Method for establishing a wireless connection, electronic device, program product and storage medium

By using the Ultra Wideband (UWB) channel for device location and authentication and generating a shared key, the problem of inconvenient wireless connection caused by the special location of the router is solved, and convenient and secure connection between devices is achieved.

CN115767541BActive Publication Date: 2026-03-17HONOR DEVICE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-03
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

In large venues, routers are often installed on the ceiling, making it inconvenient for configurators to scan QR codes on the devices and affecting the convenience of wireless connectivity.

Method used

Ultra-wideband (UWB) channel technology is used for device positioning and authentication. A shared key or derived key is generated by sending a public key, and the trustworthiness of the device is verified by using spatial location information to achieve wireless connection between devices.

Benefits of technology

It improves the convenience and security of wireless connections between devices, ensuring connection reliability and privacy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115767541B_ABST
    Figure CN115767541B_ABST
Patent Text Reader

Abstract

The application provides a method for establishing a wireless connection, applied to a first device, comprising: the first device positioning a second device to obtain first spatial position information; the first device sending a first public key to the second device through a UWB channel, the first public key being used to generate a first shared key or a derivative key of the first shared key, the UWB channel being verified by the first device using the first spatial position information to determine whether it is trustworthy; the first device and the second device being authenticated based on the first shared key or the derivative key of the first shared key; and the first device establishing a wireless connection with the second device or with a third device using a connection key, the third device being authenticated with the second device based on a second shared key or a derivative key of the second shared key. Since the first device sends the first public key to the second device through the UWB channel, the convenience of establishing a wireless connection between devices is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network technology, and in particular to a method for establishing a wireless connection, an electronic device, a program product, and a storage medium. Background Technology

[0002] The WPA3 standard introduced by the Wi-Fi Alliance includes a Device Provision Protocol (DPP) that enables the establishment of wireless connections between different devices, such as routers, mobile phones, printers, and Internet of Things (IoT) devices, through a configurator.

[0003] In one application scenario example, the mobile phone acts as a Configurator, first scanning the QR code on the router, and then scanning the QR code on the printer, allowing the printer to establish a wireless network connection with the router.

[0004] However, if the device used to establish a wireless network connection is located in a special location, such as a large venue where the router is usually installed on the ceiling, it will be inconvenient for the configurator to scan the QR code on the device. Summary of the Invention

[0005] This application provides a method for establishing a wireless connection, an electronic device, a software product, and a storage medium to improve the convenience of establishing wireless connections between devices.

[0006] To achieve the above objectives, the present invention provides the following technical solution:

[0007] In a first aspect, this application provides a method for establishing a wireless connection, applied to a first device. In one application scenario, the first device establishes a wireless connection with a second device. The method for establishing the wireless connection includes: the first device locating the second device to obtain first spatial location information; the first device sending a first public key to the second device through an Ultra Wideband (UWB) channel, the first public key being used to generate a first shared key or a derived key of the first shared key, the UWB channel being verified by the first device using the first spatial location information; the first device and the second device authenticating each other based on the first shared key or the derived key of the first shared key; and the first device establishing a wireless connection with the second device using a connection key.

[0008] In an application scenario involving a first device, a second device, and a third device, the second device can act as an administrator, assisting the first and third devices in establishing a connection. The second device can verify the legitimacy of the first and second devices. Specifically, the second device can verify the first device based on its spatial location information and the third device based on its spatial location information. The method for establishing this wireless connection includes: the first device locating the second device to obtain first spatial location information; the first device sending a first public key to the second device via an Ultra Wideband (UWB) channel, the first public key being used to generate a first shared key or a derived key of the first shared key; the first device using the first spatial location information to verify the trustworthiness of the UWB channel; the first device and the second device authenticating each other based on the first shared key or a derived key of the first shared key; the third device authenticating with the second device based on a second shared key or a derived key of the second shared key, the second shared key being generated based on the third device's public key; and the first device using a connection key to establish a wireless connection with the third device.

[0009] As can be seen from the above, in the application scenario of connecting the first and second devices wirelessly, the first device sends a first public key to the second device via an Ultra Wideband (UWB) channel. This first public key is used to generate a first shared key or a derived key of the first shared key. The UWB channel is verified by the first device using first spatial location information. Furthermore, authentication between the first and second devices is successful based on the first shared key or its derived key. The first device then uses the connection key to establish a wireless connection with the second device, thus ensuring the security of the wireless connection. Moreover, because the first device uses a UWB channel to send the first public key to the second device, the ease of establishing a wireless connection between the devices is also guaranteed.

[0010] In an application scenario involving a first device, a second device, and a third device, the first device locates the second device, obtaining first spatial location information. The first device then sends a first public key to the second device via an Ultra Wideband (UWB) channel. This first public key is used to generate a first shared key or a derived key of the first shared key. The first device verifies the trustworthiness of the UWB channel using the first spatial location information. The first and second devices authenticate each other based on the first shared key or its derived key. The third device authenticates with the second device based on a second shared key or its derived key, which is generated from the third device's public key. The first device then establishes a wireless connection with the third device using a connection key, ensuring the security of this wireless connection. Furthermore, the use of a UWB channel by the first device to send the first public key to the second device also ensures the convenience of establishing wireless connections between the devices.

[0011] In one possible implementation, after the first device locates the second device and obtains the first spatial location information, the method further includes: the first device verifying the second device based on the first spatial location information; wherein, if the first device determines that the second device passes the verification, then the UWB channel is deemed trustworthy.

[0012] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device determining whether the difference between the first spatial location information and the second spatial location information is within a preset range, wherein the second spatial location information is obtained by the second device locating the first device; wherein, if the first device determines that the difference between the first spatial location information and the second spatial location information is within the preset range, the first device determines that the second device has passed the verification.

[0013] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device verifies the second device based on the first spatial location information in response to an operation command.

[0014] In one possible implementation, the operation instructions responded to by the first device include: various touch operations on the display screen performed by the user on the display screen of the first device, such as long press, short press, and multiple clicks on the user interface; voice input by the user to the first device; and specific actions input by the user to the first device, such as characteristic gestures.

[0015] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device using the first spatial location information to determine whether the second device is within a preset range of the first device; wherein, if the first device determines that the second device is within the preset range of the first device, then the first device determines that the second device has passed the verification.

[0016] In one possible implementation, the authentication method between the first device and the second device based on a first shared key or a derived key of the first shared key includes: the first device generating a first verification value based on the first shared key or a derived key of the first shared key and sending the first verification value to the second device; the first device receiving a second verification value sent by the second device and verifying the second verification value, wherein the second verification value is generated by the second device based on the first shared key or a derived key of the first shared key when verifying that the first verification value is correct.

[0017] In one possible implementation, the first device verifies the second verification value, including: whether the first device successfully decrypts the second verification value; or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; or, the first device compares whether the first verification value is the same as the second verification value.

[0018] In one possible implementation, the authentication method between the first device and the second device based on a first shared key or a derived key of the first shared key includes: the first device generating a first verification value based on first spatial location information and the first shared key or a verification key of the first shared key, and sending the first verification value to the second device; the first device receiving the second verification value sent by the second device, and verifying the second verification value, wherein the second verification value is generated by the second device based on the second spatial location information and the first shared key or a derived key of the first shared key when verifying that the first verification value is correct, and the second spatial location information is obtained by the second device locating the first device.

[0019] In one possible implementation, the first device generates a first verification value based on the first spatial location information and the first shared key or the verification key of the first shared key, including: the first device performs a hash operation on the first spatial location information or a derived value of the first spatial location information, and the first shared key or a derived key of the first shared key, to obtain a hash operation result, and all or part of the hash operation result is used as the first verification value; the derived value of the first spatial location information includes: part of the data of the first spatial location information, or all or part of the value after hashing the first spatial location information, or all or part of the value after hashing the first spatial location information and one or more plaintext information or derived information of plaintext information.

[0020] In one possible implementation, the first device verifies the second verification value, including: whether the first device successfully decrypts the second verification value; or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; or, the first device compares whether the first verification value is the same as the second verification value; or, the first device decrypts the second verification value to obtain second spatial location information; the first device determines whether the difference between the first spatial location information and the second spatial location information is within a predetermined range.

[0021] In one possible implementation, the verification of the second device based on the first spatial location information provided by the aforementioned possible implementations can be performed once or multiple times.

[0022] In one possible implementation, the verification methods for the second device based on the first spatial location information provided by the aforementioned possible implementation methods can be used in combination.

[0023] In one possible implementation, before the first device locates the second device and obtains the first spatial location information, the method further includes: the first device discovering the second device via WiFi messages or UWB messages.

[0024] In the above possible implementations, after the first device discovers the second device via WiFi or UWB messages, it locates the second device to ensure that the first device can locate the discovered device, and establishes a wireless connection when the verification is successful.

[0025] In one possible implementation, after the first device discovers the second device via UWB messages, the first device can inform the second device of its own Service Set Identifier (SSID), MAC address, and WiFi channel via UWB messages.

[0026] In one possible implementation, after the first device discovers the second device via WiFi or UWB messages, it triggers the location process of the first device for the second device via WiFi messages.

[0027] In one possible implementation, the WiFi message carries trigger indication information to trigger location execution.

[0028] In one possible implementation, during the discovery process between the first device and the second device via WiFi messages, the WiFi messages may carry information indicating that the device supports UWB functionality, or supports WiFi configuration via UWB, or supports WSC configuration.

[0029] In one possible implementation, the IE can carry information indicating that it supports UWB functionality, or supports WiFi configuration via UWB, or supports WSC configuration.

[0030] In one possible implementation, the first device discovers the second device via WiFi messages, including: the first device receiving a beacon frame broadcast by the second device.

[0031] In one possible implementation, the first device discovers the second device via WiFi messages, including: the first device sending a probe request frame; the first device receiving a probe response frame sent by the second device, wherein the probe response frame is sent by the second device after receiving the probe request frame.

[0032] In one possible implementation, the user selects the second device from the WLAN list of the first device, and the probe request frame sent by the first device to the second device may carry information about the second device. For example, at least one of the following: service set identifier (SSID) and MAC (Media Access Control) address.

[0033] In one possible implementation, the user can click the "Configure" button on the display of the first device, or click the name of the WiFi network to connect to. The first device responds to the user's action by sending a probe request frame to the second device.

[0034] In one possible implementation, before the first device establishes a wireless connection with the second device using the connection key, the process further includes: the first device receiving first signature information sent by the second device; and the first device verifying that the first signature information is correct.

[0035] In one possible implementation, before the first device establishes a wireless connection with the third device using the connection key, the process further includes: the first device receiving first signature information sent by the second device; and the first device verifying that the first signature information is correct.

[0036] In one possible implementation, the first device verifies the correctness of the first signature information by: the first device successfully decrypting the first signature information using the first signature public key; or, the first device decrypting the first signature information using the first signature public key to obtain a first hash value carried by the first signature information; the first device performing a hash operation on the first connection public key to obtain a second hash value; the first device determining that the first hash value and the second hash value are the same; or, the first device decrypting the first signature information using the first signature public key to obtain device information carried by the first signature information; and the first device verifying the correctness of the device information.

[0037] In one possible implementation, before the first device establishes a wireless connection with the second device using the connection key, the method further includes: the first device generating or receiving a connection key sent by the second device; wherein the connection key includes: a first connection key or a derivative key of the first connection key.

[0038] In one possible implementation, the first device generates a connection key by: the first device using a first connection public key and a second connection private key to generate a first connection key or a derived key of the first connection key, wherein the second connection private key is the private key of the first device.

[0039] In the above possible implementations, the first device uses the connection public key and its own private key to generate a connection key, and then uses the connection key to establish a wireless connection with the second or third device. This can ensure that the private key is not exchanged when the first device and the second device, or the first device and the third device, interact, thereby further ensuring security.

[0040] In one possible implementation, the first device generates a derived key of the first connection key using a first connection public key and a second connection private key, including: the first device generating a first connection key using the first connection public key and the second connection private key; the first device extracting a portion of the first connection key as a derived key of the first connection key; or, the first device generating a first connection key using the first connection public key and the second connection private key; the first device performing a hash operation on the first connection key to obtain a result, and using all or part of the result as a derived key of the first connection key; or, the first device generating a first connection key using the first connection public key and the second connection private key; the first device performing a hash operation on the first connection key and one or more plaintext information or derived information of plaintext information to obtain a derived key of the first connection key.

[0041] In one possible implementation, before the first device and the second device authenticate each other based on the first shared key or a derived key of the first shared key, the method further includes: the first device receiving a second public key sent by the second device via a UWB channel or a WiFi channel; the first device using the second public key and the first private key to generate the first shared key or a derived key of the first shared key, wherein the first private key is the private key of the first device.

[0042] In one possible implementation, the first device locates the second device to obtain first spatial location information, including: the first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the second device and obtain the first spatial location information.

[0043] Secondly, this application provides a method for establishing a wireless connection, applied to a first device, for use in an application scenario including a first device, a second device and a third device, wherein the first device acts as the administrator. The method for establishing a wireless connection includes: a first device locating a second device to obtain first spatial location information; the first device sending a first public key to the second device via an Ultra Wideband (UWB) channel, the first public key being used to generate a first shared key or a derived key of the first shared key, the UWB channel being verified by the first device using the first spatial location information; the first device and the second device authenticating each other based on the first shared key or the derived key of the first shared key; the first device locating a third device to obtain third spatial location information; the first device sending a third public key to the third device via the UWB channel, the third public key being used to generate a second shared key or a derived key of the second shared key, the UWB channel being verified by the first device using the third spatial location information; the first device and the third device authenticating each other based on the second shared key or the derived key of the second shared key; wherein: if the first device and the second device successfully authenticate each other based on the first shared key or the derived key of the first shared key, and the first device and the third device successfully verify authentication based on the second shared key or the derived key of the second shared key, the second device establishes a wireless connection with the third device using a connection key.

[0044] As can be seen from the above, in application scenarios involving a first device, a second device, and a third device, the first device sends a first public key to the second device via an Ultra Wideband (UWB) channel and a third public key to the third device via the same UWB channel. The first and second devices authenticate each other based on a first shared key or a derived key of the first shared key, and the first and third devices verify authentication based on a second shared key or a derived key of the second shared key. The second device uses a connection key to establish a wireless connection with the third device, thus ensuring the security and convenience of establishing a wireless connection between the second and third devices.

[0045] Furthermore, the first device verifies the second device based on the first spatial location information, and verifies the third device based on the third spatial location information. Once the first device determines that the second and third devices have been verified, the second device uses the connection key to establish a wireless connection with the third device. In this way, the establishment of a wireless network connection between the second and third devices can be easily completed.

[0046] In one possible implementation, after the first device locates the second device and obtains the first spatial location information, the method further includes: the first device verifying the second device based on the first spatial location information; wherein, if the first device determines that the second device passes the verification, then the UWB channel is deemed trustworthy.

[0047] In one possible implementation, the first device verifies the second device based on the first spatial location information, including: the first device responding to an operation command and verifying the second device based on the first spatial location information; or, the first device using the first spatial location information to determine whether the second device is within a preset range of the first device; wherein, if the first device determines that the second device is within the preset range of the first device, then the first device determines that the second device has passed verification; or, the first device determining whether the difference between the first spatial location information and the second spatial location information is within a preset range; wherein, the second spatial location information is obtained by the second device locating the first device; if the first device determines that the difference between the first spatial location information and the second spatial location information is within the preset range, then the first device determines that the second device has passed verification.

