Key updating method and device of equipment, electronic equipment and storage medium

By dynamically generating and updating keys based on network connection time and identification information in smart home devices, the problem of easy cracking of traditional fixed passwords is solved, and the timeliness and high security of keys is achieved, and the risk of hacker intrusion is avoided.

CN120128918APending Publication Date: 2025-06-10HUIZHOU TCL MOBILE COMM CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510193230.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

The traditional fixed password management model is likely to become a breakthrough for hackers in smart homes, and how to improve the security of device key management has become an urgent problem.

Method used

By determining the network connection time of the device within a specified period, generating a target key based on the network connection time and the identification information of the device, replacing the historical key, dynamic update and timeliness of the key are achieved.

Benefits of technology

This makes the target key of the device time-consuming and difficult to crack, effectively prevents the risk of hackers cracking fixed keys, and improves the security of the device's key, so that users do not need to manually set it.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128918A_ABST
    Figure CN120128918A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a secret key updating method and device of equipment, electronic equipment and a computer readable storage medium, and relates to the technical field of secret key security, and the method comprises the following steps: determining the network connection duration of the equipment in a specified period; generating a target key of the device based on the network connection duration and the identification information of the device; and based on the target key, replacing a historical key of the device. Therefore, the target key of the equipment has timeliness and is difficult to crack, and the risk that a hacker cracks a fixed key is effectively prevented. The aging key is dynamically generated based on the network connection duration and rule of the equipment in the specified period, intelligent key management is realized by using network data characteristics, the key security of the equipment is improved, and a user does not need to manually set the key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present disclosure relate to the technical field of key security, and particularly to a method, apparatus, electronic device, and computer-readable storage medium for updating a key of a device. Background Art

[0002] In the context of the rapid development of current smart homes, the issue of home security has become increasingly prominent. There are numerous Internet-connected devices in modern homes, and various smart home devices have become necessities of life. Modern smart homes need to interact with users and require remote management, so each smart home has a key for encryption used for identity authentication, permission control, etc. The traditional fixed password management mode can no longer meet the requirements and is easily exploited by hackers as a breakthrough point.

[0003] Therefore, how to improve the security of device key management is an urgent problem to be solved at present. Summary of the Invention

[0004] Embodiments of the present disclosure provide a method, apparatus, electronic device, and computer-readable storage medium for updating a key of a device, aiming to solve at least one of the technical problems in the related art to a certain extent.

[0005] In a first aspect, embodiments of the present disclosure provide a method for updating a key of a device, the method comprising:

[0006] Determining the network connection duration of the device within a specified period;

[0007] Generating a target key of the device based on the network connection duration and the identification information of the device;

[0008] Replacing the historical key of the device based on the target key.

[0009] In a second aspect, embodiments of the present disclosure further provide a device for updating a key of a device, the device comprising:

[0010] A determination module, configured to determine the network connection duration of the device within a specified period;

[0011] A generation module, configured to generate a target key of the device based on the network connection duration and the identification information of the device;

[0012] A replacement module, configured to replace the historical key of the device based on the target key.

[0013] In a third aspect, embodiments of the present disclosure further provide an electronic device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the computer program is executed by the processor, the steps in the above method for updating a key of a device are implemented.

[0014] Fourthly, an embodiment of the present disclosure further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the key update method of the above-mentioned device are implemented.

[0015] Fifthly, an embodiment of the present disclosure further provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the methods provided in various alternative implementations of the embodiments of the present disclosure.

[0016] In the embodiments of the present disclosure, first, the network connection duration of the device within a specified period is determined, and then based on the network connection duration and the identification information of the device, a target key of the device is generated. Then, based on the target key, the historical key of the device is replaced. Thus, the target key of the device has timeliness and is difficult to be cracked, effectively preventing the risk of hackers cracking the fixed key. Based on the network connection duration of the device within a specified period, a time-limited key is regularly and dynamically generated, and the intelligent management of the key is realized by using the characteristics of network data, improving the key security of the device without the need for users to set it manually.

[0017] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the present disclosure, the drawings required for the description of the embodiments will be briefly introduced below. Obviously, the following drawings are only some embodiments of the present invention, and those skilled in the art can obtain other drawings without creative efforts based on these drawings.

