerable to man-in-the-middle attacks.
By using a verification mechanism based on spatial location information, the first device locates and verifies the second device, generates a connection key, and establishes a wireless connection to ensure the security between devices.
It improves the security of wireless connections between devices, prevents man-in-the-middle attacks, and ensures the legitimacy and privacy of connections.
Smart Images

Figure CN115767529B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network technology, and in particular to a method for establishing a wireless connection, an electronic device, a program product, and a storage medium. Background Technology
[0002] When the enrollee and registrar establish a wireless connection using Wi-Fi Simple Configuration (WSC), they use the default password 00000000 for authentication, which poses a significant security risk. Summary of the Invention
[0003] This application provides a method for establishing a wireless connection, an electronic device, a software product, and a storage medium to improve the security of establishing wireless connections between devices.
[0004] To achieve the above objectives, the present invention provides the following technical solution:
[0005] Firstly, this application provides a method for establishing a wireless connection, applied to a first device. In one application scenario, the first device establishes a wireless connection with a second device. The method for establishing the wireless connection includes: the first device locating the second device to obtain first spatial location information; the first device verifying the second device based on the first spatial location information; if the first device determines that the second device has passed the verification, the first device establishes a connection with the second device using a connection key.
[0006] In an application scenario involving a first device, a second device, and a third device, the second device can act as an administrator, assisting the first and third devices in establishing a connection. The second device can verify the legitimacy of the first and third devices. Specifically, the second device can verify the first device based on the spatial location information of the first device, and verify the third device based on the spatial location information of the third device. The method for establishing this wireless connection includes: the first device locating the second device to obtain first spatial location information; the first device verifying the second device based on the first spatial location information; and if the first device determines that the second device has passed verification, the first device uses a connection key to establish a wireless connection with the third device.
[0007] As can be seen from the above, in the application scenario of wireless connection between the first device and the second device, the first device verifies the second device based on the first spatial location information, and after the second device passes the verification, the first device uses the connection key to establish a connection with the second device, thus ensuring the security of the wireless connection between the first device and the second device.
[0008] In an application scenario involving a first device, a second device, and a third device, the second device verifies the third device's location based on the third device's spatial location information, and the first device verifies the second device's location based on the first device's spatial location information. Then, the first device and the third device establish a connection using a connection key, which can ensure the security of the wireless connection established between the first device and the third device.
[0009] In one possible implementation, the first device verifies the second device based on first spatial location information, including: the first device determining whether the difference between the first spatial location information and the second spatial location information is within a preset range, wherein the second spatial location information is obtained by the second device locating the first device. Specifically, if the first device determines that the difference between the first spatial location information and the second spatial location information is within the preset range, then the first device determines that the second device has passed verification.
[0010] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device verifies the second device based on the first spatial location information in response to an operation command.
[0011] In one possible implementation, the operation instructions responded to by the first device include: various touch operations on the display screen performed by the user on the display screen of the first device, such as long press, short press, and multiple clicks on the user interface; voice input by the user to the first device; and specific actions input by the user to the first device, such as characteristic gestures.
[0012] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device sending a request message to the second device, the request message carrying a first shared key, the first shared key being generated by the first device using the first spatial location information; and the first device receiving a response message sent by the second device, the response message being generated by the second device when verifying the first device using the first shared key.
[0013] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device using the first spatial location information to determine whether the second device is within a preset range of the first device; wherein, if the first device determines that the second device is within the preset range of the first device, then the first device determines that the second device has passed the verification.
[0014] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device receiving a second public key sent by the second device; the first device generating a first shared key or a derived key of the first shared key based on the second public key and the first private key, wherein the first private key is the private key of the first device; and the first device verifying the second device based on the first shared key or the derived key of the first shared key.
[0015] In one possible implementation, the first device receives a second public key sent by the second device via a WiFi channel.
[0016] In one possible implementation, the first device sends a first public key to the second device via a WiFi channel. The second device generates a first shared key or a derived key of the first shared key based on the first public key and the second private key. The second private key is the private key of the second device. The second device verifies the first device based on the first shared key or the derived key of the first shared key.
[0017] In one possible implementation, the first device verifies the second device based on a first shared key or a derived key of the first shared key, including: the first device generating a first verification value based on the first shared key or a derived key of the first shared key, and sending the first verification value to the second device; the first device receiving a second verification value sent by the second device, and verifying the second verification value, wherein the second verification value is generated by the second device based on the first shared key or a derived key of the first shared key when verifying that the first verification value is correct.
[0018] In one possible implementation, the first device verifies the second verification value, including: whether the first device successfully decrypts the second verification value; or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; or, the first device compares whether the first verification value is the same as the second verification value.
[0019] In one possible implementation, the first device verifies the second device based on a first shared key or a derived key of the first shared key, including: the first device generating a first verification value based on first spatial location information and the first shared key or a verification key of the first shared key, and sending the first verification value to the second device; the first device receiving the second verification value sent by the second device, and verifying the second verification value, wherein the second verification value is generated by the second device based on the second spatial location information and the first shared key or a derived key of the first shared key when verifying that the first verification value is correct, and the second spatial location information is obtained by the second device locating the first device.
[0020] In one possible implementation, the first device generates a first verification value based on the first spatial location information and the first shared key or the verification key of the first shared key, including: the first device performs a hash operation on the first spatial location information or a derived value of the first spatial location information, and the first shared key or a derived key of the first shared key, to obtain a hash operation result, and all or part of the hash operation result is used as the first verification value; the derived value of the first spatial location information includes: part of the data of the first spatial location information, or all or part of the value after hashing the first spatial location information, or all or part of the value after hashing the first spatial location information and one or more plaintext information or derived information of plaintext information.
[0021] In one possible implementation, the first device verifies the second verification value, including: whether the first device successfully decrypts the second verification value; or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; or, the first device compares whether the first verification value is the same as the second verification value; or, the first device decrypts the second verification value to obtain second spatial location information; the first device determines whether the difference between the first spatial location information and the second spatial location information is within a predetermined range.
[0022] In one possible implementation, the verification of the second device based on the first spatial location information provided by the aforementioned possible implementations can be performed once or multiple times.
[0023] In one possible implementation, the verification methods for the second device based on the first spatial location information provided by the aforementioned possible implementation methods can be used in combination.
[0024] In one possible implementation, before the first device establishes a connection with the second device using the connection key, the process further includes: the first device responding to a positioning command from the second device, and the second device obtaining the spatial location information of the first device; the first device responding to a verification command from the second device, which is used by the second device to verify the first device based on the spatial location information of the first device; the first device successfully verifies the second device, and the second device successfully verifies the first device, then the first device and the second device establish a wireless connection using the connection key.
[0025] In one possible implementation, before the first device establishes a connection with the third device using the connection key, the process further includes: the second device verifying the first device's access based on the first device's spatial location information, and the third device verifying the second device's access based on the second device's spatial location information.
[0026] In one possible implementation, before the first device locates the second device and obtains the first spatial location information, the method further includes: the first device discovering the second device via WiFi messages or UWB messages.
[0027] In the above possible implementations, after the first device discovers the second device via WiFi or UWB messages, it locates the second device to ensure that the first device can locate the discovered device, and establishes a wireless connection when the verification is successful.
[0028] In one possible implementation, after the first device discovers the second device via UWB messages, the first device can inform the second device of its own Service Set Identifier (SSID), MAC address, and WiFi channel via UWB messages.
[0029] In one possible implementation, after the first device discovers the second device via WiFi or UWB messages, it triggers the location process of the first device for the second device via WiFi messages.
[0030] In one possible implementation, the WiFi message carries trigger indication information to trigger location execution.
[0031] In one possible implementation, during the discovery process between the first device and the second device via WiFi messages, the WiFi messages may carry information indicating that the device supports UWB functionality, or supports WiFi configuration via UWB, or supports WSC configuration.
[0032] In one possible implementation, the IE can carry information indicating that it supports UWB functionality, or supports WiFi configuration via UWB, or supports WSC configuration.
[0033] In one possible implementation, the first device discovers the second device via WiFi messages, including: the first device receiving a beacon frame broadcast by the second device.
[0034] In one possible implementation, the first device discovers the second device via WiFi messages, including: the first device sending a probe request frame; the first device receiving a probe response frame sent by the second device, wherein the probe response frame is sent by the second device after receiving the probe request frame.
[0035] In one possible implementation, the user selects the second device from the WLAN list of the first device, and the probe request frame sent by the first device to the second device may carry information about the second device. For example, at least one of the following: service set identifier (SSID) and MAC (Media Access Control) address.
[0036] In one possible implementation, the user can click the "Configure" button on the display of the first device, or click the name of the WiFi network to connect to. The first device responds to the user's action by sending a probe request frame to the second device.
[0037] In one possible implementation, before the first device establishes a wireless connection with the second device using the connection key, the process further includes: the first device receiving first signature information sent by the second device; and the first device verifying that the first signature information is correct.
[0038] In one possible implementation, before the first device establishes a wireless connection with the third device using the connection key, the process further includes: the first device receiving first signature information sent by the second device; and the first device verifying that the first signature information is correct.
[0039] In one possible implementation, the first device verifies the correctness of the first signature information by: the first device successfully decrypting the first signature information using the first signature public key; or, the first device decrypting the first signature information using the first signature public key to obtain a first hash value carried by the first signature information; the first device performing a hash operation on the first connection public key to obtain a second hash value; the first device determining that the first hash value and the second hash value are the same; or, the first device decrypting the first signature information using the first signature public key to obtain device information carried by the first signature information; and the first device verifying the correctness of the device information.
[0040] In one possible implementation, before the first device establishes a wireless connection with the second device using the connection key, the method further includes: the first device generating or receiving a connection key sent by the second device; wherein the connection key includes: a first connection key or a derivative key of the first connection key.
[0041] In one possible implementation, before the first device establishes a wireless connection with the third device using the connection key, the method further includes: the first device generating or receiving a connection key sent by the second device; wherein the connection key includes: a first connection key or a derivative key of the first connection key.
[0042] In one possible implementation, the first device generates a connection key by: the first device using a first connection public key and a second connection private key to generate a first connection key or a derived key of the first connection key, wherein the second connection private key is the private key of the first device.
[0043] In the above possible implementations, the first device generates a connection key using the connection public key and its own private key, and then uses the connection key to establish a wireless connection with the second or third device. This ensures that the private key is not exchanged when the first device and the second device, or the first device and the third device, interact, thereby further ensuring security.
[0044] In one possible implementation, the algorithm used to perform the key exchange can be the DH (Diffie-Hellman) algorithm or the ECDH (elliptic curve Diffie-Hellman) algorithm.
[0045] In one possible implementation, the first device generates a derived key of the first connection key using a first connection public key and a second connection private key, including: the first device generating a first connection key using the first connection public key and the second connection private key; the first device extracting a portion of the first connection key as a derived key of the first connection key; or, the first device generating a first connection key using the first connection public key and the second connection private key; the first device performing a hash operation on the first connection key to obtain a result, and using all or part of the result as a derived key of the first connection key; or, the first device generating a first connection key using the first connection public key and the second connection private key; the first device performing a hash operation on the first connection key and one or more plaintext information or derived information of plaintext information to obtain a derived key of the first connection key.
[0046] In one possible implementation, the first device locates the second device to obtain first spatial location information, including: the first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the second device and obtain the first spatial location information.
[0047] Secondly, this application provides a method for establishing a wireless connection, applied to a first device in an application scenario comprising a first device, a second device, and a third device, wherein the first device acts as a manager. The method for establishing the first wireless connection includes: the first device locating the second device to obtain first spatial location information; the first device verifying the second device based on the first spatial location information; the first device locating the third device to obtain third spatial location information; and the first device verifying the third device based on the third spatial location information; wherein: if the first device determines that the second device and the third device have passed verification, the second device establishes a wireless connection with the third device using a connection key.
[0048] As can be seen from the above, in application scenarios involving a first device, a second device, and a third device, the first device verifies the third device's access based on the third spatial location information, and the first device verifies the second device's access based on the first spatial location information. Then, the second and third devices establish a connection using the connection key, which can ensure the security of the wireless connection established between the second and third devices.
[0049] Furthermore, the first device verifies the second device based on the first spatial location information, and verifies the third device based on the third spatial location information. Once the first device determines that the second and third devices have been verified, the second device uses the connection key to establish a wireless connection with the third device. In this way, the establishment of a wireless network connection between the second and third devices can be easily completed.
[0050] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device responding to an operation command and verifying the second device based on the first spatial location information; or, the first device using the first spatial location information to determine whether the second device is within a preset range of the first device; wherein, if the first device determines that the second device is within the preset range of the first device, then the first device determines that the second device has passed verification; or, the first device determining whether the difference between the first spatial location information and the second spatial location information is within a preset range; wherein, the second spatial location information is obtained by the second device locating the first device; if the first device determines that the difference between the first spatial location information and the second spatial location information is within the preset range, then the first device determines that the second device has passed verification.
[0051] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device receiving a second public key sent by the second device; the first device generating a first shared key or a derived key of the first shared key based on the second public key and the first private key, wherein the first private key is the private key of the first device; and the first device verifying the second device based on the first spatial location information and the first shared key or the derived key of the first shared key.
[0052] In one possible implementation, the first device verifies the second device based on first spatial location information and a first shared key or a derived key of the first shared key, including: the first device generating a first verification value based on the first spatial location information and the first shared key or a verification key of the first shared key, and sending the first verification value to the second device; the first device receiving the second verification value sent by the second device, and verifying the second verification value, wherein the second verification value is generated by the second device based on the second spatial location information and the first shared key or a derived key of the first shared key when verifying that the first verification value is correct, and the second spatial location information is obtained by the second device locating the first device.
