Wireless networking communication method, communication equipment and storage medium

By performing key negotiation and encrypted communication in the wireless network communication method, the security risks caused by the lack of encryption of broadcast messages in the prior art are solved, and secure and efficient communication between devices are achieved.

CN120128920APending Publication Date: 2025-06-10湖北星纪魅族集团有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510507564.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-22
Publication Date
2025-06-10

AI Technical Summary

Technical Problem

In the existing wireless network communication methods, broadcast messages lack encryption, resulting in the security risks of privacy leakage and false information attacks in messages communicated between devices.

Method used

A wireless network communication method is adopted to receive the network access request of the device to be entered through a wireless broadcast network beacon, and use the public key of the device to be entered and the private key of the network node to generate a key, perform key negotiation, and generate a network communication key for encrypting communication.

Benefits of technology

Encrypted communication between devices is realized, the security of communication is improved, privacy leakage and false information attacks are prevented, and network security and efficiency are enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128920A_ABST
    Figure CN120128920A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a wireless networking communication method, which comprises the following steps of: presetting different static keys and static key factors for different nodes in wireless networking, storing the static keys in the nodes by adopting a distributed method, and storing the static key factors in a server. And a symmetric key is negotiated by using a random value calculated by a network node random algorithm and the equipment to be accessed to the network, so that an attacker is prevented from easily obtaining a static key of the node, the attacker is difficult to simulate illegal access by using the uncertainty of a random number, and the communication security of each node in the wireless network is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of intelligent devices, and particularly to a wireless networking communication method, a communication device, and a storage medium. Background Art

[0002] This section aims to provide background information related to understanding various technologies described herein. As implied by the title of this section, this is in no way intended to imply that the relevant technologies are necessarily prior art. Therefore, it should be understood that any statement in this section should be read from this perspective and not as any admission of prior art.

[0003] The scenario of sharing broadcast messages within a network among intelligent devices has many user scenarios and high commercial value. For example, in scenic spots, museums, etc., guides give voice or text introductions to tourists in a group; when traveling in a group, route or other information is shared within the group; in a meeting, the host shares voice and information, etc. These scenarios can all be transmitted through the broadcast function of intelligent devices such as AR glasses and mobile phones. Broadcasting has the advantages of not being limited by the number of devices, simple layout, and significantly reducing power consumption compared to direct connections.

[0004] However, currently, the broadcast messages of communication solutions are not encrypted, such as the broadcast messages of Bluetooth BLE and WIFI technologies. In this scenario, the messages communicated between devices have security risks such as privacy leakage and false information attacks. Summary of the Invention

[0005] To solve any of the above problems, the present disclosure provides a wireless networking communication method and a communication device;

[0006] According to a first aspect of the present disclosure, there is provided a wireless networking communication method applied to a network node, including:

[0007] Wirelessly broadcast a network beacon;

[0008] Receive an access request from a device to be accessed, where the access request includes the public key of the device to be accessed;

[0009] Generate a key using the public key of the device to be accessed and the private key of the network node;

[0010] Generate a first random number, and encrypt the first random number using the key to obtain a random number ciphertext;

[0011] Send the random number ciphertext and the public key of the network node to the device to be accessed;

[0012] Generate an authentication code using a random number generation algorithm, and share the authentication code with the device to be accessed through an out-of-band method;

[0013] Obtain a static key and a static key factor of a network node, and calculate a static encryption factor based on the static key and the static key factor;

[0014] Calculate a network communication key based on a network beacon, a first random number, an authentication code, and the static encryption factor; and

[0015] Conduct encrypted communication with the device to be networked using the network communication key;

[0016] Wherein, any device that can be networked stores a static key, the server stores a static key factor corresponding to the static key, the static encryption factor calculated from the static key of any device that can be networked and the corresponding static key factor is the same, and the static key of each device that can be networked and its corresponding static key factor are different from those of another device that can be networked.

[0017] According to the second aspect of the present disclosure, a communication method for wireless networking is provided, which is applied to a device to be networked, and includes:

[0018] Receive the network beacon of the network node;

[0019] Send an access request to the network node based on the network beacon, and the access request includes the public key of the device to be networked;

[0020] Receive the random number ciphertext and the public key of the network node sent by the network node based on the access request, and the authentication code shared by the network node through an out-of-band method;

[0021] Decrypt the random number ciphertext using the public key of the network node and the private key of the device to be networked to obtain a first random number;

[0022] Obtain a static key and a static key factor of the device to be networked, and calculate a static encryption factor based on the static key and the static key factor;

[0023] Calculate a network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor;

[0024] Conduct encrypted communication with the network node using the network communication key;

[0025] Wherein, any device that can be networked stores a static key, the server stores a static key factor corresponding to the static key, the static encryption factor calculated from the static key of any device that can be networked and the corresponding static key factor is the same, and the static key of each device that can be networked and its corresponding static key factor are different from those of another device that can be networked.

[0026] According to a third aspect of the present disclosure, there is provided a communication device for wireless networking, including a processor and a memory. The processor is configured to call and run a computer program stored in the memory to execute the method according to any one of the first aspect.

[0027] According to a fourth aspect of the present disclosure, there is provided a communication device for wireless networking, including a processor and a memory. The processor is configured to call and run a computer program stored in the memory to execute the method according to any one of the second aspect.

[0028] According to a fifth aspect of the present disclosure, there is provided a computer-readable storage medium for storing a computer program, and the computer program causes a computer to execute the method according to any one of the first aspect.

[0029] According to a sixth aspect of the present disclosure, there is provided a computer-readable storage medium for storing a computer program, and the computer program causes a computer to execute the method according to any one of the second aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] With reference to the accompanying drawings, the above and other features of the present disclosure will become apparent, wherein,

[0031] Figure 1 FIG. shows a schematic structural diagram of a wireless network system taking a smart glasses as an example of a node according to an embodiment of the present disclosure;

[0032] Figure 2 FIG. shows a schematic structural diagram of a wireless network system according to another embodiment of the present disclosure;

[0033] Figure 3 FIG. shows a flowchart of a wireless networking communication method according to another embodiment of the present disclosure;

[0034] Figure 4 FIG. shows a schematic flow interaction diagram of a wireless networking communication method according to another embodiment of the present disclosure

[0035] Figure 5 FIG. shows a flowchart of a wireless networking communication method according to another embodiment of the present disclosure;

[0036] Figure 6 FIG. shows a schematic flow interaction diagram of a wireless networking communication method according to another embodiment of the present disclosure;

[0037] Figure 7 FIG. shows a schematic flow interaction diagram of a wireless networking communication method according to another embodiment of the present disclosure;

[0038] Figure 8 FIG. shows a schematic structural diagram of a communication device for wireless networking according to another embodiment of the present disclosure;

[0039] Figure 9 Shows a schematic structural diagram of a communication device for wireless networking provided by another embodiment of the present disclosure. Detailed implementation manners

[0040] It is easy to understand that according to the technical solution of the present disclosure, without changing the essence of the present disclosure, those of ordinary skill in the art can propose various interchangeable implementation manners. Therefore, the following detailed implementation manners and the accompanying drawings are only exemplary descriptions of the technical solution of the present disclosure, and should not be regarded as all of the present disclosure or as a limitation or restriction on the technical solution of the present disclosure.