[0019] Figure 1 is a schematic flowchart of the key update method of the device provided in the first embodiment of the present disclosure;

[0020] Figure 2 is a schematic flowchart of the key update method of the device provided in the second embodiment of the present disclosure;

[0021] Figure 3 is a schematic structural diagram of the key update device of the device provided in the embodiments of the present disclosure;

[0022] Figure 4 is a schematic structural diagram of the electronic device provided in the embodiments of the present disclosure. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] Some embodiments of the present disclosure will be described in detail herein, and examples thereof are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. Various changes, modifications, and equivalents of the methods, apparatuses, and / or systems described herein will become apparent after understanding the present disclosure. For example, the order of operations described herein is merely an example and is not limited to those set forth herein, but may be changed as will be apparent after understanding the present disclosure, except for operations that must be performed in a specific order. Additionally, descriptions of features known in the art may be omitted for the sake of clarity and conciseness.

[0024] The embodiments described in some embodiments of the present disclosure below do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of apparatuses and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0025] It should be noted that the execution subject of the key update method of the device in this embodiment can be the key update device of the device, and this device can be configured in any type of network device. For example, it can be a router, which is not limited herein.

[0026] In the embodiments of the present disclosure, the "router" will be used as the execution subject to execute the "key update method of the device" for illustration, which is not limited herein.

[0027] It should be noted that the description order of the following embodiments does not limit the priority order of the embodiments.

[0028] Figure 1 is a schematic flowchart of the key update method of the device provided in the first embodiment of the present disclosure.

[0029] As Figure 1 shown, the method includes:

[0030] Step 101, determine the network connection duration of the device within a specified period.

[0031] As a possible implementation manner, it is possible to first monitor the network connection information of the device within a specified period based on the wireless network receiver, and then count the network connection duration of the device within the specified period based on the network connection information.

[0032] Among them, the device can be any type of network device. For example, it can be a household appliance device, such as an air conditioner, a television, a washing machine, a refrigerator, a door lock, a smart light strip, etc., which is not limited herein.

[0033] Among them, the specified period can be a time period with a specific duration. For example, the time between 8 o'clock and 24 o'clock can be used as the specified period.

[0034] Among them, the network connection information can be the relevant information during the process of the device connecting to the wireless network, such as the start connection time, disconnection time, data traffic, etc., which are not limited here.

[0035] Among them, the network connection duration can be the total duration of the device connecting to the network within a specified period. For example, if the specified period is from 8 am to 9 pm, and the total duration of the air conditioner connecting to the network is 7 hours, then 7 hours can be used as the network connection duration corresponding to the air conditioner device.

[0036] Specifically, it is necessary to first ensure that the wireless network receiver is correctly installed and connected to the network device (such as a router). The router can configure the receiver to receive and process the network connection information from the device according to the instructions provided by the receiver model and manufacturer.

[0037] Among them, the receiver can capture the electromagnetic wave signal from the device through the antenna. The radio frequency amplifier inside the receiver enhances the signal intensity. The tuning circuit selects a specific frequency signal and filters out signals of other frequencies. The mixer mixes the tuned signal with the signal output by the local oscillator to generate an intermediate frequency signal. The intermediate frequency amplifier further enhances the signal intensity and improves the signal quality. The demodulator extracts useful information from the intermediate frequency signal, such as device identification, connection status, data traffic, etc. The wireless network receiver records the parsed network connection information into a database or a log file, ensuring that the recorded network connection information includes key data such as device ID, connection time, disconnection time, data traffic, etc.

[0038] Furthermore, the router can filter out the network connection information within a specified period from the recorded data, and then group the data according to the device ID and the network connection duration.

[0039] For example, if the specified period is 24 hours a day, the devices include a smart bulb, a smart socket, and a smart camera. The smart bulb goes online at 8:10 and goes offline at 18:30, and the network connection duration is 10 hours and 20 minutes. The smart socket goes online at 8:05 and goes offline at 22:00, and the network connection duration is 13 hours and 55 minutes. The smart camera is online for 24 hours throughout the day, and the network connection duration is 24 hours, which is not limited here.