[0053] In one possible implementation, the first device generates a first verification value based on the first spatial location information and the first shared key or the verification key of the first shared key, including: the first device performs a hash operation on the first spatial location information or a derived value of the first spatial location information, and the first shared key or a derived key of the first shared key, to obtain a hash operation result, and all or part of the hash operation result is used as the first verification value; the derived value of the first spatial location information includes: part of the data of the first spatial location information, or all or part of the value after hashing the first spatial location information, or all or part of the value after hashing the first spatial location information and one or more plaintext information or derived information of plaintext information.
[0054] In one possible implementation, the first device verifies the second verification value, including: whether the first device successfully decrypts the second verification value; or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; or, the first device compares whether the first verification value is the same as the second verification value; or, the first device decrypts the second verification value to obtain second spatial location information; the first device determines whether the difference between the first spatial location information and the second spatial location information is within a predetermined range.
[0055] In one possible implementation, the first device verifies the third device based on third spatial location information, including: the first device responding to an operation command by verifying the third device based on the third spatial location information; or, the first device using the third spatial location information to determine whether the third device is within a preset range of the first device; wherein, if the first device determines that the third device is within the preset range of the first device, then the first device determines that the third device has passed verification; or, the first device determining whether the difference between the third spatial location information and the fourth spatial location information is within a preset range; wherein, the fourth spatial location information is obtained by the third device locating the first device; wherein, if the first device determines that the difference between the third spatial location information and the fourth spatial location information is within a preset range, then the first device determines that the third device has passed verification.
[0056] In one possible implementation, the first device verifies the third device based on the third spatial location information, including: the first device receiving a fourth public key sent by the third device; the first device generating a second shared key or a derived key of the second shared key based on the fourth public key and the third private key, wherein the third private key is the private key of the first device; and the first device verifying the third device based on the third spatial location information and the second shared key or the derived key of the second shared key.
[0057] In one possible implementation, the first device verifies the third device based on third spatial location information and a second shared key or a derived key of the second shared key, including: the first device generating a fourth verification value based on the third spatial location information and the second shared key or a verification key of the second shared key, and sending the fourth verification value to the third device; the first device receiving a fifth verification value sent by the third device, and verifying the fifth verification value, wherein the fifth verification value is generated by the third device based on the fourth spatial location information and the second shared key or a derived key of the second shared key when verifying that the fourth verification value is correct, and the fourth spatial location information is obtained by the third device locating the first device.
[0058] In one possible implementation, the first device generates a fourth verification value based on the third spatial location information and the second shared key or the verification key of the second shared key. This includes: the first device performing a hash operation on the third spatial location information or its derived value, and the second shared key or its derived key, to obtain a hash operation result. All or part of the hash operation result is used as the fourth verification value. The derived value of the third spatial location information includes: partial data of the third spatial location information, or all or part of the value after hashing the third spatial location information, or all or part of the value after hashing the third spatial location information and one or more plaintext information or its derived information.
[0059] In one possible implementation, the first device verifies the fifth verification value, including: whether the first device successfully decrypts the fifth verification value; or, the first device generates a sixth verification value and compares whether the fifth verification value and the sixth verification value are the same.
[0060] Alternatively, the first device compares the fourth verification value with the fifth verification value to see if they are the same; or, the first device decrypts the fifth verification value to obtain the fourth spatial location information; the first device determines whether the difference between the third spatial location information and the fourth spatial location information is within a predetermined range.
[0061] In one possible implementation, before the first device locates the second device and obtains the first spatial location information, the method further includes: the first device discovering the second device via WiFi messages or UWB messages.
[0062] In one possible implementation, before the first device locates the third device and obtains the first spatial location information, the method further includes: the first device discovering the third device via WiFi messages or UWB messages.
[0063] In one possible implementation, if the first device determines that the second device and the third device have passed the verification, the method further includes: the first device sending a connection key to the second device and the third device respectively.
[0064] In one possible implementation, after the first device determines that the second device and the third device have passed the verification, the method further includes: the first device sending first signature information to the second device; and the first device sending second signature information to the third device.
[0065] In one possible implementation, the first device locates the second device to obtain first spatial location information, including: the first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the second device and obtain the first spatial location information.
[0066] In one possible implementation, the first device locates the third device to obtain third spatial location information, including: the first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the third device and obtain third spatial location information.
[0067] Thirdly, this application provides an electronic device, which includes a first device or a second device. The electronic device includes: one or more processors, a memory, and a wireless communication module; the memory and the wireless communication module are coupled to one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and when one or more processors execute the computer instructions, the electronic device executes the wireless connection establishment method provided by the first aspect or any possible implementation of the first aspect, or executes the wireless connection establishment method provided by the second aspect or any possible implementation of the second aspect.
[0068] Fourthly, this application provides a computer storage medium for storing a computer program, which, when executed, is specifically used to implement the wireless connection establishment method provided by the first aspect or any possible implementation of the first aspect, or to implement the wireless connection establishment method provided by the second aspect or any possible implementation of the second aspect.
[0069] Fifthly, this application provides a computer program product that, when run on a computer, causes the computer to execute a wireless connection establishment method as provided in the first aspect or any possible implementation of the first aspect, or to execute a wireless connection establishment method as provided in the second aspect or any possible implementation of the second aspect. Attached Figure Description
[0070] Figure 1 A schematic diagram illustrating the establishment of a wireless connection between a mobile phone and a router, as provided in an embodiment of this application;
[0071] Figure 2 Another schematic diagram illustrating the establishment of a wireless connection between a mobile phone and a router as provided in this application embodiment;
[0072] Figure 3 A schematic diagram illustrating the hardware structure of an electronic device provided in an embodiment of this application;
[0073] Figure 4 A schematic diagram illustrating the hardware structure of a router provided in an embodiment of this application;
[0074] Figure 5 A diagram illustrating the relative distance and relative orientation angle between a mobile phone and a router provided in an embodiment of this application;
[0075] Figure 6 A flowchart illustrating a method for accessing a wireless network provided in an embodiment of this application;
[0076] Figure 7 A schematic diagram illustrating the establishment of a wireless connection between a mobile phone and a router, provided in another embodiment of this application;
[0077] Figure 8 This is a schematic diagram illustrating an application scenario provided in another embodiment of this application;
[0078] Figure 9 A timing diagram of a method for establishing a wireless network connection provided in another embodiment of this application;
[0079] Figure 10 A timing diagram of a method for establishing a wireless network connection provided in another embodiment of this application;
[0080] Figure 11a , Figure 11b and Figure 11c This is a schematic diagram illustrating an application scenario provided in another embodiment of this application;
[0081] Figure 12 A timing diagram of a method for establishing a wireless network connection provided in another embodiment of this application;
[0082] Figure 13This is a timing diagram of a method for establishing a wireless network connection, provided in another embodiment of this application. Detailed Implementation
[0083] The terms "first," "second," and "third," etc., used in this application specification, claims, and drawings are used to distinguish different objects, not to limit a specific order.
[0084] In this application, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0085] To simplify the Wi-Fi access configuration process, the Wi-Fi Alliance proposed a simple Wi-Fi configuration method, also known as Wi-Fi Simple Configuration (WSC). WSC was originally called Wi-Fi Protected Setup (WPS).
[0086] WSC defines the Enrollee and the Registrar. The Registrar can be integrated with an Access Point (AP) to form a Standalone AP, or it can be a standalone functional module. The Enrollee is generally represented as a station (STA). If the Enrollee needs to establish a connection with the Registrar, it must register with the Registrar via the Registrar protocol through the WSC trigger method.
[0087] One way WSC is triggered is through Push Button Configuration (PBC) triggering.
[0088] Specifically, Figure 1In (a), the AP is exemplified by a router with a WPS button, and the STA is exemplified by a mobile phone with a virtual WPS button displayed on its screen (the virtual WPS button shown on the phone screen in the image is just one example). When the phone needs to establish a connection with the router, the user triggers both the WPS button on the router and the virtual WPS button on the phone screen. Based on this, the router and the phone interact multiple times to complete the discovery of each other. Afterwards, the router and the phone exchange information multiple times, with the phone obtaining the wireless network security configuration information from the router and using this information to establish a connection with the router. If the router is already connected to the network, the phone can join the wireless network provided by the router, such as... Figure 1 As shown in (b).
[0089] However, when a mobile phone obtains the wireless network security configuration information from the router and uses this information to establish a wireless network connection, both the phone and the router use the default password "00000000" for authentication. This poses a significant security risk. For example, the default password "00000000" is easily parsed by a man-in-the-middle attack. In the event of a man-in-the-middle attack, the connection between the phone and the router will be compromised as follows: Figure 2 As shown, the connection has changed from the phone connecting to the middleman, and the middleman connecting to the router.
[0090] Based on this, embodiments of this application provide a method for establishing a wireless network connection, applied to a first device and a second device. Commonly, two types of devices—stations and access points—establish wireless network connections. Therefore, this explanation will use one of the first and second devices as a station (STA) and the other as an access point (AP), specifically using the first device as the STA and the second device as the AP as an example.
[0091] Of course, the devices establishing a wireless network connection are not limited to sites and access points; any devices that support the WiFi communication protocol can establish a wireless network connection. It should also be noted that before the first and second devices establish a wireless network connection, they can exchange management frames and control frames; after the first and second devices establish a wireless network connection, they can exchange management frames, control frames, and data frames.
[0092] In this embodiment, the access point (AP) is the central node of the wireless network. Typically, an AP can include routers, repeaters, wireless network cards, and mobile phones. A station (STA) can refer to each terminal connected to the wireless network, such as mobile phones, tablets, desktops, laptops, ultra-mobile personal computers (UMPCs), handheld computers, netbooks, personal digital assistants (PDAs), wearable electronic devices, smartwatches, and network-connected electronic devices such as printers.
[0093] Figure 3 A schematic diagram of a network-enabled electronic device 300 is shown. The electronic device 300 may include a processor 310, an internal memory 320, an antenna 1, a wireless communication module 330, and a power supply module 340, etc.
[0094] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 300. In other embodiments of this application, the electronic device 300 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0095] Processor 310 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, memory, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). Different processing units may be independent devices or integrated into one or more processors. The processor may serve as the central nervous system and command center of the electronic device 300. The processor can generate operation control signals based on instruction opcodes and timing signals to control instruction fetching and execution.
[0096] The processor 310 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 310 is a cache memory. This memory can store instructions or data that the processor 310 has just used or that are used repeatedly. If the processor 310 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 310, and thus improves the efficiency of the system.
[0097] Internal memory 320 can be used to store executable program code, including instructions. Processor 310 executes various functional applications and data processing of electronic device 300 by running the instructions stored in internal memory 320. Internal memory 320 may include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback, image playback, etc.). The data storage area may store data created during the use of electronic device 300 (such as audio data, phonebook, etc.). Furthermore, internal memory 320 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.
[0098] The wireless communication function of the electronic device can be implemented through antenna 1 and wireless communication module 330, etc. Antenna 1 is used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device can be used to cover one or more communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in conjunction with a tuning switch.
[0099] The wireless communication module 330 can provide solutions for wireless communication applications in electronic devices, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), near field communication (NFC) technology, and ultra-wideband (UWB) technology.
[0100] The wireless communication module 330 can be one or more devices integrating at least one communication processing module. The wireless communication module 330 receives electromagnetic waves via antenna 1, performs frequency modulation and filtering of the electromagnetic wave signal, and sends the processed signal to processor 310. The wireless communication module 330 can also receive signals to be transmitted from processor 310, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 1.
[0101] In some embodiments, the antenna 1 of the electronic device is coupled to the wireless communication module 330, enabling the electronic device 300 to communicate with networks and other devices via wireless communication technologies. Wireless communication technologies may include BT, WLAN, NFC, and UWB technologies, etc.
[0102] The power module 340 may include a power supply, a power management component, etc. The power management component is used to manage the charging of the power supply and the power supply to other modules of the electronic device 300.
[0103] Figure 4 A schematic diagram of a router that can be used as an access point (AP) is shown. The router 400 includes: a processor 410, an internal memory 420, a power module 430, an interface 440, a console port 450, an auxiliary port 460, a wireless communication module 470, and an antenna 1.
[0104] It is understood that the structure illustrated in the embodiments of this application does not constitute a specific limitation on router 400. In other embodiments of this application, router 400 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0105] Processor 410 may include one or more processing units, such as processing modules or circuits of a central processing unit (CPU), graphics processing unit (GPU), digital signal processor (DSP), microprocessor (MCU), AI (Artificial Intelligence) processor, or field programmable gate array (FPGA). Different processing units may be independent devices or integrated into one or more processors. Processor 410 may include memory units for storing instructions and data.
[0106] The memory 420 can employ non-volatile memory, random access memory (RAM), flash memory, or read-only memory (ROM). RAM discards its information during router startup or power-off intervals. ROM stores the router's boot software, the first software to run on the router, responsible for entering normal operating mode. The router stores the complete operating system in RAM as a backup in case the operating system becomes unavailable. ROM is typically located on one or more chips soldered onto the router's motherboard. Flash memory primarily stores the router's operating system, maintaining normal operation. If flash memory is installed, it's mainly used to boot the default location of the operating system. With sufficient capacity, multiple operating system images can be stored, providing multiple boot options. Non-volatile memory primarily stores configuration data (boot configuration) read during operating system startup. RAM mainly serves as storage for the operating system table and buffer. The operating system can satisfy all its regular storage needs through RAM, allowing the router to quickly access this information. RAM's storage speed is superior to the three types mentioned above.
[0107] The power module 430 may include a power supply, a power management component, etc. The power management component is used to manage the charging of the power supply and the power supply to other modules of the router 400.
