Network connection method and device, electronic equipment and readable storage medium

By using the first ciphertext in the electronic device to negotiate the key with the mutual aid device, the target key is generated, and the problem of complex and inefficient key negotiation in the prior art is solved, and the security and efficient negotiation of data transmission are achieved.

CN120201584APending Publication Date: 2025-06-24MIDEA GRP (SHANGHAI) CO LTD +1
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202311791581.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-22
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the prior art, the key negotiation method between electronic devices is complex and the negotiation efficiency is low, making it difficult to ensure the security of data transmission.

Method used

The connection request of the first network is sent through the device to be connected, including the first ciphertext, determine the mutual aid device to be connected, and negotiates the key with it to generate a target key, and conducts network connection based on the key.

Benefits of technology

The device to be connected to the first network through the mutual aid device is realized, ensuring the security of data transmission, and improving the efficiency of key negotiation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120201584A_ABST
    Figure CN120201584A_ABST
Patent Text Reader

Abstract

The invention provides a network connection method and device, electronic equipment and a readable storage medium, the network connection method is executed by to-be-connected equipment, the connection method comprises the steps that a connection request of a first network is sent, and the connection request comprises a first ciphertext; according to the connection request, determining a mutual assistance device needing to be connected, the mutual assistance device being connected to the first network; performing key negotiation with the mutual assistance device according to the first ciphertext to generate a target key; and performing network connection with the mutual assistance device based on the target key.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet of Things technology. Specifically, it relates to a method for connecting networks, a connection device, an electronic device, and a readable storage medium. Background Art

[0002] In the related art, during the data transmission process between electronic devices through a network, corresponding keys need to be set between the electronic devices so that the electronic devices can encrypt and decrypt the transmitted data through the keys to ensure the security of data transmission. However, the existing key negotiation methods are relatively complex and the negotiation efficiency is low. Summary of the Invention

[0003] This application aims to solve at least one of the technical problems existing in the prior art.

[0004] To this end, the first aspect of this application provides a method for connecting a network.

[0005] The second aspect of this application provides a method for connecting a network.

[0006] The third aspect of this application provides a connection device for a network.

[0007] The fourth aspect of this application provides a connection device for a network.

[0008] The fifth aspect of this application provides an electronic device.

[0009] The sixth aspect of this application provides a computer-readable storage medium.

[0010] The seventh aspect of this application provides a computer program product.

[0011] The first aspect of this application provides a method for connecting a network, which is executed by a device to be connected. The connection method includes: sending a connection request for a first network, where the connection request includes a first ciphertext; determining, according to the connection request, a mutual assistance device to be connected, where the mutual assistance device is connected to the first network; performing key negotiation with the mutual assistance device according to the first ciphertext to generate a target key; and performing a network connection with the mutual assistance device based on the target key.

[0012] The network connection method provided by this application can be used to connect a device to be connected to a first network to enable the device to be connected to access the Internet through the first network.

[0013] Specifically, first, control the device to be connected to send a connection request for the first network. Herein, the first network can be the network to which the routing device is connected. Controlling the device to be connected to send a connection request for the first network means sending a connection request to the routing device to request the device to be connected to the routing device, so as to enable the device to be connected to the first network through the routing device.

[0014] Further, after receiving the connection request from the device to be connected, the routing device can send feedback information to the device to be connected. Further, the device to be connected determines whether it meets the connection conditions for the first network according to the feedback information sent by the routing device. Specifically, the connection conditions for the first network can be whether the intensity of the network signal of the routing device received by the device to be connected is greater than a preset intensity. It can be understood that if the intensity of the network signal of the routing device that the device to be connected can receive is high, it means that the device to be connected can stably connect to the routing device, so as to stably and continuously access the first network. If the intensity of the network signal of the routing device that the device to be connected can receive is low, it will cause the device to be connected unable to connect to the routing device or have frequent disconnections. The preset intensity of the network signal can be set to -55dBm.

[0015] Further, in the case where the device to be connected does not meet the connection conditions for the first network, the mutual assistance device that the device to be connected needs to connect to can be determined according to the connection request. After determining the mutual assistance device, key negotiation can be carried out with the mutual assistance device according to the first ciphertext in the connection request, and then the target key is generated.

[0016] After the target key is generated, the device to be connected can be controlled to establish a network connection with the mutual assistance device based on the target key. That is, in the process of data transmission between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, so as to ensure the security of the data transmission process.

[0017] The network connection method provided by this application can, in the case where the device to be connected does not meet the connection conditions for the first network, be connected to the first network through the mutual assistance device by connecting to the mutual assistance device, so that the device to be connected can realize the Internet access function through the first network. Further, the device to be connected negotiates keys with the mutual assistance device according to the first ciphertext, so as to determine the target key required for data transmission between the device to be connected and the mutual assistance device, so that in the process of data transmission between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, so as to ensure the security of the data transmission process.

[0018] According to a second aspect of the present application, a method for connecting a network is provided, which is executed by a mutual assistance device. The mutual assistance device is connected to a first network. The connection method includes: receiving a connection request for the first network sent by a device to be connected, where the connection request includes a first ciphertext; performing key negotiation with the device to be connected according to the first ciphertext to generate a target key; and performing a network connection with the device to be connected based on the target key.

[0019] For the network connection method provided by the present application, when the device to be connected does not meet the connection conditions of the first network, the mutual assistance device to which the device to be connected needs to be connected can be determined according to the connection request. After determining the mutual assistance device, key negotiation can be performed with the mutual assistance device according to the first ciphertext in the connection request, and then a target key can be generated.

[0020] After generating the target key, the device to be connected can be controlled to perform a network connection with the mutual assistance device based on the target key. That is, during the data transmission process between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thereby ensuring the security during the data transmission process.