[0040] Step 102, generate the target key of the device based on the network connection duration and the identification information of the device.

[0041] Among them, the device identification information can be the unique identifier of the device, such as the serial number of the device, the MAC address, or the device name defined by the user, which is not limited herein. Optionally, the identification information (ID) of the device can include the identification characters of the device, the character length, etc., which is not limited herein. If the device ID is "Device001", the character length is 9 bits.

[0042] Among them, the network connection duration can be the duration from when the device connects to the network to the current moment, usually recorded in seconds, minutes, or hours.

[0043] As a possible implementation, the device identification information and the network connection duration can be combined into a single data string, which is to associate two related pieces of information together as the basic data for generating the key. For example, if the device identification information is "Device001" and the network connection duration is 3600 seconds (1 hour), they can be combined into a string like "Device0013600".

[0044] As an implementation, the PBKDF2HMAC algorithm (password-based key derivation function) can be used to encrypt the string. To improve security, a random salt value is also prepared first. The salt value is a random byte string, such as "some_random_sa lt". The role of the salt value is that even for the same input data (the combination of device identification information and connection duration), due to different salt values, the finally generated key will be different, thereby increasing the randomness and security of the key.

[0045] Optionally, a hash algorithm, such as SHA256, can be selected as the basic hash algorithm of the PBKDF2HMAC algorithm. Then, the length of the key to be generated can be determined, usually 32 bytes (256 bits), to meet modern encryption standards. Set an iteration count, such as 100000 times. The higher the iteration count, the more secure the calculated key, but it will also consume more computing resources. Then, the combined data string (device identification information and connection duration), the salt value, and the set algorithm parameters can be input into the PBKDF2HMAC algorithm. The algorithm will perform multiple iterations and hash operations on the input data. By using the selected hash algorithm, the input data is continuously transformed during the iteration process, and finally a 32-byte key is obtained.

[0046] It should be noted that the above examples are only illustrative and not a limitation to the present disclosure.

[0047] Step 103, replace the historical key of the device based on the target key.

[0048] Among them, the historical key is also the old key of the device, the key originally used. After the router determines the new key, that is, the current target key, it can replace the historical key with the target key to update the key.

[0049] Optionally, the router can send the target key to the corresponding device based on the identification information corresponding to the device, so that the device replaces the historical key based on the target key.

[0050] As a possible implementation, the router can, at a specified time, based on the identification information corresponding to each device, send a key synchronization instruction to each device at the same time. The key synchronization instruction contains the target key corresponding to the device. The key synchronization instructions received by different devices are different. After receiving the key synchronization instruction, the device can replace the historical key according to the target key contained in the key synchronization instruction.

[0051] Optionally, the router can determine that the device has received the target key in response to receiving the historical key and the signed identification information returned by the device.

[0052] It should be noted that in order to ensure that the device has successfully received and processed the key synchronization instruction, the router can use the following mechanism for confirmation:

[0053] After successfully receiving the key synchronization instruction and replacing the key, the device can return a confirmation message to the router. This confirmation message can contain the historical key of the device (as a way to verify the identity to ensure that it is a legitimate device returning the confirmation) and the signed identification information (such as the signed device ID).

[0054] After receiving the confirmation message returned by the device, the router first verifies the validity of the signature to ensure that the information is sent by a legitimate device. Then, the router can check whether the returned historical key matches the historical key previously sent to the device as a further basis for verifying the device identity. If the signature verification is successful and the historical key matches, the router can determine that the device has successfully received the target key and completed the key replacement.

[0055] For example, after receiving an instruction, the smart bulb transmits the signed ID (assumed to be SignedBulb001 after signing) and the old ciphertext (assumed to be OldBulbCipher before) through its own home appliance security verification component. After receiving the instruction, the smart socket transmits the signed ID (assumed to be SignedSocket001 after signing) and the old ciphertext (assumed to be OldSocketCipher before). After receiving the instruction, the smart camera transmits the signed ID (assumed to be SignedCamera001 after signing) and the old ciphertext (assumed to be OldCameraCipher before).

