Networking a household appliance to a network with assistance
By using connected smart home appliances as auxiliary devices and using the asymmetric password authentication protocol to share network credentials, the security and complexity problems in the process of smart home appliances are solved, and an automated and secure network access process is realized.
Patent Information
- Application Number
- CN202380082181.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-12-07
- Filing Date
- 2023-09-20
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, when smart home appliances are connected to the network, there are security problems in sharing network connection credentials, and for inexperienced users, the network access process is complicated and not intuitive.
By utilizing smart home appliances that have been connected to the network as auxiliary devices, storing and sharing network connection credentials, using the asymmetric password authentication protocol to authenticate the network access device, and providing network connection credentials after the authentication is passed.
It realizes automatic and secure access to the network of smart home appliances, simplifies the access process, reduces user operation complexity, and improves the security of the access process.
Smart Images

Figure CN120283378A_ABST
Abstract
Description
[0001] Technical Field of the Invention
[0002] The present invention generally relates to household appliances, such as washing machines, dishwashers, ovens, etc., and particularly to smart household appliances, also known as network - connectable or Internet - of - Things (IoT) household appliances, i.e., household appliances or home appliances provided with wireless communication interfaces that are designed to allow the household appliance to connect to the network to which other smart household appliances are connected.
[0003] Particularly, the present invention relates to onboarding a smart household appliance into a communication network by leveraging smart household appliances that are already connected to the network and securely share their network connection credentials with the household appliance to be onboarded. Background Art
[0004] As is well - known, an increasing number of household appliances are connected to the Internet to provide new services to customers. The challenge of connecting and preparing a household appliance for operation is known as onboarding, provisioning, or network set - up, and it includes either or both of connecting the household appliance to a wireless local area network (e.g., the Wi - Fi network of the customer's home) and associating the household appliance with the customer's account.
[0005] The simplest way to onboard a household appliance into a network (usually a WLAN) is to use a household appliance that is already connected to the network and shares its network connection credentials with the smart household appliance being connected.
[0006] The sharing of network connections needs to be performed by protecting the confidentiality of the network connection. Broadcasting is insecure because anyone listening can use such credentials. Sharing secrets between the household appliances involved also poses complexity for less - experienced or inexperienced customers. Companies or associations that support the principle of sharing usage credentials without giving any user access rights and other sharing need a method to verify whether the onboarded household appliance is trustworthy (i.e., whether it belongs to the same company or association domain and is reliable) without a network connection before sharing the secret.
[0007] To complete the process of onboarding a household appliance into a WLAN, the customer must know the WLAN settings and / or the customer's account details and follow a specific sequence of steps, which can be confusing or overly complex for some less - experienced or inexperienced customers.
[0008] In addition, in recent years, customers have demanded that household appliances automatically connect to their smart devices (such as smartphones or tablets) installed with software applications (apps) that are designed to allow customers to easily manage the operation of the household appliances.
[0009] Object of the Invention and Summary of the Invention
[0010] The applicant has noticed the importance of protecting the WLAN credentials shared for connecting smart home appliances to the network and preventing malicious users from connecting to a private WLAN (such as the customer WLAN to which a smart appliance is connected, where sensitive applications may be installed).
[0011] Therefore, an object of the present invention is to provide a technique that allows a smart home appliance to automatically and securely connect to a WLAN by using network connection credentials shared by home appliances already connected to the same WLAN.
[0012] Therefore, the present invention relates to a system and method for allowing a smart home appliance to automatically connect to a wireless local area network as claimed in the appended claims.
[0013] In particular, according to a first aspect of the present invention, the present invention relates to a system for allowing a first home appliance to automatically connect to a network with the assistance of a second home appliance connected to the network, wherein the second home appliance is configured to:
[0014] ο Store network connection credentials by means of which the second home appliance connects to the network;
[0015] ο Receive an access assistance request from the first home appliance and including a unique identifier of the first home appliance;
[0016] ο Authenticate the first home appliance based on the unique identifier in the received access assistance request; and
[0017] ο Provide the network connection credentials to the first home appliance when the first home appliance is authenticated;
[0018] And the first home appliance is configured to:
[0019] ο Broadcast an access request;
[0020] ο Receive the network connection credentials from the second home appliance; and
[0021] ο Use the received network connection credentials to connect to the network.