[0021] For the network connection method provided by the present application, when the device to be connected does not meet the connection conditions of the first network, it can be connected to the first network by connecting to a mutual assistance device, so that the device to be connected can access the Internet through the first network. Further, key negotiation is performed between the device to be connected and the mutual assistance device according to the first ciphertext, so as to determine the target key required for data transmission between the device to be connected and the mutual assistance device, so that during the data transmission process between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thereby ensuring the security during the data transmission process.

[0022] According to a third aspect of the present application, a network connection device is provided for a device to be connected. The connection device includes: a sending unit, configured to send a connection request for the first network, where the connection request includes a first ciphertext; a determining unit, configured to determine the mutual assistance device to be connected according to the connection request, where the mutual assistance device is connected to the first network; a generating unit, configured to perform key negotiation with the mutual assistance device according to the first ciphertext to generate a target key; and a connecting unit, configured to perform a network connection with the mutual assistance device based on the target key.

[0023] The network connection device provided by the present application can be connected to a mutual assistance device when the device to be connected does not meet the connection conditions of the first network, so as to be connected to the first network through the mutual assistance device, enabling the device to be connected to access the Internet through the first network. Further, the device to be connected negotiates a key with the mutual assistance device according to the first ciphertext, so as to determine the target key required for data transmission between the device to be connected and the mutual assistance device. During the data transmission between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thus ensuring the security of the data transmission process.

[0024] According to the fourth aspect of the present application, a network connection device for a mutual assistance device is proposed. The mutual assistance device is connected to the first network. The connection device includes: a receiving unit, configured to receive a connection request for the first network sent by the device to be connected, where the connection request includes a first ciphertext; a generating unit, configured to negotiate a key with the device to be connected according to the first ciphertext and generate a target key; and a connecting unit, configured to perform a network connection with the device to be connected based on the target key.

[0025] The network connection device provided by the present application can be connected to a mutual assistance device when the device to be connected does not meet the connection conditions of the first network, so as to be connected to the first network through the mutual assistance device, enabling the device to be connected to access the Internet through the first network. Further, the device to be connected negotiates a key with the mutual assistance device according to the first ciphertext, so as to determine the target key required for data transmission between the device to be connected and the mutual assistance device. During the data transmission between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thus ensuring the security of the data transmission process.

[0026] According to the fifth aspect of the present application, an electronic device is proposed, including: a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the network connection method provided in the first aspect and / or the second aspect are implemented.

[0027] The electronic device provided by the present application includes a memory and a processor, and also includes a program or instruction stored on the memory. When the program or instruction is executed by the processor, the steps of the network connection method in the above-mentioned first aspect and / or the second aspect can be implemented. Therefore, the electronic device has all the beneficial effects of the above-mentioned network connection method, which will not be elaborated here.

[0028] According to the sixth aspect of the present application, a computer-readable storage medium is proposed, on which a program or instruction is stored. When the program or instruction is executed by the processor, the steps of the network connection method in the above-mentioned first aspect and / or the second aspect are implemented.

[0029] The computer-readable storage medium provided by the present application stores a program or instructions thereon. When the program or instructions are executed by a processor, the steps of the network connection method in the above first aspect and / or second aspect can be implemented. Therefore, the computer-readable storage medium has all the beneficial effects of the above network connection method, which will not be elaborated herein.

[0030] According to the seventh aspect of the present application, a computer program product is proposed, including a computer program or instructions, and when the computer program or instructions are executed by a processor, the steps of the network connection method in the above first aspect and / or second aspect are implemented.

[0031] The computer program product provided by the present application includes a computer program or instructions. When the computer program or instructions are executed by a processor, the steps of the network connection method in the above first aspect and / or second aspect are implemented. Therefore, the computer program product has all the beneficial effects of the above network connection method, which will not be elaborated herein.

[0032] The additional aspects and advantages of the present application will become apparent in the following description section or be learned through the practice of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0033] The above and / or additional aspects and advantages of the present application will become apparent and be readily understood from the description of the embodiments in conjunction with the following drawings, where:

[0034] Figure 1 FIG. 1 shows one of the flow diagrams of the network connection method provided by an embodiment of the present application;

[0035] Figure 2 FIG. 2 shows another flow diagram of the network connection method provided by an embodiment of the present application;

[0036] Figure 3 FIG. 3 shows one of the block diagrams of the network connection device provided by an embodiment of the present application;

[0037] Figure 4 FIG. 4 shows another block diagram of the network connection device provided by an embodiment of the present application;

[0038] Figure 5 FIG. 5 shows the topology diagram of the network connection provided by an embodiment of the present application;

[0039] Figure 6 FIG. 6 shows the schematic diagram of the address mode during the data transmission provided by an embodiment of the present application;

[0040] Figure 7 FIG. 7 shows one of the address link diagrams of the network connection provided by an embodiment of the present application;

[0041] Figure 8 Shows the second address link diagram of the network connection provided according to the embodiment of the present application.

[0042] Among them, Figures 3 to 5 The corresponding relationship between the reference numerals in the

[0043] Connection device of the 300 network, sending unit 302, determining unit 304, generating unit 306, connecting unit 308, connection device of the 400 network, receiving unit 402, generating unit 404, connecting unit 406, device to be connected 502, routing device 504, mutual assistance device 506, target mutual assistance device 508. Specific implementation mode

[0044] In order to be able to more clearly understand the above objects, features and advantages of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific implementation modes. It should be noted that, without conflict, the embodiments of the present application and the features in the embodiments can be combined with each other.

[0045] Many specific details are set forth in the following description in order to fully understand the present application. However, the present application may also be implemented in other ways different from those described herein. Therefore, the protection scope of the present application is not limited by the specific embodiments disclosed below.