[0056] In the embodiments of the present disclosure, first, the network connection duration of the device within a specified period is determined. Then, based on the network connection duration and the identification information of the device, a target key of the device is generated. Then, based on the target key, the historical key of the device is replaced. Thus, the target key of the device has timeliness and is difficult to be cracked, effectively preventing the risk of hackers cracking the fixed key. Based on the network connection duration of the device within a specified period, a time-limited key is regularly and dynamically generated, and the characteristics of network data are utilized to realize intelligent key management, improving the key security of the device without the need for users to set it manually.

[0057] As an example, the execution entity in the embodiments of the present disclosure may be a router. As the Wi-Fi router at the core of the home network, it stores rich and up-to-date network usage data. Valuable time-series feature resources are hidden in these data but have not been deeply mined and applied. Users not only hope that the home system is reliable and efficient but also desire more rigorous protection. However, manually setting and updating keys are often cumbersome and ineffective. Therefore, the "device key update method" in the embodiments of the present disclosure can center around the router to manage the system that regularly and dynamically generates time-limited keys based on daily traffic, and further can ensure the innovation orientation of home intelligent security and improve the user experience, and utilize the characteristics of network data to realize intelligent key management.

[0058] Figure 2 It is a schematic flowchart of the device key update method provided in the second embodiment of the present disclosure.

[0059] As shown in Figure 2 the figure, the method includes:

[0060] Step 201, determine the network connection duration of the device within a specified period.

[0061] It should be noted that the specific implementation manner of step 201 may refer to the above embodiments and will not be elaborated here.

[0062] Step 202, perform hash encryption on the network connection duration to obtain a starting string.

[0063] Among them, the starting string is the result of hashing and encrypting the network connection duration. In the embodiments of the present disclosure, the starting string can be used as a seed. In a cryptographic system, a seed is a very important starting value, and the starting string is the basis for generating subsequent password-related content.

[0064] As an example, in the embodiments of the present disclosure, the SHA256 hashing and encryption algorithm can be used to process the network connection duration to obtain a 256-bit starting string.

[0065] For example, for a smart bulb device, the initialization seed generated on the first day may be a 256-bit string obtained by SHA256 hashing and encryption based on its connection duration information on the first day (such as 10 hours and 20 minutes): "3A4F7D2E1C9B658023456789ABCDEF0123456789ABCDEF0123456789ABCDEF0123456789".

[0066] It should be noted that the above example is only an illustrative description and does not limit the present disclosure.

[0067] It can be understood that the role of the starting string (as a seed) is to provide an initial and random state for subsequent digital generation algorithms. Since the seed itself is hashed based on information such as network connection duration, and information such as network connection duration changes at different times, the starting string has a certain degree of randomness and timeliness.

[0068] Step 203: Obtain a random string library based on a preset digital generation algorithm and the starting string.

[0069] Among them, the digital generation algorithm is a program or method that generates a series of numbers through specific calculation rules or mathematical formulas. These algorithms can generate a digital sequence with a certain pattern or randomness according to different inputs (such as the initial seed).

[0070] Among them, the random string library is a set that stores multiple random strings.

[0071] Optionally, the preset digital generation algorithm can be a pseudo-random number generation algorithm, which is not limited herein.

[0072] Among them, the pseudo-random number generation algorithm includes the linear congruence method, the Mersenne Twister algorithm, etc. These algorithms use an initial value (seed) and a set of fixed parameters to generate a series of random digital sequences through iterative calculations.

[0073] It can be understood that each random digital sequence obtained by iterating the digital generation algorithm can be collected to obtain a random string library.

[0074] Optionally, the digital generation algorithm can be initialized based on the starting string first, and then the initialized digital generation algorithm can be iterated multiple times to obtain a random string library.

[0075] It can be understood that the starting string acts as a seed in this process. It provides an initial state or starting point for the digital generation algorithm. The starting string will determine where the digital generation algorithm starts to generate digital sequences. After the digital generation algorithm is initialized, it starts to iterate multiple times to generate a series of numbers. Each iteration updates the internal state of the algorithm and outputs a new digital sequence.

[0076] It should be noted that the generated random strings can be stored in a data structure, such as a list, an array, or a database, to form a random string library. Optionally, the size of the string library can also be set according to different requirements, such as storing 100, 1000, or more random strings. At the same time, according to the application scenario, the length range of the strings can be set, such as generating random strings with lengths between 8 and 16 bits.