[0048] In one possible implementation, after the first device locates the third device and obtains the third spatial location information, the method further includes: the first device verifies the third device based on the third spatial location information; wherein, if the first device determines that the third device passes the verification, it determines that the UWB channel is trustworthy.

[0049] In one possible implementation, the first device verifies the third device based on third spatial location information, including: the first device responding to an operation command and verifying the third device based on the third spatial location information; or, the first device using the third spatial location information to determine whether the third device is within a preset range of the first device; wherein, if the first device determines that the third device is within the preset range of the first device, then the first device determines that the third device has passed verification; or, the first device determining whether the difference between the third spatial location information and the fourth spatial location information is within a preset range; wherein, the fourth spatial location information is obtained by the third device locating the first device; wherein, if the first device determines that the difference between the third spatial location information and the fourth spatial location information is within a preset range, then the first device determines that the third device has passed verification.

[0050] In one possible implementation, the first device and the second device authenticate each other based on a first shared key or a derived key of the first shared key, including: the first device generating a first verification value based on the first shared key or a derived key of the first shared key, and sending the first verification value to the second device; the first device receiving a second verification value sent by the second device, and verifying the second verification value, wherein the second verification value is generated by the second device based on the first shared key or a derived key of the first shared key when verifying that the first verification value is correct.

[0051] In one possible implementation, the first device verifies the second verification value by: whether the first device successfully decrypts the second verification value; or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value.

[0052] Alternatively, the first device can compare the first verification value with the second verification value to see if they are the same.

[0053] In one possible implementation, the first device and the second device authenticate each other based on a first shared key or a derived key of the first shared key, including: the first device generating a first verification value based on first spatial location information and the first shared key or a derived key of the first shared key, and sending the first verification value to the second device; the first device receiving a second verification value sent by the second device and verifying the second verification value, wherein the second verification value is generated by the second device based on second spatial location information and the first shared key or a derived key of the first shared key when verifying that the first verification value is correct, and the second spatial location information is obtained by the second device locating the first device.

[0054] In one possible implementation, the first device generates a first verification value based on a first shared key or a derived key of the first shared key, including: the first device performs a hash operation on the first spatial location information or a derived value of the first spatial location information, and the first shared key or a derived key of the first shared key, to obtain a hash operation result, and all or part of the hash operation result is used as the first verification value; the derived value of the first spatial location information includes: part of the data of the first spatial location information, or all or part of the value after hashing the first spatial location information, or all or part of the value after hashing the first spatial location information and one or more plaintext information or derived information of plaintext information.

[0055] In one possible implementation, the first device verifies the second verification value, including: whether the first device successfully decrypts the second verification value; or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; or, the first device compares whether the first verification value is the same as the second verification value; or, the first device decrypts the second verification value to obtain second spatial location information; the first device determines whether the difference between the first spatial location information and the second spatial location information is within a predetermined range.

[0056] In one possible implementation, the first device and the third device perform authentication based on a second shared key or a derived key of the second shared key, including: the first device generating a fourth verification value based on the second shared key or a derived key of the second shared key, and sending the fourth verification value to the third device; the first device receiving a fifth verification value sent by the third device, and verifying the fifth verification value, wherein the fifth verification value is generated by the third device based on the second shared key or a derived key of the second shared key when verifying that the fourth verification value is correct.

[0057] In one possible implementation, the first device verifies the fifth verification value by: whether the first device successfully decrypts the fifth verification value; or, the first device generates a sixth verification value and compares whether the sixth verification value is the same as the fifth verification value; or, the first device compares whether the fourth verification value is the same as the fifth verification value.

[0058] In one possible implementation, the authentication method between the first device and the third device based on the second shared key or a derived key of the second shared key includes: the first device generating a fourth verification value based on the third spatial location information and the second shared key or a derived key of the second shared key, and sending the fourth verification value to the third device; the first device receiving a fifth verification value sent by the third device, and verifying the fifth verification value, wherein the fifth verification value is generated by the third device based on the fourth spatial location information and the second shared key or a derived key of the second shared key when verifying that the fourth verification value is correct, and the fourth spatial location information is obtained by the third device locating the first device.

[0059] In one possible implementation, the first device generates a fourth verification value based on the third spatial location information and the second shared key or a derived key of the second shared key. This includes: the first device performing a hash operation on the third spatial location information or the derived value of the third spatial location information, and the second shared key or the derived key of the second shared key, to obtain a hash operation result. All or part of the hash operation result is used as the fourth verification value. The derived value of the third spatial location information includes: partial data of the third spatial location information, or all or part of the value after performing a hash operation on the third spatial location information, or all or part of the value after performing a hash operation on the third spatial location information and one or more plaintext information or derived information of plaintext information.

[0060] In one possible implementation, the first device verifies the fifth verification value, including: whether the first device successfully decrypts the fifth verification value; or, the first device generates a sixth verification value and compares whether the sixth verification value is the same as the fifth verification value; or, the first device compares whether the fourth verification value is the same as the fifth verification value; or, the first device decrypts the fifth verification value to obtain fourth spatial location information; the first device determines whether the difference between the third spatial location information and the fourth spatial location information is within a predetermined range.

[0061] In one possible implementation, before the first device locates the second device and obtains the first spatial location information, the method further includes: the first device discovering the second device via WiFi messages or UWB messages.

[0062] In one possible implementation, before the first device locates the third device and obtains the third spatial location information, the method further includes: the first device discovering the third device via WiFi messages or UWB messages.

[0063] In one possible implementation, the method further includes: the first device sending connection keys to the second device and the third device, respectively.

[0064] In one possible implementation, the method further includes: the first device sending first signature information to the second device; and the first device sending second signature information to the third device.

[0065] In one possible implementation, the first device locates the second device to obtain first spatial location information, including:

[0066] The first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the second device and obtain the first spatial location information.

[0067] In one possible implementation, the first device locates the third device to obtain third spatial location information, including:

[0068] The first device uses ultra-wideband (UWB) positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, or optical positioning to locate the third device and obtain its spatial location information.

[0069] Thirdly, this application provides an electronic device, which includes a first device or a second device. The electronic device includes: one or more processors, a memory, and a wireless communication module; the memory and the wireless communication module are coupled to one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and when one or more processors execute the computer instructions, the electronic device executes the wireless connection establishment method provided by the first aspect or any possible implementation of the first aspect, or executes the wireless connection establishment method provided by the second aspect or any possible implementation of the second aspect.

[0070] Fourthly, this application provides a computer storage medium for storing a computer program, which, when executed, is specifically used to implement the wireless connection establishment method provided by the first aspect or any possible implementation of the first aspect, or to implement the wireless connection establishment method provided by the second aspect or any possible implementation of the second aspect.

[0071] Fifthly, this application provides a computer program product that, when run on a computer, causes the computer to execute a wireless connection establishment method as provided in the first aspect or any possible implementation of the first aspect, or to execute a wireless connection establishment method as provided in the second aspect or any possible implementation of the second aspect. Attached Figure Description

[0072] Figure 1 This application provides an schematic diagram illustrating the establishment of a wireless network connection between devices, as shown in the embodiments of this application.

[0073] Figure 2 This is a schematic diagram of the structure of the electronic device provided in the embodiments of this application;

[0074] Figure 3 This is a schematic diagram of the router structure provided in an embodiment of this application;

[0075] Figure 4 A diagram illustrating the relative distance and relative orientation angle between a mobile phone and a router provided in an embodiment of this application;

[0076] Figure 5a This is an application diagram illustrating the establishment of a wireless network connection between devices, provided in another embodiment of this application.

[0077] Figure 5b A timing diagram of a wireless connection establishment method provided in another embodiment of this application;

[0078] Figure 6 A schematic diagram illustrating the establishment of a wireless connection between a mobile phone and a router, provided in another embodiment of this application;

[0079] Figure 7 A schematic diagram illustrating the establishment of a wireless connection between a mobile phone and a router, provided in another embodiment of this application;

[0080] Figure 8 A timing diagram of a wireless connection establishment method provided in another embodiment of this application;

[0081] Figure 9a , Figure 9b and Figure 9c This is a schematic diagram illustrating an application scenario provided in another embodiment of this application;

[0082] Figure 10 A timing diagram of a wireless connection establishment method provided in another embodiment of this application;

[0083] Figure 11 A timing diagram of a method for establishing a wireless connection provided in another embodiment of this application. Detailed Implementation

[0084] The terms "first," "second," and "third," etc., used in this application specification, claims, and drawings are used to distinguish different objects, not to limit a specific order.

[0085] In this application, the terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0086] The WPA3 standard introduced by the Wi-Fi Alliance includes a Device Provision Protocol (DPP) that enables the establishment of wireless connections between different devices, such as routers, mobile phones, printers, and Internet of Things (IoT) devices, through a configurator.

[0087] In an application scenario example, such as Figure 1 As shown in (a), the mobile phone acts as the Configurator, first scanning the QR code on the router, and then... Figure 1 As shown in (b), scan the QR code on the printer again, and the printer can establish a wireless network connection with the router.

[0088] However, the location of devices that establish wireless network connections is often unusual, such as in large venues where routers are typically installed on the ceiling, making it inconvenient for configurators to scan the QR codes on the devices.

[0089] Based on this, embodiments of this application provide a method for establishing a wireless network connection, applied to a first device and a second device. Commonly, two types of devices—stations and access points—establish wireless network connections. Therefore, this explanation will use one of the first and second devices as a station (STA) and the other as an access point (AP), specifically using the first device as the STA and the second device as the AP as an example.

[0090] Of course, the devices establishing a wireless network connection are not limited to sites and access points; any devices that support the WiFi communication protocol can establish a wireless network connection. It should also be noted that before the first and second devices establish a wireless network connection, they can exchange management frames and control frames; after the first and second devices establish a wireless network connection, they can exchange management frames, control frames, and data frames.

[0091] In this embodiment, the access point (AP) is the central node of the wireless network. Typically, an AP can include routers, repeaters, wireless network cards, and mobile phones. A site (STA) can refer to each terminal connected to the wireless network, such as mobile phones, tablets, desktops, laptops, ultra-mobile personal computers (UMPCs), handheld computers, netbooks, personal digital assistants (PDAs), wearable electronic devices, smartwatches, and network-connected electronic devices such as printers.

[0092] Figure 2 A schematic diagram of a network-enabled electronic device 200 is shown. The electronic device 200 may include a processor 210, an internal memory 220, an antenna 1, a wireless communication module 230, and a power supply module 240, etc.

[0093] It is understood that the structures illustrated in the embodiments of this application do not constitute a specific limitation on the electronic device 200. In other embodiments of this application, the electronic device 200 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0094] Processor 210 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, memory, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). Different processing units may be independent devices or integrated into one or more processors. The processor may serve as the central nervous system and command center of the electronic device 200. The processor can generate operation control signals based on instruction opcodes and timing signals to control instruction fetching and execution.

[0095] The processor 210 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 210 is a cache memory. This memory can store instructions or data that the processor 210 has just used or that are used repeatedly. If the processor 210 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 210, and thus improves the efficiency of the system.

[0096] Internal memory 220 can be used to store computer executable program code, which includes instructions. Processor 210 executes various functional applications and data processing of electronic device 200 by running the instructions stored in internal memory 220. Internal memory 220 may include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function (such as sound playback, image playback, etc.), etc. The data storage area may store data created during the use of electronic device 200 (such as audio data, phonebook, etc.). Furthermore, internal memory 220 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc.

[0097] The wireless communication function of the electronic device can be implemented through antenna 1 and wireless communication module 220, etc. Antenna 1 is used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device can be used to cover one or more communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In some other embodiments, the antenna can be used in conjunction with a tuning switch.

[0098] The wireless communication module 230 can provide solutions for wireless communication applications in electronic devices, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), near field communication (NFC) technology, and ultra-wideband (UWB) technology.

[0099] The wireless communication module 230 can be one or more devices integrating at least one communication processing module. The wireless communication module 230 receives electromagnetic waves via antenna 1, performs frequency modulation and filtering of the electromagnetic wave signal, and sends the processed signal to processor 210. The wireless communication module 230 can also receive signals to be transmitted from processor 210, perform frequency modulation and amplification, and then convert them into electromagnetic waves for radiation via antenna 1.

[0100] In some embodiments, the antenna 1 of the electronic device is coupled to the wireless communication module 230, enabling the electronic device 200 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include technologies such as BitTorrent, WLAN, NFC, and UWB.

[0101] The power module 240 may include a power supply, a power management component, etc. The power management component is used to manage the charging of the power supply and the power supply to other modules of the electronic device 200.

[0102] Figure 3 A schematic diagram of a router that can be used as an access point (AP) is shown. The router 300 includes: a processor 310, an internal memory 320, a power module 330, an interface 340, a console port 350, an auxiliary port 360, a wireless communication module 370, and an antenna 1.

[0103] It is understood that the structure illustrated in the embodiments of this application does not constitute a specific limitation on router 300. In other embodiments of this application, router 300 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0104] Processor 310 may include one or more processing units, such as processing modules or circuits of a central processing unit (CPU), graphics processing unit (GPU), digital signal processor (DSP), microprocessor (MCU), AI (Artificial Intelligence) processor, or field programmable gate array (FPGA). Different processing units may be independent devices or integrated into one or more processors. Processor 310 may include memory units for storing instructions and data.

[0105] The memory 320 can employ non-volatile memory, random access memory (RAM), flash memory, or read-only memory (ROM). RAM discards its information during router startup or power-off intervals. ROM stores the router's boot software, the first software to run on the router, responsible for entering normal operating mode. The router stores the complete operating system in RAM as a backup in case the operating system becomes unavailable. ROM is typically located on one or more chips soldered onto the router's motherboard. Flash memory primarily stores the router's operating system, maintaining normal operation. If flash memory is installed, it's mainly used to boot the router's operating system from its default location. With sufficient flash memory capacity, multiple operating system images can be stored, providing multiple boot options. Non-volatile memory primarily stores configuration data (boot configuration) read during operating system startup. RAM primarily serves as storage for the operating system table and buffers. The operating system can satisfy all its regular storage needs through RAM, allowing the router to quickly access this information. RAM's storage speed is superior to the three types mentioned above.

[0106] The power module 330 may include a power supply, a power management component, etc. The power management component is used to manage the charging of the power supply and the power supply to other modules of the router 300.

[0107] Interface 340 has a name and a number. The full name of an interface consists of an interface type identifier and a numerical number, starting from 0. For routers with fixed interfaces or those using modular interfaces, the full name of the interface uses only one number, numbered according to its physical order within the router. For example, Ethernet0 represents the first Ethernet interface, and Serial1 represents the second serial port. For routers that support "online plug-in and remove" or allow changing physical interface configurations, the full name of the interface must contain at least two numbers separated by a forward slash " / ". The first number represents the slot number, and the second number represents the port number within the interface card. For routers supporting "universal interface processors", the interface number format is "slot / port adapter / port number", such as Ethernet4 / 0 / 1, which is the second Ethernet interface of the first port adapter on slot 4.

[0108] Console port 350 enables users or administrators to communicate with router 300 using network-connected devices to complete router configuration. This port provides an EIA / TIA-232 asynchronous serial interface for configuration on router 300.

[0109] Similar to console port 350, auxiliary port 360 also provides an EIA / TIA-232 asynchronous serial interface. However, it is often used to connect a modem to enable remote management of router 300.

[0110] The router's wireless communication function can be achieved through antenna 1 and wireless communication module 370, etc. Antenna 1 is used to transmit and receive electromagnetic wave signals. The router's antenna can be used to cover one or more communication frequency bands.