[0022] In order to authenticate the first home appliance, the second home appliance is further configured to:
[0023] - Obtain the public cryptographic key of the first home appliance; and
[0024] - Authenticate the accessing home appliance based on the public cryptographic key of the first home appliance and an asymmetric cryptographic authentication protocol.
[0025] In a possible embodiment, to authenticate the first household appliance, the second household appliance is further configured to:
[0026] - Access a public cryptographic key database, in which the public cryptographic keys of household appliances are stored in association with the unique identifiers of these household appliances, to retrieve from the public cryptographic key database the public cryptographic key of the first household appliance stored in association with the unique identifier of the first household appliance; and
[0027] - Authenticate the first household appliance based on the public cryptographic key of the first household appliance retrieved from the public cryptographic key database and based on the asymmetric cryptographic authentication protocol.
[0028] In another possible embodiment, to authenticate the first household appliance, the second household appliance is further configured to:
[0029] - Access a public cryptographic key database, in which values calculated based on a one-way function from the public cryptographic keys of household appliances are stored in association with the unique identifiers of these household appliances, the one-way function converting these public cryptographic keys into values representing these public cryptographic keys, conveniently a hash of the public cryptographic key, to retrieve from the public cryptographic key database the value calculated based on the public cryptographic key of the first household appliance and stored in association with the unique identifier of the first household appliance;
[0030] - Communicate with the first household appliance to receive from the first household appliance the stored public cryptographic key of the first household appliance;
[0031] - Calculate a value based on the public cryptographic key received from the first household appliance and based on the same one-way function, the value retrieved from the public cryptographic key database and stored in association with the unique identifier of the first household appliance being calculated based on the public cryptographic key of the first household appliance based on the one-way function;
[0032] - Check whether the value retrieved from the public cryptographic key database matches the value calculated based on the public cryptographic key of the first household received from the first household appliance;
[0033] - If it is determined that the stored value retrieved from the public cryptographic key database matches the calculated value calculated based on the public cryptographic key of the first household received from the first household appliance, authenticate the first household appliance based on the public cryptographic key of the first household appliance received from the first household appliance and based on the asymmetric cryptographic authentication protocol.
[0034] This public cryptographic key database is preferably a cryptographic key database.
[0035] Preferably, the second household appliance is configured to authenticate the first household appliance based on an asymmetric cryptographic challenge - response authentication protocol.
[0036] In a possible embodiment, according to the asymmetric cryptographic challenge - response authentication protocol, the second household appliance is configured to:
[0037] ο Generate a challenge for the first household appliance;
[0038] ο Encrypt the challenge using the public cryptographic key of the first household appliance;
[0039] ο Send the encrypted challenge to the first household appliance;
[0040] ο Receive a response from the first household appliance;
[0041] ο Check whether the received response to the challenge is valid; and
[0042] ο If it is determined that the received response to the challenge is valid, authenticate the first household appliance;
[0043] And the first household appliance is configured to:
[0044] ο Receive the encrypted challenge;
[0045] ο Decrypt the encrypted challenge using the cryptographic private key of the first household appliance;
[0046] ο Calculate a response and send the response to the second household appliance.
[0047] In a possible embodiment, the first household appliance may broadcast the network access assistance request in response to detecting an auxiliary availability announcement, which is broadcast by the second household appliance and announces the availability of the second household appliance to assist the first household appliance in accessing the network.
[0048] In another possible embodiment, the first household appliance may broadcast the network access assistance request in response to receiving a network access trigger command from a customer mobile terminal communicating with the first household appliance.
[0049] The network access trigger command may be generated by the customer mobile terminal in response to a customer trigger gesture or a trigger voice command spoken by the customer on the customer mobile terminal.
[0050] In one embodiment, the second household appliance may be configured to become authorized to assist the first household appliance in accessing the network by receiving an access authorization command from one or both of the control panel of the second household appliance and a customer mobile terminal directly or indirectly connected to the second household appliance.
[0051] In another possible embodiment, the second household appliance may be configured to become authorized to assist the first household appliance in accessing the network by receiving an access authorization command from the seller of the first household appliance or a cloud system and generated in response to the first household appliance registering to the customer's account.
