Network access method, network system and storage medium

By using ternary information verification of ECDH key, static key and network password in wireless grid networks, the problems of equipment legality and security in the network are solved, and equipment authentication and network expansion with low power consumption and high security are achieved.

CN120378880APending Publication Date: 2025-07-25湖北星纪魅族集团有限公司
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510693257.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

How to ensure the legality and security of devices within the network in a wireless grid network, especially in multi-hop interconnects and mesh topology, prevent man-in-the-middle attacks and ensure device legality and data security.

Method used

The device authentication is used to combine ECDH key, static key and network password for ternary information to generate a session key to ensure the legality and security of the devices in the network.

Benefits of technology

Through the verification of ternary information, the legality and security of the devices in the network are ensured, the difficulty of user interaction is reduced, network security is optimized, computing resources is saved, the uniqueness of network addresses is ensured, and the network relay function is provided to expand the scalability of the network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378880A_ABST
    Figure CN120378880A_ABST
Patent Text Reader

Abstract

The invention relates to a network access method, a network system and a storage medium. Obtaining a second network password; receiving a public key, a random number and a first encryption confirmation code sent by the wireless device; calculating a second shared key based on the public key of the wireless device and the private key of the network node; obtaining a second static key from the network node; performing calculation based on ternary information of a second shared key, a second static key and a second network password by adopting a key derivation algorithm to obtain a second network confirmation key; encrypting the received random number by using a second network acknowledgement key to generate a second encryption acknowledgement code; confirming that the second encryption confirmation code is equal to the received first encryption confirmation code; calculating to obtain a session key based on the network identifier, the second static key and the second network password; encrypting the session key by using a second network confirmation key to generate an encrypted session key; the encrypted session key is sent to the wireless device. Therefore, the legality and the data security of the equipment in the network can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technologies, and particularly to an access method, a network system, and a storage medium. Background Art

[0002] With the multi-hop interconnection and mesh topology characteristics, wireless mesh networks (i.e., Mesh networks) have evolved into an effective solution applicable to various wireless access networks such as broadband home networks, community networks, enterprise networks, and metropolitan area networks. However, how to ensure the legality and security of devices within the network has become an urgent problem to be solved currently. Summary of the Invention

[0003] Embodiments of the present disclosure provide an access method, a network system, a storage medium, etc.

[0004] According to a first aspect of the present disclosure, there is provided an access method applied to a network node and a wireless device applying for network access. The method includes:

[0005] At the wireless device: receiving network information broadcast by the network node and a public key in a public-private key pair of the network node; inputting a first network password obtained through an out-of-band method; generating a public-private key pair of the wireless device and sending the public key therein to the network node; calculating a first shared key based on the private key in the public-private key pair of the wireless device and the received public key of the network node; obtaining a preset first static key from the wireless device; calculating a first network confirmation key based on the first shared key, the first static key, and the first network password triple information by using a key derivation algorithm; generating a random number and encrypting the random number with the first network confirmation key to generate a first encrypted confirmation code; sending the random number and the first encrypted confirmation code to the network node for device authentication;

[0006] At the network node: obtain a second network password, where the second network password is the same as the first network password transmitted out-of-band to the wireless device; receive the public key of the wireless device, the random number, and the first encrypted confirmation code sent by the wireless device; calculate a second shared key based on the public key of the wireless device and the private key of the network node; obtain a preset second static key from the network node; use the key derivation algorithm to calculate a second network confirmation key based on the three elements of the second shared key, the second static key, and the second network password; encrypt the received random number with the second network confirmation key to generate a second encrypted confirmation code; confirm that the second encrypted confirmation code is equal to the received first encrypted confirmation code; calculate a session key based on a network identifier, the second static key, and the second network password; encrypt the session key with the second network confirmation key to generate an encrypted session key; send the encrypted session key to the wireless device so that the wireless device and the network node can perform encrypted communication through the session key.

[0007] Optionally, the method further includes: at the wireless device: send the device unique identifier of the wireless device to the network node; at the network node: calculate a unique device address within the network based on the received device unique identifier of the wireless device; encrypt the unique device address within the network with the second network confirmation key to generate an encrypted network address; send the encrypted network address to the wireless device.

[0008] Optionally, the method further includes: at the wireless device: broadcast locally generated network information so that other wireless devices applying for network access outside the broadcast coverage of the network node but within the broadcast coverage of the wireless device can obtain the session key via the wireless device to communicate with the network node within the network.

[0009] Optionally, the method further includes: at the wireless device: send the out-of-band input method and / or out-of-band output method supported by the wireless device to the network node; at the network node: send the out-of-band method specified based on the received out-of-band input method and / or out-of-band output method supported by the wireless device to the wireless device so that the wireless device obtains the first network password according to the out-of-band method specified by the network node.

[0010] Optionally, the method further includes: at the wireless device: in response to a network search instruction input by a user, searching for network information broadcast by a nearby network node; in response to receiving the network information broadcast by the network node, outputting prompt information related to the network information; in response to an instruction to apply for network access input by the user, sending a network access request to the network node; at the network node: receiving the network access request sent by the wireless device; sending a network configuration start instruction to the network node, the network configuration start instruction including a public key in a public-private key pair of the network node.