[0041] The "first", "second", "third", etc. or similar expressions mentioned or possibly mentioned in this specification are only for descriptive and differentiating purposes, and should not be construed as indicating or implying the relative importance of the corresponding components.

[0042] The following will describe in detail the technical solutions disclosed in each embodiment of the present disclosure with reference to the accompanying drawings.

[0043] In the networking of wireless devices, each device needs to share with other devices. Refer to Figure 1 , there are 5 devices in the network. For example, device A needs to send the same message to the other four devices. It can broadcast the message to the other four devices through, but not limited to, Bluetooth BLE, WIFI, ZIGBEE, etc. However, in the current prior art, the information shared by device A is easily eavesdropped by other devices within the wireless network range except B, C, D, and E, resulting in problems such as the theft of user privacy, and security problems such as the simulation of false devices accessing the network will also occur.

[0044] Figure 2 According to the schematic structural diagram of the wireless network system provided by another embodiment of the present disclosure, as Figure 2 shown, the system architecture 200 includes network nodes and devices to be networked. Among them, the devices to be networked can be devices waiting to join the network, and the network nodes can be devices that have already joined the network or active devices that establish the network. Generally speaking, devices that have already joined the network or active devices that establish the network are called "nodes", and devices before joining the network are called "devices that can be networked" or "devices to be networked". Specifically, the network nodes include multiple nodes. For example, nodes A, C, and D have established a network. One or more nodes in the network actively send network beacons to indicate an invitation to access the network and listen for access requests from devices to be networked (such as device B and device E to be networked); or, by way of example, the network nodes only include one node A, then node A actively sends a network beacon to indicate that the device to be networked joins the network, thereby establishing the network.

[0045] It should be noted that the types of networks established include, but are not limited to, ring networks, bus networks, star networks, mesh networks, etc.

[0046] It should be understood that in the embodiments of the present application, the network node and the device to be networked can be electronic devices with end-to-end key negotiation capabilities. In one possible implementation, the node and the device to be networked can be routing devices, such as wireless switches for wireless networks, WiFi wireless routers, optical network terminals, WiFi wireless repeaters, or customer premise equipment (CPE) terminals, portable terminal hotspots, etc. In another possible implementation, the node and the device to be networked can be devices with routing functions, such as including wireless routers, smart TVs, large-screen devices, smart air conditioners, mobile phones, tablets, laptops, large-screen TVs, smart home products, personal digital assistants (PDAs), point of sales (POS), in-vehicle computers, wearable electronic devices, etc. In another possible implementation, the node and the device to be networked can be the same type of device or different types of devices, as long as the node and the device to be networked can establish a network. It should also be understood that in the embodiments of the present application, there can be multiple nodes. Among these multiple nodes, one is the main node, and the others are standby main nodes. When the main node fails and cannot work properly, one of the standby main nodes can replace the main node and work normally; the number of devices to be networked can also be one or more.

[0047] As Figure 3 , this embodiment discloses a communication method for wireless networking, which is applied to a network node and includes:

[0048] Step S300: Wirelessly broadcast a network beacon;

[0049] Step S310: Receive an access request from a device to be networked, where the access request includes the public key of the device to be networked;

[0050] Step S320: Generate a key using the public key of the device to be networked and the private key of the network node;

[0051] Step S330: Generate a first random number and encrypt the first random number using the key to obtain a random number ciphertext;

[0052] Step S340: Send the random number ciphertext and the public key of the network node to the device to be networked;

[0053] Step S350: Generate an authentication code using a random number generation algorithm and share the authentication code with the device to be networked through an out-of-band method;

[0054] It should be noted that step S340 can be carried out before step S350 or simultaneously, and there is no limitation here.

[0055] Step S360: Obtain a static key and a static key factor of the network node, and calculate a static encryption factor based on the static key and the static key factor;

[0056] Step S370: Calculate a network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor;

[0057] Step S380: Conduct encrypted communication with the device to be networked using the network communication key; among them, any device that can be networked stores a static key, the server stores a static key factor corresponding to the static key, the static encryption factor calculated from the static key of any device that can be networked and the corresponding static key factor is the same, and the static key of each device that can be networked and its corresponding static key factor are different from those of another device that can be networked.

[0058] It should be noted that a device that has already joined the network or an active device that establishes the network is called a "node", while a device before it joins the network is called an "admissible device" or "device to be networked". Different descriptions are only used to distinguish whether the device has joined the network. That is to say, before the network node joins the network, it is called an "admissible device". Similarly, the above-mentioned device to be networked can be called an "admissible device". Therefore, before multiple devices (i.e., admissible devices) establish a wireless network, a static encryption factor is preset for each of the multiple devices, and a static encryption factor is split into a static key and a static key factor. The static key is stored in the corresponding device, and the corresponding static key factor is stored in the server. At the same time, it is ensured that among the multiple devices (i.e., admissible devices), the static encryption factor calculated from the static key of any one device (i.e., admissible device) and the corresponding static key factor is the same, and the static key of each device (i.e., admissible device) and its corresponding static key factor are different from those of another device. With such a design, not only can a symmetric key be successfully negotiated after the multiple devices form a wireless network, and the multiple devices can use the same network communication key to encrypt and communicate with each other, but also the static key and the static key factor are stored in different places in a distributed manner, preventing attackers from attacking and improving the security of communication. Exemplarily, the multiple devices include Device 1, Device 2, and Device 3. A static key 1 and a corresponding static key factor 1 are preset for Device 1, a static key 2 and a corresponding static key factor 2 are preset for Device 2, and a static key 3 and a corresponding static key factor 3 are preset for Device 3. The static keys 1, 2, and 3 are stored in Device 1, Device 2, and Device 3 respectively, and the static key factors 1, 2, and 3 are all stored in the server. After Device 1, Device 2, and Device 3 establish a wireless network, that is, Device 1, Device 2, and Device 3 also become the corresponding Node 1, Node 2, and Node 3. When negotiating the symmetric key among Node 1, Node 2, and Node 3, it is necessary to obtain the static key encryption factors of each node. That is to say, based on the static key factor 1 and the static key 1, the static encryption factor 1 of Node 1 can be obtained. Similarly, the static encryption factor 2 of Node 2 and the static encryption factor 3 of Node 3 can also be obtained, and the static encryption factors 1, 2, and 3 are equal to each other, but the static key factors 1, 2, and 3, the static keys 1, 2, and 3 are not equal to each other. In this way, Node 1, Node 2, and Node 3 can uniformly negotiate the network communication key, and each node encrypts and communicates with each other. That is, for the encrypted data broadcast by Node 1 in the network, Node 2 and Node 3 can both decrypt the encrypted data broadcast by Node 1.It is understandable that the number of devices required to form a network is at least 2, such as 2, 3, 4, etc., which is not limited here.