[0111] The wireless communication module 370 can provide solutions for wireless communication applications on routers, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks) and ultra-wideband (UWB) technology.

[0112] The wireless communication module 370 can be one or more devices integrating at least one communication processing module. The wireless communication module 370 receives electromagnetic waves via antenna 1, performs frequency modulation and filtering of the electromagnetic wave signal, and sends the processed signal to processor 310. The wireless communication module 370 can also receive signals to be transmitted from processor 310, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 1.

[0113] In some embodiments, the antenna 1 of the electronic device is coupled to the wireless communication module 370, enabling the electronic device 300 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include WLAN and UWB technologies, etc.

[0114] First, it should be noted that the first and second devices can use various methods to locate each other, such as UWB positioning, ultrasonic positioning, Bluetooth positioning, cellular positioning, geomagnetic positioning, infrared positioning, RFID positioning, Zigbee positioning, ultra-wideband radio positioning, broadcast signal positioning, and optical positioning. Because UWB and ultrasonic positioning methods offer higher accuracy, they are more commonly used.

[0115] The following describes the positioning process of the first and second devices based on UWB positioning and ultrasonic positioning methods.

[0116] Specifically, the first device exchanges information with the second device multiple times in one-way or two-way based on the UWB communication protocol. The wireless signals used to exchange information are used for ranging and direction finding to obtain the relative distance L and relative azimuth angle θ between the first device and the second device, which is the first spatial position information. Figure 4 An example is shown illustrating the relative distance L and relative orientation angle θ between a first device and a second device. Furthermore, the first and second devices are positioned differently, such as the first device being placed vertically or horizontally, yet the relative distance and relative orientation angle between the first and second devices remain the same.

[0117] The first device can use a Time of Flight (ToF) positioning algorithm or a Time Difference of Arrival (TDoA) positioning algorithm to measure distance using UWB signals and obtain the relative distance between the first and second devices; alternatively, it can use an Angle-of-Arrival (AoA) positioning algorithm or an Angle-of-Departure (AoD) positioning algorithm to measure direction using UWB signals and obtain the relative azimuth angle between the first and second devices.

[0118] Similarly, the second device can also exchange information with the first device multiple times in one-way or two-way based on the UWB communication protocol. By using the wireless signals of the exchanged information to perform ranging and direction finding, the relative distance and relative azimuth angle between the second device and the first device can be obtained, which is the second spatial location information.

[0119] The second device can use the Time of Flight (ToF) positioning algorithm and the Time Difference of Arrival (TDoA) positioning algorithm to measure the distance and obtain the relative distance between the second device and the first device; alternatively, it can use the Angle-of-Arrival (AoA) positioning algorithm and the Angle of Departure (AoD) positioning algorithm to measure the direction and obtain the relative azimuth angle between the second device and the first device.

[0120] TOF and TDoA positioning algorithms can be further divided into Single-sided Two-way Ranging (SS-TWR), Double-sided Two-way Ranging (DS-TWR), and One-way Ranging (OWR). The following explanation uses the SS-TWR TOF positioning algorithm with the first device as an example to illustrate the specific process of obtaining the relative distance between the first and second devices. Furthermore, the explanation also uses the Angle of Arrival (AOA) positioning algorithm with the first device as an example to illustrate the specific process of obtaining the relative direction angle between the first and second devices.

[0121] The first device uses the SS-TWR ToF positioning algorithm to obtain the relative distance between the first and second devices as follows:

[0122] The first device sends a UWB signal to the second device at time S1. The UWB signal arrives at the second device after time Tp. The second device receives the UWB signal at time S2. After receiving the UWB signal, the second device sends a UWB feedback signal back to the first device at time S3. The time period between time S2 and time S3 is called the response processing delay Tr. The UWB feedback signal carries the response processing delay Tr. The UWB feedback signal arrives at the first device after time Tp. The first device receives the UWB feedback signal at time S4. After receiving the UWB feedback signal, the first device can determine the time period between time S1 and time S4, which is denoted as the loopback delay Td. Based on the loopback delay Td and the response processing delay Tr carried in the UWB feedback signal, the time Tp required for the UWB signal to be transmitted between the second device and the first device is calculated according to the following formula (1).

[0123]

[0124] The first device calculates the relative distance between the first device and the second device based on the transmission time Tp and the transmission speed of the UWB signal.

[0125] The relative azimuth angle between the first device and the second device is obtained using the Angle of Arrival (AoA) method as follows:

[0126] The antenna 1 of the first device is configured as an antenna array for receiving UWB signals. The antenna array includes a receiver and multiple antennas connected to the receiver. After the second device emits a UWB signal, all multiple antennas of the first device will receive the UWB signal. Due to the positional deviation of the multiple antennas, the phase of the UWB signal emitted by the second device will have a certain deviation when it reaches the multiple antennas. The first device uses the phase difference of the multiple antennas to calculate the relative azimuth angle between the first device and the second device.

[0127] Both the first and second devices are equipped with microphone arrays that can transmit directional ultrasonic waves. The first and second devices use ultrasonic waves to locate each other.

[0128] The first and second devices can also be positioned using Time of Flight (ToF) or Time Difference of Arrival (TDoA) positioning algorithms, utilizing ultrasonic signals for ranging to obtain the relative distance between the two devices; alternatively, they can be positioned using Angle-of-Arrival (AoA) or Angle-of-Departure (AoD) positioning algorithms, utilizing ultrasonic signals for direction finding to obtain the relative azimuth angle between the first and second devices. See the foregoing for details.

[0129] It should also be noted that before introducing the proposed solution, a brief explanation of the basic process of DPP will be given.

[0130] DPP mainly includes the following four processes: bootstrapping, authentication, configuration, and network introduction.

[0131] 1. Bootstrapping

[0132] The purpose of bootstrapping is to allow one party to obtain the other party's public key for use in subsequent processes.

[0133] 2. Authentication

[0134] The party that initiates the authentication process is called the initiator.

[0135] After this step, the Initiator confirms that the Responder is indeed the true owner of the public key it obtained. Furthermore, this step also identifies which party, acting as the Configurator or Enrollee, is involved in establishing the wireless connection.

[0136] In addition, this step also generates a session key ke for use in the subsequent configuration step.

[0137] In summary, authentication has three main functions: 1) authentication; 2) determining the roles of both parties; and 3) generating a key.

[0138] 3. Configuration

[0139] Both parties who have successfully completed the authentication process proceed to the configuration phase. This phase is initiated by the Enrollee, and the information sent by the Enrollee is encrypted using the aforementioned ke.

[0140] During the configuration phase, the Enrollee informs the Configurator whether it is an AP or a STA (or Configurator) by sending a request message. Upon receiving the request message from the Enrollee, the Configurator sends network configuration information to the Enrollee. This information includes the target network's SSID, AKM, and credential information (which may vary depending on the target network type and DPP protocol version, such as the pre-shared key and connector). If the Enrollee receives a pre-shared key as its credential, the DPP process ends.

[0141] In summary, the functions of configuration are: 1) to determine the Enrollee role; and 2) to provide network configuration information.

[0142] 4. Network introduction

[0143] The network access phase will only occur when 1) the Enrollee is a STA; or 2) the network configuration information received during the configuration phase contains a Connector.

[0144] Example 1

[0145] In one application scenario, the first device is a mobile phone, and the second device is a router. (See [link / reference]). Figure 5a When a user holds their mobile phone and approaches the router, a wireless network connection can be established after multiple interactions between the phone and the router once the phone is within a certain range of the router.

[0146] To achieve the above application scenarios, see Figure 5b The present application provides a method for establishing a wireless network connection, which includes the following steps:

[0147] S501, the first device and the second device complete the discovery through WiFi messages.

[0148] The discovery process in step S501 can be implemented in two ways. Implementation method one includes the following steps:

[0149] S501a, the second device sends a beacon frame.

[0150] Normally, the second device broadcasts beacon frames at a set period. Devices within the transmission range of the second device's WiFi signal can receive the beacon frames broadcast by the second device.

[0151] In some embodiments, such as Figure 6 As shown in (a), the second device has a button for completing WiFi configuration; the figure illustrates this by naming the button the WPS button. When the WPS button on the second device is triggered, the second device also broadcasts a beacon frame even before the scheduled broadcast time. Devices within the WiFi signal transmission range of the second device can receive the beacon frame sent by the second device. If the first device is within the receiving range of the beacon frame sent by the second device, the first device can also receive the beacon frame. Upon receiving the beacon frame sent by the second device, the first device can determine that there is an access point nearby where a wireless network connection can be established.

[0152] It should also be noted that when the WPS button on the second device is triggered, the beacon frame sent by the second device can also carry information. This information can be used to indicate that the second device is a device to be configured and can enter the establishment of a wireless network connection, or that the second device supports the configuration function of a wireless network connection, etc.

[0153] It is understandable that when the first device receives the beacon frame broadcast by the second device, it has completed the discovery of the second device by the first device.

[0154] S501b: The first device sends a probe request frame to the second device.

[0155] The first device receives a beacon frame sent by the second device and has detected the second device. The first device can then send a probe request frame to the second device.

[0156] In some embodiments, the display screen of the first device may display, such as Figure 6 (b) shows the information to remind the user that there are access points around the first device where a wireless network connection can be established.

[0157] If the first device discovers the second device, it can send a probe request frame to the second device. In some embodiments, such as Figure 6 As shown in (c), the user clicks the "Connect" button on the display of the first device, and the first device responds to the user's operation by sending a probe request frame to the second device.

[0158] In other embodiments, the display screen of the first device may also display a "configuration button" or the name of the WiFi network to be connected. The user can click the "configuration button" or the name of the WiFi network to be connected on the display screen of the first device. In response to the user's operation, the first device sends a probe request frame to the second device.

[0159] S501c, the second device sends a probe response frame to the first device.

[0160] Upon receiving the probe request frame from the first device, the second device can determine that a site exists in its vicinity where a wireless network connection can be established. Therefore, the second device returns a probe response frame to the first device.

[0161] It is understandable that when the second device receives the probe request frame sent by the first device and then returns a probe response frame to the first device, the second device has completed the discovery of the first device.

[0162] In some embodiments, the first device and the second device can perform unilateral discovery, meaning either the first device discovers the second device, or the second device discovers the first device. Based on this, the aforementioned steps S501b and S501c are optional steps. When only the first device discovering the second device is required, steps S501b and S501c may not be executed.

[0163] Implementation method two includes the following steps:

[0164] S501d, the first device sends a probe request frame.

[0165] The first device can periodically broadcast probe request frames. Devices within the transmission range of the first device's WiFi signal can receive the probe request frames broadcast by the first device.

[0166] The first device sends a probe request frame, and the second device receives the probe request frame, thus enabling the second device to discover the first device.

[0167] In some embodiments, see Figure 7 (d) The available WLAN list of the first device displays multiple wireless network access points around the first device. If a user needs to control the first device to connect to an access point in the available WLAN list, they can click the desired access point button in the available WLAN list of the first device, such as... Figure 7 Access point WLAN3 in (d). It should be noted that the multiple wireless network access points displayed in the available WLAN list of the first device are determined by the second device sending beacon frames and the first device receiving these beacon frames.

[0168] Because the second device referred to by WLAN3 supports WPS functionality, when the user clicks WLAN3, the display of the first device will... Figure 7 As shown in (e), a prompt message appears indicating that the first device and WLAN3 have established a wireless connection via WPS. The user... Figure 7 (e) Click the “Connect” button on the display interface. The first device will respond to the user’s operation and send a probe request frame to the second device (referring to WLAN3).

[0169] The first device sends a probe request frame, and the second device receives the probe request frame, thus enabling the second device to discover the first device.

[0170] In some embodiments, the user selects WLAN3 in the WLAN list of the first device, and the probe request frame sent by the first device to the second device may carry information about WLAN3. For example, at least one of the service set identifier (SSID) and MAC (Media Access Control) address.

[0171] S501e, the second device sends a probe response frame to the first device.

[0172] The second device receives the probe request frame sent by the first device, and then the second device returns a probe response frame to the first device.

[0173] Understandably, when the second device receives a probe request frame sent by the first device, it can determine that there are sites around it that need to access the wireless network, thus completing the discovery of the first device.

[0174] S501f, the second device sends a beacon frame.

[0175] The second device can periodically detect beacon frames. In some embodiments, the user follows... Figure 7 (e) The displayed prompts control the first device to move closer to the second device, for example... Figure 7 As shown in (f), the WPS button on the second device is triggered. Once the WPS button on the second device is triggered, the second device can broadcast beacon frames.

[0176] When the first device approaches the signal reception range of the second device, it can receive the beacon frame broadcast by the second device. Upon receiving the beacon frame broadcast by the second device, the first device can determine that there is an accessible access point in its vicinity, thus completing the discovery of the second device.

[0177] S501f is an optional step. In some embodiments, step S501f may not be performed.

[0178] The messages exchanged between the first device and the second device in the two aforementioned implementation methods can be understood as WiFi messages, which are the interaction between the first device and the second device through WiFi communication technology.

[0179] In some embodiments, during the discovery process between the first device and the second device via WiFi messages, information indicating that the device supports UWB functionality may be included in the WiFi messages.

[0180] Specifically, the beacon frames sent by the second device, the probe request frames sent by the first device, and the probe response frames returned by the second device can all carry UWB IE (information element) messages. These messages are used to indicate that the device supports UWB functionality, or supports WiFi configuration via UWB, or supports WSC configuration (WSC implicitly indicates that UWB configuration methods are supported).

[0181] The format of a UWB IE (information element) message is as follows:

[0182] A UWB IE can be divided into at least three parts, as shown in the table below. The first part: Element ID indicates that it is a UWB IE; the second part: length indicates the number of bytes occupied by the entire UWB IE; and the third part: indicates the information carried by the UWB IE, such as capability information.

[0183]

[0184] In some embodiments, the UWB IE (information element) message may be carried within the attribute information of the WSC IE in the beacon frame, probe request frame, and probe response frame. In other embodiments, the UWB IE (information element) message may also be carried as a separate IE in the beacon frame, probe request frame, and probe response frame.

[0185] It should be noted that WSC IE is an IE defined in the Wi-Fi Alliance for WiFi configuration, and is not limited to the name WSC IE.

[0186] It should also be noted that step S501 and its two implementations are optional, and their purpose is to enable the first and second devices to discover each other's devices. In some application scenarios, when the first and second devices establish a wireless network connection, step S501 and its two implementations can be skipped, and step S502 can be executed directly.

[0187] After the first device and the second device discover each other via WiFi messages, they locate each other to obtain the other's spatial location information. Specifically, the first device executes step S502, and the second device executes step S503. It should also be noted that there is no restriction on the execution order of step S502 by the first device and step S503 by the second device. Figure 5b The example shown is parallel execution.

[0188] The foregoing content describes how the first and second devices perform the discovery process via WiFi messages. The first and second devices can also perform the discovery process via other technologies, such as UWB.

[0189] The discovery between the first and second devices via UWB messages is accomplished as follows:

[0190] Method 1: The first device sends a beacon frame.

[0191] The second device listens for beacon frames sent by the first device.

[0192] If the second device detects a beacon frame sent by the first device, then the second device has completed the discovery of the first device.

[0193] The specific format of the beacon frames sent by the first device and the beacon frames sent by the second device can be found in the UWB technical requirements, which will not be elaborated here.

[0194] In some embodiments, the beacon frame sent by the first device may carry a message, such as information indicating that it supports UWB functionality.

[0195] Method 2: The first device sends a Beacon Request frame.