[0011] Optionally, the network access request includes: the algorithm type supported by the wireless device; the out-of-band input method and / or out-of-band output method supported by the wireless device; the unique device identifier of the wireless device, and the network configuration start instruction further includes: the shared key calculation method; the key derivation algorithm; the out-of-band method.

[0012] Optionally, the wireless device includes smart glasses.

[0013] According to a second aspect of the present disclosure, there is provided a network system, including: at least one network node and at least one wireless device applying for network access,

[0014] At the wireless device: receiving the network information broadcast by the network node and the public key in a public-private key pair of the network node; inputting a first network password obtained through an out-of-band method; generating a public-private key pair of the wireless device and sending the public key therein to the network node; calculating a first shared key based on the private key in the public-private key pair of the wireless device and the received public key of the network node; obtaining a preset first static key from the wireless device; using a key derivation algorithm to calculate a first network confirmation key based on the three-element information of the first shared key, the first static key, and the first network password; generating a random number and encrypting the random number with the first network confirmation key to generate a first encrypted confirmation code; sending the random number and the first encrypted confirmation code to the network node for device authentication;

[0015] At the network node: obtain a second network password, which is the same as the first network password transmitted out-of-band to the wireless device; receive the public key of the wireless device, the random number, and the first encryption confirmation code sent by the wireless device; calculate a second shared key based on the public key of the wireless device and the private key of the network node; obtain a preset second static key from the network node; use the key derivation algorithm to calculate a second network confirmation key based on the ternary information of the second shared key, the second static key, and the second network password; encrypt the received random number with the second network confirmation key to generate a second encryption confirmation code; confirm that the second encryption confirmation code is equal to the received first encryption confirmation code; calculate a session key based on a network identifier, the second static key, and the second network password; encrypt the session key with the second network confirmation key to generate an encrypted session key; send the encrypted session key to the wireless device, so that the wireless device and the network node can perform encrypted communication through the session key.

[0016] According to a third aspect of the present disclosure, there is provided a non-transitory machine-readable storage medium having executable code stored thereon, which when executed by a processor of an electronic device, causes the processor to execute the method as described in the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] By describing the exemplary embodiments of the present disclosure in more detail in conjunction with the accompanying drawings, the above and other objects, features, and advantages of the present disclosure will become more apparent, wherein in the exemplary embodiments of the present disclosure, the same reference numerals generally represent the same components.

[0018] Figure 1 、 Figure 2 FIG. shows a schematic flowchart of an access method according to an embodiment.

[0019] Figure 3 FIG. shows a schematic diagram of a network creation process according to an embodiment.

[0020] Figure 4 FIG. shows a schematic diagram of a process of joining a network according to an embodiment.

[0021] Figure 5 FIG. shows a schematic diagram of a network relay process according to an embodiment.

[0022] Figure 6 FIG. shows a schematic diagram of the structure of a network system according to an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] The preferred embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although the preferred embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.

[0024] Those skilled in the art should understand that the terms "first", "second", etc. in the specification, claims and drawings of the present disclosure are used to distinguish similar objects, rather than to describe a specific order or sequence, and have no additional limiting effect.

[0025] The present disclosure creatively proposes to use a three - element information combination of an ECDH (Elliptic Curve Diffie - Hellman) key, a static key, and a network password to verify the legality of the network - accessing device, so as to ensure the legality and security of the devices within the network. The present disclosure also proposes to use a three - element information combination of a network identifier, a second static key, and a second network password to generate a session key, so as to ensure the security of the session key.

[0026] Figure 1 、 Figure 2 Fig. shows a schematic flowchart of a network - accessing method according to an embodiment of the present disclosure.

[0027] Figure 1 What is shown is the step - by - step process executed at the wireless device end. That is, Figure 1 The steps S110 to S180 shown are executed by the wireless device. The wireless device can be any device with wireless transmission capabilities. Exemplarily, the wireless device can include, but is not limited to, smart glasses. Smart glasses can include, but are not limited to, Augmented Reality (AR) glasses, Extended Reality (XR) glasses.

[0028] Figure 2 What is shown is the step - by - step process executed at the network node end. That is, Figure 2 The steps S210 to S295 shown are executed by the network node. The network node can be any device node within the network. The network node can be, for example, a device node that creates the network (i.e., the creator of the network), or a device node that enables the network relay function. Regarding the network relay function, reference can be made to the description below.

[0029] Next, in combination with Figure 1 、 Figure 2 An exemplary description will be given of the network - accessing process of the wireless device.

[0030] Refer toFigure 1 In step S110, network information broadcast by a network node and a public key in a public-private key pair of the network node are received.

[0031] The network information may include, but is not limited to, a network name, a network ID, and a network address of the network node.

[0032] In some embodiments, the network node may first broadcast the network information and then, after receiving an access request sent by a wireless device, send the public key in its own public-private key pair to the wireless device. That is to say, for the network node, the sending of the network information and the public key may not be synchronized, but may have a sequence. For example, the network node may first broadcast the network information externally and then, after receiving an access request sent by the wireless device, send the public key to the wireless device.

