Network parameter updating method, router, storage medium and network system

The router actively establishes a secure channel with IoT devices and concurrently updates network parameters, solving the problem of manual modification of multiple devices and improving update efficiency and user experience.

CN120416871APending Publication Date: 2025-08-01HONOR DEVICE CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202411757148.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-29
Publication Date
2025-08-01

AI Technical Summary

Technical Problem

In a home scenario, as the number of IoT devices increases, the operation of manually modifying router network parameters becomes cumbersome and time-consuming, and the user experience is poor.

Method used

By detecting the modification operation of network parameters, the router uses the established secure channel to send updated network parameters asynchronously to multiple IoT devices, realizing concurrent network parameter updates and reducing user manual operations.

Benefits of technology

It improves the efficiency and user experience of network parameter updates of multiple IoT devices, simplifies operational processes, and reduces resource consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416871A_ABST
    Figure CN120416871A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of communication, and provides a network parameter updating method, a router, a storage medium and a network system. The method comprises the steps that a first network parameter modification instruction is received, the first network parameter modification instruction carries a first network parameter, and the first network parameter comprises a first network name SSID and / or a first network password; determining to-be-synchronized IoT equipment from an IoT equipment linked list stored in the router, wherein the IoT equipment linked list is used for storing equipment information of the IoT equipment which passes the security authentication of the router and establishes a secure channel with the router; and asynchronously sending the first network parameter to the plurality of IoT devices to be synchronized through the secure channel of each IoT device to be synchronized. According to the invention, network parameter updating of multiple IoT devices can be efficiently completed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communication technologies, and in particular, to a network parameter update method, a router, a storage medium, and a network system. Background Art

[0002] With the rapid development of Internet of Things (IoT) technologies, the applications of electronic products (IoT devices) developed based on IoT technologies are becoming more and more widespread, such as IoT devices of the home type. In a home scenario, a network parameter (such as a network name and / or a network password) of an IoT device is configured through an electronic device (such as a mobile phone) with display and input capabilities, so that the IoT device can be connected to a router. The mobile phone can also be connected to the router, so that multiple IoT devices can be viewed, managed, and controlled through an application on the mobile phone.

[0003] When the network parameters of the router change, it is necessary for the user to manually modify the network parameters of each IoT device one by one through the mobile phone. When the number of IoT devices is large, the operation is particularly cumbersome and time-consuming, and the user experience is not good. Summary of the Invention

[0004] In view of the above problems, embodiments of the present application provide a network parameter update method, a router, a storage medium, and a network system, which improve the efficiency of updating network parameters for multiple IoT devices.

[0005] According to one aspect of the embodiments of the present application, a network parameter update method is provided. The method is applied to a router and includes: receiving a first network parameter modification instruction, where the first network parameter modification instruction carries a first network parameter, and the first network parameter includes a first service set identifier (SSID) and / or a first network password; determining, from an IoT device linked list stored in the router, IoT devices to be synchronized, where the IoT device linked list is used to store device information of IoT devices that have passed the security authentication of the router and established a secure channel with the router; and asynchronously sending the first network parameter to multiple IoT devices to be synchronized respectively through the secure channels of each IoT device to be synchronized.

[0006] In the embodiments of the present application, when the router detects a modification operation of network parameters, it can determine IoT devices to be synchronized from the IoT device linked list, and send the modified network parameters to some or all of the IoT devices to be synchronized based on the secure channels established between the router and the IoT devices, so as to efficiently complete the update of network parameters of multiple IoT devices and eliminate the cumbersome manual operations of the user. The process of the router sending the modified network parameters to each IoT device is executed concurrently, further improving the update efficiency of network parameters and the user experience.

[0007] In an alternative manner, the first network parameter modification instruction further carries the SSID before modification, and the device information includes the SSID configured by the IoT device; determining the IoT device to be synchronized from the IoT device list stored in the router further includes: determining whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification; if the SSID configured by the IoT device is the same as the SSID before modification, determining the IoT device as the IoT device to be synchronized. By verifying whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification, and determining the IoT device passing the verification as the IoT device to be synchronized, for other IoT devices that fail the verification, since the configured SSID is different from the SSID before modification, it indicates that the physical channel between such an IoT device and the router may have been disconnected, resulting in the failure of the previous network parameter modification. Such IoT devices are not determined as the IoT devices to be synchronized, avoiding subsequent invalid modification operations and reducing unnecessary resource consumption.

[0008] In an alternative manner, the first network parameter modification instruction further carries first frequency band information, and the first frequency band information is used to indicate the network frequency band being modified currently. The device information further includes second frequency band information, and the second frequency band information is used to indicate the frequency band configured by the IoT device; before determining whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification, determining the IoT device to be synchronized from the IoT device list stored in the router further includes: according to the first frequency band information and the second frequency band information, determining whether the frequency band configured by the IoT device in the IoT device list is the same as the network frequency band being modified currently; if the frequency band configured by the IoT device is the same as the network frequency band being modified currently, performing the step of determining whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification; if the frequency band configured by the IoT device is different from the network frequency band being modified currently, not performing the step of determining whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification. Before verifying whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification, first verify whether the frequency band configured by the IoT device is the same as the network frequency band being modified currently. If the frequency bands are the same, then continue to verify the SSID, avoiding meaningless SSID verification for IoT devices that are not connected to the network frequency band for which the network parameters are being modified currently, and reducing unnecessary resource consumption.

[0009] In one optional embodiment, an IoT device list includes a first IoT device and a second IoT device; an IoT device to be synchronized is determined from the IoT device list stored in a router; and first network parameters are asynchronously sent to each of the multiple IoT devices to be synchronized via a secure channel for each IoT device to be synchronized. The method further includes: determining whether the first IoT device is an IoT device to be synchronized; if the first IoT device is determined to be an IoT device to be synchronized, sending the first network parameters to the first IoT device via the secure channel of the first IoT device; determining whether the second IoT device is an IoT device to be synchronized; if the second IoT device is determined to be an IoT device to be synchronized, sending the first network parameters to the second IoT device via the secure channel of the second IoT device. After sending the modified network parameters to the first IoT device, the network parameter update operation is continued for the second IoT device in the IoT device list without waiting for a response from the first IoT device. The step of determining whether the second IoT device is an IoT device to be synchronized is performed before receiving a response from the first IoT device. Through the above-described method, network parameter updates for multiple IoT devices to be synchronized are performed concurrently, improving the efficiency of network parameter updates and enhancing the user experience.

[0010] In one optional embodiment, asynchronously sending the first network parameters to multiple IoT devices to be synchronized via the secure channel of each IoT device to be synchronized further includes: determining a channel identifier of the secure channel currently connected between the IoT device to be synchronized and the router; and sending the first network parameters to the IoT device to be synchronized via the secure channel corresponding to the channel identifier. Determining the secure channel by the channel identifier improves the efficiency and accuracy of determining the secure channel, thereby improving the efficiency and accuracy of sending the modified network parameters.

[0011] In an alternative manner, after receiving the first network parameter modification instruction, the method further includes: starting a timer; determining the IoT devices to be synchronized from the IoT device list stored in the router, further including: before the timing time of the timer arrives, determining the IoT devices to be synchronized from the IoT device list stored in the router; when the timing time of the timer arrives, stopping determining the IoT devices to be synchronized from the IoT device list stored in the router, and identifying the IoT devices in the IoT device list that have not been sent the first network parameter, obtaining the identified IoT devices; the method further includes: receiving a second network parameter modification instruction, the second network parameter modification instruction carrying second network parameters, the second network parameters including a second network name SSID and / or a second network password; sending the second network parameters to the identified IoT devices through the secure channels of the identified IoT devices; after sending the second network parameters to all the identified IoT devices, updating the network parameters of the remaining IoT devices in the IoT device list except the identified IoT devices. By starting the timer, when the timer reaches the timing time, no further network parameter update operation is performed on the IoT devices in the IoT device list that have not yet performed network parameter updates, avoiding long waiting times for the user when there are many IoT devices and improving the user experience; and by marking the IoT devices that were not updated this time, the IoT devices that were not updated last time are preferentially updated during the next network parameter update, balancing the network parameter update opportunities for each IoT device.

[0012] In an alternative manner, identifying the IoT devices in the IoT device list that have not been sent the first network parameter further includes: adjusting the identified IoT devices to the head of the IoT device list in the IoT device list. When traversing the IoT devices in the IoT device list in the order of the IoT device list to update the network parameters of the IoT devices, by adjusting the identified IoT devices to the head of the IoT device list, the network parameters of the identified IoT devices are preferentially updated during the next network parameter update.

[0013] In an alternative manner, the method further includes: receiving the network parameter modification result sent by the IoT device to be synchronized; obtaining summary modification data based on the received network parameter modification result; sending the network parameter modification result and the summary modification data to an electronic device, the electronic device being a device other than the router. By sending the network parameter modification result and the summary modification data to the electronic device, the electronic device can learn and display the above modification data to prompt the user, improving the user experience.

[0014] In an alternative manner, receiving a first network parameter modification instruction includes: receiving a first network parameter modification instruction sent by an electronic device, where the electronic device is a device other than a router. When the router is the master router in a Mesh network or a router in a non-Mesh network, the user performs a network parameter modification operation on the electronic device, and the router receives the first network parameter modification instruction sent by the electronic device to update the network parameters of the IoT device, which is convenient for the user to operate.

[0015] In an alternative manner, when the router is a sub-router, receiving a first network parameter modification instruction includes: receiving a first network parameter modification instruction sent by the master router. In a Mesh network, the sub-router receives the network parameter modification instruction sent by the master router and performs a network parameter update operation on the IoT devices connected to the sub-router, improving the network parameter update efficiency.

[0016] In an alternative manner, the router includes a router process, a network parameter synchronization service process, a network password modification module, and a device management module; receiving a first network parameter modification instruction includes: the router process receives the first network parameter modification instruction; after receiving the first network parameter modification instruction, the method further includes: the router process sends the first network parameter modification instruction to the network parameter synchronization service process; the network parameter synchronization service process parses the first network parameter modification instruction to obtain the first SSID and / or the first network password, generates a network parameter update message based on the first SSID and / or the first network password; the network parameter synchronization service process sends the network parameter update message to the network password modification module; the network password modification module, in response to receiving the network parameter update message, obtains the IoT device list from the device management module. By having the router process receive the first network parameter modification instruction, and having the network parameter synchronization service process that stores the router network parameters parse the first SSID and / or the first network password in the first network parameter modification instruction and assemble the network parameter update message, and then triggering the network password modification module to obtain the IoT device list from the device management module, the response and reasonable processing of the first network parameter modification instruction are achieved.

[0017] In an alternative manner, the router includes a network password modification module and a device management module, and the IoT device list is stored by the device management module; determining the IoT devices to be synchronized from the IoT device list stored in the router further includes: the network password modification module obtaining the IoT device list from the device management module; the network password modification module determining whether the IoT devices in the IoT device list are IoT devices to be synchronized. By obtaining the IoT device list from the device management module, the network password modification module determines the IoT devices to be synchronized from the IoT device list. Since the IoT devices in the IoT device list stored by the device management module are IoT devices that have passed the security authentication of the router and established a secure channel with the router, the efficiency and accuracy of determining the IoT devices to be synchronized are improved.

[0018] In an alternative manner, the first network parameter modification instruction further carries the SSID before modification, and the device information includes the SSID configured by the IoT device; determining whether the IoT devices in the IoT device list are IoT devices to be synchronized by the network password modification module further includes: the network password modification module determining whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification; if the SSID configured by the IoT device is the same as the SSID before modification, the network password modification module determines the IoT device as an IoT device to be synchronized.

[0019] In an alternative manner, the first network parameter modification instruction further carries the SSID before modification and the first frequency band information. The first frequency band information is used to indicate the network frequency band currently being modified. The device information includes the SSID configured by the IoT device and the second frequency band information. The second frequency band information is used to indicate the frequency band configured by the IoT device. The method further includes: The network password modification module determines, according to the first frequency band information and the second frequency band information, whether the frequency band configured by the IoT device in the IoT device list is the same as the network frequency band currently being modified. If the frequency band configured by the IoT device is the same as the network frequency band currently being modified, the network password modification module determines whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification. If the SSID configured by the IoT device is the same as the SSID before modification, the network password modification module determines the IoT device as the IoT device to be synchronized. If the frequency band configured by the IoT device is different from the network frequency band currently being modified, the network password modification module determines, according to the first frequency band information and the second frequency band information, whether the next IoT device in the IoT device list is the IoT device to be synchronized. The network password modification module first verifies whether the frequency band configured by the IoT device is the same as the network frequency band currently being modified. If the frequency bands are the same, it then continues to verify whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification, avoiding meaningless SSID verification for IoT devices that are not connected to the frequency band of the currently modified network parameters, and reducing unnecessary resource consumption. Further, by verifying whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification, the IoT device that passes the verification is determined as the IoT device to be synchronized. For other IoT devices that fail the verification, since the configured SSID is different from the SSID before modification, it indicates that the physical channel between such an IoT device and the router may have been disconnected, resulting in the failure of the previous network parameter modification. Such IoT devices are not determined as the IoT devices to be synchronized, avoiding subsequent ineffective modification operations and reducing unnecessary resource consumption.

[0020] In an alternative manner, the router further includes an active session connection module; after the network password modification module determines the IoT device to be a to-be-synchronized IoT device, the method further includes: the network password modification module queries the active session connection module for the secure channel through which the to-be-synchronized IoT device is currently connected to the router, and obtains the channel identifier of the secure channel through which the to-be-synchronized IoT device is currently connected to the router; the network password modification module sends the first network parameter and the channel identifier to the active session connection module; the active session connection module sends the first network parameter information to the to-be-synchronized IoT device through the secure channel corresponding to the channel identifier. By querying the active session connection module for the channel identifier of the secure channel through which the to-be-synchronized IoT device is currently connected to the router and determining the secure channel based on the channel identifier, the efficiency and accuracy of determining the secure channel are improved, and then the efficiency and accuracy of sending the modified network parameters are improved.

[0021] In an alternative manner, the router further includes an active session connection module; the method further includes: in response to receiving a first network parameter modification instruction, the network password modification module starts a timer; the network password modification module determines whether the IoT device in the IoT device list is a to-be-synchronized IoT device, which further includes: before the timing time of the timer arrives, the network password modification module determines whether the IoT device in the IoT device list is a to-be-synchronized IoT device; when the timing time of the timer arrives, the network password modification module stops determining whether the IoT device in the IoT device list is a to-be-synchronized IoT device, and marks the IoT devices in the IoT device list that have not been sent the first network parameter, obtaining the marked IoT devices; the method further includes: receiving a second network parameter modification instruction, where the second network parameter modification instruction carries second network parameters, and the second network parameters include a second network name SSID and / or a second network password; the network password modification module sends the second network parameters to the marked IoT devices through the secure channels of the marked IoT devices via the active session connection module; after sending the second network parameters to all the marked IoT devices, the network password modification module updates the network parameters of the remaining IoT devices in the IoT device list except the marked IoT devices. By starting the timer and no longer performing network parameter update operations on the IoT devices in the IoT device list that have not yet performed network parameter updates when the timer reaches the timing time, it avoids long waiting times for users when there are many IoT devices, improving the user experience; and the network password modification module marks the IoT devices that have not been updated this time in the IoT device list of the device management module, and preferentially updates the IoT devices that have not been updated last time during the next network parameter update, balancing the network parameter update opportunities for each IoT device.

[0022] According to another aspect of the embodiments of the present application, a router is provided, including a memory, a processor, and a computer program stored on the memory. The processor executes the computer program to implement the network parameter update method provided in any of the above embodiments.

[0023] According to still another aspect of the embodiments of the present application, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, it implements the network parameter update method provided in any of the above embodiments.

[0024] According to yet another aspect of the embodiments of the present application, a network system is provided, including a main router and at least one sub-router. The sub-router is communicatively connected to the main router, and IoT devices are connected under the sub-router. The main router is configured to receive a first network parameter modification instruction sent by an electronic device, where the electronic device is a device other than the main router and the sub-router; the main router is configured to asynchronously send the first network parameter modification instruction to each sub-router; each sub-router is configured to determine, in response to receiving the first network parameter modification instruction, the IoT devices to be synchronized from the IoT device list stored in itself, and the IoT device list is used to store the device information of the IoT devices that have passed the security authentication of the sub-router and established a secure channel with the sub-router, and respectively send the first network parameter to multiple IoT devices to be synchronized asynchronously through the secure channels of each IoT device to be synchronized.

[0025] In an optional manner, the sub-router is configured to execute the embodiments that can be executed by the sub-router in the above embodiments of the network parameter update method.

[0026] In an optional manner, the main router has IoT devices connected under it, and the main router is configured to execute the embodiments that can be executed by the main router in the above embodiments of the network parameter update method.