[0196] The second device receives the beacon request frame and then sends a beacon frame to the first device.

[0197] The first device sends a beacon request frame, and the second device receives the beacon request frame and returns a beacon frame to the first device, thus completing the mutual discovery between the first and second devices.

[0198] In some embodiments, the beacon request frame sent by the first device and the beacon frame sent by the second device may also carry messages, such as information indicating that they support UWB functionality.

[0199] S502, The first device locates the second device and obtains the first spatial location information.

[0200] The first spatial location information includes the relative distance between the first device and the second device, and optionally, the relative azimuth angle. The following explanation uses an example where the first spatial location information includes the relative distance and relative azimuth angle between the first device and the second device.

[0201] The specific method by which the first device locates the second device and obtains the first spatial location information is as described above and will not be repeated here.

[0202] In some embodiments, the first device may present the obtained first spatial location information to the user through means such as a display screen, indicator light, speaker or vibration motor.

[0203] In some embodiments, if the first device has a display screen, the first spatial location information can be displayed on the display screen.

[0204] In some embodiments, if the first device is equipped with an indicator light, the second spatial location information can be presented through different operating modes of the indicator light. In some embodiments, different colors of the indicator light can be used to indicate the relative distance and relative azimuth angle between the first and second devices. In one example, a green light indicates a range of 1 meter, and a red light indicates a range of more than 1 meter; or, a green light indicates a relative azimuth angle within 90 degrees, and a red light indicates a relative azimuth angle exceeding 90 degrees. In other embodiments, different flashing frequencies of the indicator light can be used to indicate the relative distance and relative azimuth angle between the second and second devices. In one example, low-frequency flashing indicates a range of 1 meter, and high-frequency flashing indicates a range of more than 1 meter; or, low-frequency flashing indicates a relative azimuth angle within 90 degrees, and high-frequency flashing indicates a relative azimuth angle exceeding 90 degrees.

[0205] In some embodiments, if the first device is equipped with an audio signal output component such as a speaker, the first spatial location information can be broadcast verbally through the audio signal output component. If the audio signal output component is a simple buzzer, the first spatial location information can be presented through different operating modes of the buzzer. In one example, buzzers of different durations are used to indicate different relative distances or different relative azimuth angles between the first and second devices.

[0206] In some embodiments, if the first device is equipped with a vibration motor, the first device can output first spatial position information through the vibration motor. Specifically, different vibration durations and / or frequencies of the vibration motor can be used to output the first spatial position information. In one example, vibrations of different durations of the vibration motor are used to indicate different relative distances between the first device and the second device, and vibrations of different frequencies of the vibration motor are used to indicate different relative orientation angles between the first device and the second device.

[0207] S503, The second device locates the first device and obtains the second spatial location information.

[0208] The second spatial location information may also include the relative distance and relative azimuth angle between the first and second devices. Similarly, the specific method for obtaining the second spatial location information by locating the first device using the second device is as described above.

[0209] In some embodiments, the second device may present the obtained second spatial location information to the user through means such as a display screen, indicator light, speaker, or vibration motor.

[0210] In some embodiments, if the second device has a display screen, the second spatial location information can be displayed on the display screen.

[0211] In some embodiments, if the second device is equipped with an indicator light, the second spatial position information can be presented through different operating modes of the indicator light. In some embodiments, different colors of the indicator light can be used to indicate the relative distance and relative azimuth angle between the first and second devices. In one example, a green light indicates a range of 1 meter, and a red light indicates a range of more than 1 meter; or, a green light indicates a relative azimuth angle within 90 degrees, and a red light indicates a relative azimuth angle exceeding 90 degrees. In other embodiments, different flashing frequencies of the indicator light can be used to indicate the relative distance and relative azimuth angle between the second and second devices. In one example, low-frequency flashing indicates a range of 1 meter, and high-frequency flashing indicates a range of more than 1 meter; or, low-frequency flashing indicates a relative azimuth angle within 90 degrees, and high-frequency flashing indicates a relative azimuth angle exceeding 90 degrees.

[0212] In some embodiments, if the second device is equipped with an audio signal output component such as a speaker, the second spatial location information can be broadcast verbally through the audio signal output component. If the audio signal output component is a simple buzzer, the second spatial location information can be presented through different operating modes of the buzzer. In one example, buzzers of different durations are used to indicate different relative distances or different relative azimuth angles between the first and second devices.

[0213] In some embodiments, if the second device is equipped with a vibration motor, the second device can output second spatial position information through the vibration motor. Specifically, different vibration durations and / or frequencies of the vibration motor can be used to output the second spatial position information. In one example, different durations of vibration of the vibration motor are used to indicate different relative distances between the first device and the second device, and different frequencies of vibration of the vibration motor are used to indicate different relative orientation angles between the first device and the second device.

[0214] In some embodiments, before steps S502 and S503, the first device may notify the second device via a WiFi message that the first device wants to initiate location services; and / or, the second device may notify the first device via a WiFi message that the second device wants to initiate location services.

[0215] Specifically, the first device sends a probe request frame to the second device. This probe request frame carries indication information, which instructs the first device to initiate location services. In some embodiments, this indication information is a 1-bit indication information, which can be carried in the UWB IE or the WiFi-configured IE.

[0216] The second device sends a beacon frame to the first device. The beacon frame carries indication information, which is also used to instruct the second device to initiate a location.

[0217] It should be noted that, as mentioned earlier, the first device in this embodiment is a STA (Stationary Access Point), and the second device is an AP (Access Point). Typically, the STA sends a probe request frame, and the AP sends a beacon frame. Therefore, the probe request frame sent by the first device to the second device, and the beacon frame sent by the second device, carry indication information. However, the first device can also send a beacon frame, and the second device can also send a probe request frame. This can be understood as the WiFi message sent by the first device to the second device carrying indication information, and the WiFi message sent by the second device to the first device also carrying indication information.

[0218] S504. The first device verifies the second device based on the first spatial location information.

[0219] The first device verifies the second device based on the first spatial location information, which can be implemented in the following two ways.

[0220] Method 1, S504a: The first device verifies the second device based on the first spatial location information by responding to user operations.

[0221] The first device presents first spatial location information. In some embodiments, the first device has a display screen that displays the first spatial location information. In other embodiments, the first device has an audio signal output component through which the first device plays the first spatial location information.

[0222] After the first device presents the first spatial location information, the user performs a confirmation action. This includes various touch operations on the first device's display screen, such as long press, short press, and multiple taps on the user interface. The first device responds to these touch operations to complete the verification of the second device. Alternatively, the user can input voice; the first device recognizes the user's voice to complete the verification of the second device. The user can also perform specific actions, such as specific gestures; the first device responds to these specific actions to complete the verification of the second device.

[0223] The first device displays a list of WiFi networks, which includes at least the second device. When a user clicks on the second device to connect, the first device responds to the user's click on the WiFi list and verifies the second device. In some embodiments, if the WiFi list includes multiple access points besides the second device, the spatial location information of the second device and each access point may also be displayed.

[0224] Method 2, S504b: The first device determines whether the first spatial location information meets the first condition, the second condition, or the first condition and the second condition.

[0225] First condition: The first spatial location information is within the preset range.

[0226] The first device determines that the relative distance between the first device and the second device in the first spatial position is within a preset range, such as within 1 meter or 2 meters.

[0227] The second condition is that the first spatial location information and the second spatial location information match. The first spatial location information is the same as the second spatial location information, or the difference between the first spatial location information and the second spatial location information is within a predetermined range. Specifically, the difference in the relative distance between the first device and the second device is within the first range, and the difference in the relative directional angle between the first device and the second device is within the second range. In one example, the distance difference is about 10 cm, and the directional angle difference is about 3 degrees.

[0228] When the first device determines whether the first spatial location information meets the second condition, the first device also needs to obtain the second spatial location information of the second device through message interaction.

[0229] S505. The second device verifies the first device based on the second spatial location information.

[0230] The second device verifies the first device based on the second spatial location information in the same way as the first device verifies the second device based on the first spatial location information, as described above.

[0231] Specifically: S505a, the second device verifies the first device based on the second spatial location information by responding to user operations. Alternatively, S505b, the second device determines whether the second spatial location information meets the first condition, the second condition, or both the first and second conditions.

[0232] It should be noted that step S504, where the first device verifies the second device based on the first spatial location information, and step S505, where the second device verifies the first device based on the second spatial location information, can also be implemented using the following methods, see details below. Figure 5b The implementation method includes:

[0233] S506, The first device sends the first public key to the second device.

[0234] The first device is configured with an asymmetric key pair, which includes a first public key and a first private key. The first public key can be publicly disclosed, while the first private key is not. The asymmetric key pair can be generated by the first device or pre-stored.

[0235] In some embodiments, the first device sends a first public key via a UWB channel, and the second device receives the first public key via a UWB channel. Before employing the verification method provided in this embodiment, the first and second devices could verify each other's devices using either of the aforementioned two verification methods. Thus, since the first and second devices use the UWB function to locate each other's devices, and the location verification is successful, it indicates that the interaction between the first and second devices via the UWB channel is trustworthy. Based on this, the first device sends the first public key via the UWB channel.

[0236] Of course, the first and second devices can also be verified directly using the verification method provided in this embodiment, without executing the two embodiments described above.

[0237] In some embodiments, the first device sends the first public key via a UWB channel, or the first public key can be transmitted encrypted over the UWB channel. Specifically, the first device encrypts the first public key to obtain an encrypted first public key, and then sends the encrypted first public key to the second device via the UWB channel.

[0238] The encryption method used by the first device for the first public key is not limited; various common encryption algorithms can be used, which will not be elaborated here. Furthermore, the first and second devices must agree in advance on the encryption method for the first public key.

[0239] In other embodiments, the first device sends a first public key to the second device via a UWB channel. The second device sends a second public key to the first device via a WiFi channel.

[0240] In this process, the second device obtains information about the first device's WiFi channel through the UWB channel, which helps the second device discover the first device using the WiFi channel.

[0241] Specifically, the first device sends a UWB message via a UWB channel, carrying information such as the first device's WiFi channel and MAC address. The second device receives the UWB message and can determine the first device's WiFi channel based on the information carried in the message. Thus, the second device can send a second public key to the first device via the WiFi channel.

[0242] S507, The second device sends the second public key to the first device.

[0243] The second device may also generate or pre-store an asymmetric key pair, which includes a second public key and a fourth private key. The second public key can be published, while the fourth private key is not disclosed.

[0244] In some embodiments, the second device sends a second public key to the first device via a UWB channel.

[0245] In other embodiments, the second device sends a second public key to the first device via a WiFi channel.

[0246] The method by which the second device sends the second public key to the first device can be found in step S506 above, and will not be repeated here.

[0247] It should be noted that steps S506 and S507 can be understood as the bootstrapping steps in the DPP process.

[0248] In this embodiment, the first device obtains the spatial location information of the second device through step S502, and through step S504, the first device verifies the second device through the spatial location information of the second device, and when the second device is successfully verified, the first device sends a first public key to the second device. The first public key is used in subsequent steps of the DPP process.

[0249] Similarly, the second device also obtains the spatial location information of the first device through step S503. After step S505, the second device verifies the first device through the spatial location information of the first device, and sends the second public key to the first device when the first device successfully verifies it. The second public key is also used in subsequent steps of the DPP process.

[0250] This shows that it is relatively convenient for the first and second devices to obtain each other's public keys.

[0251] It should be noted that in the two public key exchange steps, where the first device sends the first public key to the second device and the second device sends the second public key to the first device, it is only necessary to ensure that the public key is sent from one device to the other using the UWB channel, and usually the device that sends the public key first will use the UWB channel first.

[0252] It should also be noted that after the first device obtains the spatial location information of the second device through step S502, and then after step S504, the first device successfully verifies the second device through the spatial location information of the second device before sending the first public key to the second device. This ensures that the first device sends the first public key to the legitimate second device, and then uses the public key to complete the subsequent process, so as to establish a wireless network connection between the first device and the legitimate second device.

[0253] Similarly, after the second device obtains the spatial location information of the first device through step S503, and then through step S505, after the second device successfully verifies the first device using the spatial location information of the first device, the second device sends the second public key to the first device. This also ensures that the second device sends the second public key to the legitimate first device, and also ensures that the subsequent process is executed with the second public key, so as to realize the establishment of a wireless network connection between the second device and the legitimate first device.

[0254] S508. The first device uses the second public key and the first private key to generate a first shared key or a derived key of the first shared key.

[0255] In some embodiments, after the first device generates a first shared key using a first private key and a second public key, it may extract a portion of the first shared key as a derived key of the first shared key.

[0256] In other embodiments, the first device may also perform one or more hash operations on the first shared key, and all or part of the hash values ​​are used as derived keys of the first shared key.

[0257] In other embodiments, the first device may also use the first shared key in combination with one or more plaintext messages or derived messages jointly owned by both devices to perform one or more hash operations to obtain a derived key of the first shared key. Furthermore, a portion of the first shared key may be extracted as the derived key to be used.

[0258] The plaintext information jointly owned by both devices may include:

[0259] A random number generated by a first or second device; attribute information of the first or second device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.

[0260] The methods for generating derivative information of one or more plaintext messages jointly owned by both devices are as follows: 1. Take a portion of one or more plaintext messages as a derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.

[0261] One or more plaintext messages jointly owned by both devices can be transmitted in the following ways: One device sends one or more plaintext messages to the other. Alternatively, the first and second devices may agree upon this. Or, they may obtain publicly available information relevant to both the first and second devices.

[0262] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.

[0263] S509. The second device uses the first public key and the fourth private key to generate a first shared key or a derived key of the first shared key.

[0264] The method by which the second device generates the derived key of the first shared key is the same as the method by which the first device generates the derived key of the first shared key in step S508, and will not be repeated here.

[0265] Furthermore, if the first device receives the second public key correctly and the second device receives the first public key correctly, the first shared key generated by the second device and the first shared key generated by the first device are the same key.

[0266] S510, the first device and the second device authenticate based on the first shared key or a derived key of the first shared key.

[0267] In one possible implementation, step S510, the authentication method of the first device and the second device based on the first shared key or a derived key of the first shared key, includes:

[0268] 1) The first device generates a first verification value based on the first shared key or a derived key of the first shared key, and sends the first verification value to the first device.

[0269] 2) After receiving the first verification value sent by the first device, the second device verifies the first verification value.

[0270] 3) The second device generates a second verification value based on the first shared key or a derived key of the first shared key, and sends the second verification value to the first device.

[0271] The second device can generate a second verification value based on the first shared key or a derived key of the first shared key after verifying that the first verification value is correct.

[0272] 4) After receiving the second verification value sent by the second device, the first device verifies the second verification value.

[0273] In this embodiment, the first device performs one or more hash operations on the first shared key or a derived key of the first shared key, and uses all or part of the hash values ​​as the first verification value. Similarly, the second device performs one or more hash operations on the first shared key or a derived key of the first shared key, and uses all or part of the hash values ​​as the second verification value.

[0274] It should be noted that if the first shared key or the derived key of the first shared key generated by the first device and the second device are the same, the first device and the second device use the same verification value generation method, and the generated first verification value and second verification value are the same.

[0275] In this embodiment, since the first device and the second device generate the verification value using the same generation method, the method for verifying the other device's generation is also the same. The following description uses the method of the first device verifying the second verification value as an example:

[0276] In some embodiments, the first device verifies the second verification value by: decrypting the second verification value to obtain a decrypted value, and then verifying whether the decrypted value is correct.