[0033] Correspondingly, for the wireless device, the reception of the network information and the public key may not be synchronized, but may have a sequence. For example, the wireless device may first receive the broadcast information, and after determining to join the network based on the broadcast information, send an access request to the network node, and then receive the public key sent by the network node.

[0034] In step S120, a first network password is input, and the first network password is obtained through an out-of-band method.

[0035] The out-of-band method (Out-of-Band, OOB) refers to a physical or logical channel independent of the network communication channel.

[0036] Obtaining the first network password through an out-of-band method can avoid man-in-the-middle attacks and enhance security.

[0037] One of the out-of-band methods supported by the wireless device can be selected as the method for obtaining the first network password. OOB includes two types: input out-of-band (Input OOB) and output out-of-band (Output OOB). Input OOB refers to the ability of the device to input information. Output OOB refers to the ability of the device to output information.

[0038] In some embodiments, the network node may specify the out-of-band method for the wireless device to obtain the first network password. Exemplarily, the wireless device may send the input out-of-band method and / or output out-of-band method supported by itself to the network node. The network node may send the specified out-of-band method based on the received input out-of-band method and / or output out-of-band method supported by the wireless device to the wireless device, so that the wireless device obtains the first network password according to the out-of-band method specified by the network node.

[0039] For example, for a device with information input capabilities (such as supporting voice input), the first network password can be obtained through information input; for a device without information input capabilities, the input of the first network password can be achieved by leveraging the information output capabilities of the device. For example, the first network password can be obtained by leveraging the screen display function of the device, the specific number of times (or frequency) of light flashing, etc., which are the capabilities of expressing information.

[0040] In step S130, a public-private key pair of the wireless device is generated, and the public key is sent to the network node.

[0041] In step S140, a first shared key is calculated based on the private key in the public-private key pair of the wireless device and the public key of the received network node.

[0042] Based on the private key in the public-private key pair of the wireless device and the public key of the received network node, the first shared key can be calculated using the ECDH algorithm to ensure that the data cannot be eavesdropped or cracked. The ECDH algorithm is a key agreement algorithm based on ECC (Elliptic Curves Cryptography). The core idea of the ECDH algorithm can be summarized as follows: the wireless device can calculate a unique ECDHSecret (i.e., the first shared key) based on its own private key and the public key transmitted by the network node, and this ECDHSecret is the same as the ECDHSecret (i.e., the second shared key) calculated by the network node based on its own private key and the public key transmitted by the wireless device.

[0043] In step S150, a preset first static key is obtained from the wireless device.

[0044] The first static key can be set in the device before leaving the factory. The first static key can be a static one-time-one-key.

[0045] In some embodiments, the static one-time-one-key may refer to the same static key being used for the same device type, and different static keys being used for different device types. In these embodiments, the device types of all network nodes in the same network are the same. That is, only devices of the same type can form a network.

[0046] In some other embodiments, the static one-time-one-key can be a broader concept and is not limited to one static key for one device model. For example, the same static key can be configured for all devices under the same manufacturer or the same manufacturer alliance. For instance, the same static key can be pre-set in the Full Function Devices and Low Power Devices belonging to the same manufacturer. Thus, in these embodiments, networking between different types of devices is supported.

[0047] In step S160, a first network confirmation key is calculated based on the first shared key, the first static key, and the first network password triple information by using a key derivation algorithm.

[0048] A key derivation algorithm (Key Derivation Function, KDF) is a method for converting input information into a key with higher security. The key derivation algorithm can be but is not limited to the triple key derivation algorithm HKDF (HMAC-based Key Derivation Function), such as the SHA256 algorithm. Exemplarily, the first shared key, the first static key, and the first network password can be used to derive a unique first network confirmation key through the HKDK algorithm (such as the simple SHA256 algorithm).

[0049] In step S170, a random number is generated and encrypted with the first network confirmation key to generate a first encrypted confirmation code. The first encrypted confirmation code is the result of encrypting the random number with the first network confirmation key. Exemplarily, the random number can be encrypted by using the AES (Advanced Encryption Standard) encryption algorithm.

[0050] In step S180, the random number and the first encrypted confirmation code are sent to the network node for device authentication.

[0051] Figure 2 The flowchart showing the device authentication by the network node is illustrated.

[0052] See Figure 2 , in step S210, a second network password is obtained.

[0053] The second network password refers to the real network password, that is, the first network password that is transmitted out of band to the wireless device seeking to access the network.

[0054] Taking the example that the network node refers to the creator of the network, the second network password can be input by the user when creating the network through the network node. When creating the network, the user can input the network name and network password to create the network. The input method can include but is not limited to any one of multimodal interaction methods such as voice interaction, keyboard input, eye tracking input, etc. Exemplarily, the network password can be a 6-digit numeric password.

[0055] In step S220, the public key, random number, and first encryption confirmation code of the wireless device sent by the wireless device are received.

[0056] As Figure 1 shown, the wireless device can first send the public key to the network node, and then send the random number and the first encryption confirmation code to the network node. That is, the network node can first receive the public key, and then receive the random number and the first encryption confirmation code.

[0057] In step S230, a second shared key is calculated based on the public key of the wireless device and the private key of the network node.