[0059] In this embodiment, before the network node and the device to be networked form a wireless network, the static encryption factors of the network node and the device to be networked are split into static keys and corresponding static key factors, which are respectively stored locally on the device and in the server, and it is ensured that the static keys of each device and their corresponding static key factors are different from those of another device, and the static encryption factors of each device are the same. Using the distributed storage method can prevent attackers from easily obtaining the static encryption factors of the devices and improve the security of network communication. And based on the above settings, other devices to be networked can also negotiate the same network communication key to achieve unobstructed communication between each node in the network, improving the efficiency and flexibility of communication. At the same time, in the key negotiation, multiple random algorithms are used to further increase the randomness of the negotiation and improve network security. To make it easier to understand Figure 2 the embodiment, taking the communication interaction between network node A and the device B to be networked as an example, continue to refer to Figure 4 This embodiment discloses a communication method for wireless networking, which is applied to a network node A and includes:

[0060] Step S400, wirelessly broadcast a network beacon;

[0061] Specifically, in combination with Figure 2 description, in a possible embodiment, for example, nodes A, C, and D in the network node have established a wireless mesh network. Nodes in the wireless mesh network need to share information with the device B to be networked. The network node needs to broadcast a network beacon to indicate the device B to be networked to join the network. Specifically, a node in the wireless mesh network can be used as the master device to broadcast the network beacon, or multiple nodes in the wireless mesh network can broadcast the network beacon simultaneously; in another case, if node A has not established a network with other nodes and node A needs to share information with the device B to be networked and / or the device E to be networked, then taking node A as the master node, it actively broadcasts a network beacon to create a shared device network to indicate the device node B to be networked and / or the device E to be networked to establish a network with node A;

[0062] In some embodiments, the broadcast method can be implemented through Bluetooth BLE, WIFI, ZIGBEE, etc.;

[0063] In some embodiments, the network beacon includes at least one piece of information such as a network number (NetId), a network name (Name), a UUID, etc. Exemplarily, the network beacon can be represented as: Name: "Node A"; NetId: 000123; The network beacon can also be represented only by the network number (NetId), which is a random number generated by a network node, such as a 6-byte random number.

[0064] Step S410: Receive an access request from a device to be accessed to the network, where the access request includes the public key of the device to be accessed to the network.

[0065] Specifically, after a device to be accessed to the network (Device B to be accessed to the network) detects the network beacon of a network node (Network Node A), the device to be accessed to the network encapsulates its own public key in the access request based on the network beacon and sends it to Network Node A to indicate its willingness to join the network.

[0066] Step S420: Generate a key using the public key of the device to be accessed to the network and the private key of the network node.

[0067] Specifically, for example, after Network Node A receives the public key (PubKey B ) of the device to be accessed to the network, based on the private key (PriKey A ) of Network Node A , uses an encryption algorithm to calculate the key (EcKey A ), for example, the ECDH (Elliptic Curve Diffie-Hellman Key Exchange) algorithm, that is, EcKey A = ECDH(PubKey B , PriKey A ). It can be understood that the ECDH key negotiation algorithm combines the ECC algorithm and the DH key exchange principle for key negotiation. Using the ECDH algorithm for calculation can further improve the security of communication between network devices.

[0068] It should be noted that in addition to using the ECDH algorithm, in some embodiments, the ECDHE (Ephemeral Elliptic Curve Diffie-Hellman Key Exchange) algorithm, the SM2 algorithm, etc. can also be used to generate the key (EcKey A ), which is not limited here.

[0069] Step S430: Generate a first random number and encrypt the first random number using the key to obtain a ciphertext of the random number.

[0070] Specifically, to further improve the security between devices in the network, Network Node A generates a first random number (R) and encrypts the first random number (R) through the key (EcKey A ) to obtain a ciphertext of the random number.

[0071] Step S440: Send the random number ciphertext and the public key of the network node to the device to be networked;

[0072] Specifically, network node A sends the random number ciphertext and its own public key to device B to be networked, so that device B to be networked can decrypt the random number ciphertext.

[0073] Step S460: Generate an authentication code using a random number generation algorithm and share the authentication code with the device to be networked through an out-of-band method;

[0074] Specifically, when network node A receives the network access request from device B to be networked, it means that a network connection is initially established between network node A and device B to be networked. Then network node A uses a random number generation algorithm to generate a random number (such as a 6-digit random number) as the authentication code (AuthCode) for joining the network. And it is shared with device B to be networked that needs to join the network through an out-of-band method (such as SMS message, oral notification, WeChat message, etc.) for authentication.

[0075] In some embodiments, the network node is built-in with a Cryptographically Secure Pseudorandom Number Generator (CSPRNG), which uses a technical combination from a Pseudorandom Number Generation algorithm (PRNG) and a True Random Number Generation (TRNG) to generate a first random number (R) that is both unpredictable and statistically random. Specifically, for example, when the network node is a smart glasses, the noise sampling from the glasses microphone can be used as the random number generation seed.

[0076] In some embodiments, the standard process of out-of-band (OOB) authentication may include a no out-of-band (NoOOB) authentication process, a static out-of-band (Static OOB) authentication process, an input out-of-band (Input OOB) authentication process, and an output out-of-band (Output OOB) authentication process.

[0077] It should be noted that step S440 can be before step S460 or can be carried out simultaneously, and there is no limitation here.

[0078] Step S480: Obtain the static key factor of the network node from the server;

[0079] It should be noted that in the prior art, a static key with a fixed value is set and stored in the device before the device leaves the factory. However, based on the current technology, it is easy for a man-in-the-middle to crack the static key of the device, resulting in the insecurity of network device communication. Therefore, in order to further improve communication security, in this embodiment, before the network node leaves the factory, the static key of the network node is divided into two parts, one part is stored in the network node itself, and the other part is stored in the server. Exemplarily, the preset static key of network node A is SKey A , and the static key factor is Y A , SKey A and Y A have a functional relationship. Store SKey A in network node A, and store Y A in the server. Finally, calculate the static encryption factor (S A ) of network node A through a pre-designed calculation method. For example, use the sum of squares calculation, and the specific formula is expressed as:

[0080] S = SKey 2 +(Y) 2

[0081] (where S represents the static encryption factor of the node, one of SKey and Y represents the static key of the node, and the other represents the static key factor). It can be understood that SKey A can be stored in the server as the static key factor of network node A, and Y A can be stored locally as the static key of network node A, and there is no limitation here.