[0052] According to another aspect of the present invention, the present invention relates to software modules that can be loaded into a first household appliance to be accessed to a network and a second household appliance already connected to the network; when executed by the first household appliance and the second household appliance, these software modules are designed to configure the first household appliance and the second household appliance to cooperate so that the first household appliance can be automatically accessed to the network with the assistance of the second household appliance already connected to the network according to the above system.
[0053] The present invention also relates to a method for accessing a household appliance to a network, the method comprising the following steps:
[0054] - Broadcasting, by a first household appliance, an access assistance request, the access assistance request including a unique identifier of the first household appliance;
[0055] - Receiving, in a second household appliance, the access assistance request;
[0056] - Obtaining, by the second household appliance, a public cryptographic key of the first household appliance based on the unique identifier;
[0057] - Authenticating, in the second household appliance, the first household appliance based on the public cryptographic key and based on an asymmetric cryptographic authentication protocol;
[0058] - After authenticating the first household appliance, sending, to the first household appliance, network connection credentials of the second household appliance; and
[0059] - Connecting, using the network connection credentials of the second household appliance, the first household appliance to the network.
[0060] The public cryptographic key database is preferably a trusted cryptographic key database.
[0061] The network connection credentials of the second household appliance are advantageously sent by the second household appliance to the first household appliance.
[0062] In a possible embodiment, the step of obtaining the public cryptographic key of the first household appliance includes the following steps:
[0063] - The second household appliance accesses a public cryptographic key database in which the public cryptographic keys of the household appliances are stored in association with the unique identifiers of these household appliances, and
[0064] - Identifies in the public cryptographic key database the public cryptographic key associated with the unique identifier of the first household appliance.
[0065] In another possible embodiment, the step of obtaining the public cryptographic key of the first household appliance includes the following steps:
[0066] - The second household appliance accesses a public cryptographic key database in which values calculated based on a one-way function from the public cryptographic keys of the household appliances are stored in association with the unique identifiers of these household appliances, and
[0067] - Identifies in the database the first value calculated based on the public cryptographic key of the first household appliance;
[0068] And authenticating the first household appliance includes:
[0069] - Sending from the first household appliance to the second household appliance the public cryptographic key of the first household appliance;
[0070] - Calculating in the second household appliance a second value based on the one-way function from the public cryptographic key received from the first household appliance;
[0071] - Checking whether the first value matches the second value;
[0072] - If the first value matches the second value, authenticating the first household appliance based on the public cryptographic key received from the first household appliance and based on the asymmetric cryptographic authentication protocol.
[0073] Advantageously, the public cryptographic key of the first household appliance sent from the first household appliance to the second household appliance is stored in the first household appliance. Brief Description of the Drawings
[0074] Figure 1 Shows a block diagram of a system for allowing intelligent household appliances to automatically connect to a network according to the present invention.
[0075] Figures 2 to 5 Shows Figure 1 A block diagram of the operation of the system shown. Detailed Description of the Embodiment
[0076] The present invention will now be described in detail with reference to the accompanying drawings to enable a person skilled in the art to implement and use the present invention. Various modifications to the described embodiments will be readily apparent to those skilled in the art, and the general principles described can be applied to other embodiments and applications without departing from the scope of the present invention as defined by the appended claims. Therefore, the present invention should not be considered limited to the embodiments described and shown herein, but should be accorded the broadest scope consistent with the described and claimed features.
[0077] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains. In case of conflict, the present specification (including the provided definitions) will prevail. In addition, these examples are provided for illustrative purposes only and should not be considered limiting.
[0078] In particular, the block diagrams included in the drawings and the following description are not intended as a representation of structural features or construction limitations, but must be interpreted as a representation of functional features (i.e., the inherent properties of the device) and are defined by the obtained effects or functional limitations, and it can be implemented in different ways, and thus, in order to protect its functionality (the possibility of functions).
[0079] To facilitate the understanding of the embodiments described herein, reference will be made to some specific embodiments, and these embodiments will be described using specific language. The terms used herein are for the purpose of describing only the specific embodiments and are not intended to limit the scope of the present invention.
[0080] Figure 1 System 1 is shown, which is used to allow a first intelligent household appliance 2 to automatically connect to a communication network 3 with the assistance of a second intelligent household appliance 4 that has been connected to the network 3.