[0058] In the same way as the calculation method of the first shared key, the network node can calculate the second shared key based on the public key of the wireless device and the private key of the network node by using the ECDH algorithm. Under normal circumstances, if the public keys sent by both parties to each other are not tampered with, the first shared key and the second shared key calculated by both parties should be the same.

[0059] In step S240, a preset second static key is obtained from the network node.

[0060] The second static key preset in the network node is the same as the first static key preset in the wireless device, indicating that the wireless device applying to access the network is legal in terms of device type and can form a network with the network node. Conversely, if the second static key preset in the network node is different from the first static key preset in the wireless device, it indicates that the wireless device applying to access the network is illegal in terms of device type and cannot form a network with the network node.

[0061] In step S250, a key derivation algorithm is used to calculate a second network confirmation key based on the three - element information of the second shared key, the second static key, and the second network password.

[0062] The key derivation algorithm used by the network node to calculate the second network confirmation key is the same as the key derivation algorithm based on three - element information used by the wireless device to calculate the first network confirmation key.

[0063] In step S260, the received random number is encrypted with the second network confirmation key to generate a second encryption confirmation code.

[0064] The encryption algorithm used by the network node to encrypt the received random number is the same as the encryption algorithm used by the wireless device to encrypt the generated random number.

[0065] In step S270, it is confirmed that the second encryption confirmation code is equal to the received first encryption confirmation code.

[0066] After generating the second encryption confirmation code, the network node can compare whether the second encryption confirmation code is equal to the received first encryption confirmation code. The equality of the second encryption confirmation code and the received first encryption confirmation code indicates that the wireless device is three-factor secure. Three-factor security includes security based on a static key, security based on a first network password, and security based on a first shared key. Thus, the legitimacy and security of devices within the network can be fully guaranteed.

[0067] In the case where it is confirmed that the second encryption confirmation code is equal to the received first encryption confirmation code, the network node can execute steps S280 to S295 to enable the wireless device to access the network. Conversely, in the case where it is confirmed that the second encryption confirmation code is not equal to the received first encryption confirmation code, it indicates that the three-factor security authentication of the wireless device fails, and the network node does not execute steps S280 to S295 to reject the wireless device from accessing the network.

[0068] In step S280, a session key is calculated based on a network identifier, a second static key, and a second network password. The network identifier can include, but is not limited to, a network name and / or a network ID.

[0069] The acquisition of the network identifier, the second static key, and the second network password has nothing to do with the wireless device. Therefore, the session key can be pre-calculated. Taking the network node as the creator of the network as an example, when the user creates a network through the network node, the session key can be calculated based on the network identifier, the second static key, and the second network password.

[0070] In some embodiments, an irreversible algorithm (such as an irreversible obfuscation algorithm) can be used to generate the session key. Exemplarily, algorithms such as SHA128, HMAC256, MD5, etc. can be used to generate the session key.

[0071] In step S290, the session key is encrypted with a second network confirmation key to generate an encrypted session key.

[0072] Exemplarily, the AES (Advanced Encryption Standard) encryption algorithm can be used to encrypt the session key with the second network confirmation key.

[0073] In step S295, the encrypted session key is sent to the wireless device, enabling the wireless device and the network node to perform encrypted communication using the session key.

[0074] After receiving the encrypted session key, the wireless device can decrypt the encrypted session key using the first network confirmation key to obtain the session key. Thus, the wireless device can perform data communication with any node within the network, and all data can be encrypted using the session key. The encryption method can be, but is not limited to, the AES encryption algorithm.

[0075] In some embodiments, when the network node confirms that the second encryption confirmation code is equal to the received first encryption confirmation code, the network node can also assign a network address (i.e., the device address within the network) to the wireless device.

[0076] To ensure the uniqueness of the assigned network address, the wireless device can send its unique device identifier to the network node. The network node can calculate the unique device address within the network based on the received unique device identifier of the wireless device. Then, the network node can encrypt the unique device address within the network using the second network confirmation key to generate an encrypted network address and send the encrypted network address to the wireless device. Among them, the encryption method can be, but is not limited to, the AES encryption algorithm. After receiving the encrypted network address, the wireless device can decrypt the encrypted network address using the first network confirmation key to obtain the network address assigned by the network node.

[0077] The unique device identifier can be, but is not limited to, the Bluetooth MAC public address (BLE MAC Public Address). Exemplarily, the network node can derive a 2-byte Network Address (network address) based on the BLE MAC Public Address. The derivation algorithm needs to ensure the uniqueness of the Network Address. For example, Network Address = Reverse(Byte[0:1] of BLE MAC Public Address), where Reverse represents the bitwise inversion calculation.

[0078] In some embodiments, after successfully accessing the network, the wireless device can also broadcast locally generated network information, enabling other wireless devices applying for network access that are outside the broadcast coverage range of the network node but within the broadcast coverage range of the wireless device to obtain the session key via the wireless device and thus communicate with the network nodes within the network. Thus, other wireless devices that are outside the broadcast coverage range of the network node but within the broadcast coverage range of the wireless device can successfully access the network by relying on the network relay function provided by the wireless device. The network access process is consistent with the description combined with Figure 1 、 Figure 2 above.