[0082] In the embodiment of the present application, by dividing the static key of the node into two parts and storing them in different places, and finally performing certain encryption calculations, in this way, it is avoided that a man-in-the-middle easily cracks the static key stored locally by the node, and the communication security of the node in the network is improved.

[0083] Specifically, after the device B to be networked listens and scans the network signal of the network node, it will notify the user of the device B to be networked to input an authentication code (before this, the authentication code has been shared with the user of the device B to be networked by the network node A through an out-of-band method). In some embodiments, the notification methods include but are not limited to voice broadcast, pop-up prompt window, etc.; in some embodiments, the methods for the user to input the authentication code include but are not limited to voice input, input on the interface popped up by the device B to be networked, etc.

[0084] Further, after the user inputs the authentication code, that is, when the network node knows that the device to be networked has passed the authentication, the network node will look up its own static key factor from the server. It should be understood that the server stores the static key factors of all nodes (network nodes and devices to be networked), and the static key factor of each node (network node and device to be networked) is stored in the server in association with the corresponding identifier. Exemplarily, the identifier can be the SN number, SN (Serial Number), and the SN number is the digital identifier of the product identity, the unique ID card of the product, which gives a legal mark to each product and ensures the uniqueness and authenticity of the product. Generally, the SN serial number has other aliases, such as authentication code, registration application code, etc. The network node A sends a service request to the server, and the service request carries the SN number of the network node A. The server receives and parses the service request, obtains the SN number of the network node A, queries the static key factor of the network node A in the database according to the SN number, and sends the static key factor to the network node A.

[0085] Alternatively, in some embodiments, the identifier can also be related to information such as the MAC address, UUID, IP address, production date of the node, etc. In short, as long as a unique mapping relationship between different identifiers and the static key factors of different nodes can be formed and stored in the server.

[0086] Or, in some embodiments, since there is a static key (SKey) in each node, and there is a functional relationship between each static key and a corresponding static key factor (Y), the static key factor can also be stored in the server by associating the static key with the static key factor based on this functional relationship.

[0087] Step S500: Calculate the static encryption factor based on the static key of the network node and the corresponding static key factor;

[0088] In one embodiment, the static encryption factor (S A ) of the network node A can be calculated through a pre-designed calculation method, such as using the sum of squares calculation.

[0089] Step S520: Calculate the network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor

[0090] Specifically, the network beacon, the first random number (R), the authentication code (AuthCode), and the static encryption factor (S) of the network node A are subjected to an encryption algorithm to obtain the network communication key (NetKey). In some embodiments, the encryption algorithm can be a hash algorithm, such as the SHA-1 and / or SHA-2 algorithms.

[0091] Step S540: Conduct encrypted communication with the device to be networked using the network communication key;

[0092] It should be noted that since the network communication key (NetKey) itself is not transmitted in the network and is generated by the static encryption factor (S), random number (R), and authentication code (AuthCode), it has relatively high security. Also, since the random number (R), authentication code (AuthCode), and static encryption factor (S) of the device to be networked are the same, the network communication key (NetKey) calculated by the device to be networked is also the same. To ensure that the static key factors calculated by each node (including network nodes and devices to be networked) are consistent, the following preset is performed on the devices to be networked before device networking: A static key is stored in any device that can be networked (i.e., network node / device to be networked), and the server stores the static key factor corresponding to the static key, and it is ensured that the static encryption factor calculated from the static key of any device that can be networked (i.e., network node / device to be networked) is the same as the corresponding static key factor, and at the same time, the static key of each device that can be networked (i.e., network node / device to be networked) and its corresponding static key factor are different from those of another device that can be networked (i.e., network node / device to be networked). Therefore, after the above preset, all nodes in the network can not only communicate with each other using the same network communication key (NetKey), but also improve the security of communication.

[0093] In one embodiment, to ensure that the static encryption factors (S) obtained by each device in the network (such as Figure 2 node A, node C, node D shown) and devices to be networked (such as Figure 2 device to be networked B and device to be networked E shown) are consistent, and the above devices can negotiate the same network communication key (NetKey) to communicate with each other. Specifically, the static key and static key factor of the device that can be networked (network node / device to be networked) are preset in the following way:

[0094] Step S1: Randomly assign a solution value (x, y) to a device that can be networked on the preset function, where the solution values (x, y) of different devices that can be networked are not the same;

[0095] It can be understood that a device that has already joined the network or an active device that establishes the network can be called a "node"; while a device before it joins the network can only be called a "device that can be networked" or "device to be networked", and cannot be described as a "node". Different descriptions are only used to distinguish the state of whether the device has joined the network. That is, referring to Figure 2, before nodes A, C, and D form a network, they are respectively network - connectable devices A, C, and D. And the preset static keys and static key factors for the devices are set before the devices establish a network. Therefore, based on the status of whether the devices have formed a network, in this step S1, exemplarily, for network - connectable device A, network - connectable device C, network - connectable device D, to - be - networked device B (also known as network - connectable device B), and to - be - networked device E (also known as network - connectable device E), there are respectively set 5 solution values corresponding to (x1, y1), (x2, y2), (x3, y3), (x4, y4), (x5, y5), and these 5 solution values are not equal to each other. Further, the x - value and the y - value can be obtained by simulating sampling through a preset function. Step S2: Determine a random constant K;

[0096] Step S3: Multiply the x - value and the y - value in the solution values by the random constant K respectively, calculate to obtain two product values of the x - value and the K - value and the y - value and the K - value. Set one of the two product values as the static key factor and store it in the server, and set the other as the static key and store it in the node; that is, set one of x*K and y*K as the static key (SKey) and store it in the node, and set the other as the static key factor (Y) and store it in the server.

[0097] In some other embodiments, the preset function is as follows:

[0098] x 2 +y 2 =R 2

[0099] It should be noted that in the program, for the sampling of numerical values, the number of digits stored is limited. Therefore, it is necessary to first determine the number of digits of R. For example, R takes 2 digits after the decimal point (such as R = 67.16) or R takes 6 digits (such as R = 5.11125). In this way, it can be ensured that multiple different (x, y) values can finally calculate the same R 2 value.