[0081] In the remainder of this specification, the first intelligent household appliance 2 (i.e., the household appliance to be connected to the network) will be referred to as the "network-connected household appliance", and the second intelligent household appliance 4 (i.e., the intelligent household appliance that has been connected to the network 3) will be referred to as the "assisting household appliance".
[0082] The network 3 can be based on any wired or wireless computer network technology, especially wired local area network (LAN) (such as Ethernet), wireless local area network (WLAN) (such as Wi-Fi network or BLE (Bluetooth Low Energy) network). Without loss of generality, the following description will refer to the WLAN network.
[0083] In order to be able to connect to network 3, the networked household appliance 2 and the auxiliary household appliance 4 are provided with corresponding network controllers. In one embodiment, the networked household appliance 2 and the auxiliary household appliance 4 support WLAN and are provided with corresponding WLAN controllers. In different embodiments, the networked household appliance 2 and the auxiliary household appliance 4 may also support BLE and are provided with corresponding BLE network controllers.
[0084] As Figure 2 shown, in order to assist the networked household appliance 2 in accessing the WLAN 3, the auxiliary household appliance 4 is programmed to:
[0085] - Store WLAN credentials by means of which the auxiliary household appliance 4 connects to the WLAN 3 (block 10);
[0086] - Detect an access assistance request broadcast by the networked household appliance 2 and containing the unique identifier of the networked household appliance 2 (in an embodiment, this unique identifier is considered to be the MAC address of the WLAN / BLE controller of the networked household appliance 2) (block 20);
[0087] - In response to detecting an access assistance request broadcast by the networked household appliance 2, authenticate the networked household appliance 2 based on the unique identifier in the received access request and according to an asymmetric cryptographic authentication protocol (also known as asymmetric key encryption) (conveniently but not necessarily the asymmetric cryptographic challenge-response authentication protocol), which will be described below (block 30); and
[0088] - When the networked household appliance 2 passes the authentication, provide the WLAN credentials to the networked household appliance 2 (block 40).
[0089] Therefore, the networked household appliance 2 is programmed to:
[0090] - For example, after power-on, announce that the networked household appliance needs to be assisted in accessing the WLAN 3 by broadcasting an access assistance request (block 50);
[0091] - Support the asymmetric cryptographic authentication protocol and cooperate with the auxiliary household appliance 4 to authenticate the networked household appliance by the auxiliary household appliance based on the asymmetric cryptographic authentication protocol (block 60);
[0092] - Receive the WLAN credentials from the auxiliary household appliance 4 (block 70);
[0093] - Use the received WLAN credentials to connect to the WLAN 3 (block 80); and
[0094] - Notify the customer of successful access to the WLAN 3 (block 90).
[0095] In one embodiment, the networked household appliance 2 broadcasts a network access assistance request in response to detecting an assistance availability announcement, which is broadcast by the assisting household appliance 4 and announces the availability of the assisting household appliance to assist the networked household appliance 2 in accessing the WLAN 3.
[0096] To this end, the assisting household appliance 4 is programmed to announce the availability of the assisting household appliance to assist the networked household appliance 2 in accessing the WLAN 3 by broadcasting an assistance availability announcement, and the networked household appliance 2 is programmed to detect the assistance availability announcement broadcast by the assisting household appliance 4 and broadcast a network access assistance request accordingly.
[0097] Conveniently, the assisting household appliance 4 can utilize the BLE electronic beacon function to announce the assistance availability announcement. According to this function, the BLE interface of the assisting household appliance 4 can be operated as a BLE electronic beacon device, that is, the assisting household appliance broadcasts an announcement signal that contains the assistance availability announcement and is intended to be received by BLE-enabled devices.
[0098] In different embodiments, the networked household appliance 2 broadcasts a network access assistance request in response to receiving a network access trigger command from a customer mobile terminal 6 (such as a smart phone or a tablet computer) that communicates with the networked household appliance 4, conveniently via a short-range wireless communication technology (e.g., Wi-Fi or Bluetooth technology).