[0027] The above description is only an overview of the technical solutions of the embodiments of the present application. In order to be able to understand the technical means of the embodiments of the present application more clearly, it can be implemented according to the content of the specification. And in order to make the above and other purposes, features, and advantages of the embodiments of the present application more obvious and understandable, the following specifically illustrates the specific implementation manners of the present application. Description of the Drawings

[0028] The drawings are only used to illustrate the embodiments and are not considered as a limitation to the present application. Moreover, throughout the drawings, the same reference numerals are used to represent the same components. In the drawings:

[0029] Figure 1 A schematic diagram of an application scenario provided by an embodiment of the present application is shown;

[0030] Figure 2 A schematic diagram of the hardware structure of a router provided by an embodiment of the present application is shown;

[0031] Figure 3 Shows the schematic software structure diagram of the router provided by the embodiment of the present application;

[0032] Figure 4 Shows the schematic software structure diagram of the IoT device provided by the embodiment of the present application;

[0033] Figure 5 Shows the schematic diagram of the binding scenario between the APP and the router in the electronic device provided by the embodiment of the present application;

[0034] Figure 6 Shows the schematic diagram of the authentication process between the router and the electronic device provided by the embodiment of the present application;

[0035] Figure 7 Shows the schematic diagram of the process of registering the router to the cloud server provided by the embodiment of the present application;

[0036] Figure 8 Shows the schematic diagram of the process of the router scanning the IoT device provided by the embodiment of the present application;

[0037] Figure 9 Shows the schematic diagram of the authentication process between the router and the IoT device provided by the embodiment of the present application;

[0038] Figure 10 Shows the schematic diagram of the process of establishing a channel between the router and the IoT device provided by the embodiment of the present application;

[0039] Figure 11 Shows the schematic diagram of the process of network parameter update provided by the embodiment of the present application;

[0040] Figure 12 Shows the schematic diagram of the network parameter update scenario provided by the embodiment of the present application;

[0041] Figure 13 Shows the schematic diagram of the process of evenly updating network parameters provided by the embodiment of the present application;

[0042] Figure 14 Shows the Mesh network architecture diagram provided by the embodiment of the present application;

[0043] Figure 15 Shows the schematic diagram of the process of router Mesh networking provided by the embodiment of the present application;

[0044] Figure 16 Shows the schematic diagram of the process of network parameter update in the Mesh networking scenario provided by the embodiment of the present application;

[0045] Figure 17It shows a schematic flow chart of network parameter update through a sub-router in the Mesh networking scenario provided by the embodiments of the present application;

[0046] Figure 18 It shows a schematic diagram of the network parameter update scenario in the Mesh networking scenario provided by the embodiments of the present application; and

[0047] Figure 19 It shows a schematic structural diagram of the router provided by the embodiments of the present application. Detailed implementation manners

[0048] Hereinafter, the exemplary embodiments of the present application will be described in more detail with reference to the accompanying drawings. Although the exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein.

[0049] The types of IoT devices deployed in current households are increasing, such as smart refrigerators, smart air conditioners, smart projectors, smart printers, smart speakers, and so on. Users can use electronic devices to control multiple IoT devices. The electronic devices can be devices such as mobile phones, tablets, laptops, all-in-one computers, and desktop computers. Figure 1 It shows a schematic diagram of an application scenario of the present application. Taking the electronic device as the mobile phone 20, and the multiple IoT devices as the smart air conditioner 10A, smart projector 10B, smart printer 10C, and smart speaker 10D respectively, the application installed on the mobile phone 20 binds the account of the application with the IoT devices and registers the IoT devices with the cloud server 30. After the mobile phone 20 is connected to the router 40 through Wi-Fi, and the smart air conditioner 10A, smart projector 10B, smart printer 10C, and smart speaker 10D are all connected to the router 40 through Wi-Fi, the user can view, manage, and control the smart air conditioner 10A, smart projector 10B, smart printer 10C, and smart speaker 10D through the application on the mobile phone 20. For example, controlling the turning on and off of the smart air conditioner 10A, controlling the smart projector 10B to play a movie, controlling the smart speaker 10D to play the weather forecast or a song, etc.

[0050] The mobile phone 20 is the active device, and the router 40 and the above-mentioned multiple IoT devices are all passive devices. The passive devices rely on the active device for authentication and data interaction. For example, the user usually needs to enter the name and password of the router 40 or the IoT device (or scan the QR code on the IoT device) in the application on the mobile phone 20 to complete the authentication process. Once the authentication is successful, the mobile phone 20 can establish a secure communication channel with the router 40 or the IoT device and perform data or instruction transmission based on this communication channel.

[0051] In the above application scenario, the network parameters (such as network name and / or network password) of the IoT device are usually configured through the mobile phone 20 (which has display and input capabilities) so that the IoT device can connect to the router 40. Hereinafter, the network name is also referred to as SSID (Service Set Identifier), and the network password is simply referred to as password. For example, the network name and password of the router 40 are SSID1 / password1, and the network name and password saved by the IoT device after network configuration through the mobile phone 20 are SSID1 / password1. When the network name and / or password of the router 40 remain unchanged, the IoT device can connect to the router 40 through the saved network name and password and perform data interaction with the router 40. When the user modifies the old network name and password SSID1 / password1 of the router 40 to the new network name and password SSID2 / password2 through the mobile phone 20, the IoT device cannot connect to the router 40 through the old network name and password SSID1 / password1. In one implementation, when the network name and password of the router 40 change, the user needs to manually modify the network parameters of each IoT device one by one through the mobile phone 20. When the number of IoT devices is large, the operation is particularly cumbersome and time-consuming, and the user experience is not good.

[0052] Based on this, the present application provides a network parameter update method. The router actively authenticates with the IoT device for device-to-device authentication, and actively establishes a secure channel with the IoT device after successful authentication. Thus, the router can perform data transmission with the IoT device through the established secure channel. When the router detects a modification operation of the network parameters, it can determine the IoT devices to be synchronized from the IoT device list (which stores the information of the IoT devices that have established a secure channel with the router), and based on the established secure channel, send the modified network parameters to some or all of the IoT devices to be synchronized, which can efficiently complete the network parameter update of multiple IoT devices and eliminate the cumbersome manual operation of the user. Moreover, the entire process of the router sending the modified network parameters to each IoT device is executed concurrently, further improving the network parameter update efficiency and user experience.

[0053] The above-mentioned secure channel is a service channel established on the basis of a physical channel. The physical channel is an actual medium for carrying signal transmission established based on a communication protocol stack, including but not limited to wired cables, optical fibers, or wireless frequency bands. In this application, the physical channels between the router and IoT devices mainly include the 2.4G Wi-Fi and 5G Wi-Fi channels in the wireless frequency band. The service channel is a logical path established on top of the physical channel and is implemented through protocols for transmitting specific service data. The physical channel provides the basis for transmission for the service channel, and the service channel utilizes the physical channel to implement specific data transmission services. In this application, since the service channel between the router and IoT devices is established based on session key negotiation, which improves the security of data transmission, the service channel established between the router and IoT devices is also referred to as a secure channel.

[0054] In the embodiments of this application, the IoT device can be a smart speaker, smart table lamp, smart night light, smart door lock, smart camera, smart power strip, smart switch, smart air conditioner, smart refrigerator, smart washing machine, smart air humidifier, smart air purifier, or smart projector, etc. Additionally, the IoT device can also be an intelligent device such as a vehicle-mounted device, wearable device, augmented reality (AR) / virtual reality (VR) device, etc. The embodiments of this application do not make any limitations on the specific types of IoT devices. The router that can be used as an active-end device is integrated with a bi-directional transceiver module, and the bi-directional transceiver module includes but is not limited to communication modules such as Wi-Fi modules, Bluetooth modules, ZigBee modules, radio frequency modules, LoRa (Long Range) modules, or 4G / 5G modules. The IoT device that can be used as a passive-end device can be integrated with the above-mentioned bi-directional transceiver module or may not be integrated with the above-mentioned bi-directional transceiver module.

[0055] In the embodiments of this application, the IoT device can be a device with a relatively small storage resource level. For example, the capacity of the operating memory of the IoT device is usually between 100 KB and 16 MB, and the capacity of the hardware storage is between 2 MB and 256 MB. Of course, the IoT device can also be a device with a relatively large storage resource level. For example, the capacity of the operating memory can reach 16 MB or even higher. The IoT device can support any one, two, or more of Wi-Fi communication, Bluetooth communication, ZigBee communication, radio frequency communication, LoRa (Long Range) communication, and 4G / 5G communication.

[0056] In one implementation, the router, as a passive device, cannot interact with IoT devices without the participation of an active device. To implement the network parameter update method of this application, it is first necessary to enable the router to act as an active device to actively authenticate with IoT devices and establish a secure channel, and then send the modified network parameters based on this secure channel. Before explaining the network parameter update method provided in the embodiments of this application, first, the structure of the router applicable to the network parameter update method provided in the embodiments of this application will be described. Please refer to Figure 2 , Figure 2 which is a schematic diagram of the hardware structure of the router provided in the embodiments of this application. As shown in the figure, the router 40 may include a processor 101, a memory 102, a wireless communication circuit 103, an antenna 104, a network port 105, and a power module 106. It can be understood that the structure illustrated in the embodiments of this application does not constitute a specific limitation on the router 40.

[0057] The processor 101 may include one or more processing units. For example, it may include a Central Processing Unit (CPU), a Graphics Processing Unit (GPU), a Digital Signal Processor (DSP), a Micro-programmed Control Unit (MCU), an Artificial Intelligence (AI) processor, or a processing module or processing circuit such as a Field Programmable Gate Array (FPGA). Among them, different processing units may be independent devices or integrated in one or more processors. A storage unit may be provided in the processor 101 for storing instructions, parameters related to the router 40, and parameters related to IoT devices and cloud servers.

[0058] The memory 102 is used to store instructions and data. In some embodiments of this application, the memory 102 may use non-volatile memory, random access memory, flash memory, and read-only memory, and this embodiment does not make any limitations in this regard.

[0059] The wireless communication circuit 103 may be configured to communicate via wireless local area network standards such as Wi-Fi, Bluetooth (BT), ZigBee, etc., or via broader wireless communication technologies such as radio frequency, LoRa, or 4G / 5G. The wireless communication circuit 103 may be one or more devices integrating at least one communication processing module. The wireless communication circuit 103 may receive electromagnetic waves via the antenna 104, perform frequency modulation and filtering processing on the electromagnetic wave signals, and send the processed signals to the processor 101. The wireless communication circuit 103 may also receive the signals to be sent from the processor 101, perform frequency modulation on the signals, amplify them, and convert them into electromagnetic waves through the antenna 104 for radiation.

[0060] The wireless communication circuit 103 may provide solutions for wireless communication including Wireless Local Area Networks (WLANs) (such as Wireless Fidelity (Wi-Fi) networks), Bluetooth, Near Field Communication (NFC), Infrared (IR), etc. applied on the router 40.

[0061] The network port 105 may include a wired network interface, which may be configured to be coupled to the network of the Internet through a wired network such as broadband and provide access to the Internet for multiple terminals. The network port 105 may also include a mobile communication module (not shown in the figure), and the mobile communication module may be configured to connect to the core network through wireless communication technologies.

[0062] The power supply module 106 may include a power supply, a power management component, etc. The power management component is used to manage the charging of the power supply and the power supply to other modules.

[0063] In the embodiments of the present application, the router 40 may communicate with electronic devices and IoT devices in a dual role. It can not only act as a passive end device to passively establish communication with electronic devices, but also act as an active end device to actively complete device authentication with IoT devices, actively establish a channel with IoT devices, and actively perform data transmission with IoT devices through this channel. The software structure of the router will be introduced below.

[0064] Figure 3 It shows a schematic diagram of the software structure of the router provided by the embodiments of the present application. Please refer to Figure 3 , the software modules of the router include a router process and a link SDK. Among them, SDK refers to the Software Development Kit, which is a collection of related documents, examples, and tools for assisting in the development of a certain type of software.

[0065] Specifically, the router process includes the router process, the network parameter synchronization service process, the link startup process, and the link SDK process. The link SDK includes the Interface layer, the service function modules, the active link processing thread, the active session connection module, the active authentication networking module, the active discovery and scanning module, the device management module, the passive session connection module, the passive authentication networking module, the passive discovery and scanning module, the session management module, the communication connection component, and the communication open source library.

[0066] The router process is a series of software programs running inside the router. It can respond to the operations of the electronic device and start the network parameter synchronization service process. The network parameter synchronization service process can be triggered by the router process when the router modifies network parameters to start the link SDK process. The link startup process can be triggered by the network parameter synchronization service process or the service function modules. Its functions include: triggering the startup of the link SDK process to ensure that the link SDK independently executes tasks; managing the registration channels on the service side through data interaction with the link SDK; being responsible for managing and updating routing information, as well as handling interactions with the electronic device; actively calling the interfaces of the link SDK to initiate active authentication and channel establishment. The link SDK process can be triggered by the electronic device, the router process, or the link startup process to start the link SDK to execute tasks.

[0067] The link SDK can establish a physical transmission channel between devices for the router, provide data transmission capabilities and dual - role authentication capabilities, that is, it can passively authenticate with the electronic device and at the same time actively authenticate with IoT devices for device - to - device authentication.

[0068] The Interface layer can provide the router with interfaces such as passive notification of SDK events, reporting the results of the same - account network information update, triggering active scanning and authentication interaction, and updating the network information of the same - account devices.

[0069] The service function modules are used to implement service functions. For example, when the service function module is the network password modification module, it can implement the function of modifying the network name and / or password of the wireless network provided by the router. Among them, if the service function module is the network password modification module, the network password modification module can interact with the link startup process, the link SDK process, the active link processing thread, and the active session connection module to achieve the transmission of network parameters.

[0070] The active link processing thread can be started by the electronic device to interact with the cloud server, or can be started by the link SDK process to initialize the active session connection module, the active authentication networking module, the active discovery and scanning module, and the device management module.

[0071] The active session connection module can interact with the active authentication networking module and the passive session connection module. The active session connection module and the passive session connection module provide the router with active control capabilities and passive control capabilities. For example, the active session connection module can actively establish an encrypted channel with the IoT device and actively interact with encrypted data, and the passive session connection module can respond to the control of the electronic device and passively establish an encrypted channel.

[0072] The active authentication networking module can interact with the passive session connection module, the active discovery scanning module, and the device management module. The passive authentication networking module can interact with the electronic device. The active authentication networking module and the passive authentication networking module respectively provide the router with active authentication capabilities and passive authentication capabilities.

[0073] The active discovery scanning module can interact with the device management module, the session management module, and the communication connection component. The passive discovery scanning module can interact with the electronic device. The active discovery scanning module and the passive discovery scanning module respectively provide the router with active discovery capabilities and passive discovery capabilities.

[0074] The device management module is used to store and manage the device information of the router and the IoT devices that authenticate with the router, and to obtain the device information of the IoT devices with the same account from the cloud server.

[0075] The communication connection component and the communication open source library provide the router with communication functions for IoT devices that support different communication protocols.

[0076] The software structure of the IoT device will be introduced below. Figure 4 The schematic diagram of the software structure of the IoT device provided by the embodiment of the present application is shown. Please refer to Figure 4 The functional modules of the IoT device include the Link SDK. Among them, the Link SDK includes a business function module, a device management module, a passive session connection module, a passive authentication networking module, a passive discovery scanning module, a session management module, a communication connection component, and a communication open source library.

[0077] Among them, the business function module is a module for implementing business functions. If the business function module is a data transmission module, the data transmission module can interact with the link startup process and the Link SDK process to achieve data transmission.

[0078] The functions of the passive session connection module, device management module, passive discovery scanning module, passive authentication networking module, communication connection component and communication open source library can be referred to the software structure of the above router and will not be repeated here.

[0079] The following describes the network parameter updating method provided by the embodiment of the present application in detail with reference to the accompanying drawings and application scenarios. First, the process of the router as the active end device actively performing security authentication with the IoT device and establishing a secure channel is introduced.

[0080] For newly deployed routers, before the router actively establishes a secure channel with the IoT device, it needs to use electronic devices to complete the registration process with the cloud server. This process is the binding process between the application (hereinafter referred to as APP) installed on the electronic device for managing each IoT device and the router.

[0081] It should be noted that the electronic device of this embodiment is installed with an APP for managing the router and IoT devices. Users can use the APP on the electronic device to perform operations such as binding the router and IoT devices, registering the router and IoT devices, modifying the router's network name and password, and managing router access devices. In addition, users can also log in and use the APP by registering an APP account on the APP. The binding or association of the APP with the router mentioned above can also be regarded as binding or associating the APP account (information) of the APP with the router.

[0082] The following combination Figure 5 The binding process between the APP and the router in the electronic device of this embodiment is described.

[0083] For example, Figure 5 (a) is the display interface of the APP. Under the "All" menu in the main interface 21, the IoT devices that are bound or associated with the electronic device in the current environment will be displayed (if there are none, they will not be displayed). At the same time, the main interface 21 also displays the IoT devices associated with the APP account (135******531) currently logged in by the APP. In response to the user's operation on the control "+" 22 in the main interface 21, the electronic device displays Figure 5 (b) shows a card 23, in which controls such as "Add device", "Create scene", "Share device" and "Connect to third-party platform" are displayed. In response to the user's operation on the control "Add device", the electronic device displays Figure 5 (c) shows the device scanning interface 24. During this process, the APP controls the electronic device to scan the router. The electronic device then displays the scanned router, for example, in the device scanning interface 24. Figure 5The connection card 25 shown in (d) can prompt the user whether to connect the router to the APP. In the exemplary connection card 25, there are shown a control "Connect" 251 and a control "Cancel" 252. In response to the user's operation on the control "Cancel" 252, the device scanning interface 24 of the electronic device no longer shows the connection card 25. Optionally, to avoid the situation where the electronic device fails to scan the router through the above-mentioned active scanning method and cannot complete the binding, the device scanning interface 24 of the APP also integrates page controls for manually adding a device and adding a device by scanning a code, that is, the user can complete the binding between the APP (or APP account) and the router by manually adding or scanning a code. Then, in response to the user's operation on the control "Connect" 251 in the connection card 25, the electronic device displays Figure 5 the connection interface 26 shown in (e). In the exemplary connection interface 26, it is shown that the connection between the router and the APP is in progress. After the binding between the APP (or APP account) of the electronic device and the router is completed, in response to the user's operation of opening the APP again, the electronic device can display the bound router 27 on the main interface 21 of the APP, such as Figure 5 the interface shown in (f).