[0077] Step 204: Generate a target key for the device based on the random string library and the identification information of the device.

[0078] Optionally, the target string can be obtained from the random string library based on the identification length of the device first, and then the initial password can be obtained by combining the target string and the identification characters of the device. After that, the initial password can be symmetrically encrypted to obtain the target key.

[0079] Optionally, the target key and the identification information of the device can be associated and stored, where the storage locations of the target keys corresponding to different devices are different.

[0080] First, the identification length of the device needs to be known. The identification of the device can be the device ID, MAC address, or other unique identifiers. For example, the identification of the device is Device001, and its length is 9. Find a string in the random string library with the same length as the device identification. Suppose the random string library contains ["abcdefghi", "1234569", "zyxwsr", "0987654"]. For the device identification Device001, the string with a length of 9, such as "abcdefghi", will be selected as the target string.

[0081] Furthermore, the target string and the device identification can be combined.

[0082] For example, combining abcdefghi and Device001 can have multiple combination methods. Commonly, there is concatenation, resulting in abcdefghiDevice001 or Device001 abcdefghi. This combined string is the initial password, and its length is the sum of the lengths of the two, which is 18 in this example.

[0083] Furthermore, a symmetric encryption algorithm can be selected, such as AES (Advanced Encryption Standard). When using the AES algorithm, a key is required. This key can be a pre-generated key or generated based on other information of the system. Then, the initial password can be used as the plaintext input and encrypted using the AES algorithm. For example, when using AES-256 for encryption, the 18-bit initial password abcdefghiDevice001 will be processed according to the encryption process of AES-256.

[0084] Among them, AES-256 will divide the initial password into blocks of 128 bits (16 bytes). If the length of the initial password is not a multiple of 16, padding (such as PKCS7 padding) will be performed. Then, these blocks will be encrypted in multiple rounds using the key (assuming a 256-bit key), including operations such as byte substitution, row shift, column mixing, and round key addition, and finally the encrypted ciphertext, that is, the target key, will be obtained.

[0085] It should be noted that the target keys corresponding to different devices are stored in different locations. The device identifier can be used as an index for the storage location. For example, the target key of Device001 is stored in the storage area named Device001, which is convenient for subsequent searching of the corresponding target key according to the device identifier. The storage location can be a database, a file system, or a secure storage chip, and at the same time, the security of the storage should be ensured to prevent information leakage.

[0086] Step 205, replace the historical key of the device based on the target key.

[0087] It should be noted that the specific implementation method of step 205 can refer to the above embodiments and will not be elaborated here.

[0088] Step 206, obtain the key currently used by the device at a specified period.

[0089] Optionally, the router can send requests to the devices at a specified period, that is, at a certain time interval (for example, every hour, every day, or every week), to obtain the keys they are currently using. This time interval can be set according to the system requirements and security requirements.

[0090] The router can send requests to the device using network communication protocols (such as HTTP, MQTT, CoAP, etc.). After receiving the request, the device returns the key information it is currently using to the management software monitoring component.

[0091] Step 207, in the case where the currently used key is inconsistent with the current target key of the device, determine that the device has an abnormal password synchronization, and reissue the corresponding target key to the device.

[0092] It can be understood that the router can pre-store a device list, which contains detailed information of each device, such as the unique identifier of the device (such as device ID, MAC address) and the corresponding target key. These data are the correct password information that the system believes the device should use. The router can compare the currently used key obtained from the device with the target key of the device recorded.

[0093] For example, if it is found during the comparison process that the currently used key of a certain device does not match the stored target key, it means that the password of the device has not been updated. At this time, the device is marked as "abnormal password synchronization" status. The marking can be achieved by adding a status marking field in the data structure of the management software monitoring component. For example, the status field of the device is set to "abnormal password synchronization" for subsequent processing. Then, the router can be notified to retry the password issuance work. Among them, the management software monitoring component in the router will send a notice to the router, informing the router which devices need to have their passwords reissued.

[0094] Step 208, if the device does not receive the target key, add the device to the abnormal device list and notify the user.