[0100] In this embodiment, by presetting the static keys and static key factors of each node in a distributed storage manner, it can prevent a man - in - the - middle from easily cracking the static keys in the node devices. At the same time, different static keys and static key factor values are simulated through the same preset function relationship, so as to ensure that each node in the wireless network can communicate with each other smoothly.

[0101] Such as Figure 5 , this embodiment discloses a communication method for wireless networking, which is applied to a to - be - networked device and includes:

[0102] Step S600: Receive the network beacon of the network node;

[0103] Step S610: Send an access request to the network node based on the network beacon. The access request includes the public key of the device to be accessed to the network.

[0104] Step S620: Receive the ciphertext of the random number and the public key of the network node sent by the network node based on the access request, as well as the authentication code shared by the network node through an out-of-band method.

[0105] Step S630: Decrypt the ciphertext of the random number using the public key of the network node and the private key of the device to be accessed to the network to obtain the first random number.

[0106] Step S640: Obtain a static key and a static key factor of the device to be accessed to the network, and calculate a static encryption factor based on the static key and the static key factor.

[0107] Step S650: Calculate a network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor.

[0108] Step S660: Conduct encrypted communication with the network node using the network communication key; wherein, any device that can access the network stores a static key, the server stores the static key factor corresponding to the static key, the static encryption factor calculated from the static key of any device that can access the network and the corresponding static key factor is the same, and the static key of each device that can access the network, the corresponding static key factor, and those of another device that can access the network are different.

[0109] It should be noted that a device that has already joined the network or an active device that establishes the network is called a "node", while a device before it joins the network is called an "attachable device" or "device to be attached to the network". Different descriptions are only used to distinguish whether the device has joined the network. That is to say, before the network node joins the network, it is called an "attachable device". Similarly, the above-mentioned device to be attached to the network can be called an "attachable device". Therefore, before multiple devices (i.e., devices to be attached to the network / attachable devices) establish a wireless network, a static encryption factor is preset for each of the multiple devices, and a static encryption factor is split into a static key and a static key factor. A static key is stored in the corresponding device, and the corresponding static key factor is stored in the server. At the same time, it is ensured that among the multiple devices (i.e., devices to be attached to the network / attachable devices), the static encryption factor calculated from the static key of any one device (i.e., device to be attached to the network / attachable device) and the corresponding static key factor is the same, and the static key of each device (i.e., device to be attached to the network / attachable device) and its corresponding static key factor are different from those of another device. With such a design, not only can a symmetric key be successfully negotiated after the multiple devices form a wireless network, and the multiple devices can use the same network communication key to encrypt and communicate with each other, but also the static key and the static key factor are stored in different places in a distributed manner, preventing attackers from attacking and improving the security of communication.

[0110] In this embodiment, before the devices to be attached to the network form a wireless network, the static encryption factor of the devices to be attached to the network is split into a static key and the corresponding static key factor, and they are respectively stored locally in the device and in the server, and it is ensured that the static key of each device and its corresponding static key factor are different from those of another device, and the static encryption factor of each device is the same. By using the distributed storage method, it is possible to prevent attackers from easily obtaining the static encryption factor of the device and improve the security of network communication. And based on the above settings, it is also possible for other devices to be attached to the network to negotiate the same network communication key to achieve unobstructed communication between each node in the network, improving the efficiency and flexibility of communication. At the same time, in the key negotiation, multiple random algorithms are used to further increase the randomness of the negotiation and improve network security.

[0111] For a further easier understanding Figure 5 of the embodiment, taking the communication interaction between network node A and the device B to be attached to the network as an example, continue to refer to Figure 4 , this embodiment of the present application also discloses a communication method, which is applied to the device B to be attached to the network and includes:

[0112] Step 400, receiving a network beacon of the network node;

[0113] It should be noted that this step is similar to the technical principle described above and will not be repeated here.

[0114] Step S410: Send an access request to the network node based on the network beacon, where the access request includes the public key of the device to be accessed.

[0115] Specifically, after the device B to be accessed listens to the network beacon of the network node A through wireless communication, it sends an access request carrying its own public key to the network node A to indicate joining the network established by the network node A. The wireless communication method may include but is not limited to Bluetooth Low Energy (BLE), Wi-Fi, ZigBee, etc. In some embodiments, the network beacon includes at least one piece of information such as a network ID (NetId), a network name (Name), a UUID, etc. Exemplarily, when the network beacon is a network ID (NetId), the network node A can generate a random number, such as a 6-byte random number as the network ID (NetId).

[0116] Step S440: Receive the ciphertext of the random number of the network node and the public key of the network node.

[0117] Exemplarily, the network node A will generate a first random number (R). After receiving the public key (PubKey B ) of the device B to be accessed, based on the private key (PriKey A ) of the network node A and the public key (PubKey B ) of the device B to be accessed, use the Elliptic Curve Diffie-Hellman (ECDH) encryption algorithm to calculate the encryption key (EcKey A ), and finally encrypt the first random number (R) using the encryption key (EcKey A ) to obtain the ciphertext of the random number. The specific implementation principle can be referred to above and will not be repeated here.

[0118] Step S450: Decrypt the ciphertext of the random number using the public key of the network node and the private key of the device to be accessed to obtain the first random number.

[0119] Step S470: Obtain the authentication code shared by the network node through an out-of-band method.

[0120] In some embodiments, the standard process of out-of-band (OOB) authentication may include a no-out-of-band (NoOOB) authentication process, a static out-of-band (Static OOB) authentication process, an input out-of-band (Input OOB) authentication process, and an output out-of-band (Output OOB) authentication process.

[0121] It should be noted that step S440 can be before step S470 or can be carried out simultaneously, and there is no limitation here.

[0122] Step S490: Receive the static key factor sent by the server;

[0123] It should be understood that how to preset the static key factor of the device B to be networked and how the device B to be networked specifically obtains the static key factor of the device B from the server are similar to the principles described above and will not be repeated here.

[0124] Step S510: Calculate the static encryption factor based on the static key of the device to be networked and the corresponding static key factor;

[0125] It should be noted that in order for the network node and the device B to be networked to negotiate a symmetric key, that is, the network node and the device B to be networked can each calculate the same encrypted communication key (NetKey). Therefore, the static encryption factors calculated by the network node A and the device B to be networked must be the same. Therefore, before device networking, the following presets are made for the devices to be networked: Any device that can be networked (i.e., network node / device to be networked) stores a static key, and the server stores the static key factor corresponding to the static key, and it is ensured that the static encryption factor calculated from the static key of any device that can be networked (i.e., network node / device to be networked) and the corresponding static key factor is the same. At the same time, the static key of each device that can be networked (i.e., network node / device to be networked) and its corresponding static key factor are different from those of another device that can be networked (i.e., network node / device to be networked).