[0108] Interface 440 has a name and a number. The full name of an interface consists of an interface type identifier and a numerical number, starting from 0. For routers with fixed interfaces or those using modular interfaces, the full name of the interface uses only one number, numbered according to its physical order within the router. For example, Ethernet0 represents the first Ethernet interface, and Serial1 represents the second serial port. For routers that support "online plug-in and remove" or allow changing physical interface configurations, the full name of the interface must contain at least two numbers separated by a forward slash " / ". The first number represents the slot number, and the second number represents the port number within the interface card. For routers supporting "universal interface processors", the interface number format is "slot / port adapter / port number", such as Ethernet4 / 0 / 1, which is the second Ethernet interface of the first port adapter on slot 4.
[0109] Console port 450 enables users or administrators to communicate with router 400 using network-connected devices to complete router configuration. This port provides an EIA / TIA-232 asynchronous serial interface for configuration on router 400.
[0110] Auxiliary port 460 is similar to console port 450, also providing an EIA / TIA-232 asynchronous serial interface. However, it is often used to connect a modem to enable remote management of router 400.
[0111] The router's wireless communication function can be implemented through antenna 1 and wireless communication module 470, etc. Antenna 1 is used to transmit and receive electromagnetic wave signals. The router's antenna can be used to cover one or more communication frequency bands.
[0112] The wireless communication module 470 can provide solutions for wireless communication applications on routers, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks) and ultra-wideband (UWB) technology.
[0113] The wireless communication module 470 can be one or more devices integrating at least one communication processing module. The wireless communication module 470 receives electromagnetic waves via antenna 1, performs frequency modulation and filtering of the electromagnetic wave signal, and sends the processed signal to processor 410. The wireless communication module 470 can also receive signals to be transmitted from processor 410, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 1.
[0114] In some embodiments, the antenna 1 of the electronic device is coupled to the wireless communication module 470, enabling the electronic device 400 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include WLAN and UWB technologies, etc.
[0115] First, it should be noted that the first and second devices can use various methods to locate each other, such as UWB positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, and optical positioning. Because UWB and ultrasonic positioning methods offer higher accuracy, they are more commonly used.
[0116] The following describes the positioning process of the first and second devices based on UWB positioning and ultrasonic positioning methods.
[0117] Specifically, the first device exchanges information with the second device multiple times in one-way or two-way based on the UWB communication protocol. The wireless signals used to exchange information are used for ranging and direction finding to obtain the relative distance L and relative azimuth angle θ between the first device and the second device, which is the first spatial position information. Figure 5 An example is shown illustrating the relative distance L and relative orientation angle θ between a first device and a second device. Furthermore, the first and second devices are positioned in different ways, such as the first device being placed vertically or horizontally, yet the relative distance and relative orientation angle between the first and second devices remain the same.
[0118] The first device can use a Time of Flight (ToF) positioning algorithm or a Time Difference of Arrival (TDoA) positioning algorithm to measure distance using UWB signals and obtain the relative distance between the first and second devices; alternatively, it can use an Angle-of-Arrival (AoA) positioning algorithm or an Angle-of-Departure (AoD) positioning algorithm to measure direction using UWB signals and obtain the relative azimuth angle between the first and second devices.
[0119] Similarly, the second device can also exchange information with the first device multiple times in one-way or two-way based on the UWB communication protocol. By using the wireless signals of the exchanged information to perform ranging and direction finding, the relative distance and relative azimuth angle between the second device and the first device can be obtained, which is the second spatial location information.
[0120] Normally, the relative distance and relative orientation angle between the second device and the first device obtained by the second device are the same as the relative distance and relative orientation angle between the first device and the second device obtained by the first device.
[0121] The second device can use the Time of Fly (ToF) positioning algorithm and the Time Difference of Arrival (TDoA) positioning algorithm to measure the distance and obtain the relative distance between the second device and the first device; alternatively, it can use the Angle-of-Arrival (AoA) positioning algorithm and the Angle of Departure (AoD) positioning algorithm to measure the direction and obtain the relative azimuth angle between the second device and the first device.
[0122] TOF and TDoA positioning algorithms can be further divided into Single-sided Two-way Ranging (SS-TWR), Double-sided Two-way Ranging (DS-TWR), and One-way Ranging (OWR). The following explanation uses the SS-TWR TOF positioning algorithm with the first device as an example to illustrate the specific process of obtaining the relative distance between the first and second devices. Furthermore, the explanation also uses the Angle of Arrival (AOA) positioning algorithm with the first device as an example to illustrate the specific process of obtaining the relative direction angle between the first and second devices.
[0123] The first device uses the SS-TWR ToF positioning algorithm to obtain the relative distance between the first and second devices as follows:
[0124] The first device sends a UWB signal to the second device at time S1. The UWB signal arrives at the second device after time Tp. The second device receives the UWB signal at time S2. After receiving the UWB signal, the second device sends a UWB feedback signal back to the first device at time S3. The time period between time S2 and time S3 is called the response processing delay Tr. The UWB feedback signal carries the response processing delay Tr. The UWB feedback signal arrives at the first device after time Tp. The first device receives the UWB feedback signal at time S4. After receiving the UWB feedback signal, the first device can determine the time period between time S1 and time S4, which is denoted as the loopback delay Td. Based on the loopback delay Td and the response processing delay Tr carried in the UWB feedback signal, the time Tp required for the UWB signal to be transmitted between the second device and the first device is calculated according to the following formula (1).
[0125]
[0126] The first device calculates the relative distance between the first device and the second device based on the transmission time Tp and the transmission speed of the UWB signal.
[0127] The relative azimuth angle between the first device and the second device is obtained using the Angle of Arrival (AoA) method as follows:
[0128] The antenna 1 of the first device is configured as an antenna array for receiving UWB signals. The antenna array includes a receiver and multiple antennas connected to the receiver. After the second device emits a UWB signal, all multiple antennas of the first device will receive the UWB signal. Due to the positional deviation of the multiple antennas, the phase of the UWB signal emitted by the second device will have a certain deviation when it reaches the multiple antennas. The first device uses the phase difference of the multiple antennas to calculate the relative azimuth angle between the first device and the second device.
[0129] Both the first and second devices are equipped with microphone arrays that can transmit directional ultrasonic waves. The first and second devices use ultrasonic waves to locate each other.
[0130] The first and second devices can also be positioned using Time of Flight (ToF) or Time Difference of Arrival (TDoA) positioning algorithms, utilizing ultrasonic signals for ranging to obtain the relative distance between the two devices; alternatively, they can be positioned using Angle-of-Arrival (AoA) or Angle-of-Departure (AoD) positioning algorithms, utilizing ultrasonic signals for direction finding to obtain the relative azimuth angle between the first and second devices. See the foregoing for details.
[0131] Example 1
[0132] Based on the foregoing, this application provides a method for establishing a wireless network connection, applicable to a first device and a second device. See [link to relevant documentation]. Figure 6 The method for establishing a wireless network connection provided in this application includes:
[0133] S601, The first device and the second device perform a discovery process via WiFi messages.
[0134] The discovery process in step S601 can be implemented in two ways. Implementation method one includes the following steps:
[0135] S601a, The second device sends a beacon frame.
[0136] Normally, the second device broadcasts beacon frames at a set period. Devices within the transmission range of the second device's WiFi signal can receive the beacon frames broadcast by the second device.
[0137] In some embodiments, such as Figure 7As shown in (a), the second device has a button for completing WiFi configuration; the figure illustrates this by naming the button the WPS button. When the WPS button on the second device is triggered, the second device also broadcasts a beacon frame even before the scheduled broadcast time. Devices within the WiFi signal transmission range of the second device can receive the beacon frame sent by the second device. If the first device is within the receiving range of the beacon frame sent by the second device, the first device can also receive the beacon frame. Upon receiving the beacon frame sent by the second device, the first device can determine that there is an access point nearby where a wireless network connection can be established.
[0138] It should also be noted that when the WPS button on the second device is triggered, the beacon frame sent by the second device can also carry information. This information can be used to indicate that the second device is a device to be configured and can enter the establishment of a wireless network connection, or that the second device supports the configuration function of a wireless network connection, etc.
[0139] It is understandable that when the first device receives the beacon frame broadcast by the second device, it has completed the discovery of the second device by the first device.
[0140] S601b: The first device sends a probe request frame to the second device.
[0141] The first device receives a beacon frame sent by the second device and detects the second device. The first device can send a probe request frame to the second device. In some embodiments, the display screen of the first device can display something like... Figure 7 (b) shows the information to remind the user that there are access points around the first device where a wireless network connection can be established.
[0142] If the first device discovers the second device, it can send a probe request frame to the second device. In some embodiments, such as Figure 7 As shown in (c), the user clicks the "Connect" button on the display of the first device, and the first device responds to the user's operation by sending a probe request frame to the second device.
[0143] In other embodiments, the display screen of the first device may also display a "configuration button" or the name of the WiFi network to be connected. The user can click the "configuration button" or the name of the WiFi network to be connected on the display screen of the first device. In response to the user's operation, the first device sends a probe request frame to the second device.
[0144] S601c, The second device sends a probe response frame to the first device.
[0145] Upon receiving the probe request frame from the first device, the second device can determine that a site exists in its vicinity where a wireless network connection can be established. Therefore, the second device returns a probe response frame to the first device.
[0146] It is understandable that when the second device receives the probe request frame sent by the first device and then returns a probe response frame to the first device, the second device has completed the discovery of the first device.
[0147] In some embodiments, the first device and the second device can perform unilateral discovery, meaning either the first device discovers the second device, or the second device discovers the first device. Therefore, the aforementioned steps S601b and S601c are optional steps. When only the first device discovering the second device is required, steps S601b and S601c can be omitted.
[0148] Implementation method two includes the following steps:
[0149] S601d, the first device sends a probe request frame.
[0150] The first device can periodically broadcast probe request frames. Devices within the transmission range of the first device's WiFi signal can receive the probe request frames broadcast by the first device.
[0151] In some embodiments, see Figure 7 (d) The available WLAN list of the first device displays multiple wireless network access points around the first device. If a user needs to control the first device to connect to an access point in the available WLAN list, they can click the desired access point button in the available WLAN list of the first device, such as... Figure 7 Access point WLAN3 in (d). It should be noted that the multiple wireless network access points displayed in the available WLAN list of the first device are determined by the second device sending beacon frames and the first device receiving these beacon frames.
[0152] Because the second device referred to by WLAN3 supports WPS functionality, when the user clicks WLAN3, the display of the first device will... Figure 7 As shown in (e), a prompt message appears indicating that the first device and WLAN3 have established a wireless connection via WPS. The user... Figure 7 (e) Click the “Connect” button on the display interface. The first device will respond to the user’s operation and send a probe request frame to the second device (referring to WLAN3).
[0153] The first device sends a probe request frame, and the second device receives the probe request frame, thus enabling the second device to discover the first device.
[0154] In some embodiments, the user selects WLAN3 in the WLAN list of the first device, and the probe request frame sent by the first device to the second device may carry information about WLAN3. For example, at least one of the service set identifier (SSID) and MAC (Media Access Control) address.
[0155] S601e, the second device sends a probe response frame to the first device.
[0156] The second device receives the probe request frame sent by the first device, and then the second device returns a probe response frame to the first device.
[0157] Understandably, when the second device receives a probe request frame sent by the first device, it can determine that there are sites around it where a wireless network connection can be established, thus completing the discovery of the first device.
[0158] When the second device receives the probe request frame, it sends a probe response frame to the first device. When the first device receives the probe response frame from the second device, the first device completes the discovery of the second device.
[0159] S601f, the second device sends a beacon frame.
[0160] The second device can periodically detect beacon frames. In some embodiments, the user follows... Figure 7 (e) The displayed prompts control the first device to move closer to the second device, for example... Figure 7 As shown in (f), the WPS button on the second device is triggered. Once the WPS button on the second device is triggered, the second device can broadcast beacon frames.
[0161] When the first device approaches the signal reception range of the second device, it can receive the beacon frame broadcast by the second device. Upon receiving the beacon frame broadcast by the second device, the first device can determine that there is an accessible access point in its vicinity, thus completing the discovery of the second device.
[0162] S601f is an optional step. In some embodiments, step S601f may not be performed.
[0163] The messages exchanged between the first device and the second device in the two aforementioned implementation methods can be understood as WiFi messages, which are the interaction between the first device and the second device through WiFi communication technology.
[0164] In some embodiments, during the discovery process between the first device and the second device via WiFi messages, information indicating that the device supports UWB functionality may be included in the WiFi messages.
[0165] Specifically, the beacon frames sent by the second device, the probe request frames sent by the first device, and the probe response frames returned by the second device can all carry UWB IE (information element) messages. These messages are used to indicate that the device supports UWB functionality, or supports WiFi configuration via UWB, or supports WSC configuration (WSC implicitly indicates that UWB configuration methods are supported).
[0166] The format of a UWB IE (information element) message is as follows:
[0167] A UWB IE can be divided into at least three parts, as shown in the table below. The first part: Element ID indicates that it is a UWB IE; the second part: length indicates the number of bytes occupied by the entire UWB IE; and the third part: indicates the information carried by the UWB IE, such as capability information.
[0168]
[0169] In some embodiments, the UWB IE (information element) message may be carried within the attribute information of the WSC IE in the beacon frame, probe request frame, and probe response frame. In other embodiments, the UWB IE (information element) message may also be carried as a separate IE in the beacon frame, probe request frame, and probe response frame.
[0170] It should be noted that WSC IE is an IE defined in the WiFi Alliance for WiFi configuration, and is not limited to the name WSC IE.
[0171] It should also be noted that step S601 and its two implementations are optional, and their purpose is to enable the first and second devices to discover each other's devices. In some application scenarios, when the first and second devices establish a wireless network connection, step S601 and its two implementations can be skipped, and step S602 can be executed directly.
[0172] After the first device and the second device discover each other via WiFi messages, they locate each other to obtain the other's spatial location information. Specifically, the first device executes step S602, and the second device executes step S603. It should also be noted that there is no restriction on the execution order of step S602 by the first device and step S603 by the second device. Figure 6 The example shown is parallel execution.