[0099] The network access trigger command can be generated by the customer mobile terminal 6 in response to a customer trigger gesture on the customer mobile terminal 6. A mobile application is installed and executed in the customer mobile terminal, and the mobile application is designed to allow the customer to trigger the network access of the networked household appliance 2 by means of a gesture (e.g., by clicking an "Add Device" button, which correspondingly enables the "Add Device" function to be selected and executed).
[0100] The network access trigger can also be generated by the customer mobile terminal 6 in response to a trigger voice command spoken by the customer.
[0101] In an exemplary embodiment where multiple assisting household appliances 4 are already connected to the WLAN 3, the mobile application can be designed to transmit the network access trigger command to a cloud system (not shown), and the cloud system re-transmits the network access trigger command to all customer household appliances 4.
[0102] In this embodiment, in response to detecting the network access assistance request broadcast by the networked household appliance 2, the assisting household appliance 4 is programmed to notify the networked household appliance 2 of the availability of the assisting household appliance to assist the networked household appliance 2 in accessing the WLAN 3, and the networked household appliance 2 is programmed to notify the assisting household appliance 4 of accepting the assistance of the assisting household appliance 4 in accessing the WLAN 3.
[0103] Accordingly, in response to detecting an access request from the accessing home appliance 2, the assisting home appliance 4 is programmed to: send a connectionless message to the accessing home appliance 2 or establish a connection with the accessing home appliance; and thus, the accessing home appliance 2 is programmed to: receive the connectionless message from the assisting home appliance 4 in response, or establish a connection with the assisting home appliance and broadcast the access request in response.
[0104] In one embodiment, the accessing home appliance 2 is programmed to: broadcast an access assistance request by creating a Wi-Fi or BLE (Bluetooth Low Energy) network, and broadcast a Wi-Fi SSID (Service Set Identifier) or BLE network name (predefined name structure or fixed name) that includes the unique identifier of the accessing home appliance 2, particularly the MAC address of the WLAN / BLE controller of the accessing home appliance 2.
[0105] In Figure 3 In the embodiment shown, in order to authenticate the accessing home appliance 2, the assisting home appliance 4 is programmed to:
[0106] - Access a public cryptographic key database 5 (connected locally or remotely to the WLAN via a cloud connection) - in which the public cryptographic keys of the home appliances are stored associated with the unique identifiers of the home appliances included in the access requests - to retrieve the public cryptographic key of the accessing home appliance 2 stored associated with the unique identifier of the accessing home appliance from the public cryptographic key database 5 (block 100);
[0107] - Authenticate the accessing home appliance 2 based on the public cryptographic key of the accessing home appliance 2 retrieved from the database 5 and based on an asymmetric cryptographic authentication protocol (block 110).
[0108] In Figure 4 In a different embodiment shown, in order to authenticate the accessing home appliance 2, the assisting home appliance 4 is alternatively programmed to:
[0109] - Access a public cryptographic key database 5 (connected locally or remotely to the WLAN via a cloud connection) - a hash of the public cryptographic key of the home appliance (i.e., a value calculated according to the public cryptographic key and a cryptographic hash function (CHF) suitable for the intended use) is stored associated with the unique identifier of the home appliance - to retrieve the hash of the public cryptographic key of the accessing home appliance 2 stored associated with the unique identifier of the accessing home appliance from the public cryptographic key database 5 (block 120);
[0110] - Communicate with the accessing home appliance 2 to receive the stored public cryptographic key of the accessing home appliance itself from the accessing home appliance, and calculate the hash of the received public cryptographic key (block 130);
[0111] - Check whether the hash of the public cryptographic key of the networked household appliance 2 calculated based on the public cryptographic key of the networked household appliance 2 received from the networked household appliance matches the hash of the public cryptographic key of the networked household appliance 2 retrieved from the public cryptographic key database 5 (block 140);
[0112] - If it is determined that the hashes of the public cryptographic keys of the networked household appliance 2 match, authenticate the networked household appliance 2 based on the public cryptographic key of the networked household appliance 2 and based on a predetermined authentication protocol (block 150).
[0113] At the end of this process, the authenticity of the networked household appliance 2 has been verified, that is, its identity has been proven to be part of the company's equipment or authorized by the organization and has not been revoked.