[0084] In the process of binding the APP of the electronic device to the router as described above, Figure 5 the process shown in (b)-(f) involves the authentication process of the router and the registration process of the router. First, the authentication process of the router will be described in combination with Figure 6 is a schematic diagram of the authentication process between the router and the electronic device, which may specifically include: Figure 6 Step S201: The electronic device obtains the device information of the router.

[0085] Specifically, in response to the user's operation of scanning the device, the electronic device performs signal broadcasting to obtain the device information of the router. For example, the electronic device can respond to the user's operation on

[0086] the control "Add Device" shown in (b) and perform signal broadcasting. Figure 5 the control "Add Device" shown in (b) and perform signal broadcasting.

[0087] If the passive discovery scanning module of the router receives the broadcast signal, it can send a reply message to the electronic device, which carries its own device information. When the electronic device receives (i.e., scans) the reply message from the router, it can obtain the router's device information from the reply message. The device information obtained by the electronic device includes but is not limited to the router's serial number (SN), Internet Protocol address (IP address), Media Access Control Address (MAC address), etc.

[0088] In other embodiments, when the electronic device fails to actively scan the router, the electronic device may also Figure 5 The control "Scan code to add" shown in (c) scans the QR code on the router to obtain the device information of the router.

[0089] After obtaining the device information of the router, the electronic device displays the device information in the device scanning interface 24. Figure 5 (d) The connection card 25 shown.

[0090] Step S202: The electronic device generates authentication identification information according to the device information.

[0091] The authentication identification information may be a PIN (Personal Identification Number). Figure 5 By operating the "Connect" control 251 in the connection card 25 shown in (d), the electronic device can generate a corresponding PIN based on the device information of the router. Optionally, the electronic device can encode the device information according to a preset rule to generate the PIN. For example, the electronic device can concatenate the first 6 digits of the SN and the last 4 digits of the IP address, or the first 6 digits of the SN and the last 4 digits of the MAC address, according to a preset rule to obtain a string, and then perform a hash calculation on the string to obtain the PIN.

[0092] Step S203: The electronic device sends first authentication information to the router based on the authentication identification information.

[0093] Among them, the first authentication information at least includes the salt value (salt), Universally Unique Identifier (UUID), and the first verification value of the electronic device. Specifically, after the electronic device generates the PIN, it can initiate an authentication process to the passive authentication networking module of the router. First, the electronic device generates the salt and UUID, then uses a predetermined algorithm (such as an encryption algorithm, a hashing algorithm) to calculate the first verification value for the PIN, salt, and UUID, and finally packages the salt, UUID, and the first verification value into the first authentication information and sends it to the passive authentication networking module of the router. Optionally, the electronic device can also use a predetermined algorithm to calculate the first verification value for the salt, UUID, other fixed parameters, or a timestamp.

[0094] Step S204: The router generates the second authentication information and uses the second authentication information to verify the first authentication information.

[0095] Among them, the second authentication information at least includes the salt value (salt), Universally Unique Identifier (UUID), and the second verification value of the router. Specifically, after the passive authentication networking module of the router receives the first authentication information, it generates the salt and UUID of the router, and uses a predetermined algorithm (such as an encryption algorithm, a hashing algorithm) to calculate the second verification value for the preset PIN, salt, and UUID of itself. The second verification value is used to verify whether the first authentication information is valid. For example, when the second verification value is consistent with the first verification value, the first authentication information passes the verification; when the second verification value is inconsistent with the first verification value, the first authentication information fails the verification.

[0096] Step S205: After verifying that the first authentication information passes, the router sends the second authentication information to the electronic device.

[0097] After the first authentication information passes the verification, the router packages its own salt, UUID, and the second verification value into the second authentication information and sends it to the electronic device.

[0098] Step S206: The electronic device verifies the second authentication information and generates the first confirmation information after the verification passes.

[0099] After receiving the second authentication information, the electronic device uses the same algorithm to calculate the PIN, the salt of the router, and the UUID of the electronic device to obtain a third verification value. Through the third verification value, it can be determined whether the second authentication information sent by the router is valid. If the third verification value is consistent with the second verification value, the second authentication information of the router passes the verification, that is, the second authentication information sent by the router is valid. After that, the electronic device generates a first confirmation message (ack1). If the third verification value is inconsistent with the second verification value, the second authentication information fails the verification, then the second authentication information is invalid, and the electronic device stops the authentication process with the router.

[0100] Step S207: The electronic device sends a first confirmation message to the router.

[0101] After generating ack1, the electronic device sends ack1 to the passive authentication networking module of the router.

[0102] Step S208: After the router verifies that the first confirmation message passes, it generates a first session key and a second confirmation message.

[0103] After receiving ack1, the passive authentication networking module of the router first checks ack1, such as checking the validity and timestamp of ack1. After passing the check of ack1, the passive authentication networking module of the router generates a first session key (rootkey1) based on its own salt and UUID and the salt and UUID of the electronic device using a key generation function, such as a key derivation function (KDF). After passing the check of ack1, the passive authentication networking module of the router also generates a second confirmation message (ack2).

[0104] Step S209: The router sends a second confirmation message to the electronic device.

[0105] After generating ack2, the router sends ack2 to the electronic device to notify the electronic device that the authentication process is completed.

[0106] Step S210: In response to the received second confirmation message, the electronic device generates a first session key.

[0107] After the electronic device receives ack2, it can confirm that the entire authentication process is completed. After that, the electronic device generates rootkey1 based on its own salt and UUID and the salt and UUID of the router and uses the same key generation function.

[0108] Step S211: The electronic device and the router negotiate to establish a secure channel based on the first session key.

[0109] After the above process, the rootkey1 generated by the electronic device and the router is the same. After that, the electronic device and the router can use rootkey1 to encrypt and decrypt the data transmitted between them, that is, the electronic device constructs a secure channel with the router based on rootkey1.

[0110] After the above steps S201 - S211, a secure channel is established between the electronic device and the router. During this process, the electronic device sequentially displays Figure 5 the interfaces shown in (b) - 5(e). While the electronic device continuously displays Figure 5 the connection interface 26 shown in (e), the electronic device assists the router to perform the operation of registering to the cloud server through the established secure channel. The following combines Figure 7 to describe the registration process of the router, Figure 7 is a schematic diagram of the process of the router registering to the cloud server, which specifically may include:

[0111] Step S212: The electronic device encrypts the access address of the cloud server using the first session key and sends the encrypted access address to the router.

[0112] Specifically, the access address of the cloud server can be pre - set in the APP of the electronic device. The user can send the access address of the cloud server to the active connection processing thread of the router through the APP. To ensure the security of data transmission, the electronic device encrypts the access address of the cloud server using the above - generated rootkey1 and then sends it to the active connection processing thread of the router.

[0113] Optionally, the access address can be a Uniform Resource Locator (URL), which at least includes the protocol, host name, port number, etc. for accessing the cloud server. Through this access address, the active connection processing thread of the router can access the resources of the cloud server.

[0114] Step S213: The router decrypts the encrypted access address using the first session key, obtains the access address of the cloud server, and generates a device authentication code and an authentication code identifier.

[0115] After the active connection processing thread of the router receives the encrypted access address of the cloud server, it decrypts it using its own rootkey1 to obtain the access address of the cloud server.

[0116] After the active link processing thread of the router receives the access address of the cloud server, the link SDK generates a device authentication code (authcode) and an authentication code identifier (authcode ID) for the router. Among them, the authcode can be a 4-6 bit random number generated by the link SDK and is configured with a certain validity period. After the expiration, it will become invalid, and the link SDK of the router needs to regenerate the device authentication code. The authcode ID is the number that identifies the authcode. Optionally, a unique authcode ID can be assigned to the authcode of each device to facilitate the management and query of the device's authcode.

[0117] Step S214: The router uploads the universally unique identifier, the device authentication code, and the authentication code identifier to the cloud server according to the access address of the cloud server.

[0118] Specifically, the router sends the UUID of the router and the authcode and authcode ID generated by the link SDK of the router to the cloud server according to the access address of the cloud server to implement the registration of the router with the cloud server. Among them, the UUID is used for the cloud server to identify and distinguish the devices registered with the cloud server.

[0119] Step S215: After the cloud server receives the universally unique identifier, the device authentication code, and the authentication code identifier of the router, it generates a device identification code for the router according to the universally unique identifier, the device authentication code, and the authentication code identifier.

[0120] After the cloud server receives the UUID, authcode, and authcode ID of the router, it correspondingly generates a device identification code (device ID) for the router according to the UUID, authcode, and authcode ID of the router. Moreover, the cloud server will also associate and store the UUID, authcode, authcode ID, and device ID of the router.

[0121] Optionally, the cloud server can perform a hash process on the UUID and authcode to obtain the device ID, or perform a hash process on the UUID, authcode, and authcode ID to obtain the device ID, or perform a hash process on the UUID, authcode, authcode ID, and random number to obtain the device ID.

[0122] Step S216: The cloud server sends the device identification code to the router.

[0123] After the cloud server generates the device ID of the router, it sends the device ID to the active connection processing thread of the router.

[0124] Step S217: The router stores the device identification code.

[0125] After the active connection processing thread of the router receives the device ID, it saves the device ID to the device management module of the router. Therefore, after the router completes the registration on the cloud server, both the router and the cloud server store the UUID, authcode, authcode ID, and device ID of the router.

[0126] Optionally, before the electronic device sends the access address of the cloud server to the router, the user logs in to the APP account on the APP of the electronic device, and the electronic device applies to the cloud server for the registration information of the APP account based on this APP account. The registration information may include a registration ID and a verification code (verify code). After receiving the APP account, the cloud server can assign a registration ID and the corresponding verification code to the APP account, and return the registration ID and the verification code to the electronic device. Optionally, the registration ID may be a random number generated by the cloud server. When any electronic device applies to the cloud server for registration information through the APP account, it can obtain a corresponding registration ID. Therefore, when the electronic device sends the access address of the cloud server to the router, it can also send the registration information to the router together.

[0127] When the router sends the UUID, authcode, and authcode ID to the cloud server, it also sends the registration information to the cloud server together, so that the cloud server can determine the APP account corresponding to the router according to the registration information, and associate and store the APP account, UUID, authcode, authcode ID, and device ID. Optionally, the router can also send other information of itself (such as device name, SN, model, and device upgrade information, etc.) to the cloud server for the cloud server to associate and store together.

[0128] Optionally, to ensure the security of the router registration, the router usually also generates a signature and uploads the signature, UUID, authcode, and authcode ID to the cloud server together. The signature can be generated by using information such as the UUID of the router and the current timestamp as input through a hash algorithm.

[0129] After the above steps S212 - S217, the router completes the process of registering with the cloud server, and the electronic device is as Figure 5As shown in (f), the bound router 27 is displayed on the main interface 21 of the APP.

[0130] It should be noted that for the authentication process and registration process of the IoT device in the embodiments of the present application, reference can be made to the authentication process and registration process of the router shown above Figure 6 and Figure 7 and will not be elaborated here.

[0131] After the above process, the registration process of the router and the IoT device to the cloud server is completed. In the embodiments of the present application, both the router as the active device and the IoT device as the passive device can be registered to the cloud server with the help of an electronic device. When the active device such as the router needs to obtain the authcode and authcode ID of the IoT device in the future, it can directly obtain them from the cloud server, reducing data interaction with the IoT device and improving security.

[0132] In Figure 6 and Figure 7 's embodiments, the router acts as a passive device, passively authenticates with the electronic device and registers to the cloud server. Next, the router can act as an active device, actively scan and discover IoT devices, and actively authenticate with the scanned and discovered IoT devices to establish a secure channel with the actively authenticated IoT devices. First, the process of the router scanning and discovering IoT devices provided by the embodiments of the present application will be elaborated in detail in combination with Figure 8 below. Figure 8 FIG. shows a schematic flowchart of the router scanning for IoT devices provided by the embodiments of the present application, which may specifically include:

[0133] Step S301: The link startup process sends a self-organizing network instruction to the active authentication networking module.

[0134] After the router is powered on and starts up, the router's router process is triggered to run, and then the router's link SDK process is triggered. After that, the link SDK process starts an active link processing thread, and initializes the active session connection module, active authentication networking module, active discovery module, and device management module of the link SDK in sequence. And when the service function module of the link SDK is the network password change module, the link SDK process also initializes the network password change module. After the network password change module is initialized, a session server is created in the passive session connection module.

[0135] After the link SDK is initialized, the link startup process of the router sends a self-organizing network instruction to the active authentication networking module to enable the active authentication networking module to initiate self-organizing networking.

[0136] Step S302: The active authentication networking module sends an active discovery instruction to the active discovery scanning module.

[0137] After receiving the self - networking instruction sent by the link startup process, the active authentication networking module sends an active discovery instruction to the active discovery scanning module to start the active discovery scanning module to scan and discover IoT devices in the self - organized network.

[0138] In some embodiments, after the link startup process sends the self - networking instruction to the active authentication networking module, the active authentication networking module can start a timer. For example, the active authentication networking module can start a timer with a timing time of 30 minutes. When the timer reaches the timing time, if the active authentication networking module does not send an active discovery instruction to the active discovery scanning module, or the active discovery instruction sent by the active authentication networking module is lost, the active authentication networking module sends a LOCAL message (such as CLIENT_DISCOVERY_LOCAL) to the active discovery scanning module to start the active discovery scanning module to scan and discover IoT devices in the self - organized network.

[0139] Step S303: The active discovery scanning module sends a generation request instruction to the communication connection component, and the generation request instruction is used to instruct the communication connection component to generate a discovery request.

[0140] In the embodiments of the present application, the communication connection component includes at least one or more of components such as a coap connection component, a Wi - Fi connection component, a Bluetooth connection component, and a zigbee connection component. The active discovery module can send a generation request instruction to one of the coap connection component, the Wi - Fi connection component, the Bluetooth connection component, and the zigbee connection component, or can also send a generation request instruction to multiple of the coap connection component, the Wi - Fi connection component, the Bluetooth connection component, and the zigbee connection component at the same time.

[0141] Step S304: The communication connection component generates a discovery request in response to the generation request instruction.

[0142] Among them, the discovery request carries a registered identifier of the router, and the registered identifier is used to indicate that the router has been registered to the cloud server.

[0143] The communication open - source library includes at least one or more of a coap open - source library, a Wi - Fi open - source library, a Bluetooth open - source library, a zigbee open - source library, etc., corresponding to the coap connection component, the Wi - Fi connection component, the Bluetooth connection component, and the zigbee connection component respectively.

[0144] For example, when the CoAP connection component receives a generation request instruction, it generates a CoAP discovery request. When the Wi-Fi connection component receives a generation request instruction, it generates a Wi-Fi discovery request. When the Bluetooth connection component receives a generation request instruction, it generates a Bluetooth discovery request. When the Zigbee connection component receives a generation request instruction, it generates a Zigbee discovery request.

[0145] Step S305: The communication connection component sends the discovery request to the communication open source library.

[0146] In specific implementation, after different types of communication connection components generate discovery requests, they will call the interfaces of the corresponding communication open source libraries to broadcast the discovery requests. For example, the CoAP connection component sends the CoAP discovery request to the CoAP open source library. The Wi-Fi connection component sends the Wi-Fi discovery request to the Wi-Fi open source library. The Bluetooth connection component sends the Bluetooth discovery request to the Bluetooth open source library. The Zigbee connection component sends the Zigbee discovery request to the Zigbee open source library.

[0147] Step S306: The communication open source library broadcasts the discovery request.

[0148] Specifically, after the communication open source library receives the discovery request, it converts the discovery request into a data packet that conforms to the protocol specification and sends it out through the interface to ensure that the discovery request can be received and understood by IoT devices that support the corresponding protocol.

[0149] For example, the CoAP open source library converts the CoAP discovery request into a data packet that conforms to the CoAP protocol specification. After this data packet is broadcast, it is used to discover IoT devices that support the CoAP communication protocol. The Wi-Fi open source library converts the Wi-Fi discovery request into a data packet that conforms to the Wi-Fi protocol specification. After this data packet is broadcast, it is used to discover IoT devices that support the Wi-Fi communication protocol. The Bluetooth open source library converts the Bluetooth discovery request into a data packet that conforms to the Bluetooth protocol specification. After this data packet is broadcast, it is used to discover IoT devices that support the Bluetooth communication protocol. The Zigbee open source library converts the Zigbee discovery request into a data packet that conforms to the Zigbee protocol specification. After this data packet is broadcast, it is used to discover IoT devices that support the Zigbee communication protocol.