[0095] Specifically, the router will try to reissue the target key to the abnormal device according to the received notice. If the retry fails, the router will feedback the result to the management software monitoring component. The management software monitoring component adds the device that fails the retry to the pending abnormal list. This list can be stored in a data structure in the database or memory for subsequent processing and tracking. At the same time, the component will send a notice to the user. The notice method can be through email, SMS, system notice or push notification of the mobile application, informing the user which devices have password synchronization problems and requiring the user to check and repair.

[0096] It should be noted that the router can also continuously track the results of each password update operation based on the management software monitoring component, whether it is a normal update or an abnormal situation. A counter can be used to record the number of successful and failed password updates, and calculate the password update success rate. For example, the success rate = the number of successful updates / (the number of successful updates + the number of failed updates). If there is a long-term problem with password synchronization for some devices (e.g., consecutive failed password updates), the management software monitoring component will feedback this information to the router. The router can analyze this information, which may involve checking network connections, device status, and communication protocol issues, and try to find the reason for the password synchronization failure and repair it.

[0097] In the embodiments of the present disclosure, first, the network connection duration of the device within a specified period is determined, then the network connection duration is hashed and encrypted to obtain a starting string. Then, based on a preset digital generation algorithm and the starting string, a random string library is obtained. Then, based on the random string library and the identification information of the device, the target key of the device is generated. After that, based on the target key, the historical key of the device is replaced. Then, if the currently used key is inconsistent with the current target key of the device, it is determined that the device has an abnormal password synchronization, and the corresponding target key is reissued to the device. After that, if the device does not receive the target key, the device is added to the abnormal device list and the user is notified. Thus, the security of device key updates can be guaranteed, abnormalities can be detected in a timely manner, key synchronization can be ensured, the security of the system can be enhanced, the abnormal devices can be managed, and the overall system stability and security can be improved.

[0098] It should be noted that the embodiments of the present disclosure adopt a dynamic time-limited key management mode based on network connection duration. Compared with the traditional fixed key method, it has the following advantages and benefits: higher security. The time-limited key is generated and updated daily, which is extremely difficult to crack, effectively preventing the risk of hackers cracking the fixed key. More intelligent management. The system automatically learns the user's behavior habits and realizes seamless management for the device. The user does not need to manually set cumbersome passwords. More secret password updates. The system adopts a concealed update strategy, and the actual password cannot be known externally, greatly reducing the risk of brute-force cracking. More convenient management. Real-time monitoring of household appliances can be achieved on the mobile side, and the user can remotely control them with one touch from any location. Better user experience. The dynamic password mechanism does not require user participation and does not affect the daily use of household appliances, providing a seamless intelligent experience. Stronger compatibility. The system supports most intelligent household appliances and router devices, with a wider range of applications. Higher cost-effectiveness. Compared with other card swiping or biometric identification solutions, this solution has the advantages of strong accessibility and simple implementation.

[0099] To facilitate better implementation of the key update method for the device of the present disclosure, the present disclosure also provides a key update device for the device based on the above key update method for the device. The meanings of the nouns are the same as those in the above key update method for the device, and the specific implementation details can be referred to the descriptions in the method embodiments.

[0100] Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of the key update device for the device provided by the embodiments of the present disclosure. The key update device 300 for the device includes:

[0101] A determination module 310, configured to determine the network connection duration of the device within a specified period;

[0102] A generation module 320, configured to generate a target key for the device based on the network connection duration and the identification information of the device;

[0103] A replacement module 330, configured to replace the historical key of the device based on the target key.

[0104] Optionally, the generation module includes:

[0105] An encryption unit, configured to perform hash encryption on the network connection duration to obtain a starting string;

[0106] A first generation unit, configured to obtain a random string library based on a preset digital generation algorithm and the starting string;

[0107] A second generation unit, configured to generate a target key for the device based on the random string library and the identification information of the device.

[0108] Optionally, the first generation unit is specifically configured to:

[0109] Initialize the digital generation algorithm based on the starting string;

[0110] Perform multiple iterations on the initialized digital generation algorithm to obtain a random string library.