[0114] It goes without saying that instead of the hash of the public cryptographic key of the household appliance, the public cryptographic key database 5 may store any other equivalent value calculated based on any one-way function that converts or maps the public cryptographic key into a fixed-length string or value representing the public cryptographic key, based on any mathematical conversion algorithm suitable for the intended use, according to the public cryptographic key of the household appliance.
[0115] In the above different embodiments, the public cryptographic key database is advantageously a trusted cryptographic key database.
[0116] As previously mentioned, the auxiliary household appliance 4 is programmed to authenticate the networked household appliance 2 conveniently but not necessarily based on an asymmetric cryptographic authentication protocol (conveniently an asymmetric cryptographic challenge-response authentication protocol), the block diagram of which is shown in Figure 5 shown.
[0117] To authenticate the networked household appliance 2 in an encrypted challenge-response manner:
[0118] - The auxiliary household appliance 4 is programmed to:
[0119] ο Generate a challenge (question) for the networked household appliance 2 (block 200);
[0120] ο Encrypt the challenge using the cryptographic public key of the networked household appliance 2, which is the cryptographic public key retrieved from the trusted database 5 in the first embodiment above, or the cryptographic public key received from the networked household appliance 2 in the second embodiment above (block 210);
[0121] ο Send the encrypted challenge to the networked household appliance 2 (block 220);
[0122] ο Receive a response from the networked household appliance 2 (block 230);
[0123] ο Check whether the received response to the challenge is valid (block 240); and
[0124] o If it is determined that the received response to the challenge is valid, then authenticating the networked household appliance 2 (block 250);
[0125] - and the connected household appliance 2 is programmed to:
[0126] o receiving an encrypted challenge (block 260);
[0127] o Decrypting the encrypted challenge using the networked home appliance's cryptographic private key (block 270);
[0128] o Calculate a response (block 280); and
[0129] o Send the response to the auxiliary home appliance 4 (block 290).
[0130] In one embodiment, the challenge from the auxiliary home appliance 4 may be a random number that is returned to the auxiliary home appliance 4 as a response from the networked home appliance 2, where it is checked whether the random number matches the random number transmitted to the networked home appliance 2. The response may also be in the form of a number calculated based on the random number and a proprietary algorithm.
[0131] During operation, the customer can run a mobile application on his mobile terminal 6, which responsively starts automatically joining the home appliance 2 to the network 3 with the assistance of one of the customer's home appliances 4 that has been connected to the WLAN 3. In particular, the mobile application causes the joining trigger command to be transmitted to the cloud system, which responsively transmits a joining request to all of the customer's home appliances 4 that have been connected to the WLAN 3, and one of all of these customer's home appliances responsively authenticates the joining home appliance 2.
[0132] In various embodiments, the customer's home appliances 4 that are already connected to the WLAN 3 are programmed to periodically search for additional smart home appliances 2 to be assisted in joining the WLAN 3 .
[0133] When the auxiliary household appliance 4 receives the network access assistance request from the networked household appliance 2, the auxiliary household appliance 4 is programmed to request the customer to authorize the automatic network access of the networked household appliance 2 to the WLAN 3 through the auxiliary household appliance 4. The request can be transmitted to the customer via the control panel of the auxiliary household appliance 4 and / or via the customer mobile terminal 6.
[0134] When the customer authorizes the on-line configuration, the auxiliary home appliance 4 starts to assist the on-line home appliance 2 by performing the above-mentioned authentication of the on-line home appliance 2 .
[0135] In various embodiments, the auxiliary home appliance 4 is programmed to establish a connection with the networked home appliance 2 or send a connectionless message to the networked home appliance in response to a network access authorization command received from the seller of the networked home appliance 2 and generated and transmitted to the auxiliary home appliance 4 in response to the networked home appliance 2 registering to the customer's account.
[0136] The customer account can be indexed, for example, using the customer's email account or phone number or any other unique combination, and then, during the registration of the networked home appliance 2 to the customer account, the product identification code (i.e., model, type, etc.) and its serial number are provided and linked to the customer account, which should be unique in the production of the networked home appliance 2 of a specific model.
[0137] In this embodiment, when the networked home appliance 2 is authenticated, before providing the WLAN credentials to the networked home appliance 2, the auxiliary home appliance 4 can be further programmed to check whether the product identification code and serial number provided during the registration of the networked home appliance 2 to the customer account match the stored product identification code and serial number associated with the customer account, and if this further check also has a positive result, provide the WLAN credentials to the networked home appliance 2.