[0150] Step S307: The IoT device determines that the router has been registered with the cloud server based on the discovery request.

[0151] When the IoT device receives the discovery request, it parses the discovery request to obtain the registered identifier of the router. Based on the registered identifier, the IoT device can determine that the router that sent the discovery request is a device that has been registered with the cloud server, that is, the discovery request sent by this router is a request that the IoT device needs to respond to.

[0152] Step S308: The IoT device sends a response message to the communication open-source library.

[0153] When the IoT device determines that it needs to respond to the router's discovery request, the IoT device packages its registration field, device ID, IP address, port number, and MAC address into a response message and sends the response message to the communication open-source library. Among them, the registration field of the IoT device can be the isregistered field, which is used to identify whether the IoT device has been registered to the cloud server.

[0154] After broadcasting the discovery request, the communication open-source library starts to listen for the response message of the IoT device. When receiving the response message of the IoT device, the communication open-source library parses the response message and converts it into a format that the communication connection component can understand.

[0155] For example, after an IoT device that supports CoAP communication sends a CoAP response message, the CoAP open-source library receives it, parses the CoAP response message, and then sends it to the CoAP open-source library. After an IoT device that supports Wi-Fi communication sends a Wi-Fi response message, the Wi-Fi open-source library receives it, parses the Wi-Fi response message, and then sends it to the Wi-Fi open-source library. After an IoT device that supports Bluetooth communication sends a Bluetooth response message, the Bluetooth open-source library receives it, parses the Bluetooth response message, and then sends it to the Bluetooth open-source library. After an IoT device that supports ZigBee communication sends a ZigBee response message, the ZigBee open-source library receives it, parses the ZigBee response message, and then sends it to the ZigBee open-source library.

[0156] Step S309: The communication open-source library sends the response message to the active discovery scanning module.

[0157] In the embodiments of the present application, all types of communication open-source libraries send the received response message to the active discovery scanning module.

[0158] Step S310: The active discovery scanning module parses the response message to obtain the registration field, device identification code, IP address, port number, and MAC address of the IoT device.

[0159] When the registration field is 1, it indicates that the IoT device has been registered to the cloud server, and the cloud server stores the authcode of the IoT device. The router can request the cloud server to obtain the authcode of the IoT device, that is, the router can actively authenticate with the IoT device for device-to-device authentication. When the registration field is 0, it indicates that the IoT device has not been registered to the cloud server, and there is no authcode of the IoT device in the cloud server. That is, the router cannot obtain the authcode of the IoT device, and thus will not actively authenticate with the IoT device for device-to-device authentication.

[0160] Step S311: The active discovery and scanning module determines the IoT devices registered with the cloud server as registered IoT devices according to the registration fields.

[0161] Specifically, the active discovery and scanning module first judges the registration fields of the IoT devices. When the registration field is 1, the IoT device is a registered IoT device that the router can actively authenticate with. When the registration field is 0, the IoT device is an unregistered IoT device that the router cannot actively authenticate with, and the active discovery and scanning module does not process the information of this unregistered IoT device.

[0162] Step S312: The active discovery and scanning module sends the device identification code, IP address, port number, and MAC address of the registered IoT devices to the device management module.

[0163] After determining the registered IoT devices, the active discovery and scanning module sends the device ID, IP address, port number, and MAC address of the registered IoT devices to the device management module.

[0164] Step S313: The device management module determines the registered IoT devices as IoT devices to be authenticated according to the IP address, port number, and MAC address.

[0165] After receiving the device ID, IP address, port number, and MAC address of the IoT devices to be authenticated, the device management module first queries whether the device ID of the IoT device exists in the device management module. When the device ID does not exist in the device management module, the device management module creates a device node for the registered IoT device. When the device ID of the registered IoT device exists in the device management module, it indicates that a device node storing the information of the registered IoT device has been created in the device management module.

[0166] After querying whether there is a device node of the registered IoT device in the device management module according to the device ID, the device management module also queries whether the router has actively authenticated with the registered IoT device and established a secure channel according to the IP address and port number, or the MAC address of the registered IoT device. When the IP address and port number of the registered IoT device exist in the device management module, or the MAC address of the registered IoT device exists, it proves that the router has actively authenticated with the registered IoT device, generated a session key, and established a secure channel. Then the router can directly interact with the registered IoT device through the established secure channel. When the IP address and port number of the registered IoT device do not exist in the device management module, and the MAC address of the registered IoT device does not exist, it proves that the router has not actively authenticated with the registered IoT device, and then the registered IoT device is determined as a to-be-authenticated IoT device.

[0167] Among them, if the IP address and port number of the registered IoT device exist in the device management module, it indicates that the router has established a secure channel supporting the Wi-Fi protocol with the registered IoT device. If the MAC address of the registered IoT device exists in the device management module, it indicates that the router has established a secure channel supporting the Bluetooth protocol with the registered IoT device.

[0168] Step S314: The device management module stores the device identification code, IP address, port number, and MAC address of the to-be-authenticated IoT device.

[0169] After determining the to-be-authenticated IoT device, the device management module stores the device ID, IP address, port number, and MAC address of the to-be-authenticated IoT device in the device node of the to-be-authenticated IoT device.

[0170] Step S315: The device management module sends the to-be-authenticated IoT device to the active authentication networking module, so that the active authentication networking module initiates active authentication to the to-be-authenticated IoT device.

[0171] In this step, the to-be-authenticated IoT device sent by the device management module to the active authentication networking module (the information for distinguishing different IoT devices such as the device name of the to-be-authenticated IoT device sent here) is an IoT device discovered by the router and registered to the cloud server, that is, these IoT devices are devices with which the router can actively perform active authentication.

[0172] Optionally, the device management module can send the device ID, IP address, port number, and MAC address of the to-be-authenticated IoT device to the active authentication networking module to notify the active authentication networking module that it can initiate active authentication to the to-be-authenticated IoT device.

[0173] When the router scans and discovers an IoT device and determines the IoT device to be authenticated, the router initiates an active authentication to the IoT device to be authenticated. Figure 9 The figure shows a schematic flowchart of the authentication between the router and the IoT device provided by the embodiments of the present application. The following will combine Figure 9 to elaborate in detail on the process of the router actively authenticating with the IoT device provided by the embodiments of the present application.

[0174] Step S316: The active discovery and scanning module sends a request to exchange device information to the active authentication networking module.

[0175] After the device management module sends the IoT device to be authenticated to the active authentication networking module, the active discovery and scanning module sends a request to exchange device information to the active authentication networking module, so that the active authentication networking module starts to exchange device information with the IoT device to be authenticated.

[0176] Step S317: Based on the request to exchange device information, the active authentication networking module sends the active authentication identification information and the unique device identifier of the router to the IoT device to be authenticated.

[0177] After receiving the request to exchange device information sent by the active discovery and scanning module, the active authentication networking module can send the active authentication identification of the router and the unique device identifier (Unique Device Identifier, abbreviated as UDID) of the information device to the IoT device to be authenticated according to the IP address, port number, and MAC address of the IoT device to be authenticated. Among them, the active authentication identification is used for the IoT device to be authenticated to determine that the router needs to exchange device information with the IoT device to be authenticated for active authentication. The UDID is used for the IoT device to be authenticated to determine whether it can authenticate with the router. It should be noted that when the active authentication networking module sends the active authentication identification information and UDID of the router, it will also carry the IP address, port number, and MAC address of the router and send the above parameters to the IoT device to be authenticated together.

[0178] Step S318: The IoT device to be authenticated sends the session key index, device identification code, and authentication code identifier of the IoT device to be authenticated to the active authentication networking module according to the active authentication identification information and the unique device identifier.

[0179] Among them, the session key index (rootkeyidx) of the IoT device to be authenticated is used to identify the active authentication of the router for the IoT device to be authenticated. The rootkeyidx can be a random number generated by the IoT device to be authenticated. When any active device exchanges device information with the IoT device to be authenticated for active authentication, the IoT device to be authenticated generates the corresponding rootkeyidx for the active device to mark this active authentication. The device ID and authcode ID of the IoT device to be authenticated are generated during the process of registering the IoT device to be authenticated with the cloud server.

[0180] Specifically, after receiving the active authentication identification information and UDID of the router, the IoT device to be authenticated can know through the active authentication identification information that the router wants to exchange device information with the IoT device to be authenticated. After verifying the UDID of the router and determining that it can authenticate with the router, the rootkeyidx is generated. Then, the IoT device to be authenticated sends the rootkeyidx, device ID, and authcode ID to the active authentication networking module according to the IP address, port number, and MAC address of the router. It should be noted that when the IoT device to be authenticated sends the rootkeyidx, device ID, and authcode ID, it will also carry the UDID, IP address, port number, and MAC address of the IoT device to be authenticated and send the above parameters to the active authentication networking module together.

[0181] After receiving the rootkeyidx, device ID, and authcode ID of the IoT device to be authenticated, the active authentication networking module stores the rootkeyidx, device ID, and authcode ID in the device management module.

[0182] Step S319: The active authentication networking module queries whether there is a device identification code of the IoT device to be authenticated in the device management module.

[0183] Specifically, the active authentication networking module can query whether the device ID in the device management module is consistent with the received device ID of the IoT device to be authenticated based on the IP address, port number, and MAC address of the IoT device to be authenticated, so as to determine whether the device ID of the IoT device to be authenticated exists in the device management module. If they are consistent, it indicates that the device ID of the IoT device to be authenticated exists in the device management module, and the query for the authcode ID of the IoT device to be authenticated can continue, that is, step S320 is then executed. If they are inconsistent, it indicates that the device ID of the IoT device to be authenticated does not exist in the device management module, and the active authentication networking module needs to update the information of the IoT device to be authenticated in the device management module, that is, step S321 is then executed.

[0184] Step S320: When the device identification code of the IoT device to be authenticated exists in the device management module, the active authentication networking module queries whether the authentication code identifier of the IoT device to be authenticated exists in the device management module.

[0185] The active authentication networking module can query whether the authcode ID in the device management module is consistent with the received authcode ID of the IoT device to be authenticated based on the IP address, port number, MAC address, and device ID of the IoT device to be authenticated, so as to determine whether the authcode ID of the IoT device to be authenticated exists in the device management module. If they are consistent, it indicates that the authcode ID of the IoT device to be authenticated exists in the device management module, indicating that both the authcode and authcode ID of the IoT device to be authenticated stored in the device management module are up-to-date, and authentication can be performed, that is, step S327 is then executed. If they are inconsistent, it indicates that the authcode ID of the IoT device to be authenticated does not exist in the device management module, and the active authentication networking module needs to update the information of the IoT device to be authenticated in the device management module and request the cloud server to obtain the authcode of the IoT device to be authenticated, that is, step S321 is then executed.

[0186] Step S321: When the authentication code identifier of the IoT device to be authenticated does not exist in the device management module, the active authentication networking module sends the session key index, device identification code, and authentication code identifier of the IoT device to be authenticated to the device management module.

[0187] In the embodiment of the present application, for a newly deployed router, the device management module does not store the authcode ID of the IoT device to be authenticated. Therefore, in step S320, the active authentication networking module cannot query the authcode ID of the IoT device to be authenticated in the device management module. As a result, the active authentication networking module needs to send the rootkeyidx, device ID, and authcode ID of the IoT device to be authenticated to the device management module.

[0188] Step S322: The device management module refreshes the information corresponding to the IoT device to be authenticated according to the rootkeyidx, device ID, and authcode ID.

[0189] After receiving the rootkeyidx, device ID, and authcode ID sent by the active authentication networking module, the device management module can use the received rootkeyidx, device ID, and authcode ID to refresh the information corresponding to the IoT device to be authenticated.

[0190] In some embodiments, since the device ID of the IoT device to be authenticated has a validity period, the following situation may occur: After the IoT device 1 to be authenticated is scanned and discovered by the active discovery scanning module and sends the device ID1 to the active discovery scanning module, the device ID1 of the IoT device 1 to be authenticated reaches the validity period. Then, the IoT device 1 to be authenticated updates the device ID1 to the device ID2. After that, when the IoT device 1 to be authenticated exchanges device information with the active authentication networking module, it sends the device ID2 to the active authentication networking module. Finally, the device ID2 obtained by the active authentication networking module after exchanging device information with the IoT device 1 to be authenticated is inconsistent with the device ID1 of the IoT device 1 to be authenticated stored in the device management module. In this case, in step S319, the active authentication networking module cannot query the device ID2 of the IoT device to be authenticated in the device management module. As a result, the active authentication networking module needs to send the rootkeyidx, device ID, and authcode ID of the IoT device to be authenticated to the device management module so that the device management module can use the received rootkeyidx, device ID, and authcode ID to refresh the information corresponding to the IoT device to be authenticated. For example, the device management module replaces the originally stored device ID1 with the device ID2 and stores the newly received rootkeyidx and authcode ID of the IoT device 1 to be authenticated.

[0191] In some other embodiments, since the authcode and authcode ID of the IoT device to be authenticated have a validity period, the following situation may also occur: When the IoT device 1 to be authenticated exchanges device information with the active authentication networking module and sends the authcode ID1 to the active authentication networking module, the device authentication code 1 and authcode ID1 of the IoT device 1 to be authenticated reach the validity period. Then, the IoT device 1 to be authenticated updates the device authentication code 1 and authcode ID1 to the device authentication code 2 and authcode ID2. Finally, the authcode ID2 obtained after the active authentication networking module exchanges device information with the IoT device 1 to be authenticated is inconsistent with the authcode ID1 of the IoT device 1 to be authenticated stored in the device management module. In this case, in step S320, the active authentication networking module cannot query the authcode ID2 of the IoT device to be authenticated in the device management module. Therefore, the active authentication networking module needs to send the rootkeyidx, device ID, and authcode ID of the IoT device to be authenticated to the device management module so that the device management module can use the received rootkeyidx, device ID, and authcode ID to refresh the information corresponding to the IoT device to be authenticated. For example, the device management module replaces the originally stored device ID1 with device ID2, replaces the originally stored authcode ID1 with authcode ID2, and stores the newly received rootkeyidx and UDID of the IoT device 1 to be authenticated.

[0192] Step S323: The device management module requests the device authentication code and authentication code identifier of the IoT device to be authenticated from the cloud server according to the device identification code of the IoT device to be authenticated.

[0193] After the device node of the IoT device to be authenticated in the device management module stores the latest rootkeyidx, device ID, and authcode ID of the IoT device to be authenticated, the device management module can request the authcode and authcode ID of the IoT device to be authenticated from the cloud server according to the device ID of the IoT device to be authenticated. Specifically, the device management module sends a request message to the cloud server, and the request message includes the device ID of the IoT device to be authenticated to request the authcode and authcode ID of the IoT device to be authenticated, so as to ensure that the router obtains the latest authcode and authcode ID of the IoT device to be authenticated.

[0194] Step S324: The cloud server sends the device authentication code and the authentication code identifier of the IoT device to be authenticated to the device management module.

[0195] Specifically, when the cloud server receives the request message from the device management module, it verifies the device ID of the IoT device to be authenticated in the request message. If the device ID of one of the IoT devices stored in itself is the same as the device ID of the IoT device to be authenticated in the request message, it indicates that the authcode and authcode ID of this IoT device are the authcode and authcode ID of the IoT device to be authenticated requested by the device management module, and then the authcode and authcode ID of this IoT device are sent to the device management module. If there is no device ID in the IoT devices stored in itself that is the same as the device ID of the IoT device to be authenticated in the request message, the cloud server does not perform subsequent processing.

[0196] It can be understood that when the cloud server sends the authcode and authcode ID of the IoT device to be authenticated to the device management module, it also sends the device ID of the IoT device to be authenticated in the request message to the device management module. Thus, the device management module can determine the IoT device to be authenticated corresponding to the received authcode and authcode ID according to the device ID of the IoT device to be authenticated, and store the authcode and authcode ID in the device node of this IoT device to be authenticated.

[0197] Step S325: The device management module determines whether there is a device authentication code of the IoT device to be authenticated in the device management module.

[0198] After receiving the authcode of the IoT device to be authenticated sent by the cloud server, the device management module needs to compare the authcode of the IoT device to be authenticated with the authcode of this IoT device to be authenticated in the device node of the device management module, so as to update the authcode of the IoT device to be authenticated in the device management module to the latest authcode of the IoT device to be authenticated.

[0199] When the router has not authenticated with the IoT device to be authenticated, the device node of the IoT device to be authenticated in the device management module does not store the authcode. When the router has authenticated with the IoT device to be authenticated, there are the following two cases: If the device node of the IoT device to be authenticated in the device management module stores the authcode of the IoT device to be authenticated and the authcode has not expired, then the authcode of the IoT device to be authenticated in the device management module is the same as the authcode of the IoT device to be authenticated sent by the cloud server. In this case, it means that the authcode stored in the device management module is the latest and can be used for authentication, that is, step S327 is executed next; If the device node of the IoT device to be authenticated in the device management module stores the authcode of the IoT device to be authenticated, but the device authentication code has expired, then the authcode of the IoT device to be authenticated in the device management module is different from the authcode of the IoT device to be authenticated sent by the cloud server. At this time, the device management module needs to update the authcode of the IoT device to be authenticated, that is, step S326 is executed next.

[0200] It should be noted that when the device management module receives the authcode ID of the IoT device to be authenticated sent by the cloud server, it updates the authcode ID of the IoT device to be authenticated in the device management module with the authcode ID sent by the cloud server.