[0046] The following refers to Figures 1 to 8 to describe a network connection method, connection device, electronic device and readable storage medium provided according to some embodiments of the present application.

[0047] As Figure 1 shown, according to an embodiment of the present application, a network connection method is proposed, including:

[0048] S102, sending a connection request for the first network;

[0049] Among them, the connection request includes a first ciphertext;

[0050] S104, determining the mutual assistance device to be connected according to the connection request;

[0051] Among them, the mutual assistance device is connected to the first network;

[0052] S106, performing key negotiation with the mutual assistance device according to the first ciphertext to generate a target key;

[0053] S108, performing network connection with the mutual assistance device based on the target key.

[0054] The network connection method provided by this application can be used to connect a device to be connected to a first network, so that the device to be connected can access the Internet through the first network.

[0055] Specifically, first, control the device to be connected to send a connection request for the first network. Among them, the first network can be the network connected by the routing device. Controlling the device to be connected to send a connection request for the first network means sending a connection request to the routing device to request the device to be connected to the routing device, so as to realize that the device to be connected is connected to the first network through the routing device.

[0056] Further, after receiving the connection request from the device to be connected, the routing device can send feedback information to the device to be connected. Further, the device to be connected determines whether the device to be connected meets the connection conditions of the first network according to the feedback information sent by the routing device. Specifically, the connection conditions of the first network can be whether the intensity of the network signal of the routing device received by the device to be connected is greater than the preset intensity. It can be understood that if the intensity of the network signal of the routing device that the device to be connected can receive is relatively high, it means that the device to be connected can be stably connected to the routing device, so that it can stably and continuously access the first network. If the intensity of the network signal of the routing device that the device to be connected can receive is relatively low, it will cause the device to be connected to be unable to connect to the routing device or experience frequent disconnections. The preset intensity of the network signal can be set to -55dBm.

[0057] Further, in the case where the device to be connected does not meet the connection conditions of the first network, the mutual assistance device that the device to be connected needs to connect can be determined according to the connection request. After determining the mutual assistance device, the target key can be generated by negotiating the key with the mutual assistance device according to the first ciphertext in the connection request.

[0058] After generating the target key, the device to be connected can be controlled to establish a network connection with the mutual assistance device based on the target key. That is, during the data transmission process between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, so as to ensure the security of the data transmission process.

[0059] The network connection method provided by this application can, when the device to be connected does not meet the connection conditions of the first network, connect to the mutual assistance device, so as to connect to the first network through the mutual assistance device, enabling the device to be connected to achieve the Internet access function through the first network. Further, the device to be connected negotiates a key with the mutual assistance device based on the first ciphertext, thereby determining the target key required for data transmission between the device to be connected and the mutual assistance device, so that during the data transmission between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thus ensuring the security during the data transmission process.

[0060] In some embodiments, optionally, negotiating a key with the mutual assistance device according to the first ciphertext to generate the target key includes: receiving the second ciphertext sent by the mutual assistance device, where the second ciphertext is obtained by the mutual assistance device encrypting the first text and the second text, the first text is obtained by the mutual assistance device decrypting the first ciphertext, and the second text is a preset text for the mutual assistance device and the device to be connected to negotiate the key; decrypting the second ciphertext to generate the third text; determining the negotiation result of the key negotiation according to the third text; and sending the negotiation result to the mutual assistance device, where the negotiation result is used for the mutual assistance device to receive to indicate the mutual assistance device to generate the target key.

[0061] In this embodiment, the device to be connected first sends the first ciphertext to the target mutual assistance device, and the first ciphertext is obtained by encrypting the first text according to the public key of the target mutual assistance device. Further, the mutual assistance device receives the first ciphertext sent by the device to be connected and then decrypts the first ciphertext to generate the first text.

[0062] Further, after decrypting the first text, the mutual assistance device can encrypt the first text and the second text based on the public key of the mutual assistance device to generate the second ciphertext. The second text is a preset text for the mutual assistance device and the device to be connected to negotiate the key. Then the second ciphertext is sent to the device to be connected.

[0063] Further, after receiving the second ciphertext, the device to be connected can decrypt the second ciphertext to generate the third text. Then the device to be connected determines the negotiation result of the key negotiation with the mutual assistance device according to the third text.

[0064] Further, when the negotiation result of the key negotiation is determined to be successful, the mutual assistance device can generate the target key according to the first text and the second text.

[0065] During the key negotiation process, the device to be connected and the mutual assistance device respectively generate a first ciphertext and a second ciphertext based on the public key of the other party. Then, after decrypting the first ciphertext and the second ciphertext, the negotiation result of the key negotiation is determined according to the generated third text, thereby realizing the key negotiation between the device to be connected and the mutual assistance device and ensuring the accuracy of the negotiation result.

[0066] In some embodiments, preferably, determining the negotiation result of the key negotiation according to the third text includes: obtaining the text content of the third text; when the text content of the third text includes the first text, determining that the negotiation result is successful.

[0067] In this embodiment, after receiving the second ciphertext, the device to be connected can decrypt the second ciphertext to generate the third text. Then, the device to be connected determines the negotiation result of the key negotiation with the mutual assistance device according to the third text.

[0068] Specifically, first, the text content of the third text can be obtained to determine whether the first text sent by the device to be connected exists in the third text. If the first text exists in the third text, it indicates that the mutual assistance device generates the third text based on the first text sent by the device to be connected. Then, it can be determined that the negotiation result of the key negotiation between the mutual assistance device and the device to be connected is successful. Furthermore, the mutual assistance device can generate the target key according to the first text and the second text.