[0079] In some embodiments, the wireless device may search for network information broadcast by a network node nearby in response to a network search instruction input by a user. In response to receiving the network information broadcast by the network node, the wireless device outputs prompt information related to the network information to prompt the user whether to join the network. The output method of the prompt information may include but is not limited to any one of voice output, text output, and light prompt. The content of the prompt information may include the network name and a prompt statement whether to join the network. In response to the network access application instruction input by the user, the wireless device sends a network access request to the network node. In response to receiving the network access request sent by the wireless device, the network node sends a network configuration start instruction to the network node, and the network configuration start instruction includes a public key in a public-private key pair of the network node.

[0080] Exemplarily, the network access request may also include, but is not limited to: the algorithm type supported by the wireless device; the out-of-band input method and / or out-of-band output method supported by the wireless device; the device unique identifier of the wireless device. The network configuration start instruction may also include, but is not limited to: the shared key calculation method; the key derivation algorithm; the out-of-band method.

[0081] Taking wireless devices as smart devices (such as AR / XR devices) as an example, smart devices have a big difference compared to traditional IoT (Internet of Things) devices, that is, smart devices have multimodal interaction capabilities, such as voice interaction, screen display, virtual keyboard input, etc. The present disclosure uses the multimodal interaction capabilities of wireless devices to allow each wireless device to actively initiate an "application for network access", which greatly reduces the difficulty of user interaction compared to other Mesh networking methods (such as invitation-based access methods), and is a very friendly networking mode for scenarios such as team travel. The invitation-based access method means that if an IoT device wants to join the Mesh network, it must be invited by the network owner. The operation threshold is high, especially when many IoT devices need to be invited. The operation is very difficult.

[0082] The details involved in the present disclosure are further exemplified below in conjunction with specific embodiments.

[0083] Figure 3 A schematic diagram of a network creation process according to an embodiment is shown.

[0084] See also Figure 3 ,The network creation process mainly includes steps 1.1 to 1.4.

[0085] Step 1.1: In response to a user input instruction to create a team, a network is created.

[0086] The instruction for creating a team input by the first user (i.e., User 1) may include a network name and a 6-digit PinCode. The 6-digit PinCode corresponds to the second network password mentioned above. The input methods may include but are not limited to multimodal interaction methods such as voice interaction, keyboard input, eye tracking input, etc.

[0087] Step 1.2: Generate a session key.

[0088] Based on the network name and 6-digit PinCode input by User 1, Device 1 automatically and randomly generates an 8-digit hexadecimal ID (corresponding to the network ID mentioned above) through software, and then adds the 32-byte symmetric key Static Key information of the device solution provider with one key for each type. Through an irreversible confusion algorithm, a unique session key (Network Key) within the network is generated. Optional solutions include but are not limited to SHA128 / HMAC256 / MD5, etc. For example, NetworkKey = HMAC256(Name, ID, Static Key, PinCode). Among them, Name is the network name, and Static Key is the static key of Device 1.

[0089] Step 1.3: Broadcast network information.

[0090] Device 1 periodically (e.g., 500ms) broadcasts the locally generated Mesh network information externally, facilitating other intelligent devices to discover the network and join the network, and at the same time starts the discoverable broadcast timing. The recommended broadcast network information includes "network name, 8-byte network ID, 2-byte network address of this device".

[0091] Step 1.4: Stop broadcasting.

[0092] When the discoverable broadcast timing times out (e.g., 60 seconds of discoverable time), Device 1 can automatically stop broadcasting the teaming discoverable broadcast, thereby stopping other devices from searching for the network and joining the network.

[0093] User 1 can manually turn on the teaming discoverable broadcast of the network again as needed.

[0094] Figure 4 Shows a schematic diagram of the process of joining a network according to an embodiment.

[0095] See Figure 4 , the process of joining a network mainly includes steps 2.1 to 2.12.

[0096] Step 2.1: Obtain the instruction for finding a team input by the user.

[0097] The second user (i.e., User 2) inputs the instruction "find a team" by means of the multimodal interaction ability of Device 2, such as voice or menu touch navigation.

[0098] Step 2.2: TTS announces the search results.

[0099] Device 2 periodically enables local BLE (Bluetooth Low Energy) scanning.

[0100] After detecting the "team-up discoverable broadcast" sent by Device 1, through multimodal interaction, such as voice TTS (TextTo Speech) announcement, prompt User 2 with "Team-up of Zhang San has been detected. Do you want to join?" and wait for the instruction feedback from User 2.

[0101] Step 2.3: Obtain the instruction on whether to team up input by the user.

[0102] User 2 gives the instruction feedback "Confirm to join the network".

[0103] Step 2.4: Device 2 sends a network access request to Device 1.

[0104] The network access request may include the provision capabilities provided by Device 2. The provision capabilities are used to characterize the configuration capabilities and features supported by Device 2 when applying to join the network.

[0105] The provision capabilities may specifically include, but are not limited to: the type of asymmetric encryption algorithm, Input OOB and OutputOOB capabilities, BLE MAC Public Address. Among them, the type of asymmetric encryption algorithm defaults to the FIPS P-256 Elliptic Curve algorithm. The Input OOB and Output OOB capabilities are used to indicate whether the current device has the capabilities of keyboard input, voice input, or text display.