[0201] Step S326: When the device authentication code of the IoT device to be authenticated does not exist in the device management module, the device management module refreshes the device authentication code of the IoT device to be authenticated with the device authentication code sent by the cloud server.

[0202] Specifically, when the device node of the IoT device to be authenticated in the device management module does not store the authcode, the authcode sent by the cloud server is stored in the device node of the IoT device to be authenticated in the device management module. When the authcode of the IoT device to be authenticated in the device management module is different from the authcode of the IoT device to be authenticated sent by the cloud server, the authcode sent by the cloud server is used to replace the authcode of the IoT device to be authenticated. When the authcode of the IoT device to be authenticated in the device management module is the same as the authcode of the IoT device to be authenticated sent by the cloud server, the device management module does not perform the authcode update operation.

[0203] Step S327: The device management module sends the device authentication code and the session key index of the IoT device to be authenticated to the active authentication networking module.

[0204] Specifically, when the device node of the to-be-authenticated IoT device in the device management module stores the latest authcode of the to-be-authenticated IoT device, that is, step S317 determines that the device node of the to-be-authenticated IoT device in the device management module stores an authcode ID that is consistent with the authcode ID of the to-be-authenticated IoT device, then the to-be-authenticated IoT device can be authenticated. The device management module sends the authcode and rootkeyidx of the to-be-authenticated IoT device to the active authentication networking module, so that the active authentication networking module initiates authentication to the to-be-authenticated IoT device according to the authcode and rootkeyidx of the to-be-authenticated IoT device.

[0205] Optionally, the device management module also sends the device ID, authcode ID, IP address, port number, and MAC address of the to-be-authenticated IoT device to the active authentication networking module.

[0206] Step S328: The active authentication networking module sends an authentication request to the to-be-authenticated IoT device.

[0207] Among them, the authentication request can include the authentication identification information of the router and rootkeyidx, etc. The authentication identification information indicates that the subsequent communication between the active authentication networking module and the to-be-authenticated IoT device is based on the password-based authentication key exchange process. Rootkeyidx is used to identify this authentication between the active authentication networking module and the to-be-authenticated IoT device.

[0208] Optionally, the authentication request can also include a role identifier and the version information of the security module. Among them, the role identifier (flag) is used to indicate the role of the active end device that sends the authentication request, which helps the to-be-authenticated IoT device distinguish the source of the authentication request and the role that sends the authentication request. The version information of the security module is the version information of the router security module, which helps the to-be-authenticated IoT device determine the protocol version supported by the router security module.

[0209] Step S329: In response to the authentication request, the to-be-authenticated IoT device generates the third authentication information according to the device authentication code of the to-be-authenticated IoT device.

[0210] The third authentication information at least includes salt1, the temporary public key (epk1), and challenge value 1 of the to-be-authenticated IoT device, etc. Among them, salt1, epk1, and challenge value 1 of the to-be-authenticated IoT device are generated based on the authcode of the to-be-authenticated IoT device, and challenge value 1 is used to require the active end device that initiates the authentication to prove the identity of the active end device or perform certain calculations.

[0211] Optionally, during this process, after the IoT device to be authenticated confirms that the version of its own security module is compatible with the version of the security module of the router, it will also send the version information of its own security module to the active authentication networking module.

[0212] Step S330: The IoT device to be authenticated sends the third authentication information to the active authentication networking module.

[0213] Step S331: The active authentication networking module calculates the fourth check value for the third authentication information and generates the fourth authentication information based on the device authentication code of the authenticated IoT device.

[0214] The active authentication networking module calculates the fourth check value by using a key derivation function on its own private key, the salt1 of the IoT device to be authenticated, and the challenge value 1. The fourth authentication information includes at least the salt2, epk2, and challenge value 2 of the router. Among them, the salt2, epk2, and challenge value 2 of the router are generated by the active authentication networking module based on the authcode of the IoT device to be authenticated, and the challenge value 2 is used by the router to verify the identity and computing ability of the IoT device to be authenticated.

[0215] Step S332: The active authentication networking module sends the fourth check value and the fourth authentication information to the IoT device to be authenticated.

[0216] Step S333: The IoT device to be authenticated calculates the fifth check value for the fourth authentication information and generates the second session key by using the third authentication information after passing the verification of the fourth check value based on the fifth check value.

[0217] The IoT device to be authenticated calculates the fifth check value by using the same key derivation function on the salt2, epk2, and challenge value 2 of the router. Then, the IoT device to be authenticated compares the fifth check value with the fourth check value. If the fifth check value is the same as the fourth check value, the fourth authentication information passes the verification, and the IoT device to be authenticated generates the second session key (rootkey2) of the IoT device to be authenticated based on its own salt1, epk1, and challenge value 1.

[0218] In some embodiments, due to logical errors or abnormal crashes inside the active authentication networking module, calculation errors may occur, resulting in incorrect calculation of the fifth verification value, causing the fifth verification value to be different from the fourth verification value. Or when the IoT device to be authenticated generates a new authcode after the authcode has expired, and since the old authcode is still in use and the new authcode is not uploaded to the cloud server in a timely manner, the router requests the old authcode from the cloud server and uses the old authcode to generate salt2, epk2, and challenge value 2, while the IoT device to be authenticated uses the new authcode to generate salt1, epk1, and challenge value 1, resulting in the fifth verification value being different from the fourth verification value. In these two cases, the fifth verification value fails to pass the verification of the fourth verification value. At this time, the active authentication networking module determines that this authentication fails and sends the result of the authentication failure to the link startup process, so that the link startup process reports it to the APP of the electronic device.

[0219] Step S334: The IoT device to be authenticated sends the fifth verification value to the active authentication networking module.

[0220] Step S335: After the active authentication networking module passes the verification of the fifth verification value according to the fourth verification value, it generates the second session key using the fourth authentication information.

[0221] The active authentication networking module compares the fourth verification value with the fifth verification value. If the fourth verification value is the same as the fifth verification value, the active authentication networking module generates the rootkey2 of the router based on its own salt2, epk2, and challenge value 2.

[0222] Since the IoT device to be authenticated will generate a new rootkeyidx and send it to the router when exchanging device information with the router, and then the router will use the rootkeyidx to mark the active authentication with the IoT device to be authenticated. Therefore, after the IoT device to be authenticated and the active authentication networking module generate their respective rootkey2, they can both associate and store the rootkeyidx with their respective rootkey2, so that the IoT device to be authenticated and the router can distinguish the rootkey2 generated by the router each time after authenticating with the IoT device to be authenticated according to the rootkeyidx.

[0223] In some embodiments, rootkey2 has a validity period, such as 7 days. Therefore, the router is provided with a session key expiration monitoring mechanism, such as a session management module, which can send a LOCAL message (such as CLIENT_DISCOVERY_LOCAL) to the active discovery module when rootkey2 expires, to initiate the active discovery scanning module to start scanning and discovering IoT devices in the ad-hoc network, so as to re-authenticate actively with the IoT devices and generate a new rootkey2.

[0224] Through the above process, device authentication is performed between the router and the IoT devices actively. The device management module stores the information of the authenticated IoT devices in an IoT device linked list. The information of the IoT devices stored in the IoT device linked list includes but is not limited to the IP address, port number, MAC address, UDID, rootkeyidx, authcode, authcodeID, and device ID of the IoT devices. After that, the router can negotiate with the IoT devices to establish a secure channel.

[0225] Figure 10 The flowchart showing the process of the router provided by the embodiment of the present application establishing a channel with the IoT device is shown. Below, in combination with Figure 10 The process of the router provided by the embodiment of the present application actively establishing a channel with the IoT device will be elaborated in detail. Figure 10 Taking the application scenario of modifying the router network parameters as an example, the process of the router establishing a channel with the IoT device is described. In the application scenario of modifying the router network parameters, the service function module is the network password modification module. The process of the router establishing a channel with the IoT device includes:

[0226] Step S336: The active authentication networking module determines the authenticated IoT device to be authenticated as the authenticated IoT device.

[0227] After the active authentication networking module completes the authentication with the IoT device, it determines the IoT device actively authenticated by the router as the authenticated IoT device.

[0228] Step S337: The active authentication networking module sends the authenticated IoT device to the network password modification module.

[0229] After determining the authenticated IoT device, the active authentication networking module sends the authenticated IoT device (here, the device name and other information used to distinguish different IoT devices for sending the authenticated IoT device) to the network password modification module to initiate a session by the network password modification module based on the service of modifying the router network parameters.

[0230] Optionally, in this step, the active authentication networking module may send the root key 2 of the authenticated IoT device to the network password change module.

[0231] Step S338: The network password change module generates an initiate session instruction.

[0232] After receiving the authenticated IoT device sent by the active authentication networking module, the network password change module generates an initiate session instruction and sends the initiate session instruction to the active session connection module, so that the active session connection module initiates a session to the authenticated IoT device.

[0233] Step S339: The network password change module sends the initiate session instruction to the active session connection module, so that the active session connection module initiates a session to the authenticated IoT device.

[0234] Optionally, in this step, the initiate session instruction sent by the network password change module to the active session connection module may carry the root key 2 of the authenticated IoT device.

[0235] Step S340: In response to the initiate session instruction, the active session connection module generates a create session node instruction for creating a channel with the authenticated IoT device.

[0236] Optionally, after completing the authentication with the IoT device, the active authentication networking module may report the authentication result to the link startup process, and the link startup process sends the authentication result to the APP or WebUI of the electronic device through Inter-Process Communication (IPC). Among them, the WebUI (Web User Interface) is a user interface accessed through a Web browser, and through this interface, network devices such as routers can be configured and managed. After that, the APP or WebUI of the electronic device responds to the operation of the user to modify the router network parameters, triggering the network parameter synchronization service process of the electronic device, or the router process responds to the user operation to trigger the network parameter synchronization service process, and the network parameter synchronization service process sends an initiate session instruction to the link startup process through IPC, so that the link startup process sends the initiate session instruction to the active session connection module.

[0237] Step S341: The active session connection module sends the create session node instruction to the passive session connection module, so that the passive session connection module creates a session node.

[0238] In this step, the active session connection module can respond to the session initiation instruction of the link startup process and send a session node creation instruction to the passive session connection module.

[0239] Step S342: The passive session connection module creates a session node in response to the session node creation instruction.

[0240] The passive session connection module creates a session node in the session management module in response to the session node creation instruction sent by the active session connection module. Herein, the session node is used to identify, track, and manage the session between the router and the IoT device.

[0241] Step S343: The active session connection module generates a session establishment message and encrypts the session establishment message using the second session key.

[0242] Specifically, the active session connection module first generates a session establishment message. Before sending the session establishment message to the authenticated IoT device, the active session connection module needs to encapsulate the session establishment message into packet data in a specific format. After that, the active session connection module encrypts the packet data using the router's rootkey2 and an encryption algorithm to obtain the encrypted packet data. The encryption algorithm can use the Advanced Encryption Standard (AES), RSA (Rivest-Shamir-Adleman), etc. Optionally, the active session connection module can also first generate an encryption key using rootkey2 and then encrypt the packet data using the encryption key and the encryption algorithm to obtain the encrypted packet data.

[0243] Step S344: The active session connection module sends the encrypted session establishment message to the authenticated IoT device.

[0244] After obtaining the encrypted message data, first, the active session connection module calls the sendMsg function to add the encrypted message data to the operation linked list (or message queue). This operation linked list is used to store and manage message data in sequence, ensuring that message data will not be lost even if errors or delays occur during transmission and can be resent. Then, after the active session connection module decides to send the encrypted message data to the authenticated IoT device, the active session connection module retrieves the encrypted message data from the operation linked list, encapsulates it into the format required by the network protocol, and then sends the encrypted message data to the authenticated IoT device. For example, when the communication protocol used for the established channel is the Wi-Fi protocol, the active session connection module encapsulates the encrypted message data retrieved from the operation linked list into the Wi-Fi protocol format and then sends it to the authenticated IoT device.

[0245] Step S345: The authenticated IoT device decrypts the encrypted session establishment message using the second session key to obtain the session establishment message, and establishes a session node in response to the session establishment message.

[0246] After receiving the encrypted session establishment message, the authenticated IoT device first decrypts the encrypted session establishment message using its own rootkey2 to obtain the session establishment message, thereby determining that the router wants to establish a communication channel with this authenticated IoT device. Then, the passive session connection module of the authenticated IoT device establishes a session node in the session management module.

[0247] Step S346: The authenticated IoT device generates a third confirmation message and encrypts the third confirmation message using the second session key.

[0248] After the passive session connection module of the authenticated IoT device establishes a session node in the session management module, the authenticated IoT device generates a third confirmation message (ack3). Then, the authenticated IoT device encrypts ack3 using its own rootkey2.

[0249] Step S347: The authenticated IoT device sends the encrypted third confirmation message to the passive session connection module.

[0250] After encrypting ack3, the authenticated IoT device sends the encrypted ack3 to the passive session connection module of the router.

[0251] Step S348: The passive session connection module sends the encrypted third confirmation message to the active session connection module.

[0252] Step S349: The active session connection module decrypts the encrypted third confirmation message using the second session key to obtain the third confirmation message.

[0253] After the active session connection module decrypts to obtain the ack3 of the authenticated IoT device, the active session connection module and the authenticated IoT device can encrypt and decrypt the data transmitted between them (i.e., between the session node of the router and the session node of the authenticated IoT device) using the rootkey2, which means that a secure channel is successfully established between the router and the authenticated IoT device.

[0254] If the establishment of a secure channel fails between the router and a certain authenticated IoT device, the communication connection component of the router sends a message indicating the failure of establishing the secure channel to the device management module. The device management module removes the IoT device that has not successfully established a secure channel with the router from the IoT device linked list to update the IoT device linked list. In this way, the IoT devices in the IoT device linked list are all IoT devices that have established a secure channel with the router. In some embodiments, after the network password change module sends a session establishment instruction to the active session connection module, it can set a timing time and a callback function to call the callback function to obtain the decrypted ack3 of the active session connection module when the ack3 sent by the active session connection module is not received after the timeout. Alternatively, when the passive session connection module does not receive the ack3 of the authenticated IoT device, the passive session connection module sends the result of the failed session establishment to the active session connection module, and the network password change module calls the callback function to obtain the result of the failed session establishment of the active session connection module.

[0255] In some embodiments, after the active session connection module reports the result of the failed session establishment to the network password change module, the active session connection module also sends a session node deletion instruction to the passive session connection module to enable the passive session connection module to delete the session node in the session management module to save the memory resources of the router.

[0256] Through the above steps, the router actively authenticates with multiple IoT devices, and correspondingly generates a rootkey2 for each IoT device. Therefore, the router and each IoT device can encrypt and decrypt the data transmitted between them through the rootkey2 corresponding to each IoT device, that is, the router actively establishes a secure channel with multiple IoT devices. Further, the router can authenticate with the same IoT device multiple times, and correspondingly generate different rootkey2s for the IoT device. Therefore, the router and the IoT device can encrypt and decrypt the transmitted data between them through different rootkey2s, that is, the router and the IoT device establish multiple secure channels. For example, the router can establish a Wi-Fi channel, a Bluetooth channel, or a ZigBee channel that supports Wi-Fi communication protocol, Bluetooth communication protocol, or ZigBee communication protocol with the IoT device. Optionally, the Wi-Fi channel can include channels in frequency bands such as 2.4 GHz band and 5 GHz band.

[0257] In the embodiment of the present application, the router obtains the device ID of the IoT device and requests the cloud server to obtain the authcode of the IoT device through the device ID of the IoT device, so that the router can actively initiate a security authentication to the IoT device based on the authcode of the IoT device, and can actively establish a secure communication channel with the IoT device after authentication, enabling the router to have the capabilities of both passive security authentication interaction and active security authentication interaction. This enables the router to establish a secure channel with electronic devices such as mobile phones passively as a passive end device, and at the same time, as an active end device, it can actively establish a secure channel with other IoT devices and actively transmit data with other IoT devices. Moreover, the router can transmit data with the IoT device through the secure channel actively established with the IoT device, improving the security of data transmission between the router and the IoT device.

[0258] After the above steps, a secure channel has been established between the router and the IoT device. If the user modifies the network parameters of the router, the router can update the network parameters stored in the IoT device based on this secure channel. The following combines Figure 11 to elaborate on the process of updating network parameters in detail. Figure 11 shows a schematic flowchart of network parameter update provided by the embodiment of the present application, which may specifically include:

[0259] Step S350: The electronic device generates a network parameter modification instruction in response to an operation of modifying network parameters.

[0260] Among them, the network parameter modification instruction includes new network parameter information (i.e., the first network parameter), and the network parameter information includes a network name (i.e., the first network name / the first SSID) and a password (i.e., the first network password). When the user modifies the network parameters of the router through the APP or WebUI on the electronic device, the APP or WebUI generates a network parameter modification instruction in response to the user's operation of modifying the router network parameters.