[0069] In some embodiments, preferably, sending the negotiation result to the mutual assistance device includes: encrypting the negotiation result based on the public key of the device to be connected to generate a third ciphertext; sending the third ciphertext to the mutual assistance device.

[0070] In this embodiment, after receiving the second ciphertext, the device to be connected can decrypt the second ciphertext to generate the third text. Then, the device to be connected determines the negotiation result of the key negotiation with the mutual assistance device according to the third text.

[0071] Furthermore, after the device to be connected determines that the negotiation result of the key negotiation is successful according to the third text, it can encrypt the negotiation result based on the public key of the device to be connected to generate a third ciphertext, and then send the third ciphertext to the mutual assistance device to notify the mutual assistance device of the negotiation result.

[0072] Furthermore, after receiving the third ciphertext, the mutual assistance device can decrypt the third ciphertext to determine whether the negotiation result is successful. After receiving the negotiation result, the mutual assistance device can generate the target key according to the first text and the second text.

[0073] Specifically, the negotiation result can be the text "ok".

[0074] Such as Figure 2As shown, according to an embodiment of the present application, a method for connecting a network is proposed, which is executed by a mutual assistance device. The mutual assistance device is connected to a first network. The connection method includes:

[0075] S202, receiving a connection request for the first network sent by the device to be connected;

[0076] Wherein, the connection request includes a first ciphertext;

[0077] S204, performing key negotiation with the device to be connected according to the first ciphertext to generate a target key;

[0078] S206, performing a network connection with the device to be connected based on the target key.

[0079] For the network connection method provided by the present application, when the device to be connected does not meet the connection conditions of the first network, the mutual assistance device to which the device to be connected needs to be connected can be determined according to the connection request. After determining the mutual assistance device, key negotiation can be performed with the mutual assistance device according to the first ciphertext in the connection request, and then a target key is generated.

[0080] After generating the target key, the device to be connected can be controlled to perform a network connection with the mutual assistance device based on the target key. That is, during the data transmission process between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thereby ensuring the security during the data transmission process.

[0081] For the network connection method provided by the present application, when the device to be connected does not meet the connection conditions of the first network, it can be connected to the first network by connecting to the mutual assistance device, so that the device to be connected can implement the Internet access function through the first network. Further, key negotiation is performed between the device to be connected and the mutual assistance device according to the first ciphertext, so as to determine the target key required for data transmission between the device to be connected and the mutual assistance device, so that during the data transmission process between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thereby ensuring the security during the data transmission process.

[0082] In some embodiments, optionally, performing key negotiation with the device to be connected according to the first ciphertext to generate a target key includes: decrypting the first ciphertext to generate a first text; encrypting the first text and a second text to generate and send a second ciphertext; receiving the key negotiation result sent by the device to be connected, and when the key negotiation result is successful, generating a target key according to the first text and the second text; wherein, the key negotiation result is determined by the device to be connected according to a third text obtained by decrypting the second ciphertext.

[0083] In this embodiment, the device to be connected first sends a first ciphertext to the target mutual assistance device, and the first ciphertext is obtained by encrypting a first text according to the public key of the target mutual assistance device. Further, the mutual assistance device receives the first ciphertext from the device to be connected, and then decrypts the first ciphertext to generate a first text.

[0084] Further, after decrypting the first text, the mutual assistance device may encrypt the first text and a second text based on the public key of the mutual assistance device to generate a second ciphertext. The second text is a preset text for key negotiation between the mutual assistance device and the device to be connected. Then the second ciphertext is sent to the device to be connected.

[0085] Further, after the device to be connected receives the second ciphertext, it can decrypt the second ciphertext to generate a third text. Then the device to be connected determines the negotiation result of the key negotiation with the mutual assistance device according to the third text.

[0086] Further, when it is determined that the negotiation result of the key negotiation is successful, the mutual assistance device can generate a target key according to the first text and the second text.

[0087] During the key negotiation process, the device to be connected and the mutual assistance device respectively generate a first ciphertext and a second ciphertext according to the public key of the other party. Thus, after decrypting the first ciphertext and the second ciphertext, the negotiation result of the key negotiation is determined according to the generated third text, thereby realizing the key negotiation between the device to be connected and the mutual assistance device and ensuring the accuracy of the negotiation result.

[0088] In some embodiments, preferably, the connection method further includes: sending the target key to all devices connected to the mutual assistance device.

[0089] In this embodiment, after generating the target key, the mutual assistance device sends the target key to the device to be connected, so that the device to be connected can transmit data with the mutual assistance device based on the target key.

[0090] In addition, the mutual assistance device may also send the target key to other devices connected to it, so that when other devices transmit data with the device to be connected through the mutual assistance device, they can encrypt and decrypt the data based on the target key, ensuring the security of the data transmission process between other devices and the device to be connected through the mutual assistance device.

[0091] In a specific embodiment, such as Figure 5As shown, when the device to be connected 502 needs to connect to the first network, first, the device to be connected 502 is controlled to send a connection request for the first network to discover connectable Internet devices. Specifically, the device to be connected 502 can send a connection request every 0.5 s. If no response from other devices is received for a long time, the device to be connected 502 can send requests at random intervals of 0.1 s within 5 s. At the same time, the device to be connected 502 also listens to the beacon sent by the routing device 504, and makes a comprehensive judgment based on the scanned wireless access points and the device information of the mutual assistance device 506 to determine whether to connect to the routing device 504 or the mutual assistance device 506.