[0126] Exemplarily, in combination with Figure 2 , it includes network nodes A, C, D, and devices B and E to be networked. Before networking, the above 5 devices have respectively preset and stored static keys A, B, C, D, and E on their own, and these 5 static keys are all different; in addition, static key factors A, B, C, D, and E are respectively set corresponding to these 5 static keys. These 5 static key factors are all stored in the server, and these 5 static key factors are all different, but the static encryption factors of the 5 devices (A, B, C, D, E) calculated based on the above static keys and static key factors are all the same, that is: Static key A + Static key factor A = Static key B + Static key factor B = Static key C + Static key factor C = Static key D + Static key factor D = Static key E + Static key factor E;

[0127] In some embodiments, in order to enable each network-accessible device (including one or more of the above-mentioned devices to be networked and / or one or more of the above-mentioned network nodes) to calculate the same static encryption factor in the network negotiation key even when different static keys are preset in the locals of different network-accessible devices, and to ensure that symmetric keys can be negotiated with each other, a function equation based on a planar circle (such as x 2 +y 2 =R 2 ) can be used to preset the static key and static key factor of each network-accessible device. The specific presetting method is the same as the principle disclosed above and will not be repeated here.

[0128] Step S530: Calculate the network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor;

[0129] Specifically, the device B to be networked performs an encryption algorithm on the network beacon, the first random number (R), the authentication code (AuthCode), and the static encryption factor (S) of the network node to obtain the network communication key (NetKey). In some embodiments, the encryption algorithm can be a hash algorithm, such as the SHA-1 and / or SHA-2 algorithms.

[0130] S540: Perform encrypted communication with the network node using the network communication key;

[0131] It should be noted that, similarly, other devices to be networked, such as Figure 2 the device E to be networked can negotiate the network communication key (NetKey) with the network node A based on the method disclosed in this embodiment. Then, the data communicated between the network node A, the device B to be networked, and the device E to be networked can be encrypted and decrypted with each other. It should be understood that when encrypting the same type of numerical values during key negotiation between two devices or multiple devices, the same encryption algorithm needs to be used. Exemplarily, if the device B to be networked uses the SHA-1 algorithm when performing the encryption operation on the network communication key (NetKey), correspondingly, the network node A also needs to use the SHA-1 algorithm when performing the encryption operation on the network communication key (NetKey) to ensure that symmetric keys can be negotiated between different nodes.

[0132] In the embodiments of the present application, by presetting the static key and static key factor of each device in a distributed storage manner, it is possible to prevent a man-in-the-middle from easily cracking the static key in the node device. At the same time, different static keys and static key factor values are simulated through the same preset function relationship, so as to ensure that each device in the wireless network can communicate with each other smoothly.

[0133] Such as Figure 6, an embodiment of the present application also discloses a device authentication method applied to a network node. Before the network node encrypts and communicates with the network node using a network communication key, the method specifically includes:

[0134] Step S710: Receive a second random number and a first confirmation value of the device to be connected to the network;

[0135] Specifically, the second random number (RandomB) of the device B to be connected to the network can be generated according to a random algorithm. The specific implementation of generating the second random number (RandomB) is similar to the above-mentioned technical principle and will not be repeated here; the first confirmation value (ConfirmationB) of the device B to be connected to the network is generated based on the second random number (RandomB), the network communication key (NetKey), the network beacon, and the authentication code (AuthCode) through an encryption algorithm. Further, first, the second random number (RandomB), the network beacon, and the authentication code (AuthCode) are hashed through an irreversible hash algorithm to obtain a hash value, and then the network communication key (NetKey) is used to perform a symmetric encryption algorithm (Enc1) on the hash value, and finally the first confirmation value (ConfirmationB) is calculated. Among them, the irreversible hash algorithm includes, but is not limited to, algorithms such as MD5, SHA-1, SHA-2, and SHA-256, and the symmetric encryption algorithm (Enc1) includes, but is not limited to, algorithms such as AES, DES, and RC4.

[0136] Step S720: Calculate a third confirmation value based on the second random number, the network communication key, the network beacon, and the authentication code, and verify the first confirmation value with the third confirmation value;

[0137] Specifically, based on the second random number (RandomB), network communication key (NetKey), network beacon, and authentication code (AuthCode), network node A calculates the third confirmation value (ConfirmLocalA) through an encryption algorithm. The process principle of calculating the third confirmation value (ConfirmLocalA) is similar to that of calculating the first confirmation value (ConfirmationB), which will not be repeated here. Then, it verifies the first confirmation value (ConfirmationB). If the verification is successful, that is, the third confirmation value (ConfirmLocalA) is equal to the first confirmation value (ConfirmationB), it indicates that network node A and the device B to be networked have successfully negotiated a symmetric key, which means that network node A and the device B to be networked can use the same key to encrypt and decode data. If the verification fails, it means that the device B to be networked is not a legitimate device and the network joining fails. It should be understood that when different nodes perform encryption operations on their respective confirmation values, the same encryption algorithm needs to be used. Exemplarily, if network node A uses the AES algorithm to perform the encryption operation on the third confirmation value (ConfirmLocalA), correspondingly, the device B to be networked also needs to use the AES algorithm to perform the encryption operation on the first confirmation value (ConfirmationB).

[0138] In the embodiments of the present application, adding the device authentication process can further improve the security of network communication and avoid common attacks such as man-in-the-middle and replay attacks.

[0139] Such as Figure 6 , the embodiments of the present application also disclose a device authentication method applied to a device to be networked. Before the network node encrypts and communicates with the network node using the network communication key, the method specifically includes:

[0140] Step S700: Receive the third random number and the second confirmation value of the network node

[0141] Exemplarily, the third random number (RandomA) of network node A can be generated according to a random algorithm. The specific implementation method of generating the third random number (RandomA) is similar to the above-mentioned technical principle and will not be repeated here. The second confirmation value (ConfirmationA) of the network node is calculated through an encryption algorithm based on the third random number (RandomA), network communication key (NetKey), network beacon, and authentication code (AuthCode). The specific calculation process principle of the second confirmation value (ConfirmationA) is similar to the above disclosure and will not be repeated here.

[0142] Step S740: Calculate a fourth confirmation value based on the third random number, the network communication key, the network beacon, and the authentication code, and use the fourth confirmation value to verify the second confirmation value

[0143] Exemplarily, the device B to be networked calculates a fourth confirmation value (ConfirmLocalB) based on the third random number (RandomA), the network communication key (NetKey), the network beacon, and the authentication code (AuthCode) through an encryption algorithm, and verifies the second confirmation value (ConfirmationA). If the verification is successful, that is, the fourth confirmation value (ConfirmLocalB) is equal to the second confirmation value (ConfirmationA), it indicates that the network node A and the device B to be networked have successfully negotiated a symmetric key, that is, the network node A and the device B to be networked can use the same key to encrypt and decrypt data; if the verification is not successful, it indicates that the device B to be networked is not a legitimate device and the network joining fails. The specific calculation process principle of the fourth confirmation value (ConfirmLocalB) is similar to that disclosed above. For the sake of brevity, it will not be repeated here.