[0261] Exemplarily, when the user needs to modify the network parameters of the router, the user can click on the router 27 on the main interface 21 of the APP shown in Figure 5 (d). Then the electronic device enters the router interface 28 shown in Figure 12 (a) in response to the user's operation on the router 27. On the router interface 28, the user can click to use functions such as "One - key Health Check", "Upgrade Management", "Routing Settings", "Routing Login Password Settings", "WiFi Settings", and "Network Settings", or can click to view "Operation Weekly Report" and "User Guide". Correspondingly, if the user needs to modify the network parameters of the router, at this time, the user can click on "Wi - Fi Settings" 29 in this interface. After that, the electronic device enters the Wi - Fi settings interface 30 shown in Figure 12 12(b) in response to the user's operation on "Wi - Fi Settings" 29. This interface can display the Wi - Fi name and Wi - Fi password of different - band Wi - Fis. For example, the Wi - Fi name and Wi - Fi password of the 2.4GHz - band Wi - Fi and the Wi - Fi name and Wi - Fi password of the 5GHz - band Wi - Fi. In the Wi - Fi settings interface 30, the user can turn on both the 2.4GHz - band Wi - Fi and the 5GHz - band Wi - Fi at the same time, or can choose to turn on one of the 2.4GHz - band Wi - Fi and the 5GHz - band Wi - Fi, or can turn off both the 2.4GHz - band Wi - Fi and the 5GHz - band Wi - Fi at the same time. In the Wi - Fi settings interface 30, the user can modify the Wi - Fi name and Wi - Fi password of any one - band Wi - Fi. For example, when the user modifies the Wi - Fi name and Wi - Fi password of the 2.4GHz - band Wi - Fi and clicks on the "√" 31 in the Wi - Fi settings interface 30, the electronic device displays a prompt message of "Saving settings" shown in 12(c) in the Wi - Fi settings interface 30 in response to the above operation. When the APP saves the modified network parameter information, the APP will generate a network parameter modification instruction according to the network parameter information.

[0262] When the router has multiple bands, the network parameter modification instruction can also include the band to inform the router which band the modified network parameters specifically correspond to. Of course, when the router has only one band, the network parameter modification instruction can also include the band.

[0263] Step S351: The electronic device sends a network parameter modification instruction to the router process of the router.

[0264] After generating the network parameter modification instruction, the electronic device sends the generated network parameter modification instruction to the router process. Then, the Wi-Fi settings interface 30 displays the prompt message "Synchronizing other IoT devices, please wait" as shown in 12(d).

[0265] Step S352: The router process sends the network parameter modification instruction to the network parameter synchronization service process.

[0266] After receiving the network parameter modification instruction, the router process determines to start the network parameter modification process and sends the network parameter modification instruction to the network parameter synchronization service process.

[0267] Step S353: The network parameter synchronization service process parses the network parameter modification instruction to obtain new network parameter information, and generates a network parameter update message based on the new network parameter information.

[0268] After receiving the network parameter modification instruction, the network parameter synchronization service process parses the network parameter modification instruction to obtain new network parameter information. The new network parameter information includes the modified network name and / or the modified password.

[0269] All frequency bands of the router, the current network name (i.e., the network name before modification) and password of each frequency band are stored in the network parameter synchronization service process. If the router has multiple frequency bands, the network parameter synchronization service process can determine the network name before modification according to the frequency band in the network parameter modification instruction; if the router has only one frequency band, the network parameter synchronization service process can directly determine the network name before modification.

[0270] The network parameter update message generated based on the new network parameter information includes at least the frequency band (i.e., the frequency band corresponding to the network parameters modified this time), the network name before modification (SSID1), the network name after modification (SSID2), and the password after modification (password2, simply referred to as PW2). A frequency band identifier can be set for the frequency band, and the specific frequency band is identified by the frequency band identifier in the network parameter update message. For a single-band router, the frequency band can be 2.4Ghz (for example, the frequency band identifier is 0) or 5Ghz (for example, the frequency band identifier is 1). For a dual-band router, the frequency band can be 2.4GHz + 5GHz (for example, the frequency band identifier is 2). If the SSID is not modified, the SSID before modification and the SSID after modification in the network parameter update message are the same. If the password is not modified, the password after modification in the network parameter update message is the current password. In some embodiments, the network parameter update message may further include the IP address and security mode of the router.

[0271] Step S354: The network parameter synchronization service process sends the network parameter update message to the network password modification module.

[0272] Step S355: The network password modification module obtains the IoT device list from the device management module.

[0273] As described above, the device management module stores the IoT device list. The network password modification module can obtain the IoT device list from the device management module during the network parameter modification process to determine the IoT devices to be synchronized.

[0274] In some embodiments, after obtaining the IoT device list, the network password modification module can also send the IoT devices in the IoT device list to the network parameter synchronization service process (the information sent here is the device name of the IoT device, etc., which is used to distinguish different IoT devices. The same applies to "sending the IoT devices" below), so that the network parameter synchronization service process sends the IoT devices to the APP of the electronic device to display these IoT devices on the interface of the APP of the electronic device. In this case, the user can select one or more IoT devices from the displayed IoT devices for synchronization of the new network parameter information. For example, when the IoT devices displayed on the interface of the APP are a refrigerator, an air conditioner, a speaker, and a door lock, the user can only select the refrigerator, the air conditioner, and the speaker for synchronization of the new network parameter information.

[0275] Step S356: The network password modification module determines whether the IoT devices in the IoT device list are the IoT devices to be synchronized.

[0276] In some embodiments, after the router actively authenticates with the IoT device, the network password modification module obtains the SSID configured by the IoT device from the network parameter synchronization service process according to the IP address of the IoT device, and stores the SSID configured by the IoT device in the IoT device linked list. In this way, the SSID configured by each IoT device in the linked list is stored in the IoT device linked list of the device management module. The network password modification module obtains the SSID configured by the IoT device from the IoT device linked list, and determines whether the SSID configured by the IoT device is the same as the SSID before modification in the network parameter update message.

[0277] If the SSID configured by the IoT device is the same as the SSID before modification in the network parameter update message, it indicates that the IoT device is an IoT device that needs to update network parameters. The IoT device is determined as the IoT device to be synchronized, and a network parameter update message can be sent to the IoT device to be synchronized to update the network parameters saved by the IoT device to be synchronized. For example, if the network parameter update this time changes the network name from SSID1 to SSID2, the SSID before modification in the network parameter update message is SSID1. If the SSID configured by the IoT device is SSID1, the IoT device is determined as the IoT device to be synchronized. Another example, if the network parameter update this time does not modify the network name and changes the password from password1 to password2, the SSID before modification in the network parameter update message is also SSID1. If the SSID configured by the IoT device is SSID1, the IoT device is determined as the IoT device to be synchronized.

[0278] If the SSID configured by the IoT device is different from the SSID before modification in the network parameter update message, it indicates that due to reasons such as the disconnection of the physical channel between the IoT device and the router, the network parameters of the IoT device were not successfully modified during the previous network parameter update. During this network parameter update, a network parameter update message will no longer be sent to the IoT device, and steps S357 and subsequent steps will not be executed for the IoT device. For example, during the previous network parameter update, the network name was changed from SSID1 to SSID2, but the network name of the IoT device was not successfully modified. Then the network name configured by the IoT device is still SSID1. During this network parameter update, the network name is changed from SSID2 to SSID3. Since the network name configured by the IoT device is SSID1, which is inconsistent with the SSID (SSID2) before modification in the network parameter update message, the IoT device is not determined as the IoT device to be synchronized, and thus the network parameters of the IoT device will not be modified during this update.

[0279] It should be noted that the router can periodically monitor the IoT devices connected to the router through a heartbeat mechanism. If an IoT device is disconnected from the router on the physical channel, the router will remove the disconnected IoT device from the IoT device linked list. For the disconnected IoT devices that have been removed from the IoT device linked list, the judgment of whether they are IoT devices to be synchronized in step S356 will not be executed. For such devices, the user can manually configure the network parameters.

[0280] In some embodiments, before executing step S356, the network password modification module can also first determine whether the frequency band configured by the IoT devices in the IoT device linked list is the same as the frequency band in the network parameter update message. If they are the same, it means that the IoT device is an IoT device connected to the frequency band for which the network parameters are currently being modified, and it can be further determined whether the IoT device is an IoT device to be synchronized. Then, step S356 is executed for this IoT device. If they are different, it means that the IoT device is not an IoT device connected to the frequency band for which the network parameters are currently being modified, and there is no need to update the network parameters this time. Then, step S356 and subsequent steps are not executed for this IoT device, and it continues to determine whether the frequency band configured by the next IoT device in the IoT device linked list is the same as the frequency band in the network parameter update message. If they are the same, step S356 is executed for the next IoT device to determine whether the next IoT device is an IoT device to be synchronized.

[0281] Step S357: The network password modification module queries the active session connection module for the security channel to which the IoT device to be synchronized is currently connected.

[0282] As mentioned above, the router can establish multiple security channels with each IoT device, each supporting a different communication protocol, and the router can establish security channels with multiple IoT devices. After the router establishes a security channel with an IoT device, the active session connection module of the router records the channel identifier of each security channel and the corresponding relationship between the security channel and the IoT device. After the network password modification module determines the IoT device to be synchronized, it queries the active session connection module for the security channel to which the IoT device to be synchronized is currently connected, so as to know which security channel needs to be used to send the new network parameters to the IoT device to be synchronized. The active session connection module sends the channel identifier of the security channel to which the IoT device to be synchronized is currently connected to the network password modification module.

[0283] Step S358: The network password modification module sends the new network parameter information and the channel identifier of the security channel to which the IoT device to be synchronized is currently connected to the active session connection module.

[0284] The new network parameter information includes the modified network name and the modified password. The network password modification module sends the modified SSID and the modified password in the received network parameter update message to the active session connection module, and the active session connection module distributes them to the IoT devices to be synchronized. The network password modification module also sends the channel identifier of the security channel currently connected by the IoT devices to be synchronized to the active session connection module, so as to inform the active session connection module which security channel to use to distribute data.

[0285] Step S359: The active session connection module asynchronously sends the new network parameter information to the IoT devices to be synchronized through the security channel.

[0286] In the embodiment of the present application, the method of distributing the modified SSID and the modified password to the IoT devices to be synchronized is an asynchronous sending method. Specifically, in step S356, the network password modification module determines whether the SSID configured by the first IoT device in the IoT device list is the same as the SSID before modification in the network parameter update message. If they are the same, steps S357 to S359 are executed to send the modified SSID and the modified password to the first IoT device. After the network password modification module finishes executing steps S356 to S358 for the first IoT device, without waiting for the response of the first IoT device, it continues to execute step S356 for the second IoT device in the IoT device list... and so on. Usually, before receiving the response of the previous IoT device, the network password modification module has already started to execute step S356 for the next IoT device. If the SSID configured by the first IoT device is different from the SSID before modification in the network parameter update message, steps S357 to S359 are not executed, and the network password modification module also does not wait and continues to execute step S356 for the second IoT device in the IoT device list.

[0287] Since the processing rate of IoT devices is slow, if the router waits for the response of the first IoT device before continuing to modify the network parameters of the second IoT device, it will affect the efficiency of network parameter update, and then affect the user experience. In the embodiment of the present application, the router asynchronously sends the modified SSID and the modified password to the IoT devices to be synchronized. During the whole process, there is no need to detect in real time whether the previous IoT device to be synchronized has received the modified SSID and the modified password, and the network parameter update of the next IoT device can be continued. The network parameter updates of multiple IoT devices to be synchronized are carried out concurrently, improving the efficiency of network parameter update and enhancing the user experience.

[0288] The active session connection module uses the secure channel corresponding to the channel identifier sent by the network password modification module to send the modified SSID and the modified password to the IoT device to be synchronized. The active session connection module can encrypt the modified SSID and the modified password using rootkey2 and send the encrypted modified SSID and the modified password to the IoT device to be synchronized.

[0289] In this embodiment, in step S356, the network password modification module can traverse the entire IoT device linked list, determine whether each IoT device in the IoT device linked list is an IoT device to be synchronized, and send the modified SSID and the modified password to the IoT device to be synchronized through steps S357 and S358. In one implementation, the IoT device can also set whether to automatically update network parameters through the APP or WebUI of the electronic device. In step S356, the network password modification module only determines whether the IoT devices in the IoT device linked list that are set to automatically update network parameters are IoT devices to be synchronized.

[0290] Step S360: The IoT device to be synchronized modifies the network parameters according to the new network parameter information and generates a modification result.

[0291] The IoT device to be synchronized decrypts the encrypted modified network name and the modified password using rootkey2 to obtain the new network parameter information, and modifies the network parameters to the SSID and password in the new network parameter information. After that, the IoT device to be synchronized generates a modification result. The modification result is success or failure, which is used to indicate that the network parameter modification of the IoT device to be synchronized is successful or the network parameter modification fails.

[0292] Step S361: The IoT device to be synchronized sends the modification result to the passive session connection module.

[0293] Step S362: The passive session connection module sends the modification result to the active session connection module.

[0294] Step S363: The active session connection module sends the modification result to the network password modification module.

[0295] Step S364: The network password modification module sends the modification result to the network parameter synchronization service process.

[0296] Step S365: After receiving the modification results sent back by all the IoT devices to be synchronized in the IoT device linked list, the network password modification module sends the aggregated modification data to the network parameter synchronization service process.

[0297] All IoT devices in the IoT device list are traversed. After network parameter updates are performed on all IoT devices confirmed to be IoT devices to be synchronized, the network password modification module aggregates the received modification results to obtain aggregated modification data and sends it to the network parameter synchronization service process. The aggregated modification data includes whether the network parameter update of the IoT device with the current modification (i.e., the last modification) is successful, the number of IoT devices with successful network parameter updates, the number of IoT devices with failed network parameter updates, and the number of all IoT devices in the IoT device list. Among them, if the physical channel between the IoT device to be synchronized and the router is disconnected, resulting in the router failing to send new network parameters to the IoT device to be synchronized, or if the IoT device to be synchronized sends a modification result but the modification result fails to reach the router successfully, both will cause the network password modification module of the router not to receive the modification result of the IoT device to be synchronized. When the network password modification module counts the number of IoT devices with failed network parameter updates, the IoT devices with failed network parameter updates include IoT devices whose received modification result is failed by the network password modification module, and IoT devices that have been sent new network parameters but no modification result returned by the IoT device has been received.

[0298] Step S366: The network parameter synchronization service process sends the modification result and the aggregated modification data to the router process.

[0299] Specifically, the network parameter synchronization service process sends the modification result and the aggregated modification data to the router process through IPC.

[0300] Step S367: The router process sends the modification result and the aggregated modification data to the electronic device.

[0301] Specifically, the router process sends the modification result and the aggregated modification data to the APP or WebUI of the electronic device to notify the APP or WebUI of the electronic device of the synchronization result of the network parameters.

[0302] Step S368: The electronic device displays the modification result and the aggregated modification data.

[0303] Exemplarily, after the network password modification module synchronizes all new network parameters to the IoT devices to be synchronized, Figure 12 a "Synchronization Successful" prompt as shown in 12(e) is displayed next to the 2.4G Wi-Fi in the Wi-Fi settings interface 30 to remind the user that the network parameters of the IoT device have been successfully modified this time. Figure 12In addition to displaying the "Synchronization Successful" prompt, 12(e) can also display some or all of the data in the summary modified data, such as "XX IoT device network parameters updated successfully", "XX IoT device network parameter update failed", etc. For the IoT devices that have not been successfully modified this time, the user can also choose to manually update the network parameters on the electronic device.

[0304] In some embodiments, after receiving the network parameter update message sent by the network parameter synchronization service process, the network password modification module can start a timer, for example, a timer with a timing time of 30s. When the timer reaches the timing time, the network password modification module stops executing step S356, that is, even if the IoT device linked list has not been traversed completely at this time, the network password modification module will no longer traverse the IoT device linked list. In step S365, when the network password modification module receives the modification results sent back by all the to-be-synchronized IoT devices in the IoT device linked list, or when the timer reaches the timing time, as long as one of them is satisfied, it will send the summary modified data to the network parameter synchronization service process.

[0305] In some other embodiments, the network password modification module can send the to-be-synchronized IoT devices with failed modification results to the network parameter synchronization service process, so that the network parameter synchronization service process sends these IoT devices to the APP or WebUI of the electronic device, and displays the failed modification results of the above IoT devices in the interface of the APP or WebUI of the electronic device.

[0306] In the above manner, after modifying the network parameters of the router, there is no need to send new network parameters to each IoT device one by one through the APP or WebUI of the electronic device to reconfigure the network for the IoT devices. The router can automatically modify the network parameters of multiple to-be-synchronized IoT devices, eliminating the cumbersome manual operations of the user, not only improving the user experience, but also avoiding errors and omissions in manual operations. Moreover, the entire process of the router sending the modified network parameters to each IoT device is executed concurrently, further improving the update efficiency of the network parameters and the user experience. And since the router sends the new network parameters through the secure channel actively established with the IoT device, the security of the network parameters transmitted between the router and the IoT device is guaranteed.

[0307] In the solution of starting a timer in the network password modification module, if there are a large number of IoT devices in the IoT device list, it may not be possible to complete the update of the network parameters of all IoT devices in the IoT device list to be confirmed and synchronized within the timing time of the timer. For example, if there are 128 IoT devices in the IoT device list to be confirmed and synchronized, when the 30s timing time of the timer arrives, only the network parameters of 100 IoT devices are updated, and the steps S356 - S358 have not been executed for the remaining 28 IoT devices. The router can mark the IoT devices whose network parameters have not been updated and cache this mark, and give priority to updating the IoT devices that were not updated last time during the next network parameter update operation, so as to balance the network parameter update opportunities for each IoT device. It should be noted that the number of the above IoT devices is only an example. Figure 13 The flowchart showing the process of balancing the update of network parameters provided by the embodiments of the present application is shown in Figure 13 , and the process includes:

[0308] Step S401: The network password modification module identifies the IoT devices in the IoT device list of the device management module that have not had their network parameters updated when the timing time of the timer arrives.