[0173] The foregoing content describes how the first and second devices perform the discovery process via WiFi messages. The first and second devices can also perform the discovery process via other technologies, such as UWB.
[0174] The discovery between the first and second devices via UWB messages is accomplished as follows:
[0175] Method 1: The first device sends a beacon frame.
[0176] The second device listens for beacon frames sent by the first device.
[0177] If the second device detects a beacon frame sent by the first device, then the second device has completed the discovery of the first device.
[0178] The specific format of the beacon frames sent by the first device and the beacon frames sent by the second device can be found in the UWB technical requirements, which will not be elaborated here.
[0179] In some embodiments, the beacon frame sent by the first device may carry a message, such as information indicating that it supports UWB functionality.
[0180] Method 2: The first device sends a Beacon Request frame.
[0181] The second device receives the beacon request frame and then sends a beacon frame to the first device.
[0182] The first device sends a beacon request frame, and the second device receives the beacon request frame and returns a beacon frame to the first device, thus completing the mutual discovery between the first and second devices.
[0183] In some embodiments, the beacon request frame sent by the first device and the beacon frame sent by the second device may also carry messages, such as information indicating that they support UWB functionality.
[0184] S602, The first device locates the second device to obtain the first spatial location information.
[0185] The first spatial location information includes the relative distance between the first device and the second device, and optionally, the relative azimuth angle. The following explanation uses an example where the first spatial location information includes the relative distance and relative azimuth angle between the first device and the second device.
[0186] The specific method by which the first device locates the second device and obtains the first spatial location information is as described above and will not be repeated here.
[0187] In some embodiments, the first device may present the obtained first spatial location information to the user through means such as a display screen, indicator light, speaker or vibration motor.
[0188] In some embodiments, if the first device has a display screen, the first spatial location information can be displayed on the display screen.
[0189] In some embodiments, if the first device is equipped with an indicator light, the first spatial position information can be presented through different operating modes of the indicator light. In some embodiments, different colors of the indicator light can be used to indicate the relative distance and relative azimuth angle between the first and second devices. In one example, a green light indicates a range of 1 meter, and a red light indicates a range of more than 1 meter; or, a green light indicates a relative azimuth angle within 90 degrees, and a red light indicates a relative azimuth angle exceeding 90 degrees. In other embodiments, different flashing frequencies of the indicator light can be used to indicate the relative distance and relative azimuth angle between the second and second devices. In one example, low-frequency flashing indicates a range of 1 meter, and high-frequency flashing indicates a range of more than 1 meter; or, low-frequency flashing indicates a relative azimuth angle within 90 degrees, and high-frequency flashing indicates a relative azimuth angle exceeding 90 degrees.
[0190] In some embodiments, if the first device is equipped with an audio signal output component such as a speaker, the first spatial location information can be broadcast verbally through the audio signal output component. If the audio signal output component is a simple buzzer, the first spatial location information can be presented through different operating modes of the buzzer. In one example, buzzers of different durations are used to indicate different relative distances or different relative azimuth angles between the first and second devices.
[0191] In some embodiments, if the first device is equipped with a vibration motor, the first device can output first spatial position information through the vibration motor. Specifically, different vibration durations and / or frequencies of the vibration motor can be used to output the first spatial position information. In one example, vibrations of different durations of the vibration motor are used to indicate different relative distances between the first device and the second device, and vibrations of different frequencies of the vibration motor are used to indicate different relative orientation angles between the first device and the second device.
[0192] S603, The second device locates the first device and obtains the second spatial location information.
[0193] The second spatial location information may also include the relative distance and relative azimuth angle between the first and second devices. Similarly, the specific method for obtaining the second spatial location information by locating the first device using the second device is as described above.
[0194] In some embodiments, the second device may present the obtained second spatial location information to the user through means such as a display screen, indicator light, speaker, or vibration motor.
[0195] In some embodiments, if the second device has a display screen, the second spatial location information can be displayed on the display screen.
[0196] In some embodiments, if the second device is equipped with an indicator light, the second spatial position information can be presented through different operating modes of the indicator light. In some embodiments, different colors of the indicator light can be used to indicate the relative distance and relative azimuth angle between the first and second devices. In one example, a green light indicates a range of 1 meter, and a red light indicates a range of more than 1 meter; or, a green light indicates a relative azimuth angle within 90 degrees, and a red light indicates a relative azimuth angle exceeding 90 degrees. In other embodiments, different flashing frequencies of the indicator light can be used to indicate the relative distance and relative azimuth angle between the second and second devices. In one example, low-frequency flashing indicates a range of 1 meter, and high-frequency flashing indicates a range of more than 1 meter; or, low-frequency flashing indicates a relative azimuth angle within 90 degrees, and high-frequency flashing indicates a relative azimuth angle exceeding 90 degrees.
[0197] In some embodiments, if the second device is equipped with an audio signal output component such as a speaker, the second spatial location information can be broadcast verbally through the audio signal output component. If the audio signal output component is a simple buzzer, the second spatial location information can be presented through different operating modes of the buzzer. In one example, buzzers of different durations are used to indicate different relative distances or different relative azimuth angles between the first and second devices.
[0198] In some embodiments, if the second device is equipped with a vibration motor, the second device can output second spatial position information through the vibration motor. Specifically, different vibration durations and / or frequencies of the vibration motor can be used to output the second spatial position information. In one example, different durations of vibration of the vibration motor are used to indicate different relative distances between the first device and the second device, and different frequencies of vibration of the vibration motor are used to indicate different relative orientation angles between the first device and the second device.
[0199] In some embodiments, before steps S602 and S603, the first device may notify the second device via a WiFi message that the first device wants to initiate location; and / or, the second device may notify the first device via a WiFi message that the second device wants to initiate location.
[0200] Specifically, the first device sends a probe request frame to the second device. This probe request frame carries indication information, which instructs the first device to initiate location services. In some embodiments, this indication information is a 1-bit indication information, which can be carried in the UWB IE or the WiFi-configured IE.
[0201] The second device sends a beacon frame to the first device. The beacon frame carries indication information, which is also used to instruct the second device to initiate a location.
[0202] It should be noted that, as mentioned earlier, the first device in this embodiment is a STA (Stationary Access Point), and the second device is an AP (Access Point). Typically, the STA sends a probe request frame, and the AP sends a beacon frame. Therefore, the probe request frame sent by the first device to the second device, and the beacon frame sent by the second device, carry indication information. However, the first device can also send a beacon frame, and the second device can also send a probe request frame. This can be understood as the WiFi message sent by the first device to the second device carrying indication information, and the WiFi message sent by the second device to the first device also carrying indication information.
[0203] S604, the first and second equipment undergo preliminary certification.
[0204] Specifically, the preliminary certification process for the first and second devices is as follows:
[0205] S604a The first device sends an authentication request frame to the second device.
[0206] The first device attempts to authenticate with the second device by sending an authentication request frame.
[0207] The S604b second device sends an authentication response frame to the first device.
[0208] If the second device determines that the first device has passed authentication, it returns an authentication response frame to the first device.
[0209] S605, the first and second devices are initially connected.
[0210] Specifically, the initial connection between the first and second devices is as follows:
[0211] S605a, The first device sends an association request frame to the second device.
[0212] Upon receiving the authentication response frame from the second device, the first device can determine that it has passed authentication. Based on this, the first device sends an association request frame to the second device. In some embodiments, the association request frame carries WSC IE information, which indicates that the first device supports the WPS protocol for interaction with the second device.
[0213] S605b: The second device sends an association response frame to the first device.
[0214] If the second device supports the WPS protocol, it will return an association response frame to the first device upon receiving the association request frame, in order to notify the first device that it supports the WPS protocol.
[0215] After steps S605a and S605b, the initial connection between the first device and the second device is completed. The first device can then initiate the EAP-WSC process with the second device. Typically, the EAP-WSC process begins with the first device sending an EAPOL-Start message to the second device and ends with the second device sending an EAP-Fail message to the first device. During the EAP-WSC process, the first and second devices must verify each other's identities and transmit security configuration information, among other things.
[0216] In some application scenarios, when the first device and the second device perform the wireless network access method, steps S604 to S605 can be skipped, and step S606 can be executed directly.
[0217] S606, The first device sends an EAPOL-Start message to the second device.
[0218] S607. The second device sends an EAP-Request / Identity message to the first device.
[0219] The second device sends an EAP-Request / Identity message to the first device to determine the ID of the first device.
[0220] S608, The first device sends an EAP-Response / Identity message to the second device.
[0221] The first device needs to use the WSC authentication method for authentication. Therefore, the first device replies to the second device with an EAP-Response / Identity message, and generally the Identity should be set to "WFA-SimpleConfig-Enrollee-1-0" in the EAP-Response / Identity message.
[0222] In some embodiments, the execution of steps S608 to S610 by the first and second devices will trigger the linkage of the four state machines in EAPOL. The linkage process of the four state machines in EAPOL can be found in the detailed description of the EAP-WSC processing flow, and will not be elaborated here.
[0223] S609. The second device sends an EAP Request (Start) message to the first device.
[0224] If the second device receives the EAP-Response / Identity message sent by the first device and determines that the Identity in the EAP-Response / Identity message is "WFA-SimpleConfig-Enrollee-1-0", it will send an EAP Request(Start) message to the first device to start the EAP-WSC authentication process.
[0225] S610, the first device sends an EAP Response (M1) message to the second device.
[0226] The EAP Response (M1) message consists of multiple attribute fields. The following are some of the more important attribute fields.
[0227] 1) Message Type: Represents the message type, and its value can range from 0x01 (representing Beacon) to 0x0F (representing WSC_DONE). For EAP Response (M1) messages, its Message Type value is 0x04.
[0228] 2) MAC Address: Represents the MAC (Media Access Control) address of the first device.
[0229] 3) Enrollee Nonce: Represents a string of random numbers generated by the first device, which can be understood as the first public key.
[0230] 4) Public Key: is the DH Key.
[0231] 5) Authentication Type Flags and Encryption Type Flags: These indicate the supported authentication algorithms and encryption algorithm types.
[0232] 6) Connection Type Flags: Represents the 802.11 network type supported by the first device. A value of 0x01 represents ESS, and a value of 0x02 represents IBSS.
[0233] S611, The second device sends an EAP Request (M2) message to the first device.
[0234] After receiving the EAP Response (M1) message and processing it accordingly, the second device returns an EAP Request (M2) message to the first device.
[0235] The EAP Request (M2) message can carry the following information:
[0236] 1) Registrar Nonce: Represents a string of random numbers generated by the second device, which can be understood as a second public key;
[0237] 2) Public Key: is a DH Key;
[0238] 3) Authenticator: A 256-bit binary string is obtained from the HMAC-SHA-256 and AuthKey algorithms. The Authenticator property only contains the first 64 bits of the binary content.
[0239] S612, The first device sends an EAP Response (M3) message to the second device.
[0240] After receiving and processing the EAP Request (M2) message, the first device will reply with an EAP Response (M3) message. The EAP Response (M3) message may carry the following information:
[0241] 1) Registrar Nonce: This is the Registrar Nonce of the EAP Request (M2);
[0242] 2) E Hash, its calculation method is as follows:
[0243] a. Generate a first shared key (PSK1) using the AuthKey and the first spatial location information.
[0244] b. Use the AuthKey to encrypt the two random numbers to obtain ES.
[0245] c. Calculate the E Hash by using the HMAC algorithm and AuthenKey on ES, PSK1, the DH Key of the first device and the D-HKey of the second device.
[0246] It should also be noted that generating the first shared key (PSK1) using the AuthKey and the first spatial location information can also be done as follows:
[0247] A portion of the first spatial location information is extracted as a derived key. Using the AuthKey and the derived key from the first spatial location information, a first shared key (PSK1) is generated. In one example, the first spatial location information includes: the relative distance between the first device and the second device is 0.8 meters and the relative direction angle is 30 degrees. This information is then converted into the number 08 as a derived key, or into the number 30 as a derived key, or into the number 0830 as a derived key.
[0248] In other embodiments, a hash operation is performed on the first spatial location information, and the hash result is used as a derived key; or, a portion of the hash result is used as a derived key; using the AuthKey and the derived key of the first spatial location information, a first shared key (PSK1) is generated.
[0249] In other embodiments, the first spatial location information is combined with one or more plaintext information (or derived information of plaintext information) jointly owned by both devices to perform a hash operation to obtain a derived key. The AuthKey and the derived key of the first spatial location information are used to generate a first shared key (PSK1).
[0250] S613, The second device sends an EAP Request (M4) message to the first device.
[0251] After receiving and processing the EAP Response (M3) message, the second device will reply with an EAP Request (M4) message.
[0252] The EAP Request (M4) message can carry the following information: R Hash and Encrypted Settings.
[0253] The R-Hash is calculated as follows:
[0254] a. Generate a second shared key (PSK2) using the AuthKey and the second spatial location information.
[0255] b. Use AuthKey to encrypt two random numbers to obtain RS.
[0256] c. Calculate the R Hash by using the HMAC algorithm and AuthenKey on RS, PSK2, the DH Key of the first device and the D-HKey of the second device.
[0257] Encrypted Settings encrypts the data obtained from RS using the Key Wrap Key on the second device.
[0258] It should be noted that a second shared key (PSK2) can also be generated using the AuthKey and the derived key derived from the second spatial location information. The methods for generating the derived key from the second spatial location information include:
[0259] A portion of the second spatial location information is extracted as a derived key; or, a hash operation is performed on the second spatial location information, and the hash result is used as a derived key; or, a portion of the hash result is used as a derived key; or, the second spatial location information is combined with one or more plaintext information (or derived information of plaintext information) jointly owned by both devices to perform a hash operation to obtain a derived key.