[0106] Step 2.5: Device 1 sends a provision start instruction to Device 2.

[0107] The provision start instruction is used to interact authentication information with Device 2. The provision start instruction may include, but is not limited to, the type of asymmetric encryption algorithm, a 32-byte Public Key, and a field indicating that Device 2 needs to provide Input OOB information. Among them, the 32-byte Public Key is also the public key in the public-private key pair of Device 1. The private key in the public-private key pair of Device 1 is securely stored locally on Device 1.

[0108] Step 2.6: Device 2 sends the public key to Device 1.

[0109] Device 2 generates a public-private key pair, sends the public key to Device 1, and securely stores the private key locally.

[0110] Step 2.7: Remind User 2 to enter a password.

[0111] Device 2 can use multimodal interaction, such as voice TTS, to remind User 2 to enter a 6-digit Pin Code. The Pin Code can be obtained through an out-of-band method.

[0112] Step 2.8: User 2 enters the password

[0113] User 2 can use multimodal interaction, such as voice commands, to enter a 6-digit Pin Code.

[0114] Step 2.9: Device 2 sends the random number and the encrypted confirmation code to Device 1.

[0115] Device 2 generates a Random (e.g., 16 bytes) and an encrypted confirmation code (ConfirmationValue), and sends both to Device 1 for device legitimacy authentication. The encrypted confirmation code corresponds to the first encrypted confirmation code mentioned above.

[0116] The specific algorithm for the encrypted confirmation code is as follows.

[0117] Based on the FIPS P-256 Elliptic Curve and the ECC asymmetric encryption algorithm, the ECDHSecret is calculated by integrating the local Private Key and the other party's Public Key. ConfirmationKey = HKDF(ECDHSecret, Static Key, Pin Code), where HKDF is a three-key derivation algorithm, such as SHA256. ConfirmationValue = AES(ConfirmationKey, Random).

[0118] Step 2.10: Device 1 verifies the legitimacy of Device 2, and if the legitimacy verification passes, sends the encrypted session key and network address to Device 2.

[0119] Device 1 verifies the legitimacy of Device 2 according to the algorithm used to generate the encrypted confirmation code in Step 2.9, combining the Random sent by the other party and the locally calculated ConfirmationKey (corresponding to the second encrypted confirmation code mentioned above). The specific verification process can be seen in the relevant description above. If the legitimacy verification passes, Device 1 sends the encrypted Network Key and Network Address to Device 2.

[0120] SecuredNetworkKey=AES(ConfirmationKey,NetworkKey). SecuredNetworkKey represents the encrypted Network Key. The encryption method of Network Address is similar to that of NetworkKey, that is, SecuredNetworkAddress=AES(ConfirmationKey,NetworkAddress). Network Address=Reverse(Byte[0:1]of BLE MAC Public Address).

[0121] Step 2.11: Notify user 2 of the network access result.

[0122] After receiving the Network Key and Network Address, Device 2 considers that the network access is successful, and notifies User 2 of the network access result through multimodal interaction, such as voice TTS broadcast.

[0123] Step 2.12: Secure Data Communication

[0124] Device 2 can communicate data with any node in the network, and all data is encrypted using NetworkKey. That is, SecuredData = AES (NetworkKey, Data). Among them, SecuredData is the encrypted data, AES is the encryption algorithm, and Data is the data to be transmitted before encryption.

[0125] Figure 5 A schematic diagram of a network relay process according to an embodiment is shown.

[0126] Network relay means that when the "device N" applying to join the network and the network creator "device 1" are too far away to establish stable communication, the device 2 that has already joined the network can join the network.

[0127] See also Figure 5 ,The network relay process mainly includes steps 3.1 to 3.10.

[0128] Steps 3.1 to 3.3 refer to user 2 allowing device 2, which has been connected to the network, to turn on the network relay function through multimodal interaction, such as voice commands. Specifically, in step 3.1, user 2 uses the multimodal interaction capabilities of device 2, such as voice or menu touch navigation, to input the command "find a team". In step 3.2, device 2 determines that it is already in the team, and prompts the user through TTS broadcast "You are already in a team, do you want to invite more friends to join", and waits for user 2's command feedback. In step 3.3, user 2 gives the command feedback "Yes".

[0129] Step 3.4, Device 2 broadcasts network information.

[0130] Device 2 can periodically (e.g., every 500 ms) broadcast locally generated Mesh network information externally, facilitating other smart devices to discover and join the network, and at the same time start the discoverable broadcast timer. It is recommended that the broadcast network information include "network name, 8-byte network ID, and 2-byte local network address of this device".

[0131] Step 3.5, Stop broadcasting.

[0132] When the discoverable broadcast timer times out (e.g., 60 seconds of discoverable time), Device 2 will automatically stop broadcasting the discoverable broadcast, stopping new devices from searching for and joining the network. User 2 can manually turn on the discoverable broadcast of the network again as needed.