[0309] This step can be executed after Figure 11 the step S365 shown. Hereinafter, the IoT devices identified in the IoT device list are referred to as identified IoT devices. In addition, the IoT devices disconnected from the router on the physical channel will be regularly removed from the IoT device list by the router. For example, the original IoT device list includes IoT devices 1 - 100, among which IoT devices 70 - 80 are removed from the IoT device list due to disconnection from the router. When the timing time of the timer arrives, the IoT devices that have had their network parameters updated or are not IoT devices to be synchronized include IoT devices 1 - 69, and the IoT devices that have not had their network parameters updated include IoT devices 81 - 100. The network password modification module identifies IoT devices 81 - 100 in the IoT device list. The IoT devices that have had their network parameters updated refer to the IoT devices to which the router has sent new network parameter information, regardless of whether the network parameter modification result of the IoT device is successful or not. The IoT devices that have not had their network parameters updated are the IoT devices to which the router has not sent new network parameter information.

[0310] An IoT device can be identified by adding a flag field (such as a gender field) to the structure body of each device node in the IoT device list and initializing this flag field. When an IoT device needs to be identified, the value of the flag field of the node of this IoT device is updated to 1, indicating that this IoT device is an IoT device that has not had its network parameters updated when the timing time of the timer arrives.

[0311] Step S402: The network password modification module receives a network parameter update message.

[0312] After performing a network parameter modification process as shown in Figure 11 , the network parameters are modified again. The electronic device sends a second network parameter modification instruction to the router. The second network parameter modification instruction carries second network parameters, and the second network parameters include a second network name (second SSID) and / or a second network password. By executing the same process as steps S350 - S354, the network password modification module receives a network parameter update message again. The modified SSID (i.e., the second SSID) and password (i.e., the second network password) in the received network parameter update message this time can be different from or the same as the SSID and password after the previous network parameter modification. For example, the previous network parameter update changed the network name from SSID1 to SSID2 and the password from password1 to password2, and this network parameter update changes the network name from SSID2 to SSID3 and the password from password2 to password3; or this network parameter update only changes the password from password2 to password3 and the network name remains unchanged, still being SSID2.

[0313] Step S403: The network password modification module obtains the IoT device list from the device management module.

[0314] If the network parameter update of some of the IoT devices to be synchronized in the IoT device list was not completed within the scheduled time during the previous network parameter modification, the IoT device list obtained in this step includes the identified IoT devices.

[0315] Step S404: The network password modification module queries the active session connection module for the secure channels currently connected by the identified IoT devices in the IoT device list.

[0316] For the identified IoT device, the network password modification module does not verify the SSID of the IoT device, that is, it does not determine whether the configured SSID of the identified IoT device is the same as the SSID before modification in the network parameter update message, and directly updates the network parameters of the identified IoT device. For example, the previous network parameter update changed the network name from SSID1 to SSID2, and this network parameter update changes the network name from SSID2 to SSID3. Since the identified IoT device did not perform a network parameter update last time and the configured network name is SSID1, even if the configured network name SSID1 of the identified IoT device is inconsistent with the SSID (SSID2) before modification in this network parameter update message, the network password modification module still updates the network parameters of the identified IoT device, directly executes step S404 for the identified IoT device, and the SSID configured by the identified IoT device does not need to be changed from SSID1 to SSID3.

[0317] The identified IoT device also belongs to the IoT device to be synchronized. It's just that for the identified IoT device, it is not necessary to execute the foregoing step S356. The identified IoT device is directly regarded as the IoT device to be synchronized for network parameter update.

[0318] Step S405: The network password modification module sends the new network parameter information and the channel identifier of the secure channel currently connected by the identified IoT device to the active session connection module.

[0319] Step S406: The active session connection module asynchronously sends the new network parameter information to the identified IoT device through the secure channel. The new network parameter information refers to the modified SSID and password in the latest network parameter update message received by the network password modification module in step S402.

[0320] In the embodiment of the present application, the method of sending the modified SSID and the modified password to the identified IoT device is an asynchronous sending method. Specifically, in step S404, the network password modification module queries the secure channel currently connected by the first identified IoT device in the IoT device list from the active session connection module, and continues to execute steps S405 to S406 to send the modified SSID and the modified password to the first identified IoT device. After the network password modification module finishes executing steps S404 to S405 for the first identified IoT device, it does not need to wait for the response of the first identified IoT device, and continues to execute steps S404 to S405 for the second identified IoT device in the IoT device list... and so on. Through the above method, the network parameter updates of multiple identified IoT devices are carried out concurrently, improving the efficiency of network parameter update and enhancing the user experience.

[0321] Step S407: The network password modification module updates the network parameters of the remaining IoT devices in the IoT device list except the identified IoT device. After traversing the identified IoT devices in the IoT device list, the network password modification module also does not need to wait for the response of the last identified IoT device and continues to update the network parameters of the remaining IoT devices in the IoT device list, that is, the network parameter update of the IoT devices is all asynchronous. The process of updating the network parameters of the remaining IoT devices in the IoT device list except the identified IoT device in this step can refer to the foregoing steps S356 - S359 and will not be elaborated here.

[0322] After the active session connection module asynchronously sends new network parameter information to each IoT device, the network parameter update process will also execute Figure 11 Steps S360 to S368 shown. The IoT device that receives the new network parameter information modifies the network parameters according to the new network parameter information to generate a modification result. The network password modification module reports the modification result and the aggregated modification data to the electronic device in sequence through other processes in the router, and the electronic device displays the modification result and the aggregated modification data.

[0323] In some embodiments, the network password modification module can adjust the identified IoT device (for example, the IoT device with the node flag field being 1) to the head of the IoT device list in the IoT device list. When the network password modification module performs the network parameter update in steps S404 - S406, it updates according to the order of the IoT device list, that is, the network password modification module traverses the IoT devices in the IoT device list according to the order of the IoT device list, and first updates the IoT device at the head of the list (that is, the identified IoT device), and then sequentially updates the remaining IoT devices in the IoT device list except the identified IoT device. In the above manner, when a network parameter update fails to complete the update of all IoT devices at a certain time, by marking the IoT devices that are not updated this time, the IoT devices that were not updated last time are preferentially updated in the next network parameter update operation, balancing the network parameter update opportunities for each IoT device. When there are many IoT devices, it is possible to avoid the situation where the IoT devices ranked at the end of the IoT device list in the device management module are always unable to perform network parameter updates.

[0324] When there is only one router in the home network scenario, due to factors such as the hardware performance of a single router, antenna gain, and physical obstacles (such as walls and floors), problems such as limited wireless network coverage, unstable signals, and difficult network expansion often occur. To solve the above problems of traditional wireless networks, Mesh networking technology has emerged. Figure 14 Shows the Mesh network architecture diagram provided by the embodiments of the present application. AsFigure 14 As shown in the figure, a Mesh network includes multiple routers (40A and 40B). A user can set one of the routers (such as router 40A) as the main router and the remaining routers (such as multiple routers 40B) as sub-routers through the APP or WebUI of an electronic device. The main router 40A is the main device in the Mesh network, responsible for connecting to the Internet and managing the entire network. The main router 40A usually configures network settings such as network name and password, and synchronizes the network settings to all sub-routers 40B in the network. The sub-router 40B connects to the main router 40A to expand the coverage of the wireless network. IoT devices near each sub-router 40B are communicatively connected to the sub-router 40B. The sub-router 40B does not need to be configured separately, can automatically obtain network settings from the main router 40A, and cooperate with the main router 40A to form a unified network. The network parameters of each sub-router 40B are the same as those of the main router 40A.

[0325] For example, in a Mesh networking scenario, there is 1 main router and 3 sub-routers (sub-router 1, sub-router 2, and sub-router 3). Sub-router 1 is located in the living room, sub-router 2 is located in the bedroom, and sub-router 3 is located in the kitchen. IoT devices such as televisions and projectors located in the living room are connected to sub-router 1, IoT devices such as speakers and air conditioners located in the bedroom are connected to sub-router 2, and IoT devices such as rice cookers and water purifiers located in the kitchen are connected to sub-router 3. Mobile IoT devices such as mobile phones and tablets select to connect to the nearest sub-router according to the current location of the device. For example, when the mobile phone is in the living room, it is connected to sub-router 1, and when the user takes the mobile phone into the bedroom, the router to which the mobile phone is connected switches from sub-router 1 to sub-router 2.

[0326] Generally, in a Mesh network, IoT devices are all connected to the nearby sub-router, and the main router does not hang (i.e., connect) IoT devices. In a possible implementation, the main router can also hang IoT devices.

[0327] The process of registering the main router 40A and the sub-router 40B to the cloud server through an electronic device is similar to the process described above Figure 5 - 7 as shown, and for details, reference can be made to the description of Figure 5 - 7 and will not be elaborated here.

[0328] Figure 15 The flowchart of the router Mesh networking provided by the embodiment of the present application is shown. Please refer to Figure 15 , and the process includes:

[0329] Step S501: Power on the first router.

[0330] After the router is powered on and starts up, the router process of the router is triggered to run.

[0331] Step S502: The electronic device sets the first router as the main router.

[0332] Specifically, the APP or WebUI of the electronic device sets the first router as the main router in response to the user's first setting operation.

[0333] Step S503: The second router is powered on.

[0334] The second router can be powered on simultaneously with the first router or successively. In the embodiments of the present application, the step numbers do not constitute a limitation on the execution order of the steps.

[0335] Step S504: The electronic device sets the second router as a sub-router.

[0336] Multiple second routers are connected to the first router by wire (network cable) or wireless (Wi-Fi) means. Among them, each second router can be directly connected to the first router or indirectly connected to the first router through other second routers. The APP or WebUI of the electronic device sets each second router as a sub-router in response to the user's second setting operation. For the convenience of illustration, only 1 second router is shown in the figure.

[0337] Through the above method, Mesh networking of the routers is achieved, and the main router and multiple sub-routers jointly form a mesh structure. The IoT device is communicatively connected to the sub-router, and the sub-router is communicatively connected to the main router. Among them, one sub-router can be connected to one or more IoT devices.

[0338] In the Mesh networking scenario, each sub-router performs scanning, authentication, and channel establishment for the IoT devices connected to it. The specific process is the same as that of Figure 8 the process of the router scanning the IoT device shown, Figure 9 the process of the router authenticating with the IoT device shown, and Figure 10 the process of the router establishing a channel with the IoT device shown, and can refer to the description of Figure 8 - 10 in the previous text.

[0339] When the network parameters of the main router are modified, the main router sends the modified network parameters to each sub-router, and each sub-router respectively updates the network parameters of the IoT devices connected to it. That is, after receiving the modified network parameters, the sub-router executes Figure 11 and Figure 13 the relevant steps in the network parameter update process shown. Figure 16The figure shows a schematic flowchart of network parameter update in the Mesh networking scenario provided by the embodiments of the present application. For the convenience of illustration, only three sub-routers are shown in the figure. The update process includes:

[0340] Step S601: The electronic device sends a network parameter modification instruction to the main router.

[0341] After the electronic device receives the operation of the user to modify the network parameters, it generates a network parameter modification instruction and sends it to the main router.

[0342] Step S602: The main router sends network parameter modification instructions to Sub-router 1, Sub-router 2, and Sub-router 3 respectively.

[0343] Among them, Step S602 includes Steps S602a to S602c:

[0344] Step S602a: The main router sends a network parameter modification instruction to Sub-router 1.

[0345] Step S602b: The main router sends a network parameter modification instruction to Sub-router 2.

[0346] Step S602c: The main router sends a network parameter modification instruction to Sub-router 3.

[0347] The main router can send network parameter modification instructions to the three sub-routers in an asynchronous manner without waiting for the response of each sub-router, so as to improve the network parameter update efficiency.

[0348] Step S603: Each sub-router updates the network parameters of the IoT devices connected to it.

[0349] Taking Sub-router 1 as an example, the process of Sub-router 1 updating the network parameters of the IoT devices connected to it includes Steps S603a to S603c:

[0350] Step S603a: Sub-router 1 updates the network parameters of the IoT device 1 connected to it.

[0351] Step S603b: Sub-router 2 updates the network parameters of the IoT device 2 connected to it.

[0352] Step S603c: Sub-router 3 updates the network parameters of the IoT device 3 connected to it.

[0353] The processes of Sub-router 2 and Sub-router 3 updating the network parameters of the IoT devices connected to them are similar to that of Sub-router 1 and are not listed one by one in the figure.

[0354] Among them, the network parameter updates for the IoT devices connected to each sub-router can be synchronized. Moreover, when each sub-router updates the network parameters of the IoT devices connected to it, the new network parameter information can be sent to the IoT devices asynchronously to improve the network parameter update efficiency.

[0355] In the scenario where the main router also has IoT devices connected to it, after receiving the network parameter modification instruction, in addition to performing step S602, the main router also updates the network parameters of the IoT devices connected to itself. The process of the main router updating the network parameters of the IoT devices connected to itself is the same as Figure 11 the process shown. The following combines Figure 17 to elaborate in detail on the process of modifying network parameters through sub-routers in the Mesh networking scenario. Figure 17 FIG. shows a schematic flow diagram of network parameter update through a sub-router in the Mesh networking scenario provided by an embodiment of the present application. For the convenience of illustration, only 1 sub-router is shown in the figure. When the Mesh network includes multiple sub-routers, the network parameter update process involved in each sub-router is the same as that of the sub-router shown in the figure. The network parameter update process may specifically include:

[0356] Step S701: The electronic device generates a network parameter modification instruction in response to an operation of modifying network parameters.

[0357] For example, the user modifies the old network name and password SSID1 / password1 of the main router to the new network name and password SSID2 / password2 through a mobile phone. Correspondingly, the network name and password SSID1 / password1 of all sub-routers connected to the main router are also modified to the new network name and password SSID2 / password2.

[0358] Step S702: The electronic device sends the network parameter modification instruction to the router process of the main router.

[0359] The specific implementation processes of steps S701 - S702 are similar to those of steps S350 - S351. The difference is that the router involved in S350 - S351 is the only router in the network scenario, and the router that receives the network parameter modification instruction in steps S701 - S702 is the main router in the Mesh networking scenario.

[0360] For the scenario of network parameter update on the electronic device in the Mesh networking scenario, refer to Figure 18 . Figure 18 18(a) - 18(c) in Figure 12The interfaces in FIGS. 12(a)-12(c) are the same. For the specific operation method and the content displayed on the interface, please refer to the previous description of Figure 12 . Figure 18 The difference from Figure 12 is that after the electronic device sends a network parameter modification instruction to the router process of the router in step S702, the Wi-Fi settings interface 30 displays Figure 18 the prompt message "Synchronizing other Mesh devices, please wait" shown in FIG. 8(d).

[0361] Step S703: The router process of the main router sends the network parameter modification instruction to the router process of the sub-router.

[0362] The main router sends a network parameter modification instruction to each sub-router in the current Mesh network through the local area network. For the convenience of illustration, only 1 sub-router is shown in the figure.

[0363] In a possible implementation manner, if the main router is also connected to IoT devices, after receiving the network parameter modification instruction in step S702, in addition to executing step S703, the main router also updates the network parameters of the IoT devices to be synchronized under itself. That is, for the IoT devices connected to the main router, the same steps as Figure 11 the steps S352 to S366 shown in FIG. 19 are also executed to update the network parameters.

[0364] Step S704: The router process of the sub-router sends the network parameter modification instruction to the network parameter synchronization service process.

[0365] Step S705: The network parameter synchronization service process of the sub-router analyzes the network parameter modification instruction to obtain new network parameter information, and generates a network parameter update message based on the new network parameter information.

[0366] The new network parameter information includes the modified network name (SSID2) and / or the modified password (password2, simply referred to as PW2). The network parameter update message generated by the network parameter information at least includes the frequency band (i.e., the frequency band corresponding to the modified network parameters), the network name before modification (SSID1), the network name after modification (SSID2), and the modified password (password2).

[0367] Step S706: The network parameter synchronization service process of the sub-router sends the network parameter update message to the network password modification module.

[0368] Step S707: The network password modification module of the sub-router obtains the IoT device list from the device management module of the sub-router.

[0369] The IoT devices in the IoT device list obtained by the sub-router are the IoT devices connected under this sub-router.

[0370] Step S708: The network password modification module of the sub-router determines whether the IoT devices in the IoT device list are IoT devices to be synchronized.

[0371] Step S709: The network password modification module of the sub-router queries the active session connection module for the security channels to which the IoT devices to be synchronized are currently connected.

[0372] Step S710: The network password modification module of the sub-router sends the new network parameter information and the channel identifier of the security channel to which the IoT device to be synchronized is currently connected to the active session connection module.

[0373] Step S711: The active session connection module of the sub-router asynchronously sends the new network parameter information to the IoT device to be synchronized through the security channel.

[0374] Step S712: The IoT device to be synchronized modifies the network parameters according to the new network parameter information and generates a modification result.

[0375] Step S713: The IoT device to be synchronized sends the modification result to the passive session connection module of the sub-router.