[0092] Specifically, during the information interaction process between the device to be connected 502, the routing device 504, and the mutual assistance device 506, the information sent includes multiple fields. Among them, the key fields include capability display, frame type, message ID, CMD, level, etc. In one embodiment, the key fields are described as follows: Capability display: 8 bits, b0:1 supports mutual assistance; b0:0 does not support mutual assistance; other bits are reserved; Frame type: 01: probe request; 02: probe response; 03: action; Message ID: global ID, set by the initiator and echoed by the responder with the same ID. CMD: 01: key negotiation; 02: password update; 03: routing table update; Level: the network layer where the mutual assistance device 506 is located. The mutual assistance device 506 directly connected to the routing device 504 is layer 0, the mutual assistance device 506 connected to the mutual assistance device 506 directly connected to the routing device 504 is 1, the leaf connected to 1 is 2... The level range can be less than or equal to 4 layers.

[0093] Specifically, the connection request sent by the device to be connected 502 may include the following fields: protocol version, capability display, frame type, message ID, CMD, negotiation step, Pubkey, Sha, R1. In one embodiment, the protocol version is used to indicate the version of the communication protocol of the sent connection request; the capability display is used to show whether the device to be connected 502 supports the connection of the mutual assistance device 506; the frame type is used to indicate the message type of the sent connection request; the message ID is used to show the sent ID information, set by the initiator and echoed by the responder with the same ID; CMD, 01 indicates key negotiation, 02 indicates password update, 03 indicates routing table update; the negotiation step is used to show the process in the current connection; Pub key is the public key generated by the device to be connected 502; Sha is the ciphertext encryption method; R1 is the ciphertext based on public key encryption.

[0094] Further, after receiving the response information of the routing device 504, the strength of the network signal of the routing device 504 that the device to be connected 502 can receive is determined according to the response information of the routing device 504. If the strength of the network signal of the routing device 504 that the device to be connected 502 can receive is lower than -55 dBm, it will cause the device to be connected 502 to be unable to connect to the routing device 504 or frequent disconnections may occur. At this time, it can be determined whether the response information of the mutual assistance device 506 is received.

[0095] When the mutual assistance device 506 receives a connection request, it sends a response message after rule judgment. Judgment rules: 1. It is allowed to access the device to be connected itself; 2. The device that the device to be connected 502 requests to access is the mutual assistance device 506; 3. The name of the routing device 504 requesting access is the same as the network it accesses itself. The response information includes other information such as business private information, the number of connected terminals, and the floor where it is located.

[0096] Specifically, the response information sent by the mutual assistance device 506 may include the following fields in addition to the fields in the connection request sent by the device to be connected 502: level, which is used to indicate the level of the mutual assistance device 506 in the first network; the number of access points, which is used to indicate the number of devices accessed by the mutual assistance device 506; the strength of the network signal; R2, the ciphertext encrypted based on the public key of the mutual assistance device 506; R1.

[0097] Further, according to the response information sent by multiple mutual assistance devices 506, a target mutual assistance device 508 is determined among the multiple mutual assistance devices 506. First, a preliminary selection can be made according to the signal strength of the mutual assistance device 506, the floor of the mutual assistance device 506 in the first network, and the number of devices connected by the mutual assistance device 506. Specifically, the mutual assistance devices 506 with a signal strength greater than -55 dBm, a floor less than or equal to 4 floors, and a connection point number less than 6 can be screened out.

[0098] Further, among the screened mutual assistance devices 506, the connection index of the mutual assistance device 506 is determined according to the signal strength of the mutual assistance device 506, the floor of the mutual assistance device 506 in the first network, and the number of devices connected by the mutual assistance device 506. The mutual assistance device 506 with the largest connection index is determined as the target mutual assistance device 508. Specifically, first, the signal strength of the mutual assistance device 506, the strength weight and strength score corresponding to the signal strength, the floor weight and floor score corresponding to the floor, and the point weight and point score corresponding to the connection point number can be determined, and then the connection index of each mutual assistance device 506 is calculated.

[0099] Specifically, the connection index can be calculated according to the formula P = A×a + B×b + C×c, where P is the connection index, A is the strength score, a is the strength weight, B is the point score, b is the point weight, C is the level score, and c is the level weight. For example, the strength weight of the signal strength is 0.5. When the signal strength is -50 dBm, the corresponding strength score is 4. The point weight of the connection points is 0.5. When the number of connection points is 5, the point score is 4. The level weight of the number of layers is 0.3. When the number of layers is 3, the corresponding level score is 4. When the model strength of the mutual assistance device 506 is -50 dBm, the number of connection points is 5, and the number of layers is 3, the connection index of the mutual assistance device is: P = 4×0.5 + 4×0.3 + 4×0.2 = 4.

[0100] Further, after the target mutual assistance device 508 is determined, the control device 502 to be connected negotiates a key with the target mutual assistance device 508 to generate a key for data transmission between the device 502 to be connected and the target mutual assistance device 508. The connection request sent by the device 502 to be connected includes the text R1 encrypted by the public key of the device 502 to be connected. Correspondingly, the response information sent by the target mutual assistance device 508 to the device 502 to be connected includes R1 and the texts R1 and R2 encrypted by the public key of the device 502 to be connected.

[0101] During the key negotiation process, the encryption key is obtained using the ECC encryption algorithm. While the device to be connected initiates a scan, it also initiates key negotiation, and the target mutual assistance device 508 responds to implement the second step of key negotiation. The third and fourth steps use the ACTION frame to implement key confirmation.

[0102] First, after the device 502 to be connected receives the response information from the target mutual assistance device 508, it decrypts the encrypted text. If the decrypted text includes R1, it indicates that the key negotiation between the device 502 to be connected and the mutual assistance device 506 is successful. Then, the device 502 to be connected encrypts the negotiation result "OK" based on the public key of the mutual assistance device 506 and sends it to the mutual assistance device 506. After receiving the negotiation result, the mutual assistance device 506 generates a key according to R1 and R2, encrypts the text "OK" based on the generated key, and sends it to the device 502 to be connected, and the key negotiation is completed. Then, data transmission is performed between the device 502 to be connected and the mutual assistance device 506 based on the generated key. Specifically, during the key negotiation process, the device 502 to be connected uses the 4-address mode action frame to send key negotiation information. Among them, the information sent by the device 502 to be connected and the mutual assistance device 506 can include the following fields: protocol version, capability display, frame type, message ID, CMD, negotiation step, and ciphertext.