[0277] In other embodiments, the first device verifies the second verification value by generating a third verification value and comparing it with the second verification value. If the first device determines that the third verification value and the second verification value are the same, then the second verification value is verified as correct.

[0278] In other embodiments, the first device verifies the second verification value by comparing whether the first verification value and the second verification value are the same. If the first device determines that the first verification value and the second verification value are the same, then the second verification value is verified as correct.

[0279] In another possible implementation, step S510, the authentication method of the first device and the second device based on the first shared key or a derived key of the first shared key, includes:

[0280] 1) The first device generates a first verification value based on the first shared key or a derived key of the first shared key and the first spatial location information, and sends the first verification value to the first device.

[0281] 2) After receiving the first verification value sent by the first device, the second device verifies the first verification value.

[0282] 3) The second device generates a second verification value based on the first shared key or a derived key of the first shared key and the second spatial location information, and sends the second verification value to the first device.

[0283] The second device may also generate a second verification value based on the first shared key or a derived key of the first shared key, and the second spatial location information, after verifying that the first verification value is correct.

[0284] 4) After receiving the second verification value sent by the second device, the first device verifies the second verification value.

[0285] In this embodiment, the second device generates the second verification value in the same way as the first device generates the first verification value. The following description uses the method of the first device generating the first verification value as an example:

[0286] The first device performs one or more hash operations on the first shared key and the first spatial location information, and uses all or part of the hash result as the first verification value. Alternatively, the first device performs a hash operation on the derived key of the first shared key and the first spatial location information, and uses all or part of the hash result as the first verification value.

[0287] In some embodiments, the first device may extract a portion of the first spatial location information as a derived key, and a first shared key or a derived key of the first shared key, to generate a first verification value. In one example, the first spatial location information includes: the relative distance between the first device and the second device is 0.8 meters, and the relative direction angle is 30 degrees. This information is then converted into the number 08 as a derived key, or into the number 30 as a derived key, or into the number 0830 as a derived key.

[0288] In other embodiments, the first device may perform one or more hash operations on the first spatial location information, and use all or part of the hashed values ​​as a derived key, and generate a first verification value together with the first shared key or a derived key of the first shared key.

[0289] In other embodiments, the first device may perform one or more hash operations on the first spatial location information and one or more plaintext information or derived information of plaintext information, and use all or part of the values ​​after the hash operation as a derived key; and then use the derived key and the first shared key or a derived key of the first shared key to generate a first verification value.

[0290] In this embodiment, since the first device and the second device generate the verification value using the same generation method, the method for verifying the other device's generation is also the same. The following description will also take the method of the first device verifying the second verification value as an example:

[0291] In some embodiments, the first device verifies the second verification value by: the first device decrypting the second verification value to obtain the second spatial location information; the first device comparing the first spatial location information and the second spatial location information; if the first spatial location information and the second spatial location information are the same, or if the difference between the first spatial location information and the second spatial location information is within a predetermined range, then the first device verifies that the second verification value is correct.

[0292] The difference between the first spatial location information and the second spatial location information is within a predetermined range, which can refer to: the distance difference between the first device and the second device being within the first range, and the angular difference between the relative directions of the first device and the second device being within the second range. In one example, the distance difference is approximately 10 cm, and the angular difference is approximately 3 degrees.

[0293] In other embodiments, the first device verifies the second verification value by generating a third verification value and comparing it with the second verification value. If the first device determines that the third verification value and the second verification value are the same, then the second verification value is verified as correct.

[0294] In other embodiments, the first device verifies the second verification value by comparing whether the first verification value and the second verification value are the same. If the first device determines that the first verification value and the second verification value are the same, then the second verification value is verified as correct.

[0295] The process from step S508 to step S510 can be understood as the verification step in the DPP process.

[0296] It should also be noted that the aforementioned first device, based on the first spatial location information, can verify each implementation of the second device multiple times. Furthermore, the aforementioned first device, based on the first spatial location information, can verify several implementations of the second device in any combination, enabling the first device to verify the second device multiple times based on the first spatial location information. Similarly, the second device, based on the second spatial location information, can verify each implementation of the first device multiple times. Furthermore, the second device, based on the second spatial location information, can verify several implementations of the first device in any combination, enabling the second device to verify the first device multiple times based on the second spatial location information.

[0297] S511 After the first device and the second device successfully authenticate based on the first shared key or a derived key of the first shared key, the second device sends the first connection public key to the first device.

[0298] The second device generates an asymmetric key pair, including a first connection public key and a first connection private key.

[0299] In this embodiment, the first device is a mobile phone, and the second device is a router. Because mobile phones have more functions and are more convenient to use than routers, this embodiment uses a mobile phone as the key administrator. However, this does not limit the execution of steps S512 to S514 to be performed solely by the first device as the administrator.

[0300] S512. The first device uses the first signature private key to sign the first connection public key, generating first signature information.

[0301] The first device is equipped with an asymmetric key pair including a first signing private key and a first signing public key. The first device receives a first connection public key sent by the second device, and uses the first signing private key to sign the first connection public key, generating first signature information.

[0302] Specifically, the first device performs a hash operation on the first connection public key to obtain a first hash value, and then encrypts the first hash value using the first signature private key to obtain the first signature information.

[0303] In some embodiments, the first device may also use the first signing private key to sign the first connection public key and other information to obtain first signature information. The other information may be device information such as device role information and group identifier information.

[0304] S513, The first device sends the first signature information and the first signature public key to the second device.

[0305] S514. The first device generates a second connection public key and signs the second connection public key using the first signing private key to generate second signature information.

[0306] In this process, the first device generates a second connection public key, and also generates a corresponding second connection private key. The second connection public key and the second connection private key form an asymmetric private key pair.

[0307] Specifically, the first device performs a hash operation on the second connection public key to obtain a second hash value, and then uses the first signature private key to encrypt the second hash value to obtain the second signature information.

[0308] In some embodiments, the second device may also sign the second connection public key and other information, which may include device information such as device role information and group identification information.

[0309] S515, the second device sends the first connection public key and the first signature information to the first device.

[0310] In this step, the first connection public key sent by the second device is the same as the first connection public key sent by the second device in step S511. The first signature information sent by the second device is: the first signature information received by the second device from the first device in step S5113.

[0311] S516. The first device uses the first signature public key to verify whether the first signature information is correct.

[0312] In some embodiments, the first device verifies the first signature information using the first signature public key by: the first device decrypting the first signature information using the first signature public key; if decryption is successful, the verification is successful; if decryption fails, the verification is unsuccessful.

[0313] In other embodiments, the first device verifies the first signature information using the first signature public key as follows: The first device decrypts the first signature information using the first signature public key to obtain a first hash value. The first device performs a hash operation on the first connection public key to obtain a second hash value, and compares the first hash value with the second hash value; if the first hash value and the second hash value are the same, the verification is successful; otherwise, the verification fails.

[0314] In other embodiments, the first device uses the first signature public key to decrypt the first signature information and obtains the first hash value, as well as device information such as the device's role information and group identifier information. The first device then verifies whether the device information such as the device's role information and group identifier information is correct. If the device information such as the device's role information and group identifier information is correct, then the first signature information is verified to be correct.

[0315] If the first device uses the first signature private key to verify that the first signature information is correct, then execute S517. The first device uses the first connection public key and the second connection private key to generate the first connection key or a derivative key of the first connection key.

[0316] It should be noted that the first device generates a first connection key using the first connection public key and the second connection private key, and can generate a derived key based on the first connection key.

[0317] The first device can perform a hash operation on the first connection public key and the second connection private key to obtain the first connection key.

[0318] In some embodiments, the first device intercepts a portion of the first connection key as a derived key of the first connection key.

[0319] In other embodiments, the first device performs one or more hash operations on the first connection key, and all or part of the hash values ​​are used as derived keys of the first connection key.

[0320] In other embodiments, the first device uses the first connection key in combination with one or more plaintext messages or derived messages jointly owned by both devices to perform one or more hash operations to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.

[0321] The plaintext information jointly owned by both devices may include:

[0322] A random number generated by a first or second device; attribute information of the first or second device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.

[0323] The methods for generating derivative information of one or more plaintext messages jointly owned by both devices are as follows: 1. Take a portion of one or more plaintext messages as a derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.

[0324] One or more plaintext messages jointly owned by both devices can be transmitted in the following ways: One device sends one or more plaintext messages to the other. Alternatively, the first and second devices may agree upon this. Or, they may obtain publicly available information relevant to both the first and second devices.

[0325] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.

[0326] S518, The first device sends the second connection public key and the second signature information to the second device.

[0327] It should be noted that step S518 can be executed at any time after the second signature information is obtained in step S514. Figure 5b This demonstrates one possible execution location for step S518, but does not constitute a limitation on the execution location of S518.

[0328] S519. The second device uses the first signature public key to verify whether the second signature information is correct.

[0329] In some embodiments, the second device receives the second connection public key and the second signature information. The second device uses the first signature public key to verify the second signature information. Specifically, the second device uses the first signature public key to decrypt the second signature information. If the decryption is successful, the verification is successful. If the decryption fails, the verification is unsuccessful.

[0330] In other embodiments, the second device verifies the second signature information using the first signature public key as follows: the second device decrypts the second signature information using the first signature public key to obtain a second hash value. The second device performs a hash operation on the second connection public key to obtain a third hash value, and compares the third hash value with the second hash value; if the third hash value is the same as the second hash value, the verification is successful; otherwise, the verification fails.

[0331] In other embodiments, the second device uses the first signature public key to decrypt the second signature information. In addition to obtaining the second hash value, it also obtains device information such as the device's role information and group identifier information. The second device then further verifies whether the device information such as the device's role information and group identifier information is correct. If the device information such as the device's role information and group identifier information is verified to be correct, then the second signature information is verified to be correct.

[0332] The second device uses the first signature private key to verify that the second signature information is correct, and then executes S520. The second device uses the second connection public key and the first connection private key to generate the first connection key or a derivative key of the first connection key.

[0333] In this step, the second device generates the derived key of the first connection key in the same way as in the aforementioned step S517. Please refer to the content of the aforementioned step S517, which will not be repeated here.

[0334] The process from step S511 to step S520 can be understood as the configuration phase in the DPP process.

[0335] S521. The first device and the second device establish a WiFi connection using the first connection key or a derived key of the first connection key.

[0336] Specifically, the first device and the second device use the first connection key or a derived key of the first connection key as a PSK (preshared key), or a Passphrase, or a password, or a PMK (Pairwise Master Key) to establish a connection by executing the IEEE 802.11 protocol: this can be the execution of the 802.11 four-way handshake process.

[0337] In this embodiment, the first device and the second device only exchange public keys and do not exchange private keys, thus enhancing security. Furthermore, the first device uses the first connection private key and the second connection public key to generate a first connection key or a derived key from the first connection key. Since the first connection private key is the first device's private key, different first devices can establish wireless connections with the second device using connection keys or derived keys generated from their own connection private keys, further improving security.

[0338] Step S521 can be understood as the network access step in the DPP process.

[0339] Example 2

[0340] The method for establishing a wireless network connection performed by the first device and the second device can also be another execution process, see [link to relevant documentation]. Figure 8 Another embodiment of this application provides a method for establishing a wireless network connection, which includes the following steps:

[0341] S801, the first device and the second device are discovered through WiFi messages.

[0342] S802, the first device and the second device perform a positioning process to obtain the first spatial location information.

[0343] S803, the second device and the first device perform a positioning process to obtain the second spatial location information.

[0344] For specific implementation details of steps S801 to S803 in this embodiment, please refer to the corresponding... Figure 5b The contents of steps S501 to S503 in the embodiments will not be repeated here.

[0345] Step S801 is also an optional step. In some application scenarios, step S801 can be skipped, and steps S802 and S803 can be executed directly. Furthermore, there is no restriction on the execution order of steps S802 and S803. Figure 9 shows an example of steps S802 and S803 being executed in parallel.

[0346] S804. The first device verifies the second device based on the first spatial location information.

[0347] S805, the second device verifies the first device based on the second spatial location information.

[0348] The second device verifies the first device based on the second spatial location information in the same way as the first device verifies the second device based on the first spatial location information, as described above.

[0349] Since steps S806 to S810 can also achieve verification between the first device and the second device based on spatial location information, steps S804 and S805 are optional steps. When the first device and the second device perform verification using steps S806 to S810, steps S804 and S805 may not be executed.

[0350] S806, The first device sends the first public key to the second device.

[0351] The first device is configured with an asymmetric key pair, which includes a first public key and a first private key. The first public key can be publicly disclosed, while the first private key is not. The asymmetric key pair can be generated by the first device or pre-stored.

[0352] The method by which the first device sends the first public key to the second device is as described in step S506 above, and will not be repeated here.

[0353] S807, The second device sends the second public key to the first device.

[0354] The second device may also generate or pre-store an asymmetric key pair, which includes a second public key and a second private key. The second public key can be published, but the second private key is not disclosed.

[0355] The method by which the second device sends the second public key to the first device can be found in the aforementioned step S507, and will not be repeated here.

[0356] It should be noted that steps S806 and S807 can be understood as the bootstrapping steps in the DPP process.

[0357] Furthermore, the content of steps S802 to S807 can achieve the same technical effect as the aforementioned steps S502 to S507.

[0358] S808. The first device uses the second public key and the first private key to generate a first shared key or a derived key of the first shared key.

[0359] The first device uses the second public key and the first private key to generate a first shared key or a derived key of the first shared key, as described in step S508 above, and will not be repeated here.

[0360] S809. The second device uses the first public key and the second private key to generate a first shared key or a derived key of the first shared key.

[0361] The second device can generate the first shared key or a derived key of the first shared key in the same way as in step S509 above, and will not be repeated here.

[0362] S810, the first device and the second device authenticate each other based on the first shared key or a derived key of the first shared key.

[0363] The authentication method for the first device and the second device based on the first shared key or a derived key of the first shared key can be as described in step S510 above, and will not be repeated here.

[0364] The process from step S808 to step S810 can be understood as the verification step in the DPP process.

[0365] If the first device and the second device successfully authenticate based on the first shared key or a derived key of the first shared key, then execute S811, whereby the first device and the second device establish a WiFi connection using the connection key.

[0366] In one possible implementation, step S811, where the first device and the second device establish a WiFi connection using a connection key, includes:

[0367] S811a, The first device sends a first letter of trust information to the second device. The first letter of trust information includes a first connection key or a derived key of the first connection key. The first connection key or the derived key of the first connection key is used to establish a WiFi connection between the first device and the second device.

[0368] The first connection key can be a password for the network set by the user or a pre-stored password for the network. The first trust information is a data structure that can contain information that allows the device to connect to the wireless connection.

[0369] S811b, the first device, and the second device establish a WiFi connection using the first connection key or a derived key of the first connection key.

[0370] Specifically, the connection is established by using the first connection key or a derived key of the first connection key as the PSK (preshared key), or, Passphrase, or, password, or, PMK (Pairwise Master Key) to execute the IEEE 802.11 protocol: this can be the execution of the 802.11 four-way handshake process.

[0371] In another possible implementation, in step S811, the first device and the second device establish a WiFi connection using a connection key, including:

[0372] S811c, the second device sends a second trust letter to the first device. The second trust letter contains a second connection key or a derived key of the second connection key. The second connection key or the derived key of the second connection key is used to establish a WiFi connection between the first device and the second device.

[0373] The second connection key can be a password set by the user for the network to connect to, or a password for the network to connect to that network that has been pre-stored. The second trust information is also a data structure that can contain information that allows the device to connect to the wireless connection.