[0260] S614. The first device sends an EAP Response (M5) message to the second device.
[0261] The EAP Response (M5) message is similar to the EAP Request (M4) message. The Encrypted Settings are obtained by the first device using the Key Wrap Key to encrypt the ES.
[0262] It should be noted that the first device receives the EAP Request (M4) message sent by the second device and verifies it.
[0263] If the Encrypted Settings in the EAP Request (M4) message are verified correctly, an EAP Response (M5) message is generated and sent to the second device.
[0264] It should also be noted that the first device needs to use the second shared key (PSK2) to decrypt the Encrypted Settings in the EAP Request (M4) message. If the decryption is successful, the verification is correct.
[0265] If the first device verifies the Encrypted Settings in the EAP Request (M4) message and finds them incorrect, the EAP-WSC process can be terminated.
[0266] S615, The second device sends an EAP Request (M6) message to the first device.
[0267] After the second device confirms that the EAP Response (M5) message is correct, it will send an EAP Request (M6) message. In some embodiments, the EAP Request (M6) message carries security configuration information.
[0268] Specifically, if the second device verifies that the Encrypted Settings in the EAP Response (M5) message are correct, it will generate and send an EAP Request (M6) message to the first device.
[0269] It should also be noted that the second device uses the first shared key (PSK1) to decrypt the Encrypted Settings in the EAP Response (M5) message. If the decryption is successful, the verification is correct.
[0270] S616, The first device sends an EAP Response (Done) message to the second device.
[0271] After processing the EAP Request (M6) message, the first device will reply with an EAP Response (Done) message to the second device, indicating that the EAP Request (M6) message has been successfully processed.
[0272] The EAP-WSC process can be considered complete, and the disconnection and reconnection process can begin:
[0273] 1) The second device sends an EAP-Fail message and a Deauthentication message to the first device.
[0274] 2) Upon receiving this message, the first device will cancel its association with the second device;
[0275] 3) The first device will rescan the surrounding wireless networks.
[0276] Since the first device has obtained the security configuration information of the second device, it can use this information to join the wireless network where the second device is located. The method by which the first device uses the security configuration information to join the wireless network where the second device is located can be as described in step S617.
[0277] It should also be noted that steps S610 to S615 are the process of the first device and the second device performing identity authentication based on the first spatial location information and the second spatial location information. This authentication process enhances security.
[0278] S617. The first device and the second device establish a WiFi connection using a connection key.
[0279] In one possible implementation, step S617 involves the first device and the second device establishing a WiFi connection using a connection key, including:
[0280] S617a, The first device sends a first letter of trust information to the second device. The first letter of trust information includes a first connection key, which is used to establish a WiFi connection between the first device and the second device.
[0281] The first connection key can be a password set by the user for the network to connect to, or a password for the network to connect to that network that has been stored in advance.
[0282] S617b, the first device, and the second device establish a WiFi connection using the first connection key.
[0283] Specifically, the first connection key is used as the PSK (preshared key), or, Passphrase, or, password, or PMK (Pairwise Master Key) to establish a connection using the IEEE 802.11 protocol: this can be the 802.11 four-way handshake process.
[0284] It should also be noted that the first device and the second device can establish a WiFi connection using a derived key from the first connection key.
[0285] In some embodiments, the first device intercepts a portion of the first connection key as a derived key of the first connection key.
[0286] In other embodiments, the first device performs one or more hash operations on the first connection key, and all or part of the hash values are used as derived keys of the first connection key.
[0287] In other embodiments, the first device uses the first connection key in combination with one or more plaintext messages or derived messages jointly owned by both devices to perform a hash operation to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.
[0288] The plaintext information jointly owned by both devices may include:
[0289] A random number generated by a first or second device; attribute information of the first or second device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.
[0290] The following are the methods for generating derivative information of one or more plaintext messages jointly owned by both devices: 1. Take a portion of one or more plaintext messages as the derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.
[0291] The way in which one or more plaintext messages are jointly owned by both devices can be: one of the first and second devices sends one or more plaintext messages to the other. Alternatively, it can be an agreement between the first and second devices. Or it can be obtaining publicly available information relevant to both the first and second devices.
[0292] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.
[0293] In another possible implementation, in step S617, the first device and the second device establish a WiFi connection using a connection key, including:
[0294] S617c, The second device sends a second trust letter to the first device. The second trust letter contains a second connection key, which is used to establish a WiFi connection between the first device and the second device.
[0295] The second connection key can be a password set by the user for the network to connect to, or a password for the network to connect to that network that has been stored in advance.
[0296] S617d, the second device, and the first device establish a WiFi connection using the second connection key.
[0297] Specifically, the second connection key is used as the PSK (preshared key), or, Passphrase, or, password, or PMK (Pairwise Master Key) to establish a connection using the IEEE 802.11 protocol: this can be the execution of the 802.11 four-way handshake process.
[0298] In this step, the second device and the first device can also establish a WiFi connection using a derived key of the second connection key. The method for generating the derived key of the second connection key can be the same as the method for generating the derived key of the first connection key described in step S617b above, and will not be repeated here.
[0299] Example 2
[0300] In one application scenario, the first device is a mobile phone, and the second device is a router. (See [link / reference]). Figure 8 When a user holds their mobile phone and approaches the router, a wireless network connection can be established after multiple interactions between the phone and the router once the phone is within a certain range of the router.
[0301] Based on this application scenario, another embodiment of the wireless network connection establishment method executed by the first device and the second device in this application may also be another execution process, see [link to relevant documentation]. Figure 9Another embodiment of this application provides a method for establishing a wireless network connection, which includes the following steps:
[0302] S901, the first device and the second device are discovered through WiFi messages.
[0303] Discovery between the first and second devices can also be accomplished via UWB messages, as follows:
[0304] Method 1: The first device sends a beacon frame.
[0305] The second device listens for beacon frames sent by the first device.
[0306] If the second device detects a beacon frame sent by the first device, then the second device has completed the discovery of the first device.
[0307] The specific format of the beacon frames sent by the first device and the beacon frames sent by the second device can be found in the UWB technical requirements, which will not be elaborated here.
[0308] In some embodiments, the beacon frame sent by the first device may carry a message, such as information indicating that it supports UWB functionality.
[0309] Method 2: The first device sends a Beacon Request frame.
[0310] The second device receives the beacon request frame and then sends a beacon frame to the first device.
[0311] The first device sends a beacon request frame, and the second device receives the beacon request frame and returns a beacon frame to the first device, thus completing the mutual discovery between the first and second devices.
[0312] In some embodiments, the beacon request frame sent by the first device and the beacon frame sent by the second device may also carry messages, such as information indicating that they support UWB functionality.
[0313] S902, The first device and the second device perform a positioning process to obtain the first spatial location information.
[0314] S903, the second device and the first device perform a positioning process to obtain the second spatial location information.
[0315] For specific implementation details of steps S901 to S903 in this embodiment, please refer to the corresponding... Figure 6 The contents of steps S601 to S603 in the embodiments will not be repeated here.
[0316] Step S901 is also an optional step. In some application scenarios, step S901 can be skipped, and steps S902 and S903 can be executed directly. Furthermore, there is no restriction on the execution order of steps S902 and S903. Figure 9 An example is shown where steps S902 and S903 are performed in parallel.
[0317] S904. The first device verifies the second device based on the first spatial location information.
[0318] Method 1, S904a: The first device verifies the second device by responding to user operations based on the first spatial location information.
[0319] The first device presents first spatial location information. In some embodiments, the first device has a display screen that displays the first spatial location information. In other embodiments, the first device has an audio signal output component through which the first device plays the first spatial location information.
[0320] After the first device presents the first spatial location information, the user performs a confirmation action. This includes various touch operations on the first device's display screen, such as long press, short press, and multiple taps on the user interface. The first device responds to these touch operations to complete the verification of the second device. Alternatively, the user can input voice; the first device recognizes the user's voice to complete the verification of the second device. The user can also perform specific actions, such as specific gestures; the first device responds to these specific actions to complete the verification of the second device.
[0321] The first device displays a list of WiFi networks, which includes at least the second device. When a user clicks on the second device to connect, the first device responds to the user's click on the WiFi list and verifies the second device. In some embodiments, if the WiFi list includes multiple access points besides the second device, the spatial location information of the second device and each access point may also be displayed.
[0322] Method 2, S904b: The first device determines whether the first spatial location information meets the first condition, or the second condition, or both the first and second conditions.
[0323] First condition: The first spatial location information is within the preset range.
[0324] The first device determines that the relative distance between the first device and the second device in the first spatial position is within a preset range, such as within 1 meter or 2 meters.
[0325] The second condition is that the first spatial location information and the second spatial location information match. The first spatial location information is the same as the second spatial location information, or the difference between the first spatial location information and the second spatial location information is within a predetermined range. Specifically, the difference in the relative distance between the first device and the second device is within the first range, and the difference in the relative directional angle between the first device and the second device is within the second range. In one example, the distance difference is about 10 cm, and the directional angle difference is about 3 degrees.
[0326] When the first device determines whether the first spatial location information meets the second condition, the first device also needs to obtain the second spatial location information of the second device through message interaction.
[0327] S905. The second device verifies the first device based on the second spatial location information.
[0328] The second device verifies the first device based on the second spatial location information in the same way as the first device verifies the second device based on the first spatial location information, as described above.
[0329] Specifically: S905a, the second device verifies the first device based on the second spatial location information by responding to user operations. Alternatively, S905b, the second device determines whether the second spatial location information meets the first condition, the second condition, or both the first and second conditions.
[0330] It should be noted that step S904, where the first device verifies the second device based on the first spatial location information, and step S905, where the second device verifies the first device based on the second spatial location information, can also be implemented in the following ways. First, it should be noted that in this implementation, the first device and the second device verify each other through WiFi messages, that is, the messages exchanged between the first device and the second device are all transmitted through the WiFi channel.
[0331] See details Figure 9 The implementation method includes:
[0332] S904c: The first device sends a first message to the second device, and the first message carries the first public key.
[0333] The first device generates an asymmetric key, which includes a public key (i.e., the first public key) and a private key. The public key can be published, but the private key is not disclosed.
[0334] S905c: The second device sends a second message to the first device, the second message carrying a second public key.
[0335] Similarly, the second device also generates an asymmetric key that includes a public key (i.e., the second public key) and a private key.
[0336] After steps S904c and S905c, the first device and the second device exchanged each other's public keys.
[0337] S904d, the first device generates a first shared key based on the second public key and the private key corresponding to the first public key.
[0338] Furthermore, the first device can obtain a derived key from the first shared key based on the first shared key.
[0339] In some embodiments, the first device intercepts a portion of the first shared key as a derived key of the first shared key.
[0340] In other embodiments, the first device performs one or more hash operations on the first shared key, and all or part of the hash values are used as derived keys of the first shared key.
[0341] In other embodiments, the first device uses the first shared key in combination with one or more plaintext messages or derived messages jointly owned by both devices to perform a hash operation to obtain a derived key of the first shared key. Furthermore, a portion of the first shared key can be extracted as the derived key to be used.
[0342] The plaintext information jointly owned by both devices may include:
[0343] A random number generated by a first or second device; attribute information of the first or second device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.
[0344] The following are the methods for generating derivative information of one or more plaintext messages jointly owned by both devices: 1. Take a portion of one or more plaintext messages as the derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.
[0345] The way in which one or more plaintext messages are jointly owned by both devices can be: one of the first and second devices sends one or more plaintext messages to the other. Alternatively, it can be an agreement between the first and second devices. Or it can be obtaining publicly available information relevant to both the first and second devices.
[0346] The hash operations mentioned above can all be performed using algorithms such as SHA-256 and SHA-129.
[0347] S905d and the second device generate a first shared key based on the private keys corresponding to the first public key and the second public key.
[0348] In some embodiments, the second device may also generate a derived key of the first shared key based on the first shared key. The method by which the second device generates the derived key of the first shared key can be found in step S904d, and will not be repeated here.
[0349] It should also be noted that the first shared key generated by the first device and the first shared key generated by the second device are the same.
[0350] S904e, the first device generates a first verification value based on the first shared key and the first spatial location information.
[0351] Specifically, the first device performs a hash operation on the first shared key and the first spatial location information, and uses all or part of the hash result as the first verification value.
[0352] In some embodiments, a portion of the first spatial location information can be extracted as a derived key and used with the first shared key to generate a first verification value. In one example, the first spatial location information includes: the relative distance between the first device and the second device is 0.8 meters and the relative direction angle is 30 degrees. This information can be converted into the number 08 as a derived key, or into the number 30 as a derived key, or into the number 0830 as a derived key.
[0353] In other embodiments, a hash operation is performed on the first spatial location information, and all or part of the hash result is used as a derived key and a first shared key to generate a first verification value.
[0354] In other embodiments, a hash operation is performed on the first spatial location information and one or more plaintext information or derived information of plaintext information. All or part of the values after the hash operation are used as a derived key. Then, the derived key and the first shared key are used to generate a first verification value.
[0355] S904f: The first device sends the first verification value to the second device.
[0356] S905e and the second device generate a second verification value based on the first shared key and the second spatial location information.
[0357] Similar to step S904e, the second device can perform a hash operation on the first shared key and the second spatial location information, and use all or part of the hash value as the second verification value.
[0358] The specific method for generating the second verification value is the same as that for generating the first verification value, and will not be repeated here.
[0359] S905f: The second device sends a second verification value to the first device.
[0360] S904g, the first device verifies whether the second verification value is correct.
[0361] In some embodiments, the first device verifies the second verification value by verifying whether it can correctly decrypt the second verification value. If the first device can successfully decrypt the second verification value, the verification of the second verification value is correct; if the first device cannot successfully decrypt the value, the verification fails. For example, the second device uses the AES-SIV (Advanced Encryption Standard-Synthetic Initialization Vector) encryption and decryption algorithm; the first device uses AES-SIV for decryption. If decryption fails, the verification fails. If decryption succeeds, the verification is correct.