[0133] Steps 3.6 to 3.9 are similar to Figure 4 Steps 2.1 to 2.11 therein. Device N can successfully access the network by relaying through Device 2.

[0134] Step 3.10, Secure data communication.

[0135] Device N can communicate data with any node in the network, and all data is encrypted using the NetworkKey.

[0136] In the current field of smart hardware, the standards for Mesh networks include Zigbee, Thread, and BLE Mesh, etc., each with its own advantages and disadvantages. Zigbee and Thread are based on IEEE 802.15.4 MAC / PHY, with advantages such as low power consumption, low latency, low cost, and large capacity. The disadvantages are that the software and hardware ecosystems are not perfect, the number of supported hardware devices is small, and there is no solution for implementation on AR / XR yet. BLE Mesh is based on the MAC / PHY of Bluetooth 4.0. Currently, most devices supporting Bluetooth on the market can support the BLE Mesh network through software upgrade. The disadvantages are low rate, only supporting control commands, the invitation-based network access mode is not friendly to AR-interactive devices, and broadcast flooding reduces communication efficiency and power consumption performance, etc.

[0137] Currently, AR / XR smart hardware generally has the basic capabilities of AI interaction and input display. Therefore, designing a new Mesh network protocol with self-organizing network capabilities, high security, low power consumption, and meeting the requirements of medium and low rate scenarios such as voice interaction and single-color display is very valuable for the interoperability experience of AR / XR products.

[0138] The present disclosure proposes a new Mesh networking communication solution among wireless devices (such as smart devices). Compared with other Mesh networking solutions, it can reduce the complexity of device networking, optimize network security, and improve performance such as lower power consumption and higher speed. More specifically, compared with other Mesh networking solutions, the present disclosure has at least the following beneficial effects.

[0139] 1) Based on the "application-based" network access mode described in combination with the embodiments of the present disclosure Figure 3 、 Figure 4 , each wireless device is allowed to actively initiate an "application for network access", which greatly reduces the difficulty of user interaction compared with other Mesh networking methods.

[0140] 2) The "three-element security solution" described in combination with Figure 4 simplifies the calculation process and saves the consumption of storage and CPU resources while ensuring the legitimacy and security of devices in the network compared with other Mesh solutions.

[0141] 3) Currently, the Network Address of Mesh networking technologies such as Zigbee and BLE Mesh generally adopts a random strategy. For the application-based network access method, the random strategy cannot guarantee the uniqueness of device addresses in the network. The Network Address derivation strategy proposed by the present disclosure ensures that the network addresses of devices in the network are not repeated through the uniqueness of the BLE MAC address, which is more reliable than other solutions using random numbers.

[0142] 4) Mesh networking technologies such as Zigbee and BLE Mesh limit that devices to be networked must be within the connectable distance of the network owner and can only join the network through the invitation-based network access mode. The network relay function proposed by the present disclosure is a function that other Meshes do not have, which ensures the expandability of the network, especially the expandability of the network in the application-based network access mode.

[0143] The present disclosure also proposes a network system.

[0144] The network system includes at least one network node and at least one wireless device applying for network access.

[0145] In the wireless device, the steps S110 to S180 in Figure 1 can be executed.

[0146] In the network node, the steps S210 to S295 in Figure 2 can be executed.

[0147] Figure 6 shows a schematic structural diagram of a network system according to an embodiment.

[0148] As shown Figure 6 Node 1 can create a network and broadcast the locally generated network information externally.

[0149] Nodes 2, 3, and 4 within the broadcast coverage range of Node 1 can join the network by interacting with Node 1. For the specific process of joining the network, please refer to the relevant description above.

[0150] After joining the network, Node 4 can enable the network relay function. Nodes 6 and 7, which are outside the broadcast coverage range of Node 1 but within the broadcast coverage range of Node 4, can both join the network by leveraging the network relay function of Node 4.

[0151] In some embodiments, Nodes 1 to 7 can be Full Function Devices, and Node 8 can be a Low Power Device. Node 8 can join the same network as Nodes 1 to 7. For example, Node 8 can join the network by leveraging the network relay function of Node 7.

[0152] The network access method and network system according to the present disclosure have been described in detail above with reference to the accompanying drawings.

[0153] In addition, the method according to the present disclosure can also be implemented as a computer program or a computer program product, which includes computer program code instructions for executing the above steps defined in the above method of the present disclosure.

[0154] Alternatively, the present disclosure can also be implemented as a non - transitory machine - readable storage medium (or computer - readable storage medium, or machine - readable storage medium), on which executable code (or computer program, or computer instruction code) is stored. When the executable code (or computer program, or computer instruction code) is executed by a processor of an electronic device (or computing device, server, etc.), the processor executes each step of the above - mentioned method according to the present disclosure.

[0155] Those skilled in the art will also understand that the various exemplary logical blocks, modules, circuits, and algorithm steps described in connection with the present disclosure can be implemented as a combination of electronic hardware, computer software, or both.

[0156] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems and methods according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code, which contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0157] The embodiments of the present disclosure have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art in the technical field without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, the practical application, or the improvement of the technology in the market, or to enable other ordinary skill in the art in the technical field to understand the embodiments disclosed herein.