[0374] S811d, the second device, and the first device establish a WiFi connection using the second connection key or a derived key of the second connection key.

[0375] Specifically, the connection is established by using the second connection key or a derived key of the second connection key as the PSK (preshared key), or, Passphrase, or, password, or PMK (Pairwise Master Key) to execute the IEEE 802.11 protocol: this can be the execution of the 802.11 four-way handshake process.

[0376] Step S811 can be understood as the network access step in the DPP process.

[0377] Example 3

[0378] The variety of devices capable of establishing wireless network connections is increasing, such as portable devices like mobile phones, which can easily be brought close together to establish a wireless network connection. However, large electronic devices are not easily moved and cannot use the wireless network connection establishment method provided in the aforementioned embodiments to establish a wireless network connection between two devices.

[0379] In one application scenario, see Figure 9aIf the printer and router are far apart, the wireless network connection establishment process provided in the aforementioned embodiments may fail due to the inability to locate each other's devices. Therefore, this application provides another wireless network connection establishment scheme in which the router and printer use a portable device, such as a mobile phone, to establish the wireless network connection.

[0380] In the wireless network connection establishment scheme provided in this embodiment, the user can first... Figure 9b As shown, location and location verification are performed using a mobile phone and router, and then... Figure 9c The system will locate and verify the location of the mobile phone and printer. If the location verification of both the mobile phone and router is successful, and the location verification of both the mobile phone and printer is also successful, the printer can establish a wireless network connection with the router.

[0381] In this application scenario, the mobile phone, printer, and router all need to have UWB functionality. The hardware structure of the mobile phone, printer, and other electronic devices used as the site can be as follows: Figure 2 As shown; the hardware structure of devices such as routers that serve as access points can also be as shown. Figure 3 As shown.

[0382] The following describes the method for establishing a wireless network connection using three devices: a mobile phone, a printer, and a router.

[0383] The second device establishes a wireless connection with the third device through the first device. Alternatively, this can be implemented in another way; see [link to relevant documentation]. Figure 10 Another embodiment of this application provides a method for accessing a wireless network, comprising the following steps:

[0384] S1001, the first device and the second device complete the discovery through WiFi messages.

[0385] S1002, The first device locates the second device and obtains the first spatial location information.

[0386] S1003, The second device locates the first device and obtains the second spatial location information.

[0387] For specific implementation methods of steps S1001 to S1003 in this embodiment, please refer to the corresponding... Figure 5b The contents of steps S501 to S503 in the embodiments will not be repeated here.

[0388] Step S1001 is an optional step. In some application scenarios, step S1001 can be skipped, and steps S1002 and S1003 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1002 and S1003. Figure 10An example is shown where steps S1002 and S1003 are performed in parallel.

[0389] S1004. The first device verifies the second device based on the first spatial location information.

[0390] S1005. The second device verifies the first device based on the second spatial location information.

[0391] For specific implementation details of steps S1004 and S1004 in this embodiment, please refer to the corresponding... Figure 5b The specific implementation details are not repeated here.

[0392] Since steps S1006 to S1010 can also achieve verification between the first device and the second device based on spatial location information, steps S1004 and S1005 are optional steps. When the first device and the second device perform verification using steps S1006 to S1010, steps S1004 and S1005 may not be executed.

[0393] S1006. The first device successfully verifies the second device, and the first device sends the first public key to the second device.

[0394] The first device is configured with an asymmetric key pair, which includes a first public key and a first private key. The first public key can be publicly disclosed, while the first private key is not. The asymmetric key pair can be generated by the first device or pre-stored.

[0395] In some embodiments, the first device sends a first public key to the second device via a UWB channel.

[0396] The method by which the first device sends the first public key to the second device is as described in step S506 above, and will not be repeated here.

[0397] S1007. The second device successfully verifies the first device and sends the second public key to the first device.

[0398] The second device may also generate or pre-store an asymmetric key pair, which includes a second public key and a second private key. The second public key can be published, but the second private key is not disclosed.

[0399] In some embodiments, the second device sends a second public key to the first device via a UWB channel.

[0400] In other embodiments, the second device sends a second public key to the first device via a WiFi channel.

[0401] The method by which the second device sends the second public key to the first device can be found in step S507 above, and will not be repeated here.

[0402] S1008. The first device uses the second public key and the first private key to generate a first shared key or a derived key of the first shared key.

[0403] The method by which the first device generates a derived key of the first shared key or a derived key of the first shared key can be as described in step S508, and will not be repeated here.

[0404] S1009. The second device uses the first public key and the second private key to generate a first shared key or a derived key of the first shared key.

[0405] The method by which the second device generates a derived key of the first shared key or a derived key of the first shared key can be as described in step S509 above, and will not be repeated here.

[0406] Furthermore, if the first device receives the second public key correctly and the second device receives the first public key correctly, the first shared key generated by the second device and the first shared key generated by the first device are the same.

[0407] S1010, the first device and the second device authenticate each other based on the first shared key or a derived key of the first shared key.

[0408] The authentication method between the first device and the second device based on the first shared key or a derived key of the first shared key can be as described in step S510 above, and will not be repeated here.

[0409] If the first device and the second device successfully authenticate based on the first shared key or a derived key of the first shared key, then step S1011 is executed: the second device sends the first connection public key to the first device.

[0410] The second device generates an asymmetric key pair, including a first connection public key and a first connection private key.

[0411] S1012. The first device uses the first signature private key to sign the first connection public key, generating first signature information.

[0412] The first device is equipped with an asymmetric key pair including a first signing private key and a first signing public key. The first device receives a first connection public key sent by the second device, and the second device uses the first signing private key to sign the first connection public key to generate first signature information.

[0413] In some embodiments, the first device may also use the first signing private key to sign the first connection public key and other information to obtain first signature information. The other information may be device information such as device role information and group identifier information.

[0414] S1013, The first device sends the first signature information and the first signature public key to the second device.

[0415] S1014, The first and third devices complete the discovery via WiFi messages.

[0416] The discovery process between the first and third devices via WiFi messages can be implemented as follows: Figure 5b The details of step S501 in the embodiments will not be repeated here.

[0417] In some embodiments, the third device may also be equipped with a WPS button. When the third device is powered on, the first device and the third device can discover each other via WiFi messages.

[0418] The first and third devices can also perform the discovery process via UWB, and the specific process can be described as follows: Figure 5b The details of step S501 in the embodiments will not be repeated here.

[0419] S1015. The first device locates the third device and obtains the third spatial location information.

[0420] S1016. The third device locates the first device and obtains the fourth spatial location information.

[0421] For specific implementation details of steps S1015 to S1016 in this embodiment, please refer to the corresponding... Figure 5b The contents of steps S502 to S503 in the embodiments will not be repeated here.

[0422] Step S1014 is also an optional step. In some application scenarios, step S1014 can be skipped, and steps S1015 and S1016 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1015 and S1016. Figure 10 An example is shown where steps S1015 and S1016 are performed in parallel.

[0423] S1017. The first device verifies the third device based on the third spatial location information.

[0424] S1018. The third device verifies the first device based on the fourth spatial location information.

[0425] For specific implementation methods of steps S1017 and S1018 in this embodiment, please refer to the corresponding... Figure 5b The details of the embodiments are not repeated here.

[0426] Since steps S1019 to S1023 can also achieve verification between the first device and the third device based on spatial location information, steps S1017 and S1018 are optional steps. When the first device and the third device perform verification using steps S1019 to S1023, steps S1017 and S1018 may not be executed.

[0427] S1019. The first device successfully verifies the third device, and the first device sends the third public key to the third device.

[0428] The first device is configured with an asymmetric key pair, which includes a third public key and a third private key. The third public key can be publicly disclosed, while the third private key is not. The asymmetric key pair can be generated by the first device or pre-stored.

[0429] The third public key and the third private key can be the same as the first public key and the first private key in step S1006.

[0430] In some embodiments, the first device sends a third public key via a UWB channel, and the third device receives the third public key via a UWB channel. Since the first and third devices use UWB functionality to locate each other's devices, and the location verification is successful, it indicates that the communication between the first and third devices via the UWB channel is trustworthy. Based on this, the first device sends the third public key via the UWB channel.

[0431] In some embodiments, the first device sends the third public key via a UWB channel, or the third public key can be transmitted encrypted over the UWB channel. Specifically, the first device encrypts the third public key to obtain an encrypted third public key, and then sends the encrypted third public key to the third device via the UWB channel.

[0432] The first device does not restrict the encryption method used for the third public key; it can employ various common encryption algorithms, which will not be elaborated here. Furthermore, the first and third devices must agree on the encryption method for the third public key beforehand.

[0433] S1020: The third device successfully verifies the first device's identity and sends the fourth public key to the first device.

[0434] The third device can also generate or pre-store an asymmetric key pair, which includes a fourth public key and a fourth private key. The first public key can be published, but the first private key is not disclosed.

[0435] In some embodiments, the third device sends a fourth public key to the first device via a UWB channel.

[0436] In other embodiments, the third device sends a fourth public key to the first device via a WiFi channel.

[0437] The method by which the third device sends the fourth public key to the first device can be found in step S1019 above, and will not be repeated here.

[0438] When the third device sends the fourth public key via a WiFi channel, the first device sends a UWB message via a UWB channel. This message carries information such as the first device's WiFi channel and MAC address. Upon receiving the UWB message, the third device can determine the first device's WiFi channel based on the information carried in the message. Thus, the third device can send the fourth public key to the first device via the WiFi channel.

[0439] S1021. The first device uses the fourth public key and the third private key to generate a second shared key or a derivative key of the second shared key.

[0440] In some embodiments, after the first device generates a second shared key using a third private key and a fourth public key, it may extract a portion of the second shared key as a derived key of the second shared key.

[0441] In other embodiments, the first device may also perform a hash operation on the second shared key, and the entire or part of the hash result may be used as a derived key of the second shared key.

[0442] In other embodiments, the first device may also use the second shared key in conjunction with one or more plaintext messages or derived information of plaintext messages jointly owned by both devices to perform a hash operation to obtain a derived key of the second shared key. Furthermore, a portion of the second shared key may be extracted as the derived key to be used.

[0443] The plaintext information jointly owned by both devices may include:

[0444] A random number generated by a first or third device; attribute information of the first or third device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.

[0445] The methods for generating derivative information of one or more plaintext messages jointly owned by both devices are as follows: 1. Take a portion of one or more plaintext messages as a derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.

[0446] One or more plaintext messages jointly owned by both devices can be transmitted by one of them to the other: (1) The first device and the third device send one or more plaintext messages to the other. (2) The first device and the third device agree upon the same method. (3) The first device and the third device obtain publicly available information.

[0447] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.

[0448] S1022. The third device uses the third public key and the fourth private key to generate a second shared key or a derivative key of the second shared key.

[0449] The method by which the third device generates the derivative key of the second shared key is the same as the method by which the first device generates the derivative key of the first shared key in step S1021, and will not be repeated here.

[0450] Furthermore, if the first device receives the fourth public key correctly and the third device receives the third public key correctly, the second shared key generated by the third device and the second shared key generated by the first device are the same.

[0451] S1023. The first device and the third device authenticate based on the second shared key or a derived key of the second shared key.

[0452] In one possible implementation, step S1023, the authentication method between the first device and the third device based on the second shared key or a derived key of the second shared key, includes:

[0453] 1) The first device generates a first verification value based on the second shared key or a derived key of the second shared key, and sends the first verification value to the third device.

[0454] 2) After receiving the first verification value sent by the first device, the third device verifies the first verification value.

[0455] 3) The third device generates a second verification value based on the second shared key or a derived key of the second shared key, and sends the second verification value to the first device.

[0456] The third device can generate a second verification value based on the second shared key or a derived key of the second shared key after verifying that the first verification value is correct.

[0457] 4) After receiving the second verification value sent by the third device, the first device verifies the second verification value.

[0458] In this embodiment, the first device performs one or more hash operations on the second shared key or a derived key of the second shared key, and uses all or part of the hash result as the first verification value. Similarly, the third device performs one or more hash operations on the second shared key or a derived key of the second shared key, and uses all or part of the hash result as the second verification value.

[0459] It should be noted that if the second shared key or a derived key of the second shared key generated by the first device and the third device are the same, and the first device and the third device use the same verification value generation method, the generated first verification value and second verification value are the same.

[0460] In this embodiment, since the first device and the third device generate the verification value using the same generation method, the method for verifying the other device's generation is also the same. The following description uses the method of the first device verifying the second verification value as an example:

[0461] In some embodiments, the first device verifies the second verification value by: decrypting the second verification value to obtain a decrypted value, and then verifying whether the decrypted value is correct.

[0462] In other embodiments, the first device verifies the second verification value by generating a third verification value and comparing it with the second verification value. If the first device determines that the third verification value and the second verification value are the same, then the second verification value is verified as correct.

[0463] In other embodiments, the first device verifies the second verification value by comparing whether the first verification value and the second verification value are the same. If the first device determines that the first verification value and the second verification value are the same, then the second verification value is verified as correct.

[0464] In another possible implementation, step S1023, the authentication method between the first device and the third device based on the second shared key or a derived key of the second shared key, includes:

[0465] 1) The first device generates a first verification value based on the second shared key or a derived key of the second shared key and the first spatial location information, and sends the first verification value to the first device.

[0466] 2) After receiving the first verification value sent by the first device, the third device verifies the first verification value.

[0467] 3) The third device generates a second verification value based on the second shared key or a derived key of the second shared key and the second spatial location information, and sends the second verification value to the first device.

[0468] The third device may also generate a second verification value based on the second shared key or a derived key of the second shared key, and the second spatial location information, after verifying that the first verification value is correct.

[0469] 4) After receiving the second verification value sent by the third device, the first device verifies the second verification value.

[0470] After the first device and the third device successfully authenticate based on the second shared key or a derived key of the second shared key, step S1024 is executed, in which the third device sends the first connection public key to the first device.

[0471] The first device generates an asymmetric key pair, including a first connection public key and a first connection private key.

[0472] S1025. The first device uses the first signing private key to sign the second connection public key, generating second signature information.

[0473] Equivalent to step S1012, the first device can also use the first signing private key to sign the second connection public key and other information to obtain the second signature information. The other information can be device information such as device role information and group identifier information.

[0474] S1026. The first device sends the second signature information and the first signature public key to the third device.

[0475] In this embodiment, the first device acts as the key manager. Therefore, both the second and third devices send their connection public keys to the first device. The first device then generates first and second signature information and sends them to the second and third devices. The second and third devices can verify the legitimacy of each other's devices based on the first and second signature information.

[0476] It should also be noted that there is no limitation on the order in which steps S1001 to 1013, and steps S1014 to 1026, are performed by the first and second devices. Figure 10 An example is shown in which the first device and the second device first execute steps S1001 to 1013, and then the first device and the third device execute steps S1014 to 1026.

[0477] S1027. The second device sends the first connection public key and the first signature information to the third device.

[0478] S1028. The third device uses the first signature public key to verify whether the first signature information is correct.

[0479] In some embodiments, the third device verifies the first signature information using the first signature public key by: the third device decrypting the first signature information using the first signature public key; if decryption is successful, the verification is successful; if decryption fails, the verification is unsuccessful.

[0480] In other embodiments, the third device verifies the first signature information using the first signature public key as follows: the third device decrypts the first signature information using the first signature public key to obtain a first hash value. The third device performs a hash operation on the first connection public key to obtain a second hash value, and compares the first hash value with the second hash value; if the first hash value and the second hash value are the same, the verification is successful; otherwise, the verification fails.