[0103] Further, after the key negotiation is completed, the device node link of the first network can be updated. Specifically, in the original link of the first network, if there is no device node downstream of the target mutual assistance device 508, the device node of the device to be connected 502 can be directly added downstream of the target mutual assistance device 508 in the original link to complete the update of the device node link of the first network.

[0104] If the downstream node of the target mutual assistance device 508 is occupied, that is, there is a device node downstream of the target mutual assistance device 508. At this time, the original link of the first network can be assisted to generate a replicated link, and the replicated link is the same as the original link of the first network at this time. Then, the downstream device node of the target mutual assistance device 508 in the replicated link is replaced with the device node of the device to be connected 502, so as to generate a new device node link and complete the update of the device node link of the first network.

[0105] For example, as Figure 7 and Figure 8 shown, the original link is A - B - C - D. When E is accessed, D adds E to the end to get A - B - C - D - E. At the same time, the device node direction in front of D reports adding E to the end of the A - B - C - D routing table. After each node receives this information, it will add E after D to complete node synchronization. If a new F is added to the end of D on the A - B - C - D path at the same time. At this time, D finds that its end is occupied, so it replicates a link and adds F to the end of D. At the same time, the D node synchronizes the information that needs to be added to the end to the root node. If each node is occupied, it is also replicated and added. Each node will obtain two complete linked lists: A - B - C - D - F and A - B - C - D - E. Specifically, the data sent to the forward device node for all node updates may include the following fields: protocol version; capability display; frame type; message ID; CMD; Sub, which is used to update the linked list for the associated network link; Len, which is used to indicate the length of the string, usually a multiple of 6; Macdata, mac data, 6(N + 2) bytes, where N represents the layer where the device is currently located. Mac is in little - endian alignment and is arranged sequentially from the mutual assistance device connected to the routing device backwards. MACdata arrangement example: MAC root, MAC1, MAC2... MACend.

[0106] Further, after the device to be connected 502 is connected to the first network through the target mutual assistance device 508, the data forwarding rules are as follows:

[0107] As Figure 6As shown, a 4 - address mode is adopted for data transmission between the device to be connected 502 and the target mutual - assistance device 508. A 3 - address mode is adopted for data transmission between the target mutual - assistance device 508 and other mutual - assistance devices 506, and between the target mutual - assistance device 508 and the routing device 504. The device to be connected 502 is connected to the target mutual - assistance device 508, the target mutual - assistance device 508 is connected to the routing device 504, and the routing device 504 is connected to the host device. The process of the device to be connected 502 sending data to the host device: The device to be connected 502 sends 4 addresses to the target mutual - assistance device 508: receiving address (RA) - the physical address of the target mutual - assistance device 508, sending address (TA) - the physical address of the device to be connected 502, destination address (DA) - the physical address of the host device, source address (SA) - the physical address of the device to be connected 502; The target mutual - assistance device 508 sends 3 addresses to the routing device 504: receiving address (RA) - the physical address of the routing device 504, source address (SA) - the physical address of the target mutual - assistance device 508, destination address (DA) - the physical address of the host device; The routing device 504 sends 3 addresses to the host device: destination address (DA) - the physical address of the host device, sending address (TA) - the physical address of the routing device 504, source address (SA) - the physical address of the target mutual - assistance device 508.

[0108] The process of the host device sending data to the device to be connected 502: The host device sends 3 addresses to the routing device 504: receiving address (RA) - the physical address of the routing device 504, source address (SA) - the physical address of the host device, destination address (DA) - the physical address of the target mutual - assistance device 508; The routing device 504 sends 3 addresses to the target mutual - assistance device 508: destination address (DA) - the physical address of the target mutual - assistance device 508, sending address (TA) - the physical address of the routing device 504, source address (SA) - the physical address of the host device; The target mutual - assistance device 508 sends 4 addresses to the device to be connected 502: receiving address (RA) - the physical address of the device to be connected 502, sending address (TA) - the physical address of the target mutual - assistance device 508, destination address (DA) - the physical address of the device to be connected 502, source address (SA) - the physical address of the host device.

[0109] Specifically: When the device to be connected 502 actively sends data, it detects whether the address resolution protocol (ARP table) of the device to be connected 502 contains the physical address of the target mutual - assistance device 508. If it does, it directly converts it into a 4 - address mode and sends it to the target mutual - assistance device 508. If not, it sends the data through the 4 - address mode step - by - step through the target mutual - assistance device 508 to the mutual - assistance device 506 connected to the routing device 504.

[0110] When the mutual assistance device 506 connected to the routing device 504 receives the data sent by the routing device 504, it first determines whether the logical address of the local device exists in the received data. If the logical address of the local device exists, the data is transmitted to the application layer of the local device. If not, the physical address of the next-level device is determined from the physical address routing table stored in the local device, and the data is transmitted to the next-level device.

[0111] Further, after the device to be connected 502 is connected to the first network through the target mutual assistance device 508, the device to be connected 502 sends detection data to the target mutual assistance device 508 once every 1 minute. If the target mutual assistance device 508 does not receive the detection data of the device to be connected 502 for 2 minutes, it is considered that the device to be connected 502 is lost, and the relevant information of the device to be connected 502 is cleared; when the device to be connected 502 does not receive the detection data reply from the target mutual assistance device 508, it means that the connection fails, and all devices under this node need to be notified to clear the connection relationship and search for the network again. The detection data may include the following fields: protocol version, capability display, frame type, message ID, and CMD.