Claims

1. An access method, applied to a network node and a wireless device applying for network access, the method comprising: At the wireless device: Receiving network information broadcast by the network node and the public key in a public-private key pair of the network node; Inputting a first network password, the first network password obtained through an out-of-band method; Generating a public-private key pair of the wireless device and sending the public key therein to the network node; Calculating a first shared key based on the private key in the public-private key pair of the wireless device and the public key of the received network node; Obtaining a preset first static key from the wireless device; Using a key derivation algorithm to calculate a first network confirmation key based on the three-element information of the first shared key, the first static key, and the first network password; Generating a random number and encrypting the random number with the first network confirmation key to generate a first encrypted confirmation code; Sending the random number and the first encrypted confirmation code to the network node for device authentication; At the network node: Obtaining a second network password, the second network password being the same as the first network password sent to the wireless device out of band; Receiving the public key of the wireless device, the random number, and the first encrypted confirmation code sent by the wireless device; Calculating a second shared key based on the public key of the wireless device and the private key of the network node; Obtaining a preset second static key from the network node; Using the key derivation algorithm to calculate a second network confirmation key based on the three-element information of the second shared key, the second static key, and the second network password; Encrypting the received random number with the second network confirmation key to generate a second encrypted confirmation code; Confirming that the second encrypted confirmation code is equal to the received first encrypted confirmation code; Calculating a session key based on a network identifier, the second static key, and the second network password; Encrypting the session key with the second network confirmation key to generate an encrypted session key; Sending the encrypted session key to the wireless device, enabling the wireless device and the network node to perform encrypted communication through the session key.

2. The network access method according to claim 1, wherein The method further comprises: At the wireless device: Sending the device unique identifier of the wireless device to the network node; At the network node: Calculating a unique device address within the network based on the received device unique identifier of the wireless device; Encrypting the unique device address within the network with the second network confirmation key to generate an encrypted network address; Sending the encrypted network address to the wireless device.

3. The network access method according to claim 1, wherein The method further comprises: At the wireless device: Broadcasting locally generated network information externally, enabling other wireless devices applying for network access that are outside the broadcast coverage range of the network node but within the broadcast coverage range of the wireless device to obtain the session key via the wireless device and thus communicate with the network node within the network.

4. The network access method according to claim 1, wherein, The method further comprises: At the wireless device: Send the out-of-band input method and / or out-of-band output method supported by the wireless device to the network node; At the network node: Send the out-of-band method specified based on the received out-of-band input method and / or out-of-band output method supported by the wireless device to the wireless device, so that the wireless device obtains the first network password according to the out-of-band method specified by the network node.

5. The network access method according to claim 1, wherein The method further includes: At the wireless device: In response to a network search instruction input by the user, search for network information broadcast by a nearby network node; In response to receiving the network information broadcast by the network node, output prompt information related to the network information; In response to an application for network access instruction input by the user, send a network access request to the network node; At the network node: Receive the network access request sent by the wireless device; Send a network configuration start instruction to the network node, and the network configuration start instruction includes the public key in a public-private key pair of the network node.

6. The network access method according to claim 5, wherein, The network access request includes: the algorithm type supported by the wireless device; the out-of-band input method and / or out-of-band output method supported by the wireless device; the device unique identifier of the wireless device, The network configuration start instruction further includes: a shared key calculation method; the key derivation algorithm; the out-of-band method.

7. The network access method according to any one of claims 1 to 6, wherein The wireless device includes smart glasses.

8. A network system, comprising: At least one network node and at least one wireless device applying for network access, At the wireless device: Receive the network information broadcast by the network node and the public key in a public-private key pair of the network node; Input a first network password, and the first network password is obtained through an out-of-band method; Generate a public-private key pair of the wireless device and send the public key therein to the network node; Calculate a first shared key based on the private key in the public-private key pair of the wireless device and the public key of the received network node; Obtain a preset first static key from the wireless device; Use the key derivation algorithm to calculate a first network confirmation key based on the first shared key, the first static key, and the first network password triple information; Generate a random number and encrypt the random number with the first network confirmation key to generate a first encrypted confirmation code; Send the random number and the first encrypted confirmation code to the network node for device authentication; At the network node: Obtain a second network password, and the second network password is the same as the first network password transmitted out of band to the wireless device; Receive the public key of the wireless device, the random number, and the first encrypted confirmation code sent by the wireless device; Calculate a second shared key based on the public key of the wireless device and the private key of the network node; Obtain a preset second static key from the network node; Use the key derivation algorithm to calculate a second network confirmation key based on the second shared key, the second static key, and the second network password triple information; Encrypt the received random number with the second network confirmation key to generate a second encrypted confirmation code; Confirm that the second encrypted confirmation code is equal to the received first encrypted confirmation code; Calculate a session key based on a network identifier, the second static key, and the second network password; Encrypt the session key with the second network confirmation key to generate an encrypted session key; Send the encrypted session key to the wireless device, enabling the wireless device and the network node to perform encrypted communication through the session key.

9. A non-transitory machine-readable storage medium having executable code stored thereon, which, when executed by a processor of an electronic device, causes the processor to execute the method according to any one of claims 1 to 7.