[0111] Optionally, the second generation unit is specifically configured to:

[0112] Obtain a target string from the random string library based on the identification length of the device;

[0113] Combine the target string and the identification characters of the device to obtain an initial password;

[0114] Perform symmetric encryption processing on the initial password to obtain a target key.

[0115] Optionally, the second generation unit is further configured to:

[0116] Associate and store the target key and the identification information of the device.

[0117] Among them, the storage locations of the target keys corresponding to different devices are different.

[0118] Optionally, the replacement module 330 is specifically configured to:

[0119] Send the target key to the corresponding device based on the identification information corresponding to the device, so that the device replaces the historical key based on the target key.

[0120] Optionally, the device further includes:

[0121] The first determination sub-module is configured to determine that the device has received the target key in response to receiving the historical key and the signed identification information returned by the device.

[0122] Optionally, the device further includes:

[0123] The acquisition sub-module is configured to acquire the key currently used by the device at a specified period;

[0124] The second determination sub-module is configured to determine that the device has an abnormal password synchronization and reissue the corresponding target key to the device if the currently used key is inconsistent with the current target key of the device;

[0125] The notification sub-module is configured to add the device to the abnormal device list and notify the user if the device has not received the target key.

[0126] Optionally, the determination module is specifically configured to:

[0127] Monitor the network connection information of the device within a specified period based on the wireless network receiver;

[0128] Statistically calculate the network connection duration of the device within the specified period based on the network connection information.

[0129] In the embodiments of the present disclosure, first, the network connection duration of the device within a specified period is determined, then the target key of the device is generated based on the network connection duration and the identification information of the device, and then the historical key of the device is replaced based on the target key. Thus, the target key of the device has timeliness and is difficult to be cracked, effectively preventing the risk of hackers cracking the fixed key. Based on the network connection duration of the device within a specified period, the time-limited key is regularly and dynamically generated, and the intelligent management of the key is realized by using the characteristics of network data, improving the key security of the device without the need for the user to manually set it.

[0130] In addition, the present disclosure also provides an electronic device, such as Figure 4 shown, which shows a schematic structural diagram of the electronic device involved in the present disclosure. Specifically:

[0131] The electronic device may include a processor 401 with one or more processing cores, a memory 402 with one or more computer-readable storage media, a power supply 403, an input unit 404, and other components. Those skilled in the art can understand that Figure 4 the structure of the electronic device shown in

[0132] does not limit the electronic device, and it may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements. Among them:

[0133] The processor 401 is the control center of the electronic device, connecting various parts of the entire electronic device through various interfaces and lines. By running or executing software programs and / or modules stored in the memory 402, and calling the data stored in the memory 402, it executes various functions of the electronic device and processes data, thereby monitoring the electronic device as a whole. Optionally, the processor 401 may include one or more processing cores; preferably, the processor 401 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 401.

[0133] The memory 402 can be used to store software programs and modules. The processor 401 executes various functional applications and data processing by running the software programs and modules stored in the memory 402. The memory 402 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system, application programs required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the electronic device. In addition, the memory 402 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one magnetic disk storage device, a flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory 402 may also include a memory controller to provide the processor 401 with access to the memory 402.

[0134] The electronic device also includes a power supply 403 that powers each component. Preferably, the power supply 403 can be logically connected to the processor 401 through a power management system, so as to realize functions such as management of charging, discharging, and power consumption management through the power management system. The power supply 403 may also include any components such as one or more DC or AC power supplies, a recharge system, a power device debugging circuit, a power converter or inverter, and a power status indicator.

[0135] The electronic device may further include an input unit 404, which can be used to receive input digital or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function controls.

[0136] Although not shown, the electronic device may further include a display unit and the like, which will not be elaborated here. Specifically, in this embodiment, the processor 401 in the electronic device will load the executable files corresponding to the processes of one or more application programs into the memory 402 according to the following instructions, and the processor 401 will run the application programs stored in the memory 402, so as to implement the steps in any device key update method provided by the embodiments of the present disclosure.