[0362] In some embodiments, the first device verifies the second verification value by: decrypting the second verification value to obtain a decrypted value, and verifying whether the decrypted value is correct. Specifically, the first device decrypts the second verification value to obtain second spatial location information. The first device compares the first spatial location information with the second spatial location information. If the first spatial location information and the second spatial location information are the same, or if the difference between the first spatial location information and the second spatial location information is within a predetermined range, then the first device verifies that the second verification value is correct.
[0363] The difference between the first spatial location information and the second spatial location information is within a predetermined range, which can refer to: the distance difference between the first device and the second device being within the first range, and the angular difference between the relative directions of the first device and the second device being within the second range. In one example, the distance difference is approximately 10 cm, and the angular difference is approximately 3 degrees.
[0364] In other embodiments, the first device verifies the second verification value by generating a third verification value and comparing it with the second verification value. If the first device determines that the third verification value and the second verification value are the same, then the second verification value is verified as correct.
[0365] In other embodiments, the first device verifies the second verification value by comparing whether the first verification value and the second verification value are the same. If the first device determines that the first verification value and the second verification value are the same, then the second verification value is verified as correct.
[0366] S905g, the second device verifies whether the first verification value is correct.
[0367] The method by which the second device verifies whether the first verification value is correct is the same as the method by which the first device verifies the second verification value. Please refer to step S904g for details, which will not be repeated here.
[0368] It should also be noted that the aforementioned first device, based on the first spatial location information, can verify each implementation of the second device multiple times. Furthermore, the aforementioned first device, based on the first spatial location information, can verify several implementations of the second device in any combination, enabling the first device to verify the second device multiple times based on the first spatial location information. Similarly, the second device, based on the second spatial location information, can verify each implementation of the first device multiple times. Furthermore, the second device, based on the second spatial location information, can verify several implementations of the first device in any combination, enabling the second device to verify the first device multiple times based on the second spatial location information.
[0369] If the first device verifies that the second verification value is correct, and the second device verifies that the first verification value is correct, then execute S906: the first device and the second device establish a WiFi connection using the connection key.
[0370] In one possible implementation, step S906 involves the first device and the second device establishing a WiFi connection using a connection key, including:
[0371] S906a, The first device sends a first letter of trust information to the second device. The first letter of trust information includes a first connection key, which is used to establish a WiFi connection between the first device and the second device.
[0372] The first connection key can be a password set by the user for the network to connect to, or a password for the network to connect to that network that has been pre-stored. The first letter of trust is a data structure that can contain information that allows the device to connect to the wireless connection.
[0373] S906b, the first device and the second device establish a WiFi connection using the first connection key.
[0374] Specifically, the first connection key is used as the PSK (preshared key), or, Passphrase, or, password, or PMK (Pairwise Master Key) to establish a connection using the IEEE 902.11 protocol: this can be the execution of the 902.11 four-way handshake process.
[0375] In another possible implementation, in step S906, the first device and the second device establish a WiFi connection using a connection key, including:
[0376] S906c, the second device sends a second trust letter to the first device. The second trust letter contains a second connection key, which is used to establish a WiFi connection between the first device and the second device.
[0377] The second connection key can be a password set by the user for the network to connect to, or a password for the network to connect to that network that has been pre-stored. The second trust information is also a data structure that can contain information that allows the device to connect to the wireless connection.
[0378] S906d, the second device, and the first device establish a WiFi connection using the second connection key.
[0379] Specifically, the second connection key is used as the PSK (preshared key), or, Passphrase, or, password, or PMK (Pairwise Master Key) to establish a connection using the IEEE 802.11 protocol: this can be the execution of the 902.11 four-way handshake process.
[0380] It should be noted that in step S906 of this embodiment, a WiFi connection can also be established using a derived key of the first connection key or a derived key of the second connection key, as described in step S617 of the aforementioned embodiment, and will not be repeated here.
[0381] Example 3
[0382] In the aforementioned Embodiment 1 and Embodiment 2, the first device and the second device need to exchange connection keys, which introduces the risk of connection key interception and man-in-the-middle attacks. Furthermore, if multiple first devices connect to the same second device, the connection keys used by all the first devices to connect to the second device are the same. Therefore, if the connection key is intercepted, the wireless connections of all the first devices and the second device will be at risk.
[0383] Based on this, another embodiment of this application provides a method for wireless network access, see [link to relevant documentation]. Figure 10 It includes the following steps:
[0384] S1001, the first device and the second device complete the discovery through WiFi messages.
[0385] Of course, the first and second devices can also be discovered through UWB messages, as detailed above.
[0386] S1002, The first device locates the second device and obtains the first spatial location information.
[0387] S1003, The second device locates the first device and obtains the second spatial location information.
[0388] For specific implementation methods of steps S1001 to S1003 in this embodiment, please refer to the corresponding... Figure 6 The contents of steps S601 to S603 in the embodiments will not be repeated here.
[0389] Step S1001 is also an optional step. In some application scenarios, step S1001 can be skipped, and steps S1002 and S1003 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1002 and S1003. Figure 10 An example is shown where steps S1002 and S1003 are performed in parallel.
[0390] S1004. The first device verifies the second device based on the first spatial location information.
[0391] S1005. The second device verifies the first device based on the second spatial location information.
[0392] For specific implementation methods of steps S1004 and S1005 in this embodiment, please refer to the corresponding... Figure 9 The contents of steps S904 to S905 in the embodiments will not be repeated here.
[0393] S1006, The second device sends the first connection public key to the first device.
[0394] The second device generates an asymmetric key pair, including a first connection public key and a first connection private key.
[0395] In this embodiment, the first device is a mobile phone, and the second device is a router. Because mobile phones have more functions and are more convenient to use than routers, this embodiment uses a mobile phone as the key administrator. However, this does not limit the following steps to only being performed by the first device as the administrator.
[0396] Steps S1007 to S1009.
[0397] S1007. The first device uses the first signature private key to sign the first connection public key, generating the first signature information.
[0398] The first device is equipped with an asymmetric key pair including a first signing private key and a first signing public key. The first device receives a first connection public key sent by the second device, and uses the first signing private key to sign the first connection public key, generating first signature information.
[0399] Specifically, the first device performs a hash operation on the first connection public key to obtain a first hash value, and then encrypts the first hash value using the first signature private key to obtain the first signature information.
[0400] In some embodiments, the first device may also use the first signing private key to sign the first connection public key and other information to obtain first signature information. The other information may be device information such as device role information and group identifier information.
[0401] S1008. The first device sends the first signature information and the first signature public key to the second device.
[0402] S1009. The first device generates a second connection public key and signs the second connection public key using the first signing private key to generate second signature information.
[0403] In this process, the first device generates a second connection public key, and also generates a corresponding second connection private key. The second connection public key and the second connection private key form an asymmetric private key pair.
[0404] Specifically, the first device performs a hash operation on the second connection public key to obtain a second hash value, and then uses the first signature private key to encrypt the second hash value to obtain the second signature information.
[0405] In some embodiments, the first device may also sign the second connection public key and other information to obtain second signature information. Other information may include device information such as device role information and group identification information.
[0406] S1010, the second device sends the first connection public key and the first signature information to the first device.
[0407] In this step, the first connection public key sent by the second device is the same as the first connection public key sent by the second device in step S1006. The first signature information sent by the second device is: the first signature information received by the second device from the first device in step S1008.
[0408] S1011. The first device uses the first signature public key to verify whether the first signature information is correct.
[0409] In some embodiments, the first device verifies the first signature information using the first signature public key by: the first device decrypting the first signature information using the first signature public key; if decryption is successful, the verification is successful; if decryption fails, the verification is unsuccessful.
[0410] In other embodiments, the first device verifies the first signature information using the first signature public key as follows: The first device decrypts the first signature information using the first signature public key to obtain a first hash value. The first device performs a hash operation on the first connection public key to obtain a second hash value, and compares the first hash value with the second hash value; if the first hash value and the second hash value are the same, the verification is successful; otherwise, the verification fails.
[0411] In other embodiments, the first device uses the first signature public key to decrypt the first signature information and obtains the first hash value, as well as device information such as the device's role information and group identifier information. The first device then verifies whether the device information such as the device's role information and group identifier information is correct. If the device information such as the device's role information and group identifier information is correct, then the first signature information is verified to be correct.
[0412] If the first device uses the first signature private key to verify that the first signature information is correct, then execute S1012. The first device uses the first connection public key and the second connection private key to generate the first connection key or a derivative key of the first connection key.
[0413] It should be noted that the first device generates a first connection key using the first connection public key and the second connection private key, and can generate a derived key based on the first connection key.
[0414] The first device can perform a hash operation on the first connection public key and the second connection private key to obtain the first connection key.
[0415] In some embodiments, the first device intercepts a portion of the first connection key as a derived key of the first connection key.
[0416] In other embodiments, the first device performs one or more hash operations on the first connection key, and all or part of the hash values are used as derived keys of the first connection key.
[0417] In other embodiments, the first device uses the first connection key in combination with one or more plaintext messages or derived messages jointly owned by both devices to perform one or more hash operations to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.
[0418] The plaintext information jointly owned by both devices may include:
[0419] A random number generated by a first or second device; attribute information of the first or second device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.
[0420] The following are the methods for generating derivative information of one or more plaintext messages jointly owned by both devices: 1. Take a portion of one or more plaintext messages as the derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.
[0421] The way in which one or more plaintext messages are jointly owned by both devices can be: one of the first and second devices sends one or more plaintext messages to the other. Alternatively, it can be an agreement between the first and second devices. Or it can be obtaining publicly available information relevant to both the first and second devices.
[0422] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.
[0423] S1013, The first device sends the second connection public key and the second signature information to the second device.
[0424] It should be noted that step S1013 can be executed at any time after the second signature information is obtained in step S1009. Figure 10 This demonstrates one execution location for step S1013, but does not constitute a limitation on the execution location of S1013.
[0425] S1014. The second device uses the first signature public key to verify whether the second signature information is correct.
[0426] In some embodiments, the second device receives the second connection public key and the second signature information. The second device uses the first signature public key to verify the second signature information. Specifically, the second device uses the first signature public key to decrypt the second signature information. If the decryption is successful, the verification is successful; if the decryption fails, the verification is unsuccessful.
[0427] In other embodiments, the second device verifies the second signature information using the first signature public key as follows: the second device decrypts the second signature information using the first signature public key to obtain a second hash value. The second device performs a hash operation on the second connection public key to obtain a third hash value, and compares the third hash value with the second hash value; if the third hash value is the same as the second hash value, the verification is successful; otherwise, the verification fails.
[0428] In other embodiments, the second device uses the first signature public key to decrypt the second signature information. In addition to obtaining the second hash value, it also obtains device information such as the device's role information and group identifier information. The second device then further verifies whether the device information such as the device's role information and group identifier information is correct. If the device information such as the device's role information and group identifier information is verified to be correct, then the second signature information is verified to be correct.
[0429] The second device uses the first signature private key to verify that the second signature information is correct, and then executes S1015. The second device uses the second connection public key and the first connection private key to generate the first connection key or a derivative key of the first connection key.
[0430] In this step, the second device generates the derived key of the first connection key in the same way as in the aforementioned step S1012. Please refer to the content of the aforementioned step S1012, which will not be repeated here.
[0431] S1016. The first device and the second device establish a WiFi connection using the first connection key or a derived key of the first connection key.
[0432] Specifically, the first device and the second device use the first connection key or a derived key of the first connection key as a PSK (preshared key), or a Passphrase, or a password, or a PMK (Pairwise Master Key) to establish a connection by executing the IEEE 802.11 protocol: this can be the execution of the 802.11 four-way handshake process.
[0433] The specific implementation of step S1016 can be found in step S617 of the aforementioned embodiment, and will not be repeated here.
[0434] In this embodiment, the first device and the second device only exchange public keys and do not exchange private keys, thus enhancing security. Furthermore, the first device uses the first connection private key and the second connection public key to generate a first connection key or a derived key of the first connection key. Since the first connection private key is the first device's private key, different first devices can establish wireless connections with the second device using connection keys or derived keys generated from their own connection private keys, further improving security.
[0435] Example 4
[0436] The variety of devices capable of establishing wireless network connections is increasing, such as portable devices like mobile phones, which can easily be brought close together to establish a wireless network connection. However, large electronic devices are not easily moved and cannot use the wireless network connection establishment method provided in the aforementioned embodiments to establish a wireless network connection between two devices.
[0437] In one application scenario, see Figure 11a If the printer and router are far apart, the wireless network connection establishment process provided in the aforementioned embodiments may fail due to the inability to locate each other's devices. Therefore, this application provides another wireless network connection establishment scheme in which the router and printer use a portable device, such as a mobile phone, to establish the wireless network connection.
[0438] In the wireless network connection establishment scheme provided in this embodiment, the user can first... Figure 11b As shown, location and location verification are performed using a mobile phone and router, and then... Figure 11c The system will locate and verify the location of the mobile phone and printer. If the location verification of both the mobile phone and router is successful, and the location verification of both the mobile phone and printer is also successful, the printer can establish a wireless network connection with the router.
[0439] In this application scenario, the mobile phone, printer, and router all need to have UWB functionality. The hardware structure of the mobile phone, printer, and other electronic devices used as the site can be as follows: Figure 3 As shown; the hardware structure of devices such as routers that serve as access points can also be as shown. Figure 4 As shown.
[0440] The following describes the method for establishing a wireless network connection using three devices: a mobile phone, a printer, and a router.
[0441] See Figure 12 This application provides a method for wireless network access, including:
[0442] S1201, the first device and the second device complete the discovery through WiFi messages.