[0144] In the embodiments of the present application, adding the device authentication process can further improve the security of network communication and avoid common attacks such as man-in-the-middle and replay attacks.

[0145] Such as Figure 7 , the embodiments of the present application also disclose a communication method applied to a network node. In the process of the network node encrypting and communicating with the network node using the network communication key, the method specifically includes:

[0146] Step S800: Encrypt and sign the communication data with the network communication key to obtain a communication ciphertext;

[0147] Step S810: Send the communication ciphertext to the device to be networked;

[0148] It should be understood that when the node communicates, in order to verify whether the communication data in the communication process has been tampered with by an attacker and improve the reliability and security of the data, it is necessary to perform message signing (MAC, Message authentication code) on the communication data.

[0149] Exemplarily, the hash algorithm can be used to sign the communication data. Specifically, the network node encrypts the communication data with the network communication key (NetKey) using a symmetric encryption algorithm to obtain a ciphertext, and then uses the Hash function to calculate the hash value of the communication data, and splices the hash value to the ciphertext to form a communication ciphertext.

[0150] In the embodiments of the present application, the legitimacy of a device can be further verified during communication by means of message signature, improving the security of network communication and avoiding common attacks such as man-in-the-middle attacks and replay attacks.

[0151] For example Figure 7 , the embodiments of the present application also disclose a communication method applied to a device to be networked. During the process of encrypted communication between the network node and the network node using the network communication key, the method specifically includes:

[0152] Step S810: Receive the communication ciphertext sent by the network node;

[0153] Step S820: Decrypt the communication ciphertext sent by the network node and verify the communication cipher;

[0154] It should be understood that when the node communicates, in order to verify whether the communication data during the communication process has been tampered with by an attacker and improve the reliability and security of the data, the communication data needs to be message-signed (MAC, Message Authentication Code). When the receiving party (i.e., the device to be networked) receives the signed communication data sent by the sending party (i.e., the network node), it needs to verify whether the communication data is legal before processing the communication data.

[0155] Exemplarily, the sending party (i.e., the network node) signs and encrypts the communication data using a hash function and an encryption algorithm and then sends it to the receiving party (i.e., the device to be networked). When the receiving party (i.e., the device to be networked) receives the communication ciphertext sent by the sending party (i.e., the network node), after decrypting the communication ciphertext using the network communication key (NetKey), it obtains the communication data and the hash value of the communication data. The receiving party then uses the communication data to calculate the hash value through the hash function to verify whether the hash value sent by the sending party is the same. If they are the same, it proves that the communication data is legal and valid, and then the receiving party processes the communication data.

[0156] In the embodiments of the present application, the legitimacy of a device can be further verified during communication by means of message signature, improving the security of network communication and avoiding common attacks such as man-in-the-middle attacks and replay attacks.

[0157] The embodiments of the present application also disclose a network node applied to wireless networking, including:

[0158] A broadcast unit configured to wirelessly broadcast a network beacon;

[0159] A first receiving unit configured to receive an access request from a device to be networked, where the access request includes the public key of the device to be networked;

[0160] A first processing unit, configured to generate a key using the public key of the device to be networked and the private key of the network node;

[0161] A second processing unit, configured to generate a first random number and encrypt the first random number using the key to obtain a ciphertext of the random number;

[0162] A first sending unit, configured to send the ciphertext of the random number and the public key of the network node to the device to be networked;

[0163] A third processing unit, configured to generate an authentication code using a random number generation algorithm and share the authentication code with the device to be networked in an out-of-band manner;

[0164] A fourth processing unit, configured to obtain a static key and a static key factor of the network node, and calculate a static encryption factor based on the static key and the static key factor;

[0165] A fifth processing unit, configured to calculate a network communication key based on the network number, the first random number, the authentication code, and the static encryption factor;

[0166] A first communication unit, configured to perform encrypted communication with the device to be networked using the network communication key;

[0167] Wherein, any device that can be networked stores a static key, the server stores a static key factor corresponding to the static key, the static encryption factors calculated from the static keys of any device that can be networked and the corresponding static key factors are the same, and the static keys of each device that can be networked and their corresponding static key factors are different from those of another device that can be networked.

[0168] An embodiment of the present application also discloses a device to be networked, applied to wireless networking, including:

[0169] A listening unit, configured to receive a network beacon of the network node;

[0170] A second sending unit, configured to send an access request to the network node based on the network beacon, where the access request includes the public key of the device to be networked;

[0171] A sixth processing unit, configured to receive the ciphertext of the random number and the public key of the network node sent by the network node based on the access request, and the authentication code shared by the network node in an out-of-band manner;

[0172] A seventh processing unit, configured to decrypt the ciphertext of the random number using the public key of the network node and the private key of the device to be networked to obtain the first random number;

[0173] An eighth processing unit, configured to obtain a static key and a static key factor of the device to be networked, and calculate a static encryption factor based on the static key and the static key factor;

[0174] A ninth processing unit, configured to calculate a network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor;

[0175] A second communication unit, configured to perform encrypted communication with the network node using the network communication key;

[0176] Wherein, any device that can be networked stores a static key, the server stores a static key factor corresponding to the static key, the static encryption factor calculated from the static key of any device that can be networked and the corresponding static key factor is the same, and the static key of each device that can be networked and its corresponding static key factor are different from those of another device that can be networked.

[0177] It should be understood that the device embodiments and the method embodiments can correspond to each other, and similar descriptions can refer to the method embodiments.

[0178] This application embodiment also discloses a communication device, refer to Figure 8 , including a memory 910, a processor 900, and a computer program 920 stored on the memory 910 and operable on the processor 700;

[0179] Optionally, this communication device is applied to a network node, and when the processor 900 executes the computer program, it executes the corresponding processes implemented by the network node in each method of this application embodiment.

[0180] This application embodiment also discloses a communication device, refer to Figure 9 , including a memory 1100, a processor 1000, and a computer program 1200 stored on the memory 1100 and operable on the processor 1000;

[0181] Optionally, this communication device is applied to a device to be networked, and when the processor 1000 executes the computer program, it executes the corresponding processes implemented by the device to be networked in each method of this application embodiment.