[0112] Further, after the device to be connected 502 is connected to the first network through the target mutual assistance device 508, it is necessary to detect the connection anomaly of the device to be connected 502 in real time. Specifically, when the connection between the target mutual assistance device 508 and the routing device 504 is disconnected, the routing device 504 should retain the device information of all mutual assistance devices 506 connected to it and the address resolution protocol. After the routing device 504 is restarted, at this time, it is not necessary to clear the device information of the mutual assistance devices 506 connected to the routing device 504 and the address resolution protocol, and only the device addresses in the address resolution protocol need to be cleared. Then, an instruction is sent to the mutual assistance device 506 connected to it to notify the mutual assistance device 506 to re-initiate the Dynamic Host Configuration Protocol and update the physical address routing table, so that the mutual assistance device 506 and the routing device 504 re-establish the connection. Among them, the instruction sent by the routing device 504 may include the following fields: protocol version, capability display, frame type, message ID, and CMD.

[0113] Further, when the target mutual assistance device 508 finds that it is disconnected from the routing device 504, it can send an instruction to the device to be connected 502 connected to it to notify the device to be connected 502 to re-initiate the connection. Specifically, the instruction sent by the target mutual assistance device 508 may include the following fields: protocol version, capability display, frame type, message ID, and CMD.

[0114] According to the third aspect of the present application, as Figure 3As shown, a connection device 300 for a network is proposed for a device to be connected. The connection device includes: a sending unit 302 for sending a connection request for a first network, where the connection request includes a first ciphertext; a determining unit 304 for determining, according to the connection request, a mutual assistance device to be connected, where the mutual assistance device is connected to the first network; a generating unit 306 for performing key negotiation with the mutual assistance device according to the first ciphertext to generate a target key; and a connecting unit 308 for performing a network connection with the mutual assistance device based on the target key.

[0115] The connection device 300 for the network provided in this application can, in the case where the device to be connected does not meet the connection conditions of the first network, achieve connection to the first network through the mutual assistance device by connecting with the mutual assistance device, so that the device to be connected can implement the Internet access function through the first network. Further, the device to be connected performs key negotiation with the mutual assistance device according to the first ciphertext, so as to determine the target key required for data transmission between the device to be connected and the mutual assistance device, so that during the data transmission process between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thereby ensuring the security during the data transmission process.

[0116] Further, the generating unit 306 is specifically configured to receive a second ciphertext sent by the mutual assistance device, where the second ciphertext is obtained by the mutual assistance device encrypting a first text and a second text, the first text is obtained by the mutual assistance device decrypting the first ciphertext, and the second text is a preset text for the mutual assistance device to perform key negotiation with the device to be connected; decrypt the second ciphertext to generate a third text; determine the negotiation result of the key negotiation according to the third text; and send the negotiation result to the mutual assistance device, where the negotiation result is used for the mutual assistance device to receive to instruct the mutual assistance device to generate the target key.

[0117] Further, the generating unit 306 is specifically further configured to obtain the text content of the third text; and determine that the negotiation result is successful when the text content of the third text includes the first text.

[0118] Further, the generating unit 306 is specifically further configured to encrypt the negotiation result based on the public key of the device to be connected to generate a third ciphertext; and send the third ciphertext to the mutual assistance device.

[0119] According to the fourth aspect of this application, as Figure 4As shown, a connection device 400 for a network is proposed for a mutual assistance device. The mutual assistance device is connected to a first network. The connection device includes: a receiving unit 402 for receiving a connection request for the first network sent by a device to be connected, where the connection request includes a first ciphertext; a generating unit 404 for performing key negotiation with the device to be connected according to the first ciphertext to generate a target key; and a connecting unit 406 for performing network connection with the device to be connected based on the target key.

[0120] The connection device 400 for the network provided in this application, in the case where the device to be connected does not meet the connection conditions of the first network, can be connected to the mutual assistance device, so as to be connected to the first network through the mutual assistance device, enabling the device to be connected to implement an Internet access function through the first network. Further, the device to be connected performs key negotiation with the mutual assistance device according to the first ciphertext, thereby determining the target key required for data transmission between the device to be connected and the mutual assistance device, so that during the data transmission process between the device to be connected and the mutual assistance device, the data can be encrypted and decrypted based on the target key, thus ensuring the security during the data transmission process.

[0121] Further, the generating unit 404 is specifically configured to decrypt the first ciphertext to generate a first text; encrypt the first text and a second text to generate and send a second ciphertext; receive the key negotiation result sent by the device to be connected, and in the case where the key negotiation result is successful, generate a target key according to the first text and the second text; where the key negotiation result is determined by the device to be connected according to a third text obtained by decrypting the second ciphertext.

[0122] Further, the connection device 400 for the network further includes a sending unit for sending the target key to all devices connected to the mutual assistance device.

[0123] According to the fifth aspect of this application, an electronic device is proposed, including: a processor and a memory. The memory stores a program or instruction that can run on the processor. When the program or instruction is executed by the processor, the steps of the network connection method provided in any one of the above embodiments are implemented.

[0124] The electronic device provided in this application includes a memory and a processor, and also includes a program or instruction stored on the memory. When the program or instruction is executed by the processor, the steps of the connection method in any one of the above embodiments can be implemented. Therefore, this electronic device has all the beneficial effects of the above network connection method, which will not be elaborated here.

[0125] According to the sixth aspect of this application, a computer-readable storage medium is proposed, on which a program or instruction is stored. When the program or instruction is executed by a processor, the steps of the network connection method provided in any one of the above embodiments are implemented.