[0137] In the embodiments of the present disclosure, first, the network connection duration of the device within a specified period is determined, then based on the network connection duration and the identification information of the device, a target key of the device is generated, and then based on the target key, the historical key of the device is replaced. Thereby, the target key of the device has timeliness and is difficult to be cracked, effectively preventing the risk of hackers cracking the fixed key. Based on the network connection duration of the device within a specified period, a time-limited key is regularly and dynamically generated, and the characteristics of network data are utilized to realize intelligent key management, improve the key security of the device, and the user does not need to set it manually.

[0138] For the specific implementation of the above operations, reference can be made to the previous embodiments, which will not be elaborated here.

[0139] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by controlling related hardware through instructions. The instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.

[0140] Therefore, the present disclosure provides a computer-readable storage medium, on which a computer program is stored. The computer program can be loaded by a processor to execute the steps in any device key update method provided by the present disclosure.

[0141] For the specific implementation of the above operations, reference can be made to the previous embodiments, which will not be elaborated here.

[0142] Among them, the computer-readable storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disk, etc.

[0143] Since the instructions stored in the computer-readable storage medium can execute the steps in the key update method of any device provided by the present disclosure, the beneficial effects achievable by the key update method of any device provided by the present disclosure can be realized. For details, refer to the previous embodiments and will not be elaborated herein.

[0144] The key update method, device, electronic device, and computer-readable storage medium provided by the present disclosure have been introduced in detail above. Specific examples are used in this article to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those skilled in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A method for updating a key of a device, characterized in that: include: Determine how long a device has been connected to the network over a specified period of time; Generate a target key for the device based on the network connection duration and the identification information of the device; Based on the target key, the historical key of the device is replaced.

2. The method according to claim 1, characterized in that: The generating a target key of the device based on the network connection duration and the identification information of the device includes: Hash-encrypt the network connection duration to obtain a starting character string; Based on a preset digital generation algorithm and the starting character string, a random character string library is obtained; A target key for the device is generated based on the random string library and the identification information of the device.

3. The method according to claim 2, characterized in that The method of obtaining a random string library based on a preset digital generation algorithm and the starting string includes: Initializing the number generation algorithm based on the starting character string; The initialized number generation algorithm is iterated multiple times to obtain a random string library.

4. The method according to claim 2, characterized in that: The generating a target key of the device based on the random string library and the identification information of the device includes: Based on the identification length of the device, obtaining a target string from the random string library; Combining the target character string with the identification character of the device to obtain an initial password; The initial password is symmetrically encrypted to obtain a target key.

5. The method according to claim 4, characterized in that After the initial password is symmetrically encrypted to obtain the target key, the method further includes: The target key and the identification information of the device are stored in association, The target key storage locations corresponding to different devices are different.

6. The method according to claim 1, characterized in that The replacing the historical key of the device based on the target key includes: Based on the identification information corresponding to the device, the target key is sent to the corresponding device, so that the device replaces the historical key based on the target key.

7. The method according to claim 6, characterized in that Also includes: In response to receiving the historical key and the signed identification information returned by the device, it is determined that the device has received the target key.

8. The method according to claim 1, characterized in that Also includes: Obtaining a key currently used by the device according to a specified period; In the case that the currently used key is inconsistent with the current target key of the device, determining that the device has a password synchronization abnormality, and re-issuing the corresponding target key to the device; If the device does not receive the target key, the device is added to the abnormal device list and the user is notified.

9. The method according to claim 1, characterized in that: Determining the network connection duration of the device within a specified period includes: Based on the wireless network receiver, monitoring the network connection information of the device within a specified period; Based on the network connection information, the network connection duration of the device in the specified period is counted.

10. A key updating device for a device, characterized in that: include: A determination module, used to determine the network connection duration of the device within a specified period; A generating module, configured to generate a target key for the device based on the network connection duration and the identification information of the device; A replacement module is used to replace the historical key of the device based on the target key.

11. An electronic device, characterized in that: It comprises a processor and a memory, wherein the memory stores a plurality of instructions; the processor loads instructions from the memory to execute the steps in the key updating method of a device as claimed in any one of claims 1 to 9.

12. A storage medium, characterized in that: The storage medium stores a plurality of instructions, and the instructions are suitable for being loaded by a processor to execute the steps in the key updating method for a device according to any one of claims 1 to 9.