[0443] Of course, the first and second devices can also be discovered through UWB messages, as detailed above.
[0444] S1202, The first device locates the second device and obtains the first spatial location information.
[0445] S1203, The second device locates the first device and obtains the second spatial location information.
[0446] For specific implementation details of steps S1201 to S1203 in this embodiment, please refer to the corresponding... Figure 6 The contents of steps S601 to S603 in the embodiments will not be repeated here.
[0447] Step S1201 is an optional step. In some application scenarios, step S1201 can be skipped, and steps S1202 and S1203 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1202 and S1203. Figure 12 An example is shown where steps S1202 and S1203 are performed in parallel.
[0448] S1204. The first device verifies the second device based on the first spatial location information.
[0449] S1205. The second device verifies the first device based on the second spatial location information.
[0450] For specific implementation details of steps S1204 and S1204 in this embodiment, please refer to the corresponding... Figure 9 The contents of steps S904 to S905 in the embodiments will not be repeated here.
[0451] S1206. The first device sends a first letter of trust information to the second device, the first letter of trust information containing a first connection key.
[0452] It should also be noted that the first letter of trust information may also include a derived key of the first connection key.
[0453] In some embodiments, the second device intercepts a portion of the first connection key as a derived key of the first connection key.
[0454] In other embodiments, the second device performs one or more hash operations on the first connection key, and all or part of the hash values are used as derived keys of the first connection key.
[0455] In other embodiments, the second device uses the first connection key in combination with one or more plaintext messages or derived messages shared by both devices to perform a hash operation to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.
[0456] The plaintext information jointly owned by both devices may include:
[0457] A random number generated by a first or second device; attribute information of the first or second device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.
[0458] The following are the methods for generating derivative information of one or more plaintext messages jointly owned by both devices: 1. Take a portion of one or more plaintext messages as the derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.
[0459] The way in which one or more plaintext messages are jointly owned by both devices can be: one of the first and second devices sends one or more plaintext messages to the other. Alternatively, it can be an agreement between the first and second devices. Or it can be obtaining publicly available information relevant to both the first and second devices.
[0460] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.
[0461] S1207, the first device and the third device complete the discovery via WiFi messages.
[0462] The first and third devices can also be discovered through UWB messages, as detailed above.
[0463] S1208. The first device locates the third device and obtains the third spatial location information.
[0464] S1209, The third device locates the first device and obtains the fourth spatial location information.
[0465] For specific implementation details of steps S1207 to S1209 in this embodiment, please refer to the corresponding... Figure 6 The contents of steps S601 to S603 in the embodiments will not be repeated here.
[0466] Step S1207 is also an optional step. In some application scenarios, step S1207 can be skipped, and steps S1208 and S1209 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1208 and S1209. Figure 12 An example is shown where steps S1208 and S1209 are performed in parallel.
[0467] S1210. The first device verifies the third device based on the third spatial location information.
[0468] S1211, The third device verifies the first device based on the fourth spatial location information.
[0469] For specific implementation details of steps S1210 and S1211 in this embodiment, please refer to the corresponding... Figure 9 The contents of steps S904 to S905 in the embodiments will not be repeated here.
[0470] It should also be noted that there is no limitation on the order in which steps S1201 to 1206, performed by the first device and the second device, and steps S1207 to 1212, performed by the first device and the second device. Figure 12 An example is shown whereby the first and second devices first execute steps S1201 to 1206, and then the first and third devices execute steps S1207 to 1212.
[0471] S1212, the first device sends a second letter of trust information to the third device, the second letter of trust information containing the first connection key.
[0472] Similar to step S1206, the second trust certificate information sent by the first device to the third device may also include a derived key of the first connection key. The method for generating the derived key is described in step S1211 and will not be repeated here.
[0473] S1213, The second device and the third device establish a WiFi connection using the first connection key.
[0474] Using the first connection key as the PSK (preshared key), or, Passphrase, or, password, or PMK (Pairwise Master Key), the IEEE 802.11 protocol is executed to establish a connection: this can be the execution of the 802.11 four-way handshake process.
[0475] When the letter of trust information sent by the first device to the second and third devices includes a derived key of the first connection key, the second and third devices can establish a WiFi connection using the derived key of the first connection key.
[0476] The specific implementation of step S1213 can be found in step S617 of the aforementioned embodiment, and will not be repeated here.
[0477] In this embodiment, the first device sends a first connection key to both the second and third devices. The third device and the second device can establish a WiFi connection using the first connection key. This facilitates the establishment of a wireless network connection between the second and third devices.
[0478] Example 5
[0479] The second device establishes a wireless connection with the third device through the first device. Alternatively, this can be implemented in another way; see [link to relevant documentation]. Figure 13 Another embodiment of this application provides a method for accessing a wireless network, comprising the following steps:
[0480] S1301, the first device and the second device complete the discovery through WiFi messages.
[0481] The first and second devices can also be discovered based on UWB messages.
[0482] S1302, The first device locates the second device and obtains the first spatial location information.
[0483] S1303, The second device locates the first device and obtains the second spatial location information.
[0484] For specific implementation details of steps S1301 to S1303 in this embodiment, please refer to the corresponding... Figure 6 The contents of steps S601 to S603 in the embodiments will not be repeated here.
[0485] Step S1301 is an optional step. In some application scenarios, step S1301 can be skipped, and steps S1302 and S1303 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1302 and S1303. Figure 13 An example is shown where steps S1302 and S1303 are performed in parallel.
[0486] S1304. The first device verifies the second device based on the first spatial location information.
[0487] S1305. The second device verifies the first device based on the second spatial location information.
[0488] For specific implementation details of steps S1304 and S1305 in this embodiment, please refer to the corresponding... Figure 9 The contents of steps S904 to S905 in the embodiments will not be repeated here.
[0489] S1306, The second device sends the first connection public key to the first device.
[0490] The second device generates an asymmetric key pair, including a first connection public key and a first connection private key.
[0491] S1307. The first device uses the first signature private key to sign the first connection public key and generates the first signature information.
[0492] The first device is equipped with an asymmetric key pair including a first signing private key and a first signing public key. The first device receives a first connection public key sent by the second device, and the second device uses the first signing private key to sign the first connection public key to generate first signature information.
[0493] Specifically, the first device performs a hash operation on the first connection public key to obtain a first hash value, and then encrypts the first hash value using the first signature private key to obtain the first signature information.
[0494] In some embodiments, the first device may also use the first signing private key to sign the first connection public key and other information to obtain first signature information. The other information may be device information such as device role information and group identifier information.
[0495] S1308. The first device sends the first signature information and the first signature public key to the second device.
[0496] S1309, the first device and the third device complete the discovery via WiFi messages.
[0497] The first and third devices can be discovered via WiFi messages, or alternatively via UWB messages. For detailed implementation instructions, please refer to the corresponding... Figure 6 The details of step S601 in the embodiments will not be repeated here.
[0498] S1310, The first device locates the third device and obtains the third spatial location information.
[0499] S1311, The third device locates the first device and obtains the fourth spatial location information.
[0500] For specific implementation details of steps S1309 to S1311 in this embodiment, please refer to the corresponding... Figure 6 The contents of steps S502 to S603 in the embodiments will not be repeated here.
[0501] Step S1309 is also an optional step. In some application scenarios, step S1309 can be skipped, and steps S1310 and S1311 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1310 and S1311. Figure 13 An example is shown where steps S1310 and S1311 are performed in parallel.
[0502] S1312. The first device verifies the third device based on the third spatial location information.
[0503] S1313, The third device verifies the first device based on the fourth spatial location information.
[0504] For specific implementation details of steps S1312 and S1313 in this embodiment, please refer to the corresponding... Figure 9 The contents of steps S904 to S905 in the embodiments will not be repeated here.
[0505] S1314. The third device sends the second connection public key to the first device.
[0506] The third device generates an asymmetric key pair that includes a second connection public key and a second connection private key.
[0507] S1315. The first device uses the first signing private key to sign the second connection public key, generating second signature information.
[0508] The method by which the first device generates the second signature information is the same as in step S1307.
[0509] S1316. The first device sends the second signature information and the first signature public key to the third device.
[0510] It should also be noted that there is no limitation on the order in which steps S1301 to 1308, performed by the first and second devices, and steps S1309 to 1316, performed by the first and third devices. Figure 13 An example is shown whereby the first and second devices first execute steps S1301 to 1308, and then the first and third devices execute steps S1309 to 1316.
[0511] In this embodiment, the first device acts as the key manager. Therefore, both the second and third devices send their connection public keys to the first device. The first device then generates first and second signature information and sends them to the second and third devices. The second and third devices can verify the legitimacy of each other's devices based on the first and second signature information.
[0512] S1317. The second device sends the first connection public key and the first signature information to the third device.
[0513] S1318. The third device verifies whether the first signature information is correct.
[0514] The method by which the third device verifies whether the first signature information is correct can be found in step S1011 of the aforementioned embodiment, and will not be repeated here.
[0515] If the third device verifies that the first signature information is correct, then step S1319 is executed: the third device uses the first connection public key and the second connection private key to generate the first connection key or a derived key of the first connection key.
[0516] The third device verifies that the first signature information is correct, and then uses the first connection public key and its own second connection private key to generate the first connection key or a derivative key of the first connection key.
[0517] In some embodiments, the third device intercepts a portion of the first connection key as a derived key of the first connection key.
[0518] In other embodiments, the third device performs a hash operation on the first connection key, and the entire or partial value of the hash operation is used as a derived key of the first connection key.
[0519] In other embodiments, the third device uses the first connection key in combination with one or more plaintext messages or derived messages shared by both devices to perform a hash operation to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.
[0520] The plaintext information jointly owned by both devices may include:
[0521] A random number generated by a second or third device; attribute information of the second or third device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.
[0522] The following are the methods for generating derivative information of one or more plaintext messages jointly owned by both devices: 1. Take a portion of one or more plaintext messages as the derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.
[0523] One or more plaintext messages jointly owned by both devices can be transmitted in the following ways: One of the second or third devices sends one or more plaintext messages to the other. Alternatively, the second and third devices may agree upon this. Or, they may obtain publicly available information for both the second and third devices.
[0524] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.
[0525] S1320, the third device sends the second connection public key and the second signature information to the second device.
[0526] S1321. The second device verifies whether the second signature information is correct.
[0527] The method by which the second device verifies whether the second signature information is correct can be found in step S1014 of the aforementioned embodiment, and will not be repeated here.
[0528] If the second device verifies that the second signature information is correct, then execute S1322, whereby the second device uses the second connection public key and the first connection private key to generate the first connection key or a derivative key of the first connection key.
[0529] The second device verifies that the second signature information is correct, and then uses the second connection public key and its own first connection private key to generate a first connection key or a derivative key of the first connection key.
[0530] The method by which the second device generates a derived key for the first connection key can be found in step S1319, and will not be repeated here.
[0531] S1323, The second device and the third device establish a connection using the first connection key or a derived key of the first connection key.
[0532] WiFi connection.
[0533] The second and third devices may use the first connection key or a derived key of the first connection key as...
[0534] PSK (preshared key), or Passphrase, or password, or PMK (Pairwise MasterKey), executes the IEEE 802.11 protocol to establish a connection: it can be the 802.11 four-way handshake process.
[0535] The specific implementation of step S1323 can be found in step S617 of the aforementioned embodiment, and will not be repeated here.
[0536] In this embodiment, the third device and the second device can establish a WiFi connection using the first connection key. This facilitates the establishment of a wireless network connection between the second and third devices.
[0537] Another embodiment of this application provides a computer-readable storage medium storing instructions that, when executed on a computer or processor, cause the computer or processor to perform one or more steps of any of the above methods.
[0538] Another embodiment of this application provides a computer program product containing instructions. When the computer program product is run on a computer or processor, it causes the computer or processor to perform one or more steps of any of the methods described above.
Claims
1. A method for establishing a wireless connection, characterized in that, The wireless connection establishment method, applied to a first device, includes: The first device locates the second device to obtain first spatial location information; The first device verifies the second device based on the first spatial location information; If the first device determines that the second device has passed verification and the first device receives the first signature information sent by the second device, and the first device verifies that the first signature information is correct, the first device establishes a wireless connection with the second device using the connection key; wherein, the first device verifies that the first signature information is correct includes: the first device successfully decrypting the first signature information using the first signature public key; or, the first device decrypting the first signature information using the first signature public key to obtain a first hash value carried by the first signature information; the first device performing a hash operation on the connection public key to obtain a second hash value; the first device determining that the first hash value and the second hash value are the same; or, the first device decrypting the first signature information using the first signature public key to obtain device information carried by the first signature information; the first device verifying that the device information is correct; Alternatively, if the first device determines that the second device has been verified, the first device uses the connection key to establish a wireless connection with the third device, and the third device is verified by the second device based on the spatial location information of the third device.
2. The method for establishing a wireless connection according to claim 1, characterized in that, The first device verifies the second device based on the first spatial location information, including: The first device determines whether the difference between the first spatial location information and the second spatial location information is within a preset range, wherein the second spatial location information is obtained by the second device locating the first device. If the first device determines that the difference between the first spatial location information and the second spatial location information is within a preset range, then the first device determines that the second device has passed the verification.
3. The method for establishing a wireless connection according to claim 1, characterized in that, The first device verifies the second device based on the first spatial location information, including: The first device responds to the operation command and verifies the second device based on the first spatial location information.
4. The method for establishing a wireless connection according to claim 1, characterized in that, The first device verifies the second device based on the first spatial location information, including: The first device sends a request message to the second device, the request message carrying a first shared key, which is generated by the first device using the first spatial location information; The first device receives a response message sent by the second device, which is generated by the second device when it verifies the first device's success using the first shared key.