[0126] The computer-readable storage medium provided by the present application stores a program or instructions. When the program or instructions are executed by a processor, the steps of the network connection method in any one of the above embodiments can be implemented. Therefore, the computer-readable storage medium has all the beneficial effects of the above network connection method, which will not be elaborated here.

[0127] According to the seventh aspect of the present application, a computer program product is proposed, including a computer program or instructions. When the computer program or instructions are executed by a processor, the steps of the network connection method in any one of the above embodiments are implemented.

[0128] The computer program product provided by the present application includes a computer program or instructions. When the computer program or instructions are executed by a processor, the steps of the network connection method in any one of the embodiments are implemented. Therefore, the computer program product has all the beneficial effects of the above network connection method, which will not be elaborated here.

[0129] In the description of the present application, the term "plurality" means two or more, unless otherwise clearly defined. The orientation or positional relationship indicated by terms such as "upper", "lower", etc. is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation to the present application; terms such as "connection", "installation", "fixation", etc. should all be understood in a broad sense. For example, "connection" can be a fixed connection, a detachable connection, or an integral connection; it can be directly connected, or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms in the present application can be understood according to specific circumstances.

[0130] In the description of this specification, the description of terms such as "one embodiment", "some embodiments", "specific embodiments", etc. means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or instance. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0131] The above are only the preferred embodiments of the present application and are not used to limit the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. A connection method for a network, which is executed by a device to be connected, characterized in that, The connection method includes: Sending a connection request for the first network, where the connection request includes a first ciphertext; Determining the mutual assistance device to be connected according to the connection request, where the mutual assistance device is connected to the first network; Performing key negotiation with the mutual assistance device according to the first ciphertext to generate a target key; Performing a network connection with the mutual assistance device based on the target key.

2. The connection method according to claim 1, wherein The performing key negotiation with the mutual assistance device according to the first ciphertext to generate a target key includes: Receiving a second ciphertext sent by the mutual assistance device, where the second ciphertext is obtained by the mutual assistance device encrypting a first text and a second text, the first text is obtained by the mutual assistance device decrypting the first ciphertext, and the second text is a preset text for the mutual assistance device to perform key negotiation with the device to be connected; Decrypting the second ciphertext to generate a third text; Determining the negotiation result of the key negotiation according to the third text; Sending the negotiation result to the mutual assistance device, where the negotiation result is used for the mutual assistance device to receive to indicate the mutual assistance device to generate the target key.

3. The connection method according to claim 2, characterized in that, The determining the negotiation result of the key negotiation according to the third text includes: Obtaining the text content of the third text; Determining that the negotiation result is successful when the text content of the third text includes the first text.

4. The connection method according to claim 2, wherein The sending the negotiation result to the mutual assistance device includes: Encrypting the negotiation result based on the public key of the device to be connected to generate a third ciphertext; Sending the third ciphertext to the mutual assistance device.

5. A connection method of a network, which is executed by a mutual assistance device, characterized in that The mutual assistance device is connected to the first network, and the connection method includes: Receiving the connection request for the first network sent by the device to be connected, where the connection request includes a first ciphertext; Performing key negotiation with the device to be connected according to the first ciphertext to generate a target key; Performing a network connection with the device to be connected based on the target key.

6. The connection method according to claim 5, characterized in that The performing key negotiation with the device to be connected according to the first ciphertext to generate a target key includes: Decrypting the first ciphertext to generate a first text; Encrypting the first text and the second text to generate and send a second ciphertext; Receiving the key negotiation result sent by the device to be connected, and generating the target key according to the first text and the second text when the key negotiation result is successful; Wherein, the key negotiation result is determined by the device to be connected according to the third text obtained by decrypting the second ciphertext.

7. The connection method according to claim 5 or 6, characterized in that, The connection method further includes: Sending the target key to all devices connected to the mutual assistance device.

8. A connection device for a network, for a device to be connected, characterized in that, The connection device includes: A sending unit, configured to send a connection request for the first network, where the connection request includes a first ciphertext; A determining unit, configured to determine the mutual assistance device to be connected according to the connection request, where the mutual assistance device is connected to the first network; A generating unit, configured to perform key negotiation with the mutual assistance device according to the first ciphertext to generate a target key; A connection unit for making a network connection with the mutual assistance device based on the target key.

9. A connection device for a network, used for mutual assistance devices, characterized in that, The mutual assistance device is connected to a first network, and the connection device includes: A receiving unit for receiving the connection request of the first network sent by the device to be connected, where the connection request includes a first ciphertext; A generating unit for performing key negotiation with the device to be connected according to the first ciphertext to generate a target key; A connection unit for making a network connection with the device to be connected based on the target key.

10. An electronic device, characterized in that, Comprising: A processor and a memory, the memory stores programs or instructions that can run on the processor, and when the programs or instructions are executed by the processor, the steps of the method described in any one of claims 1 to 4 and / or the steps of the method described in any one of claims 5 to 7 are implemented.

11. A computer-readable storage medium, characterized in that, Programs or instructions are stored on the computer-readable storage medium, and when the programs or instructions are executed by the processor, the steps of the method described in any one of claims 1 to 4 and / or the steps of the method described in any one of claims 5 to 7 are implemented.

12. A computer program product comprising a computer program or instructions, characterized in that, When the computer program or instruction is executed by the processor, the steps of the method described in any one of claims 1 to 4 and / or the steps of the method described in any one of claims 5 to 7 are implemented.

Citation Information

Cited By

  • Network connection method and apparatus, and electronic device and readable storage medium

    EP4746575A1

  • Network connection method and apparatus, and electronic device and readable storage medium

    WO2025130033A1