[0376] Step S714: The passive session connection module of the sub-router sends the modification result to the active session connection module.

[0377] Step S715: The active session connection module of the sub-router sends the modification result to the network password modification module.

[0378] Step S716: The network password modification module of the sub-router sends the modification result to the network parameter synchronization service process.

[0379] Step S717: After the network password modification module of the sub-router receives the modification results sent back by all the IoT devices to be synchronized in the IoT device list, it sends the aggregated modification data to the network parameter synchronization service process.

[0380] After all the IoT devices in the IoT device list of the sub-router are traversed, and network parameter updates are performed on all the IoT devices confirmed to be IoT devices to be synchronized among them, the network password modification module of the sub-router aggregates the received modification results to obtain aggregated modification data and sends it to the network parameter synchronization service process.

[0381] The summary modified data includes whether the network parameter update of the IoT devices with current modifications (i.e., the last modification) is successful, the number of IoT devices with successful network parameter updates, the number of IoT devices with failed network parameter updates, and the number of all IoT devices in the IoT device linked list. Among them, if the physical channel between the IoT device to be synchronized and the router is disconnected, resulting in the router failing to send new network parameters to the IoT device to be synchronized, or the IoT device to be synchronized sends a modification result to the router but the modification result fails to reach the router successfully, both will cause the network password modification module of the router not to receive the modification result of the IoT device to be synchronized. When the network password modification module counts the number of IoT devices with failed network parameter updates, the IoT devices with failed network parameter updates include the IoT devices for which the modification result received by the network password modification module is failed, and the IoT devices that have been sent new network parameters but have not received the modification result returned by the IoT device.

[0382] Step S718: The network parameter synchronization service process of the sub-router sends the modification result and the summary modified data to the router process.

[0383] The specific implementation process of steps S704 - S718 is similar to that of steps S352 - S366. The difference is that the router involved in S352 - S366 is the only router in the network scenario, and the router in steps S704 - S716 is the sub-router in the Mesh networking scenario.

[0384] Step S719: The router process of the sub-router sends the modification result and the summary modified data to the router process of the main router.

[0385] Specifically, each sub-router sends the network parameter modification result and the summary modified data of the IoT devices it is connected to the main router, so that the main router can obtain the network parameter modification results of all IoT devices in the Mesh network scenario and the summary modified data of the IoT devices connected to each sub-router.

[0386] Step S720: The router process of the main router sends the received modification result and the summary modified data to the electronic device.

[0387] Specifically, the router process of the main router sends the modification result and the summary modified data to the APP or WebUI of the electronic device to notify the APP or WebUI of the electronic device of the synchronization result of the network parameters.

[0388] Step S721: The electronic device displays the modification result and the summary modified data.

[0389] Exemplarily, after the network password modification module of each sub-router synchronizes all the new network parameters to the IoT devices to be synchronized, a "Synchronization Successful" prompt as shown in 18(e) in Figure 18 is displayed beside the 2.4G Wi-Fi of the Wi-Fi settings interface 30 to remind the user that the modification of the network parameters of the IoT devices this time is successful. For the IoT devices for which the modification is not successful this time, the user can also choose to manually update the network parameters on the electronic device. Figure 18 After the network password modification module of each sub-router synchronizes all the new network parameters to the IoT devices to be synchronized, a "Synchronization Successful" prompt as shown in 18(e) in Figure 18 is displayed beside the 2.4G Wi-Fi of the Wi-Fi settings interface 30 to remind the user that the modification of the network parameters of the IoT devices this time is successful. For the IoT devices for which the modification is not successful this time, the user can also choose to manually update the network parameters on the electronic device.

[0390] In the above manner, after modifying the network parameters of the main router in the Mesh networking scenario, the main router sends a network parameter modification instruction to the sub-router, and the sub-router automatically modifies the network parameters of each IoT device connected to the sub-router, eliminating the cumbersome manual operations of the user, not only improving the user experience, but also avoiding errors and omissions in manual operations. The network parameter modification operations of multiple sub-routers can be executed synchronously, and the entire process of each sub-router sending the modified network parameters to each IoT device connected to it is also executed concurrently, further improving the update efficiency of network parameters and the user experience. Moreover, since the router issues the new network parameters through the security channel actively established with the IoT device, the security of the network parameters transmitted between the router and the IoT device is ensured.

[0391] The embodiment of the present application also provides a router. Figure 19 The structural schematic diagram of the router provided by the embodiment of the present application is shown. As shown in Figure 19 , the router 40 may include: a processor 302 and a memory 304. Figure 19 As shown in Figure 19 , the router 40 may include: a processor 302 and a memory 304.

[0392] Among them, the memory 304 is used to store a computer program 306. The memory 304 may include a high-speed RAM memory, and may also include non-volatile memory, such as at least one disk memory. The computer program 306 may include computer executable instructions.

[0393] The processor 302 is used to execute the computer program 306 to implement the above-mentioned embodiment of the network parameter update method. When the router 40 is a router in a non-Mesh networking scenario, the processor 302 is used to execute the computer program 306 to implement the above-mentioned Figure 1 - 13 shown embodiment of the network parameter update method. When the router 40 is the main router in the Mesh networking scenario, the processor 302 is used to execute the computer program 306 to implement the operation process of the main router in the above-mentioned Figure 14 - 18 shown network parameter update method. When the router 40 is a sub-router in the Mesh networking scenario, the processor 302 is used to execute the computer program 306 to implement the above-mentioned Figure 14 - 18The operation process of the sub-router in the network parameter update method shown above.

[0394] The processor 302 can be a central processing unit (CPU), or a specific application integrated circuit (ASIC), or one or more integrated circuits configured to implement the embodiments of the present application. One or more processors included in the router 40 can be of the same type of processor, such as one or more CPUs; or they can be of different types of processors, such as one or more CPUs and one or more ASICs.

[0395] The embodiments of the present application also provide a computer-readable storage medium, which is a non-volatile storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, it implements the embodiments of the above-mentioned network parameter update method.

[0396] The embodiments of the present application also provide a computer program, which can be executed by a processor to implement the embodiments of the above-mentioned network parameter update method.

[0397] The embodiments of the present application also provide a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the embodiments of the above-mentioned network parameter update method.

[0398] In several embodiments provided by the present application, if any function is implemented in the form of a software functional module / unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, all or part of the technical solutions of the present application can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be an electronic device such as a personal computer or a server) to execute all or part of the steps of the methods described in the various embodiments of the present application. The foregoing storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs, etc., which can store computer program codes.

[0399] The algorithms or displays provided herein are not inherently related to any specific computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings provided herein. The structure required to construct such a system will be apparent from the above description. In addition, the embodiments of the present application are not directed to any specific programming language. It should be understood that the content of the present application described herein can be implemented using various programming languages, and the description of the specific language above is for disclosing the best mode of the present application.

[0400] It should be noted that the above embodiments are illustrative of the present application rather than restrictive of the present application, and those skilled in the art can design alternative embodiments without departing from the scope of the appended claims. In the claims, any reference signs placed between parentheses shall not be construed as limiting the claim. The word "comprising" does not exclude the presence of elements or steps not listed in the claim. The word "a" or "an" preceding an element does not exclude the presence of a plurality of such elements. The present application can be implemented by means of hardware including several different elements and by means of a suitably programmed computer. In a claim listing several devices, several units or modules of these devices may be embodied by the same item of hardware. The use of the words first, second, and third, etc. does not denote any order. These words can be interpreted as names. The steps in the above embodiments, unless otherwise specified, should not be construed as limiting the order of execution.

[0401] The above-described embodiments merely represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but should not be construed as limiting the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. A network parameter update method, applied to a router, characterized in that Including: Receiving a first network parameter modification instruction, where the first network parameter modification instruction carries a first network parameter, and the first network parameter includes a first network name SSID and / or a first network password; Determining IoT devices to be synchronized from an IoT device linked list stored in the router, where the IoT device linked list is used to store device information of IoT devices that have passed the security authentication of the router and established a secure channel with the router; Asynchronously sending the first network parameter to multiple IoT devices to be synchronized respectively through the secure channels of each IoT device to be synchronized.

2. The method according to claim 1, characterized in that The first network parameter modification instruction further carries the SSID before modification, and the device information includes the SSID configured by the IoT device; The determining IoT devices to be synchronized from the IoT device linked list stored in the router further includes: Judging whether the SSID configured by the IoT device in the IoT device linked list is the same as the SSID before modification; If the SSID configured by the IoT device is the same as the SSID before modification, determining the IoT device as an IoT device to be synchronized.

3. The method according to claim 2, wherein The first network parameter modification instruction further carries first frequency band information, where the first frequency band information is used to indicate the currently modified network frequency band, and the device information further includes second frequency band information, where the second frequency band information is used to indicate the frequency band configured by the IoT device; Before judging whether the SSID configured by the IoT device in the IoT device linked list is the same as the SSID before modification, the determining IoT devices to be synchronized from the IoT device linked list stored in the router further includes: Judging whether the frequency band configured by the IoT device in the IoT device linked list is the same as the currently modified network frequency band according to the first frequency band information and the second frequency band information; If the frequency band configured by the IoT device is the same as the currently modified network frequency band, performing the step of judging whether the SSID configured by the IoT device in the IoT device linked list is the same as the SSID before modification; If the frequency band configured by the IoT device is different from the currently modified network frequency band, not performing the step of judging whether the SSID configured by the IoT device in the IoT device linked list is the same as the SSID before modification.

4. The method according to claim 1, wherein The IoT device linked list includes a first IoT device and a second IoT device; The determining IoT devices to be synchronized from the IoT device linked list stored in the router and asynchronously sending the first network parameter to multiple IoT devices to be synchronized respectively through the secure channels of each IoT device to be synchronized further includes: Determining whether the first IoT device is an IoT device to be synchronized; If it is determined that the first IoT device is an IoT device to be synchronized, sending the first network parameter to the first IoT device through the secure channel of the first IoT device; Determining whether the second IoT device is an IoT device to be synchronized; If it is determined that the second IoT device is an IoT device to be synchronized, send the first network parameter to the second IoT device through the secure channel of the second IoT device.

5. The method according to claim 1, characterized in that, The step of asynchronously sending the first network parameter to multiple IoT devices to be synchronized through the secure channels of each IoT device to be synchronized respectively further includes: Determine the channel identifier of the secure channel currently connected between the IoT device to be synchronized and the router; Send the first network parameter to the IoT device to be synchronized through the secure channel corresponding to the channel identifier.

6. The method according to claim 1, wherein After receiving the first network parameter modification instruction, the method further includes: starting a timer; The step of determining the IoT device to be synchronized from the IoT device list stored in the router further includes: Before the timing time of the timer arrives, determine the IoT device to be synchronized from the IoT device list stored in the router; When the timing time of the timer arrives, stop determining the IoT device to be synchronized from the IoT device list stored in the router, and identify the IoT devices in the IoT device list that have not been sent the first network parameter, to obtain the identified IoT devices; The method further includes: Receiving a second network parameter modification instruction, the second network parameter modification instruction carrying a second network parameter, the second network parameter including a second network name SSID and / or a second network password; Send the second network parameter to the identified IoT device through the secure channel of the identified IoT device; After sending the second network parameter to all the identified IoT devices, update the network parameters of the remaining IoT devices in the IoT device list other than the identified IoT devices.

7. The method according to claim 6, wherein The step of identifying the IoT devices in the IoT device list that have not been sent the first network parameter further includes: In the IoT device list, adjust the identified IoT device to the head of the IoT device list.

8. The method according to claim 1, characterized in that The method further includes: Receiving the network parameter modification result sent by the IoT device to be synchronized; Obtain summary modification data according to the received network parameter modification result; Send the network parameter modification result and the summary modification data to an electronic device, the electronic device being a device other than the router.

9. The method according to any one of claims 1-8, characterized in that The step of receiving the first network parameter modification instruction includes: receiving the first network parameter modification instruction sent by an electronic device, the electronic device being a device other than the router.

10. The method according to any one of claims 1-8, characterized in that, The router is a sub-router, The step of receiving the first network parameter modification instruction includes: receiving the first network parameter modification instruction sent by the main router.

11. The method according to claim 1, wherein The router includes a router process, a network parameter synchronization service process, a network password modification module, and a device management module; The step of receiving the first network parameter modification instruction includes: the router process receives the first network parameter modification instruction; After receiving the first network parameter modification instruction, the method further includes: The router process sends the first network parameter modification instruction to the network parameter synchronization service process; The network parameter synchronization service process parses the first network parameter modification instruction to obtain the first SSID and / or the first network password, and generates a network parameter update message based on the first SSID and / or the first network password; The network parameter synchronization service process sends the network parameter update message to the network password modification module; In response to receiving the network parameter update message, the network password modification module obtains the IoT device list from the device management module.

12. The method according to claim 1, characterized in that, The router includes a network password modification module and a device management module, and the IoT device list is stored by the device management module; Determining the IoT devices to be synchronized from the IoT device list stored in the router further includes: The network password modification module obtains the IoT device list from the device management module; The network password modification module determines whether the IoT devices in the IoT device list are IoT devices to be synchronized.

13. The method according to claim 12, wherein The first network parameter modification instruction further carries the SSID before modification and the first frequency band information, where the first frequency band information is used to indicate the network frequency band currently being modified, the device information includes the SSID configured by the IoT device and the second frequency band information, and the second frequency band information is used to indicate the frequency band configured by the IoT device; the method further includes: The network password modification module determines whether the frequency band configured by the IoT device in the IoT device list is the same as the currently modified network frequency band according to the first frequency band information and the second frequency band information; If the frequency band configured by the IoT device is the same as the currently modified network frequency band, the network password modification module determines whether the SSID configured by the IoT device in the IoT device list is the same as the SSID before modification; If the SSID configured by the IoT device is the same as the SSID before modification, the network password modification module determines the IoT device as an IoT device to be synchronized; If the frequency band configured by the IoT device is different from the currently modified network frequency band, the network password modification module determines whether the next IoT device in the IoT device list is an IoT device to be synchronized according to the first frequency band information and the second frequency band information.

14. The method according to claim 13, characterized in that, The router further includes an active session connection module; After the network password modification module determines the IoT device as an IoT device to be synchronized, the method further includes: The network password modification module queries the active session connection module for the secure channel currently connected between the IoT device to be synchronized and the router, and obtains the channel identifier of the secure channel currently connected between the IoT device to be synchronized and the router; The network password modification module sends the first network parameter and the channel identifier to the active session connection module; The active session connection module sends the first network parameter information to the IoT device to be synchronized through the secure channel corresponding to the channel identifier.

15. The method according to claim 12, characterized in that, The router further includes an active session connection module; The method further includes: in response to receiving the first network parameter modification instruction, the network password modification module starts a timer; The network password modification module determines whether the IoT devices in the IoT device list are IoT devices to be synchronized, and further includes: Before the timing time of the timer arrives, the network password modification module determines whether the IoT devices in the IoT device list are IoT devices to be synchronized; When the timing time of the timer arrives, the network password modification module stops determining whether the IoT devices in the IoT device list are IoT devices to be synchronized, and identifies the IoT devices in the IoT device list that have not been sent the first network parameter, obtaining the identified IoT devices; The method further includes: Receiving a second network parameter modification instruction, the second network parameter modification instruction carrying second network parameters, the second network parameters including a second network name SSID and / or a second network password; The network password modification module sends the second network parameters to the identified IoT devices through the secure channels of the identified IoT devices via the active session connection module; After sending the second network parameters to all the identified IoT devices, the network password modification module updates the network parameters of the remaining IoT devices in the IoT device list other than the identified IoT devices.

16. A router, comprising a memory, a processor, and a computer program stored on the memory, characterized in that, The processor executes the computer program to implement the network parameter update method according to any one of claims 1 to 15.

17. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the network parameter update method according to any one of claims 1 to 15.

18. A network system, including a main router and at least one sub-router, the sub-router being communicatively connected to the main router, and IoT devices being connected under the sub-router, characterized in that The main router is configured to receive a first network parameter modification instruction sent by an electronic device, the electronic device being a device other than the main router and the sub-router; The main router is configured to asynchronously send the first network parameter modification instruction to each sub-router; Each sub-router is configured to, in response to receiving the first network parameter modification instruction, determine IoT devices to be synchronized from the IoT device list stored in itself, the IoT device list being used to store the device information of the IoT devices that have passed the security authentication of the sub-router and established secure channels with the sub-router, and asynchronously send the first network parameter to a plurality of IoT devices to be synchronized through the secure channels of each IoT device to be synchronized.

19. The network system according to claim 18, wherein The sub-router is configured to execute the network parameter update method according to any one of claims 1 to 7 and 10 to 15.

20. The network system according to claim 18, characterized in that, IoT devices are connected under the main router, and the main router is configured to execute the network parameter update method according to any one of claims 1 to 9 and 11 to 15.

Citation Information

Patent Citations

  • Wireless configuration parameter synchronization method and device, network equipment and computer readable storage medium

    CN110602732A

  • Network updating method, device and equipment for networked intelligent equipment and storage medium

    CN115174388A

  • Password updating method and system, electronic equipment and computer readable storage medium

    CN116669026A

  • Communication method, readable medium and electronic equipment

    CN116684216A

  • Internet of Things Network Management and Control System and Method Thereof

    US20220159559A1