[0138] Based on the foregoing, those skilled in the art can easily understand the technical advantages and innovative features of the present invention.
[0139] In particular, the present invention allows avoiding the need for the customer to have specific technical skills by implementing an automatic configuration process, in which one of the following steps 1.a, 1.b, 1.c and the following step 2 are performed:
[0140] 1.a) Simplify the automatic configuration process with the support of the seller, which is compatible with e-commerce services and platforms;
[0141] 1.b) In the case of network access performed through the customer mobile terminal 6, require one operation on the app (i.e., select the "Add Device" function) to network the networked home appliance 2;
[0142] 1.c) Require one operation (i.e., select the "Accept Device" function) on the auxiliary home appliance 4 or a smart device 6 connected (via a local or remote network); and
[0143] 2.) Authenticate the networked home appliance 2 as part of the same ecosystem or company product, such that the auxiliary home appliance 4 already configured in the network 3 does not share credentials with any home appliance, but only with trusted / identified home appliances (such as the networked home appliance 2).
Claims
1. A system (1) for allowing a first household appliance (2) to automatically connect to a network (3) with the assistance of a second household appliance (4) connected to the network (3), wherein, The second household appliance (4) is configured to: ο Store network connection credentials by means of which the second household appliance (4) connects to the network (3); ο Receive an access assistance request from the first household appliance (2) and containing the unique identifier of the first household appliance (2); ο Authenticate the first household appliance (2) based on the unique identifier in the received access assistance request; And ο Provide the network connection credentials to the first household appliance (2) when the first household appliance (2) is authenticated; And the first household appliance (2) is configured to: ο Broadcast an access request; ο Receive the network connection credentials from the second household appliance (4); ο Connect to the network (3) using the received network connection credentials; It is characterized in that the second household appliance (4) is further configured to: - Obtain the public cryptographic key of the first household appliance (2); and - Authenticate the first household appliance (2) based on the public cryptographic key of the first household appliance (2) and an asymmetric cryptographic authentication protocol.
2. The system (1) according to claim 1, wherein, For authenticating the first household appliance (2), the second household appliance (4) is further configured to: - Access a public cryptographic key database (5) in which the public cryptographic keys of household appliances are stored associated with the unique identifiers of these household appliances, to retrieve from the public cryptographic key database (5) the public cryptographic key of the first household appliance (2) stored associated with the unique identifier of the first household appliance; And - Authenticate the first household appliance based on the public cryptographic key of the first household appliance (2) retrieved from the public cryptographic key database (5) and based on the asymmetric cryptographic authentication protocol.
3. The system (1) according to claim 1, wherein, For authenticating the first household appliance (2), the second household appliance (4) is further configured to: - Access a public cryptographic key database (5) in which values calculated based on a one-way function from the public cryptographic keys of household appliances are stored associated with the unique identifiers of these household appliances, the one-way function converting these public cryptographic keys into values representing these public cryptographic keys, conveniently a hash of the public cryptographic key, to retrieve from the public cryptographic key database (5) the value calculated based on the public cryptographic key of the first household appliance (2) and stored associated with the unique identifier of the first household appliance; - Communicate with the first household appliance (2) to receive from the first household appliance the stored public cryptographic key of the first household appliance (2); - Calculate a value according to the public cryptographic key received from the first household appliance (2) and based on the same one-way function, the value retrieved from the public cryptographic key database (5) and stored associated with the unique identifier of the first household appliance is calculated based on the one-way function from the public cryptographic key of the first household appliance; - Check whether the value retrieved from the public cryptographic key database (5) matches the value calculated according to the public cryptographic key of the first household received from the first household appliance; - If it is determined that the stored value retrieved from the public cryptographic key database (5) matches the calculated value calculated based on the public cryptographic key of the first household appliance received from the first household appliance, then authenticate the first household appliance (2) based on the public cryptographic key of the first household appliance received from the first household appliance and based on the asymmetric cryptographic authentication protocol.
4. The system (1) according to any one of the preceding claims, wherein, The second household appliance (4) is configured to authenticate the first household appliance (2) based on the asymmetric cryptographic challenge-response authentication protocol.