5. The method for establishing a wireless connection according to claim 1, characterized in that, The first device verifies the second device based on the first spatial location information, including: The first device uses the first spatial location information to determine whether the second device is within the preset range of the first device; If the first device determines that the second device is within the preset range of the first device, then the first device determines that the second device has passed the verification.
6. The method for establishing a wireless connection according to claim 1, characterized in that, The first device verifies the second device based on the first spatial location information, including: The first device receives the second public key sent by the second device; The first device generates a first shared key or a derived key of the first shared key based on the second public key and the first private key, wherein the first private key is the private key of the first device; The first device verifies the second device based on the first shared key or a derived key of the first shared key.
7. The method for establishing a wireless connection according to claim 6, characterized in that, The first device verifies the second device based on the first shared key or a derived key of the first shared key, including: The first device generates a first verification value based on the first shared key or a derived key of the first shared key, and sends the first verification value to the second device; The first device receives the second verification value sent by the second device and verifies the second verification value. The second verification value is generated by the second device based on the first shared key or a derived key of the first shared key when verifying that the first verification value is correct.
8. The method for establishing a wireless connection according to claim 7, characterized in that, The first device verifies the second verification value, including: Did the first device successfully decrypt the second verification value? Alternatively, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; Alternatively, the first device compares whether the first verification value and the second verification value are the same.
9. The method for establishing a wireless connection according to claim 6, characterized in that, The first device verifies the second device based on the first shared key or a derived key of the first shared key, including: The first device generates a first verification value based on the first spatial location information and the first shared key or the verification key of the first shared key, and sends the first verification value to the second device; The first device receives the second verification value sent by the second device and verifies the second verification value. The second verification value is generated by the second device based on the second spatial location information and the first shared key or a derived key of the first shared key when verifying that the first verification value is correct. The second spatial location information is obtained by the second device locating the first device.
10. The method for establishing a wireless connection according to claim 9, characterized in that, The first device generates a first verification value based on the first spatial location information and the first shared key or the verification key of the first shared key, including: The first device performs a hash operation on the first spatial location information or a derived value of the first spatial location information, and the first shared key or a derived key of the first shared key to obtain a hash operation result. All or part of the hash operation result is used as the first verification value. The derived values of the first spatial location information include: partial data of the first spatial location information, or all or part of the values after hashing the first spatial location information, or all or part of the values after hashing the first spatial location information and one or more plaintext information or derived information of plaintext information.
11. The method for establishing a wireless connection according to claim 9, characterized in that, The first device verifies the second verification value, including: Did the first device successfully decrypt the second verification value? Alternatively, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; Alternatively, the first device compares whether the first verification value and the second verification value are the same; Alternatively, the first device decrypts the second verification value to obtain the second spatial location information; The first device determines whether the difference between the first spatial location information and the second spatial location information is within a predetermined range.
12. The method for establishing a wireless connection according to any one of claims 1 to 11, characterized in that, Before the first device locates the second device and obtains the first spatial location information, the process also includes: The first device discovers the second device via WiFi messages or UWB messages.
13. The method for establishing a wireless connection according to any one of claims 1 to 11, characterized in that, Before the first device establishes a wireless connection with the third device using the connection key, it also includes: The first device receives the first signature information sent by the second device; The first device verifies that the first signature information is correct.
14. The method for establishing a wireless connection according to claim 13, characterized in that, The first device verifies that the first signature information is correct, including: The first device successfully decrypted the first signature information using the first signature public key; Alternatively, the first device may use the first signature public key to decrypt the first signature information and obtain the first hash value carried by the first signature information. The first device performs a hash operation on the connection public key to obtain a second hash value; The first device determines that the first hash value and the second hash value are the same; Alternatively, the first device may use the first signature public key to decrypt the first signature information and obtain the device information carried by the first signature information. The first device verifies that the device information is correct.
15. The method for establishing a wireless connection according to any one of claims 1 to 11, characterized in that, Before the first device establishes a wireless connection with the second device using the connection key, it also includes: The first device generates or receives the connection key sent by the second device; wherein the connection key includes: a first connection key or a derived key of the first connection key.
16. The method for establishing a wireless connection according to any one of claims 1 to 11, characterized in that, Before the first device establishes a wireless connection with the third device using the connection key, it also includes: The first device generates or receives the connection key sent by the second device; wherein the connection key includes: a first connection key or a derived key of the first connection key.
17. The method for establishing a wireless connection according to claim 15, characterized in that, The first device generates the connection key, including: The first device uses the first connection public key and the second connection private key to generate the first connection key or a derived key of the first connection key, wherein the second connection private key is the private key of the first device.
18. The method for establishing a wireless connection according to claim 16, characterized in that, The first device generates the connection key, including: The first device uses the first connection public key and the second connection private key to generate the first connection key or a derived key of the first connection key, wherein the second connection private key is the private key of the first device.
19. The method for establishing a wireless connection according to claim 18, characterized in that, The first device uses the first connection public key and the second connection private key to generate a derived key of the first connection key, including: The first device uses the first connection public key and the second connection private key to generate the first connection key; The first device extracts a portion of the first connection key as a derived key of the first connection key; Alternatively, the first device may generate the first connection key using the first connection public key and the second connection private key; The first device performs a hash operation on the first connection key to obtain the operation result. All or part of the value of the operation result is used as a derived key of the first connection key. Alternatively, the first device may generate the first connection key using the first connection public key and the second connection private key; The first device uses the first connection key and one or more plaintext information or derived information of plaintext information to perform a hash operation to obtain a derived key of the first connection key.
20. The method for establishing a wireless connection according to any one of claims 1 to 11, characterized in that, The first device locates the second device to obtain first spatial location information, including: The first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the second device and obtain the first spatial location information.
21. A method for establishing a wireless connection, characterized in that, The wireless connection establishment method, applied to a first device, includes: The first device locates the second device to obtain first spatial location information; The first device verifies the second device based on the first spatial location information; The first device locates the third device and obtains the third spatial location information; The first device verifies the third device based on the third spatial location information; Wherein: if the first device determines that the second device and the third device have passed the verification, the first device sends first signature information to the second device and second signature information to the third device; if the third device verifies that the first signature information is correct, the second device uses the connection key to establish a wireless connection with the third device; the first signature information is sent by the second device to the third device; The third device verifies the correctness of the first signature information by: the third device successfully decrypting the first signature information using the first signature public key; or, the third device decrypting the first signature information using the first signature public key to obtain a first hash value carried by the first signature information; the third device performing a hash operation on the connection public key to obtain a second hash value; the third device determining that the first hash value and the second hash value are the same; or, the third device decrypting the first signature information using the first signature public key to obtain device information carried by the first signature information; and the third device verifying the correctness of the device information.
22. The method for establishing a wireless connection according to claim 21, characterized in that, The first device verifies the second device based on the first spatial location information, including: The first device responds to the operation command and verifies the second device based on the first spatial location information; Alternatively, the first device may use the first spatial location information to determine whether the second device is within a preset range of the first device; wherein, if the first device determines that the second device is within the preset range of the first device, then the first device determines that the second device has passed verification. Alternatively, the first device determines whether the difference between the first spatial location information and the second spatial location information is within a preset range; wherein, the second spatial location information is obtained by the second device locating the first device; if the first device determines that the difference between the first spatial location information and the second spatial location information is within a preset range, then the first device determines that the second device has passed verification.
23. The method for establishing a wireless connection according to claim 21, characterized in that, The first device verifies the second device based on the first spatial location information, including: The first device receives the second public key sent by the second device; The first device generates a first shared key or a derived key of the first shared key based on the second public key and the first private key, wherein the first private key is the private key of the first device; The first device verifies the second device based on the first spatial location information and the first shared key or a derived key of the first shared key.
24. The method for establishing a wireless connection according to claim 23, characterized in that, The first device verifies the second device based on the first spatial location information and the first shared key or a derived key of the first shared key, including: The first device generates a first verification value based on the first spatial location information and the first shared key or the verification key of the first shared key, and sends the first verification value to the second device; The first device receives the second verification value sent by the second device and verifies the second verification value. The second verification value is generated by the second device based on the second spatial location information and the first shared key or a derived key of the first shared key when verifying that the first verification value is correct. The second spatial location information is obtained by the second device locating the first device.
25. The method for establishing a wireless connection according to claim 24, characterized in that, The first device generates a first verification value based on the first spatial location information and the first shared key or the verification key of the first shared key, including: The first device performs a hash operation on the first spatial location information or a derived value of the first spatial location information, and the first shared key or a derived key of the first shared key to obtain a hash operation result. All or part of the hash operation result is used as the first verification value. The derived values of the first spatial location information include: partial data of the first spatial location information, or all or part of the values after hashing the first spatial location information, or all or part of the values after hashing the first spatial location information and one or more plaintext information or derived information of plaintext information.
26. The method for establishing a wireless connection according to claim 24, characterized in that, The first device verifies the second verification value, including: Did the first device successfully decrypt the second verification value? Alternatively, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; Alternatively, the first device compares whether the first verification value and the second verification value are the same; Alternatively, the first device can decrypt the second verification value to obtain the second spatial location information; The first device determines whether the difference between the first spatial location information and the second spatial location information is within a predetermined range.
27. The method for establishing a wireless connection according to any one of claims 21 to 26, characterized in that, The first device verifies the third device based on the third spatial location information, including: The first device responds to the operation command and verifies the third device based on the third spatial location information; Alternatively, the first device may use the third spatial location information to determine whether the third device is within a preset range of the first device; wherein, if the first device determines that the third device is within the preset range of the first device, then the first device determines that the third device has passed verification. Alternatively, the first device determines whether the difference between the third spatial location information and the fourth spatial location information is within a preset range; wherein the fourth spatial location information is obtained by the third device locating the first device; wherein if the first device determines that the difference between the third spatial location information and the fourth spatial location information is within a preset range, the first device determines that the third device has passed verification.
28. The method for establishing a wireless connection according to any one of claims 21 to 26, characterized in that, The first device verifies the third device based on the third spatial location information, including: The first device receives the fourth public key sent by the third device; The first device generates a second shared key or a derived key of the second shared key based on the fourth public key and the third private key, wherein the third private key is the private key of the first device; The first device verifies the third device based on the third spatial location information and the second shared key or a derived key of the second shared key.
29. The method for establishing a wireless connection according to claim 28, characterized in that, The first device verifies the third device based on the third spatial location information and the second shared key or a derived key of the second shared key, including: The first device generates a fourth verification value based on the third spatial location information and the second shared key or the verification key of the second shared key, and sends the fourth verification value to the third device; The first device receives the fifth verification value sent by the third device and verifies the fifth verification value. The fifth verification value is generated by the third device based on the fourth spatial location information and the second shared key or a derived key of the second shared key when verifying that the fourth verification value is correct. The fourth spatial location information is obtained by the third device locating the first device.
30. The method for establishing a wireless connection according to claim 29, characterized in that, The first device generates a fourth verification value based on the third spatial location information and the second shared key or the verification key of the second shared key, including: The first device performs a hash operation on the third spatial location information or a derived value of the third spatial location information, and the second shared key or a derived key of the second shared key to obtain a hash operation result. All or part of the hash operation result is used as the fourth verification value. The derived values of the third spatial location information include: partial data of the third spatial location information, or all or part of the values after hashing the third spatial location information, or all or part of the values after hashing the third spatial location information and one or more plaintext information or derived information of plaintext information.
31. The method for establishing a wireless connection according to claim 30, characterized in that, The first device verifies the fifth verification value, including: Did the first device successfully decrypt the fifth verification value? Alternatively, the first device generates a sixth verification value and compares whether the fifth verification value and the sixth verification value are the same; Alternatively, the first device compares whether the fourth verification value and the fifth verification value are the same; Alternatively, the first device decrypts the fifth verification value to obtain the fourth spatial location information; The first device determines whether the difference between the third spatial location information and the fourth spatial location information is within a predetermined range.
32. The method for establishing a wireless connection according to any one of claims 21 to 26, characterized in that, Before the first device locates the second device and obtains the first spatial location information, the process also includes: The first device discovers the second device via WiFi messages or UWB messages.
33. The method for establishing a wireless connection according to any one of claims 21 to 26, characterized in that, Before the first device locates the third device and obtains the first spatial location information, the process also includes: The first device discovers the third device via WiFi messages or UWB messages.
34. The method for establishing a wireless connection according to any one of claims 21 to 26, characterized in that, If the first device determines that the verification of the second device and the third device has passed, the method further includes: The first device sends connection keys to the second device and the third device respectively.
35. The method for establishing a wireless connection according to any one of claims 21 to 26, characterized in that, The first device locates the second device to obtain first spatial location information, including: The first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the second device and obtain the first spatial location information.
36. The method for establishing a wireless connection according to any one of claims 21 to 26, characterized in that, The first device locates the third device and obtains the third spatial location information, including: The first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the third device and obtain the third spatial location information.
37. An electronic device, characterized in that, The electronic device includes a first device, the electronic device comprising: One or more processors, memory, and wireless communication modules; The memory and the wireless communication module are coupled to the one or more processors. The memory is used to store computer program code, which includes computer instructions. When the one or more processors execute the computer instructions, the electronic device performs the wireless connection establishment method as described in any one of claims 1 to 20, or the wireless connection establishment method as described in any one of claims 21 to 36.
38. A computer storage medium, characterized in that, Used to store a computer program, which, when executed, is specifically used to implement the wireless connection establishment method as described in any one of claims 1 to 20, or the wireless connection establishment method as described in any one of claims 21 to 36.
39. A computer program product, characterized in that, When the computer program product is run on a computer, it causes the computer to perform the wireless connection establishment method as described in any one of claims 1 to 20, or the wireless connection establishment method as described in any one of claims 21 to 36.
Citation Information
Patent Citations
Device connecting method, electronic device and server
CN102801721A
Method and device for establishing connection
CN105357633A
Communication establishment method and terminal and storage medium
CN109121121A