[0481] In other embodiments, the third device uses the first signature public key to decrypt the first signature information and obtains not only the first hash value, but also device information such as the device's role information and group identifier information. The third device then verifies whether the device's role information and group identifier information are correct. If the device's role information and group identifier information are all correct, then the first signature information is verified to be correct.

[0482] If the third device verifies that the first signature information is correct, then step S1029 is executed: the third device uses the first connection public key and the second connection private key to generate the first connection key or a derived key of the first connection key.

[0483] The third device verifies that the first signature information is correct, and then uses the first connection public key and its own second connection private key to generate the first connection key or a derived key of the first connection key.

[0484] In some embodiments, the third device intercepts a portion of the first connection key as a derived key of the first connection key.

[0485] In other embodiments, the third device performs a hash operation on the first connection key, and the entire or partial value of the hash operation is used as a derived key of the first connection key.

[0486] In other embodiments, the third device uses the first connection key in combination with one or more plaintext messages or derived messages shared by both devices to perform one or more hash operations to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.

[0487] The plaintext information jointly owned by both devices may include:

[0488] A random number generated by a second or third device; attribute information of the second or third device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.

[0489] The methods for generating derivative information of one or more plaintext messages jointly owned by both devices are as follows: 1. Take a portion of one or more plaintext messages as a derivative key; 2. Perform one or more hash operations on one or more plaintext messages, and use all or part of the hash result as the derivative information.

[0490] One or more plaintext messages jointly owned by both devices can be transmitted in the following ways: One of the second or third devices sends one or more plaintext messages to the other. Alternatively, the second and third devices may agree upon this. Or, they may obtain publicly available information for both the second and third devices.

[0491] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.

[0492] S1030, the third device sends the second connection public key and the second signature information to the second device.

[0493] S1031. The second device uses the first signature public key to verify whether the second signature information is correct.

[0494] The method by which the second device verifies the correctness of the second signature information using the first signature public key can be as described in step S519 above, and will not be repeated here.

[0495] If the second device verifies that the second signature information is correct, then execute S1032, whereby the second device uses the second connection public key and the first connection private key to generate the first connection key or a derivative key of the first connection key.

[0496] The second device verifies that the second signature information is correct, and then uses the second connection public key and its own first connection private key to generate a first connection key or a derivative key of the first connection key.

[0497] In some embodiments, the second device intercepts a portion of the first connection key as a derived key of the first connection key.

[0498] In other embodiments, the second device performs a hash operation on the first connection key, and the entire or partial value after the hash operation is used as a derived key of the first connection key.

[0499] In other embodiments, the second device uses the first connection key in combination with one or more plaintext messages or derived messages shared by both devices to perform a hash operation to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.

[0500] The plaintext information jointly owned by both devices may include:

[0501] A random number generated by a second or third device; attribute information of the second or third device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.

[0502] The methods for generating derivative information of one or more plaintext messages jointly owned by both devices are as follows: 1. Take a portion of one or more plaintext messages as a derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.

[0503] One or more plaintext messages jointly owned by both devices can be transmitted in the following ways: One of the second or third devices sends one or more plaintext messages to the other. Alternatively, the second and third devices may agree upon this. Or, they may obtain publicly available information for both the second and third devices.

[0504] The hash operations mentioned above can all use algorithms such as SHA-256 and SHA-128.

[0505] S1033. The second device and the third device establish a WiFi connection using the first connection key or a derived key of the first connection key.

[0506] The second and third devices can use the first connection key or a derived key of the first connection key as a PSK (preshared key), or a Passphrase, or a password, or a PMK (Pairwise Master Key) to establish a connection by executing the IEEE 802.11 protocol: this can be the execution of the 802.11 four-way handshake process.

[0507] In this embodiment, the third device and the second device can establish a WiFi connection using the first connection key. This facilitates the establishment of a wireless network connection between the second and third devices.

[0508] Example 4

[0509] See Figure 11 This application provides a method for establishing a wireless network connection, including:

[0510] S1101, the first device and the second device complete the discovery through WiFi messages.

[0511] S1102, The first device locates the second device and obtains the first spatial location information.

[0512] S1103, The second device locates the first device and obtains the second spatial location information.

[0513] For specific implementation details of steps S1101 to S1103 in this embodiment, please refer to the corresponding... Figure 5b The contents of steps S501 to S503 in the embodiments will not be repeated here.

[0514] Step S1101 is an optional step. In some application scenarios, step S1101 can be skipped, and steps S1102 and S1103 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1102 and S1103. Figure 11 An example is shown where steps S1102 and S1103 are performed in parallel.

[0515] S1104. The first device verifies the second device based on the first spatial location information.

[0516] S1105. The second device verifies the first device based on the second spatial location information.

[0517] For specific implementation details of steps S1104 and S1105 in this embodiment, please refer to the corresponding... Figure 5b The details of the embodiments are not repeated here.

[0518] S1106. The first device sends the first public key to the second device.

[0519] The first device is configured with an asymmetric key pair, which includes a first public key and a first private key. The first public key can be publicly disclosed, while the first private key is not. The asymmetric key pair can be generated by the first device or pre-stored.

[0520] In some embodiments, the first device sends the first public key to the first device via a UWB channel.

[0521] In other embodiments, the first device sends the first public key to the first device via a WiFi channel.

[0522] The method by which the first device sends the first public key to the second device is as described in step S506 above, and will not be repeated here.

[0523] S1107. The second device sends the second public key to the first device.

[0524] The second device may also generate or pre-store an asymmetric key pair, which includes a second public key and a second private key. The second public key can be published, but the second private key is not disclosed.

[0525] In some embodiments, the second device sends a second public key to the first device via a UWB channel.

[0526] In other embodiments, the second device sends a second public key to the first device via a WiFi channel.

[0527] The method by which the second device sends the second public key to the first device can be found in step S507 above, and will not be repeated here.

[0528] S1108. The first device uses the second public key and the first private key to generate a first shared key or a derived key of the first shared key.

[0529] The method by which the first device generates a derived key of the first shared key or a derived key of the first shared key can be as described in step S508, and will not be repeated here.

[0530] S1109. The second device uses the first public key and the second private key to generate a first shared key or a derived key of the first shared key.

[0531] The method by which the second device generates a derived key of the first shared key or a derived key of the first shared key can be as described in step S509 above, and will not be repeated here.

[0532] Furthermore, if the first device receives the second public key correctly and the second device receives the first public key correctly, the first shared key generated by the second device and the first shared key generated by the first device are the same.

[0533] S1110, the first device and the second device authenticate each other based on the first shared key or a derived key of the first shared key.

[0534] The authentication method between the first device and the second device based on the first shared key or a derived key of the first shared key can be as described in step S510 above, and will not be repeated here.

[0535] The first device and the second device successfully authenticated each other based on the first shared key or a derived key of the first shared key.

[0536] S1111, the first device sends a first letter of trust information to the second device, the first letter of trust information containing a first connection key.

[0537] It should also be noted that the first letter of trust information may also include a derived key of the first connection key.

[0538] In some embodiments, the second device intercepts a portion of the first connection key as a derived key of the first connection key.

[0539] In other embodiments, the second device performs one or more hash operations on the first connection key, and all or part of the hash values ​​are used as derived keys of the first connection key.

[0540] In other embodiments, the second device uses the first connection key in combination with one or more plaintext messages or derived messages shared by both devices to perform one or more hash operations to obtain a derived key of the first connection key. Furthermore, a portion of the first connection key can be extracted as the derived key to be used.

[0541] The plaintext information jointly owned by both devices may include:

[0542] A random number generated by a first or second device; attribute information of the first or second device, which may include one or more of the following: device description information, device capability information, device status, device address, protocol name used in the application, protocol version, and public key information; a key that can be filled with multiple numbers, which are generally 0 or 1; time; and other fixed plaintext information.

[0543] The methods for generating derivative information of one or more plaintext messages jointly owned by both devices are as follows: 1. Take a portion of one or more plaintext messages as a derivative key; 2. Perform a hash operation on one or more plaintext messages, and use all or part of the hash result as the derivative information.

[0544] One or more plaintext messages jointly owned by both devices can be transmitted in the following ways: One device sends one or more plaintext messages to the other. Alternatively, the first and second devices may agree upon this. Or, they may obtain publicly available information relevant to both the first and second devices.

[0545] The hash operations mentioned above can all be performed using algorithms such as SHA-256 and SHA-118.

[0546] S1112, The first and third devices complete the discovery via WiFi messages.

[0547] S1113. The first device locates the third device and obtains the third spatial location information.

[0548] S1114. The third device locates the first device and obtains the fourth spatial location information.

[0549] For specific implementation details of steps S1112 to S1114 in this embodiment, please refer to the corresponding... Figure 5b The contents of steps S501 to S503 in the embodiments will not be repeated here.

[0550] Step S1112 is also an optional step. In some application scenarios, step S1112 can be skipped, and steps S1113 and S1114 can be executed directly. Furthermore, there is no restriction on the execution order of steps S1113 and S1114. Figure 11 An example is shown where steps S1113 and S1114 are performed in parallel.

[0551] S1115. The first device verifies the third device based on the third spatial location information.

[0552] S1116. The third device verifies the first device based on the fourth spatial location information.

[0553] For specific implementation details of steps S1115 and S1116 in this embodiment, please refer to the corresponding... Figure 5b The details of the embodiments are not repeated here.

[0554] S1117. The first device sends the third public key to the third device.

[0555] The first device is configured with an asymmetric key pair, which includes a third public key and a third private key. The third public key can be publicly disclosed, while the third private key is not. The asymmetric key pair can be generated by the first device or pre-stored.

[0556] The third public key and the third private key can be the same as the first public key and the first private key in step S1106.

[0557] In some embodiments, the first device sends a third public key to the third device via a UWB channel.

[0558] The method by which the first device sends the third public key can be found in step S1019 above, and will not be repeated here.

[0559] S1118, The third device sends the fourth public key to the first device.

[0560] The third device can also generate or pre-store an asymmetric key pair, which includes a fourth public key and a fourth private key. The first public key can be published, but the first private key is not disclosed.

[0561] In some embodiments, the third device sends a fourth public key to the first device via a UWB channel.

[0562] In other embodiments, the third device sends a fourth public key to the first device via a WiFi channel.

[0563] The method by which the third device sends the fourth public key to the first device can be found in the aforementioned step S1020, and will not be repeated here.

[0564] S1119. The first device uses the fourth public key and the third private key to generate a second shared key or a derivative key of the second shared key.

[0565] The method by which the first device generates the second shared key or a derived key of the second shared key is as described in step S1021 above, and will not be repeated here.

[0566] S1120, the third device uses the third public key and the fourth private key to generate a second shared key or a derivative key of the second shared key.

[0567] The method by which the third device generates the derived key of the second shared key is as described in step S1022, and will not be repeated here.

[0568] Furthermore, if the first device receives the fourth public key correctly and the third device receives the third public key correctly, the second shared key generated by the third device and the second shared key generated by the first device are the same.

[0569] S1121. The first device and the third device authenticate each other based on the second shared key or a derived key of the second shared key.

[0570] The authentication method between the first device and the third device based on the second shared key or a derived key of the second shared key can be as described in step S1023 above, and will not be repeated here.

[0571] After the first device and the third device successfully authenticate based on the second shared key or a derived key of the second shared key, step S1122 is executed: the first device sends a second letter of trust information to the third device, the second letter of trust information containing the first connection key.

[0572] The second trust certificate information sent by the first device to the third device may also include a derived key of the first connection key. The method for generating the derived key is described in the aforementioned step S1111, and will not be repeated here.

[0573] It should also be noted that there is no limitation on the order in which steps S1101 to 1111 are performed by the first and second devices, and steps S1112 to 1122 are performed by the first and third devices. Figure 11 An example is shown whereby the first and second devices first execute steps S1101 to 1111, and then the first and third devices execute steps S1112 to 1122.

[0574] S1123, The second device and the third device establish a WiFi connection using the first connection key.

[0575] Using the first connection key as the PSK (preshared key), or, Passphrase, or, password, or PMK (Pairwise Master Key), the IEEE 802.11 protocol is executed to establish a connection: this can be the execution of the 802.11 four-way handshake process.

[0576] When the letter of trust information sent by the first device to the second and third devices includes a derived key of the first connection key, the second and third devices can establish a WiFi connection using the derived key of the first connection key.

[0577] The specific implementation of step S1123 can be found in step S519 of the aforementioned embodiment, and will not be repeated here.

[0578] In this embodiment, the first device sends a first connection key to both the second and third devices. The third device and the second device can establish a WiFi connection using the first connection key. This facilitates the establishment of a wireless network connection between the second and third devices.

[0579] Another embodiment of this application provides a computer-readable storage medium storing instructions that, when executed on a computer or processor, cause the computer or processor to perform one or more steps of any of the above methods.

[0580] Another embodiment of this application provides a computer program product containing instructions. When the computer program product is run on a computer or processor, it causes the computer or processor to perform one or more steps of any of the methods described above.

Claims

1. A method of establishing a wireless connection, characterized by The application is applied to a first device, and the method for establishing a wireless connection comprises: The first device locates a second device to obtain first spatial position information; The first device sends a first public key to the second device through an ultra-wideband (UWB) channel, the first public key being used to generate a first shared key or a derivative key of the first shared key, and the UWB channel being verified by the first device as being trustworthy by using the first spatial position information; The first device and the second device are authenticated based on the first shared key or the derivative key of the first shared key; The first device establishes a wireless connection with the second device or a third device by using a connection key, the third device being authenticated with the second device based on a second shared key or a derivative key of the second shared key, the second shared key or the derivative key of the second shared key being generated based on a public key of the third device.

2. The method of establishing a wireless connection according to claim 1, characterized in that, After the first device locates the second device to obtain the first spatial position information, the method further comprises: The first device verifies the second device based on the first spatial position information; The first device determines that the UWB channel is trustworthy if the second device passes the verification.

3. The method of establishing a wireless connection according to claim 2, characterized in that, The first device verifies the second device based on the first spatial position information, and the method comprises: The first device determines whether a difference between the first spatial position information and second spatial position information obtained by the second device from locating the first device is within a preset range; The first device determines that the second device passes the verification if the first device determines that the difference between the first spatial position information and the second spatial position information is within the preset range.

4. The method of establishing a wireless connection according to claim 2, characterized by, The first device verifies the second device based on the first spatial position information, and the method comprises: The first device verifies the second device based on the first spatial position information in response to an operation instruction.

5. The method of establishing a wireless connection according to claim 2, wherein, The first device verifies the second device based on the first spatial position information, and the method comprises: The first device determines whether the second device is within a preset range of the first device by using the first spatial position information; The first device determines that the second device passes the verification if the first device determines that the second device is within the preset range of the first device.

6. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized in that, The first device and the second device are authenticated based on the first shared key or the derivative key of the first shared key, and the method comprises: The first device generates a first verification value based on the first shared key or the derivative key of the first shared key, and sends the first verification value to the second device; The first device receives a second verification value sent by the second device, and verifies the second verification value, the second verification value being generated by the second device based on the first shared key or the derivative key of the first shared key when the first verification value is verified as being correct.

7. The method of establishing a wireless connection according to claim 6, characterized by, The first device verifies the second verification value, and the method comprises: Whether the first device successfully decrypts the second verification value; Or, the first device generates a third verification value, and compares the third verification value with the second verification value; Or, the first device compares the first verification value with the second verification value.

8. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized in that, The manner in which the first device and the second device are authenticated based on the first shared key or a derived key of the first shared key comprises: The first device generates a first verification value based on the first spatial location information and the first shared key or a derived key of the first shared key, and sends the first verification value to the second device; The first device receives a second verification value sent by the second device, and verifies the second verification value, wherein the second verification value is generated by the second device based on second spatial location information and the first shared key or a derived key of the first shared key when the first verification value is verified to be correct, and the second spatial location information is obtained by the second device positioning the first device.

9. The method of establishing a wireless connection according to claim 8, characterized by, The first device generates a first verification value based on the first spatial location information and the first shared key or a derived key of the first shared key, comprising: The first device performs hash operation on the first spatial location information or a derived value of the first spatial location information, and the first shared key or a derived key of the first shared key, to obtain a hash operation result, and all or part of the values of the hash operation result are used as the first verification value; The derived value of the first spatial location information comprises: part of the data of the first spatial location information, or all or part of the values obtained by performing hash operation on the first spatial location information, or all or part of the values obtained by performing hash operation on the first spatial location information and one or more plaintext information or derived information of the plaintext information.

10. The method of establishing a wireless connection according to claim 8, wherein, The first device verifies the second verification value, comprising: Whether the first device successfully decrypts the second verification value; Or, the first device generates a third verification value, and compares the third verification value with the second verification value; Or, the first device compares the first verification value with the second verification value. Or, the first device decrypts the second verification value to obtain second spatial location information. The first device judges whether the difference between the first spatial location information and the second spatial location information is within a predetermined range.

11. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized by, Before the first device positions the second device to obtain the first spatial location information, the method further comprises: The first device discovers the second device through a WiFi message or a UWB message.

12. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized by, Before the first device establishes a wireless connection with the second device by using the connection key, the method further comprises: The first device receives first signature information sent by the second device; The first device verifies that the first signature information is correct.

13. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized by, Before the first device establishes a wireless connection with the third device by using the connection key, the method further comprises: The first device receives first signature information sent by the second device; The first device verifies that the first signature information is correct.

14. The method of establishing a wireless connection according to claim 12 or 13, characterized by, The first device verifies that the first signature information is correct, including: The first device successfully decrypts the first signature information by using the first signature public key of the first device; Or, the first device decrypts the first signature information by using the first signature public key of the first device to obtain the first hash value carried by the first signature information; The first device performs hash operation on the first connection public key of the second device to obtain a second hash value; The first device judges that the first hash value is the same as the second hash value; Or, the first device decrypts the first signature information by using the first signature public key of the first device to obtain the device information carried by the first signature information; The first device verifies that the device information is correct.

15. The method of establishing a wireless connection according to claim 13, wherein, The first device verifies that the first signature information is correct, including: The first device successfully decrypts the first signature information by using the first signature public key of the first device; Or, the first device decrypts the first signature information by using the first signature public key of the first device to obtain the first hash value carried by the first signature information; The first device performs hash operation on the first connection public key of the second device to obtain a second hash value; The first device judges that the first hash value is the same as the second hash value; Or, the first device decrypts the first signature information by using the first signature public key of the first device to obtain the device information carried by the first signature information; The first device verifies that the device information is correct.

16. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized by, Before the first device establishes a wireless connection with the second device by using the connection key, the first device further includes: The first device generates or receives the connection key sent by the second device; wherein the connection key includes: a first connection key or a derivative key of the first connection key.

17. The method of establishing a wireless connection according to claim 16, characterized by, The first device generates the connection key, including: The first device generates the first connection key or the derivative key of the first connection key by using the first connection public key and the second connection private key, and the second connection private key is the private key of the first device.

18. The method of establishing a wireless connection according to claim 17, characterized by, The first device generates the derivative key of the first connection key by using the first connection public key and the second connection private key, including: The first device generates the first connection key by using the first connection public key and the second connection private key; The first device intercepts a part of the first connection key as the derivative key of the first connection key; Or, the first device generates the first connection key by using the first connection public key and the second connection private key; The first device performs hash operation on the first connection key to obtain an operation result, and all or part of the values of the operation result are used as the derivative key of the first connection key; Or, the first device generates the first connection key by using the first connection public key and the second connection private key; The first device performs hash operation on the first connection key and one or more plaintext information or derivative information of the plaintext information to obtain the derivative key of the first connection key.

19. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized by, Before authentication passes based on the first shared key or the derivative key of the first shared key, the first device and the second device further comprise: The first device receives a second public key sent by the second device through the UWB channel or the WiFi channel; The first device generates the first shared key or the derivative key of the first shared key by using the second public key and a first private key, the first private key being a private key of the first device.

20. The method of establishing a wireless connection according to any one of claims 1 to 5, characterized by, The first device positions the second device to obtain first spatial position information, comprising: The first device positions the second device by using an ultra-wideband (UWB) positioning method, an ultrasonic positioning method, a Bluetooth positioning method, a cellular positioning method, a geomagnetic positioning method, an infrared positioning method, a radio frequency tag positioning method, a Zigbee positioning method, an ultra-wideband radio positioning method, a broadcast signal positioning method, or a light positioning method to obtain the first spatial position information.

21. A method of establishing a wireless connection, characterized by The method for establishing a wireless connection is applied to a first device, and comprises: The first device positions the second device to obtain first spatial position information; The first device sends a first public key to the second device through an ultra-wideband (UWB) channel, the first public key being used to generate a first shared key or a derivative key of the first shared key, and the UWB channel being verified by the first device by using the first spatial position information to determine whether it is trustworthy; The first device and the second device pass authentication based on the first shared key or the derivative key of the first shared key; The first device positions the third device to obtain third spatial position information; The first device sends a third public key to the third device through the UWB channel, the third public key being used to generate a second shared key or a derivative key of the second shared key, and the UWB channel being verified by the first device by using the third spatial position information to determine whether it is trustworthy; The first device and the third device pass authentication based on the second shared key or the derivative key of the second shared key; If the first device and the second device pass authentication based on the first shared key or the derivative key of the first shared key, and the first device and the third device pass authentication based on the second shared key or the derivative key of the second shared key, the second device establishes a wireless connection with the third device by using a connection key.

22. The method of establishing a wireless connection according to claim 21, wherein, After the first device positions the second device to obtain first spatial position information, the first device further comprises: The first device verifies the second device based on the first spatial position information; If the first device determines that the second device passes the verification, the first device determines that the UWB channel is trustworthy.

23. The method of establishing a wireless connection according to claim 22, characterized by, The first device verifies the second device based on the first spatial position information, comprising: The first device verifies the second device based on the first spatial position information in response to an operation instruction. Or, the first device determines whether the second device is within a preset range of the first device by using the first spatial position information; and the first device determines that the second device passes the verification when the first device determines that the second device is within the preset range of the first device. Or, the first device determines whether a difference between the first spatial position information and second spatial position information is within a preset range; the second spatial position information is obtained by the second device positioning the first device; and the first device determines that the second device passes the verification when the first device determines that the difference between the first spatial position information and the second spatial position information is within the preset range.

24. The method of establishing a wireless connection according to any one of claims 21 to 23, characterized by, After the first device positions the third device to obtain third spatial position information, the method further includes: The first device verifies the third device based on the third spatial position information. When the first device determines that the third device passes the verification, the first device determines that the UWB channel is reliable.

25. The method of establishing a wireless connection according to claim 24, characterized by, The first device verifies the third device based on the third spatial position information, including: The first device verifies the third device based on the third spatial position information in response to an operation instruction. Or, the first device determines whether the third device is within a preset range of the first device by using the third spatial position information; and the first device determines that the third device passes the verification when the first device determines that the third device is within the preset range of the first device. Or, the first device determines whether a difference between the third spatial position information and fourth spatial position information is within a preset range; the fourth spatial position information is obtained by the third device positioning the first device; and the first device determines that the third device passes the verification when the first device determines that the difference between the third spatial position information and the fourth spatial position information is within the preset range.

26. The method of establishing a wireless connection according to any one of claims 21 to 23, characterized by, The first device and the second device perform authentication based on the first shared key or a derivative key of the first shared key, including: The first device generates a first verification value based on the first shared key or a derivative key of the first shared key, and sends the first verification value to the second device. The first device receives a second verification value sent by the second device, and verifies the second verification value; the second verification value is generated by the second device based on the first shared key or a derivative key of the first shared key when the first verification value is correct.

27. The method of establishing a wireless connection according to claim 26, characterized by, The first device verifies the second verification value, including: Whether the first device successfully decrypts the second verification value; Or, the first device generates a third verification value, and compares the third verification value with the second verification value to determine whether they are the same. Or, the first device compares the first verification value with the second verification value to determine whether they are the same.

28. The method of establishing a wireless connection according to any one of claims 21 to 23, wherein, The first device and the second device perform authentication based on the first shared key or a derivative key of the first shared key, including: The first device generates a first verification value based on the first spatial position information and the first shared key or a derivative key of the first shared key, and sends the first verification value to the second device; The first device receives a second verification value sent by the second device, and verifies the second verification value, wherein the second verification value is generated by the second device based on second spatial position information and the first shared key or a derivative key of the first shared key when the first verification value is verified to be correct, and the second spatial position information is obtained by the second device positioning the first device.

29. The method of establishing a wireless connection according to claim 28, characterized by, The first device generates a first verification value based on the first shared key or a derivative key of the first shared key, and sends the first verification value to the second device; The first device performs hash operation on the first spatial position information or a derivative value of the first spatial position information, and the first shared key or a derivative key of the first shared key, to obtain a hash operation result, and all or part of the values of the hash operation result are used as the first verification value; The derivative value of the first spatial position information includes part of the data of the first spatial position information, or all or part of the values obtained by performing hash operation on the first spatial position information, or all or part of the values obtained by performing hash operation on the first spatial position information and one or more plaintext information or derivative information of the plaintext information.

30. The method of establishing a wireless connection according to claim 28, wherein, The first device verifies the second verification value, including: Whether the first device successfully decrypts the second verification value; Or, the first device generates a third verification value and compares whether the third verification value is the same as the second verification value; Or, the first device compares whether the first verification value is the same as the second verification value; Or, the first device decrypts the second verification value to obtain second spatial position information; The first device judges whether the difference between the first spatial position information and the second spatial position information is within a predetermined range.

31. The method of establishing a wireless connection according to any one of claims 21 to 23, wherein, The first device and the third device perform authentication based on the second shared key or a derivative key of the second shared key, including: The first device generates a fourth verification value based on the second shared key or a derivative key of the second shared key, and sends the fourth verification value to the third device; The first device receives a fifth verification value sent by the third device, and verifies the fifth verification value, wherein the fifth verification value is generated by the third device based on the second shared key or a derivative key of the second shared key when the fourth verification value is verified to be correct.

32. The method of establishing a wireless connection according to claim 31, wherein, The first device verifies the fifth verification value, including: Whether the first device successfully decrypts the fifth verification value; Or, the first device generates a sixth verification value and compares whether the sixth verification value is the same as the fifth verification value; Or, the first device compares whether the fourth verification value is the same as the fifth verification value.

33. The method of establishing a wireless connection according to any one of claims 21 to 23, characterized by, The authentication manner of the first device and the third device based on the second shared key or a derivative key of the second shared key includes: The first device generates a fourth verification value based on the third spatial location information and the second shared key or a derived key of the second shared key, and sends the fourth verification value to the third device; The first device receives a fifth verification value sent by the third device, and verifies the fifth verification value, wherein the fifth verification value is generated by the third device based on fourth spatial location information and the second shared key or a derived key of the second shared key when the fourth verification value is verified to be correct, and the fourth spatial location information is obtained by the third device positioning the first device.

34. The method of establishing a wireless connection according to claim 33, wherein, The first device generates a fourth verification value based on the third spatial location information and the second shared key or a derived key of the second shared key, and sends the fourth verification value to the third device; The first device performs hash operation on the third spatial location information or a derived value of the third spatial location information, and the second shared key or a derived key of the second shared key, to obtain a hash operation result, and all or part of the values of the hash operation result are used as the fourth verification value; The derived value of the third spatial location information includes: part of the data of the third spatial location information, or all or part of the values after hash operation on the third spatial location information, or all or part of the values after hash operation on the third spatial location information and one or more plaintext information or derived information of the plaintext information.

35. The method of establishing a wireless connection of claim 33, wherein, The first device verifies the fifth verification value, including: Whether the first device successfully decrypts the fifth verification value; Or, the first device generates a sixth verification value and compares whether the sixth verification value is the same as the fifth verification value; Or, the first device compares whether the fourth verification value is the same as the fifth verification value; Or, the first device decrypts the fifth verification value to obtain fourth spatial location information; The first device judges whether the difference between the third spatial location information and the fourth spatial location information is within a predetermined range.

36. The method of establishing a wireless connection according to any one of claims 21 to 23, wherein, Before the first device positions the second device to obtain the first spatial location information, the method further includes: The first device discovers the second device through a WiFi message or a UWB message.

37. The method of establishing a wireless connection according to any one of claims 21 to 23, characterized by, Before the first device positions the third device to obtain the third spatial location information, the method further includes: The first device discovers the third device through a WiFi message or a UWB message.

38. The method of establishing a wireless connection according to any one of claims 21 to 23, wherein, Further including: The first device sends a connection key to the second device and the third device respectively.

39. The method of establishing a wireless connection according to any one of claims 21 to 23, characterized by, Further including: The first device sends first signature information to the second device; The first device sends second signature information to the third device.

40. The method of establishing a wireless connection according to any one of claims 21 to 23, wherein, The first device positions the second device to obtain the first spatial location information, including: The first device adopts an ultra-wideband (UWB) positioning method, an ultrasonic positioning method, a Bluetooth positioning method, a cellular positioning method, a geomagnetic positioning method, an infrared positioning method, a radio frequency tag positioning method, a Zigbee positioning method, an ultra-wideband radio positioning method, a broadcast signal positioning method, or a light positioning method to position the second device to obtain the first spatial position information.

41. The method of establishing a wireless connection according to any one of claims 21 to 23, wherein, The first device positions a third device to obtain third spatial position information, including: The first device adopts an ultra-wideband (UWB) positioning method, an ultrasonic positioning method, a Bluetooth positioning method, a cellular positioning method, a geomagnetic positioning method, an infrared positioning method, a radio frequency tag positioning method, a Zigbee positioning method, an ultra-wideband radio positioning method, a broadcast signal positioning method, or a light positioning method to position the third device to obtain the third spatial position information.

42. An electronic device, comprising: The electronic device includes a first device, and the electronic device includes: one or more processors, memories, and wireless communication modules; The memories and the wireless communication modules are coupled with the one or more processors, and the memories are configured to store computer program codes including computer instructions, and when the one or more processors execute the computer instructions, the electronic device performs the method for establishing a wireless connection according to any one of claims 1 to 20 or the method for establishing a wireless connection according to any one of claims 21 to 41.

43. A computer storage medium, comprising, A computer program for storing is specifically configured to implement the method for establishing a wireless connection according to any one of claims 1 to 20 or the method for establishing a wireless connection according to any one of claims 21 to 41.

44. A computer program product, characterised in that, When a computer program product is running on a computer, the computer is caused to perform the method for establishing a wireless connection according to any one of claims 1 to 20 or the method for establishing a wireless connection according to any one of claims 21 to 41.

Citation Information

Patent Citations

  • Power Internet of Things terminal equipment authentication method based on group authentication and segmented authentication

    CN112910861A

  • Key configuration method and apparatus

    WO2015061941A1