5. The system (1) according to claim 4, wherein, According to the asymmetric cryptographic challenge-response authentication protocol, the second household appliance (4) is configured to: ο Generate a challenge for the first household appliance (2); ο Encrypt the challenge using the public cryptographic key of the first household appliance (2); ο Send the encrypted challenge to the first household appliance (2); ο Receive a response from the first household appliance (2); ο Check whether the received response to the challenge is valid; And ο If it is determined that the received response to the challenge is valid, then authenticate the first household appliance (2); And the first household appliance (2) is configured to: ο Receive the encrypted challenge; ο Decrypt the encrypted challenge using the private cryptographic key of the first household appliance; ο Calculate a response and send the response to the second household appliance (4).
6. The system (1) according to any one of the preceding claims, wherein, The first household appliance (2) broadcasts the network access assistance request in response to detecting an auxiliary availability announcement, which is broadcast by the second household appliance (4) and announces the availability of the second household appliance to assist the first household appliance (2) in accessing the network (3).
7. The system (1) according to any one of the preceding claims 1 to 5, wherein, The first household appliance (2) broadcasts the network access assistance request in response to receiving a network access trigger command from a customer mobile terminal (6) communicating with the first household appliance (4).
8. The system (1) according to claim 7, wherein, The network access trigger command is generated by the customer mobile terminal (6) in response to a customer trigger gesture or a trigger voice command spoken by the customer on the customer mobile terminal (6).
9. The system (1) according to any one of the preceding claims, wherein, The second household appliance (4) is configured to become authorized to assist the first household appliance (2) in accessing the network (3) by receiving a network access authorization command from one or both of the control panel of the second household appliance (4) and the customer mobile terminal (6) directly or indirectly connected to the second household appliance (4).
10. The system (1) according to any one of the preceding claims, wherein, The second household appliance (4) is configured to become authorized to assist the first household appliance (2) in accessing the network (3) by receiving, from the seller of the first household appliance (2) or the cloud system, and in response to the first household appliance (2) registering to the customer's account, a network access authorization command.
11. A software module that can be loaded in a first household appliance (2) to be connected to a network (3) and in a second household appliance (4) already connected to the network (3); when executed by the first household appliance and the second household appliance (2, 4), these software modules are designed to configure the first household appliance and the second household appliance (2, 4) to cooperate so that the first household appliance (2) can automatically connect to the network (3) with the assistance of the second household appliance (4) already connected to the network (3) according to any one of the preceding claims.
12. A method for connecting a household appliance to a network, the method comprising the following steps: - Broadcasting an access assistance request by a first household appliance, the access assistance request including a unique identifier of the first household appliance; - Receiving the access assistance request in a second household appliance; - Obtaining a public cryptographic key of the first household appliance by the second household appliance based on the unique identifier; - Authenticating the first household appliance in the second household appliance based on the public cryptographic key and based on an asymmetric cryptographic authentication protocol; - After authenticating the first household appliance, sending network connection credentials of the second household appliance to the first household appliance; And - Connecting the first household appliance to the network using the network connection credentials of the second household appliance.
13. The method according to claim 12, wherein Obtaining the public cryptographic key of the first household appliance includes: - The second household appliance accessing a public cryptographic key database in which the public cryptographic keys of household appliances are stored in association with the unique identifiers of these household appliances, and - Identifying in the public cryptographic key database the public cryptographic key associated with the unique identifier of the first household appliance.
14. The method according to claim 12, wherein The step of obtaining the public cryptographic key of the first household appliance includes: - The second household appliance accessing a public cryptographic key database in which values calculated based on a one-way function from the public cryptographic keys of household appliances are stored in association with the unique identifiers of these household appliances, and - Identifying in the database a first value calculated based on the public cryptographic key of the first household appliance; And the step of authenticating the first household appliance includes: - Sending the public cryptographic key of the first household appliance from the first household appliance to the second household appliance; - Calculating a second value in the second household appliance based on the one-way function from the public cryptographic key received from the first household appliance; - Checking whether the first value matches the second value; - If the first value matches the second value, authenticating the first household appliance based on the public cryptographic key received from the first household appliance and based on the asymmetric cryptographic authentication protocol.