[0182] This application embodiment also provides a computer storage medium, in which computer instructions are stored, and when the computer instructions run on a terminal device, the terminal device is caused to execute the method implementing this application embodiment;

[0183] Optionally, this computer storage medium can be applied to the network node in this application embodiment, and the computer instructions cause the terminal device to execute the corresponding processes implemented by the network node in each method of this application embodiment.

[0184] The embodiments of the present application further provide a computer storage medium, in which computer instructions are stored. When the computer instructions run on a terminal device, the terminal device is enabled to execute the method of the embodiments of the present application;

[0185] Optionally, the computer storage medium can be applied to the device to be networked in the embodiments of the present application, and the computer instructions enable the terminal device to execute the corresponding processes implemented by the device to be networked in each method of the embodiments of the present application.

[0186] In addition, the embodiments of the present application further provide a device, which may specifically be a chip, a component or a module. The device may include a processor and a memory connected to each other. Among them, the memory is used to store a computer program. When the device runs, the processor may execute the computer program stored in the memory, so that the chip executes the methods in the above method embodiments.

[0187] Among them, the network device, terminal device, device to be networked, network node, computer storage medium, computer program product or chip provided in the embodiments of the present application are all used to execute the corresponding methods provided above. Therefore, the beneficial effects that can be achieved by them can refer to the beneficial effects in the corresponding methods provided above, and will not be elaborated here.

[0188] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and brevity of description, only the above division of each functional module is used as an example. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.

[0189] In the several embodiments provided by the present application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point, the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces, and the indirect coupling or communication connection of the device or unit may be in an electrical, mechanical or other form.

[0190] When an integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The software product is stored in a storage medium and includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods of the various embodiments of the present application.

[0191] The processors mentioned above may include, but are not limited to: general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor can be used to implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The steps of the methods disclosed in combination with the embodiments of the present application can be directly embodied as being executed by a hardware decoding processor, or executed by a combination of hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and combines its hardware to complete the steps of the above methods.

[0192] The memories mentioned above include, but are not limited to: volatile memories and / or non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synch link dynamic random access memory (SLDRAM), and direct rambus random access memory (DR RAM).

[0193] It should be noted that the memories described herein are intended to include these and any other suitable types of memories.

[0194] The above content is only a specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A wireless networking communication method, applied to a network node, characterized in that: include: Wirelessly broadcast a web beacon; Receiving a network access request from a device to be networked, wherein the network access request includes a public key of the device to be networked; Generate a key using the public key of the device to be connected to the network and the private key of the network node; Generate a first random number, and encrypt the first random number using the key to obtain a random number ciphertext; Sending the random number ciphertext and the public key of the network node to the device to be networked; Generate an authentication code using a random number generation algorithm, and share the authentication code with the device to be connected to the network in an out-of-band manner; Obtaining a static key and a static key factor of the network node, and calculating a static encryption factor based on the static key and the static key factor; Calculating a network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor; and Use the network communication key to perform encrypted communication with the device to be connected to the network; Among them, any network-accessible device stores a static key, and the server stores a static key factor corresponding to the static key. The static key of any network-accessible device is the same as the static encryption factor calculated by the corresponding static key factor. The static key of each network-accessible device and the static key factor corresponding to it are different from those of another network-accessible device.

2. The communication method according to claim 1, characterized in that: in, For network-accessible devices, preset static keys and static key factors by following the steps below: S1. Randomly assign a solution value (x, y) to a network-accessible device based on a preset function, wherein the solution values ​​(x, y) of different network-accessible devices are not the same; S2. Determine a random constant K; S3, multiplying the x value and the y value in the solution value by the random constant K respectively, calculating two product values ​​of the x value and the K value and the y value and the K value, setting one of the two product values ​​as a static key factor and storing it in the server, and setting the other as a static key and storing it in the network-accessible device; The preset function is as follows: x 2 +y 2 =R 2 。 3. The communication method according to claim 1, characterized in that: Before using the network communication key to perform encrypted communication with the device to be connected to the network, the following step is also included: Receive a first confirmation value and a second random number of the device to be connected to the network; Calculating a third confirmation value based on the second random number, the network communication key, the network beacon, and the authentication code; It is determined that the first confirmation value is equal to the third confirmation value, and it is determined that the key negotiation between the network node and the device to be networked is successful.

4. A wireless networking communication method, characterized in that: Applied to a device to be connected to the network, including: Receive network beacons from network nodes; Sending a network access request to the network node based on the network beacon, wherein the network access request includes a public key of the device to be networked; Receiving a random number ciphertext and a public key of the network node sent by the network node based on the network access request, and an authentication code shared by the network node in an out-of-band manner; Decrypting the random number ciphertext using the public key of the network node and the private key of the device to be connected to the network to obtain a first random number; Obtaining a static key and a static key factor of the device to be connected to the network, and calculating a static encryption factor based on the static key and the static key factor; Calculating a network communication key based on the network beacon, the first random number, the authentication code, and the static encryption factor; and Use the network communication key to perform encrypted communication with the network node; Among them, any network-accessible device stores a static key, and the server stores a static key factor corresponding to the static key. The static key of any network-accessible device is the same as the static encryption factor calculated by the corresponding static key factor. The static key of each network-accessible device and the static key factor corresponding to it are different from those of another network-accessible device.

5. The communication method according to claim 4, characterized in that: For network-accessible devices, preset static keys and static key factors by following the steps below: S1. Randomly assign a solution value (x, y) to a network-accessible device based on a preset function, where the solution values ​​(x, y) of different nodes are not the same; S2. Determine a random constant K; S3, multiplying the x value and the y value in the solution value by the random constant K respectively, calculating two product values ​​of the x value and the K value and the y value and the K value, setting one of the two product values ​​as a static key factor and storing it in the server, and setting the other as a static key and storing it in the network-accessible device; The preset function is as follows: x 2 +y 2 =R 2 。 6. The communication method according to claim 4, characterized in that: Before the encrypted communication with the network node using the network communication key, the method includes: receiving a second confirmation value and a third random number from the network node; Calculating a fourth confirmation value based on the third random number, the network communication key, the network beacon, and the authentication code; It is determined that the fourth confirmation value is equal to the second confirmation value, and it is determined that the key negotiation between the network node and the device to be networked is successful.

7. A wireless networking communication device, characterized in that: The system comprises a processor and a memory, wherein the processor is used to call and run a computer program stored in the memory to execute the method according to any one of claims 1 to 3.

8. A wireless networking communication device, characterized in that: The system comprises a processor and a memory, wherein the processor is used to call and run a computer program stored in the memory to execute the method according to any one of claims 4 to 7.

9. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein the computer program causes a computer to execute the method according to any one of claims 1 to 3.

10. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein the computer program causes a computer to execute the method according to any one of claims 4 to 7.